Malware

Résolu
Bonjour
J'ai des alertes de l'antivirus AVAST qui met un fichier en quarantaine :
Fichier: networker.exe C\ Program. Files\ Installer Win32: Malware-gen

Comment puis-je régler simplement ce problème ?

Dans le disque C. Programme Files(x86) j'ai:
Inetworker. Modifié le 14-12-2010 Application 7 KO
Puis-je le supprimer sans risque?

Merci de me répondre.

Ordinateur HP, Windows 7

31 réponses

Résumé de la discussion

Problème central: Avast signale le fichier networker.exe comme Malware-gen et le place en quarantaine sur un PC HP sous Windows 7, intriguant l'utilisateur qui se demande s'il peut le supprimer sans risque. Des éléments de réponse privilégient une approche prudente: redémarrer le système puis relancer un outil de diagnostic (OTL) avant toute suppression afin d'évaluer si le fichier est réellement nuisible. Une autre intervention fournit un rapport OTL détaillé répertoriant les processus, modules et services actifs, notamment Avast et des composants Windows et HP, pour vérifier l'origine et les interactions du fichier. En cas de doute persistant, des observations techniques indiquent que des détections peuvent être des fausses alertes et nécessitent une vérification croisée avant toute suppression.

Bobot (l’IA à votre service)
  1. salut

    ▶ Télécharge ici : Ad-remover sur ton bureau :

    ▶ Déconnecte toi et ferme toutes applications en cours !

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

    ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

    ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport qui apparait à la fin , sur le forum ...

    ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    0
    1. Bonsoir, Voici le rapport

      ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

      Mis à jour par TeamXscript le 16/01/11 à 02:00
      Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
      Site web: http://www.teamxscript.org

      C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [2]) -> Lancé à 20:08:27 le 17/01/2011, Mode normal

      Microsoft Windows 7 Édition Familiale Premium (X64)
      JEAN@JEAN-HP (Hewlett-Packard p6514fr)

      ============== ACTION(S) ==============

      (!) -- Fichiers temporaires supprimés.

      ============== SCAN ADDITIONNEL ==============

      ** Internet Explorer Version [8.0.7600.16385] **

      [HKCU\Software\Microsoft\Internet Explorer\Main]
      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Do404Search: 0x01000000
      Enable Browser Extensions: yes
      Local Page: C:\Windows\system32\blank.htm
      Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
      Show_ToolBar: yes
      Start Page: hxxp://fr.msn.com/
      Use Search Asst: no

      [HKLM\Software\Microsoft\Internet Explorer\Main]
      AutoHide: yes
      Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Delete_Temp_Files_On_Exit: yes
      Enable Browser Extensions: yes
      Local Page: C:\Windows\SysWOW64\blank.htm
      Search bar: hxxp://search.msn.com/spbasic.htm
      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Start Page: hxxp://fr.msn.com/
      Use Search Asst: no

      [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
      Tabs: res://ieframe.dll/tabswelcome.htm
      Blank: res://mshtml.dll/blank.htm

      ========================================

      C:\Program Files (x86)\Ad-Remover\Quarantine: 39 Fichier(s)
      C:\Program Files (x86)\Ad-Remover\Backup: 16 Fichier(s)

      C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (2729 Octet(s))
      C:\Ad-Report-CLEAN[2].txt - 17/01/2011 (1911 Octet(s))

      Fin à: 20:09:11, 17/01/2011

      ============== E.O.F ==============

      Merci de me donner la conduite à tenir
      0
      1. je peux lire celui-ci ? :

        C:\Ad-Report-CLEAN[1].txt
        0
        1. Re bonsoir,
          Je n'ai pas compris la réponse.
          Que dois-je faire ?
          0
          1. coller le contenu du rapport demandé deux posts plus haut
            0
            1. Encore une fois désolé , je ne comprends rien à le réponse . Détaillez-moi de façon simple ce que je dois faire.
              Je suis un Papi peu doué en informatique.
              Merci
              0
              1. dans ton disque dur dans ton poste de travail , il y a ce fichier

                C:\Ad-Report-CLEAN[1].txt

                ouvre-le et colle son contenu
                0
                1. OK, voici le contenu

                  ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

                  Mis à jour par TeamXscript le 16/01/11 à 02:00
                  Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                  Site web: http://www.teamxscript.org

