Prosím o kontrolu logu - pomalý PC Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 21 lis 2013 13:40

Dobrý den, tento týden jsem měla problém s PC. Při spuštění se mi na obrazovce objevila hláška "NTLDR is missing". Vše jsme tady společně vyřešili. Od té doby mám ale pomalý pc, dlouho se načítají stránky na internetu, videa se sekají, a celkové je počítač jako šnek.
Prosím o kontrolu logu a navrhnutí dalšího postupu. Díky moc :-)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:30:12, on 21.11.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Cobian Backup 11\Cobian.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\Cobian Backup 11\cbInterface.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Cobian Backup 11\cbVSCService11.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Jitka Trnková\Dokumenty\Stažené soubory\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cobian Backup 11] "C:\Program Files\Cobian Backup 11\Cobian.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-854245398-220523388-1606980848-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'postgres')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8436779125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files\Cobian Backup 11\cbVSCService11.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:/postgreSQL/bin/pg_ctl.exe

--
End of file - 5925 bytes

Reklama
fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 21 lis 2013 18:17

Dle rad z minulosti, když byly problémy s PC, jsem provedla vyčištění PC programem ATF Cleaner. Poté jsem si stáhla program Malwarebytes' Anti-Malware a provedla kontrolu, a z kontroly zasílám log níže. Díky.

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.21.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jitka Trnková :: VCELICKA [administrátor]

Ochrana: Povolena

21.11.2013 17:33:45
MBAM-log-2013-11-21 (18-14-52).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215576
Uplynulý čas: 38 minut, 14 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 1
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod Orcus » 21 lis 2013 18:54

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

====================================================

Stáhni si Junkware Removal Tool

na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

====================================================

Znovu spusť MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 21 lis 2013 21:13

Hotovo. Zasílám logy.

AdwCleaner:

# AdwCleaner v3.012 - Report created 21/11/2013 at 20:24:36
# Updated 11/11/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Jitka Trnková - VCELICKA
# Running from : C:\Documents and Settings\Jitka Trnková\Dokumenty\Stažené soubory\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\END
Folder Found : C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
Folder Found C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\CT1750559
Folder Found C:\Documents and Settings\Jitka Trnková\Data aplikací\thinstall

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\smartbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\smartbar
Key Found : HKLM\Software\Conduit

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\prefs.js ]

Line Found : user_pref("CT1750559.FF19Solved", "true");
Line Found : user_pref("CT1750559.UserID", "UN21752994255855693");
Line Found : user_pref("CT1750559.fullUserID", "UN21752994255855693.IN.20131007114231");
Line Found : user_pref("CT1750559.installDate", "07/10/2013 11:42:36");
Line Found : user_pref("CT1750559.installSessionId", "15fe12e0-352c-4ca8-9c28-4816f3b24fab");
Line Found : user_pref("CT1750559.installSp", "FALSE");
Line Found : user_pref("CT1750559.installerVersion", "1.7.1.7");
Line Found : user_pref("CT1750559.keyword", "true");
Line Found : user_pref("CT1750559.originalSearchAddressUrl", "");
Line Found : user_pref("CT1750559.searchRevert", "false");
Line Found : user_pref("CT1750559.searchUserMode", "1");
Line Found : user_pref("CT1750559.versionFromInstaller", "10.20.1.8");
Line Found : user_pref("CT1750559.xpeMode", "0");
Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN21752994255855693&UM=1&q=");
Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT1750559");
Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN21752994255855693&UM=1&q=");
Line Found : user_pref("smartbar.machineId", "NIBQHN87FBZE97GCJQ6SHUHTCDSP7CN2AMF4RM+XK0BUVHFTVOODRCHHI+RBY5MBEZFHAFLDEACAKOUY3FYGKG");

*************************

AdwCleaner[R0].txt - [2710 octets] - [21/11/2013 20:24:36]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2770 octets] ##########



Junkware Removal Tool:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Microsoft Windows XP x86
Ran by Jitka Trnkov  on źt 21.11.2013 at 20:31:38,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit



~~~ Files

Successfully deleted: [File] "C:\end"



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Jitka Trnkov \Data aplikacˇ\thinstall"



~~~ FireFox

Successfully deleted the following from C:\Documents and Settings\Jitka Trnkov \Data aplikacˇ\mozilla\firefox\profiles\wxr3wktu.default\prefs.js

user_pref("CT1750559.FF19Solved", "true");
user_pref("CT1750559.UserID", "UN21752994255855693");
user_pref("CT1750559.fullUserID", "UN21752994255855693.IN.20131007114231");
user_pref("CT1750559.installDate", "07/10/2013 11:42:36");
user_pref("CT1750559.installSessionId", "15fe12e0-352c-4ca8-9c28-4816f3b24fab");
user_pref("CT1750559.installSp", "FALSE");
user_pref("CT1750559.installerVersion", "1.7.1.7");
user_pref("CT1750559.keyword", "true");
user_pref("CT1750559.originalSearchAddressUrl", "");
user_pref("CT1750559.searchRevert", "false");
user_pref("CT1750559.searchUserMode", "1");
user_pref("CT1750559.versionFromInstaller", "10.20.1.8");
user_pref("CT1750559.xpeMode", "0");
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN21752994255855693&UM=1&q=");
user_pref("smartbar.addressBarOwnerCTID", "CT1750559");
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&CUI=UN21752994255855693&UM=1&q=");
user_pref("smartbar.machineId", "NIBQHN87FBZE97GCJQ6SHUHTCDSP7CN2AMF4RM+XK0BUVHFTVOODRCHHI+RBY5MBEZFHAFLDEACAKOUY3FYGKG");





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 21.11.2013 at 20:53:13,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Ještě jdu na log MbAM. Minutku.

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 21 lis 2013 21:24

Dodávám aktuální log z MbAM. REMOVE SELECTED jsem nedávala, žádné infekce nebyly nalezeny. Díky.

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.21.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Jitka Trnková :: VCELICKA [administrátor]

Ochrana: Povolena

21.11.2013 21:14:21
mbam-log-2013-11-21 (21-14-21).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 215451
Uplynulý čas: 8 minut, 18 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 21 lis 2013 21:56

Jinak teď jsem zkoušela videa a hudbu na netu a žádná změna. Obrazy jsou zpomalený, "rozčtverečkovávaj se" a počítač se taky nijak výrazně nezrychlil..... Díky za další typy.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod jaro3 » 22 lis 2013 09:27

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 22 lis 2013 09:30

Nelze mi ty programy spustit jako Správce, jsem jediný uživatel pc - "Jitka" - takže jsem poprvé zadávala tuto možnost, jinou variantu mi to nenabízí. Je to tak správně? Díky.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod jaro3 » 22 lis 2013 09:38

Jako správce platí jen pro majitele win Vista , w7 a 8.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 22 lis 2013 12:52

Díky za podrobný instrukce, přikládám logy. Poprvý mi z AdwCleaner vylezla v logu jen jedna větička, PC se mi nerestartoval:"# AdwCleaner v3.012 - Report created 22/11/2013 at 11:53:13", takže jsem dělala teď naposledy znova, jako poslední teda AdwCleaner.

