悪代官の伏魔殿掲示板
広告が出てきて困っています。
他の方と同様の質問ですが、どうか力をお貸しくださいませんか?

 知恵袋から進められてきました。昨日からIE8でwebページを開くたびに、高確率で、ページ内右下に正方形の小さな広告が出てきます。uniblueばかりかと思えば、ソシャゲの広告やブラウザゲーの広告なども出て、特にこれといって決まってはいない感があります。「ttp://adshield.find-allyouneed.com/ads.php?id=(以下略」が多いです。

ウイルス感染を疑ってMicrosoftSecurityEssentialsを使って調べたら「torojan DOS rovnix.d」が検出されました。削除しようにも、エラーが出て「検疫済み」と出るだけで、状況は改善されません。試みにウィルスバスタークラウドの体験版を使って調べたら、トロイは見つかりませんでしたが、代わりに上のアドレスがweb脅威として検出、ブロックされています。

javaは最新版にして、skypeも6.6.0.106にし、よけいなツールバーやソフトがないかコントロールパネルのプログラムのアンインストールで確認しましたが特に見当たりませんでした。

依然として状況の改善が見られないので、こちらで質問させていただいた次第です。OTLでとったログを貼りますので、どうかよろしくお願いします。

ログはこれから分割して貼ります。
  • 宵子
  • 2013/08/20 (Tue) 21:49:15
OTLでのログその1
OTL logfile created on: 2013/08/20 21:05:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\PCUser\Pictures\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

2.93 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 52.31% Memory free
5.85 Gb Paging File | 4.47 Gb Available in Paging File | 76.45% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 282.99 Gb Total Space | 150.78 Gb Free Space | 53.28% Space Free | Partition Type: NTFS
Drive D: | 282.99 Gb Total Space | 237.02 Gb Free Space | 83.76% Space Free | Partition Type: NTFS

Computer Name: ICEPC | User Name: PCUser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013/08/20 21:03:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\PCUser\Pictures\Desktop\OTL.exe
PRC - [2013/06/17 18:10:46 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2013/06/12 18:52:32 | 000,814,472 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
PRC - [2013/05/10 16:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/16 03:09:04 | 000,233,048 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
PRC - [2013/04/16 03:07:06 | 000,039,056 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/02/04 23:07:48 | 001,039,320 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
PRC - [2013/02/04 23:06:52 | 000,132,920 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2013/01/04 11:59:29 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012/07/13 20:17:36 | 000,221,264 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
PRC - [2012/07/13 20:17:24 | 000,142,984 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
PRC - [2012/07/13 20:17:02 | 000,674,464 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\AMSP\AMSP_LogServer.exe
PRC - [2011/11/30 19:46:41 | 000,207,456 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\System32\npkcmsvc.exe
PRC - [2011/02/26 14:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/07 15:21:56 | 001,212,416 | ---- | M] (Susumu Terao Software Library) -- C:\Program Files\TeraPad\TeraPad.exe
PRC - [2010/07/16 11:19:52 | 001,824,064 | ---- | M] (AuthenTec, Inc.) -- C:\Program Files\Fingerprint Sensor\AtService.exe
PRC - [2010/07/09 16:04:52 | 000,028,320 | ---- | M] () -- c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe
PRC - [2010/06/23 17:14:46 | 000,249,344 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
PRC - [2010/06/17 15:44:08 | 000,062,824 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\PSUtility\PSUService.exe
PRC - [2010/05/20 16:15:00 | 000,110,736 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2010/05/06 14:30:18 | 000,062,824 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\DustSolution\FJDService.exe
PRC - [2010/03/12 15:43:38 | 000,241,808 | ---- | M] (Paltiosoft Inc.) -- C:\Program Files\SoftDenchi\UCManSvc.exe
PRC - [2010/03/11 14:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/03/10 11:04:16 | 000,165,736 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
PRC - [2010/03/07 00:05:50 | 001,372,160 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
PRC - [2010/03/07 00:01:16 | 000,356,352 | ---- | M] (Red Bend Ltd.) -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
PRC - [2010/03/05 10:01:46 | 000,862,480 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2010/03/05 09:43:50 | 000,473,360 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2010/02/04 16:03:05 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/01/20 22:20:22 | 000,085,088 | ---- | M] () -- C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe
PRC - [2009/10/01 12:34:22 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/10/01 12:33:08 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/08/27 15:30:12 | 000,040,960 | ---- | M] (Softex Inc.) -- C:\Program Files\Softex\OmniPass\OmniServ.exe
PRC - [2009/08/27 15:21:10 | 000,073,728 | ---- | M] () -- C:\Program Files\Softex\OmniPass\opvapp.exe
PRC - [2009/08/27 12:17:00 | 000,012,800 | ---- | M] (FUJITSU LIMITED) -- C:\Program Files\Fujitsu\chitose\updnvsrv.exe
PRC - [2009/07/02 20:09:24 | 000,107,792 | ---- | M] () -- C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/05/03 04:26:30 | 000,049,152 | ---- | M] () -- C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_49.dll
MOD - [2012/05/03 04:24:14 | 000,057,344 | ---- | M] () -- C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_49.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [Auto | Running] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe -- (Amsp)
SRV - [2013/06/21 09:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/06/12 19:52:46 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/10 16:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/16 03:07:06 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/02 15:39:58 | 000,131,168 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SsBeService2.exe -- (SonicStage Back-End Service2)
SRV - [2012/10/19 02:09:44 | 000,163,424 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2012/01/13 07:36:01 | 000,316,888 | ---- | M] (Protection Technology) [Auto | Stopped] -- C:\windows\System32\appdrvrem01.exe -- (appdrvrem01)
SRV - [2011/11/30 20:01:04 | 000,678,416 | ---- | M] (Wellbia.com Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\xsherlock.xem -- (xsherlock)
SRV - [2011/11/30 19:46:41 | 000,207,456 | ---- | M] (INCA Internet Co., Ltd.) [Auto | Running] -- C:\Windows\System32\npkcmsvc.exe -- (npkcmsvc)
SRV - [2011/02/07 11:23:46 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/07/16 11:19:52 | 001,824,064 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- C:\Program Files\Fingerprint Sensor\AtService.exe -- (ATService)
SRV - [2010/07/09 16:04:52 | 000,028,320 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe -- (UDSS)
SRV - [2010/06/23 17:14:46 | 000,249,344 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe -- (PFNService)
SRV - [2010/06/17 15:44:08 | 000,062,824 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\PSUtility\PSUService.exe -- (PowerSavingUtilityService)
SRV - [2010/05/20 16:15:00 | 000,110,736 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2010/05/07 05:21:00 | 003,571,952 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2010/05/06 14:30:18 | 000,062,824 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\DustSolution\FJDService.exe -- (FjDstService)
SRV - [2010/03/12 15:43:38 | 000,241,808 | ---- | M] (Paltiosoft Inc.) [Auto | Running] -- C:\Program Files\SoftDenchi\UCManSvc.exe -- (UCManSvc)
SRV - [2010/03/11 14:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/03/10 11:04:16 | 000,165,736 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe -- (PUSCSRVC)
SRV - [2010/03/07 00:05:50 | 001,372,160 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv)
SRV - [2010/03/07 00:01:16 | 000,356,352 | ---- | M] (Red Bend Ltd.) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent)
SRV - [2010/03/05 10:01:46 | 000,862,480 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2010/03/05 09:43:50 | 000,473,360 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2010/01/20 22:20:22 | 000,085,088 | ---- | M] () [Auto | Running] -- C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe -- (CLHNService3)
SRV - [2009/10/01 12:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/10/01 12:33:08 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/08/27 15:30:12 | 000,040,960 | ---- | M] (Softex Inc.) [Auto | Running] -- C:\Program Files\Softex\OmniPass\OmniServ.exe -- (omniserv)
SRV - [2009/08/27 12:17:00 | 000,012,800 | ---- | M] (FUJITSU LIMITED) [Auto | Running] -- C:\Program Files\Fujitsu\chitose\updnvsrv.exe -- (UpdateNaviInstallService)
SRV - [2009/07/14 10:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 10:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/02 20:09:24 | 000,107,792 | ---- | M] () [Auto | Running] -- C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe -- (NetworkPlayer Server)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\xhunter1.sys -- (xhunter1)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\vtany.sys -- (vtany)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2013/03/17 22:44:39 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
DRV - [2012/12/21 19:50:12 | 000,258,976 | ---- | M] (Trend Micro Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2012/12/21 19:50:12 | 000,096,248 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2012/12/21 19:50:12 | 000,076,648 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2012/12/08 03:32:32 | 000,083,256 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tmeevw.sys -- (tmeevw)
DRV - [2012/07/06 12:33:22 | 000,171,064 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tmnciesc.sys -- (tmnciesc)
DRV - [2012/05/03 04:27:24 | 000,092,304 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2012/01/13 07:36:01 | 003,332,784 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\Windows\System32\drivers\appdrv01.sys -- (appdrv01)
DRV - [2011/11/16 20:11:56 | 000,010,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf001.sys -- (apf001)
DRV - [2010/07/16 11:36:58 | 000,659,968 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATSwpWDF.sys -- (ATSwpWDF)
DRV - [2010/06/20 10:53:54 | 000,029,168 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\clwvd.sys -- (clwvd)
DRV - [2010/06/08 04:36:14 | 000,343,592 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x)
DRV - [2010/05/11 13:47:18 | 003,486,976 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC)
DRV - [2010/05/07 11:19:54 | 000,193,056 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010/04/22 10:39:14 | 000,031,840 | ---- | M] (INCA Internet Co.,Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\npkakl.sys -- (npkakl)
DRV - [2010/03/17 22:21:16 | 006,758,912 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5s32.sys -- (NETw5s32)
DRV - [2010/02/26 16:31:22 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/24 11:09:38 | 000,141,568 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2010/02/24 11:09:38 | 000,060,544 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2010/02/03 06:36:34 | 000,232,960 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2010/01/20 22:20:28 | 000,119,536 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\ntk3.sys -- (ntk3)
DRV - [2009/12/22 21:37:54 | 000,144,384 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bpmp.sys -- (bpmp)
DRV - [2009/12/22 21:37:50 | 000,069,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bpusb.sys -- (bpusb)
DRV - [2009/12/22 21:37:46 | 000,056,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bpenum.sys -- (bpenum)
DRV - [2009/09/18 05:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009/09/10 15:29:08 | 000,055,200 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\npkcrypt.sys -- (npkcrypt)
DRV - [2009/07/14 08:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 08:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/14 07:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/07/02 11:51:29 | 000,012,776 | ---- | M] (FUJITSU LIMITED) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\FJGSDisk.sys -- (FJGSDisk)
DRV - [2009/06/24 14:33:18 | 000,017,008 | ---- | M] (FUJITSU LIMITED) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\FBIOSDRV.sys -- (FBIOSDRV)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/12/26 12:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vcsvad.sys -- (VCSVADHWSer)
DRV - [2007/04/17 20:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\regi.sys -- (regi)
DRV - [2006/11/01 19:59:24 | 000,005,632 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fuj02e3.sys -- (FUJ02E3)
DRV - [2006/11/01 19:20:28 | 000,005,888 | ---- | M] (FUJITSU LIMITED) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fuj02b1.sys -- (FUJ02B1)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://jp.hao123.com/?tn=smt_hp_hao123_jp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.jword.jp/jwd_sb_srchcust.htm?ielang={SUB_RFC1766}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,OCustomizeSearch = http://search.jword.jp/jwd_sb_srchcust.htm?ielang={SUB_RFC1766}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,OSearchAssistant = http://search.jword.jp/jwd_sb_srchasst.htm?ielang={SUB_RFC1766}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.jword.jp/jwd_sb_srchasst.htm?ielang={SUB_RFC1766}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{3A2FD38D-4D66-4950-A885-98C34AFBA65D}: "URL" = http://pt.afl.rakuten.co.jp/c/0c1426d1.3abb9778/_RTfujt11001004?v=2&s=1&sitem={searchTerms}
IE - HKLM\..\SearchScopes\{68DDB57F-3F01-45FF-BD69-0F7B57DC3015}: "URL" = http://azby.search.nifty.com/cgi-bin/search.cgi?select=1064&htmltype=2&cflg=%e6%a4%9c%e7%b4%a2&Text={searchTerms}
IE - HKLM\..\SearchScopes\{A437E1C7-7296-4224-833B-FD8F484B1585}: "URL" = http://www.amazon.co.jp/s/ref=azs_osd_ieajp?ie=UTF-8&tag=fujitsu07baawps-22&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\..\SearchScopes\{DB3C0454-D580-4934-8E3A-842A1AF5E4E2}: "URL" = http://ck.jp.ap.valuecommerce.com/servlet/referral?sid=2597372&pid=879140005&vc_url=http%3a%2f%2fshopping%2esearch%2eyahoo%2eco%2ejp%2fsearch%3fp%3d{searchTerms}
IE - HKLM\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpro.com/search/toolbar/hao123/{8AD499AB-226F-14BE-6AF9-7AA1EB74D396}?q={searchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://jp.msn.com/?ocid=iefvrt
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\URLSearchHook: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - No CLSID value found
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes,DefaultScope = {186575F1-85E3-4D4D-80DE-07369FD93E13}
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{186575F1-85E3-4D4D-80DE-07369FD93E13}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3281675&CUI=UN20675211112849183&UM=2
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpro.com/search/toolbar/hao123/{8AD499AB-226F-14BE-6AF9-7AA1EB74D396}?q={searchTerms}
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@gamechu.jp/gamechusupport-4: C:\GameOn\Common files\npgamechusupport.dll (GameOn)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@TrendMicro.com/FFExtension: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll (Trend Micro Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/17 18:13:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/06/17 18:13:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\tmbepff-7.5@trendmicro.com: C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1136\7.5.1136\firefoxextension [2013/08/20 21:01:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2013/08/20 17:23:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension\ [2013/08/20 21:01:17 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2009/06/11 06:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\2.5.1331\6.8.1094\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\7.5.1136\7.5.1136\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AzbyClubツールバー(&A)) - {3DB1C21B-A7E0-4C3F-B39E-E00DD8792D90} - C:\Program Files\@nifty toolbar\ntoolbar.dll (NIFTY Corporation)
O3 - HKLM\..\Toolbar: (Trend ツールバー) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\Toolbar\WebBrowser: (AzbyClubツールバー(&A)) - {3DB1C21B-A7E0-4C3F-B39E-E00DD8792D90} - C:\Program Files\@nifty toolbar\ntoolbar.dll (NIFTY Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CnsMin] C:\Windows\Downloaded Program Files\CnsMin.dll (JWord Inc. (Accessport Inc.))
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\PCUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: JWordでウェブ検索(&J) - C:\Windows\Downloaded Program Files\CnsMin.dll (JWord Inc. (Accessport Inc.))
O9 - Extra Button: OneNote に送る - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote に送る(&N) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: JWord (日本語キーワード) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.jword.jp/intro/?partner=AP&type=lk&frm=iebutton File not found
O9 - Extra Button: OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote リンク ノート(&K) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader6/DMMDownloader.cab (DMM Downloader)
O16 - DPF: {0E15796F-7B3A-4FB3-BF69-7B11D20A4A62} https://azby.fmworld.net/register/entrance/UserReg.CAB (AzbyClub ユーザー登録用 コントロール)
O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab (HGPluginJP28 Class)
O16 - DPF: {2B658B62-1B6F-4CFF-8A7C-225B7BB15336} http://static1.dotbook.jp/plugins/crochet_plug/T-TimeCrochet.cab#version=1,1,0,3 (CrochetCtrl Control)
O16 - DPF: {34E113CC-1B67-413A-9B0E-E9AA813DB888} https://n3o.qonline.jp/QGameStart.cab (QGameStart Control)
O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab (SpecAnalyzer Class)
O16 - DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} https://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab (Game Starter Control)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab (SysInfo Class)
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} https://nprotect.gameon.co.jp/nprotect/keycrypt/gamechu/npkcx_1005031.cab (NPKCX Control)
O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab (HgTAgent2 Extension Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab (PubPlugin Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{699EFE0D-ED46-4EAB-B7BF-5E21B1E80815}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C589A5D4-39A8-4332-AE18-66BC4570A6D1}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\7.5.1136\7.5.1136\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\2.5.1331\6.8.1094\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 06:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point
  • 宵子
  • 2013/08/20 (Tue) 21:50:30
OTLのログその2
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2013/08/20 21:03:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\PCUser\Pictures\Desktop\OTL.exe
[2013/08/20 18:24:38 | 000,083,256 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmeevw.sys
[2013/08/20 18:24:37 | 000,171,064 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmnciesc.sys
[2013/08/20 17:28:35 | 000,000,000 | -H-D | C] -- C:\TMRescueDisk
[2013/08/20 17:24:32 | 000,000,000 | ---D | C] -- C:\Users\PCUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ウイルスバスター クラウド
[2013/08/20 17:23:54 | 000,092,304 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmtdi.sys
[2013/08/20 17:23:52 | 000,258,976 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmcomm.sys
[2013/08/20 17:23:52 | 000,096,248 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmactmon.sys
[2013/08/20 17:23:52 | 000,076,648 | ---- | C] (Trend Micro Inc.) -- C:\windows\System32\drivers\tmevtmgr.sys
[2013/08/20 17:10:12 | 137,050,768 | ---- | C] (Trend Micro Inc.) -- C:\Users\Public\Desktop\Trend_Micro.exe
[2013/08/20 16:26:00 | 000,000,000 | ---D | C] -- C:\temp
[2013/08/20 16:13:12 | 000,000,000 | ---D | C] -- C:\Users\PCUser\AppData\Local\Trend Micro
[2013/08/20 16:11:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Trend Micro
[2013/08/20 15:56:45 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2013/08/20 14:33:11 | 000,000,000 | ---D | C] -- C:\Users\PCUser\Pictures\Desktop\new39
[2013/08/19 23:58:21 | 000,000,000 | ---D | C] -- C:\Users\PCUser\AppData\Roaming\Oracle
[2013/08/19 23:28:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013/08/19 23:28:01 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2013/08/19 23:27:51 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2013/08/19 23:27:51 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\windows\System32\java.exe
[2013/08/19 23:26:43 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2013/08/19 22:29:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/19 22:28:49 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/08/19 22:28:43 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/08/19 22:28:43 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/08/14 17:26:50 | 000,000,000 | ---D | C] -- C:\windows\System32\MRT
[2013/08/01 01:31:26 | 000,000,000 | ---D | C] -- C:\Users\PCUser\Pictures\Desktop\pic20130801
[2013/07/21 23:33:15 | 000,000,000 | ---D | C] -- C:\Users\PCUser\Pictures\Desktop\書籍・論文の内容まとめ
[2013/07/21 22:59:52 | 000,000,000 | ---D | C] -- C:\Users\PCUser\Pictures\Desktop\内言
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2013/08/20 21:03:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\PCUser\Pictures\Desktop\OTL.exe
[2013/08/20 20:54:18 | 000,009,920 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 20:54:18 | 000,009,920 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 20:52:00 | 000,000,626 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/08/20 20:45:54 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/08/20 20:45:51 | 2355,580,928 | -HS- | M] () -- C:\hiberfil.sys
[2013/08/20 17:23:15 | 000,000,242 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2013/08/20 17:23:15 | 000,000,059 | ---- | M] () -- C:\windows\System32\SupportTool.exe.bat
[2013/08/20 17:20:47 | 137,050,768 | ---- | M] (Trend Micro Inc.) -- C:\Users\Public\Desktop\Trend_Micro.exe
[2013/08/20 16:10:14 | 000,000,036 | ---- | M] () -- C:\Users\PCUser\AppData\Local\housecall.guid.cache
[2013/08/20 15:46:49 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2013/08/19 23:27:35 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\windows\System32\WindowsAccessBridge.dll
[2013/08/19 23:27:31 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2013/08/19 23:27:31 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2013/08/19 23:27:30 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\windows\System32\java.exe
[2013/08/19 23:27:29 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\windows\System32\npDeployJava1.dll
[2013/08/19 23:27:29 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\windows\System32\deployJava1.dll
[2013/08/14 17:21:28 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/08/14 17:21:28 | 000,391,258 | ---- | M] () -- C:\windows\System32\perfh011.dat
[2013/08/14 17:21:28 | 000,106,756 | ---- | M] () -- C:\windows\System32\perfc011.dat
[2013/08/14 17:21:28 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/08/08 16:54:37 | 000,001,171 | ---- | M] () -- C:\Users\PCUser\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM PLAYER.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013/08/20 17:23:15 | 000,000,059 | ---- | C] () -- C:\windows\System32\SupportTool.exe.bat
[2013/08/20 16:11:45 | 000,000,242 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2013/08/20 16:10:14 | 000,000,036 | ---- | C] () -- C:\Users\PCUser\AppData\Local\housecall.guid.cache
[2013/03/17 22:44:39 | 000,016,304 | ---- | C] () -- C:\windows\System32\apl003.sys
[2013/03/17 22:44:39 | 000,013,232 | ---- | C] () -- C:\windows\System32\apf003.sys
[2012/04/30 16:51:55 | 000,009,728 | ---- | C] () -- C:\Users\PCUser\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/16 20:11:56 | 000,012,920 | ---- | C] () -- C:\windows\System32\apl001.sys
[2011/11/16 20:11:56 | 000,010,872 | ---- | C] () -- C:\windows\System32\apf001.sys
[2011/05/15 19:48:17 | 000,000,017 | ---- | C] () -- C:\Users\PCUser\AppData\Local\resmon.resmoncfg
[2011/02/07 10:51:37 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 13:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 13:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 10:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 10:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %windir%\tasks\*.job >[/color]
[2013/08/20 20:52:00 | 000,000,626 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job

[color=#E56717]========== Drive Information ==========[/color]

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD6400BPVT-16HXZT1
Partitions: 4
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 30.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 200.00MB
Starting Offset: 32213303296
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 283.00GB
Starting Offset: 32423018496
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 283.00GB
Starting Offset: 336278323200
Hidden sectors: 0


[color=#E56717]========== Base Services ==========[/color]
SRV - [2009/07/14 10:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2009/07/14 10:14:53 | 000,046,592 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009/07/14 10:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2009/07/14 10:16:12 | 000,589,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2009/07/14 10:14:59 | 000,493,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/17 14:36:26 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/07/14 10:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012/07/05 06:23:55 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012/06/02 13:45:21 | 000,139,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2009/07/14 10:16:13 | 000,376,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2009/07/14 10:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011/03/03 14:29:23 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/07/14 10:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/07/14 10:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009/07/14 10:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2009/07/14 10:15:33 | 000,350,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/07/14 10:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009/07/14 10:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009/07/14 10:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009/07/14 10:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2009/07/14 10:16:03 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009/07/14 10:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011/05/24 19:35:34 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012/02/11 14:41:06 | 000,316,928 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/17 14:36:26 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009/07/14 10:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2009/07/14 10:16:12 | 000,285,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2009/07/14 10:16:13 | 000,376,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009/07/14 10:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/17 14:36:26 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2010/12/21 14:38:24 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/08/27 14:46:48 | 000,168,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2009/07/14 10:16:14 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010/11/02 13:39:32 | 000,749,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2009/07/14 10:16:15 | 000,241,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/14 10:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012/05/02 13:52:09 | 000,163,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2009/07/14 10:14:43 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2009/07/14 10:14:57 | 000,473,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2009/07/14 10:14:57 | 000,473,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2009/07/14 10:16:13 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2009/07/14 10:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 10:16:18 | 001,086,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2009/07/14 10:15:41 | 000,565,760 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2009/07/14 10:16:18 | 000,462,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
SRV - [2009/07/14 10:14:25 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/07/14 10:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/03 07:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2009/07/14 10:15:12 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009/07/14 10:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2009/07/14 10:16:19 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< End of report >
  • 宵子
  • 2013/08/20 (Tue) 21:51:36
OTLでのログ―Extrasその1
OTL Extras logfile created on: 2013/08/20 21:05:38 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\PCUser\Pictures\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

2.93 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 52.31% Memory free
5.85 Gb Paging File | 4.47 Gb Available in Paging File | 76.45% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 282.99 Gb Total Space | 150.78 Gb Free Space | 53.28% Space Free | Partition Type: NTFS
Drive D: | 282.99 Gb Total Space | 237.02 Gb Free Space | 83.76% Space Free | Partition Type: NTFS

Computer Name: ICEPC | User Name: PCUser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00C1F53D-3AF1-46D1-BA65-B7F27224B4A9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{03137D03-B1A0-4B8B-BD2E-335DF3360B64}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{106CCFC3-5754-497E-B9CF-26928C290B65}" = rport=139 | protocol=6 | dir=out | app=system |
"{11D624F8-DD84-4456-9CEB-E25E389DDE11}" = rport=138 | protocol=17 | dir=out | app=system |
"{1364CA9D-2B10-447D-B0DF-B83799C9847F}" = lport=137 | protocol=17 | dir=in | app=system |
"{164501B5-D108-4095-9BA7-9402F42FF636}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2DB7ED6F-A522-4EF7-9731-8EDBD9CF11D2}" = lport=138 | protocol=17 | dir=in | app=system |
"{2FB3FBE8-9409-4811-BD29-6B1973807323}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{3C9B269D-16E8-4980-B3FF-FDB68EF3EC4E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{415DB9B9-A5F8-4F03-BCBA-44C3CB641194}" = lport=445 | protocol=6 | dir=in | app=system |
"{486C2212-C2AF-4B62-B2A3-B14E2B63155C}" = lport=10800 | protocol=17 | dir=in | name=非想天則ポート開放のルール |
"{508E321B-3154-46EA-B20D-F8192064063E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7ACC8476-804D-4117-87BA-92D8D37A37DC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{89AD47C9-965A-43A6-AC24-B927CAA4BEE1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{922B8236-7D4C-453A-A7B7-AC740F2007C7}" = rport=137 | protocol=17 | dir=out | app=system |
"{AD7D0CC1-D07D-4EDC-AEA0-536720449B45}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B89F6670-8483-46CD-A06C-2310623A94D9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BCD2F528-C638-49E6-9E60-6CB76F1F4BA6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CF3CF084-4FA8-4DF9-B748-41D404CFF6FA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{CFEB8A4F-A7D8-4A6C-A270-8BB707D7016C}" = rport=445 | protocol=6 | dir=out | app=system |
"{D57DC6D1-8B7B-4485-A629-3A3A9BA82D4B}" = lport=139 | protocol=6 | dir=in | app=system |
"{D869BAC3-2287-4BB3-AE55-E24695112E4B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D9D6642E-628F-4D17-B4DB-197CB6D69B63}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DC856C42-9E00-42F6-ADAA-1791368C7BFB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DFD9464B-B0AB-4BFC-BA5B-32FA2A57ABC0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F3F6790D-61EF-4E54-B603-99E8D04E2D43}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{F5A4B3C4-7D0C-4B83-BB46-477BDDA1C9C1}" = rport=10800 | protocol=17 | dir=out | name=非想天則ポート開放のルール |
"{FC14FE24-D567-4A7A-B467-4A3C6444A52D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05FCA165-D416-42C9-85FB-9EB1C478A866}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{163B4594-F12B-4DA5-B372-F9E583D7DDE0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1703FE64-2DB1-4182-80FA-3C988BBCCBFE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{19BEB529-3F1A-4146-A5A4-8305EE72DD47}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1EF7ECB7-2C22-472E-936F-9ED061E172D9}" = protocol=17 | dir=in | app=c:\program files\giraffic\veoh_girafficwatchdog.exe |
"{1F8B0F96-3E33-4397-A8A6-E9E2C492614B}" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe |
"{22AF88B7-EFE1-4CDC-93EF-4181039AFE54}" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe |
"{248D8D1E-76E1-42DB-9BCD-0DDF9A7ECA09}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{28C317F9-5ED4-4B7C-AE32-889C37F7756E}" = dir=in | app=c:\program files\janetter2\bin\janettersrv.exe |
"{29D8510B-89DD-40C6-9BB8-ECB27350B6F1}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{2ABDCD72-3397-4D55-BDF9-2B70C6760200}" = protocol=17 | dir=in | app=c:\program files\upnpcj\upnpcj.exe |
"{2DF07D71-A9DB-4108-B8C5-DB22E46CB2CB}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{41F5F02C-915E-4BF8-8751-9D79A0FDE152}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{46287FC9-C98F-4EB0-BCBD-C862EC4283D3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{4FB8B354-8C59-4168-8DC0-E2022E04D1A0}" = protocol=6 | dir=in | app=c:\program files\logmein hamachi\hamachi-2-ui.exe |
"{54CC943C-C488-49DC-97F4-6EDAA8910A4A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{55994DCE-4915-4E87-87DB-F95D1371C80B}" = protocol=6 | dir=in | app=c:\hanpurple\elsword\data\x2.exe |
"{5A42AFE3-C551-4115-8ECB-B6744DAE95CF}" = protocol=6 | dir=in | app=c:\vector\harezora\_launcher.exe |
"{5E5EF8F9-44EA-4AF6-89A8-BD99545D63E9}" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe |
"{60A392E0-98AA-48A6-AD64-D6E67AF26E3B}" = protocol=17 | dir=in | app=c:\program files\logmein hamachi\hamachi-2-ui.exe |
"{688C47BD-9347-45F8-8522-5D5D7BDFC437}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{69CA6358-7955-4FF9-8DF2-16D5979CF528}" = protocol=17 | dir=in | app=c:\program files\領域zero\東方スカイアリーナ\tsa.exe |
"{703C7019-F3A9-4F49-B59D-C858DF51A849}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{7219E68A-1911-42C3-AE65-74DEA65711C7}" = protocol=17 | dir=in | app=c:\program files\gretech\gomplayer\gom.exe |
"{775E6FAF-CC3F-437A-ACB8-B59BA05681AD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{77FBCA8A-9CD9-4B5E-ADA7-F1D2C5A77341}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7CBFFE12-2F5C-4FEC-84AC-DC4459F1DEB1}" = protocol=17 | dir=in | app=c:\hanpurple\elsword\data\x2.exe |
"{7E11B47D-942C-4B13-B004-18F495B176B6}" = protocol=6 | dir=in | app=c:\program files\intel\wimax\bin\appsrv.exe |
"{8108350F-9D96-4F53-A1BC-A1CDF9DA1028}" = protocol=6 | dir=in | app=c:\vector\harezora\_launcher.exe |
"{83239D63-28E5-4CE6-9DD9-1019DC413CAF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8356C7BB-B58E-49C1-AF86-B99342CC453C}" = protocol=6 | dir=in | app=c:\program files\giraffic\veoh_girafficwatchdog.exe |
"{86954D90-E804-4B2C-BF85-E24257A9B591}" = protocol=17 | dir=in | app=c:\hanpurple\dnest\dragonnest.exe |
"{875FB7A4-96CB-4F78-AA41-10C1A2F94369}" = dir=in | app=c:\program files\fujitsu\networkplayer\networkplayer.exe |
"{8B9F78C4-5AA7-408E-A9F6-6587F3179DD6}" = protocol=6 | dir=in | app=c:\program files\gretech\gomplayer\gom.exe |
"{8DBDFC7B-41CE-4D91-AF6C-75269D5AD201}" = protocol=17 | dir=in | app=c:\vector\harezora\_launcher.exe |
"{8F30374D-1E28-47AD-A4E5-7586F1898A5E}" = protocol=6 | dir=in | app=c:\program files\upnpcj\upnpcj.exe |
"{90A4618E-04D7-4959-B49F-23FFF744EB39}" = dir=in | app=c:\program files\fujitsu\networkplayer server\fmvsttool.exe |
"{951394F2-E36E-4B48-9638-525C2F3C7D63}" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\th123\th123.exe |
"{A6901A1C-1868-4975-BEA3-2DEDFA00250F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A69C47B9-6D91-4BEF-AB6D-26661DA42D1C}" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\th123\th123.exe |
"{A798A7F6-46E5-4F67-8010-CAAF8BB1F7F5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A8BB87F3-BD6A-44E7-9DD0-DD3C624F7781}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AF007B6E-1662-48C2-989B-6C509726C6A9}" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe |
"{B6EA5E9A-6C4C-474E-87FD-E4FF26213467}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BC88AD87-3B52-451B-BF69-00212ACD7636}" = protocol=6 | dir=in | app=c:\hanpurple\dnest\dragonnest.exe |
"{BFF9815F-A9CC-4160-B14D-B41EEF90A2D0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C04851DF-B37C-4133-B3F3-B1A3776D8DFA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C1E82428-1DE5-4A15-B887-50A591669BAD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C52E0219-3DDF-410B-808E-1F075F669CFF}" = protocol=6 | dir=in | app=c:\program files\領域zero\東方スカイアリーナ\tsa.exe |
"{CBBCE7D9-474D-41A2-AF63-1B372D16A0F0}" = protocol=58 | dir=in | app=system |
"{CD8E1130-3B64-4209-81C6-905B06DB5EE1}" = protocol=17 | dir=in | app=c:\program files\intel\wimax\bin\dmagent.exe |
"{D4DA1EC5-9790-4721-A365-DA0FB436170F}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{D8D301D1-10AF-497C-BF3C-CEDD900922B2}" = protocol=6 | dir=in | app=c:\users\pcuser\saved games\東方project\th123\th123.exe |
"{DA5AB80F-E996-47E6-B511-2D8E912C6E13}" = protocol=17 | dir=in | app=c:\vector\harezora\_launcher.exe |
"{DE34F321-E256-49BF-B2B4-25B659A35D41}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{DE4CC77E-520A-4DA8-AE84-1816D5475CDD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E07C0387-9721-480E-9305-BF68E2323734}" = protocol=17 | dir=in | app=c:\program files\intel\wimax\bin\appsrv.exe |
"{E1FEAD68-8D42-4A1F-9F30-16CA3DF95033}" = protocol=17 | dir=in | app=c:\program files\giraffic\veoh_giraffic.exe |
"{E53064DC-10D2-435D-9E76-4002A75782B2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{E87D4ED1-42C1-412F-9686-50A4844437FC}" = dir=in | app=c:\program files\fujitsu\networkplayer server\networkplayerserver.exe |
"{E8A8D3AA-183C-4637-B276-7A1B5A1A1A31}" = protocol=17 | dir=in | app=c:\users\pcuser\saved games\東方project\th123\th123.exe |
"{EB19C5D6-753D-441B-8FA9-4D240E8A633B}" = protocol=6 | dir=out | app=system |
"{EBE88EC2-93FD-4E88-AB59-056AAE806046}" = protocol=6 | dir=in | app=c:\program files\intel\wimax\bin\dmagent.exe |
"{EEEDF533-7F3B-499F-8CF6-87841F40ECF6}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{EF71B34F-90B8-4104-9936-5D25D7AF15C3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F386104B-1332-4220-8E67-E10894B580E3}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{F5D8C5EE-B66E-4A21-B4B0-0B7463FC0AD5}" = protocol=6 | dir=in | app=c:\program files\giraffic\veoh_giraffic.exe |
"{FE6380DC-6473-4661-8BF7-8E420AC9BBD0}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{0641D3A4-CF02-4840-9A8C-B3031FA49FC1}C:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe |
"TCP Query User{119B5D3E-35FC-4D0D-B7D3-05A6666D2777}C:\program files\gretech\gomplayer\gom.exe" = protocol=6 | dir=in | app=c:\program files\gretech\gomplayer\gom.exe |
"TCP Query User{19D49776-B53B-41A7-9319-0765F6637E48}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{342CB75A-1419-4DC3-816E-F76A0378FCE2}C:\program files\領域zero\東方スカイアリーナ\tsa.exe" = protocol=6 | dir=in | app=c:\program files\領域zero\東方スカイアリーナ\tsa.exe |
"TCP Query User{A8B8F1D3-FA70-4E17-AD80-B85E2090D067}C:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe |
"TCP Query User{A938129C-DD7B-45EE-AC98-7DC455DAA4D6}C:\users\pcuser\pictures\desktop\th123\th123.exe" = protocol=6 | dir=in | app=c:\users\pcuser\pictures\desktop\th123\th123.exe |
"TCP Query User{B7E515AA-408D-4708-A4A1-A6F44EA3191A}C:\users\pcuser\saved games\東方project\th123\th123.exe" = protocol=6 | dir=in | app=c:\users\pcuser\saved games\東方project\th123\th123.exe |
"TCP Query User{DF16EC84-48A2-4679-8274-487B1DE52EE2}C:\windows\downloaded program files\plauncher.exe" = protocol=6 | dir=in | app=c:\windows\downloaded program files\plauncher.exe |
"TCP Query User{ED42574C-9ED5-4CF9-A133-6370A1E0D36C}C:\users\pcuser\downloads\bouyomichan\bouyomichan.exe" = protocol=6 | dir=in | app=c:\users\pcuser\downloads\bouyomichan\bouyomichan.exe |
"UDP Query User{00A04E35-419F-42FF-A7D8-73AD7894727B}C:\users\pcuser\downloads\bouyomichan\bouyomichan.exe" = protocol=17 | dir=in | app=c:\users\pcuser\downloads\bouyomichan\bouyomichan.exe |
"UDP Query User{01CC1018-D4ED-43AD-8FCB-1BE5CB6E3A5E}C:\program files\領域zero\東方スカイアリーナ\tsa.exe" = protocol=17 | dir=in | app=c:\program files\領域zero\東方スカイアリーナ\tsa.exe |
"UDP Query User{0389BC94-65F7-4596-8C4C-907685A9C05A}C:\users\pcuser\saved games\東方project\th123\th123.exe" = protocol=17 | dir=in | app=c:\users\pcuser\saved games\東方project\th123\th123.exe |
"UDP Query User{11EEFFCA-FB47-4A47-B3F5-163141C8B713}C:\users\pcuser\pictures\desktop\th123\th123.exe" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\th123\th123.exe |
"UDP Query User{1A9616EC-661E-4B9E-B476-A58BFECBE67A}C:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\bouyomichan\bouyomichan.exe |
"UDP Query User{90D2953D-1EC2-4CF0-84D9-6771D3F10726}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{A265D07F-A044-4705-AB4A-E9B702A5BC24}C:\program files\gretech\gomplayer\gom.exe" = protocol=17 | dir=in | app=c:\program files\gretech\gomplayer\gom.exe |
"UDP Query User{C241BD4E-0D1C-4FAE-8510-4833E6BCCD76}C:\windows\downloaded program files\plauncher.exe" = protocol=17 | dir=in | app=c:\windows\downloaded program files\plauncher.exe |
"UDP Query User{D3EFF1CE-7012-419D-918D-1DC7EDF1F806}C:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe" = protocol=17 | dir=in | app=c:\users\pcuser\pictures\desktop\thmj3g_tr\thmj3g_tr.exe |
  • 宵子
  • 2013/08/20 (Tue) 21:52:47
OTLでのログ―Extrasその2
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{E185BD5C-0E10-479F-AF44-63D3A068446A}" = Corel Digital Studio for Fujitsu
"{019EF473-6D0A-415C-9A2E-1AF5F66AC60F}" = Windows Live Messenger
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F3EF57F-D82E-4668-A199-6E7D13E85413}" = 筆ぐるめ Ver.17
"{10AB1F40-BDEC-4A8D-B427-30F9429378B0}" = Windows Live Movie Maker
"{13364813-4BAE-4F34-B0E9-32AF14A4E1B3}" = Windows Live Sync
"{140347A0-4A0C-44FC-9CA1-C8A3471899B7}" = SdRt4200
"{14B79826-8E53-30C2-8D88-28B8726C90FF}" = Microsoft .NET Framework 4 Client Profile JPN Language Pack
"{15D95497-8F76-41E5-8894-EDDB59E39BD9}" = Windows Live メール
"{160BDB91-D920-4C92-B543-C081176E3B5F}" = 電源オフUSB充電ユーティリティ
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1976F816-F838-4C2D-AC91-AF688351DD56}" = GIZMO テレビ連携 for PIXELA 2
"{1A8BA6CE-822D-4888-89E2-ACBF4308F271}" = インテル(R) PROSet/Wireless WiFi ソフトウェア
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{223469C7-3B3F-4D18-AB4A-4F4B298D0DB2}" = x-APPLICATION Components
"{224F03EA-8DA5-4413-9B80-FD3B7EABAF9B}" = 富士通モビリティセンター拡張
"{22A1A1C1-CEEC-4911-B36F-121464642478}" = ゆったり設定2
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29276E3F-15EF-49FC-9793-B07811C8059D}" = PC乗換ガイド
"{2B97F94C-F062-4508-817E-DAD1D1ABF526}" = AuthenTec Fingerprint Software
"{2BDE2BF2-AD90-4191-B3C8-D0046CE54916}" = Fujitsu Display Manager
"{3280C6F4-E3AC-45E5-8F57-F698F9357315}" = らくらく手書き入力
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{362E3F90-7937-4AA9-806D-0C40260C3D98}" = テレビNaviガジェット
"{378C547F-7AE3-467D-9E11-C888B026F62D}" = NetworkPlayer サーバー
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = FJ Camera
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B1E1F4C-031D-410F-A93A-1220236608C8}" = Microsoft Antimalware Service JA-JP Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C569633-C8DE-46E2-BB8F-F65198681C2F}" = マイフォト
"{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}" = RealDownloader
"{40CBEE04-BBA4-4243-87BA-1FC643562A0F}" = Plugfree NETWORK
"{41938788-1E1C-4A8B-A1CD-F34C7A4D3E0D}" = セキュリティ対策ソフト選択
"{42B44AE0-E0C3-4346-8FCC-A3E091CA41AF}" = GIZMO テレビ連携 for Windows Media Center
"{44193AE6-D871-473C-8D1F-D55FBCB45552}" = Inst5657
"{47BC37A3-35C8-484A-8CBD-851914EB095E}" = アップデートナビ
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype(TM) 6.6
"{4F26C164-9373-4974-8F43-E0F2176AF937}" = インテル WiMAX チュートリアル
"{502F994F-C810-4443-9223-5E3468A99910}" = 富士通PC 辞書セット(スーパー統合辞書+学研総合百科辞典+三省堂デイリー3か国語辞典)
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client JA-JP Language Pack
"{51FAA187-38A0-43CE-AD03-42108F503966}" = お手入れナビ
"{5705EC66-E894-454D-A014-ADF1DF920C10}" = いつもNAVI PC
"{5961706F-0832-4511-8108-A061BF6807C2}" = Yamaha Wave Sound Decorator
"{5C1F18D2-F6B7-4242-B803-B5A78648185D}" = Corel WinDVD
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = ワンタッチボタン設定
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6548B189-BEA4-4041-80E0-AEB60548E046}" = インテル(R) PROSet/Wireless WiMAX ソフトウェア
"{675D8E1E-2388-4718-902C-E5FC4888AC0E}" = Windows Live Essentials
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C3F8916-D6A5-4A31-9DA8-80C973CE437F}" = Windows Live Writer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BA0ECC1-2636-4169-9BF0-F49A1F7AAD87}" = 富士通起動ユーティリティ
"{7BA64D21-EE46-4a9a-8145-52B0175C3F86}" = Plugfree NETWORK
"{7E4CB404-F1E4-4E81-A1CB-2CBB310481D1}" = MLE
"{82F4EA7F-BBBD-4860-A347-5EC89897C7A4}" = Inspirium辞書検索ライブラリ
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83F00304-550B-4652-A12C-E301CB8B1EE4}" = スクリーンセーバー for FUJITSU PC
"{88A686A9-D687-4295-B633-50D8A4B88371}" = Windows Live Writer Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A66A2C8-0032-4949-8D99-C293A3EACF79}" = Windows Live Photo Common
"{8D59BE38-3A4F-4525-AD0D-8980E9E31EFA}" = Windows Live フォト ギャラリー
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E38F042-3863-43D6-9430-04B3610298C3}" = かんたんバックアップ
"{8E5CFA2B-8CC5-4C8D-88CB-C4A1D4AD9790}_is1" = 東方非想天則 Ver1.10aアップデート
"{90140000-0016-0411-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Japanese) 2010
"{90140000-0016-0411-0000-0000000FF1CE}_Office14.EssentialsR_{7F3577FB-B07A-47AB-A6E1-26D14D21C6BA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0411-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Japanese) 2010
"{90140000-0018-0411-0000-0000000FF1CE}_Office14.EssentialsR_{7F3577FB-B07A-47AB-A6E1-26D14D21C6BA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0411-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Japanese) 2010
"{90140000-001A-0411-0000-0000000FF1CE}_Office14.EssentialsR_{7F3577FB-B07A-47AB-A6E1-26D14D21C6BA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0411-0000-0000000FF1CE}" = Microsoft Office Word MUI (Japanese) 2010
"{90140000-001B-0411-0000-0000000FF1CE}_Office14.EssentialsR_{7F3577FB-B07A-47AB-A6E1-26D14D21C6BA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.EssentialsR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2010
"{90140000-001F-0411-0000-0000000FF1CE}_Office14.EssentialsR_{9FB78D03-3A34-4A57-B65D-0D7F32C1B603}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2010
"{90140000-0028-0411-0000-0000000FF1CE}_Office14.EssentialsR_{5E056779-9F4B-4593-86D3-28E5548A8B64}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0411-0000-0000000FF1CE}" = Microsoft Office Proofing (Japanese) 2010
"{90140000-002C-0411-0000-0000000FF1CE}_Office14.EssentialsR_{5FCA98B1-D6ED-43DC-B146-2C8DF169C353}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0411-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Japanese) 2010
"{90140000-006E-0411-0000-0000000FF1CE}_Office14.EssentialsR_{9DBC2773-7F63-45EE-AA4D-4677BA8B18B2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0411-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Japanese) 2010
"{90140000-00A1-0411-0000-0000000FF1CE}_Office14.EssentialsR_{7F3577FB-B07A-47AB-A6E1-26D14D21C6BA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0013-0000-0000-0000000FF1CE}" = Microsoft Office Essentials 2010
"{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{925F1DB6-E86E-4378-9091-D1F68B0583C9}" = iCloud
"{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B486871-27EB-49A5-8832-77176E63333C}" = iTunes
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A33E457B-5369-481F-8B53-71108AE2EB5B}" = Roxio Creator LJ
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = NetworkPlayer
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = ウイルスバスター クラウド
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium
"{AC76BA86-7AD7-1041-7B44-AA1000000001}" = Adobe Reader X (10.1.7) - Japanese
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B351DC34-2758-492A-ADEE-66C17A61860E}" = PowerUtility - スケジュール機能
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B49613B5-EEA6-48B4-AC9C-EA1F8BCF9EFF}" = GIZMO
"{B641E348-377C-4819-B92F-03F1D35A7EE3}_is1" = 東方心綺楼 Ver1.02
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BA0B4781-7874-49CF-BF45-D83DAB54888C}" = x-アプリ
"{BA0CC975-682B-4678-A35C-05E607F36387}" = IndicatorUtility
"{C24447C3-CACD-4ce3-BA95-1BE092E0C4F8}" = AzbyClubガジェットプログラム
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}" = System Requirements Lab for Intel
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A1B85E-328C-47C0-80EB-3AF2C567114E}" = 電子辞書
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{D8FA2A48-A1E8-432E-AE96-5276D9E6A50F}" = Sony Media Library Earth 8.0.00
"{DA98FA14-7784-4801-9E61-174F6738AAEA}" = 省電力ユーティリティ
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E1754ED2-CD39-4F5F-AC98-0271EAE1C116}" = Setup
"{E185BD5C-0E10-479F-AF44-63D3A068446A}" = ICA
"{E24A5C1E-8647-43FD-838B-DF7149D492E4}" = DeviceIO
"{E2C2F547-4C5B-45F9-8445-C59E223CCB08}" = ContentHD
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3C1C994-CA69-4B3C-A290-C311617DE271}" = Contents
"{E5636C06-A318-4CF3-803B-5BD9F5C10822}" = PureHD
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5D50A9A-B973-46DE-89E4-8BDDD8A9F988}" = Share
"{E6ABA0E9-65E7-4366-9770-514ED4341611}" = VIO
"{E7218813-D5BE-463A-986B-D64B9D4D2DDB}" = 晴空物語
"{E7EFA8C8-4CDE-4466-8E0E-01C04589ED90}" = ISCOM
"{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = 富士通拡張機能ユーティリティ
"{E902DA50-B519-4820-81C2-694226E23B2E}" = @niftyでブロードバンド
"{E91C1011-2083-4DD6-858D-11753DCDFF2D}" = Corel Direct DiscRecorder
"{E9327EB0-7209-4E47-8EE2-999D5E567CAE}" = テレビ出力ユーティリティ
"{EA6625D5-E563-4FE3-8D98-B3F5B64CBC67}" = IPM_OEM
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{EDD9E0C4-B402-40DF-B33D-405CA1E23BA6}" = DFPro
"{EE408577-9C0E-4E5F-BCB2-DB5B3A220958}" = Windows Live UX Platform Language Pack
"{EF47455E-86A0-4320-A269-52B753627244}" = x-APPLICATION NetMD Driver for x86
"{F03FB836-F44A-4AF1-A55B-087ECAAC0FA0}" = GIZMO テレビ連携 コアコンポーネント
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F33CFF0E-6684-43A8-AF99-2F1191B67152}" = Shock Sensor Utility
"{F37A2CB1-90B7-4AF9-BFFE-9B6DB8431E07}" = サポートナビ
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass 7.00.02
"{F52DF932-95C7-444F-A37B-86B5FD65A916}" = バッテリーユーティリティ
"{F7F60AC4-4B4B-48bd-A536-381F43DAED0E}" = AzbyClubツールバー
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171
"{FE51662F-D8F6-43B5-99D9-D4894AF00F83}" = Roxio Creator LJ
"AC3Filter_is1" = AC3Filter 2.5b
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 2.0
"AVS Audio Editor_is1" = AVS Audio Editor version 6.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"CnsMin" = JWord (日本語キーワード)
"CoreAAC" = CoreAAC
"CravingExplorer_is1" = Craving Explorer Version 1.5.2
"FaceSave" = Sense YOU Technology 設定
"GameChu" = ゲームチューインストールマネージャー
"Gamechu_common" = Common
"GOM ENCODER" = GOM ENCODER
"GOM PICKER" = GOM PICKER
"GOM Player" = GOM Player
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1C725459-5053-42A5-B22A-F3E91484DF65}" = @メニュー
"InstallShield_{224F03EA-8DA5-4413-9B80-FD3B7EABAF9B}" = 富士通モビリティセンター拡張
"InstallShield_{22A1A1C1-CEEC-4911-B36F-121464642478}" = ゆったり設定2
"InstallShield_{29276E3F-15EF-49FC-9793-B07811C8059D}" = PC乗換ガイド
"InstallShield_{2BDE2BF2-AD90-4191-B3C8-D0046CE54916}" = Fujitsu Display Manager
"InstallShield_{41938788-1E1C-4A8B-A1CD-F34C7A4D3E0D}" = セキュリティ対策ソフト選択
"InstallShield_{51FAA187-38A0-43CE-AD03-42108F503966}" = お手入れナビ
"InstallShield_{6226477E-444F-4DFE-BA19-9F4F7D4565BC}" = ワンタッチボタン設定
"InstallShield_{7BA0ECC1-2636-4169-9BF0-F49A1F7AAD87}" = 富士通起動ユーティリティ
"InstallShield_{83F00304-550B-4652-A12C-E301CB8B1EE4}" = スクリーンセーバー for FUJITSU PC
"InstallShield_{B351DC34-2758-492A-ADEE-66C17A61860E}" = PowerUtility - スケジュール機能
"InstallShield_{BA0B4781-7874-49CF-BF45-D83DAB54888C}" = x-アプリ 5.0.01
"InstallShield_{BA0CC975-682B-4678-A35C-05E607F36387}" = IndicatorUtility
"InstallShield_{D1A1B85E-328C-47C0-80EB-3AF2C567114E}" = 電子辞書
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"InstallShield_{D8FA2A48-A1E8-432E-AE96-5276D9E6A50F}" = Sony Media Library Earth 8.0.00
"InstallShield_{DFEA0A70-42C9-43A2-9455-93EDAB702E4B}" = なるほどパソコン入門
"InstallShield_{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}" = 富士通拡張機能ユーティリティ
"InstallShield_{E91C1011-2083-4DD6-858D-11753DCDFF2D}" = Corel Direct DiscRecorder 3.7
"InstallShield_{E9327EB0-7209-4E47-8EE2-999D5E567CAE}" = テレビ出力ユーティリティ
"InstallShield_{F33CFF0E-6684-43A8-AF99-2F1191B67152}" = Shock Sensor Utility
"InstallShield_{F37A2CB1-90B7-4AF9-BFFE-9B6DB8431E07}" = サポートナビ
"InstallShield_{F52DF932-95C7-444F-A37B-86B5FD65A916}" = バッテリーユーティリティ
"InstallShield_{F9A0B009-1449-4302-9436-45BBD51670FA}" = @メニュー用データ
"Janetter2_is1" = Janetter 4.1.0.0
"Lhaplus" = Lhaplus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile JPN Language Pack" = Microsoft .NET Framework 4 Client Profile Language Pack - 日本語
"npkcxp" = nProtect KeyCrypt
"Office14.EssentialsR" = Microsoft Office Home and Business 2010
"ProInst" = Intel PROSet Wireless
"RadioLine Free" = RadioLine Free
"RCKP314" = リサイズ超簡単!Pro v3.14
"RealPlayer 16.0" = RealPlayer
"SmaHey" = SmaHey
"SoundEngine Free" = SoundEngine Free
"TeraPad" = TeraPad
"Veoh Web Player Beta" = Veoh Web Player
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinGOGO" = 午後のこ~だ
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"東方神霊廟_is1" = 東方神霊廟 ver 1.00c