                  C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 20:03:28 le 17/01/2011, Mode normal

                  Microsoft Windows 7 Édition Familiale Premium (X64)
                  JEAN@JEAN-HP (Hewlett-Packard p6514fr)

                  ============== ACTION(S) ==============

                  Service: "sdmBackupIP" Stoppé et supprimé

                  Dossier supprimé: C:\Program Files (x86)\Installer
                  Fichier supprimé: C:\Windows\SysWOW64\Utils.dll
                  Dossier supprimé: C:\Windows\BackupIP
                  Dossier supprimé: C:\Users\JEAN\AppData\LocalLow\PriceGong
                  Dossier supprimé: C:\Users\JEAN\AppData\Local\networker

                  (!) -- Fichiers temporaires supprimés.

                  Clé supprimée: HKLM\Software\Install Pedia Limited
                  Clé supprimée: HKCU\Software\AppDataLow\Software\PriceGong
                  Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                  Clé supprimée: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                  Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}

                  ============== SCAN ADDITIONNEL ==============

                  ** Internet Explorer Version [8.0.7600.16385] **

                  [HKCU\Software\Microsoft\Internet Explorer\Main]
                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Do404Search: 0x01000000
                  Enable Browser Extensions: yes
                  Local Page: C:\Windows\system32\blank.htm
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  Show_ToolBar: yes
                  Start Page: hxxp://fr.msn.com/
                  Use Search Asst: no

                  [HKLM\Software\Microsoft\Internet Explorer\Main]
                  AutoHide: yes
                  Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Delete_Temp_Files_On_Exit: yes
                  Enable Browser Extensions: yes
                  Local Page: C:\Windows\SysWOW64\blank.htm
                  Search bar: hxxp://search.msn.com/spbasic.htm
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Start Page: hxxp://fr.msn.com/
                  Use Search Asst: no

                  [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                  Tabs: res://ieframe.dll/tabswelcome.htm
                  Blank: res://mshtml.dll/blank.htm

                  ========================================

                  C:\Program Files (x86)\Ad-Remover\Quarantine: 39 Fichier(s)
                  C:\Program Files (x86)\Ad-Remover\Backup: 14 Fichier(s)

                  C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (2599 Octet(s))

                  Fin à: 20:04:54, 17/01/2011

                  ============== E.O.F ==============
                  merci de me donner la conduite à tenir
                  0
                  1. parfait

                    Télécharge ici :OTL

                    ▶ enregistre le sur ton Bureau.

                    si tu as XP => double clique
                    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                    sur OTL.exe pour le lancer.

                    ▶ Coche les 2 cases Lop et Purity

                    ▶ Coche la case devant tous les utilisateurs

                    ▶ règle age du fichier sur "60 jours"

                    ▶ dans les 6 onglets de la moitié gauche , mets tout sur "tous"

                    ne modifie pas ceci :

                    "fichiers créés" et "fichiers Modifiés"


                    ▶Clic sur Analyse.

                    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                    ▶▶▶ NE LE POSTE PAS SUR LE FORUM

                    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                    ▶ Clique sur Ouvrir.

                    ▶ Clique sur "Cliquez ici pour déposer le fichier".

                    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

                    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                    ▶ Copie ce lien dans ta réponse.

                    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
                    0
                    1. Voici le lien demandé

                      http://www.cijoint.fr/cjlink.php?file=cj201101/cijGwfv1Hy.txt

                      http://www.cijoint.fr/cjlink.php?file=cj201101/cij0YAEx58.txt

                      J'espère que c'est bon.
                      Merci de poursuivre
                      0
                      1. fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                        ▶ Télécharge ici :

                        Malwarebytes

                        ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                        (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                        ▶ Potasses le Tuto pour te familiariser avec le prg :

                        ( cela dit, il est très simple d'utilisation ).

                        relance malwarebytes en suivant scrupuleusement ces consignes :

                        ! Déconnecte toi et ferme toutes applications en cours !

                        ▶ Lance Malwarebyte's .

                        Fais un examen dit "Complet" .

