A voir également:
- Trojan:Win32/Sirefef.J
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Trojan win32 - Forum Virus
- Csrss.exe trojan - Forum Virus
- Csrss.exe : processus suspect/virus ? - Forum Virus
- Trojan agent ✓ - Forum Virus
82 réponses
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Utilisateur anonyme
27 oct. 2011 à 13:31
27 oct. 2011 à 13:31
refais ca mais sans pre_scan :
https://forums.commentcamarche.net/forum/affich-23399074-trojan-win32-sirefef-j?full#1
https://forums.commentcamarche.net/forum/affich-23399074-trojan-win32-sirefef-j?full#1
un bug de window defender ? rien de détecter :
13:40:34.0896 2540 TDSS rootkit removing tool 2.6.13.0 Oct 25 2011 13:56:21
13:40:35.0036 2540 ============================================================
13:40:35.0036 2540 Current date / time: 2011/10/27 13:40:35.0036
13:40:35.0036 2540 SystemInfo:
13:40:35.0036 2540
13:40:35.0036 2540 OS Version: 6.1.7601 ServicePack: 1.0
13:40:35.0036 2540 Product type: Workstation
13:40:35.0036 2540 ComputerName: PC-STEPHANE
13:40:35.0036 2540 UserName: arthur
13:40:35.0036 2540 Windows directory: C:\Windows
13:40:35.0036 2540 System windows directory: C:\Windows
13:40:35.0036 2540 Processor architecture: Intel x86
13:40:35.0036 2540 Number of processors: 2
13:40:35.0036 2540 Page size: 0x1000
13:40:35.0036 2540 Boot type: Normal boot
13:40:35.0036 2540 ============================================================
13:40:36.0815 2540 Initialize success
13:40:38.0234 2468 ============================================================
13:40:38.0234 2468 Scan started
13:40:38.0234 2468 Mode: Manual;
13:40:38.0234 2468 ============================================================
13:40:39.0451 2468 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
13:40:39.0451 2468 1394ohci - ok
13:40:39.0498 2468 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
13:40:39.0498 2468 ACPI - ok
13:40:39.0529 2468 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
13:40:39.0529 2468 AcpiPmi - ok
13:40:39.0576 2468 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
13:40:39.0592 2468 adp94xx - ok
13:40:39.0607 2468 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
13:40:39.0607 2468 adpahci - ok
13:40:39.0638 2468 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
13:40:39.0638 2468 adpu320 - ok
13:40:39.0701 2468 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
13:40:39.0701 2468 AFD - ok
13:40:39.0732 2468 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
13:40:39.0732 2468 agp440 - ok
13:40:39.0763 2468 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
13:40:39.0763 2468 aic78xx - ok
13:40:39.0794 2468 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
13:40:39.0794 2468 aliide - ok
13:40:39.0841 2468 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
13:40:39.0841 2468 amdagp - ok
13:40:39.0841 2468 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
13:40:39.0841 2468 amdide - ok
13:40:39.0872 2468 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
13:40:39.0872 2468 AmdK8 - ok
13:40:39.0888 2468 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
13:40:39.0888 2468 AmdPPM - ok
13:40:39.0935 2468 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys
13:40:39.0935 2468 amdsata - ok
13:40:39.0950 2468 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
13:40:39.0950 2468 amdsbs - ok
13:40:39.0982 2468 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys
13:40:39.0982 2468 amdxata - ok
13:40:40.0013 2468 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
13:40:40.0013 2468 AppID - ok
13:40:40.0106 2468 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
13:40:40.0106 2468 arc - ok
13:40:40.0122 2468 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
13:40:40.0122 2468 arcsas - ok
13:40:40.0153 2468 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
13:40:40.0153 2468 aswFsBlk - ok
13:40:40.0216 2468 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
13:40:40.0216 2468 aswMonFlt - ok
13:40:40.0278 2468 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
13:40:40.0278 2468 aswRdr - ok
13:40:40.0325 2468 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
13:40:40.0340 2468 aswSnx - ok
13:40:40.0400 2468 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
13:40:40.0410 2468 aswSP - ok
13:40:40.0450 2468 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
13:40:40.0450 2468 aswTdi - ok
13:40:40.0500 2468 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
13:40:40.0500 2468 AsyncMac - ok
13:40:40.0530 2468 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
13:40:40.0540 2468 atapi - ok
13:40:40.0750 2468 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
13:40:40.0810 2468 atikmdag - ok
13:40:40.0920 2468 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
13:40:40.0920 2468 b06bdrv - ok
13:40:40.0960 2468 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
13:40:40.0960 2468 b57nd60x - ok
13:40:41.0000 2468 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
13:40:41.0010 2468 Beep - ok
13:40:41.0040 2468 blbdrive (a6b4c8894619b4bf735db45108fb0322) C:\Windows\system32\DRIVERS\blbdrive.sys
13:40:41.0040 2468 blbdrive - ok
13:40:41.0160 2468 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
13:40:41.0170 2468 bowser - ok
13:40:41.0240 2468 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:40:41.0250 2468 BrFiltLo - ok
13:40:41.0280 2468 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:40:41.0290 2468 BrFiltUp - ok
13:40:41.0340 2468 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
13:40:41.0340 2468 Brserid - ok
13:40:41.0390 2468 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
13:40:41.0390 2468 BrSerWdm - ok
13:40:41.0420 2468 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:40:41.0430 2468 BrUsbMdm - ok
13:40:41.0440 2468 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
13:40:41.0450 2468 BrUsbSer - ok
13:40:41.0480 2468 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
13:40:41.0490 2468 BTHMODEM - ok
13:40:41.0610 2468 catchme - ok
13:40:41.0660 2468 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
13:40:41.0660 2468 cdfs - ok
13:40:41.0720 2468 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
13:40:41.0720 2468 cdrom - ok
13:40:41.0760 2468 CFcatchme - ok
13:40:41.0780 2468 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
13:40:41.0780 2468 circlass - ok
13:40:41.0820 2468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
13:40:41.0820 2468 CLFS - ok
13:40:41.0890 2468 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
13:40:41.0890 2468 CmBatt - ok
13:40:41.0950 2468 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
13:40:41.0950 2468 cmdide - ok
13:40:41.0990 2468 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
13:40:42.0000 2468 CNG - ok
13:40:42.0030 2468 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
13:40:42.0040 2468 Compbatt - ok
13:40:42.0080 2468 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
13:40:42.0080 2468 CompositeBus - ok
13:40:42.0110 2468 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
13:40:42.0110 2468 crcdisk - ok
13:40:42.0160 2468 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
13:40:42.0170 2468 CSC - ok
13:40:42.0220 2468 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
13:40:42.0220 2468 DfsC - ok
13:40:42.0240 2468 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
13:40:42.0240 2468 discache - ok
13:40:42.0270 2468 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
13:40:42.0270 2468 Disk - ok
13:40:42.0350 2468 driverhardwarev2 (b019db2d3bc4530759abd8440e6bcd28) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
13:40:42.0360 2468 driverhardwarev2 - ok
13:40:42.0390 2468 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
13:40:42.0390 2468 drmkaud - ok
13:40:42.0422 2468 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
13:40:42.0422 2468 DXGKrnl - ok
13:40:42.0484 2468 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
13:40:42.0515 2468 ebdrv - ok
13:40:42.0562 2468 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
13:40:42.0562 2468 elxstor - ok
13:40:42.0593 2468 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
13:40:42.0593 2468 ErrDev - ok
13:40:42.0624 2468 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
13:40:42.0624 2468 exfat - ok
13:40:42.0656 2468 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
13:40:42.0656 2468 fastfat - ok
13:40:42.0671 2468 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
13:40:42.0671 2468 fdc - ok
13:40:42.0702 2468 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
13:40:42.0702 2468 FileInfo - ok
13:40:42.0718 2468 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
13:40:42.0718 2468 Filetrace - ok
13:40:42.0734 2468 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
13:40:42.0734 2468 flpydisk - ok
13:40:42.0749 2468 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
13:40:42.0749 2468 FltMgr - ok
13:40:42.0780 2468 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
13:40:42.0780 2468 FsDepends - ok
13:40:42.0827 2468 fssfltr (491e9d9a26a745f6ae7d570849f4bd87) C:\Windows\system32\DRIVERS\fssfltr.sys
13:40:42.0843 2468 fssfltr - ok
13:40:42.0890 2468 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
13:40:42.0890 2468 Fs_Rec - ok
13:40:42.0936 2468 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
13:40:42.0952 2468 fvevol - ok
13:40:42.0983 2468 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:40:42.0983 2468 gagp30kx - ok
13:40:42.0999 2468 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:40:43.0014 2468 GEARAspiWDM - ok
13:40:43.0092 2468 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
13:40:43.0108 2468 hamachi - ok
13:40:43.0373 2468 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
13:40:43.0389 2468 hcw85cir - ok
13:40:43.0607 2468 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
13:40:43.0607 2468 HdAudAddService - ok
13:40:43.0763 2468 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
13:40:43.0779 2468 HDAudBus - ok
13:40:43.0810 2468 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
13:40:43.0810 2468 HidBatt - ok
13:40:43.0872 2468 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
13:40:43.0888 2468 HidBth - ok
13:40:43.0919 2468 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
13:40:43.0919 2468 HidIr - ok
13:40:43.0982 2468 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
13:40:43.0982 2468 HidUsb - ok
13:40:44.0044 2468 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
13:40:44.0044 2468 HpSAMD - ok
13:40:44.0091 2468 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
13:40:44.0106 2468 HTTP - ok
13:40:44.0153 2468 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
13:40:44.0153 2468 hwpolicy - ok
13:40:44.0184 2468 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
13:40:44.0184 2468 i8042prt - ok
13:40:44.0231 2468 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys
13:40:44.0247 2468 iaStorV - ok
13:40:44.0278 2468 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
13:40:44.0309 2468 iirsp - ok
13:40:44.0356 2468 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
13:40:44.0356 2468 intelide - ok
13:40:44.0387 2468 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
13:40:44.0387 2468 intelppm - ok
13:40:44.0403 2468 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:40:44.0403 2468 IpFilterDriver - ok
13:40:44.0434 2468 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
13:40:44.0434 2468 IPMIDRV - ok
13:40:44.0450 2468 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
13:40:44.0465 2468 IPNAT - ok
13:40:44.0496 2468 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
13:40:44.0496 2468 IRENUM - ok
13:40:44.0528 2468 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
13:40:44.0528 2468 isapnp - ok
13:40:44.0559 2468 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
13:40:44.0559 2468 iScsiPrt - ok
13:40:44.0590 2468 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
13:40:44.0590 2468 kbdclass - ok
13:40:44.0621 2468 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
13:40:44.0621 2468 kbdhid - ok
13:40:44.0652 2468 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
13:40:44.0668 2468 KSecDD - ok
13:40:44.0684 2468 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
13:40:44.0684 2468 KSecPkg - ok
13:40:44.0699 2468 LgBttPort - ok
13:40:44.0715 2468 lgbusenum - ok
13:40:44.0746 2468 LGVMODEM - ok
13:40:44.0793 2468 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
13:40:44.0793 2468 lltdio - ok
13:40:44.0840 2468 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:40:44.0840 2468 LSI_FC - ok
13:40:44.0871 2468 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:40:44.0871 2468 LSI_SAS - ok
13:40:44.0886 2468 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:40:44.0886 2468 LSI_SAS2 - ok
13:40:44.0902 2468 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:40:44.0918 2468 LSI_SCSI - ok
13:40:44.0949 2468 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
13:40:44.0949 2468 luafv - ok
13:40:44.0996 2468 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
13:40:44.0996 2468 megasas - ok
13:40:45.0027 2468 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
13:40:45.0027 2468 MegaSR - ok
13:40:45.0042 2468 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
13:40:45.0042 2468 Modem - ok
13:40:45.0074 2468 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
13:40:45.0074 2468 monitor - ok
13:40:45.0136 2468 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