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3434746701-2890909996-1344222391-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1428B69E-DFF5-40e6-8FD8-93DE4054DCFC}" = 妹ぱらだいす!
"Hangame.com" = Hangame

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2013/08/15 21:11:44 | Computer Name = icePC | Source = Application Hang | ID = 1002
Description = プログラム iexplore.exe バージョン 8.0.7600.17267 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション
センター コントロール パネルで、問題の履歴をクリックしてください。 プロセス ID: 1400 開始時刻: 01ce9a1bb57b8166 終了時刻: 328 アプリケーション
パス: C:\Program Files\Internet Explorer\iexplore.exe レポート ID: cb46d7b7-0610-11e3-a2ae-9f58bb679f55


Error - 2013/08/15 22:51:08 | Computer Name = icePC | Source = Application Hang | ID = 1002
Description = プログラム iexplore.exe バージョン 8.0.7600.17267 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション
センター コントロール パネルで、問題の履歴をクリックしてください。 プロセス ID: 1c40 開始時刻: 01ce9a1e08b49d8e 終了時刻: 20 アプリケーション
パス: C:\Program Files\Internet Explorer\iexplore.exe レポート ID: ad1b8c4d-061e-11e3-a2ae-9f58bb679f55


Error - 2013/08/16 21:25:20 | Computer Name = icePC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: iexplore.exe、バージョン: 8.0.7600.17267、タイム スタンプ: 0x51317269
障害が発生しているモジュール名:
urlmon.dll、バージョン: 8.0.7600.17267、タイム スタンプ: 0x513188bc 例外コード: 0xc0000005 障害オフセット:
0x0000573f 障害が発生しているプロセス ID: 0x1aa4 障害が発生しているアプリケーションの開始時刻: 0x01ce9ae8a252bd35 障害が発生しているアプリケーション
パス: C:\Program Files\Internet Explorer\iexplore.exe 障害が発生しているモジュール パス: C:\windows\system32\urlmon.dll
レポート
ID: e0d74458-06db-11e3-a309-e41ffb798724

Error - 2013/08/17 22:12:44 | Computer Name = icePC | Source = Application Error | ID = 1000
Description = 障害が発生しているアプリケーション名: install_flashplayer11x32axau_gtbd_chrd_dn_aaa_aih[1]_1.exe、バージョン:
3.3.7.0、タイム スタンプ: 0x51494fab 障害が発生しているモジュール名: igdumd32.dll、バージョン: 8.15.10.2141、タイム
スタンプ: 0x4c0688b3 例外コード: 0xc0000409 障害オフセット: 0x00016596 障害が発生しているプロセス ID: 0x1080 障害が発生しているアプリケーションの開始時刻:
0x01ce9bb86be45a83 障害が発生しているアプリケーション パス: C:\Users\PCUser\AppData\Local\Temp\install_flashplayer11x32axau_gtbd_chrd_dn_aaa_aih[1]_1.exe
障害が発生しているモジュール
パス: C:\windows\system32\igdumd32.dll レポート ID: aaa88b63-07ab-11e3-bcdd-e5e4da39fe25

Error - 2013/08/17 22:25:03 | Computer Name = icePC | Source = UCManSvc | ID = 7006
Description = LoadComm41(4) failed.(4200)

Error - 2013/08/17 22:25:03 | Computer Name = icePC | Source = UCManSvc | ID = 7006
Description = LoadPublic41(4) failed.(4200)

Error - 2013/08/17 22:25:03 | Computer Name = icePC | Source = UCManSvc | ID = 7008
Description = SelectSystem(1,010017EC)=4200,0,4200,0,0,0

Error - 2013/08/17 22:25:03 | Computer Name = icePC | Source = UCManSvc | ID = 7008
Description = CountID=0

Error - 2013/08/20 0:49:39 | Computer Name = icePC | Source = Application Hang | ID = 1002
Description = プログラム GOM.EXE バージョン 2.2.53.5163 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション
センター コントロール パネルで、問題の履歴をクリックしてください。 プロセス ID: 149c 開始時刻: 01ce9d60887cb608 終了時刻: 15 アプリケーション
パス: C:\Program Files\GRETECH\GomPlayer\GOM.EXE レポート ID: d98a13e6-0953-11e3-886e-ee3b5b0a844a


Error - 2013/08/20 7:36:19 | Computer Name = icePC | Source = VSS | ID = 8194
Description =

[ System Events ]
Error - 2013/08/19 14:34:44 | Computer Name = icePC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2013/08/19 14:34:44 | Computer Name = icePC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2013/08/19 14:34:44 | Computer Name = icePC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2013/08/19 14:34:44 | Computer Name = icePC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2013/08/19 14:34:44 | Computer Name = icePC | Source = Service Control Manager | ID = 7001
Description = Network List Service サービスは、次のエラーが原因で開始できなかった Network Location Awareness
サービスに依存しています: %%1068

Error - 2013/08/19 14:39:29 | Computer Name = icePC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 2013/08/19 21:17:00 | Computer Name = icePC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 2013/08/19 21:17:00 | Computer Name = icePC | Source = Microsoft Antimalware | ID = 1119
Description =

Error - 2013/08/20 3:06:37 | Computer Name = icePC | Source = DCOM | ID = 10010
Description =

Error - 2013/08/20 8:13:49 | Computer Name = icePC | Source = bowser | ID = 8003
Description =


< End of report >
  • 宵子
  • 2013/08/20 (Tue) 21:54:19
Re: 広告が出てきて困っています。
こんばんは、こちらで回答しておりますイルカです。


Trojan.DOS/Rovnix.Dはいわゆるルートキットで、マルウェアの中でも最も深刻な部類のものの一つです。
OTLのログを見ましたが、迷惑ソフトのエントリは、ブラウザ設定には残っているものの、他のケースのようにアドオンとしては見られません。
以前に1件だけあった、ルートキットが原因の広告ということも考えられます。

いずれにせよ、ルートキット感染はリカバリになるケースも多いので、まずは必要なデータのバックアップを取っておいてください。


■Fixスクリプトによる処置
OTLを起動後、以下のスクリプトを「Custom Scan/Fixes」に貼り付け、「Run Fix」を押してください。
最初の「:OTL」を抜かさないように。

実行するとプロセスがすべて強制終了されますので、アプリはできるだけ終了しておいてください。
また、ごみ箱が空になりますので、必要なファイルがある場合は先に救出してください。
なお、OTLがフリーズしてしまって先に進まない場合は、セーフモードでコンピュータを起動したうえで実行してください。

セーフモードへの入り方:
http://www.higaitaisaku.com/safemode.html

完了後、再起動を要求されますので、「OK」で再起動してください。再起動後、ログが出ますので、そちらを載せてください。なお、今回のログに関しては、そのまま貼り付けで構いません。
なお、ログを閉じてしまった場合は、C:\_OTL\MovedFiles フォルダ内にログ(日付と時刻からなる数字ファイル名のファイル)がありますので、そちらの内容をお知らせください。

---ここから

:OTL
DRV - [2013/03/17 22:44:39 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://jp.hao123.com/?tn=smt_hp_hao123_jp
IE - HKLM\..\SearchScopes\{A437E1C7-7296-4224-833B-FD8F484B1585}: "URL" = http://www.amazon.co.jp/s/ref=azs_osd_ieajp?ie=UTF-8&tag=fujitsu07baawps-22&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\..\SearchScopes\{DB3C0454-D580-4934-8E3A-842A1AF5E4E2}: "URL" = http://ck.jp.ap.valuecommerce.com/servlet/referral?sid=2597372&pid=879140005&vc_url=http%3a%2f%2fshopping%2esearch%2eyahoo%2eco%2ejp%2fsearch%3fp%3d{searchTerms}
IE - HKLM\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpro.com/search/toolbar/hao123/{8AD499AB-226F-14BE-6AF9-7AA1EB74D396}?q={searchTerms}
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{186575F1-85E3-4D4D-80DE-07369FD93E13}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3281675&CUI=UN20675211112849183&UM=2
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes,DefaultScope = {186575F1-85E3-4D4D-80DE-07369FD93E13}
IE - HKU\S-1-5-21-3434746701-2890909996-1344222391-1001\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://www.bigseekpro.com/search/toolbar/hao123/{8AD499AB-226F-14BE-6AF9-7AA1EB74D396}?q={searchTerms}
[2013/08/20 16:26:00 | 000,000,000 | ---D | C] -- C:\temp

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[reboot]

---ここまで



■aswMBRによるログの取得
以下のファイルをダウンロードし、デスクトップ等に置いてください。
http://public.avast.com/~gmerek/aswMBR.exe

ダウンロード後、実行すると、英語で「定義ファイルをダウンロードしますか?」と聞いてきます。数分~10分程度かかりますが、「はい」でダウンロードしてください。
起動したら、「Scan」を押し、数分待つとスキャンが完了します。完了したら、「Save Log」をクリックし、ログをデスクトップへ保存してください。
その後、ログをこちらに投稿してください。



■TDSS Killerによる検査
http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe
から、TDSSKiller.exeをダウンロードしてください。

あらかじめ、各種アプリを終了しておいてください。

起動後、画面の「Change prameters」をクリックし、「Detect TDLFS File System」にチェックを入れて「OK」を押してください。
画面が戻ったら、「Start Scan」を押せばスキャンが始まります。

何かエントリが見つかった場合でも、選択肢を「Ignore」に切り替えて「Next」を押してください。

実行後、結果をお知らせください。
  • イルカ
  • 2013/08/20 (Tue) 22:25:33
OTL―Fixスクリプトのログ
All processes killed
========== OTL ==========
Service apf003 stopped successfully!
Service apf003 deleted successfully!
C:\Windows\System32\apf003.sys moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A437E1C7-7296-4224-833B-FD8F484B1585}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A437E1C7-7296-4224-833B-FD8F484B1585}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DB3C0454-D580-4934-8E3A-842A1AF5E4E2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB3C0454-D580-4934-8E3A-842A1AF5E4E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}\ not found.
Registry key HKEY_USERS\S-1-5-21-3434746701-2890909996-1344222391-1001\Software\Microsoft\Internet Explorer\SearchScopes\{186575F1-85E3-4D4D-80DE-07369FD93E13}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{186575F1-85E3-4D4D-80DE-07369FD93E13}\ not found.
HKEY_USERS\S-1-5-21-3434746701-2890909996-1344222391-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3434746701-2890909996-1344222391-1001\Software\Microsoft\Internet Explorer\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}\ not found.
C:\temp folder moved successfully.
========== FILES ==========
[color=#A23BEC]< ipconfig /flushdns /c >[/color]
Windows IP 構成
DNS リゾルバー キャッシュは正常にフラッシュされました。
C:\Users\PCUser\Pictures\Desktop\cmd.bat deleted successfully.
C:\Users\PCUser\Pictures\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 456 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: PCUser
->Temp folder emptied: 3372113264 bytes
->Temporary Internet Files folder emptied: 7526030302 bytes
->Java cache emptied: 5020696 bytes
->Flash cache emptied: 523 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 239177107 bytes
RecycleBin emptied: 4838801342 bytes

Total Files Cleaned = 15,241.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 08202013_223518

Files\Folders moved on Reboot...
C:\Users\PCUser\AppData\Local\Temp\Low\JavaDeployReg.log moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\X63KIUT3\ad_spotCAT5JH8T.htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OYLQM90M\afrCAW6DYBM.htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OYLQM90M\Collection[3].htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OYLQM90M\pd[1].htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IESOKMMK\akudaikan-0_bbs_fc2_com[1].htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IESOKMMK\RestoreXidToMediaStorage[1].htm moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Users\PCUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 宵子
  • 2013/08/21 (Wed) 00:36:32
aswMBRのログ
よろしくお願いします。



aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-08-21 00:23:32
-----------------------------
00:23:32.956 OS Version: Windows 6.1.7600
00:23:32.956 Number of processors: 4 586 0x2505
00:23:32.972 ComputerName: ICEPC UserName:
00:23:35.920 Initialize success
00:28:04.415 AVAST engine defs: 13081900
00:28:18.845 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
00:28:18.845 Disk 0 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 3
00:28:18.985 Disk 0 MBR read successfully
00:28:18.985 Disk 0 MBR scan
00:28:19.001 Disk 0 Windows 7 default MBR code
00:28:19.001 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 30720 MB offset 2048
00:28:19.032 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 200 MB offset 62916608
00:28:19.048 Disk 0 Partition 2 **INFECTED** MBR:Rovnix-A [Rtk]
00:28:19.048 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 289779 MB offset 63326208
00:28:19.079 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 289779 MB offset 656793600
00:28:19.079 Disk 0 MBR [SST] **ROOTKIT**
00:28:19.656 Scan finished successfully
00:28:37.986 Disk 0 MBR has been saved successfully to "C:\Users\PCUser\Pictures\Desktop\MBR.dat"
00:28:37.986 The log file has been saved successfully to "C:\Users\PCUser\Pictures\Desktop\aswMBR.txt"
  • 宵子
  • 2013/08/21 (Wed) 00:37:46
TDSS Killerによる検出
こちらはtxt形式での保存がなかったと思いますので、メモしたものを書きだします。
以下のものが検出されました。「Reboot」せずに終了したので、ただ検出しただけになっているはずです。

【1つ目】
Rootkit.Win32.Backboot.gen
Physical drive:¥Device¥Harddisc0¥DR0
Suspicious object, medium risk

【2つ目】
Rootkit.Boot.Cidox.b
Logical drive:¥Device¥Harddisc0¥DR0¥Partition1
Malware object, high risk


3行目は赤系の色で書かれておりました。


もしこちらの操作で誤りがあったり報告漏れなどがありましたらお教えください。
以上、報告です。なにとぞよろしくお願い申し上げます。
  • 宵子
  • 2013/08/21 (Wed) 00:42:55
叩いてみましょう
出ましたね。

00:28:19.032 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 200 MB offset 62916608
00:28:19.048 Disk 0 Partition 2 **INFECTED** MBR:Rovnix-A [Rtk]
00:28:19.079 Disk 0 MBR [SST] **ROOTKIT**

MBR:SST。TDSS系統の、これまた有名なルートキットの一つです。
TDSS Killerで検出された2項目(Rootkit.Win32.Backboot.gen、Rootkit.Boot.Cidox.b)が、それぞれaswMBRの2項目(MBR:SST、MBR:Rovnix-A [Rtk])に対応してますね。


データのバックアップは取れたでしょうか?今回はTDSS Killerが対応しているようなので、まずはこれで叩いてみましょう。


■TDSS Killerによる検査
http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe
から、最新のTDSSKiller.exeをダウンロードしてください。

あらかじめ、各種アプリを終了しておいてください。

起動後、画面の「Change prameters」をクリックし、「Detect TDLFS File System」にチェックを入れて「OK」を押してください。
画面が戻ったら、「Start Scan」を押せばスキャンが始まります。

前回見つかった項目について、両方とも「Cure」を選び、「Next」を押してください。
「Cure」が無ければ「Quarantine」、それもなければ「Delete」です。

今回は再起動が必要になります。再起動後、ログが出るはずですので、その内容をこちらに載せてください。
長すぎて切れてしまうかもしれませんので、真ん中で2分割にしてください。

ログが表示されない場合は、Cドライブにログが作成されているはずですので、そちらを載せてください。前回の、今回ので2つあると思います。


上手く行くことを祈ります。
  • イルカ
  • 2013/08/21 (Wed) 01:19:29
Re: 叩いてみましょう
先ほど検出できた2項目ですが、今回は検出できませんでした。素人判断は危険と承知の上ですが、見つからないようにウイルスが隠れでもしたのでしょうか。以前として広告は出てきますので、状況改善には至っていないようです。

TDSSKillerのログ2回分を掲載しますので、指示を仰ぎたいと思います。イルカさんにおかれましてはご面倒をおかけいたしますがよろしくお願いします。
  • 宵子
  • 2013/08/21 (Wed) 01:37:04
TDSSKiller1回目ログその1
一回目の前半です。

