jsn.donecore.net Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 28 lis 2013 14:55

a tady je ten poslední log z malware bytes
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.28.06

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16736
uzivatel :: RF-NB [administrátor]

28. 11. 2013 14:49:21
MBAM-log-2013-11-28 (14-53-36).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 227721
Uplynulý čas: 3 minut, 28 sekund

Nalezené procesy v paměti: 1
C:\ProgramData\eSafe\eGdpSvc.exe (PUP.Optional.Wsys.A) -> 1516 -> Nebyla provedena žádná instrukce.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 17
HKLM\SYSTEM\CurrentControlSet\Services\WsysSvc (PUP.Optional.Wsys.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{0113A098-06EA-4776-A011-D75590778F1E} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\qvo6Software (PUP.Optional.qvo6.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 1
HKLM\SYSTEM\CurrentControlSet\Services\WsysSvc|ImagePath (PUP.Optional.Esafe.A) -> Data: C:\ProgramData\eSafe\eGdpSvc.exe -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 5
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Špatný: (http://www.qvo6.com/?utm_source=b&utm_m ... 1377736260) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Špatný: (http://www.qvo6.com/?utm_source=b&utm_m ... 1377736260) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Špatný: (http://www.qvo6.com/?utm_source=b&utm_m ... 1377736260) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Špatný: (http://www.qvo6.com/?utm_source=b&utm_m ... 1377736260) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Špatný: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Dobrý: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Nebyla provedena žádná instrukce.

Nalezené složky: 26
C:\Users\uzivatel\AppData\Roaming\Desk 365 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\1 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\3 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\35 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\36 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\39 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\4 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\41 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\42 (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\components (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\sysicons (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123 (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ch (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome\content (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ie (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 103
C:\ProgramData\eSafe\eGdpSvc.exe (PUP.Optional.Wsys.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ie\BetterSurf.dll (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\components\component_libcef_1.1364.1123.exe (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\Downloads\iLividSetup-r1235-n-bc.exe (PUP.Optional.Bandoo) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote.xml (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\accelerate (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg_list.xml (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_list.xml (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_settings.ini (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\process_mgr.xml (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\1\angrybirds.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\1\angrybirds.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\3\BigFarm.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\3\BigFarm.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\35\Gmail.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\35\Gmail.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\36\Outlook.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\36\Outlook.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\39\ESPN.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\39\ESPN.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\4\Empire.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\4\Empire.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\41\gcalendar.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\41\gcalendar.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\42\pulse.db (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\app\config\42\pulse.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_1.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_2.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_3.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_4.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_5.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_default.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\337_7c9140b13c049fd26989f7fa25b77cb1_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\angrybirds_00ff92c12703baaf0130d6aec427d047_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Barbie_00a67ff4ef657679a6c88553135d62ad_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\BigFarm_de933b0e5218a4db24bebe3d55ed3558_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\chrome_184cd382546b8c4b4b869b6e7b4749be.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\chrome_184cd382546b8c4b4b869b6e7b4749be_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Empire_22b42f57d1c467841280810e218d5510_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\ESPN_a7b078f5f5f5b87efcef66ab5783cf9d_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Facebook_aab07bc79cf599b25c0110f32d46a3ef_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\gcalendar_50b3e3c5fc202f0cfcae8032b2465c1b_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Gmail_731b6d011bd9f67463a916a496775935_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Google_60d75cb277f0c452fa60dba8350caf65_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\GotClip_50a61dc7c7b08cd8355ed2a78f4f315e.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\GotClip_50a61dc7c7b08cd8355ed2a78f4f315e_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\iexplore_866f9b5d10d931b638c5c4af0c0ad78a.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\iexplore_866f9b5d10d931b638c5c4af0c0ad78a_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Mario_52934d81761dc31187a93a3a0be7fecc_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Outlook_6f817b67fa6af1a9c8abfa3813a8595c_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\pulse_b5a242da04cc06eacd02b1ca41e3583c_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_computer_20_20.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_computer_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_control_panel_20_20.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_control_panel_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_downloads_20_20.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_my_documents_20_20.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\sys_my_documents_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\icons\Youtube_bf18fdfc4aefd6417a8bacae4be5b415_48_48.png (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\337.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\337_7c9140b13c049fd26989f7fa25b77cb1.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\barbie.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Barbie_00a67ff4ef657679a6c88553135d62ad.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\facebook.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Facebook_aab07bc79cf599b25c0110f32d46a3ef.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\GameCenter.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\google.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Google_60d75cb277f0c452fa60dba8350caf65.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\mario.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Mario_52934d81761dc31187a93a3a0be7fecc.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\twitter.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\v9.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\youtube.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\promote\Youtube_bf18fdfc4aefd6417a8bacae4be5b415.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\sysicons\43226148c94eba7657ae76bf9e5aa27f_21.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\sysicons\b28cd8d8c9f06649c429f11dcf563c9f_104.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\sysicons\b28cd8d8c9f06649c429f11dcf563c9f_107.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\sysicons\b28cd8d8c9f06649c429f11dcf563c9f_175.ico (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r0.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r1.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r2.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r3.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r4.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r5.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r6.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r7.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r8.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Users\uzivatel\AppData\Roaming\Desk 365\wp\r9.jpg (PUP.Optional.Desk365.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\icudt.dll (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\libcef.dll (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales\en-US.pak (PUP.Optional.337Technologies.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ch\Chrome.crx (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\BetterSurf.xpi (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\build.cmd (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome.manifest (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\install.rdf (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome\content\firefox.js (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome\content\inject.js (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\BetterSurf\ff\chrome\content\overlay.xul (PUP.Optional.BetterSurf) -> Nebyla provedena žádná instrukce.

(konec)

jinak uz mam vše hotové udělal jsem i ten atf cleaner i když používam google chrome

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod jaro3 » 29 lis 2013 11:40

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 29 lis 2013 14:20

v tomADW jsem vymazat clean nenašel , mam w8 a spustil jsem jako správce

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 29 lis 2013 15:07

nakonec se mi to nějak podařilo tady je prozatím ten adw
# AdwCleaner v3.013 - Report created 29/11/2013 at 15:01:36
# Updated 24/11/2013 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : uzivatel - RF-NB
# Running from : C:\Users\uzivatel\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : WsysSvc

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\eSafe
Folder Deleted : C:\Program Files (x86)\BetterSurf
Folder Deleted : C:\Program Files (x86)\Common Files\337
Folder Deleted : C:\Users\uzivatel\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\uzivatel\AppData\Roaming\Desk 365
File Deleted : C:\windows\Tasks\AmiUpdXp.job
File Deleted : C:\windows\System32\Tasks\AmiUpdXp
File Deleted : C:\windows\System32\Tasks\Desk 365 RunAsStdUser

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Shortcut Disinfected : C:\Users\uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Handy Updater]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\BI
Key Deleted : HKLM\Software\delta-homesSoftware
Key Deleted : HKLM\Software\Desksvc
Key Deleted : HKLM\Software\eSafeSecControl
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\qvo6Software
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16537

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v31.0.1650.57

[ File : C:\Users\uzivatel\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [7404 octets] - [28/11/2013 14:43:24]
AdwCleaner[R1].txt - [7352 octets] - [29/11/2013 14:58:05]
AdwCleaner[S0].txt - [5359 octets] - [29/11/2013 15:01:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5419 octets] ##########

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 29 lis 2013 15:19

tady máme log z JRT ale příde mi prázdný
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8 x64
Ran by uzivatel on p  29. 11. 2013 at 15:10:04,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\windows\syswow64\ai_recyclebin"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  29. 11. 2013 at 15:17:59,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 29 lis 2013 15:32

tady je log z mbam
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.28.06

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16736
uzivatel :: RF-NB [administrátor]

29. 11. 2013 15:21:14
mbam-log-2013-11-29 (15-21-14).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 228016
Uplynulý čas: 4 minut, 28 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
C:\Users\uzivatel\Downloads\iLividSetup-r1235-n-bc.exe (PUP.Optional.Bandoo) -> Přesun do karantény a smazání se zdařilo.

(konec)

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 29 lis 2013 15:39

a tady je poslední log z roguekiller
RogueKiller V8.7.9 _x64_ [Nov 25 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Kontrola -- Datum : 11/29/2013 15:37:40
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 89a120893187f2c5eea90c97701d04ac
[BSP] 5feb4771526c4bdd304665065adc97d3 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_11292013_153740.txt >>

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod Žbeky » 29 lis 2013 18:19

Zavři všechny programy a prohlížeče.
Odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller (Pro Windows Vista nebo WIN7 klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status box zobrazuje "Scan" "
- Klikni na "Delete"
- Počkej, dokud status box zobrazuje "Smazání - Finished"
- Klikni na "Zprávy", zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [1].txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 01 pro 2013 18:31

omlouvam se o víkendu jsem nebyl doma ale už jsem to udělal takže tady je ten rogue killer
RogueKiller V8.7.9 _x64_ [Nov 25 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : uzivatel [Práva správce]
Mód : Odebrat -- Datum : 12/01/2013 18:30:07
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 89a120893187f2c5eea90c97701d04ac
[BSP] 5feb4771526c4bdd304665065adc97d3 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_12012013_183007.txt >>
RKreport[0]_S_11292013_153740.txt;RKreport[0]_S_12012013_182959.txt

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 01 pro 2013 18:44

ten z TDSS killeru se sem nevešel takže co mam delat, skoušel jsem ho dat jako přílohu ale napsalo to přípona txt není povolena

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod jaro3 » 01 pro 2013 20:39

Vlož sem do několika příspěvků.

+
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

fisik
Level 1
Level 1
Příspěvky: 65
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: jsn.donecore.net