13:40:45.0136 2468 mouclass - ok
13:40:45.0401 2468 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
13:40:45.0401 2468 mouhid - ok
13:40:45.0448 2468 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
13:40:45.0448 2468 mountmgr - ok
13:40:45.0495 2468 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
13:40:45.0495 2468 mpio - ok
13:40:45.0510 2468 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
13:40:45.0526 2468 mpsdrv - ok
13:40:45.0557 2468 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
13:40:45.0557 2468 MRxDAV - ok
13:40:45.0588 2468 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:40:45.0604 2468 mrxsmb - ok
13:40:45.0635 2468 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:40:45.0635 2468 mrxsmb10 - ok
13:40:45.0651 2468 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:40:45.0666 2468 mrxsmb20 - ok
13:40:45.0682 2468 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
13:40:45.0682 2468 msahci - ok
13:40:45.0729 2468 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
13:40:45.0729 2468 msdsm - ok
13:40:45.0760 2468 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
13:40:45.0776 2468 Msfs - ok
13:40:45.0791 2468 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
13:40:45.0791 2468 mshidkmdf - ok
13:40:45.0807 2468 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\Windows\system32\Drivers\nx6000.sys
13:40:45.0807 2468 MSHUSBVideo - ok
13:40:45.0838 2468 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
13:40:45.0838 2468 msisadrv - ok
13:40:45.0869 2468 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
13:40:45.0885 2468 MSKSSRV - ok
13:40:45.0885 2468 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
13:40:45.0885 2468 MSPCLOCK - ok
13:40:45.0900 2468 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
13:40:45.0900 2468 MSPQM - ok
13:40:45.0932 2468 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
13:40:45.0932 2468 MsRPC - ok
13:40:45.0947 2468 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
13:40:45.0947 2468 mssmbios - ok
13:40:45.0963 2468 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
13:40:45.0963 2468 MSTEE - ok
13:40:45.0978 2468 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
13:40:45.0978 2468 MTConfig - ok
13:40:46.0010 2468 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
13:40:46.0010 2468 Mup - ok
13:40:46.0041 2468 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
13:40:46.0041 2468 NativeWifiP - ok
13:40:46.0088 2468 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
13:40:46.0103 2468 NDIS - ok
13:40:46.0119 2468 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
13:40:46.0119 2468 NdisCap - ok
13:40:46.0150 2468 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
13:40:46.0150 2468 NdisTapi - ok
13:40:46.0181 2468 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
13:40:46.0181 2468 Ndisuio - ok
13:40:46.0212 2468 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
13:40:46.0228 2468 NdisWan - ok
13:40:46.0259 2468 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
13:40:46.0259 2468 NDProxy - ok
13:40:46.0275 2468 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
13:40:46.0275 2468 NetBIOS - ok
13:40:46.0306 2468 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
13:40:46.0306 2468 NetBT - ok
13:40:46.0384 2468 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
13:40:46.0384 2468 nfrd960 - ok
13:40:46.0446 2468 npf (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys
13:40:46.0446 2468 npf - ok
13:40:46.0462 2468 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
13:40:46.0462 2468 Npfs - ok
13:40:46.0493 2468 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
13:40:46.0493 2468 nsiproxy - ok
13:40:46.0540 2468 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys
13:40:46.0556 2468 Ntfs - ok
13:40:46.0571 2468 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
13:40:46.0571 2468 Null - ok
13:40:46.0602 2468 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys
13:40:46.0618 2468 nvraid - ok
13:40:46.0634 2468 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys
13:40:46.0649 2468 nvstor - ok
13:40:46.0680 2468 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
13:40:46.0680 2468 nv_agp - ok
13:40:46.0696 2468 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
13:40:46.0712 2468 ohci1394 - ok
13:40:46.0758 2468 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
13:40:46.0758 2468 Parport - ok
13:40:46.0790 2468 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
13:40:46.0790 2468 partmgr - ok
13:40:46.0805 2468 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
13:40:46.0805 2468 Parvdm - ok
13:40:46.0836 2468 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
13:40:46.0836 2468 pci - ok
13:40:46.0852 2468 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
13:40:46.0852 2468 pciide - ok
13:40:46.0883 2468 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
13:40:46.0883 2468 pcmcia - ok
13:40:46.0914 2468 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
13:40:46.0914 2468 pcw - ok
13:40:46.0946 2468 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
13:40:46.0946 2468 PEAUTH - ok
13:40:47.0117 2468 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
13:40:47.0133 2468 PptpMiniport - ok
13:40:47.0148 2468 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
13:40:47.0148 2468 Processor - ok
13:40:47.0211 2468 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
13:40:47.0211 2468 Psched - ok
13:40:47.0258 2468 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
13:40:47.0273 2468 ql2300 - ok
13:40:47.0304 2468 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
13:40:47.0304 2468 ql40xx - ok
13:40:47.0336 2468 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
13:40:47.0336 2468 QWAVEdrv - ok
13:40:47.0351 2468 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
13:40:47.0351 2468 RasAcd - ok
13:40:47.0382 2468 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:40:47.0382 2468 RasAgileVpn - ok
13:40:47.0414 2468 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:40:47.0414 2468 Rasl2tp - ok
13:40:47.0445 2468 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
13:40:47.0445 2468 RasPppoe - ok
13:40:47.0476 2468 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
13:40:47.0476 2468 RasSstp - ok
13:40:47.0507 2468 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
13:40:47.0507 2468 rdbss - ok
13:40:47.0523 2468 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
13:40:47.0523 2468 rdpbus - ok
13:40:47.0554 2468 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:40:47.0554 2468 RDPCDD - ok
13:40:47.0585 2468 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
13:40:47.0585 2468 RDPDR - ok
13:40:47.0616 2468 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
13:40:47.0616 2468 RDPENCDD - ok
13:40:47.0632 2468 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
13:40:47.0648 2468 RDPREFMP - ok
13:40:47.0663 2468 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
13:40:47.0679 2468 RDPWD - ok
13:40:47.0710 2468 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
13:40:47.0726 2468 rdyboost - ok
13:40:47.0772 2468 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
13:40:47.0772 2468 rspndr - ok
13:40:47.0804 2468 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys
13:40:47.0819 2468 RTL8167 - ok
13:40:47.0850 2468 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
13:40:47.0850 2468 s3cap - ok
13:40:47.0882 2468 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
13:40:47.0897 2468 sbp2port - ok
13:40:47.0928 2468 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
13:40:47.0928 2468 scfilter - ok
13:40:47.0975 2468 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
13:40:47.0975 2468 secdrv - ok
13:40:48.0022 2468 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
13:40:48.0022 2468 Serenum - ok
13:40:48.0038 2468 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
13:40:48.0038 2468 Serial - ok
13:40:48.0084 2468 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
13:40:48.0084 2468 sermouse - ok
13:40:48.0116 2468 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
13:40:48.0116 2468 sffdisk - ok
13:40:48.0131 2468 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
13:40:48.0131 2468 sffp_mmc - ok
13:40:48.0147 2468 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
13:40:48.0162 2468 sffp_sd - ok
13:40:48.0194 2468 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
13:40:48.0194 2468 sfloppy - ok
13:40:48.0225 2468 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
13:40:48.0225 2468 sisagp - ok
13:40:48.0256 2468 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:40:48.0256 2468 SiSRaid2 - ok
13:40:48.0272 2468 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
13:40:48.0287 2468 SiSRaid4 - ok
13:40:48.0303 2468 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
13:40:48.0318 2468 Smb - ok
13:40:48.0350 2468 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
13:40:48.0350 2468 spldr - ok
13:40:48.0381 2468 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
13:40:48.0396 2468 srv - ok
13:40:48.0412 2468 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
13:40:48.0412 2468 srv2 - ok
13:40:48.0459 2468 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
13:40:48.0459 2468 srvnet - ok
13:40:48.0506 2468 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\Windows\system32\drivers\StarOpen.sys
13:40:48.0506 2468 StarOpen - ok
13:40:48.0552 2468 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
13:40:48.0552 2468 stexstor - ok
13:40:48.0584 2468 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
13:40:48.0584 2468 storflt - ok
13:40:48.0630 2468 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
13:40:48.0630 2468 storvsc - ok
13:40:48.0662 2468 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
13:40:48.0662 2468 swenum - ok
13:40:48.0740 2468 Tcpip (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\drivers\tcpip.sys
13:40:48.0755 2468 Tcpip - ok
13:40:48.0771 2468 TCPIP6 (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\DRIVERS\tcpip.sys
13:40:48.0786 2468 TCPIP6 - ok
13:40:48.0818 2468 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
13:40:48.0833 2468 tcpipreg - ok
13:40:48.0864 2468 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
13:40:48.0864 2468 TDPIPE - ok
13:40:48.0880 2468 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
13:40:48.0880 2468 TDTCP - ok
13:40:48.0911 2468 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
13:40:48.0911 2468 tdx - ok
13:40:48.0942 2468 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
13:40:48.0942 2468 TermDD - ok
13:40:49.0005 2468 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:40:49.0005 2468 tssecsrv - ok
13:40:49.0052 2468 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
13:40:49.0052 2468 TsUsbFlt - ok
13:40:49.0208 2468 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
13:40:49.0239 2468 tunnel - ok
13:40:49.0379 2468 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
13:40:49.0410 2468 uagp35 - ok
13:40:49.0598 2468 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
13:40:49.0613 2468 udfs - ok
13:40:49.0754 2468 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
13:40:49.0785 2468 uliagpkx - ok
13:40:49.0925 2468 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
13:40:49.0941 2468 umbus - ok
13:40:49.0972 2468 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
13:40:50.0003 2468 UmPass - ok
13:40:50.0097 2468 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys
13:40:50.0097 2468 USBAAPL - ok
13:40:50.0206 2468 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
13:40:50.0206 2468 usbaudio - ok
13:40:50.0253 2468 usbbus (9419faac6552a51542dbba02971c841c) C:\Windows\system32\DRIVERS\lgusbbus.sys
13:40:50.0253 2468 usbbus - ok
13:40:50.0315 2468 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\drivers\usbccgp.sys
13:40:50.0315 2468 usbccgp - ok
13:40:50.0346 2468 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
13:40:50.0346 2468 usbcir - ok
13:40:50.0378 2468 UsbDiag (c0a466fa4ffec464320e159bc1bbdc0c) C:\Windows\system32\DRIVERS\lgusbdiag.sys
13:40:50.0378 2468 UsbDiag - ok
13:40:50.0409 2468 usbehci (cfbce999c057d78979a181c9c60f208e) C:\Windows\system32\drivers\usbehci.sys
13:40:50.0409 2468 usbehci - ok
13:40:50.0487 2468 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys
13:40:50.0502 2468 usbhub - ok
13:40:50.0565 2468 USBModem (f74a54774a9b0afeb3c40adec68aa600) C:\Windows\system32\DRIVERS\lgusbmodem.sys
13:40:50.0565 2468 USBModem - ok
13:40:50.0596 2468 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\drivers\usbohci.sys
13:40:50.0612 2468 usbohci - ok
13:40:50.0658 2468 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
13:40:50.0658 2468 usbprint - ok
13:40:50.0690 2468 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
13:40:50.0690 2468 usbscan - ok
13:40:50.0705 2468 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:40:50.0705 2468 USBSTOR - ok
13:40:50.0736 2468 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\drivers\usbuhci.sys
13:40:50.0736 2468 usbuhci - ok
13:40:50.0799 2468 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
13:40:50.0814 2468 usbvideo - ok
13:40:50.0861 2468 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
13:40:50.0861 2468 vdrvroot - ok
13:40:50.0924 2468 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
13:40:50.0924 2468 vga - ok
13:40:50.0955 2468 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
