Dobrý den,
Dneska jsem se díval co mám vlastně všechno zapnuto při zapínání PC a našel jsem tam nějaký explorer.exe který je v appdatech (pravý má být ve složce windows).Nechal jsem ho oskenovat přes https://www.virustotal.com a vyšlo mi že 26/48 antivirů ho ukazuje zavirovaný.
( https://www.virustotal.com/cs/file/9859 ... 388216710/ )
Co s tím mám prosím dělat nevím co ten soubor přesně v PC dělá ale nechci ho tam mít + ted mám v prohlížeči v textu různé odkazy že jsem vyhrál ipad atd.
Za každou radu moc děkuji
tady je screen těch odkazů v textu:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:31, on 28.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
D:\Program Files (x86)\Steam\Steam.exe
C:\Users\lukas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\lukas\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\coIEPlg.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Dolby PCEE4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Steam] "D:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [79a15d4ee74fd62f44984e4a3ced32de] "C:\Users\lukas\AppData\Roaming\explorer.exe" ..
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\lukas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\lukas\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [EADM] "D:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
--
End of file - 10358 bytes
Falešný explorer.exe v appdata\roaming Vyřešeno
Re: Falešný explorer.exe v appdata\roaming
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
lukas :: LUKAS-PC [administrátor]
Ochrana: Povolena
28.12.2013 9:01:34
MBAM-log-2013-12-28 (09-11-53).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 238958
Uplynulý čas: 10 minut, 5 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|79a15d4ee74fd62f44984e4a3ced32de (Trojan.MSIL) -> Data: "C:\Users\lukas\AppData\Roaming\explorer.exe" .. -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Users\lukas\AppData\Roaming\explorer.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Desktop\explorer.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\Microsoft Toolkit 2.4.5 final stable.rar.exe (PUP.Optional.InstalleRex) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\PowerISO5-x64.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\WinRAR.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
(konec)
www.malwarebytes.org
Verze: v2013.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
lukas :: LUKAS-PC [administrátor]
Ochrana: Povolena
28.12.2013 9:01:34
MBAM-log-2013-12-28 (09-11-53).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 238958
Uplynulý čas: 10 minut, 5 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|79a15d4ee74fd62f44984e4a3ced32de (Trojan.MSIL) -> Data: "C:\Users\lukas\AppData\Roaming\explorer.exe" .. -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Users\lukas\AppData\Roaming\explorer.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Desktop\explorer.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\Microsoft Toolkit 2.4.5 final stable.rar.exe (PUP.Optional.InstalleRex) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\PowerISO5-x64.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\lukas\Downloads\WinRAR.exe (Trojan.MSIL) -> Nebyla provedena žádná instrukce.
(konec)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Falešný explorer.exe v appdata\roaming
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Falešný explorer.exe v appdata\roaming
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
lukas :: LUKAS-PC [administrátor]
Ochrana: Povolena
28.12.2013 9:01:34
mbam-log-2013-12-28 (09-01-34).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 238958
Uplynulý čas: 10 minut, 5 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|79a15d4ee74fd62f44984e4a3ced32de (Trojan.MSIL) -> Data: "C:\Users\lukas\AppData\Roaming\explorer.exe" .. -> Přesun do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Users\lukas\AppData\Roaming\explorer.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Desktop\explorer.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\Microsoft Toolkit 2.4.5 final stable.rar.exe (PUP.Optional.InstalleRex) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\PowerISO5-x64.exe (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\WinRAR.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
(konec)
www.malwarebytes.org
Verze: v2013.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
lukas :: LUKAS-PC [administrátor]
Ochrana: Povolena
28.12.2013 9:01:34
mbam-log-2013-12-28 (09-01-34).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 238958
Uplynulý čas: 10 minut, 5 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|79a15d4ee74fd62f44984e4a3ced32de (Trojan.MSIL) -> Data: "C:\Users\lukas\AppData\Roaming\explorer.exe" .. -> Přesun do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 5
C:\Users\lukas\AppData\Roaming\explorer.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Desktop\explorer.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\Microsoft Toolkit 2.4.5 final stable.rar.exe (PUP.Optional.InstalleRex) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\PowerISO5-x64.exe (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\lukas\Downloads\WinRAR.exe (Trojan.MSIL) -> Přesun do karantény a smazání se zdařilo.
(konec)
Re: Falešný explorer.exe v appdata\roaming
# AdwCleaner v3.016 - Report created 28/12/2013 at 11:13:22
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : lukas - LUKAS-PC
# Running from : C:\Users\lukas\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files (x86)\surff anD keepp
Folder Found C:\Program Files (x86)\YoutubeAdblocker
Folder Found C:\ProgramData\QuickSet
Folder Found C:\ProgramData\surff anD keepp
Folder Found C:\ProgramData\YoutubeAdblocker
Folder Found C:\Users\lukas\AppData\Local\torch
Folder Found C:\Users\lukas\AppData\Roaming\EZDownloader
Folder Found C:\Users\UpdatusUser\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\79a15d4ee74fd62f44984e4a3ced32de
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\lukas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1444 octets] - [28/12/2013 11:13:22]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1504 octets] ##########
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : lukas - LUKAS-PC
# Running from : C:\Users\lukas\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files (x86)\surff anD keepp
Folder Found C:\Program Files (x86)\YoutubeAdblocker
Folder Found C:\ProgramData\QuickSet
Folder Found C:\ProgramData\surff anD keepp
Folder Found C:\ProgramData\YoutubeAdblocker
Folder Found C:\Users\lukas\AppData\Local\torch
Folder Found C:\Users\lukas\AppData\Roaming\EZDownloader
Folder Found C:\Users\UpdatusUser\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\79a15d4ee74fd62f44984e4a3ced32de
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\lukas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1444 octets] - [28/12/2013 11:13:22]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1504 octets] ##########
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Falešný explorer.exe v appdata\roaming
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Falešný explorer.exe v appdata\roaming
# AdwCleaner v3.016 - Report created 28/12/2013 at 12:06:59
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : lukas - LUKAS-PC
# Running from : C:\Users\lukas\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\QuickSet
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\ProgramData\surff anD keepp