# AdwCleaner v3.012 - Report created 22/11/2013 at 11:53:13
# AdwCleaner v3.012 - Report created 22/11/2013 at 12:45:20
# Updated 11/11/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Jitka Trnková - VCELICKA
# Running from : C:\Documents and Settings\Jitka Trnková\Dokumenty\Stažené soubory\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\CT1750559
Folder Deleted : C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Documents and Settings\Jitka Trnková\Data aplikací\Mozilla\Firefox\Profiles\wxr3wktu.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [2850 octets] - [21/11/2013 20:24:36]
AdwCleaner[R1].txt - [1304 octets] - [22/11/2013 11:51:07]
AdwCleaner[S0].txt - [1173 octets] - [22/11/2013 11:53:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1233 octets] ##########
___________________________________________________________________________

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Microsoft Windows XP x86
Ran by Jitka Trnkov  on p  22.11.2013 at 11:55:25,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Jitka Trnkov \Data aplikacˇ\thinstall"



~~~ FireFox

Successfully deleted the following from C:\Documents and Settings\Jitka Trnkov \Data aplikacˇ\mozilla\firefox\profiles\wxr3wktu.default\prefs.js

user_pref("keyword.URL", "hxxp://search.seznam.cz/?sourceid=Quicksearch_12454&q=");





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  22.11.2013 at 12:18:52,75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
_______________________________________________________________________________
RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Jitka Trnková [Práva správce]
Mód : Kontrola -- Datum : 11/22/2013 12:24:19
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP PATH] szndesktop.exe -- C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-854245398-220523388-1606980848-1004\[...]\Run : cz.seznam.software.autoupdate ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-854245398-220523388-1606980848-1004\[...]\Run : cz.seznam.software.szndesktop ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 1 ¤¤¤
[All Users][SUSP UNIC] ASUS WiFi-AP Solo.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\ASUS WiFi-AP Solo.lnk @C:\PROGRA~1\ASUSWI~1\RtWLan.exe /H [-][-] -> NALEZENO

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD2500AAJB-00J3A0 +++++
--- User ---
[MBR] e81080347353b5ade9a0ceffb7893e61
[BSP] 7ac34b608267c31a89d9ef7591754165 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Samsung M2 Portable USB Device +++++
--- User ---
[MBR] a96a44a24fe50dc89c66853010c26efe
[BSP] 9fbf27cee58291aa6b6f71aa47a3a37d : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 64 | Size: 305242 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ USB) Kingston DataTraveler 2.0 USB Device +++++
--- User ---
[MBR] 5c3f2a6e49c64b98033da7bc6042e569
[BSP] ef3177ea6997481f5647d45aa222b26f : Empty MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 8064 | Size: 1933 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[0]_S_11222013_122419.txt >>

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod Žbeky » 22 lis 2013 23:02

Zavři všechny programy a prohlížeče.
Odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller (Pro Windows Vista nebo WIN7 klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status box zobrazuje "Scan" "
- Klikni na "Delete"
- Počkej, dokud status box zobrazuje "Smazání - Finished"
- Klikni na "Zprávy", zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [1].txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

fcelicka
Level 1.5
Level 1.5
Příspěvky: 136
Registrován: leden 12
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu - pomalý PC

Příspěvekod fcelicka » 22 lis 2013 23:24

Děkuji, zasílám logy:

RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Jitka Trnková [Práva správce]
Mód : Odebrat -- Datum : 11/22/2013 23:16:31
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\szninstall.exe" -c [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-854245398-220523388-1606980848-1004\[...]\Run : cz.seznam.software.autoupdate ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\szninstall.exe" -c [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[RUN][SUSP PATH] HKUS\S-1-5-21-854245398-220523388-1606980848-1004\[...]\Run : cz.seznam.software.szndesktop ("C:\Documents and Settings\Jitka Trnková\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 1 ¤¤¤
[All Users][SUSP UNIC] ASUS WiFi-AP Solo.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\ASUS WiFi-AP Solo.lnk @C:\PROGRA~1\ASUSWI~1\RtWLan.exe /H [-][-] -> VYMAZÁNO

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD2500AAJB-00J3A0 +++++
--- User ---
[MBR] e81080347353b5ade9a0ceffb7893e61
[BSP] 7ac34b608267c31a89d9ef7591754165 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_11222013_231631.txt >>
RKreport[0]_S_11222013_122419.txt;RKreport[0]_S_11222013_231604.txt



_______________________________________________________________________________________________________________________

23:19:27.0046 0x05a8 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
23:19:42.0921 0x05a8 ============================================================
23:19:42.0921 0x05a8 Current date / time: 2013/11/22 23:19:42.0921
23:19:42.0921 0x05a8 SystemInfo:
23:19:42.0921 0x05a8
23:19:42.0921 0x05a8 OS Version: 5.1.2600 ServicePack: 3.0
23:19:42.0921 0x05a8 Product type: Workstation
23:19:42.0921 0x05a8 ComputerName: VCELICKA
23:19:42.0921 0x05a8 UserName: Jitka Trnková
23:19:42.0921 0x05a8 Windows directory: C:\WINDOWS
23:19:42.0921 0x05a8 System windows directory: C:\WINDOWS
23:19:42.0921 0x05a8 Processor architecture: Intel x86
23:19:42.0921 0x05a8 Number of processors: 2
23:19:42.0921 0x05a8 Page size: 0x1000
23:19:42.0921 0x05a8 Boot type: Normal boot
23:19:42.0921 0x05a8 ============================================================
23:19:45.0109 0x05a8 KLMD registered as C:\WINDOWS\system32\drivers\71552312.sys
23:19:45.0750 0x05a8 System UUID: {8CA32B3D-EC16-B383-791A-F51757C55846}
23:19:47.0375 0x05a8 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:19:47.0375 0x05a8 ============================================================
23:19:47.0375 0x05a8 \Device\Harddisk0\DR0:
23:19:47.0375 0x05a8 MBR partitions:
23:19:47.0375 0x05a8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D1C0681
23:19:47.0375 0x05a8 ============================================================
23:19:47.0406 0x05a8 C: <-> \Device\Harddisk0\DR0\Partition1
23:19:47.0406 0x05a8 ============================================================
23:19:47.0406 0x05a8 Initialize success
23:19:47.0406 0x05a8 ============================================================
