PLS kontrola HJT log - zánovní NTB po výměně SW Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 24 led 2013 16:26

Dostal se mi do ruky ježíškovský NTB Thoshiba satelite k doplnění programů a rozchození Win8 a protože se ni ve spuštěných procesech ukazují zbytky původních programů např McFree antivir (licence na 30 dnů) byl nahrazen avast-em s roční licencí požádal bych o preventivní kontrolu HJT Log
PS: Není vyloučeno že při procházení log HJT narazíte na nějaký vir NTB patří 12-ti leté neteři a je to dítě Facebooku.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:13:44, on 24. 1. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\user\Desktop\udržba PC\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [ToshibaDynamicIconUtility] "C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
O4 - HKLM\..\Run: [TPUReg] "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TEMPRO Service (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7768 bytes
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod memphisto » 24 led 2013 23:45

To McAfee vyházej pryč

v logu fixni:


PLS kontrola HJT log - zánovní NTB po výměně SW

Nepřečtený příspěvekod Jan Pašek » 24 Led 2013, 16:26
Dostal se mi do ruky ježíškovský NTB Thoshiba satelite k doplnění programů a rozchození Win8 a protože se ni ve spuštěných procesech ukazují zbytky původních programů např McFree antivir (licence na 30 dnů) byl nahrazen avast-em s roční licencí požádal bych o preventivní kontrolu HJT Log
PS: Není vyloučeno že při procházení log HJT narazíte na nějaký vir NTB patří 12-ti leté neteři a je to dítě Facebooku.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:13:44, on 24. 1. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\user\Desktop\udržba PC\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranìní historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit doèasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po probìhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 25 led 2013 08:40

nový HJT log po fixnutí položek a restartu PC:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:34:49, on 25. 1. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\user\Desktop\udržba PC\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [ToshibaDynamicIconUtility] "C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
O4 - HKLM\..\Run: [TPUReg] "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TEMPRO Service (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Teco\TecoService.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7460 bytes

Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod memphisto » 25 led 2013 08:45

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 25 led 2013 11:10

Než sem měl čas nastrkat sem všechno co si chtěl už mám další instrukce takže pro pořádek...


Mbam kompletní scan bez nálezu.


# AdwCleaner v2.108 - Logfile created 01/25/2013 at 11:02:12
# Updated 24/01/2013 by Xplode
# Operating system : Windows 8 (64 bits)
# User : user - SATELLITE
# Boot Mode : Normal
# Running from : C:\Users\user\Desktop\udržba PC\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16453

[OK] Registry is clean.

-\\ Mozilla Firefox v18.0.1 (cs)

*************************

AdwCleaner[R1].txt - [534 octets] - [25/01/2013 11:02:12]

########## EOF - C:\AdwCleaner[R1].txt - [593 octets] ##########


Log dsskiler nelze pro velký počet znaků vložit v otevřené formě



Odkazovaná verze SW Combofix není kompatibilní s Win8 nelze spustit nelze vytvořit log!!!!
pokud dobře rozumím tomu co je psáno zde http://translate.google.cz/translate?hl ... CDcQ7gEwAA požadovaná verze Combofix je zatím ve vývoji pokud je vůbec vyvíjena!
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod memphisto » 25 led 2013 12:05

Ten TDDS sem vlož a rozděl to na více témat. V tom texťáku to nejde číst, protože to špatně zalamuje řádky
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 25 led 2013 13:35

Ano vaše antivirová výsosti log TDDS dle vašeho přání níže.

Ve spuštěných procesech stále spuštěno:
McAfree core firewal service - (odkaz na vyhledání on-line tak jak jej zprostředkuje Správce úloh W8) - https://www.google.cz/search?q=mfefire+ ... =firefox-a

McAfree On-Access Scaner service (McAfree McShield) - https://www.google.cz/search?q=McShield ... =firefox-a

McAfree Proces Validation service (McAfree Validation Trust protection service) - https://www.google.cz/search?q=mfevtp+M ... =firefox-a

Podle toho co jsem si načetl jsou soubory umístěny v jádru systému a bez pomoci někoho znalejšího si netroufám je zastavit a následně odstranit. Mají vůbec W8 vlastní firewall?