                        ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                        ▶ à la fin tu cliques sur "résultat" .
                        ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                        ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                        ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                        0
                        1. Bien, j'ai téléchargé Malwarebytes et vu que l'examen complet est très long.
                          Vu l'heure, je poursuivrai demain et donnerai ma réponse dès que possible
                          Encore grand merci et à demain pour la suite.
                          0
                          1. Bonjour,
                            Voici le rapport de l'examen complet de Malwarebytes.
                            Je n'ai pas trouvé d'objets infectés à supprimer.

                            Malwarebytes' Anti-Malware 1.50
                            www.malwarebytes.org

                            Version de la base de données: 5542

                            Windows 6.1.7600
                            Internet Explorer 8.0.7600.16385

                            18/01/2011 07:39:29
                            mbam-log-2011-01-18 (07-39-29).txt

                            Type d'examen: Examen complet (C:\|D:\|)
                            Elément(s) analysé(s): 296012
                            Temps écoulé: 22 minute(s), 5 seconde(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            J'attends la conduite à tenir et bonne journée
                            0
                            1. salut repasse AD-Remover nettoyage en mode sans echec stp
                              0
                              1. Bonjour, voici AD- Remover en mode sans échec

                                ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

                                Mis à jour par TeamXscript le 16/01/11 à 02:00
                                Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                                Site web: http://www.teamxscript.org

                                C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [3]) -> Lancé à 12:55:27 le 18/01/2011, Mode sans echec

                                Microsoft Windows 7 Édition Familiale Premium (X64)
                                JEAN@JEAN-HP (Hewlett-Packard p6514fr)

                                ============== ACTION(S) ==============

                                (!) -- Fichiers temporaires supprimés.

                                ============== SCAN ADDITIONNEL ==============

                                ** Internet Explorer Version [8.0.7600.16385] **

                                [HKCU\Software\Microsoft\Internet Explorer\Main]
                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Do404Search: 0x01000000
                                Enable Browser Extensions: yes
                                Local Page: C:\Windows\system32\blank.htm
                                Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                Show_ToolBar: yes
                                Start Page: hxxp://fr.msn.com/
                                Use Search Asst: no

                                [HKLM\Software\Microsoft\Internet Explorer\Main]
                                AutoHide: yes
                                Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Delete_Temp_Files_On_Exit: yes
                                Enable Browser Extensions: yes
                                Local Page: C:\Windows\SysWOW64\blank.htm
                                Search bar: hxxp://search.msn.com/spbasic.htm
                                Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Start Page: hxxp://fr.msn.com/
                                Use Search Asst: no

                                [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                                Tabs: res://ieframe.dll/tabswelcome.htm
                                Blank: res://mshtml.dll/blank.htm

                                ========================================

                                C:\Program Files (x86)\Ad-Remover\Quarantine: 39 Fichier(s)
                                C:\Program Files (x86)\Ad-Remover\Backup: 30 Fichier(s)

                                C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (2729 Octet(s))
                                C:\Ad-Report-CLEAN[2].txt - 17/01/2011 (2041 Octet(s))
                                C:\Ad-Report-CLEAN[3].txt - 18/01/2011 (0 Octet(s))

                                Fin à: 12:56:16, 18/01/2011

                                ============== E.O.F ==============
                                0
                                1. je peux lire ce rapport-ci ?

                                  C:\Ad-Report-CLEAN[2].txt
                                  0
                                  1. voici le rapport

                                    ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

                                    Mis à jour par TeamXscript le 16/01/11 à 02:00
                                    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                                    Site web: http://www.teamxscript.org

                                    C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [2]) -> Lancé à 20:08:27 le 17/01/2011, Mode normal

                                    Microsoft Windows 7 Édition Familiale Premium (X64)
                                    JEAN@JEAN-HP (Hewlett-Packard p6514fr)

                                    ============== ACTION(S) ==============

                                    (!) -- Fichiers temporaires supprimés.

