Zdravím, před chvíli byl tento ntb infikován virem.
Provedl jsem v nouz. režimu MBAM a odstranil dva výsledky (trojan ransom a ještě něco v tempu). Udělal jsem CCleaner a ADW Cleaner.
Tady je HJT, možná už je to pryč:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:17:52, on 24.2.2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\system32\DllHost.exe
C:\Users\marek\Downloads\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [BigDog303] C:\Windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{789B4302-27CD-4727-BA87-8B5EC3E54992}: NameServer = 192.168.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Windows\RtkAudioService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDs.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10884 bytes
AdwCleaner (S1):
# AdwCleaner v2.113 - Logfile created 02/24/2013 at 14:52:16
# Updated 23/02/2013 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : marek - MAREK-PC
# Boot Mode : Safe mode with networking
# Running from : C:\Users\marek\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\user.js
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\ICQ6Toolbar
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\Users\marek\AppData\Local\Babylon
Folder Deleted : C:\Users\marek\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\marek\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\marek\AppData\Roaming\Babylon
Folder Deleted : C:\Users\marek\AppData\Roaming\Mozilla\Firefox\Profiles\7qz43w63.default-1351720089763\extensions\toolbar@ask.com
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
***** [Registry] *****
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
-\\ Mozilla Firefox v18.0.2 (cs)
File : C:\Users\marek\AppData\Roaming\Mozilla\Firefox\Profiles\x7xmw8p6.default-1353672640472\prefs.js
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=VDJ&o=41647960&local[...]
-\\ Google Chrome v24.0.1312.57
File : C:\Users\marek\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [11672 octets] - [24/02/2013 14:51:43]
AdwCleaner[S1].txt - [11131 octets] - [24/02/2013 14:52:16]
########## EOF - C:\AdwCleaner[S1].txt - [11192 octets] ##########
Policie ČR (vir) na tomto NTB
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
Odinstaluj McAfee Security Scan Plus
Fixni:
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
Fixni:
Kód: Vybrat vše
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
- Clorky
- Moderátor / člen HW týmu
-
Master Level 8.5
- Příspěvky: 7032
- Registrován: květen 10
- Bydliště: Moravskoslezský kraj
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
15:54:27.0695 4432 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
15:54:28.0304 4432 ============================================================
15:54:28.0304 4432 Current date / time: 2013/02/24 15:54:28.0304
15:54:28.0304 4432 SystemInfo:
15:54:28.0304 4432
15:54:28.0304 4432 OS Version: 6.0.6002 ServicePack: 2.0
15:54:28.0304 4432 Product type: Workstation
15:54:28.0304 4432 ComputerName: MAREK-PC
15:54:28.0304 4432 UserName: marek
15:54:28.0304 4432 Windows directory: C:\Windows
15:54:28.0304 4432 System windows directory: C:\Windows
15:54:28.0304 4432 Processor architecture: Intel x86
15:54:28.0304 4432 Number of processors: 2
15:54:28.0304 4432 Page size: 0x1000
15:54:28.0304 4432 Boot type: Normal boot
15:54:28.0304 4432 ============================================================
15:54:29.0427 4432 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
15:54:29.0427 4432 ============================================================
15:54:29.0427 4432 \Device\Harddisk0\DR0:
15:54:29.0427 4432 MBR partitions:
15:54:29.0427 4432 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xFEC800, BlocksNum 0x1C1D8970
15:54:29.0427 4432 ============================================================
15:54:29.0614 4432 C: <-> \Device\Harddisk0\DR0\Partition1
15:54:29.0614 4432 ============================================================
15:54:29.0614 4432 Initialize success
15:54:29.0614 4432 ============================================================
15:54:32.0204 4232 ============================================================
15:54:32.0204 4232 Scan started
15:54:32.0204 4232 Mode: Manual;
15:54:32.0204 4232 ============================================================
15:54:34.0434 4232 ================ Scan system memory ========================
15:54:34.0434 4232 System memory - ok
15:54:34.0434 4232 ================ Scan services =============================
15:54:34.0824 4232 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
15:54:34.0824 4232 ACPI - ok
15:54:34.0949 4232 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:54:34.0949 4232 AdobeFlashPlayerUpdateSvc - ok
15:54:35.0043 4232 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
15:54:35.0058 4232 adp94xx - ok
15:54:35.0090 4232 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
15:54:35.0105 4232 adpahci - ok
15:54:35.0105 4232 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
15:54:35.0121 4232 adpu160m - ok
15:54:35.0136 4232 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
15:54:35.0136 4232 adpu320 - ok
15:54:35.0292 4232 [ B11C71B29FA69E4586F9B65560E6604D ] AdvancedSystemCareService5 C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
15:54:35.0308 4232 AdvancedSystemCareService5 - ok
15:54:35.0324 4232 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
15:54:35.0324 4232 AeLookupSvc - ok
15:54:35.0433 4232 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
15:54:35.0433 4232 AFD - ok
15:54:35.0495 4232 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
15:54:35.0495 4232 agp440 - ok
15:54:35.0558 4232 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
15:54:35.0573 4232 aic78xx - ok
15:54:35.0589 4232 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
15:54:35.0589 4232 ALG - ok
15:54:35.0604 4232 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
15:54:35.0604 4232 aliide - ok
15:54:35.0604 4232 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
15:54:35.0620 4232 amdagp - ok
15:54:35.0620 4232 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
15:54:35.0636 4232 amdide - ok
15:54:35.0636 4232 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
15:54:35.0636 4232 AmdK7 - ok
15:54:35.0651 4232 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
15:54:35.0651 4232 AmdK8 - ok
15:54:35.0776 4232 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
15:54:35.0776 4232 Appinfo - ok
15:54:36.0010 4232 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
15:54:36.0026 4232 arc - ok
15:54:36.0072 4232 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
15:54:36.0088 4232 arcsas - ok
15:54:36.0135 4232 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
15:54:36.0135 4232 AsyncMac - ok
15:54:36.0166 4232 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
15:54:36.0182 4232 atapi - ok
15:54:36.0322 4232 [ 600EFE56F37ADBD65A0FB076B50D1B8D ] athr C:\Windows\system32\DRIVERS\athr.sys
15:54:36.0338 4232 athr - ok
15:54:36.0696 4232 [ A4E212F45B2457B39D59D4972A67AF47 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
15:54:36.0806 4232 atikmdag - ok
15:54:36.0915 4232 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:54:36.0915 4232 AudioEndpointBuilder - ok
15:54:36.0930 4232 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
15:54:36.0930 4232 Audiosrv - ok
15:54:37.0102 4232 [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
15:54:37.0102 4232 BcmSqlStartupSvc - ok
15:54:37.0180 4232 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
15:54:37.0180 4232 Beep - ok
15:54:37.0258 4232 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
15:54:37.0274 4232 BFE - ok
15:54:37.0367 4232 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
15:54:37.0383 4232 BITS - ok
15:54:37.0430 4232 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
15:54:37.0430 4232 blbdrive - ok
15:54:37.0461 4232 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:54:37.0461 4232 bowser - ok
15:54:37.0492 4232 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
15:54:37.0492 4232 BrFiltLo - ok
15:54:37.0508 4232 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
15:54:37.0508 4232 BrFiltUp - ok
15:54:37.0554 4232 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
15:54:37.0554 4232 Browser - ok
15:54:37.0570 4232 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
15:54:37.0570 4232 Brserid - ok
15:54:37.0586 4232 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
15:54:37.0586 4232 BrSerWdm - ok
15:54:37.0601 4232 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
15:54:37.0601 4232 BrUsbMdm - ok
15:54:37.0617 4232 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
15:54:37.0617 4232 BrUsbSer - ok
15:54:37.0632 4232 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
15:54:37.0632 4232 BTHMODEM - ok
15:54:37.0679 4232 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:54:37.0679 4232 cdfs - ok
15:54:37.0710 4232 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
15:54:37.0710 4232 cdrom - ok
15:54:37.0788 4232 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
15:54:37.0788 4232 CertPropSvc - ok
15:54:37.0820 4232 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
15:54:37.0835 4232 circlass - ok
15:54:37.0866 4232 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
15:54:37.0882 4232 CLFS - ok
15:54:37.0929 4232 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:54:37.0929 4232 clr_optimization_v2.0.50727_32 - ok
15:54:38.0007 4232 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:54:38.0022 4232 clr_optimization_v4.0.30319_32 - ok
15:54:38.0085 4232 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
15:54:38.0085 4232 CmBatt - ok
15:54:38.0100 4232 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
15:54:38.0100 4232 cmdide - ok
15:54:38.0132 4232 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
15:54:38.0132 4232 Compbatt - ok
15:54:38.0132 4232 COMSysApp - ok
15:54:38.0147 4232 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
15:54:38.0147 4232 crcdisk - ok
15:54:38.0147 4232 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
15:54:38.0163 4232 Crusoe - ok
15:54:38.0241 4232 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:54:38.0241 4232 CryptSvc - ok
15:54:38.0334 4232 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
15:54:38.0350 4232 DcomLaunch - ok
15:54:38.0412 4232 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
15:54:38.0412 4232 DfsC - ok
15:54:38.0662 4232 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
15:54:38.0834 4232 DFSR - ok
15:54:38.0927 4232 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
15:54:38.0943 4232 Dhcp - ok
15:54:38.0974 4232 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
15:54:38.0974 4232 disk - ok
15:54:39.0052 4232 [ F206E28ED74C491FD5D7C0A1119CE37F ] DMICall C:\Windows\system32\DRIVERS\DMICall.sys
15:54:39.0052 4232 DMICall - ok
15:54:39.0114 4232 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:54:39.0114 4232 Dnscache - ok
15:54:39.0192 4232 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
15:54:39.0192 4232 dot3svc - ok
15:54:39.0255 4232 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
15:54:39.0255 4232 DPS - ok
15:54:39.0333 4232 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
15:54:39.0333 4232 drmkaud - ok
15:54:39.0426 4232 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:54:39.0442 4232 DXGKrnl - ok
15:54:39.0473 4232 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
15:54:39.0473 4232 E1G60 - ok
15:54:39.0536 4232 [ E31464CE787E3A0FFEA55BAA591897F0 ] eamon C:\Windows\system32\DRIVERS\eamon.sys
15:54:39.0536 4232 eamon - ok
15:54:39.0598 4232 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
15:54:39.0598 4232 EapHost - ok
15:54:39.0676 4232 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
15:54:39.0676 4232 Ecache - ok
15:54:39.0738 4232 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
15:54:39.0738 4232 ehRecvr - ok
15:54:39.0754 4232 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
15:54:39.0754 4232 ehSched - ok
15:54:39.0770 4232 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
15:54:39.0770 4232 ehstart - ok
15:54:39.0848 4232 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
15:54:39.0863 4232 elxstor - ok
15:54:39.0926 4232 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
15:54:39.0926 4232 EMDMgmt - ok
15:54:39.0957 4232 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
15:54:39.0957 4232 ErrDev - ok
15:54:40.0050 4232 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
15:54:40.0050 4232 EventSystem - ok
15:54:40.0097 4232 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
15:54:40.0113 4232 exfat - ok
15:54:40.0144 4232 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:54:40.0144 4232 fastfat - ok
15:54:40.0175 4232 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
15:54:40.0175 4232 fdc - ok
15:54:40.0206 4232 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
15:54:40.0206 4232 fdPHost - ok
15:54:40.0222 4232 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
15:54:40.0222 4232 FDResPub - ok
15:54:40.0269 4232 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:54:40.0269 4232 FileInfo - ok
15:54:40.0316 4232 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:54:40.0316 4232 Filetrace - ok
15:54:40.0316 4232 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
15:54:40.0316 4232 flpydisk - ok
15:54:40.0378 4232 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:54:40.0378 4232 FltMgr - ok
15:54:40.0550 4232 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
15:54:40.0565 4232 FontCache - ok
15:54:40.0643 4232 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
15:54:40.0643 4232 FontCache3.0.0.0 - ok
15:54:40.0674 4232 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:54:40.0690 4232 Fs_Rec - ok
15:54:40.0721 4232 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
15:54:40.0721 4232 gagp30kx - ok
15:54:40.0830 4232 [ 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F ] GoogleDesktopManager-051210-111108 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