13:40:50.0955 2468 VgaSave - ok
13:40:50.0986 2468 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
13:40:50.0986 2468 vhdmp - ok
13:40:51.0033 2468 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
13:40:51.0033 2468 viaagp - ok
13:40:51.0064 2468 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
13:40:51.0080 2468 ViaC7 - ok
13:40:51.0126 2468 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
13:40:51.0126 2468 viaide - ok
13:40:51.0173 2468 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
13:40:51.0173 2468 vmbus - ok
13:40:51.0204 2468 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
13:40:51.0220 2468 VMBusHID - ok
13:40:51.0251 2468 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
13:40:51.0251 2468 volmgr - ok
13:40:51.0282 2468 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
13:40:51.0298 2468 volmgrx - ok
13:40:51.0392 2468 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
13:40:51.0407 2468 volsnap - ok
13:40:51.0485 2468 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
13:40:51.0501 2468 vsmraid - ok
13:40:51.0548 2468 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
13:40:51.0563 2468 vwifibus - ok
13:40:51.0641 2468 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
13:40:51.0641 2468 WacomPen - ok
13:40:51.0766 2468 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:40:51.0766 2468 WANARP - ok
13:40:51.0782 2468 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:40:51.0797 2468 Wanarpv6 - ok
13:40:52.0140 2468 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
13:40:52.0156 2468 Wd - ok
13:40:52.0265 2468 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
13:40:52.0296 2468 Wdf01000 - ok
13:40:52.0468 2468 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
13:40:52.0468 2468 WfpLwf - ok
13:40:52.0562 2468 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
13:40:52.0562 2468 WIMMount - ok
13:40:52.0718 2468 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
13:40:52.0733 2468 WinUsb - ok
13:40:52.0842 2468 WLNdis50 (bb2c5a7a555b387b85481b8bde5370d7) C:\Windows\system32\DRIVERS\wlndis50.sys
13:40:52.0858 2468 WLNdis50 - ok
13:40:52.0936 2468 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
13:40:52.0952 2468 WmiAcpi - ok
13:40:53.0076 2468 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
13:40:53.0092 2468 ws2ifsl - ok
13:40:53.0232 2468 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
13:40:53.0248 2468 WudfPf - ok
13:40:53.0451 2468 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:40:53.0466 2468 WUDFRd - ok
13:40:53.0560 2468 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:40:53.0591 2468 \Device\Harddisk0\DR0 - ok
13:40:53.0607 2468 Boot (0x1200) (8086c33801f016f75be26d3cf7eb402d) \Device\Harddisk0\DR0\Partition0
13:40:53.0607 2468 \Device\Harddisk0\DR0\Partition0 - ok
13:40:53.0622 2468 Boot (0x1200) (6a154f0f04b3c917e0c6ec54fe781ce0) \Device\Harddisk0\DR0\Partition1
13:40:53.0638 2468 \Device\Harddisk0\DR0\Partition1 - ok
13:40:53.0654 2468 Boot (0x1200) (8a91e871226e431aba9411619e90cbf0) \Device\Harddisk0\DR0\Partition2
13:40:53.0654 2468 \Device\Harddisk0\DR0\Partition2 - ok
13:40:53.0654 2468 ============================================================
13:40:53.0654 2468 Scan finished
13:40:53.0654 2468 ============================================================
13:40:53.0685 2600 Detected object count: 0
13:40:53.0685 2600 Actual detected object count: 0
13:41:29.0382 4024 ============================================================
13:41:29.0382 4024 Scan started
13:41:29.0382 4024 Mode: Manual;
13:41:29.0382 4024 ============================================================
13:41:30.0132 4024 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
13:41:30.0132 4024 1394ohci - ok
13:41:30.0172 4024 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
13:41:30.0172 4024 ACPI - ok
13:41:30.0192 4024 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
13:41:30.0192 4024 AcpiPmi - ok
13:41:30.0242 4024 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
13:41:30.0242 4024 adp94xx - ok
13:41:30.0262 4024 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
13:41:30.0272 4024 adpahci - ok
13:41:30.0292 4024 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
13:41:30.0292 4024 adpu320 - ok
13:41:30.0342 4024 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
13:41:30.0352 4024 AFD - ok
13:41:30.0362 4024 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
13:41:30.0362 4024 agp440 - ok
13:41:30.0382 4024 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
13:41:30.0382 4024 aic78xx - ok
13:41:30.0402 4024 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
13:41:30.0412 4024 aliide - ok
13:41:30.0422 4024 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
13:41:30.0422 4024 amdagp - ok
13:41:30.0437 4024 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
13:41:30.0437 4024 amdide - ok
13:41:30.0453 4024 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
13:41:30.0453 4024 AmdK8 - ok
13:41:30.0469 4024 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
13:41:30.0469 4024 AmdPPM - ok
13:41:30.0484 4024 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys
13:41:30.0484 4024 amdsata - ok
13:41:30.0500 4024 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
13:41:30.0500 4024 amdsbs - ok
13:41:30.0531 4024 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys
13:41:30.0531 4024 amdxata - ok
13:41:30.0562 4024 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
13:41:30.0562 4024 AppID - ok
13:41:30.0593 4024 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
13:41:30.0593 4024 arc - ok
13:41:30.0625 4024 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
13:41:30.0625 4024 arcsas - ok
13:41:30.0640 4024 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
13:41:30.0640 4024 aswFsBlk - ok
13:41:30.0687 4024 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
13:41:30.0687 4024 aswMonFlt - ok
13:41:30.0749 4024 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
13:41:30.0749 4024 aswRdr - ok
13:41:30.0796 4024 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
13:41:30.0812 4024 aswSnx - ok
13:41:30.0859 4024 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
13:41:30.0859 4024 aswSP - ok
13:41:30.0890 4024 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
13:41:30.0890 4024 aswTdi - ok
13:41:30.0905 4024 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
13:41:30.0905 4024 AsyncMac - ok
13:41:30.0937 4024 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
13:41:30.0937 4024 atapi - ok
13:41:31.0061 4024 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
13:41:31.0093 4024 atikmdag - ok
13:41:31.0139 4024 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
13:41:31.0139 4024 b06bdrv - ok
13:41:31.0171 4024 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
13:41:31.0171 4024 b57nd60x - ok
13:41:31.0202 4024 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
13:41:31.0202 4024 Beep - ok
13:41:31.0233 4024 blbdrive (a6b4c8894619b4bf735db45108fb0322) C:\Windows\system32\DRIVERS\blbdrive.sys
13:41:31.0233 4024 blbdrive - ok
13:41:31.0264 4024 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
13:41:31.0264 4024 bowser - ok
13:41:31.0280 4024 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:41:31.0295 4024 BrFiltLo - ok
13:41:31.0311 4024 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:41:31.0311 4024 BrFiltUp - ok
13:41:31.0342 4024 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
13:41:31.0342 4024 Brserid - ok
13:41:31.0358 4024 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
13:41:31.0358 4024 BrSerWdm - ok
13:41:31.0373 4024 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:41:31.0373 4024 BrUsbMdm - ok
13:41:31.0405 4024 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
13:41:31.0405 4024 BrUsbSer - ok
13:41:31.0420 4024 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
13:41:31.0420 4024 BTHMODEM - ok
13:41:31.0514 4024 catchme - ok
13:41:31.0545 4024 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
13:41:31.0545 4024 cdfs - ok
13:41:31.0592 4024 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
13:41:31.0592 4024 cdrom - ok
13:41:31.0607 4024 CFcatchme - ok
13:41:31.0623 4024 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
13:41:31.0623 4024 circlass - ok
13:41:31.0654 4024 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
13:41:31.0670 4024 CLFS - ok
13:41:31.0717 4024 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
13:41:31.0717 4024 CmBatt - ok
13:41:31.0748 4024 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
13:41:31.0748 4024 cmdide - ok
13:41:31.0779 4024 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
13:41:31.0779 4024 CNG - ok
13:41:31.0795 4024 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
13:41:31.0795 4024 Compbatt - ok
13:41:31.0826 4024 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
13:41:31.0826 4024 CompositeBus - ok
13:41:31.0841 4024 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
13:41:31.0841 4024 crcdisk - ok
13:41:31.0888 4024 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
13:41:31.0888 4024 CSC - ok
13:41:31.0935 4024 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
13:41:31.0935 4024 DfsC - ok
13:41:31.0966 4024 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
13:41:31.0966 4024 discache - ok
13:41:31.0982 4024 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
13:41:31.0982 4024 Disk - ok
13:41:32.0044 4024 driverhardwarev2 (b019db2d3bc4530759abd8440e6bcd28) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
13:41:32.0044 4024 driverhardwarev2 - ok
13:41:32.0075 4024 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
13:41:32.0075 4024 drmkaud - ok
13:41:32.0138 4024 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
13:41:32.0153 4024 DXGKrnl - ok
13:41:32.0247 4024 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
13:41:32.0263 4024 ebdrv - ok
13:41:32.0309 4024 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
13:41:32.0309 4024 elxstor - ok
13:41:32.0325 4024 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
13:41:32.0325 4024 ErrDev - ok
13:41:32.0372 4024 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
13:41:32.0372 4024 exfat - ok
13:41:32.0387 4024 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
13:41:32.0387 4024 fastfat - ok
13:41:32.0419 4024 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
13:41:32.0419 4024 fdc - ok
13:41:32.0434 4024 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
13:41:32.0434 4024 FileInfo - ok
13:41:32.0450 4024 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
13:41:32.0450 4024 Filetrace - ok
13:41:32.0465 4024 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
13:41:32.0465 4024 flpydisk - ok
13:41:32.0497 4024 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
13:41:32.0497 4024 FltMgr - ok
13:41:32.0512 4024 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
13:41:32.0512 4024 FsDepends - ok
13:41:32.0543 4024 fssfltr (491e9d9a26a745f6ae7d570849f4bd87) C:\Windows\system32\DRIVERS\fssfltr.sys
13:41:32.0543 4024 fssfltr - ok
13:41:32.0575 4024 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
13:41:32.0575 4024 Fs_Rec - ok
13:41:32.0606 4024 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
13:41:32.0621 4024 fvevol - ok
13:41:32.0637 4024 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:41:32.0637 4024 gagp30kx - ok
13:41:32.0668 4024 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:41:32.0668 4024 GEARAspiWDM - ok
13:41:32.0731 4024 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
13:41:32.0731 4024 hamachi - ok
13:41:32.0746 4024 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
13:41:32.0762 4024 hcw85cir - ok
13:41:32.0793 4024 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
13:41:32.0793 4024 HdAudAddService - ok
13:41:32.0824 4024 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
13:41:32.0824 4024 HDAudBus - ok
13:41:32.0855 4024 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
13:41:32.0855 4024 HidBatt - ok
13:41:32.0871 4024 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
13:41:32.0871 4024 HidBth - ok
13:41:32.0902 4024 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
13:41:32.0902 4024 HidIr - ok
13:41:32.0933 4024 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
13:41:32.0933 4024 HidUsb - ok
13:41:32.0965 4024 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
13:41:32.0965 4024 HpSAMD - ok
13:41:32.0996 4024 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
13:41:32.0996 4024 HTTP - ok
13:41:33.0027 4024 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
13:41:33.0043 4024 hwpolicy - ok
13:41:33.0074 4024 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
13:41:33.0074 4024 i8042prt - ok
13:41:33.0105 4024 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys
13:41:33.0105 4024 iaStorV - ok
13:41:33.0121 4024 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
13:41:33.0121 4024 iirsp - ok
13:41:33.0152 4024 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
13:41:33.0152 4024 intelide - ok
13:41:33.0183 4024 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
13:41:33.0183 4024 intelppm - ok
13:41:33.0214 4024 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:41:33.0214 4024 IpFilterDriver - ok
13:41:33.0245 4024 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
13:41:33.0245 4024 IPMIDRV - ok
13:41:33.0277 4024 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
