Prosím kontrolu, podezření na spam v PC Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 13:57

Ahoj, mám v PC problém ze strany Ads by Browse to Save. Neustále se my zobrazují všude na internetu reklamy na nejrůznější hry, kasína apd. Zapnu chrome a hned my vyskočí další stránka s reklamou. Jinak my PC šlape dobře, akorát mě deptají ty spamy. Díky za kontrolu.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:52:36, on 9.5.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Windows\PixArt\Pac207\Monitor.exe
E:\Advanced SystemCare 6\ASCTray.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
E:\Verbatim GREEN BUTTON\GREEN BUTTON.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Users\Zkuřka\Desktop\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 190.7.212.30:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - E:\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 6] "E:\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Easy Driver Pro] E:\Easy Driver Pro\DPLauncher.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Zkuřka\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Startup: Verbatim GREEN BUTTON.lnk = E:\Verbatim GREEN BUTTON\GREEN BUTTON.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://E:\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~2\websea~1\sprote~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - E:\Advanced SystemCare 6\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - E:\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - E:\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 9029 bytes
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod memphisto » 09 kvě 2013 14:11

Odinstaluj BingBar

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 16:46

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.05.09.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16540
Zkuřka :: WEED [administrátor]

Ochrana: Zakázána

9.5.2013 16:42:41
mbam-log-2013-05-09 (16-42-41).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 238881
Uplynulý čas: 2 minut, 30 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 16:51

# AdwCleaner v2.300 - Log vytvooen 09/05/2013 v 16:51:20
# Aktualizováno 28/04/2013 Xplode
# Operaení systém : Windows 7 Ultimate Service Pack 1 (64 bits)
# Uživatel : Zkuřka - WEED
# Spuštin systém : Normální
# Spuštino z : C:\Users\Zkuřka\Desktop\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Nalezeno : C:\Program Files (x86)\WebSearch
Složka Nalezeno : C:\ProgramData\continuetosiavee
Složka Nalezeno : C:\ProgramData\InstallMate
Složka Nalezeno : C:\ProgramData\Trymedia
Složka Nalezeno : C:\Users\Zkuřka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkfpgolbdllpbecnmhkgpdbnelldffge
Složka Nalezeno : C:\Users\Zkuřka\AppData\Local\PackageAware

***** [Registry] *****

Data Nalezeno : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\websea~1\sprote~1.dll
Klíe Nalezeno : HKCU\Software\AppDataLow\SProtector
Klíe Nalezeno : HKCU\Software\ilivid
Klíe Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Klíe Nalezeno : HKLM\Software\SP Global
Klíe Nalezeno : HKLM\Software\SProtector
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíe Nalezeno : HKLM\SOFTWARE\Software
Klíe Nalezeno : HKU\S-1-5-21-2655182105-3363366893-1067691081-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16537

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ

-\\ Google Chrome v26.0.1410.64

Soubor : C:\Users\Zkuřka\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

-\\ Opera v12.15.1748.0

Soubor : C:\Users\Zkuřka\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [2233 octets] - [09/05/2013 16:51:20]

########## EOF - C:\AdwCleaner[R1].txt - [2293 octets] ##########
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod jaro3 » 09 kvě 2013 19:14

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 22:04

# AdwCleaner v2.300 - Log vytvooen 09/05/2013 v 22:01:33
# Aktualizováno 28/04/2013 Xplode
# Operaení systém : Windows 7 Ultimate Service Pack 1 (64 bits)
# Uživatel : Zkuřka - WEED
# Spuštin systém : Normální
# Spuštino z : C:\Users\Zkuřka\Desktop\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Vymazáno : C:\Program Files (x86)\WebSearch
Složka Vymazáno : C:\ProgramData\continuetosiavee
Složka Vymazáno : C:\ProgramData\InstallMate
Složka Vymazáno : C:\ProgramData\Trymedia
Složka Vymazáno : C:\Users\Zkuřka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkfpgolbdllpbecnmhkgpdbnelldffge
Složka Vymazáno : C:\Users\Zkuřka\AppData\Local\PackageAware

***** [Registry] *****

Data Vymazáno : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\websea~1\sprote~1.dll
Klíe Vymazáno : HKCU\Software\AppDataLow\SProtector
Klíe Vymazáno : HKCU\Software\ilivid
Klíe Vymazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Klíe Vymazáno : HKLM\Software\SP Global
Klíe Vymazáno : HKLM\Software\SProtector
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíe Vymazáno : HKLM\SOFTWARE\Software

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16537

Zaminino : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ --> hxxp://www.google.com
Zaminino : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.youwillfind.info/?pid= ... g=EN&cc=CZ --> hxxp://www.google.com

-\\ Google Chrome v26.0.1410.64

Soubor : C:\Users\Zkuřka\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

-\\ Opera v12.15.1748.0

Soubor : C:\Users\Zkuřka\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [2358 octets] - [09/05/2013 22:01:26]
AdwCleaner[S1].txt - [2208 octets] - [09/05/2013 22:01:33]

########## EOF - C:\AdwCleaner[S1].txt - [2268 octets] ##########
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 22:07

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Zkuřka [Práva správce]
Mód : Kontrola -- Datum : 05/09/2013 22:06:36
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (190.7.212.30:3128) -> NALEZENO
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> NALEZENO
[HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDS721010CLA632 ATA Device +++++
--- User ---
[MBR] 61f82927ed911fcd49265f84909aae5f
[BSP] c945ffedc6472dcf8bb589ce98e452b8 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 99900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 204802048 | Size: 853867 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SAMSUNG HD753LJ ATA Device +++++
--- User ---
[MBR] 4de7d93eebd0bde0a49f043689127bfa
[BSP] 86aeddf56fdaf8bcb32c67f734b60a62 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 715402 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1]_S_05092013_02d2206.txt >>
RKreport[1]_S_05092013_02d2206.txt
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 22:10