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\surff anD keepp
Folder Deleted : C:\Users\lukas\AppData\Local\torch
Folder Deleted : C:\Users\lukas\AppData\Roaming\EZDownloader
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\79a15d4ee74fd62f44984e4a3ced32de
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\lukas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1588 octets] - [28/12/2013 11:13:22]
AdwCleaner[R1].txt - [1648 octets] - [28/12/2013 12:06:36]
AdwCleaner[S0].txt - [1607 octets] - [28/12/2013 12:06:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1667 octets] ##########
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : lukas - LUKAS-PC
# Running from : C:\Users\lukas\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\QuickSet
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\ProgramData\surff anD keepp
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\surff anD keepp
Folder Deleted : C:\Users\lukas\AppData\Local\torch
Folder Deleted : C:\Users\lukas\AppData\Roaming\EZDownloader
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\79a15d4ee74fd62f44984e4a3ced32de
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
***** [ Browsers ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\lukas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1588 octets] - [28/12/2013 11:13:22]
AdwCleaner[R1].txt - [1648 octets] - [28/12/2013 12:06:36]
AdwCleaner[S0].txt - [1607 octets] - [28/12/2013 12:06:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1667 octets] ##########
Re: Falešný explorer.exe v appdata\roaming
RogueKiller V8.8.0 _x64_ [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : lukas [Práva správce]
Mód : Kontrola -- Datum : 12/28/2013 12:13:32
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][HJNAME] HKLM\[...]\Run : 79a15d4ee74fd62f44984e4a3ced32de ("C:\Users\lukas\AppData\Roaming\explorer.exe" .. [x][-]) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 06c257094fc86a2454dda65188886d9d
[BSP] d1168606dd6b3a69158f4778da2e69f2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 203590 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 417161153 | Size: 750175 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_12282013_121332.txt >>
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : lukas [Práva správce]
Mód : Kontrola -- Datum : 12/28/2013 12:13:32
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][HJNAME] HKLM\[...]\Run : 79a15d4ee74fd62f44984e4a3ced32de ("C:\Users\lukas\AppData\Roaming\explorer.exe" .. [x][-]) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 06c257094fc86a2454dda65188886d9d
[BSP] d1168606dd6b3a69158f4778da2e69f2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 203590 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 417161153 | Size: 750175 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_12282013_121332.txt >>
Re: Falešný explorer.exe v appdata\roaming
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by lukas on so 28.12.2013 at 12:14:26,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 28.12.2013 at 12:22:12,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by lukas on so 28.12.2013 at 12:14:26,79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 28.12.2013 at 12:22:12,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Falešný explorer.exe v appdata\roaming
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Falešný explorer.exe v appdata\roaming
RogueKiller V8.8.0 _x64_ [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : lukas [Práva správce]
Mód : Odebrat -- Datum : 12/29/2013 10:31:33
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[RUN][HJNAME] HKLM\[...]\Run : 79a15d4ee74fd62f44984e4a3ced32de ("C:\Users\lukas\AppData\Roaming\explorer.exe" .. [x][-]) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 06c257094fc86a2454dda65188886d9d
[BSP] d1168606dd6b3a69158f4778da2e69f2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 203590 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 417161153 | Size: 750175 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_12292013_103133.txt >>
RKreport[0]_S_12292013_103122.txt
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : lukas [Práva správce]
Mód : Odebrat -- Datum : 12/29/2013 10:31:33
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[RUN][HJNAME] HKLM\[...]\Run : 79a15d4ee74fd62f44984e4a3ced32de ("C:\Users\lukas\AppData\Roaming\explorer.exe" .. [x][-]) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 06c257094fc86a2454dda65188886d9d
[BSP] d1168606dd6b3a69158f4778da2e69f2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 203590 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 417161153 | Size: 750175 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_12292013_103133.txt >>
RKreport[0]_S_12292013_103122.txt
Re: Falešný explorer.exe v appdata\roaming
10:33:20.0329 7140 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
10:33:23.0155 7140 ============================================================
10:33:23.0155 7140 Current date / time: 2013/12/29 10:33:23.0155
10:33:23.0155 7140 SystemInfo:
10:33:23.0155 7140
10:33:23.0155 7140 OS Version: 6.1.7601 ServicePack: 1.0
10:33:23.0155 7140 Product type: Workstation
10:33:23.0156 7140 ComputerName: LUKAS-PC
10:33:23.0156 7140 UserName: lukas
10:33:23.0156 7140 Windows directory: C:\Windows
10:33:23.0156 7140 System windows directory: C:\Windows
10:33:23.0156 7140 Running under WOW64
10:33:23.0156 7140 Processor architecture: Intel x64
10:33:23.0156 7140 Number of processors: 4
10:33:23.0156 7140 Page size: 0x1000
10:33:23.0156 7140 Boot type: Normal boot
10:33:23.0156 7140 ============================================================
10:33:23.0672 7140 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:33:23.0680 7140 ============================================================
10:33:23.0680 7140 \Device\Harddisk0\DR0:
10:33:23.0681 7140 MBR partitions:
10:33:23.0681 7140 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:33:23.0681 7140 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x18DA32AF
10:33:23.0697 7140 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x18DD6000, BlocksNum 0x5B92F000
10:33:23.0698 7140 ============================================================
10:33:23.0760 7140 C: <-> \Device\Harddisk0\DR0\Partition2
10:33:23.0804 7140 D: <-> \Device\Harddisk0\DR0\Partition3
10:33:23.0804 7140 ============================================================
10:33:23.0804 7140 Initialize success
10:33:23.0804 7140 ============================================================
10:33:25.0435 7156 ============================================================
10:33:25.0436 7156 Scan started
10:33:25.0436 7156 Mode: Manual;
10:33:25.0436 7156 ============================================================
10:33:25.0561 7156 ================ Scan system memory ========================
10:33:25.0562 7156 System memory - ok
10:33:25.0562 7156 ================ Scan services =============================
10:33:26.0002 7156 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
10:33:26.0005 7156 1394ohci - ok
10:33:26.0041 7156 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
10:33:26.0045 7156 ACPI - ok
10:33:26.0064 7156 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
10:33:26.0065 7156 AcpiPmi - ok
10:33:26.0173 7156 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:33:26.0175 7156 AdobeARMservice - ok