Příspěvekod fisik » 02 pro 2013 15:31

tak jo tady je ten tdss killer první část
18:33:57.0164 0x13f4 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
18:33:57.0164 0x13f4 UEFI system
18:34:01.0086 0x13f4 ============================================================
18:34:01.0086 0x13f4 Current date / time: 2013/12/01 18:34:01.0086
18:34:01.0086 0x13f4 SystemInfo:
18:34:01.0086 0x13f4
18:34:01.0086 0x13f4 OS Version: 6.2.9200 ServicePack: 0.0
18:34:01.0086 0x13f4 Product type: Workstation
18:34:01.0086 0x13f4 ComputerName: RF-NB
18:34:01.0086 0x13f4 UserName: uzivatel
18:34:01.0086 0x13f4 Windows directory: C:\windows
18:34:01.0086 0x13f4 System windows directory: C:\windows
18:34:01.0086 0x13f4 Running under WOW64
18:34:01.0086 0x13f4 Processor architecture: Intel x64
18:34:01.0086 0x13f4 Number of processors: 4
18:34:01.0086 0x13f4 Page size: 0x1000
18:34:01.0086 0x13f4 Boot type: Normal boot
18:34:01.0086 0x13f4 ============================================================
18:34:02.0086 0x13f4 KLMD registered as C:\windows\system32\drivers\89508477.sys
18:34:02.0211 0x13f4 System UUID: {1EB837B7-5326-76F2-AB30-AEE276B1488D}
18:34:02.0555 0x13f4 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:34:02.0555 0x13f4 ============================================================
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0:
18:34:02.0555 0x13f4 GPT partitions:
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {76710F23-D213-46AA-A214-0B5BACE53E40}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {BF6088F7-ECA1-4651-8F8F-317B5E4ACED8}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {F8EE14E6-E3F3-4952-8100-9EAFA58CFDA1}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {F47982DB-864D-44C8-B8FB-72120387455C}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {F43AB1BC-2D05-4F1A-80AF-ED188D388E33}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x6E85C000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {D327CF7B-41AA-4B92-ACDD-D910FBEB4E96}, Name: Basic data partition, StartLBA 0x6ED06800, BlocksNum 0x3200000
18:34:02.0555 0x13f4 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {6A241E16-E4F8-42BC-97F2-117FEF19B79B}, Name: Basic data partition, StartLBA 0x71F06800, BlocksNum 0x2800000
18:34:02.0555 0x13f4 MBR partitions:
18:34:02.0555 0x13f4 ============================================================
18:34:02.0617 0x13f4 C: <-> \Device\Harddisk0\DR0\Partition5
18:34:02.0680 0x13f4 D: <-> \Device\Harddisk0\DR0\Partition6
18:34:02.0680 0x13f4 ============================================================
18:34:02.0680 0x13f4 Initialize success
18:34:02.0680 0x13f4 ============================================================
18:34:05.0336 0x0e14 ============================================================
18:34:05.0336 0x0e14 Scan started
18:34:05.0336 0x0e14 Mode: Manual;
18:34:05.0336 0x0e14 ============================================================
18:34:05.0336 0x0e14 KSN ping started
18:34:27.0665 0x0e14 KSN ping finished: true
18:34:28.0071 0x0e14 ================ Scan system memory ========================
18:34:28.0071 0x0e14 System memory - ok
18:34:28.0071 0x0e14 ================ Scan services =============================
18:34:28.0243 0x0e14 [ E890C46E4754F0DF51BAFCC8D2E07498, E620D03030F3B65442E0A5CB8B59016A6E8DB3BCA52741977B8897B34438E902 ] 1394ohci C:\windows\System32\drivers\1394ohci.sys
18:34:28.0243 0x0e14 1394ohci - ok
18:34:28.0259 0x0e14 [ 4F18D4C7EA14F11A7211F60D553C03DB, 09AB6D2D8E9B7B6D6A97708551C0E4B34538947A15EA2A69C11764D7BC0BB7F6 ] 3ware C:\windows\system32\drivers\3ware.sys
18:34:28.0259 0x0e14 3ware - ok
18:34:28.0275 0x0e14 [ 975AABEB243B800C23626D6B652C5A9C, FB02336F26AF10BA2A0D1B97C33CB1D78BB90CA51EF008A613A0274779798FAD ] ACPI C:\windows\system32\drivers\ACPI.sys
18:34:28.0290 0x0e14 ACPI - ok
18:34:28.0306 0x0e14 [ DC968C37822117E576B933F34A2D130C, 4C94E00ADC242296D7CBBFC7346D5F9AE5FE1B0C616ECA3BDE10A7B34FD2040B ] acpiex C:\windows\system32\Drivers\acpiex.sys
18:34:28.0306 0x0e14 acpiex - ok
18:34:28.0306 0x0e14 [ 0CA9F7C3A78227C21A0A7854E245CFB2, D54147C9C1EE2F0098B863B0852E027DB89D6FA67F6B7FD54F609D9715A11442 ] acpipagr C:\windows\System32\drivers\acpipagr.sys
18:34:28.0306 0x0e14 acpipagr - ok
18:34:28.0321 0x0e14 [ 8EB8DA03B142D3DD1EB9ED8107A76C43, 24B9B24F9A5BDF3AAD13C4EE0638497D9CA4A100096C6EAE403E0215EA89C439 ] AcpiPmi C:\windows\System32\drivers\acpipmi.sys
18:34:28.0321 0x0e14 AcpiPmi - ok
18:34:28.0321 0x0e14 [ CBCE725C5D86ABA7D2604E22951AA9B8, DE0440F0E943F057EBCD01DB4B1E12DBC241FBF03C42021306D322AB88FF8F21 ] acpitime C:\windows\System32\drivers\acpitime.sys
18:34:28.0321 0x0e14 acpitime - ok
18:34:28.0337 0x0e14 [ 3B42D95D20CD2AACDB0564471AE43ED7, BF49568D7060159F61D5F6DE7ECDECCCD1F920A2881544BA83CF420C822F6653 ] ACPIVPC C:\windows\System32\drivers\AcpiVpc.sys
18:34:28.0337 0x0e14 ACPIVPC - ok
18:34:28.0400 0x0e14 [ ADDA5E1951B90D3D23C56D3CF0622ADC, E85E7BFD29F00ED34BF5BE8BD4DA93CBB14278E16809BB55406875F0DA88551E ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
18:34:28.0400 0x0e14 AdobeARMservice - ok
18:34:28.0431 0x0e14 [ 93C6388592B99925C1D1576E465BC80F, 4C48BE5471DA4788357D71E90DFEA20FE320C7AAE1F4C55AFBE2E46FEA5CF8FB ] adp94xx C:\windows\system32\drivers\adp94xx.sys
18:34:28.0431 0x0e14 adp94xx - ok
18:34:28.0446 0x0e14 [ D27763E0247292654E7F7D16444C7C72, 0314C713D31E2B34F215B52F804F014D876E6ED92DC656CC3E27920CCD36CF0E ] adpahci C:\windows\system32\drivers\adpahci.sys
18:34:28.0446 0x0e14 adpahci - ok
18:34:28.0446 0x0e14 [ 67B90070FF48F794AF19F9FCF0080D75, 5D0D352606D58D2CA0814F38EF7B1774C030BE44353DF5910CBFAAF4FDE64ED6 ] adpu320 C:\windows\system32\drivers\adpu320.sys
18:34:28.0462 0x0e14 adpu320 - ok
18:34:28.0493 0x0e14 [ 974AE60BF5B90E31412D93596C968E5B, 092B59C2B67C4618E7B1800615D1DF7199482F60D0D27BD91763F7F8D7FC883F ] AeLookupSvc C:\windows\System32\aelupsvc.dll
18:34:28.0493 0x0e14 AeLookupSvc - ok
18:34:28.0525 0x0e14 [ 7C0E0EDF18D6CC565D7BFBB451709FA5, 47C21CD9D87B5C1B5EB14F6166B5E3349B1A6F10501E63CCED8D52A9FE22765D ] AFD C:\windows\system32\drivers\afd.sys
18:34:28.0525 0x0e14 AFD - ok
18:34:28.0556 0x0e14 [ 01590377A5AB19E792528C628A2A68F9, F3A4B6CA4E8D4436E44E36D7F7EEF3DC861D1EE50D41F4273226C4ED95674B84 ] agp440 C:\windows\system32\drivers\agp440.sys
18:34:28.0556 0x0e14 agp440 - ok
18:34:28.0571 0x0e14 [ D1BE8E6E5B3AF23A4393AF1BF867977A, B3AE97D35A9304198715D76F6C3F0545AA176FDEBA6C2055782558B11DFA14EB ] ALG C:\windows\System32\alg.exe
18:34:28.0571 0x0e14 ALG - ok
18:34:28.0603 0x0e14 [ 025E8C755BE293E50854D26D1BBE5133, 4373639689306A3D8FE0F862072711BAD5DBAA45E105CD3129586439A90EE070 ] AllUserInstallAgent C:\windows\system32\AUInstallAgent.dll
18:34:28.0603 0x0e14 AllUserInstallAgent - ok
18:34:28.0634 0x0e14 [ 5A81054B824004B1ECC04F0034A1CDF9, 73A1986A4B346C425157216EBF16CC90EFFC642EDF6109E6364CF0552E3388FD ] AmdK8 C:\windows\System32\drivers\amdk8.sys
18:34:28.0634 0x0e14 AmdK8 - ok
18:34:28.0650 0x0e14 [ B849D453E644FAB9BC8EF6DC8CA9C4C6, B803CDA478D3385937C44CBB05A0E65ABACEFEBA682975787C44E2904FB89D2D ] AmdPPM C:\windows\System32\drivers\amdppm.sys
18:34:28.0650 0x0e14 AmdPPM - ok
18:34:28.0681 0x0e14 [ 35A0EB5AECB0FA3C41A2FB514A562304, 737783ABF348288471AC7051D4DC6CB336D686C94EC7B8938DCA74AFE9BECB1C ] amdsata C:\windows\system32\drivers\amdsata.sys
18:34:28.0681 0x0e14 amdsata - ok
18:34:28.0696 0x0e14 [ 00452671904F5EE94B50BF0219C97164, 99F9B86D3DB3E10B014120A63CD43CBAAB22C8E38851090ABE37D89ABD61F7B6 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
18:34:28.0696 0x0e14 amdsbs - ok
18:34:28.0712 0x0e14 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7, DC0B8B798720F5F75F8AFD3383CF69194282AEEE84DCACB97382F4C86E1D3E49 ] amdxata C:\windows\system32\drivers\amdxata.sys
