Prosím o kontrolu logu obfuscator.xz VirTool

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 06 pro 2013 19:37

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:36:54, on 6. 12. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
E:\Program Files (x86)\Origin\Origin.exe
E:\Program Files (x86)\Steam\Steam.exe
E:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP ... 5&tsp=4986
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [EADM] "E:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Steam] "E:\Program Files (x86)\Steam\steam.exe" -silent
O4 - Startup: Odeslat do OneNote.lnk = C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
O4 - Startup: RAT 9 Charge Indicator.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8861 bytes
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod jaro3 » 06 pro 2013 20:30

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 06 pro 2013 21:12

TFC odstranil těch 29 Gb Temporary souborů které jsem nevěděl kde jsou.
Adw :# AdwCleaner v3.014 - Report created 06/12/2013 at 21:05:58
# Updated 01/12/2013 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Tadeáš - PC-TED
# Running from : C:\Users\Tadeáš\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\WINDOWS\System32\roboot64.exe
Folder Found C:\ProgramData\Babylon
Folder Found C:\Users\Tadeáš\AppData\Roaming\OpenCandy
Folder Found C:\Users\Tadeáš\AppData\Roaming\Systweak

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\systweak
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\systweak
Key Found : HKLM\SOFTWARE\Classes\Prod.cap

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www2.delta-search.com/?babsrc=HP ... 5&tsp=4986

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Tadeáš\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found : homepage
Found : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [1575 octets] - [06/12/2013 21:05:07]
AdwCleaner[R1].txt - [1481 octets] - [06/12/2013 21:05:58]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1541 octets] ##########


AntiMalware: Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.12.06.08

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16438
Tadeáš :: PC-TED [administrátor]

6. 12. 2013 21:08:50
MBAM-log-2013-12-06 (21-11-58).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 247662
Uplynulý čas: 2 minut, 51 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 1
HKCU\Software\Systweak\RegClean Pro (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage) -> Špatný: (http://www2.delta-search.com/?babsrc=HP ... 5&tsp=4986) Dobrý: (http://www.google.com) -> Nebyla provedena žádná instrukce.

Nalezené složky: 2
C:\Users\Tadeáš\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tadeáš\AppData\Roaming\OpenCandy\1FCA759F56DC43F8BBC4093830126EDB (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 1
C:\Users\Tadeáš\AppData\Roaming\OpenCandy\1FCA759F56DC43F8BBC4093830126EDB\avg_tuht_stf_cs_2014_206_CZ.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.

(konec)
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod jaro3 » 07 pro 2013 10:10

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 10:45

AdwCleaner: Smazal to
# AdwCleaner v3.014 - Report created 08/12/2013 at 10:41:17
# Updated 01/12/2013 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Tadeáš - PC-TED
# Running from : C:\Users\Tadeáš\Desktop\Čističe\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\Tadeáš\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Tadeáš\AppData\Roaming\Systweak
File Deleted : C:\WINDOWS\System32\roboot64.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\systweak

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Tadeáš\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[S0].txt - [1184 octets] - [08/12/2013 10:41:17]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1244 octets] ##########
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 10:49

JRT: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 x64
Ran by Tade ç on ne 08. 12. 2013 at 10:46:43,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 08. 12. 2013 at 10:48:58,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 10:54

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.12.06.08

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16438
Tadeáš :: PC-TED [administrátor]

8. 12. 2013 10:51:22
mbam-log-2013-12-08 (10-51-22).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 247956
Uplynulý čas: 2 minut, 52 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 11:08

RogueKiller V8.7.11 _x64_ [Nov 25 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Tadeáš [Práva správce]
Mód : Kontrola -- Datum : 12/08/2013 11:08:10
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 2 ¤¤¤
[Tadeáš][SUSP UNIC] Odeslat do OneNote.lnk : C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Odeslat do OneNote.lnk @C:\PROGRA~1\MICROS~1\root\office15\ONENOTEM.EXE /tsr [-][7] -> NALEZENO
[Tadeáš][SUSP UNIC] RAT 9 Charge Indicator.lnk : C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RAT 9 Charge Indicator.lnk @C:\Users\Tadeáš\AppData\Roaming\Microsoft\Installer\{E351A4AC-5D5D-4748-A2FE-310EC70F3E05}\_CD6D2B41032FC8A5BF211A.exe [-][-] -> NALEZENO

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000VX000-9YW162 +++++
--- User ---
[MBR] 5a27b934a987b7cb7cd2ca66087f7a89
[BSP] f15fb94c0916ea3664b499426a594fe2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 728064 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1491793920 | Size: 225453 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_12082013_110810.txt >>



Asi to mmám smazat že ?
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod jaro3 » 08 pro 2013 11:09

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 11:17

Díky moc že se mnou ztrácíte čas :) Díky
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 11:22

RogueKiller V8.7.11 _x64_ [Nov 25 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Tadeáš [Práva správce]
Mód : Odebrat -- Datum : 12/08/2013 11:21:06
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 2 ¤¤¤
[Tadeáš][SUSP UNIC] Odeslat do OneNote.lnk : C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Odeslat do OneNote.lnk @C:\PROGRA~1\MICROS~1\root\office15\ONENOTEM.EXE /tsr [-][7] -> VYMAZÁNO
[Tadeáš][SUSP UNIC] RAT 9 Charge Indicator.lnk : C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RAT 9 Charge Indicator.lnk @C:\Users\Tadeáš\AppData\Roaming\Microsoft\Installer\{E351A4AC-5D5D-4748-A2FE-310EC70F3E05}\_CD6D2B41032FC8A5BF211A.exe [-][-] -> VYMAZÁNO