15:54:40.0830 4232 GoogleDesktopManager-051210-111108 - ok
15:54:40.0877 4232 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
15:54:40.0893 4232 gpsvc - ok
15:54:40.0971 4232 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
15:54:40.0971 4232 gupdate - ok
15:54:41.0049 4232 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
15:54:41.0049 4232 gupdatem - ok
15:54:41.0205 4232 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
15:54:41.0220 4232 gusvc - ok
15:54:41.0330 4232 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:54:41.0330 4232 HdAudAddService - ok
15:54:41.0392 4232 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
15:54:41.0392 4232 HDAudBus - ok
15:54:41.0408 4232 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
15:54:41.0408 4232 HidBth - ok
15:54:41.0408 4232 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
15:54:41.0423 4232 HidIr - ok
15:54:41.0454 4232 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
15:54:41.0454 4232 hidserv - ok
15:54:41.0470 4232 [ 3C64042B95E583B366BA4E5D2450235E ] HidUsb C:\Windows\system32\drivers\hidusb.sys
15:54:41.0470 4232 HidUsb - ok
15:54:41.0501 4232 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
15:54:41.0501 4232 hkmsvc - ok
15:54:41.0532 4232 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
15:54:41.0532 4232 HpCISSs - ok
15:54:41.0610 4232 [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
15:54:41.0610 4232 HSFHWAZL - ok
15:54:41.0704 4232 [ 7BC42C65B5C6281777C1A7605B253BA8 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
15:54:41.0735 4232 HSF_DPV - ok
15:54:41.0798 4232 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
15:54:41.0798 4232 HSXHWAZL - ok
15:54:41.0844 4232 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:54:41.0860 4232 HTTP - ok
15:54:41.0907 4232 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
15:54:41.0907 4232 i2omp - ok
15:54:42.0047 4232 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
15:54:42.0047 4232 i8042prt - ok
15:54:42.0219 4232 [ DB0CC620B27A928D968C1A1E9CD9CB87 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
15:54:42.0234 4232 iaStor - ok
15:54:42.0266 4232 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
15:54:42.0266 4232 iaStorV - ok
15:54:42.0422 4232 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:54:42.0453 4232 idsvc - ok
15:54:42.0843 4232 [ CE5FF5D5E3F4CA974E36DC24C15474D0 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
15:54:42.0905 4232 igfx - ok
15:54:42.0936 4232 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
15:54:42.0936 4232 iirsp - ok
15:54:42.0968 4232 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
15:54:42.0983 4232 IKEEXT - ok
15:54:43.0108 4232 [ 4A0F260DF9A5333C07F4AB40CA9D4F4B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
15:54:43.0124 4232 IntcAzAudAddService - ok
15:54:43.0155 4232 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
15:54:43.0155 4232 intelide - ok
15:54:43.0217 4232 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
15:54:43.0217 4232 intelppm - ok
15:54:43.0326 4232 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
15:54:43.0342 4232 IPBusEnum - ok
15:54:43.0389 4232 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:54:43.0389 4232 IpFilterDriver - ok
15:54:43.0451 4232 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:54:43.0451 4232 iphlpsvc - ok
15:54:43.0467 4232 IpInIp - ok
15:54:43.0514 4232 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
15:54:43.0560 4232 IPMIDRV - ok
15:54:43.0592 4232 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
15:54:43.0592 4232 IPNAT - ok
15:54:43.0623 4232 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:54:43.0623 4232 IRENUM - ok
15:54:43.0670 4232 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
15:54:43.0670 4232 isapnp - ok
15:54:43.0732 4232 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
15:54:43.0732 4232 iScsiPrt - ok
15:54:43.0748 4232 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
15:54:43.0748 4232 iteatapi - ok
15:54:43.0794 4232 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
15:54:43.0794 4232 iteraid - ok
15:54:43.0857 4232 [ 213822072085B5BBAD9AF30AB577D817 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
15:54:43.0857 4232 IviRegMgr - ok
15:54:43.0888 4232 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
15:54:43.0888 4232 kbdclass - ok
15:54:43.0919 4232 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
15:54:43.0919 4232 kbdhid - ok
15:54:43.0950 4232 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
15:54:43.0950 4232 KeyIso - ok
15:54:43.0997 4232 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:54:43.0997 4232 KSecDD - ok
15:54:44.0122 4232 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
15:54:44.0138 4232 KtmRm - ok
15:54:44.0247 4232 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
15:54:44.0262 4232 LanmanServer - ok
15:54:44.0387 4232 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:54:44.0403 4232 LanmanWorkstation - ok
15:54:44.0450 4232 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
15:54:44.0450 4232 lltdio - ok
15:54:44.0512 4232 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:54:44.0528 4232 lltdsvc - ok
15:54:44.0543 4232 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
15:54:44.0543 4232 lmhosts - ok
15:54:44.0590 4232 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
15:54:44.0590 4232 LSI_FC - ok
15:54:44.0606 4232 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
15:54:44.0606 4232 LSI_SAS - ok
15:54:44.0621 4232 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
15:54:44.0621 4232 LSI_SCSI - ok
15:54:44.0668 4232 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
15:54:44.0668 4232 luafv - ok
15:54:44.0730 4232 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
15:54:44.0730 4232 MBAMProtector - ok
15:54:44.0808 4232 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
15:54:44.0808 4232 MBAMScheduler - ok
15:54:44.0886 4232 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
15:54:44.0902 4232 MBAMService - ok
15:54:45.0011 4232 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
15:54:45.0011 4232 McComponentHostService - ok
15:54:45.0042 4232 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
15:54:45.0058 4232 Mcx2Svc - ok
15:54:45.0089 4232 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
15:54:45.0089 4232 mdmxsdk - ok
15:54:45.0136 4232 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
15:54:45.0136 4232 megasas - ok
15:54:45.0198 4232 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
15:54:45.0198 4232 MegaSR - ok
15:54:45.0308 4232 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
15:54:45.0308 4232 Microsoft Office Groove Audit Service - ok
15:54:45.0354 4232 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
15:54:45.0354 4232 MMCSS - ok
15:54:45.0370 4232 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
15:54:45.0370 4232 Modem - ok
15:54:45.0448 4232 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
15:54:45.0448 4232 monitor - ok
15:54:45.0495 4232 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
15:54:45.0495 4232 mouclass - ok
15:54:45.0526 4232 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\drivers\mouhid.sys
15:54:45.0526 4232 mouhid - ok
15:54:45.0573 4232 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
15:54:45.0573 4232 MountMgr - ok
15:54:45.0620 4232 [ 51A84B690DF519DCF656F780243D953E ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
15:54:45.0620 4232 MozillaMaintenance - ok
15:54:45.0635 4232 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
15:54:45.0651 4232 mpio - ok
15:54:45.0682 4232 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
15:54:45.0682 4232 mpsdrv - ok
15:54:45.0713 4232 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
15:54:45.0729 4232 MpsSvc - ok
15:54:45.0744 4232 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
15:54:45.0760 4232 Mraid35x - ok
15:54:45.0776 4232 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
15:54:45.0791 4232 MRxDAV - ok
15:54:45.0822 4232 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
15:54:45.0822 4232 mrxsmb - ok
15:54:45.0854 4232 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:54:45.0854 4232 mrxsmb10 - ok
15:54:45.0854 4232 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:54:45.0869 4232 mrxsmb20 - ok
15:54:45.0885 4232 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
15:54:45.0885 4232 msahci - ok
15:54:45.0963 4232 [ A99D2C7E30AD63EF920A894131CAF5F7 ] MSCSPTISRV C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
15:54:45.0963 4232 MSCSPTISRV - ok
15:54:45.0994 4232 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
15:54:45.0994 4232 msdsm - ok
15:54:46.0025 4232 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
15:54:46.0025 4232 MSDTC - ok
15:54:46.0072 4232 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
15:54:46.0072 4232 Msfs - ok
15:54:46.0088 4232 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
15:54:46.0088 4232 msisadrv - ok
15:54:46.0134 4232 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
15:54:46.0150 4232 MSiSCSI - ok
15:54:46.0150 4232 msiserver - ok
15:54:46.0197 4232 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
15:54:46.0197 4232 MSKSSRV - ok
15:54:46.0197 4232 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
15:54:46.0212 4232 MSPCLOCK - ok
15:54:46.0212 4232 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
15:54:46.0212 4232 MSPQM - ok
15:54:46.0259 4232 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
15:54:46.0259 4232 MsRPC - ok
15:54:46.0275 4232 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
15:54:46.0275 4232 mssmbios - ok
15:54:46.0431 4232 MSSQL$MSSMLBIZ - ok
15:54:46.0446 4232 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
15:54:46.0446 4232 MSSQLServerADHelper - ok
15:54:46.0478 4232 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
15:54:46.0478 4232 MSTEE - ok
15:54:46.0524 4232 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
15:54:46.0524 4232 Mup - ok
15:54:46.0556 4232 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
15:54:46.0556 4232 napagent - ok
15:54:46.0602 4232 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
15:54:46.0602 4232 NativeWifiP - ok
15:54:46.0712 4232 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
15:54:46.0727 4232 NDIS - ok
15:54:46.0758 4232 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:54:46.0758 4232 NdisTapi - ok
15:54:46.0790 4232 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
15:54:46.0790 4232 Ndisuio - ok
15:54:46.0821 4232 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
15:54:46.0836 4232 NdisWan - ok
15:54:46.0852 4232 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
15:54:46.0852 4232 NDProxy - ok
15:54:46.0961 4232 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
15:54:46.0977 4232 Nero BackItUp Scheduler 4.0 - ok
15:54:47.0008 4232 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
15:54:47.0008 4232 NetBIOS - ok
15:54:47.0070 4232 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
15:54:47.0070 4232 netbt - ok
15:54:47.0086 4232 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
15:54:47.0086 4232 Netlogon - ok
15:54:47.0148 4232 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
15:54:47.0148 4232 Netman - ok
15:54:47.0180 4232 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
15:54:47.0195 4232 netprofm - ok
15:54:47.0258 4232 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:54:47.0258 4232 NetTcpPortSharing - ok
15:54:47.0304 4232 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
15:54:47.0304 4232 nfrd960 - ok
15:54:47.0351 4232 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
15:54:47.0351 4232 NlaSvc - ok
15:54:47.0476 4232 [ 9A908A9BB857C2CCEB2907EB9DCAEB8B ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
15:54:47.0476 4232 nmwcd - ok
15:54:47.0492 4232 [ 68EC3EE2348E475EA62C66E6AAFCFC9B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
15:54:47.0492 4232 nmwcdc - ok
15:54:47.0538 4232 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
15:54:47.0538 4232 Npfs - ok
15:54:47.0585 4232 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
15:54:47.0601 4232 nsi - ok
15:54:47.0632 4232 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
15:54:47.0632 4232 nsiproxy - ok
15:54:47.0710 4232 [ FD141D19F1392920A6A517316910D770 ] NSUService C:\Program Files\Sony\Network Utility\NSUService.exe
15:54:47.0710 4232 NSUService - ok
15:54:47.0772 4232 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
15:54:47.0788 4232 Ntfs - ok
15:54:47.0819 4232 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
15:54:47.0819 4232 ntrigdigi - ok
15:54:47.0850 4232 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
15:54:47.0850 4232 Null - ok
15:54:47.0866 4232 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
15:54:47.0866 4232 nvraid - ok
15:54:47.0866 4232 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
15:54:47.0882 4232 nvstor - ok
15:54:47.0897 4232 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
15:54:47.0897 4232 nv_agp - ok
15:54:47.0913 4232 NwlnkFlt - ok
15:54:47.0913 4232 NwlnkFwd - ok
15:54:48.0006 4232 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:54:48.0006 4232 odserv - ok
15:54:48.0100 4232 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
15:54:48.0100 4232 ohci1394 - ok
15:54:48.0240 4232 [ D3530461AF3737392E5693D9E2CEA4A2 ] OODefragAgent C:\Program Files\OO Software\Defrag\oodag.exe
15:54:48.0272 4232 OODefragAgent - ok
15:54:48.0303 4232 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:54:48.0303 4232 ose - ok
15:54:48.0381 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
15:54:48.0396 4232 p2pimsvc - ok
15:54:48.0412 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
15:54:48.0428 4232 p2psvc - ok
15:54:48.0459 4232 [ 41C33FB4FD929FED732A00D2DAEF5BE0 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
15:54:48.0459 4232 PACSPTISVR - ok
15:54:48.0506 4232 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
15:54:48.0506 4232 Parport - ok
15:54:48.0552 4232 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
15:54:48.0552 4232 partmgr - ok
