explorer_1 - kontrola logu Vyřešeno

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 21 led 2014 15:13

Na ntb mám Windows 8.1 64-bit a neustále ve správci vidím jak mi běží explorer_1 a zabírá docela dost procesor co stím? Jde to nějak smazat?
Naposledy upravil(a) Michalkalensky dne 21 led 2014 16:28, celkem upraveno 1 x.

Reklama
Uživatelský avatar
lukas.sei
Level 4
Level 4
Příspěvky: 1070
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: explorer_1

Příspěvekod lukas.sei » 21 led 2014 15:35

Změň název na Explorer_1 kontrola logu
A dodej log z hijackthis on už se tu na to někdo podívá

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1

Příspěvekod Michalkalensky » 21 led 2014 16:27

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:27:08, on 21. 1. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\SysWOW64\WScript.exe
C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\GTAIV.exe
C:\Users\Michal\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll
O2 - BHO: InjectScript - {F6C07882-D703-4DD5-905A-2C4E815A5066} - C:\Users\Michal\AppData\Roaming\D394D188-BAC7-4e03-8FAF-389A4D7EC6F4\Shopping Suggestion.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll" (file missing)
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [msgvjltgSrv] "C:\Windows\system32\msgvjltg.vbe" msrbvj msdyfs
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [20131224] C:\Program Files\AVAST Software\Avast\setup\emupdate\ad63b417-091e-49bc-8495-662b7eefb317.exe /check
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Michal\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [test] C:\Windows\bat_starter.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Michal\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Lync] "C:\Program Files (x86)\Microsoft Office\Office15\lync.exe" /fromrunkey
O4 - HKCU\..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe
O4 - HKCU\..\Run: [08f4dc96bbb7af09d1a37fe35c75a42f] "C:\Users\Michal\AppData\Local\Temp\explorer.exe" ..
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - Startup: Odeslat do OneNote.lnk = C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update GreyGray - Unknown owner - C:\Program Files (x86)\GreyGray\updateGreyGray.exe
O23 - Service: Util GreyGray - Unknown owner - C:\Program Files (x86)\GreyGray\bin\utilGreyGray.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12950 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod jaro3 » 21 led 2014 22:21

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 27 led 2014 22:12

ADW Cleaner

# AdwCleaner v3.017 - Report created 27/01/2014 at 22:03:01
# Updated 12/01/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Michal - MICHAL
# Running from : C:\Users\Michal\Downloads\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Windows\System32\Tasks\GoforFilesUpdate
File Found : C:\Windows\Tasks\AmiUpdXp.job
Folder Found C:\Program Files (x86)\BitLord
Folder Found C:\Program Files (x86)\Mobogenie
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitLord
Folder Found C:\Users\Michal\AppData\Local\FilesFrog Update Checker
Folder Found C:\Users\Michal\AppData\Local\genienext
Folder Found C:\Users\Michal\AppData\Local\Mobogenie
Folder Found C:\Users\Michal\AppData\Local\SwvUpdater
Folder Found C:\Users\Michal\AppData\Local\webplayer
Folder Found C:\Users\Michal\AppData\Roaming\goforfiles
Folder Found C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
Folder Found C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Folder Found C:\Users\Michal\AppData\Roaming\newnext.me
Folder Found C:\Users\Michal\Documents\Mobogenie

***** [ Shortcuts ] *****

Shortcut Found : C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk ( _?=C:\Users\Michal\AppData\Local\WebPlayer\AppsHat )

***** [ Registry ] *****

Key Found : HKCU\Software\08f4dc96bbb7af09d1a37fe35c75a42f
Key Found : HKCU\Software\GoforFiles
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps
Key Found : HKCU\Software\Somoto
Key Found : HKCU\Software\Webplayer
Key Found : [x64] HKCU\Software\GoforFiles
Key Found : [x64] HKCU\Software\Somoto
Key Found : [x64] HKCU\Software\Webplayer
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\Software\GoforFiles
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [AppsHat]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\bpsr0739.default\prefs.js ]


[ File : C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\kwmerohu.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [3660 octets] - [27/01/2014 22:03:01]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3720 octets] ##########

----------------------------------------------------------------------------------

Malwarebytes Anti-Malware

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.04.04.07

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16476
Michal :: MICHAL [administrátor]

Ochrana: Povolena

27. 1. 2014 22:05:57
MBAM-log-2014-01-27 (22-11-34).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 265295
Uplynulý čas: 5 minut, 17 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 6
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Users\Michal\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.

(konec)



co ted? :)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod jaro3 » 28 led 2014 09:43

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 30 led 2014 21:16

# AdwCleaner v3.018 - Report created 30/01/2014 at 20:45:38
# Updated 28/01/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Michal - MICHAL
# Running from : C:\Users\Michal\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitLord
Folder Deleted : C:\Program Files (x86)\BitLord
Folder Deleted : C:\Users\Michal\AppData\Local\FilesFrog Update Checker
Folder Deleted : C:\Users\Michal\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Michal\AppData\Roaming\goforfiles
Folder Deleted : C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
Folder Deleted : C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
File Deleted : C:\Windows\Tasks\AmiUpdXp.job
File Deleted : C:\Windows\System32\Tasks\GoforFilesUpdate

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk

***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [AppsHat]
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKCU\Software\08f4dc96bbb7af09d1a37fe35c75a42f
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKCU\Software\Somoto
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\bpsr0739.default\prefs.js ]


[ File : C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\kwmerohu.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [3824 octets] - [27/01/2014 22:03:01]
AdwCleaner[R1].txt - [2931 octets] - [30/01/2014 20:44:40]
AdwCleaner[S0].txt - [2698 octets] - [30/01/2014 20:45:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2758 octets] ##########


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 8.1 Pro x64
Ran by Michal on źt 30. 01. 2014 at 20:49:07,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?

Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Michal\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l




~~~ Registry Keys

Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\speedupmycomputer
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AD109C83-E2D8-4978-8D5F-5B1107FA7DC7}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Michal\appdata\local\appshat mobile apps"
Successfully deleted: [Folder] "C:\Users\Michal\appdata\local\webplayer"
Failed to delete: [Folder] "C:\Program Files (x86)\appshat mobile apps"
Failed to delete: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\Users\Michal\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 30. 01. 2014 at 20:56:31,09
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.01.30.06

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16476
Michal :: MICHAL [administrátor]

Ochrana: Povolena

30. 1. 2014 20:57:19
mbam-log-2014-01-30 (20-57-19).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 265797
Uplynulý čas: 5 minut, 50 sekund

Nalezené procesy v paměti: 2
C:\Program Files (x86)\GreyGray\updateGreyGray.exe (PUP.Optional.GreyGray.A) -> 2904 -> Bude smazán při restartu.
C:\Program Files (x86)\GreyGray\bin\utilGreyGray.exe (PUP.Optional.GreyGray.A) -> 2396 -> Bude smazán při restartu.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 6
HKLM\SYSTEM\CurrentControlSet\Services\Update GreyGray (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
HKLM\SYSTEM\CurrentControlSet\Services\Util GreyGray (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
HKCR\Typelib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} (PUP.Optional.OutBrowse) -> Přesun do karantény a smazání se zdařilo.
HKCR\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} (PUP.Optional.OutBrowse) -> Přesun do karantény a smazání se zdařilo.
HKCU\Software\GreyGray (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
HKLM\Software\GreyGray (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msgvjltgSrv (Trojan.Script) -> Data: "C:\Windows\system32\msgvjltg.vbe" msrbvj msdyfs -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Data: C:\Windows\SysWOW64\rundll32.exe "C:\Users\Michal\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|08f4dc96bbb7af09d1a37fe35c75a42f (Backdoor.Agent.TRJE) -> Data: "C:\Users\Michal\AppData\Local\Temp\explorer.exe" .. -> Přesun do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 6
C:\Program Files (x86)\GreyGray (PUP.Optional.GreyGray.A) -> Bude smazán při restartu.
C:\Program Files (x86)\GreyGray\bin (PUP.Optional.GreyGray.A) -> Bude smazán při restartu.
C:\Program Files (x86)\GreyGray\bin\plugins (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer (PUP.Optional.SpeedupmyComputer) -> Přesun do karantény a smazání se zdařilo.

Nalezené soubory: 40
C:\Program Files (x86)\GreyGray\updateGreyGray.exe (PUP.Optional.GreyGray.A) -> Bude smazán při restartu.
C:\Program Files (x86)\GreyGray\bin\utilGreyGray.exe (PUP.Optional.GreyGray.A) -> Bude smazán při restartu.
C:\Users\Michal\AppData\Local\Temp\DownloadManager.exe (PUP.Optional.OutBrowse) -> Přesun do karantény a smazání se zdařilo.
C:\$Recycle.Bin\S-1-5-21-4202670712-14329881-303778152-1001\$R1TXMYA.exe (PUP.Optional.4Shared.A) -> Přesun do karantény a smazání se zdařilo.
C:\$Recycle.Bin\S-1-5-21-4202670712-14329881-303778152-1001\$RALR55I.exe (PUP.Optional.Somoto.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\appshat_generic.exe (PUP.Optional.Somoto.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\awh9FC4.tmp (PUP.Optional.Amonetize) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\bitool.dll (PUP.Optional.Somoto) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\Launcher_i269071775.exe (PUP.Optional.InstallMonetizer) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\presetup.exe (Trojan.BHO) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\SpeedUpMyComputer.exe (PUP.Optional.SmartTweak) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\uninstall6152484.exe (PUP.Optional.GoForFiles.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\nsaD302.tmp\DTLite.exe (PUP.Optional.OpenCandy) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Local\Temp\RarSFX0\winkeyfinderultimate13123final__2827_il1636278.exe (PUP.Optional.InstallMonetizer) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\Downloads\CamStudio_Setup_v2.7.2_r326.exe (PUP.Optional.Freemium.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\Local Settings\Temporary Internet Files\IE\4M1S5M8Q\BiTool[1].dll (PUP.Optional.Somoto) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\Local Settings\Temporary Internet Files\IE\VCR7BQ4J\Setup[1].exe (PUP.Optional.Greygray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\Local Settings\Temporary Internet Files\IE\VCR7BQ4J\The Walking Dead Episodes 1 2 3 4 5 PC full Game ^^nosTEAM^^.exe (PUP.Optional.BundleInstaller.A) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\explorer_2.exe (PUP.Optional.BitCoinMiner) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\System32\msgvjltg.vbe (Trojan.Script) -> Přesun do karantény a smazání se zdařilo.
C:\Windows\SysWOW64\msgvjltg.vbe (Trojan.Script) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\GreyGray.ico (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\GreyGrayUninstall.exe (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\updateGreyGray.InstallState (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\GreyGray.BrowserFilter.Helper.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\GreyGray.BrowserFilter.Helper.dll.old.2888704f-c363-447d-ba0e-67c9a93da9c9 (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\GreyGrayBrowserFilter.exe (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\sqlite3.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\utilGreyGray.InstallState (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\plugins\GreyGray.BrowserFilter.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\plugins\GreyGray.FFUpdate.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\plugins\GreyGray.GCUpdate.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\GreyGray\bin\plugins\GreyGray.IEUpdate.dll (PUP.Optional.GreyGray.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Users\Michal\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe (PUP.Optional.SpeedupmyComputer) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.url (PUP.Optional.SpeedupmyComputer) -> Přesun do karantény a smazání se zdařilo.
C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\uninst.exe (PUP.Optional.SpeedupmyComputer) -> Přesun do karantény a smazání se zdařilo.

(konec)

RogueKiller V8.8.4 _x64_ [Jan 27 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal [Práva správce]
Mód : Kontrola -- Datum : 01/30/2014 21:10:54
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 9 ¤¤¤
[SUSP PATH] HiSuiteOuc64.exe -- C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] HuaweiHiSuiteService64.exe -- C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [-] -> SMAZÁNO [TermProc]
[SUSP PATH][DLL] explorer.exe -- C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\30864libfoxloader-x64.dll [x] -> ODEBRÁNO
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szninstall.exe -- C:\Users\Michal\AppData\Roaming\Seznam.cz\szninstall.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szndesktop.exe -- C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] explorer_1.exe -- C:\Windows\explorer_1.exe [-] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]
[SUSP PATH] hwtransport.exe -- C:\Users\Michal\AppData\Local\HiSuite\userdata\hwtools\hwtransport.exe [7] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : test (C:\Windows\bat_starter.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Michal\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-4202670712-14329881-303778152-1001\[...]\Run : test (C:\Windows\bat_starter.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-4202670712-14329881-303778152-1001\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Michal\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-4202670712-14329881-303778152-1001\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Michal\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP PATH] SomotoUpdateCheckerAutoStart : C:\Users\Michal\AppData\Local\FilesFrog Update Checker\update_checker.exe - /auto [x] -> NALEZENO

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] 630e4fdbe650d148a1f7c3eff8e7bb99
[BSP] dbcf146c463bbc7c9a28454074d03841 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 2048 | Size: 1000 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2050048 | Size: 951867 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1951473664 | Size: 1000 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_01302014_211054.txt >>


co ted?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod jaro3 » 31 led 2014 09:50

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 31 led 2014 12:11

RogueKiller V8.8.4 _x64_ [Jan 27 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal [Práva správce]
Mód : Kontrola -- Datum : 01/31/2014 11:56:33
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] 630e4fdbe650d148a1f7c3eff8e7bb99
[BSP] dbcf146c463bbc7c9a28454074d03841 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 2048 | Size: 1000 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2050048 | Size: 951867 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1951473664 | Size: 1000 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_01312014_115633.txt >>


11:58:46.0511 0x1ae0 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
11:58:58.0917 0x1ae0 ============================================================
11:58:58.0917 0x1ae0 Current date / time: 2014/01/31 11:58:58.0917
11:58:58.0917 0x1ae0 SystemInfo:
11:58:58.0917 0x1ae0
11:58:58.0917 0x1ae0 OS Version: 6.3.9600 ServicePack: 0.0
11:58:58.0917 0x1ae0 Product type: Workstation
11:58:58.0917 0x1ae0 ComputerName: MICHAL
11:58:58.0917 0x1ae0 UserName: Michal
11:58:58.0917 0x1ae0 Windows directory: C:\Windows
11:58:58.0917 0x1ae0 System windows directory: C:\Windows
11:58:58.0917 0x1ae0 Running under WOW64
11:58:58.0917 0x1ae0 Processor architecture: Intel x64
11:58:58.0917 0x1ae0 Number of processors: 4
11:58:58.0917 0x1ae0 Page size: 0x1000
11:58:58.0917 0x1ae0 Boot type: Normal boot
11:58:58.0917 0x1ae0 ============================================================
11:58:59.0011 0x1ae0 KLMD registered as C:\Windows\system32\drivers\60150943.sys
11:58:59.0480 0x1ae0 System UUID: {0901C1B0-6920-AC91-9115-BA22E23A568D}
11:58:59.0839 0x1ae0 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:58:59.0855 0x1ae0 ============================================================
11:58:59.0855 0x1ae0 \Device\Harddisk0\DR0:
11:58:59.0855 0x1ae0 MBR partitions:
11:58:59.0855 0x1ae0 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xB, StartLBA 0x800, BlocksNum 0x1F4000
11:58:59.0855 0x1ae0 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1F4800, BlocksNum 0x7431D800
11:58:59.0855 0x1ae0 ============================================================
11:58:59.0870 0x1ae0 C: <-> \Device\Harddisk0\DR0\Partition2
11:58:59.0870 0x1ae0 ============================================================
11:58:59.0870 0x1ae0 Initialize success
11:58:59.0870 0x1ae0 ============================================================
11:59:03.0026 0x19c4 Deinitialize success


co ted?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43072
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod jaro3 » 31 led 2014 18:59

log z TDSS není celý!

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 31 led 2014 20:43

20:22:05.0337 0x14ec TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
20:22:08.0029 0x14ec ============================================================
20:22:08.0029 0x14ec Current date / time: 2014/01/31 20:22:08.0029
20:22:08.0029 0x14ec SystemInfo:
20:22:08.0029 0x14ec
20:22:08.0029 0x14ec OS Version: 6.3.9600 ServicePack: 0.0
20:22:08.0029 0x14ec Product type: Workstation
20:22:08.0029 0x14ec ComputerName: MICHAL
20:22:08.0030 0x14ec UserName: Michal
20:22:08.0030 0x14ec Windows directory: C:\Windows
20:22:08.0030 0x14ec System windows directory: C:\Windows
20:22:08.0030 0x14ec Running under WOW64
20:22:08.0030 0x14ec Processor architecture: Intel x64
20:22:08.0030 0x14ec Number of processors: 4
20:22:08.0030 0x14ec Page size: 0x1000
20:22:08.0030 0x14ec Boot type: Normal boot
20:22:08.0030 0x14ec ============================================================
20:22:08.0063 0x14ec KLMD registered as C:\Windows\system32\drivers\46576188.sys
20:22:08.0299 0x14ec System UUID: {0901C1B0-6920-AC91-9115-BA22E23A568D}
20:22:08.0664 0x14ec Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:22:08.0667 0x14ec Drive \Device\Harddisk1\DR1 - Size: 0x7470206000 (465.75 Gb), SectorSize: 0x200, Cylinders: 0xED80, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:22:08.0668 0x14ec ============================================================
20:22:08.0668 0x14ec \Device\Harddisk0\DR0:
20:22:08.0668 0x14ec MBR partitions:
20:22:08.0668 0x14ec \Device\Harddisk0\DR0\Partition1: MBR, Type 0xB, StartLBA 0x800, BlocksNum 0x1F4000
20:22:08.0668 0x14ec \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1F4800, BlocksNum 0x7431D800
20:22:08.0668 0x14ec \Device\Harddisk1\DR1:
20:22:08.0668 0x14ec MBR partitions:
20:22:08.0668 0x14ec \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A37CE80
20:22:08.0668 0x14ec ============================================================
20:22:08.0669 0x14ec C: <-> \Device\Harddisk0\DR0\Partition2
20:22:08.0670 0x14ec H: <-> \Device\Harddisk1\DR1\Partition1
20:22:08.0670 0x14ec ============================================================
20:22:08.0670 0x14ec Initialize success
20:22:08.0670 0x14ec ============================================================
20:22:09.0699 0x0754 ============================================================
20:22:09.0699 0x0754 Scan started
20:22:09.0699 0x0754 Mode: Manual;
20:22:09.0699 0x0754 ============================================================
20:22:09.0699 0x0754 KSN ping started
20:22:12.0547 0x0754 KSN ping finished: true
20:22:13.0116 0x0754 ================ Scan system memory ========================
20:22:13.0116 0x0754 System memory - ok
20:22:13.0117 0x0754 ================ Scan services =============================
20:22:13.0266 0x0754 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
20:22:13.0272 0x0754 1394ohci - ok
20:22:13.0286 0x0754 [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware C:\Windows\system32\drivers\3ware.sys
20:22:13.0289 0x0754 3ware - ok
20:22:13.0307 0x0754 [ 3D30878A269D934100FA5F972E53AF39, 3D2D22D1A9D80DB94D6059C789FBD04DC945722B8644DF6DAA73D5713A10EC52 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:22:13.0320 0x0754 ACPI - ok
20:22:13.0325 0x0754 [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex C:\Windows\system32\Drivers\acpiex.sys
20:22:13.0327 0x0754 acpiex - ok
20:22:13.0342 0x0754 [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
20:22:13.0344 0x0754 acpipagr - ok
20:22:13.0352 0x0754 [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
20:22:13.0353 0x0754 AcpiPmi - ok
20:22:13.0367 0x0754 [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime C:\Windows\System32\drivers\acpitime.sys
20:22:13.0368 0x0754 acpitime - ok
20:22:13.0372 0x0754 [ 3B42D95D20CD2AACDB0564471AE43ED7, BF49568D7060159F61D5F6DE7ECDECCCD1F920A2881544BA83CF420C822F6653 ] ACPIVPC C:\Windows\System32\drivers\AcpiVpc.sys
20:22:13.0373 0x0754 ACPIVPC - ok
