kontrola logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 10 srp 2014 14:04

log z TDSSKiller

12:34:05.0635 0x10ac TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
12:34:05.0635 0x10ac UEFI system
12:34:15.0533 0x10ac ============================================================
12:34:15.0533 0x10ac Current date / time: 2014/08/10 12:34:15.0533
12:34:15.0534 0x10ac SystemInfo:
12:34:15.0534 0x10ac
12:34:15.0534 0x10ac OS Version: 6.2.9200 ServicePack: 0.0
12:34:15.0534 0x10ac Product type: Workstation
12:34:15.0534 0x10ac ComputerName: EVGENKA
12:34:15.0534 0x10ac UserName: Evgenija
12:34:15.0534 0x10ac Windows directory: C:\WINDOWS
12:34:15.0534 0x10ac System windows directory: C:\WINDOWS
12:34:15.0534 0x10ac Running under WOW64
12:34:15.0534 0x10ac Processor architecture: Intel x64
12:34:15.0534 0x10ac Number of processors: 2
12:34:15.0534 0x10ac Page size: 0x1000
12:34:15.0534 0x10ac Boot type: Normal boot
12:34:15.0534 0x10ac ============================================================
12:34:17.0422 0x10ac KLMD registered as C:\WINDOWS\system32\drivers\50463628.sys
12:34:17.0898 0x10ac System UUID: {A2F651A8-EDE8-71FE-3C63-68ECB77792BE}
12:34:19.0000 0x10ac Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:34:19.0000 0x10ac ============================================================
12:34:19.0000 0x10ac \Device\Harddisk0\DR0:
12:34:19.0000 0x10ac GPT partitions:
12:34:19.0000 0x10ac \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {FE282917-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xE1000
12:34:19.0000 0x10ac \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {FE28291F-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0xE1800, BlocksNum 0x82000
12:34:19.0000 0x10ac \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {FE282921-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x163800, BlocksNum 0x40000
12:34:19.0000 0x10ac \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {FE282929-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x1A3800, BlocksNum 0x38DA1800
12:34:19.0000 0x10ac \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {26B3207E-CB64-4A62-8DEF-4794BED022DF}, Name: Basic data partition, StartLBA 0x38F45000, BlocksNum 0x1441000
12:34:19.0000 0x10ac MBR partitions:
12:34:19.0000 0x10ac ============================================================
12:34:19.0032 0x10ac C: <-> \Device\Harddisk0\DR0\Partition4
12:34:19.0032 0x10ac ============================================================
12:34:19.0032 0x10ac Initialize success
12:34:19.0032 0x10ac ============================================================
12:34:21.0829 0x10f0 ============================================================
12:34:21.0829 0x10f0 Scan started
12:34:21.0829 0x10f0 Mode: Manual;
12:34:21.0829 0x10f0 ============================================================
12:34:21.0829 0x10f0 KSN ping started
12:34:24.0188 0x10f0 KSN ping finished: true
12:34:25.0438 0x10f0 ================ Scan system memory ========================
12:34:25.0438 0x10f0 System memory - ok
12:34:25.0438 0x10f0 ================ Scan services =============================
12:34:25.0610 0x10f0 [ E890C46E4754F0DF51BAFCC8D2E07498, E620D03030F3B65442E0A5CB8B59016A6E8DB3BCA52741977B8897B34438E902 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
12:34:25.0626 0x10f0 1394ohci - ok
12:34:25.0657 0x10f0 [ 4F18D4C7EA14F11A7211F60D553C03DB, 09AB6D2D8E9B7B6D6A97708551C0E4B34538947A15EA2A69C11764D7BC0BB7F6 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
12:34:25.0657 0x10f0 3ware - ok
12:34:25.0673 0x10f0 [ 975AABEB243B800C23626D6B652C5A9C, FB02336F26AF10BA2A0D1B97C33CB1D78BB90CA51EF008A613A0274779798FAD ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
12:34:25.0688 0x10f0 ACPI - ok
12:34:25.0704 0x10f0 [ DC968C37822117E576B933F34A2D130C, 4C94E00ADC242296D7CBBFC7346D5F9AE5FE1B0C616ECA3BDE10A7B34FD2040B ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
12:34:25.0704 0x10f0 acpiex - ok
12:34:25.0735 0x10f0 [ 0CA9F7C3A78227C21A0A7854E245CFB2, D54147C9C1EE2F0098B863B0852E027DB89D6FA67F6B7FD54F609D9715A11442 ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
12:34:25.0735 0x10f0 acpipagr - ok
12:34:25.0751 0x10f0 [ 8EB8DA03B142D3DD1EB9ED8107A76C43, 24B9B24F9A5BDF3AAD13C4EE0638497D9CA4A100096C6EAE403E0215EA89C439 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
12:34:25.0751 0x10f0 AcpiPmi - ok
12:34:25.0782 0x10f0 [ CBCE725C5D86ABA7D2604E22951AA9B8, DE0440F0E943F057EBCD01DB4B1E12DBC241FBF03C42021306D322AB88FF8F21 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
12:34:25.0782 0x10f0 acpitime - ok
12:34:25.0923 0x10f0 [ A6B6AB9502B63F43A9A56AE6AFB22078, DD1F0BA3D8F3333F52A71EAE3719A001F6EF844D647FFABF0E4C56C6C764ACA7 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:34:25.0938 0x10f0 AdobeFlashPlayerUpdateSvc - ok
12:34:25.0985 0x10f0 [ 93C6388592B99925C1D1576E465BC80F, 4C48BE5471DA4788357D71E90DFEA20FE320C7AAE1F4C55AFBE2E46FEA5CF8FB ] adp94xx C:\WINDOWS\system32\drivers\adp94xx.sys
12:34:26.0016 0x10f0 adp94xx - ok
12:34:26.0048 0x10f0 [ D27763E0247292654E7F7D16444C7C72, 0314C713D31E2B34F215B52F804F014D876E6ED92DC656CC3E27920CCD36CF0E ] adpahci C:\WINDOWS\system32\drivers\adpahci.sys
12:34:26.0063 0x10f0 adpahci - ok
12:34:26.0063 0x10f0 [ 67B90070FF48F794AF19F9FCF0080D75, 5D0D352606D58D2CA0814F38EF7B1774C030BE44353DF5910CBFAAF4FDE64ED6 ] adpu320 C:\WINDOWS\system32\drivers\adpu320.sys
12:34:26.0079 0x10f0 adpu320 - ok
12:34:26.0110 0x10f0 [ 974AE60BF5B90E31412D93596C968E5B, 092B59C2B67C4618E7B1800615D1DF7199482F60D0D27BD91763F7F8D7FC883F ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll
12:34:26.0126 0x10f0 AeLookupSvc - ok
12:34:26.0188 0x10f0 [ FE7FB9612D354EB41DF4F0FF5D6FB259, 98D5BD9C1300195C49CB0717A831A06D99F7AE631D5EA065E10BFE7C2FA57A18 ] AFD C:\WINDOWS\system32\drivers\afd.sys
12:34:26.0204 0x10f0 AFD - ok
12:34:26.0204 0x10f0 [ 01590377A5AB19E792528C628A2A68F9, F3A4B6CA4E8D4436E44E36D7F7EEF3DC861D1EE50D41F4273226C4ED95674B84 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys
12:34:26.0204 0x10f0 agp440 - ok
12:34:26.0220 0x10f0 [ D1BE8E6E5B3AF23A4393AF1BF867977A, B3AE97D35A9304198715D76F6C3F0545AA176FDEBA6C2055782558B11DFA14EB ] ALG C:\WINDOWS\System32\alg.exe
12:34:26.0235 0x10f0 ALG - ok
12:34:26.0251 0x10f0 [ 025E8C755BE293E50854D26D1BBE5133, 4373639689306A3D8FE0F862072711BAD5DBAA45E105CD3129586439A90EE070 ] AllUserInstallAgent C:\WINDOWS\system32\AUInstallAgent.dll
12:34:26.0251 0x10f0 AllUserInstallAgent - ok
12:34:26.0282 0x10f0 [ 5A81054B824004B1ECC04F0034A1CDF9, 73A1986A4B346C425157216EBF16CC90EFFC642EDF6109E6364CF0552E3388FD ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
12:34:26.0298 0x10f0 AmdK8 - ok
12:34:26.0298 0x10f0 [ B849D453E644FAB9BC8EF6DC8CA9C4C6, B803CDA478D3385937C44CBB05A0E65ABACEFEBA682975787C44E2904FB89D2D ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
12:34:26.0298 0x10f0 AmdPPM - ok
12:34:26.0329 0x10f0 [ 35A0EB5AECB0FA3C41A2FB514A562304, 737783ABF348288471AC7051D4DC6CB336D686C94EC7B8938DCA74AFE9BECB1C ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
12:34:26.0345 0x10f0 amdsata - ok
12:34:26.0360 0x10f0 [ 00452671904F5EE94B50BF0219C97164, 99F9B86D3DB3E10B014120A63CD43CBAAB22C8E38851090ABE37D89ABD61F7B6 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
12:34:26.0360 0x10f0 amdsbs - ok
12:34:26.0391 0x10f0 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7, DC0B8B798720F5F75F8AFD3383CF69194282AEEE84DCACB97382F4C86E1D3E49 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
12:34:26.0391 0x10f0 amdxata - ok
12:34:26.0407 0x10f0 [ 83B3682CE922FB0F415734B26D9D6233, 9102E8B410BB1AE426770896B6AB584D1F02830337FBB2DEC182F3F19832F35F ] AppID C:\WINDOWS\system32\drivers\appid.sys
12:34:26.0407 0x10f0 AppID - ok
12:34:26.0438 0x10f0 [ CE2BEAD7F31816FF0AC490D048C969F9, 7D24C5A9E8F7C21CC6D8BF2CA29A8B79DDE7EEDE2F37D36B9071ECE1CF61371F ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
12:34:26.0438 0x10f0 AppIDSvc - ok
12:34:26.0470 0x10f0 [ 4F750B7EFCB6520AE01E01D082D7D476, AD2A67D727A1D4DD0BBACC6B4BB432FA9A14D50D8BA292B95A4747CEC9F85728 ] Appinfo C:\WINDOWS\System32\appinfo.dll
12:34:26.0470 0x10f0 Appinfo - ok
12:34:26.0470 0x10f0 [ E933401B392387F4BE34DE8BAF1722A7, 57CC6DE31E2C82D2B12509F0A5EC9EC70DD2EF6A1F31A66ADF62DC6AE0A67323 ] arc C:\WINDOWS\system32\drivers\arc.sys
12:34:26.0485 0x10f0 arc - ok
12:34:26.0501 0x10f0 [ 07CA323EF2E8247A568AB0F3662AD644, 1224B41193F0E9B164732BA5BF707A13427C82C1D8C3EDC2AAE5C5C75454B9F6 ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
12:34:26.0516 0x10f0 arcsas - ok
12:34:26.0548 0x10f0 [ D95E64416A4A3ED6986E0F474DA934BD, DBB4A0DED0DABE1F8FF0DB8C0E9EC4EC906A85A45DC0AEC013A8744F9BF5D40E ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys
12:34:26.0548 0x10f0 aswHwid - ok
12:34:26.0579 0x10f0 [ FF1E537A3632CBB9A0BF72B9FD0878D5, B26E6A1F6E6FA5280A12861EFAD44D8F49353F47B21843EBA73E149CF613DCBC ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
12:34:26.0579 0x10f0 aswMonFlt - ok
12:34:26.0595 0x10f0 [ A5757DE5F9C83AB40667A53D5126EA40, 58B72B1B126CF641188703CE82E26BEB0C41AD7587CFFCCCE9E3C64CC7AACC90 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys
12:34:26.0595 0x10f0 aswRdr - ok
12:34:26.0657 0x10f0 [ 645D97385F3F284FB5604F9B970F4D24, 15A9D7F0F4C1062210E4E744A9069B8645177D19F35B8740D74022639DC05F2E ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
12:34:26.0657 0x10f0 aswRvrt - ok
12:34:26.0751 0x10f0 [ B8FDEDE963B82CFD23B3A53A3084666D, 3537E5B684FB6F0AA589A5FA7CD111E1744DF384AB1A266D4114100F104ED11B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
12:34:26.0782 0x10f0 aswSnx - ok
12:34:26.0829 0x10f0 [ 0DEDC041DF594AEC2C3BD00417CFAF60, 0D3A8924503986546EE256D185225C0B080FDB6B0C8B0BED7516B07A7334371B ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
12:34:26.0845 0x10f0 aswSP - ok
12:34:26.0876 0x10f0 [ 48DED912CDE54FC0923B9858512366E1, 9B216B934408A7CB3CE2B41240B7EF01EAA3BC066211B784064FF8AC97A29B4E ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys
12:34:26.0876 0x10f0 aswStm - ok
12:34:26.0891 0x10f0 [ 471A311745848B80339436688A8286E6, E51C57236CEC19AC38E85D115DB97875517D837811188AD2E53FA49055B53890 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
12:34:26.0907 0x10f0 aswVmm - ok
12:34:26.0923 0x10f0 [ 74DBAEC35366C4EE7670428808715A6A, 3B3A7A81CD8038C4750560B94A9247C4409410780B312BA71EDF2E393DCA7474 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:34:26.0923 0x10f0 AsyncMac - ok
12:34:26.0938 0x10f0 [ A721FF570C2387E383BDDEA9632863C9, 45DD7787F44A2C742560FEB03AB66910C2F0002D95BB02C55EEDE973AA92AD24 ] atapi C:\WINDOWS\system32\drivers\atapi.sys
12:34:26.0954 0x10f0 atapi - ok
12:34:26.0985 0x10f0 [ BCD7A47EF587DC00DD61D12D9C2D1E44, 95BC9AC8BA8A86DB5C7A6317002BD9872F193B401A0C58DF252DCF3D4A7541E2 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
12:34:27.0001 0x10f0 AudioEndpointBuilder - ok
12:34:27.0063 0x10f0 [ 599B3F685A263A114FFAF3BE29C49C75, 579E9561BA8537888E061E303F3F89E2E6F8B8DED74369C3767DB10B35CD45E8 ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
12:34:27.0110 0x10f0 Audiosrv - ok
12:34:27.0251 0x10f0 [ 73F5C13B431915BAE35254B4E95DFB71, 393A045859382C44133C004598B1512048046BCC129FED2247A77FDBFCDB6DFF ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
12:34:27.0266 0x10f0 avast! Antivirus - ok
12:34:27.0298 0x10f0 [ 89491EF71D5EA011127832C588002853, 05620E4235956D8446FB9604F930738C8AA97E3A74C907E37F7CC08B8EDA0461 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
12:34:27.0298 0x10f0 AxInstSV - ok
12:34:27.0376 0x10f0 [ 87AB5BB072A3F128541D5B815F82FFDD, 186AF33D3DE90638C3E165CAC3DA17295E8A80CDB523F9BE4AF7D38CA6954905 ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
12:34:27.0392 0x10f0 b06bdrv - ok
12:34:27.0423 0x10f0 [ 81703BC5D68DEDBB086C2368FBE7B334, CFD4A55C8045C482F8D410514F3211AEFA00097AB395F5A04BFE983ED6254F6B ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
12:34:27.0438 0x10f0 BasicDisplay - ok
12:34:27.0438 0x10f0 [ 5EC68164E14D25675C98BBB5F09E8606, 1D7EDB21C87039FC5F39F46460AD852BC4EC6B179B1C205D189DD3C397343435 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
12:34:27.0454 0x10f0 BasicRender - ok
12:34:27.0485 0x10f0 [ 89143A7BA7850F5C7E61B43BB44B6418, 00BB781DF87D4FF1BAFD318AFE237296B4F5925023BA4486405EC0A384C88D8F ] BDESVC C:\WINDOWS\System32\bdesvc.dll
12:34:27.0501 0x10f0 BDESVC - ok
12:34:27.0501 0x10f0 [ 9E7AEA59776D904607985AFFE7E5E183, C3DB745A9F4DA7CB9628A7913DD52B2444B14FEB9D588FF6558CF52CEB8955EB ] Beep C:\WINDOWS\system32\drivers\Beep.sys
12:34:27.0517 0x10f0 Beep - ok
12:34:27.0579 0x10f0 [ 53AA55632B94622F2DC3695E86EF9363, 9B5BB8EDA48A37AE97BCD42D83B25A6D10AA6231EABE745DCCE6D60E19094A6F ] BFE C:\WINDOWS\System32\bfe.dll
12:34:27.0610 0x10f0 BFE - ok
12:34:27.0688 0x10f0 [ D598C44A7072D3108D8D8102EC5E07F7, D7472E9BAAB7B6E1D30F4E153412E2A16EE5C08DE2BF8BFF4D65089825226FE0 ] BITS C:\WINDOWS\System32\qmgr.dll
12:34:27.0720 0x10f0 BITS - ok
12:34:27.0735 0x10f0 [ B17AC10B47C7FCB44D22A1F06415840E, 990D6F629D93F4F913D218ACE5187A26DCB762BAFB2BB279CCE8CAF2755D85A5 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
12:34:27.0735 0x10f0 bowser - ok
12:34:27.0782 0x10f0 [ 038FA1B55531E7020DB705B42FCCE373, 023E87E3204D64890D6FEA78E762E5BC5BD0A59325EBC264834727779EEEDBC5 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
12:34:27.0782 0x10f0 BrokerInfrastructure - ok
12:34:27.0829 0x10f0 [ 310068BDA80B1D55C36580FD8A873FAF, A75412FF1F483461F526E9A359DCEECA5E683441514464D5ED82D1A9740D583E ] Browser C:\WINDOWS\System32\browser.dll
12:34:27.0829 0x10f0 Browser - ok
12:34:27.0860 0x10f0 [ 6695200F455E251F0BCC9CE4D0978D59, 4DB2F967E449581A9330EF43E794B45B93581564B20C5B991FC1EC665A640D69 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
12:34:27.0876 0x10f0 BthAvrcpTg - ok
12:34:27.0892 0x10f0 [ A8B20D852B07AE19A13B5D47EC4E4C3B, 86571C9E2BA15BB169CAB2D24C4D0598154C02FD173638CAFC685A7F6B09472D ] BthEnum C:\WINDOWS\System32\drivers\BthEnum.sys
12:34:27.0892 0x10f0 BthEnum - ok
12:34:27.0938 0x10f0 [ 616EB8748C988AEE98D93DA141C3D3B4, 15A055B0496BDB29CBCF6EEBF112D4BA1C7A2FF39124728830D0FD1FD7A404CB ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
12:34:27.0938 0x10f0 BthHFEnum - ok
12:34:27.0970 0x10f0 [ DCB4EBD928A6FB368BE6CAE522412DE1, 9E1345F29467054689B9F48B5CCB567760D36610A4EA9AF41B829EAD60347269 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
12:34:27.0970 0x10f0 bthhfhid - ok
12:34:27.0985 0x10f0 [ 42201C346F0B8C458E1E9CDE04D68A2C, 6168FD0D10CD06B00B5C79D5D2B5C353AAC22FD99CE8D417DDBA33ED63CFB8BF ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
12:34:28.0001 0x10f0 BthLEEnum - ok
12:34:28.0001 0x10f0 [ 033916CE8784A848B9A3D686B7F66D97, B4D0514D59646CF6B70D4FA488CF95C38EA38CC5C509329CC8753E897C640AFA ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
12:34:28.0017 0x10f0 BTHMODEM - ok
12:34:28.0017 0x10f0 [ 091BB978E9504D0AD14586929431A957, ACED02B879026A228E35F40847C210BC30A5AFC948FFE922DB21663E4A8DFF1D ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
12:34:28.0032 0x10f0 BthPan - ok
12:34:28.0110 0x10f0 [ 13795CAA34239D97A7211E7F9D96E012, C4F3402B063A7CFCE386D1AE9255975A199164BA9E7DCDB6129725213A0642B1 ] BTHPORT C:\WINDOWS\System32\Drivers\BTHport.sys
12:34:28.0142 0x10f0 BTHPORT - ok
12:34:28.0173 0x10f0 [ A4387C3D271959313E2577DB7BE8BA7A, C71474802102102EBE04DF036EEB2F5FB3380BE288E3842F19F234EFAE977D70 ] bthserv C:\WINDOWS\system32\bthserv.dll
12:34:28.0173 0x10f0 bthserv - ok
12:34:28.0188 0x10f0 [ 1F715957F5236D30B6020A19A4271F6A, C06B637C2C6919E2DE1055AE249AE3EAF7B4890799F22BF5757CC10CEF145043 ] BTHUSB C:\WINDOWS\System32\Drivers\BTHUSB.sys
12:34:28.0188 0x10f0 BTHUSB - ok
12:34:28.0220 0x10f0 [ 990B1BABE6E81FB18E65A87EBEFB1772, 1820D4AC57E1D4B7FB5AA89C277B16910ED73712878D2B43FE542CE16DFE16C3 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
12:34:28.0220 0x10f0 cdfs - ok
12:34:28.0251 0x10f0 [ 339BFF85D788268752DA8C9644B188EE, C2279F1A39AED39865A5027D2FD087F8E82F3ED8C94BA4D922855B98E792AFC5 ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
12:34:28.0267 0x10f0 cdrom - ok
12:34:28.0282 0x10f0 [ BAF8F0F55BC300E5F882E521F054E345, FB228DB18F2FA55D8BA35A7E6778EE5D2EB0C29D384F1A0A868F90AE706188D7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
12:34:28.0298 0x10f0 CertPropSvc - ok
12:34:28.0313 0x10f0 [ F64B7D1A37CC1D5F421D5359EEC81E2E, 2B4879DD32B2C20B94847755E22B1BCBE2B567B3989C57A9BA2DD783307EFFDB ] circlass C:\WINDOWS\System32\drivers\circlass.sys
12:34:28.0313 0x10f0 circlass - ok
12:34:28.0329 0x10f0 [ 9905168708DB68849B879B5548F68AB3, B7A495E57B9398704988DC472126CBC5B8D76761A34F51732FBF6CC88E3AB79A ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
12:34:28.0345 0x10f0 CLFS - ok
12:34:28.0360 0x10f0 [ 2DC8538A2260647484A6C921CA837313, 094059DD66B0C50A1CAE288F920107B0B6AD1AA5758284E35B92C131EDEA30EA ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
12:34:28.0360 0x10f0 CmBatt - ok
12:34:28.0423 0x10f0 [ DBF9E5346431557BF56F41E7F8EC0DC1, D5FA34C873DA9BE40301D53198355556506AB5145B78B14D0AA88570A0058589 ] CNG C:\WINDOWS\system32\Drivers\cng.sys
12:34:28.0438 0x10f0 CNG - ok
12:34:28.0454 0x10f0 [ 0E5B1E9E7122EDAAF1F6CE047965CA92, 803E585B92D1E2E5B6BF67BE511E88DC2629A12407C3E30F7AEFB544D390A9B8 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys
12:34:28.0454 0x10f0 CompositeBus - ok
12:34:28.0454 0x10f0 COMSysApp - ok
12:34:28.0470 0x10f0 [ D9CB0782AF819548072AA45B70F8B22D, 04796F39ABB88759A534DE3D0C51F684BF2A8DE1F4028B657CCFDBDD39A6618C ] condrv C:\WINDOWS\system32\drivers\condrv.sys
12:34:28.0470 0x10f0 condrv - ok
12:34:28.0517 0x10f0 [ 9C2838A9F02BE7F3A1493498602448EE, 2A8338C41FDF2C5F2B4271F5B960502731DFECC7D3DE8312BD66CF0D7154BD76 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe

Reklama
evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 10 srp 2014 14:05

12:34:28.0517 0x10f0 cphs - ok
12:34:28.0563 0x10f0 [ 5CE2742F063731EC10C1B2EE386A2C08, 309919BDDD4649AFB95A99DCF8AFC3BAE10F9BC1E2819C0794CFD0F80682C223 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
12:34:28.0579 0x10f0 CryptSvc - ok
12:34:28.0610 0x10f0 [ FAEF4C245BE832DB41B15DAAC336AFB7, 1F8C98AB0DF4327FCB01FE0356025488E19B48A45FFFA50576B49A8587FAC42B ] dam C:\WINDOWS\system32\drivers\dam.sys
12:34:28.0610 0x10f0 dam - ok
12:34:28.0688 0x10f0 [ 1EC6E533C954BDDF2A37E7851A7E58FD, C25936A7465B6A2B3D05D2FCB09D91ACC07CFE038A5E968C99CFA9D9F2967DD4 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
12:34:28.0704 0x10f0 DcomLaunch - ok
12:34:28.0751 0x10f0 [ C8650D1F61149AA546BDBC99172EBBC1, D9592ED1B6F23B6EC76A0B93635B6E38702311B0A6982F0F9DEC37FCDAF1288B ] defragsvc C:\WINDOWS\System32\defragsvc.dll
12:34:28.0767 0x10f0 defragsvc - ok
12:34:28.0813 0x10f0 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16, ADAC7FD6AC12B50F4998C5EB0BD770DD4B80A94C4CC1B9376AD77648E48D012D ] DeviceAssociationService C:\WINDOWS\system32\das.dll
12:34:28.0813 0x10f0 DeviceAssociationService - ok
12:34:28.0845 0x10f0 [ 799BE46D45D486704CE0F37CA5385262, BB78DEE83B9DB613B1C083D55FAA458BE3E394AED80EB91B599185A7272F33B3 ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
12:34:28.0860 0x10f0 DeviceInstall - ok
12:34:28.0892 0x10f0 [ 431141C6859990824D17F71C30A78728, 448B3DC20C8FDD5B66217E0E01DBCC4904F94BDA0826F109D139DDD2C2D7FBF2 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
12:34:28.0892 0x10f0 Dfsc - ok
12:34:28.0970 0x10f0 [ 9E0E72222264745ADEB0E5AC680B0ED6, 576AFC8741695396A3B8E9DBDD3703E9D70370437D09D162262E47A140D101B4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
12:34:28.0985 0x10f0 Dhcp - ok
12:34:29.0001 0x10f0 [ 3C736FAE17BA6F91BA37594AAB139CD0, 34304A194105B19E7ADD80108DC85C3B7AA9E942C84A7EF93C475CE1D9AE4615 ] discache C:\WINDOWS\system32\drivers\discache.sys
12:34:29.0017 0x10f0 discache - ok
12:34:29.0032 0x10f0 [ AE3786294CC246A5403783E1B86A0168, 29A7B4B490CBB16DAEF5D67D0A58A2577CF3FEE8F889484DB867F6913D9D2A28 ] disk C:\WINDOWS\system32\drivers\disk.sys
12:34:29.0032 0x10f0 disk - ok
12:34:29.0048 0x10f0 [ 82A7C72593793FE1EADA7A305BD1567A, 75F432E4C75AE9EFF553BD860B3B250853BDDA85C17DBD9B7242D74593506A86 ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
12:34:29.0048 0x10f0 dmvsc - ok
12:34:29.0079 0x10f0 [ 066B9710B36AB550E01EEFCA52155968, DCA9F3F4856A6866D3F5A2EEE34E96A83F40198DB0B5AC6381A7568DE1F56FAB ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
12:34:29.0095 0x10f0 Dnscache - ok
12:34:29.0110 0x10f0 [ 9949AD2ABA168A618D46C799D6CC898C, DFAC86A0AEE83C9EFE1BEE9EC15C8CAF1D619D55AF3ACC3986057A5AC985D06A ] dot3svc C:\WINDOWS\System32\dot3svc.dll
12:34:29.0110 0x10f0 dot3svc - ok
12:34:29.0142 0x10f0 [ 109FC3F80BF4F4DC5A071058074F13C1, F30736F45BA1811D59E9CB1C172D8D1EA9F5A7D36DCFFBFC9E7E02448C1CF851 ] DPS C:\WINDOWS\system32\dps.dll
12:34:29.0142 0x10f0 DPS - ok
12:34:29.0157 0x10f0 [ 9C7C183F937951AE17C5B8B3259CF3FF, 8ED607139F15D08B4835ACF864421BA4C08C88FE90B9AAF707F5D8514D7731B1 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
12:34:29.0157 0x10f0 drmkaud - ok
12:34:29.0204 0x10f0 [ F87F4AAAF6664906248D11D5E579A53B, F283932F68ED93891EEF00C18724359AB7057E922A3CDC8BC6F33F84D2B0BEE5 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
12:34:29.0220 0x10f0 DsmSvc - ok
12:34:29.0313 0x10f0 [ E6AF4DF1817953D73C519B17CF849756, 26A90EB368A3F572086F223ABED87B8FC6F998AE401C9E52BEB5EE76AB052702 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
12:34:29.0345 0x10f0 DXGKrnl - ok
12:34:29.0392 0x10f0 [ 58BA473DD88F5FC1932282BA683AA03E, B8A4407D3006D91BE88F9C5389AC1CACC73BEBF6F66433A1E5EB8E58E8836C12 ] Eaphost C:\WINDOWS\System32\eapsvc.dll
12:34:29.0392 0x10f0 Eaphost - ok
12:34:29.0532 0x10f0 [ 5AB97B3282D7D6114949D1EB5C8598E4, FB9449CC1CDC12C12AA0469BB6ACC770CB011250EDFD86E9600E754610608EFD ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
12:34:29.0610 0x10f0 ebdrv - ok
12:34:29.0642 0x10f0 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] EFS C:\WINDOWS\System32\lsass.exe
12:34:29.0642 0x10f0 EFS - ok
12:34:29.0673 0x10f0 [ 66D60BD9A4C05616ABECA2A901475098, 8111550DB03FFD72F1822F47B16F075DA92874B64F19342D7CF60B0EE648AFEF ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
12:34:29.0673 0x10f0 EhStorClass - ok
12:34:29.0689 0x10f0 [ A61D0F543024E458C0FE32352E1978E2, BDE6BC140300EAF790F16466C28897CE0BD7D94DCED13FDE20AA4AACA0F6A4FD ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
12:34:29.0689 0x10f0 EhStorTcgDrv - ok
12:34:29.0704 0x10f0 [ D790D058D67582DB9C84C2D33695FE6B, A5763D7F6D191EA4B290B3E92D842AC36FD46DF598472E70B46E45D8CCD2F912 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
12:34:29.0704 0x10f0 ErrDev - ok
12:34:29.0751 0x10f0 [ F9E01C2D9F8BC049E04CF5DC24A5F638, CB6CCB59C77D4A59DDA846608AABEF1DFEC24C8422712AB8D59E27C13D731D2E ] EventSystem C:\WINDOWS\system32\es.dll
12:34:29.0782 0x10f0 EventSystem - ok
12:34:29.0798 0x10f0 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03, 6B0146A4C9AD32DCDC2DEE8E8C5A29F687665458486449E0D37B151ED63B8ADC ] exfat C:\WINDOWS\system32\drivers\exfat.sys
12:34:29.0798 0x10f0 exfat - ok
12:34:29.0814 0x10f0 [ 60996602A7111FD2D086E803F33E4282, E62A91C90F8542990BEA4E6A5D9DD3D070F4EB23B4C13414C5DA2B0219509749 ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
12:34:29.0829 0x10f0 fastfat - ok
12:34:29.0876 0x10f0 [ F0E7F8382ED5E138B0DFA4CB5058BCFE, 6247C7B75F975F5AB080FFB9881EF58A6F360219F7AF2DE871F38E80CAF3B62C ] Fax C:\WINDOWS\system32\fxssvc.exe
12:34:29.0907 0x10f0 Fax - ok
12:34:29.0907 0x10f0 [ 73B2D11DF0B6E03A0CB0323218ACB3E4, BA9256919BAA2E0760F6A658B557FDC389ACE8F9820D1A41FD995FC5613F5AA6 ] fdc C:\WINDOWS\System32\drivers\fdc.sys
12:34:29.0907 0x10f0 fdc - ok
12:34:29.0954 0x10f0 [ 0828E3E7BD77C89149EAD3232BFD38DB, A6A296647A4EDBFF59124E3A9C0AB48759AA1738615ACFA5A454FF6BD3C31BA2 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
12:34:29.0954 0x10f0 fdPHost - ok
12:34:29.0970 0x10f0 [ 872506AAB591E8908DF4461475AF92DF, 772F2D08CB95775E438822B9EA005CBA92ED4071ADAB2C0101156A7D037D4704 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
12:34:29.0985 0x10f0 FDResPub - ok
12:34:30.0001 0x10f0 [ 0588950D93A426F97C7AAADB1A9B0458, ABCB3619BD58CAC438FC032495AE45A7B6FFDD4BD33C1B3D1BC7F9F13FCB727A ] fhsvc C:\WINDOWS\system32\fhsvc.dll
12:34:30.0001 0x10f0 fhsvc - ok
12:34:30.0032 0x10f0 [ 88A9EBACD1058ABB237A6B4E96E7F397, 263D25D33B679EB01D97763701347C31B2F72E28CE2C7EC8013EA77756D98BE1 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
12:34:30.0032 0x10f0 FileInfo - ok
12:34:30.0048 0x10f0 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02, 1D7BFB00D74A28AC13ECBA1E0036D50EE79266AC02CEDB2632466BF9DD46F211 ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
12:34:30.0048 0x10f0 Filetrace - ok
12:34:30.0064 0x10f0 [ B1D4C168FF7B8579E3745888658FFB1D, 1A5C13E902A0C788A8B995ADD2FBC3303005911C0AA3F3F4497D3016AA0EF583 ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
12:34:30.0064 0x10f0 flpydisk - ok
12:34:30.0095 0x10f0 [ B33EC133AE4E6C1881D2302D93D2467D, 77E3A16257EA3698B3FCD947D004144E8D1EEE48EF5C82DF49B1B9B2B3C61DB2 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
12:34:30.0095 0x10f0 FltMgr - ok
12:34:30.0189 0x10f0 [ 0BCDC0FF11B984162B0CF0FF6E9E0146, D44A3CECBA36B7A64854E244FA6B5E65047896BF9983D20B431410FBBA36697A ] FontCache C:\WINDOWS\system32\FntCache.dll
12:34:30.0220 0x10f0 FontCache - ok
12:34:30.0314 0x10f0 [ 0B56259F5611787222A04A8F254E51D4, F77AEC0ACBFAF9154E32223B84B613229DACCD953AEBC3E96C27570F9AB10FD0 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:34:30.0314 0x10f0 FontCache3.0.0.0 - ok
12:34:30.0360 0x10f0 [ A5F7873A39E4E9FAAAE59B7E9E36B705, 32036109F5A50E9F3BEF97C5B28AE8179B3A5E22517868A83CADE4671FF90DEC ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
12:34:30.0360 0x10f0 FsDepends - ok
12:34:30.0376 0x10f0 [ A6DD7D491F587F4BC13FB972977DC8E8, B86F97F17F6F443EC16DEF67CCA4EF78AFE56078D2877838A982FECB19557C87 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:34:30.0376 0x10f0 Fs_Rec - ok
12:34:30.0423 0x10f0 [ C1646A95EAC515F60CDB2A7A8A013C1E, F559B83C02B17265EDE95DD497C1A94E402F07EC251FC47449F789907AFFED14 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
12:34:30.0439 0x10f0 fvevol - ok
12:34:30.0470 0x10f0 [ A969D92973DFA895E7776B4BFE36DBB2, 7528E6983ECC59291A7A386E4E459B19D1593ABDDFFD276E2F01B0EA21693E20 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys
12:34:30.0470 0x10f0 FxPPM - ok
12:34:30.0501 0x10f0 [ 52BC441E07A827EBAB70CDC7EAEDB28D, 8DECBD8E12EA52039742599CFBBF0D3B6610B57EF8D9DAEEEA33D202A478D286 ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys
12:34:30.0501 0x10f0 gagp30kx - ok
12:34:30.0595 0x10f0 [ C403C5DB49A0F9AAF4F2128EDC0106D8, 3C6948B63278022D8182F773C5FA15784514F76C1546118DDBADBA322B962D12 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
12:34:30.0595 0x10f0 GamesAppService - ok
12:34:30.0610 0x10f0 [ 721F8EEF5E9747F32670DEFF7FB92541, E0A8EF70753E260C2C7D93D316B5EF9589DB086FDF829BDA2958C6A09CE471A6 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
12:34:30.0610 0x10f0 gencounter - ok
12:34:30.0657 0x10f0 [ 4E1D0A246E10CFDDBF856432418DE404, 17AC5322A50D0914F90F41E9CBFEBE04CDC3BCA1CFAFE8A3F6CADD305738E1AF ] GFNEXSrv C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
12:34:30.0657 0x10f0 GFNEXSrv - ok
12:34:30.0704 0x10f0 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E, 4BF196E1CAC94E9265EBEB68F41C3E29F0C709ECFF9420B5B1C9C82680D5D6A8 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
12:34:30.0704 0x10f0 GPIOClx0101 - ok
12:34:30.0798 0x10f0 [ 5358678C6370F2ADC5291849F6503262, 841633D7A936C3889690C67E189BAD4C6B294C196FFFE5B564FCECDFE46A9E52 ] gpsvc C:\WINDOWS\System32\gpsvc.dll
12:34:30.0845 0x10f0 gpsvc - ok
12:34:30.0892 0x10f0 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:34:30.0907 0x10f0 gupdate - ok
12:34:30.0907 0x10f0 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:34:30.0907 0x10f0 gupdatem - ok
12:34:30.0985 0x10f0 [ 630555943E5A3FE21010CE91EC7FC84F, 20D7247A4363EE9E851501D89A466564ADCAEC304DE42280E4E09AD8499436A9 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys
12:34:31.0001 0x10f0 HdAudAddService - ok
12:34:31.0032 0x10f0 [ 7D87B5B6C7188D553E11B59DC7F0B111, FC633DB71E1D72E8AD8F89BBB54324CC6ED17F5594EF55DD0BDB58EE1F601FF5 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
12:34:31.0032 0x10f0 HDAudBus - ok
12:34:31.0048 0x10f0 [ 3F76BBA53D65E85A7F53E7A71082082C, D1E18815BB19CD11007C4A66162C76F55D4FE6B09B34ED45969C7ECC29D394AD ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
12:34:31.0064 0x10f0 HidBatt - ok
12:34:31.0095 0x10f0 [ 085F150D002B7F0153D3C06DDF33A143, 41847FD02608ECFE3A6B4B38CBDE8416B0EF17491868511FD704B0BCC280338E ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
12:34:31.0095 0x10f0 HidBth - ok
12:34:31.0110 0x10f0 [ CC4A07E51D89575CAB6F4EB590D87CD4, DFB4EAF0923EF9FF6C42EDD1EA5E4025F243C9BE2D03D5423FE8A897DC01D657 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
12:34:31.0110 0x10f0 hidi2c - ok
12:34:31.0126 0x10f0 [ DC96F7DACB777CDEAEF9958A50BFDA06, 7CE79F32D5EE65C0178CFF56523825D3EE01095B2CE8C67634A6604A821A9086 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
12:34:31.0126 0x10f0 HidIr - ok
12:34:31.0157 0x10f0 [ FAC37D7B3D6354A5A5E19A45B50B4008, 2962B552A1DA545DFDEF0886582E82596FE8A3A19AAF989B025AFDA84D16D4EC ] hidserv C:\WINDOWS\system32\hidserv.dll
12:34:31.0173 0x10f0 hidserv - ok
12:34:31.0173 0x10f0 [ 012C354B4AB48E9A7A657DF39E3A2073, B15D0089CE509FF1CF73DFE095425C1C99FC3971622DCAAD9CAEB989A12A4FDB ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
12:34:31.0173 0x10f0 HidUsb - ok
12:34:31.0220 0x10f0 [ 43F884B61A24377567CD0FEB35236334, B3BA36B527C8D6D83DE2FBCD8D503B87FD2611BF15B07A7BC138DC8BAE6A50C1 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll
12:34:31.0220 0x10f0 hkmsvc - ok
12:34:31.0282 0x10f0 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF, E6967F3F465C6E903221BC0FCBAE7D05FD18C0BF110D929335F5935364B3C1BC ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
12:34:31.0282 0x10f0 HomeGroupListener - ok
12:34:31.0345 0x10f0 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E, B965DCC72625188F3B896CB447B7696F22687266EAFC5AA270E2AD53DD9F324D ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
12:34:31.0360 0x10f0 HomeGroupProvider - ok
12:34:31.0392 0x10f0 [ 64DB7A8D97CA53DCCF93D0A1E08342CF, 02CAB7F28D3830C482683425C60044239C6F1562556688A274CA2C237C846E76 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
12:34:31.0392 0x10f0 HpSAMD - ok
12:34:31.0439 0x10f0 [ F4A91D985EB9D1D2717D538F3424603C, 454AD2FF3A7963B9835AEF300F6672F92D0CCF59593BA2CCC83F0EC1446BB659 ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
12:34:31.0470 0x10f0 HTTP - ok
12:34:31.0485 0x10f0 [ 2A98301068801700906C06649860FE94, 664394A52326289DCA0828B0041A105653F4FEF3E3DCCC3787AAE0F6FDC73A14 ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
12:34:31.0485 0x10f0 hwpolicy - ok
12:34:31.0501 0x10f0 [ DC76901D82097C9E297F20C287CB9A27, 01A412D0D8A65050BE4250A7C4B9F98A4C43FD891827761E0C830369A5F9F09C ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
12:34:31.0501 0x10f0 hyperkbd - ok
12:34:31.0517 0x10f0 [ 716413AB3CA12DE0A7222D28C1C9352C, B82B586BD9DBD70DDA19A02504E8CB00DA53677703AB848B53387601C5BAD3D3 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
12:34:31.0517 0x10f0 HyperVideo - ok
12:34:31.0532 0x10f0 [ C9E9CBF73AFFBFE3E801EFB516787BA3, 1A850D614BDA6AA4195CC657702BC6242BA51B90131717743182AA160F65E72C ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
12:34:31.0548 0x10f0 i8042prt - ok
12:34:31.0579 0x10f0 [ 050F2539E14F9D5E90A4B61738EC29BD, 0E65468B9F452FA7DB6DF2C1B2B2E9439C79031E27054FBDBDFE28A9F98721D7 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
12:34:31.0595 0x10f0 iaStorA - ok
12:34:31.0610 0x10f0 [ 5E394EBD26FD68AA9300332C46BEDD62, 56A5DA7CE08C07B519E55D0A46AA9D10B640349808EFE02B3278267B75B5F603 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
12:34:31.0626 0x10f0 iaStorV - ok
12:34:31.0939 0x10f0 [ 11A31FC2481BFE69B0507ED8C80215F4, 8A1E90611F749E8F04B6D86E835E981CAC16D0841305CADB19E58682DA006698 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
12:34:32.0142 0x10f0 igfx - ok
12:34:32.0267 0x10f0 [ 24847A06B84339FEEDE5CABF3D27D320, 7727B1DAD0D4A1D474FBBEFCEBDF36A1F07D1AA300869AE57A24ED91BF84B6B4 ] iirsp C:\WINDOWS\system32\drivers\iirsp.sys
12:34:32.0282 0x10f0 iirsp - ok
12:34:32.0345 0x10f0 [ E455C83E029121270BED73CDAC381F37, 433D525C19DBF26FAC28853C606C872D973104842B0EF1B2BF2EAC85457E2953 ] IKEEXT C:\WINDOWS\System32\ikeext.dll
12:34:32.0392 0x10f0 IKEEXT - ok
12:34:32.0579 0x10f0 [ E0B2C982CA743CE8B3CBD7DD50AB82B0, 04B65ED97DD747BAF4A1110836DBCEDB1F1971FDFAFB06BD003B2950393513EA ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
12:34:32.0673 0x10f0 IntcAzAudAddService - ok
12:34:32.0736 0x10f0 [ F5495B38BFB9149925F54F65AB40EFBF, 7CBB72C41E2343DACBFB967A39CA04788561EDECB289C41BC2D6A06B80882AC4 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
12:34:32.0736 0x10f0 IntcDAud - ok
12:34:32.0829 0x10f0 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC, F791EE101EEF8B9F48102B6C63A89B78F7C0041C750C4F4C0D16D54B583B7B5C ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
12:34:32.0845 0x10f0 Intel(R) Capability Licensing Service Interface - ok
12:34:32.0923 0x10f0 [ 9656F8E29F6C3161A3E99BCD3A472FF9, 30AD00B53CCB2E4121508729F3471D3C0568F1C32324C398382C97E8BC43ECF0 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