15:54:48.0599 4232 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
15:54:48.0599 4232 Parvdm - ok
15:54:48.0630 4232 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
15:54:48.0630 4232 PcaSvc - ok
15:54:48.0708 4232 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
15:54:48.0708 4232 pccsmcfd - ok
15:54:48.0740 4232 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
15:54:48.0755 4232 pci - ok
15:54:48.0786 4232 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
15:54:48.0786 4232 pciide - ok
15:54:48.0802 4232 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
15:54:48.0802 4232 pcmcia - ok
15:54:48.0849 4232 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
15:54:48.0864 4232 PEAUTH - ok
15:54:48.0958 4232 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
15:54:48.0989 4232 pla - ok
15:54:49.0005 4232 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
15:54:49.0020 4232 PlugPlay - ok
15:54:49.0083 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
15:54:49.0083 4232 PNRPAutoReg - ok
15:54:49.0098 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
15:54:49.0114 4232 PNRPsvc - ok
15:54:49.0161 4232 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
15:54:49.0161 4232 PolicyAgent - ok
15:54:49.0208 4232 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
15:54:49.0208 4232 PptpMiniport - ok
15:54:49.0239 4232 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
15:54:49.0239 4232 Processor - ok
15:54:49.0286 4232 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
15:54:49.0286 4232 ProfSvc - ok
15:54:49.0301 4232 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
15:54:49.0317 4232 ProtectedStorage - ok
15:54:49.0348 4232 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
15:54:49.0348 4232 PSched - ok
15:54:49.0395 4232 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
15:54:49.0410 4232 PxHelp20 - ok
15:54:49.0598 4232 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
15:54:49.0613 4232 ql2300 - ok
15:54:49.0629 4232 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
15:54:49.0629 4232 ql40xx - ok
15:54:49.0691 4232 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
15:54:49.0707 4232 QWAVE - ok
15:54:49.0722 4232 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
15:54:49.0722 4232 QWAVEdrv - ok
15:54:49.0738 4232 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
15:54:49.0738 4232 RasAcd - ok
15:54:49.0754 4232 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
15:54:49.0754 4232 RasAuto - ok
15:54:49.0800 4232 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
15:54:49.0816 4232 Rasl2tp - ok
15:54:49.0847 4232 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
15:54:49.0847 4232 RasMan - ok
15:54:49.0894 4232 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
15:54:49.0894 4232 RasPppoe - ok
15:54:49.0910 4232 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
15:54:49.0910 4232 RasSstp - ok
15:54:50.0003 4232 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
15:54:50.0003 4232 rdbss - ok
15:54:50.0034 4232 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
15:54:50.0034 4232 RDPCDD - ok
15:54:50.0081 4232 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
15:54:50.0081 4232 rdpdr - ok
15:54:50.0097 4232 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
15:54:50.0097 4232 RDPENCDD - ok
15:54:50.0175 4232 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
15:54:50.0175 4232 RDPWD - ok
15:54:50.0222 4232 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\Windows\system32\drivers\regi.sys
15:54:50.0222 4232 regi - ok
15:54:50.0284 4232 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
15:54:50.0284 4232 RemoteAccess - ok
15:54:50.0315 4232 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
15:54:50.0315 4232 RemoteRegistry - ok
15:54:50.0393 4232 [ D0C2A0CE1091E08EFB7CCBA6CEA4C3F9 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
15:54:50.0393 4232 rimsptsk - ok
15:54:50.0440 4232 [ C22E4E27CCDF9AA5FE8143104F28CDE3 ] risdptsk C:\Windows\system32\DRIVERS\risdptsk.sys
15:54:50.0440 4232 risdptsk - ok
15:54:50.0471 4232 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
15:54:50.0471 4232 RpcLocator - ok
15:54:50.0534 4232 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
15:54:50.0534 4232 RpcSs - ok
15:54:50.0580 4232 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
15:54:50.0580 4232 rspndr - ok
15:54:50.0643 4232 [ 65330E78C17DB8A99A7FF1BA3C8824B6 ] RtkAudioService C:\Windows\RtkAudioService.exe
15:54:50.0643 4232 RtkAudioService - ok
15:54:50.0658 4232 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
15:54:50.0674 4232 SamSs - ok
15:54:50.0705 4232 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
15:54:50.0705 4232 sbp2port - ok
15:54:50.0768 4232 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
15:54:50.0768 4232 SCardSvr - ok
15:54:50.0814 4232 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
15:54:50.0830 4232 Schedule - ok
15:54:50.0861 4232 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
15:54:50.0861 4232 SCPolicySvc - ok
15:54:50.0908 4232 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
15:54:50.0908 4232 sdbus - ok
15:54:50.0939 4232 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
15:54:50.0939 4232 SDRSVC - ok
15:54:50.0955 4232 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
15:54:50.0955 4232 secdrv - ok
15:54:50.0970 4232 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
15:54:50.0970 4232 seclogon - ok
15:54:50.0986 4232 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
15:54:50.0986 4232 SENS - ok
15:54:51.0002 4232 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
15:54:51.0002 4232 Serenum - ok
15:54:51.0017 4232 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
15:54:51.0017 4232 Serial - ok
15:54:51.0033 4232 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
15:54:51.0033 4232 sermouse - ok
15:54:51.0095 4232 [ 3EC8DE67B1C78C31E54C0F030E6BD7D5 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
15:54:51.0095 4232 ServiceLayer - ok
15:54:51.0126 4232 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
15:54:51.0126 4232 SessionEnv - ok
15:54:51.0189 4232 [ 8B7C1768D2CDE2E02E09A66563DDFD16 ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys
15:54:51.0189 4232 SFEP - ok
15:54:51.0204 4232 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
15:54:51.0204 4232 sffdisk - ok
15:54:51.0236 4232 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
15:54:51.0236 4232 sffp_mmc - ok
15:54:51.0236 4232 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
15:54:51.0236 4232 sffp_sd - ok
15:54:51.0251 4232 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
15:54:51.0251 4232 sfloppy - ok
15:54:51.0282 4232 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
15:54:51.0298 4232 SharedAccess - ok
15:54:51.0314 4232 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:54:51.0314 4232 ShellHWDetection - ok
15:54:51.0329 4232 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
15:54:51.0329 4232 sisagp - ok
15:54:51.0345 4232 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
15:54:51.0345 4232 SiSRaid2 - ok
15:54:51.0345 4232 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
15:54:51.0360 4232 SiSRaid4 - ok
15:54:51.0657 4232 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
15:54:51.0782 4232 Skype C2C Service - ok
15:54:51.0860 4232 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
15:54:51.0860 4232 SkypeUpdate - ok
15:54:52.0125 4232 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
15:54:53.0248 4232 slsvc - ok
15:54:53.0295 4232 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
15:54:53.0310 4232 SLUINotify - ok
15:54:53.0342 4232 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
15:54:53.0342 4232 Smb - ok
15:54:53.0466 4232 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
15:54:53.0466 4232 SNMPTRAP - ok
15:54:53.0638 4232 [ DC826AFFA608F50C385BCA4C71EF1BDD ] SOHCImp C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe
15:54:53.0638 4232 SOHCImp - ok
15:54:53.0685 4232 [ 1EC739F65C51FA1C7AC4502464A3C3A8 ] SOHDms C:\Program Files\Sony\VAIO Media plus\SOHDms.exe
15:54:53.0700 4232 SOHDms - ok
15:54:53.0700 4232 [ EC8FAB4AC684445D6032AA5C6E77CA2E ] SOHDs C:\Program Files\Sony\VAIO Media plus\SOHDs.exe
15:54:53.0700 4232 SOHDs - ok
15:54:53.0794 4232 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
15:54:53.0794 4232 spldr - ok
15:54:53.0903 4232 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
15:54:53.0903 4232 Spooler - ok
15:54:54.0044 4232 [ F63102F289AE2039940B22E9B2A8E0BD ] SPTISRV C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
15:54:54.0044 4232 SPTISRV - ok
15:54:54.0075 4232 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
15:54:54.0090 4232 SQLBrowser - ok
15:54:54.0122 4232 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
15:54:28.0304 4432 ============================================================
15:54:28.0304 4432 Current date / time: 2013/02/24 15:54:28.0304
15:54:28.0304 4432 SystemInfo:
15:54:28.0304 4432
15:54:28.0304 4432 OS Version: 6.0.6002 ServicePack: 2.0
15:54:28.0304 4432 Product type: Workstation
15:54:28.0304 4432 ComputerName: MAREK-PC
15:54:28.0304 4432 UserName: marek
15:54:28.0304 4432 Windows directory: C:\Windows
15:54:28.0304 4432 System windows directory: C:\Windows
15:54:28.0304 4432 Processor architecture: Intel x86
15:54:28.0304 4432 Number of processors: 2
15:54:28.0304 4432 Page size: 0x1000
15:54:28.0304 4432 Boot type: Normal boot
15:54:28.0304 4432 ============================================================
15:54:29.0427 4432 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
15:54:29.0427 4432 ============================================================
15:54:29.0427 4432 \Device\Harddisk0\DR0:
15:54:29.0427 4432 MBR partitions:
15:54:29.0427 4432 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xFEC800, BlocksNum 0x1C1D8970
15:54:29.0427 4432 ============================================================
15:54:29.0614 4432 C: <-> \Device\Harddisk0\DR0\Partition1
15:54:29.0614 4432 ============================================================
15:54:29.0614 4432 Initialize success
15:54:29.0614 4432 ============================================================
15:54:32.0204 4232 ============================================================
15:54:32.0204 4232 Scan started
15:54:32.0204 4232 Mode: Manual;
15:54:32.0204 4232 ============================================================
15:54:34.0434 4232 ================ Scan system memory ========================
15:54:34.0434 4232 System memory - ok
15:54:34.0434 4232 ================ Scan services =============================
15:54:34.0824 4232 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
15:54:34.0824 4232 ACPI - ok
15:54:34.0949 4232 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:54:34.0949 4232 AdobeFlashPlayerUpdateSvc - ok
15:54:35.0043 4232 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
15:54:35.0058 4232 adp94xx - ok
15:54:35.0090 4232 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
15:54:35.0105 4232 adpahci - ok
15:54:35.0105 4232 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
15:54:35.0121 4232 adpu160m - ok
15:54:35.0136 4232 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
15:54:35.0136 4232 adpu320 - ok
15:54:35.0292 4232 [ B11C71B29FA69E4586F9B65560E6604D ] AdvancedSystemCareService5 C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
15:54:35.0308 4232 AdvancedSystemCareService5 - ok
15:54:35.0324 4232 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
15:54:35.0324 4232 AeLookupSvc - ok
15:54:35.0433 4232 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
15:54:35.0433 4232 AFD - ok
15:54:35.0495 4232 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
15:54:35.0495 4232 agp440 - ok
15:54:35.0558 4232 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
15:54:35.0573 4232 aic78xx - ok
15:54:35.0589 4232 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
15:54:35.0589 4232 ALG - ok
15:54:35.0604 4232 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
15:54:35.0604 4232 aliide - ok
15:54:35.0604 4232 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
15:54:35.0620 4232 amdagp - ok
15:54:35.0620 4232 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
15:54:35.0636 4232 amdide - ok
15:54:35.0636 4232 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
15:54:35.0636 4232 AmdK7 - ok
15:54:35.0651 4232 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
15:54:35.0651 4232 AmdK8 - ok
15:54:35.0776 4232 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
15:54:35.0776 4232 Appinfo - ok
15:54:36.0010 4232 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
15:54:36.0026 4232 arc - ok
15:54:36.0072 4232 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
15:54:36.0088 4232 arcsas - ok
15:54:36.0135 4232 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
15:54:36.0135 4232 AsyncMac - ok
15:54:36.0166 4232 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
15:54:36.0182 4232 atapi - ok
15:54:36.0322 4232 [ 600EFE56F37ADBD65A0FB076B50D1B8D ] athr C:\Windows\system32\DRIVERS\athr.sys
15:54:36.0338 4232 athr - ok
15:54:36.0696 4232 [ A4E212F45B2457B39D59D4972A67AF47 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
15:54:36.0806 4232 atikmdag - ok
15:54:36.0915 4232 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:54:36.0915 4232 AudioEndpointBuilder - ok
15:54:36.0930 4232 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
15:54:36.0930 4232 Audiosrv - ok
15:54:37.0102 4232 [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
15:54:37.0102 4232 BcmSqlStartupSvc - ok
15:54:37.0180 4232 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
15:54:37.0180 4232 Beep - ok
15:54:37.0258 4232 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
15:54:37.0274 4232 BFE - ok
15:54:37.0367 4232 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
15:54:37.0383 4232 BITS - ok
15:54:37.0430 4232 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
15:54:37.0430 4232 blbdrive - ok
15:54:37.0461 4232 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:54:37.0461 4232 bowser - ok