20:22:13.0406 0x0754 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:22:13.0408 0x0754 AdobeARMservice - ok
20:22:13.0457 0x0754 [ 8D268693A6DCE3D7319DF14834841BAF, 229C95FE2E6A692EBC2842823A1C7D438F8DF18F44691BD7AFE79DB76F092F9D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:22:13.0472 0x0754 AdobeFlashPlayerUpdateSvc - ok
20:22:13.0500 0x0754 [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX C:\Windows\system32\drivers\ADP80XX.SYS
20:22:13.0514 0x0754 ADP80XX - ok
20:22:13.0549 0x0754 [ B19CA8E441D35AA2B1EE51C10B27DA1B, EBEB96EA44E665B2D4FCD1CC58621A20A17F036EA4A695340A2B65F94F69CDDC ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:22:13.0553 0x0754 AeLookupSvc - ok
20:22:13.0568 0x0754 [ 239268BAB58EAE9A3FF4E08334C00451, 13F927730DF9BAEDB3A7AB6F7238270A20E4CDEB3D5324A1C471DF2209F3D239 ] AFD C:\Windows\system32\drivers\afd.sys
20:22:13.0579 0x0754 AFD - ok
20:22:13.0592 0x0754 [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:22:13.0595 0x0754 agp440 - ok
20:22:13.0609 0x0754 [ 8E8E34B7BA059050EED827410D0697A2, 85B6684709F24729A6497563812A90A54068AC2DD9EEA03037CB1EEF5C85AAA9 ] ahcache C:\Windows\system32\DRIVERS\ahcache.sys
20:22:13.0612 0x0754 ahcache - ok
20:22:13.0617 0x0754 [ A91D8E1E433EFB32551BCE69037E1CE7, 41DFDD5B56918D19D09DFB3E4B07460AA85647A8647ABBBB906158D8D6653290 ] ALG C:\Windows\System32\alg.exe
20:22:13.0619 0x0754 ALG - ok
20:22:13.0633 0x0754 [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
20:22:13.0635 0x0754 AmdK8 - ok
20:22:13.0658 0x0754 [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
20:22:13.0661 0x0754 AmdPPM - ok
20:22:13.0666 0x0754 [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata C:\Windows\system32\drivers\amdsata.sys
20:22:13.0668 0x0754 amdsata - ok
20:22:13.0676 0x0754 [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
20:22:13.0681 0x0754 amdsbs - ok
20:22:13.0685 0x0754 [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata C:\Windows\system32\drivers\amdxata.sys
20:22:13.0686 0x0754 amdxata - ok
20:22:13.0693 0x0754 [ EA3F776E71584D7B51D9B1ADCE80DF08, DFBE52589DDBBD6CC22FFF6DE9874F9E8144DF58C06F14DD1176BDF5CD2DB649 ] AMPPAL C:\Windows\System32\drivers\AMPPAL.sys
20:22:13.0697 0x0754 AMPPAL - ok
20:22:13.0702 0x0754 [ EA3F776E71584D7B51D9B1ADCE80DF08, DFBE52589DDBBD6CC22FFF6DE9874F9E8144DF58C06F14DD1176BDF5CD2DB649 ] AMPPALP C:\Windows\system32\DRIVERS\amppal.sys
20:22:13.0704 0x0754 AMPPALP - ok
20:22:13.0745 0x0754 [ 9BE647AB104153BD0053EB4A48F50B31, 06BE3CA2C3F0D675DC3802BE8D12511495553EA1FB8118427998F5D2EDA550C7 ] AMPPALR3 C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
20:22:13.0772 0x0754 AMPPALR3 - ok
20:22:13.0778 0x0754 [ 04951A9A937CBE28A2D3FEEA360B6D1F, D8AAF000BE4FE4B203DC2EB2A64F780A542E5238CE3F9952FD03277379B11529 ] AppID C:\Windows\system32\drivers\appid.sys
20:22:13.0780 0x0754 AppID - ok
20:22:13.0790 0x0754 [ C0DC3F58214A227980AEB091CFD2F973, 0C3E8453C9F65ADA3E74C38C0E3AC3E0CBFD807B827097046265B38839E151E3 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:22:13.0792 0x0754 AppIDSvc - ok
20:22:13.0798 0x0754 [ 7E790DE2487CEDB349D1750B9E47F090, EDA4A87EA2F89ABD174E9590DD46E70B9E7E4B35BDFC3ED90D79CD594F8CB2CD ] Appinfo C:\Windows\System32\appinfo.dll
20:22:13.0800 0x0754 Appinfo - ok
20:22:13.0807 0x0754 [ 8176FBA685178FB0F52D46693474FA50, 69FE3692C7FE24289A479ADD74F2C782B59A099B7B07FE5ACFC4DA899E40BFDE ] AppMgmt C:\Windows\System32\appmgmts.dll
20:22:13.0811 0x0754 AppMgmt - ok
20:22:13.0825 0x0754 [ 4B964AE0DF433A3BFA7BD24713BC2E9B, DC8933265E67E43CAE96EA64B146CB9067B536A4DA2C90EDCB38302BBFA1CE6B ] AppReadiness C:\Windows\system32\AppReadiness.dll
20:22:13.0835 0x0754 AppReadiness - ok
20:22:13.0865 0x0754 [ 0B726D9ED75C787D6FFAF1E3873BCC70, DC3822B35FB65D53CC5D0E3982C326C5F47F0911BEB1F66DCC84A79C84621E1E ] AppXSvc C:\Windows\system32\appxdeploymentserver.dll
20:22:13.0886 0x0754 AppXSvc - ok
20:22:13.0894 0x0754 [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas C:\Windows\system32\drivers\arcsas.sys
20:22:13.0896 0x0754 arcsas - ok
20:22:13.0913 0x0754 [ 0ACC3F49015E628590CA4372322EB46B, EB4E22EB4E840261168AF750E878E7A28CC080A89CEF77B5037C2897C40D1DE3 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
20:22:13.0916 0x0754 aswMonFlt - ok
20:22:13.0920 0x0754 [ 679712B7A353EE665B9301592164A172, CA3C918106A355BAFD0833BB493DF2CCBC2D0F90CA7EBF5E27CC088C7170B0E0 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys
20:22:13.0923 0x0754 aswRdr - ok
20:22:13.0928 0x0754 [ C04F7B373881009D7994D9BF55D24AB4, 5DEEA804F4F9862024F40A204E88DBCFFBDD2DC87CA86145E3FB649CFCCDC624 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
20:22:13.0929 0x0754 aswRvrt - ok
20:22:13.0970 0x0754 [ 43599E630DFC30AD4E6A2B4B269EB1C0, DA6C7FDC1F6A57117B17F697A94190CC0BB9E32B8CBB4F8C042AA461361CC74C ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
20:22:13.0988 0x0754 aswSnx - ok
20:22:14.0007 0x0754 [ F22DE5F5BA8ADA0A861441B624B51EB5, 58EF9FB3328B6B470F3652DBCE8ACEDAEE6839AC393889A02052298CA204689B ] aswSP C:\Windows\system32\drivers\aswSP.sys
20:22:14.0014 0x0754 aswSP - ok
20:22:14.0023 0x0754 [ FD3EA14ADF6216BDF4030DB2EFD43D96, 2D3009008AAE93285301B5844DC214D6B05ECB05D37AE08895D8E7187A0BB619 ] aswStm C:\Windows\system32\drivers\aswStm.sys
20:22:14.0025 0x0754 aswStm - ok
20:22:14.0045 0x0754 [ 90399625F341AB76BA4B85A5E860EB1F, 92DD461B14240222F451F971642844A4DAD9DF4FFEAA8F12D16EA117822BEEF3 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
20:22:14.0049 0x0754 aswVmm - ok
20:22:14.0054 0x0754 [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi C:\Windows\system32\drivers\atapi.sys
20:22:14.0055 0x0754 atapi - ok
20:22:14.0070 0x0754 [ 4903CBC14742B5AB4DCF7A92F7DEC483, B8491FDA1D1E767658ECC5C3C3DDFB3EB12A969F0F6ACF116C18300FF54075D5 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
20:22:14.0074 0x0754 AudioEndpointBuilder - ok
20:22:14.0101 0x0754 [ 86DD7884124D363A63CCE7A11FDEBBED, E7BAE477D964E395A96342E077774467AA9DE5D8112BFCDE27EEA1CB04A2A480 ] Audiosrv C:\Windows\System32\Audiosrv.dll
20:22:14.0130 0x0754 Audiosrv - ok
20:22:14.0207 0x0754 [ D74884939D53612FD84AC82C59CCFE27, 07BFB34A3748E018C0A674A6253A03FFA522B31AE1942E84B3CC4DDDED9C16A9 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:22:14.0212 0x0754 avast! Antivirus - ok
20:22:14.0226 0x0754 [ 96E8CAF20FC4B6C31CAD7816A801EB78, E4870DB8FFBDCFEE98449338D0BDBF2DD0B5FEC75514E41C11A882BE6EB16833 ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:22:14.0235 0x0754 AxInstSV - ok
20:22:14.0287 0x0754 [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
20:22:14.0304 0x0754 b06bdrv - ok
20:22:14.0313 0x0754 [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
20:22:14.0315 0x0754 BasicDisplay - ok
20:22:14.0319 0x0754 [ 2748E116F8621A4DB0D39FCDD7318C01, DA2DEB7FE1D887B1EF5E2B5103270B72268D8ABDDA36C396627305C0BA90FC20 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
20:22:14.0320 0x0754 BasicRender - ok
20:22:14.0342 0x0754 [ F2E8CEFC8CF4D6454F4121C5FF93136A, DFD05AD328BD0FDD8BF44043C40084A6DF98BF6F5CEAE71BF793176AF6ADFBBB ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BBSvc.exe
20:22:14.0345 0x0754 BBSvc - ok
20:22:14.0353 0x0754 [ 6E1BCC590C9D30FEE8FC14DBD053CE94, 4F698D399225A890B7FDCE3773E504B2880534ED1C0F4C37589568C44BA51743 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.exe
20:22:14.0357 0x0754 BBUpdate - ok
20:22:14.0361 0x0754 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2 C:\Windows\System32\drivers\bcmfn2.sys
20:22:14.0362 0x0754 bcmfn2 - ok
20:22:14.0372 0x0754 [ BBE61A40665B83488901E41082A6097D, ADF750DB32E1295C57C03D587A60194529C8B83F90F433C3458288FB5E8F475B ] BDESVC C:\Windows\System32\bdesvc.dll
20:22:14.0378 0x0754 BDESVC - ok
20:22:14.0391 0x0754 [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep C:\Windows\system32\drivers\Beep.sys
20:22:14.0392 0x0754 Beep - ok
20:22:14.0412 0x0754 [ 6468B696C65775D51A06615830E0E79D, CC4081B3A4895192B4796A745F0BCE8C9C3149B854A7B9BEF84668A2E1D074B5 ] BFE C:\Windows\System32\bfe.dll
20:22:14.0426 0x0754 BFE - ok
20:22:14.0451 0x0754 [ 15225081966C785A9192782401643FD4, E2BA0C8D044556FDD9DD7A25F7F71553DE7A2924E78F9284413C2AC46F0BF4EB ] BITS C:\Windows\System32\qmgr.dll
20:22:14.0469 0x0754 BITS - ok
20:22:14.0514 0x0754 [ BAE8683BE3463B25E51875B380AB695A, 3EDB44560F798BB05AB7F534CEC4688C35AD9092B7D1CC5F58B47E82BD8EA270 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
20:22:14.0535 0x0754 Bluetooth Device Monitor - ok
20:22:14.0578 0x0754 [ AF06006C7A8B6CE409ABD351867A9544, AB985CEB86E57AB99E8D273058533CD3D04FF3232C62688DFD8F9D6A5B6586CD ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
20:22:14.0597 0x0754 Bluetooth OBEX Service - ok
20:22:14.0615 0x0754 [ 6B4FFFDDC618FCF64473CAA86E305697, 29EA66071D5822920F5C50533673ADAB5204F8B25C11027AD27450D881F1142D ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:22:14.0620 0x0754 bowser - ok
20:22:14.0635 0x0754 [ 748141CC03DF40C38F17D3F96BB15C80, 8F1FA850BC6C6497325C0758DEA36C2839BE53C3F8143DFD3A905BEEFF538126 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
20:22:14.0645 0x0754 BrokerInfrastructure - ok
20:22:14.0661 0x0754 [ D528D6A92D187777691993DD757AF19A, 2C79978310193431E5FC462368424A172858D5351C92D4815C2A7E35B5DDE50C ] Browser C:\Windows\System32\browser.dll
20:22:14.0665 0x0754 Browser - ok
20:22:14.0669 0x0754 [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
20:22:14.0670 0x0754 BthAvrcpTg - ok
20:22:14.0676 0x0754 [ 131F1C8573E7BFB41C54FBF5309CCD94, DAFE51E3BADBD82A33B580F212B2D6520A120877C23F6D675521FEA2F4BA5A1F ] BthEnum C:\Windows\System32\drivers\BthEnum.sys
20:22:14.0677 0x0754 BthEnum - ok
20:22:14.0683 0x0754 [ 746B9F94214915AECDE4B7FEA5FF9664, EA2877D49DB4B7B9CE61653D63E8776DFF1CBCCAB12C14DB1D20DA44B8F06357 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
20:22:14.0684 0x0754 BthHFEnum - ok
20:22:14.0689 0x0754 [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
20:22:14.0690 0x0754 bthhfhid - ok
20:22:14.0700 0x0754 [ FCD8BD17B7193CFFF18C332D1A381D7F, CD8A03086695F8FF2566697164D1FD1B60210C017220EFBD78CB12C38CD12BE1 ] BthLEEnum C:\Windows\system32\DRIVERS\BthLEEnum.sys
20:22:14.0706 0x0754 BthLEEnum - ok
20:22:14.0721 0x0754 [ 07E33226AD218A2A162662A05CAFB52F, 0AC3D8B79EDA6DA232FA4E1CAF6592420A9EDE96350D1F0504C2434261684F0B ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
20:22:14.0723 0x0754 BTHMODEM - ok
20:22:14.0729 0x0754 [ 3AFE71D80EDF5D4DE0C5731352905669, 3E370169B8C5D301954D1F1DA302F7A0DB2A034990E10B3D64458C48E5693205 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
20:22:14.0732 0x0754 BthPan - ok
20:22:14.0766 0x0754 [ 10EDF9E0838BA4578FFFFF274632D454, 7719C161A3A05DF62124177A8EC97800DFE855D2B738C443F1B44E8643A4CF44 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
20:22:14.0790 0x0754 BTHPORT - ok
20:22:14.0796 0x0754 [ E5E48FEED73D463175EAB1542495191C, 0A8182F5BA7B694AB1DD3680F1194E4A568FE40DBA4BFDFF2EA09BAD045FFB29 ] bthserv C:\Windows\system32\bthserv.dll
20:22:14.0798 0x0754 bthserv - ok
20:22:14.0803 0x0754 [ D30286FF3C7B6318C024D2BC2955C1BF, 47863D046C94A5C19F7D4E0BA393E6FE1E249C78FAB9B8705F7DD2CD87EAC16C ] BTHSSecurityMgr C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
20:22:14.0806 0x0754 BTHSSecurityMgr - ok
20:22:14.0811 0x0754 [ 0E7FA34B975764C33B5DBC6F8C401627, 9727B9D216D0670D2F2BC5B464B5FDAEC8BC769CA6ADC7F3858EDA3DA0F8036C ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
20:22:14.0813 0x0754 BTHUSB - ok
20:22:14.0819 0x0754 [ 8F5E4E166C19A1B60F508057CF2FF96E, 6924EC4B820BB9C1753C1153AF315717826C7393D42C3AFB097957885987B7A3 ] btmaux C:\Windows\system32\DRIVERS\btmaux.sys
20:22:14.0822 0x0754 btmaux - ok
20:22:14.0877 0x0754 [ FD6DCB9E986D4B88655370C7F3976F78, F106BBC3147BF4FFEE3A56B477BA7F26A269CAE659570930860AF033F1171A70 ] btmhsf C:\Windows\system32\DRIVERS\btmhsf.sys
20:22:14.0908 0x0754 btmhsf - ok
20:22:14.0915 0x0754 [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:22:14.0917 0x0754 cdfs - ok
20:22:14.0925 0x0754 [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom C:\Windows\System32\drivers\cdrom.sys
20:22:14.0929 0x0754 cdrom - ok
20:22:14.0935 0x0754 [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] CertPropSvc C:\Windows\System32\certprop.dll
20:22:14.0939 0x0754 CertPropSvc - ok
20:22:14.0943 0x0754 [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass C:\Windows\System32\drivers\circlass.sys
20:22:14.0944 0x0754 circlass - ok
20:22:14.0955 0x0754 [ 7F006813C2AFE622C13D7AF94F56CD07, 9F4AEEE19B44F4117BE036F1475CE2E91ED740EB7D8D38364F9724517F777482 ] CLFS C:\Windows\system32\drivers\CLFS.sys
20:22:14.0962 0x0754 CLFS - ok
20:22:14.0970 0x0754 [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
20:22:14.0971 0x0754 CmBatt - ok
20:22:14.0985 0x0754 [ 825BE21E6395E00698D8A23955A87972, 303F10C3BA72ABB3BA27D08968B10E8EB03FFB6951943B0E9DD35CF48BB72578 ] CNG C:\Windows\system32\Drivers\cng.sys
20:22:14.0995 0x0754 CNG - ok
20:22:15.0000 0x0754 [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
20:22:15.0002 0x0754 CompositeBus - ok
20:22:15.0004 0x0754 COMSysApp - ok
20:22:15.0018 0x0754 [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv C:\Windows\system32\drivers\condrv.sys
20:22:15.0020 0x0754 condrv - ok
20:22:15.0054 0x0754 [ CB8DEFDDD90AFDD6D817FD066C1630E6, 446B0237B7BA252CA20AB10AD2B034182C9A5C128CA14195FB7BFE22273FF0E1 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
20:22:15.0063 0x0754 cphs - ok
20:22:15.0082 0x0754 [ 0EFE4B5884A8032617826A4D76F80969, 083D296CC623C83D36A97AEE343ADF819B17E490F931DBE4D161BD1E8C289E02 ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:22:15.0086 0x0754 CryptSvc - ok
20:22:15.0101 0x0754 [ EE2F3C0D6ADBC975D6B621EC15ACF4E2, D158C0FACA6344BCD77616EC3D23212F9FD76D7D0C834ACA51998B80162106D5 ] CSC C:\Windows\system32\drivers\csc.sys
20:22:15.0112 0x0754 CSC - ok
20:22:15.0131 0x0754 [ 936D9E2871CEEFF6A33695D98374367B, C30D42E870F196C4FA20AF95C7B9D9C9C5414D6DDE71268F88C3FC5BF372E61B ] CscService C:\Windows\System32\cscsvc.dll
20:22:15.0145 0x0754 CscService - ok
20:22:15.0151 0x0754 [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam C:\Windows\system32\drivers\dam.sys
20:22:15.0152 0x0754 dam - ok
20:22:15.0182 0x0754 [ 3FD5AE42EC87C6F532A931F96BE731DD, 8282823022391ACF65E23F461FCE5CAFFB5ADC077647FEF80B91BC4BC31EDFE2 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:22:15.0196 0x0754 DcomLaunch - ok
20:22:15.0209 0x0754 [ F4CCAADC2C78F57E4F16B24C9201CE22, B76A5C487A814CB986FE8CC398FB7493C9EAB9ACC933A3C35384FA447092EF00 ] defragsvc C:\Windows\System32\defragsvc.dll
20:22:15.0217 0x0754 defragsvc - ok
20:22:15.0234 0x0754 [ 0BC71D4D3B5883903C37BF4E13B0F0C5, C5EC2AD001FB7E72D3D12DBADFE01C308ACCB7426E0B90CCB3ECE2DE49D5E7D4 ] DeviceAssociationService C:\Windows\system32\das.dll
20:22:15.0244 0x0754 DeviceAssociationService - ok
20:22:15.0250 0x0754 [ 752A457320A946E03C3AA86C3ACD735E, 63946150581532D862F4220606E74FFC479209E1A36CD57AA78AC4AE34A26F49 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
20:22:15.0255 0x0754 DeviceInstall - ok
20:22:15.0273 0x0754 [ 5DB26D7E0216D0BF364A81D3829AD7B9, FD786D530EA9ADBCB48782FE091E926505A83F2BF3B4181A3D4EDFAA991C4E5E ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
20:22:15.0276 0x0754 Dfsc - ok
20:22:15.0287 0x0754 [ 8B107F55FD61654A6C9F1B819AEC5FC4, 773B1B9D3583F17B7C89BDE1EC4487ABB0AE039DF4583F8746460425443DA291 ] Dhcp C:\Windows\system32\dhcpcore.dll
20:22:15.0293 0x0754 Dhcp - ok
20:22:15.0300 0x0754 [ 4D40C9B33F738797CF50E77CB7C53E85, 7BA341342A47DEB15B51971C97A5237ACD8BDAD9033F63DF0000892BE43F8E13 ] disk C:\Windows\system32\drivers\disk.sys
20:22:15.0303 0x0754 disk - ok
20:22:15.0306 0x0754 [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