18:34:28.0712 0x0e14 amdxata - ok
18:34:28.0712 0x0e14 [ 83B3682CE922FB0F415734B26D9D6233, 9102E8B410BB1AE426770896B6AB584D1F02830337FBB2DEC182F3F19832F35F ] AppID C:\windows\system32\drivers\appid.sys
18:34:28.0712 0x0e14 AppID - ok
18:34:28.0728 0x0e14 [ CE2BEAD7F31816FF0AC490D048C969F9, 7D24C5A9E8F7C21CC6D8BF2CA29A8B79DDE7EEDE2F37D36B9071ECE1CF61371F ] AppIDSvc C:\windows\System32\appidsvc.dll
18:34:28.0728 0x0e14 AppIDSvc - ok
18:34:28.0759 0x0e14 [ 4F750B7EFCB6520AE01E01D082D7D476, AD2A67D727A1D4DD0BBACC6B4BB432FA9A14D50D8BA292B95A4747CEC9F85728 ] Appinfo C:\windows\System32\appinfo.dll
18:34:28.0759 0x0e14 Appinfo - ok
18:34:28.0759 0x0e14 [ E933401B392387F4BE34DE8BAF1722A7, 57CC6DE31E2C82D2B12509F0A5EC9EC70DD2EF6A1F31A66ADF62DC6AE0A67323 ] arc C:\windows\system32\drivers\arc.sys
18:34:28.0775 0x0e14 arc - ok
18:34:28.0775 0x0e14 [ 07CA323EF2E8247A568AB0F3662AD644, 1224B41193F0E9B164732BA5BF707A13427C82C1D8C3EDC2AAE5C5C75454B9F6 ] arcsas C:\windows\system32\drivers\arcsas.sys
18:34:28.0790 0x0e14 arcsas - ok
18:34:28.0853 0x0e14 [ 9F34AA1124EEA112E49E48258B1D6394, F8648E5EDD7DDFE8D0F5F410E90D0713381A5DB0980D4F0D13D6A5B1F9F4E9A6 ] aswFsBlk C:\windows\system32\drivers\aswFsBlk.sys
18:34:28.0853 0x0e14 aswFsBlk - ok
18:34:28.0884 0x0e14 [ 5C49AB607897C94E123EC8364FF4BF61, 77F69B00DDE1433C115AA617E0063CB93EE29B3E8D168EF2497E31DD573D5A13 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
18:34:28.0884 0x0e14 aswMonFlt - ok
18:34:28.0931 0x0e14 [ 679712B7A353EE665B9301592164A172, CA3C918106A355BAFD0833BB493DF2CCBC2D0F90CA7EBF5E27CC088C7170B0E0 ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
18:34:28.0946 0x0e14 aswRdr - ok
18:34:28.0962 0x0e14 [ C04F7B373881009D7994D9BF55D24AB4, 5DEEA804F4F9862024F40A204E88DBCFFBDD2DC87CA86145E3FB649CFCCDC624 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
18:34:28.0978 0x0e14 aswRvrt - ok
18:34:29.0025 0x0e14 [ 1BA60C77EB3CDB6129DAD25BAF675F43, 1D5BB6B427E065494C8A363996974048C890F9DBBEEF305B7034873696DFD969 ] aswSnx C:\windows\system32\drivers\aswSnx.sys
18:34:29.0040 0x0e14 aswSnx - ok
18:34:29.0087 0x0e14 [ 79ADA401A6E2054F110E7FBDFAC71942, 0E551FB9E5FE598900036E872E16EB407F7F63FD7A8A0AFAB5094D9DFA75CFCF ] aswSP C:\windows\system32\drivers\aswSP.sys
18:34:29.0087 0x0e14 aswSP - ok
18:34:29.0118 0x0e14 [ 59787B95DD9CA44CB139D96863438587, C36E1A812931BBEACE38BF1E621C950439144979E31961C016AD1AE323579058 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
18:34:29.0118 0x0e14 aswVmm - ok
18:34:29.0134 0x0e14 [ 74DBAEC35366C4EE7670428808715A6A, 3B3A7A81CD8038C4750560B94A9247C4409410780B312BA71EDF2E393DCA7474 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
18:34:29.0134 0x0e14 AsyncMac - ok
18:34:29.0150 0x0e14 [ A721FF570C2387E383BDDEA9632863C9, 45DD7787F44A2C742560FEB03AB66910C2F0002D95BB02C55EEDE973AA92AD24 ] atapi C:\windows\system32\drivers\atapi.sys
18:34:29.0150 0x0e14 atapi - ok
18:34:29.0181 0x0e14 [ BCD7A47EF587DC00DD61D12D9C2D1E44, 95BC9AC8BA8A86DB5C7A6317002BD9872F193B401A0C58DF252DCF3D4A7541E2 ] AudioEndpointBuilder C:\windows\System32\AudioEndpointBuilder.dll
18:34:29.0196 0x0e14 AudioEndpointBuilder - ok
18:34:29.0228 0x0e14 [ 599B3F685A263A114FFAF3BE29C49C75, 579E9561BA8537888E061E303F3F89E2E6F8B8DED74369C3767DB10B35CD45E8 ] Audiosrv C:\windows\System32\Audiosrv.dll
18:34:29.0243 0x0e14 Audiosrv - ok
18:34:29.0306 0x0e14 [ 4D41D30E2FAB3307967C7A0B045DC874, 620482D08544478862C78285E17DEE9BC3466DF8B62BD502B0C17AE6501D2B5E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:34:29.0306 0x0e14 avast! Antivirus - ok
18:34:29.0337 0x0e14 [ 89491EF71D5EA011127832C588002853, 05620E4235956D8446FB9604F930738C8AA97E3A74C907E37F7CC08B8EDA0461 ] AxInstSV C:\windows\System32\AxInstSV.dll
18:34:29.0337 0x0e14 AxInstSV - ok
18:34:29.0368 0x0e14 [ 87AB5BB072A3F128541D5B815F82FFDD, 186AF33D3DE90638C3E165CAC3DA17295E8A80CDB523F9BE4AF7D38CA6954905 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
18:34:29.0368 0x0e14 b06bdrv - ok
18:34:29.0400 0x0e14 [ 81703BC5D68DEDBB086C2368FBE7B334, CFD4A55C8045C482F8D410514F3211AEFA00097AB395F5A04BFE983ED6254F6B ] BasicDisplay C:\windows\System32\drivers\BasicDisplay.sys
18:34:29.0400 0x0e14 BasicDisplay - ok
18:34:29.0415 0x0e14 [ 5EC68164E14D25675C98BBB5F09E8606, 1D7EDB21C87039FC5F39F46460AD852BC4EC6B179B1C205D189DD3C397343435 ] BasicRender C:\windows\System32\drivers\BasicRender.sys
18:34:29.0415 0x0e14 BasicRender - ok
18:34:29.0446 0x0e14 [ 656B7660FB8FD2D3D015172486A2DB04, CF2F71EAE9413346F509E4C8D25199C040485CEBDD7AD3967889D9CE06479881 ] bcbtums C:\windows\system32\drivers\bcbtums.sys
18:34:29.0446 0x0e14 bcbtums - ok
18:34:29.0650 0x0e14 [ 73D175B291DDE56AE609BA1422E236CC, F483B2C276014690D939BFC8934C63488CEA7DEB1C70C1A7D36A99A584A8307B ] BCM43XX C:\windows\system32\DRIVERS\bcmwl63a.sys
18:34:29.0743 0x0e14 BCM43XX - ok
18:34:29.0821 0x0e14 [ 47F0FE026652F601F367ECE2DFFCFC40, 93986523D33FEF323727A15BF5FB7BA7472CEBC1E185917897AF212E4EA9302D ] BcmBtRSupport C:\windows\system32\BtwRSupportService.exe
18:34:29.0853 0x0e14 BcmBtRSupport - ok
18:34:29.0900 0x0e14 [ 89143A7BA7850F5C7E61B43BB44B6418, 00BB781DF87D4FF1BAFD318AFE237296B4F5925023BA4486405EC0A384C88D8F ] BDESVC C:\windows\System32\bdesvc.dll
18:34:29.0900 0x0e14 BDESVC - ok
18:34:29.0931 0x0e14 [ 9E7AEA59776D904607985AFFE7E5E183, C3DB745A9F4DA7CB9628A7913DD52B2444B14FEB9D588FF6558CF52CEB8955EB ] Beep C:\windows\system32\drivers\Beep.sys
18:34:29.0931 0x0e14 Beep - ok
18:34:29.0978 0x0e14 [ 53AA55632B94622F2DC3695E86EF9363, 9B5BB8EDA48A37AE97BCD42D83B25A6D10AA6231EABE745DCCE6D60E19094A6F ] BFE C:\windows\System32\bfe.dll
18:34:29.0993 0x0e14 BFE - ok
18:34:30.0040 0x0e14 [ D598C44A7072D3108D8D8102EC5E07F7, D7472E9BAAB7B6E1D30F4E153412E2A16EE5C08DE2BF8BFF4D65089825226FE0 ] BITS C:\windows\System32\qmgr.dll
18:34:30.0056 0x0e14 BITS - ok
18:34:30.0056 0x0e14 [ B17AC10B47C7FCB44D22A1F06415840E, 990D6F629D93F4F913D218ACE5187A26DCB762BAFB2BB279CCE8CAF2755D85A5 ] bowser C:\windows\system32\DRIVERS\bowser.sys
18:34:30.0071 0x0e14 bowser - ok
18:34:30.0103 0x0e14 [ 038FA1B55531E7020DB705B42FCCE373, 023E87E3204D64890D6FEA78E762E5BC5BD0A59325EBC264834727779EEEDBC5 ] BrokerInfrastructure C:\windows\System32\bisrv.dll
18:34:30.0103 0x0e14 BrokerInfrastructure - ok
18:34:30.0150 0x0e14 [ 310068BDA80B1D55C36580FD8A873FAF, A75412FF1F483461F526E9A359DCEECA5E683441514464D5ED82D1A9740D583E ] Browser C:\windows\System32\browser.dll
18:34:30.0150 0x0e14 Browser - ok
18:34:30.0181 0x0e14 [ 6695200F455E251F0BCC9CE4D0978D59, 4DB2F967E449581A9330EF43E794B45B93581564B20C5B991FC1EC665A640D69 ] BthAvrcpTg C:\windows\System32\drivers\BthAvrcpTg.sys
18:34:30.0181 0x0e14 BthAvrcpTg - ok
18:34:30.0196 0x0e14 [ A8B20D852B07AE19A13B5D47EC4E4C3B, 86571C9E2BA15BB169CAB2D24C4D0598154C02FD173638CAFC685A7F6B09472D ] BthEnum C:\windows\System32\drivers\BthEnum.sys
18:34:30.0196 0x0e14 BthEnum - ok
18:34:30.0228 0x0e14 [ 616EB8748C988AEE98D93DA141C3D3B4, 15A055B0496BDB29CBCF6EEBF112D4BA1C7A2FF39124728830D0FD1FD7A404CB ] BthHFEnum C:\windows\System32\drivers\bthhfenum.sys
18:34:30.0228 0x0e14 BthHFEnum - ok
18:34:30.0259 0x0e14 [ DCB4EBD928A6FB368BE6CAE522412DE1, 9E1345F29467054689B9F48B5CCB567760D36610A4EA9AF41B829EAD60347269 ] bthhfhid C:\windows\System32\drivers\BthHFHid.sys
18:34:30.0259 0x0e14 bthhfhid - ok
18:34:30.0275 0x0e14 [ 42201C346F0B8C458E1E9CDE04D68A2C, 6168FD0D10CD06B00B5C79D5D2B5C353AAC22FD99CE8D417DDBA33ED63CFB8BF ] BthLEEnum C:\windows\system32\DRIVERS\BthLEEnum.sys
18:34:30.0275 0x0e14 BthLEEnum - ok
18:34:30.0290 0x0e14 [ 033916CE8784A848B9A3D686B7F66D97, B4D0514D59646CF6B70D4FA488CF95C38EA38CC5C509329CC8753E897C640AFA ] BTHMODEM C:\windows\System32\drivers\bthmodem.sys
18:34:30.0290 0x0e14 BTHMODEM - ok