22:09:08.0223 0472 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:09:08.0379 0472 ============================================================
22:09:08.0379 0472 Current date / time: 2013/05/09 22:09:08.0379
22:09:08.0379 0472 SystemInfo:
22:09:08.0379 0472
22:09:08.0379 0472 OS Version: 6.1.7601 ServicePack: 1.0
22:09:08.0379 0472 Product type: Workstation
22:09:08.0379 0472 ComputerName: WEED
22:09:08.0379 0472 UserName: Zkuřka
22:09:08.0379 0472 Windows directory: C:\Windows
22:09:08.0379 0472 System windows directory: C:\Windows
22:09:08.0379 0472 Running under WOW64
22:09:08.0379 0472 Processor architecture: Intel x64
22:09:08.0379 0472 Number of processors: 4
22:09:08.0379 0472 Page size: 0x1000
22:09:08.0379 0472 Boot type: Normal boot
22:09:08.0379 0472 ============================================================
22:09:09.0955 0472 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
22:09:09.0955 0472 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:09:10.0002 0472 ============================================================
22:09:10.0002 0472 \Device\Harddisk0\DR0:
22:09:10.0017 0472 MBR partitions:
22:09:10.0017 0472 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:09:10.0017 0472 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xC31E000
22:09:10.0017 0472 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xC350800, BlocksNum 0x683B5800
22:09:10.0017 0472 \Device\Harddisk1\DR1:
22:09:10.0033 0472 MBR partitions:
22:09:10.0033 0472 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x57545000
22:09:10.0033 0472 ============================================================
22:09:10.0111 0472 C: <-> \Device\Harddisk0\DR0\Partition2
22:09:10.0142 0472 D: <-> \Device\Harddisk1\DR1\Partition1
22:09:10.0205 0472 E: <-> \Device\Harddisk0\DR0\Partition3
22:09:10.0205 0472 ============================================================
22:09:10.0205 0472 Initialize success
22:09:10.0205 0472 ============================================================
22:09:15.0883 3856 ============================================================
22:09:15.0883 3856 Scan started
22:09:15.0883 3856 Mode: Manual;
22:09:15.0883 3856 ============================================================
22:09:16.0710 3856 ================ Scan system memory ========================
22:09:16.0710 3856 System memory - ok
22:09:16.0710 3856 ================ Scan services =============================
22:09:16.0850 3856 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:09:16.0850 3856 1394ohci - ok
22:09:16.0897 3856 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:09:16.0897 3856 ACPI - ok
22:09:16.0913 3856 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:09:16.0913 3856 AcpiPmi - ok
22:09:17.0006 3856 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:09:17.0006 3856 AdobeARMservice - ok
22:09:17.0100 3856 [ 479901C99FA62D1C3261B7ACB1228DAD ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:09:17.0100 3856 AdobeFlashPlayerUpdateSvc - ok
22:09:17.0115 3856 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
22:09:17.0131 3856 adp94xx - ok
22:09:17.0147 3856 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
22:09:17.0147 3856 adpahci - ok
22:09:17.0178 3856 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
22:09:17.0178 3856 adpu320 - ok
22:09:17.0334 3856 [ 8539A04EEE824B24A86E7317AB64DFBE ] AdvancedSystemCareService6 E:\Advanced SystemCare Ultimate\ascsvc.exe
22:09:17.0349 3856 AdvancedSystemCareService6 - ok
22:09:17.0381 3856 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:09:17.0396 3856 AeLookupSvc - ok
22:09:17.0427 3856 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
22:09:17.0427 3856 AFD - ok
22:09:17.0443 3856 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
22:09:17.0443 3856 agp440 - ok
22:09:17.0474 3856 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
22:09:17.0474 3856 ALG - ok
22:09:17.0505 3856 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
22:09:17.0505 3856 aliide - ok
22:09:17.0505 3856 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
22:09:17.0505 3856 amdide - ok
22:09:17.0537 3856 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:09:17.0537 3856 AmdK8 - ok
22:09:17.0552 3856 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
22:09:17.0568 3856 AmdPPM - ok
22:09:17.0599 3856 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:09:17.0599 3856 amdsata - ok
22:09:17.0630 3856 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
22:09:17.0630 3856 amdsbs - ok
22:09:17.0646 3856 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:09:17.0646 3856 amdxata - ok
22:09:17.0677 3856 [ E71711D37C48AC40FD3E2866A5ABBA51 ] anvsnddrv C:\Windows\system32\drivers\anvsnddrv.sys
22:09:17.0677 3856 anvsnddrv - ok
22:09:17.0708 3856 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
22:09:17.0708 3856 AppID - ok
22:09:17.0755 3856 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:09:17.0755 3856 AppIDSvc - ok
22:09:17.0786 3856 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
22:09:17.0786 3856 Appinfo - ok
22:09:17.0802 3856 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
22:09:17.0817 3856 AppMgmt - ok
22:09:17.0817 3856 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
22:09:17.0817 3856 arc - ok
22:09:17.0817 3856 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
22:09:17.0817 3856 arcsas - ok
22:09:17.0849 3856 [ E85EA064C10E4B3EC1029B598D0589C6 ] ASCAntivirusSrv E:\Advanced SystemCare Ultimate\ascavsvc.exe
22:09:17.0864 3856 ASCAntivirusSrv - ok
22:09:17.0927 3856 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:09:17.0958 3856 aspnet_state - ok
22:09:17.0989 3856 [ F3F5F2FDE0DEABA4F2CE336E9454FAE2 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
22:09:17.0989 3856 aswFsBlk - ok
22:09:18.0036 3856 [ E37E33F5B710FA130E6C328332B50FC1 ] aswFW C:\Windows\system32\drivers\aswFW.sys
22:09:18.0036 3856 aswFW - ok
22:09:18.0036 3856 [ 7BA96B748762759E5AC844DE672A49AD ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
22:09:18.0036 3856 aswKbd - ok
22:09:18.0067 3856 [ 90980D5291F8E725700272E4B64EDA10 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
22:09:18.0067 3856 aswMonFlt - ok
22:09:18.0114 3856 [ 518B8D447A1975AB46DA093A2E743256 ] aswNdis C:\Windows\system32\DRIVERS\aswNdis.sys
22:09:18.0114 3856 aswNdis - ok
22:09:18.0145 3856 [ 157F3CBFD8FFA55D2964A934075D179F ] aswNdis2 C:\Windows\system32\drivers\aswNdis2.sys
22:09:18.0145 3856 aswNdis2 - ok
22:09:18.0161 3856 [ A4C94945B8A1FFE449A500C2CF0B5882 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
22:09:18.0161 3856 aswRdr - ok
22:09:18.0192 3856 [ A06E330475C1957C50C13B483D41F2BD ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
22:09:18.0192 3856 aswRvrt - ok
22:09:18.0285 3856 [ 9237BE2AB3C7D611F1F8FB7018691BAC ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
22:09:18.0285 3856 aswSnx - ok
22:09:18.0348 3856 [ D8FEC7F7BFE1BAD685DC8D1EF384693D ] aswSP C:\Windows\system32\drivers\aswSP.sys
22:09:18.0348 3856 aswSP - ok
22:09:18.0379 3856 [ 3D9BA0EF6C5847E4482FC01ABCD26683 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
22:09:18.0379 3856 aswTdi - ok
22:09:18.0426 3856 [ 3C7D772F6059C142991D00FE3AB61D40 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
22:09:18.0426 3856 aswVmm - ok
22:09:18.0441 3856 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:09:18.0457 3856 AsyncMac - ok
22:09:18.0488 3856 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
22:09:18.0488 3856 atapi - ok
22:09:18.0535 3856 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:09:18.0566 3856 AudioEndpointBuilder - ok
22:09:18.0582 3856 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
22:09:18.0582 3856 AudioSrv - ok
22:09:18.0644 3856 [ 6F702A7EA2D5F2B55CC90C333FBE9978 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:09:18.0644 3856 avast! Antivirus - ok
22:09:18.0675 3856 [ 214AA6F5F763B966BE2680DBEF0D8280 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
22:09:18.0675 3856 avast! Firewall - ok
22:09:18.0753 3856 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:09:18.0769 3856 AxInstSV - ok
22:09:18.0785 3856 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
22:09:18.0800 3856 b06bdrv - ok
22:09:18.0800 3856 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
22:09:18.0816 3856 b57nd60a - ok
22:09:18.0831 3856 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
22:09:18.0847 3856 BDESVC - ok
22:09:18.0847 3856 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
22:09:18.0847 3856 Beep - ok
22:09:18.0878 3856 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