13:41:33.0277 4024 IPNAT - ok
13:41:33.0292 4024 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
13:41:33.0292 4024 IRENUM - ok
13:41:33.0323 4024 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
13:41:33.0323 4024 isapnp - ok
13:41:33.0355 4024 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
13:41:33.0355 4024 iScsiPrt - ok
13:41:33.0417 4024 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
13:41:33.0417 4024 kbdclass - ok
13:41:33.0448 4024 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
13:41:33.0448 4024 kbdhid - ok
13:41:33.0495 4024 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
13:41:33.0495 4024 KSecDD - ok
13:41:33.0511 4024 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
13:41:33.0526 4024 KSecPkg - ok
13:41:33.0542 4024 LgBttPort - ok
13:41:33.0557 4024 lgbusenum - ok
13:41:33.0573 4024 LGVMODEM - ok
13:41:33.0589 4024 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
13:41:33.0589 4024 lltdio - ok
13:41:33.0635 4024 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:41:33.0635 4024 LSI_FC - ok
13:41:33.0651 4024 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:41:33.0651 4024 LSI_SAS - ok
13:41:33.0667 4024 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:41:33.0667 4024 LSI_SAS2 - ok
13:41:33.0713 4024 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:41:33.0713 4024 LSI_SCSI - ok
13:41:33.0745 4024 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
13:41:33.0745 4024 luafv - ok
13:41:33.0776 4024 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
13:41:33.0776 4024 megasas - ok
13:41:33.0791 4024 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
13:41:33.0807 4024 MegaSR - ok
13:41:33.0823 4024 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
13:41:33.0823 4024 Modem - ok
13:41:33.0854 4024 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
13:41:33.0854 4024 monitor - ok
13:41:33.0885 4024 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
13:41:33.0885 4024 mouclass - ok
13:41:33.0901 4024 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
13:41:33.0901 4024 mouhid - ok
13:41:33.0932 4024 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
13:41:33.0932 4024 mountmgr - ok
13:41:33.0979 4024 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
13:41:33.0994 4024 mpio - ok
13:41:34.0010 4024 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
13:41:34.0025 4024 mpsdrv - ok
13:41:34.0072 4024 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
13:41:34.0072 4024 MRxDAV - ok
13:41:34.0088 4024 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:41:34.0088 4024 mrxsmb - ok
13:41:34.0135 4024 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:41:34.0135 4024 mrxsmb10 - ok
13:41:34.0150 4024 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:41:34.0150 4024 mrxsmb20 - ok
13:41:34.0181 4024 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
13:41:34.0181 4024 msahci - ok
13:41:34.0213 4024 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
13:41:34.0213 4024 msdsm - ok
13:41:34.0228 4024 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
13:41:34.0228 4024 Msfs - ok
13:41:34.0244 4024 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
13:41:34.0244 4024 mshidkmdf - ok
13:41:34.0259 4024 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\Windows\system32\Drivers\nx6000.sys
13:41:34.0275 4024 MSHUSBVideo - ok
13:41:34.0291 4024 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
13:41:34.0291 4024 msisadrv - ok
13:41:34.0322 4024 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
13:41:34.0322 4024 MSKSSRV - ok
13:41:34.0322 4024 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
13:41:34.0337 4024 MSPCLOCK - ok
13:41:34.0337 4024 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
13:41:34.0337 4024 MSPQM - ok
13:41:34.0369 4024 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
13:41:34.0369 4024 MsRPC - ok
13:41:34.0400 4024 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
13:41:34.0400 4024 mssmbios - ok
13:41:34.0400 4024 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
13:41:34.0400 4024 MSTEE - ok
13:41:34.0431 4024 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
13:41:34.0431 4024 MTConfig - ok
13:41:34.0447 4024 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
13:41:34.0447 4024 Mup - ok
13:41:34.0478 4024 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
13:41:34.0478 4024 NativeWifiP - ok
13:41:34.0525 4024 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
13:41:34.0525 4024 NDIS - ok
13:41:34.0556 4024 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
13:41:34.0556 4024 NdisCap - ok
13:41:34.0571 4024 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
13:41:34.0571 4024 NdisTapi - ok
13:41:34.0603 4024 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
13:41:34.0603 4024 Ndisuio - ok
13:41:34.0634 4024 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
13:41:34.0634 4024 NdisWan - ok
13:41:34.0681 4024 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
13:41:34.0681 4024 NDProxy - ok
13:41:34.0727 4024 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
13:41:34.0727 4024 NetBIOS - ok
13:41:34.0790 4024 NetBT (280122ddcf
13:40:34.0896 2540 TDSS rootkit removing tool 2.6.13.0 Oct 25 2011 13:56:21
13:40:35.0036 2540 ============================================================
13:40:35.0036 2540 Current date / time: 2011/10/27 13:40:35.0036
13:40:35.0036 2540 SystemInfo:
13:40:35.0036 2540
13:40:35.0036 2540 OS Version: 6.1.7601 ServicePack: 1.0
13:40:35.0036 2540 Product type: Workstation
13:40:35.0036 2540 ComputerName: PC-STEPHANE
13:40:35.0036 2540 UserName: arthur
13:40:35.0036 2540 Windows directory: C:\Windows
13:40:35.0036 2540 System windows directory: C:\Windows
13:40:35.0036 2540 Processor architecture: Intel x86
13:40:35.0036 2540 Number of processors: 2
13:40:35.0036 2540 Page size: 0x1000
13:40:35.0036 2540 Boot type: Normal boot
13:40:35.0036 2540 ============================================================
13:40:36.0815 2540 Initialize success
13:40:38.0234 2468 ============================================================
13:40:38.0234 2468 Scan started
13:40:38.0234 2468 Mode: Manual;
13:40:38.0234 2468 ============================================================
13:40:39.0451 2468 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
13:40:39.0451 2468 1394ohci - ok
13:40:39.0498 2468 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
13:40:39.0498 2468 ACPI - ok
13:40:39.0529 2468 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
13:40:39.0529 2468 AcpiPmi - ok
13:40:39.0576 2468 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
13:40:39.0592 2468 adp94xx - ok
13:40:39.0607 2468 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
13:40:39.0607 2468 adpahci - ok
13:40:39.0638 2468 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
13:40:39.0638 2468 adpu320 - ok
13:40:39.0701 2468 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
13:40:39.0701 2468 AFD - ok
13:40:39.0732 2468 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
13:40:39.0732 2468 agp440 - ok
13:40:39.0763 2468 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
13:40:39.0763 2468 aic78xx - ok
13:40:39.0794 2468 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
13:40:39.0794 2468 aliide - ok
13:40:39.0841 2468 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
13:40:39.0841 2468 amdagp - ok
13:40:39.0841 2468 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
13:40:39.0841 2468 amdide - ok
13:40:39.0872 2468 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
13:40:39.0872 2468 AmdK8 - ok
13:40:39.0888 2468 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
13:40:39.0888 2468 AmdPPM - ok
13:40:39.0935 2468 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys
13:40:39.0935 2468 amdsata - ok
13:40:39.0950 2468 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
13:40:39.0950 2468 amdsbs - ok
13:40:39.0982 2468 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys
13:40:39.0982 2468 amdxata - ok
13:40:40.0013 2468 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
13:40:40.0013 2468 AppID - ok
13:40:40.0106 2468 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
13:40:40.0106 2468 arc - ok
13:40:40.0122 2468 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
13:40:40.0122 2468 arcsas - ok
13:40:40.0153 2468 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
13:40:40.0153 2468 aswFsBlk - ok
13:40:40.0216 2468 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
13:40:40.0216 2468 aswMonFlt - ok
13:40:40.0278 2468 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
13:40:40.0278 2468 aswRdr - ok
13:40:40.0325 2468 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
13:40:40.0340 2468 aswSnx - ok
13:40:40.0400 2468 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
13:40:40.0410 2468 aswSP - ok
13:40:40.0450 2468 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
13:40:40.0450 2468 aswTdi - ok
13:40:40.0500 2468 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
13:40:40.0500 2468 AsyncMac - ok
13:40:40.0530 2468 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
13:40:40.0540 2468 atapi - ok
13:40:40.0750 2468 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
13:40:40.0810 2468 atikmdag - ok
13:40:40.0920 2468 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
13:40:40.0920 2468 b06bdrv - ok
13:40:40.0960 2468 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
13:40:40.0960 2468 b57nd60x - ok
13:40:41.0000 2468 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
13:40:41.0010 2468 Beep - ok
13:40:41.0040 2468 blbdrive (a6b4c8894619b4bf735db45108fb0322) C:\Windows\system32\DRIVERS\blbdrive.sys
13:40:41.0040 2468 blbdrive - ok
13:40:41.0160 2468 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
13:40:41.0170 2468 bowser - ok
13:40:41.0240 2468 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:40:41.0250 2468 BrFiltLo - ok
13:40:41.0280 2468 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:40:41.0290 2468 BrFiltUp - ok
13:40:41.0340 2468 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
13:40:41.0340 2468 Brserid - ok
13:40:41.0390 2468 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
13:40:41.0390 2468 BrSerWdm - ok
13:40:41.0420 2468 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:40:41.0430 2468 BrUsbMdm - ok
13:40:41.0440 2468 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
13:40:41.0450 2468 BrUsbSer - ok
13:40:41.0480 2468 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
13:40:41.0490 2468 BTHMODEM - ok
13:40:41.0610 2468 catchme - ok
13:40:41.0660 2468 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
13:40:41.0660 2468 cdfs - ok
13:40:41.0720 2468 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
13:40:41.0720 2468 cdrom - ok
13:40:41.0760 2468 CFcatchme - ok
13:40:41.0780 2468 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
13:40:41.0780 2468 circlass - ok
13:40:41.0820 2468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
13:40:41.0820 2468 CLFS - ok
13:40:41.0890 2468 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
13:40:41.0890 2468 CmBatt - ok
13:40:41.0950 2468 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
13:40:41.0950 2468 cmdide - ok
13:40:41.0990 2468 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
13:40:42.0000 2468 CNG - ok
13:40:42.0030 2468 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
13:40:42.0040 2468 Compbatt - ok
13:40:42.0080 2468 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
13:40:42.0080 2468 CompositeBus - ok
13:40:42.0110 2468 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
13:40:42.0110 2468 crcdisk - ok
13:40:42.0160 2468 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
13:40:42.0170 2468 CSC - ok
13:40:42.0220 2468 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
13:40:42.0220 2468 DfsC - ok
13:40:42.0240 2468 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
13:40:42.0240 2468 discache - ok
13:40:42.0270 2468 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
13:40:42.0270 2468 Disk - ok
13:40:42.0350 2468 driverhardwarev2 (b019db2d3bc4530759abd8440e6bcd28) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
13:40:42.0360 2468 driverhardwarev2 - ok
13:40:42.0390 2468 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
13:40:42.0390 2468 drmkaud - ok
13:40:42.0422 2468 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
13:40:42.0422 2468 DXGKrnl - ok
13:40:42.0484 2468 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
13:40:42.0515 2468 ebdrv - ok
13:40:42.0562 2468 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
13:40:42.0562 2468 elxstor - ok
13:40:42.0593 2468 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
13:40:42.0593 2468 ErrDev - ok
13:40:42.0624 2468 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
13:40:42.0624 2468 exfat - ok
13:40:42.0656 2468 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
13:40:42.0656 2468 fastfat - ok
13:40:42.0671 2468 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
13:40:42.0671 2468 fdc - ok
13:40:42.0702 2468 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
13:40:42.0702 2468 FileInfo - ok
13:40:42.0718 2468 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
13:40:42.0718 2468 Filetrace - ok
13:40:42.0734 2468 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
13:40:42.0734 2468 flpydisk - ok
13:40:42.0749 2468 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
13:40:42.0749 2468 FltMgr - ok