                                    ============== SCAN ADDITIONNEL ==============

                                    ** Internet Explorer Version [8.0.7600.16385] **

                                    [HKCU\Software\Microsoft\Internet Explorer\Main]
                                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                    Do404Search: 0x01000000
                                    Enable Browser Extensions: yes
                                    Local Page: C:\Windows\system32\blank.htm
                                    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                    Show_ToolBar: yes
                                    Start Page: hxxp://fr.msn.com/
                                    Use Search Asst: no

                                    [HKLM\Software\Microsoft\Internet Explorer\Main]
                                    AutoHide: yes
                                    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                    Delete_Temp_Files_On_Exit: yes
                                    Enable Browser Extensions: yes
                                    Local Page: C:\Windows\SysWOW64\blank.htm
                                    Search bar: hxxp://search.msn.com/spbasic.htm
                                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                    Start Page: hxxp://fr.msn.com/
                                    Use Search Asst: no

                                    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                                    Tabs: res://ieframe.dll/tabswelcome.htm
                                    Blank: res://mshtml.dll/blank.htm

                                    ========================================

                                    C:\Program Files (x86)\Ad-Remover\Quarantine: 39 Fichier(s)
                                    C:\Program Files (x86)\Ad-Remover\Backup: 16 Fichier(s)

                                    C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (2729 Octet(s))
                                    C:\Ad-Report-CLEAN[2].txt - 17/01/2011 (1911 Octet(s))

                                    Fin à: 20:09:11, 17/01/2011

                                    ============== E.O.F ==============
                                    0
                                    1. redemarre ton pc et refais OTL avant toute autre action
                                      0
                                      1. voici le rapport OTL.

                                        OTL logfile created on: 1/18/2011 2:24:56 PM - Run 2
                                        OTL by OldTimer - Version 3.2.20.2 Folder = C:\Users\JEAN\Documents\Downloads
                                        64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
                                        Internet Explorer (Version = 8.0.7600.16385)
                                        Locale: 00000409 | Country: France | Language: FRA | Date Format: dd/MM/yyyy

                                        4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 73.00% Memory free
                                        8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
                                        Paging file location(s): ?:\pagefile.sys [binary data]

                                        %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
                                        Drive C: | 453.17 Gb Total Space | 410.73 Gb Free Space | 90.64% Space Free | Partition Type: NTFS
                                        Drive D: | 12.49 Gb Total Space | 1.53 Gb Free Space | 12.23% Space Free | Partition Type: NTFS

                                        Computer Name: JEAN-HP | User Name: JEAN | Logged in as Administrator.
                                        Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
                                        Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

                                        [color=#E56717]========== Processes (All) ==========[/color]

                                        PRC - [2011/01/18 14:16:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\JEAN\Documents\Downloads\OTL (1).exe
                                        PRC - [2011/01/13 09:47:34 | 003,396,624 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                                        PRC - [2011/01/13 09:47:33 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                        PRC - [2011/01/13 09:47:32 | 000,119,200 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\afwServ.exe
                                        PRC - [2010/11/10 01:13:30 | 000,025,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
                                        PRC - [2010/10/19 22:06:01 | 000,071,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
                                        PRC - [2010/10/14 17:27:38 | 000,092,216 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
                                        PRC - [2010/09/23 04:47:04 | 000,035,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
                                        PRC - [2010/09/23 00:19:02 | 001,448,800 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe
                                        PRC - [2010/07/27 14:46:08 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                        PRC - [2010/03/11 02:16:44 | 000,098,304 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                                        PRC - [2010/01/25 20:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
                                        PRC - [2010/01/22 19:14:00 | 000,073,728 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
                                        PRC - [2010/01/18 18:21:08 | 000,568,888 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                                        PRC - [2010/01/15 20:41:30 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
                                        PRC - [2010/01/15 20:41:28 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
                                        PRC - [2009/11/09 13:30:06 | 001,036,856 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
                                        PRC - [2008/12/08 22:50:04 | 000,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
                                        PRC - [2008/11/20 18:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe

                                        [color=#E56717]========== Modules (All) ==========[/color]