12:34:32.0923 0x10f0 Intel(R) ME Service - ok
12:34:32.0954 0x10f0 [ 4F37726CF764CA18A8A84F85EF3A7F24, 6212B23917526E127CE641A11A58DA93651FFE70829C4079FE465DBDC81CF470 ] intelide C:\WINDOWS\system32\drivers\intelide.sys
12:34:32.0954 0x10f0 intelide - ok
12:34:33.0001 0x10f0 [ E15CDF68DD73423F15D4AC404793AF0D, E2D0136AF68D1A73EB3A63C83284B4661222CB0A4AFACCF276CB57CBD4850287 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
12:34:33.0001 0x10f0 intelppm - ok
12:34:33.0032 0x10f0 [ 8FCA66234A0933D796BB780B7953BAB9, 7DD677F5EE09A8D7A75C9E475B5E6B3DCA49D1E846C7D160B839D7029B1C5B6D ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:34:33.0032 0x10f0 IpFilterDriver - ok
12:34:33.0111 0x10f0 [ C217B8D2E58C57A319B16125C3D4B69C, 905BB858E1782BD08FF080A4A604CE662440A15601B178FBD30269C306C04CCF ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
12:34:33.0142 0x10f0 iphlpsvc - ok
12:34:33.0173 0x10f0 [ A4071DA3AE419F9694BFCB267C7DB8D7, 392DEE1DA51606C29418A98D2861F115E9F67C688B4281C53E87BA73A98809FB ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
12:34:33.0173 0x10f0 IPMIDRV - ok
12:34:33.0204 0x10f0 [ 3969B9C218DD3FAA9F4ED2FFC3651C02, 93447F124CC55FB17055126432194153E1BB8F0FD95A47608494B6834A5F7089 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
12:34:33.0220 0x10f0 IPNAT - ok
12:34:33.0220 0x10f0 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C, 4099BAA2DB4ADB93B878D71E241B7D9EB7E0EE7ED0FE2450CCB9E4718B3726EB ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
12:34:33.0220 0x10f0 IRENUM - ok
12:34:33.0298 0x10f0 [ B1812629E609D0D34723E75075F40055, 13A2FC0249956654824AFA877C9337872CF0BF78FF25764F965E0E2336A7D9DB ] iSafeKrnl C:\Program Files (x86)\iSafe\iSafeKrnl.sys
12:34:33.0298 0x10f0 iSafeKrnl - ok
12:34:33.0329 0x10f0 [ 2526313ED5B17A70F47779251489C0AE, 62562A0C75A1C45F2ACA8821E528FE153D8AB49E5FFD338A75E41EB0C5558C36 ] iSafeKrnlBoot C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys
12:34:33.0345 0x10f0 iSafeKrnlBoot - ok
12:34:33.0345 0x10f0 [ 9C5FB725EC439BDE15CF2FB3D400E7CC, BA5489641E3B676C4FC2FCD555B59A2BBD5D67C7E71CDFD0357855A27C983F38 ] iSafeKrnlKit C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys
12:34:33.0361 0x10f0 iSafeKrnlKit - ok
12:34:33.0423 0x10f0 [ DE3EF2748B229FAAF478756584BDD831, EAF8F9DDA3E2DE2C588E8C705BBEE983B3AA8467607A5F1925BBBED440CBA6F8 ] iSafeKrnlR3 C:\Program Files (x86)\iSafe\iSafeKrnlR3.sys
12:34:33.0423 0x10f0 iSafeKrnlR3 - ok
12:34:33.0470 0x10f0 [ 5666681720B9A3071E589C80A6FB9D5E, B92E2CEC2DD84D8605439BF5CF1ECEB9E4D2C2C4149F59D0F1D5B1226EE87AE1 ] iSafeNetFilter C:\Program Files (x86)\iSafe\iSafeNetFilter.sys
12:34:33.0470 0x10f0 Suspicious file ( Forged ): C:\Program Files (x86)\iSafe\iSafeNetFilter.sys. Real md5: 5666681720B9A3071E589C80A6FB9D5E, sha256: B92E2CEC2DD84D8605439BF5CF1ECEB9E4D2C2C4149F59D0F1D5B1226EE87AE1, fake md5: A5EFCD41E193757C92FCDB5F0403D26B, fake sha256: 0ABA7D2EF8F6230DBA5B113B61D0D5934EF45DFDDB0085CB33F64BFD71531BF9
12:34:33.0470 0x10f0 iSafeNetFilter - detected ForgedFile.Multi.Generic ( 1 )
12:34:35.0939 0x10f0 iSafeNetFilter ( ForgedFile.Multi.Generic ) - warning
12:34:35.0939 0x10f0 Force sending object to P2P due to detect: iSafeNetFilter
12:34:38.0361 0x10f0 Object send P2P result: true
12:34:42.0095 0x10f0 [ 922B8CC8646025B511174552BD5720A9, DA4406E62B92E763031B7F444E5325257A8360C89CCA32D4597B52AE6B77A08B ] iSafeService C:\Program Files (x86)\iSafe\iSafeSvc.exe
12:34:42.0095 0x10f0 iSafeService - ok
12:34:42.0142 0x10f0 [ D940C5BB9DC92E588533C19ABCC3D2C2, D1442854CEDE86F2C187A35851E74C873D34B772C60BC118FA1577F79C03364D ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
12:34:42.0142 0x10f0 isapnp - ok
12:34:42.0205 0x10f0 [ E6530FD4F61B40F338BF4355A21B9A09, FE9BF039B9901BEC260A69F7C49ACFA9881AD470DCCBA70C7EC36F518DA71702 ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
12:34:42.0220 0x10f0 iScsiPrt - ok
12:34:42.0299 0x10f0 [ 78ABBE558F57144047F10A0F50FE4B2F, 6BE608F7697D83FD6C7E6EA422AC5637933BDC96B1044C12DE9A419CE7D6F6CE ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
12:34:42.0314 0x10f0 jhi_service - ok
12:34:42.0314 0x10f0 [ 8FBD94B69D6423E20ABCD59D86368B21, 218EF992095E365EC917413749856A64D55D8129D77098E24D670843233377F4 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
12:34:42.0330 0x10f0 kbdclass - ok
12:34:42.0345 0x10f0 [ E88C932ABDF8185A62C8F2FC7B051FB6, 67F9AF58237A11F0BF3D15AA5B32E5CE66B7AA039B999D938F7F6E63DCEA7A6E ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
12:34:42.0345 0x10f0 kbdhid - ok
12:34:42.0361 0x10f0 [ FB6C185092E18011EF49989425C2AA87, 043524409E0A764201DD221C48B7DEEA0D161945EB37D4B88313BAB2299949DF ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys
12:34:42.0361 0x10f0 kdnic - ok
12:34:42.0361 0x10f0 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] KeyIso C:\WINDOWS\system32\lsass.exe
12:34:42.0377 0x10f0 KeyIso - ok
12:34:42.0408 0x10f0 [ 8B3EB6372436195B8EA8AE09A184BCE2, 9AFB7A9D6AEEBF5994C85B355155024768116E2D537C9FA169BC3F4594ECD35C ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
12:34:42.0424 0x10f0 KSecDD - ok
12:34:42.0455 0x10f0 [ 3DD9C86EA88E8B5A51904AD87E1F2E78, F9EC9A571212117C01934CD29057EB1B3FA095F670294244AF7D9387D3F6E555 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
12:34:42.0455 0x10f0 KSecPkg - ok
12:34:42.0502 0x10f0 [ 81492FEEBF2F26455B00EE8DBAE8A1B0, E33AA2DFB2D3BB30B02CDADA2EC290F86329DA3198327A653F39A843D86390B9 ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
12:34:42.0502 0x10f0 ksthunk - ok
12:34:42.0564 0x10f0 [ 5825DBACEDC3812B5CF8D40B997BF210, 1C2997BCC707C1029B21876E093038CE3BBF6E6694B4CCF7EEDD47172ED9A541 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
12:34:42.0580 0x10f0 KtmRm - ok
12:34:42.0627 0x10f0 [ 256EE31588257E8A555DBFAA13F1908E, B6817F632EDEA483E35BF26846DCDD4E95E860620959179B2A5D8AD7EEDDB126 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
12:34:42.0642 0x10f0 LanmanServer - ok
12:34:42.0705 0x10f0 [ 16650912BE5A94B40E0B3B4C39652B56, 908C2C9367AE0AC9AECB5D91514BB33ACD746D99F19C1A8DD6A9550E9CAD9E00 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
12:34:42.0705 0x10f0 LanmanWorkstation - ok
12:34:42.0736 0x10f0 [ CEEFD29FC551F289810B0B9381B321DC, 900F206B487B2190D9363F28AA4BA0CD7DCFE1D005BE05A48AF74B1B81194691 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys
12:34:42.0736 0x10f0 lltdio - ok
12:34:42.0767 0x10f0 [ BCF53485E0A94722CDE3C4A93CD8EB8C, D24E1066EB102245A89A5D17D608DB9DF6B71C99F1C77E070B95EFD17D268141 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
12:34:42.0783 0x10f0 lltdsvc - ok
12:34:42.0799 0x10f0 [ 5A2F7F1CBC2E631A497DAD16164E06D2, 35274FC6C386380B01B5E8F467E71A2C4E2FB2AD701554F9B1A9B036B0340142 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
12:34:42.0799 0x10f0 lmhosts - ok
12:34:42.0830 0x10f0 [ 2C24DC448DBE8DB9BE1441B824C57E79, DA2257EEC964A47D03C2BB13317FD788E51D4685E2395B303ED7B2575FEF3B19 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
12:34:42.0845 0x10f0 LMS - ok
12:34:42.0892 0x10f0 [ 022CDD12161B063D7852B1075BF3FFF2, E21267243AF2FC208D27E67827B1264A762C99AECEDB7AD2C48A04F421A6B2F0 ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
12:34:42.0892 0x10f0 LSI_SAS - ok
12:34:42.0908 0x10f0 [ 07AD59D669B996F29F91817F0ECFA34F, 026F332F862D142BFFC9D169CCD17A35BFB6B301EEC72AA13E16369B3520919C ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys
12:34:42.0908 0x10f0 LSI_SAS2 - ok
12:34:42.0924 0x10f0 [ 216FB796AA4E252ACCE93B1BCB80B5EC, 5B1E49B5F7B9C7A778198D27F8EE500FE35DC32D40B22A3D6ED67560BEB04212 ] LSI_SCSI C:\WINDOWS\system32\drivers\lsi_scsi.sys
12:34:42.0939 0x10f0 LSI_SCSI - ok
12:34:42.0955 0x10f0 [ 5E80530AF37102488EE980B4A92AF99F, 364E18EAD9AC22F8A306B24C6C43E58224F6BE2744EFEAA2484696B8D9880851 ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
12:34:42.0955 0x10f0 LSI_SSS - ok
12:34:43.0002 0x10f0 [ D85E906ACB458BE4BF5F3C9B35404A74, BE054A5521F6D2E88BC4A4A9A7DD74A73CFAD80EDDD0C86491A6F4629BE3DAB5 ] LSM C:\WINDOWS\System32\lsm.dll
12:34:43.0017 0x10f0 LSM - ok
12:34:43.0064 0x10f0 [ 2BDC5D711FA61307CE6190D47C956368, 6BCDC6CBB9783F1ABE8957BDA94AF977DFB2A310BB6D19085EFC8609C97FD180 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
12:34:43.0080 0x10f0 luafv - ok
12:34:43.0095 0x10f0 [ 9B0D829C3BE4E7472DB9DD2B79908E3C, ACED5806FFF39E84007B5A3DCB16315329DC53007F46B1BEEDC391CC659F7DD3 ] megasas C:\WINDOWS\system32\drivers\megasas.sys
12:34:43.0095 0x10f0 megasas - ok
12:34:43.0127 0x10f0 [ ECC3F54C7AFC318271C4F0B4606D8DB0, FD1ACB18B8C912C7A57DABCD5460800DD0721A82E09C8D79C47B3392D61CBEA6 ] MegaSR C:\WINDOWS\system32\drivers\MegaSR.sys
12:34:43.0127 0x10f0 MegaSR - ok
12:34:43.0158 0x10f0 [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
12:34:43.0158 0x10f0 MEIx64 - ok
12:34:43.0189 0x10f0 [ EEE908BE7143FCA48CF0CB87214E2AB8, 4F9BD299F559DD36DBD93489CFAA753F236FBB70946E034D2E2260059AE20962 ] MMCSS C:\WINDOWS\system32\mmcss.dll
12:34:43.0189 0x10f0 MMCSS - ok
12:34:43.0205 0x10f0 [ 780098AD5DA8A4822E2563984C85EF7B, 29312970774E944B5ED388316CF3D350DCABF721F9695737B0AC56BE878B0446 ] Modem C:\WINDOWS\system32\drivers\modem.sys
12:34:43.0205 0x10f0 Modem - ok
12:34:43.0236 0x10f0 [ EA8EAD3F5B762F889CC7F3966625B48B, B701A42E5E08B7BC6601560446146803182E5DC631AB73E9408F19CB6432F121 ] monitor C:\WINDOWS\System32\drivers\monitor.sys
12:34:43.0236 0x10f0 monitor - ok
12:34:43.0252 0x10f0 [ 618446B98C79776654340CE27C73485E, EFE7169FDD545933B5949DA2D09266971C0C3E6894E7BD8AFE29E41567C72B16 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys
12:34:43.0252 0x10f0 mouclass - ok
12:34:43.0283 0x10f0 [ C0ADEBED913295803B579ED288936CBB, 58F71541166D1DA07C18FBD27458D55E3F8AD7291CB7496B3A2F01372A5B0CAE ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys
12:34:43.0283 0x10f0 mouhid - ok
12:34:43.0330 0x10f0 [ 89D263DBF08119CE16273991C120D6DD, 9771EDAD266F0E234E71DFB6792F396710E051F2ADCA5CDADEBBD2790D0E6054 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys
12:34:43.0330 0x10f0 mountmgr - ok
12:34:43.0361 0x10f0 [ 4CCBBD4944777CA100B9A6C2F149A46F, 7FC172FAF8266BFBBBBAD94FD67EA3C1872F5927DC3900A9A54DB2DFE34E7415 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys
12:34:43.0361 0x10f0 mpsdrv - ok
12:34:43.0517 0x10f0 [ 9DE3341BD4E14BC5FADFCAD3019F2D0D, 37E0531EADABC6D4BCC496826651D4D14CF0D10156FF13C11BDE466084B44FF4 ] MpsSvc C:\WINDOWS\system32\mpssvc.dll
12:34:43.0549 0x10f0 MpsSvc - ok
12:34:43.0564 0x10f0 [ 3D70147F55F1EC84EB9139ED7FFE48BC, 12429C2FDDDA13815F0E18F9009011AA5360955759A23A38175543F480CB92EF ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
12:34:43.0564 0x10f0 MRxDAV - ok
12:34:43.0611 0x10f0 [ 7A761AEE58658378BBA45D360F874CB0, 31972E63D93E07D92EF69571B7ED1E69B1358DCA5BEED62A9372F6411B4DFDB3 ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:34:43.0627 0x10f0 mrxsmb - ok
12:34:43.0642 0x10f0 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3, C665B7896501D42C73955F4EAF4FA3C6B2C9286957D6023C235AFBF9BFB761C6 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
12:34:43.0658 0x10f0 mrxsmb10 - ok
12:34:43.0674 0x10f0 [ 697B78CE3925E4FBFC544232A5E9E2EB, 2D03425513572F6098BAAF82C0EDB49EBAB88438971D349CA1917DA0BDB76334 ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
12:34:43.0674 0x10f0 mrxsmb20 - ok
12:34:43.0736 0x10f0 [ 98487487D6B3797CA927E9D7B030AE13, 05840AF0DD2E3CB596DA768DBD0728B52210EC05B55AB5921E697AD8956938DD ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys
12:34:43.0736 0x10f0 MsBridge - ok
12:34:43.0752 0x10f0 [ 4A07458EB4F17573BD39F22029A991C1, 74D7A1882EA4D19B8F090C2813489E5D3F759BF4AF2D88AE852EC6510C405B5E ] MSDTC C:\WINDOWS\System32\msdtc.exe
12:34:43.0767 0x10f0 MSDTC - ok
12:34:43.0783 0x10f0 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2, ECCA22985838A914EDC866C491DEB64B9FF5110EFA9BEE541F634AC5EC3081F9 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
12:34:43.0783 0x10f0 Msfs - ok
12:34:43.0799 0x10f0 [ C32A7A39B960A42BA9D4FBE47213CA03, 4DA48587138972DA5E95AEDBBBE73BA8CCADC8172C6654427ABEAC8047B27E95 ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
12:34:43.0799 0x10f0 msgpiowin32 - ok
12:34:43.0814 0x10f0 [ D3857A767B91A061B408CCAB02DA4F40, A4D780772086AD8717EE6DC2B6189F796939FB5E5AA08FD9D1984101998FBECF ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys
12:34:43.0814 0x10f0 mshidkmdf - ok
12:34:43.0830 0x10f0 [ 839B48910FB1E887635C48F3EC11A05E, F8CFD99911500CC1B6A90C8E2A1697BD5A6E5776A62A62FE5B342FE204C936B1 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
12:34:43.0830 0x10f0 mshidumdf - ok
12:34:43.0845 0x10f0 [ 55C0DB741E3AB7463242B185B1C2997C, D2E2A5B48A64EA0EC2A6566C08E65A38D11CEA64BCA7B57793BA0D009E4D974A ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys
12:34:43.0861 0x10f0 msisadrv - ok
12:34:43.0908 0x10f0 [ 216C6B035A4BA5560E1255BD8E5BB89F, A14E038604B9A5506DB145A4D9F51E2751AC825240D2744924F39C332B5DE00B ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll
12:34:43.0908 0x10f0 MSiSCSI - ok
12:34:43.0924 0x10f0 msiserver - ok
12:34:43.0939 0x10f0 [ 509809566E49F4411055864EA8D437CD, 70F37BF9C759E8BCA1C6AC8FB9805950925E1C648ED37E8561A0F7A407DFDC28 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:34:43.0939 0x10f0 MSKSSRV - ok
12:34:43.0955 0x10f0 [ 63145201D6458E4958E572E7D6FC2604, EDD4A8A3BBE94B983554B1117734E66A2647B867269C5F0567C47EDE6F3FACCB ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys
12:34:43.0955 0x10f0 MsLldp - ok
12:34:43.0971 0x10f0 [ 99D526E803DB6D7FF290FD98B6204641, 4AFAA3B1186621AEAD19E12D3DBE104DD8FCD5C106F9EC3ADA4AD1BC7093E61F ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:34:43.0971 0x10f0 MSPCLOCK - ok
12:34:43.0986 0x10f0 [ 06FA77C3E2A491ADCD704C5E73006269, 465A7EE5387E6C11398A554F73437278F5BF110356E7F49F315905C1F2459278 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
12:34:43.0986 0x10f0 MSPQM - ok
12:34:44.0017 0x10f0 [ E134EC4DE11CF78CB01432D180710D84, BB111F97AEEFDCA5866B157E9957599CD7A4952B5BCCA0B0BCA9EDFCD17E61FE ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys
12:34:44.0017 0x10f0 MsRPC - ok
12:34:44.0033 0x10f0 [ B5AECF12F09DEE97C9FCAA5BA016CE1E, F5305C4CE6C93A3A3481BD13BE0C23FE26571E11029ACFFE75FB78913681FCFC ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys
12:34:44.0033 0x10f0 mssmbios - ok
12:34:44.0064 0x10f0 [ 72D66A05E0F99F2528F6C6204FD22AA1, B14D433BC5795F1DC4C672302285E665DC012693E75574F60664AAD8874DE562 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
12:34:44.0064 0x10f0 MSTEE - ok
12:34:44.0080 0x10f0 [ 8AAAE399FC255FA105D4158CBA289001, 2F55C02605B4A3406B289FF9D46C76260B9138E3DE96AFAEA0E0522E5A2A746C ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
12:34:44.0080 0x10f0 MTConfig - ok
12:34:44.0096 0x10f0 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A, 00D33A4AB3E7C5F65F59C63F8E2FD27EF38D5484595F785D5632E9414E29352C ] Mup C:\WINDOWS\system32\Drivers\mup.sys
12:34:44.0096 0x10f0 Mup - ok
12:34:44.0111 0x10f0 [ 3A1E095277BBD406CEA8EA6B76950664, 47838F307A6354E77C19A7B1F3F3E22726EF60403B611F358AD6FFE81D7214E7 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
12:34:44.0127 0x10f0 mvumis - ok
12:34:44.0158 0x10f0 [ 4B18840511D720BA118D3017E8165875, 724458A69269A5AE57E8DAB74FF3C198A79B6F7A9602BF38A70B4A40543ED167 ] napagent C:\WINDOWS\system32\qagentRT.dll
12:34:44.0174 0x10f0 napagent - ok
12:34:44.0221 0x10f0 [ 43D7388A90A4C6EA346A4D6FF0377479, DFDCFA448B49C8A577056070AF516F08CD2E452706A3CF9173195ABA4256F35D ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
12:34:44.0221 0x10f0 NativeWifiP - ok
12:34:44.0346 0x10f0 [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 10 srp 2014 14:06

] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
12:34:44.0361 0x10f0 NAUpdate - ok
12:34:44.0392 0x10f0 [ 6A0C3996DA7DAE6D6939676D786EEEC4, 6E8A4C6234FD3040BC889E92016A4D5AC7BCAF5059521E50C733966163A546A0 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
12:34:44.0408 0x10f0 NcaSvc - ok
12:34:44.0424 0x10f0 [ C982FE4CC91DECE2259F494FCEB4030F, 4C285407E6F9FBBA92180F4063AEFB736ED142D802F0151002F0CC20AB7BB4E5 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
12:34:44.0439 0x10f0 NcdAutoSetup - ok
12:34:44.0502 0x10f0 [ A10E176F3B2BF83EDE7B5C4658C93B66, 42F2FAEB4A29BBC6727D7E159D3E7E2E66D33785E5C98496EEB44D281601A23E ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
12:34:44.0517 0x10f0 NDIS - ok
12:34:44.0549 0x10f0 [ 39C8A1D9D46F5E83A016BCAB72455284, 80DBED610E0818C2C7122FBC5BC8C15BCE981538AE48DC48F464A86389AF3F68 ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
12:34:44.0549 0x10f0 NdisCap - ok
12:34:44.0564 0x10f0 [ 762941932B7E4C588E48A577BA9D6440, 71FA1870E398CB848D8294FEF6C60E0499CAB9A16EC3F487564C41072590E4F3 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
12:34:44.0580 0x10f0 NdisImPlatform - ok
12:34:44.0596 0x10f0 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7, D902AE15194A9F8A2198914FC76184FE7E2B589747275952A04A52853128FDB8 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:34:44.0596 0x10f0 NdisTapi - ok
12:34:44.0611 0x10f0 [ 79AB68BB3FFF974AD4F41FA559F4EC67, 1745EC6520B48E325C56D98A1F4DB9CE135FE3E097B3D66E6598791132CAD7BD ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:34:44.0611 0x10f0 Ndisuio - ok
12:34:44.0642 0x10f0 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:34:44.0642 0x10f0 NdisWan - ok
12:34:44.0658 0x10f0 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NDISWANLEGACY C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:34:44.0658 0x10f0 NDISWANLEGACY - ok
12:34:44.0689 0x10f0 [ 3730942D7DB2F8BB5F84542B7FF6F650, 89C9D7D7305205BDB304CE6DA7D1A57EDE86A9D77429698802A39D75EB78CAAB ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
12:34:44.0689 0x10f0 NDProxy - ok
12:34:44.0736 0x10f0 [ D3F60A4345FCA9C1BE68AD7D0D6DE770, 214AF09F4B021C2F8655FBC8AC8C801E89CD9115CDE690FAEBDA69D63D660EDD ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
12:34:44.0752 0x10f0 Ndu - ok
12:34:44.0752 0x10f0 [ 7C203A76394F9AE68F69EEE5F9612C4A, 2222654915913BDC9367A2075714906A10CF22C047A7494CD59CB71834ED1B62 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
12:34:44.0767 0x10f0 NetBIOS - ok
12:34:44.0799 0x10f0 [ 7CEC25C682D319D484630B3952C31A11, 025C46B367E0570E9E3F9DF1564C3E47B1524E9E9A180BBDF0E9C684838F5E42 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
12:34:44.0814 0x10f0 NetBT - ok
12:34:44.0830 0x10f0 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] Netlogon C:\WINDOWS\system32\lsass.exe
12:34:44.0830 0x10f0 Netlogon - ok
12:34:44.0877 0x10f0 [ 89519D29CBEC2121CA65CC29C4D345E0, F3BA7BCAFEC8DD8B29837458D1B2B1DEE748AEAAAE0575FD3AAE65CFC72A04CD ] Netman C:\WINDOWS\System32\netman.dll
12:34:44.0892 0x10f0 Netman - ok
12:34:44.0939 0x10f0 [ 79FA9393C67EBBF92A56923592CF7A7C, A8AB8A6346B97B68810CC632F425085BE9E63ACAED0F119A7BFD03F2DA4AA5F6 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
12:34:44.0955 0x10f0 netprofm - ok
12:34:45.0033 0x10f0 [ 5243CFC2E7161C91C2B355240035B9E4, CFD77485A9D7BC47F3A9C53D73B2AE2D5D04B90ED38628F3124EA569F4DE969E ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:34:45.0064 0x10f0 NetTcpPortSharing - ok
12:34:45.0096 0x10f0 [ 12DD2800E4EEA37DC9AE256AD62423B4, 34740469EEA8740CBACD881CB232C9ABB9AB180DE5F45336BC6DBE154259F29B ] nfrd960 C:\WINDOWS\system32\drivers\nfrd960.sys
12:34:45.0096 0x10f0 nfrd960 - ok
12:34:45.0142 0x10f0 [ 80ABCD4C2DE9FD832477303AE0CA3BE5, 98F3958E650CEB1006D92980503E1B176D2CA55D2A6742C1C27CDE829D137DA9 ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
12:34:45.0174 0x10f0 NlaSvc - ok
12:34:45.0189 0x10f0 [ 17E19A742FB30C002F8B43575451DBE1, 59D226A4A5B5281C399BE96C694915E38EEAF335D31F346B0C65D8F469D7C9C3 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
12:34:45.0189 0x10f0 Npfs - ok
12:34:45.0205 0x10f0 [ 8ED299C30792544264E558BEA79F0947, 8A03FDA9AADB79ECBCBCDC988B7D8CF0672689C9DF673A2ECFE0D2D88A9C6A6B ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
12:34:45.0205 0x10f0 npsvctrig - ok
12:34:45.0221 0x10f0 [ 832B5FDF0B5577713FD7F2465FCD0ACE, 4A551CDBACED47DD781EC59F8B59A13D66EFD85DCF636BCFCBACFE5972A78E93 ] nsi C:\WINDOWS\system32\nsisvc.dll
12:34:45.0236 0x10f0 nsi - ok
12:34:45.0267 0x10f0 [ 689B3B1E95C70ABF7AFF29F9406EF1E0, 8B62D8AE53E1B3218158FADC0075682AB06D18998CF5DE82C920A9CD91C0652F ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
12:34:45.0267 0x10f0 nsiproxy - ok
12:34:45.0424 0x10f0 [ 7BE3EDFFA3216F989A6BDCB14795DD08, 19A2D0120C46CA9BCFBC16DC3E65687ACDDCBA33B79128188652BA2AFAA2EE2F ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
12:34:45.0471 0x10f0 Ntfs - ok
12:34:45.0486 0x10f0 [ 4163ADE07DB51843AE31F65B94F5398D, 4349E7EF1EE1E71E1F436BA42F5B58871D82B987D513BA2D6E1CEB8A21BD1B20 ] Null C:\WINDOWS\system32\drivers\Null.sys
12:34:45.0486 0x10f0 Null - ok
12:34:45.0502 0x10f0 [ D6D34118263412D3AAA8348A9572B7F2, 66106A25BC5A4CA7697A23ED67CEDB5C0BF678EA70FD967A405D2DF76F4CA3A4 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
12:34:45.0502 0x10f0 nvraid - ok
12:34:45.0517 0x10f0 [ 27AFC428D1D32ABD04A86763A4EDDEA9, 0920866013A8C8CFEE00E6AECDD41736F5501C49837E2D785998734F087F6B98 ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
12:34:45.0533 0x10f0 nvstor - ok
12:34:45.0533 0x10f0 [ 051CFB5107BAAE510419BDC41F8C4036, 9990906F17A3886EF301D2AA6556263B52A1C0554C6BD18331AF44ECECAEE4B5 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
12:34:45.0549 0x10f0 nv_agp - ok
12:34:45.0580 0x10f0 [ AB76700D764A342D7475FB8F47CAB18C, ECDF705D3E69EF6E7044C98A462A7281D0E7D0D85769C0815555D934B0B69C8D ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
12:34:45.0596 0x10f0 p2pimsvc - ok
12:34:45.0658 0x10f0 [ 4319FD931DCD796435ECB5DB4A04FBA5, 20185B2F359EEC202B37019A4E4F5B914ADCF78B97AF0CBD91EECED2259FC6DE ] p2psvc C:\WINDOWS\system32\p2psvc.dll
12:34:45.0674 0x10f0 p2psvc - ok
12:34:45.0705 0x10f0 [ 4563DAF8C6A740AD7F501E219BD10766, 7A1212DDAE2D66A9C2041262796904E36036CDC4C5B75C2F66B8DF9D89F7C25D ] Parport C:\WINDOWS\System32\drivers\parport.sys
12:34:45.0705 0x10f0 Parport - ok
12:34:45.0752 0x10f0 [ D6ACCF9F2EEEEA711C14EFD976E573F3, 60D2A81832A8D24F91C3EF134440D5026354917F59462BACBCE7A01D84767D91 ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
12:34:45.0752 0x10f0 partmgr - ok
12:34:45.0783 0x10f0 [ 4811D9EC53649105A5A8BEA661B0F936, C77907E03D0561500FCFEAFAC323E9679E66297329901A0CA2BD7E919419A8E8 ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
12:34:45.0799 0x10f0 PcaSvc - ok
12:34:45.0814 0x10f0 [ 4A003E8F718C1E6A2050CA98CD53E3E2, BCC3BE1EC3FA4967353371D85094D096940A7B5944A6FFCA31E8FBE83D92CC6C ] pci C:\WINDOWS\system32\drivers\pci.sys
12:34:45.0830 0x10f0 pci - ok
12:34:45.0830 0x10f0 [ F9908D274D458220F91E89B54D78D837, 1E89ABFA6B375383E0297CEE5AF66E37F90E16DD21ABA5C91777A86CDF013B4D ] pciide C:\WINDOWS\system32\drivers\pciide.sys
12:34:45.0846 0x10f0 pciide - ok
12:34:45.0861 0x10f0 [ 84D19CB6102627932DCB5DFDF89FE269, 2F9C47E076645B35877D9ACA77968EFFCDA8794D76265CD9A4AAA239C4B33C5F ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
12:34:45.0861 0x10f0 pcmcia - ok
12:34:45.0877 0x10f0 [ CEBBAD5391C2644560C55628A40BFD27, 8AAA6EBD8D89FC91AECCCF1452F53C5650A1A17027FF4E64D224371404CE4C8B ] pcw C:\WINDOWS\system32\drivers\pcw.sys
12:34:45.0877 0x10f0 pcw - ok
12:34:45.0908 0x10f0 [ 0698DEDEAD6A00AD0D468C687D830FBF, B9DCA1A61F2EF80DB26380F390F2E9A17114D33129D61CF465B949B6A7916CAA ] pdc C:\WINDOWS\system32\drivers\pdc.sys
12:34:45.0908 0x10f0 pdc - ok
12:34:45.0971 0x10f0 [ 61FE70659CD43E07F94DA4DC31DEC493, 3739B6670B440173FD81DE3D47B0B90FAF296802AD4F57C05BF5CF191BF16022 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
12:34:45.0986 0x10f0 PEAUTH - ok
12:34:46.0002 0x10f0 [ EE926C59CBD4DC4DC9FBB85014A2F1A5, 777459BD30A480E03EA5D0BBA431C2CD573403687FAA0B29F172086A0304E230 ] PEGAGFN C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys
12:34:46.0002 0x10f0 PEGAGFN - ok
12:34:46.0111 0x10f0 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A, 459CF99D5243C4ACAA38C7B426ADC52F1044C759D06A925D475DF6213AEB85CD ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
12:34:46.0111 0x10f0 PerfHost - ok
12:34:46.0205 0x10f0 [ 6E84BFF58F7643499277F29DFA2F8C8D, 401CCF137F35D9690C7B56B2BFEDB2DB72709EBE38626D787904B67640EF6F14 ] pla C:\WINDOWS\system32\pla.dll
12:34:46.0268 0x10f0 pla - ok
12:34:46.0314 0x10f0 [ 799BE46D45D486704CE0F37CA5385262, BB78DEE83B9DB613B1C083D55FAA458BE3E394AED80EB91B599185A7272F33B3 ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
12:34:46.0314 0x10f0 PlugPlay - ok
12:34:46.0346 0x10f0 [ 8E2414E818C26C4A9C70CB2B8567F04F, A16B22AE143BA070C562FBE5DEF32F7E228F50B302B66E46B46C44C0F50A4461 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
12:34:46.0346 0x10f0 PNRPAutoReg - ok
12:34:46.0377 0x10f0 [ AB76700D764A342D7475FB8F47CAB18C, ECDF705D3E69EF6E7044C98A462A7281D0E7D0D85769C0815555D934B0B69C8D ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
12:34:46.0377 0x10f0 PNRPsvc - ok
12:34:46.0439 0x10f0 [ 0108C8E5176D590F242701EF5A62CC26, 3A72F5D4402663B7445F6B3C55F01E83A619B6192F7D3CC2DE3C57F9F50D5A2D ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
12:34:46.0455 0x10f0 PolicyAgent - ok
12:34:46.0455 0x10f0 [ F1E067F56373F11EA4B785CAE823740A, 69BD30E64DA17595FF29C9C9FF9AD4F2F4BE29B688FBAC9DABB2FA9D13A47FF0 ] Power C:\WINDOWS\system32\umpo.dll
12:34:46.0471 0x10f0 Power - ok
12:34:46.0502 0x10f0 [ 362D47E5B4D67270DE4B8606036F4ADD, 716E229C68D91AEA5B5629F60133D5CBDC0C95ABA54D9DC6264E923CAF4DC6C0 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:34:46.0502 0x10f0 PptpMiniport - ok
12:34:46.0689 0x10f0 [ CC0B8655E4B2A5BBB215CDA8FC3BE4DE, 878E46E308BC3AC689CFC401BAA12D217BFB9911C29A10DB5DFFAC250A58CE55 ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
12:34:46.0783 0x10f0 PrintNotify - ok
12:34:46.0814 0x10f0 [ DD979EB6A7212F60E4AFBE96EDC7AE6D, BC681D64C5B8F08FD4613D71111853FCD5B05E4BD127D2C6258BAED7627105BE ] Processor C:\WINDOWS\System32\drivers\processr.sys
12:34:46.0814 0x10f0 Processor - ok
12:34:46.0861 0x10f0 [ 429E8502AD2227CF88F8840FC5BD590D, A186DA46C083580ACEDE9C7E3156865034302CD803140EEEC8E1DE16DA4BC99B ] ProfSvc C:\WINDOWS\system32\profsvc.dll
12:34:46.0877 0x10f0 ProfSvc - ok
12:34:46.0893 0x10f0 [ EB8034147D4820CD31BFCB11A2A652DF, B10B5E16B7A05D2DB2D5D1945B6146DE15EEDE2C778772A59F104706B5145E46 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
12:34:46.0893 0x10f0 Psched - ok
12:34:46.0939 0x10f0 [ 0AFBF333B6F87A2F598EAB379AF100B8, D11F3A4D7E4463B62E2DBDE5FC61425B1FDFB07DD1A19BC001D479CA1F554510 ] QWAVE C:\WINDOWS\system32\qwave.dll
12:34:46.0955 0x10f0 QWAVE - ok
12:34:46.0986 0x10f0 [ 13D47BB0CCA2FC51BD15F8E85C6A078E, EA832A9511007C9E8599C3066E1FA66BE869E8A27886D9A9AC590BD4DFBD1A15 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
12:34:46.0986 0x10f0 QWAVEdrv - ok
12:34:47.0002 0x10f0 [ 873C60F8178100557740A832FCE10B5F, 400EF60CB2C98E2AFE122AF3D01CCE56A1548AF865345EE2194AB74DBCBF4C48 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:34:47.0002 0x10f0 RasAcd - ok
12:34:47.0033 0x10f0 [ 69B93F623B130976243ECA3D84CC99CA, F27617E651EADFAEE479619AAB01CDAA98111BA63E204D5C44A1256732CB0100 ] RasAgileVpn C:\WINDOWS\system32\DRIVERS\AgileVpn.sys
12:34:47.0033 0x10f0 RasAgileVpn - ok
12:34:47.0049 0x10f0 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0, 2F3C90A04964D4D906238BD557D90F7AC05DF86FE9729C4378B39431F54DDAE3 ] RasAuto C:\WINDOWS\System32\rasauto.dll
12:34:47.0049 0x10f0 RasAuto - ok
12:34:47.0064 0x10f0 [ A14D625C5AEE5FFE0F47D1A1D419FAAE, 1229B81C23340AD5B436B1FD227876EB41715CE6BD270BA367F18879D26B8F04 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:34:47.0064 0x10f0 Rasl2tp - ok
12:34:47.0096 0x10f0 [ C923C785A2DE0B396AD6D13ACAFF2DE9, 4F950DA776FBABEC7D546983D6F3018733F61268A4BF95C01D4836AD000BD073 ] RasMan C:\WINDOWS\System32\rasmans.dll
12:34:47.0111 0x10f0 RasMan - ok
12:34:47.0111 0x10f0 [ 00695B9C2DB6111064499C529E90C042, 3CD4DF4D8001C2BBF52EEEB1F0D587209878BEAC339D268892477AD840D490F1 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:34:47.0111 0x10f0 RasPppoe - ok
12:34:47.0143 0x10f0 [ A7F24D8CD1956B0A1FDCB86CC5114DE4, 30489D235362DF62B105378597168B13F4BAC74A8EDDBDA25237E3C017B69FEE ] RasSstp C:\WINDOWS\system32\DRIVERS\rassstp.sys
12:34:47.0143 0x10f0 RasSstp - ok
12:34:47.0205 0x10f0 [ CA03D642ACE58E1BA54E4B383F91CD69, 39BB942603801CF11FBEA28E24F8C8D1EF2AF615D1FABF951683A015D6A6EF37 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:34:47.0221 0x10f0 rdbss - ok
12:34:47.0236 0x10f0 [ CA7DF5EC95D8DE0DD24BE7FF97369F68, 153E6F716CA935DBCACB8FF1BB8DE5F5551CE3D18878225470E45893CA69BDB8 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
12:34:47.0236 0x10f0 rdpbus - ok
12:34:47.0268 0x10f0 [ B2A3AD74FF2E2FFA73AF2567108231B3, DF8CEA6215F75C634D56F6B8AE11ECCEEB5F8CBC091AC3D6D9F7DE214B00A439 ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
12:34:47.0268 0x10f0 RDPDR - ok
12:34:47.0299 0x10f0 [ 57F4787E4602A3FCA719C0A33137C6DA, D03AE59A184EB5D126F8EAB9D36EE406ABB8B9ED834F2D2496DDB1349FF56F89 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
12:34:47.0299 0x10f0 RdpVideoMiniport - ok
12:34:47.0330 0x10f0 [ B3CB0721E81E30419CE7D837EF4EA151, EC9410818661BF77E4A19694E3A3030E1D983B36F49C72E27F92A1424E0729C2 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
12:34:47.0330 0x10f0 RDPWD - ok
12:34:47.0361 0x10f0 [ 62C1F8A0685FE07E998AA296C4F697C4, C636AB2D0F139003A6AD7A12E9DC13EE4485A62F30DA59AF842FF02FE07442EE ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
12:34:47.0377 0x10f0 rdyboost - ok
12:34:47.0424 0x10f0 [ 3663CCF243EE0C04E9F6F91ED1737273, 31D06445996F99A7F6B32004D1BA63A21C61DE125373F860BA9A9DE5278E8293 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
12:34:47.0424 0x10f0 RemoteAccess - ok
12:34:47.0455 0x10f0 [ E80DD61E52EDFFF9DA1ED7260A68855B, 97909F42AE35E28B8F98C01A1D8BAD80A949CDCA0C88FB4ACF0A655DC7C10E45 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
12:34:47.0455 0x10f0 RemoteRegistry - ok
12:34:47.0486 0x10f0 [ CCBFCABDFE2BC22F0645CEAADDB36004, 279EA9075079F91165027CEFD4FBC61A213CA602EE7DE106F7D2D243468706AA ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys
12:34:47.0486 0x10f0 RFCOMM - ok
12:34:47.0502 0x10f0 [ 73F2E030B5C24E4E41401B5F0D59E6FD, FAA8B5E3159684E0836900C6EAF63857B445F7F180169B56D5790F097EDAA38B ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
12:34:47.0518 0x10f0 RpcEptMapper - ok
12:34:47.0549 0x10f0 [ 10B21284B3D964AB3DC45490E57D422E, 12D5E3A7785F21C99C5EAD14A88EB7A86A058E26C091991339356D99D196CC13 ] RpcLocator C:\WINDOWS\system32\locator.exe