15:54:37.0492 4232 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
15:54:37.0492 4232 BrFiltLo - ok
15:54:37.0508 4232 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
15:54:37.0508 4232 BrFiltUp - ok
15:54:37.0554 4232 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
15:54:37.0554 4232 Browser - ok
15:54:37.0570 4232 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
15:54:37.0570 4232 Brserid - ok
15:54:37.0586 4232 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
15:54:37.0586 4232 BrSerWdm - ok
15:54:37.0601 4232 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
15:54:37.0601 4232 BrUsbMdm - ok
15:54:37.0617 4232 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
15:54:37.0617 4232 BrUsbSer - ok
15:54:37.0632 4232 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
15:54:37.0632 4232 BTHMODEM - ok
15:54:37.0679 4232 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:54:37.0679 4232 cdfs - ok
15:54:37.0710 4232 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
15:54:37.0710 4232 cdrom - ok
15:54:37.0788 4232 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
15:54:37.0788 4232 CertPropSvc - ok
15:54:37.0820 4232 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
15:54:37.0835 4232 circlass - ok
15:54:37.0866 4232 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
15:54:37.0882 4232 CLFS - ok
15:54:37.0929 4232 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:54:37.0929 4232 clr_optimization_v2.0.50727_32 - ok
15:54:38.0007 4232 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:54:38.0022 4232 clr_optimization_v4.0.30319_32 - ok
15:54:38.0085 4232 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
15:54:38.0085 4232 CmBatt - ok
15:54:38.0100 4232 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
15:54:38.0100 4232 cmdide - ok
15:54:38.0132 4232 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
15:54:38.0132 4232 Compbatt - ok
15:54:38.0132 4232 COMSysApp - ok
15:54:38.0147 4232 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
15:54:38.0147 4232 crcdisk - ok
15:54:38.0147 4232 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
15:54:38.0163 4232 Crusoe - ok
15:54:38.0241 4232 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:54:38.0241 4232 CryptSvc - ok
15:54:38.0334 4232 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
15:54:38.0350 4232 DcomLaunch - ok
15:54:38.0412 4232 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
15:54:38.0412 4232 DfsC - ok
15:54:38.0662 4232 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
15:54:38.0834 4232 DFSR - ok
15:54:38.0927 4232 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
15:54:38.0943 4232 Dhcp - ok
15:54:38.0974 4232 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
15:54:38.0974 4232 disk - ok
15:54:39.0052 4232 [ F206E28ED74C491FD5D7C0A1119CE37F ] DMICall C:\Windows\system32\DRIVERS\DMICall.sys
15:54:39.0052 4232 DMICall - ok
15:54:39.0114 4232 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:54:39.0114 4232 Dnscache - ok
15:54:39.0192 4232 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
15:54:39.0192 4232 dot3svc - ok
15:54:39.0255 4232 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
15:54:39.0255 4232 DPS - ok
15:54:39.0333 4232 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
15:54:39.0333 4232 drmkaud - ok
15:54:39.0426 4232 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:54:39.0442 4232 DXGKrnl - ok
15:54:39.0473 4232 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
15:54:39.0473 4232 E1G60 - ok
15:54:39.0536 4232 [ E31464CE787E3A0FFEA55BAA591897F0 ] eamon C:\Windows\system32\DRIVERS\eamon.sys
15:54:39.0536 4232 eamon - ok
15:54:39.0598 4232 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
15:54:39.0598 4232 EapHost - ok
15:54:39.0676 4232 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
15:54:39.0676 4232 Ecache - ok
15:54:39.0738 4232 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
15:54:39.0738 4232 ehRecvr - ok
15:54:39.0754 4232 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
15:54:39.0754 4232 ehSched - ok
15:54:39.0770 4232 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
15:54:39.0770 4232 ehstart - ok
15:54:39.0848 4232 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
15:54:39.0863 4232 elxstor - ok
15:54:39.0926 4232 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
15:54:39.0926 4232 EMDMgmt - ok
15:54:39.0957 4232 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
15:54:39.0957 4232 ErrDev - ok
15:54:40.0050 4232 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
15:54:40.0050 4232 EventSystem - ok
15:54:40.0097 4232 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
15:54:40.0113 4232 exfat - ok
15:54:40.0144 4232 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:54:40.0144 4232 fastfat - ok
15:54:40.0175 4232 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
15:54:40.0175 4232 fdc - ok
15:54:40.0206 4232 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
15:54:40.0206 4232 fdPHost - ok
15:54:40.0222 4232 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
15:54:40.0222 4232 FDResPub - ok
15:54:40.0269 4232 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:54:40.0269 4232 FileInfo - ok
15:54:40.0316 4232 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:54:40.0316 4232 Filetrace - ok
15:54:40.0316 4232 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
15:54:40.0316 4232 flpydisk - ok
15:54:40.0378 4232 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:54:40.0378 4232 FltMgr - ok
15:54:40.0550 4232 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
15:54:40.0565 4232 FontCache - ok
15:54:40.0643 4232 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
15:54:40.0643 4232 FontCache3.0.0.0 - ok
15:54:40.0674 4232 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:54:40.0690 4232 Fs_Rec - ok
15:54:40.0721 4232 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
15:54:40.0721 4232 gagp30kx - ok
15:54:40.0830 4232 [ 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F ] GoogleDesktopManager-051210-111108 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
15:54:40.0830 4232 GoogleDesktopManager-051210-111108 - ok
15:54:40.0877 4232 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
15:54:40.0893 4232 gpsvc - ok
15:54:40.0971 4232 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
15:54:40.0971 4232 gupdate - ok
15:54:41.0049 4232 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
15:54:41.0049 4232 gupdatem - ok
15:54:41.0205 4232 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
15:54:41.0220 4232 gusvc - ok
15:54:41.0330 4232 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:54:41.0330 4232 HdAudAddService - ok
15:54:41.0392 4232 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
15:54:41.0392 4232 HDAudBus - ok
15:54:41.0408 4232 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
15:54:41.0408 4232 HidBth - ok
15:54:41.0408 4232 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
15:54:41.0423 4232 HidIr - ok
15:54:41.0454 4232 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
15:54:41.0454 4232 hidserv - ok
15:54:41.0470 4232 [ 3C64042B95E583B366BA4E5D2450235E ] HidUsb C:\Windows\system32\drivers\hidusb.sys
15:54:41.0470 4232 HidUsb - ok
15:54:41.0501 4232 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
15:54:41.0501 4232 hkmsvc - ok
15:54:41.0532 4232 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
15:54:41.0532 4232 HpCISSs - ok
15:54:41.0610 4232 [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
15:54:41.0610 4232 HSFHWAZL - ok
15:54:41.0704 4232 [ 7BC42C65B5C6281777C1A7605B253BA8 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
15:54:41.0735 4232 HSF_DPV - ok
15:54:41.0798 4232 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
15:54:41.0798 4232 HSXHWAZL - ok
15:54:41.0844 4232 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:54:41.0860 4232 HTTP - ok
15:54:41.0907 4232 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
15:54:41.0907 4232 i2omp - ok
15:54:42.0047 4232 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
15:54:42.0047 4232 i8042prt - ok
15:54:42.0219 4232 [ DB0CC620B27A928D968C1A1E9CD9CB87 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
15:54:42.0234 4232 iaStor - ok
15:54:42.0266 4232 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
15:54:42.0266 4232 iaStorV - ok
15:54:42.0422 4232 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:54:42.0453 4232 idsvc - ok
15:54:42.0843 4232 [ CE5FF5D5E3F4CA974E36DC24C15474D0 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
15:54:42.0905 4232 igfx - ok
15:54:42.0936 4232 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
15:54:42.0936 4232 iirsp - ok
15:54:42.0968 4232 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
15:54:42.0983 4232 IKEEXT - ok
15:54:43.0108 4232 [ 4A0F260DF9A5333C07F4AB40CA9D4F4B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
15:54:43.0124 4232 IntcAzAudAddService - ok
15:54:43.0155 4232 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
15:54:43.0155 4232 intelide - ok
15:54:43.0217 4232 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
15:54:43.0217 4232 intelppm - ok
15:54:43.0326 4232 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
15:54:43.0342 4232 IPBusEnum - ok
15:54:43.0389 4232 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:54:43.0389 4232 IpFilterDriver - ok
15:54:43.0451 4232 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:54:43.0451 4232 iphlpsvc - ok
15:54:43.0467 4232 IpInIp - ok
15:54:43.0514 4232 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
15:54:43.0560 4232 IPMIDRV - ok
15:54:43.0592 4232 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
15:54:43.0592 4232 IPNAT - ok
15:54:43.0623 4232 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:54:43.0623 4232 IRENUM - ok
15:54:43.0670 4232 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
15:54:43.0670 4232 isapnp - ok
15:54:43.0732 4232 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
15:54:43.0732 4232 iScsiPrt - ok
15:54:43.0748 4232 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
15:54:43.0748 4232 iteatapi - ok
15:54:43.0794 4232 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
15:54:43.0794 4232 iteraid - ok
15:54:43.0857 4232 [ 213822072085B5BBAD9AF30AB577D817 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
15:54:43.0857 4232 IviRegMgr - ok
15:54:43.0888 4232 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
15:54:43.0888 4232 kbdclass - ok
15:54:43.0919 4232 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
15:54:43.0919 4232 kbdhid - ok
15:54:43.0950 4232 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
15:54:43.0950 4232 KeyIso - ok
15:54:43.0997 4232 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:54:43.0997 4232 KSecDD - ok
15:54:44.0122 4232 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
15:54:44.0138 4232 KtmRm - ok
15:54:44.0247 4232 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
15:54:44.0262 4232 LanmanServer - ok
15:54:44.0387 4232 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:54:44.0403 4232 LanmanWorkstation - ok
15:54:44.0450 4232 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
15:54:44.0450 4232 lltdio - ok
15:54:44.0512 4232 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:54:44.0528 4232 lltdsvc - ok
15:54:44.0543 4232 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
15:54:44.0543 4232 lmhosts - ok
15:54:44.0590 4232 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
15:54:44.0590 4232 LSI_FC - ok
15:54:44.0606 4232 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
15:54:44.0606 4232 LSI_SAS - ok
15:54:44.0621 4232 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
15:54:44.0621 4232 LSI_SCSI - ok
15:54:44.0668 4232 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
15:54:44.0668 4232 luafv - ok
15:54:44.0730 4232 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
15:54:44.0730 4232 MBAMProtector - ok
15:54:44.0808 4232 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
15:54:44.0808 4232 MBAMScheduler - ok
15:54:44.0886 4232 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
15:54:44.0902 4232 MBAMService - ok
15:54:45.0011 4232 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
15:54:45.0011 4232 McComponentHostService - ok
15:54:45.0042 4232 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
15:54:45.0058 4232 Mcx2Svc - ok
15:54:45.0089 4232 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
15:54:45.0089 4232 mdmxsdk - ok
15:54:45.0136 4232 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
15:54:45.0136 4232 megasas - ok
15:54:45.0198 4232 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
15:54:45.0198 4232 MegaSR - ok
15:54:45.0308 4232 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
15:54:45.0308 4232 Microsoft Office Groove Audit Service - ok
15:54:45.0354 4232 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
15:54:45.0354 4232 MMCSS - ok
15:54:45.0370 4232 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
15:54:45.0370 4232 Modem - ok
15:54:45.0448 4232 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
15:54:45.0448 4232 monitor - ok
15:54:45.0495 4232 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
15:54:45.0495 4232 mouclass - ok
15:54:45.0526 4232 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\drivers\mouhid.sys
15:54:45.0526 4232 mouhid - ok
15:54:45.0573 4232 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
15:54:45.0573 4232 MountMgr - ok
15:54:45.0620 4232 [ 51A84B690DF519DCF656F780243D953E ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
15:54:45.0620 4232 MozillaMaintenance - ok
15:54:45.0635 4232 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
15:54:45.0651 4232 mpio - ok
15:54:45.0682 4232 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
15:54:45.0682 4232 mpsdrv - ok
15:54:45.0713 4232 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
15:54:45.0729 4232 MpsSvc - ok
15:54:45.0744 4232 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
15:54:45.0760 4232 Mraid35x - ok