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000VX000-9YW162 +++++
--- User ---
[MBR] 5a27b934a987b7cb7cd2ca66087f7a89
[BSP] f15fb94c0916ea3664b499426a594fe2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 728064 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1491793920 | Size: 225453 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_12082013_112106.txt >>
RKreport[0]_S_12082013_112103.txt
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,

Uživatelský avatar
tarogar
Level 3.5
Level 3.5
Příspěvky: 829
Registrován: červen 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu obfuscator.xz VirTool

Příspěvekod tarogar » 08 pro 2013 11:25

11:24:16.0117 3352 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:24:18.0118 3352 ============================================================
11:24:18.0118 3352 Current date / time: 2013/12/08 11:24:18.0118
11:24:18.0118 3352 SystemInfo:
11:24:18.0118 3352
11:24:18.0118 3352 OS Version: 6.2.9200 ServicePack: 0.0
11:24:18.0118 3352 Product type: Workstation
11:24:18.0118 3352 ComputerName: PC-TED
11:24:18.0119 3352 UserName: Tadeáš
11:24:18.0119 3352 Windows directory: C:\WINDOWS
11:24:18.0119 3352 System windows directory: C:\WINDOWS
11:24:18.0119 3352 Running under WOW64
11:24:18.0119 3352 Processor architecture: Intel x64
11:24:18.0119 3352 Number of processors: 4
11:24:18.0119 3352 Page size: 0x1000
11:24:18.0119 3352 Boot type: Normal boot
11:24:18.0119 3352 ============================================================
11:24:18.0390 3352 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:24:18.0392 3352 ============================================================
11:24:18.0392 3352 \Device\Harddisk0\DR0:
11:24:18.0392 3352 MBR partitions:
11:24:18.0392 3352 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
11:24:18.0392 3352 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0x58E00000
11:24:18.0392 3352 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x58EAF800, BlocksNum 0x1B856800
11:24:18.0392 3352 ============================================================
11:24:18.0410 3352 C: <-> \Device\Harddisk0\DR0\Partition3
11:24:18.0439 3352 E: <-> \Device\Harddisk0\DR0\Partition2
11:24:18.0439 3352 ============================================================
11:24:18.0439 3352 Initialize success
11:24:18.0439 3352 ============================================================
11:24:19.0698 4376 ============================================================
11:24:19.0698 4376 Scan started
11:24:19.0698 4376 Mode: Manual;
11:24:19.0698 4376 ============================================================
11:24:19.0995 4376 ================ Scan system memory ========================
11:24:19.0995 4376 System memory - ok
11:24:19.0996 4376 ================ Scan services =============================
11:24:20.0117 4376 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
11:24:20.0119 4376 1394ohci - ok
11:24:20.0133 4376 [ AD508A1A46EC21B740AB31C28EFDFDB1 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
11:24:20.0134 4376 3ware - ok
11:24:20.0162 4376 [ 3D30878A269D934100FA5F972E53AF39 ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
11:24:20.0167 4376 ACPI - ok
11:24:20.0176 4376 [ AC8279D229398BCF05C3154ADCA86813 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
11:24:20.0177 4376 acpiex - ok
11:24:20.0188 4376 [ A8970D9BF23CD309E0403978A1B58F3F ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
11:24:20.0189 4376 acpipagr - ok
11:24:20.0212 4376 [ 111A89C99C5B4F1A7BCE5F643DD86F65 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
11:24:20.0212 4376 AcpiPmi - ok
11:24:20.0230 4376 [ 5758387D68A20AE7D3245011B07E36E7 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
11:24:20.0231 4376 acpitime - ok
11:24:20.0295 4376 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:24:20.0296 4376 AdobeARMservice - ok
11:24:20.0380 4376 [ A283108E14F3970432C21AF4C0CB1BCE ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
11:24:20.0383 4376 AdobeFlashPlayerUpdateSvc - ok
11:24:20.0408 4376 [ 7C1FDF1B48298CBA7CE4BDD4978951AD ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS
11:24:20.0414 4376 ADP80XX - ok
11:24:20.0442 4376 [ B19CA8E441D35AA2B1EE51C10B27DA1B ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll
11:24:20.0444 4376 AeLookupSvc - ok
11:24:20.0462 4376 [ 239268BAB58EAE9A3FF4E08334C00451 ] AFD C:\WINDOWS\system32\drivers\afd.sys
11:24:20.0466 4376 AFD - ok