                                        MOD - [2011/01/18 14:16:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\JEAN\Documents\Downloads\OTL (1).exe
                                        MOD - [2011/01/13 09:47:35 | 000,189,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
                                        MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
                                        MOD - [2010/07/27 15:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll
                                        MOD - [2010/06/29 06:02:02 | 001,413,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll
                                        MOD - [2010/04/07 08:10:36 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll
                                        MOD - [2010/03/24 07:37:04 | 001,289,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll
                                        MOD - [2009/12/11 08:39:06 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll
                                        MOD - [2009/12/11 08:36:33 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll
                                        MOD - [2009/07/14 02:16:19 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll
                                        MOD - [2009/07/14 02:16:17 | 001,123,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll
                                        MOD - [2009/07/14 02:16:17 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll
                                        MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll
                                        MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll
                                        MOD - [2009/07/14 02:16:15 | 000,171,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll
                                        MOD - [2009/07/14 02:16:15 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll
                                        MOD - [2009/07/14 02:16:14 | 001,668,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll
                                        MOD - [2009/07/14 02:16:14 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll
                                        MOD - [2009/07/14 02:16:14 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll
                                        MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll
                                        MOD - [2009/07/14 02:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll
                                        MOD - [2009/07/14 02:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll
                                        MOD - [2009/07/14 02:16:12 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll
                                        MOD - [2009/07/14 02:16:12 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll
                                        MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll
                                        MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll
                                        MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll
                                        MOD - [2009/07/14 02:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll
                                        MOD - [2009/07/14 02:15:50 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll
                                        MOD - [2009/07/14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll
                                        MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll
                                        MOD - [2009/07/14 02:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll
                                        MOD - [2009/07/14 02:15:07 | 000,486,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
                                        MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll
                                        MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll
                                        MOD - [2009/07/14 02:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll
                                        MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll
                                        MOD - [2009/07/14 02:14:53 | 000,640,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll
                                        MOD - [2009/07/14 02:14:53 | 000,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll
                                        MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
                                        MOD - [2009/07/14 02:14:08 | 000,319,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv
                                        MOD - [2009/07/14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll
                                        MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll
                                        MOD - [2009/07/14 02:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll
                                        MOD - [2009/07/14 02:11:23 | 000,662,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll
                                        MOD - [2009/07/14 02:11:23 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll
                                        MOD - [2009/07/14 02:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll
                                        MOD - [2009/07/14 02:11:21 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll
                                        MOD - [2009/07/14 02:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll

                                        [color=#E56717]========== Win32 Services (All) ==========[/color]