13:40:42.0780 2468 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
13:40:42.0780 2468 FsDepends - ok
13:40:42.0827 2468 fssfltr (491e9d9a26a745f6ae7d570849f4bd87) C:\Windows\system32\DRIVERS\fssfltr.sys
13:40:42.0843 2468 fssfltr - ok
13:40:42.0890 2468 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
13:40:42.0890 2468 Fs_Rec - ok
13:40:42.0936 2468 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
13:40:42.0952 2468 fvevol - ok
13:40:42.0983 2468 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:40:42.0983 2468 gagp30kx - ok
13:40:42.0999 2468 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:40:43.0014 2468 GEARAspiWDM - ok
13:40:43.0092 2468 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
13:40:43.0108 2468 hamachi - ok
13:40:43.0373 2468 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
13:40:43.0389 2468 hcw85cir - ok
13:40:43.0607 2468 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
13:40:43.0607 2468 HdAudAddService - ok
13:40:43.0763 2468 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
13:40:43.0779 2468 HDAudBus - ok
13:40:43.0810 2468 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
13:40:43.0810 2468 HidBatt - ok
13:40:43.0872 2468 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
13:40:43.0888 2468 HidBth - ok
13:40:43.0919 2468 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
13:40:43.0919 2468 HidIr - ok
13:40:43.0982 2468 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
13:40:43.0982 2468 HidUsb - ok
13:40:44.0044 2468 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
13:40:44.0044 2468 HpSAMD - ok
13:40:44.0091 2468 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
13:40:44.0106 2468 HTTP - ok
13:40:44.0153 2468 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
13:40:44.0153 2468 hwpolicy - ok
13:40:44.0184 2468 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
13:40:44.0184 2468 i8042prt - ok
13:40:44.0231 2468 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys
13:40:44.0247 2468 iaStorV - ok
13:40:44.0278 2468 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
13:40:44.0309 2468 iirsp - ok
13:40:44.0356 2468 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
13:40:44.0356 2468 intelide - ok
13:40:44.0387 2468 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
13:40:44.0387 2468 intelppm - ok
13:40:44.0403 2468 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:40:44.0403 2468 IpFilterDriver - ok
13:40:44.0434 2468 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
13:40:44.0434 2468 IPMIDRV - ok
13:40:44.0450 2468 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
13:40:44.0465 2468 IPNAT - ok
13:40:44.0496 2468 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
13:40:44.0496 2468 IRENUM - ok
13:40:44.0528 2468 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
13:40:44.0528 2468 isapnp - ok
13:40:44.0559 2468 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
13:40:44.0559 2468 iScsiPrt - ok
13:40:44.0590 2468 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
13:40:44.0590 2468 kbdclass - ok
13:40:44.0621 2468 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
13:40:44.0621 2468 kbdhid - ok
13:40:44.0652 2468 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
13:40:44.0668 2468 KSecDD - ok
13:40:44.0684 2468 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
13:40:44.0684 2468 KSecPkg - ok
13:40:44.0699 2468 LgBttPort - ok
13:40:44.0715 2468 lgbusenum - ok
13:40:44.0746 2468 LGVMODEM - ok
13:40:44.0793 2468 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
13:40:44.0793 2468 lltdio - ok
13:40:44.0840 2468 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:40:44.0840 2468 LSI_FC - ok
13:40:44.0871 2468 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:40:44.0871 2468 LSI_SAS - ok
13:40:44.0886 2468 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:40:44.0886 2468 LSI_SAS2 - ok
13:40:44.0902 2468 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:40:44.0918 2468 LSI_SCSI - ok
13:40:44.0949 2468 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
13:40:44.0949 2468 luafv - ok
13:40:44.0996 2468 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
13:40:44.0996 2468 megasas - ok
13:40:45.0027 2468 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
13:40:45.0027 2468 MegaSR - ok
13:40:45.0042 2468 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
13:40:45.0042 2468 Modem - ok
13:40:45.0074 2468 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
13:40:45.0074 2468 monitor - ok
13:40:45.0136 2468 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
13:40:45.0136 2468 mouclass - ok
13:40:45.0401 2468 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
13:40:45.0401 2468 mouhid - ok
13:40:45.0448 2468 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
13:40:45.0448 2468 mountmgr - ok
13:40:45.0495 2468 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
13:40:45.0495 2468 mpio - ok
13:40:45.0510 2468 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
13:40:45.0526 2468 mpsdrv - ok
13:40:45.0557 2468 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
13:40:45.0557 2468 MRxDAV - ok
13:40:45.0588 2468 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:40:45.0604 2468 mrxsmb - ok
13:40:45.0635 2468 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:40:45.0635 2468 mrxsmb10 - ok
13:40:45.0651 2468 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:40:45.0666 2468 mrxsmb20 - ok
13:40:45.0682 2468 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
13:40:45.0682 2468 msahci - ok
13:40:45.0729 2468 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
13:40:45.0729 2468 msdsm - ok
13:40:45.0760 2468 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
13:40:45.0776 2468 Msfs - ok
13:40:45.0791 2468 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
13:40:45.0791 2468 mshidkmdf - ok
13:40:45.0807 2468 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\Windows\system32\Drivers\nx6000.sys
13:40:45.0807 2468 MSHUSBVideo - ok
13:40:45.0838 2468 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
13:40:45.0838 2468 msisadrv - ok
13:40:45.0869 2468 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
13:40:45.0885 2468 MSKSSRV - ok
13:40:45.0885 2468 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
13:40:45.0885 2468 MSPCLOCK - ok
13:40:45.0900 2468 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
13:40:45.0900 2468 MSPQM - ok
13:40:45.0932 2468 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
13:40:45.0932 2468 MsRPC - ok
13:40:45.0947 2468 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
13:40:45.0947 2468 mssmbios - ok
13:40:45.0963 2468 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
13:40:45.0963 2468 MSTEE - ok
13:40:45.0978 2468 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
13:40:45.0978 2468 MTConfig - ok
13:40:46.0010 2468 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
13:40:46.0010 2468 Mup - ok
13:40:46.0041 2468 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
13:40:46.0041 2468 NativeWifiP - ok
13:40:46.0088 2468 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
13:40:46.0103 2468 NDIS - ok
13:40:46.0119 2468 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
13:40:46.0119 2468 NdisCap - ok
13:40:46.0150 2468 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
13:40:46.0150 2468 NdisTapi - ok
13:40:46.0181 2468 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
13:40:46.0181 2468 Ndisuio - ok
13:40:46.0212 2468 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
13:40:46.0228 2468 NdisWan - ok
13:40:46.0259 2468 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
13:40:46.0259 2468 NDProxy - ok
13:40:46.0275 2468 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
13:40:46.0275 2468 NetBIOS - ok
13:40:46.0306 2468 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
13:40:46.0306 2468 NetBT - ok
13:40:46.0384 2468 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
13:40:46.0384 2468 nfrd960 - ok
13:40:46.0446 2468 npf (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys
13:40:46.0446 2468 npf - ok
13:40:46.0462 2468 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
13:40:46.0462 2468 Npfs - ok
13:40:46.0493 2468 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
13:40:46.0493 2468 nsiproxy - ok
13:40:46.0540 2468 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys
13:40:46.0556 2468 Ntfs - ok
13:40:46.0571 2468 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
13:40:46.0571 2468 Null - ok
13:40:46.0602 2468 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys
13:40:46.0618 2468 nvraid - ok
13:40:46.0634 2468 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys
13:40:46.0649 2468 nvstor - ok
13:40:46.0680 2468 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
13:40:46.0680 2468 nv_agp - ok
13:40:46.0696 2468 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
13:40:46.0712 2468 ohci1394 - ok
13:40:46.0758 2468 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
13:40:46.0758 2468 Parport - ok
13:40:46.0790 2468 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
13:40:46.0790 2468 partmgr - ok
13:40:46.0805 2468 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
13:40:46.0805 2468 Parvdm - ok
13:40:46.0836 2468 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
13:40:46.0836 2468 pci - ok
13:40:46.0852 2468 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
13:40:46.0852 2468 pciide - ok
13:40:46.0883 2468 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
13:40:46.0883 2468 pcmcia - ok
13:40:46.0914 2468 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
13:40:46.0914 2468 pcw - ok
13:40:46.0946 2468 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
13:40:46.0946 2468 PEAUTH - ok
13:40:47.0117 2468 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
13:40:47.0133 2468 PptpMiniport - ok
13:40:47.0148 2468 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
13:40:47.0148 2468 Processor - ok
13:40:47.0211 2468 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
13:40:47.0211 2468 Psched - ok
13:40:47.0258 2468 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
13:40:47.0273 2468 ql2300 - ok
13:40:47.0304 2468 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
13:40:47.0304 2468 ql40xx - ok
13:40:47.0336 2468 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
13:40:47.0336 2468 QWAVEdrv - ok
13:40:47.0351 2468 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
13:40:47.0351 2468 RasAcd - ok
13:40:47.0382 2468 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:40:47.0382 2468 RasAgileVpn - ok
13:40:47.0414 2468 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:40:47.0414 2468 Rasl2tp - ok
13:40:47.0445 2468 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
13:40:47.0445 2468 RasPppoe - ok
13:40:47.0476 2468 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
13:40:47.0476 2468 RasSstp - ok
13:40:47.0507 2468 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
13:40:47.0507 2468 rdbss - ok
13:40:47.0523 2468 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
13:40:47.0523 2468 rdpbus - ok
13:40:47.0554 2468 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:40:47.0554 2468 RDPCDD - ok
13:40:47.0585 2468 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
13:40:47.0585 2468 RDPDR - ok
13:40:47.0616 2468 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
13:40:47.0616 2468 RDPENCDD - ok
13:40:47.0632 2468 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
13:40:47.0648 2468 RDPREFMP - ok
13:40:47.0663 2468 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
13:40:47.0679 2468 RDPWD - ok
13:40:47.0710 2468 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
13:40:47.0726 2468 rdyboost - ok
13:40:47.0772 2468 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
13:40:47.0772 2468 rspndr - ok
13:40:47.0804 2468 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys
13:40:47.0819 2468 RTL8167 - ok
13:40:47.0850 2468 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
13:40:47.0850 2468 s3cap - ok
13:40:47.0882 2468 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
13:40:47.0897 2468 sbp2port - ok
13:40:47.0928 2468 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
13:40:47.0928 2468 scfilter - ok
13:40:47.0975 2468 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
13:40:47.0975 2468 secdrv - ok
13:40:48.0022 2468 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
13:40:48.0022 2468 Serenum - ok
13:40:48.0038 2468 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
13:40:48.0038 2468 Serial - ok
13:40:48.0084 2468 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
13:40:48.0084 2468 sermouse - ok
13:40:48.0116 2468 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
13:40:48.0116 2468 sffdisk - ok
13:40:48.0131 2468 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
13:40:48.0131 2468 sffp_mmc - ok
13:40:48.0147 2468 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
13:40:48.0162 2468 sffp_sd - ok
13:40:48.0194 2468 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
13:40:48.0194 2468 sfloppy - ok
13:40:48.0225 2468 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
13:40:48.0225 2468 sisagp - ok
13:40:48.0256 2468 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:40:48.0256 2468 SiSRaid2 - ok
13:40:48.0272 2468 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
13:40:48.0287 2468 SiSRaid4 - ok
13:40:48.0303 2468 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
13:40:48.0318 2468 Smb - ok