11:24:20.0483 4376 [ 7DFAEBA9AD62D20102B576D5CAC45EC8 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys
11:24:20.0483 4376 agp440 - ok
11:24:20.0500 4376 [ 8E8E34B7BA059050EED827410D0697A2 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
11:24:20.0501 4376 ahcache - ok
11:24:20.0534 4376 [ A91D8E1E433EFB32551BCE69037E1CE7 ] ALG C:\WINDOWS\System32\alg.exe
11:24:20.0535 4376 ALG - ok
11:24:20.0542 4376 [ 7589DE749DB6F71A68489DCE04158729 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
11:24:20.0543 4376 AmdK8 - ok
11:24:20.0549 4376 [ B46D2D89AFF8A9490FA8C98C7A5616E3 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
11:24:20.0550 4376 AmdPPM - ok
11:24:20.0568 4376 [ D2BF2F94A47D332814910FD47C6BBCD2 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
11:24:20.0568 4376 amdsata - ok
11:24:20.0584 4376 [ A8E04943C7BBA7219AA50400272C3C6E ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
11:24:20.0586 4376 amdsbs - ok
11:24:20.0600 4376 [ CEA5F4F27CFC08E3A44D576811B35F50 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
11:24:20.0600 4376 amdxata - ok
11:24:20.0617 4376 [ 04951A9A937CBE28A2D3FEEA360B6D1F ] AppID C:\WINDOWS\system32\drivers\appid.sys
11:24:20.0618 4376 AppID - ok
11:24:20.0644 4376 [ C0DC3F58214A227980AEB091CFD2F973 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
11:24:20.0644 4376 AppIDSvc - ok
11:24:20.0663 4376 [ 7E790DE2487CEDB349D1750B9E47F090 ] Appinfo C:\WINDOWS\System32\appinfo.dll
11:24:20.0664 4376 Appinfo - ok
11:24:20.0707 4376 [ 30E3850F303EAE5C364782EA78579CC9 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:24:20.0708 4376 Apple Mobile Device - ok
11:24:20.0729 4376 [ 4B964AE0DF433A3BFA7BD24713BC2E9B ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
11:24:20.0733 4376 AppReadiness - ok
11:24:20.0762 4376 [ 27334B4E29DC8E26FF86E0F075A6CED5 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
11:24:20.0773 4376 AppXSvc - ok
11:24:20.0788 4376 [ 65045784366F7EC5FB4E71BCF923187B ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
11:24:20.0789 4376 arcsas - ok
11:24:20.0804 4376 [ 74B14192CF79A72F7536B27CB8814FBD ] atapi C:\WINDOWS\system32\drivers\atapi.sys
11:24:20.0805 4376 atapi - ok
11:24:20.0827 4376 [ 4903CBC14742B5AB4DCF7A92F7DEC483 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
11:24:20.0829 4376 AudioEndpointBuilder - ok
11:24:20.0848 4376 [ 86DD7884124D363A63CCE7A11FDEBBED ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
11:24:20.0854 4376 Audiosrv - ok
11:24:20.0864 4376 [ 96E8CAF20FC4B6C31CAD7816A801EB78 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
11:24:20.0865 4376 AxInstSV - ok
11:24:20.0881 4376 [ A4A73F631FE2AA2826FBE4A399B04DEF ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
11:24:20.0884 4376 b06bdrv - ok
11:24:20.0902 4376 [ 8CC7F7E4AFCBA605921B137ED7992C68 ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
11:24:20.0903 4376 BasicDisplay - ok
11:24:20.0913 4376 [ 2748E116F8621A4DB0D39FCDD7318C01 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
11:24:20.0913 4376 BasicRender - ok
11:24:20.0924 4376 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21 ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys
11:24:20.0924 4376 bcmfn2 - ok
11:24:20.0965 4376 [ BBE61A40665B83488901E41082A6097D ] BDESVC C:\WINDOWS\System32\bdesvc.dll
11:24:20.0968 4376 BDESVC - ok
11:24:20.0983 4376 [ EC19013E4CF87609534165DF897274D6 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
11:24:20.0984 4376 Beep - ok
11:24:21.0007 4376 [ 6468B696C65775D51A06615830E0E79D ] BFE C:\WINDOWS\System32\bfe.dll
11:24:21.0013 4376 BFE - ok
11:24:21.0060 4376 [ 15225081966C785A9192782401643FD4 ] BITS C:\WINDOWS\System32\qmgr.dll
11:24:21.0069 4376 BITS - ok
11:24:21.0111 4376 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
11:24:21.0115 4376 Bonjour Service - ok
11:24:21.0125 4376 [ 6B4FFFDDC618FCF64473CAA86E305697 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
11:24:21.0126 4376 bowser - ok
11:24:21.0138 4376 [ 748141CC03DF40C38F17D3F96BB15C80 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
11:24:21.0140 4376 BrokerInfrastructure - ok
11:24:21.0153 4376 [ D528D6A92D187777691993DD757AF19A ] Browser C:\WINDOWS\System32\browser.dll
11:24:21.0155 4376 Browser - ok
11:24:21.0171 4376 [ A8F23D453A424FF4DE04989C4727ECC7 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
11:24:21.0172 4376 BthAvrcpTg - ok