23:19:52.0093 0x03ac ============================================================
23:19:52.0093 0x03ac Scan started
23:19:52.0093 0x03ac Mode: Manual;
23:19:52.0093 0x03ac ============================================================
23:19:52.0093 0x03ac KSN ping started
23:19:55.0015 0x03ac KSN ping finished: true
23:19:55.0515 0x03ac ================ Scan system memory ========================
23:19:55.0515 0x03ac System memory - ok
23:19:55.0515 0x03ac ================ Scan services =============================
23:19:55.0734 0x03ac Abiosdsk - ok
23:19:55.0750 0x03ac abp480n5 - ok
23:19:55.0843 0x03ac [ 4FE34F1F3126B61FCC6B2043AA8112C9, DE370865E47A5D2A4B227EEFFB42384F67F08D622BF936A9C9CEF70CC47F324B ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:19:55.0843 0x03ac ACPI - ok
23:19:56.0031 0x03ac [ AFDFF022A01F0B11C776F0860C3B282F, 135E5257B62D921B76271014301E9EA1E2383D5DBB04E475DC3A7EFFD2561F56 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
23:19:56.0031 0x03ac ACPIEC - ok
23:19:56.0093 0x03ac [ D392183CC5379E302E50CEBA635248EB, 43DDD87C7F749B2F6DD3BC7759BC25C1C5968ABAAEE4A9E13CA0851AF0E394BE ] ADIHdAudAddService C:\WINDOWS\system32\drivers\ADIHdAud.sys
23:19:56.0093 0x03ac ADIHdAudAddService - ok
23:19:56.0234 0x03ac [ A283108E14F3970432C21AF4C0CB1BCE, 1D3219EF916D54232838870EDE557296AACB714B456ED0AAE0DE3CE3822F4643 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
23:19:56.0234 0x03ac AdobeFlashPlayerUpdateSvc - ok
23:19:56.0250 0x03ac adpu160m - ok
23:19:56.0296 0x03ac [ 9F59AE2DE835641FBB0C6AFD80D8FA9B, 20DBA4F85654C637305CC9429D1942EC5E4F54731F605292B3851F931A5B1039 ] AEAudioService C:\WINDOWS\system32\drivers\AEAudio.sys
23:19:56.0296 0x03ac AEAudioService - ok
23:19:56.0328 0x03ac [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
23:19:56.0343 0x03ac aec - ok
23:19:56.0406 0x03ac [ 30BB1BDE595CA65FD5549462080D94E5, 04BAFCC9445F82A2CAA9852F1B35ECBD18CDD6333E73F6861704E96D740A7C79 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys
23:19:56.0406 0x03ac AegisP - ok
23:19:56.0468 0x03ac [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
23:19:56.0468 0x03ac AFD - ok
23:19:56.0484 0x03ac Aha154x - ok
23:19:56.0515 0x03ac aic78u2 - ok
23:19:56.0546 0x03ac aic78xx - ok
23:19:56.0609 0x03ac [ E0A6FA244B8624D78FE5FF6F56A33BAE, 26B828FDB03AE4A4F1DC7A1792F9BAD69CF947897D47F5E567F24F4B6D5CB541 ] Alerter C:\WINDOWS\system32\alrsvc.dll
23:19:56.0609 0x03ac Alerter - ok
23:19:56.0640 0x03ac [ 88842DE939A827577BF24243699AC80A, A49C9A6A9941F3A2FBBCFE1F6DB48B632739D00670AC98ECCCBC7FD9E786B21A ] ALG C:\WINDOWS\System32\alg.exe
23:19:56.0640 0x03ac ALG - ok
23:19:56.0656 0x03ac AliIde - ok
23:19:56.0687 0x03ac amsint - ok
23:19:56.0718 0x03ac AppMgmt - ok
23:19:56.0734 0x03ac asc - ok
23:19:56.0765 0x03ac asc3350p - ok
23:19:56.0796 0x03ac asc3550 - ok
23:19:56.0843 0x03ac [ 19A1DAC5BC607C212E8A94C05886ED52, F00EB55DC225EAED1AA0CF813BC45F1E12166BE2214DC863D7F0553943A53208 ] AsIO C:\WINDOWS\system32\drivers\AsIO.sys
23:19:56.0843 0x03ac AsIO - ok
23:19:57.0015 0x03ac [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
23:19:57.0046 0x03ac aspnet_state - ok
23:19:57.0109 0x03ac [ F5C2CCDB273A546E9C3A15250F1D9165, DEE995DF3F63FF987B35A64B1723B4CB998A1B9C5909B7DBD48EA65257D6CE5A ] asuskbnt C:\WINDOWS\system32\drivers\atkkbnt.sys
23:19:57.0109 0x03ac asuskbnt - ok
23:19:57.0171 0x03ac [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:19:57.0171 0x03ac AsyncMac - ok
23:19:57.0234 0x03ac [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
23:19:57.0234 0x03ac atapi - ok
23:19:57.0250 0x03ac Atdisk - ok
23:19:57.0296 0x03ac [ 9269B6C37E874EDC54A553CF6F0A32D7, 5B8A67DD87BAE3CA8A1D3E7DC0C58D0417BBDAF75D99043BAFCE8C5EDB9778B1 ] ATKKeyboardService C:\WINDOWS\ATKKBService.exe
23:19:57.0312 0x03ac ATKKeyboardService - ok
23:19:57.0390 0x03ac [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:19:57.0390 0x03ac Atmarpc - ok
23:19:57.0421 0x03ac [ DE31B88962A8645DBA5A37B993E7B0F1, CA93F25A3FD0CE68BB9B8E3AB6B813BF38DE3EDDFC990291B3957FAA59B2B274 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
23:19:57.0437 0x03ac AudioSrv - ok
23:19:57.0468 0x03ac [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
23:19:57.0468 0x03ac audstub - ok
23:19:57.0531 0x03ac [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
23:19:57.0531 0x03ac Beep - ok
23:19:57.0625 0x03ac [ 19395D092FD85DDC2D9C7729CF5A2AC8, 7640F36BA19698EE8A6257BF78A8C57DD9D734BED9CA6BB9B68603BAEA092412 ] BITS C:\WINDOWS\system32\qmgr.dll
23:19:57.0640 0x03ac BITS - ok
23:19:57.0718 0x03ac [ 89E739BBA5F636297EA5B5F811189E06, 151B32B12F5DD0D388134DA2471FE9741CF22B9C408DA58FEF8019D3C4EC836B ] Browser C:\WINDOWS\System32\browser.dll
23:19:57.0718 0x03ac Browser - ok
23:19:57.0765 0x03ac [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
23:19:57.0765 0x03ac cbidf2k - ok
23:19:57.0859 0x03ac [ 58BF7714A312698108A96D0DE2BB6825, 87E0EC24520C9C421AF6A680FEF42E18911AABA373A9F927C5CE77AD50F8196F ] cbVSCService11 C:\Program Files\Cobian Backup 11\cbVSCService11.exe
23:19:57.0859 0x03ac cbVSCService11 - ok
23:19:57.0875 0x03ac cd20xrnt - ok
23:19:57.0921 0x03ac [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
23:19:57.0921 0x03ac Cdaudio - ok
23:19:58.0000 0x03ac [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
23:19:58.0000 0x03ac Cdfs - ok
23:19:58.0062 0x03ac [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:19:58.0062 0x03ac Cdrom - ok
23:19:58.0078 0x03ac Changer - ok
23:19:58.0140 0x03ac [ E390DC1D7C461D7D56EC53402F329928, FB37F84E71353CD83FCDDD39C898C6D84C05130C5F1BEF022E3DFDE160398C0E ] CiSvc C:\WINDOWS\system32\cisvc.exe
23:19:58.0140 0x03ac CiSvc - ok
23:19:58.0156 0x03ac [ 064507A8DFA8C5C7E2FFDDD3E6F424FA, 1725067BC759484A7185A4F1A44ED3CBE481529D187FE98EF279425B79177EB1 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
23:19:58.0156 0x03ac ClipSrv - ok
23:19:58.0234 0x03ac [ 7FA87325900183197BC9710D1CE4C9FA, EFFCB4FDB69A01B019785F203F9779832AF7DE77FCE47B9421BEDC34816C1D82 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:19:58.0265 0x03ac clr_optimization_v2.0.50727_32 - ok
23:19:58.0312 0x03ac [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:19:58.0390 0x03ac clr_optimization_v4.0.30319_32 - ok
23:19:58.0406 0x03ac CmdIde - ok
23:19:58.0437 0x03ac COMSysApp - ok
23:19:58.0484 0x03ac Cpqarray - ok
23:19:58.0546 0x03ac [ F3AB0933CBD166D271992F411C27CCAF, 50E01F3B058F814BE914FA5050B2D972E8584A467719A5ABCF9D9EBD596A54A7 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
23:19:58.0546 0x03ac CryptSvc - ok
23:19:58.0562 0x03ac dac2w2k - ok
23:19:58.0593 0x03ac dac960nt - ok
23:19:58.0687 0x03ac [ BE27674D1CBC3214AEC84B4336A38BBF, 3DF5F9A9E97595A61314B2731DF4F3D3C19D1B9D2291624A63B8E1861FFC2D76 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