18:34:30.0290 0x0e14 [ 091BB978E9504D0AD14586929431A957, ACED02B879026A228E35F40847C210BC30A5AFC948FFE922DB21663E4A8DFF1D ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
18:34:30.0290 0x0e14 BthPan - ok
18:34:30.0337 0x0e14 [ 13795CAA34239D97A7211E7F9D96E012, C4F3402B063A7CFCE386D1AE9255975A199164BA9E7DCDB6129725213A0642B1 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
18:34:30.0353 0x0e14 BTHPORT - ok
18:34:30.0384 0x0e14 [ A4387C3D271959313E2577DB7BE8BA7A, C71474802102102EBE04DF036EEB2F5FB3380BE288E3842F19F234EFAE977D70 ] bthserv C:\windows\system32\bthserv.dll
18:34:30.0384 0x0e14 bthserv - ok
18:34:30.0400 0x0e14 [ 1F715957F5236D30B6020A19A4271F6A, C06B637C2C6919E2DE1055AE249AE3EAF7B4890799F22BF5757CC10CEF145043 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
18:34:30.0400 0x0e14 BTHUSB - ok
18:34:30.0415 0x0e14 [ 183E8A570E03F14C357F0948D2F5E2FE, 6DA6D837EFBFB8C825D58E7B4346FEF4D573261F7D6984BD789027C236D656CA ] btwampfl C:\windows\system32\drivers\btwampfl.sys
18:34:30.0431 0x0e14 btwampfl - ok
18:34:30.0431 0x0e14 [ 187686608DF41BE0E436FBF3F88986CC, 3CD6E3641E01DF2F580AA15E35C19FD7E02D78DCFA273B91A877E0F0B03C08FD ] btwaudio C:\windows\system32\drivers\btwaudio.sys
18:34:30.0446 0x0e14 btwaudio - ok
18:34:30.0462 0x0e14 [ B68927792C57BD730308230BB9A5D070, 767F3FCB3141E1DC8744156DF03EAB3D43D37A7E5D325BA2C5FB807137593D69 ] btwavdt C:\windows\system32\drivers\btwavdt.sys
18:34:30.0462 0x0e14 btwavdt - ok
18:34:30.0525 0x0e14 [ 848250AC2A5E0378A02708C5FFC148B6, A57300AB7F8311A9A268B770EEE7FFD3D72975F970CDEFC5B0CFDB4437284C95 ] btwdins C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
18:34:30.0540 0x0e14 btwdins - ok
18:34:30.0556 0x0e14 [ C3C8974D99F976C927165363855690CD, 2B73E11FE341DE581CFF655E58C5671B83F4331529C30DADCAA9B6BE615D5E1F ] btwl2cap C:\windows\system32\DRIVERS\btwl2cap.sys
18:34:30.0556 0x0e14 btwl2cap - ok
18:34:30.0556 0x0e14 [ 7BBD1461FBE22E68668C70891512E9AB, 349DF69F97614A467CCFAF8BE20D3F73CC91BEA10A00B5E13685B84ED890455B ] btwrchid C:\windows\System32\drivers\btwrchid.sys
18:34:30.0556 0x0e14 btwrchid - ok
18:34:30.0572 0x0e14 [ 990B1BABE6E81FB18E65A87EBEFB1772, 1820D4AC57E1D4B7FB5AA89C277B16910ED73712878D2B43FE542CE16DFE16C3 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
18:34:30.0572 0x0e14 cdfs - ok
18:34:30.0603 0x0e14 [ 339BFF85D788268752DA8C9644B188EE, C2279F1A39AED39865A5027D2FD087F8E82F3ED8C94BA4D922855B98E792AFC5 ] cdrom C:\windows\System32\drivers\cdrom.sys
18:34:30.0603 0x0e14 cdrom - ok
18:34:30.0650 0x0e14 [ BAF8F0F55BC300E5F882E521F054E345, FB228DB18F2FA55D8BA35A7E6778EE5D2EB0C29D384F1A0A868F90AE706188D7 ] CertPropSvc C:\windows\System32\certprop.dll
18:34:30.0650 0x0e14 CertPropSvc - ok
18:34:30.0650 0x0e14 [ F64B7D1A37CC1D5F421D5359EEC81E2E, 2B4879DD32B2C20B94847755E22B1BCBE2B567B3989C57A9BA2DD783307EFFDB ] circlass C:\windows\System32\drivers\circlass.sys
18:34:30.0650 0x0e14 circlass - ok
18:34:30.0681 0x0e14 [ 9905168708DB68849B879B5548F68AB3, B7A495E57B9398704988DC472126CBC5B8D76761A34F51732FBF6CC88E3AB79A ] CLFS C:\windows\system32\drivers\CLFS.sys
18:34:30.0681 0x0e14 CLFS - ok
18:34:30.0697 0x0e14 [ 2DC8538A2260647484A6C921CA837313, 094059DD66B0C50A1CAE288F920107B0B6AD1AA5758284E35B92C131EDEA30EA ] CmBatt C:\windows\System32\drivers\CmBatt.sys
18:34:30.0697 0x0e14 CmBatt - ok
18:34:30.0728 0x0e14 [ E708BFF0473EC6B271EA46B65B16CA56, 2B4C661F7C5A4395CA4204122A1C3C8AA766B56C3D01CD8BAAFA18F71FC7B591 ] CNG C:\windows\system32\Drivers\cng.sys
18:34:30.0728 0x0e14 CNG - ok
18:34:30.0790 0x0e14 [ 1F925AA990A6A446E8BA926B2D0A5201, F278C272E3F40C37D04935CE19938C4B63A4BC2AA378D0F56C32FE78308D6993 ] CnxtHdAudService C:\windows\system32\drivers\CHDRT64.sys
18:34:30.0806 0x0e14 CnxtHdAudService - ok
18:34:30.0837 0x0e14 [ 0E5B1E9E7122EDAAF1F6CE047965CA92, 803E585B92D1E2E5B6BF67BE511E88DC2629A12407C3E30F7AEFB544D390A9B8 ] CompositeBus C:\windows\System32\drivers\CompositeBus.sys
18:34:30.0837 0x0e14 CompositeBus - ok
18:34:30.0837 0x0e14 COMSysApp - ok
18:34:30.0853 0x0e14 [ D9CB0782AF819548072AA45B70F8B22D, 04796F39ABB88759A534DE3D0C51F684BF2A8DE1F4028B657CCFDBDD39A6618C ] condrv C:\windows\system32\drivers\condrv.sys
18:34:30.0853 0x0e14 condrv - ok
18:34:30.0900 0x0e14 [ 243F52663EC3485F73B836DFFAD17AA4, C856FFC3648309AEB7F688558D7EBF518846C8030CE639FBEF2ED77E3C95286B ] cphs C:\windows\SysWow64\IntelCpHeciSvc.exe
18:34:30.0915 0x0e14 cphs - ok
18:34:30.0947 0x0e14 [ 5CE2742F063731EC10C1B2EE386A2C08, 309919BDDD4649AFB95A99DCF8AFC3BAE10F9BC1E2819C0794CFD0F80682C223 ] CryptSvc C:\windows\system32\cryptsvc.dll
18:34:30.0947 0x0e14 CryptSvc - ok
18:34:30.0978 0x0e14 [ 48AED45DF009081AF3F5144F7D624674, 4425C15EB9E1177EE5134A33F63DAF7FF876577946DBF1EAD92C5614025113BB ] CxAudMsg C:\windows\system32\CxAudMsg64.exe
18:34:30.0978 0x0e14 CxAudMsg - ok
18:34:31.0009 0x0e14 [ FAEF4C245BE832DB41B15DAAC336AFB7, 1F8C98AB0DF4327FCB01FE0356025488E19B48A45FFFA50576B49A8587FAC42B ] dam C:\windows\system32\drivers\dam.sys
18:34:31.0009 0x0e14 dam - ok
18:34:31.0040 0x0e14 [ 1EC6E533C954BDDF2A37E7851A7E58FD, C25936A7465B6A2B3D05D2FCB09D91ACC07CFE038A5E968C99CFA9D9F2967DD4 ] DcomLaunch C:\windows\system32\rpcss.dll
18:34:31.0056 0x0e14 DcomLaunch - ok
18:34:31.0087 0x0e14 [ C8650D1F61149AA546BDBC99172EBBC1, D9592ED1B6F23B6EC76A0B93635B6E38702311B0A6982F0F9DEC37FCDAF1288B ] defragsvc C:\windows\System32\defragsvc.dll
18:34:31.0087 0x0e14 defragsvc - ok
18:34:31.0118 0x0e14 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16, ADAC7FD6AC12B50F4998C5EB0BD770DD4B80A94C4CC1B9376AD77648E48D012D ] DeviceAssociationService C:\windows\system32\das.dll
18:34:31.0118 0x0e14 DeviceAssociationService - ok
18:34:31.0150 0x0e14 [ 799BE46D45D486704CE0F37CA5385262, BB78DEE83B9DB613B1C083D55FAA458BE3E394AED80EB91B599185A7272F33B3 ] DeviceInstall C:\windows\system32\umpnpmgr.dll
18:34:31.0165 0x0e14 DeviceInstall - ok
18:34:31.0181 0x0e14 [ 09D9EB9E7898F8E6561473A20CC808B9, 0F511593D36084843E5138AF6D55FE08D77803968AE12A236A02368DB364347E ] Dfsc C:\windows\system32\Drivers\dfsc.sys
18:34:31.0181 0x0e14 Dfsc - ok
18:34:31.0228 0x0e14 [ 9E0E72222264745ADEB0E5AC680B0ED6, 576AFC8741695396A3B8E9DBDD3703E9D70370437D09D162262E47A140D101B4 ] Dhcp C:\windows\system32\dhcpcore.dll
18:34:31.0228 0x0e14 Dhcp - ok
18:34:31.0243 0x0e14 [ 3C736FAE17BA6F91BA37594AAB139CD0, 34304A194105B19E7ADD80108DC85C3B7AA9E942C84A7EF93C475CE1D9AE4615 ] discache C:\windows\system32\drivers\discache.sys
18:34:31.0243 0x0e14 discache - ok
18:34:31.0243 0x0e14 [ 560495FF4CA22E1D9B1972FA18F43B6F, 41FFDD4C1097AA857A8177E34F101A1A9C1429A4E8DEC3D395C6135A9E112CD6 ] disk C:\windows\system32\drivers\disk.sys
18:34:31.0243 0x0e14 disk - ok
18:34:31.0259 0x0e14 [ 82A7C72593793FE1EADA7A305BD1567A, 75F432E4C75AE9EFF553BD860B3B250853BDDA85C17DBD9B7242D74593506A86 ] dmvsc C:\windows\System32\drivers\dmvsc.sys
18:34:31.0259 0x0e14 dmvsc - ok
18:34:31.0290 0x0e14 [ 066B9710B36AB550E01EEFCA52155968, DCA9F3F4856A6866D3F5A2EEE34E96A83F40198DB0B5AC6381A7568DE1F56FAB ] Dnscache C:\windows\System32\dnsrslvr.dll
18:34:31.0290 0x0e14 Dnscache - ok
18:34:31.0306 0x0e14 [ 9949AD2ABA168A618D46C799D6CC898C, DFAC86A0AEE83C9EFE1BEE9EC15C8CAF1D619D55AF3ACC3986057A5AC985D06A ] dot3svc C:\windows\System32\dot3svc.dll
18:34:31.0322 0x0e14 dot3svc - ok
18:34:31.0337 0x0e14 [ 109FC3F80BF4F4DC5A071058074F13C1, F30736F45BA1811D59E9CB1C172D8D1EA9F5A7D36DCFFBFC9E7E02448C1CF851 ] DPS C:\windows\system32\dps.dll
18:34:31.0337 0x0e14 DPS - ok
18:34:31.0368 0x0e14 [ 9C7C183F937951AE17C5B8B3259CF3FF, 8ED607139F15D08B4835ACF864421BA4C08C88FE90B9AAF707F5D8514D7731B1 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
18:34:31.0368 0x0e14 drmkaud - ok
18:34:31.0384 0x0e14 [ F87F4AAAF6664906248D11D5E579A53B, F283932F68ED93891EEF00C18724359AB7057E922A3CDC8BC6F33F84D2B0BEE5 ] DsmSvc C:\windows\System32\DeviceSetupManager.dll