00:29:13.0290 0x0d24 TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29
00:29:14.0148 0x0d24 ============================================================
00:29:14.0148 0x0d24 Current date / time: 2013/08/21 00:29:14.0148
00:29:14.0148 0x0d24 SystemInfo:
00:29:14.0148 0x0d24
00:29:14.0148 0x0d24 OS Version: 6.1.7600 ServicePack: 0.0
00:29:14.0148 0x0d24 Product type: Workstation
00:29:14.0148 0x0d24 ComputerName: ICEPC
00:29:14.0148 0x0d24 UserName: PCUser
00:29:14.0148 0x0d24 Windows directory: C:\windows
00:29:14.0148 0x0d24 System windows directory: C:\windows
00:29:14.0148 0x0d24 Processor architecture: Intel x86
00:29:14.0148 0x0d24 Number of processors: 4
00:29:14.0148 0x0d24 Page size: 0x1000
00:29:14.0148 0x0d24 Boot type: Normal boot
00:29:14.0148 0x0d24 ============================================================
00:29:14.0975 0x0d24 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:29:14.0991 0x0d24 ============================================================
00:29:14.0991 0x0d24 \Device\Harddisk0\DR0:
00:29:14.0991 0x0d24 MBR partitions:
00:29:14.0991 0x0d24 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3C00800, BlocksNum 0x64000
00:29:14.0991 0x0d24 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3C64800, BlocksNum 0x235F9800
00:29:14.0991 0x0d24 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x2725E000, BlocksNum 0x235F9800
00:29:14.0991 0x0d24 ============================================================
00:29:15.0006 0x0d24 C: <-> \Device\Harddisk0\DR0\Partition2
00:29:15.0053 0x0d24 D: <-> \Device\Harddisk0\DR0\Partition3
00:29:15.0053 0x0d24 ============================================================
00:29:15.0053 0x0d24 Initialize success
00:29:15.0053 0x0d24 ============================================================
00:29:44.0958 0x08e4 ============================================================
00:29:44.0958 0x08e4 Scan started
00:29:44.0958 0x08e4 Mode: Manual; TDLFS;
00:29:44.0958 0x08e4 ============================================================
00:29:45.0114 0x08e4 ================ Scan system memory ========================
00:29:45.0114 0x08e4 System memory - ok
00:29:45.0114 0x08e4 ================ Scan services =============================
00:29:45.0395 0x08e4 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
00:29:45.0411 0x08e4 1394ohci - ok
00:29:45.0458 0x08e4 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\windows\system32\drivers\ACPI.sys
00:29:45.0458 0x08e4 ACPI - ok
00:29:45.0520 0x08e4 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
00:29:45.0551 0x08e4 AcpiPmi - ok
00:29:45.0707 0x08e4 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
00:29:45.0707 0x08e4 AdobeARMservice - ok
00:29:45.0816 0x08e4 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:29:45.0816 0x08e4 AdobeFlashPlayerUpdateSvc - ok
00:29:45.0863 0x08e4 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\drivers\adp94xx.sys
00:29:45.0941 0x08e4 adp94xx - ok
00:29:45.0972 0x08e4 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\drivers\adpahci.sys
00:29:46.0004 0x08e4 adpahci - ok
00:29:46.0066 0x08e4 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\drivers\adpu320.sys
00:29:46.0113 0x08e4 adpu320 - ok
00:29:46.0144 0x08e4 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
00:29:46.0160 0x08e4 AeLookupSvc - ok
00:29:46.0222 0x08e4 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\windows\system32\drivers\afd.sys
00:29:46.0222 0x08e4 AFD - ok
00:29:46.0284 0x08e4 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
00:29:46.0284 0x08e4 agp440 - ok
00:29:46.0347 0x08e4 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\drivers\djsvs.sys
00:29:46.0394 0x08e4 aic78xx - ok
00:29:46.0425 0x08e4 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
00:29:46.0425 0x08e4 ALG - ok
00:29:46.0440 0x08e4 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
00:29:46.0456 0x08e4 aliide - ok
00:29:46.0487 0x08e4 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
00:29:46.0518 0x08e4 amdagp - ok
00:29:46.0565 0x08e4 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
00:29:46.0596 0x08e4 amdide - ok
00:29:46.0612 0x08e4 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
00:29:46.0643 0x08e4 AmdK8 - ok
00:29:46.0659 0x08e4 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
00:29:46.0690 0x08e4 AmdPPM - ok
00:29:46.0737 0x08e4 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\windows\system32\drivers\amdsata.sys
00:29:46.0846 0x08e4 amdsata - ok
00:29:46.0893 0x08e4 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\drivers\amdsbs.sys
00:29:47.0002 0x08e4 amdsbs - ok
00:29:47.0033 0x08e4 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\windows\system32\drivers\amdxata.sys
00:29:47.0064 0x08e4 amdxata - ok
00:29:47.0361 0x08e4 [ F52603B708438E39FF38475807A01CBC ] Amsp C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
00:29:47.0392 0x08e4 Amsp - ok
00:29:47.0470 0x08e4 [ 7B4BEB577C5D0171F9B66F390EC29284 ] apf001 C:\windows\system32\apf001.sys
00:29:47.0517 0x08e4 apf001 - ok
00:29:47.0673 0x08e4 [ 98F481241BA8BBA38AA565BD3BF678F9 ] appdrv01 C:\windows\system32\Drivers\appdrv01.sys
00:29:48.0032 0x08e4 appdrv01 - ok
00:29:48.0032 0x08e4 appdrvrem01 - ok
00:29:48.0094 0x08e4 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\windows\system32\drivers\appid.sys
00:29:48.0094 0x08e4 AppID - ok
00:29:48.0156 0x08e4 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
00:29:48.0156 0x08e4 AppIDSvc - ok
00:29:48.0172 0x08e4 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\windows\System32\appinfo.dll
00:29:48.0172 0x08e4 Appinfo - ok
00:29:48.0297 0x08e4 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
00:29:48.0297 0x08e4 Apple Mobile Device - ok
00:29:48.0344 0x08e4 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\drivers\arc.sys
00:29:48.0390 0x08e4 arc - ok
00:29:48.0406 0x08e4 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\drivers\arcsas.sys
00:29:48.0453 0x08e4 arcsas - ok
00:29:48.0484 0x08e4 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
00:29:48.0484 0x08e4 AsyncMac - ok
00:29:48.0531 0x08e4 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
00:29:48.0531 0x08e4 atapi - ok
00:29:48.0671 0x08e4 [ 457117113973C615046836889AA2E1E3 ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
00:29:48.0734 0x08e4 ATService - ok
00:29:48.0780 0x08e4 [ 51D379DB1C53C2A55FDF9372E748E5C7 ] ATSwpWDF C:\windows\system32\Drivers\ATSwpWDF.sys
00:29:48.0796 0x08e4 ATSwpWDF - ok
00:29:48.0827 0x08e4 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
00:29:48.0827 0x08e4 AudioEndpointBuilder - ok
00:29:48.0843 0x08e4 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\windows\System32\Audiosrv.dll
00:29:48.0843 0x08e4 Audiosrv - ok
00:29:48.0890 0x08e4 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\windows\System32\AxInstSV.dll
00:29:48.0890 0x08e4 AxInstSV - ok
00:29:48.0936 0x08e4 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
00:29:48.0999 0x08e4 b06bdrv - ok
00:29:49.0014 0x08e4 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
00:29:49.0108 0x08e4 b57nd60x - ok
00:29:49.0139 0x08e4 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
00:29:49.0155 0x08e4 BDESVC - ok
00:29:49.0186 0x08e4 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
00:29:49.0186 0x08e4 Beep - ok
00:29:49.0233 0x08e4 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\windows\System32\bfe.dll
00:29:49.0248 0x08e4 BFE - ok
00:29:49.0295 0x08e4 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\windows\System32\qmgr.dll
00:29:49.0311 0x08e4 BITS - ok
00:29:49.0358 0x08e4 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\drivers\blbdrive.sys
00:29:49.0420 0x08e4 blbdrive - ok
00:29:49.0514 0x08e4 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
00:29:49.0514 0x08e4 Bonjour Service - ok
00:29:49.0560 0x08e4 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\windows\system32\DRIVERS\bowser.sys
00:29:49.0560 0x08e4 bowser - ok
00:29:49.0623 0x08e4 [ F30A1AEF42106AF072547377E0CE0C7E ] bpenum C:\windows\system32\DRIVERS\bpenum.sys
00:29:49.0701 0x08e4 bpenum - ok
00:29:49.0716 0x08e4 [ DE04B62A29F10FD0AFC1990D107DD841 ] bpmp C:\windows\system32\DRIVERS\bpmp.sys
00:29:49.0763 0x08e4 bpmp - ok
00:29:49.0810 0x08e4 [ A10647B31715023E4988D65851E9B487 ] bpusb C:\windows\system32\Drivers\bpusb.sys
00:29:49.0841 0x08e4 bpusb - ok
00:29:49.0872 0x08e4 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
00:29:49.0919 0x08e4 BrFiltLo - ok
00:29:49.0950 0x08e4 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
00:29:49.0966 0x08e4 BrFiltUp - ok
00:29:49.0997 0x08e4 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\windows\System32\browser.dll
00:29:50.0013 0x08e4 Browser - ok
00:29:50.0044 0x08e4 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
00:29:50.0122 0x08e4 Brserid - ok
00:29:50.0138 0x08e4 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
00:29:50.0184 0x08e4 BrSerWdm - ok
00:29:50.0216 0x08e4 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
00:29:50.0247 0x08e4 BrUsbMdm - ok
00:29:50.0278 0x08e4 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
00:29:50.0294 0x08e4 BrUsbSer - ok
00:29:50.0309 0x08e4 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
00:29:50.0356 0x08e4 BTHMODEM - ok
00:29:50.0387 0x08e4 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
00:29:50.0387 0x08e4 bthserv - ok
00:29:50.0434 0x08e4 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
00:29:50.0434 0x08e4 cdfs - ok
00:29:50.0481 0x08e4 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
00:29:50.0496 0x08e4 cdrom - ok
00:29:50.0543 0x08e4 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\windows\System32\certprop.dll
00:29:50.0543 0x08e4 CertPropSvc - ok
00:29:50.0543 0x08e4 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\drivers\circlass.sys
00:29:50.0590 0x08e4 circlass - ok
00:29:50.0621 0x08e4 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
00:29:50.0621 0x08e4 CLFS - ok
00:29:50.0730 0x08e4 [ DEB7F963F49F329EC0AA31E3F3DC9A59 ] CLHNService3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe
00:29:51.0198 0x08e4 CLHNService3 - ok
00:29:51.0292 0x08e4 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:29:51.0308 0x08e4 clr_optimization_v2.0.50727_32 - ok
00:29:51.0370 0x08e4 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:29:51.0432 0x08e4 clr_optimization_v4.0.30319_32 - ok
00:29:51.0495 0x08e4 [ DB4643A1F4D12825EBD7F675D1AF8C8F ] clwvd C:\windows\system32\DRIVERS\clwvd.sys
00:29:51.0542 0x08e4 clwvd - ok
00:29:51.0604 0x08e4 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\drivers\CmBatt.sys
00:29:51.0604 0x08e4 CmBatt - ok
00:29:51.0635 0x08e4 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
00:29:51.0666 0x08e4 cmdide - ok
00:29:51.0729 0x08e4 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\windows\system32\Drivers\cng.sys
00:29:51.0729 0x08e4 CNG - ok
00:29:51.0791 0x08e4 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\drivers\compbatt.sys
00:29:51.0838 0x08e4 Compbatt - ok
00:29:51.0900 0x08e4 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
00:29:51.0900 0x08e4 CompositeBus - ok
00:29:51.0932 0x08e4 COMSysApp - ok
00:29:51.0947 0x08e4 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
00:29:51.0994 0x08e4 crcdisk - ok
00:29:52.0041 0x08e4 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\windows\system32\cryptsvc.dll
00:29:52.0041 0x08e4 CryptSvc - ok
00:29:52.0088 0x08e4 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\windows\system32\rpcss.dll
00:29:52.0103 0x08e4 DcomLaunch - ok
00:29:52.0134 0x08e4 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
00:29:52.0150 0x08e4 defragsvc - ok
00:29:52.0197 0x08e4 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\windows\system32\Drivers\dfsc.sys
00:29:52.0197 0x08e4 DfsC - ok
00:29:52.0228 0x08e4 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\windows\system32\dhcpcore.dll
00:29:52.0228 0x08e4 Dhcp - ok
00:29:52.0259 0x08e4 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
00:29:52.0259 0x08e4 discache - ok
00:29:52.0322 0x08e4 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\drivers\disk.sys
00:29:52.0322 0x08e4 Disk - ok
00:29:52.0415 0x08e4 [ BA870E4749421275EBA05AD6B08CB4F5 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
00:29:52.0478 0x08e4 DMAgent - ok
00:29:52.0524 0x08e4 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\windows\System32\dnsrslvr.dll
00:29:52.0524 0x08e4 Dnscache - ok
00:29:52.0540 0x08e4 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\windows\System32\dot3svc.dll
00:29:52.0556 0x08e4 dot3svc - ok
00:29:52.0571 0x08e4 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\windows\system32\dps.dll
00:29:52.0587 0x08e4 DPS - ok
00:29:52.0634 0x08e4 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
00:29:52.0634 0x08e4 drmkaud - ok
00:29:52.0696 0x08e4 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
00:29:52.0727 0x08e4 DXGKrnl - ok
00:29:52.0774 0x08e4 EagleXNt - ok
00:29:52.0805 0x08e4 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
00:29:52.0821 0x08e4 EapHost - ok
00:29:52.0914 0x08e4 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\drivers\evbdx.sys
00:29:53.0070 0x08e4 ebdrv - ok
00:29:53.0117 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\windows\System32\lsass.exe
00:29:53.0117 0x08e4 EFS - ok
00:29:53.0180 0x08e4 [ BC667D6C0A8A857CABA77818F1A953FD ] ehRecvr C:\windows\ehome\ehRecvr.exe
00:29:53.0195 0x08e4 ehRecvr - ok
00:29:53.0226 0x08e4 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
00:29:53.0242 0x08e4 ehSched - ok
00:29:53.0273 0x08e4 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\drivers\elxstor.sys
00:29:53.0336 0x08e4 elxstor - ok
00:29:53.0367 0x08e4 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
00:29:53.0367 0x08e4 ErrDev - ok
00:29:53.0414 0x08e4 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
00:29:53.0429 0x08e4 EventSystem - ok
00:29:53.0523 0x08e4 [ 8597822F0E0EAA61A9FFD18778828792 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
00:29:53.0585 0x08e4 EvtEng - ok
00:29:53.0648 0x08e4 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
00:29:53.0648 0x08e4 exfat - ok
00:29:53.0663 0x08e4 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
00:29:53.0663 0x08e4 fastfat - ok
00:29:53.0710 0x08e4 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\windows\system32\fxssvc.exe
00:29:53.0710 0x08e4 Fax - ok
00:29:53.0757 0x08e4 [ 22EC3B0EA37CDF4355AE627004F3103C ] FBIOSDRV C:\windows\system32\Drivers\FBIOSDRV.sys
00:29:53.0788 0x08e4 FBIOSDRV - ok
00:29:53.0819 0x08e4 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\drivers\fdc.sys
00:29:53.0819 0x08e4 fdc - ok
00:29:53.0835 0x08e4 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
00:29:53.0835 0x08e4 fdPHost - ok
00:29:53.0850 0x08e4 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
00:29:53.0850 0x08e4 FDResPub - ok
00:29:53.0866 0x08e4 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
00:29:53.0866 0x08e4 FileInfo - ok
00:29:53.0882 0x08e4 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
00:29:53.0882 0x08e4 Filetrace - ok
00:29:53.0944 0x08e4 [ 31A2624507524A52A08DB2BBF2DB28EC ] FjDstService C:\Program Files\Fujitsu\DustSolution\FJDService.exe
00:29:53.0944 0x08e4 FjDstService - ok
00:29:54.0006 0x08e4 [ 1F2918E7FFB62D21FEFBA43B0F943F6B ] FJGSDisk C:\windows\system32\DRIVERS\FJGSDisk.sys
00:29:54.0053 0x08e4 FJGSDisk - ok
00:29:54.0053 0x08e4 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
00:29:54.0069 0x08e4 flpydisk - ok
00:29:54.0084 0x08e4 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
00:29:54.0084 0x08e4 FltMgr - ok
00:29:54.0131 0x08e4 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\windows\system32\FntCache.dll
00:29:54.0147 0x08e4 FontCache - ok
00:29:54.0209 0x08e4 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
00:29:54.0209 0x08e4 FontCache3.0.0.0 - ok
00:29:54.0240 0x08e4 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
00:29:54.0240 0x08e4 FsDepends - ok
00:29:54.0287 0x08e4 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
00:29:54.0287 0x08e4 Fs_Rec - ok
00:29:54.0350 0x08e4 [ 49E588AC7D2B57F057756A91C6F36D25 ] FUJ02B1 C:\windows\system32\drivers\FUJ02B1.sys
00:29:54.0365 0x08e4 FUJ02B1 - ok
00:29:54.0412 0x08e4 [ D45474A7E5E2F35150C29A3193747884 ] FUJ02E3 C:\windows\system32\drivers\FUJ02E3.sys
00:29:54.0443 0x08e4 FUJ02E3 - ok
00:29:54.0474 0x08e4 [ 4732E596BB1C50D9F9188C5074EE7782 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
00:29:54.0490 0x08e4 fvevol - ok
00:29:54.0506 0x08e4 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
00:29:54.0552 0x08e4 gagp30kx - ok
00:29:54.0584 0x08e4 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
00:29:54.0662 0x08e4 GEARAspiWDM - ok
00:29:54.0677 0x08e4 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\windows\System32\gpsvc.dll
00:29:54.0677 0x08e4 gpsvc - ok
00:29:54.0724 0x08e4 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\windows\system32\DRIVERS\hamachi.sys
00:29:54.0755 0x08e4 hamachi - ok
00:29:54.0786 0x08e4 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
00:29:54.0802 0x08e4 hcw85cir - ok
00:29:54.0849 0x08e4 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
00:29:54.0927 0x08e4 HdAudAddService - ok
00:29:54.0927 0x08e4 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
00:29:54.0927 0x08e4 HDAudBus - ok
00:29:54.0989 0x08e4 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\windows\system32\drivers\HECI.sys
00:29:55.0036 0x08e4 HECI - ok
00:29:55.0067 0x08e4 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
00:29:55.0114 0x08e4 HidBatt - ok
00:29:55.0161 0x08e4 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\drivers\hidbth.sys
00:29:55.0208 0x08e4 HidBth - ok
00:29:55.0254 0x08e4 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\drivers\hidir.sys
00:29:55.0332 0x08e4 HidIr - ok
00:29:55.0364 0x08e4 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
00:29:55.0364 0x08e4 hidserv - ok
00:29:55.0395 0x08e4 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
00:29:55.0410 0x08e4 HidUsb - ok
00:29:55.0426 0x08e4 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\windows\system32\kmsvc.dll
00:29:55.0442 0x08e4 hkmsvc - ok
00:29:55.0457 0x08e4 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\windows\system32\ListSvc.dll
00:29:55.0473 0x08e4 HomeGroupListener - ok
00:29:55.0504 0x08e4 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\windows\system32\provsvc.dll
00:29:55.0520 0x08e4 HomeGroupProvider - ok
00:29:55.0566 0x08e4 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
00:29:55.0629 0x08e4 HpSAMD - ok
00:29:55.0691 0x08e4 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\windows\system32\drivers\HTTP.sys
00:29:55.0691 0x08e4 HTTP - ok
00:29:55.0707 0x08e4 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
00:29:55.0722 0x08e4 hwpolicy - ok
00:29:55.0754 0x08e4 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
00:29:55.0769 0x08e4 i8042prt - ok
00:29:55.0800 0x08e4 [ D80AA0907748D7CC8EFAB3773F32629B ] iaStor C:\windows\system32\drivers\iaStor.sys
00:29:55.0800 0x08e4 iaStor - ok
00:29:55.0847 0x08e4 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
00:29:56.0097 0x08e4 iaStorV - ok
00:29:56.0144 0x08e4 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:29:56.0175 0x08e4 idsvc - ok
00:29:56.0362 0x08e4 [ 8E9DA2E49347AF49901526DCD4D0F397 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
00:29:57.0017 0x08e4 igfx - ok
00:29:57.0064 0x08e4 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\drivers\iirsp.sys
00:29:57.0111 0x08e4 iirsp - ok
00:29:57.0173 0x08e4 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\windows\System32\ikeext.dll
00:29:57.0204 0x08e4 IKEEXT - ok
00:29:57.0282 0x08e4 [ 91AB587F7EA44B0DEB0522F71AD7B2DC ] ImeDictUpdateService C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
00:29:57.0298 0x08e4 ImeDictUpdateService - ok
00:29:57.0345 0x08e4 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\windows\system32\drivers\Impcd.sys
00:29:57.0407 0x08e4 Impcd - ok
00:29:57.0532 0x08e4 [ AEE99ECF06CD1CEA95816CCB5BF73EC8 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
00:29:57.0875 0x08e4 IntcAzAudAddService - ok
00:29:57.0953 0x08e4 [ BF31740828A26AB451803E3B35432651 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
00:29:58.0016 0x08e4 IntcDAud - ok
00:29:58.0047 0x08e4 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
00:29:58.0062 0x08e4 intelide - ok
00:29:58.0109 0x08e4 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\drivers\intelppm.sys
00:29:58.0109 0x08e4 intelppm - ok
00:29:58.0140 0x08e4 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
00:29:58.0140 0x08e4 IPBusEnum - ok
00:29:58.0172 0x08e4 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
00:29:58.0187 0x08e4 IpFilterDriver - ok
00:29:58.0203 0x08e4 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
00:29:58.0218 0x08e4 iphlpsvc - ok
00:29:58.0234 0x08e4 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
00:29:58.0281 0x08e4 IPMIDRV - ok
00:29:58.0296 0x08e4 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
00:29:58.0296 0x08e4 IPNAT - ok
00:29:58.0406 0x08e4 [ D8B8B5A8FE57CF4F307A540D9A153C23 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
00:29:58.0421 0x08e4 iPod Service - ok
00:29:58.0452 0x08e4 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
00:29:58.0452 0x08e4 IRENUM - ok
00:29:58.0499 0x08e4 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
00:29:58.0499 0x08e4 isapnp - ok
00:29:58.0515 0x08e4 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
00:29:58.0530 0x08e4 iScsiPrt - ok
00:29:58.0577 0x08e4 [ F415A88162D23977B5EDAE4F0410E903 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
00:29:58.0608 0x08e4 IviRegMgr - ok
00:29:58.0655 0x08e4 [ 703E40B3A128F1FB8C307ADA168CA121 ] k57nd60x C:\windows\system32\DRIVERS\k57nd60x.sys
00:29:58.0733 0x08e4 k57nd60x - ok
00:29:58.0780 0x08e4 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
00:29:58.0780 0x08e4 kbdclass - ok
00:29:58.0827 0x08e4 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
00:29:58.0827 0x08e4 kbdhid - ok
00:29:58.0858 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\windows\system32\lsass.exe
00:29:58.0858 0x08e4 KeyIso - ok
00:29:58.0905 0x08e4 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
00:29:58.0905 0x08e4 KSecDD - ok
00:29:58.0952 0x08e4 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
00:29:58.0952 0x08e4 KSecPkg - ok
00:29:58.0998 0x08e4 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
00:29:59.0014 0x08e4 KtmRm - ok
00:29:59.0061 0x08e4 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\windows\system32\srvsvc.dll
00:29:59.0061 0x08e4 LanmanServer - ok
00:29:59.0108 0x08e4 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\windows\System32\wkssvc.dll
00:29:59.0108 0x08e4 LanmanWorkstation - ok
00:29:59.0170 0x08e4 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
00:29:59.0170 0x08e4 lltdio - ok
00:29:59.0201 0x08e4 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
00:29:59.0201 0x08e4 lltdsvc - ok
00:29:59.0232 0x08e4 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
00:29:59.0232 0x08e4 lmhosts - ok
00:29:59.0295 0x08e4 [ A1C148801B4AF64847AEB9F3AD9594EF ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
00:29:59.0357 0x08e4 LMS - ok
00:29:59.0404 0x08e4 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
00:29:59.0466 0x08e4 LSI_FC - ok
00:29:59.0482 0x08e4 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
00:29:59.0529 0x08e4 LSI_SAS - ok
00:29:59.0576 0x08e4 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
00:29:59.0638 0x08e4 LSI_SAS2 - ok
00:29:59.0654 0x08e4 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
00:29:59.0700 0x08e4 LSI_SCSI - ok
00:29:59.0716 0x08e4 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
00:29:59.0716 0x08e4 luafv - ok
00:29:59.0763 0x08e4 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
00:29:59.0763 0x08e4 Mcx2Svc - ok
00:29:59.0778 0x08e4 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\drivers\megasas.sys
00:29:59.0825 0x08e4 megasas - ok
00:29:59.0856 0x08e4 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
00:29:59.0934 0x08e4 MegaSR - ok
00:29:59.0950 0x08e4 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
00:29:59.0950 0x08e4 MMCSS - ok
00:29:59.0981 0x08e4 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
00:29:59.0981 0x08e4 Modem - ok
00:29:59.0997 0x08e4 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
00:29:59.0997 0x08e4 monitor - ok
00:30:00.0012 0x08e4 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
00:30:00.0012 0x08e4 mouclass - ok
00:30:00.0059 0x08e4 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
00:30:00.0075 0x08e4 mouhid - ok
00:30:00.0106 0x08e4 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
00:30:00.0122 0x08e4 mountmgr - ok
00:30:00.0137 0x08e4 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\windows\system32\drivers\mpio.sys
00:30:00.0137 0x08e4 mpio - ok
00:30:00.0153 0x08e4 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
00:30:00.0153 0x08e4 mpsdrv - ok
00:30:00.0184 0x08e4 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\windows\system32\mpssvc.dll
00:30:00.0200 0x08e4 MpsSvc - ok
00:30:00.0215 0x08e4 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
00:30:00.0215 0x08e4 MRxDAV - ok
00:30:00.0262 0x08e4 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
00:30:00.0262 0x08e4 mrxsmb - ok
00:30:00.0309 0x08e4 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
00:30:00.0309 0x08e4 mrxsmb10 - ok
00:30:00.0324 0x08e4 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
00:30:00.0324 0x08e4 mrxsmb20 - ok
00:30:00.0340 0x08e4 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\windows\system32\drivers\msahci.sys
00:30:00.0371 0x08e4 msahci - ok
00:30:00.0387 0x08e4 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\windows\system32\drivers\msdsm.sys
00:30:00.0387 0x08e4 msdsm - ok
00:30:00.0418 0x08e4 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
00:30:00.0418 0x08e4 MSDTC - ok
00:30:00.0418 0x08e4 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
00:30:00.0434 0x08e4 Msfs - ok
00:30:00.0434 0x08e4 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
00:30:00.0449 0x08e4 mshidkmdf - ok
00:30:00.0465 0x08e4 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
00:30:00.0465 0x08e4 msisadrv - ok
00:30:00.0512 0x08e4 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
00:30:00.0527 0x08e4 MSiSCSI - ok
00:30:00.0527 0x08e4 msiserver - ok
00:30:00.0574 0x08e4 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
00:30:00.0574 0x08e4 MSKSSRV - ok
00:30:00.0605 0x08e4 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
00:30:00.0605 0x08e4 MSPCLOCK - ok
00:30:00.0621 0x08e4 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
00:30:00.0621 0x08e4 MSPQM - ok
00:30:00.0636 0x08e4 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
00:30:00.0636 0x08e4 MsRPC - ok
00:30:00.0668 0x08e4 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
00:30:00.0668 0x08e4 mssmbios - ok
00:30:00.0683 0x08e4 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
00:30:00.0683 0x08e4 MSTEE - ok
00:30:00.0699 0x08e4 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
00:30:00.0730 0x08e4 MTConfig - ok
00:30:00.0746 0x08e4 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
00:30:00.0746 0x08e4 Mup - ok
00:30:00.0777 0x08e4 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\windows\system32\qagentRT.dll
00:30:00.0792 0x08e4 napagent - ok
00:30:00.0839 0x08e4 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
00:30:00.0855 0x08e4 NativeWifiP - ok
00:30:00.0917 0x08e4 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\windows\system32\drivers\ndis.sys
00:30:00.0933 0x08e4 NDIS - ok
00:30:00.0980 0x08e4 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
00:30:00.0980 0x08e4 NdisCap - ok
00:30:01.0026 0x08e4 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
00:30:01.0026 0x08e4 NdisTapi - ok
00:30:01.0058 0x08e4 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
00:30:01.0073 0x08e4 Ndisuio - ok
00:30:01.0089 0x08e4 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
00:30:01.0089 0x08e4 NdisWan - ok
00:30:01.0104 0x08e4 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
00:30:01.0120 0x08e4 NDProxy - ok
00:30:01.0151 0x08e4 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
00:30:01.0167 0x08e4 NetBIOS - ok
00:30:01.0198 0x08e4 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
00:30:01.0198 0x08e4 NetBT - ok
00:30:01.0229 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\windows\system32\lsass.exe
00:30:01.0229 0x08e4 Netlogon - ok
00:30:01.0292 0x08e4 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
00:30:01.0307 0x08e4 Netman - ok
00:30:01.0338 0x08e4 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
00:30:01.0338 0x08e4 netprofm - ok
00:30:01.0370 0x08e4 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:30:01.0385 0x08e4 NetTcpPortSharing - ok
00:30:01.0541 0x08e4 [ 3577B851E59DA59E6D65419A057C9914 ] NETw5s32 C:\windows\system32\DRIVERS\NETw5s32.sys
00:30:02.0025 0x08e4 NETw5s32 - ok
00:30:02.0056 0x08e4 [ F282FC61839F8A719A3AD569CAB71C9C ] NetworkPlayer Server C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe
00:30:02.0540 0x08e4 NetworkPlayer Server - ok
00:30:02.0586 0x08e4 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
00:30:02.0633 0x08e4 nfrd960 - ok
00:30:02.0664 0x08e4 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\windows\System32\nlasvc.dll
00:30:02.0664 0x08e4 NlaSvc - ok
00:30:02.0680 0x08e4 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
00:30:02.0680 0x08e4 Npfs - ok
00:30:02.0742 0x08e4 npggsvc - ok
00:30:02.0836 0x08e4 [ 3964D26EE70B24B5318146247DD782DF ] npkakl C:\windows\system32\npkakl.sys
00:30:02.0883 0x08e4 npkakl - ok
00:30:02.0945 0x08e4 [ 83D727642D288A75A10100BEF5CDB756 ] npkcmsvc C:\windows\system32\npkcmsvc.exe
00:30:02.0992 0x08e4 npkcmsvc - ok
00:30:03.0023 0x08e4 [ 77BEB64EA3E83C37355B6D8EEB14008E ] npkcrypt C:\windows\system32\npkcrypt.sys
00:30:03.0054 0x08e4 npkcrypt - ok
00:30:03.0070 0x08e4 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
00:30:03.0070 0x08e4 nsi - ok
00:30:03.0086 0x08e4 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
00:30:03.0086 0x08e4 nsiproxy - ok
00:30:03.0164 0x08e4 [ A8F59428E9F361C7AC42A94AC1560BC9 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
00:30:03.0210 0x08e4 Ntfs - ok
00:30:03.0273 0x08e4 [ 588F2E8ACF3BDCE4496295806D21ECAF ] ntk3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\ntk3.sys
00:30:03.0569 0x08e4 ntk3 - ok
00:30:03.0600 0x08e4 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
00:30:03.0616 0x08e4 Null - ok
00:30:03.0647 0x08e4 [ EE0CB811A0F03038C2BC64538AA780F8 ] nusb3hub C:\windows\system32\drivers\nusb3hub.sys
00:30:03.0710 0x08e4 nusb3hub - ok
00:30:03.0756 0x08e4 [ 7CAA9F5D8602B236A92B17EDC87549F9 ] nusb3xhc C:\windows\system32\drivers\nusb3xhc.sys
00:30:03.0803 0x08e4 nusb3xhc - ok
00:30:03.0866 0x08e4 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\windows\system32\drivers\nvraid.sys
00:30:03.0975 0x08e4 nvraid - ok
00:30:04.0006 0x08e4 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\windows\system32\drivers\nvstor.sys
00:30:04.0100 0x08e4 nvstor - ok
  • 宵子
  • 2013/08/21 (Wed) 01:38:23
TDSSKiller1回目その2
1回目の後半です。

00:30:04.0100 0x08e4 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
00:30:04.0146 0x08e4 nv_agp - ok
00:30:04.0193 0x08e4 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
00:30:04.0193 0x08e4 ohci1394 - ok
00:30:04.0256 0x08e4 [ 84113AB3A3EEF32FBEBF3339D8C19100 ] omniserv C:\Program Files\Softex\OmniPass\OmniServ.exe
00:30:04.0318 0x08e4 omniserv - ok
00:30:04.0349 0x08e4 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:30:04.0380 0x08e4 ose - ok
00:30:04.0552 0x08e4 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
00:30:04.0646 0x08e4 osppsvc - ok
00:30:04.0677 0x08e4 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
00:30:04.0692 0x08e4 p2pimsvc - ok
00:30:04.0724 0x08e4 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
00:30:04.0724 0x08e4 p2psvc - ok
00:30:04.0864 0x08e4 [ CB1257208C7105192F397187C14162E9 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
00:30:04.0880 0x08e4 PACSPTISVR - ok
00:30:04.0911 0x08e4 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\drivers\parport.sys
00:30:04.0911 0x08e4 Parport - ok
00:30:04.0942 0x08e4 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\windows\system32\drivers\partmgr.sys
00:30:04.0942 0x08e4 partmgr - ok
00:30:04.0973 0x08e4 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\drivers\parvdm.sys
00:30:04.0973 0x08e4 Parvdm - ok
00:30:05.0004 0x08e4 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
00:30:05.0020 0x08e4 PcaSvc - ok
00:30:05.0036 0x08e4 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\windows\system32\drivers\pci.sys
00:30:05.0051 0x08e4 pci - ok
00:30:05.0067 0x08e4 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
00:30:05.0082 0x08e4 pciide - ok
00:30:05.0098 0x08e4 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
00:30:05.0176 0x08e4 pcmcia - ok
00:30:05.0207 0x08e4 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
00:30:05.0207 0x08e4 pcw - ok
00:30:05.0254 0x08e4 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
00:30:05.0270 0x08e4 PEAUTH - ok
00:30:05.0379 0x08e4 [ F3B3F0BBC15C668EF87FD6C265994481 ] PFNService C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
00:30:05.0441 0x08e4 PFNService - ok
00:30:05.0504 0x08e4 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\windows\system32\pla.dll
00:30:05.0566 0x08e4 pla - ok
00:30:05.0628 0x08e4 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\windows\system32\umpnpmgr.dll
00:30:05.0628 0x08e4 PlugPlay - ok
00:30:05.0660 0x08e4 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
00:30:05.0660 0x08e4 PNRPAutoReg - ok
00:30:05.0691 0x08e4 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
00:30:05.0706 0x08e4 PNRPsvc - ok
00:30:05.0738 0x08e4 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
00:30:05.0753 0x08e4 PolicyAgent - ok
00:30:05.0784 0x08e4 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\windows\system32\umpo.dll
00:30:05.0800 0x08e4 Power - ok
00:30:05.0847 0x08e4 [ AEA6984F3DD10A76552480D46CF17EBD ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe
00:30:05.0925 0x08e4 PowerSavingUtilityService - ok
00:30:05.0987 0x08e4 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
00:30:05.0987 0x08e4 PptpMiniport - ok
00:30:06.0018 0x08e4 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\drivers\processr.sys
00:30:06.0065 0x08e4 Processor - ok
00:30:06.0112 0x08e4 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\windows\system32\profsvc.dll
00:30:06.0112 0x08e4 ProfSvc - ok
00:30:06.0128 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\windows\system32\lsass.exe
00:30:06.0143 0x08e4 ProtectedStorage - ok
00:30:06.0190 0x08e4 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
00:30:06.0190 0x08e4 Psched - ok
00:30:06.0268 0x08e4 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
00:30:06.0268 0x08e4 PSI_SVC_2 - ok
00:30:06.0362 0x08e4 [ 786DBE9D3A96481F21E8CF59CFA049A6 ] PUSCSRVC C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
00:30:06.0424 0x08e4 PUSCSRVC - ok
00:30:06.0455 0x08e4 [ B6A1692FC131F1FE5162513D78A9B6FC ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
00:30:06.0486 0x08e4 PxHelp20 - ok
00:30:06.0549 0x08e4 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\drivers\ql2300.sys
00:30:06.0674 0x08e4 ql2300 - ok
00:30:06.0705 0x08e4 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
00:30:06.0752 0x08e4 ql40xx - ok
00:30:06.0783 0x08e4 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
00:30:06.0798 0x08e4 QWAVE - ok
00:30:06.0798 0x08e4 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
00:30:06.0814 0x08e4 QWAVEdrv - ok
00:30:06.0814 0x08e4 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
00:30:06.0814 0x08e4 RasAcd - ok
00:30:06.0861 0x08e4 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
00:30:06.0861 0x08e4 RasAgileVpn - ok
00:30:06.0876 0x08e4 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
00:30:06.0876 0x08e4 RasAuto - ok
00:30:06.0892 0x08e4 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
00:30:06.0892 0x08e4 Rasl2tp - ok
00:30:06.0923 0x08e4 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\windows\System32\rasmans.dll
00:30:06.0923 0x08e4 RasMan - ok
00:30:06.0939 0x08e4 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
00:30:06.0939 0x08e4 RasPppoe - ok
00:30:06.0970 0x08e4 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
00:30:06.0970 0x08e4 RasSstp - ok
00:30:07.0001 0x08e4 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
00:30:07.0001 0x08e4 rdbss - ok
00:30:07.0064 0x08e4 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\drivers\rdpbus.sys
00:30:07.0064 0x08e4 rdpbus - ok
00:30:07.0079 0x08e4 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
00:30:07.0079 0x08e4 RDPCDD - ok
00:30:07.0126 0x08e4 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
00:30:07.0126 0x08e4 RDPENCDD - ok
00:30:07.0142 0x08e4 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
00:30:07.0142 0x08e4 RDPREFMP - ok
00:30:07.0188 0x08e4 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
00:30:07.0188 0x08e4 RDPWD - ok
00:30:07.0235 0x08e4 [ 65DB288F7372B1F632891FC32BF908B7 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
00:30:07.0235 0x08e4 rdyboost - ok
00:30:07.0344 0x08e4 [ B2D01290C0E0465ACA54C2088E947823 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
00:30:07.0391 0x08e4 RealNetworks Downloader Resolver Service - ok
00:30:07.0438 0x08e4 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\windows\system32\drivers\regi.sys
00:30:07.0485 0x08e4 regi - ok
00:30:07.0547 0x08e4 [ 7AFCBE32616E08D45E4EAADB0A1DD5CF ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
00:30:07.0563 0x08e4 RegSrvc - ok
00:30:07.0594 0x08e4 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
00:30:07.0610 0x08e4 RemoteAccess - ok
00:30:07.0641 0x08e4 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
00:30:07.0641 0x08e4 RemoteRegistry - ok
00:30:07.0703 0x08e4 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
00:30:07.0719 0x08e4 RpcEptMapper - ok
00:30:07.0734 0x08e4 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
00:30:07.0750 0x08e4 RpcLocator - ok
00:30:07.0781 0x08e4 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\windows\system32\rpcss.dll
00:30:07.0781 0x08e4 RpcSs - ok
00:30:07.0797 0x08e4 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
00:30:07.0797 0x08e4 rspndr - ok
00:30:07.0859 0x08e4 [ 11CC47F1CC7A66BBC6766F6037C5A678 ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
00:30:07.0875 0x08e4 RSUSBSTOR - ok
00:30:07.0890 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\windows\system32\lsass.exe
00:30:07.0890 0x08e4 SamSs - ok
00:30:07.0953 0x08e4 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
00:30:08.0015 0x08e4 sbp2port - ok
00:30:08.0031 0x08e4 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
00:30:08.0031 0x08e4 SCardSvr - ok
00:30:08.0046 0x08e4 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
00:30:08.0062 0x08e4 scfilter - ok
00:30:08.0124 0x08e4 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\windows\system32\schedsvc.dll
00:30:08.0156 0x08e4 Schedule - ok
00:30:08.0187 0x08e4 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\windows\System32\certprop.dll
00:30:08.0187 0x08e4 SCPolicySvc - ok
00:30:08.0202 0x08e4 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\windows\System32\SDRSVC.dll
00:30:08.0202 0x08e4 SDRSVC - ok
00:30:08.0234 0x08e4 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
00:30:08.0265 0x08e4 secdrv - ok
00:30:08.0280 0x08e4 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
00:30:08.0280 0x08e4 seclogon - ok
00:30:08.0280 0x08e4 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
00:30:08.0280 0x08e4 SENS - ok
00:30:08.0327 0x08e4 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
00:30:08.0327 0x08e4 SensrSvc - ok
00:30:08.0358 0x08e4 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\drivers\serenum.sys
00:30:08.0358 0x08e4 Serenum - ok
00:30:08.0374 0x08e4 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\drivers\serial.sys
00:30:08.0374 0x08e4 Serial - ok
00:30:08.0405 0x08e4 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\drivers\sermouse.sys
00:30:08.0405 0x08e4 sermouse - ok
00:30:08.0405 0x08e4 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\windows\system32\sessenv.dll
00:30:08.0421 0x08e4 SessionEnv - ok
00:30:08.0436 0x08e4 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
00:30:08.0436 0x08e4 sffdisk - ok
00:30:08.0436 0x08e4 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
00:30:08.0436 0x08e4 sffp_mmc - ok
00:30:08.0452 0x08e4 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
00:30:08.0452 0x08e4 sffp_sd - ok
00:30:08.0468 0x08e4 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
00:30:08.0499 0x08e4 sfloppy - ok
00:30:08.0561 0x08e4 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
00:30:08.0561 0x08e4 SharedAccess - ok
00:30:08.0592 0x08e4 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\windows\System32\shsvcs.dll
00:30:08.0608 0x08e4 ShellHWDetection - ok
00:30:08.0624 0x08e4 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
00:30:08.0670 0x08e4 sisagp - ok
00:30:08.0717 0x08e4 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
00:30:08.0748 0x08e4 SiSRaid2 - ok
00:30:08.0764 0x08e4 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
00:30:08.0795 0x08e4 SiSRaid4 - ok
00:30:08.0858 0x08e4 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
00:30:09.0201 0x08e4 SkypeUpdate - ok
00:30:09.0248 0x08e4 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
00:30:09.0248 0x08e4 Smb - ok
00:30:09.0279 0x08e4 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
00:30:09.0279 0x08e4 SNMPTRAP - ok
00:30:09.0435 0x08e4 [ A7D1229E1326D02CF80F952617C5A39B ] SNP2UVC C:\windows\system32\DRIVERS\snp2uvc.sys
00:30:09.0747 0x08e4 SNP2UVC - ok
00:30:09.0825 0x08e4 [ 6AE4902A4A819A7A1545D23972D70C55 ] SonicStage Back-End Service2 C:\Program Files\Common Files\Sony Shared\AVLib\SsBeService2.exe
00:30:09.0825 0x08e4 SonicStage Back-End Service2 - ok
00:30:09.0840 0x08e4 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
00:30:09.0840 0x08e4 spldr - ok
00:30:09.0903 0x08e4 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\windows\System32\spoolsv.exe
00:30:09.0918 0x08e4 Spooler - ok
00:30:10.0043 0x08e4 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\windows\system32\sppsvc.exe
00:30:10.0106 0x08e4 sppsvc - ok
00:30:10.0121 0x08e4 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\windows\system32\sppuinotify.dll
00:30:10.0121 0x08e4 sppuinotify - ok
00:30:10.0168 0x08e4 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\windows\system32\DRIVERS\srv.sys
00:30:10.0168 0x08e4 srv - ok
00:30:10.0199 0x08e4 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
00:30:10.0199 0x08e4 srv2 - ok
00:30:10.0246 0x08e4 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
00:30:10.0246 0x08e4 srvnet - ok
00:30:10.0262 0x08e4 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
00:30:10.0277 0x08e4 SSDPSRV - ok
00:30:10.0293 0x08e4 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
00:30:10.0293 0x08e4 SstpSvc - ok
00:30:10.0324 0x08e4 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\drivers\stexstor.sys
00:30:10.0355 0x08e4 stexstor - ok
00:30:10.0402 0x08e4 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\windows\System32\wiaservc.dll
00:30:10.0418 0x08e4 StiSvc - ok
00:30:10.0449 0x08e4 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
00:30:10.0480 0x08e4 swenum - ok
00:30:10.0511 0x08e4 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
00:30:10.0511 0x08e4 swprv - ok
00:30:10.0574 0x08e4 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\windows\system32\sysmain.dll
00:30:10.0605 0x08e4 SysMain - ok
00:30:10.0620 0x08e4 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\windows\System32\TabSvc.dll
00:30:10.0636 0x08e4 TabletInputService - ok
00:30:10.0652 0x08e4 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\windows\System32\tapisrv.dll
00:30:10.0667 0x08e4 TapiSrv - ok
00:30:10.0683 0x08e4 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
00:30:10.0683 0x08e4 TBS - ok
00:30:10.0761 0x08e4 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] Tcpip C:\windows\system32\drivers\tcpip.sys
00:30:10.0792 0x08e4 Tcpip - ok
00:30:10.0823 0x08e4 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
00:30:10.0839 0x08e4 TCPIP6 - ok
00:30:10.0870 0x08e4 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
00:30:10.0870 0x08e4 tcpipreg - ok
00:30:10.0886 0x08e4 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
00:30:10.0886 0x08e4 TDPIPE - ok
00:30:10.0917 0x08e4 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
00:30:10.0932 0x08e4 TDTCP - ok
00:30:10.0932 0x08e4 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\windows\system32\DRIVERS\tdx.sys
00:30:10.0948 0x08e4 tdx - ok
00:30:10.0964 0x08e4 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\windows\system32\drivers\termdd.sys
00:30:10.0964 0x08e4 TermDD - ok
00:30:10.0995 0x08e4 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\windows\System32\termsrv.dll
00:30:11.0010 0x08e4 TermService - ok
00:30:11.0026 0x08e4 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
00:30:11.0026 0x08e4 Themes - ok
00:30:11.0042 0x08e4 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
00:30:11.0042 0x08e4 THREADORDER - ok
00:30:11.0135 0x08e4 [ 883B3052721452E8667F5597AD2C5379 ] tmactmon C:\windows\system32\DRIVERS\tmactmon.sys
00:30:11.0182 0x08e4 tmactmon - ok
00:30:11.0260 0x08e4 [ F33C3F08536F988AAC84D72D83B139A6 ] tmcomm C:\windows\system32\DRIVERS\tmcomm.sys
00:30:11.0291 0x08e4 tmcomm - ok
00:30:11.0338 0x08e4 [ A17D672CBE700272DA499AA3ED60D3CC ] tmeevw C:\windows\system32\DRIVERS\tmeevw.sys
00:30:11.0432 0x08e4 tmeevw - ok
00:30:11.0478 0x08e4 [ 8FE7172FF137249BEA4EBC750EF90093 ] tmevtmgr C:\windows\system32\DRIVERS\tmevtmgr.sys
00:30:11.0510 0x08e4 tmevtmgr - ok
00:30:11.0541 0x08e4 [ 0C40396F071A8092964C8DC951F62B17 ] tmnciesc C:\windows\system32\DRIVERS\tmnciesc.sys
00:30:11.0619 0x08e4 tmnciesc - ok
00:30:11.0650 0x08e4 [ 43C1B7C778B296D492AF6D2ABB2ECF7F ] tmtdi C:\windows\system32\DRIVERS\tmtdi.sys
00:30:11.0666 0x08e4 tmtdi - ok
00:30:11.0712 0x08e4 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
00:30:11.0712 0x08e4 TrkWks - ok
00:30:11.0744 0x08e4 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
00:30:11.0744 0x08e4 TrustedInstaller - ok
00:30:11.0775 0x08e4 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
00:30:11.0775 0x08e4 tssecsrv - ok
00:30:11.0822 0x08e4 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
00:30:11.0822 0x08e4 tunnel - ok
00:30:11.0837 0x08e4 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\drivers\uagp35.sys
00:30:11.0900 0x08e4 uagp35 - ok
00:30:12.0009 0x08e4 [ F7DF6654663AD07DAB615A7AF513D90C ] UCManSvc C:\Program Files\SoftDenchi\UCManSvc.exe
00:30:12.0508 0x08e4 UCManSvc - ok
00:30:12.0539 0x08e4 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\windows\system32\DRIVERS\udfs.sys
00:30:12.0555 0x08e4 udfs - ok
00:30:12.0617 0x08e4 [ 27B37460477592A4C591F83675A096F9 ] UDSS c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe
00:30:12.0617 0x08e4 UDSS - ok
00:30:12.0648 0x08e4 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
00:30:12.0664 0x08e4 UI0Detect - ok
00:30:12.0711 0x08e4 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
00:30:12.0758 0x08e4 uliagpkx - ok
00:30:12.0789 0x08e4 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\windows\system32\DRIVERS\umbus.sys
00:30:12.0789 0x08e4 umbus - ok
00:30:12.0820 0x08e4 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\drivers\umpass.sys
00:30:12.0836 0x08e4 UmPass - ok
00:30:12.0914 0x08e4 [ 41118D920B2B268C0ADC36421248CDCF ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
00:30:13.0007 0x08e4 UNS - ok
00:30:13.0054 0x08e4 [ C11D90101CB125AFC47525066EFF4AE9 ] UpdateNaviInstallService C:\Program Files\Fujitsu\chitose\updnvsrv.exe
00:30:13.0085 0x08e4 UpdateNaviInstallService - ok
00:30:13.0116 0x08e4 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
00:30:13.0116 0x08e4 upnphost - ok
00:30:13.0179 0x08e4 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\windows\system32\Drivers\usbaapl.sys
00:30:13.0226 0x08e4 USBAAPL - ok
00:30:13.0272 0x08e4 [ 5C233AEFB566EE78C1EFBC0493FB066A ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
00:30:13.0272 0x08e4 usbccgp - ok
00:30:13.0304 0x08e4 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\windows\system32\drivers\usbcir.sys
00:30:13.0335 0x08e4 usbcir - ok
00:30:13.0366 0x08e4 [ 5B71019A6ACA0116FD21B368F19C0B91 ] usbehci C:\windows\system32\drivers\usbehci.sys
00:30:13.0366 0x08e4 usbehci - ok
00:30:13.0428 0x08e4 [ 5823D3965C2A4F6F785ED1A3B403F3B8 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
00:30:13.0444 0x08e4 usbhub - ok
00:30:13.0475 0x08e4 [ E753ED6C49DA13967EBABF9EA616454A ] usbohci C:\windows\system32\drivers\usbohci.sys
00:30:13.0522 0x08e4 usbohci - ok
00:30:13.0600 0x08e4 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
00:30:13.0647 0x08e4 usbprint - ok
00:30:13.0694 0x08e4 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\windows\system32\DRIVERS\usbscan.sys
00:30:13.0772 0x08e4 usbscan - ok
00:30:13.0803 0x08e4 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
00:30:13.0803 0x08e4 USBSTOR - ok
00:30:13.0850 0x08e4 [ 6A30928A469CE802600E1EA8C0F2F53F ] usbuhci C:\windows\system32\drivers\usbuhci.sys
00:30:13.0850 0x08e4 usbuhci - ok
00:30:13.0896 0x08e4 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
00:30:13.0974 0x08e4 usbvideo - ok
00:30:13.0990 0x08e4 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
00:30:13.0990 0x08e4 UxSms - ok
00:30:14.0006 0x08e4 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\windows\system32\lsass.exe
00:30:14.0006 0x08e4 VaultSvc - ok
00:30:14.0052 0x08e4 [ B2ABAB4CA46BAD182E27763DC19C780F ] VCSVADHWSer C:\windows\system32\DRIVERS\vcsvad.sys
00:30:14.0068 0x08e4 VCSVADHWSer - ok
00:30:14.0115 0x08e4 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
00:30:14.0130 0x08e4 vdrvroot - ok
00:30:14.0162 0x08e4 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\windows\System32\vds.exe
00:30:14.0162 0x08e4 vds - ok
00:30:14.0208 0x08e4 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
00:30:14.0208 0x08e4 vga - ok
00:30:14.0224 0x08e4 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
00:30:14.0224 0x08e4 VgaSave - ok
00:30:14.0255 0x08e4 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
00:30:14.0255 0x08e4 vhdmp - ok
00:30:14.0302 0x08e4 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
00:30:14.0364 0x08e4 viaagp - ok
00:30:14.0380 0x08e4 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\drivers\viac7.sys
00:30:14.0411 0x08e4 ViaC7 - ok
00:30:14.0442 0x08e4 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
00:30:14.0474 0x08e4 viaide - ok
00:30:14.0489 0x08e4 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\windows\system32\drivers\volmgr.sys
00:30:14.0489 0x08e4 volmgr - ok
00:30:14.0505 0x08e4 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
00:30:14.0505 0x08e4 volmgrx - ok
00:30:14.0552 0x08e4 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\windows\system32\drivers\volsnap.sys
00:30:14.0552 0x08e4 volsnap - ok
00:30:14.0598 0x08e4 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
00:30:14.0630 0x08e4 vsmraid - ok
00:30:14.0661 0x08e4 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\windows\system32\vssvc.exe
00:30:14.0692 0x08e4 VSS - ok
00:30:14.0739 0x08e4 vtany - ok
00:30:14.0770 0x08e4 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
00:30:14.0770 0x08e4 vwifibus - ok
00:30:14.0770 0x08e4 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
00:30:14.0770 0x08e4 vwififlt - ok
00:30:14.0817 0x08e4 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
00:30:14.0817 0x08e4 vwifimp - ok
00:30:14.0848 0x08e4 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
00:30:14.0864 0x08e4 W32Time - ok
00:30:14.0879 0x08e4 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\drivers\wacompen.sys
00:30:14.0910 0x08e4 WacomPen - ok
00:30:14.0957 0x08e4 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
00:30:14.0957 0x08e4 WANARP - ok
00:30:14.0957 0x08e4 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
00:30:14.0957 0x08e4 Wanarpv6 - ok
00:30:15.0066 0x08e4 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
00:30:15.0176 0x08e4 WatAdminSvc - ok
00:30:15.0207 0x08e4 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\windows\system32\wbengine.exe
00:30:15.0238 0x08e4 wbengine - ok
00:30:15.0254 0x08e4 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
00:30:15.0254 0x08e4 WbioSrvc - ok
00:30:15.0300 0x08e4 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\windows\System32\wcncsvc.dll
00:30:15.0300 0x08e4 wcncsvc - ok
00:30:15.0332 0x08e4 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
00:30:15.0332 0x08e4 WcsPlugInService - ok
00:30:15.0347 0x08e4 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\drivers\wd.sys
00:30:15.0378 0x08e4 Wd - ok
00:30:15.0425 0x08e4 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
00:30:15.0441 0x08e4 Wdf01000 - ok
00:30:15.0472 0x08e4 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
00:30:15.0472 0x08e4 WdiServiceHost - ok
00:30:15.0488 0x08e4 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
00:30:15.0488 0x08e4 WdiSystemHost - ok
00:30:15.0519 0x08e4 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\windows\System32\webclnt.dll
00:30:15.0534 0x08e4 WebClient - ok
00:30:15.0550 0x08e4 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
00:30:15.0566 0x08e4 Wecsvc - ok
00:30:15.0581 0x08e4 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
00:30:15.0581 0x08e4 wercplsupport - ok
00:30:15.0597 0x08e4 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
00:30:15.0612 0x08e4 WerSvc - ok
00:30:15.0659 0x08e4 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
00:30:15.0659 0x08e4 WfpLwf - ok
00:30:15.0784 0x08e4 [ FB23FA0F51001C43306BBD784F68240F ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
00:30:15.0862 0x08e4 WiMAXAppSrv - ok
00:30:15.0909 0x08e4 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
00:30:15.0909 0x08e4 WIMMount - ok
00:30:15.0971 0x08e4 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
00:30:15.0987 0x08e4 WinDefend - ok
00:30:16.0002 0x08e4 WinHttpAutoProxySvc - ok
00:30:16.0065 0x08e4 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
00:30:16.0065 0x08e4 Winmgmt - ok
00:30:16.0127 0x08e4 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\windows\system32\WsmSvc.dll
00:30:16.0174 0x08e4 WinRM - ok
00:30:16.0236 0x08e4 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
00:30:16.0314 0x08e4 WinUsb - ok
00:30:16.0361 0x08e4 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
00:30:16.0377 0x08e4 Wlansvc - ok
00:30:16.0502 0x08e4 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
00:30:16.0564 0x08e4 wlidsvc - ok
00:30:16.0595 0x08e4 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
00:30:16.0611 0x08e4 WmiAcpi - ok
00:30:16.0626 0x08e4 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
00:30:16.0626 0x08e4 wmiApSrv - ok
00:30:16.0704 0x08e4 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
00:30:16.0751 0x08e4 WMPNetworkSvc - ok
00:30:16.0767 0x08e4 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\windows\System32\wpcsvc.dll
00:30:16.0782 0x08e4 WPCSvc - ok
00:30:16.0798 0x08e4 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
00:30:16.0814 0x08e4 WPDBusEnum - ok
00:30:16.0845 0x08e4 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
00:30:16.0845 0x08e4 ws2ifsl - ok
00:30:16.0892 0x08e4 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\windows\System32\wscsvc.dll
00:30:16.0892 0x08e4 wscsvc - ok
00:30:16.0907 0x08e4 WSearch - ok
00:30:16.0985 0x08e4 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
00:30:17.0048 0x08e4 wuauserv - ok
00:30:17.0079 0x08e4 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
00:30:17.0079 0x08e4 WudfPf - ok
00:30:17.0126 0x08e4 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
00:30:17.0126 0x08e4 WUDFRd - ok
00:30:17.0157 0x08e4 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\windows\System32\WUDFSvc.dll
00:30:17.0172 0x08e4 wudfsvc - ok
00:30:17.0204 0x08e4 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\windows\System32\wwansvc.dll
00:30:17.0204 0x08e4 WwanSvc - ok
00:30:17.0250 0x08e4 xhunter1 - ok
00:30:17.0313 0x08e4 [ 4CA7D86C6B1BDDE03C0088A1FBAE9D3F ] xsherlock C:\windows\xsherlock.xem
00:30:17.0422 0x08e4 xsherlock - ok
00:30:17.0469 0x08e4 [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7 C:\windows\system32\DRIVERS\yk62x86.sys
00:30:17.0531 0x08e4 yukonw7 - ok
00:30:17.0594 0x08e4 ================ Scan global ===============================
00:30:17.0609 0x08e4 [ 9A595DF601070DA78C40481120DD2C06 ] C:\windows\system32\basesrv.dll
00:30:17.0656 0x08e4 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
00:30:17.0656 0x08e4 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
00:30:17.0687 0x08e4 [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
00:30:17.0718 0x08e4 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
00:30:17.0734 0x08e4 [Global] - ok
00:30:17.0734 0x08e4 ================ Scan MBR ==================================
00:30:17.0750 0x08e4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
00:30:18.0218 0x08e4 \Device\Harddisk0\DR0 ( Rootkit.Win32.BackBoot.gen ) - warning
00:30:18.0218 0x08e4 \Device\Harddisk0\DR0 - detected Rootkit.Win32.BackBoot.gen (1)
00:30:18.0374 0x08e4 ================ Scan VBR ==================================
00:30:18.0374 0x08e4 [ B53F29E1260986DAD93910374E16F2BB ] \Device\Harddisk0\DR0\Partition1
00:30:18.0389 0x08e4 \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - infected
00:30:18.0389 0x08e4 \Device\Harddisk0\DR0\Partition1 - detected Rootkit.Boot.Cidox.b (0)
00:30:18.0420 0x08e4 [ B3B375D5F0E2AF118828E4624AD1527B ] \Device\Harddisk0\DR0\Partition2
00:30:18.0420 0x08e4 \Device\Harddisk0\DR0\Partition2 - ok
00:30:18.0452 0x08e4 [ 7756FDF06E6D9BE0977D4C949641D1C6 ] \Device\Harddisk0\DR0\Partition3
00:30:18.0452 0x08e4 \Device\Harddisk0\DR0\Partition3 - ok
00:30:18.0452 0x08e4 ============================================================
00:30:18.0452 0x08e4 Scan finished
00:30:18.0452 0x08e4 ============================================================
00:30:18.0452 0x1340 Detected object count: 2
00:30:18.0452 0x1340 Actual detected object count: 2
00:34:27.0787 0x1340 \Device\Harddisk0\DR0 ( Rootkit.Win32.BackBoot.gen ) - skipped by user
00:34:27.0787 0x1340 \Device\Harddisk0\DR0 ( Rootkit.Win32.BackBoot.gen ) - User select action: Skip
00:34:27.0834 0x1340 \Device\Harddisk0\DR0\Partition1 - copied to quarantine
00:34:27.0865 0x1340 \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - will be cured on reboot
00:34:27.0880 0x1340 \Device\Harddisk0\DR0\Partition1 - ok
00:34:27.0880 0x1340 \Device\Harddisk0\DR0\Partition1 ( Rootkit.Boot.Cidox.b ) - User select action: Cure
00:34:44.0916 0x14e4 Deinitialize success
  • 宵子
  • 2013/08/21 (Wed) 01:39:30
TDSSKiller2回目その1
2回目の前半です。