22:09:18.0878 3856 BFE - ok
22:09:18.0909 3856 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
22:09:18.0925 3856 BITS - ok
22:09:18.0925 3856 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:09:18.0925 3856 blbdrive - ok
22:09:18.0956 3856 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:09:18.0956 3856 bowser - ok
22:09:18.0956 3856 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:09:18.0956 3856 BrFiltLo - ok
22:09:18.0972 3856 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:09:18.0972 3856 BrFiltUp - ok
22:09:18.0972 3856 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
22:09:18.0972 3856 BridgeMP - ok
22:09:18.0987 3856 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
22:09:18.0987 3856 Browser - ok
22:09:19.0003 3856 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:09:19.0003 3856 Brserid - ok
22:09:19.0003 3856 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:09:19.0003 3856 BrSerWdm - ok
22:09:19.0003 3856 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:09:19.0003 3856 BrUsbMdm - ok
22:09:19.0003 3856 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:09:19.0003 3856 BrUsbSer - ok
22:09:19.0019 3856 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
22:09:19.0019 3856 BTHMODEM - ok
22:09:19.0034 3856 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
22:09:19.0034 3856 bthserv - ok
22:09:19.0050 3856 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:09:19.0050 3856 cdfs - ok
22:09:19.0065 3856 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:09:19.0065 3856 cdrom - ok
22:09:19.0097 3856 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
22:09:19.0097 3856 CertPropSvc - ok
22:09:19.0097 3856 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
22:09:19.0097 3856 circlass - ok
22:09:19.0112 3856 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
22:09:19.0112 3856 CLFS - ok
22:09:19.0159 3856 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:09:19.0159 3856 clr_optimization_v2.0.50727_32 - ok
22:09:19.0190 3856 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:09:19.0190 3856 clr_optimization_v2.0.50727_64 - ok
22:09:19.0253 3856 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:09:19.0268 3856 clr_optimization_v4.0.30319_32 - ok
22:09:19.0284 3856 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:09:19.0299 3856 clr_optimization_v4.0.30319_64 - ok
22:09:19.0299 3856 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:09:19.0299 3856 CmBatt - ok
22:09:19.0315 3856 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:09:19.0315 3856 cmdide - ok
22:09:19.0377 3856 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
22:09:19.0377 3856 CNG - ok
22:09:19.0409 3856 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:09:19.0409 3856 Compbatt - ok
22:09:19.0424 3856 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
22:09:19.0424 3856 CompositeBus - ok
22:09:19.0424 3856 COMSysApp - ok
22:09:19.0440 3856 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
22:09:19.0440 3856 crcdisk - ok
22:09:19.0471 3856 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:09:19.0487 3856 CryptSvc - ok
22:09:19.0502 3856 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
22:09:19.0502 3856 CSC - ok
22:09:19.0518 3856 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
22:09:19.0518 3856 CscService - ok
22:09:19.0549 3856 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:09:19.0549 3856 DcomLaunch - ok
22:09:19.0580 3856 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
22:09:19.0580 3856 defragsvc - ok
22:09:19.0596 3856 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:09:19.0596 3856 DfsC - ok
22:09:19.0611 3856 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
22:09:19.0611 3856 Dhcp - ok
22:09:19.0627 3856 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
22:09:19.0627 3856 discache - ok
22:09:19.0643 3856 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
22:09:19.0643 3856 Disk - ok
22:09:19.0658 3856 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:09:19.0658 3856 Dnscache - ok
22:09:19.0689 3856 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
22:09:19.0705 3856 dot3svc - ok
22:09:19.0705 3856 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
22:09:19.0721 3856 DPS - ok
22:09:19.0736 3856 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:09:19.0736 3856 drmkaud - ok
22:09:19.0752 3856 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
22:09:19.0767 3856 dtsoftbus01 - ok
22:09:19.0861 3856 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:09:19.0861 3856 DXGKrnl - ok
22:09:19.0892 3856 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
22:09:19.0892 3856 EapHost - ok
22:09:19.0955 3856 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
22:09:19.0970 3856 ebdrv - ok
22:09:19.0986 3856 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
22:09:19.0986 3856 EFS - ok
22:09:20.0033 3856 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:09:20.0033 3856 ehRecvr - ok
22:09:20.0079 3856 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
22:09:20.0079 3856 ehSched - ok
22:09:20.0111 3856 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
22:09:20.0111 3856 elxstor - ok
22:09:20.0157 3856 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:09:20.0157 3856 ErrDev - ok
22:09:20.0189 3856 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
22:09:20.0189 3856 EventSystem - ok
22:09:20.0204 3856 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
22:09:20.0204 3856 exfat - ok
22:09:20.0235 3856 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:09:20.0235 3856 fastfat - ok
22:09:20.0267 3856 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
22:09:20.0267 3856 Fax - ok
22:09:20.0267 3856 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:09:20.0267 3856 fdc - ok
22:09:20.0282 3856 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
22:09:20.0282 3856 fdPHost - ok
22:09:20.0298 3856 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
22:09:20.0298 3856 FDResPub - ok
22:09:20.0298 3856 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:09:20.0298 3856 FileInfo - ok
22:09:20.0313 3856 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:09:20.0313 3856 Filetrace - ok
22:09:20.0329 3856 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:09:20.0329 3856 flpydisk - ok
22:09:20.0345 3856 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:09:20.0345 3856 FltMgr - ok
22:09:20.0391 3856 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
22:09:20.0391 3856 FontCache - ok
22:09:20.0438 3856 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:09:20.0438 3856 FontCache3.0.0.0 - ok
22:09:20.0454 3856 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:09:20.0454 3856 FsDepends - ok
22:09:20.0485 3856 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:09:20.0485 3856 Fs_Rec - ok
22:09:20.0516 3856 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:09:20.0516 3856 fvevol - ok
22:09:20.0547 3856 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
22:09:20.0547 3856 gagp30kx - ok
22:09:20.0547 3856 gdrv - ok
22:09:20.0625 3856 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
22:09:20.0641 3856 gpsvc - ok
22:09:20.0672 3856 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:09:20.0672 3856 gupdate - ok
22:09:20.0688 3856 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:09:20.0688 3856 gupdatem - ok
22:09:20.0703 3856 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:09:20.0703 3856 hcw85cir - ok
22:09:20.0703 3856 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:09:20.0719 3856 HdAudAddService - ok
22:09:20.0719 3856 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
22:09:20.0719 3856 HDAudBus - ok
22:09:20.0735 3856 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
22:09:20.0735 3856 HidBatt - ok
22:09:20.0735 3856 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
22:09:20.0735 3856 HidBth - ok
22:09:20.0735 3856 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
22:09:20.0735 3856 HidIr - ok
22:09:20.0766 3856 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
22:09:20.0766 3856 hidserv - ok
22:09:20.0781 3856 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:09:20.0781 3856 HidUsb - ok
22:09:20.0813 3856 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:09:20.0813 3856 hkmsvc - ok
22:09:20.0828 3856 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:09:20.0828 3856 HomeGroupListener - ok
22:09:20.0859 3856 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:09:20.0859 3856 HomeGroupProvider - ok