10:33:26.0219 7156 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
10:33:26.0224 7156 adp94xx - ok
10:33:26.0256 7156 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
10:33:26.0259 7156 adpahci - ok
10:33:26.0267 7156 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
10:33:26.0269 7156 adpu320 - ok
10:33:26.0296 7156 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
10:33:26.0297 7156 AeLookupSvc - ok
10:33:26.0342 7156 [ 79059559E89D06E8B80CE2944BE20228 ] AFD C:\Windows\system32\drivers\afd.sys
10:33:26.0347 7156 AFD - ok
10:33:26.0390 7156 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
10:33:26.0391 7156 agp440 - ok
10:33:26.0434 7156 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
10:33:26.0435 7156 ALG - ok
10:33:26.0482 7156 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
10:33:26.0483 7156 aliide - ok
10:33:26.0502 7156 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
10:33:26.0503 7156 amdide - ok
10:33:26.0511 7156 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
10:33:26.0512 7156 AmdK8 - ok
10:33:26.0518 7156 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
10:33:26.0519 7156 AmdPPM - ok
10:33:26.0560 7156 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
10:33:26.0562 7156 amdsata - ok
10:33:26.0577 7156 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
10:33:26.0580 7156 amdsbs - ok
10:33:26.0606 7156 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
10:33:26.0607 7156 amdxata - ok
10:33:26.0634 7156 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
10:33:26.0636 7156 AppID - ok
10:33:26.0659 7156 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
10:33:26.0660 7156 AppIDSvc - ok
10:33:26.0692 7156 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
10:33:26.0694 7156 Appinfo - ok
10:33:26.0716 7156 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
10:33:26.0718 7156 arc - ok
10:33:26.0736 7156 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
10:33:26.0738 7156 arcsas - ok
10:33:26.0933 7156 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
10:33:26.0964 7156 aspnet_state - ok
10:33:27.0013 7156 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
10:33:27.0015 7156 AsyncMac - ok
10:33:27.0047 7156 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
10:33:27.0048 7156 atapi - ok
10:33:27.0078 7156 [ 78B183A794A08978EA0A8D017054352B ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
10:33:27.0079 7156 AthBTPort - ok
10:33:27.0172 7156 [ 7E63E24E17B5233FA69E6613E84B5306 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
10:33:27.0174 7156 AtherosSvc - ok
10:33:27.0300 7156 [ 43E7A4298644526B0190C43AF6489DB1 ] athr C:\Windows\system32\DRIVERS\athrx.sys
10:33:27.0334 7156 athr - ok
10:33:27.0392 7156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
10:33:27.0404 7156 AudioEndpointBuilder - ok
10:33:27.0418 7156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
10:33:27.0425 7156 AudioSrv - ok
10:33:27.0458 7156 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
10:33:27.0461 7156 AxInstSV - ok
10:33:27.0514 7156 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
10:33:27.0519 7156 b06bdrv - ok
10:33:27.0557 7156 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
10:33:27.0560 7156 b57nd60a - ok
10:33:27.0611 7156 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
10:33:27.0613 7156 BDESVC - ok
10:33:27.0636 7156 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
10:33:27.0637 7156 Beep - ok
10:33:27.0686 7156 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
10:33:27.0697 7156 BFE - ok
10:33:27.0853 7156 [ 613883A3BAC6920149C83ED751589433 ] BHDrvx64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys
10:33:27.0867 7156 BHDrvx64 - ok
10:33:27.0914 7156 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
10:33:27.0927 7156 BITS - ok
10:33:27.0978 7156 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
10:33:27.0979 7156 blbdrive - ok
10:33:28.0033 7156 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
10:33:28.0035 7156 bowser - ok
10:33:28.0040 7156 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
10:33:28.0041 7156 BrFiltLo - ok
10:33:28.0047 7156 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
10:33:28.0047 7156 BrFiltUp - ok
10:33:28.0106 7156 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
10:33:28.0109 7156 Browser - ok
10:33:28.0133 7156 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
10:33:28.0137 7156 Brserid - ok
10:33:28.0142 7156 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
10:33:28.0143 7156 BrSerWdm - ok
10:33:28.0148 7156 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
10:33:28.0149 7156 BrUsbMdm - ok
10:33:28.0170 7156 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
10:33:28.0171 7156 BrUsbSer - ok
10:33:28.0215 7156 [ 3E352B570E9CD1047A596927896D6F7C ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
10:33:28.0220 7156 BTATH_A2DP - ok
10:33:28.0238 7156 [ AF715C0F2A656BDA9D4AF470224325C7 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
10:33:28.0240 7156 btath_avdt - ok
10:33:28.0292 7156 [ D438A33D568C76C24E8D7394981F42DC ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
10:33:28.0294 7156 BTATH_BUS - ok
10:33:28.0319 7156 [ 6EFA8C93009E0BE0886C2422C7D20BC5 ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
10:33:28.0322 7156 BTATH_HCRP - ok
10:33:28.0348 7156 [ 168506D0F0C8DF588F8A7E25C58A2DE6 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
10:33:28.0349 7156 BTATH_LWFLT - ok
10:33:28.0380 7156 [ 7C8FB1D73BD279DD914CCA6ED0F4F62B ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
10:33:28.0383 7156 BTATH_RCP - ok
10:33:28.0464 7156 [ 4F6EA72C82C05C8C67643C9E0585108A ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
10:33:28.0469 7156 BtFilter - ok
10:33:28.0510 7156 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
10:33:28.0511 7156 BthEnum - ok
10:33:28.0533 7156 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
10:33:28.0535 7156 BTHMODEM - ok
10:33:28.0587 7156 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
10:33:28.0589 7156 BthPan - ok
10:33:28.0629 7156 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
10:33:28.0635 7156 BTHPORT - ok
10:33:28.0672 7156 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
10:33:28.0674 7156 bthserv - ok
10:33:28.0713 7156 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
10:33:28.0714 7156 BTHUSB - ok
10:33:28.0784 7156 [ 0510396A957E9FD7205BA62D3CAE4528 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\1501000.012\ccSetx64.sys
10:33:28.0786 7156 ccSet_N360 - ok
10:33:28.0832 7156 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
10:33:28.0834 7156 cdfs - ok
10:33:28.0871 7156 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
10:33:28.0873 7156 cdrom - ok
10:33:28.0904 7156 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
10:33:28.0906 7156 CertPropSvc - ok
10:33:28.0912 7156 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
10:33:28.0914 7156 circlass - ok
10:33:28.0935 7156 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
10:33:28.0940 7156 CLFS - ok
10:33:29.0058 7156 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:33:29.0060 7156 clr_optimization_v2.0.50727_32 - ok
10:33:29.0134 7156 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:33:29.0137 7156 clr_optimization_v2.0.50727_64 - ok
10:33:29.0338 7156 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:33:29.0395 7156 clr_optimization_v4.0.30319_32 - ok
