Combofix Log
ComboFix 09-03-15.01 - Administrator 2009-03-18 7:59:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.646 [GMT 11:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
AV: Norton AntiVirus *On-access scanning disabled* (Outdated)
* Created a new restore point
FILE ::
c:\docume~1\ADMINI~1\LOCALS~1\Temp\ATICDSDr.sys
c:\windows\system32\drivers\gaopdxwviwesscosxacbrxnsvxextkbeetasmr.sys
.
((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.
2009-03-17 23:22 . 2009-03-17 23:22 <DIR> d-------- c:\program files\Western Digital Technologies
2009-03-17 22:17 . 2009-03-18 07:57 <DIR> d-------- C:\New Folder
2009-03-17 17:49 . 2009-01-10 06:19 1,089,593 --------- c:\windows\system32\dllcache\ntprint.cat
2009-03-16 15:34 . 2009-03-18 00:12 <DIR> d-------- c:\documents and settings\All Users\ShortcutBar
2009-03-16 12:52 . 2009-03-16 12:52 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-03-16 12:17 . 2009-03-16 12:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-03-16 12:16 . 2009-03-16 12:16 <DIR> d-------- c:\program files\NOS
2009-03-16 11:04 . 2009-03-16 11:04 <DIR> d-------- c:\program files\ATI Technologies
2009-03-16 11:03 . 2009-03-16 11:03 <DIR> d-------- C:\swsetup
2009-03-16 10:37 . 2009-03-16 10:37 <DIR> d-------- C:\ATI
2009-03-16 10:35 . 2009-03-16 10:35 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-16 10:35 . 2009-03-16 10:35 <DIR> d-------- c:\program files\MSBuild
2009-03-16 10:34 . 2009-03-16 10:34 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-16 10:34 . 2009-03-16 10:34 <DIR> d-------- C:\5928a8ecd7ae082322c4
2009-03-16 10:34 . 2008-07-06 23:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-16 10:34 . 2008-07-06 23:06 1,676,288 --------- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-16 10:34 . 2008-07-06 21:50 597,504 --------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-16 10:34 . 2008-07-06 23:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-16 10:34 . 2008-07-06 23:06 575,488 --------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-16 10:34 . 2008-07-06 23:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-16 10:34 . 2008-07-06 23:06 89,088 --------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-16 10:17 . 2009-03-16 10:18 <DIR> d-------- C:\ce0c6b92b18ab0d136022f0fe8e939
2009-03-16 10:17 . 2009-03-16 10:21 <DIR> d-------- C:\89c2510aac5b00fc8c88
2009-03-16 10:09 . 2009-03-16 10:09 29,696 --a------ c:\windows\system32\ATMenuxx.FTG
2009-03-16 10:09 . 2009-03-16 10:16 23,151 --ah----- c:\windows\system32\ATMenuxx.GID
2009-03-16 09:16 . 2008-04-14 11:11 21,504 --a------ c:\windows\system32\hidserv.dll
2009-03-16 09:16 . 2008-04-14 11:11 21,504 --a------ c:\windows\system32\dllcache\hidserv.dll
2009-03-15 23:58 . 2009-03-16 00:03 <DIR> d-------- C:\RootRepeal
2009-03-13 20:17 . 2009-03-13 20:17 <DIR> d-------- c:\program files\Common Files\AnswerWorks 4.0
2009-03-13 20:16 . 2009-03-13 20:16 <DIR> d-------- c:\program files\Leica Geosystems
2009-03-13 20:11 . 2009-03-13 20:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESRI
2009-03-10 20:53 . 2009-03-10 20:53 <DIR> d-------- c:\windows\system32\QuickTime
2009-03-10 20:52 . 2009-03-10 20:53 <DIR> d-------- c:\program files\QuickTime
2009-03-10 20:51 . 2009-03-10 20:51 <DIR> d-------- c:\program files\Red Orb
2009-03-09 21:07 . 2009-03-09 21:07 <DIR> d-------- c:\program files\Avira
2009-03-09 21:07 . 2009-03-09 21:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-09 20:34 . 2009-03-09 20:34 <DIR> d-------- c:\program files\Trend Micro
2009-03-08 23:35 . 2009-03-08 23:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-08 23:35 . 2009-03-16 07:53 <DIR> d-------- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-03-08 21:52 . 2001-08-18 07:00 18,944 --a------ c:\windows\system32\simptcp.dll
2009-03-08 21:52 . 2001-08-18 07:00 18,944 --a------ c:\windows\system32\dllcache\simptcp.dll
2009-03-08 19:35 . 2009-03-08 19:35 <DIR> d-------- c:\windows\system32\scripting
2009-03-08 19:34 . 2009-03-08 19:34 <DIR> d-------- c:\windows\system32\en
2009-03-08 19:34 . 2009-03-08 19:34 <DIR> d-------- c:\windows\l2schemas
2009-03-08 16:49 . 2009-03-08 16:49 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-08 16:47 . 2009-03-08 16:49 <DIR> d-------- c:\program files\Anti
2009-03-08 16:41 . 2009-03-16 00:25 <DIR> d-------- c:\program files\Malwarebytes
2009-03-08 16:41 . 2009-03-08 16:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-08 16:41 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-08 16:41 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-08 14:09 . 2009-03-08 16:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-08 11:25 . 2009-03-08 19:16 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-08 09:31 . 2009-03-08 09:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2009-03-08 09:28 . 2009-03-08 09:28 <DIR> d-------- c:\windows\system32\drivers\NAV