12:34:47.0549 0x10f0 RpcLocator - ok
12:34:47.0596 0x10f0 [ 1EC6E533C954BDDF2A37E7851A7E58FD, C25936A7465B6A2B3D05D2FCB09D91ACC07CFE038A5E968C99CFA9D9F2967DD4 ] RpcSs C:\WINDOWS\system32\rpcss.dll
12:34:47.0611 0x10f0 RpcSs - ok
12:34:47.0658 0x10f0 [ E04E770DD198B9399640717145E79EBF, 2F9BECB7E4B0A522C6370FD39CFD7DFD3FB5D0A779AECCED2EE855629FA3C952 ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
12:34:47.0658 0x10f0 rspndr - ok
12:34:47.0721 0x10f0 [ 0E32A8922DCFD28EA00AAEC07CB3F331, 27F329C6A66DB01C291E1EDCEB7781A05658520B12FF8ECD1FBD3B86EF78DF30 ] RSUSBSTOR C:\WINDOWS\System32\Drivers\RtsUStor.sys
12:34:47.0736 0x10f0 RSUSBSTOR - ok
12:34:47.0814 0x10f0 [ 3BDBB0CBFB27FEF51B7574676D1C9F6A, 80C1F54A01C4567EF0B8452C0394D82B7F141E60E5BE19778992286B3FD5D466 ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
12:34:47.0814 0x10f0 RtkAudioService - ok
12:34:47.0830 0x10f0 [ 8A78690AC84AE5150A34C7525B450395, ED23E961231673ACA3A842A44CA1B150CD1FAAB8D4568EEE245FEBB3A60F9786 ] RtkBtFilter C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys
12:34:47.0830 0x10f0 RtkBtFilter - ok
12:34:47.0877 0x10f0 [ 34DA0D14F5C3F1883A331AFB975AB434, BB5D580C1DCAE59CC1DB75C411A5A4DDF435931469E7EBFF5DFDADBFE07ADEBF ] RTL8168 C:\WINDOWS\system32\DRIVERS\Rt630x64.sys
12:34:47.0893 0x10f0 RTL8168 - ok
12:34:47.0971 0x10f0 [ 097AA0B75675862070248796E1CC04D1, F625051937CF888721672872801B905C31924327F178B54D04BCD17AB6D391B8 ] RTL8192Ce C:\WINDOWS\system32\DRIVERS\rtwlane.sys
12:34:48.0002 0x10f0 RTL8192Ce - ok
12:34:48.0049 0x10f0 [ 097AA0B75675862070248796E1CC04D1, F625051937CF888721672872801B905C31924327F178B54D04BCD17AB6D391B8 ] RTWlanE C:\WINDOWS\system32\DRIVERS\rtwlane.sys
12:34:48.0096 0x10f0 RTWlanE - ok
12:34:48.0127 0x10f0 [ 752EC7DCD2F96871A3857EEE6AFE965A, 1D0640966B9147A06ED0E733711773E6B4AB8AC6D962D5B369ECB04170D18AD8 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
12:34:48.0127 0x10f0 s3cap - ok
12:34:48.0158 0x10f0 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] SamSs C:\WINDOWS\system32\lsass.exe
12:34:48.0158 0x10f0 SamSs - ok
12:34:48.0190 0x10f0 [ 9C7B28CE0D136DB226E24DB3BC817F92, E9DE55D6432ADD08EC75F99F2B5D2BD1F553F4EE55991B1767B1578351EE0BF2 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
12:34:48.0190 0x10f0 sbp2port - ok
12:34:48.0252 0x10f0 [ 14316954FCE79C9DE5A0AFF9D42C83AA, B60FB1FAC0299F9560761411711E86EDFA2F8D27B58230E2E4BB37736FAB2287 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
12:34:48.0268 0x10f0 SCardSvr - ok
12:34:48.0283 0x10f0 [ 5D7733A12756B267FCA021672B26BC9E, 01CE5B5F49914B9E099BD909A66296F3A40644AE47BA1D5EBFFB30CD33C70A4A ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
12:34:48.0283 0x10f0 scfilter - ok
12:34:48.0361 0x10f0 [ 03F58B3FA4B5329F21F770B1EF8D984A, 32976E64E4960E5996E3CA2F8BA9374E01201C461DE52AF0FA14BA75C784AC25 ] Schedule C:\WINDOWS\system32\schedsvc.dll
12:34:48.0408 0x10f0 Schedule - ok
12:34:48.0440 0x10f0 [ BAF8F0F55BC300E5F882E521F054E345, FB228DB18F2FA55D8BA35A7E6778EE5D2EB0C29D384F1A0A868F90AE706188D7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
12:34:48.0455 0x10f0 SCPolicySvc - ok
12:34:48.0518 0x10f0 [ F58B030A0664385C707B8C1C63682041, E46AADAA2CD687B9A4B564DC5B002493C8480542588E660BC3DF89EAF9DB0427 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
12:34:48.0533 0x10f0 sdbus - ok
12:34:48.0565 0x10f0 [ 92968277ED491E4B3DDA361E3952361E, 71C50853BB2126A34C7CD014EE44D4B8B39F589E2E8E8E8F4C982E07498E3899 ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll
12:34:48.0565 0x10f0 SDRSVC - ok
12:34:48.0611 0x10f0 [ BB107AA9980B0DA4E19A3A90C3BD4460, BCB4CF0FFF1FD57302557B68044A88C8EEAAE57C2FEAE8EAD1F410F960298B6D ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
12:34:48.0611 0x10f0 sdstor - ok
12:34:48.0643 0x10f0 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
12:34:48.0643 0x10f0 secdrv - ok
12:34:48.0658 0x10f0 [ CD282626738B6BC92B6E7CD0AAE95B63, 1A56567C781786C85C63E24E79186EE5C82D3EB2679061B21BA0571A3A6CB7F5 ] seclogon C:\WINDOWS\system32\seclogon.dll
12:34:48.0658 0x10f0 seclogon - ok
12:34:48.0690 0x10f0 [ 9C51620998F0763039DFA6BF68E475ED, 9E496ADE7CE9A446BE8A2C2FC61B462D966778A94A4C147AABBD25C4821C2BCE ] SENS C:\WINDOWS\System32\sens.dll
12:34:48.0690 0x10f0 SENS - ok
12:34:48.0721 0x10f0 [ 0D50B4B860DAB65241628D04CD33ACAE, 2AA897C3F9ED076AB9244A32745D18489B076F3ED28A35B868C472131C5B5B46 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
12:34:48.0721 0x10f0 SensrSvc - ok
12:34:48.0736 0x10f0 [ 87C46B239A7EEF30FDFDD5E9BD46130C, F36FB5B20AC58FBD31F7E636059D2D865B751E178E51A03B94ABE0BBD1AB1EC9 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
12:34:48.0736 0x10f0 SerCx - ok
12:34:48.0752 0x10f0 [ 7A1F9347C85FD55E39B8A76B3A25C5AD, 03AF3B23285278A38F4CBEAB7FD326A48FA1EC7F8D044C059CE5403C6D225639 ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
12:34:48.0752 0x10f0 Serenum - ok
12:34:48.0768 0x10f0 [ F640A0A218BBF857F1D04A15D7D939F6, 948C13886281FE7947E10FB7B34D5CCFE512FB632F1132B6062AC85149F79950 ] Serial C:\WINDOWS\System32\drivers\serial.sys
12:34:48.0768 0x10f0 Serial - ok
12:34:48.0783 0x10f0 [ F1A5F56B2620B862CC28FF96A0A6DAAB, E5367212B2CADF3820D657CFC27CD961547E28DAB950C68E1380CF97FB68F3F4 ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
12:34:48.0783 0x10f0 sermouse - ok
12:34:48.0861 0x10f0 [ CB60A60340788C8D6DE2A269D28086AB, 2D8948E59BB9B00E16D20E425F80E7B862957DBAC9A4D1484E5191FAF333B60D ] SessionEnv C:\WINDOWS\system32\sessenv.dll
12:34:48.0877 0x10f0 SessionEnv - ok
12:34:48.0893 0x10f0 [ 7EE65419B29302C795714FF8073969A1, E28D89A5423E3A5062030EB2418E9435DD5D8B9D16570046E782D3FCFDA2E79A ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
12:34:48.0908 0x10f0 sfloppy - ok
12:34:48.0971 0x10f0 [ 090AE16F79C8EAD04E6031F863DA85F3, 3F27BE46DF602B53940414A6E9FEB23B36CFFB8E9A7F41440C3315B8E27D0029 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
12:34:49.0002 0x10f0 SharedAccess - ok
12:34:49.0033 0x10f0 [ A77F3ABE13FCC698511E5DEC7ACEBD5F, 78A43FDA9F770FD8BA107605DB44BC71D8B89D7E75560DA783AA6356C1873C15 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
12:34:49.0096 0x10f0 ShellHWDetection - ok
12:34:49.0143 0x10f0 [ 2560721D6F16D5B611C36A3A9D28C1B2, 15C30404902654ABA5DB5367FC5BD31343B12A3FC22B4BC5A26B09016447B5ED ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
12:34:49.0143 0x10f0 SiSRaid2 - ok
12:34:49.0158 0x10f0 [ 3AA8FDE1DBF65BB8B88B053529554A0D, 8060D946344D043D336F4735363C23C37C91A6DB3F81E575C267B2EC2BECB0EC ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
12:34:49.0158 0x10f0 SiSRaid4 - ok
12:34:49.0174 0x10f0 [ 4A2972573225A2DE4DEC0AD68529DF0F, CA0F7AF29019B18C37AE2C31361C765AB4156F9E7C3E65237C7D68345D22C634 ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
12:34:49.0174 0x10f0 SmbDrvI - ok
12:34:49.0221 0x10f0 [ E660156A4588A84305CB772FD2C0DB21, 9492EB6578D4A689945E1FC2440EFA77D461049CDB2D00A645969A71B7DA68E1 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
12:34:49.0221 0x10f0 SNMPTRAP - ok
12:34:49.0283 0x10f0 [ 9110193D93960E38B8692E4519C75D72, 789381B4CCC056EE431E78E2339AC9802264A1CE4B378DDA9769649664C9A7A0 ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
12:34:49.0299 0x10f0 spaceport - ok
12:34:49.0315 0x10f0 [ 3D8679C8DF52EB26EB7583A4E0A29202, DCD9B69299275857712AB200C014AE820C8A9F7E53C4A335A84518FBE4BB56BB ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
12:34:49.0330 0x10f0 SpbCx - ok
12:34:49.0393 0x10f0 [ 3F215BF2D4D8D6756298B25B579772C2, 744192D1635E5D296BFD399E870B70592202CEAF95C31C2D2B226A868D33A3FD ] Spooler C:\WINDOWS\System32\spoolsv.exe
12:34:49.0440 0x10f0 Spooler - ok
12:34:49.0658 0x10f0 [ 061A977C920FBE4BF71FF47C966DDDCA, 746516396B72E4ADB05D978C819CD45FE44EE194756F6DA50121D755439CA590 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
12:34:49.0861 0x10f0 sppsvc - ok
12:34:49.0893 0x10f0 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6, 61EEB1349489CB85204F1B4E398BE24EDC01FB914120C9DD0487F8EE1EDA055E ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
12:34:49.0908 0x10f0 srv - ok
12:34:49.0971 0x10f0 [ 8504ADDE9C146C6295B16D13A0007560, 715E3752AE4A276FA8DAFA3B52B699C45D97E747CB25FE4AE307241D206319B7 ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
12:34:49.0986 0x10f0 srv2 - ok
12:34:50.0018 0x10f0 [ BB0F9E19C5CE4DC765B263E2A5561DE1, F7DBC96E049625E4312D8F588FCF2B4AC6318C04D04758982FE9B51DABEC2DAE ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
12:34:50.0033 0x10f0 srvnet - ok
12:34:50.0065 0x10f0 [ 7A20882D76D4A78240A5AC9F2C2EBA21, ACA05211EE542999A118BBD2CD051038A7DC8C40C4B8971DC6514BA90E90EC61 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
12:34:50.0080 0x10f0 SSDPSRV - ok
12:34:50.0111 0x10f0 [ D233B16999A8E626F6004BD7814C57EC, 5BBFE5DDF1269617ABD1BDBED85A79D99BB52EA29C2BB3A8F4A1827BFAA1A747 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
12:34:50.0127 0x10f0 SstpSvc - ok
12:34:50.0143 0x10f0 [ 4E85355B94CFCB67C135F6521A4895A7, AC4FC65C1E62A54B3834E7FE0A2B1ECC48A2AA563AE5BD508326EE68FFFBBEEE ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
12:34:50.0158 0x10f0 stexstor - ok
12:34:50.0221 0x10f0 [ BAC8A721736AECC55A4F71523AEAB65F, B52E1303B13A961A5FC190829E55B6F28ACA409A6EEF44B358D1D210558FE1D8 ] stisvc C:\WINDOWS\System32\wiaservc.dll
12:34:50.0252 0x10f0 stisvc - ok
12:34:50.0283 0x10f0 [ B240874B2CA0CD02E8CD11E140B14C57, 0FDBEE3DB644175A30065CAF020F375703ADC45A33221788C010F3111707FC25 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
12:34:50.0283 0x10f0 storahci - ok
12:34:50.0315 0x10f0 [ F74DBC95A57B1EE866D3732EB5F79BE2, E4FE9D5CD0A385ACB60D5D5E8D969F26C3A6BC0C08FF0838DBE9CA106229C8DE ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
12:34:50.0315 0x10f0 storflt - ok
12:34:50.0362 0x10f0 [ 5337E138B49ED1F44CCBA4073BC35C20, 2B296973215E3865A56C46DC3D27F1460D96BC321558CE7A911B05B0E7BF397F ] StorSvc C:\WINDOWS\system32\storsvc.dll
12:34:50.0362 0x10f0 StorSvc - ok
12:34:50.0408 0x10f0 [ 543CD3CC0E05B8D8815E0D4F040B6F59, 4B57C9534E94A0A67FC82DBD4FAECACA180BEC281FB477550A37C0A04777E09E ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
12:34:50.0408 0x10f0 storvsc - ok
12:34:50.0440 0x10f0 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A, 82CC77030D23013572B4A64A64B6156789F253BF56268B790093CE3D345410A0 ] svsvc C:\WINDOWS\system32\svsvc.dll
12:34:50.0455 0x10f0 svsvc - ok
12:34:50.0455 0x10f0 [ 4AFD66AAE74FFB5986BC240744DC5FC9, 0C9347614E3FD3B4D3B29FA4A5DA23FF6EE4CD9A1FFC378B855B8DE61B2876CF ] swenum C:\WINDOWS\System32\drivers\swenum.sys
12:34:50.0455 0x10f0 swenum - ok
12:34:50.0502 0x10f0 [ 502F9488540051F3E6C39889ECFA76BB, 22ABD681BE4CF8A1F484C6363C1334B1EF7A6C074D837B0121DE1896887B84C6 ] swprv C:\WINDOWS\System32\swprv.dll
12:34:50.0533 0x10f0 swprv - ok
12:34:50.0565 0x10f0 [ 157DFCD1E83E964A5074742AE2DFA0C1, D6F4567F42402938F54A1E482BAE3B02E1BD5AF3788835A63829A3652E5DDA67 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys
12:34:50.0565 0x10f0 SynTP - ok
12:34:50.0658 0x10f0 [ A06CB9269D29EE3D0F3F5630ABB660B8, 519A01FC7D9414B26CCBC23E7FB1CEAF1C91CD173B4F4A4025F8316B7460C584 ] SysMain C:\WINDOWS\system32\sysmain.dll
12:34:50.0705 0x10f0 SysMain - ok
12:34:50.0737 0x10f0 [ 6FB88606C4A71E1BFAF97D63A676C673, D72F93A482E989ACA50F9647B7AD699A4656AEAACF377BB2B8CEBB094B748852 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
12:34:50.0752 0x10f0 SystemEventsBroker - ok
12:34:50.0783 0x10f0 [ A6C06C45C44AD06C70AF8899AEC15BDC, AC2CCCDBA6B94BA85A6D41B47343193D175786D4ECF71AE9C7766ADD63A1273F ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
12:34:50.0799 0x10f0 TabletInputService - ok
12:34:50.0830 0x10f0 [ 88B7721AB551C4325036B25A34A2BF7B, 2817CC6294542524EC373A674535F913440736BEBE81233CA91D5ECD93620B02 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
12:34:50.0846 0x10f0 TapiSrv - ok
12:34:50.0955 0x10f0 [ 0E0C16EE82E2F4EBC2FBCA24C8F00D9E, F8B2A0257442E00C5D7C5A15BBD84194D0F0C071424656CA4B8EC850B6898D10 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
12:34:51.0002 0x10f0 Tcpip - ok
12:34:51.0096 0x10f0 [ 0E0C16EE82E2F4EBC2FBCA24C8F00D9E, F8B2A0257442E00C5D7C5A15BBD84194D0F0C071424656CA4B8EC850B6898D10 ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:34:51.0143 0x10f0 TCPIP6 - ok
12:34:51.0174 0x10f0 [ 8F2A13A5DF99D72FDDE87F502A66F989, 2228C62ACDB4CBBFDD2BE705E604E0B9A8AEA7146F65F2D8B9B2A2FB49ACFAE1 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
12:34:51.0174 0x10f0 tcpipreg - ok
12:34:51.0205 0x10f0 [ 58480A57ACF2671C343FD1D4BA990E34, 24AD9C808D06FABFE8E81242CAC8B5A91829F7D951B245865EF77B79BB795E3D ] tdcmdpst C:\WINDOWS\system32\DRIVERS\tdcmdpst.sys
12:34:51.0205 0x10f0 tdcmdpst - ok
12:34:51.0237 0x10f0 [ 73DC722CE5DF26D7638CE2446F2655C7, 9B8E6F6DEA5E0C2AEAC24A31897D2E73F86EF44F1C25FEF82D2C860353793817 ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
12:34:51.0237 0x10f0 tdx - ok
12:34:51.0315 0x10f0 [ E53A8CFB52B68AB8981B915CCDF4D5CE, D98143AFB36F430330FBF2C4F8581FBDD1D31F50C9ACCBDE9FF62EEFAF19CE37 ] TemproMonitoringService C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
12:34:51.0330 0x10f0 TemproMonitoringService - ok
12:34:51.0362 0x10f0 [ F7C8AB5D8AFFAA318D6A21093D139BF4, 0A35052EF7DC8615783A23897358D8C579BE694363615C9563FF629E7B719991 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
12:34:51.0362 0x10f0 terminpt - ok
12:34:51.0424 0x10f0 [ 541EE228D0DEF392F7B2DFD885DD021B, 594D6538FA4DB5EF4D130007D7C29051EC2EDCA39EBB119695B58E9CBB0EB728 ] TermService C:\WINDOWS\System32\termsrv.dll
12:34:51.0455 0x10f0 TermService - ok
12:34:51.0471 0x10f0 [ 519A6F672FFF56B7D8EE8C730CEC8ECD, 2B36F10C0AE16A261DC0887B1050808BA1F0568F3879E4ABC3D370F08C3FADB7 ] Themes C:\WINDOWS\system32\themeservice.dll
12:34:51.0471 0x10f0 Themes - ok
12:34:51.0502 0x10f0 [ 16E745743BABAF480B7718442F38B076, 4FF6C7CFB976BF24F2215DCAE4DCCA546A6758B1DE1F36C78251AFFE4D9CE249 ] Thotkey C:\WINDOWS\System32\drivers\Thotkey.sys
12:34:51.0502 0x10f0 Thotkey - ok
12:34:51.0533 0x10f0 [ EEE908BE7143FCA48CF0CB87214E2AB8, 4F9BD299F559DD36DBD93489CFAA753F236FBB70946E034D2E2260059AE20962 ] THREADORDER C:\WINDOWS\system32\mmcss.dll
12:34:51.0549 0x10f0 THREADORDER - ok
12:34:51.0580 0x10f0 [ 4515B9E4140F04FB3907692DF89FCA87, F68EC56524BDA877646E987BE7414C1D622BD9FF05A5AEADCA39030FDC2B0115 ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
12:34:51.0580 0x10f0 TimeBroker - ok
12:34:51.0674 0x10f0 [ 5201342394DD42848027CE96A37043DB, 7D230994799CC608AA7C116A34508ED6321AEB5DF848EBFE022C38EA33F4166B ] TMachInfo C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
12:34:51.0674 0x10f0 TMachInfo - ok
12:34:51.0737 0x10f0 [ ED32035BDFECED1AD66D459FD9CC1140, B82A15FAB4CBB5A633B9BF722441D5B20D946B63DD10BBE2A89D3A8BA3BE3339 ] TODDSrv C:\Windows\system32\TODDSrv.exe
12:34:51.0752 0x10f0 TODDSrv - ok
12:34:51.0815 0x10f0 [ 4D7977197C3EC8C65F533E8A84DE229C, 2B91272E015EDB4E489179F791B9B67C9A89CAB2F45030C89FC7F6513F24200F ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\Teco\TecoService.exe