23:19:58.0718 0x03ac DcomLaunch - ok
23:19:58.0750 0x03ac [ 8C9A53E285AC5E6704844D0459EC85BE, 9E86AF4C06CEC007C9B1590B6E056319603E4D79BED0C2471C6F1BC251B380CF ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
23:19:58.0750 0x03ac Dhcp - ok
23:19:58.0781 0x03ac [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
23:19:58.0781 0x03ac Disk - ok
23:19:58.0796 0x03ac dmadmin - ok
23:19:58.0890 0x03ac [ DB5FD2BF5B07DC54BFCB3664FF05BD7C, 46074FBBC5E4A40A7B3A45636089DEDD2A619778C7DCD797571C2BB64D775F7E ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
23:19:58.0906 0x03ac dmboot - ok
23:19:58.0953 0x03ac [ FFF1720AF51171F32F1EAD5CF71F2810, 2E40D63DC7670C1E88A532DB8923A98ABC8481C351C4D915C2753E10BA77F36D ] dmio C:\WINDOWS\system32\drivers\dmio.sys
23:19:58.0953 0x03ac dmio - ok
23:19:59.0000 0x03ac [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
23:19:59.0000 0x03ac dmload - ok
23:19:59.0031 0x03ac [ 2BFEFE9E865655A76982F050450B9591, 15C7D093D638770519AA43E7D8897310F32AB1F217027F5750D799494A985C35 ] dmserver C:\WINDOWS\System32\dmserver.dll
23:19:59.0031 0x03ac dmserver - ok
23:19:59.0078 0x03ac [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
23:19:59.0093 0x03ac DMusic - ok
23:19:59.0140 0x03ac [ DFAA406BF19F4EE806A6F8D4342137F7, EE2C11B3E37565FC009E323607B2F5F148F9219012EDF848CEFC1B273DAA98A9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
23:19:59.0156 0x03ac Dnscache - ok
23:19:59.0187 0x03ac [ 4A3E2BD20157A0946751229E92EB8621, D8C00CC2C18C517F7262EBC3C511C062E5ABA797056AEB22AC5DEB306BA8C526 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
23:19:59.0203 0x03ac Dot3svc - ok
23:19:59.0218 0x03ac dpti2o - ok
23:19:59.0250 0x03ac [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
23:19:59.0250 0x03ac drmkaud - ok
23:19:59.0296 0x03ac [ 14EA0C26137744636EB25B3FF1F2B02E, D621C86FBE526323393A359F19564BD9492D3B03C40889C6455337FF93F63A97 ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys
23:19:59.0296 0x03ac eamon - ok
23:19:59.0343 0x03ac [ 0887D9C2BE8D940778CAD1E3B85F2A41, 2E30DC06D46A5E174B7CAA2D70BDB697015495942572E90425E2EE7AC541BCF4 ] EapHost C:\WINDOWS\System32\eapsvc.dll
23:19:59.0343 0x03ac EapHost - ok
23:19:59.0390 0x03ac [ 366369746D1818FDD8589D1F2C8A6D03, 3EF30C36DEAB79C2E971CA189BDEBAC2491956D3C834E0D1ECCACBD23717B128 ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys
23:19:59.0390 0x03ac ehdrv - ok
23:19:59.0406 0x03ac EIO - ok
23:19:59.0562 0x03ac [ 7FE34FD5652C54BDA8D2DF8AC92E833A, 2B2836F47398AAD173F0D5C016B3B4DAB13F4EEC991B05D3C8B1DF310B25A96A ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
23:19:59.0609 0x03ac ekrn - ok
23:19:59.0640 0x03ac [ 5F08103444A1B5B2A38EAB729DE0A1A3, 0A8C2F9064F67A167B17E22A57F1C2866B4923C8BB702D0AAE4AE0D5D9C4F689 ] epfw C:\WINDOWS\system32\DRIVERS\epfw.sys
23:19:59.0656 0x03ac epfw - ok
23:19:59.0671 0x03ac [ 03C6C226BC364D23682A8A5AE136F038, 824BA2F956853556958E26D56B5F54AD5FAC9C7E638AA4BF2502D2E7B5EA171D ] Epfwndis C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
23:19:59.0687 0x03ac Epfwndis - ok
23:19:59.0718 0x03ac [ FEDBE43C34EF0D4CB249C22964B0E17D, 79844F1953F7593AAFA0D166DA97B69F6F6B63AA4C48265B15944FBF17B15603 ] epfwtdi C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
23:19:59.0718 0x03ac epfwtdi - ok
23:19:59.0750 0x03ac [ A2A4912798F2BE706ABADD3D30800D16, CCCCA389D22525D984DE9B59E4CEBE0EEEF315F725176EB5C4DC1A5B6157234A ] ERSvc C:\WINDOWS\System32\ersvc.dll
23:19:59.0750 0x03ac ERSvc - ok
23:19:59.0781 0x03ac [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] Eventlog C:\WINDOWS\system32\services.exe
23:19:59.0781 0x03ac Eventlog - ok
23:19:59.0875 0x03ac [ A371F11EF07653591C8DE26AFB13CE7F, 1192EDC8B146F1C27E8CD7E126DDC044F8B368C2E891A90CD81620D48C9550B6 ] EventSystem C:\WINDOWS\system32\es.dll
23:19:59.0875 0x03ac EventSystem - ok
23:19:59.0953 0x03ac [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
23:19:59.0953 0x03ac Fastfat - ok
23:20:00.0031 0x03ac [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
23:20:00.0031 0x03ac FastUserSwitchingCompatibility - ok
23:20:00.0093 0x03ac [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
23:20:00.0109 0x03ac Fdc - ok
23:20:00.0156 0x03ac [ A7415A0EDF891613F0F27E2D56976F13, 889837405B174778AC040D9778285FC3281EFAA1A7AB3792CECC9C684BE2EB53 ] FETND5BV C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
23:20:00.0156 0x03ac FETND5BV - ok
23:20:00.0187 0x03ac [ E9648254056BCE81A85380C0C3647DC4, AE58F498BD1C33360FE3BB9EA22C13EA562206B68E7946B587CB5A6DF94586A1 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys
23:20:00.0187 0x03ac FETNDIS - ok
23:20:00.0234 0x03ac [ A583BC166495B07F704533754CE29CBD, 13D7ADD409AA44F0C171943AC075CB2162E0A0D429A1649C02EAA2F083F7FAF8 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
23:20:00.0234 0x03ac FETNDISB - ok
23:20:00.0265 0x03ac [ AC366695A0796560AA37215AD5762AAF, 6ADC7443EA42D77199D4879AF3C33A07914116C69A34B895D8CB8444EE50077F ] Fips C:\WINDOWS\system32\drivers\Fips.sys
23:20:00.0265 0x03ac Fips - ok
23:20:00.0281 0x03ac [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
23:20:00.0281 0x03ac Flpydisk - ok
23:20:00.0359 0x03ac [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
23:20:00.0359 0x03ac FltMgr - ok
23:20:00.0421 0x03ac [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
23:20:00.0437 0x03ac FontCache3.0.0.0 - ok
23:20:00.0453 0x03ac [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:20:00.0453 0x03ac Fs_Rec - ok
23:20:00.0500 0x03ac [ 4E664D8541DB4A66B73A24257E322E1F, 17A2140AFE2B41E579FCCAFB82532853AD90A6EDBCB13DE80741DAE0AD5B4CC9 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:20:00.0500 0x03ac Ftdisk - ok
23:20:00.0515 0x03ac GMSIPCI - ok
23:20:00.0562 0x03ac [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:20:00.0562 0x03ac Gpc - ok
23:20:00.0609 0x03ac [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
23:20:00.0609 0x03ac HDAudBus - ok
23:20:00.0671 0x03ac [ FCFE31FB75F8A6295B6B0AF87A626282, 6BA385797DBC73EB29EFE3293B80C21B1B8A1E9B87A462476E73C526C9565E5F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
23:20:00.0671 0x03ac helpsvc - ok
23:20:00.0687 0x03ac HidServ - ok
23:20:00.0734 0x03ac [ 7A6B320928F86BC851530D63C82965D9, 1F628759D31098DFBC05244735B5A62ACD8E45DBC5C9D236260D68EB8F1E28F5 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
23:20:00.0750 0x03ac hkmsvc - ok
23:20:00.0765 0x03ac hpn - ok
23:20:00.0828 0x03ac [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
23:20:00.0828 0x03ac HTTP - ok
23:20:00.0890 0x03ac [ 58FE2F2DA3BC5573F4A35B3760D3125F, B241ACCE426402EC64DC34C49CECB8CDC0851986D54BFCCED7040D6C43F5787A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
23:20:00.0890 0x03ac HTTPFilter - ok