                                        SRV:[b]64bit:[/b] - [2011/01/13 09:47:33 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
                                        SRV:[b]64bit:[/b] - [2011/01/13 09:47:32 | 000,119,200 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\afwServ.exe -- (avast! Firewall)
                                        SRV:[b]64bit:[/b] - [2010/12/12 01:42:06 | 001,255,736 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\Wat\WatAdminSvc.exe -- (WatAdminSvc)
                                        SRV:[b]64bit:[/b] - [2010/11/02 06:16:53 | 001,114,624 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
                                        SRV:[b]64bit:[/b] - [2010/11/02 06:12:53 | 001,133,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
                                        SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
                                        SRV:[b]64bit:[/b] - [2010/09/21 14:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
                                        SRV:[b]64bit:[/b] - [2010/08/27 07:14:02 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
                                        SRV:[b]64bit:[/b] - [2010/08/21 07:29:47 | 000,558,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
                                        SRV:[b]64bit:[/b] - [2010/03/10 15:29:46 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:59 | 000,075,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\WUDFSvc.dll -- (wudfsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:58 | 002,418,176 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:58 | 002,018,816 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WsmSvc.dll -- (WinRM)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:57 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wpdbusenum.dll -- (WPDBusEnum)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:57 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpcsvc.dll -- (WPCSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,578,560 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,438,784 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\winhttp.dll -- (WinHttpAutoProxySvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,381,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,366,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wcncsvc.dll -- (wcncsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,353,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\upnphost.dll -- (upnphost)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,254,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WebClnt.dll -- (WebClient)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wecsvc.dll -- (Wecsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiSystemHost)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiServiceHost)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wercplsupport.dll -- (wercplsupport)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wersvc.dll -- (WerSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WcsPlugInService.dll -- (WcsPlugInService)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:56 | 000,038,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\uxsms.dll -- (UxSms)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,706,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\termsrv.dll -- (TermService)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,316,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\trkwks.dll -- (TrkWks)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,093,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TabSvc.dll -- (TabletInputService)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tbssvc.dll -- (TBS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 001,780,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\sysmain.dll -- (SysMain)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,369,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ssdpsrv.dll -- (SSDPSRV)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SessEnv.dll -- (SessionEnv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sstpsvc.dll -- (SstpSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 001,390,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pla.dll -- (pla)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,848,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,509,440 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,509,440 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,438,784 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\p2psvc.dll -- (p2psvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,343,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qwave.dll -- (QWAVE)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,208,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,190,976 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\SCardSvr.dll -- (SCardSvr)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,186,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\pcasvc.dll -- (PcaSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,159,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\regsvc.dll -- (RemoteRegistry)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,064,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\Sens.dll -- (SENS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:52 | 000,302,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:28 | 000,368,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtckrm.dll -- (KtmRm)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 000,824,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (THREADORDER)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:21 | 000,084,480 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:18 | 000,300,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lltdsvc.dll -- (lltdsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:18 | 000,231,936 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:18 | 000,023,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lmhsvc.dll -- (lmhosts)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:13 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\KMSVC.DLL -- (hkmsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:11 | 000,156,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:10 | 000,565,760 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:10 | 000,500,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:09 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPBusEnum.dll -- (IPBusEnum)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:08 | 000,845,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IKEEXT.DLL -- (IKEEXT)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:59 | 000,776,192 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\gpsvc.dll -- (gpsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:52 | 000,034,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FDResPub.dll -- (FDResPub)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:52 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\fdPHost.dll -- (fdPHost)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:32 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:32 | 000,182,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:32 | 000,162,816 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\dps.dll -- (DPS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:28 | 000,314,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:15 | 000,080,384 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\certprop.dll -- (SCPolicySvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:15 | 000,080,384 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:13 | 000,136,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:10 | 