01:25:30.0957 0x17e8 TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29
01:25:31.0737 0x17e8 ============================================================
01:25:31.0737 0x17e8 Current date / time: 2013/08/21 01:25:31.0737
01:25:31.0737 0x17e8 SystemInfo:
01:25:31.0737 0x17e8
01:25:31.0737 0x17e8 OS Version: 6.1.7600 ServicePack: 0.0
01:25:31.0737 0x17e8 Product type: Workstation
01:25:31.0737 0x17e8 ComputerName: ICEPC
01:25:31.0737 0x17e8 UserName: PCUser
01:25:31.0737 0x17e8 Windows directory: C:\windows
01:25:31.0737 0x17e8 System windows directory: C:\windows
01:25:31.0752 0x17e8 Processor architecture: Intel x86
01:25:31.0752 0x17e8 Number of processors: 4
01:25:31.0752 0x17e8 Page size: 0x1000
01:25:31.0752 0x17e8 Boot type: Normal boot
01:25:31.0752 0x17e8 ============================================================
01:25:32.0064 0x17e8 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
01:25:32.0080 0x17e8 ============================================================
01:25:32.0080 0x17e8 \Device\Harddisk0\DR0:
01:25:32.0080 0x17e8 MBR partitions:
01:25:32.0080 0x17e8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3C00800, BlocksNum 0x64000
01:25:32.0080 0x17e8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3C64800, BlocksNum 0x235F9800
01:25:32.0080 0x17e8 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x2725E000, BlocksNum 0x235F9800
01:25:32.0080 0x17e8 ============================================================
01:25:32.0096 0x17e8 C: <-> \Device\Harddisk0\DR0\Partition2
01:25:32.0142 0x17e8 D: <-> \Device\Harddisk0\DR0\Partition3
01:25:32.0142 0x17e8 ============================================================
01:25:32.0142 0x17e8 Initialize success
01:25:32.0142 0x17e8 ============================================================
01:26:10.0503 0x1a78 ============================================================
01:26:10.0503 0x1a78 Scan started
01:26:10.0503 0x1a78 Mode: Manual; TDLFS;
01:26:10.0503 0x1a78 ============================================================
01:26:10.0924 0x1a78 ================ Scan system memory ========================
01:26:10.0924 0x1a78 System memory - ok
01:26:10.0924 0x1a78 ================ Scan services =============================
01:26:11.0220 0x1a78 [ D61B60F7C690ADE5BE74755A1D6DECC2 ] 13653783 C:\windows\system32\drivers\83179577.sys
01:26:11.0298 0x1a78 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
01:26:11.0298 0x1a78 1394ohci - ok
01:26:11.0361 0x1a78 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\windows\system32\drivers\ACPI.sys
01:26:11.0361 0x1a78 ACPI - ok
01:26:11.0408 0x1a78 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
01:26:11.0423 0x1a78 AcpiPmi - ok
01:26:11.0579 0x1a78 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
01:26:11.0579 0x1a78 AdobeARMservice - ok
01:26:11.0673 0x1a78 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
01:26:11.0688 0x1a78 AdobeFlashPlayerUpdateSvc - ok
01:26:11.0751 0x1a78 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\drivers\adp94xx.sys
01:26:11.0751 0x1a78 adp94xx - ok
01:26:11.0798 0x1a78 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\drivers\adpahci.sys
01:26:11.0798 0x1a78 adpahci - ok
01:26:11.0844 0x1a78 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\drivers\adpu320.sys
01:26:11.0844 0x1a78 adpu320 - ok
01:26:11.0876 0x1a78 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
01:26:11.0876 0x1a78 AeLookupSvc - ok
01:26:11.0938 0x1a78 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\windows\system32\drivers\afd.sys
01:26:11.0954 0x1a78 AFD - ok
01:26:12.0000 0x1a78 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
01:26:12.0000 0x1a78 agp440 - ok
01:26:12.0078 0x1a78 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\drivers\djsvs.sys
01:26:12.0078 0x1a78 aic78xx - ok
01:26:12.0125 0x1a78 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
01:26:12.0125 0x1a78 ALG - ok
01:26:12.0141 0x1a78 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
01:26:12.0141 0x1a78 aliide - ok
01:26:12.0172 0x1a78 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
01:26:12.0172 0x1a78 amdagp - ok
01:26:12.0203 0x1a78 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
01:26:12.0203 0x1a78 amdide - ok
01:26:12.0219 0x1a78 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
01:26:12.0219 0x1a78 AmdK8 - ok
01:26:12.0234 0x1a78 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
01:26:12.0234 0x1a78 AmdPPM - ok
01:26:12.0281 0x1a78 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\windows\system32\drivers\amdsata.sys
01:26:12.0281 0x1a78 amdsata - ok
01:26:12.0344 0x1a78 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\drivers\amdsbs.sys
01:26:12.0344 0x1a78 amdsbs - ok
01:26:12.0406 0x1a78 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\windows\system32\drivers\amdxata.sys
01:26:12.0406 0x1a78 amdxata - ok
01:26:12.0640 0x1a78 [ F52603B708438E39FF38475807A01CBC ] Amsp C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
01:26:12.0640 0x1a78 Amsp - ok
01:26:12.0718 0x1a78 [ 7B4BEB577C5D0171F9B66F390EC29284 ] apf001 C:\windows\system32\apf001.sys
01:26:12.0734 0x1a78 apf001 - ok
01:26:12.0858 0x1a78 [ 98F481241BA8BBA38AA565BD3BF678F9 ] appdrv01 C:\windows\system32\Drivers\appdrv01.sys
01:26:12.0952 0x1a78 appdrv01 - ok
01:26:12.0968 0x1a78 appdrvrem01 - ok
01:26:13.0014 0x1a78 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\windows\system32\drivers\appid.sys
01:26:13.0014 0x1a78 AppID - ok
01:26:13.0077 0x1a78 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
01:26:13.0077 0x1a78 AppIDSvc - ok
01:26:13.0092 0x1a78 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\windows\System32\appinfo.dll
01:26:13.0092 0x1a78 Appinfo - ok
01:26:13.0217 0x1a78 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
01:26:13.0217 0x1a78 Apple Mobile Device - ok
01:26:13.0264 0x1a78 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\drivers\arc.sys
01:26:13.0264 0x1a78 arc - ok
01:26:13.0280 0x1a78 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\drivers\arcsas.sys
01:26:13.0280 0x1a78 arcsas - ok
01:26:13.0326 0x1a78 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
01:26:13.0326 0x1a78 AsyncMac - ok
01:26:13.0358 0x1a78 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
01:26:13.0373 0x1a78 atapi - ok
01:26:13.0498 0x1a78 [ 457117113973C615046836889AA2E1E3 ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
01:26:13.0529 0x1a78 ATService - ok
01:26:13.0576 0x1a78 [ 51D379DB1C53C2A55FDF9372E748E5C7 ] ATSwpWDF C:\windows\system32\Drivers\ATSwpWDF.sys
01:26:13.0576 0x1a78 ATSwpWDF - ok
01:26:13.0607 0x1a78 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
01:26:13.0607 0x1a78 AudioEndpointBuilder - ok
01:26:13.0623 0x1a78 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\windows\System32\Audiosrv.dll
01:26:13.0623 0x1a78 Audiosrv - ok
01:26:13.0670 0x1a78 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\windows\System32\AxInstSV.dll
01:26:13.0685 0x1a78 AxInstSV - ok
01:26:13.0748 0x1a78 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
01:26:13.0763 0x1a78 b06bdrv - ok
01:26:13.0794 0x1a78 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
01:26:13.0794 0x1a78 b57nd60x - ok
01:26:13.0826 0x1a78 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
01:26:13.0826 0x1a78 BDESVC - ok
01:26:13.0841 0x1a78 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
01:26:13.0841 0x1a78 Beep - ok
01:26:13.0888 0x1a78 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\windows\System32\bfe.dll
01:26:13.0904 0x1a78 BFE - ok
01:26:13.0950 0x1a78 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\windows\System32\qmgr.dll
01:26:13.0966 0x1a78 BITS - ok
01:26:14.0013 0x1a78 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\drivers\blbdrive.sys
01:26:14.0013 0x1a78 blbdrive - ok
01:26:14.0106 0x1a78 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
01:26:14.0106 0x1a78 Bonjour Service - ok
01:26:14.0153 0x1a78 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\windows\system32\DRIVERS\bowser.sys
01:26:14.0153 0x1a78 bowser - ok
01:26:14.0200 0x1a78 [ F30A1AEF42106AF072547377E0CE0C7E ] bpenum C:\windows\system32\DRIVERS\bpenum.sys
01:26:14.0200 0x1a78 bpenum - ok
01:26:14.0247 0x1a78 [ DE04B62A29F10FD0AFC1990D107DD841 ] bpmp C:\windows\system32\DRIVERS\bpmp.sys
01:26:14.0262 0x1a78 bpmp - ok
01:26:14.0278 0x1a78 [ A10647B31715023E4988D65851E9B487 ] bpusb C:\windows\system32\Drivers\bpusb.sys
01:26:14.0278 0x1a78 bpusb - ok
01:26:14.0309 0x1a78 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
01:26:14.0309 0x1a78 BrFiltLo - ok
01:26:14.0356 0x1a78 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
01:26:14.0356 0x1a78 BrFiltUp - ok
01:26:14.0387 0x1a78 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\windows\System32\browser.dll
01:26:14.0403 0x1a78 Browser - ok
01:26:14.0450 0x1a78 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
01:26:14.0450 0x1a78 Brserid - ok
01:26:14.0481 0x1a78 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
01:26:14.0496 0x1a78 BrSerWdm - ok
01:26:14.0528 0x1a78 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
01:26:14.0528 0x1a78 BrUsbMdm - ok
01:26:14.0559 0x1a78 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
01:26:14.0559 0x1a78 BrUsbSer - ok
01:26:14.0574 0x1a78 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
01:26:14.0590 0x1a78 BTHMODEM - ok
01:26:14.0652 0x1a78 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
01:26:14.0652 0x1a78 bthserv - ok
01:26:14.0684 0x1a78 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
01:26:14.0684 0x1a78 cdfs - ok
01:26:14.0730 0x1a78 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
01:26:14.0730 0x1a78 cdrom - ok
01:26:14.0777 0x1a78 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\windows\System32\certprop.dll
01:26:14.0793 0x1a78 CertPropSvc - ok
01:26:14.0793 0x1a78 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\drivers\circlass.sys
01:26:14.0793 0x1a78 circlass - ok
01:26:14.0824 0x1a78 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
01:26:14.0840 0x1a78 CLFS - ok
01:26:14.0933 0x1a78 [ DEB7F963F49F329EC0AA31E3F3DC9A59 ] CLHNService3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe
01:26:14.0933 0x1a78 CLHNService3 - ok
01:26:14.0996 0x1a78 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
01:26:14.0996 0x1a78 clr_optimization_v2.0.50727_32 - ok
01:26:15.0058 0x1a78 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
01:26:15.0058 0x1a78 clr_optimization_v4.0.30319_32 - ok
01:26:15.0120 0x1a78 [ DB4643A1F4D12825EBD7F675D1AF8C8F ] clwvd C:\windows\system32\DRIVERS\clwvd.sys
01:26:15.0120 0x1a78 clwvd - ok
01:26:15.0167 0x1a78 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\drivers\CmBatt.sys
01:26:15.0167 0x1a78 CmBatt - ok
01:26:15.0183 0x1a78 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
01:26:15.0198 0x1a78 cmdide - ok
01:26:15.0245 0x1a78 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\windows\system32\Drivers\cng.sys
01:26:15.0245 0x1a78 CNG - ok
01:26:15.0339 0x1a78 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\drivers\compbatt.sys
01:26:15.0339 0x1a78 Compbatt - ok
01:26:15.0386 0x1a78 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
01:26:15.0386 0x1a78 CompositeBus - ok
01:26:15.0386 0x1a78 COMSysApp - ok
01:26:15.0417 0x1a78 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
01:26:15.0417 0x1a78 crcdisk - ok
01:26:15.0464 0x1a78 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\windows\system32\cryptsvc.dll
01:26:15.0464 0x1a78 CryptSvc - ok
01:26:15.0526 0x1a78 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\windows\system32\rpcss.dll
01:26:15.0542 0x1a78 DcomLaunch - ok
01:26:15.0620 0x1a78 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
01:26:15.0620 0x1a78 defragsvc - ok
01:26:15.0666 0x1a78 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\windows\system32\Drivers\dfsc.sys
01:26:15.0666 0x1a78 DfsC - ok
01:26:15.0713 0x1a78 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\windows\system32\dhcpcore.dll
01:26:15.0729 0x1a78 Dhcp - ok
01:26:15.0744 0x1a78 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
01:26:15.0744 0x1a78 discache - ok
01:26:15.0807 0x1a78 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\drivers\disk.sys
01:26:15.0807 0x1a78 Disk - ok
01:26:15.0900 0x1a78 [ BA870E4749421275EBA05AD6B08CB4F5 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
01:26:15.0900 0x1a78 DMAgent - ok
01:26:15.0963 0x1a78 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\windows\System32\dnsrslvr.dll
01:26:15.0963 0x1a78 Dnscache - ok
01:26:15.0994 0x1a78 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\windows\System32\dot3svc.dll
01:26:15.0994 0x1a78 dot3svc - ok
01:26:16.0025 0x1a78 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\windows\system32\dps.dll
01:26:16.0025 0x1a78 DPS - ok
01:26:16.0088 0x1a78 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
01:26:16.0088 0x1a78 drmkaud - ok
01:26:16.0134 0x1a78 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
01:26:16.0166 0x1a78 DXGKrnl - ok
01:26:16.0244 0x1a78 EagleXNt - ok
01:26:16.0275 0x1a78 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
01:26:16.0290 0x1a78 EapHost - ok
01:26:16.0384 0x1a78 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\drivers\evbdx.sys
01:26:16.0478 0x1a78 ebdrv - ok
01:26:16.0524 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\windows\System32\lsass.exe
01:26:16.0524 0x1a78 EFS - ok
01:26:16.0587 0x1a78 [ BC667D6C0A8A857CABA77818F1A953FD ] ehRecvr C:\windows\ehome\ehRecvr.exe
01:26:16.0587 0x1a78 ehRecvr - ok
01:26:16.0649 0x1a78 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
01:26:16.0649 0x1a78 ehSched - ok
01:26:16.0712 0x1a78 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\drivers\elxstor.sys
01:26:16.0727 0x1a78 elxstor - ok
01:26:16.0758 0x1a78 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
01:26:16.0758 0x1a78 ErrDev - ok
01:26:16.0821 0x1a78 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
01:26:16.0821 0x1a78 EventSystem - ok
01:26:16.0930 0x1a78 [ 8597822F0E0EAA61A9FFD18778828792 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
01:26:16.0930 0x1a78 EvtEng - ok
01:26:16.0992 0x1a78 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
01:26:17.0008 0x1a78 exfat - ok
01:26:17.0024 0x1a78 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
01:26:17.0024 0x1a78 fastfat - ok
01:26:17.0070 0x1a78 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\windows\system32\fxssvc.exe
01:26:17.0086 0x1a78 Fax - ok
01:26:17.0148 0x1a78 [ 22EC3B0EA37CDF4355AE627004F3103C ] FBIOSDRV C:\windows\system32\Drivers\FBIOSDRV.sys
01:26:17.0148 0x1a78 FBIOSDRV - ok
01:26:17.0195 0x1a78 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\drivers\fdc.sys
01:26:17.0195 0x1a78 fdc - ok
01:26:17.0226 0x1a78 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
01:26:17.0226 0x1a78 fdPHost - ok
01:26:17.0242 0x1a78 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
01:26:17.0258 0x1a78 FDResPub - ok
01:26:17.0273 0x1a78 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
01:26:17.0273 0x1a78 FileInfo - ok
01:26:17.0289 0x1a78 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
01:26:17.0304 0x1a78 Filetrace - ok
01:26:17.0367 0x1a78 [ 31A2624507524A52A08DB2BBF2DB28EC ] FjDstService C:\Program Files\Fujitsu\DustSolution\FJDService.exe
01:26:17.0367 0x1a78 FjDstService - ok
01:26:17.0414 0x1a78 [ 1F2918E7FFB62D21FEFBA43B0F943F6B ] FJGSDisk C:\windows\system32\DRIVERS\FJGSDisk.sys
01:26:17.0414 0x1a78 FJGSDisk - ok
01:26:17.0429 0x1a78 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
01:26:17.0429 0x1a78 flpydisk - ok
01:26:17.0492 0x1a78 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
01:26:17.0492 0x1a78 FltMgr - ok
01:26:17.0554 0x1a78 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\windows\system32\FntCache.dll
01:26:17.0585 0x1a78 FontCache - ok
01:26:17.0741 0x1a78 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
01:26:17.0757 0x1a78 FontCache3.0.0.0 - ok
01:26:17.0788 0x1a78 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
01:26:17.0788 0x1a78 FsDepends - ok
01:26:17.0850 0x1a78 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
01:26:17.0850 0x1a78 Fs_Rec - ok
01:26:17.0897 0x1a78 [ 49E588AC7D2B57F057756A91C6F36D25 ] FUJ02B1 C:\windows\system32\drivers\FUJ02B1.sys
01:26:17.0897 0x1a78 FUJ02B1 - ok
01:26:17.0960 0x1a78 [ D45474A7E5E2F35150C29A3193747884 ] FUJ02E3 C:\windows\system32\drivers\FUJ02E3.sys
01:26:17.0960 0x1a78 FUJ02E3 - ok
01:26:17.0991 0x1a78 [ 4732E596BB1C50D9F9188C5074EE7782 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
01:26:18.0006 0x1a78 fvevol - ok
01:26:18.0022 0x1a78 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
01:26:18.0022 0x1a78 gagp30kx - ok
01:26:18.0053 0x1a78 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
01:26:18.0069 0x1a78 GEARAspiWDM - ok
01:26:18.0084 0x1a78 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\windows\System32\gpsvc.dll
01:26:18.0100 0x1a78 gpsvc - ok
01:26:18.0147 0x1a78 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\windows\system32\DRIVERS\hamachi.sys
01:26:18.0147 0x1a78 hamachi - ok
01:26:18.0178 0x1a78 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
01:26:18.0194 0x1a78 hcw85cir - ok
01:26:18.0240 0x1a78 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
01:26:18.0256 0x1a78 HdAudAddService - ok
01:26:18.0256 0x1a78 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
01:26:18.0256 0x1a78 HDAudBus - ok
01:26:18.0303 0x1a78 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\windows\system32\drivers\HECI.sys
01:26:18.0318 0x1a78 HECI - ok
01:26:18.0350 0x1a78 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
01:26:18.0350 0x1a78 HidBatt - ok
01:26:18.0381 0x1a78 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\drivers\hidbth.sys
01:26:18.0381 0x1a78 HidBth - ok
01:26:18.0428 0x1a78 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\drivers\hidir.sys
01:26:18.0428 0x1a78 HidIr - ok
01:26:18.0459 0x1a78 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
01:26:18.0459 0x1a78 hidserv - ok
01:26:18.0490 0x1a78 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
01:26:18.0490 0x1a78 HidUsb - ok
01:26:18.0537 0x1a78 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\windows\system32\kmsvc.dll
01:26:18.0552 0x1a78 hkmsvc - ok
01:26:18.0568 0x1a78 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\windows\system32\ListSvc.dll
01:26:18.0568 0x1a78 HomeGroupListener - ok
01:26:18.0599 0x1a78 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\windows\system32\provsvc.dll
01:26:18.0615 0x1a78 HomeGroupProvider - ok
01:26:18.0662 0x1a78 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
01:26:18.0677 0x1a78 HpSAMD - ok
01:26:18.0740 0x1a78 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\windows\system32\drivers\HTTP.sys
01:26:18.0740 0x1a78 HTTP - ok
01:26:18.0755 0x1a78 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
01:26:18.0771 0x1a78 hwpolicy - ok
01:26:18.0786 0x1a78 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
01:26:18.0786 0x1a78 i8042prt - ok
01:26:18.0849 0x1a78 [ D80AA0907748D7CC8EFAB3773F32629B ] iaStor C:\windows\system32\drivers\iaStor.sys
01:26:18.0849 0x1a78 iaStor - ok
01:26:18.0896 0x1a78 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
01:26:18.0911 0x1a78 iaStorV - ok
01:26:18.0974 0x1a78 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
01:26:19.0005 0x1a78 idsvc - ok
01:26:19.0208 0x1a78 [ 8E9DA2E49347AF49901526DCD4D0F397 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
01:26:19.0395 0x1a78 igfx - ok
01:26:19.0426 0x1a78 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\drivers\iirsp.sys
01:26:19.0426 0x1a78 iirsp - ok
01:26:19.0473 0x1a78 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\windows\System32\ikeext.dll
01:26:19.0488 0x1a78 IKEEXT - ok
01:26:19.0551 0x1a78 [ 91AB587F7EA44B0DEB0522F71AD7B2DC ] ImeDictUpdateService C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
01:26:19.0551 0x1a78 ImeDictUpdateService - ok
01:26:19.0613 0x1a78 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\windows\system32\drivers\Impcd.sys
01:26:19.0629 0x1a78 Impcd - ok
01:26:19.0769 0x1a78 [ AEE99ECF06CD1CEA95816CCB5BF73EC8 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
01:26:19.0863 0x1a78 IntcAzAudAddService - ok
01:26:19.0925 0x1a78 [ BF31740828A26AB451803E3B35432651 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
01:26:19.0941 0x1a78 IntcDAud - ok
01:26:19.0972 0x1a78 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
01:26:19.0988 0x1a78 intelide - ok
01:26:20.0019 0x1a78 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\drivers\intelppm.sys
01:26:20.0034 0x1a78 intelppm - ok
01:26:20.0050 0x1a78 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
01:26:20.0066 0x1a78 IPBusEnum - ok
01:26:20.0097 0x1a78 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
01:26:20.0097 0x1a78 IpFilterDriver - ok
01:26:20.0112 0x1a78 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
01:26:20.0128 0x1a78 iphlpsvc - ok
01:26:20.0159 0x1a78 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
01:26:20.0159 0x1a78 IPMIDRV - ok
01:26:20.0190 0x1a78 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
01:26:20.0190 0x1a78 IPNAT - ok
01:26:20.0284 0x1a78 [ D8B8B5A8FE57CF4F307A540D9A153C23 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
01:26:20.0300 0x1a78 iPod Service - ok
01:26:20.0331 0x1a78 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
01:26:20.0331 0x1a78 IRENUM - ok
01:26:20.0393 0x1a78 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
01:26:20.0393 0x1a78 isapnp - ok
01:26:20.0409 0x1a78 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
01:26:20.0409 0x1a78 iScsiPrt - ok
01:26:20.0471 0x1a78 [ F415A88162D23977B5EDAE4F0410E903 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
01:26:20.0471 0x1a78 IviRegMgr - ok
01:26:20.0518 0x1a78 [ 703E40B3A128F1FB8C307ADA168CA121 ] k57nd60x C:\windows\system32\DRIVERS\k57nd60x.sys
01:26:20.0518 0x1a78 k57nd60x - ok
01:26:20.0580 0x1a78 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
01:26:20.0580 0x1a78 kbdclass - ok
01:26:20.0627 0x1a78 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
01:26:20.0627 0x1a78 kbdhid - ok
01:26:20.0643 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\windows\system32\lsass.exe
01:26:20.0643 0x1a78 KeyIso - ok
01:26:20.0674 0x1a78 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
01:26:20.0690 0x1a78 KSecDD - ok
01:26:20.0721 0x1a78 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
01:26:20.0721 0x1a78 KSecPkg - ok
01:26:20.0768 0x1a78 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
01:26:20.0768 0x1a78 KtmRm - ok
01:26:20.0830 0x1a78 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\windows\system32\srvsvc.dll
01:26:20.0830 0x1a78 LanmanServer - ok
01:26:20.0861 0x1a78 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\windows\System32\wkssvc.dll
01:26:20.0861 0x1a78 LanmanWorkstation - ok
01:26:20.0924 0x1a78 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
01:26:20.0924 0x1a78 lltdio - ok
01:26:20.0955 0x1a78 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
01:26:20.0970 0x1a78 lltdsvc - ok
01:26:20.0986 0x1a78 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
01:26:20.0986 0x1a78 lmhosts - ok
01:26:21.0064 0x1a78 [ A1C148801B4AF64847AEB9F3AD9594EF ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
01:26:21.0064 0x1a78 LMS - ok
01:26:21.0111 0x1a78 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
01:26:21.0111 0x1a78 LSI_FC - ok
01:26:21.0126 0x1a78 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
01:26:21.0142 0x1a78 LSI_SAS - ok
01:26:21.0173 0x1a78 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
01:26:21.0173 0x1a78 LSI_SAS2 - ok
01:26:21.0189 0x1a78 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
01:26:21.0189 0x1a78 LSI_SCSI - ok
01:26:21.0220 0x1a78 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
01:26:21.0220 0x1a78 luafv - ok
01:26:21.0251 0x1a78 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
01:26:21.0267 0x1a78 Mcx2Svc - ok
01:26:21.0282 0x1a78 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\drivers\megasas.sys
01:26:21.0282 0x1a78 megasas - ok
01:26:21.0329 0x1a78 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
01:26:21.0345 0x1a78 MegaSR - ok
01:26:21.0360 0x1a78 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
01:26:21.0360 0x1a78 MMCSS - ok
01:26:21.0376 0x1a78 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
01:26:21.0376 0x1a78 Modem - ok
01:26:21.0407 0x1a78 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
01:26:21.0407 0x1a78 monitor - ok
01:26:21.0423 0x1a78 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
01:26:21.0423 0x1a78 mouclass - ok
01:26:21.0485 0x1a78 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
01:26:21.0501 0x1a78 mouhid - ok
01:26:21.0516 0x1a78 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
01:26:21.0516 0x1a78 mountmgr - ok
01:26:21.0532 0x1a78 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\windows\system32\drivers\mpio.sys
01:26:21.0548 0x1a78 mpio - ok
01:26:21.0563 0x1a78 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
01:26:21.0563 0x1a78 mpsdrv - ok
01:26:21.0594 0x1a78 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\windows\system32\mpssvc.dll
01:26:21.0610 0x1a78 MpsSvc - ok
01:26:21.0626 0x1a78 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
01:26:21.0626 0x1a78 MRxDAV - ok
01:26:21.0672 0x1a78 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
01:26:21.0672 0x1a78 mrxsmb - ok
01:26:21.0719 0x1a78 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
01:26:21.0719 0x1a78 mrxsmb10 - ok
01:26:21.0735 0x1a78 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
01:26:21.0735 0x1a78 mrxsmb20 - ok
01:26:21.0750 0x1a78 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\windows\system32\drivers\msahci.sys
01:26:21.0750 0x1a78 msahci - ok
01:26:21.0797 0x1a78 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\windows\system32\drivers\msdsm.sys
01:26:21.0797 0x1a78 msdsm - ok
01:26:21.0813 0x1a78 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
01:26:21.0828 0x1a78 MSDTC - ok
01:26:21.0828 0x1a78 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
01:26:21.0844 0x1a78 Msfs - ok
01:26:21.0875 0x1a78 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
01:26:21.0875 0x1a78 mshidkmdf - ok
01:26:21.0891 0x1a78 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
01:26:21.0906 0x1a78 msisadrv - ok
01:26:21.0953 0x1a78 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
01:26:21.0953 0x1a78 MSiSCSI - ok
01:26:21.0969 0x1a78 msiserver - ok
01:26:21.0984 0x1a78 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
01:26:22.0000 0x1a78 MSKSSRV - ok
01:26:22.0031 0x1a78 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
01:26:22.0031 0x1a78 MSPCLOCK - ok
01:26:22.0047 0x1a78 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
01:26:22.0047 0x1a78 MSPQM - ok
01:26:22.0062 0x1a78 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
01:26:22.0062 0x1a78 MsRPC - ok
01:26:22.0109 0x1a78 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
01:26:22.0109 0x1a78 mssmbios - ok
01:26:22.0125 0x1a78 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
01:26:22.0125 0x1a78 MSTEE - ok
01:26:22.0156 0x1a78 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
01:26:22.0156 0x1a78 MTConfig - ok
01:26:22.0172 0x1a78 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
01:26:22.0172 0x1a78 Mup - ok
01:26:22.0203 0x1a78 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\windows\system32\qagentRT.dll
01:26:22.0218 0x1a78 napagent - ok
01:26:22.0265 0x1a78 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
01:26:22.0281 0x1a78 NativeWifiP - ok
01:26:22.0312 0x1a78 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\windows\system32\drivers\ndis.sys
01:26:22.0328 0x1a78 NDIS - ok
01:26:22.0359 0x1a78 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
01:26:22.0359 0x1a78 NdisCap - ok
01:26:22.0390 0x1a78 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
01:26:22.0390 0x1a78 NdisTapi - ok
01:26:22.0437 0x1a78 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
01:26:22.0437 0x1a78 Ndisuio - ok
01:26:22.0452 0x1a78 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
01:26:22.0452 0x1a78 NdisWan - ok
01:26:22.0468 0x1a78 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
01:26:22.0468 0x1a78 NDProxy - ok
01:26:22.0515 0x1a78 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
01:26:22.0515 0x1a78 NetBIOS - ok
01:26:22.0546 0x1a78 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
01:26:22.0546 0x1a78 NetBT - ok
01:26:22.0577 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\windows\system32\lsass.exe
01:26:22.0577 0x1a78 Netlogon - ok
01:26:22.0640 0x1a78 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
01:26:22.0655 0x1a78 Netman - ok
01:26:22.0686 0x1a78 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
01:26:22.0686 0x1a78 netprofm - ok
01:26:22.0718 0x1a78 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
01:26:22.0733 0x1a78 NetTcpPortSharing - ok
01:26:22.0889 0x1a78 [ 3577B851E59DA59E6D65419A057C9914 ] NETw5s32 C:\windows\system32\DRIVERS\NETw5s32.sys
01:26:23.0045 0x1a78 NETw5s32 - ok
01:26:23.0092 0x1a78 [ F282FC61839F8A719A3AD569CAB71C9C ] NetworkPlayer Server C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe
01:26:23.0108 0x1a78 NetworkPlayer Server - ok
01:26:23.0154 0x1a78 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
01:26:23.0154 0x1a78 nfrd960 - ok
01:26:23.0186 0x1a78 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\windows\System32\nlasvc.dll
01:26:23.0186 0x1a78 NlaSvc - ok
01:26:23.0201 0x1a78 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
01:26:23.0201 0x1a78 Npfs - ok
01:26:23.0264 0x1a78 npggsvc - ok
01:26:23.0357 0x1a78 [ 3964D26EE70B24B5318146247DD782DF ] npkakl C:\windows\system32\npkakl.sys
01:26:23.0357 0x1a78 npkakl - ok
01:26:23.0420 0x1a78 [ 83D727642D288A75A10100BEF5CDB756 ] npkcmsvc C:\windows\system32\npkcmsvc.exe
01:26:23.0435 0x1a78 npkcmsvc - ok
01:26:23.0451 0x1a78 [ 77BEB64EA3E83C37355B6D8EEB14008E ] npkcrypt C:\windows\system32\npkcrypt.sys
01:26:23.0466 0x1a78 npkcrypt - ok
01:26:23.0482 0x1a78 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
01:26:23.0482 0x1a78 nsi - ok
01:26:23.0498 0x1a78 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
01:26:23.0498 0x1a78 nsiproxy - ok
01:26:23.0576 0x1a78 [ A8F59428E9F361C7AC42A94AC1560BC9 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
01:26:23.0622 0x1a78 Ntfs - ok
01:26:23.0685 0x1a78 [ 588F2E8ACF3BDCE4496295806D21ECAF ] ntk3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\ntk3.sys
01:26:23.0700 0x1a78 ntk3 - ok
01:26:23.0716 0x1a78 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
01:26:23.0716 0x1a78 Null - ok
01:26:23.0732 0x1a78 [ EE0CB811A0F03038C2BC64538AA780F8 ] nusb3hub C:\windows\system32\drivers\nusb3hub.sys
01:26:23.0747 0x1a78 nusb3hub - ok
01:26:23.0763 0x1a78 [ 7CAA9F5D8602B236A92B17EDC87549F9 ] nusb3xhc C:\windows\system32\drivers\nusb3xhc.sys
01:26:23.0778 0x1a78 nusb3xhc - ok
01:26:23.0810 0x1a78 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\windows\system32\drivers\nvraid.sys
01:26:23.0825 0x1a78 nvraid - ok
01:26:23.0856 0x1a78 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\windows\system32\drivers\nvstor.sys
01:26:23.0872 0x1a78 nvstor - ok
01:26:23.0888 0x1a78 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
01:26:23.0888 0x1a78 nv_agp - ok
01:26:23.0903 0x1a78 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
01:26:23.0903 0x1a78 ohci1394 - ok
01:26:23.0966 0x1a78 [ 84113AB3A3EEF32FBEBF3339D8C19100 ] omniserv C:\Program Files\Softex\OmniPass\OmniServ.exe
01:26:23.0966 0x1a78 omniserv - ok
01:26:24.0044 0x1a78 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
01:26:24.0044 0x1a78 ose - ok
01:26:25.0136 0x1a78 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
01:26:25.0198 0x1a78 osppsvc - ok
01:26:25.0245 0x1a78 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
01:26:25.0245 0x1a78 p2pimsvc - ok
01:26:25.0307 0x1a78 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
01:26:25.0323 0x1a78 p2psvc - ok
01:26:25.0463 0x1a78 [ CB1257208C7105192F397187C14162E9 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
01:26:25.0479 0x1a78 PACSPTISVR - ok
01:26:25.0494 0x1a78 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\drivers\parport.sys
01:26:25.0510 0x1a78 Parport - ok
01:26:25.0541 0x1a78 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\windows\system32\drivers\partmgr.sys
01:26:25.0541 0x1a78 partmgr - ok
01:26:25.0557 0x1a78 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\drivers\parvdm.sys
01:26:25.0572 0x1a78 Parvdm - ok
01:26:25.0588 0x1a78 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
01:26:25.0588 0x1a78 PcaSvc - ok
01:26:25.0619 0x1a78 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\windows\system32\drivers\pci.sys
01:26:25.0619 0x1a78 pci - ok
01:26:25.0682 0x1a78 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
01:26:25.0682 0x1a78 pciide - ok
01:26:25.0697 0x1a78 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
01:26:25.0697 0x1a78 pcmcia - ok
01:26:25.0728 0x1a78 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
01:26:25.0728 0x1a78 pcw - ok
01:26:25.0775 0x1a78 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
01:26:25.0791 0x1a78 PEAUTH - ok
01:26:25.0884 0x1a78 [ F3B3F0BBC15C668EF87FD6C265994481 ] PFNService C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
01:26:25.0900 0x1a78 PFNService - ok
01:26:25.0978 0x1a78 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\windows\system32\pla.dll
01:26:26.0040 0x1a78 pla - ok
01:26:26.0072 0x1a78 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\windows\system32\umpnpmgr.dll
01:26:26.0087 0x1a78 PlugPlay - ok
01:26:26.0103 0x1a78 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
01:26:26.0118 0x1a78 PNRPAutoReg - ok
01:26:26.0134 0x1a78 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
01:26:26.0134 0x1a78 PNRPsvc - ok
01:26:26.0165 0x1a78 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
01:26:26.0165 0x1a78 PolicyAgent - ok
01:26:26.0196 0x1a78 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\windows\system32\umpo.dll
01:26:26.0196 0x1a78 Power - ok
01:26:26.0259 0x1a78 [ AEA6984F3DD10A76552480D46CF17EBD ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe
01:26:26.0259 0x1a78 PowerSavingUtilityService - ok
01:26:26.0290 0x1a78 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
01:26:26.0306 0x1a78 PptpMiniport - ok
01:26:26.0337 0x1a78 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\drivers\processr.sys
01:26:26.0337 0x1a78 Processor - ok
01:26:26.0368 0x1a78 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\windows\system32\profsvc.dll
01:26:26.0384 0x1a78 ProfSvc - ok
01:26:26.0399 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\windows\system32\lsass.exe
01:26:26.0399 0x1a78 ProtectedStorage - ok
01:26:26.0462 0x1a78 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
01:26:26.0462 0x1a78 Psched - ok
01:26:26.0540 0x1a78 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
01:26:26.0540 0x1a78 PSI_SVC_2 - ok
01:26:26.0618 0x1a78 [ 786DBE9D3A96481F21E8CF59CFA049A6 ] PUSCSRVC C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
01:26:26.0618 0x1a78 PUSCSRVC - ok
01:26:26.0664 0x1a78 [ B6A1692FC131F1FE5162513D78A9B6FC ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
01:26:26.0664 0x1a78 PxHelp20 - ok
01:26:26.0727 0x1a78 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\drivers\ql2300.sys
01:26:26.0774 0x1a78 ql2300 - ok
01:26:26.0805 0x1a78 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
01:26:26.0805 0x1a78 ql40xx - ok
01:26:26.0852 0x1a78 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
01:26:26.0852 0x1a78 QWAVE - ok
01:26:26.0883 0x1a78 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
01:26:26.0883 0x1a78 QWAVEdrv - ok
01:26:26.0898 0x1a78 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
01:26:26.0898 0x1a78 RasAcd - ok
01:26:26.0945 0x1a78 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
01:26:26.0945 0x1a78 RasAgileVpn - ok
01:26:26.0961 0x1a78 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
01:26:26.0976 0x1a78 RasAuto - ok
01:26:26.0992 0x1a78 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
01:26:26.0992 0x1a78 Rasl2tp - ok
01:26:27.0039 0x1a78 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\windows\System32\rasmans.dll
01:26:27.0039 0x1a78 RasMan - ok
01:26:27.0054 0x1a78 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
01:26:27.0054 0x1a78 RasPppoe - ok
01:26:27.0101 0x1a78 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
01:26:27.0117 0x1a78 RasSstp - ok
01:26:27.0132 0x1a78 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
01:26:27.0148 0x1a78 rdbss - ok
01:26:27.0179 0x1a78 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\drivers\rdpbus.sys
01:26:27.0179 0x1a78 rdpbus - ok
01:26:27.0210 0x1a78 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
01:26:27.0210 0x1a78 RDPCDD - ok
01:26:27.0242 0x1a78 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
01:26:27.0257 0x1a78 RDPENCDD - ok
01:26:27.0288 0x1a78 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
01:26:27.0288 0x1a78 RDPREFMP - ok
01:26:27.0335 0x1a78 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
01:26:27.0335 0x1a78 RDPWD - ok
01:26:27.0382 0x1a78 [ 65DB288F7372B1F632891FC32BF908B7 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
01:26:27.0382 0x1a78 rdyboost - ok
01:26:27.0507 0x1a78 [ B2D01290C0E0465ACA54C2088E947823 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
01:26:27.0507 0x1a78 RealNetworks Downloader Resolver Service - ok
01:26:27.0554 0x1a78 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\windows\system32\drivers\regi.sys
01:26:27.0554 0x1a78 regi - ok
01:26:27.0632 0x1a78 [ 7AFCBE32616E08D45E4EAADB0A1DD5CF ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
01:26:27.0632 0x1a78 RegSrvc - ok
01:26:27.0725 0x1a78 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
01:26:27.0725 0x1a78 RemoteAccess - ok
01:26:27.0741 0x1a78 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
01:26:27.0756 0x1a78 RemoteRegistry - ok
01:26:27.0788 0x1a78 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
01:26:27.0788 0x1a78 RpcEptMapper - ok
01:26:27.0819 0x1a78 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
01:26:27.0819 0x1a78 RpcLocator - ok
01:26:27.0850 0x1a78 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\windows\system32\rpcss.dll
01:26:27.0850 0x1a78 RpcSs - ok
01:26:27.0866 0x1a78 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
01:26:27.0866 0x1a78 rspndr - ok
01:26:27.0944 0x1a78 [ 11CC47F1CC7A66BBC6766F6037C5A678 ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
01:26:27.0944 0x1a78 RSUSBSTOR - ok
01:26:27.0975 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\windows\system32\lsass.exe
01:26:27.0975 0x1a78 SamSs - ok
01:26:28.0037 0x1a78 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
01:26:28.0037 0x1a78 sbp2port - ok
01:26:28.0053 0x1a78 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
01:26:28.0053 0x1a78 SCardSvr - ok
01:26:28.0068 0x1a78 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
01:26:28.0068 0x1a78 scfilter - ok
01:26:28.0115 0x1a78 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\windows\system32\schedsvc.dll
01:26:28.0115 0x1a78 Schedule - ok
01:26:28.0146 0x1a78 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\windows\System32\certprop.dll
01:26:28.0146 0x1a78 SCPolicySvc - ok
01:26:28.0162 0x1a78 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\windows\System32\SDRSVC.dll
01:26:28.0162 0x1a78 SDRSVC - ok
01:26:28.0178 0x1a78 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
01:26:28.0178 0x1a78 secdrv - ok
01:26:28.0178 0x1a78 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
01:26:28.0193 0x1a78 seclogon - ok
01:26:28.0209 0x1a78 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
01:26:28.0209 0x1a78 SENS - ok
01:26:28.0240 0x1a78 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
01:26:28.0256 0x1a78 SensrSvc - ok
01:26:28.0271 0x1a78 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\drivers\serenum.sys
01:26:28.0287 0x1a78 Serenum - ok
01:26:28.0302 0x1a78 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\drivers\serial.sys
01:26:28.0302 0x1a78 Serial - ok
01:26:28.0334 0x1a78 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\drivers\sermouse.sys
01:26:28.0334 0x1a78 sermouse - ok
01:26:28.0349 0x1a78 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\windows\system32\sessenv.dll
01:26:28.0365 0x1a78 SessionEnv - ok
01:26:28.0380 0x1a78 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
01:26:28.0380 0x1a78 sffdisk - ok
01:26:28.0380 0x1a78 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
01:26:28.0380 0x1a78 sffp_mmc - ok
01:26:28.0396 0x1a78 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
01:26:28.0396 0x1a78 sffp_sd - ok
01:26:28.0427 0x1a78 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
01:26:28.0427 0x1a78 sfloppy - ok
01:26:28.0490 0x1a78 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
01:26:28.0490 0x1a78 SharedAccess - ok
01:26:28.0521 0x1a78 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\windows\System32\shsvcs.dll
01:26:28.0521 0x1a78 ShellHWDetection - ok
01:26:28.0552 0x1a78 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
01:26:28.0552 0x1a78 sisagp - ok
01:26:28.0614 0x1a78 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
01:26:28.0614 0x1a78 SiSRaid2 - ok
01:26:28.0646 0x1a78 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
01:26:28.0646 0x1a78 SiSRaid4 - ok
01:26:28.0708 0x1a78 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
01:26:28.0708 0x1a78 SkypeUpdate - ok
01:26:28.0755 0x1a78 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
01:26:28.0770 0x1a78 Smb - ok
01:26:28.0817 0x1a78 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
01:26:28.0817 0x1a78 SNMPTRAP - ok
01:26:28.0942 0x1a78 [ A7D1229E1326D02CF80F952617C5A39B ] SNP2UVC C:\windows\system32\DRIVERS\snp2uvc.sys
01:26:29.0036 0x1a78 SNP2UVC - ok
01:26:29.0114 0x1a78 [ 6AE4902A4A819A7A1545D23972D70C55 ] SonicStage Back-End Service2 C:\Program Files\Common Files\Sony Shared\AVLib\SsBeService2.exe
01:26:29.0114 0x1a78 SonicStage Back-End Service2 - ok
01:26:29.0129 0x1a78 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
01:26:29.0145 0x1a78 spldr - ok
01:26:29.0192 0x1a78 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\windows\System32\spoolsv.exe
01:26:29.0207 0x1a78 Spooler - ok
01:26:29.0301 0x1a78 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\windows\system32\sppsvc.exe
01:26:29.0379 0x1a78 sppsvc - ok
01:26:29.0394 0x1a78 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\windows\system32\sppuinotify.dll
01:26:29.0394 0x1a78 sppuinotify - ok
01:26:29.0441 0x1a78 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\windows\system32\DRIVERS\srv.sys
01:26:29.0441 0x1a78 srv - ok
01:26:29.0472 0x1a78 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
01:26:29.0472 0x1a78 srv2 - ok
01:26:29.0504 0x1a78 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
01:26:29.0504 0x1a78 srvnet - ok
01:26:29.0519 0x1a78 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
01:26:29.0535 0x1a78 SSDPSRV - ok
01:26:29.0550 0x1a78 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
01:26:29.0550 0x1a78 SstpSvc - ok
01:26:29.0582 0x1a78 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\drivers\stexstor.sys
01:26:29.0582 0x1a78 stexstor - ok
01:26:29.0628 0x1a78 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\windows\System32\wiaservc.dll
01:26:29.0644 0x1a78 StiSvc - ok
01:26:29.0691 0x1a78 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
01:26:29.0691 0x1a78 swenum - ok
01:26:29.0722 0x1a78 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
01:26:29.0738 0x1a78 swprv - ok
01:26:29.0769 0x1a78 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\windows\system32\sysmain.dll
01:26:29.0800 0x1a78 SysMain - ok
01:26:29.0816 0x1a78 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\windows\System32\TabSvc.dll
01:26:29.0831 0x1a78 TabletInputService - ok
01:26:29.0847 0x1a78 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\windows\System32\tapisrv.dll
01:26:29.0847 0x1a78 TapiSrv - ok
01:26:29.0878 0x1a78 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
01:26:29.0878 0x1a78 TBS - ok
01:26:29.0925 0x1a78 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] Tcpip C:\windows\system32\drivers\tcpip.sys
01:26:29.0956 0x1a78 Tcpip - ok
01:26:30.0003 0x1a78 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
01:26:30.0003 0x1a78 TCPIP6 - ok
01:26:30.0050 0x1a78 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
01:26:30.0050 0x1a78 tcpipreg - ok
01:26:30.0065 0x1a78 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
01:26:30.0065 0x1a78 TDPIPE - ok
01:26:30.0096 0x1a78 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
01:26:30.0112 0x1a78 TDTCP - ok
01:26:30.0128 0x1a78 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\windows\system32\DRIVERS\tdx.sys
01:26:30.0128 0x1a78 tdx - ok
01:26:30.0159 0x1a78 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\windows\system32\drivers\termdd.sys
01:26:30.0159 0x1a78 TermDD - ok
01:26:30.0190 0x1a78 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\windows\System32\termsrv.dll
01:26:30.0206 0x1a78 TermService - ok
01:26:30.0221 0x1a78 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
01:26:30.0237 0x1a78 Themes - ok
01:26:30.0252 0x1a78 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
01:26:30.0252 0x1a78 THREADORDER - ok
01:26:30.0330 0x1a78 [ 883B3052721452E8667F5597AD2C5379 ] tmactmon C:\windows\system32\DRIVERS\tmactmon.sys
01:26:30.0330 0x1a78 tmactmon - ok
01:26:30.0440 0x1a78 [ F33C3F08536F988AAC84D72D83B139A6 ] tmcomm C:\windows\system32\DRIVERS\tmcomm.sys
01:26:30.0440 0x1a78 tmcomm - ok
01:26:30.0502 0x1a78 [ A17D672CBE700272DA499AA3ED60D3CC ] tmeevw C:\windows\system32\DRIVERS\tmeevw.sys
01:26:30.0502 0x1a78 tmeevw - ok
01:26:30.0549 0x1a78 [ 8FE7172FF137249BEA4EBC750EF90093 ] tmevtmgr C:\windows\system32\DRIVERS\tmevtmgr.sys
01:26:30.0549 0x1a78 tmevtmgr - ok
01:26:30.0580 0x1a78 [ 0C40396F071A8092964C8DC951F62B17 ] tmnciesc C:\windows\system32\DRIVERS\tmnciesc.sys
01:26:30.0580 0x1a78 tmnciesc - ok
01:26:30.0627 0x1a78 [ 43C1B7C778B296D492AF6D2ABB2ECF7F ] tmtdi C:\windows\system32\DRIVERS\tmtdi.sys
01:26:30.0627 0x1a78 tmtdi - ok
01:26:30.0674 0x1a78 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
01:26:30.0674 0x1a78 TrkWks - ok
01:26:30.0720 0x1a78 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
01:26:30.0720 0x1a78 TrustedInstaller - ok
01:26:30.0752 0x1a78 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
01:26:30.0752 0x1a78 tssecsrv - ok
01:26:30.0783 0x1a78 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
01:26:30.0798 0x1a78 tunnel - ok
01:26:30.0814 0x1a78 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\drivers\uagp35.sys
01:26:30.0814 0x1a78 uagp35 - ok
01:26:30.0908 0x1a78 [ F7DF6654663AD07DAB615A7AF513D90C ] UCManSvc C:\Program Files\SoftDenchi\UCManSvc.exe
01:26:30.0923 0x1a78 UCManSvc - ok
01:26:30.0954 0x1a78 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\windows\system32\DRIVERS\udfs.sys
01:26:30.0954 0x1a78 udfs - ok
01:26:31.0032 0x1a78 [ 27B37460477592A4C591F83675A096F9 ] UDSS c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe
01:26:31.0048 0x1a78 UDSS - ok
01:26:31.0064 0x1a78 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
01:26:31.0079 0x1a78 UI0Detect - ok
01:26:31.0126 0x1a78 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
01:26:31.0126 0x1a78 uliagpkx - ok
01:26:31.0173 0x1a78 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\windows\system32\DRIVERS\umbus.sys
01:26:31.0188 0x1a78 umbus - ok
01:26:31.0235 0x1a78 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\drivers\umpass.sys
01:26:31.0235 0x1a78 UmPass - ok
01:26:31.0329 0x1a78 [ 41118D920B2B268C0ADC36421248CDCF ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
01:26:31.0344 0x1a78 UNS - ok
01:26:31.0376 0x1a78 [ C11D90101CB125AFC47525066EFF4AE9 ] UpdateNaviInstallService C:\Program Files\Fujitsu\chitose\updnvsrv.exe
01:26:31.0391 0x1a78 UpdateNaviInstallService - ok
01:26:31.0407 0x1a78 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
01:26:31.0407 0x1a78 upnphost - ok
01:26:31.0469 0x1a78 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\windows\system32\Drivers\usbaapl.sys
01:26:31.0469 0x1a78 USBAAPL - ok
01:26:31.0516 0x1a78 [ 5C233AEFB566EE78C1EFBC0493FB066A ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
01:26:31.0516 0x1a78 usbccgp - ok
01:26:31.0547 0x1a78 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\windows\system32\drivers\usbcir.sys
01:26:31.0547 0x1a78 usbcir - ok
01:26:31.0594 0x1a78 [ 5B71019A6ACA0116FD21B368F19C0B91 ] usbehci C:\windows\system32\drivers\usbehci.sys
01:26:31.0594 0x1a78 usbehci - ok
01:26:31.0641 0x1a78 [ 5823D3965C2A4F6F785ED1A3B403F3B8 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
01:26:31.0656 0x1a78 usbhub - ok
01:26:31.0688 0x1a78 [ E753ED6C49DA13967EBABF9EA616454A ] usbohci C:\windows\system32\drivers\usbohci.sys
01:26:31.0688 0x1a78 usbohci - ok
01:26:31.0734 0x1a78 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
01:26:31.0734 0x1a78 usbprint - ok
01:26:31.0797 0x1a78 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\windows\system32\DRIVERS\usbscan.sys
01:26:31.0797 0x1a78 usbscan - ok
01:26:31.0859 0x1a78 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
01:26:31.0859 0x1a78 USBSTOR - ok
01:26:31.0890 0x1a78 [ 6A30928A469CE802600E1EA8C0F2F53F ] usbuhci C:\windows\system32\drivers\usbuhci.sys
01:26:31.0906 0x1a78 usbuhci - ok
01:26:31.0953 0x1a78 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
01:26:31.0953 0x1a78 usbvideo - ok
01:26:31.0984 0x1a78 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
01:26:32.0000 0x1a78 UxSms - ok
01:26:32.0015 0x1a78 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\windows\system32\lsass.exe
01:26:32.0015 0x1a78 VaultSvc - ok
01:26:32.0078 0x1a78 [ B2ABAB4CA46BAD182E27763DC19C780F ] VCSVADHWSer C:\windows\system32\DRIVERS\vcsvad.sys
01:26:32.0078 0x1a78 VCSVADHWSer - ok
01:26:32.0093 0x1a78 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
01:26:32.0109 0x1a78 vdrvroot - ok
01:26:32.0140 0x1a78 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\windows\System32\vds.exe
01:26:32.0156 0x1a78 vds - ok
01:26:32.0202 0x1a78 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
01:26:32.0218 0x1a78 vga - ok
01:26:32.0249 0x1a78 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
01:26:32.0249 0x1a78 VgaSave - ok
01:26:32.0280 0x1a78 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
01:26:32.0280 0x1a78 vhdmp - ok
01:26:32.0343 0x1a78 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
01:26:32.0343 0x1a78 viaagp - ok
01:26:32.0358 0x1a78 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\drivers\viac7.sys
01:26:32.0374 0x1a78 ViaC7 - ok
01:26:32.0405 0x1a78 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
01:26:32.0405 0x1a78 viaide - ok
01:26:32.0421 0x1a78 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\windows\system32\drivers\volmgr.sys
01:26:32.0421 0x1a78 volmgr - ok
01:26:32.0436 0x1a78 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
01:26:32.0436 0x1a78 volmgrx - ok
01:26:32.0468 0x1a78 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\windows\system32\drivers\volsnap.sys
01:26:32.0468 0x1a78 volsnap - ok
01:26:32.0530 0x1a78 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
01:26:32.0530 0x1a78 vsmraid - ok
01:26:32.0624 0x1a78 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\windows\system32\vssvc.exe
01:26:32.0655 0x1a78 VSS - ok
01:26:32.0702 0x1a78 vtany - ok
01:26:32.0717 0x1a78 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
01:26:32.0733 0x1a78 vwifibus - ok
01:26:32.0733 0x1a78 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
01:26:32.0733 0x1a78 vwififlt - ok
01:26:32.0780 0x1a78 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
01:26:32.0795 0x1a78 vwifimp - ok
01:26:32.0811 0x1a78 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
01:26:32.0826 0x1a78 W32Time - ok
01:26:32.0842 0x1a78 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\drivers\wacompen.sys
01:26:32.0858 0x1a78 WacomPen - ok
01:26:32.0889 0x1a78 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
01:26:32.0889 0x1a78 WANARP - ok
01:26:32.0904 0x1a78 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
01:26:32.0904 0x1a78 Wanarpv6 - ok
01:26:32.0982 0x1a78 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
01:26:33.0029 0x1a78 WatAdminSvc - ok
01:26:33.0076 0x1a78 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\windows\system32\wbengine.exe
01:26:33.0107 0x1a78 wbengine - ok
01:26:33.0123 0x1a78 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
01:26:33.0138 0x1a78 WbioSrvc
  • 宵子
  • 2013/08/21 (Wed) 01:40:41
TDSSKiller2回目その2
2回目の中盤です。