23:20:00.0906 0x03ac i2omgmt - ok
23:20:00.0937 0x03ac i2omp - ok
23:20:00.0968 0x03ac [ C528E27945367191E7BAE364930B6932, 1B95C7B49B4CAE734DC6C9EC22555C5356EEC856B8491C761C777479264CF854 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:20:00.0984 0x03ac i8042prt - ok
23:20:01.0062 0x03ac [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
23:20:01.0078 0x03ac IDriverT - ok
23:20:01.0234 0x03ac [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:20:01.0265 0x03ac idsvc - ok
23:20:01.0296 0x03ac [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
23:20:01.0296 0x03ac Imapi - ok
23:20:01.0359 0x03ac [ F7B93AAFAD33B2320954C17E26C8D361, 8CFDB11A68B59E195F280BE08B25FA59F1F70833832919B8BECCE17616999934 ] ImapiService C:\WINDOWS\system32\imapi.exe
23:20:01.0375 0x03ac ImapiService - ok
23:20:01.0406 0x03ac ini910u - ok
23:20:01.0437 0x03ac IntelIde - ok
23:20:01.0515 0x03ac [ 27B290D632AF2CF3CF40BFDDB7370985, 2C266777B4A96706658B8C9A7B30D15D6E495C815FAE23A0A1FC747E9B5AE363 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:20:01.0515 0x03ac intelppm - ok
23:20:01.0562 0x03ac [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
23:20:01.0562 0x03ac Ip6Fw - ok
23:20:01.0593 0x03ac [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:20:01.0593 0x03ac IpFilterDriver - ok
23:20:01.0625 0x03ac [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:20:01.0625 0x03ac IpInIp - ok
23:20:01.0671 0x03ac [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:20:01.0671 0x03ac IpNat - ok
23:20:01.0734 0x03ac [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:20:01.0734 0x03ac IPSec - ok
23:20:01.0781 0x03ac [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
23:20:01.0781 0x03ac IRENUM - ok
23:20:01.0859 0x03ac [ CC9F8A2D60AED1A51A3AC34C59B987AE, CBF69817BE3D9A4617390B1A3306074CB8581F21562CD1357D32BC3E542F3CEE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:20:01.0859 0x03ac isapnp - ok
23:20:01.0921 0x03ac [ 1B6162FE7F66B1A71A4B70F941C4AA9B, C2EA494BAB0513A6027414FB1E75834F980A77852D0DC8559E8942FC222A075A ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:20:01.0921 0x03ac Kbdclass - ok
23:20:01.0968 0x03ac [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
23:20:01.0984 0x03ac kmixer - ok
23:20:02.0015 0x03ac [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
23:20:02.0031 0x03ac KSecDD - ok
23:20:02.0078 0x03ac [ 3428E8F86F8ADD36B42FB23542C7B3E4, 9CF643D1A70AF08407ACD5FD6FE4B8777521DDF41B5E63C2E6E1E4CAAC69A403 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
23:20:02.0078 0x03ac LanmanServer - ok
23:20:02.0156 0x03ac [ 936C1D110232D23B621CB0196E4F80F0, 2DE3AF93E20F1DC7A6FF31B18054EA4D2350387E4DA91C4B16D451384F0C57E2 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
23:20:02.0156 0x03ac lanmanworkstation - ok
23:20:02.0171 0x03ac lbrtfdc - ok
23:20:02.0281 0x03ac [ 0AB159F536E3E8F7F07113702A07CCA5, 3218C553183E6697C663B6D12790E09756B50505590858DD5AC62411D37CDD7C ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
23:20:02.0281 0x03ac LmHosts - ok
23:20:02.0328 0x03ac [ 4470E3C1E0C3378E4CAB137893C12C3A, CA8E66356F0E671D5454E561E7EAD74DE25DCF53BE452369F96ECACFA8709489 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
23:20:02.0328 0x03ac MBAMProtector - ok
23:20:02.0421 0x03ac [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:20:02.0437 0x03ac MBAMScheduler - ok
23:20:02.0484 0x03ac [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
23:20:02.0500 0x03ac MBAMService - ok
23:20:02.0546 0x03ac [ 221CD1C815B8A6B79389C3F5D1018DE8, 6D0D25D6669C4F9452F74EC72C6138A41D9408E01AF5FD01C08F27BE7BC9C905 ] Messenger C:\WINDOWS\System32\msgsvc.dll
23:20:02.0546 0x03ac Messenger - ok
23:20:02.0593 0x03ac [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
23:20:02.0593 0x03ac mnmdd - ok
23:20:02.0640 0x03ac [ 9A57D046F88F4B69751B11FD40088A61, 62F65433024CE411F111A88723747B8A83B31076FBAF4CFF40FD02A53D7FF7DF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
23:20:02.0640 0x03ac mnmsrvc - ok
23:20:02.0671 0x03ac [ 44032B0C6D9954D3FD26438330B99EE7, A49749A4C00D50F57170AA5DA9E2DEECC8C524A48B144C8B784894F2C202FBEE ] Modem C:\WINDOWS\system32\drivers\Modem.sys
23:20:02.0671 0x03ac Modem - ok
23:20:02.0718 0x03ac [ 4CB582831DBDE63CE43B45D771218374, 6D470B26197C5B388983D9213D48D2CDE934C9591572876DC7790FE4B59E0845 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:20:02.0718 0x03ac Mouclass - ok
23:20:02.0734 0x03ac [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
23:20:02.0750 0x03ac MountMgr - ok
23:20:02.0812 0x03ac [ 5E0686615A80A6279B2314E13CD23F6E, 659931AB2DD395FAA2E5036D02BC6AAE8A7E4C9FF1A902B1FF9C15E878C89E77 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
23:20:02.0812 0x03ac MozillaMaintenance - ok
23:20:02.0828 0x03ac mraid35x - ok
23:20:02.0875 0x03ac [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:20:02.0875 0x03ac MRxDAV - ok
23:20:02.0953 0x03ac [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:20:02.0968 0x03ac MRxSmb - ok
23:20:03.0015 0x03ac [ 6DB4D1521CABA9A5FFAB54ADE0AE867D, 78D63EE2C0B0852F0771071C099643242EBC9F4DA28847B93BCE9C3CC1091938 ] MSDTC C:\WINDOWS\system32\msdtc.exe
23:20:03.0015 0x03ac MSDTC - ok
23:20:03.0062 0x03ac [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
23:20:03.0062 0x03ac Msfs - ok
23:20:03.0093 0x03ac MSIServer - ok
23:20:03.0140 0x03ac [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:20:03.0140 0x03ac MSKSSRV - ok
23:20:03.0171 0x03ac [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:20:03.0171 0x03ac MSPCLOCK - ok
23:20:03.0203 0x03ac [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
23:20:03.0203 0x03ac MSPQM - ok
23:20:03.0265 0x03ac [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:20:03.0265 0x03ac mssmbios - ok
23:20:03.0312 0x03ac [ D48659BB24C48345D926ECB45C1EBDF5, EDEDE58316827530C25F8085F62AD48EA6D44B0F8AC1917B940F53B02CF72EA6 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
23:20:03.0328 0x03ac MTsensor - ok
23:20:03.0375 0x03ac [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
23:20:03.0375 0x03ac Mup - ok
23:20:03.0421 0x03ac [ 6EA362E9DB03D44F6B996F4D8BE237E9, FE6B4C546D26C4A2832CF4CB280B86B1723E10E46A3C24AF6C9856FCCAE9D1FC ] napagent C:\WINDOWS\System32\qagentrt.dll
23:20:03.0453 0x03ac napagent - ok
23:20:03.0500 0x03ac [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
23:20:03.0500 0x03ac NDIS - ok
23:20:03.0531 0x03ac [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:20:03.0531 0x03ac NdisTapi - ok
23:20:03.0578 0x03ac [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:20:03.0578 0x03ac Ndisuio - ok
23:20:03.0593 0x03ac [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:20:03.0609 0x03ac NdisWan - ok
23:20:03.0656 0x03ac [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