13:40:48.0350 2468 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
13:40:48.0350 2468 spldr - ok
13:40:48.0381 2468 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
13:40:48.0396 2468 srv - ok
13:40:48.0412 2468 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
13:40:48.0412 2468 srv2 - ok
13:40:48.0459 2468 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
13:40:48.0459 2468 srvnet - ok
13:40:48.0506 2468 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\Windows\system32\drivers\StarOpen.sys
13:40:48.0506 2468 StarOpen - ok
13:40:48.0552 2468 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
13:40:48.0552 2468 stexstor - ok
13:40:48.0584 2468 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
13:40:48.0584 2468 storflt - ok
13:40:48.0630 2468 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
13:40:48.0630 2468 storvsc - ok
13:40:48.0662 2468 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
13:40:48.0662 2468 swenum - ok
13:40:48.0740 2468 Tcpip (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\drivers\tcpip.sys
13:40:48.0755 2468 Tcpip - ok
13:40:48.0771 2468 TCPIP6 (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\DRIVERS\tcpip.sys
13:40:48.0786 2468 TCPIP6 - ok
13:40:48.0818 2468 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
13:40:48.0833 2468 tcpipreg - ok
13:40:48.0864 2468 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
13:40:48.0864 2468 TDPIPE - ok
13:40:48.0880 2468 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
13:40:48.0880 2468 TDTCP - ok
13:40:48.0911 2468 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
13:40:48.0911 2468 tdx - ok
13:40:48.0942 2468 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
13:40:48.0942 2468 TermDD - ok
13:40:49.0005 2468 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:40:49.0005 2468 tssecsrv - ok
13:40:49.0052 2468 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
13:40:49.0052 2468 TsUsbFlt - ok
13:40:49.0208 2468 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
13:40:49.0239 2468 tunnel - ok
13:40:49.0379 2468 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
13:40:49.0410 2468 uagp35 - ok
13:40:49.0598 2468 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
13:40:49.0613 2468 udfs - ok
13:40:49.0754 2468 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
13:40:49.0785 2468 uliagpkx - ok
13:40:49.0925 2468 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
13:40:49.0941 2468 umbus - ok
13:40:49.0972 2468 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
13:40:50.0003 2468 UmPass - ok
13:40:50.0097 2468 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys
13:40:50.0097 2468 USBAAPL - ok
13:40:50.0206 2468 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
13:40:50.0206 2468 usbaudio - ok
13:40:50.0253 2468 usbbus (9419faac6552a51542dbba02971c841c) C:\Windows\system32\DRIVERS\lgusbbus.sys
13:40:50.0253 2468 usbbus - ok
13:40:50.0315 2468 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\drivers\usbccgp.sys
13:40:50.0315 2468 usbccgp - ok
13:40:50.0346 2468 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
13:40:50.0346 2468 usbcir - ok
13:40:50.0378 2468 UsbDiag (c0a466fa4ffec464320e159bc1bbdc0c) C:\Windows\system32\DRIVERS\lgusbdiag.sys
13:40:50.0378 2468 UsbDiag - ok
13:40:50.0409 2468 usbehci (cfbce999c057d78979a181c9c60f208e) C:\Windows\system32\drivers\usbehci.sys
13:40:50.0409 2468 usbehci - ok
13:40:50.0487 2468 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys
13:40:50.0502 2468 usbhub - ok
13:40:50.0565 2468 USBModem (f74a54774a9b0afeb3c40adec68aa600) C:\Windows\system32\DRIVERS\lgusbmodem.sys
13:40:50.0565 2468 USBModem - ok
13:40:50.0596 2468 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\drivers\usbohci.sys
13:40:50.0612 2468 usbohci - ok
13:40:50.0658 2468 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
13:40:50.0658 2468 usbprint - ok
13:40:50.0690 2468 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
13:40:50.0690 2468 usbscan - ok
13:40:50.0705 2468 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:40:50.0705 2468 USBSTOR - ok
13:40:50.0736 2468 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\drivers\usbuhci.sys
13:40:50.0736 2468 usbuhci - ok
13:40:50.0799 2468 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
13:40:50.0814 2468 usbvideo - ok
13:40:50.0861 2468 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
13:40:50.0861 2468 vdrvroot - ok
13:40:50.0924 2468 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
13:40:50.0924 2468 vga - ok
13:40:50.0955 2468 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
13:40:50.0955 2468 VgaSave - ok
13:40:50.0986 2468 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
13:40:50.0986 2468 vhdmp - ok
13:40:51.0033 2468 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
13:40:51.0033 2468 viaagp - ok
13:40:51.0064 2468 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
13:40:51.0080 2468 ViaC7 - ok
13:40:51.0126 2468 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
13:40:51.0126 2468 viaide - ok
13:40:51.0173 2468 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
13:40:51.0173 2468 vmbus - ok
13:40:51.0204 2468 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
13:40:51.0220 2468 VMBusHID - ok
13:40:51.0251 2468 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
13:40:51.0251 2468 volmgr - ok
13:40:51.0282 2468 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
13:40:51.0298 2468 volmgrx - ok
13:40:51.0392 2468 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
13:40:51.0407 2468 volsnap - ok
13:40:51.0485 2468 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
13:40:51.0501 2468 vsmraid - ok
13:40:51.0548 2468 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
13:40:51.0563 2468 vwifibus - ok
13:40:51.0641 2468 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
13:40:51.0641 2468 WacomPen - ok
13:40:51.0766 2468 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:40:51.0766 2468 WANARP - ok
13:40:51.0782 2468 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:40:51.0797 2468 Wanarpv6 - ok
13:40:52.0140 2468 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
13:40:52.0156 2468 Wd - ok
13:40:52.0265 2468 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
13:40:52.0296 2468 Wdf01000 - ok
13:40:52.0468 2468 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
13:40:52.0468 2468 WfpLwf - ok
13:40:52.0562 2468 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
13:40:52.0562 2468 WIMMount - ok
13:40:52.0718 2468 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
13:40:52.0733 2468 WinUsb - ok
13:40:52.0842 2468 WLNdis50 (bb2c5a7a555b387b85481b8bde5370d7) C:\Windows\system32\DRIVERS\wlndis50.sys
13:40:52.0858 2468 WLNdis50 - ok
13:40:52.0936 2468 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
13:40:52.0952 2468 WmiAcpi - ok
13:40:53.0076 2468 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
13:40:53.0092 2468 ws2ifsl - ok
13:40:53.0232 2468 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
13:40:53.0248 2468 WudfPf - ok
13:40:53.0451 2468 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:40:53.0466 2468 WUDFRd - ok
13:40:53.0560 2468 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:40:53.0591 2468 \Device\Harddisk0\DR0 - ok
13:40:53.0607 2468 Boot (0x1200) (8086c33801f016f75be26d3cf7eb402d) \Device\Harddisk0\DR0\Partition0
13:40:53.0607 2468 \Device\Harddisk0\DR0\Partition0 - ok
13:40:53.0622 2468 Boot (0x1200) (6a154f0f04b3c917e0c6ec54fe781ce0) \Device\Harddisk0\DR0\Partition1
13:40:53.0638 2468 \Device\Harddisk0\DR0\Partition1 - ok
13:40:53.0654 2468 Boot (0x1200) (8a91e871226e431aba9411619e90cbf0) \Device\Harddisk0\DR0\Partition2
13:40:53.0654 2468 \Device\Harddisk0\DR0\Partition2 - ok
13:40:53.0654 2468 ============================================================
13:40:53.0654 2468 Scan finished
13:40:53.0654 2468 ============================================================
13:40:53.0685 2600 Detected object count: 0
13:40:53.0685 2600 Actual detected object count: 0
13:41:29.0382 4024 ============================================================
13:41:29.0382 4024 Scan started
13:41:29.0382 4024 Mode: Manual;
13:41:29.0382 4024 ============================================================
13:41:30.0132 4024 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
13:41:30.0132 4024 1394ohci - ok
13:41:30.0172 4024 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
13:41:30.0172 4024 ACPI - ok
13:41:30.0192 4024 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
13:41:30.0192 4024 AcpiPmi - ok
13:41:30.0242 4024 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
13:41:30.0242 4024 adp94xx - ok
13:41:30.0262 4024 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
13:41:30.0272 4024 adpahci - ok
13:41:30.0292 4024 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
13:41:30.0292 4024 adpu320 - ok
13:41:30.0342 4024 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
13:41:30.0352 4024 AFD - ok
13:41:30.0362 4024 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
13:41:30.0362 4024 agp440 - ok
13:41:30.0382 4024 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
13:41:30.0382 4024 aic78xx - ok
13:41:30.0402 4024 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
13:41:30.0412 4024 aliide - ok
13:41:30.0422 4024 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
13:41:30.0422 4024 amdagp - ok
13:41:30.0437 4024 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
13:41:30.0437 4024 amdide - ok
13:41:30.0453 4024 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
13:41:30.0453 4024 AmdK8 - ok
13:41:30.0469 4024 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
13:41:30.0469 4024 AmdPPM - ok
13:41:30.0484 4024 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys
13:41:30.0484 4024 amdsata - ok
13:41:30.0500 4024 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
13:41:30.0500 4024 amdsbs - ok
13:41:30.0531 4024 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys
13:41:30.0531 4024 amdxata - ok
13:41:30.0562 4024 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
13:41:30.0562 4024 AppID - ok
13:41:30.0593 4024 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
13:41:30.0593 4024 arc - ok
13:41:30.0625 4024 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
13:41:30.0625 4024 arcsas - ok
13:41:30.0640 4024 aswFsBlk (c47623ffd181a1e7d63574dde2a0a711) C:\Windows\system32\drivers\aswFsBlk.sys
13:41:30.0640 4024 aswFsBlk - ok
13:41:30.0687 4024 aswMonFlt (4804753a4ec7d67cc22d226bffd1c1e3) C:\Windows\system32\drivers\aswMonFlt.sys
13:41:30.0687 4024 aswMonFlt - ok
13:41:30.0749 4024 aswRdr (36239e24470a3dd81fae37510953cc6c) C:\Windows\system32\drivers\aswRdr.sys
13:41:30.0749 4024 aswRdr - ok
13:41:30.0796 4024 aswSnx (caa846e9c83836bdc3d2d700c678db65) C:\Windows\system32\drivers\aswSnx.sys
13:41:30.0812 4024 aswSnx - ok
13:41:30.0859 4024 aswSP (748ae7f2d7da33adb063fe05704a9969) C:\Windows\system32\drivers\aswSP.sys
13:41:30.0859 4024 aswSP - ok
13:41:30.0890 4024 aswTdi (ca9925ce1dbd07ffe1eb357752cf5577) C:\Windows\system32\drivers\aswTdi.sys
13:41:30.0890 4024 aswTdi - ok
13:41:30.0905 4024 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
13:41:30.0905 4024 AsyncMac - ok
13:41:30.0937 4024 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
13:41:30.0937 4024 atapi - ok
13:41:31.0061 4024 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys
13:41:31.0093 4024 atikmdag - ok
13:41:31.0139 4024 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
13:41:31.0139 4024 b06bdrv - ok
13:41:31.0171 4024 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
13:41:31.0171 4024 b57nd60x - ok
13:41:31.0202 4024 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
13:41:31.0202 4024 Beep - ok
13:41:31.0233 4024 blbdrive (a6b4c8894619b4bf735db45108fb0322) C:\Windows\system32\DRIVERS\blbdrive.sys
13:41:31.0233 4024 blbdrive - ok
13:41:31.0264 4024 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
13:41:31.0264 4024 bowser - ok
13:41:31.0280 4024 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:41:31.0295 4024 BrFiltLo - ok
13:41:31.0311 4024 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:41:31.0311 4024 BrFiltUp - ok
13:41:31.0342 4024 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
13:41:31.0342 4024 Brserid - ok
13:41:31.0358 4024 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
13:41:31.0358 4024 BrSerWdm - ok
13:41:31.0373 4024 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:41:31.0373 4024 BrUsbMdm - ok
13:41:31.0405 4024 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
13:41:31.0405 4024 BrUsbSer - ok
13:41:31.0420 4024 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
13:41:31.0420 4024 BTHMODEM - ok
13:41:31.0514 4024 catchme - ok
13:41:31.0545 4024 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
13:41:31.0545 4024 cdfs - ok
13:41:31.0592 4024 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
13:41:31.0592 4024 cdrom - ok
13:41:31.0607 4024 CFcatchme - ok
13:41:31.0623 4024 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
13:41:31.0623 4024 circlass - ok
13:41:31.0654 4024 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
13:41:31.0670 4024 CLFS - ok
13:41:31.0717 4024 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
13:41:31.0717 4024 CmBatt - ok
13:41:31.0748 4024 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
13:41:31.0748 4024 cmdide - ok
13:41:31.0779 4024 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
13:41:31.0779 4024 CNG - ok