20:22:15.0307 0x0754 dmvsc - ok
20:22:15.0326 0x0754 [ 5BAF7714E68F93515A937A3FA8587EF9, DD9296F75341EF96D514139DD8A8680B332E9B9D476368AB897FDA2D5D674E60 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:22:15.0331 0x0754 Dnscache - ok
20:22:15.0340 0x0754 [ 50288EA079BB520C2B8C8A154202D518, 8916A9180CA009D124FFDFB4CCF5FDFEF7FA2FD37CBCD49FAD4C68E051B4734D ] dot3svc C:\Windows\System32\dot3svc.dll
20:22:15.0346 0x0754 dot3svc - ok
20:22:15.0359 0x0754 [ 27069CFFF29B7F04F4B1BB10154BE52B, 6869626F9A1D3F64224883C5E661638CEE893A3E29651C7B9302A03E52180415 ] dot4 C:\Windows\system32\DRIVERS\Dot4.sys
20:22:15.0362 0x0754 dot4 - ok
20:22:15.0376 0x0754 [ 0BD906A79F9CE3013F7D9D0AC45F9F9D, 2F7D5082E7E226D5EBEA164A8ACEE0A447C96EB1829224A6EFA3E7B4EFEE1D14 ] Dot4Print C:\Windows\System32\drivers\Dot4Prt.sys
20:22:15.0377 0x0754 Dot4Print - ok
20:22:15.0395 0x0754 [ B7D595F2F464F7B628AD53F06547792C, F5D06A91EF54FBF56305FCC882B854350B266B2A005D80CC77AEBC2929440729 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
20:22:15.0398 0x0754 dot4usb - ok
20:22:15.0405 0x0754 [ 281BEE07BA97E3E98D12A822D923D0D8, 6EB482B2D4D6048D145C3738B2B6FA27A90B5EA53E9167447820F9981B004E63 ] DPS C:\Windows\system32\dps.dll
20:22:15.0409 0x0754 DPS - ok
20:22:15.0429 0x0754 [ DDC11A202207C0400CBE07315B8FDE5E, 3ED0CA3A714582D92001BA3BFF78BE082F4DC8021298D5A2632F3B2B0A1C09DC ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:22:15.0431 0x0754 drmkaud - ok
20:22:15.0438 0x0754 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8, B8223D73C3DE123759101F7D5D45C60BD12B221F09D349575A1044CE3F43CBC5 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
20:22:15.0443 0x0754 DsmSvc - ok
20:22:15.0453 0x0754 [ 6A0E850DDCB136AA3D2FB7234382DF12, C01863E95F45E1B74AC65C9CD12C8DC769299218255B3C94E3EBF58C4D79FEF3 ] dtsoftbus01 C:\Windows\System32\drivers\dtsoftbus01.sys
20:22:15.0458 0x0754 dtsoftbus01 - ok
20:22:15.0510 0x0754 [ A3D1CB64DF885ACE126543E6D7067348, AFB5EF73F7B2854669137F586171500E4EB00F12BFCFD6B743FABD165B4AEED3 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:22:15.0536 0x0754 DXGKrnl - ok
20:22:15.0554 0x0754 [ 6073537F250B45E1CB2A02E97F0FE1B2, 653F3F2F2019168EDF225944A88AFDBF8393B62AA076BD19980691778F3DB67D ] Eaphost C:\Windows\System32\eapsvc.dll
20:22:15.0558 0x0754 Eaphost - ok
20:22:15.0641 0x0754 [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv C:\Windows\system32\drivers\evbda.sys
20:22:15.0705 0x0754 ebdrv - ok
20:22:15.0712 0x0754 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] EFS C:\Windows\System32\lsass.exe
20:22:15.0715 0x0754 EFS - ok
20:22:15.0727 0x0754 [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
20:22:15.0729 0x0754 EhStorClass - ok
20:22:15.0751 0x0754 [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
20:22:15.0755 0x0754 EhStorTcgDrv - ok
20:22:15.0762 0x0754 [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev C:\Windows\System32\drivers\errdev.sys
20:22:15.0763 0x0754 ErrDev - ok
20:22:15.0783 0x0754 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3, 5264734F0572FAEDCCB008221C9982CCB7922C4FFC358605424EA413CDCDAE99 ] EventSystem C:\Windows\system32\es.dll
20:22:15.0803 0x0754 EventSystem - ok
20:22:15.0850 0x0754 [ 00B132F23AA25DEF2060D490B0AB70EF, AAE3BA09C2201EA27D3DB761B3D3E8A3EE80A14B451B743F4DF1281D87166857 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
20:22:15.0863 0x0754 EvtEng - ok
20:22:15.0870 0x0754 [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat C:\Windows\system32\drivers\exfat.sys
20:22:15.0874 0x0754 exfat - ok
20:22:15.0882 0x0754 [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:22:15.0886 0x0754 fastfat - ok
20:22:15.0913 0x0754 [ 2BC8532ABF2B3756B78FA1DA54147DDE, DF65EE2AB0255A2CF3221085A6BE7C37E3DB6BFEED3BCADCDD69BB1049F6DCB1 ] Fax C:\Windows\system32\fxssvc.exe
20:22:15.0926 0x0754 Fax - ok
20:22:15.0930 0x0754 [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc C:\Windows\System32\drivers\fdc.sys
20:22:15.0931 0x0754 fdc - ok
20:22:15.0935 0x0754 [ DC1A78BCCCB7EE53D6FD3BD615A8E222, EE16B6853185AAE779D7135035983938009901658F76A8856AAC12EBA15BB34E ] fdPHost C:\Windows\system32\fdPHost.dll
20:22:15.0937 0x0754 fdPHost - ok
20:22:15.0941 0x0754 [ E5AD448F2DC84B1CF387FA7F2A3D1936, BBB29C79A085C503F5EFFB5144596D5DEC48A4EB34A049A4E7B38B27F6D92E0A ] FDResPub C:\Windows\system32\fdrespub.dll
20:22:15.0943 0x0754 FDResPub - ok
20:22:15.0960 0x0754 [ 0046E0BD031213D37123876B0D0FA61C, A4FE17D56F0BAFB70D0D421ED9D1B6E50AF8ADAA4B59328A41AEC5B4C068A3CB ] fhsvc C:\Windows\system32\fhsvc.dll
20:22:15.0965 0x0754 fhsvc - ok
20:22:15.0969 0x0754 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5, 85D1AC25CF8056FF303930A7E18DE5F7C3AEE429272CB791BD6F81F1DAFB7D8A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:22:15.0971 0x0754 FileInfo - ok
20:22:15.0985 0x0754 [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:22:15.0988 0x0754 Filetrace - ok
20:22:15.0992 0x0754 [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
20:22:15.0994 0x0754 flpydisk - ok
20:22:16.0015 0x0754 [ 60D5067FCE6D9433D35E04C01D8538B3, 2D97E9E8FF18CF564DE8E70F68B56F0177DC6C0E9EEB7E1C58BBDF42456CB0D8 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:22:16.0021 0x0754 FltMgr - ok
20:22:16.0053 0x0754 [ 183CA7699474FDE235853967D1DA4D9B, 8FBD5997F1E39AFFD8C4322520DF4D2227279B5149017D825C188D7411BA99AF ] FontCache C:\Windows\system32\FntCache.dll
20:22:16.0076 0x0754 FontCache - ok
20:22:16.0093 0x0754 [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:22:16.0094 0x0754 FontCache3.0.0.0 - ok
20:22:16.0102 0x0754 [ 35005534E600E993A90B036E4E599F2B, DA56FA3776FBD3D50276CB7410E0CB6F137DD8FCA84C0F3FEF8B1FEA5F6CA592 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:22:16.0104 0x0754 FsDepends - ok
20:22:16.0107 0x0754 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:22:16.0109 0x0754 Fs_Rec - ok
20:22:16.0124 0x0754 [ 83E1F0983B02A6F8EC764D18E24ECF10, B5CA3FCB442697681C513FB37C6BB74D7A72B67DC65E2FCA93A7F9E81B63EAAC ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:22:16.0135 0x0754 fvevol - ok
20:22:16.0139 0x0754 [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
20:22:16.0140 0x0754 FxPPM - ok
20:22:16.0150 0x0754 [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
20:22:16.0152 0x0754 gagp30kx - ok
20:22:16.0167 0x0754 [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
20:22:16.0170 0x0754 gencounter - ok
20:22:16.0177 0x0754 [ FDA72810CA2F8409D9B31E833C448E34, FC24350E875D2AF2A41DB5EF0BFE4F876DADEACCC0B34B9B9C9B2CA185CBAE87 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
20:22:16.0180 0x0754 GPIOClx0101 - ok
20:22:16.0210 0x0754 [ 0BDE0FCF597E9B65600121EF54FF8340, DA5C96E84E05AD09251C82B4BFEDE274342409803730CEBF24EEAD0DCD42DA7E ] gpsvc C:\Windows\System32\gpsvc.dll
20:22:16.0232 0x0754 gpsvc - ok
20:22:16.0251 0x0754 [ 56F69F7C25FB67C970997D7066DBC593, 83E03A82237DCC5BCB3E722ACECACEF3510CAA619F33E0D7C4D902A482E90418 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:22:16.0261 0x0754 HdAudAddService - ok
20:22:16.0267 0x0754 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC, 42E631B23BB004F5C2128BAD334C21AB20FAD08AFED9E8191AE9373531BC73DD ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
20:22:16.0269 0x0754 HDAudBus - ok
20:22:16.0272 0x0754 [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
20:22:16.0273 0x0754 HidBatt - ok
20:22:16.0285 0x0754 [ 1EA1B4FABB8CC348E73CA90DBA22E104, 5C18C6BD499272F216DD4626B5E8D38181AEAC9AD917FBEB614A75B70467B258 ] HidBth C:\Windows\System32\drivers\hidbth.sys
20:22:16.0287 0x0754 HidBth - ok
20:22:16.0302 0x0754 [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
20:22:16.0304 0x0754 hidi2c - ok
20:22:16.0313 0x0754 [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr C:\Windows\System32\drivers\hidir.sys
20:22:16.0315 0x0754 HidIr - ok
20:22:16.0324 0x0754 [ 449A20A674AA3FAA7F0DD4E33EE2DC20, 28B9BDA306456E8640C355718DE3477537B0FAF8C37F633C709129AAB64D9873 ] hidserv C:\Windows\system32\hidserv.dll
20:22:16.0327 0x0754 hidserv - ok
20:22:16.0331 0x0754 [ F31397220D9687E11EB448649AA6E038, 671ACEAA8E00E0D4ED7E33D06A4558121DA4F56EB94F1CBC16FEB2EF3852F7A5 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
20:22:16.0333 0x0754 HidUsb - ok
20:22:16.0386 0x0754 [ 4A5FF2053B4C47252E89DEE59A9ECDB1, 66BCDE66736C58181C2BF5590FAC3E525F14E6B9738C0A9F9AE33C3CD717BB5A ] HiSuiteOuc64.exe C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
20:22:16.0388 0x0754 HiSuiteOuc64.exe - ok
20:22:16.0393 0x0754 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5, 5758A51FD2EBE67E6DBE3A298D714D351910F9E01C428D0C1359457C9242B298 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:22:16.0397 0x0754 hkmsvc - ok
20:22:16.0405 0x0754 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18, 46BF4A968E506DE17CA401401D716B444CDC10A5C60EB081890DD4B886AEDF5F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:22:16.0412 0x0754 HomeGroupListener - ok
20:22:16.0447 0x0754 [ BE5F89BAFBD4272D5A0C0A37B97865ED, 2F80CE6D123FEED9FA7B00ACF7547FF77E0E6FDC5243942E83BE308C46D414C6 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:22:16.0456 0x0754 HomeGroupProvider - ok
20:22:16.0487 0x0754 [ 0D0213498683414DDE29B1686A4C08D5, E9B64406C04B6E55CBD17E7C47B023CEA11FEE07B791154129D6F4F29D15AB7F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
20:22:16.0492 0x0754 hpqcxs08 - ok
20:22:16.0497 0x0754 [ EE281DD6843F3F697C1AD7933EEB1E9B, 1ECE31C2150B92DDC1DCBBCECFE3E979F2C60B3F106280E3167BEC0269BF7A41 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
20:22:16.0501 0x0754 hpqddsvc - ok
20:22:16.0519 0x0754 [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:22:16.0521 0x0754 HpSAMD - ok
20:22:16.0545 0x0754 [ C995EA1C6915D897E06D41AF95B9312C, 65DE6599F1C735BBDCCE4728F7F98167BCA0BF1B8D4218BBF7546B025C9A38BD ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
20:22:16.0562 0x0754 HPSLPSVC - ok
20:22:16.0595 0x0754 [ 3502776E366C913D49C0DA928AE3E6CB, 3FB452F640B78AEDFBC09188F25C566949660163732A180331226A93DB08F26C ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:22:16.0614 0x0754 HTTP - ok
20:22:16.0655 0x0754 [ C7162F9A1784992980E8F82771A607DA, D35716854A14F535BE0899F5253070519F83531BDFAF64EC65A908C51812A784 ] HuaweiHiSuiteService64.exe C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
20:22:16.0663 0x0754 HuaweiHiSuiteService64.exe - ok
20:22:16.0679 0x0754 [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:22:16.0681 0x0754 hwpolicy - ok
20:22:16.0687 0x0754 [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
20:22:16.0689 0x0754 hyperkbd - ok
20:22:16.0704 0x0754 [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
20:22:16.0706 0x0754 HyperVideo - ok
20:22:16.0715 0x0754 [ 84CFC5EFA97D0C965EDE1D56F116A541, 0155EA62BF07D99D98D1C9B6559C8E3301B016A20D03DF1EF64B2FAB8C37403B ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
20:22:16.0719 0x0754 i8042prt - ok
20:22:16.0725 0x0754 [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO C:\Windows\System32\drivers\iaLPSSi_GPIO.sys
20:22:16.0726 0x0754 iaLPSSi_GPIO - ok
20:22:16.0744 0x0754 [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C C:\Windows\System32\drivers\iaLPSSi_I2C.sys
20:22:16.0749 0x0754 iaLPSSi_I2C - ok
20:22:16.0771 0x0754 [ FA4C48E36F0B24E7E33D3E7E1844B9C9, F61F448B8E305DEFDDA5D4A6FC4E57C798C11ED4DA0ACB885847DC8A9A7B4E98 ] iaStorA C:\Windows\system32\drivers\iaStorA.sys
20:22:16.0782 0x0754 iaStorA - ok
20:22:16.0805 0x0754 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV C:\Windows\system32\drivers\iaStorAV.sys
20:22:16.0817 0x0754 iaStorAV - ok
20:22:16.0821 0x0754 [ D5854F77CEEAFC5A8405F8ECCBEC09DF, 06D94EAF55787F807FB40E95011E90B0A719AC1A1529C2C110C1EABC5BE02C5B ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
20:22:16.0822 0x0754 IAStorDataMgrSvc - ok
20:22:16.0843 0x0754 [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:22:16.0850 0x0754 iaStorV - ok
20:22:16.0854 0x0754 [ C430482AC892D52CED021EDDD4D368A2, C54C12EAC14F40BE3E7D7159F8876A664D00CA928000E25306071D28B52EA33A ] ibtfltcoex C:\Windows\system32\DRIVERS\iBtFltCoex.sys
20:22:16.0856 0x0754 ibtfltcoex - ok
20:22:16.0859 0x0754 IEEtwCollectorService - ok
20:22:17.0039 0x0754 [ 4EB6ABBF5D78E65A418BA71EF3ACE251, 261586815680E666F61FCE3CCB5D485A1D200C42FF52D451AE31D80740EA5BDB ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
20:22:17.0157 0x0754 igfx - ok
20:22:17.0188 0x0754 [ B82255670D270B75D2D2F0F8747D1443, C40E151AC3FBF289456A4AD9E5744B314067ADA03FE729970410931904305F51 ] IKEEXT C:\Windows\System32\ikeext.dll
20:22:17.0207 0x0754 IKEEXT - ok
20:22:17.0213 0x0754 [ 4011430BC9DA46ADFAE9915EFEC312FB, 925DDDA187AE7C46C94FBBFA18FC602260957B6BA891D65DFC09385B6DDEAB58 ] intaud_WaveExtensible C:\Windows\system32\drivers\intelaud.sys
20:22:17.0215 0x0754 intaud_WaveExtensible - ok
20:22:17.0364 0x0754 [ FA2B7507CD49908B2260949E52F8B9FE, 0EA0B3B25A3B668CA18313E34138DADA5C9835E476A1BFC56588B946DF0A92E0 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:22:17.0491 0x0754 IntcAzAudAddService - ok
20:22:17.0508 0x0754 [ B375D8686E1BD2B79C0F00E3868A8C3B, A15D99F04B69FB37ED3AC0C3BBA464BF6D6EB1873D4AE1062983120E3BD1C4DB ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
20:22:17.0516 0x0754 IntcDAud - ok
20:22:17.0535 0x0754 [ DDA8E5AD97231AB50B81FED04C28F64C, 5C9E8F7CC45A9AE7FF12A02641562E271D84894DFA7C50218AC2AAA298251B60 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
20:22:17.0546 0x0754 Intel(R) Capability Licensing Service Interface - ok
20:22:17.0577 0x0754 [ 86FE509640D77FB0998FC8B1FF5523C6, 13E895DEB9B84379251699D7E52C5E3FD888994425DE01B6C4634F9E959D5584 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
20:22:17.0591 0x0754 Intel(R) Capability Licensing Service TCP IP Interface - ok
20:22:17.0619 0x0754 [ 726BFAF3DC2071218F0AE53C919A4D3B, 7934BB42C16F1DAA80AB92FA4AF4BFDD2B8AF73EF55D95950E4A77DBB3DCBF4A ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
20:22:17.0622 0x0754 Intel(R) ME Service - ok
20:22:17.0634 0x0754 [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide C:\Windows\system32\drivers\intelide.sys
20:22:17.0636 0x0754 intelide - ok
20:22:17.0640 0x0754 [ 139CFCDCD36B1B1782FD8C0014AC9B0E, E0D7E0E9B46A8CECE138D689820023BFA650FB689E4FD62855BED37E04F2D9FF ] intelpep C:\Windows\system32\drivers\intelpep.sys
20:22:17.0642 0x0754 intelpep - ok
20:22:17.0647 0x0754 [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm C:\Windows\System32\drivers\intelppm.sys
20:22:17.0650 0x0754 intelppm - ok
20:22:17.0654 0x0754 [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:22:17.0657 0x0754 IpFilterDriver - ok
20:22:17.0693 0x0754 [ DFC4050D58565ADBEE793A8D4AEBDAE6, 89B900408F030CD45753A11D6AE6CBAB87E8B0E3F8401402D2D8713C045BF488 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:22:17.0710 0x0754 iphlpsvc - ok
20:22:17.0715 0x0754 [ 9949A3C7590B8C536C05312205079A82, 9276A09D5F910AE8358A96505AB3F66C514870944D58B63B71D5E96567D1E6BB ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
20:22:17.0717 0x0754 IPMIDRV - ok
20:22:17.0728 0x0754 [ E23D32BAF152FBE35F18C6A2AB8EF271, C244E54E472B724765497731ADC0DF6DA9EBA5E7B0723A4409061F5B928851E9 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:22:17.0731 0x0754 IPNAT - ok
20:22:17.0744 0x0754 [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:22:17.0746 0x0754 IRENUM - ok
20:22:17.0762 0x0754 [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:22:17.0764 0x0754 isapnp - ok
20:22:17.0780 0x0754 [ 034D4BD9DC67C64F3A4C8A049B5173BF, C68AF5A5AD4092AA1C871BD38473AEF84EC3ECF4D06FBEB5F6C09972EF1B8A81 ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
20:22:17.0786 0x0754 iScsiPrt - ok