23:20:03.0656 0x03ac NDProxy - ok
23:20:03.0687 0x03ac [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
23:20:03.0703 0x03ac NetBIOS - ok
23:20:03.0718 0x03ac [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
23:20:03.0734 0x03ac NetBT - ok
23:20:03.0781 0x03ac [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDE C:\WINDOWS\system32\netdde.exe
23:20:03.0781 0x03ac NetDDE - ok
23:20:03.0812 0x03ac [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
23:20:03.0812 0x03ac NetDDEdsdm - ok
23:20:03.0859 0x03ac [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] Netlogon C:\WINDOWS\system32\lsass.exe
23:20:03.0859 0x03ac Netlogon - ok
23:20:03.0890 0x03ac [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40, 588C8BA14A7255FD36A88960CBE34341301773765ECF2A9A0F1760A509A08A5B ] Netman C:\WINDOWS\System32\netman.dll
23:20:03.0906 0x03ac Netman - ok
23:20:03.0984 0x03ac [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
23:20:04.0031 0x03ac NetTcpPortSharing - ok
23:20:04.0078 0x03ac [ 39EE7C3BFBC64BA87CC8CF67386E814C, B93CCB625CE370D9A49C9374D24C939D7C9FEF81401F4F822C51E12677D77E01 ] Nla C:\WINDOWS\System32\mswsock.dll
23:20:04.0078 0x03ac Nla - ok
23:20:04.0109 0x03ac [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
23:20:04.0109 0x03ac Npfs - ok
23:20:04.0187 0x03ac [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
23:20:04.0203 0x03ac Ntfs - ok
23:20:04.0234 0x03ac [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
23:20:04.0234 0x03ac NtLmSsp - ok
23:20:04.0296 0x03ac [ 023DD70573D644F3D9C8B1258A7BFD08, 9A1D3210ED5FD8BEDF92ED577A9B30E37035408A73EB66A8C950B75AB7539B83 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
23:20:04.0312 0x03ac NtmsSvc - ok
23:20:04.0359 0x03ac [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
23:20:04.0359 0x03ac Null - ok
23:20:04.0921 0x03ac [ 7C56F3FD65B2BDB315CA3605A5392D7B, 1C33B2723BBD958FE06D71B6AC5C54DF1F46491C292749FE0DB8577BF056A765 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
23:20:05.0218 0x03ac nv - ok
23:20:05.0343 0x03ac [ 60D62603950220B51DF57E461A601659, AF987DC1DB95A9D2C9FB941346CC2B32CA0B83B72D79038C1F0DC05AB898E53F ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
23:20:05.0359 0x03ac NVSvc - ok
23:20:05.0421 0x03ac [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:20:05.0421 0x03ac NwlnkFlt - ok
23:20:05.0437 0x03ac [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:20:05.0437 0x03ac NwlnkFwd - ok
23:20:05.0609 0x03ac [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:20:05.0640 0x03ac odserv - ok
23:20:05.0703 0x03ac [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:20:05.0718 0x03ac ose - ok
23:20:05.0765 0x03ac [ 46F8DB73B4A53E543F8E371DC7C75BAE, F6C5E7DE4B4AE0ED785DB075BE14EA6A0FC9050C95669B26DEF2B82D7B7D3B2C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
23:20:05.0765 0x03ac Parport - ok
23:20:05.0796 0x03ac [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
23:20:05.0796 0x03ac PartMgr - ok
23:20:05.0859 0x03ac [ 1FAE19D0457176318BBA4A8795656EBC, 5F3D6CABA203A0485D67F63A6A81151724EE200BE49ED095CFCB1EF29C19D19F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
23:20:05.0859 0x03ac ParVdm - ok
23:20:05.0906 0x03ac [ 6CE351D149CB4BEFC702951E471E1730, 758327683BB45F01D5AE550AF21856822B4CF55E17F2A4F452F559088D242B37 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
23:20:05.0906 0x03ac PCI - ok
23:20:05.0921 0x03ac PCIDump - ok
23:20:05.0953 0x03ac PCIIde - ok
23:20:06.0031 0x03ac [ 4FC31E6C19A5CE5198B1ABFF94CAE758, A031E21EC1F15DA5E8429269F435337FA961C3C06D535DAFD448C7355F33FD0C ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
23:20:06.0031 0x03ac Pcmcia - ok
23:20:06.0046 0x03ac PDCOMP - ok
23:20:06.0078 0x03ac PDFRAME - ok
23:20:06.0109 0x03ac PDRELI - ok
23:20:06.0140 0x03ac PDRFRAME - ok
23:20:06.0156 0x03ac perc2 - ok
23:20:06.0187 0x03ac perc2hib - ok
23:20:06.0296 0x03ac [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] PlugPlay C:\WINDOWS\system32\services.exe
23:20:06.0312 0x03ac PlugPlay - ok
23:20:06.0328 0x03ac [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
23:20:06.0328 0x03ac PolicyAgent - ok
23:20:06.0406 0x03ac postgresql-8.4 - ok
23:20:06.0437 0x03ac [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:20:06.0437 0x03ac PptpMiniport - ok
23:20:06.0453 0x03ac [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
23:20:06.0468 0x03ac ProtectedStorage - ok
23:20:06.0484 0x03ac [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
23:20:06.0500 0x03ac PSched - ok
23:20:06.0531 0x03ac [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:20:06.0546 0x03ac Ptilink - ok
23:20:06.0562 0x03ac ql1080 - ok
23:20:06.0578 0x03ac Ql10wnt - ok
23:20:06.0609 0x03ac ql12160 - ok
23:20:06.0640 0x03ac ql1240 - ok
23:20:06.0671 0x03ac ql1280 - ok
23:20:06.0703 0x03ac [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:20:06.0703 0x03ac RasAcd - ok
23:20:06.0734 0x03ac [ 2B5E44EA009F2F374B980E1E9A70635D, 62D8FDB80C8ACBA2C42C12760B785587C43BEDFE015EC5C41B25F2BB735EFEB0 ] RasAuto C:\WINDOWS\System32\rasauto.dll
23:20:06.0734 0x03ac RasAuto - ok
23:20:06.0765 0x03ac [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:20:06.0765 0x03ac Rasl2tp - ok
23:20:06.0796 0x03ac [ D57554C664B64604BD1EE13EA2C07E77, B090C05B91EA602BFF9A5E89AB1A0FFDE869611961FF749DA8B3F4D00F04E756 ] RasMan C:\WINDOWS\System32\rasmans.dll
23:20:06.0812 0x03ac RasMan - ok
23:20:06.0828 0x03ac [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:20:06.0828 0x03ac RasPppoe - ok
23:20:06.0859 0x03ac [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
23:20:06.0859 0x03ac Raspti - ok
23:20:06.0906 0x03ac [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:20:06.0906 0x03ac Rdbss - ok
23:20:06.0937 0x03ac [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:20:06.0937 0x03ac RDPCDD - ok
23:20:07.0015 0x03ac [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
23:20:07.0031 0x03ac RDPWD - ok
23:20:07.0078 0x03ac [ C0D9D9711CB74EE9BC66353D8CBDAB0E, F1AF9A26910707E76BF213D8DE5C902B0088D8A29EBDFF72DE6A4D867E298CC8 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
23:20:07.0093 0x03ac RDSessMgr - ok
23:20:07.0140 0x03ac [ 611BFD220305BE3A85AE876EA47D4AA5, FDF87878EB3886649025E5A12F1C3FC9072D66CCD3217944710085C1F8A4512E ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
23:20:07.0140 0x03ac redbook - ok
23:20:07.0203 0x03ac [ 127C26B5371651043450E52542099ABA, 98AADAD8D5211CB894AA7C59B6299861B1F44B6D8F46AB5837E7D2F5B615B14A ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
23:20:07.0203 0x03ac RemoteAccess - ok
23:20:07.0234 0x03ac [ 718B3BDC0BC3C2F7D065A53D26202AF9, 9E58243628F1E1396AB82A80D046FF50803A230EE07B007E0CA5D744C77B091A ] RpcLocator C:\WINDOWS\system32\locator.exe