11:12:48.0987 5020 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
11:12:48.0987 5020 UEFI system
11:12:49.0158 5020 ============================================================
11:12:49.0158 5020 Current date / time: 2013/01/25 11:12:49.0158
11:12:49.0158 5020 SystemInfo:
11:12:49.0158 5020
11:12:49.0158 5020 OS Version: 6.2.9200 ServicePack: 0.0
11:12:49.0158 5020 Product type: Workstation
11:12:49.0158 5020 ComputerName: SATELLITE
11:12:49.0158 5020 UserName: user
11:12:49.0158 5020 Windows directory: C:\windows
11:12:49.0158 5020 System windows directory: C:\windows
11:12:49.0158 5020 Running under WOW64
11:12:49.0158 5020 Processor architecture: Intel x64
11:12:49.0158 5020 Number of processors: 2
11:12:49.0158 5020 Page size: 0x1000
11:12:49.0158 5020 Boot type: Normal boot
11:12:49.0158 5020 ============================================================
11:12:49.0924 5020 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:12:49.0924 5020 ============================================================
11:12:49.0924 5020 \Device\Harddisk0\DR0:
11:12:49.0924 5020 GPT partitions:
11:12:49.0924 5020 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {38AEB8CF-F84F-11E1-9B0D-A18043F4F2E7}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xE1000
11:12:49.0924 5020 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {38AEB8D7-F84F-11E1-9B0D-A18043F4F2E7}, Name: Basic data partition, StartLBA 0xE1800, BlocksNum 0x82000
11:12:49.0924 5020 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {38AEB8D9-F84F-11E1-9B0D-A18043F4F2E7}, Name: Basic data partition, StartLBA 0x163800, BlocksNum 0x40000
11:12:49.0924 5020 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {38AEB8E1-F84F-11E1-9B0D-A18043F4F2E7}, Name: Basic data partition, StartLBA 0x1A3800, BlocksNum 0x38EBC800
11:12:49.0924 5020 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {DEE1D0EB-7F70-41A6-A705-A842447884B4}, Name: Basic data partition, StartLBA 0x39060000, BlocksNum 0x1326000
11:12:49.0924 5020 MBR partitions:
11:12:49.0924 5020 ============================================================
11:12:49.0955 5020 C: <-> \Device\Harddisk0\DR0\Partition4
11:12:49.0955 5020 ============================================================
11:12:49.0955 5020 Initialize success
11:12:49.0955 5020 ============================================================
11:12:54.0471 5268 ============================================================
11:12:54.0471 5268 Scan started
11:12:54.0471 5268 Mode: Manual;
11:12:54.0471 5268 ============================================================
11:12:55.0518 5268 ================ Scan system memory ========================
11:12:55.0518 5268 System memory - ok
11:12:55.0534 5268 ================ Scan services =============================
11:12:56.0534 5268 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\windows\System32\drivers\1394ohci.sys
11:12:56.0549 5268 1394ohci - ok
11:12:56.0565 5268 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\windows\system32\drivers\3ware.sys
11:12:56.0565 5268 3ware - ok
11:12:56.0612 5268 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\windows\system32\drivers\ACPI.sys
11:12:56.0628 5268 ACPI - ok
11:12:56.0659 5268 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\windows\system32\Drivers\acpiex.sys
11:12:56.0659 5268 acpiex - ok
11:12:56.0690 5268 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\windows\System32\drivers\acpipagr.sys
11:12:56.0690 5268 acpipagr - ok
11:12:56.0706 5268 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\windows\System32\drivers\acpipmi.sys
11:12:56.0706 5268 AcpiPmi - ok
11:12:56.0721 5268 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\windows\System32\drivers\acpitime.sys
11:12:56.0721 5268 acpitime - ok
11:12:56.0846 5268 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
11:12:56.0846 5268 AdobeFlashPlayerUpdateSvc - ok
11:12:56.0987 5268 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\windows\system32\drivers\adp94xx.sys
11:12:57.0003 5268 adp94xx - ok
11:12:57.0018 5268 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\windows\system32\drivers\adpahci.sys
11:12:57.0018 5268 adpahci - ok
11:12:57.0034 5268 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\windows\system32\drivers\adpu320.sys
11:12:57.0034 5268 adpu320 - ok
11:12:57.0065 5268 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\windows\System32\aelupsvc.dll
11:12:57.0065 5268 AeLookupSvc - ok
11:12:57.0112 5268 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\windows\system32\drivers\afd.sys
11:12:57.0128 5268 AFD - ok
11:12:57.0143 5268 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\windows\system32\drivers\agp440.sys
11:12:57.0159 5268 agp440 - ok
11:12:57.0190 5268 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\windows\System32\alg.exe
11:12:57.0190 5268 ALG - ok
11:12:57.0206 5268 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\windows\system32\AUInstallAgent.dll
11:12:57.0206 5268 AllUserInstallAgent - ok
11:12:57.0253 5268 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\windows\System32\drivers\amdk8.sys
11:12:57.0253 5268 AmdK8 - ok
11:12:57.0268 5268 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\windows\System32\drivers\amdppm.sys
11:12:57.0268 5268 AmdPPM - ok
11:12:57.0284 5268 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\windows\system32\drivers\amdsata.sys
11:12:57.0299 5268 amdsata - ok
11:12:57.0315 5268 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
11:12:57.0315 5268 amdsbs - ok
11:12:57.0331 5268 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\windows\system32\drivers\amdxata.sys
11:12:57.0346 5268 amdxata - ok
11:12:57.0362 5268 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\windows\system32\drivers\appid.sys
11:12:57.0362 5268 AppID - ok
11:12:57.0378 5268 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\windows\System32\appidsvc.dll
11:12:57.0378 5268 AppIDSvc - ok
11:12:57.0409 5268 [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo C:\windows\System32\appinfo.dll
11:12:57.0409 5268 Appinfo - ok
11:12:57.0424 5268 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\windows\system32\drivers\arc.sys
11:12:57.0424 5268 arc - ok
11:12:57.0456 5268 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\windows\system32\drivers\arcsas.sys
11:12:57.0456 5268 arcsas - ok
11:12:57.0471 5268 [ 4FCAEF0C5BE7629AEB878998E0FE959B ] aswFsBlk C:\windows\system32\drivers\aswFsBlk.sys
11:12:57.0471 5268 aswFsBlk - ok
11:12:57.0518 5268 [ B50CDD87772D6A11CB90924AAD399DF8 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
11:12:57.0518 5268 aswMonFlt - ok
11:12:57.0549 5268 [ 7415A03DEF5A4D5068112E8782FCEF75 ] aswnet C:\windows\System32\Drivers\aswnet.sys
11:12:57.0565 5268 aswnet - ok
11:12:57.0596 5268 [ 57768C7DB4681F2510F247F82EF31D4F ] aswRdr C:\windows\System32\Drivers\aswrdr2.sys
11:12:57.0596 5268 aswRdr - ok
11:12:57.0628 5268 [ E71D826A1F3CE9C9DE3E77F2D02AFFBF ] aswSnx C:\windows\system32\drivers\aswSnx.sys
11:12:57.0643 5268 aswSnx - ok
11:12:57.0706 5268 [ 538A32E2C99BF073D4CA76C30BEDAA60 ] aswSP C:\windows\system32\drivers\aswSP.sys
11:12:57.0706 5268 aswSP - ok
11:12:57.0721 5268 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
11:12:57.0721 5268 AsyncMac - ok
11:12:57.0753 5268 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\windows\system32\drivers\atapi.sys
11:12:57.0753 5268 atapi - ok
11:12:57.0799 5268 [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\windows\System32\AudioEndpointBuilder.dll
11:12:57.0799 5268 AudioEndpointBuilder - ok
11:12:57.0846 5268 [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv C:\windows\System32\Audiosrv.dll
11:12:57.0862 5268 Audiosrv - ok
11:12:57.0971 5268 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
11:12:57.0971 5268 avast! Antivirus - ok
11:12:58.0018 5268 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\windows\System32\AxInstSV.dll
11:12:58.0034 5268 AxInstSV - ok
11:12:58.0065 5268 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
11:12:58.0081 5268 b06bdrv - ok
11:12:58.0096 5268 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\windows\System32\drivers\BasicDisplay.sys
11:12:58.0096 5268 BasicDisplay - ok
11:12:58.0128 5268 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\windows\System32\drivers\BasicRender.sys
11:12:58.0128 5268 BasicRender - ok
11:12:58.0159 5268 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\windows\System32\bdesvc.dll
11:12:58.0159 5268 BDESVC - ok
11:12:58.0175 5268 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\windows\system32\drivers\Beep.sys
11:12:58.0175 5268 Beep - ok
11:12:58.0221 5268 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\windows\System32\bfe.dll
11:12:58.0237 5268 BFE - ok
11:12:58.0268 5268 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\windows\System32\qmgr.dll
11:12:58.0284 5268 BITS - ok
11:12:58.0300 5268 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\windows\system32\DRIVERS\bowser.sys
11:12:58.0300 5268 bowser - ok
11:12:58.0331 5268 [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\windows\System32\bisrv.dll
11:12:58.0331 5268 BrokerInfrastructure - ok
11:12:58.0378 5268 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\windows\System32\browser.dll
11:12:58.0378 5268 Browser - ok
11:12:58.0409 5268 [ 3AA4309EBD9491E516F13FE3DC752FEE ] BthAvrcpTg C:\windows\System32\drivers\BthAvrcpTg.sys
11:12:58.0409 5268 BthAvrcpTg - ok
11:12:58.0425 5268 [ 6AB44FF15F12E2CADABA3B8E9B2FBEB8 ] BthEnum C:\windows\System32\drivers\BthEnum.sys
11:12:58.0440 5268 BthEnum - ok
11:12:58.0471 5268 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\windows\System32\drivers\bthhfenum.sys
11:12:58.0471 5268 BthHFEnum - ok
11:12:58.0487 5268 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\windows\System32\drivers\BthHFHid.sys
11:12:58.0487 5268 bthhfhid - ok
11:12:58.0518 5268 [ 42201C346F0B8C458E1E9CDE04D68A2C ] BthLEEnum C:\windows\system32\DRIVERS\BthLEEnum.sys
11:12:58.0534 5268 BthLEEnum - ok
11:12:58.0565 5268 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\windows\System32\drivers\bthmodem.sys
11:12:58.0565 5268 BTHMODEM - ok
11:12:58.0581 5268 [ 091BB978E9504D0AD14586929431A957 ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
11:12:58.0596 5268 BthPan - ok
11:12:58.0643 5268 [ CFD630EA8B3F593FFA0030FD53BA7908 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
11:12:58.0659 5268 BTHPORT - ok
11:12:58.0675 5268 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\windows\system32\bthserv.dll