12:34:51.0830 0x10f0 TOSHIBA eco Utility Service - ok
12:34:51.0846 0x10f0 [ A884A627C0B6E8B238759FC73C1AAAAF, 5D6E38664B6175F5F541D838675429CEE9FA1492A7E25B48E98794B5EB8B6973 ] tosrfec C:\WINDOWS\System32\drivers\tosrfec.sys
12:34:51.0862 0x10f0 tosrfec - ok
12:34:51.0908 0x10f0 [ 36391C3953D191A2AF4556D5D706C641, 5191A35C86B6C98F2CBDDC23B5311ED62310345CEDE084A54BBF70CCF0F84C50 ] tos_sps64 C:\WINDOWS\system32\drivers\tos_sps64.sys
12:34:51.0924 0x10f0 tos_sps64 - ok
12:34:52.0018 0x10f0 [ 8608681DC6E2975815A593209A6432CD, 10DF382AABB97DD70900DD4D6D388A34614A67E762D956861C8D4D036947BFDA ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
12:34:52.0033 0x10f0 TPCHSrv - ok
12:34:52.0049 0x10f0 [ E94F7A7B48C7638D1F3F8089344C97B7, 276CDE59614D563A52529BCC4BFC726E5F5BE131C9C4142558A644D79328C810 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
12:34:52.0049 0x10f0 TPM - ok
12:34:52.0096 0x10f0 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA, A6846478B9E7B0A509E5A28C6C7B66ED39F0247F9AFF01E3C3CADC0DBEF3CA00 ] TrkWks C:\WINDOWS\System32\trkwks.dll
12:34:52.0112 0x10f0 TrkWks - ok
12:34:52.0127 0x10f0 TrueSight - ok
12:34:52.0158 0x10f0 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C, 4C78FE2A4A25A758D5191C4EDB2A6FE691FF82E7C16C0F146DC96DAD87D4F64E ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
12:34:52.0174 0x10f0 TrustedInstaller - ok
12:34:52.0190 0x10f0 [ 4E7C5FB10A50435523DE0CAA37DE2BD3, D6206DF61950F2541FB754E57C4D9EF9FA0CC1EDD6F6FA4E45F02B47958493F7 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
12:34:52.0190 0x10f0 TsUsbFlt - ok
12:34:52.0237 0x10f0 [ 16D684A820872EE54F6370703AC0B513, 795E20484358424CE9FA766937DD99413025A8AF967D03490392E8E02A382D0B ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
12:34:52.0237 0x10f0 TsUsbGD - ok
12:34:52.0252 0x10f0 [ 78C9EE193AC2B4CBDBC48B620314D740, 41523E47D321BFF5778F5E453545B928C0A469C3BBA51578E74D6721D7DF9273 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
12:34:52.0252 0x10f0 tunnel - ok
12:34:52.0299 0x10f0 [ 54BDBF3D4DED58DA78B702471C68D4CA, D12F9F09FFE7D38A5EE6BF79DB74D775A9861C3C87E06D7C23259E47247B1782 ] TVALZ C:\WINDOWS\system32\drivers\TVALZ_O.SYS
12:34:52.0299 0x10f0 TVALZ - ok
12:34:52.0315 0x10f0 [ 55A9A23DD64EB7781FCAB565B028CD0E, 44CE0C8244F9AE6CCCDB49C29F6D35FE4CE8C92DE5B5D44D22DBD088DE83AA10 ] TVALZFL C:\WINDOWS\system32\DRIVERS\TVALZFL.sys
12:34:52.0315 0x10f0 TVALZFL - ok
12:34:52.0330 0x10f0 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A, AA7DA2207C0236F47859A4791F9D7301E7ADB50A59D831DC859ECC7CA70D3E1D ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
12:34:52.0330 0x10f0 uagp35 - ok
12:34:52.0346 0x10f0 [ 6FD6D03B7752C78712E5CFF29A305026, F09C5188AAFCF4C77B05BA1E604F9912782A9F1371F72F959288EBC2725407ED ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
12:34:52.0346 0x10f0 UASPStor - ok
12:34:52.0393 0x10f0 [ 061BA3EE0D2BE17944990544008CF190, C9236D368EC2281B545E8C008BC2801F21A9716ED3D4DAEDB0751A5008346E81 ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
12:34:52.0393 0x10f0 UCX01000 - ok
12:34:52.0455 0x10f0 [ 25C50F4EDF70D0A831E0566BD181CCF2, F2F9E86FB5617C16077D2073EC0AA747F76F1EB5148BA110347A84F3C3569F83 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
12:34:52.0455 0x10f0 udfs - ok
12:34:52.0487 0x10f0 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D, 16DE6E0894C356A58AF12BEC2FE9B188F147DD4B16CB2414DE600CE4127F929D ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
12:34:52.0487 0x10f0 UI0Detect - ok
12:34:52.0549 0x10f0 [ 07FEBCDF24FABA0D47B635D85A0FFB7A, 452C04B14681EBCE8B1B25B75A1B7CC978722B7DDE54D624E17841B14ACCF65D ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
12:34:52.0549 0x10f0 uliagpkx - ok
12:34:52.0565 0x10f0 [ 02CEB3FE6152668A7BA420B93B664860, 613F27540FD1EFE2442E326F507DACD5A25691C8481937022B7E1104F3E6E9E2 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
12:34:52.0565 0x10f0 umbus - ok
12:34:52.0596 0x10f0 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09, 30AAD7D18FF5962CEC7180359D148EED5A1BF193DDB2B34508897FC3EBA692C3 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
12:34:52.0596 0x10f0 UmPass - ok
12:34:52.0643 0x10f0 [ 43FEFB040A0CC30F795FBF544169594D, F2A730C0F7C883321C378D4564120A40428D7F8E393F02C8D6A08934795A35C7 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
12:34:52.0659 0x10f0 UmRdpService - ok
12:34:52.0768 0x10f0 [ E1A119AD21F5AFE22EB516C549306D3D, 48769D5E7A78B7A2C00F1F6798AC133CF3E0B2C76F71D3719BD741DDD8F2D229 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
12:34:52.0768 0x10f0 UNS - ok
12:34:52.0799 0x10f0 [ 14D22C411854AA2560AFC94CD2D5E61F, BB376734733671C02319E6DB1800D41212694446FD65465498C92D4ECBFE7458 ] upnphost C:\WINDOWS\System32\upnphost.dll
12:34:52.0815 0x10f0 upnphost - ok
12:34:52.0846 0x10f0 [ C976C4306F9AE133D6BBD47FDFC3BF92, 820413D92D6A89055A7F26523BF5CC4B668610C4A06E8B0D163FBF929B1DFA9A ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
12:34:52.0862 0x10f0 usbccgp - ok
12:34:52.0877 0x10f0 [ 427B6DB8C05A5A977E8C3525370A2595, C67222CA9123AE12D953995326B3B582C146CEA89594B7209DB0B1F628A0118D ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
12:34:52.0893 0x10f0 usbcir - ok
12:34:52.0909 0x10f0 [ B24FDEB1B18496F1B463782235AA3AF1, 3F5036F36987C8007D03DAFC3EC30615515BE96D9A1DF879BCD4EB0E66CD50B1 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
12:34:52.0909 0x10f0 usbehci - ok
12:34:52.0940 0x10f0 [ F8C2A832DF9403F5EA8080CBDBDA95FB, 50E9455465672BC13EB945BEC132D2F30BA2EB25C68928D2B4C256F2DB292A83 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
12:34:52.0955 0x10f0 usbhub - ok
12:34:52.0987 0x10f0 [ E5F7328B1D29BCE791862CD3C0DD382A, E520D75CA6E4EDB06F576D97FB6B7CFD46A3EF3A3AC881537DE3BB8C862FE8C3 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
12:34:53.0002 0x10f0 USBHUB3 - ok
12:34:53.0065 0x10f0 [ 325F6179009B5A7F6118951A5BA422AB, 756CB2893530485E8C3ACFF5A40F4C6EB446E72B2296E8772058E407A5E066DE ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
12:34:53.0065 0x10f0 usbohci - ok
12:34:53.0080 0x10f0 [ 9FDBA6982582A6F2354144980F641E7B, 054A65412CB22C5BE970FD3A266E140110D869B614B9F9894628D553CE82C991 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
12:34:53.0096 0x10f0 usbprint - ok
12:34:53.0112 0x10f0 [ BFC7FE4AAEB61317A921871B4085EF4B, CBC3FBAEAD6C82A437CC87A97007EF807C64053AB8FA5C3233C2A0CF6FC8D019 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
12:34:53.0112 0x10f0 USBSTOR - ok
12:34:53.0127 0x10f0 [ 1ABF657259DB57F7E5558E4DF1357C0C, 34EAF5DEA3293CFA96BA81B036305FD90ABAE05B9CB73D4F54FB236448C1978C ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
12:34:53.0127 0x10f0 usbuhci - ok
12:34:53.0143 0x10f0 [ 9EF7C01D3ACCBC243B5CB1A95865B2FF, 367A7640B4992E68EB3E1BBD78D3014742F4CC4056750E389048C653251DAD33 ] usbvideo C:\WINDOWS\System32\Drivers\usbvideo.sys
12:34:53.0159 0x10f0 usbvideo - ok
12:34:53.0174 0x10f0 [ 8DC398D7B8E02C929A2096E74A170970, 87B3CE84D05F50C33935B28F0AFF1CB15DAA4530768BA1FB25C311609CD4B0A5 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
12:34:53.0190 0x10f0 USBXHCI - ok
12:34:53.0221 0x10f0 [ F1DA34D64F2BA200D28A7451804E2FEE, 8BDF328F18F1EB58AC0E383ABA7985BA69EA9622B262CD524E3390FDE824DEEB ] VaultSvc C:\WINDOWS\system32\lsass.exe
12:34:53.0221 0x10f0 VaultSvc - ok
12:34:53.0252 0x10f0 [ BACECBFF9C97F7627A60B0E0F1FE7EE8, DC82F767D066B93A48A090DC7146EBCCDC54B43C6CD9DF29A160E09E3A531DC8 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
12:34:53.0252 0x10f0 vdrvroot - ok
12:34:53.0299 0x10f0 [ 1B4488988E5E7512E6C5CD1255E9E973, B82C26E767A8895CFFD76C11D07D5C945C38E1BD32CC27D20A6C0FA7F6064FC5 ] vds C:\WINDOWS\System32\vds.exe
12:34:53.0330 0x10f0 vds - ok
12:34:53.0377 0x10f0 [ 74FA2D4368DE6F6CE14393EDF1F342BE, C5CE4164B2C3D583A7FB8687ADEADCDB08D36A5AB1965E5FC6949AEED15881C8 ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
12:34:53.0377 0x10f0 VerifierExt - ok
12:34:53.0409 0x10f0 [ 500BE6B2E49883720D0AE8BB859ED7A3, 4606B02A3E8123510676E554635EB5ECF9DC5F2B83928710C8563787C52CC102 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
12:34:53.0424 0x10f0 vhdmp - ok
12:34:53.0455 0x10f0 [ F5B4A14B00E89250C50982AC762DDD1D, 581CD97DD42E74A82F06BFB827DFC82618B4A8667ACA7E93C628BB0D056CE8F0 ] viaide C:\WINDOWS\system32\drivers\viaide.sys
12:34:53.0455 0x10f0 viaide - ok
12:34:53.0471 0x10f0 [ 78DB50F7329F6D1311658DABFFFC8BE0, 8CB0C831608033C4BC1D2DA7FAA7D429333A3654E76A989F7AF85BFC5F086BE9 ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
12:34:53.0487 0x10f0 vmbus - ok
12:34:53.0502 0x10f0 [ ECFEE2F2BA3932C7880D1A8F67D68F91, 57DCD55A518A9FBDEF72B511C643B1062C3F7BD339F4B0FC19E9D84C615B968D ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
12:34:53.0502 0x10f0 VMBusHID - ok
12:34:53.0549 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll
12:34:53.0565 0x10f0 vmicheartbeat - ok
12:34:53.0580 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
12:34:53.0596 0x10f0 vmickvpexchange - ok
12:34:53.0612 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicrdv C:\WINDOWS\System32\ICSvc.dll
12:34:53.0627 0x10f0 vmicrdv - ok
12:34:53.0627 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll
12:34:53.0643 0x10f0 vmicshutdown - ok
12:34:53.0659 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmictimesync C:\WINDOWS\System32\ICSvc.dll
12:34:53.0674 0x10f0 vmictimesync - ok
12:34:53.0674 0x10f0 [ B8FF4248103E6EA47B9D85C55673ABA3, 4337FA0F0FB5C45BFC42FF17DFAA5DCA394C74BA8283851504AD79F47B69CB0D ] vmicvss C:\WINDOWS\System32\ICSvc.dll
12:34:53.0690 0x10f0 vmicvss - ok
12:34:53.0705 0x10f0 [ CB60FAAED8B49B812EBBF77EB87D9B18, ADA7C68D4C4981555ED48981E8B7ACBEEF5C39F902EB98782FC3DFF495FE0C33 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
12:34:53.0705 0x10f0 volmgr - ok
12:34:53.0737 0x10f0 [ A74101DA9809251BCD0E5A26BAE0F824, 15A3A7CC31A13C5882812C344D0937A8A4503D12DB07B9F7F2A8191B739CDBF7 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
12:34:53.0752 0x10f0 volmgrx - ok
12:34:53.0784 0x10f0 [ 78A5BBA3819FFFC62FFEC3E2220D102D, A95797B97D576374C2CDA8A09E6C51A89BADE428AAA89D5093579C85062E5874 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
12:34:53.0784 0x10f0 volsnap - ok
12:34:53.0799 0x10f0 [ A8DA1C1B52ECEA3726DEBED4FF1B700D, 75C024EC3858DF24FB82FE105BDD1E37900D53EFE9D72F42CDDFFD0742525586 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
12:34:53.0815 0x10f0 vpci - ok
12:34:53.0846 0x10f0 [ 38A60CD9C009C55C6D3B5586F8E6A353, 7F7E2AE39F1A0A5245650911E310E0948BC22A18262A16FA76B44A042D66312D ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
12:34:53.0846 0x10f0 vsmraid - ok
12:34:53.0940 0x10f0 [ D0C69E44BC1E1D4AD290FD84104623D8, 4C86760EA4BD2A64FFD42D89284EC3E5048CB2F0F6F3B80D017B41C0D2456A90 ] VSS C:\WINDOWS\system32\vssvc.exe
12:34:53.0971 0x10f0 VSS - ok
12:34:54.0002 0x10f0 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC, AC2F3C70EDCA0AFBB2606267DFE6D3E8E7B0772140153BAD6B0A9EDE6A1D2F29 ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
12:34:54.0002 0x10f0 VSTXRAID - ok
12:34:54.0018 0x10f0 [ 62460A45435A26A334907E3F2EA45611, FEF86E05117CC0AAB8211CA1542776EB620BD4699BD590D91F16621ED35B9824 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
12:34:54.0018 0x10f0 vwifibus - ok
12:34:54.0049 0x10f0 [ 095E943D27025E4D588AF0A72CC2318F, 3CE406A202F93EF8C4BC7317621A672670D734C69166393CA7256D5E5E667041 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys
12:34:54.0049 0x10f0 vwififlt - ok
12:34:54.0065 0x10f0 [ 73FA1A41A97A5C34ADC03B3577FF1A86, CBA4BC0DA837C163587BBB4BF2AC1549C72440307C984D3CDF8995023718136C ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys
12:34:54.0065 0x10f0 vwifimp - ok
12:34:54.0096 0x10f0 [ F690B6EEAA94576727B24376D7ED3601, A61EE96024C8FC4058481DFB1E7F0AD746565368672FA3B6BA8F9E23D0F47E4C ] W32Time C:\WINDOWS\system32\w32time.dll
12:34:54.0112 0x10f0 W32Time - ok
12:34:54.0143 0x10f0 [ 6B806E893714019969E2B50D7EF6A4D9, 38FE2B01082DC4C2A0C11A292016A727F48C3DF1293DC3A0216B2254A452263F ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
12:34:54.0143 0x10f0 WacomPen - ok
12:34:54.0237 0x10f0 [ 61F6972FF9AC9A8D0B4D62076DC30051, 5A028036461534CA53CB2D6C1D720783D408A9F17FD77AB1ECDD75FBAD9F2381 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:34:54.0237 0x10f0 Wanarp - ok
12:34:54.0237 0x10f0 [ 61F6972FF9AC9A8D0B4D62076DC30051, 5A028036461534CA53CB2D6C1D720783D408A9F17FD77AB1ECDD75FBAD9F2381 ] Wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:34:54.0252 0x10f0 Wanarpv6 - ok
12:34:54.0330 0x10f0 [ 42DF22F8C448E7CD219F6D63743505E2, 063F4280C7BD20CE1360436B76A17DFE17FF611F75337A47373D098CC6C263BF ] wbengine C:\WINDOWS\system32\wbengine.exe
12:34:54.0362 0x10f0 wbengine - ok
12:34:54.0409 0x10f0 [ 31D37B2F6069C631EF0557D322924812, 6E18A1060F3C8F4BF220E286C44327866A8F9109E74928AA2D8C2DA9C452038B ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
12:34:54.0409 0x10f0 WbioSrvc - ok
12:34:54.0455 0x10f0 [ AF1349386D4C6786EF4E34FACEF15042, 6B33778409BC54C1955B92508ADDEBAFD629141961B71C94A91DC4CFE8391A13 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
12:34:54.0471 0x10f0 Wcmsvc - ok
12:34:54.0502 0x10f0 [ 5B5FEAB51172F5513C2CF7B39CFA6A01, 4FDAC5168E00D44781C6F5D98ECD4977A12663C5CE6FFDFF9DBC89A28D6212D8 ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
12:34:54.0534 0x10f0 wcncsvc - ok
12:34:54.0565 0x10f0 [ E19556D414332E2BEBA1F368229006B4, AB3454EC85D7B6E62D44C4510C1547AE7F736558588E54B0E265F7B3A5810E15 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
12:34:54.0565 0x10f0 WcsPlugInService - ok
12:34:54.0596 0x10f0 [ B3A4D918DAB90505B6BC7B70632913CB, ECC19DCD7902C29D0682C70B9546CF8B82477A32147EE30EB6750D8499605B46 ] Wd C:\WINDOWS\system32\drivers\wd.sys
12:34:54.0596 0x10f0 Wd - ok
12:34:54.0627 0x10f0 [ 3772FF85F0098686B0DCD77076AE0786, 8B0221F6003C53856676FFD9CDCFF43DF29B410AB2F340C10BB858F0E6EC14CE ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
12:34:54.0627 0x10f0 WdBoot - ok
12:34:54.0705 0x10f0 [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
12:34:54.0737 0x10f0 Wdf01000 - ok
12:34:54.0752 0x10f0 [ AB6F7DE8BFBF61A42F8764D9A621BD8B, DEFDC9FDC0B234403EE1339105B8D12B486D77B3BA01A703339B5DB8B95FA4D8 ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
12:34:54.0768 0x10f0 WdFilter - ok
12:34:54.0815 0x10f0 [ 240FC332484572227CD1DF82407F33E5, 5210549EC519DD3BCA6BBC995F01E1E3E0988580797E4BD1433F429E0CB30412 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
12:34:54.0815 0x10f0 WdiServiceHost - ok
12:34:54.0830 0x10f0 [ 240FC332484572227CD1DF82407F33E5, 5210549EC519DD3BCA6BBC995F01E1E3E0988580797E4BD1433F429E0CB30412 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
12:34:54.0846 0x10f0 WdiSystemHost - ok
12:34:54.0877 0x10f0 [ 9B1384CE8E681D2D77BB3524B8E86311, BDEF9D0A79A7C26A88088A306F91632F300E587736CDD2C64717EC54DD6E89FF