22:09:20.0875 3856 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:09:20.0875 3856 HpSAMD - ok
22:09:20.0906 3856 [ 4E9CAE3200A46135DE01CE22BAF832BE ] HPSIService C:\Windows\system32\HPSIsvc.exe
22:09:20.0906 3856 HPSIService - ok
22:09:20.0922 3856 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:09:20.0922 3856 HTTP - ok
22:09:20.0937 3856 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:09:20.0937 3856 hwpolicy - ok
22:09:20.0969 3856 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:09:20.0969 3856 i8042prt - ok
22:09:21.0031 3856 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:09:21.0047 3856 iaStorV - ok
22:09:21.0171 3856 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:09:21.0203 3856 idsvc - ok
22:09:21.0218 3856 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
22:09:21.0218 3856 iirsp - ok
22:09:21.0249 3856 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
22:09:21.0249 3856 IKEEXT - ok
22:09:21.0265 3856 IntcAzAudAddService - ok
22:09:21.0281 3856 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
22:09:21.0281 3856 intelide - ok
22:09:21.0296 3856 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:09:21.0296 3856 intelppm - ok
22:09:21.0312 3856 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:09:21.0327 3856 IPBusEnum - ok
22:09:21.0343 3856 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:09:21.0343 3856 IpFilterDriver - ok
22:09:21.0359 3856 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:09:21.0374 3856 iphlpsvc - ok
22:09:21.0390 3856 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:09:21.0390 3856 IPMIDRV - ok
22:09:21.0390 3856 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:09:21.0390 3856 IPNAT - ok
22:09:21.0405 3856 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:09:21.0405 3856 IRENUM - ok
22:09:21.0437 3856 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:09:21.0437 3856 isapnp - ok
22:09:21.0437 3856 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:09:21.0452 3856 iScsiPrt - ok
22:09:21.0452 3856 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:09:21.0452 3856 kbdclass - ok
22:09:21.0468 3856 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:09:21.0468 3856 kbdhid - ok
22:09:21.0483 3856 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
22:09:21.0483 3856 KeyIso - ok
22:09:21.0515 3856 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:09:21.0515 3856 KSecDD - ok
22:09:21.0546 3856 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:09:21.0546 3856 KSecPkg - ok
22:09:21.0593 3856 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
22:09:21.0593 3856 ksthunk - ok
22:09:21.0624 3856 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
22:09:21.0624 3856 KtmRm - ok
22:09:21.0639 3856 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
22:09:21.0655 3856 LanmanServer - ok
22:09:21.0686 3856 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:09:21.0686 3856 LanmanWorkstation - ok
22:09:21.0702 3856 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:09:21.0702 3856 lltdio - ok
22:09:21.0717 3856 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:09:21.0717 3856 lltdsvc - ok
22:09:21.0733 3856 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:09:21.0733 3856 lmhosts - ok
22:09:21.0749 3856 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
22:09:21.0749 3856 LSI_FC - ok
22:09:21.0749 3856 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
22:09:21.0749 3856 LSI_SAS - ok
22:09:21.0764 3856 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:09:21.0764 3856 LSI_SAS2 - ok
22:09:21.0764 3856 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:09:21.0764 3856 LSI_SCSI - ok
22:09:21.0780 3856 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
22:09:21.0780 3856 luafv - ok
22:09:21.0795 3856 [ 8B03202C731A0B967927EB7E5B2E470C ] mbamchameleon C:\Windows\system32\drivers\mbamchameleon.sys
22:09:21.0795 3856 mbamchameleon - ok
22:09:21.0827 3856 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
22:09:21.0827 3856 MBAMProtector - ok
22:09:21.0873 3856 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler E:\Malwarebytes' Anti-Malware\mbamscheduler.exe
22:09:21.0873 3856 MBAMScheduler - ok
22:09:21.0905 3856 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService E:\Malwarebytes' Anti-Malware\mbamservice.exe
22:09:21.0905 3856 MBAMService - ok
22:09:21.0936 3856 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:09:21.0936 3856 Mcx2Svc - ok
22:09:21.0967 3856 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
22:09:21.0967 3856 megasas - ok
22:09:21.0983 3856 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
22:09:21.0983 3856 MegaSR - ok
22:09:21.0998 3856 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
22:09:21.0998 3856 MEIx64 - ok
22:09:22.0029 3856 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
22:09:22.0045 3856 MMCSS - ok
22:09:22.0045 3856 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
22:09:22.0045 3856 Modem - ok
22:09:22.0061 3856 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:09:22.0061 3856 monitor - ok
22:09:22.0092 3856 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:09:22.0092 3856 mouclass - ok
22:09:22.0107 3856 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:09:22.0107 3856 mouhid - ok
22:09:22.0123 3856 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:09:22.0123 3856 mountmgr - ok
22:09:22.0154 3856 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
22:09:22.0154 3856 mpio - ok
22:09:22.0170 3856 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:09:22.0170 3856 mpsdrv - ok
22:09:22.0248 3856 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:09:22.0263 3856 MpsSvc - ok
22:09:22.0279 3856 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:09:22.0279 3856 MRxDAV - ok
22:09:22.0295 3856 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:09:22.0295 3856 mrxsmb - ok
22:09:22.0310 3856 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:09:22.0310 3856 mrxsmb10 - ok
22:09:22.0326 3856 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:09:22.0326 3856 mrxsmb20 - ok
22:09:22.0341 3856 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
22:09:22.0341 3856 msahci - ok
22:09:22.0341 3856 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:09:22.0341 3856 msdsm - ok
22:09:22.0388 3856 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
22:09:22.0388 3856 MSDTC - ok
22:09:22.0404 3856 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:09:22.0404 3856 Msfs - ok
22:09:22.0404 3856 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:09:22.0404 3856 mshidkmdf - ok
22:09:22.0419 3856 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:09:22.0419 3856 msisadrv - ok
22:09:22.0435 3856 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:09:22.0435 3856 MSiSCSI - ok
22:09:22.0451 3856 msiserver - ok
22:09:22.0451 3856 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:09:22.0451 3856 MSKSSRV - ok
22:09:22.0451 3856 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:09:22.0451 3856 MSPCLOCK - ok
22:09:22.0466 3856 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:09:22.0466 3856 MSPQM - ok
22:09:22.0482 3856 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:09:22.0482 3856 MsRPC - ok
22:09:22.0497 3856 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
22:09:22.0497 3856 mssmbios - ok
22:09:22.0497 3856 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:09:22.0497 3856 MSTEE - ok
22:09:22.0513 3856 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
22:09:22.0513 3856 MTConfig - ok
22:09:22.0529 3856 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
22:09:22.0529 3856 Mup - ok
22:09:22.0544 3856 [ 705E9675014EB688BEDD967B1ABECF19 ] mvusbews C:\Windows\system32\Drivers\mvusbews.sys
22:09:22.0560 3856 mvusbews - ok
22:09:22.0622 3856 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
22:09:22.0622 3856 napagent - ok
22:09:22.0653 3856 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:09:22.0653 3856 NativeWifiP - ok
22:09:22.0778 3856 [ 3BAE2BFCB6D69E19C8373F635DD544DC ] NBService C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
22:09:22.0778 3856 NBService - ok
22:09:22.0841 3856 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:09:22.0841 3856 NDIS - ok
22:09:22.0856 3856 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:09:22.0856 3856 NdisCap - ok
22:09:22.0903 3856 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:09:22.0903 3856 NdisTapi - ok
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 22:11