20:22:17.0790 0x0754 [ EE03564B7FAFE2E44EDA33D52E83B4A3, 53C917EEC92B813EB0C86B225E9887C9CDFDD7708AEA71BFAC0A3039E26D7BEB ] iwdbus C:\Windows\System32\drivers\iwdbus.sys
20:22:17.0791 0x0754 iwdbus - ok
20:22:17.0810 0x0754 [ 1128B38EEC9DAF1B36373B65E87C00A3, 071E9454B9B442C2C3272FBC1AE5E92911A23CDB99F1C718C34067A70B99F910 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
20:22:17.0814 0x0754 jhi_service - ok
20:22:17.0818 0x0754 [ 8BE92376799B6B44D543E8D07CDCF885, 425B8BB1BAF62F735B3CB5A002E6055879F02E7207E55942BFD37F1784F5F368 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
20:22:17.0820 0x0754 kbdclass - ok
20:22:17.0824 0x0754 [ FB6E47E569D4872ABEB506BE03A45FBA, 5C4056CADA8F67587A119D9AE2A0EFAB30387CF6298F4019FF68AC92E2F6F54B ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
20:22:17.0825 0x0754 kbdhid - ok
20:22:17.0835 0x0754 [ DB7A09BC90DF20F44F16F8B0F9ED3491, 2DF5E042284D61368A5801B2557351B2C4B1044AA6F966DF4DDCE7B453D1B9AE ] kbldfltr C:\Windows\system32\drivers\kbldfltr.sys
20:22:17.0836 0x0754 kbldfltr - ok
20:22:17.0840 0x0754 [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
20:22:17.0841 0x0754 kdnic - ok
20:22:17.0845 0x0754 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] KeyIso C:\Windows\system32\lsass.exe
20:22:17.0847 0x0754 KeyIso - ok
20:22:17.0863 0x0754 [ 8024A9BBC9F61EBD00B19349534DDB94, 9506F136F2C212D476929DCC36C52C0373B345FE9FB91435E110F972941552F8 ] KMSServerService C:\Windows\System32\KMSServer.exe
20:22:17.0865 0x0754 KMSServerService - ok
20:22:17.0881 0x0754 [ ADDECBCC777665BD113BED437E602AB0, B6283475A1219CE44E9F683DD3BEB8C42DA0943297E5C4699B22176AD8A6A7ED ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:22:17.0884 0x0754 KSecDD - ok
20:22:17.0903 0x0754 [ 7296EA420134EAC390798B3232D066A4, 1F5D51EEFD389706660DFB4DB4BF3EC570BEC7097CEB5CAE70EFFE35C3255346 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:22:17.0908 0x0754 KSecPkg - ok
20:22:17.0917 0x0754 [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:22:17.0919 0x0754 ksthunk - ok
20:22:17.0929 0x0754 [ 32B1A8351160F307A8C66BCB0F94A9C2, 52F1DEC2BBD4D5DDBB85ED20B99D96BBA7EB83304D76F183A11FDAFDA364E873 ] KtmRm C:\Windows\system32\msdtckrm.dll
20:22:17.0937 0x0754 KtmRm - ok
20:22:17.0943 0x0754 [ 50AECF8C21AB2A6428A6E1E10549D8E5, 6BC7C60CF5E8AFB9972619EE1C78357756E9C0A3EC783C3056CEB600DCBB1555 ] L1C C:\Windows\system32\DRIVERS\L1C63x64.sys
20:22:17.0946 0x0754 L1C - ok
20:22:17.0957 0x0754 [ 27B58E16CF895AC1F1A97C04814C2239, D4336155331DDBF91952CDC6C446C68FF524F979099BA8D9B3A578758F97B2BE ] LanmanServer C:\Windows\system32\srvsvc.dll
20:22:17.0965 0x0754 LanmanServer - ok
20:22:17.0975 0x0754 [ D0D9C2ECA4D03A8F06DCD91236B90C98, E2D1144DC8040EA5FEB0602A20BA4CB920B4BC86AD5AD05FC0DF7D74DC95DC66 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:22:17.0982 0x0754 LanmanWorkstation - ok
20:22:18.0003 0x0754 [ EE289BD147FDFF95EF1B9BD65D3B974A, EFD9D0F6C73E7D2D52DBE2E2A8D3009BFB6AB24776A100CA528A8365002C6105 ] lfsvc C:\Windows\System32\GeofenceMonitorService.dll
20:22:18.0012 0x0754 lfsvc - ok
20:22:18.0021 0x0754 [ BE166935083F9C38EDFDC21B9A7A679B, 89C64DBE58E1B974208AAAA5CC757C599B1439C205C3C48BF16BA054A06DBC94 ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
20:22:18.0023 0x0754 LHDmgr - ok
20:22:18.0027 0x0754 [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:22:18.0029 0x0754 lltdio - ok
20:22:18.0037 0x0754 [ 00E070FC0C673311AFD4B068D1242780, 50B0E0E625361145332C849709498FF444E46578DCAD2536E6D0289E0125580F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:22:18.0044 0x0754 lltdsvc - ok
20:22:18.0052 0x0754 [ D113FAD71A5E67AA94B32A0F8828D265, 08DDB4BBDB570C59926DBF5E27FCF46DCDF8B8212BB9251E97837E0504516FB3 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:22:18.0055 0x0754 lmhosts - ok
20:22:18.0073 0x0754 [ 60471C88EB4906DB0C2026B3290EE4B6, D51752E4149A5BA578BF9F8DA83443BFF0719BAA34D91BD938DAC831BC0BA6DC ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
20:22:18.0080 0x0754 LMS - ok
20:22:18.0096 0x0754 [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
20:22:18.0099 0x0754 LSI_SAS - ok
20:22:18.0104 0x0754 [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
20:22:18.0106 0x0754 LSI_SAS2 - ok
20:22:18.0122 0x0754 [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3 C:\Windows\system32\drivers\lsi_sas3.sys
20:22:18.0124 0x0754 LSI_SAS3 - ok
20:22:18.0129 0x0754 [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
20:22:18.0131 0x0754 LSI_SSS - ok
20:22:18.0150 0x0754 [ B6B69FF200F68888A7FAFDF204D00C91, 4C9BA7B8646C74AE1E49F513EF426930C09969F29F1533D84D020B414BB1609B ] LSM C:\Windows\System32\lsm.dll
20:22:18.0165 0x0754 LSM - ok
20:22:18.0171 0x0754 [ 5EF604B0698F4FA962778285E8C5F1F2, 0465BDAB7EFBE9CC648E7E736B0B8BE152BD2FAB0917F6306675B9039C77F454 ] luafv C:\Windows\system32\drivers\luafv.sys
20:22:18.0174 0x0754 luafv - ok
20:22:18.0189 0x0754 [ 0BB97D43299910CBFBA59C461B99B910, 27C22D9D9EE8A410D7396960DA93E9E260D4DCDD38DCE06E85E45C5E24C067DE ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
20:22:18.0191 0x0754 MBAMProtector - ok
20:22:18.0208 0x0754 [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
20:22:18.0216 0x0754 MBAMScheduler - ok
20:22:18.0238 0x0754 [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
20:22:18.0250 0x0754 MBAMService - ok
20:22:18.0255 0x0754 [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas C:\Windows\system32\drivers\megasas.sys
20:22:18.0256 0x0754 megasas - ok
20:22:18.0287 0x0754 [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr C:\Windows\system32\drivers\megasr.sys
20:22:18.0297 0x0754 megasr - ok
20:22:18.0304 0x0754 [ 6FE7B681F1840366B2E4E8B15BE8E2CB, D60DB52345FB17160C1761AE5BF6C8CF56B350FC626A40C985CA2AE5C88B2F50 ] MEIx64 C:\Windows\system32\DRIVERS\TeeDriverx64.sys
20:22:18.0306 0x0754 MEIx64 - ok
20:22:18.0317 0x0754 [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] MMCSS C:\Windows\system32\mmcss.dll
20:22:18.0321 0x0754 MMCSS - ok
20:22:18.0324 0x0754 [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem C:\Windows\system32\drivers\modem.sys
20:22:18.0326 0x0754 Modem - ok
20:22:18.0330 0x0754 [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor C:\Windows\System32\drivers\monitor.sys
20:22:18.0331 0x0754 monitor - ok
20:22:18.0336 0x0754 [ CEAC6D40FE887CE8406C2393CF97DE06, 34E76908B802764FF0D7AB3AF89BE77BD35B44787983343FAD89891891C0A045 ] mouclass C:\Windows\System32\drivers\mouclass.sys
20:22:18.0337 0x0754 mouclass - ok
20:22:18.0341 0x0754 [ 02D98BF804084E9A0D69D1C69B02CCA9, EC5BC5D87043DFFD035FD4DD27B3D94E03119063519E4151BCC3522B613E2D7F ] mouhid C:\Windows\System32\drivers\mouhid.sys
20:22:18.0342 0x0754 mouhid - ok
20:22:18.0360 0x0754 [ 515549560D481138E6E21AF7C6998E56, C7E4B38D8CCAF15B9BDA63C8C8209F6193AD220DA02E1264F1B687AACD8F409F ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:22:18.0363 0x0754 mountmgr - ok
20:22:18.0368 0x0754 [ 3B9398E0146855B1DC0E3D9769C80F01, DF69DB5CA30A5577648635C27DD468AF98515D07DF379B3FFDCC6B40744EDE66 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:22:18.0373 0x0754 MozillaMaintenance - ok
20:22:18.0377 0x0754 MpKsl798ac3ab - ok
20:22:18.0385 0x0754 [ F170510BE94CF45E3C6274578F6204B2, 344C3DDE1D622607CA2ABECB2C47CB0166D2D258BD94A7960C45A5ADBB640566 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:22:18.0388 0x0754 mpsdrv - ok
20:22:18.0419 0x0754 [ D186C5844393252147BE934F3871DB7A, 30160F8268B9F46E82C5CB536867E0CF280DC98074A481595072E3320200E343 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:22:18.0435 0x0754 MpsSvc - ok
20:22:18.0441 0x0754 [ 59DCEC7499095DE5AED741358037AE2D, 60C4CEBCAE27C121E9D63BD2BC3E5863A91ABC77616C56C10618273A8F9B6F61 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:22:18.0445 0x0754 MRxDAV - ok
20:22:18.0457 0x0754 [ 6129EDB793A4255B1E2FB41773AC9D9A, 3292C64FAB3B83C87790FB35F54D6702987891234AF33FD1D5299C7084795375 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:22:18.0465 0x0754 mrxsmb - ok
20:22:18.0478 0x0754 [ 295771B092D4F7FCF2B62F80CCD14320, 53655B5ABA43A6A9114FE545B88F84E52319B905B8393A51BD97678D3F94A178 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:22:18.0485 0x0754 mrxsmb10 - ok
20:22:18.0498 0x0754 [ AAF56E4E84D35411B4E446C445732DFE, 7AC41CAA0842AE4DA4EEF976202C58D7923DAA367F0D7E800D432323D5E7DE1A ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:22:18.0502 0x0754 mrxsmb20 - ok
20:22:18.0514 0x0754 [ 4E888019078AC363076A5433E89AA4F8, 3DEBDA290230B3E83F956C902C960E39463B7EFE86439199521356762769FD91 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
20:22:18.0517 0x0754 MsBridge - ok
20:22:18.0532 0x0754 [ A082C17D14D0790E27D064EA4B138AE1, 9A565ED885782D9D5135C8399C11C356DBF9EBF3B8EB4B4504BD2604AD0B45E6 ] MSDTC C:\Windows\System32\msdtc.exe
20:22:18.0536 0x0754 MSDTC - ok
20:22:18.0542 0x0754 [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:22:18.0543 0x0754 Msfs - ok
20:22:18.0548 0x0754 [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
20:22:18.0549 0x0754 msgpiowin32 - ok
20:22:18.0565 0x0754 [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:22:18.0566 0x0754 mshidkmdf - ok
20:22:18.0570 0x0754 [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
20:22:18.0571 0x0754 mshidumdf - ok
20:22:18.0574 0x0754 [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:22:18.0575 0x0754 msisadrv - ok
20:22:18.0581 0x0754 [ 810F8A0A0680662BB0CE44D0E2CEF90C, 5631B07911B7EF378CB1583A480A3C5715E59A5488B33A528F4D7A2F849B9113 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:22:18.0586 0x0754 MSiSCSI - ok
20:22:18.0589 0x0754 msiserver - ok
20:22:18.0593 0x0754 [ D22AE5313F6B7EFDDD8C117B5501F4A3, 1937EEE33BF9C4485F172B10FB17AEF3F3B8978371307F49C3338D74D96A8389 ] MsKeyboardFilter C:\Windows\System32\KeyboardFilterSvc.dll
20:22:18.0597 0x0754 MsKeyboardFilter - ok
20:22:18.0601 0x0754 [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:22:18.0602 0x0754 MSKSSRV - ok
20:22:18.0617 0x0754 [ 375E44168F2DFB91A68B8A3F619C5A7C, AC243E02E9A39D0B4DE9571F196941700EE6EB5E94F5B0BA8994FB551E73A7A8 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
20:22:18.0619 0x0754 MsLldp - ok
20:22:18.0623 0x0754 [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:22:18.0624 0x0754 MSPCLOCK - ok
20:22:18.0626 0x0754 [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:22:18.0627 0x0754 MSPQM - ok
20:22:18.0639 0x0754 [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:22:18.0646 0x0754 MsRPC - ok
20:22:18.0652 0x0754 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
20:22:18.0653 0x0754 mssmbios - ok
20:22:18.0656 0x0754 [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:22:18.0657 0x0754 MSTEE - ok
20:22:18.0670 0x0754 [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
20:22:18.0672 0x0754 MTConfig - ok
20:22:18.0690 0x0754 [ 619CA29326B82372621DB2C0964D8365, 4091F08E266DB45A6E33A4A8B1CE9FA78BB294B3111526AA9E3868620F30AFDF ] Mup C:\Windows\system32\Drivers\mup.sys
20:22:18.0692 0x0754 Mup - ok
20:22:18.0699 0x0754 [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis C:\Windows\system32\drivers\mvumis.sys
20:22:18.0701 0x0754 mvumis - ok
20:22:18.0709 0x0754 [ 74E1E62819D33F176821ADC9AFF8A3E7, 99E5C85E8A49ECBBBB5D9ABCA43BC7C756126F29A3B73E74D61F9644EF19FC8B ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
20:22:18.0714 0x0754 MyWiFiDHCPDNS - ok
20:22:18.0728 0x0754 [ 41A45D2A75494EABF2806EA051E00376, EB2497561C8E33A4297C044604C717FF854C7F046882A9E4A400AE7679BF5467 ] napagent C:\Windows\system32\qagentRT.dll
20:22:18.0738 0x0754 napagent - ok
20:22:18.0760 0x0754 [ CF8B989D89D6807B887690F2CF24EFD9, 7A3ED124D8D7736F57CD687111C478A206422D117099B2F752B6D933D009BCAC ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:22:18.0771 0x0754 NativeWifiP - ok
20:22:18.0779 0x0754 [ 71E3C0100AA19D11373CCEB2F51A6008, 58FBF35F5FE19BEABE483C11E9996BE93D76721C8C34465350FA98B465CA3672 ] NcaSvc C:\Windows\System32\ncasvc.dll
20:22:18.0784 0x0754 NcaSvc - ok
20:22:18.0791 0x0754 [ 51DF09CAB2CAC64FEE3E371D9028ED01, 9B81604D0D0359AF8F54FED6DA7116FFD2F40407895028EAD99FF1D7CFDC2D14 ] NcbService C:\Windows\System32\ncbservice.dll
20:22:18.0796 0x0754 NcbService - ok
20:22:18.0806 0x0754 [ 2586C4C167499210DCBF3ECFD8CCE210, D8129FEDE9918BF4FB0057CC58700D4E08457060E810B9CC25CA0F598506ADB8 ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
20:22:18.0810 0x0754 NcdAutoSetup - ok
20:22:18.0837 0x0754 [ AD9086052A5E5153AF43FE74138A4B27, A511F785F8B29CE7CCC923489C9D03B4722E8FDD9853556D4F0F3CA608CFA956 ] NDIS C:\Windows\system32\drivers\ndis.sys
20:22:18.0858 0x0754 NDIS - ok
20:22:18.0868 0x0754 [ C6BB12BC35D1637CA17AE16D3A4725EB, 01C1D9FA738886A195166F88207EEB6715A1DE0608978ED6C5DC738AF5C02513 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:22:18.0870 0x0754 NdisCap - ok
20:22:18.0888 0x0754 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37, CCD99962917BBE256F64AE14CCC9FD12433C72B5DB98E0E57CA8F212A11B3C8F ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
20:22:18.0892 0x0754 NdisImPlatform - ok
20:22:18.0896 0x0754 [ 9423421E735BD5394351E0C47C76BB92, 763E5D06F896C0EF8AD52515464F28BA85DB7A1560E451857AC9AA68FAFCBC66 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:22:18.0897 0x0754 NdisTapi - ok
20:22:18.0914 0x0754 [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ]

Michalkalensky
Level 3
Level 3
Příspěvky: 588
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: explorer_1 - kontrola logu

Příspěvekod Michalkalensky » 31 led 2014 20:44

Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:22:18.0916 0x0754 Ndisuio - ok
20:22:18.0920 0x0754 [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys
20:22:18.0921 0x0754 NdisVirtualBus - ok
20:22:18.0929 0x0754 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:22:18.0933 0x0754 NdisWan - ok
20:22:18.0940 0x0754 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWanLegacy C:\Windows\system32\DRIVERS\ndiswan.sys
20:22:18.0943 0x0754 NdisWanLegacy - ok
20:22:18.0948 0x0754 [ A5BD69A8812FA79D1A487691DD3FB244, 67B5EDE101943E0E8B8041DB2353D20C8B9F2D253E77964761CFE8F136C0BBC7 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:22:18.0950 0x0754 NDProxy - ok
20:22:18.0959 0x0754 [ 5A072F0B90C29C5233D78BE33EF5ED78, B32ED76A674B1FC743361FB7BBD4C915A78B14132AB056AADD445D5995AD4F32 ] Ndu C:\Windows\system32\drivers\Ndu.sys
20:22:18.0961 0x0754 Ndu - ok
20:22:18.0982 0x0754 [ 2334DC48997BA203B794DF3EE70521DB, 832F4EC1586C9669F2D54AB3B212943E43B87A33B24DCC8CDAD6A0264291EE2F ] Net Driver HPZ12 C:\Windows\System32\HPZinw12.dll
20:22:18.0986 0x0754 Net Driver HPZ12 - ok
20:22:19.0003 0x0754 [ A83D67D347A684F10B7D3019C8A6380C, 2B86832967981C8C786BF24C1CF8E13E01745ACE3333CF5C821DD93D623B96E4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:22:19.0005 0x0754 NetBIOS - ok
20:22:19.0016 0x0754 [ 0217532E19A748F0E5D569307363D5FD, C40C2E7AFA276057E7327A7BB173122689D6CEC9AE443C3850C3F94AF03DFBF5 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:22:19.0021 0x0754 NetBT - ok
20:22:19.0026 0x0754 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] Netlogon C:\Windows\system32\lsass.exe
20:22:19.0028 0x0754 Netlogon - ok
20:22:19.0049 0x0754 [ B7AD851A21FEBA3BA214972627614207, 29605320CCC3DAAD062CAECF0009DACBC2F6D28ED4E8AF7CE76132129F5572A0 ] Netman C:\Windows\System32\netman.dll
20:22:19.0056 0x0754 Netman - ok
20:22:19.0071 0x0754 [ F0F0A372C2EF6358399C4936F91B6131, CE596C71EB4D1A5E104D3148F2D0D8789882C59FD198DCF33CCAC7A08B50E4EE ] netprofm C:\Windows\System32\netprofmsvc.dll
20:22:19.0082 0x0754 netprofm - ok
20:22:19.0099 0x0754 [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:22:19.0103 0x0754 NetTcpPortSharing - ok