23:20:07.0250 0x03ac RpcLocator - ok
23:20:07.0296 0x03ac [ BE27674D1CBC3214AEC84B4336A38BBF, 3DF5F9A9E97595A61314B2731DF4F3D3C19D1B9D2291624A63B8E1861FFC2D76 ] RpcSs C:\WINDOWS\system32\rpcss.dll
23:20:07.0312 0x03ac RpcSs - ok
23:20:07.0375 0x03ac [ 09AB2E71E58B078038E3BFDBA7FFC984, 8CA277DEEF6376B0F48C6BA5DBBC3E8AF2245983BA9AF6AB83D1A920D35FAF93 ] RSVP C:\WINDOWS\system32\rsvp.exe
23:20:07.0375 0x03ac RSVP - ok
23:20:07.0421 0x03ac [ E4CCB77E004662432F55DCEA046A5180, 64D3E7E64E4F598969DA33013ABB8EB65233C27C06CE79678188367C00CF5EF5 ] RTLWUSB C:\WINDOWS\system32\DRIVERS\RTL8187.sys
23:20:07.0437 0x03ac RTLWUSB - ok
23:20:07.0453 0x03ac [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] SamSs C:\WINDOWS\system32\lsass.exe
23:20:07.0468 0x03ac SamSs - ok
23:20:07.0500 0x03ac [ 410046E401EB11E1E6749E9DEEA41D4A, 9507268ACD24EF51E994DC418E8EB3E10DEDE61EE892226A22A5DA7662397E25 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
23:20:07.0515 0x03ac SCardSvr - ok
23:20:07.0562 0x03ac [ 3FF232A7731621B8902D81D42418C93C, 2030C9A843D9555170179883BD4CC1E978D5FC5EC0D7FCA56518224E428BE421 ] Schedule C:\WINDOWS\system32\schedsvc.dll
23:20:07.0562 0x03ac Schedule - ok
23:20:07.0609 0x03ac [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:20:07.0609 0x03ac Secdrv - ok
23:20:07.0656 0x03ac [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6, 82EEB2345AC19050FAB202DE76C2CDD93E753F5AB67789A86A1726D3040C02E5 ] seclogon C:\WINDOWS\System32\seclogon.dll
23:20:07.0671 0x03ac seclogon - ok
23:20:07.0703 0x03ac [ ECA77BEEB2BE8D573CF1B265E44FBFBD, 1F4EC2ED5CE3AF359DC9F430F36FCDA4B3C045FDBEF075C7E5F36DCC71A3B273 ] SenFiltService C:\WINDOWS\system32\drivers\Senfilt.sys
23:20:07.0718 0x03ac SenFiltService - ok
23:20:07.0734 0x03ac [ A530B75C10C23C9AB28FDB6CE719E21F, 14568DF6457758E2F534A46A8E6245C364895C3993BEF2B5A889B98DBB201A27 ] SENS C:\WINDOWS\system32\sens.dll
23:20:07.0750 0x03ac SENS - ok
23:20:07.0765 0x03ac [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
23:20:07.0765 0x03ac serenum - ok
23:20:07.0796 0x03ac [ B842729337C9B921615C40D3C1A1AF96, 503670A56423B996C6ED6AE95F07FB88910767C4A2041A4BE9070C57A016E7FA ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
23:20:07.0796 0x03ac Serial - ok
23:20:07.0921 0x03ac [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
23:20:07.0921 0x03ac Sfloppy - ok
23:20:07.0984 0x03ac [ F58FACA9621D2DB01BD0927D9A0A208E, 239C87E09261BC9D1DBE99DABCFC4787D42289E8769563A5EFB323BE6F177C9A ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
23:20:08.0000 0x03ac SharedAccess - ok
23:20:08.0031 0x03ac [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:20:08.0031 0x03ac ShellHWDetection - ok
23:20:08.0046 0x03ac Simbad - ok
23:20:08.0125 0x03ac [ 3D7EF286E806F9BD9339AA52E28DCD67, 24D602B7DDF7718A1F149D35B24C2345D0DDE6E8B8A7FDF35062C24A6D13226D ] SjyPkt C:\WINDOWS\System32\Drivers\SjyPkt.sys
23:20:08.0125 0x03ac SjyPkt - ok
23:20:08.0203 0x03ac Sparrow - ok
23:20:08.0265 0x03ac [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
23:20:08.0265 0x03ac splitter - ok
23:20:08.0343 0x03ac [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
23:20:08.0343 0x03ac Spooler - ok
23:20:08.0406 0x03ac [ 94610C8653635E4459316A0050D55CE7, D148D33B3D2B0757060531C526F2161504A8D7C4E5957D092C7EBDB007271339 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
23:20:08.0406 0x03ac sr - ok
23:20:08.0453 0x03ac [ 35B91147124F64AC8081A2EDB9EA4DEE, 1609D19156DAC6EE3C2D2350B062966B64D9CDC289E9B8FEB6D244AAEBE90BBF ] srservice C:\WINDOWS\system32\srsvc.dll
23:20:08.0468 0x03ac srservice - ok
23:20:08.0531 0x03ac [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
23:20:08.0546 0x03ac Srv - ok
23:20:08.0578 0x03ac [ BECD5271DC4E3B7C3D035F790FCBC1E5, D63B9DB81332553C963EC5057D241CE2287AF652387333C1FD79AF8C9B5F2BA7 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
23:20:08.0593 0x03ac SSDPSRV - ok
23:20:08.0640 0x03ac [ C1CDD9275F6A115BB0AE1D55D8D27BA6, CD0511FD7F6AD832CBEB931C605AB3AD217631C57399CB8033248D27619541E4 ] stisvc C:\WINDOWS\system32\wiaservc.dll
23:20:08.0656 0x03ac stisvc - ok
23:20:08.0687 0x03ac [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
23:20:08.0687 0x03ac swenum - ok
23:20:08.0703 0x03ac [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
23:20:08.0718 0x03ac swmidi - ok
23:20:08.0734 0x03ac SwPrv - ok
23:20:08.0765 0x03ac symc810 - ok
23:20:08.0796 0x03ac symc8xx - ok
23:20:08.0812 0x03ac sym_hi - ok
23:20:08.0843 0x03ac sym_u3 - ok
23:20:08.0875 0x03ac [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
23:20:08.0890 0x03ac sysaudio - ok
23:20:08.0921 0x03ac [ CE06F01B88ACE199A1BF460CAC29C110, 3CD89E5B8E53203287D889C107E4795225742DB6C6ACA2DC0611BD9728382A27 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
23:20:08.0937 0x03ac SysmonLog - ok
23:20:08.0968 0x03ac [ C2546CD7A398476F9DF5614B2AE160E8, 11C8435BA983553E9C0806494E9B3C7080515C0375B0604F029D89B50726161A ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
23:20:08.0984 0x03ac TapiSrv - ok
23:20:09.0062 0x03ac [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:20:09.0062 0x03ac Tcpip - ok
23:20:09.0109 0x03ac [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
23:20:09.0109 0x03ac TDPIPE - ok
23:20:09.0140 0x03ac [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
23:20:09.0140 0x03ac TDTCP - ok
23:20:09.0187 0x03ac [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
23:20:09.0187 0x03ac TermDD - ok
23:20:09.0218 0x03ac [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E, 3D2B1D899061448EAD993CDE97D1EF50DD64728E9F44D80FEAE591198A937653 ] TermService C:\WINDOWS\System32\termsrv.dll
23:20:09.0234 0x03ac TermService - ok
23:20:09.0265 0x03ac [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] Themes C:\WINDOWS\System32\shsvcs.dll
23:20:09.0281 0x03ac Themes - ok
23:20:09.0296 0x03ac TosIde - ok
23:20:09.0375 0x03ac [ 38853304CCB938D30E0C4CDE8D2C2A8A, 966E7BCC9F63A1A7777F8A12E51C2A91EC688CE96109943ADC4CB4EB58DC34A6 ] TrkWks C:\WINDOWS\system32\trkwks.dll
23:20:09.0375 0x03ac TrkWks - ok
23:20:09.0421 0x03ac [ D85938F272D1BCF3DB3A31FC0A048928, 798328C8C06EEE7B0852E6D2B16C3AF24D529737ECA2E9725415261A5736D051 ] uagp35 C:\WINDOWS\system32\DRIVERS\uagp35.sys
23:20:09.0421 0x03ac uagp35 - ok
23:20:09.0437 0x03ac [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
23:20:09.0453 0x03ac Udfs - ok
23:20:09.0468 0x03ac ultra - ok
23:20:09.0562 0x03ac [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
23:20:09.0578 0x03ac Update - ok
23:20:09.0609 0x03ac [ 651BD90DCEE5B7BDC74A2EB7C9266F9E, AF7662BCA0819F82CE5EE0863E47149CC127DE664CB3DC6359B63FBD71DB54F8 ] upnphost C:\WINDOWS\System32\upnphost.dll
23:20:09.0625 0x03ac upnphost - ok