18:34:31.0384 0x0e14 DsmSvc - ok
18:34:31.0415 0x0e14 [ 6A0E850DDCB136AA3D2FB7234382DF12, C01863E95F45E1B74AC65C9CD12C8DC769299218255B3C94E3EBF58C4D79FEF3 ] dtsoftbus01 C:\windows\System32\drivers\dtsoftbus01.sys
18:34:31.0431 0x0e14 dtsoftbus01 - ok
18:34:31.0493 0x0e14 [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9, 3D348D3EFCA9C2AC25C3D0722FB8F64820936DEFD3926888740442972A0A8189 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
18:34:31.0525 0x0e14 DXGKrnl - ok
18:34:31.0556 0x0e14 [ 651FBD69A9713D623D456A240F96179C, 22A1F306B454EF9C84D25EF266F3ED0E1D896B1F5BE60170E79F37F2DBCA59F4 ] e1iexpress C:\windows\system32\DRIVERS\e1i63x64.sys
18:34:31.0556 0x0e14 e1iexpress - ok
18:34:31.0556 0x0e14 EagleX64 - ok
18:34:31.0587 0x0e14 [ 58BA473DD88F5FC1932282BA683AA03E, B8A4407D3006D91BE88F9C5389AC1CACC73BEBF6F66433A1E5EB8E58E8836C12 ] Eaphost C:\windows\System32\eapsvc.dll
18:34:31.0587 0x0e14 Eaphost - ok
18:34:31.0681 0x0e14 [ 5AB97B3282D7D6114949D1EB5C8598E4, FB9449CC1CDC12C12AA0469BB6ACC770CB011250EDFD86E9600E754610608EFD ] ebdrv C:\windows\system32\drivers\evbda.sys
18:34:31.0712 0x0e14 ebdrv - ok
18:34:31.0743 0x0e14 [ F702AB6181513303AB0FC8D59E52708B, D46939B9F672269E65C98606A573C849C4AF5A26E4E75D3A8FE56A65B3A6EA08 ] EFS C:\windows\System32\lsass.exe
18:34:31.0743 0x0e14 EFS - ok
18:34:31.0759 0x0e14 [ 66D60BD9A4C05616ABECA2A901475098, 8111550DB03FFD72F1822F47B16F075DA92874B64F19342D7CF60B0EE648AFEF ] EhStorClass C:\windows\system32\drivers\EhStorClass.sys
18:34:31.0759 0x0e14 EhStorClass - ok
18:34:31.0775 0x0e14 [ A61D0F543024E458C0FE32352E1978E2, BDE6BC140300EAF790F16466C28897CE0BD7D94DCED13FDE20AA4AACA0F6A4FD ] EhStorTcgDrv C:\windows\system32\drivers\EhStorTcgDrv.sys
18:34:31.0775 0x0e14 EhStorTcgDrv - ok
18:34:31.0790 0x0e14 [ D790D058D67582DB9C84C2D33695FE6B, A5763D7F6D191EA4B290B3E92D842AC36FD46DF598472E70B46E45D8CCD2F912 ] ErrDev C:\windows\System32\drivers\errdev.sys
18:34:31.0790 0x0e14 ErrDev - ok
18:34:31.0822 0x0e14 [ 37D255ED3F10F27C1C79E3378178F0B9, 085F683674C5858B40F0F832524777A2765D842EA0F8E7213AB937956664CF8E ] ETD C:\windows\system32\DRIVERS\ETD.sys
18:34:31.0822 0x0e14 ETD - ok
18:34:31.0868 0x0e14 [ DA8B66ECC36FE257D0683FBFF0AF272F, 8C24BF101CFD9B22A43F9BE492A9AEB8E1104F9ECA848F997556BE87FF3A6CB1 ] ETDService C:\Program Files\Elantech\ETDService.exe
18:34:31.0868 0x0e14 ETDService - ok
18:34:31.0915 0x0e14 [ F9E01C2D9F8BC049E04CF5DC24A5F638, CB6CCB59C77D4A59DDA846608AABEF1DFEC24C8422712AB8D59E27C13D731D2E ] EventSystem C:\windows\system32\es.dll
18:34:31.0931 0x0e14 EventSystem - ok
18:34:31.0947 0x0e14 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03, 6B0146A4C9AD32DCDC2DEE8E8C5A29F687665458486449E0D37B151ED63B8ADC ] exfat C:\windows\system32\drivers\exfat.sys
18:34:31.0947 0x0e14 exfat - ok
18:34:31.0962 0x0e14 [ 60996602A7111FD2D086E803F33E4282, E62A91C90F8542990BEA4E6A5D9DD3D070F4EB23B4C13414C5DA2B0219509749 ] fastfat C:\windows\system32\drivers\fastfat.sys
18:34:31.0978 0x0e14 fastfat - ok
18:34:32.0025 0x0e14 [ F0E7F8382ED5E138B0DFA4CB5058BCFE, 6247C7B75F975F5AB080FFB9881EF58A6F360219F7AF2DE871F38E80CAF3B62C ] Fax C:\windows\system32\fxssvc.exe
18:34:32.0040 0x0e14 Fax - ok
18:34:32.0056 0x0e14 [ 73B2D11DF0B6E03A0CB0323218ACB3E4, BA9256919BAA2E0760F6A658B557FDC389ACE8F9820D1A41FD995FC5613F5AA6 ] fdc C:\windows\System32\drivers\fdc.sys
18:34:32.0056 0x0e14 fdc - ok
18:34:32.0072 0x0e14 [ 0828E3E7BD77C89149EAD3232BFD38DB, A6A296647A4EDBFF59124E3A9C0AB48759AA1738615ACFA5A454FF6BD3C31BA2 ] fdPHost C:\windows\system32\fdPHost.dll
18:34:32.0072 0x0e14 fdPHost - ok
18:34:32.0087 0x0e14 [ 872506AAB591E8908DF4461475AF92DF, 772F2D08CB95775E438822B9EA005CBA92ED4071ADAB2C0101156A7D037D4704 ] FDResPub C:\windows\system32\fdrespub.dll
18:34:32.0087 0x0e14 FDResPub - ok
18:34:32.0103 0x0e14 [ 0588950D93A426F97C7AAADB1A9B0458, ABCB3619BD58CAC438FC032495AE45A7B6FFDD4BD33C1B3D1BC7F9F13FCB727A ] fhsvc C:\windows\system32\fhsvc.dll
18:34:32.0103 0x0e14 fhsvc - ok
18:34:32.0118 0x0e14 [ 88A9EBACD1058ABB237A6B4E96E7F397, 263D25D33B679EB01D97763701347C31B2F72E28CE2C7EC8013EA77756D98BE1 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
18:34:32.0118 0x0e14 FileInfo - ok
18:34:32.0134 0x0e14 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02, 1D7BFB00D74A28AC13ECBA1E0036D50EE79266AC02CEDB2632466BF9DD46F211 ] Filetrace C:\windows\system32\drivers\filetrace.sys
18:34:32.0134 0x0e14 Filetrace - ok
18:34:32.0150 0x0e14 [ B1D4C168FF7B8579E3745888658FFB1D, 1A5C13E902A0C788A8B995ADD2FBC3303005911C0AA3F3F4497D3016AA0EF583 ] flpydisk C:\windows\System32\drivers\flpydisk.sys
18:34:32.0150 0x0e14 flpydisk - ok
18:34:32.0165 0x0e14 [ B33EC133AE4E6C1881D2302D93D2467D, 77E3A16257EA3698B3FCD947D004144E8D1EEE48EF5C82DF49B1B9B2B3C61DB2 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
18:34:32.0181 0x0e14 FltMgr - ok
18:34:32.0228 0x0e14 [ 0BCDC0FF11B984162B0CF0FF6E9E0146, D44A3CECBA36B7A64854E244FA6B5E65047896BF9983D20B431410FBBA36697A ] FontCache C:\windows\system32\FntCache.dll
18:34:32.0259 0x0e14 FontCache - ok
18:34:32.0353 0x0e14 [ 0B56259F5611787222A04A8F254E51D4, F77AEC0ACBFAF9154E32223B84B613229DACCD953AEBC3E96C27570F9AB10FD0 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:34:32.0353 0x0e14 FontCache3.0.0.0 - ok
18:34:32.0368 0x0e14 [ A5F7873A39E4E9FAAAE59B7E9E36B705, 32036109F5A50E9F3BEF97C5B28AE8179B3A5E22517868A83CADE4671FF90DEC ] FsDepends C:\windows\system32\drivers\FsDepends.sys
18:34:32.0368 0x0e14 FsDepends - ok
18:34:32.0384 0x0e14 [ A6DD7D491F587F4BC13FB972977DC8E8, B86F97F17F6F443EC16DEF67CCA4EF78AFE56078D2877838A982FECB19557C87 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
18:34:32.0384 0x0e14 Fs_Rec - ok
18:34:32.0415 0x0e14 [ C1646A95EAC515F60CDB2A7A8A013C1E, F559B83C02B17265EDE95DD497C1A94E402F07EC251FC47449F789907AFFED14 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
18:34:32.0431 0x0e14 fvevol - ok
18:34:32.0462 0x0e14 [ A969D92973DFA895E7776B4BFE36DBB2, 7528E6983ECC59291A7A386E4E459B19D1593ABDDFFD276E2F01B0EA21693E20 ] FxPPM C:\windows\System32\drivers\fxppm.sys
18:34:32.0462 0x0e14 FxPPM - ok
18:34:32.0478 0x0e14 [ 52BC441E07A827EBAB70CDC7EAEDB28D, 8DECBD8E12EA52039742599CFBBF0D3B6610B57EF8D9DAEEEA33D202A478D286 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
18:34:32.0478 0x0e14 gagp30kx - ok
18:34:32.0509 0x0e14 [ 721F8EEF5E9747F32670DEFF7FB92541, E0A8EF70753E260C2C7D93D316B5EF9589DB086FDF829BDA2958C6A09CE471A6 ] gencounter C:\windows\System32\drivers\vmgencounter.sys
18:34:32.0509 0x0e14 gencounter - ok
18:34:32.0525 0x0e14 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E, 4BF196E1CAC94E9265EBEB68F41C3E29F0C709ECFF9420B5B1C9C82680D5D6A8 ] GPIOClx0101 C:\windows\system32\Drivers\msgpioclx.sys
18:34:32.0540 0x0e14 GPIOClx0101 - ok
18:34:32.0587 0x0e14 [ 5358678C6370F2ADC5291849F6503262, 841633D7A936C3889690C67E189BAD4C6B294C196FFFE5B564FCECDFE46A9E52 ] gpsvc C:\windows\System32\gpsvc.dll
18:34:32.0603 0x0e14 gpsvc - ok
18:34:32.0681 0x0e14 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:34:32.0681 0x0e14 gupdate - ok
18:34:32.0697 0x0e14 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:34:32.0697 0x0e14 gupdatem - ok
18:34:32.0728 0x0e14 [ 630555943E5A3FE21010CE91EC7FC84F, 20D7247A4363EE9E851501D89A466564ADCAEC304DE42280E4E09AD8499436A9 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
18:34:32.0728 0x0e14 HdAudAddService - ok
18:34:32.0743 0x0e14 [ 7D87B5B6C7188D553E11B59DC7F0B111, FC633DB71E1D72E8AD8F89BBB54324CC6ED17F5594EF55DD0BDB58EE1F601FF5 ] HDAudBus C:\windows\System32\drivers\HDAudBus.sys
18:34:32.0743 0x0e14 HDAudBus - ok