22:09:22.0934 3856 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:09:22.0934 3856 Ndisuio - ok
22:09:22.0965 3856 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:09:22.0965 3856 NdisWan - ok
22:09:22.0997 3856 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:09:22.0997 3856 NDProxy - ok
22:09:23.0012 3856 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:09:23.0012 3856 NetBIOS - ok
22:09:23.0043 3856 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:09:23.0043 3856 NetBT - ok
22:09:23.0059 3856 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
22:09:23.0059 3856 Netlogon - ok
22:09:23.0106 3856 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
22:09:23.0106 3856 Netman - ok
22:09:23.0121 3856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:23.0121 3856 NetMsmqActivator - ok
22:09:23.0137 3856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:23.0137 3856 NetPipeActivator - ok
22:09:23.0153 3856 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
22:09:23.0153 3856 netprofm - ok
22:09:23.0153 3856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:23.0153 3856 NetTcpActivator - ok
22:09:23.0153 3856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:23.0153 3856 NetTcpPortSharing - ok
22:09:23.0168 3856 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
22:09:23.0168 3856 nfrd960 - ok
22:09:23.0184 3856 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:09:23.0199 3856 NlaSvc - ok
22:09:23.0277 3856 [ 193FA51DDDD0BFFDED1C340F0434999A ] NMIndexingService C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
22:09:23.0277 3856 NMIndexingService - ok
22:09:23.0309 3856 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:09:23.0309 3856 Npfs - ok
22:09:23.0340 3856 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
22:09:23.0340 3856 nsi - ok
22:09:23.0340 3856 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:09:23.0340 3856 nsiproxy - ok
22:09:23.0387 3856 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:09:23.0387 3856 Ntfs - ok
22:09:23.0402 3856 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
22:09:23.0402 3856 Null - ok
22:09:23.0433 3856 [ B4F53BCA4C688FF47F04FA90098F896E ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
22:09:23.0433 3856 NVHDA - ok
22:09:23.0761 3856 [ 4EE399576F76D38C04745DB739BBC8C7 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:09:23.0808 3856 nvlddmkm - ok
22:09:23.0855 3856 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:09:23.0855 3856 nvraid - ok
22:09:23.0886 3856 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:09:23.0901 3856 nvstor - ok
22:09:23.0964 3856 [ 7335C3D78A7746D76D37F6722CC4A466 ] nvsvc C:\Windows\system32\nvvsvc.exe
22:09:23.0979 3856 nvsvc - ok
22:09:24.0120 3856 [ B7C53DA1C73FF39F4A6248643EFD979A ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
22:09:24.0120 3856 nvUpdatusService - ok
22:09:24.0151 3856 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:09:24.0151 3856 nv_agp - ok
22:09:24.0276 3856 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:09:24.0276 3856 odserv - ok
22:09:24.0323 3856 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
22:09:24.0323 3856 ohci1394 - ok
22:09:24.0369 3856 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:09:24.0369 3856 ose - ok
22:09:24.0447 3856 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:09:24.0447 3856 p2pimsvc - ok
22:09:24.0463 3856 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
22:09:24.0479 3856 p2psvc - ok
22:09:24.0510 3856 [ 3A6DCEB1848470320E4A3C12D7A35B1C ] PAC207 C:\Windows\system32\DRIVERS\PFC027.SYS
22:09:24.0510 3856 PAC207 - ok
22:09:24.0525 3856 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
22:09:24.0525 3856 Parport - ok
22:09:24.0557 3856 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:09:24.0557 3856 partmgr - ok
22:09:24.0572 3856 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
22:09:24.0588 3856 PcaSvc - ok
22:09:24.0603 3856 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
22:09:24.0603 3856 pci - ok
22:09:24.0619 3856 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
22:09:24.0619 3856 pciide - ok
22:09:24.0635 3856 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
22:09:24.0635 3856 pcmcia - ok
22:09:24.0635 3856 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
22:09:24.0635 3856 pcw - ok
22:09:24.0650 3856 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:09:24.0666 3856 PEAUTH - ok
22:09:24.0759 3856 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
22:09:24.0775 3856 PeerDistSvc - ok
22:09:24.0837 3856 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
22:09:24.0853 3856 PerfHost - ok
22:09:24.0900 3856 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
22:09:24.0931 3856 pla - ok
22:09:24.0947 3856 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\SysWOW64\IoctlSvc.exe
22:09:24.0947 3856 PLFlash DeviceIoControl Service - ok
22:09:24.0978 3856 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:09:24.0978 3856 PlugPlay - ok
22:09:24.0978 3856 PnkBstrA - ok
22:09:24.0993 3856 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:09:24.0993 3856 PNRPAutoReg - ok
22:09:25.0009 3856 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:09:25.0009 3856 PNRPsvc - ok
22:09:25.0025 3856 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:09:25.0040 3856 PolicyAgent - ok
22:09:25.0071 3856 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
22:09:25.0071 3856 Power - ok
22:09:25.0087 3856 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:09:25.0103 3856 PptpMiniport - ok
22:09:25.0118 3856 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
22:09:25.0118 3856 Processor - ok
22:09:25.0134 3856 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
22:09:25.0134 3856 ProfSvc - ok
22:09:25.0149 3856 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:09:25.0149 3856 ProtectedStorage - ok
22:09:25.0165 3856 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:09:25.0165 3856 Psched - ok
22:09:25.0212 3856 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
22:09:25.0212 3856 ql2300 - ok
22:09:25.0227 3856 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
22:09:25.0227 3856 ql40xx - ok
22:09:25.0243 3856 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
22:09:25.0259 3856 QWAVE - ok
22:09:25.0259 3856 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:09:25.0274 3856 QWAVEdrv - ok
22:09:25.0274 3856 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:09:25.0274 3856 RasAcd - ok
22:09:25.0305 3856 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:09:25.0305 3856 RasAgileVpn - ok
22:09:25.0305 3856 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
22:09:25.0305 3856 RasAuto - ok
22:09:25.0337 3856 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:09:25.0337 3856 Rasl2tp - ok
22:09:25.0368 3856 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
22:09:25.0368 3856 RasMan - ok
22:09:25.0383 3856 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:09:25.0383 3856 RasPppoe - ok
22:09:25.0399 3856 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:09:25.0399 3856 RasSstp - ok
22:09:25.0415 3856 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:09:25.0430 3856 rdbss - ok
22:09:25.0430 3856 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
22:09:25.0430 3856 rdpbus - ok
22:09:25.0446 3856 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:09:25.0446 3856 RDPCDD - ok
22:09:25.0461 3856 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
22:09:25.0461 3856 RDPDR - ok
22:09:25.0477 3856 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:09:25.0477 3856 RDPENCDD - ok
22:09:25.0477 3856 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:09:25.0477 3856 RDPREFMP - ok
22:09:25.0508 3856 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
22:09:25.0508 3856 RdpVideoMiniport - ok
22:09:25.0555 3856 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:09:25.0555 3856 RDPWD - ok
22:09:25.0586 3856 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:09:25.0586 3856 rdyboost - ok
22:09:25.0633 3856 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:09:25.0633 3856 RemoteAccess - ok
22:09:25.0649 3856 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:09:25.0664 3856 RemoteRegistry - ok