20:22:19.0122 0x0754 [ 70414DB660BFBB7BD58FCE8EA4364E1B, 6DFB3897CD55E22BA1EDF0AE672F4D7A6A1F512F8A0A26AF106765E6B1CF65AC ] netvsc C:\Windows\system32\DRIVERS\netvsc63.sys
20:22:19.0124 0x0754 netvsc - ok
20:22:19.0196 0x0754 [ 75B9B86878CC159FBC40C4F9202ADBE3, 80D9176112BAFB42E6568E723781E5C03BD5472AB382496C1BD784DB9B2FB6E6 ] NETwNe64 C:\Windows\system32\DRIVERS\NETwew00.sys
20:22:19.0251 0x0754 NETwNe64 - ok
20:22:19.0265 0x0754 [ 3A280F3B3C7A46E29C404ACD46ECBF5E, 81C3367A2A212DBCC65B8A0166FD092E3205AB31A146B4B737061335CEC51F9D ] NlaSvc C:\Windows\System32\nlasvc.dll
20:22:19.0273 0x0754 NlaSvc - ok
20:22:19.0289 0x0754 [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:22:19.0291 0x0754 Npfs - ok
20:22:19.0295 0x0754 [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
20:22:19.0296 0x0754 npsvctrig - ok
20:22:19.0300 0x0754 [ 6E2271ED0C3E95B8E29F3752B91B9E84, 44026AD9757EA82967D7F7578455802FAD7FE0057EAC088E0AE207C15F594B86 ] nsi C:\Windows\system32\nsisvc.dll
20:22:19.0303 0x0754 nsi - ok
20:22:19.0306 0x0754 [ E490B459978CB87779E84C761D22B827, 1E5CA38626E41618E4CA16DD0C70EB2FA86E986F0CF21A749BDE2A17015DEEC6 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:22:19.0308 0x0754 nsiproxy - ok
20:22:19.0355 0x0754 [ 4412D565C0278C401575E11072C7DCE3, 82A0E9AA88750900EA0E9983157345456B418745C8BA62FAF339640E759C0418 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:22:19.0387 0x0754 Ntfs - ok
20:22:19.0392 0x0754 [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null C:\Windows\system32\drivers\Null.sys
20:22:19.0393 0x0754 Null - ok
20:22:19.0667 0x0754 [ 9B93CC9C70EDE60A9C486E7719DB9E8D, 8E31BE72797D3308D8AF136E9F4C6199BCF4592F88E9FEB361752FF768225EC9 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:22:19.0890 0x0754 nvlddmkm - ok
20:22:19.0912 0x0754 [ F76296368BB813E0C6996501A3271C7C, FA1C127F881C09C5066CB83A686AFD7A40D731922185EA4001A52ABA230FD812 ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
20:22:19.0913 0x0754 nvpciflt - ok
20:22:19.0920 0x0754 [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:22:19.0924 0x0754 nvraid - ok
20:22:19.0944 0x0754 [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:22:19.0948 0x0754 nvstor - ok
20:22:19.0970 0x0754 [ FB50E60564ED30DDC855F0CE435C8467, C9A56D74F58739B8A069336FF5456FC5F3CE89371B8CFE8144B8D06A9C79C6AB ] nvsvc C:\Windows\system32\nvvsvc.exe
20:22:19.0988 0x0754 nvsvc - ok
20:22:20.0030 0x0754 [ C63E582366EAD77978BFFD959A66DBB8, BBAC11300AFED29291A08EEC8A740DA67C8C003AF89D06F9E0671CCF0E7908A0 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
20:22:20.0053 0x0754 nvUpdatusService - ok
20:22:20.0060 0x0754 [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:22:20.0062 0x0754 nv_agp - ok
20:22:20.0085 0x0754 [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:22:20.0089 0x0754 ose - ok
20:22:20.0102 0x0754 [ 3B510F20806B94E389784ED09DBD2111, EF8896C500B3AA3A811FDE97BC322EF3295E9BD0DE236715D4A4C52CF63727E1 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:22:20.0113 0x0754 p2pimsvc - ok
20:22:20.0128 0x0754 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B, 00D84EFED5A7129AAD86945940030474795905C32D65CBD5B1A3EBADCED8F873 ] p2psvc C:\Windows\system32\p2psvc.dll
20:22:20.0138 0x0754 p2psvc - ok
20:22:20.0151 0x0754 [ 764B1121867B2D9B31C491668AC72B2B, 32C04B6FCE1DDD09697B81473A23BDCED8BEEFBCD0D2D58DDC9A11A33C756967 ] Parport C:\Windows\System32\drivers\parport.sys
20:22:20.0154 0x0754 Parport - ok
20:22:20.0163 0x0754 [ EF0C1749C9A8CEE9A457473D433CC00F, A5FDAB5AD47471640D697C6CFBA6C67730878ABBA47D394EAA47C9733EDCE1F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:22:20.0165 0x0754 partmgr - ok
20:22:20.0178 0x0754 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD, 5908E0C9562F9CB24784491BD9AE7983A33A6BDF81AFA0A08045518A0C9BB2B1 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:22:20.0188 0x0754 PcaSvc - ok
20:22:20.0208 0x0754 [ C0D3F3BC1C84B4BA746D9847314C1164, 66FDF288ACAE021C5F63BCCC68D7534B4DB737E252AB16DFF746355D8BE7502D ] pci C:\Windows\system32\drivers\pci.sys
20:22:20.0215 0x0754 pci - ok
20:22:20.0230 0x0754 [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide C:\Windows\system32\drivers\pciide.sys
20:22:20.0232 0x0754 pciide - ok
20:22:20.0252 0x0754 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
20:22:20.0256 0x0754 pcmcia - ok
20:22:20.0264 0x0754 [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw C:\Windows\system32\drivers\pcw.sys
20:22:20.0266 0x0754 pcw - ok
20:22:20.0272 0x0754 [ B9D968D8E2B0F9C6301CEB39CFC9B9E4, 83F32831B0727F18B56DC3CAF37E45A3523D2BBCD54D1421F0DE5A0179D8A404 ] pdc C:\Windows\system32\drivers\pdc.sys
20:22:20.0274 0x0754 pdc - ok
20:22:20.0302 0x0754 [ BA50CC0BD19004AAB88BE37338B6FA0D, 34D4720A621CCB4707F2EB929F6F44C317DBC6F055F7F34F3FAC68DFDAA00DEF ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:22:20.0313 0x0754 PEAUTH - ok
20:22:20.0374 0x0754 [ 084DE525DFE82AE7453DD527390FA110, 8216AE63AE740D97204CDED6543B66FC1FB55DB86D42FBA0EC629361C40F9EC0 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
20:22:20.0429 0x0754 PeerDistSvc - ok
20:22:20.0463 0x0754 [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:22:20.0466 0x0754 PerfHost - ok
20:22:20.0501 0x0754 [ 928061178CD9856CA6B67FFFCE6BA766, 71DE3C7CA7F83EAAA550CD8A68FB67DE042B0AE51BFACB1ECB8852D502E11F50 ] pla C:\Windows\system32\pla.dll
20:22:20.0527 0x0754 pla - ok
20:22:20.0534 0x0754 [ 752A457320A946E03C3AA86C3ACD735E, 63946150581532D862F4220606E74FFC479209E1A36CD57AA78AC4AE34A26F49 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:22:20.0538 0x0754 PlugPlay - ok
20:22:20.0543 0x0754 [ AC78DF349F0E4CFB8B667C0CFFF83CCE, 7E635AA2E7350FCA0C954E697F1480A6204920AEFBCF06B90FFA02398DA82822 ] Pml Driver HPZ12 C:\Windows\System32\HPZipm12.dll
20:22:20.0547 0x0754 Pml Driver HPZ12 - ok
20:22:20.0550 0x0754 [ 045EB4F260606A03BE340D09DEAF3BA4, 6F34B8D414F7F69F4388F2F8A86E0F3AD179E423126990AF3E1EC4DCCB8E7693 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:22:20.0554 0x0754 PNRPAutoReg - ok
20:22:20.0564 0x0754 [ 3B510F20806B94E389784ED09DBD2111, EF8896C500B3AA3A811FDE97BC322EF3295E9BD0DE236715D4A4C52CF63727E1 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:22:20.0572 0x0754 PNRPsvc - ok
20:22:20.0588 0x0754 [ C16097D77A232A288D65F299E2E01105, 5CE4B44B06FD26569C0F92FF1D3991D0128D8444AE7BC9EBEF5A33811D721BE8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:22:20.0599 0x0754 PolicyAgent - ok
20:22:20.0611 0x0754 [ 00E08B30E7F7C13ECE2CDF4F46A77311, 1807C0A64C1794E572C86730816C01DCF4D8F773ADE9CAEA3AC0658F7BD71A4E ] Power C:\Windows\system32\umpo.dll
20:22:20.0615 0x0754 Power - ok
20:22:20.0693 0x0754 [ B7DB57A000D46D4DE75BC0C563E58072, 8183EB09DC4D44DFF027CA0AAA8C09921A14F088C1BC427B6ACA42340AAF69E6 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
20:22:20.0772 0x0754 PrintNotify - ok
20:22:20.0791 0x0754 [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor C:\Windows\System32\drivers\processr.sys
20:22:20.0794 0x0754 Processor - ok
20:22:20.0802 0x0754 [ 8513A1E7AE4B9DC82C4B4F432C648A58, C0C629BF79722A12B35BDA6D5EF6FD2D96E013D80D8F17077E9137ED3988B452 ] ProfSvc C:\Windows\system32\profsvc.dll
20:22:20.0808 0x0754 ProfSvc - ok
20:22:20.0814 0x0754 [ 8528BB05E4D4E25945F78B00B2555FB7, FF8E0D4580F93CD348080967F52FE6C2C68B56DAEACAE2EAEF04E19412A953AE ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:22:20.0817 0x0754 Psched - ok
20:22:20.0827 0x0754 [ AF90BB44C99D6820BE52C9BBAA523283, 9772D9CC1666959EC8EE4ED740A5179473CE4F38762109F1123DD68010D20EA1 ] QWAVE C:\Windows\system32\qwave.dll
20:22:20.0835 0x0754 QWAVE - ok
20:22:20.0847 0x0754 [ 3FB466684609A4329858CF2EBD62E0FD, CFC8FBAB1436948F9D34CE6A2D6DE2F86F3E93E50B86851CED979C8CCE609798 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:22:20.0849 0x0754 QWAVEdrv - ok
20:22:20.0863 0x0754 [ 2C56F0EE27E4EF70CA4B4983D3638905, AFFDD686886CE982424B644D9168D61C6F86A5244FF97BC644DF75B321E415E5 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:22:20.0864 0x0754 RasAcd - ok
20:22:20.0869 0x0754 [ 5F061AC45266841A2860C1858ED863B8, 9E0D52BAC8A50225C32D0397C35350601B996443E2481C808CC59D3B0763FEF0 ] RasAuto C:\Windows\System32\rasauto.dll
20:22:20.0874 0x0754 RasAuto - ok
20:22:20.0889 0x0754 [ BF3B17016764F20F9D28CF1A8DC210C0, F64B410D444D4A3DFEE356EFC5B758781FA2612771EDCF72DB91D3120385D7DB ] RasMan C:\Windows\System32\rasmans.dll
20:22:20.0900 0x0754 RasMan - ok
20:22:20.0904 0x0754 [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:22:20.0906 0x0754 RasPppoe - ok
20:22:20.0917 0x0754 [ B939A2A0F9D6C6C186721E268EB6FA93, 8AF03945428D8F0E9B6DE1C24627336398320C7C78E5F594E0A57AB2DB6E0A24 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:22:20.0924 0x0754 rdbss - ok
20:22:20.0937 0x0754 [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
20:22:20.0939 0x0754 rdpbus - ok
20:22:20.0956 0x0754 [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
20:22:20.0959 0x0754 RDPDR - ok
20:22:20.0976 0x0754 [ 858776908AF838E3790F3261B799CDA6, 5BE4658540382D1B2F46E503CE175D74E3870FE492B8B8F37C3CFB34FF8E2DA8 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
20:22:20.0977 0x0754 RdpVideoMiniport - ok
20:22:20.0986 0x0754 [ 847C6A08912C3515807049C93E526D65, 74AFC58793B43E73614D2F49B19FB360091E208097696D9DF0B0354761E0B30F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:22:20.0990 0x0754 rdyboost - ok
20:22:21.0020 0x0754 [ 036746D54347FD2D0385668E2A4064E4, 7C670176176C86D6C3814367A6282A78F4E950F84DDEDA849829236C891F5BB9 ] ReFS C:\Windows\system32\drivers\ReFS.sys
20:22:21.0035 0x0754 ReFS - ok
20:22:21.0054 0x0754 [ 5A118234A2251D6CFB8A11DFE7AC4B4A, C79AEAA4D35C10F3C0F5F75E525FE8FB839F43C5EA0D83AE2D5FAB8FEB8F6ECF ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
20:22:21.0056 0x0754 RegSrvc - ok
20:22:21.0069 0x0754 [ BFFB40FBE6D2C3469F8D06EE5E4934AB, 5B6763F973A740DCD53CEA75156926457BED8B075965033C484877DDA8B97F39 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:22:21.0075 0x0754 RemoteAccess - ok
20:22:21.0081 0x0754 [ 4DCCABE03D06955ED61BABBD8EF9F30F, 531CD60315AAF283B73E0F6CF77D4DE093B809E73C44D2AC43B7247500B3485E ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:22:21.0087 0x0754 RemoteRegistry - ok
20:22:21.0095 0x0754 [ 02307C86CB24769306B0DFA0C751952E, 637D90161C477995925936E4807B57EA80BE11761B26F5FC1B4B0F3EB52FBA87 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
20:22:21.0099 0x0754 RFCOMM - ok
20:22:21.0104 0x0754 [ D894CBD7DA753C881EE8D5E33B583225, DA4472A85F10A3DF8CE969F731E67FE7C75EE6095908AB8AC2C44851DC5A3F8B ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:22:21.0108 0x0754 RpcEptMapper - ok
20:22:21.0120 0x0754 [ 5CAE8F47B31D5CFC322B5B898C19E0FE, FDB5F0B6EA36403E031D9147AB0519011FAAD3AC8190DE5B1F17FB5472D79D47 ] RpcLocator C:\Windows\system32\locator.exe
20:22:21.0123 0x0754 RpcLocator - ok
20:22:21.0149 0x0754 [ 3FD5AE42EC87C6F532A931F96BE731DD, 8282823022391ACF65E23F461FCE5CAFFB5ADC077647FEF80B91BC4BC31EDFE2 ] RpcSs C:\Windows\system32\rpcss.dll
20:22:21.0162 0x0754 RpcSs - ok
20:22:21.0174 0x0754 [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:22:21.0176 0x0754 rspndr - ok
20:22:21.0407 0x0754 [ 48D95A57DBFDA470DED69573411E4C55, 08D614939A04B0368000946210EE20F0B5B86391DF673A6EFCB3EAD63166F0B0 ] rtsuvc C:\Windows\system32\DRIVERS\rtsuvc.sys
20:22:21.0645 0x0754 rtsuvc - ok
20:22:21.0665 0x0754 [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap C:\Windows\System32\drivers\vms3cap.sys
20:22:21.0666 0x0754 s3cap - ok
20:22:21.0671 0x0754 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] SamSs C:\Windows\system32\lsass.exe
20:22:21.0673 0x0754 SamSs - ok
20:22:21.0683 0x0754 [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:22:21.0686 0x0754 sbp2port - ok
20:22:21.0694 0x0754 [ 47C497FA4DDEA908633CAA60CEBE6805, 4DF5742D4C99D3F7B6A5671AEDB1E5E47D3399D36B28BA19C105FA604D8D5A1C ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:22:21.0700 0x0754 SCardSvr - ok
20:22:21.0713 0x0754 [ E76C4E98302AE39CC6FA5D20FC8B5438, B6B6B59CF427515087689285797F4A5763103440EBE5D87A61FA74F80F895BD0 ] ScDeviceEnum C:\Windows\System32\ScDeviceEnum.dll
20:22:21.0718 0x0754 ScDeviceEnum - ok
20:22:21.0735 0x0754 [ ABD0237B15DBD2B4695F4B7D734A58F7, D6831921F0CD3E03CBF1CA3ED5824EE0C75127842D12D4E897E74EC72B0792EB ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:22:21.0737 0x0754 scfilter - ok
20:22:21.0765 0x0754 [ 888A30EAB651502352C18745367FD179, 00CD9FA55F3E896D8BA81368DF1E855E2F64B5AC488EB4F9BF2C4E45ED63FD5F ] Schedule C:\Windows\system32\schedsvc.dll
20:22:21.0787 0x0754 Schedule - ok
20:22:21.0794 0x0754 [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] SCPolicySvc C:\Windows\System32\certprop.dll
20:22:21.0797 0x0754 SCPolicySvc - ok
20:22:21.0814 0x0754 [ 2F9A3380B8C0380E5608E29C7AA66899, 56D1908437DD3791E54866819E39CC89586C5CD804F47B556416FA8642D88CBB ] sdbus C:\Windows\System32\drivers\sdbus.sys
20:22:21.0819 0x0754 sdbus - ok
20:22:21.0834 0x0754 [ 4EAF4DCF9DBD9A56952A58F56D61C005, BCA42FD1553569D3603008CC97D88FD309E87F8A8B1522A4287A0E81CAE6C294 ] sdstor C:\Windows\System32\drivers\sdstor.sys
20:22:21.0836 0x0754 sdstor - ok
20:22:21.0840 0x0754 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:22:21.0841 0x0754 secdrv - ok
20:22:21.0845 0x0754 [ C49009F897BA4F2F4F31043663AA1485, 48C8BE1E3A4F150662AD012AF4E0357ABA792AD1147AB90EFF6CB2630E2501B6 ] seclogon C:\Windows\system32\seclogon.dll
20:22:21.0849 0x0754 seclogon - ok
20:22:21.0854 0x0754 [ A88882E64BDC1D8E8D6E727B71CCCC53, 12D2235F54D0CEEED8AA268C17CDE44020269F4FEFC70CE957DBBF99AF7F553D ] SENS C:\Windows\System32\sens.dll
20:22:21.0858 0x0754 SENS - ok
20:22:21.0880 0x0754 [ E66A7C8CE7ED22DED6DF1CA479FB4790, ADEB076F131E7A8C3AD96022B09BB33EB9AB26C9C831503B8C6960AA763B8975 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:22:21.0887 0x0754 SensrSvc - ok
20:22:21.0892 0x0754 [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx C:\Windows\system32\drivers\SerCx.sys
20:22:21.0894 0x0754 SerCx - ok
20:22:21.0910 0x0754 [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2 C:\Windows\system32\drivers\SerCx2.sys
20:22:21.0913 0x0754 SerCx2 - ok
20:22:21.0928 0x0754 [ 3CD600C089C1251BEEB4CD4CD5164F9E, D9F81951B4454B24E821E33ACA53A851A61F3135E8EC6FBE6761A1A3E1CDCBE2 ] Serenum C:\Windows\System32\drivers\serenum.sys
20:22:21.0929 0x0754 Serenum - ok
20:22:21.0947 0x0754 [ D864381BC9C725FAB01D94C060660166, 132FED95222BBE3B0B25B3F1F0EFC5903D04564BD047BA4D2042AD51E3FDA724 ] Serial C:\Windows\System32\drivers\serial.sys
20:22:21.0950 0x0754 Serial - ok
20:22:21.0953 0x0754 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D, F13FAFEC8FCF3E796196562717C433CE359A74A3E5876AB070647C717AF74028 ] sermouse C:\Windows\System32\drivers\sermouse.sys
20:22:21.0955 0x0754 sermouse - ok
20:22:21.0982 0x0754 [ F32DFA228910EAA64F0A3E2CEEFF2066, 72E0D620FB7F7DAE5AF7A667068A72CC4EA8259C889637DB182C7CE608782376 ] Service KMSELDI C:\Program Files\KMSpico\Service_KMS.exe
20:22:21.0993 0x0754 Service KMSELDI - ok
20:22:22.0007 0x0754 [ 441E6FF1F34D7A942946DB42A15FB519, A16BA505B74C7A2ADD08BD5B50728C2AD55062E0ABABAD7E3EE0EB97F3725523 ] SessionEnv C:\Windows\system32\sessenv.dll
20:22:22.0015 0x0754 SessionEnv - ok
20:22:22.0023 0x0754 [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
20:22:22.0024 0x0754 sfloppy - ok
20:22:22.0037 0x0754 [ F4414F57DF2CECB8FC969AA43A6B0D50, AD09A6E1294721507DD6BE82B91F2EEB0FF0151B9BC14A75840CD657DBFDECEC ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:22:22.0046 0x0754 SharedAccess - ok
20:22:22.0063 0x0754 [ 0D190D8B4B20446BE6299AC734DFADF1, 6551095971F99820BBFC5FED8FAB9591A3F8ABFA0F027887F3B71B79325FF6D9 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:22:22.0076 0x0754 ShellHWDetection - ok