11:24:21.0185 4376 [ 746B9F94214915AECDE4B7FEA5FF9664 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
11:24:21.0185 4376 BthHFEnum - ok
11:24:21.0193 4376 [ 71FE2A48E4C93DDB9798C024880B6C07 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
11:24:21.0194 4376 bthhfhid - ok
11:24:21.0211 4376 [ 07E33226AD218A2A162662A05CAFB52F ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
11:24:21.0212 4376 BTHMODEM - ok
11:24:21.0230 4376 [ E5E48FEED73D463175EAB1542495191C ] bthserv C:\WINDOWS\system32\bthserv.dll
11:24:21.0231 4376 bthserv - ok
11:24:21.0237 4376 [ 2FA6510E33F7DEFEC03658B74101A9B9 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
11:24:21.0239 4376 cdfs - ok
11:24:21.0252 4376 [ C6796EA22B513E3457514D92DCDB1A3D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
11:24:21.0253 4376 cdrom - ok
11:24:21.0265 4376 [ AB285CE3431FF3D2ACE669245874C1C7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
11:24:21.0266 4376 CertPropSvc - ok
11:24:21.0277 4376 [ BE9936EDD3267FAAFF94A7835867F00B ] circlass C:\WINDOWS\System32\drivers\circlass.sys
11:24:21.0278 4376 circlass - ok
11:24:21.0300 4376 [ 7F006813C2AFE622C13D7AF94F56CD07 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
11:24:21.0303 4376 CLFS - ok
11:24:21.0334 4376 [ EF6EF85DADC3184A10D8F2F7159973CB ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
11:24:21.0335 4376 CmBatt - ok
11:24:21.0345 4376 [ 825BE21E6395E00698D8A23955A87972 ] CNG C:\WINDOWS\system32\Drivers\cng.sys
11:24:21.0349 4376 CNG - ok
11:24:21.0373 4376 [ 03AAED827C36F35D70900558B8274905 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys
11:24:21.0373 4376 CompositeBus - ok
11:24:21.0377 4376 COMSysApp - ok
11:24:21.0385 4376 [ A1FF7DFBFBE164CF92603C651D304DD2 ] condrv C:\WINDOWS\system32\drivers\condrv.sys
11:24:21.0385 4376 condrv - ok
11:24:21.0414 4376 [ 0EFE4B5884A8032617826A4D76F80969 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
11:24:21.0415 4376 CryptSvc - ok
11:24:21.0429 4376 [ 315BA4BC19316D72B2E037534E048B93 ] dam C:\WINDOWS\system32\drivers\dam.sys
11:24:21.0430 4376 dam - ok
11:24:21.0470 4376 [ 3FD5AE42EC87C6F532A931F96BE731DD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
11:24:21.0477 4376 DcomLaunch - ok
11:24:21.0495 4376 [ F4CCAADC2C78F57E4F16B24C9201CE22 ] defragsvc C:\WINDOWS\System32\defragsvc.dll
11:24:21.0499 4376 defragsvc - ok
11:24:21.0512 4376 [ 0BC71D4D3B5883903C37BF4E13B0F0C5 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
11:24:21.0515 4376 DeviceAssociationService - ok
11:24:21.0529 4376 [ 752A457320A946E03C3AA86C3ACD735E ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
11:24:21.0532 4376 DeviceInstall - ok
11:24:21.0538 4376 [ 5DB26D7E0216D0BF364A81D3829AD7B9 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
11:24:21.0539 4376 Dfsc - ok
11:24:21.0556 4376 [ 8B107F55FD61654A6C9F1B819AEC5FC4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
11:24:21.0560 4376 Dhcp - ok
11:24:21.0570 4376 [ 4D40C9B33F738797CF50E77CB7C53E85 ] disk C:\WINDOWS\system32\drivers\disk.sys
11:24:21.0571 4376 disk - ok
11:24:21.0585 4376 [ EB70A894708D1BC176AFD690FF06085F ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
11:24:21.0586 4376 dmvsc - ok
11:24:21.0609 4376 [ 5BAF7714E68F93515A937A3FA8587EF9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
11:24:21.0612 4376 Dnscache - ok
11:24:21.0630 4376 [ 50288EA079BB520C2B8C8A154202D518 ] dot3svc C:\WINDOWS\System32\dot3svc.dll
11:24:21.0633 4376 dot3svc - ok
11:24:21.0649 4376 [ 281BEE07BA97E3E98D12A822D923D0D8 ] DPS C:\WINDOWS\system32\dps.dll
11:24:21.0651 4376 DPS - ok
11:24:21.0674 4376 [ DDC11A202207C0400CBE07315B8FDE5E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
11:24:21.0674 4376 drmkaud - ok
11:24:21.0710 4376 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
11:24:21.0712 4376 DsmSvc - ok
11:24:21.0745 4376 [ DA8E85F1BE0C9B7D2EE2949248A389D8 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
11:24:21.0757 4376 DXGKrnl - ok
11:24:21.0774 4376 [ 6073537F250B45E1CB2A02E97F0FE1B2 ] Eaphost C:\WINDOWS\System32\eapsvc.dll
11:24:21.0775 4376 Eaphost - ok
11:24:21.0829 4376 [ 114BCFDF367FF37C3F1B0A96AF542E4D ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
11:24:21.0853 4376 ebdrv - ok
11:24:21.0856 4376 [ F6F209DDB94959BA104FC8FC87C53759 ] EFS C:\WINDOWS\System32\lsass.exe
11:24:21.0857 4376 EFS - ok
11:24:21.0859 4376 [ 43531A5993380CC5113242C29D265FD9 ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
11:24:21.0859 4376 EhStorClass - ok