15:54:45.0776 4232 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
15:54:45.0791 4232 MRxDAV - ok
15:54:45.0822 4232 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
15:54:45.0822 4232 mrxsmb - ok
15:54:45.0854 4232 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:54:45.0854 4232 mrxsmb10 - ok
15:54:45.0854 4232 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:54:45.0869 4232 mrxsmb20 - ok
15:54:45.0885 4232 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
15:54:45.0885 4232 msahci - ok
15:54:45.0963 4232 [ A99D2C7E30AD63EF920A894131CAF5F7 ] MSCSPTISRV C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
15:54:45.0963 4232 MSCSPTISRV - ok
15:54:45.0994 4232 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
15:54:45.0994 4232 msdsm - ok
15:54:46.0025 4232 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
15:54:46.0025 4232 MSDTC - ok
15:54:46.0072 4232 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
15:54:46.0072 4232 Msfs - ok
15:54:46.0088 4232 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
15:54:46.0088 4232 msisadrv - ok
15:54:46.0134 4232 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
15:54:46.0150 4232 MSiSCSI - ok
15:54:46.0150 4232 msiserver - ok
15:54:46.0197 4232 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
15:54:46.0197 4232 MSKSSRV - ok
15:54:46.0197 4232 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
15:54:46.0212 4232 MSPCLOCK - ok
15:54:46.0212 4232 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
15:54:46.0212 4232 MSPQM - ok
15:54:46.0259 4232 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
15:54:46.0259 4232 MsRPC - ok
15:54:46.0275 4232 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
15:54:46.0275 4232 mssmbios - ok
15:54:46.0431 4232 MSSQL$MSSMLBIZ - ok
15:54:46.0446 4232 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
15:54:46.0446 4232 MSSQLServerADHelper - ok
15:54:46.0478 4232 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
15:54:46.0478 4232 MSTEE - ok
15:54:46.0524 4232 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
15:54:46.0524 4232 Mup - ok
15:54:46.0556 4232 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
15:54:46.0556 4232 napagent - ok
15:54:46.0602 4232 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
15:54:46.0602 4232 NativeWifiP - ok
15:54:46.0712 4232 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
15:54:46.0727 4232 NDIS - ok
15:54:46.0758 4232 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:54:46.0758 4232 NdisTapi - ok
15:54:46.0790 4232 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
15:54:46.0790 4232 Ndisuio - ok
15:54:46.0821 4232 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
15:54:46.0836 4232 NdisWan - ok
15:54:46.0852 4232 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
15:54:46.0852 4232 NDProxy - ok
15:54:46.0961 4232 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
15:54:46.0977 4232 Nero BackItUp Scheduler 4.0 - ok
15:54:47.0008 4232 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
15:54:47.0008 4232 NetBIOS - ok
15:54:47.0070 4232 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
15:54:47.0070 4232 netbt - ok
15:54:47.0086 4232 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
15:54:47.0086 4232 Netlogon - ok
15:54:47.0148 4232 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
15:54:47.0148 4232 Netman - ok
15:54:47.0180 4232 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
15:54:47.0195 4232 netprofm - ok
15:54:47.0258 4232 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:54:47.0258 4232 NetTcpPortSharing - ok
15:54:47.0304 4232 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
15:54:47.0304 4232 nfrd960 - ok
15:54:47.0351 4232 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
15:54:47.0351 4232 NlaSvc - ok
15:54:47.0476 4232 [ 9A908A9BB857C2CCEB2907EB9DCAEB8B ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
15:54:47.0476 4232 nmwcd - ok
15:54:47.0492 4232 [ 68EC3EE2348E475EA62C66E6AAFCFC9B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
15:54:47.0492 4232 nmwcdc - ok
15:54:47.0538 4232 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
15:54:47.0538 4232 Npfs - ok
15:54:47.0585 4232 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
15:54:47.0601 4232 nsi - ok
15:54:47.0632 4232 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
15:54:47.0632 4232 nsiproxy - ok
15:54:47.0710 4232 [ FD141D19F1392920A6A517316910D770 ] NSUService C:\Program Files\Sony\Network Utility\NSUService.exe
15:54:47.0710 4232 NSUService - ok
15:54:47.0772 4232 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
15:54:47.0788 4232 Ntfs - ok
15:54:47.0819 4232 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
15:54:47.0819 4232 ntrigdigi - ok
15:54:47.0850 4232 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
15:54:47.0850 4232 Null - ok
15:54:47.0866 4232 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
15:54:47.0866 4232 nvraid - ok
15:54:47.0866 4232 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
15:54:47.0882 4232 nvstor - ok
15:54:47.0897 4232 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
15:54:47.0897 4232 nv_agp - ok
15:54:47.0913 4232 NwlnkFlt - ok
15:54:47.0913 4232 NwlnkFwd - ok
15:54:48.0006 4232 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:54:48.0006 4232 odserv - ok
15:54:48.0100 4232 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
15:54:48.0100 4232 ohci1394 - ok
15:54:48.0240 4232 [ D3530461AF3737392E5693D9E2CEA4A2 ] OODefragAgent C:\Program Files\OO Software\Defrag\oodag.exe
15:54:48.0272 4232 OODefragAgent - ok
15:54:48.0303 4232 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:54:48.0303 4232 ose - ok
15:54:48.0381 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
15:54:48.0396 4232 p2pimsvc - ok
15:54:48.0412 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
15:54:48.0428 4232 p2psvc - ok
15:54:48.0459 4232 [ 41C33FB4FD929FED732A00D2DAEF5BE0 ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
15:54:48.0459 4232 PACSPTISVR - ok
15:54:48.0506 4232 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
15:54:48.0506 4232 Parport - ok
15:54:48.0552 4232 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
15:54:48.0552 4232 partmgr - ok
15:54:48.0599 4232 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
15:54:48.0599 4232 Parvdm - ok
15:54:48.0630 4232 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
15:54:48.0630 4232 PcaSvc - ok
15:54:48.0708 4232 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
15:54:48.0708 4232 pccsmcfd - ok
15:54:48.0740 4232 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
15:54:48.0755 4232 pci - ok
15:54:48.0786 4232 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
15:54:48.0786 4232 pciide - ok
15:54:48.0802 4232 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
15:54:48.0802 4232 pcmcia - ok
15:54:48.0849 4232 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
15:54:48.0864 4232 PEAUTH - ok
15:54:48.0958 4232 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
15:54:48.0989 4232 pla - ok
15:54:49.0005 4232 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
15:54:49.0020 4232 PlugPlay - ok
15:54:49.0083 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
15:54:49.0083 4232 PNRPAutoReg - ok
15:54:49.0098 4232 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
15:54:49.0114 4232 PNRPsvc - ok
15:54:49.0161 4232 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
15:54:49.0161 4232 PolicyAgent - ok
15:54:49.0208 4232 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
15:54:49.0208 4232 PptpMiniport - ok
15:54:49.0239 4232 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
15:54:49.0239 4232 Processor - ok
15:54:49.0286 4232 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
15:54:49.0286 4232 ProfSvc - ok
15:54:49.0301 4232 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
15:54:49.0317 4232 ProtectedStorage - ok
15:54:49.0348 4232 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
15:54:49.0348 4232 PSched - ok
15:54:49.0395 4232 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
15:54:49.0410 4232 PxHelp20 - ok
15:54:49.0598 4232 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
15:54:49.0613 4232 ql2300 - ok
15:54:49.0629 4232 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
15:54:49.0629 4232 ql40xx - ok
15:54:49.0691 4232 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
15:54:49.0707 4232 QWAVE - ok
15:54:49.0722 4232 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
15:54:49.0722 4232 QWAVEdrv - ok
15:54:49.0738 4232 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
15:54:49.0738 4232 RasAcd - ok
15:54:49.0754 4232 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
15:54:49.0754 4232 RasAuto - ok
15:54:49.0800 4232 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
15:54:49.0816 4232 Rasl2tp - ok
15:54:49.0847 4232 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
15:54:49.0847 4232 RasMan - ok
15:54:49.0894 4232 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
15:54:49.0894 4232 RasPppoe - ok
15:54:49.0910 4232 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
15:54:49.0910 4232 RasSstp - ok
15:54:50.0003 4232 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
15:54:50.0003 4232 rdbss - ok
15:54:50.0034 4232 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
15:54:50.0034 4232 RDPCDD - ok
15:54:50.0081 4232 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
15:54:50.0081 4232 rdpdr - ok
15:54:50.0097 4232 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
15:54:50.0097 4232 RDPENCDD - ok
15:54:50.0175 4232 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
15:54:50.0175 4232 RDPWD - ok
15:54:50.0222 4232 [ 001B4278407F4303EFC902A2B16F2453 ] regi C:\Windows\system32\drivers\regi.sys
15:54:50.0222 4232 regi - ok
15:54:50.0284 4232 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
15:54:50.0284 4232 RemoteAccess - ok
15:54:50.0315 4232 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
15:54:50.0315 4232 RemoteRegistry - ok
15:54:50.0393 4232 [ D0C2A0CE1091E08EFB7CCBA6CEA4C3F9 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
15:54:50.0393 4232 rimsptsk - ok
15:54:50.0440 4232 [ C22E4E27CCDF9AA5FE8143104F28CDE3 ] risdptsk C:\Windows\system32\DRIVERS\risdptsk.sys
15:54:50.0440 4232 risdptsk - ok
15:54:50.0471 4232 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
15:54:50.0471 4232 RpcLocator - ok
15:54:50.0534 4232 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
15:54:50.0534 4232 RpcSs - ok
15:54:50.0580 4232 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
15:54:50.0580 4232 rspndr - ok
15:54:50.0643 4232 [ 65330E78C17DB8A99A7FF1BA3C8824B6 ] RtkAudioService C:\Windows\RtkAudioService.exe
15:54:50.0643 4232 RtkAudioService - ok
15:54:50.0658 4232 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
15:54:50.0674 4232 SamSs - ok
15:54:50.0705 4232 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
15:54:50.0705 4232 sbp2port - ok
15:54:50.0768 4232 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
15:54:50.0768 4232 SCardSvr - ok
15:54:50.0814 4232 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
15:54:50.0830 4232 Schedule - ok
15:54:50.0861 4232 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
15:54:50.0861 4232 SCPolicySvc - ok
15:54:50.0908 4232 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
15:54:50.0908 4232 sdbus - ok
15:54:50.0939 4232 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
15:54:50.0939 4232 SDRSVC - ok
15:54:50.0955 4232 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
15:54:50.0955 4232 secdrv - ok
15:54:50.0970 4232 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
15:54:50.0970 4232 seclogon - ok
15:54:50.0986 4232 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
15:54:50.0986 4232 SENS - ok
15:54:51.0002 4232 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
15:54:51.0002 4232 Serenum - ok
15:54:51.0017 4232 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
15:54:51.0017 4232 Serial - ok
15:54:51.0033 4232 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
15:54:51.0033 4232 sermouse - ok
15:54:51.0095 4232 [ 3EC8DE67B1C78C31E54C0F030E6BD7D5 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
15:54:51.0095 4232 ServiceLayer - ok
15:54:51.0126 4232 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
15:54:51.0126 4232 SessionEnv - ok
15:54:51.0189 4232 [ 8B7C1768D2CDE2E02E09A66563DDFD16 ] SFEP C:\Windows\system32\DRIVERS\SFEP.sys
15:54:51.0189 4232 SFEP - ok
15:54:51.0204 4232 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
15:54:51.0204 4232 sffdisk - ok
15:54:51.0236 4232 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
15:54:51.0236 4232 sffp_mmc - ok
15:54:51.0236 4232 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
15:54:51.0236 4232 sffp_sd - ok
15:54:51.0251 4232 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
15:54:51.0251 4232 sfloppy - ok
15:54:51.0282 4232 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
15:54:51.0298 4232 SharedAccess - ok
15:54:51.0314 4232 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:54:51.0314 4232 ShellHWDetection - ok
15:54:51.0329 4232 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
15:54:51.0329 4232 sisagp - ok
15:54:51.0345 4232 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
15:54:51.0345 4232 SiSRaid2 - ok
15:54:51.0345 4232 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
15:54:51.0360 4232 SiSRaid4 - ok
15:54:51.0657 4232 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
15:54:51.0782 4232 Skype C2C Service - ok
15:54:51.0860 4232 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
15:54:51.0860 4232 SkypeUpdate - ok
15:54:52.0125 4232 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
15:54:53.0248 4232 slsvc - ok
15:54:53.0295 4232 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
15:54:53.0310 4232 SLUINotify - ok
15:54:53.0342 4232 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
15:54:53.0342 4232 Smb - ok
15:54:53.0466 4232 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
15:54:53.0466 4232 SNMPTRAP - ok