10:33:29.0418 7156 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:33:29.0422 7156 clr_optimization_v4.0.30319_64 - ok
10:33:29.0469 7156 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
10:33:29.0470 7156 CmBatt - ok
10:33:29.0497 7156 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
10:33:29.0498 7156 cmdide - ok
10:33:29.0550 7156 [ EBF28856F69CF094A902F884CF989706 ] CNG C:\Windows\system32\Drivers\cng.sys
10:33:29.0555 7156 CNG - ok
10:33:29.0579 7156 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
10:33:29.0580 7156 Compbatt - ok
10:33:29.0599 7156 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
10:33:29.0600 7156 CompositeBus - ok
10:33:29.0616 7156 COMSysApp - ok
10:33:29.0941 7156 [ CEEF9EF16A91596F849421295ABBE86F ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
10:33:29.0945 7156 cphs - ok
10:33:30.0055 7156 cpuz136 - ok
10:33:30.0079 7156 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
10:33:30.0080 7156 crcdisk - ok
10:33:30.0124 7156 [ 6B400F211BEE880A37A1ED0368776BF4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
10:33:30.0128 7156 CryptSvc - ok
10:33:30.0199 7156 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
10:33:30.0211 7156 DcomLaunch - ok
10:33:30.0261 7156 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
10:33:30.0267 7156 defragsvc - ok
10:33:30.0292 7156 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
10:33:30.0294 7156 DfsC - ok
10:33:30.0330 7156 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
10:33:30.0337 7156 Dhcp - ok
10:33:30.0343 7156 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
10:33:30.0344 7156 discache - ok
10:33:30.0374 7156 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
10:33:30.0375 7156 Disk - ok
10:33:30.0412 7156 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
10:33:30.0416 7156 Dnscache - ok
10:33:30.0454 7156 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
10:33:30.0461 7156 dot3svc - ok
10:33:30.0488 7156 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
10:33:30.0492 7156 DPS - ok
10:33:30.0549 7156 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
10:33:30.0550 7156 drmkaud - ok
10:33:30.0601 7156 [ 88612F1CE3BF42256913BF6E61C70D52 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
10:33:30.0611 7156 DXGKrnl - ok
10:33:30.0650 7156 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
10:33:30.0654 7156 EapHost - ok
10:33:30.0792 7156 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
10:33:30.0821 7156 ebdrv - ok
10:33:30.0925 7156 [ 1B7AA375F711F66D5FF2B855F9EC987F ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
10:33:30.0931 7156 eeCtrl - ok
10:33:31.0006 7156 [ 4D71227301DD8D09097B9E4CC6527E5A ] EFS C:\Windows\System32\lsass.exe
10:33:31.0008 7156 EFS - ok
10:33:31.0076 7156 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
10:33:31.0082 7156 elxstor - ok
10:33:31.0122 7156 [ 7230C8B80DDE1F0524C353240B78CC0E ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
10:33:31.0124 7156 EraserUtilRebootDrv - ok
10:33:31.0129 7156 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
10:33:31.0130 7156 ErrDev - ok
10:33:31.0194 7156 [ 2D055FAB756A79F5221ADF56EAE4CB3B ] ETD C:\Windows\system32\DRIVERS\ETD.sys
10:33:31.0198 7156 ETD - ok
10:33:31.0247 7156 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
10:33:31.0252 7156 EventSystem - ok
10:33:31.0280 7156 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
10:33:31.0282 7156 exfat - ok
10:33:31.0304 7156 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
10:33:31.0307 7156 fastfat - ok
10:33:31.0313 7156 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
10:33:31.0314 7156 fdc - ok
10:33:31.0349 7156 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
10:33:31.0351 7156 fdPHost - ok
10:33:31.0375 7156 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
10:33:31.0377 7156 FDResPub - ok
10:33:31.0406 7156 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
10:33:31.0407 7156 FileInfo - ok
10:33:31.0414 7156 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
10:33:31.0415 7156 Filetrace - ok
10:33:31.0420 7156 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
10:33:31.0421 7156 flpydisk - ok
10:33:31.0459 7156 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
10:33:31.0462 7156 FltMgr - ok
10:33:31.0534 7156 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
10:33:31.0551 7156 FontCache - ok
10:33:31.0616 7156 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:33:31.0617 7156 FontCache3.0.0.0 - ok
10:33:31.0623 7156 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
10:33:31.0624 7156 FsDepends - ok
10:33:31.0661 7156 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
10:33:31.0662 7156 Fs_Rec - ok
10:33:31.0734 7156 [ B0DAD5527EF954308839B0A6EF9413BF ] Futuremark SystemInfo Service C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
10:33:31.0739 7156 Futuremark SystemInfo Service - ok
10:33:31.0787 7156 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
10:33:31.0790 7156 fvevol - ok
10:33:31.0856 7156 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
10:33:31.0857 7156 gagp30kx - ok
10:33:31.0910 7156 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
10:33:31.0922 7156 gpsvc - ok
10:33:31.0926 7156 GPUZ - ok
10:33:32.0013 7156 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:33:32.0015 7156 gupdate - ok
10:33:32.0020 7156 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:33:32.0022 7156 gupdatem - ok
10:33:32.0057 7156 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
10:33:32.0058 7156 hamachi - ok
10:33:32.0168 7156 [ E24E88736B13BC54CA93E7F86A0F4FCF ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
10:33:32.0189 7156 Hamachi2Svc - ok
10:33:32.0228 7156 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
10:33:32.0229 7156 hcw85cir - ok
10:33:32.0273 7156 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
10:33:32.0277 7156 HdAudAddService - ok
10:33:32.0299 7156 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
10:33:32.0301 7156 HDAudBus - ok
10:33:32.0306 7156 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
10:33:32.0307 7156 HidBatt - ok
10:33:32.0313 7156 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
10:33:32.0316 7156 HidBth - ok
10:33:32.0336 7156 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
10:33:32.0337 7156 HidIr - ok
10:33:32.0361 7156 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
10:33:32.0364 7156 hidserv - ok
10:33:32.0400 7156 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
10:33:32.0402 7156 HidUsb - ok
10:33:32.0430 7156 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
10:33:32.0433 7156 hkmsvc - ok
10:33:32.0450 7156 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
10:33:32.0455 7156 HomeGroupListener - ok
10:33:32.0484 7156 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
10:33:32.0488 7156 HomeGroupProvider - ok
10:33:32.0522 7156 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
10:33:32.0524 7156 HpSAMD - ok
10:33:32.0562 7156 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
10:33:32.0570 7156 HTTP - ok
10:33:32.0575 7156 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
10:33:32.0576 7156 hwpolicy - ok
10:33:32.0590 7156 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
10:33:32.0592 7156 i8042prt - ok
10:33:32.0637 7156 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
10:33:32.0643 7156 iaStor - ok
10:33:32.0723 7156 [ 7D4B9A48430ED57ACA6373B71D5904CA ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