000,703,488 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:05 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:04 | 000,676,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:04 | 000,676,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:01 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:40:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:56 | 001,525,248 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:55 | 000,203,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbem\WmiApSrv.exe -- (wmiApSrv)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:51 | 001,503,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:50 | 001,598,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:49 | 000,532,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vds.exe -- (vds)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:48 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\UI0Detect.exe -- (UI0Detect)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:41 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:37 | 000,593,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SearchIndexer.exe -- (WSearch)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:28 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:21 | 000,141,824 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\msdtc.exe -- (MSDTC)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:21 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (VaultSvc)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (Netlogon)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\lsass.exe -- (EFS)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:15 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Locator.exe -- (RpcLocator)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:11 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dllhost.exe -- (COMSysApp)
                                        SRV:[b]64bit:[/b] - [2009/07/14 02:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
                                        SRV - [2010/12/10 16:52:08 | 000,136,176 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate) Service Google Update (gupdate)
                                        SRV - [2010/12/10 16:52:07 | 000,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
                                        SRV - [2010/11/15 09:04:22 | 000,126,520 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service)
                                        SRV - [2010/10/14 17:27:38 | 000,092,216 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
                                        SRV - [2010/10/14 17:22:50 | 000,751,672 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -- (hpqwmiex)
                                        SRV - [2010/09/23 00:21:24 | 001,493,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
                                        SRV - [2010/08/04 08:05:58 | 000,696,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)
                                        SRV - [2010/07/27 14:46:08 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
                                        SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
                                        SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
                                        SRV - [2010/01/22 19:14:00 | 000,073,728 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
                                        SRV - [2010/01/15 20:41:30 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
                                        SRV - [2009/07/14 02:39:48 | 000,194,048 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller)
                                        SRV - [2009/07/14 02:39:09 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehsched.exe -- (ehSched)
                                        SRV - [2009/07/14 02:16:20 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WsmSvc.dll -- (WinRM) Gestion à distance de Windows (Gestion WSM)
                                        SRV - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wpcsvc.dll -- (WPCSvc)
                                        SRV - [2009/07/14 02:16:19 | 000,348,672 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWow64\winhttp.dll -- (WinHttpAutoProxySvc)
                                        SRV - [2009/07/14 02:16:18 | 000,276,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wcncsvc.dll -- (wcncsvc)
                                        SRV - [2009/07/14 02:16:18 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient)
                                        SRV - [2009/07/14 02:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiSystemHost)
                                        SRV - [2009/07/14 02:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiServiceHost)
                                        SRV - [2009/07/14 02:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WcsPlugInService.dll -- (WcsPlugInService)
                                        SRV - [2009/07/14 02:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\upnphost.dll -- (upnphost)
                                        SRV - [2009/07/14 02:16:15 | 000,241,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
                                        SRV - [2009/07/14 02:16:14 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
                                        SRV - [2009/07/14 02:16:13 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\SessEnv.dll -- (SessionEnv)
                                        SRV - [2009/07/14 02:16:13 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\Sens.dll -- (SENS)
                                        SRV - [2009/07/14 02:16:12 | 001,508,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\pla.dll -- (pla)
                                        SRV - [2009/07/14 02:16:12 | 000,210,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\qwave.dll -- (QWAVE)
                                        SRV - [2009/07/14 02:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
                                        SRV - [2009/07/14 02:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
                                        SRV - [2009/07/14 02:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
                                        SRV - [2009/07/14 02:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
                                        SRV - [2009/07/14 02:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
                                        SRV - [2009/07/14 02:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
                                        SRV - [2009/07/14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
                                        SRV - [2009/07/14 02:14:35 | 000,428,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWow64\SearchIndexer.exe -- (WSearch)
                                        SRV - [2009/07/14 02:14:28 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost)
                                        SRV - [2009/07/14 02:14:25 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
                                        SRV - [2009/07/14 02:14:18 | 000,007,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\dllhost.exe -- (COMSysApp)
                                        SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
                                        SRV - [2009/06/10 21:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
                                        SRV - [2009/06/10 21:30:59 | 000,042,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
                                        SRV - [2009/06/10 21:30:45 | 000,856,384 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)