20:22:22.0080 0x0754 [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
20:22:22.0082 0x0754 SiSRaid2 - ok
20:22:22.0086 0x0754 [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
20:22:22.0088 0x0754 SiSRaid4 - ok
20:22:22.0092 0x0754 [ 99A76D83444026619CA36744F2A468C5, FEAEE7D896AD59E77034E8B66E74E84027BD65E038D9ED944DACA59EBDA5F510 ] SmbDrvI C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys
20:22:22.0094 0x0754 SmbDrvI - ok
20:22:22.0098 0x0754 [ 587ACA15210D1B01FBF272E07A08F91A, 1F3C13C218C5EA329C6E33E4AE7CFE88DAD59DA40F59FDE09D733AFD2E489000 ] smphost C:\Windows\System32\smphost.dll
20:22:22.0101 0x0754 smphost - ok
20:22:22.0107 0x0754 [ 49EEB92DE930B8566EF615D600781DB4, 0B7C929D24FAFC34F95BB4AA77DCBA29DDD8F1977EB42713B64228677D1FBFD3 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:22:22.0111 0x0754 SNMPTRAP - ok
20:22:22.0124 0x0754 [ F6EBE514D13ECE7EDC23440039CDF9AB, B58072BE7E4E52704C7B1D52DD49F469542B4B015C6D560369EEC1B046AFB254 ] spaceport C:\Windows\system32\drivers\spaceport.sys
20:22:22.0132 0x0754 spaceport - ok
20:22:22.0137 0x0754 [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
20:22:22.0139 0x0754 SpbCx - ok
20:22:22.0169 0x0754 [ FE0CB40F36D3FCDD3A1B312EF72C38D5, 42EA50869752164764DFE8CE7E1C247BE8342A0C15F39158DC808E8A692C460F ] Spooler C:\Windows\System32\spoolsv.exe
20:22:22.0184 0x0754 Spooler - ok
20:22:22.0362 0x0754 [ E6DEC72A2A23FAA53EB9FEC3C7E29D66, 58BB3B9D50DFFF99E790D5B768FAA387F16385436BA6EB704BE6DB1F63B8E4B2 ] sppsvc C:\Windows\system32\sppsvc.exe
20:22:22.0502 0x0754 sppsvc - ok
20:22:22.0522 0x0754 [ 2B78788A1485F9B99A578A299DF42C02, A87183A9B13585C9E850437A45237105D39D7F3212ADB079D6AB430B67A59643 ] srv C:\Windows\system32\DRIVERS\srv.sys
20:22:22.0530 0x0754 srv - ok
20:22:22.0562 0x0754 [ C1AE59C0B0817236EC083A91C396005A, 26F05ECB44C300DA8F333B115727C31C5C8252C83F37F0AE7DFF89B267599CDF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:22:22.0573 0x0754 srv2 - ok
20:22:22.0582 0x0754 [ 77195C32175FC63D6054EBA5A066D727, 22F5D26809BC9288021620040FC7B7BB76708D434C863B3C0C20F73200C1C6A9 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:22:22.0586 0x0754 srvnet - ok
20:22:22.0596 0x0754 [ BB9ED3EDD8E85008215A7250D325A72E, D3404E31B7706B25CDEA7CB4260C343B5F090E8CCB9A5FA203B0F94A9112F1B3 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:22:22.0603 0x0754 SSDPSRV - ok
20:22:22.0611 0x0754 [ 3911418AFDE10EA6823B7799E4815524, A73517C4C1271E666B2B3A747756070098E923742B41572AA16573170440AA07 ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:22:22.0616 0x0754 SstpSvc - ok
20:22:22.0623 0x0754 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor C:\Windows\system32\drivers\stexstor.sys
20:22:22.0624 0x0754 stexstor - ok
20:22:22.0642 0x0754 [ D638904FE86A5FE542A1BA13A9D68E5C, 89A956F932316BC50DD99B54BAF4E2809DCAA084DBB04CB84D11E5470BEAF251 ] stisvc C:\Windows\System32\wiaservc.dll
20:22:22.0655 0x0754 stisvc - ok
20:22:22.0667 0x0754 [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci C:\Windows\system32\drivers\storahci.sys
20:22:22.0670 0x0754 storahci - ok
20:22:22.0675 0x0754 [ 7A08CEE1535F5A448215634C5EA74E50, 41529CDC08A3956F8FE9D5759B147E2E56E3305149EA415EB200249F7CD32094 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
20:22:22.0676 0x0754 storflt - ok
20:22:22.0685 0x0754 [ 6B06E2D11E604BE2B1A406C4CB3B90DE, 2DDEA1568A85AD64FCE5D10D348304FCD9BE6E96C2313353EF70A2933306D188 ] stornvme C:\Windows\system32\drivers\stornvme.sys
20:22:22.0687 0x0754 stornvme - ok
20:22:22.0692 0x0754 [ 3118058E3D07021A55324A943C6D722B, 0B255DF1977DADD2B9766EEEA814B464F0ABFA34D6439F3C453083850C121F16 ] StorSvc C:\Windows\system32\storsvc.dll
20:22:22.0696 0x0754 StorSvc - ok
20:22:22.0700 0x0754 [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc C:\Windows\system32\drivers\storvsc.sys
20:22:22.0701 0x0754 storvsc - ok
20:22:22.0706 0x0754 [ 03618F935379614837F915D04C45FC0E, 9CC0CBA7AFC58E7F921C13FA3F5269714F1F827535A311E11EA48689C4D539DE ] storvsp C:\Windows\System32\drivers\storvsp.sys
20:22:22.0708 0x0754 storvsp - ok
20:22:22.0711 0x0754 [ D8E1AE075AB3E8AD56F69C44AA978596, CAFF5116DE7F0EEFFEBE38724BCEE7D11B44153AD35EE43E314C56D5E210758A ] svsvc C:\Windows\system32\svsvc.dll
20:22:22.0714 0x0754 svsvc - ok
20:22:22.0718 0x0754 [ 9CFEFD62D86DABFAC12D1C5ED72BA6A4, 1FFE4371450F53FD774CA0349CC28F559695761C18759CEB04933FDF2FD98F65 ] SWDUMon C:\Windows\system32\DRIVERS\SWDUMon.sys
20:22:22.0719 0x0754 SWDUMon - ok
20:22:22.0723 0x0754 [ 84E0F5D41C138C5CC975137A2A98F6D3, 1E36CED05E4F4365C2AB020CAF920E3959995D7F89F3FABD7B2FB05985F85F38 ] swenum C:\Windows\System32\drivers\swenum.sys
20:22:22.0724 0x0754 swenum - ok
20:22:22.0742 0x0754 [ A5DC2E63F5E5D3C0B843307374998479, B3156296D1750FEAF2354E217735B8D888C50599869233FB1B537167F2CECE0B ] swprv C:\Windows\System32\swprv.dll
20:22:22.0756 0x0754 swprv - ok
20:22:22.0770 0x0754 [ DEDF257245AD25EAA727CB8D3CFBE5C3, 44020036185B32B2877EE95F2560DCF2E595B99B024134178B7D5F1A937935DF ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
20:22:22.0778 0x0754 SynTP - ok
20:22:22.0818 0x0754 [ E45DA7CBBA34510C8B9473AD7D4FFD0B, 89C2AED757D86C276D78D29D94DCBF9C1B6A244A2153EC85CCB2E86C5F078387 ] SysMain C:\Windows\system32\sysmain.dll
20:22:22.0841 0x0754 SysMain - ok
20:22:22.0852 0x0754 [ 373382005ACB27CB16ED16722FBE946A, A1F86A014A518B3C2EC22A8DD830111E3B2A71D860ECA65A96BC82560802ACF4 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
20:22:22.0860 0x0754 SystemEventsBroker - ok
20:22:22.0866 0x0754 [ BA6DD39266A5E15515C8C14DA2DA3E5C, 5BC917BA4E7281A67CC6CEF2F4D1972DF04DECBEFB6DED0B08FFBD06E15D4B4F ] TabletInputService C:\Windows\System32\TabSvc.dll
20:22:22.0872 0x0754 TabletInputService - ok
20:22:22.0877 0x0754 [ 3C32FF010F869BC184DF71290477384E, 55CFCEC7F026C6E2E96A2FBE846AB513BB12BB0348735274FE1B71AF019C837B ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys
20:22:22.0879 0x0754 tap0901 - ok
20:22:22.0888 0x0754 [ B517410F157693043DACA21B19B258A6, 2224EECEB575CEA811036C43BB5B0A408DE5F59BC97235AB948968E4C3E438F2 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:22:22.0897 0x0754 TapiSrv - ok
20:22:22.0965 0x0754 [ 6617F44D2432C529B2249A0498B6B40A, E108D3949DE29FE3D3302337725B835BD182CD1CD9424A54829251178D0F49D3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:22:23.0030 0x0754 Tcpip - ok
20:22:23.0097 0x0754 [ 6617F44D2432C529B2249A0498B6B40A, E108D3949DE29FE3D3302337725B835BD182CD1CD9424A54829251178D0F49D3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:22:23.0132 0x0754 TCPIP6 - ok
20:22:23.0140 0x0754 [ 33A7D83EEB15431773A6E186CFAABA21, AC5100A76CA44BFADF4A54FDB09FF5D2FF13B9F8482DC1AE86C8C27005F77B0F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:22:23.0142 0x0754 tcpipreg - ok
20:22:23.0148 0x0754 [ FFF28F9F6823EB1756C60F1649560BBF, 208DFF8BF0329D0D4761C7E31527AEED7FF5F3C36C5005953D01477F35408D5C ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:22:23.0151 0x0754 tdx - ok
20:22:23.0155 0x0754 [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt C:\Windows\System32\drivers\terminpt.sys
20:22:23.0156 0x0754 terminpt - ok
20:22:23.0180 0x0754 [ 2C77831737491F4D684D315B95C62883, 90A2574A281F19646CFCDA5FDF40063220058290D2D5523AD91B7E709EC36D3D ] TermService C:\Windows\System32\termsrv.dll
20:22:23.0199 0x0754 TermService - ok
20:22:23.0214 0x0754 [ 05FBE1F7C13E87AF7A414CDF288B1F62, 24079E1A6B2E33A1A8E76A77F73473B93DD6B379E44C982CE50D6CEED9747838 ] Themes C:\Windows\system32\themeservice.dll
20:22:23.0218 0x0754 Themes - ok
20:22:23.0231 0x0754 [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] THREADORDER C:\Windows\system32\mmcss.dll
20:22:23.0234 0x0754 THREADORDER - ok
20:22:23.0242 0x0754 [ 347A3E49CE18402305B8119A6EC7CFEB, 6768B20EE577880B0353FE84B980D4A18D323929A63FAE41F7A55123BBFC8DBA ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
20:22:23.0249 0x0754 TimeBroker - ok
20:22:23.0261 0x0754 [ 82F909359600D3603FE852DB7F135626, 2EB2BB9D81AC9A2E432B2628E296B7B21F1C82EAE8009300EEF1B8596A9F418D ] TPM C:\Windows\system32\drivers\tpm.sys
20:22:23.0265 0x0754 TPM - ok
20:22:23.0279 0x0754 [ C97E14BB6A196B0554D6EB67D8818175, C00588C94988F10507F84584DFA4C0A43B8648AD1AD35E9BAE14CDD21FCF7B90 ] TrkWks C:\Windows\System32\trkwks.dll
20:22:23.0284 0x0754 TrkWks - ok
20:22:23.0289 0x0754 [ DA56FFA46030E6FEB215E3D5DAA65B11, 36B5EED8F9044475000362DBFC8A2A40B889ED46382CCEFB6BA04BE0442F98C2 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:22:23.0291 0x0754 TrustedInstaller - ok
20:22:23.0297 0x0754 [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:22:23.0298 0x0754 TsUsbFlt - ok
20:22:23.0302 0x0754 [ E0088068DCE2EE82897027DDB8E05254, FA9C201D3C885DAD2ABE6A23343EDCC83CFB342EFF9E3005FA50B1D88B21D203 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
20:22:23.0303 0x0754 TsUsbGD - ok
20:22:23.0310 0x0754 [ C8E0E78B5D284C2FF59BDFFDAF997242, BA1576C491A1246EF9866762426D110F4570F9DB42A68C174943C7D5020FE3E2 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:22:23.0313 0x0754 tunnel - ok
20:22:23.0318 0x0754 [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
20:22:23.0319 0x0754 uagp35 - ok
20:22:23.0325 0x0754 [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
20:22:23.0328 0x0754 UASPStor - ok
20:22:23.0336 0x0754 [ 5D1B430EA11064C56E7C8F84B90DEB6A, 874D9EE807F16321C4857030F9C18D2B925785FD4BB7ED047AF9535BF3F30D84 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
20:22:23.0341 0x0754 UCX01000 - ok
20:22:23.0359 0x0754 [ 1EC649F112896FAE33250F0B97AC5D0B, 0C0A1C2C7615DEB298AD3073340FD1BF91FEBE611F133E3B48D994A6EAA8369F ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:22:23.0365 0x0754 udfs - ok
20:22:23.0379 0x0754 [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI C:\Windows\System32\drivers\UEFI.sys
20:22:23.0381 0x0754 UEFI - ok
20:22:23.0391 0x0754 [ 320878AFECDBBD61BBE98624A6CAAC08, 15C090EA32A24D976B5FCB1373B1281DCC2295C075299C814345D694AEB47CB9 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:22:23.0395 0x0754 UI0Detect - ok
20:22:23.0399 0x0754 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:22:23.0401 0x0754 uliagpkx - ok
20:22:23.0406 0x0754 [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus C:\Windows\System32\drivers\umbus.sys
20:22:23.0408 0x0754 umbus - ok
20:22:23.0416 0x0754 [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass C:\Windows\System32\drivers\umpass.sys
20:22:23.0418 0x0754 UmPass - ok
20:22:23.0428 0x0754 [ E3DDF7D43E05784FAA5E042605EEE528, 8E20E880FAB09AF4FF5C438BF9EAE9970D46C05167870110869B744E498FD761 ] UmRdpService C:\Windows\System32\umrdp.dll
20:22:23.0436 0x0754 UmRdpService - ok
20:22:23.0448 0x0754 [ 4A2FFDAC45F317E17DF642C7160EB633, F1AB762912FAA5F469F322407DA37C91556086C42D1643AD27516C12A84F74D0 ] upnphost C:\Windows\System32\upnphost.dll
20:22:23.0458 0x0754 upnphost - ok
20:22:23.0470 0x0754 [ 433ECDE01A52691FA7ACA51C10C09B70, B896296A3F8EF2AF3AC5F0091B9848156608586F1E10A95D70700BAB51E8062A ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
20:22:23.0474 0x0754 usbccgp - ok
20:22:23.0492 0x0754 [ B3D6457D841A0CAEF4C52D88621715F2, CBDD76A8A28379B107B1FB530757B477B8AB74CD01F9F3CEDC7B1BA0C6E5A990 ] usbcir C:\Windows\System32\drivers\usbcir.sys
20:22:23.0495 0x0754 usbcir - ok
20:22:23.0506 0x0754 [ 5477D6E27C7D266EF8C152B9A25ADE5E, FEE81677D284A78A0C0FB60F887A952CFC759AE78B01206D73F59FE33612C519 ] usbehci C:\Windows\System32\drivers\usbehci.sys
20:22:23.0509 0x0754 usbehci - ok
20:22:23.0524 0x0754 [ DF56C2C04EFA328D7A66B69007130266, 719316EB25A8C7B82C7941D1C5B964CC4EDA4A997732F481526DE7356F6FC0D8 ] usbhub C:\Windows\System32\drivers\usbhub.sys
20:22:23.0533 0x0754 usbhub - ok
20:22:23.0549 0x0754 [ C0E33820326199CE3CFD3B9F27F81D99, C67F55E7DD6F7FC4A96256A14A805D39C5CE8725FD86675C6C860B3DE8E4DBC3 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
20:22:23.0559 0x0754 USBHUB3 - ok
20:22:23.0570 0x0754 [ 3019097FB6C985EF24C058090FF3BDBD, 24AC518D34E338D94BF3D5B3F72E53F8A1369BAA7F32FEA3EDBCF928C4FF1D17 ] usbohci C:\Windows\System32\drivers\usbohci.sys
20:22:23.0571 0x0754 usbohci - ok
20:22:23.0575 0x0754 [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint C:\Windows\System32\drivers\usbprint.sys
20:22:23.0577 0x0754 usbprint - ok
20:22:23.0581 0x0754 [ F04D164C4168701A4E7835607722E5F1, 6F743CF2CF73945B4A4B1C4402744BC2FE1624F1346C194493AD2F7110F9EB35 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
20:22:23.0583 0x0754 usbscan - ok
20:22:23.0590 0x0754 [ B1230E9813B5C7E762DF27756AA23917, 985203D267C2BF5FA88FE043785DF3DDFD796CB3CC4007E171AF63F41C413239 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
20:22:23.0594 0x0754 USBSTOR - ok
20:22:23.0598 0x0754 [ BA4FA655E0FC577DB7436FC963932CE4, 3336FDECD4AEC6B316D4C0803E22A12719EBEDD1A9427C0DF5D3B263BE600EE6 ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
20:22:23.0599 0x0754 usbuhci - ok
20:22:23.0621 0x0754 [ 18F744E8CCEB2670040EBAF7AD77B8C6, C5E2DF4EA0D946B4DA67DE29FA9D0F079DED35EC59B98E532C4C2D5F8E86DA0A ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
20:22:23.0626 0x0754 usbvideo - ok
20:22:23.0647 0x0754 [ 3B44CB989757428208CCFCC028C13110, E71BFA4BB0F4FAEDA79606C44F7DAAB317CD99C9382942E5830F440CF96D9B35 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
20:22:23.0654 0x0754 USBXHCI - ok
20:22:23.0659 0x0754 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] VaultSvc C:\Windows\system32\lsass.exe
20:22:23.0661 0x0754 VaultSvc - ok
20:22:23.0675 0x0754 [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:22:23.0677 0x0754 vdrvroot - ok
20:22:23.0719 0x0754 [ CFBAD6B48EDFAA0828A52646B7C4C08D, DDC7D607E784CE6FB5BC62E53E6309EB583D74425E6D3FC8F3D3EC705D69C075 ] vds C:\Windows\System32\vds.exe
20:22:23.0743 0x0754 vds - ok
20:22:23.0751 0x0754 [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
20:22:23.0755 0x0754 VerifierExt - ok
20:22:23.0775 0x0754 [ 041D3EF364E624DBB2703A64A5AADF89, 94A52A35AFDD09EBCC4266BD6D44014AAB4BBDFD3F6E8C997A1CA49DFB48F60D ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
20:22:23.0788 0x0754 vhdmp - ok
20:22:23.0802 0x0754 [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide C:\Windows\system32\drivers\viaide.sys
20:22:23.0804 0x0754 viaide - ok
20:22:23.0823 0x0754 [ 3CE922E34DB12D9F3C0EA856BC09687C, E50A1885FBC775E49614989ECFEA4ACBBDDA16AF459CC5361EED9E23CC7CD42C ] Vid C:\Windows\System32\drivers\Vid.sys
20:22:23.0827 0x0754 Vid - ok
20:22:23.0832 0x0754 [ C6305BDFC4F7CE51F72BB072C03D4ACE, 73E62869CA3104F48CC3B0C45E69CE9BF4F8D7D06E29C2F049B9347ABB50554D ] vmbus C:\Windows\system32\drivers\vmbus.sys
20:22:23.0835 0x0754 vmbus - ok
20:22:23.0838 0x0754 [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
20:22:23.0839 0x0754 VMBusHID - ok
20:22:23.0852 0x0754 [ 68F8C26DEA2D42E8DEC0778943433C80, 81E8F9D62815F94952CEEABD0689473CC330F7890F66872DCD35A43C06ED33CD ] vmbusr C:\Windows\System32\drivers\vmbusr.sys
20:22:23.0856 0x0754 vmbusr - ok
20:22:23.0870 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicguestinterface C:\Windows\System32\ICSvc.dll
20:22:23.0880 0x0754 vmicguestinterface - ok
20:22:23.0891 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
20:22:23.0900 0x0754 vmicheartbeat - ok
20:22:23.0911 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
20:22:23.0919 0x0754 vmickvpexchange - ok
20:22:23.0930 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicrdv C:\Windows\System32\ICSvc.dll
20:22:23.0939 0x0754 vmicrdv - ok
20:22:23.0950 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicshutdown C:\Windows\System32\ICSvc.dll
20:22:23.0958 0x0754 vmicshutdown - ok
20:22:23.0969 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmictimesync C:\Windows\System32\ICSvc.dll