11:12:58.0690 5268 bthserv - ok
11:12:58.0706 5268 [ 69C903C026CB675E234F4A7C951FD722 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
11:12:58.0721 5268 BTHUSB - ok
11:12:58.0753 5268 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
11:12:58.0753 5268 cdfs - ok
11:12:58.0768 5268 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\windows\System32\drivers\cdrom.sys
11:12:58.0784 5268 cdrom - ok
11:12:58.0800 5268 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\windows\System32\certprop.dll
11:12:58.0800 5268 CertPropSvc - ok
11:12:58.0846 5268 [ EE9F5659DA349B9BAD1AD5C160C9EEC8 ] cfwids C:\windows\system32\drivers\cfwids.sys
11:12:58.0846 5268 cfwids - ok
11:12:58.0862 5268 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\windows\System32\drivers\circlass.sys
11:12:58.0878 5268 circlass - ok
11:12:58.0909 5268 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\windows\system32\drivers\CLFS.sys
11:12:58.0909 5268 CLFS - ok
11:12:58.0940 5268 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\windows\System32\drivers\CmBatt.sys
11:12:58.0940 5268 CmBatt - ok
11:12:58.0971 5268 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\windows\system32\Drivers\cng.sys
11:12:58.0971 5268 CNG - ok
11:12:59.0003 5268 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\windows\System32\drivers\CompositeBus.sys
11:12:59.0003 5268 CompositeBus - ok
11:12:59.0018 5268 COMSysApp - ok
11:12:59.0050 5268 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\windows\system32\drivers\condrv.sys
11:12:59.0050 5268 condrv - ok
11:12:59.0159 5268 [ 7324EC715932A12B09715B50891396F7 ] cphs C:\windows\SysWow64\IntelCpHeciSvc.exe
11:12:59.0175 5268 cphs - ok
11:12:59.0581 5268 [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc C:\windows\system32\cryptsvc.dll
11:12:59.0581 5268 CryptSvc - ok
11:12:59.0643 5268 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\windows\system32\drivers\dam.sys
11:12:59.0643 5268 dam - ok
11:12:59.0706 5268 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\windows\system32\rpcss.dll
11:12:59.0737 5268 DcomLaunch - ok
11:12:59.0784 5268 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\windows\System32\defragsvc.dll
11:12:59.0784 5268 defragsvc - ok
11:12:59.0815 5268 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\windows\system32\das.dll
11:12:59.0815 5268 DeviceAssociationService - ok
11:12:59.0909 5268 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\windows\system32\umpnpmgr.dll
11:12:59.0909 5268 DeviceInstall - ok
11:12:59.0940 5268 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\windows\system32\Drivers\dfsc.sys
11:12:59.0940 5268 Dfsc - ok
11:12:59.0987 5268 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\windows\system32\dhcpcore.dll
11:12:59.0987 5268 Dhcp - ok
11:13:00.0018 5268 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\windows\system32\drivers\discache.sys
11:13:00.0018 5268 discache - ok
11:13:00.0034 5268 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\windows\system32\drivers\disk.sys
11:13:00.0034 5268 disk - ok
11:13:00.0050 5268 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\windows\System32\drivers\dmvsc.sys
11:13:00.0065 5268 dmvsc - ok
11:13:00.0096 5268 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\windows\System32\dnsrslvr.dll
11:13:00.0096 5268 Dnscache - ok
11:13:00.0128 5268 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\windows\System32\dot3svc.dll
11:13:00.0143 5268 dot3svc - ok
11:13:00.0175 5268 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\windows\system32\dps.dll
11:13:00.0175 5268 DPS - ok
11:13:00.0206 5268 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\windows\system32\drivers\drmkaud.sys
11:13:00.0206 5268 drmkaud - ok
11:13:00.0237 5268 [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc C:\windows\System32\DeviceSetupManager.dll
11:13:00.0237 5268 DsmSvc - ok
11:13:00.0300 5268 [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
11:13:00.0315 5268 DXGKrnl - ok
11:13:00.0347 5268 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\windows\System32\eapsvc.dll
11:13:00.0347 5268 Eaphost - ok
11:13:00.0550 5268 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\windows\system32\drivers\evbda.sys
11:13:00.0628 5268 ebdrv - ok
11:13:00.0690 5268 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\windows\System32\lsass.exe
11:13:00.0690 5268 EFS - ok
11:13:00.0722 5268 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\windows\system32\drivers\EhStorClass.sys
11:13:00.0722 5268 EhStorClass - ok
11:13:00.0753 5268 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\windows\system32\drivers\EhStorTcgDrv.sys
11:13:00.0753 5268 EhStorTcgDrv - ok
11:13:00.0768 5268 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\windows\System32\drivers\errdev.sys
11:13:00.0768 5268 ErrDev - ok
11:13:00.0831 5268 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\windows\system32\es.dll
11:13:00.0831 5268 EventSystem - ok
11:13:00.0847 5268 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\windows\system32\drivers\exfat.sys
11:13:00.0862 5268 exfat - ok
11:13:00.0893 5268 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\windows\system32\drivers\fastfat.sys
11:13:00.0893 5268 fastfat - ok
11:13:00.0940 5268 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\windows\system32\fxssvc.exe
11:13:00.0956 5268 Fax - ok
11:13:01.0003 5268 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\windows\System32\drivers\fdc.sys
11:13:01.0003 5268 fdc - ok
11:13:01.0018 5268 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\windows\system32\fdPHost.dll
11:13:01.0034 5268 fdPHost - ok
11:13:01.0050 5268 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\windows\system32\fdrespub.dll
11:13:01.0050 5268 FDResPub - ok
11:13:01.0097 5268 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\windows\system32\fhsvc.dll
11:13:01.0112 5268 fhsvc - ok
11:13:01.0128 5268 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
11:13:01.0128 5268 FileInfo - ok
11:13:01.0175 5268 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\windows\system32\drivers\filetrace.sys
11:13:01.0175 5268 Filetrace - ok
11:13:01.0190 5268 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\windows\System32\drivers\flpydisk.sys
11:13:01.0190 5268 flpydisk - ok
11:13:01.0237 5268 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\windows\system32\drivers\fltmgr.sys
11:13:01.0237 5268 FltMgr - ok
11:13:01.0300 5268 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\windows\system32\FntCache.dll
11:13:01.0331 5268 FontCache - ok
11:13:01.0409 5268 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:13:01.0409 5268 FontCache3.0.0.0 - ok
11:13:01.0425 5268 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\windows\system32\drivers\FsDepends.sys
11:13:01.0425 5268 FsDepends - ok
11:13:01.0440 5268 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
11:13:01.0456 5268 Fs_Rec - ok
11:13:01.0503 5268 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
11:13:01.0503 5268 fvevol - ok
11:13:01.0534 5268 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\windows\System32\drivers\fxppm.sys
11:13:01.0534 5268 FxPPM - ok
11:13:01.0550 5268 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
11:13:01.0550 5268 gagp30kx - ok
11:13:01.0675 5268 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
11:13:01.0675 5268 GamesAppService - ok
11:13:01.0706 5268 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\windows\System32\drivers\vmgencounter.sys
11:13:01.0706 5268 gencounter - ok
11:13:01.0815 5268 [ 4E1D0A246E10CFDDBF856432418DE404 ] GFNEXSrv C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
11:13:01.0815 5268 GFNEXSrv - ok
11:13:01.0831 5268 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\windows\system32\Drivers\msgpioclx.sys
11:13:01.0831 5268 GPIOClx0101 - ok
11:13:01.0878 5268 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\windows\System32\gpsvc.dll
11:13:01.0893 5268 gpsvc - ok
11:13:01.0925 5268 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
11:13:01.0925 5268 HdAudAddService - ok
11:13:01.0956 5268 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\windows\System32\drivers\HDAudBus.sys
11:13:01.0956 5268 HDAudBus - ok
11:13:01.0987 5268 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\windows\System32\drivers\HidBatt.sys
11:13:01.0987 5268 HidBatt - ok
11:13:02.0003 5268 [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth C:\windows\System32\drivers\hidbth.sys
11:13:02.0003 5268 HidBth - ok
11:13:02.0018 5268 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\windows\System32\drivers\hidi2c.sys
11:13:02.0018 5268 hidi2c - ok
11:13:02.0034 5268 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\windows\System32\drivers\hidir.sys
11:13:02.0034 5268 HidIr - ok
11:13:02.0065 5268 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\windows\system32\hidserv.dll
11:13:02.0065 5268 hidserv - ok
11:13:02.0097 5268 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb C:\windows\System32\drivers\hidusb.sys
11:13:02.0097 5268 HidUsb - ok
11:13:02.0128 5268 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\windows\system32\kmsvc.dll
11:13:02.0128 5268 hkmsvc - ok
11:13:02.0159 5268 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\windows\system32\ListSvc.dll
11:13:02.0159 5268 HomeGroupListener - ok
11:13:02.0206 5268 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\windows\system32\provsvc.dll
11:13:02.0206 5268 HomeGroupProvider - ok
11:13:02.0237 5268 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
11:13:02.0253 5268 HpSAMD - ok
11:13:02.0284 5268 [ 29CB98187BB5711F7759540976D295FC ] HTTP C:\windows\system32\drivers\HTTP.sys
11:13:02.0300 5268 HTTP - ok
11:13:02.0315 5268 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
11:13:02.0315 5268 hwpolicy - ok
11:13:02.0347 5268 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\windows\System32\drivers\hyperkbd.sys
11:13:02.0347 5268 hyperkbd - ok
11:13:02.0362 5268 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\windows\system32\DRIVERS\HyperVideo.sys
11:13:02.0362 5268 HyperVideo - ok
11:13:02.0362 5268 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\windows\System32\drivers\i8042prt.sys
11:13:02.0378 5268 i8042prt - ok
11:13:02.0409 5268 [ 050F2539E14F9D5E90A4B61738EC29BD ] iaStorA C:\windows\system32\drivers\iaStorA.sys
11:13:02.0409 5268 iaStorA - ok
11:13:02.0503 5268 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