2009-03-08 09:28 . 2009-03-08 09:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-08 09:28 . 2009-03-08 19:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-03-08 09:18 . 2009-03-08 19:16 <DIR> d-------- c:\program files\ThreatExpert Memory Scanner
2009-03-07 21:25 . 2009-03-15 23:50 <DIR> d-------- c:\windows\SxsCaPendDel
2009-03-07 20:39 . 2009-03-07 20:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Macrovision
2009-03-07 20:30 . 2009-03-07 20:30 <DIR> d-------- c:\windows\Downloaded Installations
2009-03-07 20:30 . 2009-03-07 20:30 <DIR> d-------- c:\program files\SafeNet Sentinel
2009-03-07 20:30 . 2009-03-07 20:30 <DIR> d-------- c:\program files\Common Files\SafeNet Sentinel
2009-03-07 20:24 . 2008-12-21 10:15 6,066,688 --------- c:\windows\system32\dllcache\ieframe.dll
2009-03-07 20:24 . 2007-04-17 20:32 2,455,488 --------- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-07 20:24 . 2007-03-08 16:10 991,232 --------- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-07 20:24 . 2008-12-21 10:15 459,264 --------- c:\windows\system32\dllcache\msfeeds.dll
2009-03-07 20:24 . 2008-12-21 10:15 383,488 --------- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-07 20:24 . 2008-12-21 10:15 267,776 --------- c:\windows\system32\dllcache\iertutil.dll
2009-03-07 20:24 . 2008-12-21 10:15 63,488 --------- c:\windows\system32\dllcache\icardie.dll
2009-03-07 20:24 . 2008-12-21 10:15 52,224 --------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-07 20:24 . 2008-12-19 20:10 13,824 --------- c:\windows\system32\dllcache\ieudinit.exe
2009-03-07 17:12 . 2009-03-07 17:12 <DIR> d-------- c:\program files\ESRI
2009-03-07 17:12 . 2007-04-18 08:51 2,113,536 --a------ c:\windows\system32\python25.dll
2009-03-07 17:11 . 2009-03-16 16:05 <DIR> d-------- c:\documents and settings\Administrator\Application Data\ESRI
2009-03-07 16:57 . 2009-03-13 20:15 <DIR> d-------- c:\program files\Common Files\ESRI
2009-03-07 16:54 . 2009-03-07 17:12 <DIR> d-------- C:\Python25
2009-03-07 16:54 . 2009-03-13 20:54 <DIR> d-------- c:\program files\ArcGIS
2009-03-07 15:06 . 2009-03-07 21:00 <DIR> d-------- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 01:51 --------- d-----w c:\program files\Common Files\Adobe
2009-03-16 00:04 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-07 03:54 --------- d-----w c:\documents and settings\All Users\Application Data\Kodak
2009-03-07 03:46 --------- d-----w c:\program files\Microsoft ActiveSync
2009-03-07 03:46 --------- d-----w c:\program files\EPSON
2009-03-07 03:42 --------- d-----w c:\program files\KODAK
2009-03-07 03:38 --------- d-----w c:\program files\Creative Designer
2009-03-01 09:06 --------- d-----w c:\program files\Google
2009-02-08 08:06 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-02-08 07:13 --------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
.
((((((((((((((((((((((((((((( SnapShot_2009-03-16_13.10.53.73 )))))))))))))))))))))))))))))))))))))))))
.
- 1998-10-29 05:45:06 306,688 ----a-w c:\windows\IsUninst.exe
+ 1998-10-29 04:45:06 306,688 ----a-w c:\windows\IsUninst.exe
- 2009-03-15 23:48:58 191,384 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-17 01:28:14 191,384 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2007-11-30 12:39:22 17,272 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w c:\windows\system32\spmsg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-21 68856]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eabconfg.cpl"="c:\program files\Compaq\EAB\EabServr.exe" [2002-03-07 171665]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 344064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"LTWinModem1"="ltmsg.exe" [2002-02-28 c:\windows\system32\ltmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Premier8\\Myobp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Anti\\anti.exe"=
"c:\\Program Files\\Malwarebytes\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 EterlogicVirtualSerialDriver;EterlogicVirtualSerialDriver;c:\windows\system32\drivers\VSPE.sys [2008-07-23 24192]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\progra~1\ESRI\License\arcgis9x\lmgrd.exe [2009-03-07 1431440]
R3 swivsp;AC8xx Virtual Serial Port;c:\windows\system32\drivers\swivspnt.sys [2007-04-19 20352]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [2007-04-20 81152]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [2007-04-20 90368]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-03-16 33176]
S3 NDMSHLP;Device Monitor Helper Driver;c:\program files\Common Files\HHD Software\Device Monitor\NDMSHLP.sys [2005-05-25 7632]
S3 SerMon;Serial Monitor Filter Driver;c:\program files\HHD Software\Free Serial Port Monitor\sermon.sys [2005-05-25 18432]
.