20:22:23.0978 0x0754 vmictimesync - ok
20:22:23.0989 0x0754 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicvss C:\Windows\System32\ICSvc.dll
20:22:23.0997 0x0754 vmicvss - ok
20:22:24.0013 0x0754 [ 55D7D963DE85162F1C49721E502F9744, 5AD34D6DB707EF3E5242BD8CA67B21D6258EE7E7FC477D5227BD15500AE7F45F ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:22:24.0016 0x0754 volmgr - ok
20:22:24.0028 0x0754 [ CCB9E901F7254BF96D28EB1B0E5329B7, F0E3CA4EFA544CDAEF4092284CF3EC7DF07F806A770285E281816457AD8813F5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:22:24.0034 0x0754 volmgrx - ok
20:22:24.0047 0x0754 [ 9F9CE33B50611A1C61A46B8911E0B30B, FE4EDF16CE8FC36BB2125FC7D1CF45C65B06A2C31D426635115D879987DF2159 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:22:24.0054 0x0754 volsnap - ok
20:22:24.0059 0x0754 [ 01355C98B5C3ED1EC446743CDA848FCE, B9FCF558C20E05DD0F53FFB70BBEF873EA57801E13A16701E636128D625C4B67 ] vpci C:\Windows\System32\drivers\vpci.sys
20:22:24.0061 0x0754 vpci - ok
20:22:24.0065 0x0754 [ ADBE96C33D1A5BB1BBAF90B4BC84F523, 6E9C9ED3D51E4B6E494D42ECA6F824AD86D676C12C39BBE6B8BD96366BCB02DA ] vpcivsp C:\Windows\System32\drivers\vpcivsp.sys
20:22:24.0067 0x0754 vpcivsp - ok
20:22:24.0074 0x0754 [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
20:22:24.0077 0x0754 vsmraid - ok
20:22:24.0119 0x0754 [ D51D7EF1EA5ED2BB01E9D07E6E0533BC, E31118F42B316C9B6C9072D9628AA2801FC2519F1A46C9ED167843CD67183C19 ] VSS C:\Windows\system32\vssvc.exe
20:22:24.0144 0x0754 VSS - ok
20:22:24.0162 0x0754 [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
20:22:24.0169 0x0754 VSTXRAID - ok
20:22:24.0173 0x0754 [ BE970C369E43B509C1EDA2B8FA7CECB0, 18951F2AA842A0795AA79A4E164EE925A35E6270EBE4C4CDB19D0A891830E383 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
20:22:24.0174 0x0754 vwifibus - ok
20:22:24.0179 0x0754 [ 6B26AD573CCDD5209DF4397438B76354, 2C8AC314EC471F6D8B0B12D49D621360A10DCADA7C52E73596730C954FF89FCF ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
20:22:24.0181 0x0754 vwififlt - ok
20:22:24.0185 0x0754 [ 0B48E0DFB44EE475F4FD8A8EE599AF30, 28271D4CA0C642304CD8826A3D514F44E3391F9D6D07A1595BB30CE65E7E3494 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
20:22:24.0187 0x0754 vwifimp - ok
20:22:24.0199 0x0754 [ 7599E582CA3A6AAA95A18FFE1172D339, A0410778FBBC4302EA91CF24B944427410B4706535F1192504D4F34C3ED4503E ] W32Time C:\Windows\system32\w32time.dll
20:22:24.0208 0x0754 W32Time - ok
20:22:24.0216 0x0754 [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen C:\Windows\System32\drivers\wacompen.sys
20:22:24.0227 0x0754 WacomPen - ok
20:22:24.0274 0x0754 [ 92BF4B3EBD6F163B94B7A20C65E7B698, 293E6FEFA862690A7B75443D6495144313D759971B98B495A99AAB0D2CF1F350 ] wbengine C:\Windows\system32\wbengine.exe
20:22:24.0301 0x0754 wbengine - ok
20:22:24.0329 0x0754 [ 58F28103889817C93E5B5AFABC87E709, 547381B10DAC8A3CC16FB5DE6DF2FDA3CCD8F45DF581959FFF6E30875419B011 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:22:24.0339 0x0754 WbioSrvc - ok
20:22:24.0350 0x0754 [ 772365894F14652D376B2E5030179DC9, 3D917CED040456EB269BE2B82315CEAE3589FEC016DAE37FC5BC1C3D66DE3140 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
20:22:24.0359 0x0754 Wcmsvc - ok
20:22:24.0372 0x0754 [ D2726823DF7E19F213F4805A9D6D145F, A7F582C99918D204264D3B374F70D75984BDA5805203041E3DECB8153D16E102 ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:22:24.0382 0x0754 wcncsvc - ok
20:22:24.0386 0x0754 [ 846C02A8B48CBD921A3D6AB521AA0DC4, B07573A774A6C65D24E5718DC25DF378270EB5B40221CA5A53B21D47838381D3 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:22:24.0390 0x0754 WcsPlugInService - ok
20:22:24.0408 0x0754 [ 694B28DE12AD47031FFB4B052662131A, FF3B1B1A69C82BB123073E10D9F1322ED8587F5BAC36F8AB7DAED22C7DD5C7DB ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
20:22:24.0410 0x0754 WdBoot - ok
20:22:24.0431 0x0754 [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:22:24.0446 0x0754 Wdf01000 - ok
20:22:24.0464 0x0754 [ 0B99529A3BECC3528D865DDECB62503B, 28E6B44BDC52E212D2EB269491D3574B45EE9B19821FE15167D7FA05566C89F4 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
20:22:24.0469 0x0754 WdFilter - ok
20:22:24.0481 0x0754 [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:22:24.0486 0x0754 WdiServiceHost - ok
20:22:24.0489 0x0754 [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:22:24.0494 0x0754 WdiSystemHost - ok
20:22:24.0511 0x0754 [ 282E7D46310338FF4A6B7680440EB0DA, 04242798DD82F583154AEA3D775C9BFD574FC471D01CDEB9D070872425094D82 ] WdNisDrv C:\Windows\system32\Drivers\WdNisDrv.sys
20:22:24.0514 0x0754 WdNisDrv - ok
20:22:24.0554 0x0754 WdNisSvc - ok
20:22:24.0562 0x0754 [ 6588A957873326361AB1CAC4E76F8394, BE17880CEDCAE5ED3B983443E3777842646A3E48B661422A717656E11F6DBA94 ] WebClient C:\Windows\System32\webclnt.dll
20:22:24.0568 0x0754 WebClient - ok
20:22:24.0577 0x0754 [ 3274312F263882B51B964329FAF49734, 99A020377ACF0762BE5ECD2D68EB5E1497B9D59963247E725F7F96FB5DF41FAD ] Wecsvc C:\Windows\system32\wecsvc.dll
20:22:24.0583 0x0754 Wecsvc - ok
20:22:24.0588 0x0754 [ 7CDD84E0023A0C5C230B06A7965EC65E, 6EC7DC18C76D66CF9A893C3DD20F9BE3ADD76546F9A9BA42CE4F24854709F9D9 ] WEPHOSTSVC C:\Windows\system32\wephostsvc.dll
20:22:24.0591 0x0754 WEPHOSTSVC - ok
20:22:24.0597 0x0754 [ AA1315B87D9B2E39584165318A59F15D, CD19608BE1F6B7AECF802F8D2DD4FCBDAA29450ED37F7D040DC6453924C7B0FE ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:22:24.0601 0x0754 wercplsupport - ok
20:22:24.0606 0x0754 [ 22B4C24AB921BFF7827FFBCA1F4E1BB3, B634F7018097A8E4EECDD9F032DF6A0FB6817FC3DEB92BCE6A0965B5D71D8DFA ] WerSvc C:\Windows\System32\WerSvc.dll
20:22:24.0611 0x0754 WerSvc - ok
20:22:24.0631 0x0754 [ 2E3E82D7B1076B90F4E228A8EF17B261, 0492F8E0BE09DAD9922E85CCA7BCB1548CB9DC5841F46174A0657FDC59AAC3CE ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
20:22:24.0634 0x0754 WFPLWFS - ok
20:22:24.0639 0x0754 [ E06AFE2F94BA7CFA2FE4FD2A449E60E2, 99A81E16366E9E77905D873B0246E4C11B383FE1E99E0E1D9A07FAD4E52EA9E4 ] WiaRpc C:\Windows\System32\wiarpc.dll
20:22:24.0644 0x0754 WiaRpc - ok
20:22:24.0648 0x0754 [ 867BCC69ED9C31C501465EB0E8BA9DFA, 678B7FF4D4E8624514301956CDA7FB451159BBFC83FF2E4E5E7DADAE3C7AB2EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:22:24.0649 0x0754 WIMMount - ok
20:22:24.0651 0x0754 WinDefend - ok
20:22:24.0674 0x0754 [ DD079EC8F44DCA3A176B345C6ADEFB66, 6CD9371B83EA23D2181891FAE1DB285BC111A78C35F374E57666ED09860C91A9 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
20:22:24.0690 0x0754 WinHttpAutoProxySvc - ok
20:22:24.0711 0x0754 [ 9DB490F3E823C5C3C070644B96CB9D59, 81937D0B331E43C7C61514E60B3AD51370C5201F7B4D12F8534840D91EDC32DD ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:22:24.0716 0x0754 Winmgmt - ok
20:22:24.0785 0x0754 [ 690C3FC5C9DBD6B9AEDF8341EC720E41, 0E4412BB6DEB5761F7A889FD90821FAFD7C6E173F449EAB3A0446BA653D6AD0C ] WinRM C:\Windows\system32\WsmSvc.dll
20:22:24.0852 0x0754 WinRM - ok
20:22:24.0914 0x0754 [ 9378B4E7E4E3EAE2F05823CFFF2C6EF4, 66BE95F975FAF3825DFA22BD4DA8693D37B15B83DBFDD36C7896F7363A127513 ] WlanSvc C:\Windows\System32\wlansvc.dll
20:22:24.0944 0x0754 WlanSvc - ok
20:22:24.0987 0x0754 [ C2838466CCC44FAEF2C3D4C1E5971ECB, 4CA5B1632302E59E754CEA5B3CA3977D8CE9DC7B2E8673B450BBF0D646AD7AD8 ] wlidsvc C:\Windows\system32\wlidsvc.dll
20:22:25.0018 0x0754 wlidsvc - ok
20:22:25.0024 0x0754 [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
20:22:25.0025 0x0754 WmiAcpi - ok
20:22:25.0047 0x0754 [ 7AFAC828F52D62F304A911EC32F42EEE, 4EDCF4149069413A166169F2E23F7505F47B39B7EC319E1EF6D2C46CD140AA24 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:22:25.0052 0x0754 wmiApSrv - ok
20:22:25.0063 0x0754 WMPNetworkSvc - ok
20:22:25.0119 0x0754 [ E178371E493BF17EB90FE71ABA8BE643, E6F96C62D6AD1FE65D54F6799ABC32D34DE8C6EBFF8A297CA3142EF096112FCE ] workfolderssvc C:\Windows\system32\workfolderssvc.dll
20:22:25.0147 0x0754 workfolderssvc - ok
20:22:25.0166 0x0754 [ E746BCDBA2E02CF6B8D6B26FB167FBE0, 8875BBE444A33E0C477EF1A3899955501B7E0A9479CA8AA20DD8E6AA0D9A71E6 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
20:22:25.0169 0x0754 wpcfltr - ok
20:22:25.0174 0x0754 [ 4E6A0F60DA7EF050D3D26417CD4D24E9, E6B3BFB007B641D41F8532ED086F92CB3D86E210023DBFAA9AD8152A9FD33CCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:22:25.0177 0x0754 WPCSvc - ok
20:22:25.0188 0x0754 [ D27491CFCE452C154CECFA155AD0EBC8, 1F3F74C253E3B07DE7EFE27C34DD9AF08617C7B03BB44C2902F69BA9DA3F21F2 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:22:25.0194 0x0754 WPDBusEnum - ok
20:22:25.0197 0x0754 [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
20:22:25.0199 0x0754 WpdUpFltr - ok
20:22:25.0206 0x0754 [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:22:25.0208 0x0754 ws2ifsl - ok
20:22:25.0214 0x0754 [ 5CFA46C4ACB2FD70572017052378DAE5, F09134C4433A9E174889A16F29EA6628045B21BE4FA85275ACFD24D5DFB0D937 ] wscsvc C:\Windows\System32\wscsvc.dll
20:22:25.0221 0x0754 wscsvc - ok
20:22:25.0224 0x0754 WSearch - ok
20:22:25.0301 0x0754 [ D8E3A4701376CCFD0BE542D745FA4809, CF267B5507BD02EEB6BF051534E900D592682D11159A6A13C38AE70B3CCC081F ] WSService C:\Windows\System32\WSService.dll
20:22:25.0360 0x0754 WSService - ok
20:22:25.0369 0x0754 [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys
20:22:25.0371 0x0754 wsvd - ok
20:22:25.0467 0x0754 [ 86D0BF4F792053A50D6EE43DFA5837A5, 5705DAB9C5896F10757630439AC8FEAB5754251C6C90E9E8449220A65D1E95D5 ] wuauserv C:\Windows\system32\wuaueng.dll
20:22:25.0529 0x0754 wuauserv - ok
20:22:25.0538 0x0754 [ 2FEAE33E9B2B56104596E1BA444405A9, 0A142F50E06F6224B9CB36B3CE62BE0B36DE8B8DB9F9E05D287DFB884CC7826E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:22:25.0541 0x0754 WudfPf - ok
20:22:25.0549 0x0754 [ 19240C13F526125554B5370566F21A0A, 1DD88B092451CEC309A390319342BB4D36CE938BBE6D09127BBAA53960DD8E94 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
20:22:25.0554 0x0754 WUDFRd - ok
20:22:25.0561 0x0754 [ 19240C13F526125554B5370566F21A0A, 1DD88B092451CEC309A390319342BB4D36CE938BBE6D09127BBAA53960DD8E94 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys
20:22:25.0564 0x0754 WUDFSensorLP - ok
20:22:25.0570 0x0754 [ BB73CBC65AABC4EA0A5C6A1474A0A743, D644B3C6A7202CADDADB3B68FE1B2A7C76B023FE58F667EED4D538C1F4A65D64 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:22:25.0575 0x0754 wudfsvc - ok
20:22:25.0582 0x0754 [ 19240C13F526125554B5370566F21A0A, 1DD88B092451CEC309A390319342BB4D36CE938BBE6D09127BBAA53960DD8E94 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
20:22:25.0586 0x0754 WUDFWpdFs - ok
20:22:25.0600 0x0754 [ 2FA9794CA36147756F3FDFD6CA29B46F, 4B86DC38C2411C281686E9A4E64DA6FB2992E39391371F78E012D6D8BB85123F ] WwanSvc C:\Windows\System32\wwansvc.dll
20:22:25.0612 0x0754 WwanSvc - ok
20:22:25.0721 0x0754 [ A923222A8437E6C419AFC1A3BE32FF47, ED1132AE3548AC54D838F93B36A591F3EDB34A980409ED220077871DA5630E9A ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
20:22:25.0800 0x0754 ZeroConfigService - ok
20:22:25.0815 0x0754 ================ Scan global ===============================
20:22:25.0831 0x0754 [ C89780A6F58D113C28A96D85D1261DC5, 185114F33A60916C7904E4A0F278CA43258454343E614F01F0DAFA98BAC981B1 ] C:\Windows\system32\basesrv.dll
20:22:25.0849 0x0754 [ 599F1244C60E3D6C28A8DA7FBA7A2C13, 992E5EB5E3ED6172DC986085532224A148A09A4E9A4DED9556F34533EE98E4D0 ] C:\Windows\system32\winsrv.dll
20:22:25.0872 0x0754 [ 9C1833ABD62876856836C5AE55C7CE86, 0A21E2C8B2FF3B0438C86DA7151A548F9C6F5C62CD402CBBEDB435994C8508F1 ] C:\Windows\system32\sxssrv.dll
20:22:25.0893 0x0754 [ B4B610BBCB002EC478C6FD80CF915697, CE22B87A7C7C0D325CE66FB97E7318B4A41EE0BD14D902A410126A1EBBEAA6FB ] C:\Windows\system32\services.exe
20:22:25.0915 0x0754 [ Global ] - ok
20:22:25.0915 0x0754 ================ Scan MBR ==================================
20:22:25.0922 0x0754 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:22:33.0878 0x0754 \Device\Harddisk0\DR0 - ok
20:22:33.0880 0x0754 [ 180DBDE3AF7EA48B3DB3AC27B1DDF401 ] \Device\Harddisk1\DR1
20:22:33.0885 0x0754 \Device\Harddisk1\DR1 - ok
20:22:33.0885 0x0754 ================ Scan VBR ==================================
20:22:33.0887 0x0754 [ 0AF483039B248B8CA2848FCF740831AA ] \Device\Harddisk0\DR0\Partition1
20:22:33.0888 0x0754 \Device\Harddisk0\DR0\Partition1 - ok
20:22:33.0891 0x0754 [ ED467C4024747DE6D8E62D454317CCFA ] \Device\Harddisk0\DR0\Partition2
20:22:33.0892 0x0754 \Device\Harddisk0\DR0\Partition2 - ok
20:22:33.0894 0x0754 [ 1A24BF5AC150C74927375005307AF48F ] \Device\Harddisk1\DR1\Partition1
20:22:33.0896 0x0754 \Device\Harddisk1\DR1\Partition1 - ok
20:22:34.0015 0x0754 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.3.9600.16384 ), 0x60100 ( disabled : updated )
20:22:34.0015 0x0754 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 9.0.2011.263 ), 0x41000 ( enabled : updated )
20:22:34.0016 0x0754 FW detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 9.0.2011.263 ), 0x40010 ( disabled )
20:22:34.0018 0x0754 Win FW state via NFP2: enabled
20:22:36.0498 0x0754 ============================================================
20:22:36.0498 0x0754 Scan finished
20:22:36.0498 0x0754 ============================================================
20:22:36.0513 0x1f28 Detected object count: 0
20:22:36.0513 0x1f28 Actual detected object count: 0

20:21:48.0370 0x11d8 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
20:21:54.0302 0x11d8 ============================================================
20:21:54.0302 0x11d8 Current date / time: 2014/01/31 20:21:54.0302
20:21:54.0302 0x11d8 SystemInfo:
20:21:54.0302 0x11d8
20:21:54.0302 0x11d8 OS Version: 6.3.9600 ServicePack: 0.0
20:21:54.0302 0x11d8 Product type: Workstation
20:21:54.0302 0x11d8 ComputerName: MICHAL
20:21:54.0302 0x11d8 UserName: Michal
20:21:54.0302 0x11d8 Windows directory: C:\Windows
20:21:54.0302 0x11d8 System windows directory: C:\Windows
20:21:54.0302 0x11d8 Running under WOW64
20:21:54.0302 0x11d8 Processor architecture: Intel x64
20:21:54.0302 0x11d8 Number of processors: 4
20:21:54.0302 0x11d8 Page size: 0x1000
20:21:54.0302 0x11d8 Boot type: Normal boot
20:21:54.0302 0x11d8 ============================================================
20:21:54.0338 0x11d8 KLMD registered as C:\Windows\system32\drivers\27756140.sys
20:21:54.0690 0x11d8 System UUID: {0901C1B0-6920-AC91-9115-BA22E23A568D}
20:21:55.0188 0x11d8 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:21:57.0139 0x11d8 Drive \Device\Harddisk1\DR1 - Size: 0x7470206000 (465.75 Gb), SectorSize: 0x200, Cylinders: 0xED80, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:21:57.0151 0x11d8 ============================================================
20:21:57.0151 0x11d8 \Device\Harddisk0\DR0:
20:21:57.0151 0x11d8 MBR partitions:
20:21:57.0151 0x11d8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xB, StartLBA 0x800, BlocksNum 0x1F4000
20:21:57.0151 0x11d8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1F4800, BlocksNum 0x7431D800
20:21:57.0151 0x11d8 \Device\Harddisk1\DR1:
20:21:57.0152 0x11d8 MBR partitions:
20:21:57.0152 0x11d8 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A37CE80
20:21:57.0152 0x11d8 ============================================================
20:21:57.0153 0x11d8 C: <-> \Device\Harddisk0\DR0\Partition2
20:21:57.0163 0x11d8 H: <-> \Device\Harddisk1\DR1\Partition1
20:21:57.0163 0x11d8 ============================================================
20:21:57.0163 0x11d8 Initialize success
20:21:57.0163 0x11d8 ============================================================
20:22:00.0465 0x13c4 Deinitialize success

a při spuštění ComboFix (by sUBs) mi to píše něco s kompatibilitou :-(


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 1 host