11:13:02.0518 5268 iaStorV - ok
11:13:02.0894 5268 [ FCAA07539A6137EF78AAB39CC455CC5E ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
11:13:03.0019 5268 igfx - ok
11:13:03.0050 5268 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\windows\system32\drivers\iirsp.sys
11:13:03.0050 5268 iirsp - ok
11:13:03.0112 5268 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\windows\System32\ikeext.dll
11:13:03.0128 5268 IKEEXT - ok
11:13:03.0425 5268 [ E0B2C982CA743CE8B3CBD7DD50AB82B0 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys
11:13:03.0550 5268 IntcAzAudAddService - ok
11:13:03.0597 5268 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
11:13:03.0612 5268 IntcDAud - ok
11:13:03.0737 5268 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
11:13:03.0753 5268 Intel(R) Capability Licensing Service Interface - ok
11:13:03.0815 5268 [ 9656F8E29F6C3161A3E99BCD3A472FF9 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
11:13:03.0831 5268 Intel(R) ME Service - ok
11:13:03.0862 5268 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\windows\system32\drivers\intelide.sys
11:13:03.0862 5268 intelide - ok
11:13:03.0925 5268 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\windows\System32\drivers\intelppm.sys
11:13:03.0940 5268 intelppm - ok
11:13:03.0972 5268 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
11:13:03.0972 5268 IpFilterDriver - ok
11:13:04.0034 5268 [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc C:\windows\System32\iphlpsvc.dll
11:13:04.0050 5268 iphlpsvc - ok
11:13:04.0081 5268 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\windows\System32\drivers\IPMIDrv.sys
11:13:04.0081 5268 IPMIDRV - ok
11:13:04.0081 5268 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\windows\system32\drivers\ipnat.sys
11:13:04.0081 5268 IPNAT - ok
11:13:04.0112 5268 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\windows\system32\drivers\irenum.sys
11:13:04.0128 5268 IRENUM - ok
11:13:04.0128 5268 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\windows\system32\drivers\isapnp.sys
11:13:04.0128 5268 isapnp - ok
11:13:04.0175 5268 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\windows\System32\drivers\msiscsi.sys
11:13:04.0175 5268 iScsiPrt - ok
11:13:04.0222 5268 [ 78ABBE558F57144047F10A0F50FE4B2F ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
11:13:04.0237 5268 jhi_service - ok
11:13:04.0253 5268 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\windows\System32\drivers\kbdclass.sys
11:13:04.0253 5268 kbdclass - ok
11:13:04.0284 5268 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\windows\System32\drivers\kbdhid.sys
11:13:04.0284 5268 kbdhid - ok
11:13:04.0300 5268 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\windows\system32\DRIVERS\kdnic.sys
11:13:04.0300 5268 kdnic - ok
11:13:04.0331 5268 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\windows\system32\lsass.exe
11:13:04.0331 5268 KeyIso - ok
11:13:04.0362 5268 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
11:13:04.0362 5268 KSecDD - ok
11:13:04.0394 5268 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
11:13:04.0394 5268 KSecPkg - ok
11:13:04.0425 5268 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\windows\system32\drivers\ksthunk.sys
11:13:04.0425 5268 ksthunk - ok
11:13:04.0472 5268 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\windows\system32\msdtckrm.dll
11:13:04.0487 5268 KtmRm - ok
11:13:04.0519 5268 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\windows\system32\srvsvc.dll
11:13:04.0519 5268 LanmanServer - ok
11:13:04.0550 5268 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
11:13:04.0550 5268 LanmanWorkstation - ok
11:13:04.0581 5268 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
11:13:04.0581 5268 lltdio - ok
11:13:04.0612 5268 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\windows\System32\lltdsvc.dll
11:13:04.0628 5268 lltdsvc - ok
11:13:04.0644 5268 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\windows\System32\lmhsvc.dll
11:13:04.0659 5268 lmhosts - ok
11:13:04.0690 5268 [ 2C24DC448DBE8DB9BE1441B824C57E79 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:13:04.0690 5268 LMS - ok
11:13:04.0706 5268 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
11:13:04.0722 5268 LSI_SAS - ok
11:13:04.0737 5268 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
11:13:04.0753 5268 LSI_SAS2 - ok
11:13:04.0769 5268 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
11:13:04.0769 5268 LSI_SCSI - ok
11:13:04.0784 5268 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\windows\system32\drivers\lsi_sss.sys
11:13:04.0784 5268 LSI_SSS - ok
11:13:04.0815 5268 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM C:\windows\System32\lsm.dll
11:13:04.0831 5268 LSM - ok
11:13:04.0847 5268 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\windows\system32\drivers\luafv.sys
11:13:04.0847 5268 luafv - ok
11:13:04.0940 5268 [ DC330BEE07B5BFDA4DFFC8192621EAD3 ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
11:13:04.0940 5268 McShield - ok
11:13:04.0972 5268 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\windows\system32\drivers\megasas.sys
11:13:04.0987 5268 megasas - ok
11:13:05.0003 5268 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
11:13:05.0019 5268 MegaSR - ok
11:13:05.0050 5268 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\windows\System32\drivers\HECIx64.sys
11:13:05.0050 5268 MEIx64 - ok
11:13:05.0097 5268 [ 3FEB5D39E62AE1304CEF5A5FBCC55F87 ] mfeapfk C:\windows\system32\drivers\mfeapfk.sys
11:13:05.0097 5268 mfeapfk - ok
11:13:05.0144 5268 [ 9FD7E916300179C94F598D630A93CC29 ] mfeavfk C:\windows\system32\drivers\mfeavfk.sys
11:13:05.0159 5268 mfeavfk - ok
11:13:05.0191 5268 [ 9BD8154808B37F9147A74F6E8E58E3D8 ] mfeelamk C:\windows\system32\drivers\mfeelamk.sys
11:13:05.0206 5268 mfeelamk - ok
11:13:05.0222 5268 [ BA0D980819F30D413262BAD5457F19EF ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
11:13:05.0237 5268 mfefire - ok
11:13:05.0253 5268 [ 485CE746028D4523B408244EC8F829E8 ] mfefirek C:\windows\system32\drivers\mfefirek.sys
11:13:05.0269 5268 mfefirek - ok
11:13:05.0284 5268 [ 1B681A80030ADD69047F01FEE7C6FA38 ] mfehidk C:\windows\system32\drivers\mfehidk.sys
11:13:05.0300 5268 mfehidk - ok
11:13:05.0316 5268 [ F2B85511A919FE105BBFCFFB3CA81514 ] mferkdet C:\windows\system32\drivers\mferkdet.sys
11:13:05.0316 5268 mferkdet - ok
11:13:05.0347 5268 [ EDEFD210F4C0CEB7F6DAA5F45961B02D ] mfevtp C:\Windows\system32\mfevtps.exe
11:13:05.0347 5268 mfevtp - ok
11:13:05.0378 5268 [ 2D99E50ECA9CE51B8E4D69BBAD86060A ] mfewfpk C:\windows\system32\drivers\mfewfpk.sys
11:13:05.0378 5268 mfewfpk - ok
11:13:05.0409 5268 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\windows\system32\mmcss.dll
11:13:05.0409 5268 MMCSS - ok
11:13:05.0441 5268 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\windows\system32\drivers\modem.sys
11:13:05.0441 5268 Modem - ok
11:13:05.0456 5268 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor C:\windows\system32\DRIVERS\monitor.sys
11:13:05.0456 5268 monitor - ok
11:13:05.0472 5268 [ 618446B98C79776654340CE27C73485E ] mouclass C:\windows\System32\drivers\mouclass.sys
11:13:05.0472 5268 mouclass - ok
11:13:05.0487 5268 [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid C:\windows\System32\drivers\mouhid.sys
11:13:05.0487 5268 mouhid - ok
11:13:05.0534 5268 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\windows\system32\drivers\mountmgr.sys
11:13:05.0534 5268 mountmgr - ok
11:13:05.0581 5268 [ 9C3758018DED02F4AE53CCA1C5F084A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:13:05.0581 5268 MozillaMaintenance - ok
11:13:05.0628 5268 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
11:13:05.0628 5268 mpsdrv - ok
11:13:05.0691 5268 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\windows\system32\mpssvc.dll
11:13:05.0722 5268 MpsSvc - ok
11:13:05.0753 5268 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
11:13:05.0753 5268 MRxDAV - ok
11:13:05.0784 5268 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
11:13:05.0784 5268 mrxsmb - ok
11:13:05.0816 5268 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
11:13:05.0816 5268 mrxsmb10 - ok
11:13:05.0831 5268 [ E078446D4B8622AA6030C7B8A1A08962 ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
11:13:05.0847 5268 mrxsmb20 - ok
11:13:05.0878 5268 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\windows\system32\DRIVERS\bridge.sys
11:13:05.0878 5268 MsBridge - ok
11:13:05.0894 5268 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\windows\System32\msdtc.exe
11:13:05.0894 5268 MSDTC - ok
11:13:05.0941 5268 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\windows\system32\drivers\Msfs.sys
11:13:05.0941 5268 Msfs - ok
11:13:05.0956 5268 [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32 C:\windows\System32\drivers\msgpiowin32.sys
11:13:05.0956 5268 msgpiowin32 - ok
11:13:05.0972 5268 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
11:13:05.0972 5268 mshidkmdf - ok
11:13:05.0987 5268 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\windows\System32\drivers\mshidumdf.sys
11:13:05.0987 5268 mshidumdf - ok
11:13:06.0003 5268 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\windows\system32\drivers\msisadrv.sys
11:13:06.0003 5268 msisadrv - ok
11:13:06.0034 5268 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\windows\system32\iscsiexe.dll
11:13:06.0034 5268 MSiSCSI - ok
11:13:06.0050 5268 msiserver - ok
11:13:06.0066 5268 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
11:13:06.0066 5268 MSKSSRV - ok
11:13:06.0081 5268 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\windows\system32\DRIVERS\mslldp.sys
11:13:06.0097 5268 MsLldp - ok
11:13:06.0112 5268 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
11:13:06.0112 5268 MSPCLOCK - ok
11:13:06.0112 5268 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
11:13:06.0112 5268 MSPQM - ok
11:13:06.0144 5268 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
11:13:06.0144 5268 MsRPC - ok
11:13:06.0159 5268 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\windows\System32\drivers\mssmbios.sys
11:13:06.0159 5268 mssmbios - ok
11:13:06.0191 5268 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
11:13:06.0191 5268 MSTEE - ok
11:13:06.0222 5268 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\windows\System32\drivers\MTConfig.sys
11:13:06.0222 5268 MTConfig - ok
11:13:06.0237 5268 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\windows\system32\Drivers\mup.sys
