Prosím o rychlou kontrolu logu HJT Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 05 led 2013 15:09

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:05:32, on 5.1.2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\HiJackThis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=vsl&ch ... =498805924
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=vsl&ch ... =498805924
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O2 - BHO: CrossriderApp0000435 - {11111111-1111-1111-1111-110011041135} - C:\Program Files\Premiumplay Codec-C\Premiumplay Codec-C.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - (no file)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: (no name) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [setc] C:\Program Files\MySecurityCenter\Programs\setc.exe
O4 - HKLM\..\Run: [regist] C:\Program Files\MySecurityCenter\Programs\Info.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\PC\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.3.2\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MySecurityCenter License Service - Unknown owner - C:\Program Files\MySecurityCenter\Programs\service.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: vToolbarUpdater13.3.2 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe

--
End of file - 7344 bytes

Reklama
Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod Orcus » 05 led 2013 20:06

Odinstaluj MySecurityCenter a toolbary.

Fixni:

Kód: Vybrat vše

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=vsl&ch ... =498805924
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=vsl&ch ... =498805924
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - (no file)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: (no name) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [setc] C:\Program Files\MySecurityCenter\Programs\setc.exe
O4 - HKLM\..\Run: [regist] C:\Program Files\MySecurityCenter\Programs\Info.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\PC\AppData\Local\Google\Update\GoogleUpdate.exe" /c

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

===================================================

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 05 led 2013 21:49

Dekuji,všechno jsem splnil.Zde log .

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.05.08

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
PC :: MARTINA [administrátor]

Ochrana: Povolena

5.1.2013 21:34:43
MBAM-log-2013-01-05 (21-46-01).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 194781
Uplynulý čas: 9 minut, 53 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 13
HKCR\CLSID\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{44444444-4444-4444-4444-440044044435} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{55555555-5555-5555-5555-550055045535} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCR\CrossriderApp0000435.BHO.1 (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCR\CrossriderApp0000435.BHO (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Nebyla provedena žádná instrukce.
HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Program Files\Premiumplay Codec-C\Premiumplay Codec-C.dll (PUP.Codec.PR) -> Nebyla provedena žádná instrukce.
C:\Users\PC\AppData\Local\funmoods.crx (PUP.Funmoods) -> Nebyla provedena žádná instrukce.

(konec)

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod memphisto » 06 led 2013 10:15

- Takže spus znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 06 led 2013 12:13

Tady další log z MbAM
======================
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.06.02

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
PC :: MARTINA [administrátor]

Ochrana: Povolena

6.1.2013 11:04:03
mbam-log-2013-01-06 (11-04-03).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 194327
Uplynulý čas: 8 minut, 48 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 13
HKCR\CLSID\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCR\TypeLib\{44444444-4444-4444-4444-440044044435} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCR\Interface\{55555555-5555-5555-5555-550055045535} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCR\CrossriderApp0000435.BHO.1 (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCR\CrossriderApp0000435.BHO (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Přesun do karantény a smazání se zdařilo.
HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Přesun do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Přesun do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Program Files\Premiumplay Codec-C\Premiumplay Codec-C.dll (PUP.Codec.PR) -> Přesun do karantény a smazání se zdařilo.
C:\Users\PC\AppData\Local\funmoods.crx (PUP.Funmoods) -> Přesun do karantény a smazání se zdařilo.

(konec)

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 06 led 2013 12:17

Log z TDSS Killer
===================
11:18:53.0369 2480 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
11:18:53.0658 2480 ============================================================
11:18:53.0659 2480 Current date / time: 2013/01/06 11:18:53.0658
11:18:53.0659 2480 SystemInfo:
11:18:53.0659 2480
11:18:53.0659 2480 OS Version: 6.1.7600 ServicePack: 0.0
11:18:53.0659 2480 Product type: Workstation
11:18:53.0660 2480 ComputerName: MARTINA
11:18:53.0661 2480 UserName: PC
11:18:53.0661 2480 Windows directory: C:\Windows
11:18:53.0661 2480 System windows directory: C:\Windows
11:18:53.0661 2480 Processor architecture: Intel x86
11:18:53.0661 2480 Number of processors: 2
11:18:53.0661 2480 Page size: 0x1000
11:18:53.0661 2480 Boot type: Normal boot
11:18:53.0661 2480 ============================================================
11:18:57.0685 2480 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:18:57.0692 2480 ============================================================
11:18:57.0692 2480 \Device\Harddisk0\DR0:
11:18:57.0693 2480 MBR partitions:
11:18:57.0693 2480 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:18:57.0694 2480 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1866E000
11:18:57.0694 2480 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x186A0800, BlocksNum 0x21CE5000
11:18:57.0694 2480 ============================================================
11:18:57.0717 2480 C: <-> \Device\Harddisk0\DR0\Partition2
11:18:57.0747 2480 D: <-> \Device\Harddisk0\DR0\Partition3
11:18:57.0747 2480 ============================================================
11:18:57.0748 2480 Initialize success
11:18:57.0748 2480 ============================================================
11:19:15.0978 2660 ============================================================
11:19:15.0978 2660 Scan started
11:19:15.0979 2660 Mode: Manual;
11:19:15.0979 2660 ============================================================
11:19:17.0057 2660 ================ Scan system memory ========================
11:19:17.0058 2660 System memory - ok
11:19:17.0068 2660 ================ Scan services =============================
11:19:17.0298 2660 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
11:19:17.0309 2660 1394ohci - ok
11:19:17.0349 2660 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
11:19:17.0360 2660 ACPI - ok
11:19:17.0380 2660 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
11:19:17.0386 2660 AcpiPmi - ok
11:19:17.0500 2660 [ 11A52CF7B265631DEEB24C6149309EFF ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
11:19:17.0506 2660 AdobeARMservice - ok
11:19:17.0577 2660 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:19:17.0600 2660 AdobeFlashPlayerUpdateSvc - ok
11:19:17.0651 2660 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:19:17.0682 2660 adp94xx - ok
11:19:17.0740 2660 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:19:17.0763 2660 adpahci - ok
11:19:17.0792 2660 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:19:17.0803 2660 adpu320 - ok
11:19:17.0924 2660 [ 993F7B0BA5188A0007C085AA10257B8E ] AdvancedSystemCareService6 C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
11:19:17.0940 2660 AdvancedSystemCareService6 - ok
11:19:17.0990 2660 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:19:17.0994 2660 AeLookupSvc - ok
11:19:18.0046 2660 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\Windows\system32\drivers\afd.sys
11:19:18.0075 2660 AFD - ok
11:19:18.0128 2660 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
11:19:18.0135 2660 agp440 - ok
11:19:18.0162 2660 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
11:19:18.0170 2660 aic78xx - ok
11:19:18.0201 2660 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
11:19:18.0209 2660 ALG - ok
11:19:18.0269 2660 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
11:19:18.0275 2660 aliide - ok
11:19:18.0316 2660 [ B19505648F033393E907E2E419FDE8B3 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
11:19:18.0324 2660 AMD External Events Utility - ok
11:19:18.0360 2660 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
11:19:18.0367 2660 amdagp - ok
11:19:18.0398 2660 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
11:19:18.0404 2660 amdide - ok
11:19:18.0428 2660 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:19:18.0435 2660 AmdK8 - ok
11:19:18.0468 2660 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:19:18.0475 2660 AmdPPM - ok
11:19:18.0518 2660 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:19:18.0526 2660 amdsata - ok
11:19:18.0555 2660 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:19:18.0566 2660 amdsbs - ok
11:19:18.0604 2660 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:19:18.0608 2660 amdxata - ok
11:19:18.0677 2660 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
11:19:18.0684 2660 AppID - ok
11:19:18.0724 2660 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:19:18.0730 2660 AppIDSvc - ok
11:19:18.0749 2660 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
11:19:18.0753 2660 Appinfo - ok
11:19:18.0797 2660 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
11:19:18.0805 2660 arc - ok
11:19:18.0838 2660 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:19:18.0847 2660 arcsas - ok
11:19:18.0881 2660 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:19:18.0886 2660 AsyncMac - ok
11:19:18.0912 2660 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
11:19:18.0915 2660 atapi - ok
11:19:19.0003 2660 [ 76BAB0C824E2D05B940C4DD40A9B08BF ] athr C:\Windows\system32\DRIVERS\athr.sys
11:19:19.0061 2660 athr - ok
11:19:19.0382 2660 [ 04F09923A393E4E0E8453A8F78361E73 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:19:19.0577 2660 atikmdag - ok
11:19:19.0672 2660 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:19:19.0687 2660 AudioEndpointBuilder - ok
11:19:19.0738 2660 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:19:19.0754 2660 Audiosrv - ok
11:19:20.0160 2660 [ 56C73C5BC1656656CAC38A23B4310466 ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe
11:19:20.0394 2660 AVGIDSAgent - ok
11:19:20.0479 2660 [ 7BB2C605094DBCA536D127B434214862 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdriverx.sys
11:19:20.0489 2660 AVGIDSDriver - ok
11:19:20.0527 2660 [ 8F50F98686C9A397A19FCBAE284DB1C5 ] AVGIDSHX C:\Windows\system32\DRIVERS\avgidshx.sys
11:19:20.0533 2660 AVGIDSHX - ok
11:19:20.0568 2660 [ A8DE230CC8536790CA07D37FBCD87A74 ] AVGIDSShim C:\Windows\system32\DRIVERS\avgidsshimx.sys
11:19:20.0573 2660 AVGIDSShim - ok
11:19:20.0637 2660 [ D53D35031365A0ECCB1DC1BC1B15B18E ] Avgldx86 C:\Windows\system32\DRIVERS\avgldx86.sys
11:19:20.0649 2660 Avgldx86 - ok
11:19:20.0737 2660 [ 95889A9D23F3133250FA8AD13C982D58 ] Avglogx C:\Windows\system32\DRIVERS\avglogx.sys
11:19:20.0748 2660 Avglogx - ok
11:19:20.0797 2660 [ 6C7C00B8DD22B4343B47FED148387057 ] Avgmfx86 C:\Windows\system32\DRIVERS\avgmfx86.sys
11:19:20.0806 2660 Avgmfx86 - ok
11:19:20.0878 2660 [ F3D57358DE0B8B3491013C615754A7C7 ] Avgrkx86 C:\Windows\system32\DRIVERS\avgrkx86.sys
11:19:20.0883 2660 Avgrkx86 - ok
11:19:20.0945 2660 [ BA73B38E9033FC6018DB736B635706AE ] Avgtdix C:\Windows\system32\DRIVERS\avgtdix.sys
11:19:20.0956 2660 Avgtdix - ok
11:19:21.0004 2660 [ C6B83088D7EE2D3212AF7F2515E17725 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
11:19:21.0010 2660 avgtp - ok
11:19:21.0082 2660 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe
11:19:21.0092 2660 avgwd - ok
11:19:21.0141 2660 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:19:21.0149 2660 AxInstSV - ok
11:19:21.0202 2660 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
11:19:21.0233 2660 b06bdrv - ok
11:19:21.0272 2660 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
11:19:21.0294 2660 b57nd60x - ok
11:19:21.0339 2660 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
11:19:21.0346 2660 BDESVC - ok
11:19:21.0375 2660 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
11:19:21.0382 2660 Beep - ok
11:19:21.0449 2660 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
11:19:21.0485 2660 BFE - ok
11:19:21.0538 2660 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\System32\qmgr.dll
11:19:21.0580 2660 BITS - ok
11:19:21.0641 2660 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:19:21.0647 2660 blbdrive - ok
11:19:21.0690 2660 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:19:21.0694 2660 bowser - ok
11:19:21.0732 2660 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:19:21.0739 2660 BrFiltLo - ok
11:19:21.0758 2660 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:19:21.0767 2660 BrFiltUp - ok
11:19:21.0809 2660 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\Windows\System32\browser.dll
11:19:21.0817 2660 Browser - ok
11:19:21.0868 2660 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:19:21.0892 2660 Brserid - ok
11:19:21.0913 2660 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:19:21.0921 2660 BrSerWdm - ok
11:19:21.0942 2660 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:19:21.0950 2660 BrUsbMdm - ok
11:19:21.0969 2660 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:19:21.0974 2660 BrUsbSer - ok
11:19:21.0999 2660 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:19:22.0005 2660 BTHMODEM - ok
11:19:22.0059 2660 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
11:19:22.0071 2660 bthserv - ok
11:19:22.0114 2660 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:19:22.0122 2660 cdfs - ok
11:19:22.0157 2660 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
11:19:22.0166 2660 cdrom - ok
11:19:22.0196 2660 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
11:19:22.0205 2660 CertPropSvc - ok
11:19:22.0234 2660 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:19:22.0241 2660 circlass - ok
11:19:22.0276 2660 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
11:19:22.0285 2660 CLFS - ok
11:19:22.0363 2660 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:19:22.0386 2660 clr_optimization_v2.0.50727_32 - ok
11:19:22.0475 2660 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:19:22.0575 2660 clr_optimization_v4.0.30319_32 - ok
11:19:22.0642 2660 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:19:22.0648 2660 CmBatt - ok
11:19:22.0692 2660 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
11:19:22.0698 2660 cmdide - ok
11:19:22.0748 2660 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\Windows\system32\Drivers\cng.sys
11:19:22.0763 2660 CNG - ok
11:19:22.0790 2660 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:19:22.0794 2660 Compbatt - ok
11:19:22.0854 2660 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
11:19:22.0870 2660 CompositeBus - ok
11:19:22.0892 2660 COMSysApp - ok
11:19:22.0930 2660 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:19:22.0937 2660 crcdisk - ok
11:19:23.0008 2660 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:19:23.0014 2660 CryptSvc - ok
11:19:23.0115 2660 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
11:19:23.0134 2660 DcomLaunch - ok
11:19:23.0177 2660 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
11:19:23.0190 2660 defragsvc - ok
11:19:23.0238 2660 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:19:23.0246 2660 DfsC - ok
11:19:23.0284 2660 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:19:23.0294 2660 Dhcp - ok
11:19:23.0345 2660 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
11:19:23.0353 2660 discache - ok
11:19:23.0382 2660 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:19:23.0388 2660 Disk - ok
11:19:23.0436 2660 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:19:23.0443 2660 Dnscache - ok
11:19:23.0492 2660 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
11:19:23.0515 2660 dot3svc - ok
11:19:23.0546 2660 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
11:19:23.0554 2660 DPS - ok
11:19:23.0586 2660 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:19:23.0597 2660 drmkaud - ok
11:19:23.0677 2660 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:19:23.0712 2660 DXGKrnl - ok
11:19:23.0756 2660 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
11:19:23.0763 2660 EapHost - ok
11:19:23.0914 2660 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
11:19:24.0073 2660 ebdrv - ok
11:19:24.0138 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\Windows\System32\lsass.exe
11:19:24.0144 2660 EFS - ok
11:19:24.0208 2660 [ 1697C39978CD69F6FBC15302EDCECE1F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:19:24.0243 2660 ehRecvr - ok
11:19:24.0291 2660 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
11:19:24.0298 2660 ehSched - ok
11:19:24.0358 2660 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:19:24.0393 2660 elxstor - ok
11:19:24.0437 2660 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
11:19:24.0443 2660 ErrDev - ok
11:19:24.0512 2660 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
11:19:24.0526 2660 EventSystem - ok
11:19:24.0560 2660 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
11:19:24.0570 2660 exfat - ok
11:19:24.0624 2660 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:19:24.0634 2660 fastfat - ok
11:19:24.0696 2660 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
11:19:24.0730 2660 Fax - ok
11:19:24.0759 2660 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:19:24.0765 2660 fdc - ok
11:19:24.0793 2660 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
11:19:24.0801 2660 fdPHost - ok
11:19:24.0827 2660 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
11:19:24.0835 2660 FDResPub - ok
11:19:24.0900 2660 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:19:24.0905 2660 FileInfo - ok
11:19:24.0937 2660 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:19:24.0944 2660 Filetrace - ok
11:19:24.0971 2660 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:19:24.0977 2660 flpydisk - ok
11:19:25.0012 2660 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:19:25.0020 2660 FltMgr - ok
11:19:25.0111 2660 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\Windows\system32\FntCache.dll
11:19:25.0135 2660 FontCache - ok
11:19:25.0207 2660 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:19:25.0214 2660 FontCache3.0.0.0 - ok
11:19:25.0249 2660 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:19:25.0257 2660 FsDepends - ok
11:19:25.0295 2660 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:19:25.0299 2660 Fs_Rec - ok
11:19:25.0351 2660 [ DAFBD9FE39197495AED6D51F3B85B5D2 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:19:25.0359 2660 fvevol - ok
11:19:25.0394 2660 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:19:25.0401 2660 gagp30kx - ok
11:19:25.0453 2660 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
11:19:25.0473 2660 gpsvc - ok
11:19:25.0524 2660 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:19:25.0530 2660 gupdate - ok
11:19:25.0568 2660 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:19:25.0574 2660 gupdatem - ok
11:19:25.0620 2660 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
11:19:25.0665 2660 hamachi - ok
11:19:25.0733 2660 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:19:25.0740 2660 hcw85cir - ok
11:19:25.0801 2660 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:19:25.0825 2660 HdAudAddService - ok
11:19:25.0856 2660 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
11:19:25.0879 2660 HDAudBus - ok
11:19:25.0901 2660 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:19:25.0909 2660 HidBatt - ok
11:19:25.0939 2660 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:19:25.0948 2660 HidBth - ok
11:19:25.0969 2660 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:19:25.0977 2660 HidIr - ok
11:19:26.0016 2660 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
11:19:26.0025 2660 hidserv - ok
11:19:26.0059 2660 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
11:19:26.0063 2660 HidUsb - ok
11:19:26.0104 2660 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:19:26.0111 2660 hkmsvc - ok
11:19:26.0145 2660 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:19:26.0157 2660 HomeGroupListener - ok
11:19:26.0198 2660 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:19:26.0204 2660 HomeGroupProvider - ok
11:19:26.0226 2660 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
11:19:26.0232 2660 HpSAMD - ok
11:19:26.0283 2660 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:19:26.0292 2660 HTTP - ok
11:19:26.0312 2660 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:19:26.0315 2660 hwpolicy - ok
11:19:26.0346 2660 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
11:19:26.0352 2660 i8042prt - ok
11:19:26.0405 2660 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:19:26.0428 2660 iaStorV - ok
11:19:26.0510 2660 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:19:26.0557 2660 idsvc - ok
11:19:26.0597 2660 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:19:26.0604 2660 iirsp - ok
11:19:26.0694 2660 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
11:19:26.0733 2660 IKEEXT - ok
11:19:26.0774 2660 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
11:19:26.0781 2660 intelide - ok
11:19:26.0822 2660 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:19:26.0831 2660 intelppm - ok
11:19:26.0867 2660 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:19:26.0878 2660 IPBusEnum - ok
11:19:26.0898 2660 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:19:26.0906 2660 IpFilterDriver - ok
11:19:26.0956 2660 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:19:26.0975 2660 iphlpsvc - ok
11:19:26.0998 2660 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
11:19:27.0005 2660 IPMIDRV - ok
11:19:27.0034 2660 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:19:27.0046 2660 IPNAT - ok
11:19:27.0081 2660 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:19:27.0086 2660 IRENUM - ok
11:19:27.0123 2660 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
11:19:27.0135 2660 isapnp - ok
11:19:27.0177 2660 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
11:19:27.0186 2660 iScsiPrt - ok
11:19:27.0214 2660 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:19:27.0220 2660 kbdclass - ok
11:19:27.0246 2660 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
11:19:27.0251 2660 kbdhid - ok
11:19:27.0275 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\Windows\system32\lsass.exe
11:19:27.0280 2660 KeyIso - ok
11:19:27.0308 2660 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:19:27.0312 2660 KSecDD - ok
11:19:27.0350 2660 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:19:27.0356 2660 KSecPkg - ok
11:19:27.0401 2660 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
11:19:27.0432 2660 KtmRm - ok
11:19:27.0495 2660 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\Windows\system32\srvsvc.dll
11:19:27.0508 2660 LanmanServer - ok
11:19:27.0552 2660 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:19:27.0564 2660 LanmanWorkstation - ok
11:19:27.0614 2660 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:19:27.0618 2660 lltdio - ok
11:19:27.0655 2660 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:19:27.0679 2660 lltdsvc - ok
11:19:27.0702 2660 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
11:19:27.0708 2660 lmhosts - ok
11:19:27.0784 2660 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:19:27.0807 2660 LSI_FC - ok
11:19:27.0846 2660 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:19:27.0854 2660 LSI_SAS - ok
11:19:27.0883 2660 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:19:27.0890 2660 LSI_SAS2 - ok
11:19:27.0924 2660 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:19:27.0933 2660 LSI_SCSI - ok
11:19:27.0965 2660 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
11:19:27.0970 2660 luafv - ok
11:19:28.0019 2660 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
11:19:28.0025 2660 MBAMProtector - ok
11:19:28.0109 2660 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
11:19:28.0123 2660 MBAMScheduler - ok
11:19:28.0182 2660 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
11:19:28.0201 2660 MBAMService - ok
11:19:28.0251 2660 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:19:28.0262 2660 Mcx2Svc - ok
11:19:28.0311 2660 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:19:28.0318 2660 megasas - ok
11:19:28.0356 2660 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:19:28.0380 2660 MegaSR - ok
11:19:28.0438 2660 Microsoft SharePoint Workspace Audit Service - ok
11:19:28.0484 2660 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
11:19:28.0491 2660 MMCSS - ok
11:19:28.0521 2660 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
11:19:28.0527 2660 Modem - ok
11:19:28.0553 2660 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:19:28.0556 2660 monitor - ok
11:19:28.0600 2660 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
11:19:28.0606 2660 mouclass - ok
11:19:28.0636 2660 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:19:28.0642 2660 mouhid - ok
11:19:28.0703 2660 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:19:28.0708 2660 mountmgr - ok
11:19:28.0760 2660 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:19:28.0769 2660 MozillaMaintenance - ok
11:19:28.0803 2660 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
11:19:28.0812 2660 mpio - ok
11:19:28.0845 2660 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:19:28.0858 2660 mpsdrv - ok
11:19:28.0913 2660 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
11:19:28.0934 2660 MpsSvc - ok
11:19:28.0966 2660 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:19:28.0975 2660 MRxDAV - ok
11:19:29.0026 2660 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:19:29.0034 2660 mrxsmb - ok
11:19:29.0092 2660 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:19:29.0101 2660 mrxsmb10 - ok
11:19:29.0139 2660 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:19:29.0144 2660 mrxsmb20 - ok
11:19:29.0184 2660 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
11:19:29.0189 2660 msahci - ok
11:19:29.0219 2660 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
11:19:29.0228 2660 msdsm - ok
11:19:29.0267 2660 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
11:19:29.0292 2660 MSDTC - ok
11:19:29.0337 2660 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:19:29.0343 2660 Msfs - ok
11:19:29.0372 2660 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:19:29.0379 2660 mshidkmdf - ok
11:19:29.0401 2660 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
11:19:29.0405 2660 msisadrv - ok
11:19:29.0456 2660 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:19:29.0467 2660 MSiSCSI - ok
11:19:29.0485 2660 msiserver - ok
11:19:29.0514 2660 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:19:29.0523 2660 MSKSSRV - ok
11:19:29.0547 2660 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:19:29.0555 2660 MSPCLOCK - ok
11:19:29.0581 2660 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:19:29.0603 2660 MSPQM - ok
11:19:29.0656 2660 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:19:29.0664 2660 MsRPC - ok
11:19:29.0716 2660 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
11:19:29.0728 2660 mssmbios - ok
11:19:29.0788 2660 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:19:29.0795 2660 MSTEE - ok
11:19:29.0819 2660 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:19:29.0826 2660 MTConfig - ok
11:19:29.0874 2660 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
11:19:29.0879 2660 MTsensor - ok
11:19:29.0898 2660 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
11:19:29.0904 2660 Mup - ok
11:19:29.0951 2660 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
11:19:29.0982 2660 napagent - ok
11:19:30.0024 2660 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:19:30.0036 2660 NativeWifiP - ok
11:19:30.0106 2660 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:19:30.0127 2660 NDIS - ok
11:19:30.0154 2660 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:19:30.0163 2660 NdisCap - ok
11:19:30.0199 2660 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:19:30.0206 2660 NdisTapi - ok
11:19:30.0229 2660 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:19:30.0234 2660 Ndisuio - ok
11:19:30.0273 2660 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:19:30.0293 2660 NdisWan - ok
11:19:30.0342 2660 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:19:30.0349 2660 NDProxy - ok
11:19:30.0398 2660 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:19:30.0404 2660 NetBIOS - ok
11:19:30.0440 2660 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:19:30.0451 2660 NetBT - ok
11:19:30.0489 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\Windows\system32\lsass.exe
11:19:30.0495 2660 Netlogon - ok
11:19:30.0561 2660 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
11:19:30.0575 2660 Netman - ok
11:19:30.0638 2660 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:19:30.0660 2660 NetMsmqActivator - ok
11:19:30.0686 2660 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:19:30.0692 2660 NetPipeActivator - ok
11:19:30.0780 2660 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
11:19:30.0793 2660 netprofm - ok
11:19:30.0834 2660 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:19:30.0837 2660 NetTcpActivator - ok
11:19:30.0852 2660 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:19:30.0855 2660 NetTcpPortSharing - ok
11:19:30.0914 2660 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:19:30.0918 2660 nfrd960 - ok
11:19:30.0988 2660 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
11:19:30.0995 2660 NlaSvc - ok
11:19:31.0063 2660 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
11:19:31.0067 2660 nmwcd - ok
11:19:31.0121 2660 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
11:19:31.0125 2660 nmwcdc - ok
11:19:31.0180 2660 [ 99B224F8026CB534724AA3C408561E45 ] nmwcdnsu C:\Windows\system32\drivers\nmwcdnsu.sys
11:19:31.0186 2660 nmwcdnsu - ok
11:19:31.0215 2660 [ D23257682D349A5E2E4507ED33DECC16 ] nmwcdnsuc C:\Windows\system32\drivers\nmwcdnsuc.sys
11:19:31.0219 2660 nmwcdnsuc - ok
11:19:31.0248 2660 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:19:31.0255 2660 Npfs - ok
11:19:31.0294 2660 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
11:19:31.0302 2660 nsi - ok
11:19:31.0326 2660 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:19:31.0334 2660 nsiproxy - ok
11:19:31.0487 2660 [ 5126C5402C730C2A953275D8497A4715 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:19:31.0536 2660 Ntfs - ok
11:19:31.0574 2660 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
11:19:31.0578 2660 Null - ok
11:19:31.0635 2660 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:19:31.0645 2660 nvraid - ok
11:19:31.0685 2660 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:19:31.0696 2660 nvstor - ok
11:19:31.0756 2660 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
11:19:31.0769 2660 nv_agp - ok
11:19:31.0828 2660 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
11:19:31.0835 2660 ohci1394 - ok
11:19:31.0939 2660 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:19:31.0950 2660 ose - ok
11:19:32.0195 2660 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:19:32.0380 2660 osppsvc - ok
11:19:32.0487 2660 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:19:32.0520 2660 p2pimsvc - ok
11:19:32.0608 2660 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
11:19:32.0642 2660 p2psvc - ok
11:19:32.0691 2660 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:19:32.0696 2660 Parport - ok
11:19:32.0740 2660 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:19:32.0745 2660 partmgr - ok
11:19:32.0802 2660 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:19:32.0808 2660 Parvdm - ok
11:19:32.0854 2660 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:19:32.0865 2660 PcaSvc - ok
11:19:32.0947 2660 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
11:19:32.0954 2660 pccsmcfd - ok
11:19:32.0994 2660 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
11:19:33.0001 2660 pci - ok
11:19:33.0061 2660 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
11:19:33.0067 2660 pciide - ok
11:19:33.0127 2660 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:19:33.0138 2660 pcmcia - ok
11:19:33.0173 2660 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
11:19:33.0178 2660 pcw - ok
11:19:33.0284 2660 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:19:33.0301 2660 PEAUTH - ok
11:19:33.0542 2660 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
11:19:33.0611 2660 pla - ok
11:19:33.0681 2660 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:19:33.0698 2660 PlugPlay - ok
11:19:33.0739 2660 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:19:33.0750 2660 PNRPAutoReg - ok
11:19:33.0788 2660 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:19:33.0804 2660 PNRPsvc - ok
11:19:33.0868 2660 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:19:33.0898 2660 PolicyAgent - ok
11:19:33.0954 2660 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
11:19:33.0967 2660 Power - ok
11:19:34.0019 2660 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:19:34.0027 2660 PptpMiniport - ok
11:19:34.0064 2660 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:19:34.0072 2660 Processor - ok
11:19:34.0164 2660 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\Windows\system32\profsvc.dll
11:19:34.0176 2660 ProfSvc - ok
11:19:34.0230 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:19:34.0238 2660 ProtectedStorage - ok
11:19:34.0278 2660 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:19:34.0288 2660 Psched - ok
11:19:34.0427 2660 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:19:34.0497 2660 ql2300 - ok
11:19:34.0530 2660 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:19:34.0539 2660 ql40xx - ok
11:19:34.0646 2660 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
11:19:34.0675 2660 QWAVE - ok
11:19:34.0713 2660 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:19:34.0722 2660 QWAVEdrv - ok
11:19:34.0803 2660 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:19:34.0809 2660 RasAcd - ok
11:19:34.0892 2660 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:19:34.0914 2660 RasAgileVpn - ok
11:19:34.0951 2660 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
11:19:34.0974 2660 RasAuto - ok
11:19:35.0021 2660 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:19:35.0029 2660 Rasl2tp - ok
11:19:35.0083 2660 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
11:19:35.0096 2660 RasMan - ok
11:19:35.0129 2660 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:19:35.0152 2660 RasPppoe - ok
11:19:35.0190 2660 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:19:35.0200 2660 RasSstp - ok
11:19:35.0251 2660 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:19:35.0265 2660 rdbss - ok
11:19:35.0300 2660 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:19:35.0304 2660 rdpbus - ok
11:19:35.0333 2660 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:19:35.0337 2660 RDPCDD - ok
11:19:35.0388 2660 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:19:35.0391 2660 RDPENCDD - ok
11:19:35.0443 2660 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:19:35.0446 2660 RDPREFMP - ok
11:19:35.0487 2660 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:19:35.0498 2660 RDPWD - ok
11:19:35.0532 2660 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:19:35.0538 2660 rdyboost - ok
11:19:35.0589 2660 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
11:19:35.0598 2660 RemoteAccess - ok
11:19:35.0666 2660 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:19:35.0676 2660 RemoteRegistry - ok
11:19:35.0720 2660 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:19:35.0726 2660 RpcEptMapper - ok
11:19:35.0778 2660 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
11:19:35.0783 2660 RpcLocator - ok
11:19:35.0824 2660 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
11:19:35.0843 2660 RpcSs - ok
11:19:35.0891 2660 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:19:35.0894 2660 rspndr - ok
11:19:35.0938 2660 [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:19:35.0947 2660 RTL8167 - ok
11:19:35.0969 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\Windows\system32\lsass.exe
11:19:35.0975 2660 SamSs - ok
11:19:35.0998 2660 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
11:19:36.0001 2660 sbp2port - ok
11:19:36.0042 2660 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:19:36.0048 2660 SCardSvr - ok
11:19:36.0066 2660 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:19:36.0069 2660 scfilter - ok
11:19:36.0119 2660 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\Windows\system32\schedsvc.dll
11:19:36.0131 2660 Schedule - ok
11:19:36.0151 2660 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