15:54:53.0638 4232 [ DC826AFFA608F50C385BCA4C71EF1BDD ] SOHCImp C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe
15:54:53.0638 4232 SOHCImp - ok
15:54:53.0685 4232 [ 1EC739F65C51FA1C7AC4502464A3C3A8 ] SOHDms C:\Program Files\Sony\VAIO Media plus\SOHDms.exe
15:54:53.0700 4232 SOHDms - ok
15:54:53.0700 4232 [ EC8FAB4AC684445D6032AA5C6E77CA2E ] SOHDs C:\Program Files\Sony\VAIO Media plus\SOHDs.exe
15:54:53.0700 4232 SOHDs - ok
15:54:53.0794 4232 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
15:54:53.0794 4232 spldr - ok
15:54:53.0903 4232 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
15:54:53.0903 4232 Spooler - ok
15:54:54.0044 4232 [ F63102F289AE2039940B22E9B2A8E0BD ] SPTISRV C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
15:54:54.0044 4232 SPTISRV - ok
15:54:54.0075 4232 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
15:54:54.0090 4232 SQLBrowser - ok
15:54:54.0122 4232 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- Clorky
- Moderátor / člen HW týmu
-
Master Level 8.5
- Příspěvky: 7032
- Registrován: květen 10
- Bydliště: Moravskoslezský kraj
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
15:54:54.0122 4232 SQLWriter - ok
15:54:54.0246 4232 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
15:54:54.0246 4232 srv - ok
15:54:54.0324 4232 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
15:54:54.0324 4232 srv2 - ok
15:54:54.0356 4232 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
15:54:54.0356 4232 srvnet - ok
15:54:54.0418 4232 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
15:54:54.0418 4232 SSDPSRV - ok
15:54:54.0465 4232 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
15:54:54.0480 4232 SstpSvc - ok
15:54:54.0605 4232 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
15:54:54.0621 4232 stisvc - ok
15:54:54.0730 4232 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
15:54:54.0730 4232 swenum - ok
15:54:55.0385 4232 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
15:54:55.0401 4232 SwitchBoard - ok
15:54:55.0494 4232 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
15:54:55.0526 4232 swprv - ok
15:54:55.0744 4232 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
15:54:55.0744 4232 Symc8xx - ok
15:54:55.0760 4232 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
15:54:55.0760 4232 Sym_hi - ok
15:54:55.0775 4232 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
15:54:55.0775 4232 Sym_u3 - ok
15:54:55.0916 4232 [ 99DA94793332AADBB17BBB521AE56E21 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
15:54:55.0916 4232 SynTP - ok
15:54:56.0009 4232 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
15:54:56.0025 4232 SysMain - ok
15:54:56.0087 4232 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:54:56.0087 4232 TabletInputService - ok
15:54:56.0134 4232 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
15:54:56.0150 4232 TapiSrv - ok
15:54:56.0150 4232 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
15:54:56.0165 4232 TBS - ok
15:54:56.0477 4232 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
15:54:56.0540 4232 Tcpip - ok
15:54:56.0711 4232 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
15:54:56.0727 4232 Tcpip6 - ok
15:54:56.0789 4232 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
15:54:56.0805 4232 tcpipreg - ok
15:54:56.0852 4232 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
15:54:56.0852 4232 TDPIPE - ok
15:54:56.0945 4232 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
15:54:56.0945 4232 TDTCP - ok
15:54:57.0039 4232 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
15:54:57.0039 4232 tdx - ok
15:54:57.0164 4232 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
15:54:57.0164 4232 TermDD - ok
15:54:57.0288 4232 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
15:54:57.0304 4232 TermService - ok
15:54:57.0335 4232 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
15:54:57.0351 4232 Themes - ok
15:54:57.0382 4232 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
15:54:57.0382 4232 THREADORDER - ok
15:54:57.0429 4232 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
15:54:57.0444 4232 TrkWks - ok
15:54:57.0616 4232 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:54:57.0616 4232 TrustedInstaller - ok
15:54:57.0725 4232 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
15:54:57.0725 4232 tssecsrv - ok
15:54:57.0850 4232 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
15:54:57.0866 4232 tunmp - ok
15:54:57.0959 4232 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
15:54:57.0975 4232 tunnel - ok
15:54:58.0427 4232 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
15:54:58.0427 4232 uagp35 - ok
15:54:58.0599 4232 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
15:54:58.0614 4232 udfs - ok
15:54:58.0770 4232 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
15:54:58.0786 4232 UI0Detect - ok
15:54:58.0926 4232 UIUSys - ok
15:54:59.0051 4232 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
15:54:59.0051 4232 uliagpkx - ok
15:54:59.0207 4232 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
15:54:59.0207 4232 uliahci - ok
15:54:59.0457 4232 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
15:54:59.0457 4232 UlSata - ok
15:54:59.0472 4232 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
15:54:59.0472 4232 ulsata2 - ok
15:54:59.0566 4232 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
15:54:59.0566 4232 umbus - ok
15:54:59.0660 4232 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
15:54:59.0675 4232 upnphost - ok
15:54:59.0753 4232 [ A34560A5D516A2F5240180370866B99D ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
15:54:59.0753 4232 upperdev - ok
15:54:59.0878 4232 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
15:54:59.0878 4232 usbccgp - ok
15:54:59.0925 4232 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
15:54:59.0925 4232 usbcir - ok
15:54:59.0956 4232 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
15:54:59.0956 4232 usbehci - ok
15:55:00.0346 4232 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
15:55:00.0346 4232 usbhub - ok
15:55:00.0424 4232 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
15:55:00.0424 4232 usbohci - ok
15:55:00.0486 4232 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
15:55:00.0486 4232 usbprint - ok
15:55:00.0642 4232 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
15:55:00.0689 4232 usbscan - ok
15:55:01.0079 4232 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
15:55:01.0079 4232 usbser - ok
15:55:01.0204 4232 [ 6410EEBD6E0427466812858EE84C8467 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
15:55:01.0204 4232 UsbserFilt - ok
15:55:01.0266 4232 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:55:01.0266 4232 USBSTOR - ok
15:55:01.0313 4232 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
15:55:01.0313 4232 usbuhci - ok
15:55:01.0563 4232 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
15:55:01.0563 4232 usbvideo - ok
15:55:01.0672 4232 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
15:55:01.0672 4232 UxSms - ok
15:55:01.0828 4232 [ 2A640DC735CB0112AC1DCD1E1549B27E ] VAIO Entertainment TV Device Arbitration Service C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
15:55:01.0828 4232 VAIO Entertainment TV Device Arbitration Service - ok
15:55:02.0062 4232 [ 693A3FDD279C345105FFF9DDE277849B ] VAIO Event Service C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
15:55:02.0078 4232 VAIO Event Service - ok
15:55:02.0171 4232 [ 43CEC9BF5A4F2917982AD01D92E0F44D ] VAIO Power Management C:\Program Files\Sony\VAIO Power Management\SPMService.exe
15:55:02.0202 4232 VAIO Power Management - ok
15:55:02.0499 4232 [ CBCBE2233D21E9B278F95F5CB28BC8AE ] VCFw C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
15:55:02.0733 4232 VCFw - ok
15:55:02.0795 4232 [ 27888F132D2EE0B72B28093A5F5F20EB ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
15:55:02.0811 4232 VcmIAlzMgr - ok
15:55:02.0842 4232 [ EE9ABFC2F8F2DCDC624B6A9D5CF3B19D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
15:55:02.0842 4232 VcmXmlIfHelper - ok
15:55:02.0889 4232 Vcsw - ok
15:55:03.0154 4232 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
15:55:03.0263 4232 vds - ok
15:55:03.0357 4232 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
15:55:03.0404 4232 vga - ok
15:55:03.0513 4232 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
15:55:03.0513 4232 VgaSave - ok
15:55:03.0794 4232 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
15:55:03.0794 4232 viaagp - ok
15:55:03.0840 4232 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
15:55:03.0840 4232 ViaC7 - ok
15:55:03.0856 4232 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
15:55:03.0856 4232 viaide - ok
15:55:03.0903 4232 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
15:55:03.0903 4232 volmgr - ok
15:55:04.0012 4232 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
15:55:04.0043 4232 volmgrx - ok
15:55:04.0371 4232 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
15:55:04.0371 4232 volsnap - ok
15:55:04.0433 4232 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
15:55:04.0433 4232 vsmraid - ok
15:55:04.0995 4232 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
15:55:05.0057 4232 VSS - ok
15:55:05.0135 4232 [ 071634532066C2E29350D450C3412837 ] VzCdbSvc C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
15:55:05.0135 4232 VzCdbSvc - ok
15:55:05.0369 4232 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
15:55:05.0385 4232 W32Time - ok
15:55:05.0588 4232 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
15:55:05.0588 4232 WacomPen - ok
15:55:05.0619 4232 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
15:55:05.0619 4232 Wanarp - ok
15:55:05.0634 4232 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
15:55:05.0634 4232 Wanarpv6 - ok
15:55:05.0790 4232 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
15:55:05.0806 4232 wcncsvc - ok
15:55:05.0853 4232 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:55:05.0868 4232 WcsPlugInService - ok
15:55:06.0149 4232 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
15:55:06.0149 4232 Wd - ok
15:55:06.0258 4232 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
15:55:06.0258 4232 Wdf01000 - ok
15:55:06.0305 4232 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
15:55:06.0321 4232 WdiServiceHost - ok
15:55:06.0321 4232 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
15:55:06.0336 4232 WdiSystemHost - ok
15:55:06.0539 4232 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
15:55:06.0555 4232 WebClient - ok
15:55:06.0680 4232 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
15:55:06.0680 4232 Wecsvc - ok
15:55:06.0773 4232 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
15:55:06.0773 4232 wercplsupport - ok
15:55:06.0976 4232 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
15:55:06.0992 4232 WerSvc - ok
15:55:07.0163 4232 [ 090A2B8F055343815556A01F725F6C35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys
15:55:07.0179 4232 WimFltr - ok
15:55:07.0397 4232 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
15:55:07.0491 4232 winachsf - ok
15:55:07.0616 4232 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
15:55:07.0631 4232 WinDefend - ok
15:55:07.0647 4232 WinHttpAutoProxySvc - ok
15:55:07.0943 4232 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
15:55:07.0943 4232 Winmgmt - ok
15:55:08.0364 4232 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
15:55:08.0754 4232 WinRM - ok
15:55:08.0864 4232 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
15:55:08.0879 4232 Wlansvc - ok
15:55:08.0957 4232 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
15:55:08.0957 4232 WmiAcpi - ok
15:55:09.0051 4232 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
15:55:09.0051 4232 wmiApSrv - ok
15:55:09.0238 4232 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
15:55:09.0254 4232 WMPNetworkSvc - ok
15:55:09.0456 4232 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
15:55:09.0472 4232 WPCSvc - ok
15:55:09.0488 4232 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
15:55:09.0503 4232 WPDBusEnum - ok
15:55:09.0862 4232 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
15:55:09.0893 4232 WPFFontCache_v0400 - ok
15:55:10.0080 4232 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
15:55:10.0080 4232 ws2ifsl - ok
15:55:10.0158 4232 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
15:55:10.0174 4232 wscsvc - ok
15:55:10.0174 4232 WSearch - ok
15:55:10.0392 4232 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
15:55:10.0455 4232 wuauserv - ok
15:55:10.0564 4232 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
15:55:10.0564 4232 WudfPf - ok
15:55:10.0626 4232 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
15:55:10.0626 4232 WUDFRd - ok
15:55:10.0673 4232 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
15:55:10.0673 4232 wudfsvc - ok
15:55:10.0736 4232 [ 88AF537264F2B818DA15479CEEAF5D7C ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
15:55:10.0736 4232 XAudio - ok
15:55:10.0798 4232 [ 15A317674A08DF26BE65164D959E9203 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
15:55:10.0798 4232 XAudioService - ok
15:55:10.0845 4232 [ 7D4CCA3659FA0780603206E3D12A993F ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
15:55:10.0860 4232 yukonwlh - ok
15:55:10.0954 4232 [ B53430A93FEF17B08AC3A9F245B9720F ] ZSMC303 C:\Windows\system32\Drivers\usbVM303.sys
15:55:10.0970 4232 ZSMC303 - ok
15:55:10.0985 4232 ================ Scan global ===============================
15:55:11.0063 4232 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
15:55:11.0250 4232 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
15:55:11.0266 4232 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
15:55:11.0438 4232 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
15:55:11.0438 4232 [Global] - ok
15:55:11.0453 4232 ================ Scan MBR ==================================
15:55:11.0469 4232 [ 239841E1AE8E4843C0676F3681A7D6BE ] \Device\Harddisk0\DR0
15:55:11.0921 4232 \Device\Harddisk0\DR0 - ok
15:55:11.0921 4232 ================ Scan VBR ==================================