11:24:21.0892 4376 [ 6F8E738A9505A388B1157FDDE7B3101B ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
11:24:21.0893 4376 EhStorTcgDrv - ok
11:24:21.0899 4376 [ DFFFAE1442BA4076E18EED5E406FA0D3 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
11:24:21.0899 4376 ErrDev - ok
11:24:21.0916 4376 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3 ] EventSystem C:\WINDOWS\system32\es.dll
11:24:21.0918 4376 EventSystem - ok
11:24:21.0931 4376 [ 7729D294A555C7AEB281ED8E4D0E01E4 ] exfat C:\WINDOWS\system32\drivers\exfat.sys
11:24:21.0932 4376 exfat - ok
11:24:21.0949 4376 [ 7C4E0D5900B2A1D11EDD626D6DDB937B ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
11:24:21.0950 4376 fastfat - ok
11:24:21.0978 4376 [ 2BC8532ABF2B3756B78FA1DA54147DDE ] Fax C:\WINDOWS\system32\fxssvc.exe
11:24:21.0980 4376 Fax - ok
11:24:21.0986 4376 [ 5D8402613E778B3BD45E687A8372710B ] fdc C:\WINDOWS\System32\drivers\fdc.sys
11:24:21.0986 4376 fdc - ok
11:24:21.0992 4376 [ DC1A78BCCCB7EE53D6FD3BD615A8E222 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
11:24:21.0992 4376 fdPHost - ok
11:24:21.0998 4376 [ E5AD448F2DC84B1CF387FA7F2A3D1936 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
11:24:21.0999 4376 FDResPub - ok
11:24:22.0014 4376 [ 0046E0BD031213D37123876B0D0FA61C ] fhsvc C:\WINDOWS\system32\fhsvc.dll
11:24:22.0015 4376 fhsvc - ok
11:24:22.0017 4376 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
11:24:22.0017 4376 FileInfo - ok
11:24:22.0029 4376 [ A1A66C4FDAFD6B0289523232AFB7D8AF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
11:24:22.0029 4376 Filetrace - ok
11:24:22.0040 4376 [ BE743083CF7063C486A4398E3AEFE59A ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
11:24:22.0040 4376 flpydisk - ok
11:24:22.0045 4376 [ 60D5067FCE6D9433D35E04C01D8538B3 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
11:24:22.0046 4376 FltMgr - ok
11:24:22.0071 4376 [ 183CA7699474FDE235853967D1DA4D9B ] FontCache C:\WINDOWS\system32\FntCache.dll
11:24:22.0076 4376 FontCache - ok
11:24:22.0147 4376 [ 1C52387BF5A127F5F3BFB31288F30D93 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:24:22.0148 4376 FontCache3.0.0.0 - ok
11:24:22.0161 4376 [ 35005534E600E993A90B036E4E599F2B ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
11:24:22.0161 4376 FsDepends - ok
11:24:22.0166 4376 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:24:22.0166 4376 Fs_Rec - ok
11:24:22.0187 4376 [ 83E1F0983B02A6F8EC764D18E24ECF10 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
11:24:22.0193 4376 fvevol - ok
11:24:22.0203 4376 [ 9591D0B9351ED489EAFD9D1CE52A8015 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys
11:24:22.0204 4376 FxPPM - ok
11:24:22.0223 4376 [ FC3EF65EE20D39F8749C2218DBA681CA ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys
11:24:22.0223 4376 gagp30kx - ok
11:24:22.0251 4376 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
11:24:22.0251 4376 GEARAspiWDM - ok
11:24:22.0284 4376 [ 0BF5CAD281E25F1418E5B8875DC5ADD1 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
11:24:22.0296 4376 gencounter - ok
11:24:22.0308 4376 [ FDA72810CA2F8409D9B31E833C448E34 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
11:24:22.0310 4376 GPIOClx0101 - ok
11:24:22.0346 4376 [ 0BDE0FCF597E9B65600121EF54FF8340 ] gpsvc C:\WINDOWS\System32\gpsvc.dll
11:24:22.0356 4376 gpsvc - ok
11:24:22.0393 4376 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:24:22.0394 4376 gupdate - ok
11:24:22.0399 4376 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:24:22.0400 4376 gupdatem - ok
11:24:22.0426 4376 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
11:24:22.0427 4376 HDAudBus - ok
11:24:22.0453 4376 [ 10A70BC1871CD955D85CD88372724906 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
11:24:22.0453 4376 HidBatt - ok
11:24:22.0481 4376 [ 1EA1B4FABB8CC348E73CA90DBA22E104 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
11:24:22.0482 4376 HidBth - ok
11:24:22.0500 4376 [ C241A8BAFBBFC90176EA0F5240EACC17 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
11:24:22.0501 4376 hidi2c - ok
11:24:22.0528 4376 [ 9BDDEE26255421017E161CCB9D5EDA95 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
11:24:22.0529 4376 HidIr - ok
11:24:22.0540 4376 [ 449A20A674AA3FAA7F0DD4E33EE2DC20 ] hidserv C:\WINDOWS\system32\hidserv.dll
11:24:22.0542 4376 hidserv - ok
11:24:22.0550 4376 [ F31397220D9687E11EB448649AA6E038 ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