01:26:33.0201 0x1a78 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
01:26:33.0201 0x1a78 WcsPlugInService - ok
01:26:33.0216 0x1a78 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\drivers\wd.sys
01:26:33.0216 0x1a78 Wd - ok
01:26:33.0279 0x1a78 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
01:26:33.0294 0x1a78 Wdf01000 - ok
01:26:33.0326 0x1a78 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
01:26:33.0326 0x1a78 WdiServiceHost - ok
01:26:33.0326 0x1a78 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
01:26:33.0341 0x1a78 WdiSystemHost - ok
01:26:33.0388 0x1a78 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\windows\System32\webclnt.dll
01:26:33.0388 0x1a78 WebClient - ok
01:26:33.0404 0x1a78 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
01:26:33.0419 0x1a78 Wecsvc - ok
01:26:33.0435 0x1a78 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
01:26:33.0450 0x1a78 wercplsupport - ok
01:26:33.0497 0x1a78 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
01:26:33.0497 0x1a78 WerSvc - ok
01:26:33.0528 0x1a78 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
01:26:33.0528 0x1a78 WfpLwf - ok
01:26:33.0669 0x1a78 [ FB23FA0F51001C43306BBD784F68240F ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
01:26:33.0684 0x1a78 WiMAXAppSrv - ok
01:26:33.0716 0x1a78 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
01:26:33.0716 0x1a78 WIMMount - ok
01:26:33.0794 0x1a78 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
01:26:33.0809 0x1a78 WinDefend - ok
01:26:33.0809 0x1a78 WinHttpAutoProxySvc - ok
01:26:33.0872 0x1a78 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
01:26:33.0872 0x1a78 Winmgmt - ok
01:26:33.0934 0x1a78 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\windows\system32\WsmSvc.dll
01:26:33.0981 0x1a78 WinRM - ok
01:26:34.0074 0x1a78 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
01:26:34.0074 0x1a78 WinUsb - ok
01:26:34.0121 0x1a78 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
01:26:34.0152 0x1a78 Wlansvc - ok
01:26:34.0277 0x1a78 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
01:26:34.0308 0x1a78 wlidsvc - ok
01:26:34.0355 0x1a78 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
01:26:34.0355 0x1a78 WmiAcpi - ok
01:26:34.0386 0x1a78 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
01:26:34.0386 0x1a78 wmiApSrv - ok
01:26:34.0464 0x1a78 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
01:26:34.0496 0x1a78 WMPNetworkSvc - ok
01:26:34.0511 0x1a78 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\windows\System32\wpcsvc.dll
01:26:34.0527 0x1a78 WPCSvc - ok
01:26:34.0542 0x1a78 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
01:26:34.0542 0x1a78 WPDBusEnum - ok
01:26:34.0558 0x1a78 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
01:26:34.0558 0x1a78 ws2ifsl - ok
01:26:34.0589 0x1a78 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\windows\System32\wscsvc.dll
01:26:34.0605 0x1a78 wscsvc - ok
01:26:34.0605 0x1a78 WSearch - ok
01:26:34.0683 0x1a78 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
01:26:34.0745 0x1a78 wuauserv - ok
01:26:34.0776 0x1a78 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
01:26:34.0776 0x1a78 WudfPf - ok
01:26:34.0823 0x1a78 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
01:26:34.0823 0x1a78 WUDFRd - ok
01:26:34.0854 0x1a78 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\windows\System32\WUDFSvc.dll
01:26:34.0870 0x1a78 wudfsvc - ok
01:26:34.0901 0x1a78 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\windows\System32\wwansvc.dll
01:26:34.0901 0x1a78 WwanSvc - ok
01:26:34.0964 0x1a78 xhunter1 - ok
01:26:35.0057 0x1a78 [ 4CA7D86C6B1BDDE03C0088A1FBAE9D3F ] xsherlock C:\windows\xsherlock.xem
01:26:35.0073 0x1a78 xsherlock - ok
01:26:35.0135 0x1a78 [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7 C:\windows\system32\DRIVERS\yk62x86.sys
01:26:35.0135 0x1a78 yukonw7 - ok
01:26:35.0182 0x1a78 ================ Scan global ===============================
01:26:35.0229 0x1a78 [ 9A595DF601070DA78C40481120DD2C06 ] C:\windows\system32\basesrv.dll
01:26:35.0260 0x1a78 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:26:35.0276 0x1a78 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:26:35.0307 0x1a78 [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
01:26:35.0354 0x1a78 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
01:26:35.0354 0x1a78 [Global] - ok
01:26:35.0354 0x1a78 ================ Scan MBR ==================================
01:26:35.0369 0x1a78 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
01:26:35.0853 0x1a78 \Device\Harddisk0\DR0 - ok
01:26:35.0853 0x1a78 ================ Scan VBR ==================================
01:26:35.0853 0x1a78 [ 858CC5A24FD61FFA558376040673AEE4 ] \Device\Harddisk0\DR0\Partition1
01:26:35.0868 0x1a78 \Device\Harddisk0\DR0\Partition1 - ok
01:26:35.0900 0x1a78 [ B3B375D5F0E2AF118828E4624AD1527B ] \Device\Harddisk0\DR0\Partition2
01:26:35.0900 0x1a78 \Device\Harddisk0\DR0\Partition2 - ok
01:26:35.0931 0x1a78 [ 7756FDF06E6D9BE0977D4C949641D1C6 ] \Device\Harddisk0\DR0\Partition3
01:26:35.0931 0x1a78 \Device\Harddisk0\DR0\Partition3 - ok
01:26:35.0931 0x1a78 ============================================================
01:26:35.0931 0x1a78 Scan finished
01:26:35.0931 0x1a78 ============================================================
01:26:35.0946 0x1afc Detected object count: 0
01:26:35.0946 0x1afc Actual detected object count: 0
01:26:53.0356 0x1220 ============================================================
01:26:53.0356 0x1220 Scan started
01:26:53.0356 0x1220 Mode: Manual; TDLFS;
01:26:53.0356 0x1220 ============================================================
01:26:53.0528 0x1220 ================ Scan system memory ========================
01:26:53.0528 0x1220 System memory - ok
01:26:53.0528 0x1220 ================ Scan services =============================
01:26:53.0793 0x1220 [ D61B60F7C690ADE5BE74755A1D6DECC2 ] 13653783 C:\windows\system32\drivers\83179577.sys
01:26:53.0840 0x1220 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
01:26:53.0855 0x1220 1394ohci - ok
01:26:53.0886 0x1220 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\windows\system32\drivers\ACPI.sys
01:26:53.0902 0x1220 ACPI - ok
01:26:53.0933 0x1220 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
01:26:53.0933 0x1220 AcpiPmi - ok
01:26:54.0027 0x1220 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
01:26:54.0042 0x1220 AdobeARMservice - ok
01:26:54.0105 0x1220 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
01:26:54.0105 0x1220 AdobeFlashPlayerUpdateSvc - ok
01:26:54.0152 0x1220 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\drivers\adp94xx.sys
01:26:54.0167 0x1220 adp94xx - ok
01:26:54.0214 0x1220 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\drivers\adpahci.sys
01:26:54.0214 0x1220 adpahci - ok
01:26:54.0245 0x1220 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\drivers\adpu320.sys
01:26:54.0261 0x1220 adpu320 - ok
01:26:54.0308 0x1220 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
01:26:54.0308 0x1220 AeLookupSvc - ok
01:26:54.0370 0x1220 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\windows\system32\drivers\afd.sys
01:26:54.0370 0x1220 AFD - ok
01:26:54.0417 0x1220 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
01:26:54.0417 0x1220 agp440 - ok
01:26:54.0448 0x1220 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\drivers\djsvs.sys
01:26:54.0448 0x1220 aic78xx - ok
01:26:54.0464 0x1220 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
01:26:54.0464 0x1220 ALG - ok
01:26:54.0479 0x1220 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
01:26:54.0479 0x1220 aliide - ok
01:26:54.0510 0x1220 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
01:26:54.0510 0x1220 amdagp - ok
01:26:54.0542 0x1220 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
01:26:54.0542 0x1220 amdide - ok
01:26:54.0557 0x1220 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
01:26:54.0557 0x1220 AmdK8 - ok
01:26:54.0557 0x1220 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
01:26:54.0573 0x1220 AmdPPM - ok
01:26:54.0604 0x1220 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\windows\system32\drivers\amdsata.sys
01:26:54.0620 0x1220 amdsata - ok
01:26:54.0651 0x1220 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\drivers\amdsbs.sys
01:26:54.0651 0x1220 amdsbs - ok
01:26:54.0698 0x1220 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\windows\system32\drivers\amdxata.sys
01:26:54.0698 0x1220 amdxata - ok
01:26:54.0822 0x1220 [ F52603B708438E39FF38475807A01CBC ] Amsp C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
01:26:54.0822 0x1220 Amsp - ok
01:26:54.0869 0x1220 [ 7B4BEB577C5D0171F9B66F390EC29284 ] apf001 C:\windows\system32\apf001.sys
01:26:54.0869 0x1220 apf001 - ok
01:26:54.0978 0x1220 [ 98F481241BA8BBA38AA565BD3BF678F9 ] appdrv01 C:\windows\system32\Drivers\appdrv01.sys
01:26:55.0025 0x1220 appdrv01 - ok
01:26:55.0025 0x1220 appdrvrem01 - ok
01:26:55.0056 0x1220 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\windows\system32\drivers\appid.sys
01:26:55.0056 0x1220 AppID - ok
01:26:55.0088 0x1220 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
01:26:55.0088 0x1220 AppIDSvc - ok
01:26:55.0088 0x1220 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\windows\System32\appinfo.dll
01:26:55.0088 0x1220 Appinfo - ok
01:26:55.0181 0x1220 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
01:26:55.0181 0x1220 Apple Mobile Device - ok
01:26:55.0212 0x1220 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\drivers\arc.sys
01:26:55.0212 0x1220 arc - ok
01:26:55.0228 0x1220 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\drivers\arcsas.sys
01:26:55.0228 0x1220 arcsas - ok
01:26:55.0244 0x1220 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
01:26:55.0244 0x1220 AsyncMac - ok
01:26:55.0259 0x1220 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
01:26:55.0259 0x1220 atapi - ok
01:26:55.0353 0x1220 [ 457117113973C615046836889AA2E1E3 ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
01:26:55.0384 0x1220 ATService - ok
01:26:55.0415 0x1220 [ 51D379DB1C53C2A55FDF9372E748E5C7 ] ATSwpWDF C:\windows\system32\Drivers\ATSwpWDF.sys
01:26:55.0415 0x1220 ATSwpWDF - ok
01:26:55.0446 0x1220 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
01:26:55.0446 0x1220 AudioEndpointBuilder - ok
01:26:55.0462 0x1220 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\windows\System32\Audiosrv.dll
01:26:55.0462 0x1220 Audiosrv - ok
01:26:55.0493 0x1220 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\windows\System32\AxInstSV.dll
01:26:55.0493 0x1220 AxInstSV - ok
01:26:55.0540 0x1220 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
01:26:55.0556 0x1220 b06bdrv - ok
01:26:55.0571 0x1220 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
01:26:55.0571 0x1220 b57nd60x - ok
01:26:55.0602 0x1220 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
01:26:55.0602 0x1220 BDESVC - ok
01:26:55.0634 0x1220 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
01:26:55.0634 0x1220 Beep - ok
01:26:55.0665 0x1220 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\windows\System32\bfe.dll
01:26:55.0665 0x1220 BFE - ok
01:26:55.0712 0x1220 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\windows\System32\qmgr.dll
01:26:55.0727 0x1220 BITS - ok
01:26:55.0758 0x1220 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\drivers\blbdrive.sys
01:26:55.0774 0x1220 blbdrive - ok
01:26:55.0821 0x1220 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
01:26:55.0821 0x1220 Bonjour Service - ok
01:26:55.0868 0x1220 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\windows\system32\DRIVERS\bowser.sys
01:26:55.0868 0x1220 bowser - ok
01:26:55.0914 0x1220 [ F30A1AEF42106AF072547377E0CE0C7E ] bpenum C:\windows\system32\DRIVERS\bpenum.sys
01:26:55.0914 0x1220 bpenum - ok
01:26:55.0930 0x1220 [ DE04B62A29F10FD0AFC1990D107DD841 ] bpmp C:\windows\system32\DRIVERS\bpmp.sys
01:26:55.0930 0x1220 bpmp - ok
01:26:55.0961 0x1220 [ A10647B31715023E4988D65851E9B487 ] bpusb C:\windows\system32\Drivers\bpusb.sys
01:26:55.0961 0x1220 bpusb - ok
01:26:55.0977 0x1220 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
01:26:55.0977 0x1220 BrFiltLo - ok
01:26:56.0008 0x1220 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
01:26:56.0008 0x1220 BrFiltUp - ok
01:26:56.0055 0x1220 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\windows\System32\browser.dll
01:26:56.0055 0x1220 Browser - ok
01:26:56.0070 0x1220 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
01:26:56.0070 0x1220 Brserid - ok
01:26:56.0102 0x1220 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
01:26:56.0102 0x1220 BrSerWdm - ok
01:26:56.0133 0x1220 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
01:26:56.0133 0x1220 BrUsbMdm - ok
01:26:56.0180 0x1220 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
01:26:56.0180 0x1220 BrUsbSer - ok
01:26:56.0195 0x1220 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
01:26:56.0195 0x1220 BTHMODEM - ok
01:26:56.0242 0x1220 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
01:26:56.0242 0x1220 bthserv - ok
01:26:56.0273 0x1220 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
01:26:56.0273 0x1220 cdfs - ok
01:26:56.0304 0x1220 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
01:26:56.0304 0x1220 cdrom - ok
01:26:56.0320 0x1220 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\windows\System32\certprop.dll
01:26:56.0320 0x1220 CertPropSvc - ok
01:26:56.0320 0x1220 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\drivers\circlass.sys
01:26:56.0320 0x1220 circlass - ok
01:26:56.0351 0x1220 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
01:26:56.0351 0x1220 CLFS - ok
01:26:56.0445 0x1220 [ DEB7F963F49F329EC0AA31E3F3DC9A59 ] CLHNService3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe
01:26:56.0445 0x1220 CLHNService3 - ok
01:26:56.0507 0x1220 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
01:26:56.0507 0x1220 clr_optimization_v2.0.50727_32 - ok
01:26:56.0570 0x1220 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
01:26:56.0570 0x1220 clr_optimization_v4.0.30319_32 - ok
01:26:56.0616 0x1220 [ DB4643A1F4D12825EBD7F675D1AF8C8F ] clwvd C:\windows\system32\DRIVERS\clwvd.sys
01:26:56.0616 0x1220 clwvd - ok
01:26:56.0632 0x1220 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\drivers\CmBatt.sys
01:26:56.0632 0x1220 CmBatt - ok
01:26:56.0648 0x1220 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
01:26:56.0663 0x1220 cmdide - ok
01:26:56.0710 0x1220 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\windows\system32\Drivers\cng.sys
01:26:56.0710 0x1220 CNG - ok
01:26:56.0741 0x1220 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\drivers\compbatt.sys
01:26:56.0741 0x1220 Compbatt - ok
01:26:56.0772 0x1220 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
01:26:56.0772 0x1220 CompositeBus - ok
01:26:56.0772 0x1220 COMSysApp - ok
01:26:56.0804 0x1220 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
01:26:56.0804 0x1220 crcdisk - ok
01:26:56.0835 0x1220 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\windows\system32\cryptsvc.dll
01:26:56.0850 0x1220 CryptSvc - ok
01:26:56.0897 0x1220 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\windows\system32\rpcss.dll
01:26:56.0897 0x1220 DcomLaunch - ok
01:26:56.0928 0x1220 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
01:26:56.0928 0x1220 defragsvc - ok
01:26:56.0975 0x1220 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\windows\system32\Drivers\dfsc.sys
01:26:56.0975 0x1220 DfsC - ok
01:26:57.0006 0x1220 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\windows\system32\dhcpcore.dll
01:26:57.0006 0x1220 Dhcp - ok
01:26:57.0038 0x1220 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
01:26:57.0038 0x1220 discache - ok
01:26:57.0069 0x1220 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\drivers\disk.sys
01:26:57.0069 0x1220 Disk - ok
01:26:57.0131 0x1220 [ BA870E4749421275EBA05AD6B08CB4F5 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
01:26:57.0147 0x1220 DMAgent - ok
01:26:57.0194 0x1220 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\windows\System32\dnsrslvr.dll
01:26:57.0194 0x1220 Dnscache - ok
01:26:57.0225 0x1220 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\windows\System32\dot3svc.dll
01:26:57.0225 0x1220 dot3svc - ok
01:26:57.0256 0x1220 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\windows\system32\dps.dll
01:26:57.0256 0x1220 DPS - ok
01:26:57.0287 0x1220 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
01:26:57.0287 0x1220 drmkaud - ok
01:26:57.0334 0x1220 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
01:26:57.0350 0x1220 DXGKrnl - ok
01:26:57.0350 0x1220 EagleXNt - ok
01:26:57.0396 0x1220 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
01:26:57.0396 0x1220 EapHost - ok
01:26:57.0506 0x1220 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\drivers\evbdx.sys
01:26:57.0537 0x1220 ebdrv - ok
01:26:57.0568 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\windows\System32\lsass.exe
01:26:57.0568 0x1220 EFS - ok
01:26:57.0630 0x1220 [ BC667D6C0A8A857CABA77818F1A953FD ] ehRecvr C:\windows\ehome\ehRecvr.exe
01:26:57.0630 0x1220 ehRecvr - ok
01:26:57.0662 0x1220 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
01:26:57.0677 0x1220 ehSched - ok
01:26:57.0708 0x1220 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\drivers\elxstor.sys
01:26:57.0724 0x1220 elxstor - ok
01:26:57.0740 0x1220 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
01:26:57.0740 0x1220 ErrDev - ok
01:26:57.0771 0x1220 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
01:26:57.0786 0x1220 EventSystem - ok
01:26:57.0849 0x1220 [ 8597822F0E0EAA61A9FFD18778828792 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
01:26:57.0864 0x1220 EvtEng - ok
01:26:57.0942 0x1220 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
01:26:57.0942 0x1220 exfat - ok
01:26:57.0958 0x1220 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
01:26:57.0958 0x1220 fastfat - ok
01:26:57.0989 0x1220 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\windows\system32\fxssvc.exe
01:26:58.0005 0x1220 Fax - ok
01:26:58.0005 0x1220 [ 22EC3B0EA37CDF4355AE627004F3103C ] FBIOSDRV C:\windows\system32\Drivers\FBIOSDRV.sys
01:26:58.0005 0x1220 FBIOSDRV - ok
01:26:58.0036 0x1220 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\drivers\fdc.sys
01:26:58.0036 0x1220 fdc - ok
01:26:58.0067 0x1220 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
01:26:58.0067 0x1220 fdPHost - ok
01:26:58.0067 0x1220 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
01:26:58.0067 0x1220 FDResPub - ok
01:26:58.0083 0x1220 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
01:26:58.0083 0x1220 FileInfo - ok
01:26:58.0114 0x1220 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
01:26:58.0114 0x1220 Filetrace - ok
01:26:58.0145 0x1220 [ 31A2624507524A52A08DB2BBF2DB28EC ] FjDstService C:\Program Files\Fujitsu\DustSolution\FJDService.exe
01:26:58.0161 0x1220 FjDstService - ok
01:26:58.0192 0x1220 [ 1F2918E7FFB62D21FEFBA43B0F943F6B ] FJGSDisk C:\windows\system32\DRIVERS\FJGSDisk.sys
01:26:58.0192 0x1220 FJGSDisk - ok
01:26:58.0208 0x1220 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
01:26:58.0208 0x1220 flpydisk - ok
01:26:58.0223 0x1220 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
01:26:58.0223 0x1220 FltMgr - ok
01:26:58.0270 0x1220 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\windows\system32\FntCache.dll
01:26:58.0286 0x1220 FontCache - ok
01:26:58.0332 0x1220 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
01:26:58.0332 0x1220 FontCache3.0.0.0 - ok
01:26:58.0364 0x1220 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
01:26:58.0364 0x1220 FsDepends - ok
01:26:58.0395 0x1220 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
01:26:58.0395 0x1220 Fs_Rec - ok
01:26:58.0426 0x1220 [ 49E588AC7D2B57F057756A91C6F36D25 ] FUJ02B1 C:\windows\system32\drivers\FUJ02B1.sys
01:26:58.0426 0x1220 FUJ02B1 - ok
01:26:58.0442 0x1220 [ D45474A7E5E2F35150C29A3193747884 ] FUJ02E3 C:\windows\system32\drivers\FUJ02E3.sys
01:26:58.0442 0x1220 FUJ02E3 - ok
01:26:58.0488 0x1220 [ 4732E596BB1C50D9F9188C5074EE7782 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
01:26:58.0488 0x1220 fvevol - ok
01:26:58.0488 0x1220 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
01:26:58.0488 0x1220 gagp30kx - ok
01:26:58.0520 0x1220 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
01:26:58.0535 0x1220 GEARAspiWDM - ok
01:26:58.0551 0x1220 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\windows\System32\gpsvc.dll
01:26:58.0566 0x1220 gpsvc - ok
01:26:58.0613 0x1220 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\windows\system32\DRIVERS\hamachi.sys
01:26:58.0613 0x1220 hamachi - ok
01:26:58.0644 0x1220 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
01:26:58.0644 0x1220 hcw85cir - ok
01:26:58.0676 0x1220 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
01:26:58.0691 0x1220 HdAudAddService - ok
01:26:58.0691 0x1220 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
01:26:58.0707 0x1220 HDAudBus - ok
01:26:58.0738 0x1220 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\windows\system32\drivers\HECI.sys
01:26:58.0738 0x1220 HECI - ok
01:26:58.0769 0x1220 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
01:26:58.0769 0x1220 HidBatt - ok
01:26:58.0800 0x1220 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\drivers\hidbth.sys
01:26:58.0800 0x1220 HidBth - ok
01:26:58.0832 0x1220 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\drivers\hidir.sys
01:26:58.0832 0x1220 HidIr - ok
01:26:58.0863 0x1220 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
01:26:58.0863 0x1220 hidserv - ok
01:26:58.0878 0x1220 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
01:26:58.0878 0x1220 HidUsb - ok
01:26:58.0910 0x1220 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\windows\system32\kmsvc.dll
01:26:58.0910 0x1220 hkmsvc - ok
01:26:58.0941 0x1220 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\windows\system32\ListSvc.dll
01:26:58.0941 0x1220 HomeGroupListener - ok
01:26:58.0956 0x1220 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\windows\system32\provsvc.dll
01:26:58.0972 0x1220 HomeGroupProvider - ok
01:26:58.0988 0x1220 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
01:26:58.0988 0x1220 HpSAMD - ok
01:26:59.0019 0x1220 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\windows\system32\drivers\HTTP.sys
01:26:59.0019 0x1220 HTTP - ok
01:26:59.0050 0x1220 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
01:26:59.0050 0x1220 hwpolicy - ok
01:26:59.0066 0x1220 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
01:26:59.0066 0x1220 i8042prt - ok
01:26:59.0097 0x1220 [ D80AA0907748D7CC8EFAB3773F32629B ] iaStor C:\windows\system32\drivers\iaStor.sys
01:26:59.0097 0x1220 iaStor - ok
01:26:59.0144 0x1220 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
01:26:59.0144 0x1220 iaStorV - ok
01:26:59.0206 0x1220 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
01:26:59.0206 0x1220 idsvc - ok
01:26:59.0393 0x1220 [ 8E9DA2E49347AF49901526DCD4D0F397 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
01:26:59.0440 0x1220 igfx - ok
01:26:59.0471 0x1220 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\drivers\iirsp.sys
01:26:59.0471 0x1220 iirsp - ok
01:26:59.0502 0x1220 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\windows\System32\ikeext.dll
01:26:59.0502 0x1220 IKEEXT - ok
01:26:59.0549 0x1220 [ 91AB587F7EA44B0DEB0522F71AD7B2DC ] ImeDictUpdateService C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
01:26:59.0565 0x1220 ImeDictUpdateService - ok
01:26:59.0580 0x1220 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\windows\system32\drivers\Impcd.sys
01:26:59.0580 0x1220 Impcd - ok
01:26:59.0705 0x1220 [ AEE99ECF06CD1CEA95816CCB5BF73EC8 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
01:26:59.0721 0x1220 IntcAzAudAddService - ok
01:26:59.0768 0x1220 [ BF31740828A26AB451803E3B35432651 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
01:26:59.0768 0x1220 IntcDAud - ok
01:26:59.0783 0x1220 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
01:26:59.0799 0x1220 intelide - ok
01:26:59.0814 0x1220 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\drivers\intelppm.sys
01:26:59.0814 0x1220 intelppm - ok
01:26:59.0830 0x1220 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
01:26:59.0830 0x1220 IPBusEnum - ok
01:26:59.0846 0x1220 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
01:26:59.0846 0x1220 IpFilterDriver - ok
01:26:59.0877 0x1220 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
01:26:59.0877 0x1220 iphlpsvc - ok
01:26:59.0908 0x1220 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
01:26:59.0908 0x1220 IPMIDRV - ok
01:26:59.0924 0x1220 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
01:26:59.0924 0x1220 IPNAT - ok
01:26:59.0970 0x1220 [ D8B8B5A8FE57CF4F307A540D9A153C23 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
01:26:59.0986 0x1220 iPod Service - ok
01:27:00.0002 0x1220 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
01:27:00.0002 0x1220 IRENUM - ok
01:27:00.0048 0x1220 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
01:27:00.0048 0x1220 isapnp - ok
01:27:00.0064 0x1220 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
01:27:00.0064 0x1220 iScsiPrt - ok
01:27:00.0095 0x1220 [ F415A88162D23977B5EDAE4F0410E903 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
01:27:00.0095 0x1220 IviRegMgr - ok
01:27:00.0142 0x1220 [ 703E40B3A128F1FB8C307ADA168CA121 ] k57nd60x C:\windows\system32\DRIVERS\k57nd60x.sys
01:27:00.0142 0x1220 k57nd60x - ok
01:27:00.0189 0x1220 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
01:27:00.0189 0x1220 kbdclass - ok
01:27:00.0204 0x1220 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
01:27:00.0204 0x1220 kbdhid - ok
01:27:00.0220 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\windows\system32\lsass.exe
01:27:00.0220 0x1220 KeyIso - ok
01:27:00.0251 0x1220 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
01:27:00.0267 0x1220 KSecDD - ok
01:27:00.0314 0x1220 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
01:27:00.0314 0x1220 KSecPkg - ok
01:27:00.0360 0x1220 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
01:27:00.0360 0x1220 KtmRm - ok
01:27:00.0407 0x1220 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\windows\system32\srvsvc.dll
01:27:00.0407 0x1220 LanmanServer - ok
01:27:00.0438 0x1220 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\windows\System32\wkssvc.dll
01:27:00.0454 0x1220 LanmanWorkstation - ok
01:27:00.0470 0x1220 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
01:27:00.0470 0x1220 lltdio - ok
01:27:00.0501 0x1220 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
01:27:00.0501 0x1220 lltdsvc - ok
01:27:00.0516 0x1220 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
01:27:00.0532 0x1220 lmhosts - ok
01:27:00.0563 0x1220 [ A1C148801B4AF64847AEB9F3AD9594EF ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
01:27:00.0563 0x1220 LMS - ok
01:27:00.0594 0x1220 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
01:27:00.0594 0x1220 LSI_FC - ok
01:27:00.0610 0x1220 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
01:27:00.0610 0x1220 LSI_SAS - ok
01:27:00.0641 0x1220 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
01:27:00.0657 0x1220 LSI_SAS2 - ok
01:27:00.0672 0x1220 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
01:27:00.0672 0x1220 LSI_SCSI - ok
01:27:00.0704 0x1220 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
01:27:00.0704 0x1220 luafv - ok
01:27:00.0735 0x1220 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
01:27:00.0735 0x1220 Mcx2Svc - ok
01:27:00.0782 0x1220 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\drivers\megasas.sys
01:27:00.0782 0x1220 megasas - ok
01:27:00.0828 0x1220 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
01:27:00.0828 0x1220 MegaSR - ok
01:27:00.0844 0x1220 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
01:27:00.0844 0x1220 MMCSS - ok
01:27:00.0860 0x1220 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
01:27:00.0875 0x1220 Modem - ok
01:27:00.0891 0x1220 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
01:27:00.0891 0x1220 monitor - ok
01:27:00.0906 0x1220 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
01:27:00.0906 0x1220 mouclass - ok
01:27:00.0938 0x1220 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
01:27:00.0938 0x1220 mouhid - ok
01:27:00.0953 0x1220 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
01:27:00.0953 0x1220 mountmgr - ok
01:27:00.0969 0x1220 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\windows\system32\drivers\mpio.sys
01:27:00.0969 0x1220 mpio - ok
01:27:00.0984 0x1220 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
01:27:00.0984 0x1220 mpsdrv - ok
01:27:01.0016 0x1220 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\windows\system32\mpssvc.dll
01:27:01.0031 0x1220 MpsSvc - ok
01:27:01.0047 0x1220 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
01:27:01.0047 0x1220 MRxDAV - ok
01:27:01.0094 0x1220 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
01:27:01.0094 0x1220 mrxsmb - ok
01:27:01.0125 0x1220 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
01:27:01.0125 0x1220 mrxsmb10 - ok
01:27:01.0156 0x1220 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
01:27:01.0156 0x1220 mrxsmb20 - ok
01:27:01.0156 0x1220 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\windows\system32\drivers\msahci.sys
01:27:01.0172 0x1220 msahci - ok
01:27:01.0187 0x1220 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\windows\system32\drivers\msdsm.sys
01:27:01.0187 0x1220 msdsm - ok
01:27:01.0203 0x1220 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
01:27:01.0203 0x1220 MSDTC - ok
01:27:01.0218 0x1220 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
01:27:01.0218 0x1220 Msfs - ok
01:27:01.0234 0x1220 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
01:27:01.0234 0x1220 mshidkmdf - ok
01:27:01.0250 0x1220 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
01:27:01.0250 0x1220 msisadrv - ok
01:27:01.0281 0x1220 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
01:27:01.0281 0x1220 MSiSCSI - ok
01:27:01.0296 0x1220 msiserver - ok
01:27:01.0296 0x1220 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
01:27:01.0296 0x1220 MSKSSRV - ok
01:27:01.0312 0x1220 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
01:27:01.0312 0x1220 MSPCLOCK - ok
01:27:01.0343 0x1220 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
01:27:01.0343 0x1220 MSPQM - ok
01:27:01.0343 0x1220 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
01:27:01.0343 0x1220 MsRPC - ok
01:27:01.0374 0x1220 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
01:27:01.0374 0x1220 mssmbios - ok
01:27:01.0374 0x1220 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
01:27:01.0390 0x1220 MSTEE - ok
01:27:01.0406 0x1220 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
01:27:01.0406 0x1220 MTConfig - ok
01:27:01.0421 0x1220 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
01:27:01.0421 0x1220 Mup - ok
01:27:01.0468 0x1220 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\windows\system32\qagentRT.dll
01:27:01.0468 0x1220 napagent - ok
01:27:01.0530 0x1220 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
01:27:01.0530 0x1220 NativeWifiP - ok
01:27:01.0562 0x1220 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\windows\system32\drivers\ndis.sys
01:27:01.0562 0x1220 NDIS - ok
01:27:01.0593 0x1220 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
01:27:01.0593 0x1220 NdisCap - ok
01:27:01.0624 0x1220 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
01:27:01.0624 0x1220 NdisTapi - ok
01:27:01.0640 0x1220 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
01:27:01.0640 0x1220 Ndisuio - ok
01:27:01.0655 0x1220 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
01:27:01.0671 0x1220 NdisWan - ok
01:27:01.0686 0x1220 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
01:27:01.0686 0x1220 NDProxy - ok
01:27:01.0686 0x1220 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
01:27:01.0702 0x1220 NetBIOS - ok
01:27:01.0718 0x1220 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
01:27:01.0718 0x1220 NetBT - ok
01:27:01.0733 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\windows\system32\lsass.exe
01:27:01.0733 0x1220 Netlogon - ok
01:27:01.0780 0x1220 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
01:27:01.0780 0x1220 Netman - ok
01:27:01.0796 0x1220 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
01:27:01.0796 0x1220 netprofm - ok
01:27:01.0827 0x1220 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
01:27:01.0842 0x1220 NetTcpPortSharing - ok
01:27:01.0998 0x1220 [ 3577B851E59DA59E6D65419A057C9914 ] NETw5s32 C:\windows\system32\DRIVERS\NETw5s32.sys
01:27:02.0045 0x1220 NETw5s32 - ok
01:27:02.0092 0x1220 [ F282FC61839F8A719A3AD569CAB71C9C ] NetworkPlayer Server C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe
01:27:02.0092 0x1220 NetworkPlayer Server - ok
01:27:02.0139 0x1220 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
01:27:02.0139 0x1220 nfrd960 - ok
01:27:02.0170 0x1220 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\windows\System32\nlasvc.dll
01:27:02.0170 0x1220 NlaSvc - ok
01:27:02.0186 0x1220 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
01:27:02.0186 0x1220 Npfs - ok
01:27:02.0186 0x1220 npggsvc - ok
01:27:02.0217 0x1220 [ 3964D26EE70B24B5318146247DD782DF ] npkakl C:\windows\system32\npkakl.sys
01:27:02.0217 0x1220 npkakl - ok
01:27:02.0264 0x1220 [ 83D727642D288A75A10100BEF5CDB756 ] npkcmsvc C:\windows\system32\npkcmsvc.exe
01:27:02.0264 0x1220 npkcmsvc - ok
01:27:02.0279 0x1220 [ 77BEB64EA3E83C37355B6D8EEB14008E ] npkcrypt C:\windows\system32\npkcrypt.sys
01:27:02.0279 0x1220 npkcrypt - ok
01:27:02.0295 0x1220 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
01:27:02.0310 0x1220 nsi - ok
01:27:02.0310 0x1220 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
01:27:02.0310 0x1220 nsiproxy - ok
01:27:02.0388 0x1220 [ A8F59428E9F361C7AC42A94AC1560BC9 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
01:27:02.0404 0x1220 Ntfs - ok
01:27:02.0451 0x1220 [ 588F2E8ACF3BDCE4496295806D21ECAF ] ntk3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\ntk3.sys
01:27:02.0451 0x1220 ntk3 - ok
01:27:02.0466 0x1220 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
01:27:02.0466 0x1220 Null - ok
01:27:02.0482 0x1220 [ EE0CB811A0F03038C2BC64538AA780F8 ] nusb3hub C:\windows\system32\drivers\nusb3hub.sys
01:27:02.0482 0x1220 nusb3hub - ok
01:27:02.0513 0x1220 [ 7CAA9F5D8602B236A92B17EDC87549F9 ] nusb3xhc C:\windows\system32\drivers\nusb3xhc.sys
01:27:02.0513 0x1220 nusb3xhc - ok
01:27:02.0560 0x1220 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\windows\system32\drivers\nvraid.sys
01:27:02.0560 0x1220 nvraid - ok
01:27:02.0607 0x1220 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\windows\system32\drivers\nvstor.sys
01:27:02.0607 0x1220 nvstor - ok
01:27:02.0622 0x1220 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
01:27:02.0638 0x1220 nv_agp - ok
01:27:02.0669 0x1220 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
01:27:02.0669 0x1220 ohci1394 - ok
01:27:02.0732 0x1220 [ 84113AB3A3EEF32FBEBF3339D8C19100 ] omniserv C:\Program Files\Softex\OmniPass\OmniServ.exe
01:27:02.0732 0x1220 omniserv - ok
01:27:02.0763 0x1220 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
01:27:02.0763 0x1220 ose - ok
01:27:02.0934 0x1220 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
01:27:02.0966 0x1220 osppsvc - ok
01:27:03.0012 0x1220 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
01:27:03.0012 0x1220 p2pimsvc - ok
01:27:03.0044 0x1220 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
01:27:03.0059 0x1220 p2psvc - ok
01:27:03.0168 0x1220 [ CB1257208C7105192F397187C14162E9 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
01:27:03.0168 0x1220 PACSPTISVR - ok
01:27:03.0200 0x1220 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\drivers\parport.sys
01:27:03.0200 0x1220 Parport - ok
01:27:03.0231 0x1220 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\windows\system32\drivers\partmgr.sys
01:27:03.0231 0x1220 partmgr - ok
01:27:03.0262 0x1220 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\drivers\parvdm.sys
01:27:03.0262 0x1220 Parvdm - ok
01:27:03.0293 0x1220 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
01:27:03.0293 0x1220 PcaSvc - ok
01:27:03.0324 0x1220 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\windows\system32\drivers\pci.sys
01:27:03.0324 0x1220 pci - ok
01:27:03.0356 0x1220 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
01:27:03.0356 0x1220 pciide - ok
01:27:03.0371 0x1220 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
01:27:03.0387 0x1220 pcmcia - ok
01:27:03.0402 0x1220 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
01:27:03.0418 0x1220 pcw - ok
01:27:03.0449 0x1220 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
01:27:03.0449 0x1220 PEAUTH - ok
01:27:03.0527 0x1220 [ F3B3F0BBC15C668EF87FD6C265994481 ] PFNService C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
01:27:03.0543 0x1220 PFNService - ok
01:27:03.0590 0x1220 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\windows\system32\pla.dll
01:27:03.0605 0x1220 pla - ok
01:27:03.0652 0x1220 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\windows\system32\umpnpmgr.dll
01:27:03.0652 0x1220 PlugPlay - ok
01:27:03.0668 0x1220 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
01:27:03.0683 0x1220 PNRPAutoReg - ok
01:27:03.0683 0x1220 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
01:27:03.0699 0x1220 PNRPsvc - ok
01:27:03.0730 0x1220 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
01:27:03.0730 0x1220 PolicyAgent - ok
01:27:03.0761 0x1220 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\windows\system32\umpo.dll
01:27:03.0777 0x1220 Power - ok
01:27:03.0808 0x1220 [ AEA6984F3DD10A76552480D46CF17EBD ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe
01:27:03.0808 0x1220 PowerSavingUtilityService - ok
01:27:03.0824 0x1220 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
01:27:03.0824 0x1220 PptpMiniport - ok
01:27:03.0839 0x1220 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\drivers\processr.sys
01:27:03.0839 0x1220 Processor - ok
01:27:03.0886 0x1220 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\windows\system32\profsvc.dll
01:27:03.0886 0x1220 ProfSvc - ok
01:27:03.0902 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\windows\system32\lsass.exe
01:27:03.0902 0x1220 ProtectedStorage - ok
01:27:03.0933 0x1220 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
01:27:03.0933 0x1220 Psched - ok
01:27:03.0964 0x1220 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
01:27:03.0964 0x1220 PSI_SVC_2 - ok
01:27:04.0026 0x1220 [ 786DBE9D3A96481F21E8CF59CFA049A6 ] PUSCSRVC C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
01:27:04.0026 0x1220 PUSCSRVC - ok
01:27:04.0058 0x1220 [ B6A1692FC131F1FE5162513D78A9B6FC ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
01:27:04.0058 0x1220 PxHelp20 - ok
01:27:04.0120 0x1220 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\drivers\ql2300.sys
01:27:04.0151 0x1220 ql2300 - ok
01:27:04.0182 0x1220 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
01:27:04.0182 0x1220 ql40xx - ok
01:27:04.0229 0x1220 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
01:27:04.0229 0x1220 QWAVE - ok
01:27:04.0245 0x1220 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
01:27:04.0260 0x1220 QWAVEdrv - ok
01:27:04.0260 0x1220 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
01:27:04.0260 0x1220 RasAcd - ok
01:27:04.0292 0x1220 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
01:27:04.0292 0x1220 RasAgileVpn - ok
01:27:04.0323 0x1220 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
01:27:04.0323 0x1220 RasAuto - ok
01:27:04.0354 0x1220 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
01:27:04.0354 0x1220 Rasl2tp - ok
01:27:04.0385 0x1220 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\windows\System32\rasmans.dll
01:27:04.0385 0x1220 RasMan - ok
01:27:04.0401 0x1220 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
01:27:04.0401 0x1220 RasPppoe - ok
01:27:04.0416 0x1220 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
01:27:04.0416 0x1220 RasSstp - ok
01:27:04.0448 0x1220 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
01:27:04.0448 0x1220 rdbss - ok
01:27:04.0494 0x1220 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\drivers\rdpbus.sys
01:27:04.0494 0x1220 rdpbus - ok
  • 宵子
  • 2013/08/21 (Wed) 01:43:43
TDSSKiller2回目その3
最後です。