Contents of the 'Scheduled Tasks' folder
2009-03-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icgjck5a.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-18 08:06:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(600)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\tcpsvcs.exe
c:\progra~1\ESRI\License\arcgis9x\ARCGIS.EXE
c:\windows\system32\ati2evxx.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Completion time: 2009-03-18 8:10:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-17 21:09:59
ComboFix2.txt 2009-03-16 02:12:24
ComboFix3.txt 2009-03-15 12:57:55
Pre-Run: 19,565,330,432 bytes free
Post-Run: 19,642,413,056 bytes free
203 --- E O F --- 2009-03-17 10:35:05
MBam Log
Malwarebytes' Anti-Malware 1.34
Database version: 1860
Windows 5.1.2600 Service Pack 3
18/03/2009 8:22:32 AM
mbam-log-2009-03-18 (08-22-32).txt
Scan type: Quick Scan
Objects scanned: 86590
Time elapsed: 4 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
NTBootlog
Service Pack 3 3 18 2009 08:30:27.500
Loaded driver \Windows\system32\ntoskrnl.exe
Loaded driver \Windows\system32\hal.dll
Loaded driver \Windows\system32\KDCOM.DLL
Loaded driver \Windows\system32\BOOTVID.dll
Loaded driver ACPI.sys
Loaded driver \Windows\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver compbatt.sys
Loaded driver \Windows\System32\DRIVERS\BATTC.SYS
Loaded driver intelide.sys
Loaded driver \Windows\System32\DRIVERS\PCIIDEX.SYS
Loaded driver pcmcia.sys
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver PartMgr.sys
Loaded driver ACPIEC.sys
Loaded driver \Windows\System32\DRIVERS\OPRGHDLR.SYS
Loaded driver VolSnap.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \Windows\System32\DRIVERS\CLASSPNP.SYS
Loaded driver fltmgr.sys
Loaded driver sr.sys
Loaded driver KSecDD.sys
Loaded driver Ntfs.sys
Loaded driver NDIS.sys
Loaded driver Mup.sys
Loaded driver agp440.sys
Loaded driver \SystemRoot\System32\DRIVERS\intelppm.sys
Loaded driver \SystemRoot\System32\DRIVERS\ati2mtag.sys
Loaded driver \SystemRoot\System32\DRIVERS\ltmdmxp.sys
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\System32\DRIVERS\e100b325.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbohci.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\System32\DRIVERS\serial.sys
Loaded driver \SystemRoot\System32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\DRIVERS\nscirda.sys
Loaded driver \SystemRoot\System32\DRIVERS\irenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\parport.sys
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\Drivers\Imapi.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\system32\drivers\smwdm.sys
Loaded driver \SystemRoot\System32\DRIVERS\CmBatt.sys
Loaded driver \SystemRoot\System32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\System32\Drivers\RootMdm.sys
Loaded driver \SystemRoot\System32\DRIVERS\rasirda.sys
Loaded driver \SystemRoot\System32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\System32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\System32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\System32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\System32\DRIVERS\psched.sys
Loaded driver \SystemRoot\System32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\system32\DRIVERS\swivspnt.sys
Loaded driver \SystemRoot\System32\DRIVERS\rdpdr.sys
Loaded driver \SystemRoot\System32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\System32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\System32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\System32\DRIVERS\tcpip.sys
Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\System32\DRIVERS\netbios.sys
Did not load driver \SystemRoot\System32\DRIVERS\p3.sys
Did not load driver \SystemRoot\System32\DRIVERS\processr.sys
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Loaded driver \SystemRoot\system32\DRIVERS\ssmdrv.sys
Loaded driver \SystemRoot\System32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\System32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \??\C:\Windows\system32\drivers\VSPE.sys
Loaded driver \??\C:\Windows\System32\drivers\EABFiltr.sys
Loaded driver \SystemRoot\System32\Drivers\ClntMgmt.sys
Loaded driver \SystemRoot\system32\DRIVERS\avipbb.sys
Loaded driver \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Loaded driver \SystemRoot\System32\DRIVERS\irda.sys
Loaded driver \SystemRoot\System32\DRIVERS\ndisuio.sys
Did not load driver \SystemRoot\System32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\System32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\DRIVERS\mrxdav.sys
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \??\C:\Windows\System32\drivers\Haspnt.sys
Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
Loaded driver \SystemRoot\System32\Drivers\SENTINEL.SYS
Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
Loaded driver \??\C:\Windows\System32\drivers\hardlock.sys
Loaded driver \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
Did not load driver \SystemRoot\System32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys