Prosím o kontrolu tohoto logu PC jde hodně pomalu_ Děkuji!
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:28:41, on 16.1.2013
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19088)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11g_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingApp.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingBar.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
C:\Program Files\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Programy\Windows_Commander_4_52\WINCMD32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\Elektřina\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programy\avgssie.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - C:\Program Files\Flash Capture\fcbho.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Magic Tree] C:\Users\Admin\AppData\Local\Temp\$wc\MAGICT~1.EXE
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O8 - Extra context menu item: Save F&lash with FlashCapture - res://C:\Program Files\Flash Capture\fciext.dll/FCIEXT.htm
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - C:\Program Files\Flash Capture\fciext.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 7293 bytes
Kontrola LOG pomalé PC Vyřešeno
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola LOG pomalé PC
Odinstaluj BingBar a Seznam software
v logu fixni:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po probìhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
v logu fixni:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po probìhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Kontrola LOG pomalé PC
alwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org
Verze: v2013.01.18.08
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 8.0.6001.19088
Admin :: ADMIN-PC [administrátor]
Ochrana: Povolena
18.1.2013 20:32:47
MBAM-log-2013-01-18 (20-40-08).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 217692
Uplynulý čas: 6 minut, 21 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 1
C:\ProgramData\Windows\msdr.dll (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
Nalezené klíče v registru: 1
HKCR\CLSID\{F12BE2CC-A901-4203-B4F2-ADCB957D1887} (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files\Seekeen (Trojan.Agent) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 86
C:\ProgramData\Windows\msdr.dll (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\wd0.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\r66v.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hj8ol0.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ch8l0.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\cs8v0k.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\2f88.tmp (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\p0j99p.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\pkg0u.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\nsswa.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ms0cfg32.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\pkg_0ll.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\tpl_0_c.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\er_00_0_l.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\jork_0_typ_col.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\soap0_pack.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\glom0_og.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\0_0u_l.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\go_0molg.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\roper0dun.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gagx.ee (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\toip0_tmp.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\rool0_pk.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\k8h00.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fest0r_ot.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\rty0_7z.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fe0_zip.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\deo0_sar.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\g7i0ol_kaz.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sgwe3t.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sdhttt.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gnquggbnst.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\mzyitcylscgyexywtgtocu.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kecmkjekfxzuskwkhgqhrcr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\abby0_tar.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\soap0_wsdl.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\update00.b.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\update10.b.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uezeyekhbko.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ugxzcnownvrku.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ummyiqrdyjnnxdgqv.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\upkvdnoljqd.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uxaidejkwkverzpforuudfdlmk.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uyrqycuvmebsbtoi.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\2vs2.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\1jfuweif.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\124kkk290347.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hleo32.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\clean_computer.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\win8security_scanner.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\anajbio.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kowuzpecxaxj.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kpc99ir.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sys_drive.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\irb700.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\awt43abr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\oobvr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fvjcrgr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sdjutta.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\an2ans.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\alteki.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gl4rhyq.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\spoolsv.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\teamviewer.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\vlcplayer.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\conhost.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\csrss.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hlshcfswygiumwpf.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\yzkdqxellihjwydkqfff.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\mdsndesbnacnbopudwn.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\tubnfsuacpxyosxdpuo.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\dfpxvxmilgtruppb.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fqpypxnjpxgcmhqz.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\lcqdfgfnifsykhsksop.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sseqkyaeatslxdldwsamex.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\x88ydd3.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\wlsidten.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\a1kg3am.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ua8d9ee.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\a43vtzgbdgv.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\xxx0h2ans.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fghyd.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\asknpavbb.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gmexwbrvazfmravermyqnfnan.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\vjpkqtg.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\low.exe (Backdoor.Agent.DC) -> Nebyla provedena žádná instrukce.
(konec)
www.malwarebytes.org
Verze: v2013.01.18.08
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 8.0.6001.19088
Admin :: ADMIN-PC [administrátor]
Ochrana: Povolena
18.1.2013 20:32:47
MBAM-log-2013-01-18 (20-40-08).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 217692
Uplynulý čas: 6 minut, 21 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 1
C:\ProgramData\Windows\msdr.dll (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
Nalezené klíče v registru: 1
HKCR\CLSID\{F12BE2CC-A901-4203-B4F2-ADCB957D1887} (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files\Seekeen (Trojan.Agent) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 86
C:\ProgramData\Windows\msdr.dll (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\wd0.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\r66v.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hj8ol0.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ch8l0.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\cs8v0k.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\2f88.tmp (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\p0j99p.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\pkg0u.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\nsswa.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ms0cfg32.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\pkg_0ll.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\tpl_0_c.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\er_00_0_l.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\jork_0_typ_col.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\soap0_pack.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\glom0_og.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\0_0u_l.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\go_0molg.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\roper0dun.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gagx.ee (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\toip0_tmp.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\rool0_pk.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\k8h00.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fest0r_ot.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\rty0_7z.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fe0_zip.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\deo0_sar.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\g7i0ol_kaz.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sgwe3t.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sdhttt.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gnquggbnst.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\mzyitcylscgyexywtgtocu.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kecmkjekfxzuskwkhgqhrcr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\abby0_tar.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\soap0_wsdl.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\update00.b.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\update10.b.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uezeyekhbko.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ugxzcnownvrku.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ummyiqrdyjnnxdgqv.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\upkvdnoljqd.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uxaidejkwkverzpforuudfdlmk.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\uyrqycuvmebsbtoi.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\2vs2.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\1jfuweif.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\124kkk290347.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hleo32.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\clean_computer.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\win8security_scanner.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\anajbio.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kowuzpecxaxj.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\kpc99ir.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sys_drive.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\irb700.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\awt43abr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\oobvr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fvjcrgr.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sdjutta.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\an2ans.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\alteki.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gl4rhyq.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\spoolsv.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\teamviewer.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\vlcplayer.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\conhost.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\csrss.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\hlshcfswygiumwpf.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\yzkdqxellihjwydkqfff.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\mdsndesbnacnbopudwn.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\tubnfsuacpxyosxdpuo.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\dfpxvxmilgtruppb.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fqpypxnjpxgcmhqz.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\lcqdfgfnifsykhsksop.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\sseqkyaeatslxdldwsamex.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\x88ydd3.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\wlsidten.dll (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\a1kg3am.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\ua8d9ee.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\a43vtzgbdgv.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\xxx0h2ans.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\fghyd.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\asknpavbb.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\gmexwbrvazfmravermyqnfnan.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\vjpkqtg.exe (Exploit.Drop.GS) -> Nebyla provedena žádná instrukce.
c:\users\admin\appdata\local\temp\low\low.exe (Backdoor.Agent.DC) -> Nebyla provedena žádná instrukce.
(konec)
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola LOG pomalé PC
- Takže spus znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Kontrola LOG pomalé PC
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org
Verze: v2013.01.18.08
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 8.0.6001.19088
Admin :: ADMIN-PC [administrátor]
Ochrana: Povolena
19.1.2013 19:30:43
mbam-log-2013-01-19 (19-30-43).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 217354
Uplynulý čas: 6 minut, 31 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files\Seekeen (Trojan.Agent) -> Přesun do karantény a smazání se zdařilo.
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
www.malwarebytes.org
Verze: v2013.01.18.08
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 8.0.6001.19088
Admin :: ADMIN-PC [administrátor]
Ochrana: Povolena
19.1.2013 19:30:43
mbam-log-2013-01-19 (19-30-43).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 217354
Uplynulý čas: 6 minut, 31 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files\Seekeen (Trojan.Agent) -> Přesun do karantény a smazání se zdařilo.
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
Re: Kontrola LOG pomalé PC
19:47:31.0053 6012 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
19:47:31.0677 6012 ============================================================
19:47:31.0677 6012 Current date / time: 2013/01/19 19:47:31.0677
19:47:31.0677 6012 SystemInfo:
19:47:31.0677 6012
19:47:31.0677 6012 OS Version: 6.0.6001 ServicePack: 1.0
19:47:31.0677 6012 Product type: Workstation
19:47:31.0677 6012 ComputerName: ADMIN-PC
19:47:31.0677 6012 UserName: Admin
19:47:31.0677 6012 Windows directory: C:\Windows
19:47:31.0677 6012 System windows directory: C:\Windows
19:47:31.0677 6012 Processor architecture: Intel x86
19:47:31.0677 6012 Number of processors: 2
19:47:31.0677 6012 Page size: 0x1000
19:47:31.0677 6012 Boot type: Normal boot
19:47:31.0677 6012 ============================================================
19:47:34.0516 6012 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:47:35.0374 6012 Drive \Device\Harddisk1\DR1 - Size: 0xF8400000 (3.88 Gb), SectorSize: 0x200, Cylinders: 0x1FA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:47:35.0374 6012 ============================================================
19:47:35.0374 6012 \Device\Harddisk0\DR0:
19:47:35.0374 6012 MBR partitions:
19:47:35.0374 6012 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1C13870A
19:47:35.0405 6012 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1C138788, BlocksNum 0x1E2485F8
19:47:35.0405 6012 \Device\Harddisk1\DR1:
19:47:35.0405 6012 MBR partitions:
19:47:35.0405 6012 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0x7C1FC0
19:47:35.0405 6012 ============================================================
19:47:35.0514 6012 C: <-> \Device\Harddisk0\DR0\Partition2
19:47:35.0811 6012 D: <-> \Device\Harddisk0\DR0\Partition1
19:47:35.0811 6012 ============================================================
19:47:35.0811 6012 Initialize success
19:47:35.0811 6012 ============================================================
19:47:39.0305 4060 ============================================================
19:47:39.0305 4060 Scan started
19:47:39.0305 4060 Mode: Manual;
19:47:39.0305 4060 ============================================================
19:47:40.0444 4060 ================ Scan system memory ========================
19:47:40.0444 4060 System memory - ok
19:47:40.0444 4060 ================ Scan services =============================
19:47:40.0709 4060 [ 585E64BB6DFBC0A2F1F0B554DED012DF ] 61883 C:\Windows\system32\DRIVERS\61883.sys
19:47:40.0709 4060 61883 - ok
19:47:40.0818 4060 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
19:47:40.0818 4060 ACPI - ok
19:47:40.0865 4060 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
19:47:40.0865 4060 adp94xx - ok
19:47:40.0881 4060 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
19:47:40.0881 4060 adpahci - ok
19:47:40.0928 4060 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
19:47:40.0928 4060 adpu160m - ok
19:47:40.0943 4060 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
19:47:40.0943 4060 adpu320 - ok
19:47:40.0990 4060 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:47:40.0990 4060 AeLookupSvc - ok
19:47:41.0099 4060 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
19:47:41.0099 4060 AFD - ok
19:47:41.0162 4060 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:47:41.0162 4060 agp440 - ok
19:47:41.0208 4060 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
19:47:41.0208 4060 aic78xx - ok
19:47:41.0224 4060 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
19:47:41.0224 4060 ALG - ok
19:47:41.0255 4060 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
19:47:41.0255 4060 aliide - ok
19:47:41.0271 4060 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
19:47:41.0271 4060 amdagp - ok
19:47:41.0286 4060 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
19:47:41.0286 4060 amdide - ok
19:47:41.0302 4060 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
19:47:41.0302 4060 AmdK7 - ok
19:47:41.0318 4060 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
19:47:41.0318 4060 AmdK8 - ok
19:47:41.0349 4060 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
19:47:41.0349 4060 Appinfo - ok
19:47:41.0364 4060 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
19:47:41.0364 4060 arc - ok
19:47:41.0380 4060 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
19:47:41.0396 4060 arcsas - ok
19:47:41.0411 4060 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:47:41.0411 4060 AsyncMac - ok
19:47:41.0427 4060 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
19:47:41.0427 4060 atapi - ok
19:47:41.0458 4060 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:47:41.0458 4060 AudioEndpointBuilder - ok
19:47:41.0458 4060 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
19:47:41.0458 4060 Audiosrv - ok
19:47:41.0505 4060 [ F4B56425A00BEB32F5FA6603FF7B0EA2 ] Avc C:\Windows\system32\DRIVERS\avc.sys
19:47:41.0505 4060 Avc - ok
19:47:41.0552 4060 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
19:47:41.0552 4060 Beep - ok
19:47:41.0583 4060 [ D3E6D78285529962349A7F1617035938 ] BFE C:\Windows\System32\bfe.dll
19:47:41.0598 4060 BFE - ok
19:47:41.0645 4060 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
19:47:41.0661 4060 BITS - ok
19:47:41.0676 4060 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
19:47:41.0676 4060 blbdrive - ok
19:47:41.0708 4060 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:47:41.0708 4060 bowser - ok
19:47:41.0739 4060 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
19:47:41.0739 4060 BrFiltLo - ok
19:47:41.0754 4060 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
19:47:41.0754 4060 BrFiltUp - ok
19:47:41.0801 4060 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
19:47:41.0801 4060 Browser - ok
19:47:41.0832 4060 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
19:47:41.0832 4060 Brserid - ok
19:47:41.0848 4060 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
19:47:41.0848 4060 BrSerWdm - ok
19:47:41.0864 4060 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
19:47:41.0864 4060 BrUsbMdm - ok
19:47:41.0926 4060 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
19:47:41.0926 4060 BrUsbSer - ok
19:47:41.0942 4060 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
19:47:41.0942 4060 BTHMODEM - ok
19:47:41.0973 4060 [ E292176878F933E6A3CC46D6109EF1BB ] CamSuiteVAC C:\Windows\system32\DRIVERS\CamSuiteVAC.sys
19:47:41.0973 4060 CamSuiteVAC - ok
19:47:42.0160 4060 [ 1778EBA872274C1226D869CD9486847E ] Capture Device Service C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
19:47:42.0160 4060 Capture Device Service - ok
19:47:42.0176 4060 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:47:42.0176 4060 cdfs - ok
19:47:42.0176 4060 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:47:42.0176 4060 cdrom - ok
19:47:42.0207 4060 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
19:47:42.0207 4060 CertPropSvc - ok
19:47:42.0238 4060 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
19:47:42.0238 4060 circlass - ok
19:47:42.0254 4060 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
19:47:42.0269 4060 CLFS - ok
19:47:42.0441 4060 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:47:42.0441 4060 clr_optimization_v2.0.50727_32 - ok
19:47:42.0503 4060 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:47:42.0503 4060 clr_optimization_v4.0.30319_32 - ok
19:47:42.0550 4060 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:47:42.0550 4060 cmdide - ok
19:47:42.0566 4060 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
19:47:42.0566 4060 Compbatt - ok
19:47:42.0581 4060 COMSysApp - ok
19:47:42.0597 4060 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
19:47:42.0597 4060 crcdisk - ok
19:47:42.0612 4060 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
19:47:42.0612 4060 Crusoe - ok
19:47:42.0722 4060 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:47:42.0722 4060 CryptSvc - ok
19:47:42.0893 4060 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:47:42.0909 4060 DcomLaunch - ok
19:47:43.0049 4060 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:47:43.0065 4060 DfsC - ok
19:47:43.0174 4060 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
19:47:43.0190 4060 DFSR - ok
19:47:43.0299 4060 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
19:47:43.0299 4060 Dhcp - ok
19:47:43.0346 4060 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
19:47:43.0346 4060 disk - ok
19:47:43.0392 4060 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:47:43.0392 4060 Dnscache - ok
19:47:43.0439 4060 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
19:47:43.0470 4060 dot3svc - ok
19:47:43.0533 4060 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
19:47:43.0533 4060 DPS - ok
19:47:43.0580 4060 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:47:43.0580 4060 drmkaud - ok
19:47:43.0689 4060 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:47:43.0704 4060 DXGKrnl - ok
19:47:43.0720 4060 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
19:47:43.0720 4060 E1G60 - ok
19:47:43.0736 4060 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
19:47:43.0736 4060 EapHost - ok
19:47:43.0767 4060 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
19:47:43.0767 4060 Ecache - ok
19:47:43.0892 4060 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:47:43.0892 4060 ehRecvr - ok
19:47:43.0923 4060 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
19:47:43.0923 4060 ehSched - ok
19:47:43.0938 4060 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
19:47:43.0938 4060 ehstart - ok
19:47:43.0970 4060 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
19:47:43.0970 4060 elxstor - ok
19:47:44.0079 4060 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
19:47:44.0094 4060 EMDMgmt - ok
19:47:44.0110 4060 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:47:44.0110 4060 ErrDev - ok
19:47:44.0188 4060 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
19:47:44.0188 4060 EventSystem - ok
19:47:44.0250 4060 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
19:47:44.0250 4060 exfat - ok
19:47:44.0297 4060 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:47:44.0313 4060 fastfat - ok
19:47:44.0360 4060 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
19:47:44.0360 4060 fdc - ok
19:47:44.0391 4060 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
19:47:44.0406 4060 fdPHost - ok
19:47:44.0422 4060 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
19:47:44.0422 4060 FDResPub - ok
19:47:44.0453 4060 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:47:44.0453 4060 FileInfo - ok
19:47:44.0469 4060 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:47:44.0469 4060 Filetrace - ok
19:47:44.0484 4060 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
19:47:44.0484 4060 flpydisk - ok
19:47:44.0500 4060 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:47:44.0500 4060 FltMgr - ok
19:47:44.0687 4060 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:47:44.0718 4060 FontCache3.0.0.0 - ok
19:47:44.0734 4060 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:47:44.0750 4060 Fs_Rec - ok
19:47:44.0796 4060 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
19:47:44.0812 4060 gagp30kx - ok
19:47:44.0984 4060 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
19:47:45.0015 4060 gpsvc - ok
19:47:45.0108 4060 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:47:45.0108 4060 HdAudAddService - ok
19:47:45.0171 4060 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
19:47:45.0171 4060 HDAudBus - ok
19:47:45.0186 4060 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
19:47:45.0218 4060 HidBth - ok
19:47:45.0233 4060 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
19:47:45.0233 4060 HidIr - ok
19:47:45.0264 4060 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
19:47:45.0264 4060 hidserv - ok
19:47:45.0342 4060 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:47:45.0342 4060 HidUsb - ok
19:47:45.0420 4060 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:47:45.0420 4060 hkmsvc - ok
19:47:45.0452 4060 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
19:47:45.0452 4060 HpCISSs - ok
19:47:45.0530 4060 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:47:45.0592 4060 HTTP - ok
19:47:45.0639 4060 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
19:47:45.0639 4060 i2omp - ok
19:47:45.0810 4060 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:47:45.0810 4060 i8042prt - ok
19:47:45.0873 4060 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
19:47:45.0888 4060 iaStorV - ok
19:47:46.0044 4060 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:47:46.0076 4060 idsvc - ok
19:47:46.0091 4060 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
19:47:46.0091 4060 iirsp - ok
19:47:46.0232 4060 [ 68E8C415E102E5D79FD7E4A765B8CBA4 ] IKEEXT C:\Windows\System32\ikeext.dll
19:47:46.0278 4060 IKEEXT - ok
19:47:46.0356 4060 [ 251E85A3BAC210FFF6BAD3D1F33113E8 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
19:47:46.0388 4060 IntcAzAudAddService - ok
19:47:46.0419 4060 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
19:47:46.0419 4060 intelide - ok
19:47:46.0434 4060 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:47:46.0434 4060 intelppm - ok
19:47:46.0481 4060 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:47:46.0481 4060 IPBusEnum - ok
19:47:46.0497 4060 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:47:46.0512 4060 IpFilterDriver - ok
19:47:46.0590 4060 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:47:46.0590 4060 iphlpsvc - ok
19:47:46.0606 4060 IpInIp - ok
19:47:46.0622 4060 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
19:47:46.0622 4060 IPMIDRV - ok
19:47:46.0653 4060 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
19:47:46.0653 4060 IPNAT - ok
19:47:46.0668 4060 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:47:46.0668 4060 IRENUM - ok
19:47:46.0684 4060 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:47:46.0684 4060 isapnp - ok
19:47:46.0715 4060 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
19:47:46.0715 4060 iScsiPrt - ok
19:47:46.0731 4060 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
19:47:46.0731 4060 iteatapi - ok
19:47:46.0762 4060 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
19:47:46.0762 4060 iteraid - ok
19:47:46.0793 4060 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:47:46.0793 4060 kbdclass - ok
19:47:46.0809 4060 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
19:47:46.0809 4060 kbdhid - ok
19:47:46.0856 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
19:47:46.0856 4060 KeyIso - ok
19:47:46.0980 4060 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:47:46.0996 4060 KSecDD - ok
19:47:47.0058 4060 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
19:47:47.0058 4060 KtmRm - ok
19:47:47.0090 4060 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\system32\srvsvc.dll
19:47:47.0090 4060 LanmanServer - ok
19:47:47.0199 4060 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:47:47.0199 4060 LanmanWorkstation - ok
19:47:47.0230 4060 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:47:47.0230 4060 lltdio - ok
19:47:47.0261 4060 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:47:47.0261 4060 lltdsvc - ok
19:47:47.0277 4060 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:47:47.0292 4060 lmhosts - ok
19:47:47.0324 4060 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
19:47:47.0324 4060 LSI_FC - ok
19:47:47.0355 4060 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
19:47:47.0355 4060 LSI_SAS - ok
19:47:47.0370 4060 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
19:47:47.0386 4060 LSI_SCSI - ok
19:47:47.0417 4060 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
19:47:47.0417 4060 luafv - ok
19:47:47.0448 4060 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
19:47:47.0448 4060 MBAMProtector - ok
19:47:47.0620 4060 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:47:47.0620 4060 MBAMScheduler - ok
19:47:47.0667 4060 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:47:47.0682 4060 MBAMService - ok
19:47:47.0729 4060 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:47:47.0729 4060 Mcx2Svc - ok
19:47:47.0760 4060 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
19:47:47.0776 4060 megasas - ok
19:47:47.0807 4060 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
19:47:47.0807 4060 MegaSR - ok
19:47:47.0838 4060 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
19:47:47.0838 4060 MMCSS - ok
19:47:47.0854 4060 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
19:47:47.0870 4060 Modem - ok
19:47:47.0948 4060 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:47:47.0948 4060 monitor - ok
19:47:47.0963 4060 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:47:47.0963 4060 mouclass - ok
19:47:47.0994 4060 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:47:48.0010 4060 mouhid - ok
19:47:48.0041 4060 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
19:47:48.0041 4060 MountMgr - ok
19:47:48.0072 4060 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
19:47:48.0088 4060 MpFilter - ok
19:47:48.0104 4060 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
19:47:48.0104 4060 mpio - ok
19:47:48.0244 4060 MpKsl833d6dd7 - ok
19:47:48.0275 4060 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:47:48.0275 4060 mpsdrv - ok
19:47:48.0291 4060 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
19:47:48.0291 4060 MpsSvc - ok
19:47:48.0322 4060 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
19:47:48.0322 4060 Mraid35x - ok
19:47:48.0338 4060 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:47:48.0353 4060 MRxDAV - ok
19:47:48.0384 4060 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:47:48.0384 4060 mrxsmb - ok
19:47:48.0416 4060 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:47:48.0416 4060 mrxsmb10 - ok
19:47:48.0416 4060 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:47:48.0431 4060 mrxsmb20 - ok
19:47:48.0447 4060 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
19:47:48.0447 4060 msahci - ok
19:47:48.0462 4060 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:47:48.0462 4060 msdsm - ok
19:47:48.0478 4060 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
19:47:48.0478 4060 MSDTC - ok
19:47:48.0525 4060 [ 343291A4DFD7C923C3F71F550830EC1C ] MSDV C:\Windows\system32\DRIVERS\msdv.sys
19:47:48.0525 4060 MSDV - ok
19:47:48.0540 4060 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:47:48.0540 4060 Msfs - ok
19:47:48.0556 4060 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:47:48.0556 4060 msisadrv - ok
19:47:48.0587 4060 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:47:48.0587 4060 MSiSCSI - ok
19:47:48.0587 4060 msiserver - ok
19:47:48.0618 4060 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:47:48.0618 4060 MSKSSRV - ok
19:47:48.0665 4060 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
19:47:48.0665 4060 MsMpSvc - ok
19:47:48.0681 4060 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:47:48.0681 4060 MSPCLOCK - ok
19:47:48.0681 4060 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:47:48.0681 4060 MSPQM - ok
19:47:48.0696 4060 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:47:48.0696 4060 MsRPC - ok
19:47:48.0712 4060 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
19:47:48.0712 4060 mssmbios - ok
19:47:48.0728 4060 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:47:48.0728 4060 MSTEE - ok
19:47:48.0759 4060 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
19:47:48.0759 4060 Mup - ok
19:47:48.0790 4060 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
19:47:48.0790 4060 napagent - ok
19:47:48.0806 4060 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:47:48.0806 4060 NativeWifiP - ok
19:47:48.0852 4060 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:47:48.0852 4060 NDIS - ok
19:47:48.0868 4060 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:47:48.0868 4060 NdisTapi - ok
19:47:48.0884 4060 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:47:48.0884 4060 Ndisuio - ok
19:47:48.0899 4060 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:47:48.0899 4060 NdisWan - ok
19:47:48.0915 4060 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:47:48.0915 4060 NDProxy - ok
19:47:48.0930 4060 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:47:48.0930 4060 NetBIOS - ok
19:47:48.0946 4060 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
19:47:48.0962 4060 netbt - ok
19:47:48.0993 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
19:47:48.0993 4060 Netlogon - ok
19:47:49.0133 4060 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
19:47:49.0133 4060 Netman - ok
19:47:49.0180 4060 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
19:47:49.0180 4060 netprofm - ok
19:47:49.0227 4060 [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:47:49.0227 4060 NetTcpPortSharing - ok
19:47:49.0258 4060 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
19:47:49.0258 4060 nfrd960 - ok
19:47:49.0289 4060 [ 2CD24A6AF497D0E9B9BF3DA924ED05E6 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
19:47:49.0289 4060 NisDrv - ok
19:47:49.0336 4060 [ 3B846434055F80D9E89D0742F3ADAD34 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
19:47:49.0336 4060 NisSrv - ok
19:47:49.0430 4060 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:47:49.0430 4060 NlaSvc - ok
19:47:49.0508 4060 [ C4EBBBD7165BE535F0BFD06B80601D91 ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
19:47:49.0570 4060 NMIndexingService - ok
19:47:49.0617 4060 [ C3963D85B721A7F80D8A55F4E2867A3A ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
19:47:49.0617 4060 nmwcd - ok
19:47:49.0679 4060 [ 3859C69A77793180548802DAC9F34A38 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
19:47:49.0679 4060 nmwcdc - ok
19:47:49.0679 4060 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:47:49.0679 4060 Npfs - ok
19:47:49.0710 4060 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
19:47:49.0710 4060 nsi - ok
19:47:49.0726 4060 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:47:49.0773 4060 nsiproxy - ok
19:47:49.0820 4060 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:47:49.0944 4060 Ntfs - ok
19:47:49.0960 4060 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
19:47:49.0960 4060 ntrigdigi - ok
19:47:49.0976 4060 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
19:47:49.0976 4060 Null - ok
19:47:50.0381 4060 [ 0A1B502CBC8230DA74BEFBAADDB58916 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:47:50.0459 4060 nvlddmkm - ok
19:47:50.0490 4060 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:47:50.0490 4060 nvraid - ok
19:47:50.0506 4060 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:47:50.0506 4060 nvstor - ok
19:47:50.0553 4060 [ EB5A13F9139F20AD71ADF4BF79C3AA29 ] nvsvc C:\Windows\system32\nvvsvc.exe
19:47:50.0568 4060 nvsvc - ok
19:47:50.0662 4060 [ 0629259E3AF6BB0534FCECA208973404 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
19:47:50.0678 4060 nvUpdatusService - ok
19:47:50.0693 4060 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:47:50.0693 4060 nv_agp - ok
19:47:50.0709 4060 NwlnkFlt - ok
19:47:50.0709 4060 NwlnkFwd - ok
19:47:50.0756 4060 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
19:47:50.0756 4060 ohci1394 - ok
19:47:50.0802 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
19:47:50.0912 4060 p2pimsvc - ok
19:47:50.0958 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
19:47:50.0958 4060 p2psvc - ok
19:47:50.0990 4060 [ 3F988A7C348F6990DC65C744469BF296 ] PAC7302 C:\Windows\system32\DRIVERS\PAC7302.SYS
19:47:51.0005 4060 PAC7302 - ok
19:47:51.0021 4060 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
19:47:51.0021 4060 Parport - ok
19:47:51.0021 4060 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:47:51.0021 4060 partmgr - ok
19:47:51.0036 4060 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
19:47:51.0036 4060 Parvdm - ok
19:47:51.0052 4060 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
19:47:51.0052 4060 PcaSvc - ok
19:47:51.0083 4060 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
19:47:51.0083 4060 pccsmcfd - ok
19:47:51.0099 4060 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
19:47:51.0114 4060 pci - ok
19:47:51.0114 4060 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
19:47:51.0114 4060 pciide - ok
19:47:51.0146 4060 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
19:47:51.0146 4060 pcmcia - ok
19:47:51.0177 4060 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:47:51.0192 4060 PEAUTH - ok
19:47:51.0255 4060 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
19:47:51.0270 4060 pla - ok
19:47:51.0302 4060 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:47:51.0317 4060 PlugPlay - ok
19:47:51.0333 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
19:47:51.0348 4060 PNRPAutoReg - ok
19:47:51.0364 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
19:47:51.0364 4060 PNRPsvc - ok
19:47:51.0395 4060 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:47:51.0395 4060 PolicyAgent - ok
19:47:51.0426 4060 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:47:51.0426 4060 PptpMiniport - ok
19:47:51.0442 4060 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
19:47:51.0442 4060 Processor - ok
19:47:51.0458 4060 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
19:47:51.0458 4060 ProfSvc - ok
19:47:51.0473 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:47:51.0473 4060 ProtectedStorage - ok
19:47:51.0504 4060 [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched C:\Windows\system32\DRIVERS\pacer.sys
19:47:51.0504 4060 PSched - ok
19:47:51.0551 4060 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
19:47:51.0567 4060 ql2300 - ok
19:47:51.0582 4060 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
19:47:51.0598 4060 ql40xx - ok
19:47:51.0614 4060 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
19:47:51.0614 4060 QWAVE - ok
19:47:51.0614 4060 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:47:51.0614 4060 QWAVEdrv - ok
19:47:51.0629 4060 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:47:51.0629 4060 RasAcd - ok
19:47:51.0645 4060 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
19:47:51.0660 4060 RasAuto - ok
19:47:51.0660 4060 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:47:51.0676 4060 Rasl2tp - ok
19:47:51.0707 4060 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
19:47:51.0707 4060 RasMan - ok
19:47:51.0723 4060 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:47:51.0723 4060 RasPppoe - ok
19:47:51.0738 4060 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:47:51.0738 4060 RasSstp - ok
19:47:51.0754 4060 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:47:51.0754 4060 rdbss - ok
19:47:51.0785 4060 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:47:51.0785 4060 RDPCDD - ok
19:47:51.0801 4060 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
19:47:51.0816 4060 rdpdr - ok
19:47:51.0832 4060 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:47:51.0848 4060 RDPENCDD - ok
19:47:51.0863 4060 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:47:51.0879 4060 RDPWD - ok
19:47:51.0894 4060 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:47:51.0910 4060 RemoteAccess - ok
19:47:51.0926 4060 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:47:51.0926 4060 RemoteRegistry - ok
19:47:51.0988 4060 [ BD517C7FB119997EFFBE39D5E4B37B05 ] RichVideo C:\Program Files\CyberLink\Shared Files\RichVideo.exe
19:47:51.0988 4060 RichVideo - ok
19:47:52.0004 4060 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
19:47:52.0019 4060 RpcLocator - ok
19:47:52.0050 4060 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
19:47:52.0050 4060 RpcSs - ok
19:47:52.0082 4060 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:47:52.0097 4060 rspndr - ok
19:47:52.0128 4060 [ 283392AF1860ECDB5E0F8EBD7F3D72DF ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
19:47:52.0128 4060 RTL8169 - ok
19:47:52.0128 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
19:47:52.0144 4060 SamSs - ok
19:47:52.0160 4060 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:47:52.0160 4060 sbp2port - ok
19:47:52.0191 4060 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:47:52.0191 4060 SCardSvr - ok
19:47:52.0269 4060 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
19:47:52.0284 4060 Schedule - ok
19:47:52.0300 4060 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
19:47:52.0300 4060 SCPolicySvc - ok
19:47:52.0316 4060 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:47:52.0316 4060 SDRSVC - ok
19:47:52.0331 4060 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:47:52.0331 4060 secdrv - ok
19:47:52.0378 4060 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
19:47:52.0378 4060 seclogon - ok
19:47:52.0409 4060 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
19:47:52.0409 4060 SENS - ok
19:47:52.0440 4060 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
19:47:52.0440 4060 Serenum - ok
19:47:52.0456 4060 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
19:47:52.0456 4060 Serial - ok
19:47:52.0456 4060 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
19:47:52.0456 4060 sermouse - ok
19:47:52.0565 4060 [ 2D841B7B7F6DEC32162EDFCC69D61F42 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
19:47:52.0581 4060 ServiceLayer - ok
19:47:52.0612 4060 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
19:47:52.0612 4060 SessionEnv - ok
19:47:52.0628 4060 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:47:52.0643 4060 sffdisk - ok
19:47:52.0643 4060 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:47:52.0643 4060 sffp_mmc - ok
19:47:52.0659 4060 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:47:52.0659 4060 sffp_sd - ok
19:47:52.0674 4060 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
19:47:52.0674 4060 sfloppy - ok
19:47:52.0706 4060 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:47:52.0721 4060 SharedAccess - ok
19:47:52.0737 4060 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:47:52.0752 4060 ShellHWDetection - ok
19:47:52.0752 4060 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
19:47:52.0752 4060 sisagp - ok
19:47:52.0830 4060 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
19:47:52.0830 4060 SiSRaid2 - ok
19:47:52.0846 4060 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
19:47:52.0862 4060 SiSRaid4 - ok
19:47:52.0877 4060 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
19:47:52.0877 4060 SkypeUpdate - ok
19:47:52.0971 4060 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
19:47:53.0033 4060 slsvc - ok
19:47:53.0049 4060 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
19:47:53.0064 4060 SLUINotify - ok
19:47:53.0080 4060 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:47:53.0080 4060 Smb - ok
19:47:53.0096 4060 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:47:53.0096 4060 SNMPTRAP - ok
19:47:53.0127 4060 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
19:47:53.0127 4060 spldr - ok
19:47:53.0158 4060 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
19:47:53.0158 4060 Spooler - ok
19:47:53.0220 4060 [ 4F576E516CC76EC50A244586BCFA1C78 ] sptd C:\Windows\system32\Drivers\sptd.sys
19:47:53.0220 4060 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 4F576E516CC76EC50A244586BCFA1C78
19:47:53.0220 4060 sptd ( LockedFile.Multi.Generic ) - warning
19:47:53.0220 4060 sptd - detected LockedFile.Multi.Generic (1)
19:47:53.0330 4060 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
19:47:53.0345 4060 srv - ok
19:47:53.0361 4060 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:47:53.0361 4060 srv2 - ok
19:47:53.0376 4060 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:47:53.0376 4060 srvnet - ok
19:47:53.0408 4060 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:47:53.0408 4060 SSDPSRV - ok
19:47:53.0423 4060 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:47:53.0439 4060 SstpSvc - ok
19:47:53.0486 4060 [ 5A1D0CA8A5F1E7B4EC50B9D76C001F0E ] ss_bus C:\Windows\system32\DRIVERS\ss_bus.sys
19:47:53.0486 4060 ss_bus - ok
19:47:53.0486 4060 [ F0A85580E36A3A85059037D39A9CF079 ] ss_mdfl C:\Windows\system32\DRIVERS\ss_mdfl.sys
19:47:53.0486 4060 ss_mdfl - ok
19:47:53.0532 4060 [ 84C3DBFD1BFA4ADC0A950B3D5506CB00 ] ss_mdm C:\Windows\system32\DRIVERS\ss_mdm.sys
19:47:53.0532 4060 ss_mdm - ok
19:47:53.0579 4060 [ 306521935042FC0A6988D528643619B3 ] StarOpen C:\Windows\system32\drivers\StarOpen.sys
19:47:53.0579 4060 StarOpen - ok
19:47:53.0642 4060 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
19:47:53.0657 4060 Stereo Service - ok
19:47:53.0688 4060 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
19:47:53.0688 4060 stisvc - ok
19:47:53.0720 4060 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
19:47:53.0720 4060 swenum - ok
19:47:53.0735 4060 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
19:47:53.0751 4060 swprv - ok
19:47:53.0751 4060 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
19:47:53.0766 4060 Symc8xx - ok
19:47:53.0766 4060 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
19:47:53.0766 4060 Sym_hi - ok
19:47:53.0782 4060 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
19:47:53.0782 4060 Sym_u3 - ok
19:47:53.0813 4060 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
19:47:53.0813 4060 SysMain - ok
19:47:53.0844 4060 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:47:53.0844 4060 TabletInputService - ok
19:47:53.0860 4060 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
19:47:53.0860 4060 TapiSrv - ok
19:47:53.0876 4060 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
19:47:53.0891 4060 TBS - ok
19:47:53.0938 4060 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:47:53.0938 4060 Tcpip - ok
19:47:54.0000 4060 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
19:47:54.0016 4060 Tcpip6 - ok
19:47:54.0032 4060 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:47:54.0032 4060 tcpipreg - ok
19:47:54.0063 4060 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:47:54.0063 4060 TDPIPE - ok
19:47:54.0094 4060 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:47:54.0094 4060 TDTCP - ok
19:47:54.0110 4060 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:47:54.0110 4060 tdx - ok
19:47:54.0141 4060 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
19:47:54.0141 4060 TermDD - ok
19:47:54.0172 4060 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
19:47:54.0188 4060 TermService - ok
19:47:54.0203 4060 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
19:47:54.0203 4060 Themes - ok
19:47:54.0234 4060 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
19:47:54.0234 4060 THREADORDER - ok
19:47:54.0250 4060 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
19:47:54.0250 4060 TrkWks - ok
19:47:54.0312 4060 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:47:54.0328 4060 TrustedInstaller - ok
19:47:54.0344 4060 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:47:54.0344 4060 tssecsrv - ok
19:47:54.0359 4060 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
19:47:54.0359 4060 tunmp - ok
19:47:54.0375 4060 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:47:54.0375 4060 tunnel - ok
19:47:54.0390 4060 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
19:47:54.0390 4060 uagp35 - ok
19:47:54.0406 4060 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:47:54.0406 4060 udfs - ok
19:47:54.0437 4060 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:47:54.0437 4060 UI0Detect - ok
19:47:54.0500 4060 [ 332D341D92B933600D41953B08360DFB ] UleadBurningHelper C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
19:47:54.0515 4060 UleadBurningHelper - ok
19:47:54.0531 4060 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:47:54.0531 4060 uliagpkx - ok
19:47:54.0609 4060 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
19:47:54.0609 4060 uliahci - ok
19:47:54.0640 4060 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
19:47:54.0640 4060 UlSata - ok
19:47:54.0656 4060 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
19:47:54.0656 4060 ulsata2 - ok
19:47:54.0671 4060 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:47:54.0671 4060 umbus - ok
19:47:54.0702 4060 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
19:47:54.0702 4060 upnphost - ok
19:47:54.0734 4060 [ 0CCADC7391021376EDBB8AA649D04E68 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
19:47:54.0734 4060 upperdev - ok
19:47:54.0765 4060 [ 292A25BB75A568AE2C67169BA2C6365A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
19:47:54.0780 4060 usbaudio - ok
19:47:54.0796 4060 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:47:54.0796 4060 usbccgp - ok
19:47:54.0812 4060 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:47:54.0812 4060 usbcir - ok
19:47:54.0843 4060 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
19:47:54.0843 4060 usbehci - ok
19:47:54.0858 4060 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:47:54.0858 4060 usbhub - ok
19:47:54.0874 4060 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:47:54.0874 4060 usbohci - ok
19:47:54.0905 4060 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:47:54.0905 4060 usbprint - ok
19:47:54.0921 4060 [ A96191470581A7091420D25ECD444502 ] usbser C:\Windows\system32\drivers\usbser.sys
19:47:54.0921 4060 usbser - ok
19:47:54.0936 4060 [ 68B4F83CCCF70A2FF32EE142C234332A ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
19:47:54.0936 4060 UsbserFilt - ok
19:47:54.0968 4060 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:47:54.0968 4060 USBSTOR - ok
19:47:54.0983 4060 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
19:47:54.0999 4060 usbuhci - ok
19:47:55.0030 4060 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
19:47:55.0046 4060 usbvideo - ok
19:47:55.0061 4060 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
19:47:55.0061 4060 UxSms - ok
19:47:55.0092 4060 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
19:47:55.0092 4060 vds - ok
19:47:55.0108 4060 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:47:55.0108 4060 vga - ok
19:47:55.0124 4060 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
19:47:55.0124 4060 VgaSave - ok
19:47:55.0139 4060 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
19:47:55.0139 4060 viaagp - ok
19:47:55.0170 4060 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
19:47:55.0170 4060 ViaC7 - ok
19:47:55.0186 4060 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
19:47:55.0186 4060 viaide - ok
19:47:55.0202 4060 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:47:55.0202 4060 volmgr - ok
19:47:55.0264 4060 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:47:55.0264 4060 volmgrx - ok
19:47:55.0326 4060 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:47:55.0326 4060 volsnap - ok
19:47:55.0358 4060 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
19:47:55.0358 4060 vsmraid - ok
19:47:55.0576 4060 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
19:47:55.0592 4060 VSS - ok
19:47:55.0654 4060 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
19:47:55.0670 4060 W32Time - ok
19:47:55.0685 4060 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
19:47:55.0685 4060 WacomPen - ok
19:47:55.0701 4060 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
19:47:55.0716 4060 Wanarp - ok
19:47:55.0716 4060 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:47:55.0716 4060 Wanarpv6 - ok
19:47:55.0748 4060 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:47:55.0763 4060 wcncsvc - ok
19:47:55.0779 4060 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:47:55.0779 4060 WcsPlugInService - ok
19:47:55.0794 4060 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
19:47:55.0794 4060 Wd - ok
19:47:55.0841 4060 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:47:55.0857 4060 Wdf01000 - ok
19:47:55.0872 4060 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:47:55.0888 4060 WdiServiceHost - ok
19:47:55.0888 4060 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:47:55.0888 4060 WdiSystemHost - ok
19:47:55.0935 4060 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
19:47:55.0935 4060 WebClient - ok
19:47:55.0982 4060 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:47:55.0982 4060 Wecsvc - ok
19:47:55.0997 4060 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:47:55.0997 4060 wercplsupport - ok
19:47:56.0044 4060 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
19:47:56.0044 4060 WerSvc - ok
19:47:56.0122 4060 WFIOCTL - ok
19:47:56.0122 4060 WFLR6654 - ok
19:47:56.0231 4060 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
19:47:56.0231 4060 WinDefend - ok
19:47:56.0231 4060 WinHttpAutoProxySvc - ok
19:47:56.0294 4060 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:47:56.0294 4060 Winmgmt - ok
19:47:56.0356 4060 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
19:47:56.0372 4060 WinRM - ok
19:47:56.0496 4060 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
19:47:56.0496 4060 Wlansvc - ok
19:47:56.0543 4060 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:47:56.0559 4060 WmiAcpi - ok
19:47:56.0574 4060 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:47:56.0574 4060 wmiApSrv - ok
19:47:56.0715 4060 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
19:47:56.0746 4060 WMPNetworkSvc - ok
19:47:56.0762 4060 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:47:56.0762 4060 WPCSvc - ok
19:47:56.0793 4060 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:47:56.0793 4060 WPDBusEnum - ok
19:47:56.0840 4060 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
19:47:56.0855 4060 WpdUsb - ok
19:47:57.0058 4060 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:47:57.0074 4060 WPFFontCache_v0400 - ok
19:47:57.0089 4060 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:47:57.0105 4060 ws2ifsl - ok
19:47:57.0120 4060 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
19:47:57.0120 4060 wscsvc - ok
19:47:57.0136 4060 WSearch - ok
19:47:57.0198 4060 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
19:47:57.0214 4060 wuauserv - ok
19:47:57.0261 4060 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:47:57.0261 4060 WudfPf - ok
19:47:57.0308 4060 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:47:57.0323 4060 WUDFRd - ok
19:47:57.0339 4060 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:47:57.0339 4060 wudfsvc - ok
19:47:57.0354 4060 ================ Scan global ===============================
19:47:57.0370 4060 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
19:47:57.0464 4060 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:47:57.0479 4060 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:47:57.0557 4060 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
19:47:57.0573 4060 [Global] - ok
19:47:57.0573 4060 ================ Scan MBR ==================================
19:47:57.0588 4060 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
19:47:58.0197 4060 \Device\Harddisk0\DR0 - ok
19:47:58.0212 4060 [ B6C9596D5C3355FBA2B417699EDBC3F0 ] \Device\Harddisk1\DR1
19:48:00.0568 4060 \Device\Harddisk1\DR1 - ok
19:48:00.0568 4060 ================ Scan VBR ==================================
19:48:00.0584 4060 [ DEB93F3E0F0B6A32E359169E243350A0 ] \Device\Harddisk0\DR0\Partition1
19:48:00.0584 4060 \Device\Harddisk0\DR0\Partition1 - ok
19:48:00.0599 4060 [ B59C2178D3B4B5EEAD18A9D2F5AC32A4 ] \Device\Harddisk0\DR0\Partition2
19:48:00.0615 4060 \Device\Harddisk0\DR0\Partition2 - ok
19:48:00.0615 4060 [ 31DEA3E2F2B4757011C61C359B70D343 ] \Device\Harddisk1\DR1\Partition1
19:48:00.0615 4060 \Device\Harddisk1\DR1\Partition1 - ok
19:48:00.0615 4060 ============================================================
19:48:00.0615 4060 Scan finished
19:48:00.0615 4060 ============================================================
19:48:00.0630 3000 Detected object count: 1
19:48:00.0630 3000 Actual detected object count: 1
19:47:31.0677 6012 ============================================================
19:47:31.0677 6012 Current date / time: 2013/01/19 19:47:31.0677
19:47:31.0677 6012 SystemInfo:
19:47:31.0677 6012
19:47:31.0677 6012 OS Version: 6.0.6001 ServicePack: 1.0
19:47:31.0677 6012 Product type: Workstation
19:47:31.0677 6012 ComputerName: ADMIN-PC
19:47:31.0677 6012 UserName: Admin
19:47:31.0677 6012 Windows directory: C:\Windows
19:47:31.0677 6012 System windows directory: C:\Windows
19:47:31.0677 6012 Processor architecture: Intel x86
19:47:31.0677 6012 Number of processors: 2
19:47:31.0677 6012 Page size: 0x1000
19:47:31.0677 6012 Boot type: Normal boot
19:47:31.0677 6012 ============================================================
19:47:34.0516 6012 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:47:35.0374 6012 Drive \Device\Harddisk1\DR1 - Size: 0xF8400000 (3.88 Gb), SectorSize: 0x200, Cylinders: 0x1FA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:47:35.0374 6012 ============================================================
19:47:35.0374 6012 \Device\Harddisk0\DR0:
19:47:35.0374 6012 MBR partitions:
19:47:35.0374 6012 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1C13870A
19:47:35.0405 6012 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1C138788, BlocksNum 0x1E2485F8
19:47:35.0405 6012 \Device\Harddisk1\DR1:
19:47:35.0405 6012 MBR partitions:
19:47:35.0405 6012 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0x7C1FC0
19:47:35.0405 6012 ============================================================
19:47:35.0514 6012 C: <-> \Device\Harddisk0\DR0\Partition2
19:47:35.0811 6012 D: <-> \Device\Harddisk0\DR0\Partition1
19:47:35.0811 6012 ============================================================
19:47:35.0811 6012 Initialize success
19:47:35.0811 6012 ============================================================
19:47:39.0305 4060 ============================================================
19:47:39.0305 4060 Scan started
19:47:39.0305 4060 Mode: Manual;
19:47:39.0305 4060 ============================================================
19:47:40.0444 4060 ================ Scan system memory ========================
19:47:40.0444 4060 System memory - ok
19:47:40.0444 4060 ================ Scan services =============================
19:47:40.0709 4060 [ 585E64BB6DFBC0A2F1F0B554DED012DF ] 61883 C:\Windows\system32\DRIVERS\61883.sys
19:47:40.0709 4060 61883 - ok
19:47:40.0818 4060 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
19:47:40.0818 4060 ACPI - ok
19:47:40.0865 4060 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
19:47:40.0865 4060 adp94xx - ok
19:47:40.0881 4060 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
19:47:40.0881 4060 adpahci - ok
19:47:40.0928 4060 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
19:47:40.0928 4060 adpu160m - ok
19:47:40.0943 4060 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
19:47:40.0943 4060 adpu320 - ok
19:47:40.0990 4060 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:47:40.0990 4060 AeLookupSvc - ok
19:47:41.0099 4060 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
19:47:41.0099 4060 AFD - ok
19:47:41.0162 4060 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:47:41.0162 4060 agp440 - ok
19:47:41.0208 4060 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
19:47:41.0208 4060 aic78xx - ok
19:47:41.0224 4060 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
19:47:41.0224 4060 ALG - ok
19:47:41.0255 4060 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
19:47:41.0255 4060 aliide - ok
19:47:41.0271 4060 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
19:47:41.0271 4060 amdagp - ok
19:47:41.0286 4060 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
19:47:41.0286 4060 amdide - ok
19:47:41.0302 4060 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
19:47:41.0302 4060 AmdK7 - ok
19:47:41.0318 4060 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
19:47:41.0318 4060 AmdK8 - ok
19:47:41.0349 4060 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
19:47:41.0349 4060 Appinfo - ok
19:47:41.0364 4060 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
19:47:41.0364 4060 arc - ok
19:47:41.0380 4060 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
19:47:41.0396 4060 arcsas - ok
19:47:41.0411 4060 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:47:41.0411 4060 AsyncMac - ok
19:47:41.0427 4060 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
19:47:41.0427 4060 atapi - ok
19:47:41.0458 4060 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:47:41.0458 4060 AudioEndpointBuilder - ok
19:47:41.0458 4060 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
19:47:41.0458 4060 Audiosrv - ok
19:47:41.0505 4060 [ F4B56425A00BEB32F5FA6603FF7B0EA2 ] Avc C:\Windows\system32\DRIVERS\avc.sys
19:47:41.0505 4060 Avc - ok
19:47:41.0552 4060 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
19:47:41.0552 4060 Beep - ok
19:47:41.0583 4060 [ D3E6D78285529962349A7F1617035938 ] BFE C:\Windows\System32\bfe.dll
19:47:41.0598 4060 BFE - ok
19:47:41.0645 4060 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
19:47:41.0661 4060 BITS - ok
19:47:41.0676 4060 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
19:47:41.0676 4060 blbdrive - ok
19:47:41.0708 4060 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:47:41.0708 4060 bowser - ok
19:47:41.0739 4060 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
19:47:41.0739 4060 BrFiltLo - ok
19:47:41.0754 4060 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
19:47:41.0754 4060 BrFiltUp - ok
19:47:41.0801 4060 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
19:47:41.0801 4060 Browser - ok
19:47:41.0832 4060 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
19:47:41.0832 4060 Brserid - ok
19:47:41.0848 4060 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
19:47:41.0848 4060 BrSerWdm - ok
19:47:41.0864 4060 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
19:47:41.0864 4060 BrUsbMdm - ok
19:47:41.0926 4060 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
19:47:41.0926 4060 BrUsbSer - ok
19:47:41.0942 4060 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
19:47:41.0942 4060 BTHMODEM - ok
19:47:41.0973 4060 [ E292176878F933E6A3CC46D6109EF1BB ] CamSuiteVAC C:\Windows\system32\DRIVERS\CamSuiteVAC.sys
19:47:41.0973 4060 CamSuiteVAC - ok
19:47:42.0160 4060 [ 1778EBA872274C1226D869CD9486847E ] Capture Device Service C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
19:47:42.0160 4060 Capture Device Service - ok
19:47:42.0176 4060 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:47:42.0176 4060 cdfs - ok
19:47:42.0176 4060 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:47:42.0176 4060 cdrom - ok
19:47:42.0207 4060 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
19:47:42.0207 4060 CertPropSvc - ok
19:47:42.0238 4060 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
19:47:42.0238 4060 circlass - ok
19:47:42.0254 4060 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
19:47:42.0269 4060 CLFS - ok
19:47:42.0441 4060 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:47:42.0441 4060 clr_optimization_v2.0.50727_32 - ok
19:47:42.0503 4060 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:47:42.0503 4060 clr_optimization_v4.0.30319_32 - ok
19:47:42.0550 4060 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:47:42.0550 4060 cmdide - ok
19:47:42.0566 4060 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
19:47:42.0566 4060 Compbatt - ok
19:47:42.0581 4060 COMSysApp - ok
19:47:42.0597 4060 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
19:47:42.0597 4060 crcdisk - ok
19:47:42.0612 4060 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
19:47:42.0612 4060 Crusoe - ok
19:47:42.0722 4060 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:47:42.0722 4060 CryptSvc - ok
19:47:42.0893 4060 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:47:42.0909 4060 DcomLaunch - ok
19:47:43.0049 4060 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:47:43.0065 4060 DfsC - ok
19:47:43.0174 4060 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
19:47:43.0190 4060 DFSR - ok
19:47:43.0299 4060 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
19:47:43.0299 4060 Dhcp - ok
19:47:43.0346 4060 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
19:47:43.0346 4060 disk - ok
19:47:43.0392 4060 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:47:43.0392 4060 Dnscache - ok
19:47:43.0439 4060 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
19:47:43.0470 4060 dot3svc - ok
19:47:43.0533 4060 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
19:47:43.0533 4060 DPS - ok
19:47:43.0580 4060 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:47:43.0580 4060 drmkaud - ok
19:47:43.0689 4060 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:47:43.0704 4060 DXGKrnl - ok
19:47:43.0720 4060 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
19:47:43.0720 4060 E1G60 - ok
19:47:43.0736 4060 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
19:47:43.0736 4060 EapHost - ok
19:47:43.0767 4060 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
19:47:43.0767 4060 Ecache - ok
19:47:43.0892 4060 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:47:43.0892 4060 ehRecvr - ok
19:47:43.0923 4060 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
19:47:43.0923 4060 ehSched - ok
19:47:43.0938 4060 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
19:47:43.0938 4060 ehstart - ok
19:47:43.0970 4060 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
19:47:43.0970 4060 elxstor - ok
19:47:44.0079 4060 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
19:47:44.0094 4060 EMDMgmt - ok
19:47:44.0110 4060 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:47:44.0110 4060 ErrDev - ok
19:47:44.0188 4060 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
19:47:44.0188 4060 EventSystem - ok
19:47:44.0250 4060 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
19:47:44.0250 4060 exfat - ok
19:47:44.0297 4060 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:47:44.0313 4060 fastfat - ok
19:47:44.0360 4060 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
19:47:44.0360 4060 fdc - ok
19:47:44.0391 4060 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
19:47:44.0406 4060 fdPHost - ok
19:47:44.0422 4060 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
19:47:44.0422 4060 FDResPub - ok
19:47:44.0453 4060 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:47:44.0453 4060 FileInfo - ok
19:47:44.0469 4060 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:47:44.0469 4060 Filetrace - ok
19:47:44.0484 4060 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
19:47:44.0484 4060 flpydisk - ok
19:47:44.0500 4060 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:47:44.0500 4060 FltMgr - ok
19:47:44.0687 4060 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:47:44.0718 4060 FontCache3.0.0.0 - ok
19:47:44.0734 4060 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:47:44.0750 4060 Fs_Rec - ok
19:47:44.0796 4060 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
19:47:44.0812 4060 gagp30kx - ok
19:47:44.0984 4060 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
19:47:45.0015 4060 gpsvc - ok
19:47:45.0108 4060 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:47:45.0108 4060 HdAudAddService - ok
19:47:45.0171 4060 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
19:47:45.0171 4060 HDAudBus - ok
19:47:45.0186 4060 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
19:47:45.0218 4060 HidBth - ok
19:47:45.0233 4060 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
19:47:45.0233 4060 HidIr - ok
19:47:45.0264 4060 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
19:47:45.0264 4060 hidserv - ok
19:47:45.0342 4060 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:47:45.0342 4060 HidUsb - ok
19:47:45.0420 4060 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:47:45.0420 4060 hkmsvc - ok
19:47:45.0452 4060 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
19:47:45.0452 4060 HpCISSs - ok
19:47:45.0530 4060 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:47:45.0592 4060 HTTP - ok
19:47:45.0639 4060 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
19:47:45.0639 4060 i2omp - ok
19:47:45.0810 4060 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:47:45.0810 4060 i8042prt - ok
19:47:45.0873 4060 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
19:47:45.0888 4060 iaStorV - ok
19:47:46.0044 4060 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:47:46.0076 4060 idsvc - ok
19:47:46.0091 4060 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
19:47:46.0091 4060 iirsp - ok
19:47:46.0232 4060 [ 68E8C415E102E5D79FD7E4A765B8CBA4 ] IKEEXT C:\Windows\System32\ikeext.dll
19:47:46.0278 4060 IKEEXT - ok
19:47:46.0356 4060 [ 251E85A3BAC210FFF6BAD3D1F33113E8 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
19:47:46.0388 4060 IntcAzAudAddService - ok
19:47:46.0419 4060 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
19:47:46.0419 4060 intelide - ok
19:47:46.0434 4060 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:47:46.0434 4060 intelppm - ok
19:47:46.0481 4060 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:47:46.0481 4060 IPBusEnum - ok
19:47:46.0497 4060 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:47:46.0512 4060 IpFilterDriver - ok
19:47:46.0590 4060 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:47:46.0590 4060 iphlpsvc - ok
19:47:46.0606 4060 IpInIp - ok
19:47:46.0622 4060 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
19:47:46.0622 4060 IPMIDRV - ok
19:47:46.0653 4060 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
19:47:46.0653 4060 IPNAT - ok
19:47:46.0668 4060 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:47:46.0668 4060 IRENUM - ok
19:47:46.0684 4060 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:47:46.0684 4060 isapnp - ok
19:47:46.0715 4060 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
19:47:46.0715 4060 iScsiPrt - ok
19:47:46.0731 4060 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
19:47:46.0731 4060 iteatapi - ok
19:47:46.0762 4060 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
19:47:46.0762 4060 iteraid - ok
19:47:46.0793 4060 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:47:46.0793 4060 kbdclass - ok
19:47:46.0809 4060 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
19:47:46.0809 4060 kbdhid - ok
19:47:46.0856 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
19:47:46.0856 4060 KeyIso - ok
19:47:46.0980 4060 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:47:46.0996 4060 KSecDD - ok
19:47:47.0058 4060 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
19:47:47.0058 4060 KtmRm - ok
19:47:47.0090 4060 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\system32\srvsvc.dll
19:47:47.0090 4060 LanmanServer - ok
19:47:47.0199 4060 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:47:47.0199 4060 LanmanWorkstation - ok
19:47:47.0230 4060 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:47:47.0230 4060 lltdio - ok
19:47:47.0261 4060 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:47:47.0261 4060 lltdsvc - ok
19:47:47.0277 4060 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:47:47.0292 4060 lmhosts - ok
19:47:47.0324 4060 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
19:47:47.0324 4060 LSI_FC - ok
19:47:47.0355 4060 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
19:47:47.0355 4060 LSI_SAS - ok
19:47:47.0370 4060 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
19:47:47.0386 4060 LSI_SCSI - ok
19:47:47.0417 4060 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
19:47:47.0417 4060 luafv - ok
19:47:47.0448 4060 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
19:47:47.0448 4060 MBAMProtector - ok
19:47:47.0620 4060 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:47:47.0620 4060 MBAMScheduler - ok
19:47:47.0667 4060 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:47:47.0682 4060 MBAMService - ok
19:47:47.0729 4060 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:47:47.0729 4060 Mcx2Svc - ok
19:47:47.0760 4060 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
19:47:47.0776 4060 megasas - ok
19:47:47.0807 4060 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
19:47:47.0807 4060 MegaSR - ok
19:47:47.0838 4060 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
19:47:47.0838 4060 MMCSS - ok
19:47:47.0854 4060 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
19:47:47.0870 4060 Modem - ok
19:47:47.0948 4060 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:47:47.0948 4060 monitor - ok
19:47:47.0963 4060 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:47:47.0963 4060 mouclass - ok
19:47:47.0994 4060 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:47:48.0010 4060 mouhid - ok
19:47:48.0041 4060 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
19:47:48.0041 4060 MountMgr - ok
19:47:48.0072 4060 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
19:47:48.0088 4060 MpFilter - ok
19:47:48.0104 4060 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
19:47:48.0104 4060 mpio - ok
19:47:48.0244 4060 MpKsl833d6dd7 - ok
19:47:48.0275 4060 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:47:48.0275 4060 mpsdrv - ok
19:47:48.0291 4060 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
19:47:48.0291 4060 MpsSvc - ok
19:47:48.0322 4060 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
19:47:48.0322 4060 Mraid35x - ok
19:47:48.0338 4060 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:47:48.0353 4060 MRxDAV - ok
19:47:48.0384 4060 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:47:48.0384 4060 mrxsmb - ok
19:47:48.0416 4060 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:47:48.0416 4060 mrxsmb10 - ok
19:47:48.0416 4060 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:47:48.0431 4060 mrxsmb20 - ok
19:47:48.0447 4060 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
19:47:48.0447 4060 msahci - ok
19:47:48.0462 4060 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:47:48.0462 4060 msdsm - ok
19:47:48.0478 4060 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
19:47:48.0478 4060 MSDTC - ok
19:47:48.0525 4060 [ 343291A4DFD7C923C3F71F550830EC1C ] MSDV C:\Windows\system32\DRIVERS\msdv.sys
19:47:48.0525 4060 MSDV - ok
19:47:48.0540 4060 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:47:48.0540 4060 Msfs - ok
19:47:48.0556 4060 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:47:48.0556 4060 msisadrv - ok
19:47:48.0587 4060 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:47:48.0587 4060 MSiSCSI - ok
19:47:48.0587 4060 msiserver - ok
19:47:48.0618 4060 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:47:48.0618 4060 MSKSSRV - ok
19:47:48.0665 4060 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
19:47:48.0665 4060 MsMpSvc - ok
19:47:48.0681 4060 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:47:48.0681 4060 MSPCLOCK - ok
19:47:48.0681 4060 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:47:48.0681 4060 MSPQM - ok
19:47:48.0696 4060 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:47:48.0696 4060 MsRPC - ok
19:47:48.0712 4060 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
19:47:48.0712 4060 mssmbios - ok
19:47:48.0728 4060 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:47:48.0728 4060 MSTEE - ok
19:47:48.0759 4060 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
19:47:48.0759 4060 Mup - ok
19:47:48.0790 4060 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
19:47:48.0790 4060 napagent - ok
19:47:48.0806 4060 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:47:48.0806 4060 NativeWifiP - ok
19:47:48.0852 4060 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:47:48.0852 4060 NDIS - ok
19:47:48.0868 4060 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:47:48.0868 4060 NdisTapi - ok
19:47:48.0884 4060 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:47:48.0884 4060 Ndisuio - ok
19:47:48.0899 4060 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:47:48.0899 4060 NdisWan - ok
19:47:48.0915 4060 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:47:48.0915 4060 NDProxy - ok
19:47:48.0930 4060 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:47:48.0930 4060 NetBIOS - ok
19:47:48.0946 4060 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
19:47:48.0962 4060 netbt - ok
19:47:48.0993 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
19:47:48.0993 4060 Netlogon - ok
19:47:49.0133 4060 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
19:47:49.0133 4060 Netman - ok
19:47:49.0180 4060 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
19:47:49.0180 4060 netprofm - ok
19:47:49.0227 4060 [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:47:49.0227 4060 NetTcpPortSharing - ok
19:47:49.0258 4060 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
19:47:49.0258 4060 nfrd960 - ok
19:47:49.0289 4060 [ 2CD24A6AF497D0E9B9BF3DA924ED05E6 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
19:47:49.0289 4060 NisDrv - ok
19:47:49.0336 4060 [ 3B846434055F80D9E89D0742F3ADAD34 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
19:47:49.0336 4060 NisSrv - ok
19:47:49.0430 4060 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:47:49.0430 4060 NlaSvc - ok
19:47:49.0508 4060 [ C4EBBBD7165BE535F0BFD06B80601D91 ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
19:47:49.0570 4060 NMIndexingService - ok
19:47:49.0617 4060 [ C3963D85B721A7F80D8A55F4E2867A3A ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
19:47:49.0617 4060 nmwcd - ok
19:47:49.0679 4060 [ 3859C69A77793180548802DAC9F34A38 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
19:47:49.0679 4060 nmwcdc - ok
19:47:49.0679 4060 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:47:49.0679 4060 Npfs - ok
19:47:49.0710 4060 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
19:47:49.0710 4060 nsi - ok
19:47:49.0726 4060 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:47:49.0773 4060 nsiproxy - ok
19:47:49.0820 4060 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:47:49.0944 4060 Ntfs - ok
19:47:49.0960 4060 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
19:47:49.0960 4060 ntrigdigi - ok
19:47:49.0976 4060 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
19:47:49.0976 4060 Null - ok
19:47:50.0381 4060 [ 0A1B502CBC8230DA74BEFBAADDB58916 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:47:50.0459 4060 nvlddmkm - ok
19:47:50.0490 4060 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:47:50.0490 4060 nvraid - ok
19:47:50.0506 4060 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:47:50.0506 4060 nvstor - ok
19:47:50.0553 4060 [ EB5A13F9139F20AD71ADF4BF79C3AA29 ] nvsvc C:\Windows\system32\nvvsvc.exe
19:47:50.0568 4060 nvsvc - ok
19:47:50.0662 4060 [ 0629259E3AF6BB0534FCECA208973404 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
19:47:50.0678 4060 nvUpdatusService - ok
19:47:50.0693 4060 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:47:50.0693 4060 nv_agp - ok
19:47:50.0709 4060 NwlnkFlt - ok
19:47:50.0709 4060 NwlnkFwd - ok
19:47:50.0756 4060 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
19:47:50.0756 4060 ohci1394 - ok
19:47:50.0802 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
19:47:50.0912 4060 p2pimsvc - ok
19:47:50.0958 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
19:47:50.0958 4060 p2psvc - ok
19:47:50.0990 4060 [ 3F988A7C348F6990DC65C744469BF296 ] PAC7302 C:\Windows\system32\DRIVERS\PAC7302.SYS
19:47:51.0005 4060 PAC7302 - ok
19:47:51.0021 4060 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
19:47:51.0021 4060 Parport - ok
19:47:51.0021 4060 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:47:51.0021 4060 partmgr - ok
19:47:51.0036 4060 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
19:47:51.0036 4060 Parvdm - ok
19:47:51.0052 4060 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
19:47:51.0052 4060 PcaSvc - ok
19:47:51.0083 4060 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
19:47:51.0083 4060 pccsmcfd - ok
19:47:51.0099 4060 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
19:47:51.0114 4060 pci - ok
19:47:51.0114 4060 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
19:47:51.0114 4060 pciide - ok
19:47:51.0146 4060 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
19:47:51.0146 4060 pcmcia - ok
19:47:51.0177 4060 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:47:51.0192 4060 PEAUTH - ok
19:47:51.0255 4060 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
19:47:51.0270 4060 pla - ok
19:47:51.0302 4060 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:47:51.0317 4060 PlugPlay - ok
19:47:51.0333 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
19:47:51.0348 4060 PNRPAutoReg - ok
19:47:51.0364 4060 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
19:47:51.0364 4060 PNRPsvc - ok
19:47:51.0395 4060 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:47:51.0395 4060 PolicyAgent - ok
19:47:51.0426 4060 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:47:51.0426 4060 PptpMiniport - ok
19:47:51.0442 4060 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
19:47:51.0442 4060 Processor - ok
19:47:51.0458 4060 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
19:47:51.0458 4060 ProfSvc - ok
19:47:51.0473 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:47:51.0473 4060 ProtectedStorage - ok
19:47:51.0504 4060 [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched C:\Windows\system32\DRIVERS\pacer.sys
19:47:51.0504 4060 PSched - ok
19:47:51.0551 4060 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
19:47:51.0567 4060 ql2300 - ok
19:47:51.0582 4060 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
19:47:51.0598 4060 ql40xx - ok
19:47:51.0614 4060 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
19:47:51.0614 4060 QWAVE - ok
19:47:51.0614 4060 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:47:51.0614 4060 QWAVEdrv - ok
19:47:51.0629 4060 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:47:51.0629 4060 RasAcd - ok
19:47:51.0645 4060 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
19:47:51.0660 4060 RasAuto - ok
19:47:51.0660 4060 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:47:51.0676 4060 Rasl2tp - ok
19:47:51.0707 4060 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
19:47:51.0707 4060 RasMan - ok
19:47:51.0723 4060 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:47:51.0723 4060 RasPppoe - ok
19:47:51.0738 4060 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:47:51.0738 4060 RasSstp - ok
19:47:51.0754 4060 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:47:51.0754 4060 rdbss - ok
19:47:51.0785 4060 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:47:51.0785 4060 RDPCDD - ok
19:47:51.0801 4060 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
19:47:51.0816 4060 rdpdr - ok
19:47:51.0832 4060 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:47:51.0848 4060 RDPENCDD - ok
19:47:51.0863 4060 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:47:51.0879 4060 RDPWD - ok
19:47:51.0894 4060 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:47:51.0910 4060 RemoteAccess - ok
19:47:51.0926 4060 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:47:51.0926 4060 RemoteRegistry - ok
19:47:51.0988 4060 [ BD517C7FB119997EFFBE39D5E4B37B05 ] RichVideo C:\Program Files\CyberLink\Shared Files\RichVideo.exe
19:47:51.0988 4060 RichVideo - ok
19:47:52.0004 4060 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
19:47:52.0019 4060 RpcLocator - ok
19:47:52.0050 4060 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
19:47:52.0050 4060 RpcSs - ok
19:47:52.0082 4060 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:47:52.0097 4060 rspndr - ok
19:47:52.0128 4060 [ 283392AF1860ECDB5E0F8EBD7F3D72DF ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
19:47:52.0128 4060 RTL8169 - ok
19:47:52.0128 4060 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
19:47:52.0144 4060 SamSs - ok
19:47:52.0160 4060 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:47:52.0160 4060 sbp2port - ok
19:47:52.0191 4060 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:47:52.0191 4060 SCardSvr - ok
19:47:52.0269 4060 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
19:47:52.0284 4060 Schedule - ok
19:47:52.0300 4060 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
19:47:52.0300 4060 SCPolicySvc - ok
19:47:52.0316 4060 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:47:52.0316 4060 SDRSVC - ok
19:47:52.0331 4060 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:47:52.0331 4060 secdrv - ok
19:47:52.0378 4060 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
19:47:52.0378 4060 seclogon - ok
19:47:52.0409 4060 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
19:47:52.0409 4060 SENS - ok
19:47:52.0440 4060 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
19:47:52.0440 4060 Serenum - ok
19:47:52.0456 4060 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
19:47:52.0456 4060 Serial - ok
19:47:52.0456 4060 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
19:47:52.0456 4060 sermouse - ok
19:47:52.0565 4060 [ 2D841B7B7F6DEC32162EDFCC69D61F42 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
19:47:52.0581 4060 ServiceLayer - ok
19:47:52.0612 4060 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
19:47:52.0612 4060 SessionEnv - ok
19:47:52.0628 4060 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:47:52.0643 4060 sffdisk - ok
19:47:52.0643 4060 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:47:52.0643 4060 sffp_mmc - ok
19:47:52.0659 4060 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:47:52.0659 4060 sffp_sd - ok
19:47:52.0674 4060 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
19:47:52.0674 4060 sfloppy - ok
19:47:52.0706 4060 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:47:52.0721 4060 SharedAccess - ok
19:47:52.0737 4060 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:47:52.0752 4060 ShellHWDetection - ok
19:47:52.0752 4060 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
19:47:52.0752 4060 sisagp - ok
19:47:52.0830 4060 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
19:47:52.0830 4060 SiSRaid2 - ok
19:47:52.0846 4060 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
19:47:52.0862 4060 SiSRaid4 - ok
19:47:52.0877 4060 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
19:47:52.0877 4060 SkypeUpdate - ok
19:47:52.0971 4060 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
19:47:53.0033 4060 slsvc - ok
19:47:53.0049 4060 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
19:47:53.0064 4060 SLUINotify - ok
19:47:53.0080 4060 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:47:53.0080 4060 Smb - ok
19:47:53.0096 4060 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:47:53.0096 4060 SNMPTRAP - ok
19:47:53.0127 4060 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
19:47:53.0127 4060 spldr - ok
19:47:53.0158 4060 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
19:47:53.0158 4060 Spooler - ok
19:47:53.0220 4060 [ 4F576E516CC76EC50A244586BCFA1C78 ] sptd C:\Windows\system32\Drivers\sptd.sys
19:47:53.0220 4060 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 4F576E516CC76EC50A244586BCFA1C78
19:47:53.0220 4060 sptd ( LockedFile.Multi.Generic ) - warning
19:47:53.0220 4060 sptd - detected LockedFile.Multi.Generic (1)
19:47:53.0330 4060 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
19:47:53.0345 4060 srv - ok
19:47:53.0361 4060 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:47:53.0361 4060 srv2 - ok
19:47:53.0376 4060 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:47:53.0376 4060 srvnet - ok
19:47:53.0408 4060 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:47:53.0408 4060 SSDPSRV - ok
19:47:53.0423 4060 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:47:53.0439 4060 SstpSvc - ok
19:47:53.0486 4060 [ 5A1D0CA8A5F1E7B4EC50B9D76C001F0E ] ss_bus C:\Windows\system32\DRIVERS\ss_bus.sys
19:47:53.0486 4060 ss_bus - ok
19:47:53.0486 4060 [ F0A85580E36A3A85059037D39A9CF079 ] ss_mdfl C:\Windows\system32\DRIVERS\ss_mdfl.sys
19:47:53.0486 4060 ss_mdfl - ok
19:47:53.0532 4060 [ 84C3DBFD1BFA4ADC0A950B3D5506CB00 ] ss_mdm C:\Windows\system32\DRIVERS\ss_mdm.sys
19:47:53.0532 4060 ss_mdm - ok
19:47:53.0579 4060 [ 306521935042FC0A6988D528643619B3 ] StarOpen C:\Windows\system32\drivers\StarOpen.sys
19:47:53.0579 4060 StarOpen - ok
19:47:53.0642 4060 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
19:47:53.0657 4060 Stereo Service - ok
19:47:53.0688 4060 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
19:47:53.0688 4060 stisvc - ok
19:47:53.0720 4060 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
19:47:53.0720 4060 swenum - ok
19:47:53.0735 4060 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
19:47:53.0751 4060 swprv - ok
19:47:53.0751 4060 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
19:47:53.0766 4060 Symc8xx - ok
19:47:53.0766 4060 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
19:47:53.0766 4060 Sym_hi - ok
19:47:53.0782 4060 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
19:47:53.0782 4060 Sym_u3 - ok
19:47:53.0813 4060 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
19:47:53.0813 4060 SysMain - ok
19:47:53.0844 4060 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:47:53.0844 4060 TabletInputService - ok
19:47:53.0860 4060 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
19:47:53.0860 4060 TapiSrv - ok
19:47:53.0876 4060 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
19:47:53.0891 4060 TBS - ok
19:47:53.0938 4060 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:47:53.0938 4060 Tcpip - ok
19:47:54.0000 4060 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
19:47:54.0016 4060 Tcpip6 - ok
19:47:54.0032 4060 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:47:54.0032 4060 tcpipreg - ok
19:47:54.0063 4060 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:47:54.0063 4060 TDPIPE - ok
19:47:54.0094 4060 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:47:54.0094 4060 TDTCP - ok
19:47:54.0110 4060 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:47:54.0110 4060 tdx - ok
19:47:54.0141 4060 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
19:47:54.0141 4060 TermDD - ok
19:47:54.0172 4060 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
19:47:54.0188 4060 TermService - ok
19:47:54.0203 4060 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
19:47:54.0203 4060 Themes - ok
19:47:54.0234 4060 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
19:47:54.0234 4060 THREADORDER - ok
19:47:54.0250 4060 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
19:47:54.0250 4060 TrkWks - ok
19:47:54.0312 4060 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:47:54.0328 4060 TrustedInstaller - ok
19:47:54.0344 4060 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:47:54.0344 4060 tssecsrv - ok
19:47:54.0359 4060 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
19:47:54.0359 4060 tunmp - ok
19:47:54.0375 4060 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:47:54.0375 4060 tunnel - ok
19:47:54.0390 4060 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
19:47:54.0390 4060 uagp35 - ok
19:47:54.0406 4060 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:47:54.0406 4060 udfs - ok
19:47:54.0437 4060 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:47:54.0437 4060 UI0Detect - ok
19:47:54.0500 4060 [ 332D341D92B933600D41953B08360DFB ] UleadBurningHelper C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
19:47:54.0515 4060 UleadBurningHelper - ok
19:47:54.0531 4060 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:47:54.0531 4060 uliagpkx - ok
19:47:54.0609 4060 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
19:47:54.0609 4060 uliahci - ok
19:47:54.0640 4060 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
19:47:54.0640 4060 UlSata - ok
19:47:54.0656 4060 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
19:47:54.0656 4060 ulsata2 - ok
19:47:54.0671 4060 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:47:54.0671 4060 umbus - ok
19:47:54.0702 4060 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
19:47:54.0702 4060 upnphost - ok
19:47:54.0734 4060 [ 0CCADC7391021376EDBB8AA649D04E68 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
19:47:54.0734 4060 upperdev - ok
19:47:54.0765 4060 [ 292A25BB75A568AE2C67169BA2C6365A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
19:47:54.0780 4060 usbaudio - ok
19:47:54.0796 4060 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:47:54.0796 4060 usbccgp - ok
19:47:54.0812 4060 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:47:54.0812 4060 usbcir - ok
19:47:54.0843 4060 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
19:47:54.0843 4060 usbehci - ok
19:47:54.0858 4060 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:47:54.0858 4060 usbhub - ok
19:47:54.0874 4060 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:47:54.0874 4060 usbohci - ok
19:47:54.0905 4060 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:47:54.0905 4060 usbprint - ok
19:47:54.0921 4060 [ A96191470581A7091420D25ECD444502 ] usbser C:\Windows\system32\drivers\usbser.sys
19:47:54.0921 4060 usbser - ok
19:47:54.0936 4060 [ 68B4F83CCCF70A2FF32EE142C234332A ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
19:47:54.0936 4060 UsbserFilt - ok
19:47:54.0968 4060 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:47:54.0968 4060 USBSTOR - ok
19:47:54.0983 4060 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
19:47:54.0999 4060 usbuhci - ok
19:47:55.0030 4060 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
19:47:55.0046 4060 usbvideo - ok
19:47:55.0061 4060 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
19:47:55.0061 4060 UxSms - ok
19:47:55.0092 4060 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
19:47:55.0092 4060 vds - ok
19:47:55.0108 4060 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:47:55.0108 4060 vga - ok
19:47:55.0124 4060 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
19:47:55.0124 4060 VgaSave - ok
19:47:55.0139 4060 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
19:47:55.0139 4060 viaagp - ok
19:47:55.0170 4060 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
19:47:55.0170 4060 ViaC7 - ok
19:47:55.0186 4060 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
19:47:55.0186 4060 viaide - ok
19:47:55.0202 4060 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:47:55.0202 4060 volmgr - ok
19:47:55.0264 4060 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:47:55.0264 4060 volmgrx - ok
19:47:55.0326 4060 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:47:55.0326 4060 volsnap - ok
19:47:55.0358 4060 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
19:47:55.0358 4060 vsmraid - ok
19:47:55.0576 4060 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
19:47:55.0592 4060 VSS - ok
19:47:55.0654 4060 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
19:47:55.0670 4060 W32Time - ok
19:47:55.0685 4060 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
19:47:55.0685 4060 WacomPen - ok
19:47:55.0701 4060 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
19:47:55.0716 4060 Wanarp - ok
19:47:55.0716 4060 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:47:55.0716 4060 Wanarpv6 - ok
19:47:55.0748 4060 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:47:55.0763 4060 wcncsvc - ok
19:47:55.0779 4060 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:47:55.0779 4060 WcsPlugInService - ok
19:47:55.0794 4060 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
19:47:55.0794 4060 Wd - ok
19:47:55.0841 4060 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:47:55.0857 4060 Wdf01000 - ok
19:47:55.0872 4060 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:47:55.0888 4060 WdiServiceHost - ok
19:47:55.0888 4060 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:47:55.0888 4060 WdiSystemHost - ok
19:47:55.0935 4060 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
19:47:55.0935 4060 WebClient - ok
19:47:55.0982 4060 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:47:55.0982 4060 Wecsvc - ok
19:47:55.0997 4060 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:47:55.0997 4060 wercplsupport - ok
19:47:56.0044 4060 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
19:47:56.0044 4060 WerSvc - ok
19:47:56.0122 4060 WFIOCTL - ok
19:47:56.0122 4060 WFLR6654 - ok
19:47:56.0231 4060 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
19:47:56.0231 4060 WinDefend - ok
19:47:56.0231 4060 WinHttpAutoProxySvc - ok
19:47:56.0294 4060 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:47:56.0294 4060 Winmgmt - ok
19:47:56.0356 4060 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
19:47:56.0372 4060 WinRM - ok
19:47:56.0496 4060 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
19:47:56.0496 4060 Wlansvc - ok
19:47:56.0543 4060 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:47:56.0559 4060 WmiAcpi - ok
19:47:56.0574 4060 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:47:56.0574 4060 wmiApSrv - ok
19:47:56.0715 4060 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
19:47:56.0746 4060 WMPNetworkSvc - ok
19:47:56.0762 4060 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:47:56.0762 4060 WPCSvc - ok
19:47:56.0793 4060 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:47:56.0793 4060 WPDBusEnum - ok
19:47:56.0840 4060 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
19:47:56.0855 4060 WpdUsb - ok
19:47:57.0058 4060 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:47:57.0074 4060 WPFFontCache_v0400 - ok
19:47:57.0089 4060 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:47:57.0105 4060 ws2ifsl - ok
19:47:57.0120 4060 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
19:47:57.0120 4060 wscsvc - ok
19:47:57.0136 4060 WSearch - ok
19:47:57.0198 4060 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
19:47:57.0214 4060 wuauserv - ok
19:47:57.0261 4060 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:47:57.0261 4060 WudfPf - ok
19:47:57.0308 4060 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:47:57.0323 4060 WUDFRd - ok
19:47:57.0339 4060 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:47:57.0339 4060 wudfsvc - ok
19:47:57.0354 4060 ================ Scan global ===============================
19:47:57.0370 4060 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
19:47:57.0464 4060 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:47:57.0479 4060 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
19:47:57.0557 4060 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
19:47:57.0573 4060 [Global] - ok
19:47:57.0573 4060 ================ Scan MBR ==================================
19:47:57.0588 4060 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
19:47:58.0197 4060 \Device\Harddisk0\DR0 - ok
19:47:58.0212 4060 [ B6C9596D5C3355FBA2B417699EDBC3F0 ] \Device\Harddisk1\DR1
19:48:00.0568 4060 \Device\Harddisk1\DR1 - ok
19:48:00.0568 4060 ================ Scan VBR ==================================
19:48:00.0584 4060 [ DEB93F3E0F0B6A32E359169E243350A0 ] \Device\Harddisk0\DR0\Partition1
19:48:00.0584 4060 \Device\Harddisk0\DR0\Partition1 - ok
19:48:00.0599 4060 [ B59C2178D3B4B5EEAD18A9D2F5AC32A4 ] \Device\Harddisk0\DR0\Partition2
19:48:00.0615 4060 \Device\Harddisk0\DR0\Partition2 - ok
19:48:00.0615 4060 [ 31DEA3E2F2B4757011C61C359B70D343 ] \Device\Harddisk1\DR1\Partition1
19:48:00.0615 4060 \Device\Harddisk1\DR1\Partition1 - ok
19:48:00.0615 4060 ============================================================
19:48:00.0615 4060 Scan finished
19:48:00.0615 4060 ============================================================
19:48:00.0630 3000 Detected object count: 1
19:48:00.0630 3000 Actual detected object count: 1
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola LOG pomalé PC
Ještě ten Combofix
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Kontrola LOG pomalé PC
ComboFix 13-01-17.04 - Admin 20.01.2013 14:15:27.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.1020.349 [GMT 1:00]
Spuštěný z: d:\elektřina\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DaemonTools_WhenUSave_Installer
c:\program files\DaemonTools_WhenUSave_Installer\vvsn.cfg
c:\programdata\1ef3f636-9a54-41d4-9036-569055fea77b
c:\programdata\Windows
c:\programdata\windows\dsdd.dat
c:\programdata\windows\nudr.dat
c:\users\Admin\xobglu32.dll
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\system32\tmp24DF.tmp
c:\windows\system32\tmp24EF.tmp
c:\windows\system32\tmp381F.tmp
c:\windows\system32\tmp385F.tmp
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-20 do 2013-01-20 )))))))))))))))))))))))))))))))
.
.
2013-01-20 13:23 . 2013-01-20 13:26 -------- d-----w- c:\users\Admin\AppData\Local\temp
2013-01-20 13:23 . 2013-01-20 13:23 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-20 13:23 . 2013-01-20 13:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-20 13:03 . 2013-01-20 13:03 -------- d-----w- c:\program files\CCleaner
2013-01-19 22:21 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{065FFD0C-516D-433B-99D3-8DFE6860AF50}\mpengine.dll
2013-01-19 20:29 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\users\Admin\AppData\Roaming\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\programdata\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-18 19:29 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-17 16:59 . 2013-01-18 19:57 -------- d-----w- c:\programdata\56696277-ff1c-406a-8332-e844df2c87cf
2013-01-07 20:59 . 2013-01-18 19:08 -------- d-----w- c:\program files\Seznam.cz
2013-01-07 20:58 . 2013-01-18 19:08 -------- d-----w- c:\users\Admin\AppData\Roaming\Seznam.cz
2013-01-07 20:57 . 2013-01-09 20:42 -------- d-----w- c:\program files\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-28 16:03 . 2012-11-28 16:07 740840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C801E70-EFE2-4EDE-975B-F03FF103D873}\gapaengine.dll
2012-10-23 16:29 . 2012-11-28 16:08 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-16 4702208]
"Skytel"="Skytel.exe" [2008-01-16 1826816]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 16:05 143360 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29 165784 ----a-w- c:\program files\DAEMON Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 09:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-03-04 17:21 77824 ----a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 13:10 56928 ------w- d:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Save F&lash with FlashCapture - c:\program files\Flash Capture\fciext.dll/FCIEXT.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-Moorhuhn Winter-Edition - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3108)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-01-20 14:30:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-20 13:29
.
Před spuštěním: Volných bajtů: 46 490 824 704
Po spuštění: Volných bajtů: 46 538 100 736
.
- - End Of File - - 14CC8BDD10F1663EE1E6900F75CDB02B
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.1020.349 [GMT 1:00]
Spuštěný z: d:\elektřina\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DaemonTools_WhenUSave_Installer
c:\program files\DaemonTools_WhenUSave_Installer\vvsn.cfg
c:\programdata\1ef3f636-9a54-41d4-9036-569055fea77b
c:\programdata\Windows
c:\programdata\windows\dsdd.dat
c:\programdata\windows\nudr.dat
c:\users\Admin\xobglu32.dll
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\system32\tmp24DF.tmp
c:\windows\system32\tmp24EF.tmp
c:\windows\system32\tmp381F.tmp
c:\windows\system32\tmp385F.tmp
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-20 do 2013-01-20 )))))))))))))))))))))))))))))))
.
.
2013-01-20 13:23 . 2013-01-20 13:26 -------- d-----w- c:\users\Admin\AppData\Local\temp
2013-01-20 13:23 . 2013-01-20 13:23 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-20 13:23 . 2013-01-20 13:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-20 13:03 . 2013-01-20 13:03 -------- d-----w- c:\program files\CCleaner
2013-01-19 22:21 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{065FFD0C-516D-433B-99D3-8DFE6860AF50}\mpengine.dll
2013-01-19 20:29 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\users\Admin\AppData\Roaming\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\programdata\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-18 19:29 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-17 16:59 . 2013-01-18 19:57 -------- d-----w- c:\programdata\56696277-ff1c-406a-8332-e844df2c87cf
2013-01-07 20:59 . 2013-01-18 19:08 -------- d-----w- c:\program files\Seznam.cz
2013-01-07 20:58 . 2013-01-18 19:08 -------- d-----w- c:\users\Admin\AppData\Roaming\Seznam.cz
2013-01-07 20:57 . 2013-01-09 20:42 -------- d-----w- c:\program files\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-28 16:03 . 2012-11-28 16:07 740840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C801E70-EFE2-4EDE-975B-F03FF103D873}\gapaengine.dll
2012-10-23 16:29 . 2012-11-28 16:08 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-16 4702208]
"Skytel"="Skytel.exe" [2008-01-16 1826816]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 16:05 143360 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29 165784 ----a-w- c:\program files\DAEMON Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 09:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-03-04 17:21 77824 ----a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 13:10 56928 ------w- d:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Save F&lash with FlashCapture - c:\program files\Flash Capture\fciext.dll/FCIEXT.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-Moorhuhn Winter-Edition - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3108)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2013-01-20 14:30:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-20 13:29
.
Před spuštěním: Volných bajtů: 46 490 824 704
Po spuštění: Volných bajtů: 46 538 100 736
.
- - End Of File - - 14CC8BDD10F1663EE1E6900F75CDB02B
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Kontrola LOG pomalé PC
Toto otestuj na Virustotal
c:\windows\system32\userinit.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
c:\windows\system32\userinit.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Kontrola LOG pomalé PC
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Kontrola LOG pomalé PC
ComboFix 13-01-23.01 - Admin 23.01.2013 21:42:24.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.1020.483 [GMT 1:00]
Spuštěný z: c:\filmy\ComboFix.exe
Použité ovládací přepínače :: c:\users\Admin\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-23 do 2013-01-23 )))))))))))))))))))))))))))))))
.
.
2013-01-23 20:48 . 2013-01-23 20:50 -------- d-----w- c:\users\Admin\AppData\Local\temp
2013-01-23 20:48 . 2013-01-23 20:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-23 20:48 . 2013-01-23 20:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-23 10:29 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A076D7-319F-42F1-9570-71F76486E77D}\mpengine.dll
2013-01-22 07:46 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-20 19:20 . 2013-01-20 19:20 -------- d-----w- c:\users\Admin\AppData\Local\Adobe
2013-01-20 13:03 . 2013-01-20 13:03 -------- d-----w- c:\program files\CCleaner
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\users\Admin\AppData\Roaming\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\programdata\Malwarebytes
2013-01-17 16:59 . 2013-01-18 19:57 -------- d-----w- c:\programdata\56696277-ff1c-406a-8332-e844df2c87cf
2013-01-07 20:59 . 2013-01-18 19:08 -------- d-----w- c:\program files\Seznam.cz
2013-01-07 20:58 . 2013-01-18 19:08 -------- d-----w- c:\users\Admin\AppData\Roaming\Seznam.cz
2013-01-07 20:57 . 2013-01-09 20:42 -------- d-----w- c:\program files\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-28 16:03 . 2012-11-28 16:07 740840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C801E70-EFE2-4EDE-975B-F03FF103D873}\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-16 4702208]
"Skytel"="Skytel.exe" [2008-01-16 1826816]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 16:05 143360 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29 165784 ----a-w- c:\program files\DAEMON Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 09:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 13:10 56928 ------w- d:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Save F&lash with FlashCapture - c:\program files\Flash Capture\fciext.dll/FCIEXT.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-23 21:51
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(672)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\System32\lpksetup.exe
.
**************************************************************************
.
Celkový čas: 2013-01-23 21:53:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-23 20:53
ComboFix2.txt 2013-01-20 13:30
.
Před spuštěním: Volných bajtů: 60 467 023 872
Po spuštění: Volných bajtů: 60 329 754 624
.
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.1020.483 [GMT 1:00]
Spuštěný z: c:\filmy\ComboFix.exe
Použité ovládací přepínače :: c:\users\Admin\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-23 do 2013-01-23 )))))))))))))))))))))))))))))))
.
.
2013-01-23 20:48 . 2013-01-23 20:50 -------- d-----w- c:\users\Admin\AppData\Local\temp
2013-01-23 20:48 . 2013-01-23 20:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-23 20:48 . 2013-01-23 20:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-23 10:29 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A076D7-319F-42F1-9570-71F76486E77D}\mpengine.dll
2013-01-22 07:46 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-20 19:20 . 2013-01-20 19:20 -------- d-----w- c:\users\Admin\AppData\Local\Adobe
2013-01-20 13:03 . 2013-01-20 13:03 -------- d-----w- c:\program files\CCleaner
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\users\Admin\AppData\Roaming\Malwarebytes
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\programdata\Malwarebytes
2013-01-17 16:59 . 2013-01-18 19:57 -------- d-----w- c:\programdata\56696277-ff1c-406a-8332-e844df2c87cf
2013-01-07 20:59 . 2013-01-18 19:08 -------- d-----w- c:\program files\Seznam.cz
2013-01-07 20:58 . 2013-01-18 19:08 -------- d-----w- c:\users\Admin\AppData\Roaming\Seznam.cz
2013-01-07 20:57 . 2013-01-09 20:42 -------- d-----w- c:\program files\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-28 16:03 . 2012-11-28 16:07 740840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C801E70-EFE2-4EDE-975B-F03FF103D873}\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-16 4702208]
"Skytel"="Skytel.exe" [2008-01-16 1826816]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-12-23 16:05 143360 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29 165784 ----a-w- c:\program files\DAEMON Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 09:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 13:10 56928 ------w- d:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Save F&lash with FlashCapture - c:\program files\Flash Capture\fciext.dll/FCIEXT.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-23 21:51
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(672)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\System32\lpksetup.exe
.
**************************************************************************
.
Celkový čas: 2013-01-23 21:53:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-23 20:53
ComboFix2.txt 2013-01-20 13:30
.
Před spuštěním: Volných bajtů: 60 467 023 872
Po spuštění: Volných bajtů: 60 329 754 624
.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 94 hostů