10:33:32.0724 7156 IAStorDataMgrSvc - ok
10:33:32.0773 7156 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
10:33:32.0777 7156 iaStorV - ok
10:33:32.0868 7156 [ D3090576412EC63E0C6271D8B0974D73 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
10:33:32.0891 7156 IconMan_R - ok
10:33:32.0978 7156 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:33:32.0986 7156 idsvc - ok
10:33:33.0136 7156 [ D7CB14B41DA52DF2EC143768E02F0E97 ] IDSVia64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20131227.001\IDSvia64.sys
10:33:33.0141 7156 IDSVia64 - ok
10:33:33.0450 7156 [ 276EE9CDAB16C50E1DF0E4CEFA882F5F ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
10:33:33.0537 7156 igfx - ok
10:33:33.0588 7156 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
10:33:33.0589 7156 iirsp - ok
10:33:33.0634 7156 [ 344789398EC3EE5A4E00C52B31847946 ] IKEEXT C:\Windows\System32\ikeext.dll
10:33:33.0647 7156 IKEEXT - ok
10:33:33.0783 7156 [ E83BB47C3446F0497019DE7FD6C6A86F ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
10:33:33.0824 7156 IntcAzAudAddService - ok
10:33:33.0882 7156 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
10:33:33.0886 7156 IntcDAud - ok
10:33:33.0913 7156 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
10:33:33.0914 7156 intelide - ok
10:33:33.0955 7156 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
10:33:33.0957 7156 intelppm - ok
10:33:33.0991 7156 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
10:33:33.0994 7156 IPBusEnum - ok
10:33:34.0009 7156 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:33:34.0010 7156 IpFilterDriver - ok
10:33:34.0063 7156 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
10:33:34.0073 7156 iphlpsvc - ok
10:33:34.0079 7156 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
10:33:34.0081 7156 IPMIDRV - ok
10:33:34.0089 7156 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
10:33:34.0090 7156 IPNAT - ok
10:33:34.0115 7156 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
10:33:34.0116 7156 IRENUM - ok
10:33:34.0132 7156 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
10:33:34.0133 7156 isapnp - ok
10:33:34.0170 7156 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
10:33:34.0173 7156 iScsiPrt - ok
10:33:34.0223 7156 [ 846354992EBB373F452EB9182D501B08 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
10:33:34.0224 7156 iusb3hcs - ok
10:33:34.0244 7156 [ 1D88A23853387D34D52CC8F9DDBFC56C ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
10:33:34.0248 7156 iusb3hub - ok
10:33:34.0289 7156 [ FC5EFD7C797DF19DFB999F0605A7924E ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
10:33:34.0297 7156 iusb3xhc - ok
10:33:34.0338 7156 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
10:33:34.0339 7156 kbdclass - ok
10:33:34.0344 7156 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
10:33:34.0346 7156 kbdhid - ok
10:33:34.0378 7156 [ 4D71227301DD8D09097B9E4CC6527E5A ] KeyIso C:\Windows\system32\lsass.exe
10:33:34.0380 7156 KeyIso - ok
10:33:34.0405 7156 [ 8F489706472F7E9A06BAAA198703FA64 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
10:33:34.0406 7156 KSecDD - ok
10:33:34.0419 7156 [ 868A2CAAB12EFC7A021682BCA0EEC54C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
10:33:34.0421 7156 KSecPkg - ok
10:33:34.0437 7156 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
10:33:34.0438 7156 ksthunk - ok
10:33:34.0474 7156 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
10:33:34.0481 7156 KtmRm - ok
10:33:34.0512 7156 [ 320F16CA30BC0B8FF59F6C9E1ACD8516 ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
10:33:34.0513 7156 L1C - ok
10:33:34.0577 7156 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
10:33:34.0584 7156 LanmanServer - ok
10:33:34.0613 7156 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
10:33:34.0619 7156 LanmanWorkstation - ok
10:33:34.0659 7156 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
10:33:34.0661 7156 lltdio - ok
10:33:34.0682 7156 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
10:33:34.0689 7156 lltdsvc - ok
10:33:34.0707 7156 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
10:33:34.0710 7156 lmhosts - ok
10:33:34.0741 7156 [ 02468469C450CD16FB66A56FAB70138B ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
10:33:34.0745 7156 LMIGuardianSvc - ok
10:33:34.0775 7156 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
10:33:34.0777 7156 LSI_FC - ok
10:33:34.0796 7156 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
10:33:34.0798 7156 LSI_SAS - ok
10:33:34.0804 7156 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
10:33:34.0806 7156 LSI_SAS2 - ok
10:33:34.0812 7156 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
10:33:34.0814 7156 LSI_SCSI - ok
10:33:34.0825 7156 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
10:33:34.0827 7156 luafv - ok
10:33:34.0866 7156 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
10:33:34.0868 7156 MBAMProtector - ok
10:33:34.0932 7156 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
10:33:34.0937 7156 MBAMScheduler - ok
10:33:34.0970 7156 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
10:33:34.0979 7156 MBAMService - ok
10:33:34.0985 7156 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
10:33:34.0986 7156 megasas - ok
10:33:35.0020 7156 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
10:33:35.0024 7156 MegaSR - ok
10:33:35.0050 7156 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
10:33:35.0052 7156 MEIx64 - ok
10:33:35.0247 7156 Microsoft SharePoint Workspace Audit Service - ok
10:33:35.0288 7156 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
10:33:35.0291 7156 MMCSS - ok
10:33:35.0308 7156 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
10:33:35.0309 7156 Modem - ok
10:33:35.0340 7156 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
10:33:35.0342 7156 monitor - ok
10:33:35.0356 7156 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
10:33:35.0358 7156 mouclass - ok
10:33:35.0365 7156 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
10:33:35.0366 7156 mouhid - ok
10:33:35.0391 7156 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
10:33:35.0393 7156 mountmgr - ok
10:33:23.0155 7140 ============================================================
10:33:23.0155 7140 Current date / time: 2013/12/29 10:33:23.0155
10:33:23.0155 7140 SystemInfo:
10:33:23.0155 7140
10:33:23.0155 7140 OS Version: 6.1.7601 ServicePack: 1.0
10:33:23.0155 7140 Product type: Workstation
10:33:23.0156 7140 ComputerName: LUKAS-PC
10:33:23.0156 7140 UserName: lukas
10:33:23.0156 7140 Windows directory: C:\Windows
10:33:23.0156 7140 System windows directory: C:\Windows
10:33:23.0156 7140 Running under WOW64
10:33:23.0156 7140 Processor architecture: Intel x64
10:33:23.0156 7140 Number of processors: 4
10:33:23.0156 7140 Page size: 0x1000
10:33:23.0156 7140 Boot type: Normal boot
10:33:23.0156 7140 ============================================================
10:33:23.0672 7140 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:33:23.0680 7140 ============================================================
10:33:23.0680 7140 \Device\Harddisk0\DR0:
10:33:23.0681 7140 MBR partitions:
10:33:23.0681 7140 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:33:23.0681 7140 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x18DA32AF
10:33:23.0697 7140 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x18DD6000, BlocksNum 0x5B92F000
10:33:23.0698 7140 ============================================================