11:19:36.0152 2660 SCPolicySvc - ok
11:19:36.0189 2660 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:19:36.0195 2660 SDRSVC - ok
11:19:36.0232 2660 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:19:36.0234 2660 secdrv - ok
11:19:36.0256 2660 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
11:19:36.0262 2660 seclogon - ok
11:19:36.0277 2660 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
11:19:36.0282 2660 SENS - ok
11:19:36.0307 2660 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:19:36.0313 2660 SensrSvc - ok
11:19:36.0338 2660 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:19:36.0341 2660 Serenum - ok
11:19:36.0357 2660 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:19:36.0360 2660 Serial - ok
11:19:36.0398 2660 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:19:36.0402 2660 sermouse - ok
11:19:36.0467 2660 [ E90CE237E99C5D26CB3872318A7799D0 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
11:19:36.0476 2660 ServiceLayer - ok
11:19:36.0531 2660 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
11:19:36.0538 2660 SessionEnv - ok
11:19:36.0575 2660 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:19:36.0590 2660 sffdisk - ok
11:19:36.0621 2660 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:19:36.0628 2660 sffp_mmc - ok
11:19:36.0672 2660 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:19:36.0676 2660 sffp_sd - ok
11:19:36.0702 2660 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:19:36.0706 2660 sfloppy - ok
11:19:36.0736 2660 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:19:36.0744 2660 SharedAccess - ok
11:19:36.0782 2660 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:19:36.0787 2660 ShellHWDetection - ok
11:19:36.0816 2660 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
11:19:36.0820 2660 sisagp - ok
11:19:36.0837 2660 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:19:36.0842 2660 SiSRaid2 - ok
11:19:36.0878 2660 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:19:36.0884 2660 SiSRaid4 - ok
11:19:36.0920 2660 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:19:36.0930 2660 Smb - ok
11:19:36.0998 2660 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:19:37.0001 2660 SNMPTRAP - ok
11:19:37.0020 2660 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
11:19:37.0021 2660 spldr - ok
11:19:37.0081 2660 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\Windows\System32\spoolsv.exe
11:19:37.0086 2660 Spooler - ok
11:19:37.0271 2660 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
11:19:37.0361 2660 sppsvc - ok
11:19:37.0410 2660 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:19:37.0427 2660 sppuinotify - ok
11:19:37.0501 2660 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:19:37.0512 2660 srv - ok
11:19:37.0574 2660 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:19:37.0588 2660 srv2 - ok
11:19:37.0632 2660 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:19:37.0640 2660 srvnet - ok
11:19:37.0693 2660 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:19:37.0727 2660 SSDPSRV - ok
11:19:37.0805 2660 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:19:37.0810 2660 SstpSvc - ok
11:19:37.0848 2660 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:19:37.0871 2660 stexstor - ok
11:19:37.0936 2660 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
11:19:37.0948 2660 StiSvc - ok
11:19:37.0990 2660 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
11:19:38.0001 2660 swenum - ok
11:19:38.0049 2660 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
11:19:38.0062 2660 swprv - ok
11:19:38.0136 2660 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
11:19:38.0180 2660 SysMain - ok
11:19:38.0212 2660 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:19:38.0220 2660 TabletInputService - ok
11:19:38.0242 2660 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
11:19:38.0253 2660 TapiSrv - ok
11:19:38.0276 2660 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
11:19:38.0283 2660 TBS - ok
11:19:38.0438 2660 [ 55E9965552741F3850CB22CBBA9671ED ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:19:38.0502 2660 Tcpip - ok
11:19:38.0579 2660 [ 55E9965552741F3850CB22CBBA9671ED ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:19:38.0610 2660 TCPIP6 - ok
11:19:38.0697 2660 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:19:38.0701 2660 tcpipreg - ok
11:19:38.0757 2660 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:19:38.0765 2660 TDPIPE - ok
11:19:38.0827 2660 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:19:38.0835 2660 TDTCP - ok
11:19:38.0872 2660 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:19:38.0885 2660 tdx - ok
11:19:38.0913 2660 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
11:19:38.0947 2660 TermDD - ok
11:19:39.0014 2660 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\Windows\System32\termsrv.dll
11:19:39.0060 2660 TermService - ok
11:19:39.0117 2660 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
11:19:39.0131 2660 Themes - ok
11:19:39.0172 2660 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
11:19:39.0179 2660 THREADORDER - ok
11:19:39.0271 2660 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
11:19:39.0282 2660 TrkWks - ok
11:19:39.0397 2660 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:19:39.0409 2660 TrustedInstaller - ok
11:19:39.0474 2660 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:19:39.0487 2660 tssecsrv - ok
11:19:39.0523 2660 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:19:39.0532 2660 tunnel - ok
11:19:39.0635 2660 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:19:39.0643 2660 uagp35 - ok
11:19:39.0708 2660 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:19:39.0740 2660 udfs - ok
11:19:39.0824 2660 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:19:39.0836 2660 UI0Detect - ok
11:19:39.0905 2660 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
11:19:39.0914 2660 uliagpkx - ok
11:19:39.0984 2660 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:19:39.0990 2660 umbus - ok
11:19:40.0040 2660 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:19:40.0043 2660 UmPass - ok
11:19:40.0089 2660 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
11:19:40.0110 2660 upnphost - ok
11:19:40.0156 2660 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
11:19:40.0161 2660 upperdev - ok
11:19:40.0193 2660 [ C31AE588E403042632DC796CF09E30B0 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:19:40.0198 2660 usbccgp - ok
(pokračování na další straně)