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 10 srp 2014 14:06

] WebClient C:\WINDOWS\System32\webclnt.dll
12:34:54.0893 0x10f0 WebClient - ok
12:34:54.0909 0x10f0 [ 35FD720943D4FCD75C3275BF062FF140, 9D8345E6DE1AE23F93AD0B52D27D1CCFD69EF7EE50654F92CA999BEC4570A773 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
12:34:54.0924 0x10f0 Wecsvc - ok
12:34:54.0940 0x10f0 [ 4D2612E3C462B68F499D840B1133263E, 4DDAEB4480AEC31A8184838588E0D3DFA31CE6D2FA6E906926860C75F52DC7B7 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
12:34:54.0940 0x10f0 wercplsupport - ok
12:34:54.0987 0x10f0 [ 5F70EBFC1F75B487DE79501E3CCBDB54, 2FCA57BF60A43B03BB42FBF22BBFC19AD2266FBBD818494AD114125E6E433321 ] WerSvc C:\WINDOWS\System32\WerSvc.dll
12:34:54.0987 0x10f0 WerSvc - ok
12:34:55.0018 0x10f0 [ 44BB9C31E6242C4BD1CE7C2B440C2533, E603BB001028918B687818E930340008C752679B133037367A8A8E41DA559FFE ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
12:34:55.0018 0x10f0 WFPLWFS - ok
12:34:55.0049 0x10f0 [ 60E0C220593DA4F7C289CB909D2DBAE0, 057CA7727F748600CC155043081AB9E3244763CF4913F317D13226A515F6FDB6 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
12:34:55.0065 0x10f0 WiaRpc - ok
12:34:55.0096 0x10f0 [ A3C7624A42A3447EF5EDD1ED37FE4E60, BD8BDF0A571873FA8277878AF7AED11196CFF1B4DF1EA6BA13BD4887D7B63B94 ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
12:34:55.0096 0x10f0 WIMMount - ok
12:34:55.0127 0x10f0 WinDefend - ok
12:34:55.0206 0x10f0 [ 7911470B6018059A880469A63B65700A, 4B6131491A028FBCA54AC261112D183EFD42E98160545C8E8DFBDA01C87B3FB5 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
12:34:55.0237 0x10f0 WinHttpAutoProxySvc - ok
12:34:55.0315 0x10f0 [ 3D6B518B71C75C8FA4115A33615C107A, ED7A266013D29D3B1A462464735C3632BEA121D1B32553907AEAA0B00595C3DF ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
12:34:55.0331 0x10f0 Winmgmt - ok
12:34:55.0518 0x10f0 [ 8E212A627F33F6FC3B5F3BB47212F66E, 9BBFE26ABFA14F346FE3711D13D959523EEA23608A33C16F3D750D66CA511911 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
12:34:55.0674 0x10f0 WinRM - ok
12:34:55.0815 0x10f0 [ 6351724B8FA0255C2DBD970297F00B93, A02F274479F9F32E30C75A5BD991B008B3CCB47D380D5870563EF918DAC5730E ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
12:34:55.0877 0x10f0 WlanSvc - ok
12:34:55.0971 0x10f0 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B, B76226808406D8B38DE2D3A8CCE633BB507022C8BAAA6C3DAD34204CC6CE1284 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
12:34:56.0065 0x10f0 wlidsvc - ok
12:34:56.0096 0x10f0 [ E2A596CACFC6504306CDB7B593B90084, DF89CF57249553CE922C841F18B99A213185FA1099C053B9BB8C0F6E5BC3FEC0 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
12:34:56.0096 0x10f0 WmiAcpi - ok
12:34:56.0143 0x10f0 [ D113499052C5E541906B727779F0F959, 05FB51086C0A0CE3812A7E6098C5A454ECCFE8553669CFA715153564F2226DB0 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
12:34:56.0143 0x10f0 wmiApSrv - ok
12:34:56.0190 0x10f0 WMPNetworkSvc - ok
12:34:56.0206 0x10f0 [ C6FF953D5D6F2EAE3B8883474D5076B3, 001CBB7FBC30209C892869258E5ABD3F0932886E156ECB10DCA599F6D32648BE ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
12:34:56.0206 0x10f0 wpcfltr - ok
12:34:56.0237 0x10f0 [ A6ED163169876BFD2437E872FE2F1509, C13E8676800EEEF690F51C4DEA660B36C8734AE2CCAAC48054E10D74B98949B8 ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll
12:34:56.0252 0x10f0 WPCSvc - ok
12:34:56.0284 0x10f0 [ 3013658A4D327854BEEC4A08D9655194, C4CF5AA6A47CC55E7037B0BFE20AE0A6442ADDC5DEB89D6861C98C61851FA821 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
12:34:56.0299 0x10f0 WPDBusEnum - ok
12:34:56.0315 0x10f0 [ 0346CAFC181C91C6E2330332EB332ED6, D46F44C339399CAAE13CD71C53A169E95065208E07E5420DE00A4509D6CB056F ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
12:34:56.0331 0x10f0 WpdUpFltr - ok
12:34:56.0362 0x10f0 [ BC8B5CB336E63BB25EAD1CE8EDD34B81, A42759956EDCCC6D0688240AA4F833FB9CA132D42D2D901CDCBB24DCE1788C1D ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
12:34:56.0362 0x10f0 ws2ifsl - ok
12:34:56.0393 0x10f0 [ 012CFE7F0F95266F554EE3B91EE2128A, 866312F6BF7369BE686F1BA9F01311C99E95E268C6E63BE37C841F54F5AA0DB8 ] wscsvc C:\WINDOWS\System32\wscsvc.dll
12:34:56.0393 0x10f0 wscsvc - ok
12:34:56.0409 0x10f0 WSearch - ok
12:34:56.0549 0x10f0 [ D4D04839F3DFAF09D94BAB1016F7A297, 944A41D251F522EE87189C1D01CF7EEE2C70BF4353BA4005C44F03DB485F843F ] WSService C:\WINDOWS\System32\WSService.dll
12:34:56.0674 0x10f0 WSService - ok
12:34:56.0815 0x10f0 [ 311E5E1976E0BD9110A88B93158055D5, F1AA738D6AD74C33785EEFE1FBE8A869AAB62417B7D079389293AB1209A849C1 ] wuauserv C:\WINDOWS\system32\wuaueng.dll
12:34:56.0940 0x10f0 wuauserv - ok
12:34:56.0956 0x10f0 [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
12:34:56.0956 0x10f0 WudfPf - ok
12:34:56.0987 0x10f0 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
12:34:56.0987 0x10f0 WUDFRd - ok
12:34:57.0003 0x10f0 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFSensorLP C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
12:34:57.0003 0x10f0 WUDFSensorLP - ok
12:34:57.0034 0x10f0 [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
12:34:57.0049 0x10f0 wudfsvc - ok
12:34:57.0081 0x10f0 [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
12:34:57.0096 0x10f0 WUDFWpdFs - ok
12:34:57.0159 0x10f0 [ 6D9E07436B6646EC8F7EFFD39B6BA288, 82C1CEA93ECEF17D221AD0F87C5BD96F3FD8143841C16BD9608BD4D58D90B8E0 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
12:34:57.0174 0x10f0 WwanSvc - ok
12:34:57.0190 0x10f0 ================ Scan global ===============================
12:34:57.0237 0x10f0 [ DDC1AFBF9DDF880CE9BD3896114D8DED, E2406231EA4D2689A5EDFA9BD1A1BC064359D8D23B37F113A18B5EAE3E2D4050 ] C:\WINDOWS\system32\basesrv.dll
12:34:57.0299 0x10f0 [ E9343076AE704D20BB0D01F3AF3EFFEF, FF2CE4146945976F9480690505CECD3C7C719BAF0F633E6192C8272C75EF295D ] C:\WINDOWS\system32\winsrv.dll
12:34:57.0362 0x10f0 [ BD7C6949984D19AAA609896B675E7357, 5B46538B27BC70F5A3805AA63F6AACDC780C7168468FB535F2D35CF26B9DEE06 ] C:\WINDOWS\system32\sxssrv.dll
12:34:57.0409 0x10f0 [ 8F226143046435C75C033B0C52E90FFE, 54FA316485B57D7B8104FE621F5F40DEC35E3D57C3DF46B5F7EACF57445FE7CA ] C:\WINDOWS\system32\services.exe
12:34:57.0424 0x10f0 [ Global ] - ok
12:34:57.0424 0x10f0 ================ Scan MBR ==================================
12:34:57.0440 0x10f0 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
12:34:57.0440 0x10f0 \Device\Harddisk0\DR0 - ok
12:34:57.0440 0x10f0 ================ Scan VBR ==================================
12:34:57.0456 0x10f0 [ 637C1F37524C9AE6EFD3144462357F34 ] \Device\Harddisk0\DR0\Partition1
12:34:57.0471 0x10f0 \Device\Harddisk0\DR0\Partition1 - ok
12:34:57.0487 0x10f0 [ 69D14BDC646D5648A25EC768046EC37F ] \Device\Harddisk0\DR0\Partition2
12:34:57.0503 0x10f0 \Device\Harddisk0\DR0\Partition2 - ok
12:34:57.0518 0x10f0 [ DE2C08BA2FBF216DB82F92C78F8C853D ] \Device\Harddisk0\DR0\Partition3
12:34:57.0518 0x10f0 \Device\Harddisk0\DR0\Partition3 - ok
12:34:57.0549 0x10f0 [ 0FEE12C5B35CB0CE7F118520F31AFC7A ] \Device\Harddisk0\DR0\Partition4
12:34:57.0565 0x10f0 \Device\Harddisk0\DR0\Partition4 - ok
12:34:57.0596 0x10f0 [ D0163D57B545D509B1F239F2688227F7 ] \Device\Harddisk0\DR0\Partition5
12:34:57.0596 0x10f0 \Device\Harddisk0\DR0\Partition5 - ok
12:34:57.0596 0x10f0 ================ Scan generic autorun ======================
12:34:57.0893 0x10f0 [ 08AB94079A67F4D13736387C39FC16C4, 94FE152CBD6331A1A59259B9C51E9DBE456338BF800FDFEBE04B34DA9E685DEF ] C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe
12:34:58.0049 0x10f0 TPUReg - ok
12:34:58.0268 0x10f0 [ 26B558B2D31C7425B455B00E562EAD93, B64D128A2F1FC42BA4376F8EB08D70F4B705745CB983D0631DB45851BF34BBDF ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
12:34:58.0362 0x10f0 AvastUI.exe - ok
12:34:58.0362 0x10f0 YandexElements - ok
12:34:58.0362 0x10f0 Waiting for KSN requests completion. In queue: 299
12:34:59.0378 0x10f0 Waiting for KSN requests completion. In queue: 299
12:35:00.0393 0x10f0 Waiting for KSN requests completion. In queue: 299
12:35:02.0909 0x10f0 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 9.0.2021.515 ), 0x42000 ( disabled : updated )
12:35:02.0987 0x10f0 Win FW state via NFP2: enabled
12:35:05.0347 0x10f0 ============================================================
12:35:05.0347 0x10f0 Scan finished
12:35:05.0347 0x10f0 ============================================================
12:35:05.0347 0x10e8 Detected object count: 1
12:35:05.0347 0x10e8 Actual detected object count: 1

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Orcus » 11 srp 2014 07:46

V TDSS dej nález odstranit a dodej nový log.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 11 srp 2014 10:18

log z TDSS

10:13:37.0705 0x0cc0 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
10:13:37.0705 0x0cc0 UEFI system
10:13:37.0752 0x0cc0 ============================================================
10:13:37.0752 0x0cc0 Current date / time: 2014/08/11 10:13:37.0752
10:13:37.0752 0x0cc0 SystemInfo:
10:13:37.0752 0x0cc0
10:13:37.0752 0x0cc0 OS Version: 6.2.9200 ServicePack: 0.0
10:13:37.0752 0x0cc0 Product type: Workstation
10:13:37.0752 0x0cc0 ComputerName: EVGENKA
10:13:37.0752 0x0cc0 UserName: Evgenija
10:13:37.0752 0x0cc0 Windows directory: C:\WINDOWS
10:13:37.0752 0x0cc0 System windows directory: C:\WINDOWS
10:13:37.0752 0x0cc0 Running under WOW64
10:13:37.0752 0x0cc0 Processor architecture: Intel x64
10:13:37.0752 0x0cc0 Number of processors: 2
10:13:37.0752 0x0cc0 Page size: 0x1000
10:13:37.0752 0x0cc0 Boot type: Normal boot
10:13:37.0752 0x0cc0 ============================================================
10:13:41.0393 0x0cc0 KLMD registered as C:\WINDOWS\system32\drivers\96434330.sys
10:13:43.0206 0x0cc0 System UUID: {A2F651A8-EDE8-71FE-3C63-68ECB77792BE}
10:13:44.0784 0x0cc0 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:13:44.0799 0x0cc0 ============================================================
10:13:44.0799 0x0cc0 \Device\Harddisk0\DR0:
10:13:44.0862 0x0cc0 GPT partitions:
10:13:44.0893 0x0cc0 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {FE282917-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xE1000
10:13:44.0893 0x0cc0 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {FE28291F-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0xE1800, BlocksNum 0x82000
10:13:44.0893 0x0cc0 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {FE282921-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x163800, BlocksNum 0x40000
10:13:44.0893 0x0cc0 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {FE282929-3597-11E2-B025-B6EC0D91DBCC}, Name: Basic data partition, StartLBA 0x1A3800, BlocksNum 0x38DA1800
10:13:44.0893 0x0cc0 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {26B3207E-CB64-4A62-8DEF-4794BED022DF}, Name: Basic data partition, StartLBA 0x38F45000, BlocksNum 0x1441000
10:13:44.0893 0x0cc0 MBR partitions:
10:13:44.0893 0x0cc0 ============================================================
10:13:45.0034 0x0cc0 C: <-> \Device\Harddisk0\DR0\Partition4
10:13:45.0034 0x0cc0 ============================================================
10:13:45.0034 0x0cc0 Initialize success
10:13:45.0034 0x0cc0 ============================================================
10:14:41.0459 0x0bac Deinitialize success

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 11 srp 2014 10:58

log z combofixu

ComboFix 14-08-06.02 - Evgenija . 08. 2014 10:31:26.1.2 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.3979.2917 [GMT 2:00]
Spuštěný z: c:\users\Evgenija\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru.json
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\app.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\aboutSupport.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\addonfs.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\addonmgr.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\addonStatus.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\backgroundImages.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\backup.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\barnavig.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\blacklist.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\bookmarks.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\branding.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\clids.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\cloudsource.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\colors.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\databaseMigration.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\dataprovider.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\fastdial.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\favicons.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\frontendHelper.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\installer.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\internalStructure.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\layout.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\metrika.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\migration.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\migration\install.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\migration\l-2_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\migration\l-2_3.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\migration\l-2_9.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\package.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\protocolSupport.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\safebrowsing.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\searchExample.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\searchSuggest.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\strbundle.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\sync.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\syncPinned.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\syncTopHistory.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\thumbs.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\usageHistory.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\workers\barnavig.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\cbapp\parts\ycookie.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\chrome.manifest
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\chrome\yandex-vb.jar
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\components\core.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\config.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\defaults\preferences\yandex-vb.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\defaults\vendor\vendor.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\install.rdf
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\AddonManager.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\DataURI.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\Foundation.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\async.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\database.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\ecustom.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\fileutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\misc.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\netutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\patterns.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\promise.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\strutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\sysutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\task.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\foundation\xmlutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\Log4Moz.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\Preferences.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\SimpleHTMLParser.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\SimpleProtocol.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\Stemmer.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\WindowListener.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\vb@yandex.ru\modules\WinReg.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru.json
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\bar.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\aboutSupport.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\addonfs.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\addonmgr.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\addonStatus.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\anonymousStatistic.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\autoinst.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\barnavig.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\brand_prov.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\branding.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\browserUsage.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\clids.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\compsusage.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\defender.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\distribution.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\incoming.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\installer.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\install.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-5_2_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-6_4_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-7_0_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-7_6_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-7_8_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-7_8_1.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-8_0_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\migration\l-8_1_0.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\barplugin.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\brandsvc.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\compapi.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\ncparser.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\npwidget.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native\sliceapi.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\native_comps.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\notifications.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\overlay_prov.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\pacman.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\cachedres.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\manifest.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\package.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\permissions.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\preset-with-manifest.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\preset.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\platform\unit.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\slices.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\strbundle.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\update.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\vendorCookie.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\widgetlib.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\workers\barnavig.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\action.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\attribute.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\button.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\checkbox.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\checked.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\computed.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\enabled.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\extra-text.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\grid.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\image.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\menu.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\style.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\text.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\tooltip.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\url.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\widget.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\behaviour\xml.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\elements.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\ui\event-listener.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbbase.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbcalcnodes.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbfuncs.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbparser.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbtypes.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbui.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\xb\xbwidget.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\cbapp\parts\ycookie.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\chrome.manifest
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\chrome\yasearch.jar
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\components\core.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\components\nsIYaSearch.xpt
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\components\nsSearchSuggestions.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\components\nsYaSearch.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\components\xbProtocol.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\config.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\dynamic-preferences\brand\ua\safebrowsing.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\dynamic-preferences\safebrowsing.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\preferences\yasearch.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\presets\http%3A%2F%2Fbar.yandex.ru%2Fpresets%2Fdefault-partner.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\presets\http%3A%2F%2Fbar.yandex.ru%2Fpresets%2Fdefault.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\presets\http%3A%2F%2Fbar.yandex.ru%2Fpresets%2Ftb.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\presets\http%3A%2F%2Fbar.yandex.ru%2Fpresets%2Fua.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\defaults\vendor\vendor.xml
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\install.rdf
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\AddonManager.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\DataURI.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\Foundation.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\async.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\database.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\dlqueue.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\ecustom.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\fileutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\legacy.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\misc.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\netutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\patterns.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\promise.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\strutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\sysutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\task.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\foundation\xmlutils.js
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\Log4Moz.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\Preferences.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\SimpleHTMLParser.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\SimpleProtocol.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\Stemmer.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\WindowListener.jsm
c:\users\Evgenija\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\staged\yasearch@yandex.ru\modules\WinReg.jsm
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-11 do 2014-08-11 )))))))))))))))))))))))))))))))
.
.
2014-08-11 08:48 . 2014-08-11 08:48 -------- d-----w- c:\users\Evgenija\AppData\Local\temp
2014-08-11 08:48 . 2014-08-11 08:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-11 08:48 . 2014-08-11 08:48 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-08-11 08:06 . 2014-08-11 08:06 -------- d-----w- C:\TDSSKiller_Quarantine
2014-08-10 14:32 . 2014-08-10 14:32 -------- d-----w- c:\users\Evgenija\AppData\Roaming\eCyber
2014-08-10 08:53 . 2014-08-10 13:46 -------- d-----w- c:\users\Evgenija\AppData\Local\CrashDumps
2014-08-09 09:38 . 2014-08-10 10:21 29160 ----a-w- c:\windows\SysWow64\drivers\TrueSight.sys
2014-08-09 09:38 . 2014-08-09 09:38 -------- d-----w- c:\programdata\RogueKiller
2014-08-09 09:24 . 2014-08-09 09:24 -------- d-----w- c:\users\Evgenija\AppData\Roaming\toshiba
2014-08-08 18:29 . 2014-08-10 14:33 -------- d-----w- c:\users\Evgenija\AppData\Roaming\iSafe
2014-08-08 18:24 . 2014-08-08 18:24 -------- d-----w- c:\windows\ERUNT
2014-08-08 18:16 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-08-08 08:11 . 2014-08-08 08:11 -------- d-----w- c:\users\Evgenija\AppData\Local\ElevatedDiagnostics
2014-08-08 08:11 . 2014-08-08 08:11 -------- d-----w- c:\users\Evgenija\AppData\Local\Diagnostics
2014-08-08 07:58 . 2014-08-09 08:47 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-08 07:57 . 2014-05-12 05:26 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-08 07:57 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-08 07:57 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-08 07:57 . 2014-08-08 07:57 -------- d-----w- c:\programdata\Malwarebytes
2014-08-08 07:47 . 2014-08-08 18:17 -------- d-----w- C:\AdwCleaner
2014-08-01 17:47 . 2014-08-01 17:47 -------- d-----w- c:\users\Evgenija\AppData\Roaming\AVAST Software
2014-08-01 17:46 . 2014-08-01 17:47 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-01 17:46 . 2014-08-01 17:46 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-01 17:46 . 2014-08-01 17:46 92008 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-08-01 17:46 . 2014-08-01 17:46 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-08-01 17:46 . 2014-08-01 17:46 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-01 17:46 . 2014-08-01 17:46 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-01 17:46 . 2014-08-01 17:46 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-01 17:46 . 2014-08-01 17:46 1041168 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-08-01 17:46 . 2014-08-01 17:46 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-01 17:46 . 2014-08-01 17:46 43152 ----a-w- c:\windows\avastSS.scr
2014-08-01 17:44 . 2014-08-01 17:44 -------- d-----w- c:\program files\AVAST Software
2014-07-26 14:46 . 2014-07-26 14:46 -------- d-s---w- c:\windows\system32\CompatTel
2014-07-26 13:52 . 2014-07-26 13:52 -------- d-----w- c:\users\Evgenija\AppData\Roaming\Yandex
2014-07-26 13:51 . 2014-07-26 13:51 -------- d-----w- c:\users\Evgenija\AppData\Local\Yandex
2014-07-24 13:55 . 2014-06-30 22:42 394240 ----a-w- c:\windows\system32\devinv.dll
2014-07-24 13:55 . 2014-06-30 22:42 87552 ----a-w- c:\windows\system32\aepic.dll
2014-07-24 13:55 . 2014-06-30 22:42 702464 ----a-w- c:\windows\system32\aepdu.dll
2014-07-24 13:55 . 2014-06-28 03:35 556544 ----a-w- c:\windows\system32\aeinv.dll
2014-07-14 17:28 . 2014-07-14 17:28 -------- d-----w- C:\found.016
2014-07-13 07:55 . 2014-06-06 14:06 596480 ----a-w- c:\windows\system32\qedit.dll
2014-07-13 07:55 . 2014-06-06 10:17 497152 ----a-w- c:\windows\SysWow64\qedit.dll
2014-07-13 07:52 . 2014-06-11 14:47 3262464 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-07-13 07:52 . 2014-06-11 04:18 4038144 ----a-w- c:\windows\system32\win32k.sys
2014-07-13 07:52 . 2014-06-17 23:27 1440256 ----a-w- c:\windows\SysWow64\osk.exe
2014-07-13 07:52 . 2014-06-17 23:24 1557504 ----a-w- c:\windows\system32\osk.exe
2014-07-13 07:52 . 2014-06-11 16:00 394624 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TabTip.exe
2014-07-13 07:52 . 2014-06-11 14:47 92672 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-07-13 07:52 . 2014-06-11 14:47 1616896 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-13 08:34 . 2014-05-29 10:42 96441528 ----a-w- c:\windows\system32\MRT.exe
2014-07-03 13:23 . 2014-07-03 13:23 257704 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10243.bin
2014-06-27 09:54 . 2014-06-28 16:12 44544 ----a-w- c:\windows\system32\drivers\iSafeKrnlBoot.sys
2014-06-26 20:53 . 2014-06-02 15:45 703968 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-26 20:53 . 2014-06-02 15:45 105440 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-29 22:24 . 2014-07-09 08:40 576512 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-28 13:01 . 2014-05-28 13:01 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2014-05-28 13:01 . 2014-05-28 13:01 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-05-27 13:54 . 2012-07-26 08:13 23264 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-05-24 02:48 . 2014-07-02 08:49 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2014-05-24 02:47 . 2014-07-02 08:49 2239488 ----a-w- c:\windows\system32\wininet.dll
2014-05-24 02:47 . 2014-07-02 08:49 915968 ----a-w- c:\windows\system32\uxtheme.dll
2014-05-24 02:47 . 2014-07-02 08:49 53760 ----a-w- c:\windows\system32\UXInit.dll
2014-05-24 02:47 . 2014-07-02 08:49 1366016 ----a-w- c:\windows\system32\urlmon.dll
2014-05-24 02:46 . 2014-07-02 08:49 197120 ----a-w- c:\windows\system32\msrating.dll
2014-05-24 02:46 . 2014-07-02 08:49 97792 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-24 02:46 . 2014-07-02 08:49 19290112 ----a-w- c:\windows\system32\mshtml.dll
2014-05-24 02:46 . 2014-07-02 08:49 603136 ----a-w- c:\windows\system32\msfeeds.dll
2014-05-24 02:46 . 2014-07-02 08:49 53760 ----a-w- c:\windows\system32\jsproxy.dll
2014-05-24 02:46 . 2014-07-02 08:49 855552 ----a-w- c:\windows\system32\jscript.dll
2014-05-24 02:46 . 2014-07-02 08:48 3958784 ----a-w- c:\windows\system32\jscript9.dll
2014-05-24 02:46 . 2014-07-02 08:49 39936 ----a-w- c:\windows\system32\iernonce.dll
2014-05-24 02:46 . 2014-07-02 08:49 136704 ----a-w- c:\windows\system32\iesysprep.dll
2014-05-24 02:46 . 2014-07-02 08:49 67072 ----a-w- c:\windows\system32\iesetup.dll
2014-05-24 02:46 . 2014-07-02 08:48 2650112 ----a-w- c:\windows\system32\iertutil.dll
2014-05-24 02:46 . 2014-07-02 08:49 15368704 ----a-w- c:\windows\system32\ieframe.dll
2014-05-24 02:45 . 2014-07-02 08:49 281600 ----a-w- c:\windows\system32\dxtrans.dll
2014-05-24 02:45 . 2014-07-02 08:49 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2014-05-24 02:45 . 2014-07-02 08:49 1508864 ----a-w- c:\windows\system32\inetcpl.cpl
2014-05-24 01:26 . 2014-07-02 08:49 1766400 ----a-w- c:\windows\SysWow64\wininet.dll
2014-05-24 01:26 . 2014-07-02 08:49 44032 ----a-w- c:\windows\SysWow64\UXInit.dll
2014-05-24 01:25 . 2014-07-02 08:48 2862080 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-05-24 01:25 . 2014-07-02 08:49 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-05-24 01:25 . 2014-07-02 08:49 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-05-24 01:25 . 2014-07-02 08:49 1440768 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-05-24 01:09 . 2014-07-02 08:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-24 01:03 . 2014-07-02 08:49 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-23 22:37 . 2014-07-02 08:49 534528 ----a-w- c:\windows\SysWow64\uxtheme.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TPUReg"="c:\program files (x86)\TOSHIBA\Password Utility\TosPU.exe" [2012-10-31 7148032]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-01 4085896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R0 06475101;06475101;c:\windows\system32\drivers\95964103.sys;c:\windows\SYSNATIVE\drivers\95964103.sys [x]
R1 iSafeNetFilter;iSafeNetFilter NDIS Driver;c:\program files (x86)\iSafe\iSafeNetFilter.sys;c:\program files (x86)\iSafe\iSafeNetFilter.sys [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 iSafeKrnlBoot;iSafeKrnl Boot Driver;c:\windows\system32\DRIVERS\iSafeKrnlBoot.sys;c:\windows\SYSNATIVE\DRIVERS\iSafeKrnlBoot.sys [x]
R3 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E – ovladač síťové karty;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
R3 TemproMonitoringService;TEMPRO Service;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\System32\drivers\tos_sps64.sys;c:\windows\SYSNATIVE\drivers\tos_sps64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 iSafeKrnl;iSafeKrnl;c:\program files (x86)\iSafe\iSafeKrnl.sys;c:\program files (x86)\iSafe\iSafeKrnl.sys [x]
S1 iSafeKrnlKit;iSafeKrnl Kit Driver;c:\program files (x86)\iSafe\iSafeKrnlKit.sys;c:\program files (x86)\iSafe\iSafeKrnlKit.sys [x]
S1 iSafeKrnlR3;iSafeKrnl Ring3 Driver;c:\program files (x86)\iSafe\iSafeKrnlR3.sys;c:\program files (x86)\iSafe\iSafeKrnlR3.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 GFNEXSrv;GFNEX Service;c:\program files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe;c:\program files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 iSafeService;iSafeService;c:\program files (x86)\iSafe\iSafeSvc.exe;c:\program files (x86)\iSafe\iSafeSvc.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 PEGAGFN;PEGAGFN;c:\program files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys;c:\program files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\Teco\TecoService.exe;c:\program files\TOSHIBA\Teco\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
S3 RtkBtFilter;Realtek Bluetooth Filter Driver;c:\windows\system32\DRIVERS\RtkBtfilter.sys;c:\windows\SYSNATIVE\DRIVERS\RtkBtfilter.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-27 17:56]
.
2014-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 18:32]
.
2014-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 18:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-01 17:46 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-08 398656]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-09-25 13196432]
"TODDMain"="c:\program files (x86)\TOSHIBA\System Setting\TODDMain.exe" [2012-08-04 213136]
"TecoResident"="c:\program files\TOSHIBA\Teco\TecoResident.exe" [2012-08-14 169896]
"SRS Premium Sound HD"="c:\program files\SRS Labs\SRS Control Panel\SRSPanel_64.exe" [2012-08-20 2170784]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
uDefault_Page_URL = about:blank
mDefault_Page_URL = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.10.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
Wow6432Node-HKCU-Run-YandexElements - c:\program files (x86)\Yandex\Common\elements64.exe
SafeBoot-06475101.sys
Toolbar-Locked - (no file)
Toolbar-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
WebBrowser-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\Hotkey\TCrdMain_Win8.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-Malwarebytes Anti-Malware_is1 - c:\program files (x86)\Malwarebytes Anti-Malware\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2014-08-11 10:54:00
ComboFix-quarantined-files.txt 2014-08-11 08:54
.
Před spuštěním: 433 986 338 816 bytes free
Po spuštění: 434 107 879 424 bytes free
.
- - End Of File - - A31116466B97E0570392284FB1F4FC97