18:34:32.0759 0x0e14 [ 3F76BBA53D65E85A7F53E7A71082082C, D1E18815BB19CD11007C4A66162C76F55D4FE6B09B34ED45969C7ECC29D394AD ] HidBatt C:\windows\System32\drivers\HidBatt.sys
18:34:32.0759 0x0e14 HidBatt - ok
18:34:32.0790 0x0e14 [ 085F150D002B7F0153D3C06DDF33A143, 41847FD02608ECFE3A6B4B38CBDE8416B0EF17491868511FD704B0BCC280338E ] HidBth C:\windows\System32\drivers\hidbth.sys
18:34:32.0790 0x0e14 HidBth - ok
18:34:32.0806 0x0e14 [ CC4A07E51D89575CAB6F4EB590D87CD4, DFB4EAF0923EF9FF6C42EDD1EA5E4025F243C9BE2D03D5423FE8A897DC01D657 ] hidi2c C:\windows\System32\drivers\hidi2c.sys
18:34:32.0806 0x0e14 hidi2c - ok
18:34:32.0837 0x0e14 [ DC96F7DACB777CDEAEF9958A50BFDA06, 7CE79F32D5EE65C0178CFF56523825D3EE01095B2CE8C67634A6604A821A9086 ] HidIr C:\windows\System32\drivers\hidir.sys
18:34:32.0837 0x0e14 HidIr - ok
18:34:32.0868 0x0e14 [ FAC37D7B3D6354A5A5E19A45B50B4008, 2962B552A1DA545DFDEF0886582E82596FE8A3A19AAF989B025AFDA84D16D4EC ] hidserv C:\windows\system32\hidserv.dll
18:34:32.0868 0x0e14 hidserv - ok
18:34:32.0915 0x0e14 [ 012C354B4AB48E9A7A657DF39E3A2073, B15D0089CE509FF1CF73DFE095425C1C99FC3971622DCAAD9CAEB989A12A4FDB ] HidUsb C:\windows\System32\drivers\hidusb.sys
18:34:32.0915 0x0e14 HidUsb - ok
18:34:32.0947 0x0e14 [ 43F884B61A24377567CD0FEB35236334, B3BA36B527C8D6D83DE2FBCD8D503B87FD2611BF15B07A7BC138DC8BAE6A50C1 ] hkmsvc C:\windows\system32\kmsvc.dll
18:34:32.0947 0x0e14 hkmsvc - ok
18:34:32.0978 0x0e14 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF, E6967F3F465C6E903221BC0FCBAE7D05FD18C0BF110D929335F5935364B3C1BC ] HomeGroupListener C:\windows\system32\ListSvc.dll
18:34:32.0993 0x0e14 HomeGroupListener - ok
18:34:33.0025 0x0e14 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E, B965DCC72625188F3B896CB447B7696F22687266EAFC5AA270E2AD53DD9F324D ] HomeGroupProvider C:\windows\system32\provsvc.dll
18:34:33.0040 0x0e14 HomeGroupProvider - ok
18:34:33.0040 0x0e14 [ 64DB7A8D97CA53DCCF93D0A1E08342CF, 02CAB7F28D3830C482683425C60044239C6F1562556688A274CA2C237C846E76 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
18:34:33.0040 0x0e14 HpSAMD - ok
18:34:33.0087 0x0e14 [ F4A91D985EB9D1D2717D538F3424603C, 454AD2FF3A7963B9835AEF300F6672F92D0CCF59593BA2CCC83F0EC1446BB659 ] HTTP C:\windows\system32\drivers\HTTP.sys
18:34:33.0103 0x0e14 HTTP - ok
18:34:33.0119 0x0e14 [ 2A98301068801700906C06649860FE94, 664394A52326289DCA0828B0041A105653F4FEF3E3DCCC3787AAE0F6FDC73A14 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
18:34:33.0119 0x0e14 hwpolicy - ok
18:34:33.0134 0x0e14 [ DC76901D82097C9E297F20C287CB9A27, 01A412D0D8A65050BE4250A7C4B9F98A4C43FD891827761E0C830369A5F9F09C ] hyperkbd C:\windows\System32\drivers\hyperkbd.sys
18:34:33.0134 0x0e14 hyperkbd - ok
18:34:33.0134 0x0e14 [ 716413AB3CA12DE0A7222D28C1C9352C, B82B586BD9DBD70DDA19A02504E8CB00DA53677703AB848B53387601C5BAD3D3 ] HyperVideo C:\windows\system32\DRIVERS\HyperVideo.sys
18:34:33.0134 0x0e14 HyperVideo - ok
18:34:33.0150 0x0e14 [ C9E9CBF73AFFBFE3E801EFB516787BA3, 1A850D614BDA6AA4195CC657702BC6242BA51B90131717743182AA160F65E72C ] i8042prt C:\windows\System32\drivers\i8042prt.sys
18:34:33.0150 0x0e14 i8042prt - ok
18:34:33.0181 0x0e14 [ 6C024B3AE192D72B216166802AF345DD, 67AEDBEF4A1C1EE1DA9B684BDEB3DB07715E12B766AA72B6684CC6C583A8DCC5 ] iaStorA C:\windows\system32\drivers\iaStorA.sys
18:34:33.0197 0x0e14 iaStorA - ok
18:34:33.0228 0x0e14 [ 5E394EBD26FD68AA9300332C46BEDD62, 56A5DA7CE08C07B519E55D0A46AA9D10B640349808EFE02B3278267B75B5F603 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
18:34:33.0228 0x0e14 iaStorV - ok
18:34:33.0462 0x0e14 [ 11A31FC2481BFE69B0507ED8C80215F4, 8A1E90611F749E8F04B6D86E835E981CAC16D0841305CADB19E58682DA006698 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
18:34:33.0587 0x0e14 igfx - ok
18:34:33.0603 0x0e14 [ 24847A06B84339FEEDE5CABF3D27D320, 7727B1DAD0D4A1D474FBBEFCEBDF36A1F07D1AA300869AE57A24ED91BF84B6B4 ] iirsp C:\windows\system32\drivers\iirsp.sys
18:34:33.0603 0x0e14 iirsp - ok
18:34:33.0665 0x0e14 [ E455C83E029121270BED73CDAC381F37, 433D525C19DBF26FAC28853C606C872D973104842B0EF1B2BF2EAC85457E2953 ] IKEEXT C:\windows\System32\ikeext.dll
18:34:33.0681 0x0e14 IKEEXT - ok
18:34:33.0728 0x0e14 [ F5495B38BFB9149925F54F65AB40EFBF, 7CBB72C41E2343DACBFB967A39CA04788561EDECB289C41BC2D6A06B80882AC4 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
18:34:33.0728 0x0e14 IntcDAud - ok
18:34:33.0775 0x0e14 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC, F791EE101EEF8B9F48102B6C63A89B78F7C0041C750C4F4C0D16D54B583B7B5C ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
18:34:33.0790 0x0e14 Intel(R) Capability Licensing Service Interface - ok
18:34:33.0806 0x0e14 [ 4F37726CF764CA18A8A84F85EF3A7F24, 6212B23917526E127CE641A11A58DA93651FFE70829C4079FE465DBDC81CF470 ] intelide C:\windows\system32\drivers\intelide.sys
18:34:33.0806 0x0e14 intelide - ok
18:34:33.0837 0x0e14 [ E15CDF68DD73423F15D4AC404793AF0D, E2D0136AF68D1A73EB3A63C83284B4661222CB0A4AFACCF276CB57CBD4850287 ] intelppm C:\windows\System32\drivers\intelppm.sys
18:34:33.0837 0x0e14 intelppm - ok
18:34:33.0853 0x0e14 [ 8FCA66234A0933D796BB780B7953BAB9, 7DD677F5EE09A8D7A75C9E475B5E6B3DCA49D1E846C7D160B839D7029B1C5B6D ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
18:34:33.0853 0x0e14 IpFilterDriver - ok
18:34:33.0900 0x0e14 [ C217B8D2E58C57A319B16125C3D4B69C, 905BB858E1782BD08FF080A4A604CE662440A15601B178FBD30269C306C04CCF ] iphlpsvc C:\windows\System32\iphlpsvc.dll
18:34:33.0915 0x0e14 iphlpsvc - ok
18:34:33.0915 0x0e14 [ 6E98A046A12AA113F8898AA5D612BD6E, 28816CC1F03F2BFBF099C087C0BB6949E959F44C888DD2D0528FF7ED5D665ECF ] IPMIDRV C:\windows\System32\drivers\IPMIDrv.sys
18:34:33.0915 0x0e14 IPMIDRV - ok
18:34:33.0931 0x0e14 [ 3969B9C218DD3FAA9F4ED2FFC3651C02, 93447F124CC55FB17055126432194153E1BB8F0FD95A47608494B6834A5F7089 ] IPNAT C:\windows\system32\drivers\ipnat.sys
18:34:33.0931 0x0e14 IPNAT - ok
18:34:33.0947 0x0e14 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C, 4099BAA2DB4ADB93B878D71E241B7D9EB7E0EE7ED0FE2450CCB9E4718B3726EB ] IRENUM C:\windows\system32\drivers\irenum.sys
18:34:33.0947 0x0e14 IRENUM - ok
18:34:33.0947 0x0e14 [ D940C5BB9DC92E588533C19ABCC3D2C2, D1442854CEDE86F2C187A35851E74C873D34B772C60BC118FA1577F79C03364D ] isapnp C:\windows\system32\drivers\isapnp.sys
18:34:33.0947 0x0e14 isapnp - ok
18:34:33.0978 0x0e14 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF, 8FFF92828C3DC20F0F42C42E58A03B59A4E0187963F728DC618C9595FB2D0239 ] iScsiPrt C:\windows\System32\drivers\msiscsi.sys
18:34:33.0978 0x0e14 iScsiPrt - ok
18:34:34.0056 0x0e14 [ 78ABBE558F57144047F10A0F50FE4B2F, 6BE608F7697D83FD6C7E6EA422AC5637933BDC96B1044C12DE9A419CE7D6F6CE ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
18:34:34.0056 0x0e14 jhi_service - ok
18:34:34.0072 0x0e14 [ 8FBD94B69D6423E20ABCD59D86368B21, 218EF992095E365EC917413749856A64D55D8129D77098E24D670843233377F4 ] kbdclass C:\windows\System32\drivers\kbdclass.sys
18:34:34.0072 0x0e14 kbdclass - ok
18:34:34.0072 0x0e14 [ E88C932ABDF8185A62C8F2FC7B051FB6, 67F9AF58237A11F0BF3D15AA5B32E5CE66B7AA039B999D938F7F6E63DCEA7A6E ] kbdhid C:\windows\System32\drivers\kbdhid.sys
18:34:34.0072 0x0e14 kbdhid - ok
18:34:34.0072 0x0e14 [ FB6C185092E18011EF49989425C2AA87, 043524409E0A764201DD221C48B7DEEA0D161945EB37D4B88313BAB2299949DF ] kdnic C:\windows\system32\DRIVERS\kdnic.sys
18:34:34.0072 0x0e14 kdnic - ok
18:34:34.0087 0x0e14 [ F702AB6181513303AB0FC8D59E52708B, D46939B9F672269E65C98606A573C849C4AF5A26E4E75D3A8FE56A65B3A6EA08 ] KeyIso C:\windows\system32\lsass.exe
18:34:34.0087 0x0e14 KeyIso - ok
18:34:34.0103 0x0e14 [ DFA480F6DED551464F3A5B959F437800, C07AB6F28A09FCBE11EECAD03B06CEAE1016EC24031FCA0C092639E90FBA84CF ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
18:34:34.0103 0x0e14 KSecDD - ok