11:13:06.0237 5268 Mup - ok
11:13:06.0269 5268 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\windows\system32\drivers\mvumis.sys
11:13:06.0269 5268 mvumis - ok
11:13:06.0300 5268 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\windows\system32\qagentRT.dll
11:13:06.0316 5268 napagent - ok
11:13:06.0363 5268 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
11:13:06.0378 5268 NativeWifiP - ok
11:13:06.0519 5268 [ E0E4A1F81A7D69C595A8A9DDAD084C19 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
11:13:06.0534 5268 NAUpdate - ok
11:13:06.0628 5268 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\windows\System32\ncasvc.dll
11:13:06.0644 5268 NcaSvc - ok
11:13:06.0675 5268 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\windows\System32\NcdAutoSetup.dll
11:13:06.0675 5268 NcdAutoSetup - ok
11:13:06.0722 5268 [ 0F89AE618DBA5D8AB7A2DFCC375F4159 ] NDIS C:\windows\system32\drivers\ndis.sys
11:13:06.0737 5268 NDIS - ok
11:13:06.0769 5268 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
11:13:06.0784 5268 NdisCap - ok
11:13:06.0800 5268 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\windows\system32\DRIVERS\NdisImPlatform.sys
11:13:06.0800 5268 NdisImPlatform - ok
11:13:06.0831 5268 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
11:13:06.0831 5268 NdisTapi - ok
11:13:06.0847 5268 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
11:13:06.0847 5268 Ndisuio - ok
11:13:06.0878 5268 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
11:13:06.0878 5268 NdisWan - ok
11:13:06.0878 5268 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\windows\system32\DRIVERS\ndiswan.sys
11:13:06.0894 5268 NDISWANLEGACY - ok
11:13:06.0909 5268 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
11:13:06.0909 5268 NDProxy - ok
11:13:06.0941 5268 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\windows\system32\drivers\Ndu.sys
11:13:06.0941 5268 Ndu - ok
11:13:06.0972 5268 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
11:13:06.0972 5268 NetBIOS - ok
11:13:06.0987 5268 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
11:13:06.0987 5268 NetBT - ok
11:13:07.0019 5268 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\windows\system32\lsass.exe
11:13:07.0019 5268 Netlogon - ok
11:13:07.0066 5268 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\windows\System32\netman.dll
11:13:07.0081 5268 Netman - ok
11:13:07.0112 5268 [ 20F6FD63E6D456114BC8056D62792786 ] netprofm C:\windows\System32\netprofmsvc.dll
11:13:07.0128 5268 netprofm - ok
11:13:07.0206 5268 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:13:07.0222 5268 NetTcpPortSharing - ok
11:13:07.0863 5268 [ 57B9C04D673F236D41FAB03842C8640B ] NETwNs64 C:\windows\system32\DRIVERS\NETwNs64.sys
11:13:08.0066 5268 NETwNs64 - ok
11:13:08.0081 5268 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
11:13:08.0081 5268 nfrd960 - ok
11:13:08.0128 5268 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\windows\System32\nlasvc.dll
11:13:08.0128 5268 NlaSvc - ok
11:13:08.0144 5268 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\windows\system32\drivers\Npfs.sys
11:13:08.0144 5268 Npfs - ok
11:13:08.0175 5268 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\windows\System32\drivers\npsvctrig.sys
11:13:08.0175 5268 npsvctrig - ok
11:13:08.0206 5268 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\windows\system32\nsisvc.dll
11:13:08.0206 5268 nsi - ok
11:13:08.0222 5268 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
11:13:08.0222 5268 nsiproxy - ok
11:13:08.0284 5268 [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs C:\windows\system32\drivers\Ntfs.sys
11:13:08.0300 5268 Ntfs - ok
11:13:08.0331 5268 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\windows\system32\drivers\Null.sys
11:13:08.0331 5268 Null - ok
11:13:08.0347 5268 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\windows\system32\drivers\nvraid.sys
11:13:08.0347 5268 nvraid - ok
11:13:08.0363 5268 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\windows\system32\drivers\nvstor.sys
11:13:08.0378 5268 nvstor - ok
11:13:08.0378 5268 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\windows\system32\drivers\nv_agp.sys
11:13:08.0394 5268 nv_agp - ok
11:13:08.0472 5268 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:13:08.0488 5268 ose - ok
11:13:08.0519 5268 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\windows\system32\pnrpsvc.dll
11:13:08.0519 5268 p2pimsvc - ok
11:13:08.0566 5268 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\windows\system32\p2psvc.dll
11:13:08.0581 5268 p2psvc - ok
11:13:08.0597 5268 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\windows\System32\drivers\parport.sys
11:13:08.0613 5268 Parport - ok
11:13:08.0628 5268 [ C1D7BA7F0DE487DFEEB51BF8D3EC5562 ] partmgr C:\windows\system32\drivers\partmgr.sys
11:13:08.0628 5268 partmgr - ok
11:13:08.0660 5268 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\windows\System32\pcasvc.dll
11:13:08.0675 5268 PcaSvc - ok
11:13:08.0691 5268 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\windows\system32\drivers\pci.sys
11:13:08.0691 5268 pci - ok
11:13:08.0722 5268 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\windows\system32\drivers\pciide.sys
11:13:08.0722 5268 pciide - ok
11:13:08.0738 5268 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
11:13:08.0738 5268 pcmcia - ok
11:13:08.0753 5268 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\windows\system32\drivers\pcw.sys
11:13:08.0753 5268 pcw - ok
11:13:08.0785 5268 [ EF9B4F3136B4C45F421ADE6871659FB6 ] pdc C:\windows\system32\drivers\pdc.sys
11:13:08.0785 5268 pdc - ok
11:13:08.0816 5268 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH C:\windows\system32\drivers\peauth.sys
11:13:08.0831 5268 PEAUTH - ok
11:13:08.0910 5268 [ EE926C59CBD4DC4DC9FBB85014A2F1A5 ] PEGAGFN C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys
11:13:08.0910 5268 PEGAGFN - ok
11:13:09.0113 5268 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\windows\SysWow64\perfhost.exe
11:13:09.0128 5268 PerfHost - ok
11:13:09.0972 5268 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\windows\system32\pla.dll
11:13:10.0019 5268 pla - ok
11:13:10.0050 5268 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\windows\system32\umpnpmgr.dll
11:13:10.0050 5268 PlugPlay - ok
11:13:10.0097 5268 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
11:13:10.0097 5268 PNRPAutoReg - ok
11:13:10.0144 5268 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\windows\system32\pnrpsvc.dll
11:13:10.0144 5268 PNRPsvc - ok
11:13:10.0222 5268 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
11:13:10.0238 5268 PolicyAgent - ok
11:13:10.0269 5268 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\windows\system32\umpo.dll
11:13:10.0285 5268 Power - ok
11:13:10.0331 5268 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
11:13:10.0347 5268 PptpMiniport - ok
11:13:10.0566 5268 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
11:13:10.0660 5268 PrintNotify - ok
11:13:10.0722 5268 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\windows\System32\drivers\processr.sys
11:13:10.0738 5268 Processor - ok
11:13:10.0769 5268 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\windows\system32\profsvc.dll
11:13:10.0769 5268 ProfSvc - ok
11:13:10.0800 5268 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\windows\system32\DRIVERS\pacer.sys
11:13:10.0800 5268 Psched - ok
11:13:10.0847 5268 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\windows\system32\qwave.dll
11:13:10.0863 5268 QWAVE - ok
11:13:10.0894 5268 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
11:13:10.0894 5268 QWAVEdrv - ok
11:13:10.0925 5268 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
11:13:10.0925 5268 RasAcd - ok
11:13:10.0972 5268 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
11:13:10.0972 5268 RasAgileVpn - ok
11:13:11.0003 5268 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\windows\System32\rasauto.dll
11:13:11.0019 5268 RasAuto - ok
11:13:11.0035 5268 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
11:13:11.0035 5268 Rasl2tp - ok
11:13:11.0066 5268 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\windows\System32\rasmans.dll
11:13:11.0082 5268 RasMan - ok
11:13:11.0097 5268 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
11:13:11.0097 5268 RasPppoe - ok
11:13:11.0113 5268 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
11:13:11.0113 5268 RasSstp - ok
11:13:11.0144 5268 [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
11:13:11.0144 5268 rdbss - ok
11:13:11.0175 5268 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\windows\System32\drivers\rdpbus.sys
11:13:11.0175 5268 rdpbus - ok
11:13:11.0191 5268 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\windows\system32\drivers\rdpdr.sys
11:13:11.0191 5268 RDPDR - ok
11:13:11.0238 5268 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\windows\system32\drivers\rdpvideominiport.sys
11:13:11.0238 5268 RdpVideoMiniport - ok
11:13:11.0253 5268 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
11:13:11.0269 5268 RDPWD - ok
11:13:11.0300 5268 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
11:13:11.0300 5268 rdyboost - ok
11:13:11.0332 5268 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\windows\System32\mprdim.dll
11:13:11.0347 5268 RemoteAccess - ok
11:13:11.0394 5268 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\windows\system32\regsvc.dll
11:13:11.0394 5268 RemoteRegistry - ok
11:13:11.0441 5268 [ 17EF582CBC4809F96B9E6D0543480763 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
11:13:11.0441 5268 RFCOMM - ok
11:13:11.0472 5268 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
11:13:11.0488 5268 RpcEptMapper - ok
11:13:11.0519 5268 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\windows\system32\locator.exe
11:13:11.0519 5268 RpcLocator - ok
11:13:11.0566 5268 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\windows\system32\rpcss.dll
11:13:11.0582 5268 RpcSs - ok
11:13:11.0597 5268 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
11:13:11.0613 5268 rspndr - ok
11:13:11.0660 5268 [ 0E32A8922DCFD28EA00AAEC07CB3F331 ] RSUSBSTOR C:\windows\System32\Drivers\RtsUStor.sys
11:13:11.0660 5268 RSUSBSTOR - ok
11:13:11.0769 5268 [ 3BDBB0CBFB27FEF51B7574676D1C9F6A ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
11:13:11.0769 5268 RtkAudioService - ok
11:13:11.0800 5268 [ 8A78690AC84AE5150A34C7525B450395 ] RtkBtFilter C:\windows\system32\DRIVERS\RtkBtfilter.sys