15:55:11.0968 4232 [ 71A7969C96A184562C60F41F5FEA45E5 ] \Device\Harddisk0\DR0\Partition1
15:55:11.0968 4232 \Device\Harddisk0\DR0\Partition1 - ok
15:55:11.0968 4232 ============================================================
15:55:11.0968 4232 Scan finished
15:55:11.0968 4232 ============================================================
15:55:11.0999 4284 Detected object count: 0
15:55:11.0999 4284 Actual detected object count: 0
15:55:20.0111 4564 Deinitialize success
15:54:54.0246 4232 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
15:54:54.0246 4232 srv - ok
15:54:54.0324 4232 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
15:54:54.0324 4232 srv2 - ok
15:54:54.0356 4232 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
15:54:54.0356 4232 srvnet - ok
15:54:54.0418 4232 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
15:54:54.0418 4232 SSDPSRV - ok
15:54:54.0465 4232 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
15:54:54.0480 4232 SstpSvc - ok
15:54:54.0605 4232 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
15:54:54.0621 4232 stisvc - ok
15:54:54.0730 4232 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
15:54:54.0730 4232 swenum - ok
15:54:55.0385 4232 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
15:54:55.0401 4232 SwitchBoard - ok
15:54:55.0494 4232 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
15:54:55.0526 4232 swprv - ok
15:54:55.0744 4232 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
15:54:55.0744 4232 Symc8xx - ok
15:54:55.0760 4232 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
15:54:55.0760 4232 Sym_hi - ok
15:54:55.0775 4232 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
15:54:55.0775 4232 Sym_u3 - ok
15:54:55.0916 4232 [ 99DA94793332AADBB17BBB521AE56E21 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
15:54:55.0916 4232 SynTP - ok
15:54:56.0009 4232 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
15:54:56.0025 4232 SysMain - ok
15:54:56.0087 4232 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:54:56.0087 4232 TabletInputService - ok
15:54:56.0134 4232 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
15:54:56.0150 4232 TapiSrv - ok
15:54:56.0150 4232 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
15:54:56.0165 4232 TBS - ok
15:54:56.0477 4232 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
15:54:56.0540 4232 Tcpip - ok
15:54:56.0711 4232 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
15:54:56.0727 4232 Tcpip6 - ok
15:54:56.0789 4232 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
15:54:56.0805 4232 tcpipreg - ok
15:54:56.0852 4232 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
15:54:56.0852 4232 TDPIPE - ok
15:54:56.0945 4232 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
15:54:56.0945 4232 TDTCP - ok
15:54:57.0039 4232 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
15:54:57.0039 4232 tdx - ok
15:54:57.0164 4232 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
15:54:57.0164 4232 TermDD - ok
15:54:57.0288 4232 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
15:54:57.0304 4232 TermService - ok
15:54:57.0335 4232 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
15:54:57.0351 4232 Themes - ok
15:54:57.0382 4232 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
15:54:57.0382 4232 THREADORDER - ok
15:54:57.0429 4232 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
15:54:57.0444 4232 TrkWks - ok
15:54:57.0616 4232 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:54:57.0616 4232 TrustedInstaller - ok
15:54:57.0725 4232 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
15:54:57.0725 4232 tssecsrv - ok
15:54:57.0850 4232 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
15:54:57.0866 4232 tunmp - ok
15:54:57.0959 4232 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
15:54:57.0975 4232 tunnel - ok
15:54:58.0427 4232 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
15:54:58.0427 4232 uagp35 - ok
15:54:58.0599 4232 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
15:54:58.0614 4232 udfs - ok
15:54:58.0770 4232 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
15:54:58.0786 4232 UI0Detect - ok
15:54:58.0926 4232 UIUSys - ok
15:54:59.0051 4232 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
15:54:59.0051 4232 uliagpkx - ok
15:54:59.0207 4232 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
15:54:59.0207 4232 uliahci - ok
15:54:59.0457 4232 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
15:54:59.0457 4232 UlSata - ok
15:54:59.0472 4232 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
15:54:59.0472 4232 ulsata2 - ok
15:54:59.0566 4232 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
15:54:59.0566 4232 umbus - ok
15:54:59.0660 4232 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
15:54:59.0675 4232 upnphost - ok
15:54:59.0753 4232 [ A34560A5D516A2F5240180370866B99D ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
15:54:59.0753 4232 upperdev - ok
15:54:59.0878 4232 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
15:54:59.0878 4232 usbccgp - ok
15:54:59.0925 4232 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
15:54:59.0925 4232 usbcir - ok
15:54:59.0956 4232 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
15:54:59.0956 4232 usbehci - ok
15:55:00.0346 4232 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
15:55:00.0346 4232 usbhub - ok
15:55:00.0424 4232 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
15:55:00.0424 4232 usbohci - ok
15:55:00.0486 4232 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
15:55:00.0486 4232 usbprint - ok
15:55:00.0642 4232 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
15:55:00.0689 4232 usbscan - ok
15:55:01.0079 4232 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
15:55:01.0079 4232 usbser - ok
15:55:01.0204 4232 [ 6410EEBD6E0427466812858EE84C8467 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
15:55:01.0204 4232 UsbserFilt - ok
15:55:01.0266 4232 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:55:01.0266 4232 USBSTOR - ok
15:55:01.0313 4232 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
15:55:01.0313 4232 usbuhci - ok
15:55:01.0563 4232 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
15:55:01.0563 4232 usbvideo - ok
15:55:01.0672 4232 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
15:55:01.0672 4232 UxSms - ok
15:55:01.0828 4232 [ 2A640DC735CB0112AC1DCD1E1549B27E ] VAIO Entertainment TV Device Arbitration Service C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
15:55:01.0828 4232 VAIO Entertainment TV Device Arbitration Service - ok
15:55:02.0062 4232 [ 693A3FDD279C345105FFF9DDE277849B ] VAIO Event Service C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
15:55:02.0078 4232 VAIO Event Service - ok
15:55:02.0171 4232 [ 43CEC9BF5A4F2917982AD01D92E0F44D ] VAIO Power Management C:\Program Files\Sony\VAIO Power Management\SPMService.exe
15:55:02.0202 4232 VAIO Power Management - ok
15:55:02.0499 4232 [ CBCBE2233D21E9B278F95F5CB28BC8AE ] VCFw C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
15:55:02.0733 4232 VCFw - ok
15:55:02.0795 4232 [ 27888F132D2EE0B72B28093A5F5F20EB ] VcmIAlzMgr C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
15:55:02.0811 4232 VcmIAlzMgr - ok
15:55:02.0842 4232 [ EE9ABFC2F8F2DCDC624B6A9D5CF3B19D ] VcmXmlIfHelper C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
15:55:02.0842 4232 VcmXmlIfHelper - ok
15:55:02.0889 4232 Vcsw - ok
15:55:03.0154 4232 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
15:55:03.0263 4232 vds - ok
15:55:03.0357 4232 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
15:55:03.0404 4232 vga - ok
15:55:03.0513 4232 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
15:55:03.0513 4232 VgaSave - ok
15:55:03.0794 4232 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
15:55:03.0794 4232 viaagp - ok
15:55:03.0840 4232 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
15:55:03.0840 4232 ViaC7 - ok
15:55:03.0856 4232 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
15:55:03.0856 4232 viaide - ok
15:55:03.0903 4232 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
15:55:03.0903 4232 volmgr - ok
15:55:04.0012 4232 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
15:55:04.0043 4232 volmgrx - ok
15:55:04.0371 4232 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
15:55:04.0371 4232 volsnap - ok
15:55:04.0433 4232 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
15:55:04.0433 4232 vsmraid - ok
15:55:04.0995 4232 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
15:55:05.0057 4232 VSS - ok
15:55:05.0135 4232 [ 071634532066C2E29350D450C3412837 ] VzCdbSvc C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
15:55:05.0135 4232 VzCdbSvc - ok
15:55:05.0369 4232 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
15:55:05.0385 4232 W32Time - ok
15:55:05.0588 4232 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
15:55:05.0588 4232 WacomPen - ok
15:55:05.0619 4232 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
15:55:05.0619 4232 Wanarp - ok
15:55:05.0634 4232 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
15:55:05.0634 4232 Wanarpv6 - ok
15:55:05.0790 4232 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
15:55:05.0806 4232 wcncsvc - ok
15:55:05.0853 4232 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:55:05.0868 4232 WcsPlugInService - ok
15:55:06.0149 4232 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
15:55:06.0149 4232 Wd - ok
15:55:06.0258 4232 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
15:55:06.0258 4232 Wdf01000 - ok
15:55:06.0305 4232 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
15:55:06.0321 4232 WdiServiceHost - ok
15:55:06.0321 4232 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
15:55:06.0336 4232 WdiSystemHost - ok
15:55:06.0539 4232 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
15:55:06.0555 4232 WebClient - ok
15:55:06.0680 4232 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
15:55:06.0680 4232 Wecsvc - ok
15:55:06.0773 4232 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
15:55:06.0773 4232 wercplsupport - ok
15:55:06.0976 4232 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
15:55:06.0992 4232 WerSvc - ok
15:55:07.0163 4232 [ 090A2B8F055343815556A01F725F6C35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys
15:55:07.0179 4232 WimFltr - ok
15:55:07.0397 4232 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
15:55:07.0491 4232 winachsf - ok
15:55:07.0616 4232 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
15:55:07.0631 4232 WinDefend - ok
15:55:07.0647 4232 WinHttpAutoProxySvc - ok
15:55:07.0943 4232 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
15:55:07.0943 4232 Winmgmt - ok
15:55:08.0364 4232 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
15:55:08.0754 4232 WinRM - ok
15:55:08.0864 4232 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
15:55:08.0879 4232 Wlansvc - ok
15:55:08.0957 4232 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
15:55:08.0957 4232 WmiAcpi - ok
15:55:09.0051 4232 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
15:55:09.0051 4232 wmiApSrv - ok
15:55:09.0238 4232 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
15:55:09.0254 4232 WMPNetworkSvc - ok
15:55:09.0456 4232 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
15:55:09.0472 4232 WPCSvc - ok
15:55:09.0488 4232 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
15:55:09.0503 4232 WPDBusEnum - ok
15:55:09.0862 4232 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
15:55:09.0893 4232 WPFFontCache_v0400 - ok
15:55:10.0080 4232 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
15:55:10.0080 4232 ws2ifsl - ok
15:55:10.0158 4232 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
15:55:10.0174 4232 wscsvc - ok
15:55:10.0174 4232 WSearch - ok
15:55:10.0392 4232 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
15:55:10.0455 4232 wuauserv - ok
15:55:10.0564 4232 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
15:55:10.0564 4232 WudfPf - ok
15:55:10.0626 4232 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
15:55:10.0626 4232 WUDFRd - ok
15:55:10.0673 4232 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
15:55:10.0673 4232 wudfsvc - ok
15:55:10.0736 4232 [ 88AF537264F2B818DA15479CEEAF5D7C ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
15:55:10.0736 4232 XAudio - ok
15:55:10.0798 4232 [ 15A317674A08DF26BE65164D959E9203 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
15:55:10.0798 4232 XAudioService - ok
15:55:10.0845 4232 [ 7D4CCA3659FA0780603206E3D12A993F ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
15:55:10.0860 4232 yukonwlh - ok
15:55:10.0954 4232 [ B53430A93FEF17B08AC3A9F245B9720F ] ZSMC303 C:\Windows\system32\Drivers\usbVM303.sys
15:55:10.0970 4232 ZSMC303 - ok
15:55:10.0985 4232 ================ Scan global ===============================
15:55:11.0063 4232 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
15:55:11.0250 4232 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
15:55:11.0266 4232 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
15:55:11.0438 4232 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
15:55:11.0438 4232 [Global] - ok
15:55:11.0453 4232 ================ Scan MBR ==================================
15:55:11.0469 4232 [ 239841E1AE8E4843C0676F3681A7D6BE ] \Device\Harddisk0\DR0
15:55:11.0921 4232 \Device\Harddisk0\DR0 - ok
15:55:11.0921 4232 ================ Scan VBR ==================================
15:55:11.0968 4232 [ 71A7969C96A184562C60F41F5FEA45E5 ] \Device\Harddisk0\DR0\Partition1
15:55:11.0968 4232 \Device\Harddisk0\DR0\Partition1 - ok
15:55:11.0968 4232 ============================================================
15:55:11.0968 4232 Scan finished
15:55:11.0968 4232 ============================================================
15:55:11.0999 4284 Detected object count: 0
15:55:11.0999 4284 Actual detected object count: 0
15:55:20.0111 4564 Deinitialize success
- Clorky
- Moderátor / člen HW týmu
-
Master Level 8.5
- Příspěvky: 7032
- Registrován: květen 10
- Bydliště: Moravskoslezský kraj
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
Vir je možná už pryč, a MBAM ho odstranil.