10:33:23.0760 7140 C: <-> \Device\Harddisk0\DR0\Partition2
10:33:23.0804 7140 D: <-> \Device\Harddisk0\DR0\Partition3
10:33:23.0804 7140 ============================================================
10:33:23.0804 7140 Initialize success
10:33:23.0804 7140 ============================================================
10:33:25.0435 7156 ============================================================
10:33:25.0436 7156 Scan started
10:33:25.0436 7156 Mode: Manual;
10:33:25.0436 7156 ============================================================
10:33:25.0561 7156 ================ Scan system memory ========================
10:33:25.0562 7156 System memory - ok
10:33:25.0562 7156 ================ Scan services =============================
10:33:26.0002 7156 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
10:33:26.0005 7156 1394ohci - ok
10:33:26.0041 7156 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
10:33:26.0045 7156 ACPI - ok
10:33:26.0064 7156 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
10:33:26.0065 7156 AcpiPmi - ok
10:33:26.0173 7156 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:33:26.0175 7156 AdobeARMservice - ok
10:33:26.0219 7156 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
10:33:26.0224 7156 adp94xx - ok
10:33:26.0256 7156 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
10:33:26.0259 7156 adpahci - ok
10:33:26.0267 7156 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
10:33:26.0269 7156 adpu320 - ok
10:33:26.0296 7156 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
10:33:26.0297 7156 AeLookupSvc - ok
10:33:26.0342 7156 [ 79059559E89D06E8B80CE2944BE20228 ] AFD C:\Windows\system32\drivers\afd.sys
10:33:26.0347 7156 AFD - ok
10:33:26.0390 7156 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
10:33:26.0391 7156 agp440 - ok
10:33:26.0434 7156 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
10:33:26.0435 7156 ALG - ok
10:33:26.0482 7156 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
10:33:26.0483 7156 aliide - ok
10:33:26.0502 7156 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
10:33:26.0503 7156 amdide - ok
10:33:26.0511 7156 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
10:33:26.0512 7156 AmdK8 - ok
10:33:26.0518 7156 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
10:33:26.0519 7156 AmdPPM - ok
10:33:26.0560 7156 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
10:33:26.0562 7156 amdsata - ok
10:33:26.0577 7156 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
10:33:26.0580 7156 amdsbs - ok
10:33:26.0606 7156 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
10:33:26.0607 7156 amdxata - ok
10:33:26.0634 7156 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
10:33:26.0636 7156 AppID - ok
10:33:26.0659 7156 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
10:33:26.0660 7156 AppIDSvc - ok
10:33:26.0692 7156 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
10:33:26.0694 7156 Appinfo - ok
10:33:26.0716 7156 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
10:33:26.0718 7156 arc - ok
10:33:26.0736 7156 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
10:33:26.0738 7156 arcsas - ok
10:33:26.0933 7156 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
10:33:26.0964 7156 aspnet_state - ok
10:33:27.0013 7156 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
10:33:27.0015 7156 AsyncMac - ok
10:33:27.0047 7156 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
10:33:27.0048 7156 atapi - ok
10:33:27.0078 7156 [ 78B183A794A08978EA0A8D017054352B ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
10:33:27.0079 7156 AthBTPort - ok
10:33:27.0172 7156 [ 7E63E24E17B5233FA69E6613E84B5306 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
10:33:27.0174 7156 AtherosSvc - ok
10:33:27.0300 7156 [ 43E7A4298644526B0190C43AF6489DB1 ] athr C:\Windows\system32\DRIVERS\athrx.sys
10:33:27.0334 7156 athr - ok
10:33:27.0392 7156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
10:33:27.0404 7156 AudioEndpointBuilder - ok
10:33:27.0418 7156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
10:33:27.0425 7156 AudioSrv - ok
10:33:27.0458 7156 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
10:33:27.0461 7156 AxInstSV - ok
10:33:27.0514 7156 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
10:33:27.0519 7156 b06bdrv - ok
10:33:27.0557 7156 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
10:33:27.0560 7156 b57nd60a - ok
10:33:27.0611 7156 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
10:33:27.0613 7156 BDESVC - ok
10:33:27.0636 7156 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
10:33:27.0637 7156 Beep - ok
10:33:27.0686 7156 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
10:33:27.0697 7156 BFE - ok
10:33:27.0853 7156 [ 613883A3BAC6920149C83ED751589433 ] BHDrvx64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20131203.001\BHDrvx64.sys
10:33:27.0867 7156 BHDrvx64 - ok
10:33:27.0914 7156 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
10:33:27.0927 7156 BITS - ok
10:33:27.0978 7156 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
10:33:27.0979 7156 blbdrive - ok
10:33:28.0033 7156 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
10:33:28.0035 7156 bowser - ok
10:33:28.0040 7156 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
10:33:28.0041 7156 BrFiltLo - ok
10:33:28.0047 7156 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
10:33:28.0047 7156 BrFiltUp - ok
10:33:28.0106 7156 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
10:33:28.0109 7156 Browser - ok
10:33:28.0133 7156 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
10:33:28.0137 7156 Brserid - ok
10:33:28.0142 7156 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
10:33:28.0143 7156 BrSerWdm - ok
10:33:28.0148 7156 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
10:33:28.0149 7156 BrUsbMdm - ok
10:33:28.0170 7156 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
10:33:28.0171 7156 BrUsbSer - ok
10:33:28.0215 7156 [ 3E352B570E9CD1047A596927896D6F7C ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
10:33:28.0220 7156 BTATH_A2DP - ok
10:33:28.0238 7156 [ AF715C0F2A656BDA9D4AF470224325C7 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
10:33:28.0240 7156 btath_avdt - ok
10:33:28.0292 7156 [ D438A33D568C76C24E8D7394981F42DC ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
10:33:28.0294 7156 BTATH_BUS - ok
10:33:28.0319 7156 [ 6EFA8C93009E0BE0886C2422C7D20BC5 ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
10:33:28.0322 7156 BTATH_HCRP - ok
10:33:28.0348 7156 [ 168506D0F0C8DF588F8A7E25C58A2DE6 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
10:33:28.0349 7156 BTATH_LWFLT - ok
10:33:28.0380 7156 [ 7C8FB1D73BD279DD914CCA6ED0F4F62B ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
10:33:28.0383 7156 BTATH_RCP - ok
10:33:28.0464 7156 [ 4F6EA72C82C05C8C67643C9E0585108A ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
10:33:28.0469 7156 BtFilter - ok
10:33:28.0510 7156 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
10:33:28.0511 7156 BthEnum - ok
10:33:28.0533 7156 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
10:33:28.0535 7156 BTHMODEM - ok
10:33:28.0587 7156 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
10:33:28.0589 7156 BthPan - ok
10:33:28.0629 7156 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
10:33:28.0635 7156 BTHPORT - ok
10:33:28.0672 7156 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
10:33:28.0674 7156 bthserv - ok