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 06 led 2013 12:18

Zbytek loku TDSS Killer
================
11:19:40.0220 2660 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
11:19:40.0227 2660 usbcir - ok
11:19:40.0250 2660 [ E4C436D914768CE965D5E659BA7EEBD8 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:19:40.0254 2660 usbehci - ok
11:19:40.0279 2660 [ BDCD7156EC37448F08633FD899823620 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:19:40.0287 2660 usbhub - ok
11:19:40.0310 2660 [ EB2D819A639015253C871CDA09D91D58 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
11:19:40.0314 2660 usbohci - ok
11:19:40.0333 2660 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:19:40.0337 2660 usbprint - ok
11:19:40.0366 2660 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
11:19:40.0372 2660 usbscan - ok
11:19:40.0410 2660 [ 88701ECA76145E2C011C0EEFF0F7B70E ] usbser C:\Windows\system32\drivers\usbser.sys
11:19:40.0414 2660 usbser - ok
11:19:40.0432 2660 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
11:19:40.0436 2660 UsbserFilt - ok
11:19:40.0466 2660 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:19:40.0473 2660 USBSTOR - ok
11:19:40.0509 2660 [ 22480BF4E5A09192E5E30BA4DDE79FA4 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:19:40.0514 2660 usbuhci - ok
11:19:40.0550 2660 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
11:19:40.0557 2660 usbvideo - ok
11:19:40.0591 2660 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
11:19:40.0597 2660 UxSms - ok
11:19:40.0647 2660 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\Windows\system32\lsass.exe
11:19:40.0650 2660 VaultSvc - ok
11:19:40.0690 2660 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
11:19:40.0695 2660 vdrvroot - ok
11:19:40.0732 2660 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
11:19:40.0760 2660 vds - ok
11:19:40.0789 2660 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:19:40.0798 2660 vga - ok
11:19:40.0823 2660 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:19:40.0829 2660 VgaSave - ok
11:19:40.0849 2660 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
11:19:40.0856 2660 vhdmp - ok
11:19:40.0873 2660 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
11:19:40.0879 2660 viaagp - ok
11:19:40.0907 2660 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:19:40.0913 2660 ViaC7 - ok
11:19:40.0930 2660 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
11:19:40.0936 2660 viaide - ok
11:19:40.0960 2660 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
11:19:40.0963 2660 volmgr - ok
11:19:40.0996 2660 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:19:41.0002 2660 volmgrx - ok
11:19:41.0052 2660 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:19:41.0058 2660 volsnap - ok
11:19:41.0102 2660 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:19:41.0109 2660 vsmraid - ok
11:19:41.0168 2660 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
11:19:41.0218 2660 VSS - ok
11:19:41.0323 2660 [ EF11725916A69DFAF82AB26EC219F088 ] vToolbarUpdater13.3.2 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe
11:19:41.0369 2660 vToolbarUpdater13.3.2 - ok
11:19:41.0402 2660 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:19:41.0408 2660 vwifibus - ok
11:19:41.0432 2660 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:19:41.0440 2660 vwififlt - ok
11:19:41.0506 2660 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
11:19:41.0540 2660 W32Time - ok
11:19:41.0600 2660 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:19:41.0609 2660 WacomPen - ok
11:19:41.0680 2660 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:19:41.0691 2660 WANARP - ok
11:19:41.0718 2660 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:19:41.0723 2660 Wanarpv6 - ok
11:19:41.0855 2660 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:19:41.0934 2660 WatAdminSvc - ok
11:19:42.0033 2660 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
11:19:42.0112 2660 wbengine - ok
11:19:42.0165 2660 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:19:42.0192 2660 WbioSrvc - ok
11:19:42.0244 2660 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:19:42.0275 2660 wcncsvc - ok
11:19:42.0316 2660 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:19:42.0324 2660 WcsPlugInService - ok
11:19:42.0362 2660 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:19:42.0367 2660 Wd - ok
11:19:42.0456 2660 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:19:42.0466 2660 Wdf01000 - ok
11:19:42.0502 2660 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:19:42.0511 2660 WdiServiceHost - ok
11:19:42.0547 2660 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:19:42.0558 2660 WdiSystemHost - ok
11:19:42.0613 2660 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\Windows\System32\webclnt.dll
11:19:42.0634 2660 WebClient - ok
11:19:42.0685 2660 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:19:42.0707 2660 Wecsvc - ok
11:19:42.0746 2660 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:19:42.0768 2660 wercplsupport - ok
11:19:42.0804 2660 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
11:19:42.0814 2660 WerSvc - ok
11:19:42.0836 2660 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:19:42.0841 2660 WfpLwf - ok
11:19:42.0873 2660 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:19:42.0907 2660 WIMMount - ok
11:19:42.0976 2660 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:19:43.0002 2660 WinDefend - ok
11:19:43.0016 2660 WinHttpAutoProxySvc - ok
11:19:43.0082 2660 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:19:43.0085 2660 Winmgmt - ok
11:19:43.0136 2660 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
11:19:43.0170 2660 WinRM - ok
11:19:43.0226 2660 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:19:43.0234 2660 WinUsb - ok
11:19:43.0291 2660 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:19:43.0321 2660 Wlansvc - ok
11:19:43.0348 2660 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
11:19:43.0355 2660 WmiAcpi - ok
11:19:43.0412 2660 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:19:43.0422 2660 wmiApSrv - ok
11:19:43.0508 2660 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:19:43.0567 2660 WMPNetworkSvc - ok
11:19:43.0606 2660 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:19:43.0619 2660 WPCSvc - ok
11:19:43.0679 2660 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:19:43.0691 2660 WPDBusEnum - ok
11:19:43.0728 2660 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:19:43.0737 2660 ws2ifsl - ok
11:19:43.0768 2660 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\Windows\System32\wscsvc.dll
11:19:43.0780 2660 wscsvc - ok
11:19:43.0802 2660 WSearch - ok
11:19:43.0978 2660 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:19:44.0033 2660 wuauserv - ok
11:19:44.0095 2660 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:19:44.0105 2660 WudfPf - ok
11:19:44.0142 2660 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:19:44.0153 2660 WUDFRd - ok
11:19:44.0200 2660 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:19:44.0223 2660 wudfsvc - ok
11:19:44.0265 2660 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:19:44.0295 2660 WwanSvc - ok
11:19:44.0342 2660 ================ Scan global ===============================
11:19:44.0396 2660 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
11:19:44.0442 2660 [ A9E43C040F405DB689FC29534EF0389B ] C:\Windows\system32\winsrv.dll
11:19:44.0486 2660 [ A9E43C040F405DB689FC29534EF0389B ] C:\Windows\system32\winsrv.dll
11:19:44.0527 2660 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:19:44.0575 2660 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:19:44.0591 2660 [Global] - ok
11:19:44.0593 2660 ================ Scan MBR ==================================
11:19:44.0638 2660 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:19:45.0610 2660 \Device\Harddisk0\DR0 - ok
11:19:45.0612 2660 ================ Scan VBR ==================================
11:19:45.0619 2660 [ 36F1DC35CA094A467EE5C8DBDC27CB9D ] \Device\Harddisk0\DR0\Partition1
11:19:45.0622 2660 \Device\Harddisk0\DR0\Partition1 - ok
11:19:45.0670 2660 [ E6557B6726255D2CC0471A10873FE1B3 ] \Device\Harddisk0\DR0\Partition2
11:19:45.0675 2660 \Device\Harddisk0\DR0\Partition2 - ok
11:19:45.0699 2660 [ 36955B81C1A129159D3B371DB4440917 ] \Device\Harddisk0\DR0\Partition3
11:19:45.0706 2660 \Device\Harddisk0\DR0\Partition3 - ok
11:19:45.0707 2660 ============================================================
11:19:45.0707 2660 Scan finished
11:19:45.0707 2660 ============================================================
11:19:45.0750 3036 Detected object count: 0
11:19:45.0750 3036 Actual detected object count: 0
11:20:01.0544 1324 Deinitialize success

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod MemeEme » 06 led 2013 12:27

Log z ComboFixu je složka souborů kterou když spustím tak mě to přesměruje do Počítač. Neudělal sem něco špatně?

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT

Příspěvekod Orcus » 06 led 2013 13:04

Klikni na ten log z CF pravým tlačítkem myšidla a otevři ho v Poznámkovým bloku třeba.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
MemeEme
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: leden 13
Pohlaví: Muž
Stav:
Offline

Re: Prosím o rychlou kontrolu logu HJT  Vyřešeno

Příspěvekod MemeEme » 07 led 2013 15:37

Takže zatím nebudu mít notebook po ruce zakže to zamykám.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 84 hostů