11:24:22.0551 4376 HidUsb - ok
11:24:22.0577 4376 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll
11:24:22.0579 4376 hkmsvc - ok
11:24:22.0593 4376 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
11:24:22.0596 4376 HomeGroupListener - ok
11:24:22.0629 4376 [ BE5F89BAFBD4272D5A0C0A37B97865ED ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
11:24:22.0633 4376 HomeGroupProvider - ok
11:24:22.0645 4376 [ A6AACEA4C785789BDA5912AD1FEDA80D ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
11:24:22.0646 4376 HpSAMD - ok
11:24:22.0673 4376 [ 3502776E366C913D49C0DA928AE3E6CB ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
11:24:22.0680 4376 HTTP - ok
11:24:22.0714 4376 [ 90656C0B3864804B090434EFC582404F ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
11:24:22.0714 4376 hwpolicy - ok
11:24:22.0724 4376 [ 6D6F9E3BF0484967E52F7E846BFF1CA1 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
11:24:22.0724 4376 hyperkbd - ok
11:24:22.0738 4376 [ 907C870F8C31F8DDD6F090857B46AB25 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
11:24:22.0738 4376 HyperVideo - ok
11:24:22.0765 4376 [ 84CFC5EFA97D0C965EDE1D56F116A541 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
11:24:22.0766 4376 i8042prt - ok
11:24:22.0780 4376 [ 5D90E32E36CE5D4C535D17CE08AEAF05 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
11:24:22.0781 4376 iaLPSSi_GPIO - ok
11:24:22.0796 4376 [ DD05E7E80F52ADE9AEB292819920F32C ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
11:24:22.0797 4376 iaLPSSi_I2C - ok
11:24:22.0815 4376 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys
11:24:22.0818 4376 iaStorAV - ok
11:24:22.0832 4376 [ A2200C3033FA4EF249FC096A7A7D02A2 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
11:24:22.0834 4376 iaStorV - ok
11:24:22.0836 4376 IEEtwCollectorService - ok
11:24:22.0867 4376 [ B82255670D270B75D2D2F0F8747D1443 ] IKEEXT C:\WINDOWS\System32\ikeext.dll
11:24:22.0872 4376 IKEEXT - ok
11:24:22.0968 4376 [ 9CC645EB9697AA4F2D5A39835C80A0A2 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
11:24:22.0994 4376 IntcAzAudAddService - ok
11:24:22.0997 4376 [ 4E448FCFFD00E8D657CD9E48D3E47157 ] intelide C:\WINDOWS\system32\drivers\intelide.sys
11:24:22.0997 4376 intelide - ok
11:24:23.0016 4376 [ C1A9592EE57C6FF0A0904B9DFD55942D ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
11:24:23.0016 4376 intelpep - ok
11:24:23.0026 4376 [ 47E74A8E53C7C24DCE38311E1451C1D9 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
11:24:23.0027 4376 intelppm - ok
11:24:23.0039 4376 [ 9DB76D7F9E4E53EFE5DD8C53DE837514 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:24:23.0040 4376 IpFilterDriver - ok
11:24:23.0061 4376 [ DFC4050D58565ADBEE793A8D4AEBDAE6 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
11:24:23.0068 4376 iphlpsvc - ok
11:24:23.0086 4376 [ 9949A3C7590B8C536C05312205079A82 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
11:24:23.0087 4376 IPMIDRV - ok
11:24:23.0092 4376 [ E23D32BAF152FBE35F18C6A2AB8EF271 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
11:24:23.0093 4376 IPNAT - ok
11:24:23.0120 4376 [ 33B286326BD2B1A7748C43391058FB19 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
11:24:23.0125 4376 iPod Service - ok
11:24:23.0136 4376 [ AE44C526AB5F8A487D941CEB57B10C97 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
11:24:23.0137 4376 IRENUM - ok
11:24:23.0149 4376 [ 8AFEEA3955AA43616A60F133B1D25F21 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
11:24:23.0150 4376 isapnp - ok
11:24:23.0199 4376 [ 034D4BD9DC67C64F3A4C8A049B5173BF ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
11:24:23.0202 4376 iScsiPrt - ok
11:24:23.0213 4376 [ 8BE92376799B6B44D543E8D07CDCF885 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
11:24:23.0214 4376 kbdclass - ok
11:24:23.0218 4376 [ FB6E47E569D4872ABEB506BE03A45FBA ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
11:24:23.0219 4376 kbdhid - ok
11:24:23.0228 4376 [ 813871C7D402A05F2E3A7075F9584A05 ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys
11:24:23.0229 4376 kdnic - ok
11:24:23.0239 4376 [ F6F209DDB94959BA104FC8FC87C53759 ] KeyIso C:\WINDOWS\system32\lsass.exe
11:24:23.0241 4376 KeyIso - ok
11:24:23.0255 4376 [ ADDECBCC777665BD113BED437E602AB0 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
11:24:23.0256 4376 KSecDD - ok
11:24:23.0268 4376 [ 7296EA420134EAC390798B3232D066A4 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