18:34:34.0134 0x0e14 [ 127FB0AAD232BAAD2C9BBACD374F4FC5, 3BC56F6B4374062C96149D69ACE053DF81A278F0361599F5A2F3DB1F76F0AD68 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
18:34:34.0134 0x0e14 KSecPkg - ok
18:34:34.0150 0x0e14 [ 81492FEEBF2F26455B00EE8DBAE8A1B0, E33AA2DFB2D3BB30B02CDADA2EC290F86329DA3198327A653F39A843D86390B9 ] ksthunk C:\windows\system32\drivers\ksthunk.sys
18:34:34.0165 0x0e14 ksthunk - ok
18:34:34.0197 0x0e14 [ 5825DBACEDC3812B5CF8D40B997BF210, 1C2997BCC707C1029B21876E093038CE3BBF6E6694B4CCF7EEDD47172ED9A541 ] KtmRm C:\windows\system32\msdtckrm.dll
18:34:34.0197 0x0e14 KtmRm - ok
18:34:34.0244 0x0e14 [ CBD16721541EE334F6D623CE0B4003BF, DE2C6345B2051AD4C3A3F3AB89AB63AE58A0BA6AB0BCB6B0DFCE6BCD0E8E9519 ] L1C C:\windows\system32\DRIVERS\L1C63x64.sys
18:34:34.0244 0x0e14 L1C - ok
18:34:34.0290 0x0e14 [ 256EE31588257E8A555DBFAA13F1908E, B6817F632EDEA483E35BF26846DCDD4E95E860620959179B2A5D8AD7EEDDB126 ] LanmanServer C:\windows\system32\srvsvc.dll
18:34:34.0290 0x0e14 LanmanServer - ok
18:34:34.0322 0x0e14 [ 16650912BE5A94B40E0B3B4C39652B56, 908C2C9367AE0AC9AECB5D91514BB33ACD746D99F19C1A8DD6A9550E9CAD9E00 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
18:34:34.0322 0x0e14 LanmanWorkstation - ok
18:34:34.0353 0x0e14 [ BE166935083F9C38EDFDC21B9A7A679B, 89C64DBE58E1B974208AAAA5CC757C599B1439C205C3C48BF16BA054A06DBC94 ] LHDmgr C:\windows\system32\DRIVERS\LhdX64.sys
18:34:34.0353 0x0e14 LHDmgr - ok
18:34:34.0369 0x0e14 [ CEEFD29FC551F289810B0B9381B321DC, 900F206B487B2190D9363F28AA4BA0CD7DCFE1D005BE05A48AF74B1B81194691 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
18:34:34.0369 0x0e14 lltdio - ok
18:34:34.0400 0x0e14 [ BCF53485E0A94722CDE3C4A93CD8EB8C, D24E1066EB102245A89A5D17D608DB9DF6B71C99F1C77E070B95EFD17D268141 ] lltdsvc C:\windows\System32\lltdsvc.dll
18:34:34.0415 0x0e14 lltdsvc - ok
18:34:34.0431 0x0e14 [ 5A2F7F1CBC2E631A497DAD16164E06D2, 35274FC6C386380B01B5E8F467E71A2C4E2FB2AD701554F9B1A9B036B0340142 ] lmhosts C:\windows\System32\lmhsvc.dll
18:34:34.0431 0x0e14 lmhosts - ok
18:34:34.0462 0x0e14 [ 2C24DC448DBE8DB9BE1441B824C57E79, DA2257EEC964A47D03C2BB13317FD788E51D4685E2395B303ED7B2575FEF3B19 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:34:34.0462 0x0e14 LMS - ok
18:34:34.0478 0x0e14 [ 022CDD12161B063D7852B1075BF3FFF2, E21267243AF2FC208D27E67827B1264A762C99AECEDB7AD2C48A04F421A6B2F0 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
18:34:34.0478 0x0e14 LSI_SAS - ok
18:34:34.0478 0x0e14 [ 07AD59D669B996F29F91817F0ECFA34F, 026F332F862D142BFFC9D169CCD17A35BFB6B301EEC72AA13E16369B3520919C ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
18:34:34.0478 0x0e14 LSI_SAS2 - ok
18:34:34.0478 0x0e14 [ 216FB796AA4E252ACCE93B1BCB80B5EC, 5B1E49B5F7B9C7A778198D27F8EE500FE35DC32D40B22A3D6ED67560BEB04212 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
18:34:34.0494 0x0e14 LSI_SCSI - ok
18:34:34.0494 0x0e14 [ 5E80530AF37102488EE980B4A92AF99F, 364E18EAD9AC22F8A306B24C6C43E58224F6BE2744EFEAA2484696B8D9880851 ] LSI_SSS C:\windows\system32\drivers\lsi_sss.sys
18:34:34.0494 0x0e14 LSI_SSS - ok
18:34:34.0540 0x0e14 [ A57BA284F5996FFD32DCDBC41A4657DB, 2106B83873A824BC83EF42FAC9DD9A0F741209535A84AE65EA8E786519920043 ] LSM C:\windows\System32\lsm.dll
18:34:34.0540 0x0e14 LSM - ok
18:34:34.0556 0x0e14 [ 2BDC5D711FA61307CE6190D47C956368, 6BCDC6CBB9783F1ABE8957BDA94AF977DFB2A310BB6D19085EFC8609C97FD180 ] luafv C:\windows\system32\drivers\luafv.sys
18:34:34.0572 0x0e14 luafv - ok
18:34:34.0572 0x0e14 [ 9B0D829C3BE4E7472DB9DD2B79908E3C, ACED5806FFF39E84007B5A3DCB16315329DC53007F46B1BEEDC391CC659F7DD3 ] megasas C:\windows\system32\drivers\megasas.sys
18:34:34.0572 0x0e14 megasas - ok
18:34:34.0587 0x0e14 [ ECC3F54C7AFC318271C4F0B4606D8DB0, FD1ACB18B8C912C7A57DABCD5460800DD0721A82E09C8D79C47B3392D61CBEA6 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
18:34:34.0587 0x0e14 MegaSR - ok
18:34:34.0603 0x0e14 [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\windows\System32\drivers\HECIx64.sys
18:34:34.0603 0x0e14 MEIx64 - ok
18:34:34.0634 0x0e14 [ EEE908BE7143FCA48CF0CB87214E2AB8, 4F9BD299F559DD36DBD93489CFAA753F236FBB70946E034D2E2260059AE20962 ] MMCSS C:\windows\system32\mmcss.dll
18:34:34.0634 0x0e14 MMCSS - ok
18:34:34.0634 0x0e14 [ 780098AD5DA8A4822E2563984C85EF7B, 29312970774E944B5ED388316CF3D350DCABF721F9695737B0AC56BE878B0446 ] Modem C:\windows\system32\drivers\modem.sys
18:34:34.0634 0x0e14 Modem - ok
18:34:34.0665 0x0e14 [ EA8EAD3F5B762F889CC7F3966625B48B, B701A42E5E08B7BC6601560446146803182E5DC631AB73E9408F19CB6432F121 ] monitor C:\windows\System32\drivers\monitor.sys
18:34:34.0665 0x0e14 monitor - ok
18:34:34.0681 0x0e14 [ 618446B98C79776654340CE27C73485E, EFE7169FDD545933B5949DA2D09266971C0C3E6894E7BD8AFE29E41567C72B16 ] mouclass C:\windows\System32\drivers\mouclass.sys
18:34:34.0681 0x0e14 mouclass - ok
18:34:34.0697 0x0e14 [ C0ADEBED913295803B579ED288936CBB, 58F71541166D1DA07C18FBD27458D55E3F8AD7291CB7496B3A2F01372A5B0CAE ] mouhid C:\windows\System32\drivers\mouhid.sys
18:34:34.0697 0x0e14 mouhid - ok
18:34:34.0712 0x0e14 [ 89D263DBF08119CE16273991C120D6DD, 9771EDAD266F0E234E71DFB6792F396710E051F2ADCA5CDADEBBD2790D0E6054 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
18:34:34.0712 0x0e14 mountmgr - ok
18:34:34.0744 0x0e14 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C, BCBFF081FAFB822CE29D291FB329FC310D90F0EC0D1BB69CF8CB09ED5A2E84D1 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
18:34:34.0744 0x0e14 mpsdrv - ok
18:34:34.0790 0x0e14 [ 3031573A739DBEE8923851929D0AF423, E9EA6C0D12A896AC745173B1F1A58192B52724AA424718B16B8D05E9AC091741 ] MpsSvc C:\windows\system32\mpssvc.dll
18:34:34.0806 0x0e14 MpsSvc - ok
18:34:34.0822 0x0e14 [ 3D70147F55F1EC84EB9139ED7FFE48BC, 12429C2FDDDA13815F0E18F9009011AA5360955759A23A38175543F480CB92EF ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
18:34:34.0822 0x0e14 MRxDAV - ok
18:34:34.0853 0x0e14 [ 93179D48066918323628CB016D8C94DC, FE110BF7A10EDD1DF7F6B933D373FCA51F37413282EBC4187E7C9B1965186BCC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
18:34:34.0869 0x0e14 mrxsmb - ok
18:34:34.0884 0x0e14 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3, C665B7896501D42C73955F4EAF4FA3C6B2C9286957D6023C235AFBF9BFB761C6 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
18:34:34.0900 0x0e14 mrxsmb10 - ok
18:34:34.0915 0x0e14 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26, 9822FA53E6067C0E39B7A3A3F1E88719D5D8B055D86FF894F0475B158289EA45 ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
18:34:34.0915 0x0e14 mrxsmb20 - ok
18:34:34.0931 0x0e14 [ 98487487D6B3797CA927E9D7B030AE13, 05840AF0DD2E3CB596DA768DBD0728B52210EC05B55AB5921E697AD8956938DD ] MsBridge C:\windows\system32\DRIVERS\bridge.sys
18:34:34.0931 0x0e14 MsBridge - ok
18:34:34.0962 0x0e14 [ 4A07458EB4F17573BD39F22029A991C1, 74D7A1882EA4D19B8F090C2813489E5D3F759BF4AF2D88AE852EC6510C405B5E ] MSDTC C:\windows\System32\msdtc.exe
18:34:34.0978 0x0e14 MSDTC - ok
18:34:34.0994 0x0e14 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2, ECCA22985838A914EDC866C491DEB64B9FF5110EFA9BEE541F634AC5EC3081F9 ] Msfs C:\windows\system32\drivers\Msfs.sys
18:34:34.0994 0x0e14 Msfs - ok
18:34:35.0025 0x0e14 [ C32A7A39B960A42BA9D4FBE47213CA03, 4DA48587138972DA5E95AEDBBBE73BA8CCADC8172C6654427ABEAC8047B27E95 ] msgpiowin32 C:\windows\System32\drivers\msgpiowin32.sys
18:34:35.0025 0x0e14 msgpiowin32 - ok
18:34:35.0040 0x0e14 [ D3857A767B91A061B408CCAB02DA4F40, A4D780772086AD8717EE6DC2B6189F796939FB5E5AA08FD9D1984101998FBECF ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
18:34:35.0040 0x0e14 mshidkmdf - ok
18:34:35.0040 0x0e14 [ 839B48910FB1E887635C48F3EC11A05E, F8CFD99911500CC1B6A90C8E2A1697BD5A6E5776A62A62FE5B342FE204C936B1 ] mshidumdf C:\windows\System32\drivers\mshidumdf.sys