22:09:25.0664 3856 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:09:25.0664 3856 RpcEptMapper - ok
22:09:25.0680 3856 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
22:09:25.0680 3856 RpcLocator - ok
22:09:25.0711 3856 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
22:09:25.0711 3856 RpcSs - ok
22:09:25.0727 3856 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:09:25.0727 3856 rspndr - ok
22:09:25.0742 3856 [ 6D3C7E7D82D3DC92DC2A8B0DF9F20F8A ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
22:09:25.0742 3856 RTL8167 - ok
22:09:25.0773 3856 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
22:09:25.0773 3856 s3cap - ok
22:09:25.0789 3856 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
22:09:25.0789 3856 SamSs - ok
22:09:25.0805 3856 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:09:25.0805 3856 sbp2port - ok
22:09:25.0836 3856 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:09:25.0851 3856 SCardSvr - ok
22:09:25.0867 3856 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:09:25.0867 3856 scfilter - ok
22:09:25.0883 3856 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
22:09:25.0898 3856 Schedule - ok
22:09:25.0914 3856 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
22:09:25.0914 3856 SCPolicySvc - ok
22:09:25.0945 3856 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:09:25.0945 3856 SDRSVC - ok
22:09:25.0945 3856 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:09:25.0945 3856 secdrv - ok
22:09:25.0976 3856 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
22:09:25.0976 3856 seclogon - ok
22:09:25.0976 3856 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
22:09:25.0976 3856 SENS - ok
22:09:25.0992 3856 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:09:25.0992 3856 SensrSvc - ok
22:09:26.0007 3856 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
22:09:26.0007 3856 Serenum - ok
22:09:26.0023 3856 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
22:09:26.0023 3856 Serial - ok
22:09:26.0054 3856 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
22:09:26.0054 3856 sermouse - ok
22:09:26.0070 3856 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
22:09:26.0070 3856 SessionEnv - ok
22:09:26.0085 3856 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
22:09:26.0085 3856 sffdisk - ok
22:09:26.0101 3856 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:09:26.0101 3856 sffp_mmc - ok
22:09:26.0117 3856 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
22:09:26.0117 3856 sffp_sd - ok
22:09:26.0132 3856 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
22:09:26.0132 3856 sfloppy - ok
22:09:26.0163 3856 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:09:26.0163 3856 SharedAccess - ok
22:09:26.0179 3856 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:09:26.0179 3856 ShellHWDetection - ok
22:09:26.0195 3856 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:09:26.0195 3856 SiSRaid2 - ok
22:09:26.0195 3856 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
22:09:26.0195 3856 SiSRaid4 - ok
22:09:26.0241 3856 [ 3467821FD04A66C9786DF0C8C0219A73 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
22:09:26.0241 3856 SkypeUpdate - ok
22:09:26.0257 3856 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:09:26.0257 3856 Smb - ok
22:09:26.0273 3856 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:09:26.0273 3856 SNMPTRAP - ok
22:09:26.0288 3856 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
22:09:26.0288 3856 spldr - ok
22:09:26.0335 3856 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
22:09:26.0397 3856 Spooler - ok
22:09:26.0460 3856 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
22:09:26.0491 3856 sppsvc - ok
22:09:26.0522 3856 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:09:26.0522 3856 sppuinotify - ok
22:09:26.0538 3856 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
22:09:26.0538 3856 srv - ok
22:09:26.0569 3856 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:09:26.0569 3856 srv2 - ok
22:09:26.0569 3856 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:09:26.0569 3856 srvnet - ok
22:09:26.0585 3856 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:09:26.0585 3856 SSDPSRV - ok
22:09:26.0600 3856 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:09:26.0600 3856 SstpSvc - ok
22:09:26.0616 3856 [ EF806D212D34B0E173BAEB3564D53E37 ] ss_bbus C:\Windows\system32\DRIVERS\ss_bbus.sys
22:09:26.0616 3856 ss_bbus - ok
22:09:26.0631 3856 [ 08B1B34ABEBEB6AC2DEA06900C56411E ] ss_bmdfl C:\Windows\system32\DRIVERS\ss_bmdfl.sys
22:09:26.0631 3856 ss_bmdfl - ok
22:09:26.0631 3856 [ 71A9DA6BEAA4CB54DFB827FB78600A5D ] ss_bmdm C:\Windows\system32\DRIVERS\ss_bmdm.sys
22:09:26.0631 3856 ss_bmdm - ok
22:09:26.0709 3856 [ 81F177C1954453AF407604160BD149CB ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
22:09:26.0709 3856 Stereo Service - ok
22:09:26.0725 3856 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
22:09:26.0725 3856 stexstor - ok
22:09:26.0803 3856 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
22:09:26.0803 3856 stisvc - ok
22:09:26.0819 3856 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
22:09:26.0834 3856 storflt - ok
22:09:26.0834 3856 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
22:09:26.0834 3856 storvsc - ok
22:09:26.0850 3856 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
22:09:26.0850 3856 swenum - ok
22:09:26.0881 3856 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
22:09:26.0897 3856 swprv - ok
22:09:26.0912 3856 Synth3dVsc - ok
22:09:26.0943 3856 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
22:09:26.0959 3856 SysMain - ok
22:09:26.0975 3856 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:09:26.0975 3856 TabletInputService - ok
22:09:26.0990 3856 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
22:09:27.0006 3856 TapiSrv - ok
22:09:27.0006 3856 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
22:09:27.0006 3856 TBS - ok
22:09:27.0053 3856 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:09:27.0068 3856 Tcpip - ok
22:09:27.0084 3856 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:09:27.0084 3856 TCPIP6 - ok
22:09:27.0115 3856 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:09:27.0115 3856 tcpipreg - ok
22:09:27.0131 3856 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:09:27.0131 3856 TDPIPE - ok
22:09:27.0162 3856 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:09:27.0177 3856 TDTCP - ok
22:09:27.0193 3856 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:09:27.0193 3856 tdx - ok
22:09:27.0224 3856 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
22:09:27.0224 3856 TermDD - ok
22:09:27.0271 3856 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
22:09:27.0271 3856 TermService - ok
22:09:27.0287 3856 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
22:09:27.0302 3856 Themes - ok
22:09:27.0318 3856 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
22:09:27.0318 3856 THREADORDER - ok
22:09:27.0333 3856 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
22:09:27.0333 3856 TrkWks - ok
22:09:27.0365 3856 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:09:27.0365 3856 TrustedInstaller - ok
22:09:27.0380 3856 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:09:27.0380 3856 tssecsrv - ok
22:09:27.0411 3856 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
22:09:27.0411 3856 TsUsbFlt - ok
22:09:27.0411 3856 tsusbhub - ok
22:09:27.0427 3856 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:09:27.0427 3856 tunnel - ok
22:09:27.0443 3856 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
22:09:27.0443 3856 uagp35 - ok
22:09:27.0474 3856 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:09:27.0474 3856 udfs - ok
22:09:27.0489 3856 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:09:27.0505 3856 UI0Detect - ok
22:09:27.0552 3856 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:09:27.0552 3856 uliagpkx - ok
22:09:27.0567 3856 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
22:09:27.0567 3856 umbus - ok
22:09:27.0583 3856 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
22:09:27.0583 3856 UmPass - ok
22:09:27.0599 3856 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
22:09:27.0599 3856 UmRdpService - ok
22:09:27.0630 3856 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