10:33:28.0713 7156 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
10:33:28.0714 7156 BTHUSB - ok
10:33:28.0784 7156 [ 0510396A957E9FD7205BA62D3CAE4528 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\1501000.012\ccSetx64.sys
10:33:28.0786 7156 ccSet_N360 - ok
10:33:28.0832 7156 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
10:33:28.0834 7156 cdfs - ok
10:33:28.0871 7156 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
10:33:28.0873 7156 cdrom - ok
10:33:28.0904 7156 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
10:33:28.0906 7156 CertPropSvc - ok
10:33:28.0912 7156 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
10:33:28.0914 7156 circlass - ok
10:33:28.0935 7156 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
10:33:28.0940 7156 CLFS - ok
10:33:29.0058 7156 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:33:29.0060 7156 clr_optimization_v2.0.50727_32 - ok
10:33:29.0134 7156 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:33:29.0137 7156 clr_optimization_v2.0.50727_64 - ok
10:33:29.0338 7156 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:33:29.0395 7156 clr_optimization_v4.0.30319_32 - ok
10:33:29.0418 7156 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:33:29.0422 7156 clr_optimization_v4.0.30319_64 - ok
10:33:29.0469 7156 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
10:33:29.0470 7156 CmBatt - ok
10:33:29.0497 7156 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
10:33:29.0498 7156 cmdide - ok
10:33:29.0550 7156 [ EBF28856F69CF094A902F884CF989706 ] CNG C:\Windows\system32\Drivers\cng.sys
10:33:29.0555 7156 CNG - ok
10:33:29.0579 7156 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
10:33:29.0580 7156 Compbatt - ok
10:33:29.0599 7156 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
10:33:29.0600 7156 CompositeBus - ok
10:33:29.0616 7156 COMSysApp - ok
10:33:29.0941 7156 [ CEEF9EF16A91596F849421295ABBE86F ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
10:33:29.0945 7156 cphs - ok
10:33:30.0055 7156 cpuz136 - ok
10:33:30.0079 7156 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
10:33:30.0080 7156 crcdisk - ok
10:33:30.0124 7156 [ 6B400F211BEE880A37A1ED0368776BF4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
10:33:30.0128 7156 CryptSvc - ok
10:33:30.0199 7156 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
10:33:30.0211 7156 DcomLaunch - ok
10:33:30.0261 7156 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
10:33:30.0267 7156 defragsvc - ok
10:33:30.0292 7156 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
10:33:30.0294 7156 DfsC - ok
10:33:30.0330 7156 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
10:33:30.0337 7156 Dhcp - ok
10:33:30.0343 7156 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
10:33:30.0344 7156 discache - ok
10:33:30.0374 7156 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
10:33:30.0375 7156 Disk - ok
10:33:30.0412 7156 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
10:33:30.0416 7156 Dnscache - ok
10:33:30.0454 7156 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
10:33:30.0461 7156 dot3svc - ok
10:33:30.0488 7156 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
10:33:30.0492 7156 DPS - ok
10:33:30.0549 7156 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
10:33:30.0550 7156 drmkaud - ok
10:33:30.0601 7156 [ 88612F1CE3BF42256913BF6E61C70D52 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
10:33:30.0611 7156 DXGKrnl - ok
10:33:30.0650 7156 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
10:33:30.0654 7156 EapHost - ok
10:33:30.0792 7156 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
10:33:30.0821 7156 ebdrv - ok
10:33:30.0925 7156 [ 1B7AA375F711F66D5FF2B855F9EC987F ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
10:33:30.0931 7156 eeCtrl - ok
10:33:31.0006 7156 [ 4D71227301DD8D09097B9E4CC6527E5A ] EFS C:\Windows\System32\lsass.exe
10:33:31.0008 7156 EFS - ok
10:33:31.0076 7156 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
10:33:31.0082 7156 elxstor - ok
10:33:31.0122 7156 [ 7230C8B80DDE1F0524C353240B78CC0E ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
10:33:31.0124 7156 EraserUtilRebootDrv - ok
10:33:31.0129 7156 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
10:33:31.0130 7156 ErrDev - ok
10:33:31.0194 7156 [ 2D055FAB756A79F5221ADF56EAE4CB3B ] ETD C:\Windows\system32\DRIVERS\ETD.sys
10:33:31.0198 7156 ETD - ok
10:33:31.0247 7156 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
10:33:31.0252 7156 EventSystem - ok
10:33:31.0280 7156 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
10:33:31.0282 7156 exfat - ok
10:33:31.0304 7156 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
10:33:31.0307 7156 fastfat - ok
10:33:31.0313 7156 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
10:33:31.0314 7156 fdc - ok
10:33:31.0349 7156 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
10:33:31.0351 7156 fdPHost - ok
10:33:31.0375 7156 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
10:33:31.0377 7156 FDResPub - ok
10:33:31.0406 7156 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
10:33:31.0407 7156 FileInfo - ok
10:33:31.0414 7156 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
10:33:31.0415 7156 Filetrace - ok
10:33:31.0420 7156 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
10:33:31.0421 7156 flpydisk - ok
10:33:31.0459 7156 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
10:33:31.0462 7156 FltMgr - ok
10:33:31.0534 7156 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
10:33:31.0551 7156 FontCache - ok
10:33:31.0616 7156 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:33:31.0617 7156 FontCache3.0.0.0 - ok
10:33:31.0623 7156 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
10:33:31.0624 7156 FsDepends - ok
10:33:31.0661 7156 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
10:33:31.0662 7156 Fs_Rec - ok
10:33:31.0734 7156 [ B0DAD5527EF954308839B0A6EF9413BF ] Futuremark SystemInfo Service C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
10:33:31.0739 7156 Futuremark SystemInfo Service - ok
10:33:31.0787 7156 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
10:33:31.0790 7156 fvevol - ok
10:33:31.0856 7156 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
10:33:31.0857 7156 gagp30kx - ok
10:33:31.0910 7156 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
10:33:31.0922 7156 gpsvc - ok
10:33:31.0926 7156 GPUZ - ok
10:33:32.0013 7156 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:33:32.0015 7156 gupdate - ok
10:33:32.0020 7156 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:33:32.0022 7156 gupdatem - ok
10:33:32.0057 7156 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
10:33:32.0058 7156 hamachi - ok
10:33:32.0168 7156 [ E24E88736B13BC54CA93E7F86A0F4FCF ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
10:33:32.0189 7156 Hamachi2Svc - ok
10:33:32.0228 7156 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
10:33:32.0229 7156 hcw85cir - ok
10:33:32.0273 7156 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
10:33:32.0277 7156 HdAudAddService - ok
10:33:32.0299 7156 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
10:33:32.0301 7156 HDAudBus - ok
10:33:32.0306 7156 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
10:33:32.0307 7156 HidBatt - ok
10:33:32.0313 7156 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
10:33:32.0316 7156 HidBth - ok
10:33:32.0336 7156 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