11:13:11.0800 5268 RtkBtFilter - ok
11:13:11.0832 5268 [ 34DA0D14F5C3F1883A331AFB975AB434 ] RTL8168 C:\windows\system32\DRIVERS\Rt630x64.sys
11:13:11.0847 5268 RTL8168 - ok
11:13:11.0941 5268 [ D751C8E0BE70D3D5D68439BC934EEBC4 ] RTWlanE C:\windows\system32\DRIVERS\rtwlane.sys
11:13:11.0988 5268 RTWlanE - ok
11:13:12.0066 5268 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\windows\System32\drivers\vms3cap.sys
11:13:12.0066 5268 s3cap - ok
11:13:12.0113 5268 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\windows\system32\lsass.exe
11:13:12.0113 5268 SamSs - ok
11:13:12.0175 5268 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
11:13:12.0191 5268 sbp2port - ok
11:13:12.0222 5268 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\windows\System32\SCardSvr.dll
11:13:12.0238 5268 SCardSvr - ok
11:13:12.0253 5268 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
11:13:12.0269 5268 scfilter - ok
11:13:12.0332 5268 [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule C:\windows\system32\schedsvc.dll
11:13:12.0347 5268 Schedule - ok
11:13:12.0363 5268 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\windows\System32\certprop.dll
11:13:12.0378 5268 SCPolicySvc - ok
11:13:12.0441 5268 [ 66E29CADF9FF6C8325C356BDD617F7EA ] sdbus C:\windows\System32\drivers\sdbus.sys
11:13:12.0441 5268 sdbus - ok
11:13:12.0488 5268 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\windows\System32\SDRSVC.dll
11:13:12.0503 5268 SDRSVC - ok
11:13:12.0519 5268 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\windows\System32\drivers\sdstor.sys
11:13:12.0519 5268 sdstor - ok
11:13:12.0550 5268 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys
11:13:12.0550 5268 secdrv - ok
11:13:12.0582 5268 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\windows\system32\seclogon.dll
11:13:12.0582 5268 seclogon - ok
11:13:12.0597 5268 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\windows\System32\sens.dll
11:13:12.0613 5268 SENS - ok
11:13:12.0628 5268 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\windows\system32\sensrsvc.dll
11:13:12.0628 5268 SensrSvc - ok
11:13:12.0644 5268 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\windows\system32\drivers\SerCx.sys
11:13:12.0644 5268 SerCx - ok
11:13:12.0675 5268 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\windows\System32\drivers\serenum.sys
11:13:12.0675 5268 Serenum - ok
11:13:12.0707 5268 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\windows\System32\drivers\serial.sys
11:13:12.0707 5268 Serial - ok
11:13:12.0722 5268 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\windows\System32\drivers\sermouse.sys
11:13:12.0722 5268 sermouse - ok
11:13:12.0785 5268 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\windows\system32\sessenv.dll
11:13:12.0785 5268 SessionEnv - ok
11:13:12.0785 5268 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\windows\System32\drivers\sfloppy.sys
11:13:12.0800 5268 sfloppy - ok
11:13:12.0816 5268 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\windows\System32\ipnathlp.dll
11:13:12.0832 5268 SharedAccess - ok
11:13:12.0878 5268 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\windows\System32\shsvcs.dll
11:13:12.0878 5268 ShellHWDetection - ok
11:13:12.0910 5268 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
11:13:12.0910 5268 SiSRaid2 - ok
11:13:12.0925 5268 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
11:13:12.0941 5268 SiSRaid4 - ok
11:13:12.0957 5268 [ E5D300C2193B0131E26B94FD4C68E160 ] SmbDrvI C:\windows\system32\DRIVERS\Smb_driver_Intel.sys
11:13:12.0957 5268 SmbDrvI - ok
11:13:12.0988 5268 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\windows\System32\snmptrap.exe
11:13:13.0003 5268 SNMPTRAP - ok
11:13:13.0019 5268 [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport C:\windows\system32\drivers\spaceport.sys
11:13:13.0019 5268 spaceport - ok
11:13:13.0050 5268 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\windows\system32\drivers\SpbCx.sys
11:13:13.0066 5268 SpbCx - ok
11:13:13.0097 5268 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\windows\System32\spoolsv.exe
11:13:13.0113 5268 Spooler - ok
11:13:13.0379 5268 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\windows\system32\sppsvc.exe
11:13:13.0504 5268 sppsvc - ok
11:13:13.0566 5268 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\windows\system32\DRIVERS\srv.sys
11:13:13.0582 5268 srv - ok
11:13:13.0644 5268 [ C2106BB710AA34A046126AED7BCA6964 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
11:13:13.0660 5268 srv2 - ok
11:13:13.0691 5268 [ 9400C71F5A1A380B494B6922F007D485 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
11:13:13.0707 5268 srvnet - ok
11:13:13.0754 5268 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
11:13:13.0769 5268 SSDPSRV - ok
11:13:13.0785 5268 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\windows\system32\sstpsvc.dll
11:13:13.0785 5268 SstpSvc - ok
11:13:13.0816 5268 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\windows\system32\drivers\stexstor.sys
11:13:13.0832 5268 stexstor - ok
11:13:13.0879 5268 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\windows\System32\wiaservc.dll
11:13:13.0894 5268 stisvc - ok
11:13:13.0925 5268 [ C588BBD37B432CE3204E5765B459E6B2 ] storahci C:\windows\system32\drivers\storahci.sys
11:13:13.0925 5268 storahci - ok
11:13:13.0957 5268 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\windows\system32\DRIVERS\vmstorfl.sys
11:13:13.0957 5268 storflt - ok
11:13:14.0004 5268 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\windows\system32\storsvc.dll
11:13:14.0004 5268 StorSvc - ok
11:13:14.0019 5268 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\windows\system32\drivers\storvsc.sys
11:13:14.0019 5268 storvsc - ok
11:13:14.0050 5268 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\windows\system32\svsvc.dll
11:13:14.0050 5268 svsvc - ok
11:13:14.0066 5268 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\windows\System32\drivers\swenum.sys
11:13:14.0066 5268 swenum - ok
11:13:14.0113 5268 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\windows\System32\swprv.dll
11:13:14.0144 5268 swprv - ok
11:13:14.0207 5268 [ 3675657B3A4A2868A2C2B2A160E4A3C9 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
11:13:14.0222 5268 SynTP - ok
11:13:14.0347 5268 [ DC21E1F06343773D7E24362DCEF7944B ] SysMain C:\windows\system32\sysmain.dll
11:13:14.0363 5268 SysMain - ok
11:13:14.0441 5268 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] SystemEventsBroker C:\windows\System32\SystemEventsBrokerServer.dll
11:13:14.0457 5268 SystemEventsBroker - ok
11:13:14.0472 5268 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\windows\System32\TabSvc.dll
11:13:14.0488 5268 TabletInputService - ok
11:13:14.0504 5268 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\windows\System32\tapisrv.dll
11:13:14.0504 5268 TapiSrv - ok
11:13:14.0582 5268 [ 1D644E2D0FC395A055AB1C23C3B43631 ] Tcpip C:\windows\system32\drivers\tcpip.sys
11:13:14.0597 5268 Tcpip - ok
11:13:14.0644 5268 [ 1D644E2D0FC395A055AB1C23C3B43631 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
11:13:14.0660 5268 TCPIP6 - ok
11:13:14.0691 5268 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
11:13:14.0691 5268 tcpipreg - ok
11:13:14.0738 5268 [ 58480A57ACF2671C343FD1D4BA990E34 ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys
11:13:14.0738 5268 tdcmdpst - ok
11:13:14.0769 5268 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\windows\system32\DRIVERS\tdx.sys
11:13:14.0769 5268 tdx - ok
11:13:14.0832 5268 [ E16AE419CBB6071E6A18A98498FF12FD ] TemproMonitoringService C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
11:13:14.0847 5268 TemproMonitoringService - ok
11:13:14.0879 5268 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\windows\System32\drivers\terminpt.sys
11:13:14.0879 5268 terminpt - ok
11:13:14.0925 5268 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\windows\System32\termsrv.dll
11:13:14.0941 5268 TermService - ok
11:13:14.0972 5268 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\windows\system32\themeservice.dll
11:13:14.0972 5268 Themes - ok
11:13:15.0004 5268 [ 16E745743BABAF480B7718442F38B076 ] Thotkey C:\windows\System32\drivers\Thotkey.sys
11:13:15.0004 5268 Thotkey - ok
11:13:15.0035 5268 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\windows\system32\mmcss.dll
11:13:15.0035 5268 THREADORDER - ok
11:13:15.0066 5268 [ FF4135424A79DCC2998276D8E39C9B4D ] TimeBroker C:\windows\System32\TimeBrokerServer.dll
11:13:15.0082 5268 TimeBroker - ok
11:13:15.0144 5268 [ 5201342394DD42848027CE96A37043DB ] TMachInfo C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
11:13:15.0160 5268 TMachInfo - ok
11:13:15.0175 5268 [ ED32035BDFECED1AD66D459FD9CC1140 ] TODDSrv C:\Windows\system32\TODDSrv.exe
11:13:15.0191 5268 TODDSrv - ok
11:13:15.0238 5268 [ 4D7977197C3EC8C65F533E8A84DE229C ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\Teco\TecoService.exe
11:13:15.0238 5268 TOSHIBA eco Utility Service - ok
11:13:15.0269 5268 [ A4DDAD3BF13F370EC392BE243E334EBA ] tosrfec C:\windows\System32\drivers\tosrfec.sys
11:13:15.0269 5268 tosrfec - ok
11:13:15.0300 5268 [ 36391C3953D191A2AF4556D5D706C641 ] tos_sps64 C:\windows\system32\drivers\tos_sps64.sys
11:13:15.0316 5268 tos_sps64 - ok
11:13:15.0363 5268 [ 8608681DC6E2975815A593209A6432CD ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
11:13:15.0379 5268 TPCHSrv - ok
11:13:15.0410 5268 [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM C:\windows\system32\drivers\tpm.sys
11:13:15.0410 5268 TPM - ok
11:13:15.0441 5268 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\windows\System32\trkwks.dll
11:13:15.0457 5268 TrkWks - ok
11:13:15.0519 5268 [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
11:13:15.0519 5268 TrustedInstaller - ok
11:13:15.0550 5268 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
11:13:15.0550 5268 TsUsbFlt - ok
11:13:15.0566 5268 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\windows\System32\drivers\TsUsbGD.sys
11:13:15.0566 5268 TsUsbGD - ok
11:13:15.0582 5268 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
11:13:15.0582 5268 tunnel - ok
11:13:15.0613 5268 [ 54BDBF3D4DED58DA78B702471C68D4CA ] TVALZ C:\windows\system32\drivers\TVALZ_O.SYS
11:13:15.0613 5268 TVALZ - ok
11:13:15.0644 5268 [ 55A9A23DD64EB7781FCAB565B028CD0E ] TVALZFL C:\windows\system32\DRIVERS\TVALZFL.sys
11:13:15.0644 5268 TVALZFL - ok
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 25 led 2013 13:37