Jen jestli tam nejsou zbytky. Nejsem si jist.
Jen jestli tam nejsou zbytky. Nejsem si jist.
- Clorky
- Moderátor / člen HW týmu
-
Master Level 8.5
- Příspěvky: 7032
- Registrován: květen 10
- Bydliště: Moravskoslezský kraj
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
ComboFix 13-02-24.01 - marek 24.02.2013 16:24:38.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1033.18.2938.1847 [GMT 1:00]
Spuštěný z: c:\users\marek\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\2455293.js
c:\programdata\2455293.pad
c:\users\marek\3925542.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-24 do 2013-02-24 )))))))))))))))))))))))))))))))
.
.
2013-02-24 15:33 . 2013-02-24 15:47 -------- d-----w- c:\users\marek\AppData\Local\temp
2013-02-24 15:33 . 2013-02-24 15:33 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-02-24 15:33 . 2013-02-24 15:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-24 15:16 . 2013-02-24 15:16 -------- d-----w- c:\users\marek\AppData\Roaming\Avira
2013-02-24 15:10 . 2013-02-24 15:08 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-02-24 15:10 . 2013-02-24 15:08 134336 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-02-24 15:10 . 2013-02-24 15:08 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-02-24 15:09 . 2013-02-24 15:09 -------- d-----w- c:\programdata\Avira
2013-02-24 15:09 . 2013-02-24 15:09 -------- d-----w- c:\program files\Avira
2013-02-22 07:16 . 2013-02-08 00:45 6954968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8008C840-16E2-4AC5-8FBE-6E52B25AB70D}\mpengine.dll
2013-02-13 07:27 . 2013-01-04 01:38 2048512 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 07:27 . 2012-11-08 03:48 1314816 ----a-w- c:\windows\system32\quartz.dll
2013-02-13 07:27 . 2013-01-04 11:28 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 07:27 . 2013-01-05 05:26 3602808 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-13 07:27 . 2013-01-05 05:26 3550072 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-02-08 08:11 . 2013-02-09 09:35 16365936 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-09 09:35 . 2012-04-16 16:48 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-09 09:35 . 2011-10-01 10:15 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-17 00:28 . 2010-09-29 07:16 232336 ------w- c:\windows\system32\MpSigStub.exe
2012-12-16 13:12 . 2012-12-22 02:00 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50 . 2012-12-22 02:01 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-12-14 15:49 . 2010-10-27 15:23 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-27 15:17 . 2012-11-27 15:20 1187697 ----a-w- c:\windows\unins000.exe
2013-02-06 08:11 . 2013-02-06 08:10 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-26 22:51 . 2013-02-06 08:10 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-06-28 262144]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-04 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6295552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"BigDog303"="c:\windows\VM303_STI.EXE" [2006-01-24 61440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-02-24 385248]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2012-09-14 5029232]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
O&O Defrag Tray.lnk - c:\windows\Installer\{A797B4C6-AEDB-4D46-9F4B-8E98DA192252}\DefragIcon.exe [2012-10-12 292878]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-07-07 19:28 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-29 19:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-08-31 01:57 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - SSMDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-31 17:57 1607120 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 17:12]
.
2013-02-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003Core.job
- c:\users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-19 22:34]
.
2013-02-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003UA.job
- c:\users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-19 22:34]
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 00:51]
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 00:51]
.
.
------- Doplňkový sken -------
.
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{789B4302-27CD-4727-BA87-8B5EC3E54992}: NameServer = 192.168.2.1
FF - ProfilePath - c:\users\marek\AppData\Roaming\Mozilla\Firefox\Profiles\x7xmw8p6.default-1353672640472\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-AdobeBridge - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-24 16:47
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????@?@??????????????????????????
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,
02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7
"{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{CA6319C0-31B7-401E-A518-A07C3DB8F777}"=hex:51,66,7a,6c,4c,1d,38,12,ae,1a,70,
ce,85,7f,70,05,da,0e,e3,3c,38,e6,b3,63
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:50,11,96,67,ec,49,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,b4,b8,96,41,24,43,45,be,53,8d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,b4,b8,96,41,24,43,45,be,53,8d,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(5456)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RtkAudioService.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\Sony\Network Utility\NSUService.exe
c:\program files\OO Software\Defrag\oodag.exe
c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Sony\VAIO Power Management\SPMService.exe
c:\windows\system32\DllHost.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\windows\system32\conime.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-02-24 16:51:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-24 15:51
.
Před spuštěním: 2 624 020 480 bytes free
Po spuštění: 2 493 530 112 bytes free
.
- - End Of File - - 8099ED491CC7550CAE018E1FEF7CF8A0
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1033.18.2938.1847 [GMT 1:00]
Spuštěný z: c:\users\marek\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\2455293.js
c:\programdata\2455293.pad
c:\users\marek\3925542.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-24 do 2013-02-24 )))))))))))))))))))))))))))))))
.
.
2013-02-24 15:33 . 2013-02-24 15:47 -------- d-----w- c:\users\marek\AppData\Local\temp
2013-02-24 15:33 . 2013-02-24 15:33 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-02-24 15:33 . 2013-02-24 15:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-24 15:16 . 2013-02-24 15:16 -------- d-----w- c:\users\marek\AppData\Roaming\Avira
2013-02-24 15:10 . 2013-02-24 15:08 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-02-24 15:10 . 2013-02-24 15:08 134336 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-02-24 15:10 . 2013-02-24 15:08 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-02-24 15:09 . 2013-02-24 15:09 -------- d-----w- c:\programdata\Avira
2013-02-24 15:09 . 2013-02-24 15:09 -------- d-----w- c:\program files\Avira
2013-02-22 07:16 . 2013-02-08 00:45 6954968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8008C840-16E2-4AC5-8FBE-6E52B25AB70D}\mpengine.dll
2013-02-13 07:27 . 2013-01-04 01:38 2048512 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 07:27 . 2012-11-08 03:48 1314816 ----a-w- c:\windows\system32\quartz.dll
2013-02-13 07:27 . 2013-01-04 11:28 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 07:27 . 2013-01-05 05:26 3602808 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-13 07:27 . 2013-01-05 05:26 3550072 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-02-08 08:11 . 2013-02-09 09:35 16365936 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-09 09:35 . 2012-04-16 16:48 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-09 09:35 . 2011-10-01 10:15 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-17 00:28 . 2010-09-29 07:16 232336 ------w- c:\windows\system32\MpSigStub.exe
2012-12-16 13:12 . 2012-12-22 02:00 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50 . 2012-12-22 02:01 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-12-14 15:49 . 2010-10-27 15:23 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-27 15:17 . 2012-11-27 15:20 1187697 ----a-w- c:\windows\unins000.exe
2013-02-06 08:11 . 2013-02-06 08:10 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-26 22:51 . 2013-02-06 08:10 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-06-28 262144]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-04 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6295552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"BigDog303"="c:\windows\VM303_STI.EXE" [2006-01-24 61440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-02-24 385248]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2012-09-14 5029232]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
O&O Defrag Tray.lnk - c:\windows\Installer\{A797B4C6-AEDB-4D46-9F4B-8E98DA192252}\DefragIcon.exe [2012-10-12 292878]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-07-07 19:28 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-29 19:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-08-31 01:57 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - SSMDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-31 17:57 1607120 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 17:12]
.
2013-02-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003Core.job
- c:\users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-19 22:34]
.
2013-02-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003UA.job
- c:\users\marek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-19 22:34]
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 00:51]
.
2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 00:51]
.
.
------- Doplňkový sken -------
.
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{789B4302-27CD-4727-BA87-8B5EC3E54992}: NameServer = 192.168.2.1
FF - ProfilePath - c:\users\marek\AppData\Roaming\Mozilla\Firefox\Profiles\x7xmw8p6.default-1353672640472\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-AdobeBridge - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-24 16:47
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????@?@??????????????????????????
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,
02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7
"{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{CA6319C0-31B7-401E-A518-A07C3DB8F777}"=hex:51,66,7a,6c,4c,1d,38,12,ae,1a,70,
ce,85,7f,70,05,da,0e,e3,3c,38,e6,b3,63
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:50,11,96,67,ec,49,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,b4,b8,96,41,24,43,45,be,53,8d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,b4,b8,96,41,24,43,45,be,53,8d,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(5456)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RtkAudioService.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\Sony\Network Utility\NSUService.exe
c:\program files\OO Software\Defrag\oodag.exe
c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Sony\VAIO Power Management\SPMService.exe
c:\windows\system32\DllHost.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\windows\system32\conime.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2013-02-24 16:51:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-02-24 15:51
.
Před spuštěním: 2 624 020 480 bytes free
Po spuštění: 2 493 530 112 bytes free
.
- - End Of File - - 8099ED491CC7550CAE018E1FEF7CF8A0
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
Máš málo místa na disku! Něco uvolni. To může být příčinou poroblému. Volno má být cca 15 % kapacity disku.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
File::
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3396877214-3225066777-4151611725-1003UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
- Clorky
- Moderátor / člen HW týmu
-
Master Level 8.5
- Příspěvky: 7032
- Registrován: květen 10
- Bydliště: Moravskoslezský kraj
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
Nemám teď NTB k dispozici. Děkuji za dosavadní pomoc.
Dořešili bychom to o víkendu, jestli to nevadí.
Dořešili bychom to o víkendu, jestli to nevadí.
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Policie ČR (vir) na tomto NTB
Nevadí, pak to dodej
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 91 hostů