23:20:09.0671 0x03ac [ 20A0F6A11959E92908717D09E87D670D, 3DD6C99AB0F70FAA43DF470B30078B8A51B8AF735CD5C50DBB195FEA70F4C36E ] UPS C:\WINDOWS\System32\ups.exe
23:20:09.0671 0x03ac UPS - ok
23:20:09.0718 0x03ac [ 1B611611C28D2DF25BC057D79C6F13FC, B0D86F63E44B40413BBAE6402CC088046CFAE082D41BBC2ED5A916293356B846 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:20:09.0734 0x03ac usbccgp - ok
23:20:09.0750 0x03ac [ 4BAC8DF07F1D8434FC640E677A62204E, 76C1351AF6752224BF59DEEE0F8665FE699F3DFD679F5BCD01C7D9383E6402A4 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:20:09.0750 0x03ac usbehci - ok
23:20:09.0796 0x03ac [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:20:09.0796 0x03ac usbhub - ok
23:20:09.0843 0x03ac [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:20:09.0843 0x03ac usbprint - ok
23:20:09.0890 0x03ac [ F8EDE2B6928970DCE3D5614C27D9E7F6, 6E5EBBC8B70C1D593634DAF0C190DEADFDA18C3CBC8F552A76F156F3869EF05B ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:20:09.0890 0x03ac usbscan - ok
23:20:09.0921 0x03ac [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:20:09.0921 0x03ac USBSTOR - ok
23:20:09.0953 0x03ac [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:20:09.0953 0x03ac usbuhci - ok
23:20:09.0984 0x03ac [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
23:20:09.0984 0x03ac VgaSave - ok
23:20:10.0015 0x03ac [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E, FC7FFD53FCC0F81587EFF26A43C141D25C43DBC68311520CE2BCDD739CA58CA9 ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
23:20:10.0015 0x03ac ViaIde - ok
23:20:10.0031 0x03ac Video3D - ok
23:20:10.0078 0x03ac [ C8EE49FA76EB7C41A9CDDFE58151A74E, 71BAFD268BA79772196D8B76A7383F8C171C639838A245AF6456118278A96929 ] videX32 C:\WINDOWS\system32\DRIVERS\videX32.sys
23:20:10.0078 0x03ac videX32 - ok
23:20:10.0093 0x03ac [ 28A4B296B47782173C346E376CB374D1, FE799FE4A41752A2B47027EA88214BF3E39B317302939F4A2D0F2A4EFAAC2F13 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
23:20:10.0109 0x03ac VolSnap - ok
23:20:10.0156 0x03ac [ D6BA1A63D9E00933F1CD2A885573AFB2, 36311A060635CEC1DBB6D8A746B8A4D007706EAE97D51A5E12F9958AB16BE486 ] VSS C:\WINDOWS\System32\vssvc.exe
23:20:10.0171 0x03ac VSS - ok
23:20:10.0218 0x03ac [ FA4E1CDBA256787F2149F4AAD07BC91F, 1B5FC5248335D70094D04501AA2C30F54782B58FF8D573BE8E784A21529C7CAF ] W32Time C:\WINDOWS\system32\w32time.dll
23:20:10.0218 0x03ac W32Time - ok
23:20:10.0265 0x03ac [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:20:10.0265 0x03ac Wanarp - ok
23:20:10.0281 0x03ac WDICA - ok
23:20:10.0328 0x03ac [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
23:20:10.0328 0x03ac wdmaud - ok
23:20:10.0359 0x03ac [ 47AE51048A82DFA1CD6B51D369F7E169, 742F2162B8BDE00D83715093EA9743338964597ED22648B9F4F139D7278235A4 ] WebClient C:\WINDOWS\System32\webclnt.dll
23:20:10.0375 0x03ac WebClient - ok
23:20:10.0515 0x03ac [ E488332126E3B1182D2B8A0C35408EC6, F9F60911DF0A539753B2BEF6FAD2D0AED1BC1C3F43509F79D9AF2F810CDE5D9B ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
23:20:10.0515 0x03ac winmgmt - ok
23:20:10.0625 0x03ac [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
23:20:10.0625 0x03ac WmdmPmSN - ok
23:20:10.0703 0x03ac [ 23F6F03272F7E5679F1F050AED5ACEE6, 87EBE773F3E8FFE2F1E1DB435BB0E8852031AA88112EB791085AD3DA918B49CC ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
23:20:10.0718 0x03ac WmiApSrv - ok
23:20:10.0828 0x03ac [ 3739866D20ABD42F26A7B85F9E2560AF, 9DD01194A553590146A1A1D790B2F891D244C8C0EE34DA423CF2B1F7418BD3AC ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
23:20:10.0875 0x03ac WMPNetworkSvc - ok
23:20:11.0046 0x03ac [ 15673BD0B86150CB8E27766059C72A9B, 56C23289A8BFF4945EE532CF6D62D3EC81B827CA15A359F30A327789F9FE9CAF ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:20:11.0125 0x03ac WPFFontCache_v0400 - ok
23:20:11.0187 0x03ac [ 4C86D5FAF78194995AF9CC1075F65DD3, D3B23BB0971E0DBC0A51720067489C224323B603178E91149BF56F779DE352F0 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
23:20:11.0203 0x03ac wscsvc - ok
23:20:11.0250 0x03ac [ C1364564800EE9784192145324A23308, 5345BAE00364233594C9CF99CE2CC485E65B5D4FFBB81C86B2950EDA2427584C ] wuauserv C:\WINDOWS\system32\wuauserv.dll
23:20:11.0250 0x03ac wuauserv - ok
23:20:11.0312 0x03ac [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
23:20:11.0312 0x03ac WudfPf - ok
23:20:11.0359 0x03ac [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
23:20:11.0359 0x03ac WudfRd - ok
23:20:11.0390 0x03ac [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
23:20:11.0406 0x03ac WudfSvc - ok
23:20:11.0453 0x03ac [ A27D4BA7264C0BF52F32D10405BEA1D4, 5F28607CCAB15FB601BEB35FF0B1A5CD27C678C6D1CA724E842C33EED4579B8C ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
23:20:11.0484 0x03ac WZCSVC - ok
23:20:11.0531 0x03ac [ EAA4BB9EDB3FB10CF8979FE65E63658F, B80EB477100FD3E26513360E09DB6EBF0C8D8B0618F1F4BF1F387ABA6DEC9B64 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
23:20:11.0531 0x03ac xmlprov - ok
23:20:11.0562 0x03ac ================ Scan global ===============================
23:20:11.0609 0x03ac [ F36278E42C8C5DF03CE17DAC8231C91C, D012A3C8F394DF4F0BF5D5A4C10E73BBF427762B7D3DB6CF5FAB96536E082B7A ] C:\WINDOWS\system32\basesrv.dll
23:20:11.0656 0x03ac [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
23:20:11.0687 0x03ac [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
23:20:11.0718 0x03ac [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] C:\WINDOWS\system32\services.exe
23:20:11.0734 0x03ac [ Global ] - ok
23:20:11.0734 0x03ac ================ Scan MBR ==================================
23:20:11.0765 0x03ac [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
23:20:12.0000 0x03ac \Device\Harddisk0\DR0 - ok
23:20:12.0000 0x03ac ================ Scan VBR ==================================
23:20:12.0015 0x03ac [ C1F3B11FC466A593363617962F2DE2C3 ] \Device\Harddisk0\DR0\Partition1
23:20:12.0015 0x03ac \Device\Harddisk0\DR0\Partition1 - ok
23:20:12.0031 0x03ac Waiting for KSN requests completion. In queue: 171
23:20:13.0031 0x03ac Waiting for KSN requests completion. In queue: 171
23:20:14.0031 0x03ac Waiting for KSN requests completion. In queue: 171
23:20:15.0093 0x03ac AV detected via SS1: ESET Smart Security 6.0, 6.0, enabled, updated
23:20:15.0093 0x03ac FW detected via SS1: ESET personal firewall, 6.0.316.2, enabled
23:20:17.0875 0x03ac ============================================================
23:20:17.0875 0x03ac Scan finished
23:20:17.0875 0x03ac ============================================================
23:20:17.0906 0x0ea0 Detected object count: 0
23:20:17.0906 0x0ea0 Actual detected object count: 0
23:20:31.0515 0x0af4 Deinitialize success


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 99 hostů