11:24:23.0270 4376 KSecPkg - ok
11:24:23.0274 4376 [ 11AFB527AA370B1DAFD5C36F35F6D45F ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
11:24:23.0274 4376 ksthunk - ok
11:24:23.0306 4376 [ 32B1A8351160F307A8C66BCB0F94A9C2 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
11:24:23.0310 4376 KtmRm - ok
11:24:23.0340 4376 [ 27B58E16CF895AC1F1A97C04814C2239 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
11:24:23.0344 4376 LanmanServer - ok
11:24:23.0360 4376 [ D0D9C2ECA4D03A8F06DCD91236B90C98 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
11:24:23.0364 4376 LanmanWorkstation - ok
11:24:23.0390 4376 [ EE289BD147FDFF95EF1B9BD65D3B974A ] lfsvc C:\WINDOWS\System32\GeofenceMonitorService.dll
11:24:23.0395 4376 lfsvc - ok
11:24:23.0409 4376 [ C09010B3680860131631F53E8FE7BAD8 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys
11:24:23.0409 4376 lltdio - ok
11:24:23.0430 4376 [ 00E070FC0C673311AFD4B068D1242780 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
11:24:23.0433 4376 lltdsvc - ok
11:24:23.0449 4376 [ D113FAD71A5E67AA94B32A0F8828D265 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
11:24:23.0450 4376 lmhosts - ok
11:24:23.0469 4376 [ C755AE4635457AA2A11F79C0DF857ABC ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
11:24:23.0470 4376 LSI_SAS - ok
11:24:23.0480 4376 [ ADAC09CBE7A2040B7F68B5E5C9A75141 ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys
11:24:23.0481 4376 LSI_SAS2 - ok
11:24:23.0493 4376 [ 04D1274BB9BBCCF12BD12374002AA191 ] LSI_SAS3 C:\WINDOWS\system32\drivers\lsi_sas3.sys
11:24:23.0494 4376 LSI_SAS3 - ok
11:24:23.0503 4376 [ 327469EEF3833D0C584B7E88A76AEC0C ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
11:24:23.0504 4376 LSI_SSS - ok
11:24:23.0524 4376 [ B6B69FF200F68888A7FAFDF204D00C91 ] LSM C:\WINDOWS\System32\lsm.dll
11:24:23.0530 4376 LSM - ok
11:24:23.0545 4376 [ 5EF604B0698F4FA962778285E8C5F1F2 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
11:24:23.0546 4376 luafv - ok
11:24:23.0556 4376 [ 8FF2D95CBA49B405C5DE27039FF0BF35 ] MBfilt C:\WINDOWS\system32\drivers\MBfilt64.sys
11:24:23.0557 4376 MBfilt - ok
11:24:23.0571 4376 [ EB5C03A070F30D64A6DF80E53B22F53F ] megasas C:\WINDOWS\system32\drivers\megasas.sys
11:24:23.0572 4376 megasas - ok
11:24:23.0589 4376 [ F6F13533196DE7A582D422B0241E4363 ] megasr C:\WINDOWS\system32\drivers\megasr.sys
11:24:23.0593 4376 megasr - ok
11:24:23.0607 4376 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
11:24:23.0608 4376 MEIx64 - ok
11:24:23.0617 4376 [ FD788C2D96EA91469A3C1D13E80D7473 ] MMCSS C:\WINDOWS\system32\mmcss.dll
11:24:23.0619 4376 MMCSS - ok
11:24:23.0624 4376 [ 8B38C44F69259987C95135C9627E2378 ] Modem C:\WINDOWS\system32\drivers\modem.sys
11:24:23.0624 4376 Modem - ok
11:24:23.0635 4376 [ 601589000CC90F0DF8DA2CC254A3CCC9 ] monitor C:\WINDOWS\System32\drivers\monitor.sys
11:24:23.0635 4376 monitor - ok
11:24:23.0649 4376 [ CEAC6D40FE887CE8406C2393CF97DE06 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys
11:24:23.0650 4376 mouclass - ok
11:24:23.0660 4376 [ 02D98BF804084E9A0D69D1C69B02CCA9 ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys
11:24:23.0660 4376 mouhid - ok
11:24:23.0665 4376 [ 515549560D481138E6E21AF7C6998E56 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys
11:24:23.0666 4376 mountmgr - ok
11:24:23.0671 4376 [ F170510BE94CF45E3C6274578F6204B2 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys
11:24:23.0672 4376 mpsdrv - ok
11:24:23.0709 4376 [ D186C5844393252147BE934F3871DB7A ] MpsSvc C:\WINDOWS\system32\mpssvc.dll
11:24:23.0716 4376 MpsSvc - ok
11:24:23.0721 4376 [ 59DCEC7499095DE5AED741358037AE2D ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
11:24:23.0723 4376 MRxDAV - ok
11:24:23.0750 4376 [ 6129EDB793A4255B1E2FB41773AC9D9A ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:24:23.0753 4376 mrxsmb - ok
11:24:23.0759 4376 [ 295771B092D4F7FCF2B62F80CCD14320 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
11:24:23.0761 4376 mrxsmb10 - ok
11:24:23.0791 4376 [ AAF56E4E84D35411B4E446C445732DFE ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
11:24:23.0793 4376 mrxsmb20 - ok
11:24:23.0809 4376 [ 4E888019078AC363076A5433E89AA4F8 ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys
11:24:23.0810 4376 MsBridge - ok
11:24:23.0831 4376 [ A082C17D14D0790E27D064EA4B138AE1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
11:24:23.0833 4376 MSDTC - ok