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod jaro3 » 11 srp 2014 19:02

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\windows\system32\drivers\95964103.sys
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
C:\found.016
c:\program files (x86)\Google\Update

Driver::
06475101

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 11 srp 2014 23:24

ComboFix 14-08-06.02 - Evgenija . 08. 2014 22:50:09.2.2 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.3979.2754 [GMT 2:00]
Spuštěný z: c:\users\Evgenija\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Evgenija\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
FILE ::
"c:\windows\system32\drivers\95964103.sys"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\found.016
c:\found.016\file00000000.chk
c:\program files (x86)\Google\Update
c:\program files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdateBroker.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdateComRegisterShell64.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdateHelper.msi
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\1.3.24.15\goopdate.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_am.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ar.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_bg.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_bn.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ca.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_cs.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_da.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_de.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_el.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_en-GB.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_en.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_es-419.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_es.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_et.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_fa.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_fi.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_fil.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_fr.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_gu.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_hi.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_hr.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_hu.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_id.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_is.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_it.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_iw.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ja.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_kn.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ko.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_lt.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_lv.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ml.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_mr.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ms.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_nl.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_no.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_pl.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_pt-BR.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_pt-PT.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ro.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ru.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_sk.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_sl.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_sr.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_sv.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_sw.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ta.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_te.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_th.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_tr.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_uk.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_ur.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_vi.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_zh-CN.dll
c:\program files (x86)\Google\Update\1.3.24.15\goopdateres_zh-TW.dll
c:\program files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
c:\program files (x86)\Google\Update\1.3.24.15\psmachine.dll
c:\program files (x86)\Google\Update\1.3.24.15\psmachine_64.dll
c:\program files (x86)\Google\Update\1.3.24.15\psuser.dll
c:\program files (x86)\Google\Update\1.3.24.15\psuser_64.dll
c:\program files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.24.15\GoogleUpdateSetup.exe
c:\program files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\35.0.1916.153\35.0.1916.153_35.0.1916.114_chrome_updater.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
c:\windows\SysWow64\Drivers\atapi.sys . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_06475101
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Legacy_gupdate
-------\Legacy_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-11 do 2014-08-11 )))))))))))))))))))))))))))))))
.
.
2014-08-11 21:10 . 2014-08-11 21:10 -------- d-----w- c:\users\Evgenija\AppData\Local\temp
2014-08-11 21:10 . 2014-08-11 21:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-11 08:06 . 2014-08-11 08:06 -------- d-----w- C:\TDSSKiller_Quarantine
2014-08-10 14:32 . 2014-08-10 14:32 -------- d-----w- c:\users\Evgenija\AppData\Roaming\eCyber
2014-08-10 08:53 . 2014-08-10 13:46 -------- d-----w- c:\users\Evgenija\AppData\Local\CrashDumps
2014-08-09 09:38 . 2014-08-10 10:21 29160 ----a-w- c:\windows\SysWow64\drivers\TrueSight.sys
2014-08-09 09:38 . 2014-08-09 09:38 -------- d-----w- c:\programdata\RogueKiller
2014-08-09 09:24 . 2014-08-09 09:24 -------- d-----w- c:\users\Evgenija\AppData\Roaming\toshiba
2014-08-08 18:29 . 2014-08-10 14:33 -------- d-----w- c:\users\Evgenija\AppData\Roaming\iSafe
2014-08-08 18:24 . 2014-08-08 18:24 -------- d-----w- c:\windows\ERUNT
2014-08-08 18:16 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-08-08 08:11 . 2014-08-08 08:11 -------- d-----w- c:\users\Evgenija\AppData\Local\ElevatedDiagnostics
2014-08-08 08:11 . 2014-08-08 08:11 -------- d-----w- c:\users\Evgenija\AppData\Local\Diagnostics
2014-08-08 07:58 . 2014-08-09 08:47 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-08 07:57 . 2014-05-12 05:26 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-08 07:57 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-08 07:57 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-08 07:57 . 2014-08-08 07:57 -------- d-----w- c:\programdata\Malwarebytes
2014-08-08 07:47 . 2014-08-08 18:17 -------- d-----w- C:\AdwCleaner
2014-08-01 17:47 . 2014-08-01 17:47 -------- d-----w- c:\users\Evgenija\AppData\Roaming\AVAST Software
2014-08-01 17:46 . 2014-08-01 17:47 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-01 17:46 . 2014-08-01 17:46 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-01 17:46 . 2014-08-01 17:46 92008 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-08-01 17:46 . 2014-08-01 17:46 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-08-01 17:46 . 2014-08-01 17:46 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-01 17:46 . 2014-08-01 17:46 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-01 17:46 . 2014-08-01 17:46 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-01 17:46 . 2014-08-01 17:46 1041168 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-08-01 17:46 . 2014-08-01 17:46 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-01 17:46 . 2014-08-01 17:46 43152 ----a-w- c:\windows\avastSS.scr
2014-08-01 17:44 . 2014-08-01 17:44 -------- d-----w- c:\program files\AVAST Software
2014-07-26 14:46 . 2014-07-26 14:46 -------- d-s---w- c:\windows\system32\CompatTel
2014-07-26 13:52 . 2014-07-26 13:52 -------- d-----w- c:\users\Evgenija\AppData\Roaming\Yandex
2014-07-26 13:51 . 2014-07-26 13:51 -------- d-----w- c:\users\Evgenija\AppData\Local\Yandex
2014-07-24 13:55 . 2014-06-30 22:42 394240 ----a-w- c:\windows\system32\devinv.dll
2014-07-24 13:55 . 2014-06-30 22:42 87552 ----a-w- c:\windows\system32\aepic.dll
2014-07-24 13:55 . 2014-06-30 22:42 702464 ----a-w- c:\windows\system32\aepdu.dll
2014-07-24 13:55 . 2014-06-28 03:35 556544 ----a-w- c:\windows\system32\aeinv.dll
2014-07-13 07:55 . 2014-06-06 14:06 596480 ----a-w- c:\windows\system32\qedit.dll
2014-07-13 07:55 . 2014-06-06 10:17 497152 ----a-w- c:\windows\SysWow64\qedit.dll
2014-07-13 07:52 . 2014-06-11 14:47 3262464 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-07-13 07:52 . 2014-06-11 04:18 4038144 ----a-w- c:\windows\system32\win32k.sys
2014-07-13 07:52 . 2014-06-17 23:27 1440256 ----a-w- c:\windows\SysWow64\osk.exe
2014-07-13 07:52 . 2014-06-17 23:24 1557504 ----a-w- c:\windows\system32\osk.exe
2014-07-13 07:52 . 2014-06-11 16:00 394624 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TabTip.exe
2014-07-13 07:52 . 2014-06-11 14:47 92672 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-07-13 07:52 . 2014-06-11 14:47 1616896 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-13 08:34 . 2014-05-29 10:42 96441528 ----a-w- c:\windows\system32\MRT.exe
2014-07-03 13:23 . 2014-07-03 13:23 257704 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10243.bin
2014-06-27 09:54 . 2014-06-28 16:12 44544 ----a-w- c:\windows\system32\drivers\iSafeKrnlBoot.sys
2014-06-26 20:53 . 2014-06-02 15:45 703968 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-26 20:53 . 2014-06-02 15:45 105440 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-29 22:24 . 2014-07-09 08:40 576512 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-28 13:01 . 2014-05-28 13:01 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2014-05-28 13:01 . 2014-05-28 13:01 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-05-27 13:54 . 2012-07-26 08:13 23264 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-05-24 02:48 . 2014-07-02 08:49 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2014-05-24 02:47 . 2014-07-02 08:49 2239488 ----a-w- c:\windows\system32\wininet.dll
2014-05-24 02:47 . 2014-07-02 08:49 915968 ----a-w- c:\windows\system32\uxtheme.dll
2014-05-24 02:47 . 2014-07-02 08:49 53760 ----a-w- c:\windows\system32\UXInit.dll
2014-05-24 02:47 . 2014-07-02 08:49 1366016 ----a-w- c:\windows\system32\urlmon.dll
2014-05-24 02:46 . 2014-07-02 08:49 197120 ----a-w- c:\windows\system32\msrating.dll
2014-05-24 02:46 . 2014-07-02 08:49 97792 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-24 02:46 . 2014-07-02 08:49 19290112 ----a-w- c:\windows\system32\mshtml.dll
2014-05-24 02:46 . 2014-07-02 08:49 603136 ----a-w- c:\windows\system32\msfeeds.dll
2014-05-24 02:46 . 2014-07-02 08:49 53760 ----a-w- c:\windows\system32\jsproxy.dll
2014-05-24 02:46 . 2014-07-02 08:49 855552 ----a-w- c:\windows\system32\jscript.dll
2014-05-24 02:46 . 2014-07-02 08:48 3958784 ----a-w- c:\windows\system32\jscript9.dll
2014-05-24 02:46 . 2014-07-02 08:49 39936 ----a-w- c:\windows\system32\iernonce.dll
2014-05-24 02:46 . 2014-07-02 08:49 136704 ----a-w- c:\windows\system32\iesysprep.dll
2014-05-24 02:46 . 2014-07-02 08:49 67072 ----a-w- c:\windows\system32\iesetup.dll
2014-05-24 02:46 . 2014-07-02 08:48 2650112 ----a-w- c:\windows\system32\iertutil.dll
2014-05-24 02:46 . 2014-07-02 08:49 15368704 ----a-w- c:\windows\system32\ieframe.dll
2014-05-24 02:45 . 2014-07-02 08:49 281600 ----a-w- c:\windows\system32\dxtrans.dll
2014-05-24 02:45 . 2014-07-02 08:49 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2014-05-24 02:45 . 2014-07-02 08:49 1508864 ----a-w- c:\windows\system32\inetcpl.cpl
2014-05-24 01:26 . 2014-07-02 08:49 1766400 ----a-w- c:\windows\SysWow64\wininet.dll
2014-05-24 01:26 . 2014-07-02 08:49 44032 ----a-w- c:\windows\SysWow64\UXInit.dll
2014-05-24 01:25 . 2014-07-02 08:48 2862080 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-05-24 01:25 . 2014-07-02 08:49 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-05-24 01:25 . 2014-07-02 08:49 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-05-24 01:25 . 2014-07-02 08:49 1440768 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-05-24 01:09 . 2014-07-02 08:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-24 01:03 . 2014-07-02 08:49 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-23 22:37 . 2014-07-02 08:49 534528 ----a-w- c:\windows\SysWow64\uxtheme.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TPUReg"="c:\program files (x86)\TOSHIBA\Password Utility\TosPU.exe" [2012-10-31 7148032]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-01 4085896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
2;3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
R1 iSafeNetFilter;iSafeNetFilter NDIS Driver;c:\program files (x86)\iSafe\iSafeNetFilter.sys;c:\program files (x86)\iSafe\iSafeNetFilter.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 iSafeKrnlBoot;iSafeKrnl Boot Driver;c:\windows\system32\DRIVERS\iSafeKrnlBoot.sys;c:\windows\SYSNATIVE\DRIVERS\iSafeKrnlBoot.sys [x]
R3 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E – ovladač síťové karty;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
R3 TemproMonitoringService;TEMPRO Service;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\System32\drivers\tos_sps64.sys;c:\windows\SYSNATIVE\drivers\tos_sps64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 iSafeKrnl;iSafeKrnl;c:\program files (x86)\iSafe\iSafeKrnl.sys;c:\program files (x86)\iSafe\iSafeKrnl.sys [x]
S1 iSafeKrnlKit;iSafeKrnl Kit Driver;c:\program files (x86)\iSafe\iSafeKrnlKit.sys;c:\program files (x86)\iSafe\iSafeKrnlKit.sys [x]
S1 iSafeKrnlR3;iSafeKrnl Ring3 Driver;c:\program files (x86)\iSafe\iSafeKrnlR3.sys;c:\program files (x86)\iSafe\iSafeKrnlR3.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 GFNEXSrv;GFNEX Service;c:\program files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe;c:\program files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 iSafeService;iSafeService;c:\program files (x86)\iSafe\iSafeSvc.exe;c:\program files (x86)\iSafe\iSafeSvc.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 PEGAGFN;PEGAGFN;c:\program files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys;c:\program files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\Teco\TecoService.exe;c:\program files\TOSHIBA\Teco\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
S3 RtkBtFilter;Realtek Bluetooth Filter Driver;c:\windows\system32\DRIVERS\RtkBtfilter.sys;c:\windows\SYSNATIVE\DRIVERS\RtkBtfilter.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-27 17:56]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-01 17:46 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-08 398656]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-09-25 13196432]
"TCrdMain"="c:\program files (x86)\TOSHIBA\Hotkey\TCrdMain_Win8.exe" [BU]
"TODDMain"="c:\program files (x86)\TOSHIBA\System Setting\TODDMain.exe" [2012-08-04 213136]
"TecoResident"="c:\program files\TOSHIBA\Teco\TecoResident.exe" [2012-08-14 169896]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"SRS Premium Sound HD"="c:\program files\SRS Labs\SRS Control Panel\SRSPanel_64.exe" [2012-08-20 2170784]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
uDefault_Page_URL = about:blank
mDefault_Page_URL = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.10.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
AddRemove-Malwarebytes Anti-Malware_is1 - c:\program files (x86)\Malwarebytes Anti-Malware\unins000.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\iSafe\iSafeSvc2.exe
c:\program files\AVAST Software\Avast\setup\instup.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\iSafe\iSafeTray.exe
.
**************************************************************************
.
Celkový čas: 2014-08-11 23:22:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-08-11 21:22
ComboFix2.txt 2014-08-11 08:54
.
Před spuštěním: 433 671 421 952 bytes free
Po spuštění: 433 210 519 552 bytes free
.

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 11 srp 2014 23:59

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:58:01, on 11. 8. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16921)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\iSafe\iSafeTray.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Evgenija\Downloads\HiJackThis.exe
C:\WINDOWS\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ?????????? ???????? - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - C:\Program Files (x86)\Yandex\FastDial\fastdialHost.dll (file missing)
O3 - Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
O4 - HKLM\..\Run: [TPUReg] "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\iSafe\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TEMPRO Service (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6885 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod jaro3 » 12 srp 2014 09:59

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\windows\SysWow64\Drivers\atapi.sys

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

evgeniya
nováček
Příspěvky: 20
Registrován: srpen 14
Pohlaví: Žena
Stav:
Offline

Re: kontrola logu

Příspěvekod evgeniya » 12 srp 2014 15:00

dobrý den

ačkoliv jsem postupovala podle návodu, atapi.sys nemohu objevit


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 107 hostů