11:13:15.0660 5268 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\windows\system32\drivers\uagp35.sys
11:13:15.0660 5268 uagp35 - ok
11:13:15.0691 5268 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\windows\System32\drivers\uaspstor.sys
11:13:15.0707 5268 UASPStor - ok
11:13:15.0722 5268 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000 C:\windows\System32\drivers\ucx01000.sys
11:13:15.0738 5268 UCX01000 - ok
11:13:15.0769 5268 [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs C:\windows\system32\DRIVERS\udfs.sys
11:13:15.0769 5268 udfs - ok
11:13:15.0801 5268 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\windows\system32\UI0Detect.exe
11:13:15.0816 5268 UI0Detect - ok
11:13:15.0847 5268 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
11:13:15.0847 5268 uliagpkx - ok
11:13:15.0879 5268 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\windows\System32\drivers\umbus.sys
11:13:15.0879 5268 umbus - ok
11:13:15.0894 5268 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\windows\System32\drivers\umpass.sys
11:13:15.0894 5268 UmPass - ok
11:13:15.0926 5268 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\windows\System32\umrdp.dll
11:13:15.0941 5268 UmRdpService - ok
11:13:16.0066 5268 [ E1A119AD21F5AFE22EB516C549306D3D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:13:16.0082 5268 UNS - ok
11:13:16.0222 5268 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\windows\System32\upnphost.dll
11:13:16.0238 5268 upnphost - ok
11:13:16.0269 5268 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\windows\System32\drivers\usbccgp.sys
11:13:16.0269 5268 usbccgp - ok
11:13:16.0285 5268 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\windows\System32\drivers\usbcir.sys
11:13:16.0301 5268 usbcir - ok
11:13:16.0332 5268 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\windows\System32\drivers\usbehci.sys
11:13:16.0332 5268 usbehci - ok
11:13:16.0347 5268 [ FBB6794E3BBAD92D66D59D206C1F849F ] usbhub C:\windows\System32\drivers\usbhub.sys
11:13:16.0363 5268 usbhub - ok
11:13:16.0394 5268 [ B7A948501424805571BF562BB0BFE31D ] USBHUB3 C:\windows\System32\drivers\UsbHub3.sys
11:13:16.0394 5268 USBHUB3 - ok
11:13:16.0410 5268 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\windows\System32\drivers\usbohci.sys
11:13:16.0426 5268 usbohci - ok
11:13:16.0441 5268 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\windows\System32\drivers\usbprint.sys
11:13:16.0441 5268 usbprint - ok
11:13:16.0472 5268 [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR C:\windows\System32\drivers\USBSTOR.SYS
11:13:16.0472 5268 USBSTOR - ok
11:13:16.0519 5268 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\windows\System32\drivers\usbuhci.sys
11:13:16.0519 5268 usbuhci - ok
11:13:16.0551 5268 [ 09799E701B4327097E9F63D3FE221083 ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
11:13:16.0566 5268 usbvideo - ok
11:13:16.0597 5268 [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI C:\windows\System32\drivers\USBXHCI.SYS
11:13:16.0597 5268 USBXHCI - ok
11:13:16.0629 5268 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\windows\system32\lsass.exe
11:13:16.0629 5268 VaultSvc - ok
11:13:16.0660 5268 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
11:13:16.0660 5268 vdrvroot - ok
11:13:16.0707 5268 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds C:\windows\System32\vds.exe
11:13:16.0722 5268 vds - ok
11:13:16.0738 5268 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\windows\system32\drivers\VerifierExt.sys
11:13:16.0738 5268 VerifierExt - ok
11:13:16.0769 5268 [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp C:\windows\System32\drivers\vhdmp.sys
11:13:16.0769 5268 vhdmp - ok
11:13:16.0801 5268 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\windows\system32\drivers\viaide.sys
11:13:16.0801 5268 viaide - ok
11:13:16.0832 5268 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\windows\system32\drivers\vmbus.sys
11:13:16.0832 5268 vmbus - ok
11:13:16.0847 5268 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\windows\System32\drivers\VMBusHID.sys
11:13:16.0847 5268 VMBusHID - ok
11:13:16.0894 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\windows\System32\ICSvc.dll
11:13:16.0894 5268 vmicheartbeat - ok
11:13:16.0910 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\windows\System32\ICSvc.dll
11:13:16.0910 5268 vmickvpexchange - ok
11:13:16.0926 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\windows\System32\ICSvc.dll
11:13:16.0926 5268 vmicrdv - ok
11:13:16.0926 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\windows\System32\ICSvc.dll
11:13:16.0941 5268 vmicshutdown - ok
11:13:16.0941 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\windows\System32\ICSvc.dll
11:13:16.0957 5268 vmictimesync - ok
11:13:16.0988 5268 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\windows\System32\ICSvc.dll
11:13:16.0988 5268 vmicvss - ok
11:13:17.0019 5268 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\windows\system32\drivers\volmgr.sys
11:13:17.0019 5268 volmgr - ok
11:13:17.0035 5268 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
11:13:17.0051 5268 volmgrx - ok
11:13:17.0066 5268 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap C:\windows\system32\drivers\volsnap.sys
11:13:17.0066 5268 volsnap - ok
11:13:17.0113 5268 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\windows\System32\drivers\vpci.sys
11:13:17.0113 5268 vpci - ok
11:13:17.0129 5268 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
11:13:17.0144 5268 vsmraid - ok
11:13:17.0269 5268 [ EA658570314042C914964FC72AB50E6B ] VSS C:\windows\system32\vssvc.exe
11:13:17.0332 5268 VSS - ok
11:13:17.0363 5268 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\windows\system32\drivers\vstxraid.sys
11:13:17.0363 5268 VSTXRAID - ok
11:13:17.0379 5268 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\windows\System32\drivers\vwifibus.sys
11:13:17.0379 5268 vwifibus - ok
11:13:17.0410 5268 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
11:13:17.0410 5268 vwififlt - ok
11:13:17.0472 5268 [ 73FA1A41A97A5C34ADC03B3577FF1A86 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
11:13:17.0472 5268 vwifimp - ok
11:13:17.0504 5268 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\windows\system32\w32time.dll
11:13:17.0519 5268 W32Time - ok
11:13:17.0535 5268 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\windows\System32\drivers\wacompen.sys
11:13:17.0535 5268 WacomPen - ok
11:13:17.0566 5268 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp C:\windows\system32\DRIVERS\wanarp.sys
11:13:17.0566 5268 Wanarp - ok
11:13:17.0566 5268 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
11:13:17.0566 5268 Wanarpv6 - ok
11:13:17.0629 5268 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\windows\system32\wbengine.exe
11:13:17.0644 5268 wbengine - ok
11:13:17.0676 5268 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
11:13:17.0691 5268 WbioSrvc - ok
11:13:17.0722 5268 [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc C:\windows\System32\wcmsvc.dll
11:13:17.0722 5268 Wcmsvc - ok
11:13:17.0769 5268 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\windows\System32\wcncsvc.dll
11:13:17.0785 5268 wcncsvc - ok
11:13:17.0801 5268 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
11:13:17.0816 5268 WcsPlugInService - ok
11:13:17.0832 5268 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\windows\system32\drivers\wd.sys
11:13:17.0832 5268 Wd - ok
11:13:17.0863 5268 [ 260F8DFC4D5748F4CCB9B19CFB0E58EA ] WdBoot C:\windows\system32\drivers\WdBoot.sys
11:13:17.0863 5268 WdBoot - ok
11:13:17.0894 5268 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
11:13:17.0894 5268 Wdf01000 - ok
11:13:17.0926 5268 [ 880FFFC4D5BBBB4187B6B04AB2E8C32A ] WdFilter C:\windows\system32\drivers\WdFilter.sys
11:13:17.0926 5268 WdFilter - ok
11:13:17.0957 5268 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\windows\system32\wdi.dll
11:13:17.0957 5268 WdiServiceHost - ok
11:13:17.0957 5268 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\windows\system32\wdi.dll
11:13:17.0972 5268 WdiSystemHost - ok
11:13:17.0988 5268 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\windows\System32\webclnt.dll
11:13:18.0004 5268 WebClient - ok
11:13:18.0035 5268 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\windows\system32\wecsvc.dll
11:13:18.0035 5268 Wecsvc - ok
11:13:18.0051 5268 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\windows\System32\wercplsupport.dll
11:13:18.0066 5268 wercplsupport - ok
11:13:18.0066 5268 [ 8E2426162ED6749A127B35D235F21E11 ] WerSvc C:\windows\System32\WerSvc.dll
11:13:18.0082 5268 WerSvc - ok
11:13:18.0113 5268 [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS C:\windows\system32\DRIVERS\wfplwfs.sys
11:13:18.0113 5268 WFPLWFS - ok
11:13:18.0144 5268 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\windows\System32\wiarpc.dll
11:13:18.0144 5268 WiaRpc - ok
11:13:18.0176 5268 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\windows\system32\drivers\wimmount.sys
11:13:18.0176 5268 WIMMount - ok
11:13:18.0207 5268 WinDefend - ok
11:13:18.0316 5268 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\windows\system32\winhttp.dll
11:13:18.0363 5268 WinHttpAutoProxySvc - ok
11:13:18.0441 5268 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
11:13:18.0441 5268 Winmgmt - ok
11:13:18.0598 5268 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\windows\system32\WsmSvc.dll
11:13:18.0676 5268 WinRM - ok
11:13:18.0723 5268 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\windows\System32\wlansvc.dll
11:13:18.0754 5268 WlanSvc - ok
11:13:18.0816 5268 [ 08EFA13A2234C8C3B8A99E4B88BE7E9B ] wlidsvc C:\windows\system32\wlidsvc.dll
11:13:18.0848 5268 wlidsvc - ok
11:13:18.0863 5268 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\windows\System32\drivers\wmiacpi.sys
11:13:18.0863 5268 WmiAcpi - ok
11:13:18.0894 5268 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
11:13:18.0894 5268 wmiApSrv - ok
11:13:18.0926 5268 WMPNetworkSvc - ok
11:13:18.0957 5268 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\windows\system32\DRIVERS\wpcfltr.sys
11:13:18.0957 5268 wpcfltr - ok
11:13:18.0988 5268 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\windows\System32\wpcsvc.dll
11:13:18.0988 5268 WPCSvc - ok
11:13:19.0019 5268 [ 94AA5150E35B3ABB7191FE641E3C2473 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
11:13:19.0035 5268 WPDBusEnum - ok
11:13:19.0066 5268 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\windows\system32\drivers\WpdUpFltr.sys
11:13:19.0066 5268 WpdUpFltr - ok
11:13:19.0082 5268 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
11:13:19.0082 5268 ws2ifsl - ok
11:13:19.0113 5268 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc C:\windows\System32\wscsvc.dll
11:13:19.0113 5268 wscsvc - ok
11:13:19.0113 5268 WSearch - ok
11:13:19.0207 5268 [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService C:\windows\System32\WSService.dll
11:13:19.0238 5268 WSService - ok
11:13:19.0332 5268 [ A8484C0CB54DB48180FB7CA00F1C3F8F ] wuauserv C:\windows\system32\wuaueng.dll
11:13:19.0348 5268 wuauserv - ok
11:13:19.0363 5268 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\windows\system32\drivers\WudfPf.sys
11:13:19.0379 5268 WudfPf - ok
11:13:19.0394 5268 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\windows\System32\drivers\WUDFRd.sys
11:13:19.0394 5268 WUDFRd - ok
11:13:19.0410 5268 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\windows\system32\DRIVERS\WUDFRd.sys
11:13:19.0410 5268 WUDFSensorLP - ok
11:13:19.0441 5268 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\windows\System32\WUDFSvc.dll
11:13:19.0441 5268 wudfsvc - ok
11:13:19.0457 5268 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\windows\system32\DRIVERS\WUDFRd.sys
11:13:19.0473 5268 WUDFWpdFs - ok
11:13:19.0504 5268 [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc C:\windows\System32\wwansvc.dll
11:13:19.0519 5268 WwanSvc - ok
11:13:19.0535 5268 ================ Scan global ===============================
11:13:19.0582 5268 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\windows\system32\basesrv.dll
11:13:19.0613 5268 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\windows\system32\winsrv.dll
11:13:19.0644 5268 [ BD7C6949984D19AAA609896B675E7357 ] C:\windows\system32\sxssrv.dll
11:13:19.0707 5268 [ 8F226143046435C75C033B0C52E90FFE ] C:\windows\system32\services.exe
11:13:19.0723 5268 [Global] - ok
11:13:19.0723 5268 ================ Scan MBR ==================================
11:13:19.0723 5268 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
11:13:19.0738 5268 \Device\Harddisk0\DR0 - ok
11:13:19.0738 5268 ================ Scan VBR ==================================
11:13:19.0754 5268 [ 5052BDC74E0CE4805BC8D27306CEEE4B ] \Device\Harddisk0\DR0\Partition1
11:13:19.0754 5268 \Device\Harddisk0\DR0\Partition1 - ok
11:13:19.0769 5268 [ 5269B4BA9A89AE593FD71F5D1A5AF816 ] \Device\Harddisk0\DR0\Partition2
11:13:19.0769 5268 \Device\Harddisk0\DR0\Partition2 - ok
11:13:19.0769 5268 [ B6DDCB399B8F851690B8A536749FEF52 ] \Device\Harddisk0\DR0\Partition3
11:13:19.0785 5268 \Device\Harddisk0\DR0\Partition3 - ok
11:13:19.0785 5268 [ EB53EB1C512D76B5742DE047C1BF52EC ] \Device\Harddisk0\DR0\Partition4
11:13:19.0785 5268 \Device\Harddisk0\DR0\Partition4 - ok
11:13:19.0816 5268 [ CEB1072321A436377563F32B779B2CE6 ] \Device\Harddisk0\DR0\Partition5
11:13:19.0832 5268 \Device\Harddisk0\DR0\Partition5 - ok
11:13:19.0832 5268 ============================================================
11:13:19.0832 5268 Scan finished
11:13:19.0832 5268 ============================================================
11:13:19.0848 6004 Detected object count: 0
11:13:19.0848 6004 Actual detected object count: 0
11:13:38.0552 1384 Deinitialize success
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod jaro3 » 25 led 2013 22:29