22:09:27.0630 3856 upnphost - ok
22:09:27.0645 3856 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:09:27.0645 3856 usbccgp - ok
22:09:27.0661 3856 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:09:27.0661 3856 usbcir - ok
22:09:27.0661 3856 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:09:27.0677 3856 usbehci - ok
22:09:27.0677 3856 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:09:27.0692 3856 usbhub - ok
22:09:27.0692 3856 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
22:09:27.0708 3856 usbohci - ok
22:09:27.0723 3856 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:09:27.0723 3856 usbprint - ok
22:09:27.0755 3856 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
22:09:27.0755 3856 usbscan - ok
22:09:27.0786 3856 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:09:27.0786 3856 USBSTOR - ok
22:09:27.0801 3856 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
22:09:27.0801 3856 usbuhci - ok
22:09:27.0848 3856 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
22:09:27.0864 3856 UxSms - ok
22:09:27.0864 3856 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
22:09:27.0864 3856 VaultSvc - ok
22:09:27.0879 3856 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
22:09:27.0879 3856 vdrvroot - ok
22:09:27.0911 3856 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
22:09:27.0926 3856 vds - ok
22:09:27.0926 3856 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:09:27.0926 3856 vga - ok
22:09:27.0942 3856 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
22:09:27.0942 3856 VgaSave - ok
22:09:27.0942 3856 VGPU - ok
22:09:27.0989 3856 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
22:09:27.0989 3856 vhdmp - ok
22:09:28.0020 3856 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
22:09:28.0020 3856 viaide - ok
22:09:28.0035 3856 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
22:09:28.0035 3856 vmbus - ok
22:09:28.0051 3856 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
22:09:28.0051 3856 VMBusHID - ok
22:09:28.0067 3856 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:09:28.0067 3856 volmgr - ok
22:09:28.0113 3856 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:09:28.0113 3856 volmgrx - ok
22:09:28.0145 3856 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:09:28.0145 3856 volsnap - ok
22:09:28.0160 3856 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
22:09:28.0160 3856 vsmraid - ok
22:09:28.0254 3856 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
22:09:28.0269 3856 VSS - ok
22:09:28.0269 3856 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
22:09:28.0269 3856 vwifibus - ok
22:09:28.0301 3856 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
22:09:28.0301 3856 W32Time - ok
22:09:28.0316 3856 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
22:09:28.0316 3856 WacomPen - ok
22:09:28.0332 3856 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:09:28.0332 3856 WANARP - ok
22:09:28.0332 3856 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:09:28.0332 3856 Wanarpv6 - ok
22:09:28.0363 3856 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
22:09:28.0363 3856 WatAdminSvc - ok
22:09:28.0488 3856 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
22:09:28.0503 3856 wbengine - ok
22:09:28.0581 3856 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:09:28.0581 3856 WbioSrvc - ok
22:09:28.0597 3856 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:09:28.0613 3856 wcncsvc - ok
22:09:28.0613 3856 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:09:28.0613 3856 WcsPlugInService - ok
22:09:28.0628 3856 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
22:09:28.0628 3856 Wd - ok
22:09:28.0644 3856 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:09:28.0659 3856 Wdf01000 - ok
22:09:28.0675 3856 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:09:28.0675 3856 WdiServiceHost - ok
22:09:28.0675 3856 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:09:28.0691 3856 WdiSystemHost - ok
22:09:28.0706 3856 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
22:09:28.0706 3856 WebClient - ok
22:09:28.0737 3856 [ D5BA7D43FA2EF656BF7E98A188391E40 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:09:28.0737 3856 Wecsvc - ok
22:09:28.0753 3856 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:09:28.0769 3856 wercplsupport - ok
22:09:28.0769 3856 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
22:09:28.0769 3856 WerSvc - ok
22:09:28.0784 3856 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:09:28.0784 3856 WfpLwf - ok
22:09:28.0784 3856 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:09:28.0784 3856 WIMMount - ok
22:09:28.0800 3856 WinDefend - ok
22:09:28.0800 3856 WinHttpAutoProxySvc - ok
22:09:29.0034 3856 [ 136760C1E9697BAF4ECDEAE5590A0806 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:09:29.0034 3856 Winmgmt - ok
22:09:29.0471 3856 [ 3BB6B401A780BF434C8F58137DE10BF7 ] WinRM C:\Windows\system32\WsmSvc.dll
22:09:29.0502 3856 WinRM - ok
22:09:29.0549 3856 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
22:09:29.0564 3856 Wlansvc - ok
22:09:29.0627 3856 [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:09:29.0642 3856 wlidsvc - ok
22:09:29.0658 3856 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
22:09:29.0658 3856 WmiAcpi - ok
22:09:29.0673 3856 [ 4DF841632B62A7CF19A79A05046A8AB1 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:09:29.0673 3856 wmiApSrv - ok
22:09:29.0705 3856 WMPNetworkSvc - ok
22:09:29.0720 3856 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:09:29.0736 3856 WPCSvc - ok
22:09:29.0751 3856 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:09:29.0751 3856 WPDBusEnum - ok
22:09:29.0783 3856 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:09:29.0783 3856 ws2ifsl - ok
22:09:29.0783 3856 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
22:09:29.0783 3856 wscsvc - ok
22:09:29.0783 3856 WSearch - ok
22:09:29.0845 3856 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
22:09:29.0892 3856 wuauserv - ok
22:09:29.0907 3856 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:09:29.0907 3856 WudfPf - ok
22:09:29.0923 3856 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:09:29.0923 3856 WUDFRd - ok
22:09:29.0939 3856 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:09:29.0939 3856 wudfsvc - ok
22:09:29.0954 3856 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
22:09:29.0954 3856 WwanSvc - ok
22:09:29.0970 3856 ================ Scan global ===============================
22:09:30.0001 3856 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
22:09:30.0032 3856 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:09:30.0032 3856 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:09:30.0048 3856 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
22:09:30.0063 3856 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
22:09:30.0079 3856 [Global] - ok
22:09:30.0079 3856 ================ Scan MBR ==================================
22:09:30.0079 3856 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:09:31.0077 3856 \Device\Harddisk0\DR0 - ok
22:09:31.0093 3856 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
22:09:31.0093 3856 \Device\Harddisk1\DR1 - ok
22:09:31.0093 3856 ================ Scan VBR ==================================
22:09:31.0109 3856 [ B06BECDA92B35D5CA38C7ACDB09B7DEA ] \Device\Harddisk0\DR0\Partition1
22:09:31.0109 3856 \Device\Harddisk0\DR0\Partition1 - ok
22:09:31.0124 3856 [ B6993455706825420E01637AFE435DF6 ] \Device\Harddisk0\DR0\Partition2
22:09:31.0140 3856 \Device\Harddisk0\DR0\Partition2 - ok
22:09:31.0155 3856 [ 4715BF6AA3CCAF3A2C7F62CD6F157E4A ] \Device\Harddisk0\DR0\Partition3
22:09:31.0171 3856 \Device\Harddisk0\DR0\Partition3 - ok
22:09:31.0171 3856 [ 9F6CD74A41C3F96A98C8B80C3D7E98FC ] \Device\Harddisk1\DR1\Partition1
22:09:31.0171 3856 \Device\Harddisk1\DR1\Partition1 - ok
22:09:31.0171 3856 ============================================================
22:09:31.0171 3856 Scan finished
22:09:31.0171 3856 ============================================================
22:09:31.0171 3996 Detected object count: 0
22:09:31.0171 3996 Actual detected object count: 0
22:09:40.0812 2508 Deinitialize success
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod jaro3 » 09 kvě 2013 22:25