18:34:35.0056 0x0e14 mshidumdf - ok
18:34:35.0056 0x0e14 [ 55C0DB741E3AB7463242B185B1C2997C, D2E2A5B48A64EA0EC2A6566C08E65A38D11CEA64BCA7B57793BA0D009E4D974A ] msisadrv C:\windows\system32\drivers\msisadrv.sys
18:34:35.0056 0x0e14 msisadrv - ok
18:34:35.0103 0x0e14 [ 216C6B035A4BA5560E1255BD8E5BB89F, A14E038604B9A5506DB145A4D9F51E2751AC825240D2744924F39C332B5DE00B ] MSiSCSI C:\windows\system32\iscsiexe.dll
18:34:35.0103 0x0e14 MSiSCSI - ok
18:34:35.0103 0x0e14 msiserver - ok
18:34:35.0134 0x0e14 [ 509809566E49F4411055864EA8D437CD, 70F37BF9C759E8BCA1C6AC8FB9805950925E1C648ED37E8561A0F7A407DFDC28 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
18:34:35.0134 0x0e14 MSKSSRV - ok
18:34:35.0150 0x0e14 [ 63145201D6458E4958E572E7D6FC2604, EDD4A8A3BBE94B983554B1117734E66A2647B867269C5F0567C47EDE6F3FACCB ] MsLldp C:\windows\system32\DRIVERS\mslldp.sys
18:34:35.0150 0x0e14 MsLldp - ok
18:34:35.0150 0x0e14 [ 99D526E803DB6D7FF290FD98B6204641, 4AFAA3B1186621AEAD19E12D3DBE104DD8FCD5C106F9EC3ADA4AD1BC7093E61F ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
18:34:35.0150 0x0e14 MSPCLOCK - ok
18:34:35.0150 0x0e14 [ 06FA77C3E2A491ADCD704C5E73006269, 465A7EE5387E6C11398A554F73437278F5BF110356E7F49F315905C1F2459278 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
18:34:35.0150 0x0e14 MSPQM - ok
18:34:35.0181 0x0e14 [ E134EC4DE11CF78CB01432D180710D84, BB111F97AEEFDCA5866B157E9957599CD7A4952B5BCCA0B0BCA9EDFCD17E61FE ] MsRPC C:\windows\system32\drivers\MsRPC.sys
18:34:35.0181 0x0e14 MsRPC - ok
18:34:35.0197 0x0e14 [ B5AECF12F09DEE97C9FCAA5BA016CE1E, F5305C4CE6C93A3A3481BD13BE0C23FE26571E11029ACFFE75FB78913681FCFC ] mssmbios C:\windows\System32\drivers\mssmbios.sys
18:34:35.0197 0x0e14 mssmbios - ok
18:34:35.0212 0x0e14 [ 72D66A05E0F99F2528F6C6204FD22AA1, B14D433BC5795F1DC4C672302285E665DC012693E75574F60664AAD8874DE562 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
18:34:35.0212 0x0e14 MSTEE - ok
18:34:35.0212 0x0e14 [ 8AAAE399FC255FA105D4158CBA289001, 2F55C02605B4A3406B289FF9D46C76260B9138E3DE96AFAEA0E0522E5A2A746C ] MTConfig C:\windows\System32\drivers\MTConfig.sys
18:34:35.0212 0x0e14 MTConfig - ok
18:34:35.0228 0x0e14 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A, 00D33A4AB3E7C5F65F59C63F8E2FD27EF38D5484595F785D5632E9414E29352C ] Mup C:\windows\system32\Drivers\mup.sys
18:34:35.0228 0x0e14 Mup - ok
18:34:35.0228 0x0e14 [ 3A1E095277BBD406CEA8EA6B76950664, 47838F307A6354E77C19A7B1F3F3E22726EF60403B611F358AD6FFE81D7214E7 ] mvumis C:\windows\system32\drivers\mvumis.sys
18:34:35.0228 0x0e14 mvumis - ok
18:34:35.0275 0x0e14 [ 4B18840511D720BA118D3017E8165875, 724458A69269A5AE57E8DAB74FF3C198A79B6F7A9602BF38A70B4A40543ED167 ] napagent C:\windows\system32\qagentRT.dll
18:34:35.0275 0x0e14 napagent - ok
18:34:35.0322 0x0e14 [ 43D7388A90A4C6EA346A4D6FF0377479, DFDCFA448B49C8A577056070AF516F08CD2E452706A3CF9173195ABA4256F35D ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
18:34:35.0322 0x0e14 NativeWifiP - ok
18:34:35.0369 0x0e14 [ 6A0C3996DA7DAE6D6939676D786EEEC4, 6E8A4C6234FD3040BC889E92016A4D5AC7BCAF5059521E50C733966163A546A0 ] NcaSvc C:\windows\System32\ncasvc.dll
18:34:35.0384 0x0e14 NcaSvc - ok
18:34:35.0384 0x0e14 [ C982FE4CC91DECE2259F494FCEB4030F, 4C285407E6F9FBBA92180F4063AEFB736ED142D802F0151002F0CC20AB7BB4E5 ] NcdAutoSetup C:\windows\System32\NcdAutoSetup.dll
18:34:35.0400 0x0e14 NcdAutoSetup - ok
18:34:35.0447 0x0e14 [ A10E176F3B2BF83EDE7B5C4658C93B66, 42F2FAEB4A29BBC6727D7E159D3E7E2E66D33785E5C98496EEB44D281601A23E ] NDIS C:\windows\system32\drivers\ndis.sys
18:34:35.0447 0x0e14 NDIS - ok
18:34:35.0494 0x0e14 [ 39C8A1D9D46F5E83A016BCAB72455284, 80DBED610E0818C2C7122FBC5BC8C15BCE981538AE48DC48F464A86389AF3F68 ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
18:34:35.0494 0x0e14 NdisCap - ok
18:34:35.0509 0x0e14 [ 762941932B7E4C588E48A577BA9D6440, 71FA1870E398CB848D8294FEF6C60E0499CAB9A16EC3F487564C41072590E4F3 ] NdisImPlatform C:\windows\system32\DRIVERS\NdisImPlatform.sys
18:34:35.0509 0x0e14 NdisImPlatform - ok
18:34:35.0525 0x0e14 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7, D902AE15194A9F8A2198914FC76184FE7E2B589747275952A04A52853128FDB8 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
18:34:35.0525 0x0e14 NdisTapi - ok
18:34:35.0540 0x0e14 [ 79AB68BB3FFF974AD4F41FA559F4EC67, 1745EC6520B48E325C56D98A1F4DB9CE135FE3E097B3D66E6598791132CAD7BD ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
18:34:35.0540 0x0e14 Ndisuio - ok
18:34:35.0556 0x0e14 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
18:34:35.0556 0x0e14 NdisWan - ok
18:34:35.0572 0x0e14 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8, D51FEF198F74FDF583826E259E4736F51CD49908194104677889FD135EEC2EBC ] NDISWANLEGACY C:\windows\system32\DRIVERS\ndiswan.sys
18:34:35.0572 0x0e14 NDISWANLEGACY - ok
18:34:35.0603 0x0e14 [ 3730942D7DB2F8BB5F84542B7FF6F650, 89C9D7D7305205BDB304CE6DA7D1A57EDE86A9D77429698802A39D75EB78CAAB ] NDProxy C:\windows\system32\drivers\NDProxy.sys
18:34:35.0603 0x0e14 NDProxy - ok
18:34:35.0619 0x0e14 [ D3F60A4345FCA9C1BE68AD7D0D6DE770, 214AF09F4B021C2F8655FBC8AC8C801E89CD9115CDE690FAEBDA69D63D660EDD ] Ndu C:\windows\system32\drivers\Ndu.sys
18:34:35.0619 0x0e14 Ndu - ok
18:34:35.0634 0x0e14 [ 7C203A76394F9AE68F69EEE5F9612C4A, 2222654915913BDC9367A2075714906A10CF22C047A7494CD59CB71834ED1B62 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
18:34:35.0634 0x0e14 NetBIOS - ok
18:34:35.0650 0x0e14 [ 7CEC25C682D319D484630B3952C31A11, 025C46B367E0570E9E3F9DF1564C3E47B1524E9E9A180BBDF0E9C684838F5E42 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
18:34:35.0650 0x0e14 NetBT - ok
18:34:35.0650 0x0e14 [ F702AB6181513303AB0FC8D59E52708B, D46939B9F672269E65C98606A573C849C4AF5A26E4E75D3A8FE56A65B3A6EA08 ] Netlogon C:\windows\system32\lsass.exe
18:34:35.0666 0x0e14 Netlogon - ok
18:34:35.0697 0x0e14 [ 89519D29CBEC2121CA65CC29C4D345E0, F3BA7BCAFEC8DD8B29837458D1B2B1DEE748AEAAAE0575FD3AAE65CFC72A04CD ] Netman C:\windows\System32\netman.dll
18:34:35.0697 0x0e14 Netman - ok
18:34:35.0728 0x0e14 [ 79FA9393C67EBBF92A56923592CF7A7C, A8AB8A6346B97B68810CC632F425085BE9E63ACAED0F119A7BFD03F2DA4AA5F6 ] netprofm C:\windows\System32\netprofmsvc.dll
18:34:35.0744 0x0e14 netprofm - ok
18:34:35.0806 0x0e14 [ 5243CFC2E7161C91C2B355240035B9E4, CFD77485A9D7BC47F3A9C53D73B2AE2D5D04B90ED38628F3124EA569F4DE969E ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:34:35.0837 0x0e14 NetTcpPortSharing - ok
18:34:36.0025 0x0e14 [ 57B9C04D673F236D41FAB03842C8640B, 898DCBBBF94875059CD328B0FC75BE36A4E3DD471C6E28BFAE064BCF84349518 ] NETwNs64 C:\windows\system32\DRIVERS\NETwNs64.sys
18:34:36.0134 0x0e14 NETwNs64 - ok
18:34:36.0150 0x0e14 [ 12DD2800E4EEA37DC9AE256AD62423B4, 34740469EEA8740CBACD881CB232C9ABB9AB180DE5F45336BC6DBE154259F29B ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
18:34:36.0150 0x0e14 nfrd960 - ok
18:34:36.0181 0x0e14 [ 80ABCD4C2DE9FD832477303AE0CA3BE5, 98F3958E650CEB1006D92980503E1B176D2CA55D2A6742C1C27CDE829D137DA9 ] NlaSvc C:\windows\System32\nlasvc.dll
18:34:36.0181 0x0e14 NlaSvc - ok
18:34:36.0197 0x0e14 [ 17E19A742FB30C002F8B43575451DBE1, 59D226A4A5B5281C399BE96C694915E38EEAF335D31F346B0C65D8F469D7C9C3 ] Npfs C:\windows\system32\drivers\Npfs.sys
18:34:36.0197 0x0e14 Npfs - ok
18:34:36.0197 0x0e14 [ 8ED299C30792544264E558BEA79F0947, 8A03FDA9AADB79ECBCBCDC988B7D8CF0672689C9DF673A2ECFE0D2D88A9C6A6B ] npsvctrig C:\windows\System32\drivers\npsvctrig.sys
18:34:36.0197 0x0e14 npsvctrig - ok
18:34:36.0212 0x0e14 [ 832B5FDF0B5577713FD7F2465FCD0ACE, 4A551CDBACED47DD781EC59F8B59A13D66EFD85DCF636BCFCBACFE5972A78E93 ] nsi C:\windows\system32\nsisvc.dll
18:34:36.0212 0x0e14 nsi - ok


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 97 hostů