01:27:04.0510 0x1220 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
01:27:04.0510 0x1220 RDPCDD - ok
01:27:04.0526 0x1220 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
01:27:04.0526 0x1220 RDPENCDD - ok
01:27:04.0541 0x1220 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
01:27:04.0541 0x1220 RDPREFMP - ok
01:27:04.0588 0x1220 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
01:27:04.0588 0x1220 RDPWD - ok
01:27:04.0635 0x1220 [ 65DB288F7372B1F632891FC32BF908B7 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
01:27:04.0635 0x1220 rdyboost - ok
01:27:04.0713 0x1220 [ B2D01290C0E0465ACA54C2088E947823 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
01:27:04.0713 0x1220 RealNetworks Downloader Resolver Service - ok
01:27:04.0728 0x1220 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\windows\system32\drivers\regi.sys
01:27:04.0728 0x1220 regi - ok
01:27:04.0806 0x1220 [ 7AFCBE32616E08D45E4EAADB0A1DD5CF ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
01:27:04.0822 0x1220 RegSrvc - ok
01:27:04.0838 0x1220 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
01:27:04.0853 0x1220 RemoteAccess - ok
01:27:04.0869 0x1220 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
01:27:04.0869 0x1220 RemoteRegistry - ok
01:27:04.0884 0x1220 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
01:27:04.0884 0x1220 RpcEptMapper - ok
01:27:04.0916 0x1220 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
01:27:04.0916 0x1220 RpcLocator - ok
01:27:04.0947 0x1220 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\windows\system32\rpcss.dll
01:27:04.0947 0x1220 RpcSs - ok
01:27:04.0978 0x1220 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
01:27:04.0978 0x1220 rspndr - ok
01:27:04.0994 0x1220 [ 11CC47F1CC7A66BBC6766F6037C5A678 ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
01:27:04.0994 0x1220 RSUSBSTOR - ok
01:27:05.0009 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\windows\system32\lsass.exe
01:27:05.0025 0x1220 SamSs - ok
01:27:05.0040 0x1220 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
01:27:05.0040 0x1220 sbp2port - ok
01:27:05.0056 0x1220 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
01:27:05.0056 0x1220 SCardSvr - ok
01:27:05.0072 0x1220 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
01:27:05.0072 0x1220 scfilter - ok
01:27:05.0118 0x1220 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\windows\system32\schedsvc.dll
01:27:05.0134 0x1220 Schedule - ok
01:27:05.0165 0x1220 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\windows\System32\certprop.dll
01:27:05.0165 0x1220 SCPolicySvc - ok
01:27:05.0165 0x1220 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\windows\System32\SDRSVC.dll
01:27:05.0181 0x1220 SDRSVC - ok
01:27:05.0196 0x1220 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
01:27:05.0196 0x1220 secdrv - ok
01:27:05.0212 0x1220 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
01:27:05.0228 0x1220 seclogon - ok
01:27:05.0228 0x1220 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
01:27:05.0228 0x1220 SENS - ok
01:27:05.0259 0x1220 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
01:27:05.0259 0x1220 SensrSvc - ok
01:27:05.0290 0x1220 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\drivers\serenum.sys
01:27:05.0290 0x1220 Serenum - ok
01:27:05.0306 0x1220 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\drivers\serial.sys
01:27:05.0306 0x1220 Serial - ok
01:27:05.0321 0x1220 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\drivers\sermouse.sys
01:27:05.0321 0x1220 sermouse - ok
01:27:05.0337 0x1220 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\windows\system32\sessenv.dll
01:27:05.0352 0x1220 SessionEnv - ok
01:27:05.0352 0x1220 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
01:27:05.0352 0x1220 sffdisk - ok
01:27:05.0368 0x1220 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
01:27:05.0368 0x1220 sffp_mmc - ok
01:27:05.0368 0x1220 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
01:27:05.0368 0x1220 sffp_sd - ok
01:27:05.0399 0x1220 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
01:27:05.0399 0x1220 sfloppy - ok
01:27:05.0430 0x1220 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
01:27:05.0446 0x1220 SharedAccess - ok
01:27:05.0462 0x1220 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\windows\System32\shsvcs.dll
01:27:05.0462 0x1220 ShellHWDetection - ok
01:27:05.0493 0x1220 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
01:27:05.0493 0x1220 sisagp - ok
01:27:05.0508 0x1220 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
01:27:05.0508 0x1220 SiSRaid2 - ok
01:27:05.0555 0x1220 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
01:27:05.0555 0x1220 SiSRaid4 - ok
01:27:05.0602 0x1220 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
01:27:05.0618 0x1220 SkypeUpdate - ok
01:27:05.0633 0x1220 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
01:27:05.0633 0x1220 Smb - ok
01:27:05.0696 0x1220 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
01:27:05.0696 0x1220 SNMPTRAP - ok
01:27:05.0852 0x1220 [ A7D1229E1326D02CF80F952617C5A39B ] SNP2UVC C:\windows\system32\DRIVERS\snp2uvc.sys
01:27:05.0867 0x1220 SNP2UVC - ok
01:27:05.0930 0x1220 [ 6AE4902A4A819A7A1545D23972D70C55 ] SonicStage Back-End Service2 C:\Program Files\Common Files\Sony Shared\AVLib\SsBeService2.exe
01:27:05.0930 0x1220 SonicStage Back-End Service2 - ok
01:27:05.0961 0x1220 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
01:27:05.0961 0x1220 spldr - ok
01:27:06.0008 0x1220 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\windows\System32\spoolsv.exe
01:27:06.0023 0x1220 Spooler - ok
01:27:06.0132 0x1220 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\windows\system32\sppsvc.exe
01:27:06.0148 0x1220 sppsvc - ok
01:27:06.0179 0x1220 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\windows\system32\sppuinotify.dll
01:27:06.0179 0x1220 sppuinotify - ok
01:27:06.0210 0x1220 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\windows\system32\DRIVERS\srv.sys
01:27:06.0210 0x1220 srv - ok
01:27:06.0242 0x1220 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
01:27:06.0242 0x1220 srv2 - ok
01:27:06.0288 0x1220 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
01:27:06.0288 0x1220 srvnet - ok
01:27:06.0320 0x1220 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
01:27:06.0320 0x1220 SSDPSRV - ok
01:27:06.0335 0x1220 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
01:27:06.0335 0x1220 SstpSvc - ok
01:27:06.0366 0x1220 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\drivers\stexstor.sys
01:27:06.0366 0x1220 stexstor - ok
01:27:06.0398 0x1220 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\windows\System32\wiaservc.dll
01:27:06.0413 0x1220 StiSvc - ok
01:27:06.0429 0x1220 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
01:27:06.0429 0x1220 swenum - ok
01:27:06.0460 0x1220 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
01:27:06.0476 0x1220 swprv - ok
01:27:06.0522 0x1220 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\windows\system32\sysmain.dll
01:27:06.0538 0x1220 SysMain - ok
01:27:06.0554 0x1220 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\windows\System32\TabSvc.dll
01:27:06.0554 0x1220 TabletInputService - ok
01:27:06.0585 0x1220 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\windows\System32\tapisrv.dll
01:27:06.0585 0x1220 TapiSrv - ok
01:27:06.0600 0x1220 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
01:27:06.0616 0x1220 TBS - ok
01:27:06.0663 0x1220 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] Tcpip C:\windows\system32\drivers\tcpip.sys
01:27:06.0678 0x1220 Tcpip - ok
01:27:06.0725 0x1220 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
01:27:06.0725 0x1220 TCPIP6 - ok
01:27:06.0741 0x1220 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
01:27:06.0741 0x1220 tcpipreg - ok
01:27:06.0772 0x1220 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
01:27:06.0772 0x1220 TDPIPE - ok
01:27:06.0803 0x1220 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
01:27:06.0803 0x1220 TDTCP - ok
01:27:06.0819 0x1220 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\windows\system32\DRIVERS\tdx.sys
01:27:06.0819 0x1220 tdx - ok
01:27:06.0850 0x1220 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\windows\system32\drivers\termdd.sys
01:27:06.0850 0x1220 TermDD - ok
01:27:06.0881 0x1220 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\windows\System32\termsrv.dll
01:27:06.0881 0x1220 TermService - ok
01:27:06.0897 0x1220 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
01:27:06.0912 0x1220 Themes - ok
01:27:06.0928 0x1220 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
01:27:06.0928 0x1220 THREADORDER - ok
01:27:06.0975 0x1220 [ 883B3052721452E8667F5597AD2C5379 ] tmactmon C:\windows\system32\DRIVERS\tmactmon.sys
01:27:06.0975 0x1220 tmactmon - ok
01:27:07.0022 0x1220 [ F33C3F08536F988AAC84D72D83B139A6 ] tmcomm C:\windows\system32\DRIVERS\tmcomm.sys
01:27:07.0037 0x1220 tmcomm - ok
01:27:07.0068 0x1220 [ A17D672CBE700272DA499AA3ED60D3CC ] tmeevw C:\windows\system32\DRIVERS\tmeevw.sys
01:27:07.0068 0x1220 tmeevw - ok
01:27:07.0084 0x1220 [ 8FE7172FF137249BEA4EBC750EF90093 ] tmevtmgr C:\windows\system32\DRIVERS\tmevtmgr.sys
01:27:07.0100 0x1220 tmevtmgr - ok
01:27:07.0146 0x1220 [ 0C40396F071A8092964C8DC951F62B17 ] tmnciesc C:\windows\system32\DRIVERS\tmnciesc.sys
01:27:07.0146 0x1220 tmnciesc - ok
01:27:07.0162 0x1220 [ 43C1B7C778B296D492AF6D2ABB2ECF7F ] tmtdi C:\windows\system32\DRIVERS\tmtdi.sys
01:27:07.0162 0x1220 tmtdi - ok
01:27:07.0193 0x1220 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
01:27:07.0193 0x1220 TrkWks - ok
01:27:07.0224 0x1220 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
01:27:07.0224 0x1220 TrustedInstaller - ok
01:27:07.0240 0x1220 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
01:27:07.0240 0x1220 tssecsrv - ok
01:27:07.0271 0x1220 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
01:27:07.0271 0x1220 tunnel - ok
01:27:07.0287 0x1220 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\drivers\uagp35.sys
01:27:07.0287 0x1220 uagp35 - ok
01:27:07.0349 0x1220 [ F7DF6654663AD07DAB615A7AF513D90C ] UCManSvc C:\Program Files\SoftDenchi\UCManSvc.exe
01:27:07.0365 0x1220 UCManSvc - ok
01:27:07.0396 0x1220 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\windows\system32\DRIVERS\udfs.sys
01:27:07.0396 0x1220 udfs - ok
01:27:07.0474 0x1220 [ 27B37460477592A4C591F83675A096F9 ] UDSS c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe
01:27:07.0474 0x1220 UDSS - ok
01:27:07.0505 0x1220 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
01:27:07.0521 0x1220 UI0Detect - ok
01:27:07.0552 0x1220 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
01:27:07.0552 0x1220 uliagpkx - ok
01:27:07.0583 0x1220 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\windows\system32\DRIVERS\umbus.sys
01:27:07.0583 0x1220 umbus - ok
01:27:07.0614 0x1220 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\drivers\umpass.sys
01:27:07.0614 0x1220 UmPass - ok
01:27:07.0708 0x1220 [ 41118D920B2B268C0ADC36421248CDCF ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
01:27:07.0739 0x1220 UNS - ok
01:27:07.0786 0x1220 [ C11D90101CB125AFC47525066EFF4AE9 ] UpdateNaviInstallService C:\Program Files\Fujitsu\chitose\updnvsrv.exe
01:27:07.0786 0x1220 UpdateNaviInstallService - ok
01:27:07.0802 0x1220 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
01:27:07.0817 0x1220 upnphost - ok
01:27:07.0848 0x1220 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\windows\system32\Drivers\usbaapl.sys
01:27:07.0848 0x1220 USBAAPL - ok
01:27:07.0895 0x1220 [ 5C233AEFB566EE78C1EFBC0493FB066A ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
01:27:07.0895 0x1220 usbccgp - ok
01:27:07.0942 0x1220 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\windows\system32\drivers\usbcir.sys
01:27:07.0942 0x1220 usbcir - ok
01:27:07.0973 0x1220 [ 5B71019A6ACA0116FD21B368F19C0B91 ] usbehci C:\windows\system32\drivers\usbehci.sys
01:27:07.0973 0x1220 usbehci - ok
01:27:08.0020 0x1220 [ 5823D3965C2A4F6F785ED1A3B403F3B8 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
01:27:08.0020 0x1220 usbhub - ok
01:27:08.0067 0x1220 [ E753ED6C49DA13967EBABF9EA616454A ] usbohci C:\windows\system32\drivers\usbohci.sys
01:27:08.0067 0x1220 usbohci - ok
01:27:08.0098 0x1220 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
01:27:08.0098 0x1220 usbprint - ok
01:27:08.0129 0x1220 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\windows\system32\DRIVERS\usbscan.sys
01:27:08.0129 0x1220 usbscan - ok
01:27:08.0176 0x1220 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
01:27:08.0176 0x1220 USBSTOR - ok
01:27:08.0223 0x1220 [ 6A30928A469CE802600E1EA8C0F2F53F ] usbuhci C:\windows\system32\drivers\usbuhci.sys
01:27:08.0223 0x1220 usbuhci - ok
01:27:08.0254 0x1220 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
01:27:08.0254 0x1220 usbvideo - ok
01:27:08.0285 0x1220 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
01:27:08.0285 0x1220 UxSms - ok
01:27:08.0301 0x1220 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\windows\system32\lsass.exe
01:27:08.0301 0x1220 VaultSvc - ok
01:27:08.0348 0x1220 [ B2ABAB4CA46BAD182E27763DC19C780F ] VCSVADHWSer C:\windows\system32\DRIVERS\vcsvad.sys
01:27:08.0348 0x1220 VCSVADHWSer - ok
01:27:08.0363 0x1220 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
01:27:08.0363 0x1220 vdrvroot - ok
01:27:08.0394 0x1220 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\windows\System32\vds.exe
01:27:08.0410 0x1220 vds - ok
01:27:08.0441 0x1220 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
01:27:08.0441 0x1220 vga - ok
01:27:08.0472 0x1220 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
01:27:08.0472 0x1220 VgaSave - ok
01:27:08.0488 0x1220 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
01:27:08.0488 0x1220 vhdmp - ok
01:27:08.0519 0x1220 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
01:27:08.0519 0x1220 viaagp - ok
01:27:08.0535 0x1220 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\drivers\viac7.sys
01:27:08.0550 0x1220 ViaC7 - ok
01:27:08.0566 0x1220 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
01:27:08.0566 0x1220 viaide - ok
01:27:08.0582 0x1220 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\windows\system32\drivers\volmgr.sys
01:27:08.0582 0x1220 volmgr - ok
01:27:08.0613 0x1220 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
01:27:08.0613 0x1220 volmgrx - ok
01:27:08.0644 0x1220 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\windows\system32\drivers\volsnap.sys
01:27:08.0644 0x1220 volsnap - ok
01:27:08.0675 0x1220 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
01:27:08.0675 0x1220 vsmraid - ok
01:27:08.0706 0x1220 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\windows\system32\vssvc.exe
01:27:08.0722 0x1220 VSS - ok
01:27:08.0722 0x1220 vtany - ok
01:27:08.0769 0x1220 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
01:27:08.0769 0x1220 vwifibus - ok
01:27:08.0769 0x1220 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
01:27:08.0769 0x1220 vwififlt - ok
01:27:08.0784 0x1220 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
01:27:08.0784 0x1220 vwifimp - ok
01:27:08.0800 0x1220 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
01:27:08.0800 0x1220 W32Time - ok
01:27:08.0816 0x1220 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\drivers\wacompen.sys
01:27:08.0816 0x1220 WacomPen - ok
01:27:08.0831 0x1220 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
01:27:08.0831 0x1220 WANARP - ok
01:27:08.0847 0x1220 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
01:27:08.0847 0x1220 Wanarpv6 - ok
01:27:08.0909 0x1220 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
01:27:08.0925 0x1220 WatAdminSvc - ok
01:27:08.0972 0x1220 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\windows\system32\wbengine.exe
01:27:08.0972 0x1220 wbengine - ok
01:27:08.0972 0x1220 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
01:27:08.0987 0x1220 WbioSrvc - ok
01:27:09.0018 0x1220 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\windows\System32\wcncsvc.dll
01:27:09.0034 0x1220 wcncsvc - ok
01:27:09.0050 0x1220 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
01:27:09.0065 0x1220 WcsPlugInService - ok
01:27:09.0081 0x1220 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\drivers\wd.sys
01:27:09.0081 0x1220 Wd - ok
01:27:09.0128 0x1220 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
01:27:09.0143 0x1220 Wdf01000 - ok
01:27:09.0159 0x1220 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
01:27:09.0174 0x1220 WdiServiceHost - ok
01:27:09.0174 0x1220 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
01:27:09.0190 0x1220 WdiSystemHost - ok
01:27:09.0221 0x1220 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\windows\System32\webclnt.dll
01:27:09.0237 0x1220 WebClient - ok
01:27:09.0252 0x1220 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
01:27:09.0268 0x1220 Wecsvc - ok
01:27:09.0284 0x1220 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
01:27:09.0284 0x1220 wercplsupport - ok
01:27:09.0299 0x1220 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
01:27:09.0315 0x1220 WerSvc - ok
01:27:09.0315 0x1220 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
01:27:09.0315 0x1220 WfpLwf - ok
01:27:09.0377 0x1220 [ FB23FA0F51001C43306BBD784F68240F ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
01:27:09.0393 0x1220 WiMAXAppSrv - ok
01:27:09.0408 0x1220 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
01:27:09.0408 0x1220 WIMMount - ok
01:27:09.0486 0x1220 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
01:27:09.0486 0x1220 WinDefend - ok
01:27:09.0502 0x1220 WinHttpAutoProxySvc - ok
01:27:09.0549 0x1220 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
01:27:09.0549 0x1220 Winmgmt - ok
01:27:09.0596 0x1220 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\windows\system32\WsmSvc.dll
01:27:09.0611 0x1220 WinRM - ok
01:27:09.0674 0x1220 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
01:27:09.0689 0x1220 WinUsb - ok
01:27:09.0720 0x1220 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
01:27:09.0736 0x1220 Wlansvc - ok
01:27:09.0845 0x1220 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
01:27:09.0876 0x1220 wlidsvc - ok
01:27:09.0908 0x1220 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
01:27:09.0908 0x1220 WmiAcpi - ok
01:27:09.0923 0x1220 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
01:27:09.0923 0x1220 wmiApSrv - ok
01:27:09.0970 0x1220 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
01:27:09.0986 0x1220 WMPNetworkSvc - ok
01:27:10.0001 0x1220 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\windows\System32\wpcsvc.dll
01:27:10.0001 0x1220 WPCSvc - ok
01:27:10.0017 0x1220 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
01:27:10.0017 0x1220 WPDBusEnum - ok
01:27:10.0032 0x1220 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
01:27:10.0032 0x1220 ws2ifsl - ok
01:27:10.0064 0x1220 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\windows\System32\wscsvc.dll
01:27:10.0079 0x1220 wscsvc - ok
01:27:10.0079 0x1220 WSearch - ok
01:27:10.0173 0x1220 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
01:27:10.0188 0x1220 wuauserv - ok
01:27:10.0220 0x1220 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
01:27:10.0220 0x1220 WudfPf - ok
01:27:10.0251 0x1220 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
01:27:10.0251 0x1220 WUDFRd - ok
01:27:10.0266 0x1220 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\windows\System32\WUDFSvc.dll
01:27:10.0282 0x1220 wudfsvc - ok
01:27:10.0298 0x1220 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\windows\System32\wwansvc.dll
01:27:10.0298 0x1220 WwanSvc - ok
01:27:10.0298 0x1220 xhunter1 - ok
01:27:10.0360 0x1220 [ 4CA7D86C6B1BDDE03C0088A1FBAE9D3F ] xsherlock C:\windows\xsherlock.xem
01:27:10.0360 0x1220 xsherlock - ok
01:27:10.0407 0x1220 [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7 C:\windows\system32\DRIVERS\yk62x86.sys
01:27:10.0407 0x1220 yukonw7 - ok
01:27:10.0438 0x1220 ================ Scan global ===============================
01:27:10.0454 0x1220 [ 9A595DF601070DA78C40481120DD2C06 ] C:\windows\system32\basesrv.dll
01:27:10.0500 0x1220 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:27:10.0500 0x1220 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:27:10.0532 0x1220 [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
01:27:10.0547 0x1220 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
01:27:10.0547 0x1220 [Global] - ok
01:27:10.0547 0x1220 ================ Scan MBR ==================================
01:27:10.0578 0x1220 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
01:27:11.0046 0x1220 \Device\Harddisk0\DR0 - ok
01:27:11.0046 0x1220 ================ Scan VBR ==================================
01:27:11.0046 0x1220 [ 858CC5A24FD61FFA558376040673AEE4 ] \Device\Harddisk0\DR0\Partition1
01:27:11.0046 0x1220 \Device\Harddisk0\DR0\Partition1 - ok
01:27:11.0093 0x1220 [ B3B375D5F0E2AF118828E4624AD1527B ] \Device\Harddisk0\DR0\Partition2
01:27:11.0093 0x1220 \Device\Harddisk0\DR0\Partition2 - ok
01:27:11.0109 0x1220 [ 7756FDF06E6D9BE0977D4C949641D1C6 ] \Device\Harddisk0\DR0\Partition3
01:27:11.0124 0x1220 \Device\Harddisk0\DR0\Partition3 - ok
01:27:11.0124 0x1220 ============================================================
01:27:11.0124 0x1220 Scan finished
01:27:11.0124 0x1220 ============================================================
01:27:11.0124 0x0c60 Detected object count: 0
01:27:11.0124 0x0c60 Actual detected object count: 0
01:27:15.0040 0x1640 ============================================================
01:27:15.0040 0x1640 Scan started
01:27:15.0040 0x1640 Mode: Manual; TDLFS;
01:27:15.0040 0x1640 ============================================================
01:27:15.0149 0x1640 ================ Scan system memory ========================
01:27:15.0149 0x1640 System memory - ok
01:27:15.0149 0x1640 ================ Scan services =============================
01:27:15.0352 0x1640 [ D61B60F7C690ADE5BE74755A1D6DECC2 ] 13653783 C:\windows\system32\drivers\83179577.sys
01:27:15.0399 0x1640 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
01:27:15.0399 0x1640 1394ohci - ok
01:27:15.0446 0x1640 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\windows\system32\drivers\ACPI.sys
01:27:15.0446 0x1640 ACPI - ok
01:27:15.0492 0x1640 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
01:27:15.0492 0x1640 AcpiPmi - ok
01:27:15.0602 0x1640 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
01:27:15.0602 0x1640 AdobeARMservice - ok
01:27:15.0664 0x1640 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
01:27:15.0680 0x1640 AdobeFlashPlayerUpdateSvc - ok
01:27:15.0726 0x1640 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\drivers\adp94xx.sys
01:27:15.0726 0x1640 adp94xx - ok
01:27:15.0773 0x1640 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\drivers\adpahci.sys
01:27:15.0773 0x1640 adpahci - ok
01:27:15.0820 0x1640 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\drivers\adpu320.sys
01:27:15.0820 0x1640 adpu320 - ok
01:27:15.0851 0x1640 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
01:27:15.0851 0x1640 AeLookupSvc - ok
01:27:15.0898 0x1640 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\windows\system32\drivers\afd.sys
01:27:15.0898 0x1640 AFD - ok
01:27:15.0945 0x1640 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
01:27:15.0945 0x1640 agp440 - ok
01:27:15.0976 0x1640 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\drivers\djsvs.sys
01:27:15.0976 0x1640 aic78xx - ok
01:27:16.0023 0x1640 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
01:27:16.0023 0x1640 ALG - ok
01:27:16.0023 0x1640 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
01:27:16.0023 0x1640 aliide - ok
01:27:16.0054 0x1640 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
01:27:16.0054 0x1640 amdagp - ok
01:27:16.0085 0x1640 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
01:27:16.0085 0x1640 amdide - ok
01:27:16.0101 0x1640 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
01:27:16.0101 0x1640 AmdK8 - ok
01:27:16.0116 0x1640 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
01:27:16.0116 0x1640 AmdPPM - ok
01:27:16.0163 0x1640 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\windows\system32\drivers\amdsata.sys
01:27:16.0163 0x1640 amdsata - ok
01:27:16.0194 0x1640 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\drivers\amdsbs.sys
01:27:16.0210 0x1640 amdsbs - ok
01:27:16.0257 0x1640 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\windows\system32\drivers\amdxata.sys
01:27:16.0257 0x1640 amdxata - ok
01:27:16.0397 0x1640 [ F52603B708438E39FF38475807A01CBC ] Amsp C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
01:27:16.0397 0x1640 Amsp - ok
01:27:16.0428 0x1640 [ 7B4BEB577C5D0171F9B66F390EC29284 ] apf001 C:\windows\system32\apf001.sys
01:27:16.0444 0x1640 apf001 - ok
01:27:16.0553 0x1640 [ 98F481241BA8BBA38AA565BD3BF678F9 ] appdrv01 C:\windows\system32\Drivers\appdrv01.sys
01:27:16.0569 0x1640 appdrv01 - ok
01:27:16.0569 0x1640 appdrvrem01 - ok
01:27:16.0600 0x1640 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\windows\system32\drivers\appid.sys
01:27:16.0600 0x1640 AppID - ok
01:27:16.0647 0x1640 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
01:27:16.0647 0x1640 AppIDSvc - ok
01:27:16.0647 0x1640 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\windows\System32\appinfo.dll
01:27:16.0662 0x1640 Appinfo - ok
01:27:16.0787 0x1640 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
01:27:16.0787 0x1640 Apple Mobile Device - ok
01:27:16.0818 0x1640 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\drivers\arc.sys
01:27:16.0818 0x1640 arc - ok
01:27:16.0818 0x1640 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\drivers\arcsas.sys
01:27:16.0834 0x1640 arcsas - ok
01:27:16.0834 0x1640 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
01:27:16.0834 0x1640 AsyncMac - ok
01:27:16.0865 0x1640 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
01:27:16.0865 0x1640 atapi - ok
01:27:16.0959 0x1640 [ 457117113973C615046836889AA2E1E3 ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
01:27:16.0974 0x1640 ATService - ok
01:27:17.0006 0x1640 [ 51D379DB1C53C2A55FDF9372E748E5C7 ] ATSwpWDF C:\windows\system32\Drivers\ATSwpWDF.sys
01:27:17.0006 0x1640 ATSwpWDF - ok
01:27:17.0084 0x1640 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
01:27:17.0084 0x1640 AudioEndpointBuilder - ok
01:27:17.0115 0x1640 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\windows\System32\Audiosrv.dll
01:27:17.0130 0x1640 Audiosrv - ok
01:27:17.0146 0x1640 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\windows\System32\AxInstSV.dll
01:27:17.0146 0x1640 AxInstSV - ok
01:27:17.0193 0x1640 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
01:27:17.0193 0x1640 b06bdrv - ok
01:27:17.0208 0x1640 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
01:27:17.0224 0x1640 b57nd60x - ok
01:27:17.0240 0x1640 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
01:27:17.0240 0x1640 BDESVC - ok
01:27:17.0255 0x1640 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
01:27:17.0255 0x1640 Beep - ok
01:27:17.0286 0x1640 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\windows\System32\bfe.dll
01:27:17.0286 0x1640 BFE - ok
01:27:17.0318 0x1640 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\windows\System32\qmgr.dll
01:27:17.0318 0x1640 BITS - ok
01:27:17.0349 0x1640 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\drivers\blbdrive.sys
01:27:17.0349 0x1640 blbdrive - ok
01:27:17.0396 0x1640 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
01:27:17.0396 0x1640 Bonjour Service - ok
01:27:17.0442 0x1640 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\windows\system32\DRIVERS\bowser.sys
01:27:17.0442 0x1640 bowser - ok
01:27:17.0489 0x1640 [ F30A1AEF42106AF072547377E0CE0C7E ] bpenum C:\windows\system32\DRIVERS\bpenum.sys
01:27:17.0489 0x1640 bpenum - ok
01:27:17.0520 0x1640 [ DE04B62A29F10FD0AFC1990D107DD841 ] bpmp C:\windows\system32\DRIVERS\bpmp.sys
01:27:17.0520 0x1640 bpmp - ok
01:27:17.0552 0x1640 [ A10647B31715023E4988D65851E9B487 ] bpusb C:\windows\system32\Drivers\bpusb.sys
01:27:17.0552 0x1640 bpusb - ok
01:27:17.0567 0x1640 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
01:27:17.0567 0x1640 BrFiltLo - ok
01:27:17.0614 0x1640 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
01:27:17.0614 0x1640 BrFiltUp - ok
01:27:17.0692 0x1640 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\windows\System32\browser.dll
01:27:17.0692 0x1640 Browser - ok
01:27:17.0723 0x1640 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
01:27:17.0723 0x1640 Brserid - ok
01:27:17.0739 0x1640 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
01:27:17.0739 0x1640 BrSerWdm - ok
01:27:17.0786 0x1640 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
01:27:17.0786 0x1640 BrUsbMdm - ok
01:27:17.0817 0x1640 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
01:27:17.0817 0x1640 BrUsbSer - ok
01:27:17.0832 0x1640 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
01:27:17.0832 0x1640 BTHMODEM - ok
01:27:17.0864 0x1640 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
01:27:17.0864 0x1640 bthserv - ok
01:27:17.0895 0x1640 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
01:27:17.0895 0x1640 cdfs - ok
01:27:17.0926 0x1640 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
01:27:17.0926 0x1640 cdrom - ok
01:27:17.0942 0x1640 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\windows\System32\certprop.dll
01:27:17.0942 0x1640 CertPropSvc - ok
01:27:17.0957 0x1640 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\drivers\circlass.sys
01:27:17.0957 0x1640 circlass - ok
01:27:17.0973 0x1640 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
01:27:17.0973 0x1640 CLFS - ok
01:27:18.0051 0x1640 [ DEB7F963F49F329EC0AA31E3F3DC9A59 ] CLHNService3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\CLHNService.exe
01:27:18.0051 0x1640 CLHNService3 - ok
01:27:18.0144 0x1640 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
01:27:18.0144 0x1640 clr_optimization_v2.0.50727_32 - ok
01:27:18.0191 0x1640 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
01:27:18.0207 0x1640 clr_optimization_v4.0.30319_32 - ok
01:27:18.0238 0x1640 [ DB4643A1F4D12825EBD7F675D1AF8C8F ] clwvd C:\windows\system32\DRIVERS\clwvd.sys
01:27:18.0254 0x1640 clwvd - ok
01:27:18.0269 0x1640 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\drivers\CmBatt.sys
01:27:18.0269 0x1640 CmBatt - ok
01:27:18.0300 0x1640 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
01:27:18.0300 0x1640 cmdide - ok
01:27:18.0347 0x1640 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\windows\system32\Drivers\cng.sys
01:27:18.0363 0x1640 CNG - ok
01:27:18.0394 0x1640 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\drivers\compbatt.sys
01:27:18.0394 0x1640 Compbatt - ok
01:27:18.0410 0x1640 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
01:27:18.0425 0x1640 CompositeBus - ok
01:27:18.0425 0x1640 COMSysApp - ok
01:27:18.0472 0x1640 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
01:27:18.0472 0x1640 crcdisk - ok
01:27:18.0503 0x1640 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\windows\system32\cryptsvc.dll
01:27:18.0519 0x1640 CryptSvc - ok
01:27:18.0597 0x1640 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\windows\system32\rpcss.dll
01:27:18.0597 0x1640 DcomLaunch - ok
01:27:18.0628 0x1640 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
01:27:18.0628 0x1640 defragsvc - ok
01:27:18.0675 0x1640 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\windows\system32\Drivers\dfsc.sys
01:27:18.0675 0x1640 DfsC - ok
01:27:18.0706 0x1640 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\windows\system32\dhcpcore.dll
01:27:18.0706 0x1640 Dhcp - ok
01:27:18.0737 0x1640 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
01:27:18.0737 0x1640 discache - ok
01:27:18.0769 0x1640 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\drivers\disk.sys
01:27:18.0769 0x1640 Disk - ok
01:27:18.0831 0x1640 [ BA870E4749421275EBA05AD6B08CB4F5 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
01:27:18.0831 0x1640 DMAgent - ok
01:27:18.0878 0x1640 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\windows\System32\dnsrslvr.dll
01:27:18.0878 0x1640 Dnscache - ok
01:27:18.0909 0x1640 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\windows\System32\dot3svc.dll
01:27:18.0909 0x1640 dot3svc - ok
01:27:18.0940 0x1640 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\windows\system32\dps.dll
01:27:18.0940 0x1640 DPS - ok
01:27:18.0971 0x1640 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
01:27:18.0971 0x1640 drmkaud - ok
01:27:19.0018 0x1640 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
01:27:19.0034 0x1640 DXGKrnl - ok
01:27:19.0034 0x1640 EagleXNt - ok
01:27:19.0065 0x1640 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
01:27:19.0065 0x1640 EapHost - ok
01:27:19.0221 0x1640 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\drivers\evbdx.sys
01:27:19.0237 0x1640 ebdrv - ok
01:27:19.0283 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\windows\System32\lsass.exe
01:27:19.0283 0x1640 EFS - ok
01:27:19.0330 0x1640 [ BC667D6C0A8A857CABA77818F1A953FD ] ehRecvr C:\windows\ehome\ehRecvr.exe
01:27:19.0346 0x1640 ehRecvr - ok
01:27:19.0377 0x1640 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
01:27:19.0377 0x1640 ehSched - ok
01:27:19.0424 0x1640 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\drivers\elxstor.sys
01:27:19.0424 0x1640 elxstor - ok
01:27:19.0455 0x1640 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
01:27:19.0455 0x1640 ErrDev - ok
01:27:19.0517 0x1640 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
01:27:19.0533 0x1640 EventSystem - ok
01:27:19.0595 0x1640 [ 8597822F0E0EAA61A9FFD18778828792 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
01:27:19.0611 0x1640 EvtEng - ok
01:27:19.0658 0x1640 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
01:27:19.0658 0x1640 exfat - ok
01:27:19.0673 0x1640 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
01:27:19.0673 0x1640 fastfat - ok
01:27:19.0705 0x1640 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\windows\system32\fxssvc.exe
01:27:19.0720 0x1640 Fax - ok
01:27:19.0736 0x1640 [ 22EC3B0EA37CDF4355AE627004F3103C ] FBIOSDRV C:\windows\system32\Drivers\FBIOSDRV.sys
01:27:19.0736 0x1640 FBIOSDRV - ok
01:27:19.0767 0x1640 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\drivers\fdc.sys
01:27:19.0767 0x1640 fdc - ok
01:27:19.0783 0x1640 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
01:27:19.0783 0x1640 fdPHost - ok
01:27:19.0814 0x1640 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
01:27:19.0814 0x1640 FDResPub - ok
01:27:19.0829 0x1640 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
01:27:19.0829 0x1640 FileInfo - ok
01:27:19.0845 0x1640 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
01:27:19.0861 0x1640 Filetrace - ok
01:27:19.0892 0x1640 [ 31A2624507524A52A08DB2BBF2DB28EC ] FjDstService C:\Program Files\Fujitsu\DustSolution\FJDService.exe
01:27:19.0892 0x1640 FjDstService - ok
01:27:19.0939 0x1640 [ 1F2918E7FFB62D21FEFBA43B0F943F6B ] FJGSDisk C:\windows\system32\DRIVERS\FJGSDisk.sys
01:27:19.0939 0x1640 FJGSDisk - ok
01:27:19.0939 0x1640 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
01:27:19.0954 0x1640 flpydisk - ok
01:27:19.0954 0x1640 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
01:27:19.0954 0x1640 FltMgr - ok
01:27:20.0017 0x1640 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\windows\system32\FntCache.dll
01:27:20.0017 0x1640 FontCache - ok
01:27:20.0079 0x1640 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
01:27:20.0079 0x1640 FontCache3.0.0.0 - ok
01:27:20.0095 0x1640 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
01:27:20.0110 0x1640 FsDepends - ok
01:27:20.0141 0x1640 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
01:27:20.0141 0x1640 Fs_Rec - ok
01:27:20.0141 0x1640 [ 49E588AC7D2B57F057756A91C6F36D25 ] FUJ02B1 C:\windows\system32\drivers\FUJ02B1.sys
01:27:20.0141 0x1640 FUJ02B1 - ok
01:27:20.0173 0x1640 [ D45474A7E5E2F35150C29A3193747884 ] FUJ02E3 C:\windows\system32\drivers\FUJ02E3.sys
01:27:20.0173 0x1640 FUJ02E3 - ok
01:27:20.0219 0x1640 [ 4732E596BB1C50D9F9188C5074EE7782 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
01:27:20.0219 0x1640 fvevol - ok
01:27:20.0219 0x1640 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
01:27:20.0219 0x1640 gagp30kx - ok
01:27:20.0266 0x1640 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
01:27:20.0266 0x1640 GEARAspiWDM - ok
01:27:20.0297 0x1640 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\windows\System32\gpsvc.dll
01:27:20.0297 0x1640 gpsvc - ok
01:27:20.0344 0x1640 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\windows\system32\DRIVERS\hamachi.sys
01:27:20.0344 0x1640 hamachi - ok
01:27:20.0375 0x1640 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
01:27:20.0375 0x1640 hcw85cir - ok
01:27:20.0422 0x1640 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
01:27:20.0422 0x1640 HdAudAddService - ok
01:27:20.0438 0x1640 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
01:27:20.0438 0x1640 HDAudBus - ok
01:27:20.0469 0x1640 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\windows\system32\drivers\HECI.sys
01:27:20.0469 0x1640 HECI - ok
01:27:20.0500 0x1640 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
01:27:20.0500 0x1640 HidBatt - ok
01:27:20.0531 0x1640 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\drivers\hidbth.sys
01:27:20.0547 0x1640 HidBth - ok
01:27:20.0578 0x1640 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\drivers\hidir.sys
01:27:20.0578 0x1640 HidIr - ok
01:27:20.0594 0x1640 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
01:27:20.0609 0x1640 hidserv - ok
01:27:20.0609 0x1640 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
01:27:20.0625 0x1640 HidUsb - ok
01:27:20.0641 0x1640 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\windows\system32\kmsvc.dll
01:27:20.0641 0x1640 hkmsvc - ok
01:27:20.0672 0x1640 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\windows\system32\ListSvc.dll
01:27:20.0672 0x1640 HomeGroupListener - ok
01:27:20.0703 0x1640 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\windows\system32\provsvc.dll
01:27:20.0703 0x1640 HomeGroupProvider - ok
01:27:20.0719 0x1640 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
01:27:20.0719 0x1640 HpSAMD - ok
01:27:20.0750 0x1640 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\windows\system32\drivers\HTTP.sys
01:27:20.0765 0x1640 HTTP - ok
01:27:20.0781 0x1640 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
01:27:20.0781 0x1640 hwpolicy - ok
01:27:20.0812 0x1640 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
01:27:20.0812 0x1640 i8042prt - ok
01:27:20.0828 0x1640 [ D80AA0907748D7CC8EFAB3773F32629B ] iaStor C:\windows\system32\drivers\iaStor.sys
01:27:20.0843 0x1640 iaStor - ok
01:27:20.0875 0x1640 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
01:27:20.0875 0x1640 iaStorV - ok
01:27:20.0937 0x1640 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
01:27:20.0937 0x1640 idsvc - ok
01:27:21.0140 0x1640 [ 8E9DA2E49347AF49901526DCD4D0F397 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
01:27:21.0187 0x1640 igfx - ok
01:27:21.0249 0x1640 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\drivers\iirsp.sys
01:27:21.0249 0x1640 iirsp - ok
01:27:21.0280 0x1640 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\windows\System32\ikeext.dll
01:27:21.0296 0x1640 IKEEXT - ok
01:27:21.0358 0x1640 [ 91AB587F7EA44B0DEB0522F71AD7B2DC ] ImeDictUpdateService C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
01:27:21.0358 0x1640 ImeDictUpdateService - ok
01:27:21.0389 0x1640 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\windows\system32\drivers\Impcd.sys
01:27:21.0389 0x1640 Impcd - ok
01:27:21.0499 0x1640 [ AEE99ECF06CD1CEA95816CCB5BF73EC8 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
01:27:21.0545 0x1640 IntcAzAudAddService - ok
01:27:21.0592 0x1640 [ BF31740828A26AB451803E3B35432651 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
01:27:21.0592 0x1640 IntcDAud - ok
01:27:21.0608 0x1640 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
01:27:21.0608 0x1640 intelide - ok
01:27:21.0639 0x1640 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\drivers\intelppm.sys
01:27:21.0639 0x1640 intelppm - ok
01:27:21.0655 0x1640 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
01:27:21.0655 0x1640 IPBusEnum - ok
01:27:21.0670 0x1640 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
01:27:21.0670 0x1640 IpFilterDriver - ok
01:27:21.0701 0x1640 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
01:27:21.0701 0x1640 iphlpsvc - ok
01:27:21.0717 0x1640 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
01:27:21.0733 0x1640 IPMIDRV - ok
01:27:21.0748 0x1640 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
01:27:21.0748 0x1640 IPNAT - ok
01:27:21.0795 0x1640 [ D8B8B5A8FE57CF4F307A540D9A153C23 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
01:27:21.0811 0x1640 iPod Service - ok
01:27:21.0826 0x1640 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
01:27:21.0826 0x1640 IRENUM - ok
01:27:21.0873 0x1640 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
01:27:21.0873 0x1640 isapnp - ok
01:27:21.0889 0x1640 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
01:27:21.0889 0x1640 iScsiPrt - ok
01:27:21.0920 0x1640 [ F415A88162D23977B5EDAE4F0410E903 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
01:27:21.0920 0x1640 IviRegMgr - ok
01:27:21.0967 0x1640 [ 703E40B3A128F1FB8C307ADA168CA121 ] k57nd60x C:\windows\system32\DRIVERS\k57nd60x.sys
01:27:21.0967 0x1640 k57nd60x - ok
01:27:22.0013 0x1640 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
01:27:22.0013 0x1640 kbdclass - ok
01:27:22.0029 0x1640 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
01:27:22.0029 0x1640 kbdhid - ok
01:27:22.0045 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\windows\system32\lsass.exe
01:27:22.0045 0x1640 KeyIso - ok
01:27:22.0076 0x1640 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
01:27:22.0076 0x1640 KSecDD - ok
01:27:22.0123 0x1640 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
01:27:22.0123 0x1640 KSecPkg - ok
01:27:22.0169 0x1640 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
01:27:22.0169 0x1640 KtmRm - ok
01:27:22.0216 0x1640 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\windows\system32\srvsvc.dll
01:27:22.0216 0x1640 LanmanServer - ok
01:27:22.0247 0x1640 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\windows\System32\wkssvc.dll
01:27:22.0247 0x1640 LanmanWorkstation - ok
01:27:22.0263 0x1640 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
01:27:22.0263 0x1640 lltdio - ok
01:27:22.0310 0x1640 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
01:27:22.0310 0x1640 lltdsvc - ok
01:27:22.0341 0x1640 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
01:27:22.0341 0x1640 lmhosts - ok
01:27:22.0372 0x1640 [ A1C148801B4AF64847AEB9F3AD9594EF ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
01:27:22.0388 0x1640 LMS - ok
01:27:22.0403 0x1640 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
01:27:22.0403 0x1640 LSI_FC - ok
01:27:22.0419 0x1640 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
01:27:22.0419 0x1640 LSI_SAS - ok
01:27:22.0466 0x1640 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
01:27:22.0466 0x1640 LSI_SAS2 - ok
01:27:22.0481 0x1640 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
01:27:22.0481 0x1640 LSI_SCSI - ok
01:27:22.0497 0x1640 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
01:27:22.0497 0x1640 luafv - ok
01:27:22.0544 0x1640 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
01:27:22.0544 0x1640 Mcx2Svc - ok
01:27:22.0559 0x1640 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\drivers\megasas.sys
01:27:22.0575 0x1640 megasas - ok
01:27:22.0606 0x1640 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
01:27:22.0606 0x1640 MegaSR - ok
01:27:22.0637 0x1640 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
01:27:22.0637 0x1640 MMCSS - ok
01:27:22.0653 0x1640 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
01:27:22.0653 0x1640 Modem - ok
01:27:22.0669 0x1640 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
01:27:22.0669 0x1640 monitor - ok
01:27:22.0684 0x1640 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
01:27:22.0684 0x1640 mouclass - ok
01:27:22.0715 0x1640 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
01:27:22.0715 0x1640 mouhid - ok
01:27:22.0731 0x1640 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
01:27:22.0731 0x1640 mountmgr - ok
01:27:22.0762 0x1640 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\windows\system32\drivers\mpio.sys
01:27:22.0762 0x1640 mpio - ok
01:27:22.0778 0x1640 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
01:27:22.0778 0x1640 mpsdrv - ok
01:27:22.0809 0x1640 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\windows\system32\mpssvc.dll
01:27:22.0825 0x1640 MpsSvc - ok
01:27:22.0856 0x1640 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
01:27:22.0856 0x1640 MRxDAV - ok
01:27:22.0903 0x1640 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
01:27:22.0903 0x1640 mrxsmb - ok
01:27:22.0934 0x1640 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
01:27:22.0949 0x1640 mrxsmb10 - ok
01:27:22.0965 0x1640 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
01:27:22.0965 0x1640 mrxsmb20 - ok
01:27:22.0965 0x1640 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\windows\system32\drivers\msahci.sys
01:27:22.0965 0x1640 msahci - ok
01:27:22.0996 0x1640 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\windows\system32\drivers\msdsm.sys
01:27:22.0996 0x1640 msdsm - ok
01:27:23.0012 0x1640 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
01:27:23.0012 0x1640 MSDTC - ok
01:27:23.0027 0x1640 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
01:27:23.0027 0x1640 Msfs - ok
01:27:23.0074 0x1640 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
01:27:23.0074 0x1640 mshidkmdf - ok
01:27:23.0090 0x1640 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
01:27:23.0090 0x1640 msisadrv - ok
01:27:23.0121 0x1640 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
01:27:23.0121 0x1640 MSiSCSI - ok
01:27:23.0121 0x1640 msiserver - ok
01:27:23.0155 0x1640 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
01:27:23.0156 0x1640 MSKSSRV - ok
01:27:23.0162 0x1640 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
01:27:23.0162 0x1640 MSPCLOCK - ok
01:27:23.0182 0x1640 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
01:27:23.0182 0x1640 MSPQM - ok
01:27:23.0192 0x1640 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
01:27:23.0192 0x1640 MsRPC - ok
01:27:23.0222 0x1640 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
01:27:23.0222 0x1640 mssmbios - ok
01:27:23.0232 0x1640 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
01:27:23.0232 0x1640 MSTEE - ok
01:27:23.0242 0x1640 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
01:27:23.0258 0x1640 MTConfig - ok
01:27:23.0273 0x1640 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
01:27:23.0273 0x1640 Mup - ok
01:27:23.0305 0x1640 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\windows\system32\qagentRT.dll
01:27:23.0305 0x1640 napagent - ok
01:27:23.0351 0x1640 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
01:27:23.0351 0x1640 NativeWifiP - ok
01:27:23.0398 0x1640 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\windows\system32\drivers\ndis.sys
01:27:23.0414 0x1640 NDIS - ok
01:27:23.0461 0x1640 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
01:27:23.0461 0x1640 NdisCap - ok
01:27:23.0492 0x1640 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
01:27:23.0492 0x1640 NdisTapi - ok
01:27:23.0507 0x1640 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
01:27:23.0507 0x1640 Ndisuio - ok
01:27:23.0523 0x1640 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
01:27:23.0523 0x1640 NdisWan - ok
01:27:23.0539 0x1640 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
01:27:23.0554 0x1640 NDProxy - ok
01:27:23.0554 0x1640 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
01:27:23.0570 0x1640 NetBIOS - ok
01:27:23.0585 0x1640 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
01:27:23.0585 0x1640 NetBT - ok
01:27:23.0617 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\windows\system32\lsass.exe
01:27:23.0617 0x1640 Netlogon - ok
01:27:23.0663 0x1640 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
01:27:23.0663 0x1640 Netman - ok
01:27:23.0663 0x1640 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
01:27:23.0679 0x1640 netprofm - ok
01:27:23.0710 0x1640 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
01:27:23.0710 0x1640 NetTcpPortSharing - ok
01:27:23.0882 0x1640 [ 3577B851E59DA59E6D65419A057C9914 ] NETw5s32 C:\windows\system32\DRIVERS\NETw5s32.sys
01:27:23.0929 0x1640 NETw5s32 - ok
01:27:23.0975 0x1640 [ F282FC61839F8A719A3AD569CAB71C9C ] NetworkPlayer Server C:\Program Files\Fujitsu\NetworkPlayer Server\NetworkPlayerServer.exe
01:27:23.0975 0x1640 NetworkPlayer Server - ok
01:27:24.0022 0x1640 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
01:27:24.0038 0x1640 nfrd960 - ok
01:27:24.0053 0x1640 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\windows\System32\nlasvc.dll
01:27:24.0069 0x1640 NlaSvc - ok
01:27:24.0085 0x1640 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
01:27:24.0085 0x1640 Npfs - ok
01:27:24.0085 0x1640 npggsvc - ok
01:27:24.0116 0x1640 [ 3964D26EE70B24B5318146247DD782DF ] npkakl C:\windows\system32\npkakl.sys
01:27:24.0116 0x1640 npkakl - ok
01:27:24.0147 0x1640 [ 83D727642D288A75A10100BEF5CDB756 ] npkcmsvc C:\windows\system32\npkcmsvc.exe
01:27:24.0147 0x1640 npkcmsvc - ok
01:27:24.0163 0x1640 [ 77BEB64EA3E83C37355B6D8EEB14008E ] npkcrypt C:\windows\system32\npkcrypt.sys
01:27:24.0178 0x1640 npkcrypt - ok
01:27:24.0209 0x1640 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
01:27:24.0209 0x1640 nsi - ok
01:27:24.0209 0x1640 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
01:27:24.0209 0x1640 nsiproxy - ok
01:27:24.0288 0x1640 [ A8F59428E9F361C7AC42A94AC1560BC9 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
01:27:24.0298 0x1640 Ntfs - ok
01:27:24.0328 0x1640 [ 588F2E8ACF3BDCE4496295806D21ECAF ] ntk3 C:\Program Files\Fujitsu\NetworkPlayer\Kernel\DMP\ntk3.sys
01:27:24.0328 0x1640 ntk3 - ok
01:27:24.0348 0x1640 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
01:27:24.0348 0x1640 Null - ok
01:27:24.0364 0x1640 [ EE0CB811A0F03038C2BC64538AA780F8 ] nusb3hub C:\windows\system32\drivers\nusb3hub.sys
01:27:24.0364 0x1640 nusb3hub - ok
01:27:24.0395 0x1640 [ 7CAA9F5D8602B236A92B17EDC87549F9 ] nusb3xhc C:\windows\system32\drivers\nusb3xhc.sys
01:27:24.0395 0x1640 nusb3xhc - ok
01:27:24.0442 0x1640 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\windows\system32\drivers\nvraid.sys
01:27:24.0442 0x1640 nvraid - ok
01:27:24.0489 0x1640 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\windows\system32\drivers\nvstor.sys
01:27:24.0489 0x1640 nvstor - ok
01:27:24.0504 0x1640 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
01:27:24.0504 0x1640 nv_agp - ok
01:27:24.0520 0x1640 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
01:27:24.0520 0x1640 ohci1394 - ok
01:27:24.0598 0x1640 [ 84113AB3A3EEF32FBEBF3339D8C19100 ] omniserv C:\Program Files\Softex\OmniPass\OmniServ.exe
01:27:24.0598 0x1640 omniserv - ok
01:27:24.0629 0x1640 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
01:27:24.0629 0x1640 ose - ok
01:27:24.0785 0x1640 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
01:27:24.0816 0x1640 osppsvc - ok
01:27:24.0847 0x1640 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
01:27:24.0847 0x1640 p2pimsvc - ok
01:27:24.0863 0x1640 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
01:27:24.0863 0x1640 p2psvc - ok
01:27:24.0999 0x1640 [ CB1257208C7105192F397187C14162E9 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\OpenMG\PACSPTISVR.exe
01:27:24.0999 0x1640 PACSPTISVR - ok
01:27:25.0019 0x1640 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\drivers\parport.sys
01:27:25.0019 0x1640 Parport - ok
01:27:25.0039 0x1640 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\windows\system32\drivers\partmgr.sys
01:27:25.0039 0x1640 partmgr - ok
01:27:25.0049 0x1640 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\drivers\parvdm.sys
01:27:25.0049 0x1640 Parvdm - ok
01:27:25.0080 0x1640 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
01:27:25.0080 0x1640 PcaSvc - ok
01:27:25.0111 0x1640 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\windows\system32\drivers\pci.sys
01:27:25.0111 0x1640 pci - ok
01:27:25.0142 0x1640 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
01:27:25.0142 0x1640 pciide - ok
01:27:25.0173 0x1640 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
01:27:25.0173 0x1640 pcmcia - ok
01:27:25.0205 0x1640 [
  • 宵子
  • 2013/08/21 (Wed) 01:44:56
TDSSKiller2回目その4
見切れてましたのでその分を追加します。