13:41:31.0795 4024 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
13:41:31.0795 4024 Compbatt - ok
13:41:31.0826 4024 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
13:41:31.0826 4024 CompositeBus - ok
13:41:31.0841 4024 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
13:41:31.0841 4024 crcdisk - ok
13:41:31.0888 4024 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
13:41:31.0888 4024 CSC - ok
13:41:31.0935 4024 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
13:41:31.0935 4024 DfsC - ok
13:41:31.0966 4024 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
13:41:31.0966 4024 discache - ok
13:41:31.0982 4024 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
13:41:31.0982 4024 Disk - ok
13:41:32.0044 4024 driverhardwarev2 (b019db2d3bc4530759abd8440e6bcd28) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
13:41:32.0044 4024 driverhardwarev2 - ok
13:41:32.0075 4024 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
13:41:32.0075 4024 drmkaud - ok
13:41:32.0138 4024 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
13:41:32.0153 4024 DXGKrnl - ok
13:41:32.0247 4024 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
13:41:32.0263 4024 ebdrv - ok
13:41:32.0309 4024 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
13:41:32.0309 4024 elxstor - ok
13:41:32.0325 4024 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
13:41:32.0325 4024 ErrDev - ok
13:41:32.0372 4024 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
13:41:32.0372 4024 exfat - ok
13:41:32.0387 4024 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
13:41:32.0387 4024 fastfat - ok
13:41:32.0419 4024 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
13:41:32.0419 4024 fdc - ok
13:41:32.0434 4024 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
13:41:32.0434 4024 FileInfo - ok
13:41:32.0450 4024 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
13:41:32.0450 4024 Filetrace - ok
13:41:32.0465 4024 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
13:41:32.0465 4024 flpydisk - ok
13:41:32.0497 4024 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
13:41:32.0497 4024 FltMgr - ok
13:41:32.0512 4024 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
13:41:32.0512 4024 FsDepends - ok
13:41:32.0543 4024 fssfltr (491e9d9a26a745f6ae7d570849f4bd87) C:\Windows\system32\DRIVERS\fssfltr.sys
13:41:32.0543 4024 fssfltr - ok
13:41:32.0575 4024 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
13:41:32.0575 4024 Fs_Rec - ok
13:41:32.0606 4024 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
13:41:32.0621 4024 fvevol - ok
13:41:32.0637 4024 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:41:32.0637 4024 gagp30kx - ok
13:41:32.0668 4024 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:41:32.0668 4024 GEARAspiWDM - ok
13:41:32.0731 4024 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys
13:41:32.0731 4024 hamachi - ok
13:41:32.0746 4024 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
13:41:32.0762 4024 hcw85cir - ok
13:41:32.0793 4024 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
13:41:32.0793 4024 HdAudAddService - ok
13:41:32.0824 4024 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
13:41:32.0824 4024 HDAudBus - ok
13:41:32.0855 4024 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
13:41:32.0855 4024 HidBatt - ok
13:41:32.0871 4024 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
13:41:32.0871 4024 HidBth - ok
13:41:32.0902 4024 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
13:41:32.0902 4024 HidIr - ok
13:41:32.0933 4024 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys
13:41:32.0933 4024 HidUsb - ok
13:41:32.0965 4024 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
13:41:32.0965 4024 HpSAMD - ok
13:41:32.0996 4024 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
13:41:32.0996 4024 HTTP - ok
13:41:33.0027 4024 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
13:41:33.0043 4024 hwpolicy - ok
13:41:33.0074 4024 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
13:41:33.0074 4024 i8042prt - ok
13:41:33.0105 4024 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys
13:41:33.0105 4024 iaStorV - ok
13:41:33.0121 4024 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
13:41:33.0121 4024 iirsp - ok
13:41:33.0152 4024 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
13:41:33.0152 4024 intelide - ok
13:41:33.0183 4024 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
13:41:33.0183 4024 intelppm - ok
13:41:33.0214 4024 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:41:33.0214 4024 IpFilterDriver - ok
13:41:33.0245 4024 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
13:41:33.0245 4024 IPMIDRV - ok
13:41:33.0277 4024 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
13:41:33.0277 4024 IPNAT - ok
13:41:33.0292 4024 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
13:41:33.0292 4024 IRENUM - ok
13:41:33.0323 4024 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
13:41:33.0323 4024 isapnp - ok
13:41:33.0355 4024 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
13:41:33.0355 4024 iScsiPrt - ok
13:41:33.0417 4024 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
13:41:33.0417 4024 kbdclass - ok
13:41:33.0448 4024 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
13:41:33.0448 4024 kbdhid - ok
13:41:33.0495 4024 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
13:41:33.0495 4024 KSecDD - ok
13:41:33.0511 4024 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
13:41:33.0526 4024 KSecPkg - ok
13:41:33.0542 4024 LgBttPort - ok
13:41:33.0557 4024 lgbusenum - ok
13:41:33.0573 4024 LGVMODEM - ok
13:41:33.0589 4024 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
13:41:33.0589 4024 lltdio - ok
13:41:33.0635 4024 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:41:33.0635 4024 LSI_FC - ok
13:41:33.0651 4024 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:41:33.0651 4024 LSI_SAS - ok
13:41:33.0667 4024 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:41:33.0667 4024 LSI_SAS2 - ok
13:41:33.0713 4024 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:41:33.0713 4024 LSI_SCSI - ok
13:41:33.0745 4024 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
13:41:33.0745 4024 luafv - ok
13:41:33.0776 4024 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
13:41:33.0776 4024 megasas - ok
13:41:33.0791 4024 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
13:41:33.0807 4024 MegaSR - ok
13:41:33.0823 4024 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
13:41:33.0823 4024 Modem - ok
13:41:33.0854 4024 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
13:41:33.0854 4024 monitor - ok
13:41:33.0885 4024 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys
13:41:33.0885 4024 mouclass - ok
13:41:33.0901 4024 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
13:41:33.0901 4024 mouhid - ok
13:41:33.0932 4024 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
13:41:33.0932 4024 mountmgr - ok
13:41:33.0979 4024 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
13:41:33.0994 4024 mpio - ok
13:41:34.0010 4024 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
13:41:34.0025 4024 mpsdrv - ok
13:41:34.0072 4024 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
13:41:34.0072 4024 MRxDAV - ok
13:41:34.0088 4024 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:41:34.0088 4024 mrxsmb - ok
13:41:34.0135 4024 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:41:34.0135 4024 mrxsmb10 - ok
13:41:34.0150 4024 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:41:34.0150 4024 mrxsmb20 - ok
13:41:34.0181 4024 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
13:41:34.0181 4024 msahci - ok
13:41:34.0213 4024 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
13:41:34.0213 4024 msdsm - ok
13:41:34.0228 4024 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
13:41:34.0228 4024 Msfs - ok
13:41:34.0244 4024 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
13:41:34.0244 4024 mshidkmdf - ok
13:41:34.0259 4024 MSHUSBVideo (5119ffc2a6b51089cdb0efdc75808c97) C:\Windows\system32\Drivers\nx6000.sys
13:41:34.0275 4024 MSHUSBVideo - ok
13:41:34.0291 4024 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
13:41:34.0291 4024 msisadrv - ok
13:41:34.0322 4024 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
13:41:34.0322 4024 MSKSSRV - ok
13:41:34.0322 4024 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
13:41:34.0337 4024 MSPCLOCK - ok
13:41:34.0337 4024 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
13:41:34.0337 4024 MSPQM - ok
13:41:34.0369 4024 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
13:41:34.0369 4024 MsRPC - ok
13:41:34.0400 4024 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
13:41:34.0400 4024 mssmbios - ok
13:41:34.0400 4024 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
13:41:34.0400 4024 MSTEE - ok
13:41:34.0431 4024 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
13:41:34.0431 4024 MTConfig - ok
13:41:34.0447 4024 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
13:41:34.0447 4024 Mup - ok
13:41:34.0478 4024 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
13:41:34.0478 4024 NativeWifiP - ok
13:41:34.0525 4024 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
13:41:34.0525 4024 NDIS - ok
13:41:34.0556 4024 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
13:41:34.0556 4024 NdisCap - ok
13:41:34.0571 4024 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
13:41:34.0571 4024 NdisTapi - ok
13:41:34.0603 4024 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
13:41:34.0603 4024 Ndisuio - ok
13:41:34.0634 4024 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
13:41:34.0634 4024 NdisWan - ok
13:41:34.0681 4024 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
13:41:34.0681 4024 NDProxy - ok
13:41:34.0727 4024 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
13:41:34.0727 4024 NetBIOS - ok
13:41:34.0790 4024 NetBT (280122ddcf
Utilisateur anonyme
27 oct. 2011 à 13:47
27 oct. 2011 à 13:47
▶ Télécharge : Gmer (by Przemyslaw Gmerek) clique sur "Download EXE" et enregistre-le sur ton bureau
Desactive toutes tes protections le temps du scan de gMer
Pour XP => double clique sur gmer.exe
Pour Vista et 7 => clique droit "executer en tant que...."
▶ clique sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.
▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
Desactive toutes tes protections le temps du scan de gMer
Pour XP => double clique sur gmer.exe
Pour Vista et 7 => clique droit "executer en tant que...."
▶ clique sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.
▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-27 14:15:41
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-7 SAMSUNG_HD502HI rev.1AG01118
Running: idtc96ln.exe; Driver: C:\Users\arthur\AppData\Local\Temp\fxlcypoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8D032374]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8DCA32B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8D034996]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8D0349EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8D034B04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8D0348EC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8D034A3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8D034940]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8D034AB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8D032398]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8DCA3368]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8D032162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8D0323BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8D034EFC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8D032E54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8D0349C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8D034A16]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8D034B2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8D034918]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8D034A7E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8D03496E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8D034ADC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8DCA3400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8D032D1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8D0323E0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8D032404]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8D0321BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8D0322F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8D0322D4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8D03231C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8D032428]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C85349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CBED52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82CC5D80 4 Bytes [74, 23, 03, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82CC5DA8 4 Bytes [B8, 32, CA, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82CC5E5C 8 Bytes [96, 49, 03, 8D, EE, 49, 03, ...] {XCHG ESI, EAX; DEC ECX; ADD ECX, [EBP-0x72fcb612]}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82CC5E68 4 Bytes JMP 861762EF
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82CC5E84 4 Bytes [EC, 48, 03, 8D]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E83A000, 0x2D5378, 0xE8000020]
.text peauth.sys 9EE43C9D 28 Bytes [C4, AC, 65, D4, E8, C5, 2F, ...]
.text peauth.sys 9EE43CC1 28 Bytes [C4, AC, 65, D4, E8, C5, 2F, ...]