10:33:32.0337 7156 HidIr - ok
10:33:32.0361 7156 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
10:33:32.0364 7156 hidserv - ok
10:33:32.0400 7156 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
10:33:32.0402 7156 HidUsb - ok
10:33:32.0430 7156 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
10:33:32.0433 7156 hkmsvc - ok
10:33:32.0450 7156 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
10:33:32.0455 7156 HomeGroupListener - ok
10:33:32.0484 7156 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
10:33:32.0488 7156 HomeGroupProvider - ok
10:33:32.0522 7156 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
10:33:32.0524 7156 HpSAMD - ok
10:33:32.0562 7156 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
10:33:32.0570 7156 HTTP - ok
10:33:32.0575 7156 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
10:33:32.0576 7156 hwpolicy - ok
10:33:32.0590 7156 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
10:33:32.0592 7156 i8042prt - ok
10:33:32.0637 7156 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
10:33:32.0643 7156 iaStor - ok
10:33:32.0723 7156 [ 7D4B9A48430ED57ACA6373B71D5904CA ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
10:33:32.0724 7156 IAStorDataMgrSvc - ok
10:33:32.0773 7156 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
10:33:32.0777 7156 iaStorV - ok
10:33:32.0868 7156 [ D3090576412EC63E0C6271D8B0974D73 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
10:33:32.0891 7156 IconMan_R - ok
10:33:32.0978 7156 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:33:32.0986 7156 idsvc - ok
10:33:33.0136 7156 [ D7CB14B41DA52DF2EC143768E02F0E97 ] IDSVia64 C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20131227.001\IDSvia64.sys
10:33:33.0141 7156 IDSVia64 - ok
10:33:33.0450 7156 [ 276EE9CDAB16C50E1DF0E4CEFA882F5F ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
10:33:33.0537 7156 igfx - ok
10:33:33.0588 7156 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
10:33:33.0589 7156 iirsp - ok
10:33:33.0634 7156 [ 344789398EC3EE5A4E00C52B31847946 ] IKEEXT C:\Windows\System32\ikeext.dll
10:33:33.0647 7156 IKEEXT - ok
10:33:33.0783 7156 [ E83BB47C3446F0497019DE7FD6C6A86F ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
10:33:33.0824 7156 IntcAzAudAddService - ok
10:33:33.0882 7156 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
10:33:33.0886 7156 IntcDAud - ok
10:33:33.0913 7156 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
10:33:33.0914 7156 intelide - ok
10:33:33.0955 7156 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
10:33:33.0957 7156 intelppm - ok
10:33:33.0991 7156 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
10:33:33.0994 7156 IPBusEnum - ok
10:33:34.0009 7156 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:33:34.0010 7156 IpFilterDriver - ok
10:33:34.0063 7156 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
10:33:34.0073 7156 iphlpsvc - ok
10:33:34.0079 7156 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
10:33:34.0081 7156 IPMIDRV - ok
10:33:34.0089 7156 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
10:33:34.0090 7156 IPNAT - ok
10:33:34.0115 7156 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
10:33:34.0116 7156 IRENUM - ok
10:33:34.0132 7156 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
10:33:34.0133 7156 isapnp - ok
10:33:34.0170 7156 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
10:33:34.0173 7156 iScsiPrt - ok
10:33:34.0223 7156 [ 846354992EBB373F452EB9182D501B08 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
10:33:34.0224 7156 iusb3hcs - ok
10:33:34.0244 7156 [ 1D88A23853387D34D52CC8F9DDBFC56C ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
10:33:34.0248 7156 iusb3hub - ok
10:33:34.0289 7156 [ FC5EFD7C797DF19DFB999F0605A7924E ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
10:33:34.0297 7156 iusb3xhc - ok
10:33:34.0338 7156 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
10:33:34.0339 7156 kbdclass - ok
10:33:34.0344 7156 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
10:33:34.0346 7156 kbdhid - ok
10:33:34.0378 7156 [ 4D71227301DD8D09097B9E4CC6527E5A ] KeyIso C:\Windows\system32\lsass.exe
10:33:34.0380 7156 KeyIso - ok
10:33:34.0405 7156 [ 8F489706472F7E9A06BAAA198703FA64 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
10:33:34.0406 7156 KSecDD - ok
10:33:34.0419 7156 [ 868A2CAAB12EFC7A021682BCA0EEC54C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
10:33:34.0421 7156 KSecPkg - ok
10:33:34.0437 7156 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
10:33:34.0438 7156 ksthunk - ok
10:33:34.0474 7156 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
10:33:34.0481 7156 KtmRm - ok
10:33:34.0512 7156 [ 320F16CA30BC0B8FF59F6C9E1ACD8516 ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
10:33:34.0513 7156 L1C - ok
10:33:34.0577 7156 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
10:33:34.0584 7156 LanmanServer - ok
10:33:34.0613 7156 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
10:33:34.0619 7156 LanmanWorkstation - ok
10:33:34.0659 7156 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
10:33:34.0661 7156 lltdio - ok
10:33:34.0682 7156 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
10:33:34.0689 7156 lltdsvc - ok
10:33:34.0707 7156 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
10:33:34.0710 7156 lmhosts - ok
10:33:34.0741 7156 [ 02468469C450CD16FB66A56FAB70138B ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
10:33:34.0745 7156 LMIGuardianSvc - ok
10:33:34.0775 7156 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
10:33:34.0777 7156 LSI_FC - ok
10:33:34.0796 7156 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
10:33:34.0798 7156 LSI_SAS - ok
10:33:34.0804 7156 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
10:33:34.0806 7156 LSI_SAS2 - ok
10:33:34.0812 7156 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
10:33:34.0814 7156 LSI_SCSI - ok
10:33:34.0825 7156 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
10:33:34.0827 7156 luafv - ok
10:33:34.0866 7156 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
10:33:34.0868 7156 MBAMProtector - ok
10:33:34.0932 7156 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
10:33:34.0937 7156 MBAMScheduler - ok
10:33:34.0970 7156 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
10:33:34.0979 7156 MBAMService - ok
10:33:34.0985 7156 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
10:33:34.0986 7156 megasas - ok
10:33:35.0020 7156 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
10:33:35.0024 7156 MegaSR - ok
10:33:35.0050 7156 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
10:33:35.0052 7156 MEIx64 - ok
10:33:35.0247 7156 Microsoft SharePoint Workspace Audit Service - ok
10:33:35.0288 7156 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
10:33:35.0291 7156 MMCSS - ok
10:33:35.0308 7156 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
10:33:35.0309 7156 Modem - ok
10:33:35.0340 7156 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
10:33:35.0342 7156 monitor - ok
10:33:35.0356 7156 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
10:33:35.0358 7156 mouclass - ok
10:33:35.0365 7156 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
10:33:35.0366 7156 mouhid - ok
10:33:35.0391 7156 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
10:33:35.0393 7156 mountmgr - ok
Zpět na “Viry, antiviry, firewally…”
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 2 hosti