01:27:25.0205 0x1640 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
01:27:25.0205 0x1640 pcw - ok
01:27:25.0329 0x1640 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
01:27:25.0329 0x1640 PEAUTH - ok
01:27:25.0485 0x1640 [ F3B3F0BBC15C668EF87FD6C265994481 ] PFNService C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
01:27:25.0501 0x1640 PFNService - ok
01:27:25.0844 0x1640 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\windows\system32\pla.dll
01:27:25.0860 0x1640 pla - ok
01:27:25.0953 0x1640 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\windows\system32\umpnpmgr.dll
01:27:25.0953 0x1640 PlugPlay - ok
01:27:25.0985 0x1640 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
01:27:25.0985 0x1640 PNRPAutoReg - ok
01:27:26.0078 0x1640 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
01:27:26.0078 0x1640 PNRPsvc - ok
01:27:26.0187 0x1640 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
01:27:26.0187 0x1640 PolicyAgent - ok
01:27:26.0250 0x1640 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\windows\system32\umpo.dll
01:27:26.0265 0x1640 Power - ok
01:27:26.0343 0x1640 [ AEA6984F3DD10A76552480D46CF17EBD ] PowerSavingUtilityService C:\Program Files\Fujitsu\PSUtility\PSUService.exe
01:27:26.0343 0x1640 PowerSavingUtilityService - ok
01:27:26.0406 0x1640 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
01:27:26.0406 0x1640 PptpMiniport - ok
01:27:26.0437 0x1640 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\drivers\processr.sys
01:27:26.0437 0x1640 Processor - ok
01:27:26.0484 0x1640 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\windows\system32\profsvc.dll
01:27:26.0499 0x1640 ProfSvc - ok
01:27:26.0531 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\windows\system32\lsass.exe
01:27:26.0531 0x1640 ProtectedStorage - ok
01:27:26.0562 0x1640 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
01:27:26.0562 0x1640 Psched - ok
01:27:26.0609 0x1640 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
01:27:26.0609 0x1640 PSI_SVC_2 - ok
01:27:26.0718 0x1640 [ 786DBE9D3A96481F21E8CF59CFA049A6 ] PUSCSRVC C:\Program Files\Fujitsu\PowerUtility\schedule\PUSCSRVC.exe
01:27:26.0718 0x1640 PUSCSRVC - ok
01:27:26.0780 0x1640 [ B6A1692FC131F1FE5162513D78A9B6FC ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
01:27:26.0780 0x1640 PxHelp20 - ok
01:27:27.0061 0x1640 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\drivers\ql2300.sys
01:27:27.0077 0x1640 ql2300 - ok
01:27:27.0123 0x1640 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
01:27:27.0123 0x1640 ql40xx - ok
01:27:27.0217 0x1640 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
01:27:27.0217 0x1640 QWAVE - ok
01:27:27.0248 0x1640 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
01:27:27.0248 0x1640 QWAVEdrv - ok
01:27:27.0279 0x1640 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
01:27:27.0279 0x1640 RasAcd - ok
01:27:27.0342 0x1640 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
01:27:27.0342 0x1640 RasAgileVpn - ok
01:27:27.0373 0x1640 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
01:27:27.0373 0x1640 RasAuto - ok
01:27:27.0404 0x1640 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
01:27:27.0404 0x1640 Rasl2tp - ok
01:27:27.0498 0x1640 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\windows\System32\rasmans.dll
01:27:27.0498 0x1640 RasMan - ok
01:27:27.0529 0x1640 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
01:27:27.0529 0x1640 RasPppoe - ok
01:27:27.0560 0x1640 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
01:27:27.0560 0x1640 RasSstp - ok
01:27:27.0623 0x1640 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
01:27:27.0623 0x1640 rdbss - ok
01:27:27.0732 0x1640 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\drivers\rdpbus.sys
01:27:27.0732 0x1640 rdpbus - ok
01:27:27.0810 0x1640 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
01:27:27.0810 0x1640 RDPCDD - ok
01:27:27.0841 0x1640 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
01:27:27.0841 0x1640 RDPENCDD - ok
01:27:27.0888 0x1640 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
01:27:27.0888 0x1640 RDPREFMP - ok
01:27:27.0997 0x1640 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
01:27:27.0997 0x1640 RDPWD - ok
01:27:28.0153 0x1640 [ 65DB288F7372B1F632891FC32BF908B7 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
01:27:28.0153 0x1640 rdyboost - ok
01:27:28.0262 0x1640 [ B2D01290C0E0465ACA54C2088E947823 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
01:27:28.0262 0x1640 RealNetworks Downloader Resolver Service - ok
01:27:28.0293 0x1640 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\windows\system32\drivers\regi.sys
01:27:28.0293 0x1640 regi - ok
01:27:28.0434 0x1640 [ 7AFCBE32616E08D45E4EAADB0A1DD5CF ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
01:27:28.0449 0x1640 RegSrvc - ok
01:27:28.0527 0x1640 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
01:27:28.0543 0x1640 RemoteAccess - ok
01:27:28.0559 0x1640 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
01:27:28.0559 0x1640 RemoteRegistry - ok
01:27:28.0574 0x1640 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
01:27:28.0574 0x1640 RpcEptMapper - ok
01:27:28.0605 0x1640 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
01:27:28.0605 0x1640 RpcLocator - ok
01:27:28.0637 0x1640 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\windows\system32\rpcss.dll
01:27:28.0637 0x1640 RpcSs - ok
01:27:28.0668 0x1640 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
01:27:28.0668 0x1640 rspndr - ok
01:27:28.0699 0x1640 [ 11CC47F1CC7A66BBC6766F6037C5A678 ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
01:27:28.0699 0x1640 RSUSBSTOR - ok
01:27:28.0715 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\windows\system32\lsass.exe
01:27:28.0715 0x1640 SamSs - ok
01:27:28.0746 0x1640 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
01:27:28.0746 0x1640 sbp2port - ok
01:27:28.0761 0x1640 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
01:27:28.0761 0x1640 SCardSvr - ok
01:27:28.0793 0x1640 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
01:27:28.0808 0x1640 scfilter - ok
01:27:28.0855 0x1640 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\windows\system32\schedsvc.dll
01:27:28.0871 0x1640 Schedule - ok
01:27:28.0933 0x1640 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\windows\System32\certprop.dll
01:27:28.0933 0x1640 SCPolicySvc - ok
01:27:28.0933 0x1640 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\windows\System32\SDRSVC.dll
01:27:28.0949 0x1640 SDRSVC - ok
01:27:28.0964 0x1640 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
01:27:28.0964 0x1640 secdrv - ok
01:27:28.0995 0x1640 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
01:27:28.0995 0x1640 seclogon - ok
01:27:29.0011 0x1640 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
01:27:29.0011 0x1640 SENS - ok
01:27:29.0042 0x1640 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
01:27:29.0042 0x1640 SensrSvc - ok
01:27:29.0073 0x1640 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\drivers\serenum.sys
01:27:29.0073 0x1640 Serenum - ok
01:27:29.0089 0x1640 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\drivers\serial.sys
01:27:29.0089 0x1640 Serial - ok
01:27:29.0120 0x1640 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\drivers\sermouse.sys
01:27:29.0120 0x1640 sermouse - ok
01:27:29.0120 0x1640 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\windows\system32\sessenv.dll
01:27:29.0136 0x1640 SessionEnv - ok
01:27:29.0167 0x1640 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
01:27:29.0167 0x1640 sffdisk - ok
01:27:29.0183 0x1640 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
01:27:29.0183 0x1640 sffp_mmc - ok
01:27:29.0198 0x1640 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
01:27:29.0198 0x1640 sffp_sd - ok
01:27:29.0245 0x1640 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
01:27:29.0245 0x1640 sfloppy - ok
01:27:29.0292 0x1640 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
01:27:29.0292 0x1640 SharedAccess - ok
01:27:29.0323 0x1640 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\windows\System32\shsvcs.dll
01:27:29.0323 0x1640 ShellHWDetection - ok
01:27:29.0354 0x1640 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
01:27:29.0354 0x1640 sisagp - ok
01:27:29.0385 0x1640 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
01:27:29.0385 0x1640 SiSRaid2 - ok
01:27:29.0417 0x1640 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
01:27:29.0417 0x1640 SiSRaid4 - ok
01:27:29.0479 0x1640 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
01:27:29.0479 0x1640 SkypeUpdate - ok
01:27:29.0510 0x1640 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
01:27:29.0510 0x1640 Smb - ok
01:27:29.0541 0x1640 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
01:27:29.0557 0x1640 SNMPTRAP - ok
01:27:29.0682 0x1640 [ A7D1229E1326D02CF80F952617C5A39B ] SNP2UVC C:\windows\system32\DRIVERS\snp2uvc.sys
01:27:29.0697 0x1640 SNP2UVC - ok
01:27:29.0791 0x1640 [ 6AE4902A4A819A7A1545D23972D70C55 ] SonicStage Back-End Service2 C:\Program Files\Common Files\Sony Shared\AVLib\SsBeService2.exe
01:27:29.0791 0x1640 SonicStage Back-End Service2 - ok
01:27:29.0807 0x1640 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
01:27:29.0822 0x1640 spldr - ok
01:27:29.0869 0x1640 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\windows\System32\spoolsv.exe
01:27:29.0869 0x1640 Spooler - ok
01:27:29.0947 0x1640 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\windows\system32\sppsvc.exe
01:27:29.0978 0x1640 sppsvc - ok
01:27:30.0009 0x1640 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\windows\system32\sppuinotify.dll
01:27:30.0009 0x1640 sppuinotify - ok
01:27:30.0041 0x1640 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\windows\system32\DRIVERS\srv.sys
01:27:30.0056 0x1640 srv - ok
01:27:30.0087 0x1640 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
01:27:30.0087 0x1640 srv2 - ok
01:27:30.0119 0x1640 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
01:27:30.0119 0x1640 srvnet - ok
01:27:30.0150 0x1640 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
01:27:30.0150 0x1640 SSDPSRV - ok
01:27:30.0165 0x1640 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
01:27:30.0181 0x1640 SstpSvc - ok
01:27:30.0212 0x1640 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\drivers\stexstor.sys
01:27:30.0212 0x1640 stexstor - ok
01:27:30.0228 0x1640 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\windows\System32\wiaservc.dll
01:27:30.0243 0x1640 StiSvc - ok
01:27:30.0290 0x1640 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
01:27:30.0290 0x1640 swenum - ok
01:27:30.0321 0x1640 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
01:27:30.0321 0x1640 swprv - ok
01:27:30.0399 0x1640 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\windows\system32\sysmain.dll
01:27:30.0415 0x1640 SysMain - ok
01:27:30.0431 0x1640 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\windows\System32\TabSvc.dll
01:27:30.0431 0x1640 TabletInputService - ok
01:27:30.0462 0x1640 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\windows\System32\tapisrv.dll
01:27:30.0462 0x1640 TapiSrv - ok
01:27:30.0477 0x1640 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
01:27:30.0493 0x1640 TBS - ok
01:27:30.0555 0x1640 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] Tcpip C:\windows\system32\drivers\tcpip.sys
01:27:30.0571 0x1640 Tcpip - ok
01:27:30.0602 0x1640 [ BBCEAEFF1FD72A026F827CBB2F4AA8AD ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
01:27:30.0618 0x1640 TCPIP6 - ok
01:27:30.0633 0x1640 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
01:27:30.0633 0x1640 tcpipreg - ok
01:27:30.0665 0x1640 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
01:27:30.0665 0x1640 TDPIPE - ok
01:27:30.0696 0x1640 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
01:27:30.0696 0x1640 TDTCP - ok
01:27:30.0711 0x1640 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\windows\system32\DRIVERS\tdx.sys
01:27:30.0711 0x1640 tdx - ok
01:27:30.0727 0x1640 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\windows\system32\drivers\termdd.sys
01:27:30.0743 0x1640 TermDD - ok
01:27:30.0758 0x1640 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\windows\System32\termsrv.dll
01:27:30.0774 0x1640 TermService - ok
01:27:30.0789 0x1640 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
01:27:30.0789 0x1640 Themes - ok
01:27:30.0805 0x1640 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
01:27:30.0821 0x1640 THREADORDER - ok
01:27:30.0867 0x1640 [ 883B3052721452E8667F5597AD2C5379 ] tmactmon C:\windows\system32\DRIVERS\tmactmon.sys
01:27:30.0867 0x1640 tmactmon - ok
01:27:30.0914 0x1640 [ F33C3F08536F988AAC84D72D83B139A6 ] tmcomm C:\windows\system32\DRIVERS\tmcomm.sys
01:27:30.0930 0x1640 tmcomm - ok
01:27:30.0961 0x1640 [ A17D672CBE700272DA499AA3ED60D3CC ] tmeevw C:\windows\system32\DRIVERS\tmeevw.sys
01:27:30.0961 0x1640 tmeevw - ok
01:27:30.0977 0x1640 [ 8FE7172FF137249BEA4EBC750EF90093 ] tmevtmgr C:\windows\system32\DRIVERS\tmevtmgr.sys
01:27:30.0977 0x1640 tmevtmgr - ok
01:27:31.0023 0x1640 [ 0C40396F071A8092964C8DC951F62B17 ] tmnciesc C:\windows\system32\DRIVERS\tmnciesc.sys
01:27:31.0039 0x1640 tmnciesc - ok
01:27:31.0055 0x1640 [ 43C1B7C778B296D492AF6D2ABB2ECF7F ] tmtdi C:\windows\system32\DRIVERS\tmtdi.sys
01:27:31.0055 0x1640 tmtdi - ok
01:27:31.0086 0x1640 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
01:27:31.0101 0x1640 TrkWks - ok
01:27:31.0179 0x1640 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
01:27:31.0179 0x1640 TrustedInstaller - ok
01:27:31.0195 0x1640 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
01:27:31.0211 0x1640 tssecsrv - ok
01:27:31.0242 0x1640 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
01:27:31.0242 0x1640 tunnel - ok
01:27:31.0273 0x1640 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\drivers\uagp35.sys
01:27:31.0273 0x1640 uagp35 - ok
01:27:31.0351 0x1640 [ F7DF6654663AD07DAB615A7AF513D90C ] UCManSvc C:\Program Files\SoftDenchi\UCManSvc.exe
01:27:31.0367 0x1640 UCManSvc - ok
01:27:31.0398 0x1640 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\windows\system32\DRIVERS\udfs.sys
01:27:31.0398 0x1640 udfs - ok
01:27:31.0476 0x1640 [ 27B37460477592A4C591F83675A096F9 ] UDSS c:\Program Files\Common Files\Ulead Systems\UDSS\UDSS.exe
01:27:31.0476 0x1640 UDSS - ok
01:27:31.0507 0x1640 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
01:27:31.0507 0x1640 UI0Detect - ok
01:27:31.0538 0x1640 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
01:27:31.0538 0x1640 uliagpkx - ok
01:27:31.0554 0x1640 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\windows\system32\DRIVERS\umbus.sys
01:27:31.0554 0x1640 umbus - ok
01:27:31.0585 0x1640 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\drivers\umpass.sys
01:27:31.0585 0x1640 UmPass - ok
01:27:31.0679 0x1640 [ 41118D920B2B268C0ADC36421248CDCF ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
01:27:31.0710 0x1640 UNS - ok
01:27:31.0757 0x1640 [ C11D90101CB125AFC47525066EFF4AE9 ] UpdateNaviInstallService C:\Program Files\Fujitsu\chitose\updnvsrv.exe
01:27:31.0757 0x1640 UpdateNaviInstallService - ok
01:27:31.0788 0x1640 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
01:27:31.0803 0x1640 upnphost - ok
01:27:31.0850 0x1640 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\windows\system32\Drivers\usbaapl.sys
01:27:31.0850 0x1640 USBAAPL - ok
01:27:31.0881 0x1640 [ 5C233AEFB566EE78C1EFBC0493FB066A ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
01:27:31.0897 0x1640 usbccgp - ok
01:27:31.0928 0x1640 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\windows\system32\drivers\usbcir.sys
01:27:31.0928 0x1640 usbcir - ok
01:27:31.0975 0x1640 [ 5B71019A6ACA0116FD21B368F19C0B91 ] usbehci C:\windows\system32\drivers\usbehci.sys
01:27:31.0975 0x1640 usbehci - ok
01:27:32.0022 0x1640 [ 5823D3965C2A4F6F785ED1A3B403F3B8 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
01:27:32.0022 0x1640 usbhub - ok
01:27:32.0069 0x1640 [ E753ED6C49DA13967EBABF9EA616454A ] usbohci C:\windows\system32\drivers\usbohci.sys
01:27:32.0069 0x1640 usbohci - ok
01:27:32.0100 0x1640 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
01:27:32.0115 0x1640 usbprint - ok
01:27:32.0147 0x1640 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\windows\system32\DRIVERS\usbscan.sys
01:27:32.0147 0x1640 usbscan - ok
01:27:32.0193 0x1640 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
01:27:32.0193 0x1640 USBSTOR - ok
01:27:32.0240 0x1640 [ 6A30928A469CE802600E1EA8C0F2F53F ] usbuhci C:\windows\system32\drivers\usbuhci.sys
01:27:32.0240 0x1640 usbuhci - ok
01:27:32.0271 0x1640 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
01:27:32.0271 0x1640 usbvideo - ok
01:27:32.0303 0x1640 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
01:27:32.0303 0x1640 UxSms - ok
01:27:32.0318 0x1640 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\windows\system32\lsass.exe
01:27:32.0318 0x1640 VaultSvc - ok
01:27:32.0365 0x1640 [ B2ABAB4CA46BAD182E27763DC19C780F ] VCSVADHWSer C:\windows\system32\DRIVERS\vcsvad.sys
01:27:32.0365 0x1640 VCSVADHWSer - ok
01:27:32.0427 0x1640 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
01:27:32.0427 0x1640 vdrvroot - ok
01:27:32.0490 0x1640 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\windows\System32\vds.exe
01:27:32.0490 0x1640 vds - ok
01:27:32.0537 0x1640 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
01:27:32.0537 0x1640 vga - ok
01:27:32.0552 0x1640 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
01:27:32.0552 0x1640 VgaSave - ok
01:27:32.0583 0x1640 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
01:27:32.0583 0x1640 vhdmp - ok
01:27:32.0615 0x1640 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
01:27:32.0615 0x1640 viaagp - ok
01:27:32.0630 0x1640 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\drivers\viac7.sys
01:27:32.0630 0x1640 ViaC7 - ok
01:27:32.0661 0x1640 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
01:27:32.0661 0x1640 viaide - ok
01:27:32.0693 0x1640 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\windows\system32\drivers\volmgr.sys
01:27:32.0708 0x1640 volmgr - ok
01:27:32.0739 0x1640 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
01:27:32.0739 0x1640 volmgrx - ok
01:27:32.0771 0x1640 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\windows\system32\drivers\volsnap.sys
01:27:32.0771 0x1640 volsnap - ok
01:27:32.0802 0x1640 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
01:27:32.0802 0x1640 vsmraid - ok
01:27:32.0833 0x1640 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\windows\system32\vssvc.exe
01:27:32.0849 0x1640 VSS - ok
01:27:32.0849 0x1640 vtany - ok
01:27:32.0895 0x1640 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
01:27:32.0895 0x1640 vwifibus - ok
01:27:32.0895 0x1640 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
01:27:32.0895 0x1640 vwififlt - ok
01:27:32.0927 0x1640 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
01:27:32.0927 0x1640 vwifimp - ok
01:27:32.0942 0x1640 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
01:27:32.0942 0x1640 W32Time - ok
01:27:32.0973 0x1640 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\drivers\wacompen.sys
01:27:32.0973 0x1640 WacomPen - ok
01:27:32.0989 0x1640 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
01:27:32.0989 0x1640 WANARP - ok
01:27:33.0005 0x1640 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
01:27:33.0005 0x1640 Wanarpv6 - ok
01:27:33.0083 0x1640 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
01:27:33.0098 0x1640 WatAdminSvc - ok
01:27:33.0145 0x1640 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\windows\system32\wbengine.exe
01:27:33.0176 0x1640 wbengine - ok
01:27:33.0176 0x1640 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
01:27:33.0176 0x1640 WbioSrvc - ok
01:27:33.0223 0x1640 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\windows\System32\wcncsvc.dll
01:27:33.0239 0x1640 wcncsvc - ok
01:27:33.0254 0x1640 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
01:27:33.0254 0x1640 WcsPlugInService - ok
01:27:33.0270 0x1640 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\drivers\wd.sys
01:27:33.0285 0x1640 Wd - ok
01:27:33.0332 0x1640 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
01:27:33.0348 0x1640 Wdf01000 - ok
01:27:33.0363 0x1640 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
01:27:33.0363 0x1640 WdiServiceHost - ok
01:27:33.0379 0x1640 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
01:27:33.0379 0x1640 WdiSystemHost - ok
01:27:33.0426 0x1640 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\windows\System32\webclnt.dll
01:27:33.0426 0x1640 WebClient - ok
01:27:33.0457 0x1640 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
01:27:33.0457 0x1640 Wecsvc - ok
01:27:33.0473 0x1640 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
01:27:33.0473 0x1640 wercplsupport - ok
01:27:33.0504 0x1640 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
01:27:33.0504 0x1640 WerSvc - ok
01:27:33.0519 0x1640 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
01:27:33.0519 0x1640 WfpLwf - ok
01:27:33.0597 0x1640 [ FB23FA0F51001C43306BBD784F68240F ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
01:27:33.0613 0x1640 WiMAXAppSrv - ok
01:27:33.0675 0x1640 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
01:27:33.0675 0x1640 WIMMount - ok
01:27:33.0769 0x1640 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
01:27:33.0769 0x1640 WinDefend - ok
01:27:33.0785 0x1640 WinHttpAutoProxySvc - ok
01:27:33.0863 0x1640 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
01:27:33.0863 0x1640 Winmgmt - ok
01:27:33.0909 0x1640 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\windows\system32\WsmSvc.dll
01:27:33.0925 0x1640 WinRM - ok
01:27:33.0987 0x1640 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
01:27:33.0987 0x1640 WinUsb - ok
01:27:34.0019 0x1640 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
01:27:34.0034 0x1640 Wlansvc - ok
01:27:34.0175 0x1640 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
01:27:34.0190 0x1640 wlidsvc - ok
01:27:34.0253 0x1640 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
01:27:34.0253 0x1640 WmiAcpi - ok
01:27:34.0299 0x1640 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
01:27:34.0299 0x1640 wmiApSrv - ok
01:27:34.0362 0x1640 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
01:27:34.0377 0x1640 WMPNetworkSvc - ok
01:27:34.0393 0x1640 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\windows\System32\wpcsvc.dll
01:27:34.0393 0x1640 WPCSvc - ok
01:27:34.0424 0x1640 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
01:27:34.0424 0x1640 WPDBusEnum - ok
01:27:34.0440 0x1640 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
01:27:34.0440 0x1640 ws2ifsl - ok
01:27:34.0471 0x1640 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\windows\System32\wscsvc.dll
01:27:34.0471 0x1640 wscsvc - ok
01:27:34.0471 0x1640 WSearch - ok
01:27:34.0565 0x1640 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
01:27:34.0580 0x1640 wuauserv - ok
01:27:34.0611 0x1640 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
01:27:34.0611 0x1640 WudfPf - ok
01:27:34.0643 0x1640 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
01:27:34.0643 0x1640 WUDFRd - ok
01:27:34.0689 0x1640 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\windows\System32\WUDFSvc.dll
01:27:34.0689 0x1640 wudfsvc - ok
01:27:34.0705 0x1640 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\windows\System32\wwansvc.dll
01:27:34.0721 0x1640 WwanSvc - ok
01:27:34.0721 0x1640 xhunter1 - ok
01:27:34.0767 0x1640 [ 4CA7D86C6B1BDDE03C0088A1FBAE9D3F ] xsherlock C:\windows\xsherlock.xem
01:27:34.0783 0x1640 xsherlock - ok
01:27:34.0830 0x1640 [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7 C:\windows\system32\DRIVERS\yk62x86.sys
01:27:34.0830 0x1640 yukonw7 - ok
01:27:34.0845 0x1640 ================ Scan global ===============================
01:27:34.0861 0x1640 [ 9A595DF601070DA78C40481120DD2C06 ] C:\windows\system32\basesrv.dll
01:27:34.0939 0x1640 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:27:34.0939 0x1640 [ 8531AAF69394EFB93BC653916C46D245 ] C:\windows\system32\winsrv.dll
01:27:34.0955 0x1640 [ 364455805E64882844EE9ACB72522830 ] C:\windows\system32\sxssrv.dll
01:27:34.0986 0x1640 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\windows\system32\services.exe
01:27:34.0986 0x1640 [Global] - ok
01:27:34.0986 0x1640 ================ Scan MBR ==================================
01:27:35.0017 0x1640 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
01:27:35.0516 0x1640 \Device\Harddisk0\DR0 - ok
01:27:35.0516 0x1640 ================ Scan VBR ==================================
01:27:35.0532 0x1640 [ 858CC5A24FD61FFA558376040673AEE4 ] \Device\Harddisk0\DR0\Partition1
01:27:35.0532 0x1640 \Device\Harddisk0\DR0\Partition1 - ok
01:27:35.0579 0x1640 [ B3B375D5F0E2AF118828E4624AD1527B ] \Device\Harddisk0\DR0\Partition2
01:27:35.0579 0x1640 \Device\Harddisk0\DR0\Partition2 - ok
01:27:35.0610 0x1640 [ 7756FDF06E6D9BE0977D4C949641D1C6 ] \Device\Harddisk0\DR0\Partition3
01:27:35.0610 0x1640 \Device\Harddisk0\DR0\Partition3 - ok
01:27:35.0610 0x1640 ============================================================
01:27:35.0610 0x1640 Scan finished
01:27:35.0610 0x1640 ============================================================
01:27:35.0625 0x1e34 Detected object count: 0
01:27:35.0625 0x1e34 Actual detected object count: 0
01:28:02.0957 0x0f68 Deinitialize success
  • 宵子
  • 2013/08/21 (Wed) 01:47:07
aswMBRとAdwcleanerで
ログを見ると、初回にTDSS Killerを走らせたときに、Cidox.bの方はCureされていたようですね。
もう1つの方はSkipされているので判断が難しいところですが、こちらはジェネリック検知(「既存のルートキットと似ている」ものを検知)なので、同時に修復されたのかもしれません。念のため、aswMBRをもう一度実行してみます。