.text kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text user32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes [E9, 0A, 5C, 6E, 89] {JMP 0xffffffff896e5c0f}
.text user32.dll!UnhookWinEvent 76ABB750 5 Bytes [E9, A7, 4C, 6E, 89] {JMP 0xffffffff896e4cac}
.text user32.dll!SetWindowsHookExW 76ABE30C 5 Bytes [E9, F3, 24, 6E, 89] {JMP 0xffffffff896e24f8}
.text user32.dll!SetWinEventHook 76AC24DC 5 Bytes [E9, 17, DD, 6D, 89] {JMP 0xffffffff896ddd1c}
.text user32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes [E9, EF, 98, 6B, 89] {JMP 0xffffffff896b98f4}
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\AUDIODG.EXE[368] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[396] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[476] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[476] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[476] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[476] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\wininit.exe[476] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000E0600
.text C:\Windows\system32\csrss.exe[488] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\services.exe[524] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[524] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[524] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\lsass.exe[540] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[540] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[540] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\lsm.exe[548] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsm.exe[548] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsm.exe[548] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[668] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[668] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[668] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[808] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atiesrxx.exe[808] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atiesrxx.exe[808] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002F0A08
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002F0804
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Windows\system32\winlogon.exe[868] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[868] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[868] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000C0A08
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000C03FC
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000C0804
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000C01F8
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000C0600
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[908] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001B0A08
.text C:\Windows\System32\svchost.exe[908] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001B03FC
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001B0804
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001B01F8
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001B0600
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[952] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001A0A08
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001A03FC
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001A0804
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001A01F8
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001A0600
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00FE0A08
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 00FE03FC
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00FE0804
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 00FE01F8
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00FE0600
.text C:\Windows\system32\svchost.exe[1196] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[1196] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[1196] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00600A08
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 006003FC
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00600804
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 006001F8
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00600600
.text C:\Windows\system32\atieclxx.exe[1268] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atieclxx.exe[1268] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atieclxx.exe[1268] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1376] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1376] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002C0A08
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002C03FC
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002C0804
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002C01F8
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002C0600
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Windows\System32\spoolsv.exe[1568] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[1568] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[1568] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00140A08
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001403FC
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00140804
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001401F8
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00190A08
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001903FC
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00190804
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001901F8
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00190600
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00200A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002003FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00200804
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002001F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[1752] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1752] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1752] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00300A08
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 003003FC
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00300804
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 003001F8
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00300600
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00140A08
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001403FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00140804
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001401F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\svchost.exe[1964] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1964] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1964] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2044] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[2044] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[2044] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2172] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2172] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2172] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\taskhost.exe[2256] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[2256] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[2256] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000E0600
.text C:\Windows\system32\wuauclt.exe[2312] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000B03FC
.text C:\Windows\system32\wuauclt.exe[2312] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000B01F8
.text C:\Windows\system32\wuauclt.exe[2312] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00150A08
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001503FC
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00150804
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001501F8
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00150600
.text C:\Windows\system32\Dwm.exe[2692] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2692] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2692] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\Explorer.EXE[2756] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[2756] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[2756] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[2756] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00110A08
.text C:\Windows\Explorer.EXE[2756] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001103FC
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00110804
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001101F8
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00110600
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxParamW 76AD3B9B 5 Bytes JMP 72E1160B C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxIndirectParamW 76AE3B7F 5 Bytes JMP 7300605E C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxParamA 76AFCF42 5 Bytes JMP 73005FF9 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxIndirectParamA 76AFD274 5 Bytes JMP 730060C3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxIndirectA 76B0E869 5 Bytes JMP 73005F80 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxIndirectW 76B0E963 5 Bytes JMP 73005F07 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxExA 76B0E9C9 5 Bytes JMP 73005EA3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxExW 76B0E9ED 5 Bytes JMP 73005E3F C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002F0A08
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002F0804
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2888] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002B0A08
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002B03FC
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002B0804
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002B01F8
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002B0600
.text C:\Windows\system32\SearchProtocolHost.exe[2952] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchProtocolHost.exe[2952] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchProtocolHost.exe[2952] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\SearchIndexer.exe[3236] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3236] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3236] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\SearchProtocolHost.exe[3292] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchProtocolHost.exe[3292] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchProtocolHost.exe[3292] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!CreateWindowExA 76ABBF40 5 Bytes JMP 72E83293 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxParamW 76AD3B9B 5 Bytes JMP 72E1160B C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxIndirectParamW 76AE3B7F 5 Bytes JMP 7300605E C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxParamA 76AFCF42 5 Bytes JMP 73005FF9 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxIndirectParamA 76AFD274 5 Bytes JMP 730060C3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxIndirectA 76B0E869 5 Bytes JMP 73005F80 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxIndirectW 76B0E963 5 Bytes JMP 73005F07 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxExA 76B0E9C9 5 Bytes JMP 73005EA3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxExW 76B0E9ED 5 Bytes JMP 73005E3F C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ole32.dll!OleLoadFromStream 75AA6143 5 Bytes JMP 7300682D C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\SearchFilterHost.exe[3528] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchFilterHost.exe[3528] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchFilterHost.exe[3528] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text D:\arthur\Desktop\idtc96ln.exe[3612] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text D:\arthur\Desktop\idtc96ln.exe[3612] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text D:\arthur\Desktop\idtc96ln.exe[3612] kernel32.dll!GetBinaryTypeW + 70
Rootkit scan 2011-10-27 14:15:41
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-7 SAMSUNG_HD502HI rev.1AG01118
Running: idtc96ln.exe; Driver: C:\Users\arthur\AppData\Local\Temp\fxlcypoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8D032374]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8DCA32B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8D034996]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8D0349EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8D034B04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8D0348EC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8D034A3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8D034940]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8D034AB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8D032398]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8DCA3368]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8D032162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8D0323BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8D034EFC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8D032E54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8D0349C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8D034A16]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8D034B2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8D034918]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8D034A7E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8D03496E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8D034ADC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8DCA3400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8D032D1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8D0323E0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8D032404]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8D0321BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8D0322F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8D0322D4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8D03231C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8D032428]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C85349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CBED52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82CC5D80 4 Bytes [74, 23, 03, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82CC5DA8 4 Bytes [B8, 32, CA, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82CC5E5C 8 Bytes [96, 49, 03, 8D, EE, 49, 03, ...] {XCHG ESI, EAX; DEC ECX; ADD ECX, [EBP-0x72fcb612]}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82CC5E68 4 Bytes JMP 861762EF
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82CC5E84 4 Bytes [EC, 48, 03, 8D]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E83A000, 0x2D5378, 0xE8000020]
.text peauth.sys 9EE43C9D 28 Bytes [C4, AC, 65, D4, E8, C5, 2F, ...]
.text peauth.sys 9EE43CC1 28 Bytes [C4, AC, 65, D4, E8, C5, 2F, ...]
.text kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text user32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes [E9, 0A, 5C, 6E, 89] {JMP 0xffffffff896e5c0f}
.text user32.dll!UnhookWinEvent 76ABB750 5 Bytes [E9, A7, 4C, 6E, 89] {JMP 0xffffffff896e4cac}
.text user32.dll!SetWindowsHookExW 76ABE30C 5 Bytes [E9, F3, 24, 6E, 89] {JMP 0xffffffff896e24f8}
.text user32.dll!SetWinEventHook 76AC24DC 5 Bytes [E9, 17, DD, 6D, 89] {JMP 0xffffffff896ddd1c}
.text user32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes [E9, EF, 98, 6B, 89] {JMP 0xffffffff896b98f4}
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\AUDIODG.EXE[368] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[396] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[476] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[476] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[476] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[476] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\wininit.exe[476] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\wininit.exe[476] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000E0600
.text C:\Windows\system32\csrss.exe[488] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\services.exe[524] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[524] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[524] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\lsass.exe[540] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[540] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[540] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\lsm.exe[548] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsm.exe[548] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsm.exe[548] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[668] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[668] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[668] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[748] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[748] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[808] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atiesrxx.exe[808] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atiesrxx.exe[808] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002F0A08
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002F0804
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Windows\system32\atiesrxx.exe[808] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Windows\system32\winlogon.exe[868] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[868] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[868] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000C0A08
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000C03FC
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000C0804
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000C01F8
.text C:\Windows\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000C0600
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[908] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[908] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[908] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001B0A08
.text C:\Windows\System32\svchost.exe[908] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001B03FC
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001B0804
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001B01F8
.text C:\Windows\System32\svchost.exe[908] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001B0600
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[952] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001A0A08
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001A03FC
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001A0804
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001A01F8
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001A0600
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1000] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1000] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00FE0A08
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 00FE03FC
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00FE0804
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 00FE01F8
.text C:\Windows\system32\svchost.exe[1000] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00FE0600
.text C:\Windows\system32\svchost.exe[1196] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[1196] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[1196] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00600A08
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 006003FC
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00600804
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 006001F8
.text C:\Windows\system32\svchost.exe[1196] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00600600
.text C:\Windows\system32\atieclxx.exe[1268] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atieclxx.exe[1268] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atieclxx.exe[1268] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atieclxx.exe[1268] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1376] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1376] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1376] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002C0A08
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002C03FC
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002C0804
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002C01F8
.text C:\Windows\system32\svchost.exe[1376] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002C0600
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[1468] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Windows\System32\spoolsv.exe[1568] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[1568] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[1568] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00140A08
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001403FC
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00140804
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001401F8
.text C:\Windows\System32\spoolsv.exe[1568] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00190A08
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001903FC
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00190804
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001901F8
.text C:\Windows\system32\svchost.exe[1600] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00190600
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1676] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00200A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002003FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00200804
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002001F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1716] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[1752] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1752] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1752] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[1796] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00300A08
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 003003FC
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00300804
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 003001F8
.text C:\Program Files\CDBurnerXP\NMSAccessU.exe[1836] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00300600
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00140A08
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001403FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00140804
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001401F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[1920] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\svchost.exe[1964] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1964] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1964] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2044] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[2044] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[2044] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2172] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2172] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2172] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\svchost.exe[2172] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\taskhost.exe[2256] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[2256] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[2256] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[2256] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000E0600
.text C:\Windows\system32\wuauclt.exe[2312] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000B03FC
.text C:\Windows\system32\wuauclt.exe[2312] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000B01F8
.text C:\Windows\system32\wuauclt.exe[2312] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00150A08
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001503FC
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00150804
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001501F8
.text C:\Windows\system32\wuauclt.exe[2312] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00150600
.text C:\Windows\system32\Dwm.exe[2692] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2692] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2692] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\Dwm.exe[2692] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\Explorer.EXE[2756] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[2756] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[2756] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[2756] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00110A08
.text C:\Windows\Explorer.EXE[2756] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001103FC
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00110804
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001101F8
.text C:\Windows\Explorer.EXE[2756] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00110600
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxParamW 76AD3B9B 5 Bytes JMP 72E1160B C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxIndirectParamW 76AE3B7F 5 Bytes JMP 7300605E C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxParamA 76AFCF42 5 Bytes JMP 73005FF9 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!DialogBoxIndirectParamA 76AFD274 5 Bytes JMP 730060C3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxIndirectA 76B0E869 5 Bytes JMP 73005F80 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxIndirectW 76B0E963 5 Bytes JMP 73005F07 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxExA 76B0E9C9 5 Bytes JMP 73005EA3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2788] USER32.dll!MessageBoxExW 76B0E9ED 5 Bytes JMP 73005E3F C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002F0A08
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002F0804
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE[2864] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2880] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00210600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2888] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 002B0A08
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002B03FC
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 002B0804
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002B01F8
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2896] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002B0600
.text C:\Windows\system32\SearchProtocolHost.exe[2952] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchProtocolHost.exe[2952] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchProtocolHost.exe[2952] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\SearchProtocolHost.exe[2952] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Windows\system32\SearchIndexer.exe[3236] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3236] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3236] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\SearchIndexer.exe[3236] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\SearchProtocolHost.exe[3292] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\SearchProtocolHost.exe[3292] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\SearchProtocolHost.exe[3292] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 000F0A08
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 000F03FC
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 000F0804
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 000F01F8
.text C:\Windows\system32\SearchProtocolHost.exe[3292] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 002F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!CreateWindowExA 76ABBF40 5 Bytes JMP 72E83293 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxParamW 76AD3B9B 5 Bytes JMP 72E1160B C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxIndirectParamW 76AE3B7F 5 Bytes JMP 7300605E C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxParamA 76AFCF42 5 Bytes JMP 73005FF9 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!DialogBoxIndirectParamA 76AFD274 5 Bytes JMP 730060C3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxIndirectA 76B0E869 5 Bytes JMP 73005F80 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxIndirectW 76B0E963 5 Bytes JMP 73005F07 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxExA 76B0E9C9 5 Bytes JMP 73005EA3 C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] USER32.dll!MessageBoxExW 76B0E9ED 5 Bytes JMP 73005E3F C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3308] ole32.dll!OleLoadFromStream 75AA6143 5 Bytes JMP 7300682D C:\Windows\system32\IEFRAME.dll (Navigateur Internet/Microsoft Corporation)
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe[3484] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\SearchFilterHost.exe[3528] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchFilterHost.exe[3528] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchFilterHost.exe[3528] kernel32.dll!GetBinaryTypeW + 70 76F169F4 1 Byte [62]
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!UnhookWindowsHookEx 76ABADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!UnhookWinEvent 76ABB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWindowsHookExW 76ABE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWinEventHook 76AC24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\SearchFilterHost.exe[3528] USER32.dll!SetWindowsHookExA 76AE6D0C 5 Bytes JMP 00100600
.text D:\arthur\Desktop\idtc96ln.exe[3612] ntdll.dll!LdrUnloadDll 7765C8DE 5 Bytes JMP 001603FC
.text D:\arthur\Desktop\idtc96ln.exe[3612] ntdll.dll!LdrLoadDll 776622B8 5 Bytes JMP 001601F8
.text D:\arthur\Desktop\idtc96ln.exe[3612] kernel32.dll!GetBinaryTypeW + 70
Utilisateur anonyme
27 oct. 2011 à 15:42
27 oct. 2011 à 15:42
ta capture plus haut est bien obtenue à partir d'une detection sur-le-coup ?