Uninstall McAfee:
McAfee
http://download.mcafee.com/products/lic ... s/MCPR.exe

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 25 led 2013 23:08

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-01-25 23:04:29
-----------------------------
23:04:29.054 OS Version: Windows x64 6.2.9200
23:04:29.054 Number of processors: 2 586 0x2A07
23:04:29.054 ComputerName: SATELLITE UserName: user
23:04:29.086 Initialze error 1
23:04:29.258 AVAST engine defs: 13012500
23:04:41.852 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000036
23:04:41.868 Disk 0 Vendor: TOSHIBA_MK5075GSX GT001M Size: 476940MB BusType: 11
23:04:41.883 Disk 0 MBR read successfully
23:04:41.883 Disk 0 MBR scan
23:04:41.883 Disk 0 unknown MBR code
23:04:41.899 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
23:04:41.899 Disk 0 scanning C:\windows\system32\drivers
23:04:41.899 Service scanning
23:04:42.493 Modules scanning
23:04:42.493 Disk 0 trace - called modules:
23:04:42.508 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
23:04:42.524 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006116060]
23:04:42.524 3 CLASSPNP.SYS[fffff88000a028aa] -> nt!IofCallDriver -> \Device\00000036[0xfffffa8004cd0060]
23:04:42.540 AVAST engine scan C:\windows
23:04:42.540 AVAST engine scan C:\windows\system32
23:04:42.540 AVAST engine scan C:\windows\system32\drivers
23:04:42.555 AVAST engine scan C:\Users\user
23:04:42.555 AVAST engine scan C:\ProgramData
23:04:42.555 Scan finished successfully
23:06:49.620 Disk 0 MBR has been saved successfully to "C:\Users\user\Desktop\MBR.dat"
23:06:49.807 The log file has been saved successfully to "C:\Users\user\Desktop\aswMBR.txt"
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Orcus » 26 led 2013 18:28

Spusť znovu aswMBR , dej sken a poté klikni na „Fix“ (FixMBR)
Zavři program , restartuj PC , po restartu nový log log z aswMBR.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Jan Pašek
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 3701
Registrován: leden 06
Bydliště: Plzeň
Pohlaví: Muž
Stav:
Offline

Re: PLS kontrola HJT log - zánovní NTB po výměně SW

Příspěvekod Jan Pašek » 26 led 2013 18:42

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-01-26 18:40:31
-----------------------------
18:40:31.995 OS Version: Windows x64 6.2.9200
18:40:31.995 Number of processors: 2 586 0x2A07
18:40:31.995 ComputerName: SATELLITE UserName: user
18:40:32.058 Initialze error 1
18:40:32.292 AVAST engine defs: 13012600
18:40:35.589 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000036
18:40:35.589 Disk 0 Vendor: TOSHIBA_MK5075GSX GT001M Size: 476940MB BusType: 11
18:40:35.683 Disk 0 MBR read successfully
18:40:35.683 Disk 0 MBR scan
18:40:35.730 Disk 0 unknown MBR code
18:40:35.761 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
18:40:35.933 Disk 0 scanning C:\windows\system32\drivers
18:40:35.933 Service scanning
18:40:38.855 Modules scanning
18:40:38.855 Disk 0 trace - called modules:
18:40:38.871 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
18:40:38.871 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004f98470]
18:40:38.886 3 CLASSPNP.SYS[fffff88001b888aa] -> nt!IofCallDriver -> \Device\00000036[0xfffffa8004ce4720]
18:40:38.917 AVAST engine scan C:\windows
18:40:38.917 AVAST engine scan C:\windows\system32
18:40:38.917 AVAST engine scan C:\windows\system32\drivers
18:40:38.933 AVAST engine scan C:\Users\user
18:40:38.933 AVAST engine scan C:\ProgramData
18:40:38.933 Scan finished successfully
18:40:50.887 Disk 0 MBR has been saved successfully to "C:\Users\user\Desktop\MBR.dat"
18:40:50.887 The log file has been saved successfully to "C:\Users\user\Desktop\aswMBR.txt"
Jendův rozcestník (Odkazy, které jsem měl dříve v podpisu najdete v mém rozcestníku.) Jendovy novinky - Co je pro Vás odemne nového Pokud potřebujete mermomocí vědět na čem páchám PC kriminalitu sestavy jsou v profilu.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 124 hostů