■aswMBRによるログの取得
以下のファイルをダウンロードし、デスクトップ等に置いてください。
http://public.avast.com/~gmerek/aswMBR.exe

ダウンロード後、実行すると、英語で「定義ファイルをダウンロードしますか?」と聞いてきます。数分~10分程度かかりますが、「はい」でダウンロードしてください。
起動したら、「Scan」を押し、数分待つとスキャンが完了します。完了したら、「Save Log」をクリックし、ログをデスクトップへ保存してください。
その後、ログをこちらに投稿してください。



それから、広告が残っているとのことですので、念のためAdwcleaner(アドウェア専門駆除ツール)も実行しておきましょう。


■AdwCleanerでの処置
以下のアドレスから、AdwCleanerをダウンロードして、デスクトップに置いてください。
http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner

ファイルを起動後、「Delete」をクリックしてください。
出てきた画面で「はい」を押すと、全てのプロセスが強制終了されたうえで、駆除が実行されます。
再起動を要求する画面が出たら「OK」などで再起動してください。
再起動後、ログが出ますので、その内容を同様に貼り付けてください。
  • イルカ
  • 2013/08/21 (Wed) 09:00:58
Re:aswMBRとAdwcleanerで
おはようございます。

aswMBRは何度か試してみても動作が途中で終了してしまい、ログ採取を完了できませんでした。

Adwcleanerのほうは、「delete」がないが「clean」はありました。同様の意味だろうと判断し、「scan」→「clean」と実行しました。そのログは以下に貼り付けます。

# AdwCleaner v3.000 - Report created 21/08/2013 at 11:14:44
# Updated 20/08/2013 by Xplode
# Operating System : Windows 7 Home Premium (32 bits)
# Username : PCUser - ICEPC
# Running from : C:\Users\PCUser\Pictures\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\heoldelcflnigdllmlopiefhkkobendj

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.17267


*************************

AdwCleaner[R0].txt - [714 octets] - [21/08/2013 11:14:17]
AdwCleaner[S0].txt - [638 octets] - [21/08/2013 11:14:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [697 octets] ##########


指示された通りにはいきませんでしたが、今後の対処をご指導いただけますでしょうか。
よろしくお願いします。
  • 宵子
  • 2013/08/21 (Wed) 11:23:00
Re: 広告が出てきて困っています。
現在はウイルスバスターが入っているのですね?
お手数ですが、一度ウイルスバスターをアンインストールし、Microsoft Security Essentialsに戻して、Trojan.DOS/Rovnix.Dが検知されるかどうか、確認してください。

また、広告がまだ治っていないようなので、さらに別なツールで見てみます。
なかなかしつこい広告ですが、これから念のため、見落としが無いかもう1度OTLログを確認してみます。


■Malwarebytes Anti-Malwareによる検査
以下のURLから、Malwarebytes Anti-Malwareをダウンロードしてください。
ページを開けて数秒で、ダウンロードが始まるはずです。
http://download.cnet.com/Malwarebytes-Anti-Malware/3001-8022_4-10804572.html?spi=bf35d12b0e6385b003099cb173de4a7d&part=dl-10804572

インストール・使い方に関しては、こちらを参考にしてください。
http://fine.tok2.com/home/heto2/0700SecurityApp/Malwarebytes/0001.htm

インストール時に表示をよく見ると、「Pro版を使用する」というチェックがあります。これを外しておけば、無料版としてインストールされます。

定義ファイルをアップデートしたら、「Perform full scan」でフルスキャンを実行してください。
その後、表示される結果をこちらにコピー&ペーストで貼り付けてください。
  • イルカ
  • 2013/08/21 (Wed) 21:59:58
MSE、Malwarebytes Anti-Malwareの結果
イルカさん、こんばんは。
adwclenerをかけて朝にレスしてから、なぜか広告が出なくなっています。

それから、こちらのOSはwin7ですが、SP1を未導入でしたのでインストールし、IE8をIE10にしたほか、MicrosoftOfficeのSP2のアップデートもされました。他にBingの導入と、Dドライブへのデバックシンボルの導入も行っています。

そのあとにMSEで、以前に検出したときと同じくクイックスキャンでは「Trojan.DOS/Rovnix.D」は検出されませんでした。しかし先ほど「脅威を検出しました」と出たのでログを見れば「Trojan.DOS/Rovnix.D」があり、「検疫済み」となっています。


次に、Malwarebytes Anti-Malwareの結果を貼ります。

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.21.04

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
PCUser :: ICEPC [administrator]

2013/08/21 22:27:51
MBAM-log-2013-08-22 (00-53-31).txt

Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 477760
Time elapsed: 2 hour(s), 25 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 11
HKCR\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4} (Adware.CnsMin) -> No action taken.
HKCR\TypeLib\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267} (Adware.CnsMin) -> No action taken.
HKCR\Interface\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68} (Adware.CnsMin) -> No action taken.
HKCR\CnsHelper.CH.1 (Adware.CnsMin) -> No action taken.
HKCR\CnsHelper.CH (Adware.CnsMin) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B83FC273-3522-4CC6-92EC-75CC86678DA4} (Adware.CnsMin) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CnsMin (Adware.CnsMin) -> No action taken.
HKCU\SOFTWARE\3721 (PUP.BitSpirit) -> No action taken.
HKCU\Software\DC3_FEXEC (Malware.Trace) -> No action taken.
HKLM\SOFTWARE\3721 (PUP.BitSpirit) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS (Adware.CnsMin) -> No action taken.

Registry Values Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CnsMin (Adware.CnsMin) -> Data: Rundll32.exe C:\windows\DOWNLO~1\CnsMin.dll,Rundll32 -> No action taken.
HKCU\Software\Microsoft\Internet Explorer\Main|CNSReset (Adware.CnsMin) -> Data: 3335883513 -> No action taken.
HKCU\Software\Microsoft\Internet Explorer\Main|CNSHint (Adware.CnsMin) -> Data: 1 -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\PCUser\AppData\Roaming\dclogs (Stolen.Data) -> No action taken.

Files Detected: 20
C:\Windows\Downloaded Program Files\CnsMin.dll (Adware.CnsMin) -> No action taken.
C:\Program Files\Veoh Networks\VeohWebPlayer\qlps-qlipso-sntb.exe (PUP.Optional.SweetPacks.A) -> No action taken.
C:\Program Files\Veoh Networks\VeohWebPlayer\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\PCUser\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_ja.cab (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-21-4.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-22-5.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-23-6.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-24-7.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-25-1.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-26-2.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-27-3.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-28-4.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-29-5.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-30-6.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-01-7.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-02-1.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-03-2.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-04-3.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-05-4.dc (Stolen.Data) -> No action taken.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-06-5.dc (Stolen.Data) -> No action taken.

(end)

素人のゆるい感想ですが、けっこうかかっているのではないかと思います。
引き続き、ご指導よろしくお願いいたします。
  • 宵子
  • 2013/08/22 (Thu) 00:54:26
追加
勝手な行動をして申し訳ないですが、スキャンして出たもの全てにチェックを入れて、削除を実行しました。ネットセキュリティブログを参照したところ、当ソフトの使い方として、スキャン後に削除せよとのことでしたので、それに従いました。

以下、削除後に出たログです。

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.21.04

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
PCUser :: ICEPC [administrator]

2013/08/21 22:27:51
mbam-log-2013-08-21 (22-27-51).txt

Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 477760
Time elapsed: 2 hour(s), 25 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 11
HKCR\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4} (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCR\TypeLib\{AAB6BCE3-1DF6-4930-9B14-9CA79DC8C267} (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCR\Interface\{DF692509-D9EF-48A0-9CD0-3AA5B81F6F68} (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCR\CnsHelper.CH.1 (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCR\CnsHelper.CH (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B83FC273-3522-4CC6-92EC-75CC86678DA4} (Adware.CnsMin) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CnsMin (Adware.CnsMin) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\3721 (PUP.BitSpirit) -> Quarantined and deleted successfully.
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\3721 (PUP.BitSpirit) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS (Adware.CnsMin) -> Quarantined and deleted successfully.

Registry Values Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CnsMin (Adware.CnsMin) -> Data: Rundll32.exe C:\windows\DOWNLO~1\CnsMin.dll,Rundll32 -> Quarantined and deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main|CNSReset (Adware.CnsMin) -> Data: 3335883513 -> Quarantined and deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main|CNSHint (Adware.CnsMin) -> Data: 1 -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\Users\PCUser\AppData\Roaming\dclogs (Stolen.Data) -> Quarantined and deleted successfully.

Files Detected: 20
C:\Windows\Downloaded Program Files\CnsMin.dll (Adware.CnsMin) -> Delete on reboot.
C:\Program Files\Veoh Networks\VeohWebPlayer\qlps-qlipso-sntb.exe (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Veoh Networks\VeohWebPlayer\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_ja.cab (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-21-4.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-22-5.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-23-6.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-24-7.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-25-1.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-26-2.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-27-3.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-28-4.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-29-5.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-11-30-6.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-01-7.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-02-1.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-03-2.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-04-3.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-05-4.dc (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\PCUser\AppData\Roaming\dclogs\2012-12-06-5.dc (Stolen.Data) -> Quarantined and deleted successfully.

(end)
  • 宵子
  • 2013/08/22 (Thu) 01:42:15
Re: 広告が出てきて困っています。
> 勝手な行動をして申し訳ないですが、スキャンして出たもの全てにチェックを入れて、削除を実行しました。ネットセキュリティブログを参照したところ、当ソフトの使い方として、スキャン後に削除せよとのことでしたので、それに従いました。
いえ、それで大丈夫です。どのみち駆除が必要でした。

> C:\Users\PCUser\AppData\Roaming\dclogs (Stolen.Data) -> Quarantined and deleted successfully.
あまりよろしいエントリではなさそうですね…。
日付を見ると去年の末で止まってますが、このあたりでウイルスの警告とか出ませんでしたか?

いずれにせよ、このStolen.Dataは典型的なスパイウェアがその残骸として残すファイルを検知しているそうなので、コンピュータ上のデータが一部流出した可能性があります。
各種サイトで使っているパスワード等は、できればこのコンピュータ以外のPCから、変更することをお勧めします。
また、オンラインショッピングなどを使用されていた場合は、クレジットカードの履歴等も確認されると良いでしょう。


広告自体は
> adwclenerをかけて朝にレスしてから、なぜか広告が出なくなっています。
とのことですので、Adwcleanerが1件だけ駆除した項目があるのですが、これがクロだったのかもしれません。
これに関してはまだ保留ですね。

SP1を入れてからも、相変わらずaswMBRは実行できませんか?
  • イルカ
  • 2013/08/22 (Thu) 08:48:27
Re:追加報告
>> C:\Users\PCUser\AppData\Roaming\dclogs (Stolen.Data) -> Quarantined and deleted successfully.
あまりよろしいエントリではなさそうですね…。日付を見ると去年の末で止まってますが、このあたりでウイルスの警告とか出ませんでしたか?

 特にそのような警告が出たような記憶はありません。当時からMSEは入れていたと思いますが、「プロセスをブロックしました」のようなものなら、出たかもしれません。


>各種サイトで使っているパスワード等は、できればこのコンピュータ以外のPCから、変更することをお勧めします。
また、オンラインショッピングなどを使用されていた場合は、クレジットカードの履歴等も確認されると良いでしょう。

 随時パスワードは変更していきます。クレジットカードは持っていないので、後半については大丈夫でしょう。


>SP1を入れてからも、相変わらずaswMBRは実行できませんか?

 何度か試しましたが、途中で動作を停止してしまいます。動作中に黄色の文字が出たところがあったので、それを貼り付けます。

12:35:39.894 Service MpKsl605b9dcb C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{090E4C0E-A7E5-4917-9FFD-251FEB0A6370}\MpKsl605b9dcb.sys **LOCKED** 32

 また、動作を停止してから再び起動すると、次のようなログが出ることもあったので、あわせて貼っておきます。

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-08-22 12:28:45
-----------------------------
12:28:45.877 OS Version: Windows 6.1.7601 Service Pack 1
12:28:45.877 Number of processors: 4 586 0x2505
12:28:45.877 ComputerName: ICEPC UserName:
12:28:47.094 Initialze error C000010E - driver not loaded
12:28:47.296 write error "aswCmnB.dll". プロセスはファイルにアクセスできません。別のプロセスが使用中です。
12:28:47.452 AVAST engine defs: 13082100
12:29:03.068 The log file has been saved successfully to "C:\Users\PCUser\Pictures\Desktop\aswMBR.txt"

引き続き、よろしくお願いいたします。
  • 宵子
  • 2013/08/22 (Thu) 13:01:31
Re: 広告が出てきて困っています。
今でもRovnix.Dが出てくるという状況ですね?

直接、ブートレコードの修復に取り組むしかなさそうですね。
Windows 7ですので、比較的簡単でしょう。


http://pasofaq.jp/controlpanel/nusrmgr/7restration.htm
のウェブサイトを印刷し、手元で見られるようにしてください。

コンピュータを再起動後、上記の手順に従って、「システム回復オプション」画面を開いてください。

その画面から、「コマンドプロンプト」を開いてください。

次に、以下のコマンドを打ち込んで「Enter」キーを押してください。

bootrec /fixboot

「bootrec」と「/fixboot」の間には半角スペースが入ります。


作業が完了したら、コマンドプロンプトを閉じて、コンピュータを再起動してください。
その後、Rovnix.Dが現れるか見てください。
  • イルカ
  • 2013/08/22 (Thu) 20:16:44
Re: システム回復オプションについて
PC再起動の時に、F8キーを押して、「コンピューターの修復」を選び、「システム回復オプション」は開けました。

しかし、Administratorと普段ログインしているローカルユーザーのどちらで「システム回復オプション」を開いても、「スタートアップ修復」と「システムの復元」しか項目がありませんでした。

コマンドプロンプトが表示されないのですが、どのようにしたらよいでしょうか。
  • 宵子
  • 2013/08/22 (Thu) 21:07:04
Re: 広告が出てきて困っています。
> 「スタートアップ修復」と「システムの復元」しか項目がありませんでした

普通はあるんですが…。


仕方がないので、空のCDかDVDを1枚用意して頂いて、そこから起動するしかなさそうですね。

http://windows.microsoft.com/ja-jp/windows7/create-a-system-repair-disc
にCD/DVDを使ったシステム回復オプションの起動方法が載っています。
  • イルカ
  • 2013/08/22 (Thu) 21:37:42
修復ディスクもダメでした。
「コントロールパネル」→「バックアップの作成」→「システム修復ディスクの作成」で、DVDを用いて修復ディスクを作成しました。

作成後、ディスクを入れたままでF8キーから「コンピューターの修復」を選択しましたが、先ほどと同じで「コマンドプロンプト」はありません。

次に、ディスクを入れたまま、DVDからの起動を試みました。こちらは「スタートアップ修復」や「システムの復元」の選択をすることなく、すぐに「システムの復元」に移動しました。


指示された通りにできてないのかもしれませんが、やはりコマンドプロンプトがいまだ出現させられません。


修復ディスクの作り方がダメだったのか、使い方が悪かったのか。そもそも、F8キーから「コンピューターの修復」を選択した際の、言語やキーボード選択、ユーザー選択に問題があったのでしょうか。「日本語」「MicrosoftIME」、ユーザーは「Administrator」にしています。

ご助力をお願いできますでしょうか。よろしくお願いします。
  • 宵子
  • 2013/08/22 (Thu) 22:18:24
Re: 広告が出てきて困っています。
作り方・使い方は問題ないと思いますが、なぜだか使う方法がことごとく駄目ですね…。
なかなか解決に持っていけなくて申し訳ないです。

現在の懸念はRovnix.Dだけなので、これが駆除できていることが確認できる(他のソフトで検知されない)、あるいは駆除を確信できる(コマンドプロンプトから、MBRを正規のもので上書きする)状況になれば、終了なのですが…。



お使いのPCのメーカーと型番を教えて頂けますか?
システムの構成と構造を少し調べてみます。


また、Rovnix.Dを検知できるかどうかは分かりませんが、別なツールで確認を取ってみましょう。


■RougeKillerによる検査
以下のURLからRougeKillerをダウンロードし、デスクトップに置いてください。
ブラウザから危険判定されるかもしれませんが、誤検知ですので無視して進めてください。
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe

その後、以下の操作を行ってください。
1. 可能な限りすべてのアプリを終了してください。
2. デスクトップに保存したRougeKillerを起動し、初期スキャン完了まで待ってください。
3. 初期スキャンが終了したら、「Scan」ボタンをクリックし、スキャンが終わるまで待ってください。
4. デスクトップには「RKReport.txt」が作成されているはずです。この中身を、本文に貼り付けてください。
5. ソフトは終了して構いません。閉じる際に英語で「検知されたアイテムを削除しますか?」と聞かれますが、今は「いいえ」で閉じてください。
  • イルカ
  • 2013/08/22 (Thu) 23:03:31
PCの型番とRougeKillerの報告
ことごとくうまくいきませんで、お手数おかけいたしまして申し訳ありません。

使用しているPCですが、FUJITSUのLIFEBOOK SH560/3Bです。型名はFMVS563BBです。


次にRougeKillerの結果を貼ります。

RogueKiller V8.6.6 [Aug 19 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : PCUser [Admin rights]
Mode : Scan -- Date : 08/22/2013 23:10:55
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD6400BPVT-16HXZT1 +++++
--- User ---
[MBR] 7071e876d978c79956b95631e6467043
[BSP] 851addace4f494ab8c8a152f7ff3d188 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 30720 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 62916608 | Size: 200 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63326208 | Size: 289779 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 656793600 | Size: 289779 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_08222013_231055.txt >>



よろしくお願いします。
  • 宵子
  • 2013/08/22 (Thu) 23:24:28
確認しますので少しお待ちを
RougeKillerでは何も出なかったようですね。これ自体は良い結果です。

機種がLIFEBOOKということで、調べてみると私のPCとほぼ同世代の機種でした。今は使用しているので確認できませんが、明日(今日?)にでも再起動して画面を確認します。少しお待ちください。
  • イルカ
  • 2013/08/23 (Fri) 01:32:58
よろしくお願いします。
何か2件発見されたようですが、それは大丈夫なのでしょうか。Bad processesが0なのでいいのでしょうか。

ご面倒をおかけいたしますが、ご尽力感謝しております。
明日まで待ちますのでよろしくお願いします。
  • 宵子
  • 2013/08/23 (Fri) 01:54:03
Re: 広告が出てきて困っています。
RougeKillerの2件の検知ですが、RougeKillerはかなり感度良く構成されているので、問題ないエントリでも「標準から外れている」となれば検知してきます。
ただの設定を誤検知する場合もあるので、これは置いておきます。


先ほど再起動して確認しましたが、どうやら富士通がコマンドプロンプトを表示しないよう、回復オプションの設定を上書きしてしまっているようです。
丁寧な復旧ツールが付属するのはいいのですが、標準機能を隠すというのも困りものです。

この仕様ではコマンドプロンプトを呼び出すのは無理なので、MBRを上書するにはかなり面倒な作業が必要になります。
今の方針は諦めるしかなさそうです。


現在でもRovnix.Dは検知され続けていますか?
再度TDSS Killerで確認して、MSEでもTDSS Killerでも何も出ていないのであれば、駆除されたとみなしましょう。
2つ以上のソフト(可能であれば駆除を実施したもの=TDSS Killerとは違うソフトが良いのですが、aswMBRが動かないことには…)で検査して何も出ないのであれば、正常と判断できますので。
  • イルカ
  • 2013/08/23 (Fri) 09:12:40
2ソフトによる結果
TDSS Killerでは何も検出しませんでした。MSEは、クイックスキャンでは何も検出しませんでしたが、フルスキャンで「Rovnix.D」を検出しました。詳細を見ると、項目のところに

C:\TDSSKiller_Quarantine\21.08.2013_00.29.14\boot0000\tsk0000.dta

がありました。


現在はそのままにしてありますが、これを手動で削除すればよいのでしょうか。
  • 宵子
  • 2013/08/23 (Fri) 15:26:45
大丈夫そうですね
検知されたのは駆除時に作成された隔離ファイルなので、削除してしまえば問題ありません。
何とか直ったようですね。長らくお疲れ様でした。

簡単ですが、後片付けについて案内します。


■後片付け
使ったツールを削除します。

・Malwarebytes Anti-Malware
コントロールパネルから、アンインストールしてください。

・OTL
OTLを起動後、上側にある「Clean Up」ボタンを押してください。
OTL自身も自動的に削除されます。

・AdwCleaner
起動後、画面右下にある「Uninstall」を押してください。
本当に削除するかと聞かれるので、「はい」を押すとウィンドウが閉じ、ログなどの関連ファイルがまとめて削除されます。

・RougeKiller
・TDSS Killer
・aswMBR
ダウンロードしたファイルをそのまま削除してください。


■転ばぬ先の杖
以下のリンク先の記載内容も、参考にされるとよいかと思います。
http://www.higaitaisaku.com/korobanu.html


何かありましたらまた返信をください。
  • イルカ
  • 2013/08/23 (Fri) 21:11:00
ありがとうございました。
イルカさん、本当にありがとうございました。

どうにも長らくwindowsもそうですが、いくつかアップデートをしていないものがあったようで、もしかするとそれが今回の主因かもしれません。

この度は大変なご迷惑をおかけいたしましたが、お陰様で対処することができました。
今回の件を教訓とし、よく反省しておきます。


改めて、本当にありがとうございました。
  • 宵子
  • 2013/08/23 (Fri) 21:38:18

返信フォーム






プレビュー (投稿前に内容を確認)