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání skončeno "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Jak to vypadá nyní?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 22:49

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Zkuřka [Práva správce]
Mód : Odebrat -- Datum : 05/09/2013 22:48:34
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (190.7.212.30:3128) -> NEBYLO ODSTRANĚNO, POUŽIJTE PROXYFIX
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NAHRAZENO (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDS721010CLA632 ATA Device +++++
--- User ---
[MBR] 61f82927ed911fcd49265f84909aae5f
[BSP] c945ffedc6472dcf8bb589ce98e452b8 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 99900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 204802048 | Size: 853867 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SAMSUNG HD753LJ ATA Device +++++
--- User ---
[MBR] 4de7d93eebd0bde0a49f043689127bfa
[BSP] 86aeddf56fdaf8bcb32c67f734b60a62 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 715402 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[3]_D_05092013_02d2248.txt >>
RKreport[1]_S_05092013_02d2206.txt ; RKreport[2]_S_05092013_02d2247.txt ; RKreport[3]_D_05092013_02d2248.txt
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------

Uživatelský avatar
Scanner
Level 3.5
Level 3.5
Příspěvky: 771
Registrován: srpen 11
Bydliště: Střední čechy
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím kontrolu, podezření na spam v PC

Příspěvekod Scanner » 09 kvě 2013 23:06

Vypadá to že ty reklamy jsou pryč, párkrát jsem to projel a nic se my neukázalo. :D
Co teď s těmi programy, můžu je normálně vyhodit nebo to mám nějak odinstalovat?
When You smoke herb it reveals you to yourself. All the wickedness you do is revealed by the herb - it's you conscience and gives you an honest picture of yourself.
---------- Robert Nesta Marley ----------


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 82 hostů