                                        [color=#E56717]========== Driver Services (All) ==========[/color]

                                        DRV:[b]64bit:[/b] - [2011/01/13 09:37:23 | 000,062,032 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
                                        DRV:[b]64bit:[/b] - [2010/11/02 06:21:51 | 000,982,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dxgkrnl.sys -- (DXGKrnl)
                                        DRV:[b]64bit:[/b] - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
                                        DRV:[b]64bit:[/b] - [2010/09/07 16:24:46 | 000,012,368 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswNdis.sys -- (aswNdis)
                                        DRV:[b]64bit:[/b] - [2010/08/27 04:38:04 | 000,463,360 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv.sys -- (srv)
                                        DRV:[b]64bit:[/b] - [2010/08/27 04:37:48 | 000,402,944 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv2.sys -- (srv2)
                                        DRV:[b]64bit:[/b] - [2010/08/27 04:37:26 | 000,161,792 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srvnet.sys -- (srvnet)
                                        DRV:[b]64bit:[/b] - [2010/07/20 02:49:55 | 000,343,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbhub.sys -- (usbhub)
                                        DRV:[b]64bit:[/b] - [2010/07/20 02:49:55 | 000,051,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbehci.sys -- (usbehci)
                                        DRV:[b]64bit:[/b] - [2010/06/14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tcpip.sys -- (TCPIP6)
                                        DRV:[b]64bit:[/b] - [2010/06/14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tcpip.sys -- (Tcpip)
                                        DRV:[b]64bit:[/b] - [2010/03/10 15:39:52 | 006,403,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
                                        DRV:[b]64bit:[/b] - [2010/03/10 14:34:06 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
                                        DRV:[b]64bit:[/b] - [2010/03/04 15:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
                                        DRV:[b]64bit:[/b] - [2010/02/27 08:52:29 | 000,286,720 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb10.sys -- (mrxsmb10)
                                        DRV:[b]64bit:[/b] - [2010/02/27 08:52:28 | 000,125,952 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb20.sys -- (mrxsmb20)
                                        DRV:[b]64bit:[/b] - [2010/02/27 08:52:22 | 000,157,696 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb.sys -- (mrxsmb)
                                        DRV:[b]64bit:[/b] - [2010/02/25 10:14:46 | 002,276,128 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTKVHD64.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
                                        DRV:[b]64bit:[/b] - [2010/01/28 06:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
                                        DRV:[b]64bit:[/b] - [2010/01/19 20:44:32 | 000,023,536 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms -- (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
                                        DRV:[b]64bit:[/b] - [2010/01/15 21:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
                                        DRV:[b]64bit:[/b] - [2009/12/19 04:33:34 | 000,852,256 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
                                        DRV:[b]64bit:[/b] - [2009/12/11 11:29:27 | 000,153,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)
                                        DRV:[b]64bit:[/b] - [2009/09/26 07:20:38 | 000,223,448 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)
                                        DRV:[b]64bit:[/b] - [2009/09/17 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:31 | 000,367,696 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Running] -- C:\Windows\SysNative\clfs.sys -- (CLFS) Journal commun (CLFS)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:31 | 000,021,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\compbatt.sys -- (Compbatt)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:31 | 000,017,488 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cmdide.sys -- (cmdide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,491,088 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adp94xx.sys -- (adp94xx)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,339,536 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adpahci.sys -- (adpahci)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,334,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpi.sys -- (ACPI)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,182,864 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\adpu320.sys -- (adpu320)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,097,856 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\arcsas.sys -- (arcsas)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,087,632 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\arc.sys -- (arc)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AGP440.sys -- (agp440)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atapi.sys -- (atapi)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,015,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdide.sys -- (amdide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,015,440 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aliide.sys -- (aliide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ndis.sys -- (NDIS)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,224,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msiscsi.sys -- (iScsiPrt)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,155,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mpio.sys -- (mpio)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvraid.sys -- (nvraid)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,140,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msdsm.sys -- (msdsm)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,094,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mountmgr.sys -- (mountmgr)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,060,496 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\mup.sys -- (Mup)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouclass.sys -- (mouclass)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,032,320 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mssmbios.sys -- (mssmbios)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,030,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msahci.sys -- (msahci)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:27 | 000,015,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msisadrv.sys -- (msisadrv)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:26 | 000,122,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NV_AGP.SYS -- (nv_agp)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:26 | 000,051,264 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nfrd960.sys -- (nfrd960)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaStorV.sys -- (iaStorV)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,284,736 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MegaSR.sys -- (MegaSR)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,115,776 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_scsi.sys -- (LSI_SCSI)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,114,752 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_fc.sys -- (LSI_FC)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,106,560 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas.sys -- (LSI_SAS)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,095,312 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecdd.sys -- (KSecDD)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdclass.sys -- (kbdclass)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,044,112 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iirsp.sys -- (iirsp)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,035,392 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\megasas.sys -- (megasas)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\isapnp.sys -- (isapnp)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,016,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelide.sys -- (intelide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,014,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:49 | 000,055,376 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,530,496 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\elxstor.sys -- (elxstor)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\disk.sys -- (Disk)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,070,224 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fileinfo.sys -- (FileInfo)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,065,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GAGP30KX.SYS -- (gagp30kx)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:47:47 | 000,290,368 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fltMgr.sys -- (FltMgr)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:56 | 000,022,096 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Wdf01000.sys -- (Wdf01000)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,363,584 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgrx.sys -- (volmgrx)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,294,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volsnap.sys -- (volsnap)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,217,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,161,872 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vsmraid.sys -- (vsmraid)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,071,760 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgr.sys -- (volmgr)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,064,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ULIAGPKX.SYS -- (uliagpkx)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,064,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UAGP35.SYS -- (uagp35)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,062,544 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\termdd.sys -- (TermDD)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,036,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,021,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wd.sys -- (Wd)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,017,488 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viaide.sys -- (viaide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,012,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\swenum.sys -- (swenum)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:46 | 001,524,816 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ql2300.sys -- (ql2300)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:46 | 000,214,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:46 | 000,080,464 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sisraid4.sys -- (SiSRaid4)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:46 | 000,075,840 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\partmgr.sys -- (partmgr)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,220,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcmcia.sys -- (pcmcia)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,183,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pci.sys -- (pci)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvstor.sys -- (nvstor)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,128,592 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ql40xx.sys -- (ql40xx)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,104,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sbp2port.sys -- (sbp2port)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,043,584 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sisraid2.sys -- (SiSRaid2)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:45:45 | 000,012,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pciide.sys -- (pciide)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:43:14 | 000,460,504 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:19:07 | 000,286,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerId.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
                                        DRV:[b]64bit:[/b] - [2009/07/14 02:01:19 | 000,651,264 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\PEAuth.sys -- (PEAUTH)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:38:18 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbprint.sys -- (usbprint)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:17:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:16:41 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tssecsrv.sys -- (tssecsrv)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:16:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPENCDD.sys -- (RDPENCDD)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPCDD.sys -- (RDPCDD)
                                        DRV:[b]64bit:[/b] - [2009/07/14 01:16:32 | 000,023,552 | ---- | M] (M
                                        0
                                        • 1
                                        • 2