11:24:23.0842 4376 [ D13329FBF8345B28AB30F44CC247DC08 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
11:24:23.0843 4376 Msfs - ok
11:24:23.0859 4376 [ C6B474E46F9E543B875981ED3FFE6ADD ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
11:24:23.0860 4376 msgpiowin32 - ok
11:24:23.0872 4376 [ 65C92EB9D08DB5C69F28C7FFD4E84E31 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys
11:24:23.0872 4376 mshidkmdf - ok
11:24:23.0880 4376 [ 52299F086AC2DAFD100DD5DC4A8614BA ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
11:24:23.0881 4376 mshidumdf - ok
11:24:23.0894 4376 [ 36D92AF3343C3A3E57FEF11C449AEA4C ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys
11:24:23.0895 4376 msisadrv - ok
11:24:23.0916 4376 [ 810F8A0A0680662BB0CE44D0E2CEF90C ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll
11:24:23.0918 4376 MSiSCSI - ok
11:24:23.0922 4376 msiserver - ok
11:24:23.0936 4376 [ A9BBBD2BAE6142253B9195E949AC2E8D ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:24:23.0937 4376 MSKSSRV - ok
11:24:23.0949 4376 [ 375E44168F2DFB91A68B8A3F619C5A7C ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys
11:24:23.0950 4376 MsLldp - ok
11:24:23.0963 4376 [ 7B2128EB875DCBC006E6A913211006D6 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:24:23.0963 4376 MSPCLOCK - ok
11:24:23.0975 4376 [ 1E88171579B218115C7A772F8DE04BD8 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
11:24:23.0975 4376 MSPQM - ok
11:24:23.0983 4376 [ BBE2A455053E63BECBF42C2F9B21FAE0 ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys
11:24:23.0986 4376 MsRPC - ok
11:24:24.0004 4376 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys
11:24:24.0005 4376 mssmbios - ok
11:24:24.0016 4376 [ 115019AE01E0EB9C048530D2928AB4A2 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
11:24:24.0016 4376 MSTEE - ok
11:24:24.0025 4376 [ 96D604A35070360F0DD4A7A8AF410B5E ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
11:24:24.0025 4376 MTConfig - ok
11:24:24.0030 4376 [ 619CA29326B82372621DB2C0964D8365 ] Mup C:\WINDOWS\system32\Drivers\mup.sys
11:24:24.0031 4376 Mup - ok
11:24:24.0045 4376 [ B8C35C94DCB2DFEAF03BB42131F2F77F ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
11:24:24.0045 4376 mvumis - ok
11:24:24.0071 4376 [ 41A45D2A75494EABF2806EA051E00376 ] napagent C:\WINDOWS\system32\qagentRT.dll
11:24:24.0076 4376 napagent - ok
11:24:24.0095 4376 [ CF8B989D89D6807B887690F2CF24EFD9 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
11:24:24.0099 4376 NativeWifiP - ok
11:24:24.0115 4376 [ 71E3C0100AA19D11373CCEB2F51A6008 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
11:24:24.0118 4376 NcaSvc - ok
11:24:24.0132 4376 [ 51DF09CAB2CAC64FEE3E371D9028ED01 ] NcbService C:\WINDOWS\System32\ncbservice.dll
11:24:24.0135 4376 NcbService - ok
11:24:24.0148 4376 [ 2586C4C167499210DCBF3ECFD8CCE210 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
11:24:24.0150 4376 NcdAutoSetup - ok
11:24:24.0179 4376 [ AD9086052A5E5153AF43FE74138A4B27 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
11:24:24.0187 4376 NDIS - ok
11:24:24.0197 4376 [ C6BB12BC35D1637CA17AE16D3A4725EB ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
11:24:24.0198 4376 NdisCap - ok
11:24:24.0225 4376 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
11:24:24.0226 4376 NdisImPlatform - ok
11:24:24.0241 4376 [ 9423421E735BD5394351E0C47C76BB92 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:24:24.0241 4376 NdisTapi - ok
11:24:24.0251 4376 [ B832B35055BA2B7B4181861FF94D8E59 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:24:24.0252 4376 Ndisuio - ok
11:24:24.0255 4376 [ 1F58E48EF75F34C35D8E93A0DC535CFE ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
11:24:24.0256 4376 NdisVirtualBus - ok
11:24:24.0268 4376 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:24:24.0269 4376 NdisWan - ok
11:24:24.0284 4376 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWanLegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:24:24.0286 4376 NdisWanLegacy - ok
11:24:24.0299 4376 [ A5BD69A8812FA79D1A487691DD3FB244 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
11:24:24.0300 4376 NDProxy - ok
11:24:24.0313 4376 [ 5A072F0B90C29C5233D78BE33EF5ED78 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
11:24:24.0315 4376 Ndu - ok
11:24:24.0325 4376 [ AC9AE6D15307A627D5F8574A3A788525 ] Neo_VPN C:\WINDOWS\system32\DRIVERS\Neo_VPN.sys
11:24:24.0326 4376 Neo_VPN - ok
11:24:24.0330 4376 [ A83D67D347A684F10B7D3019C8A6380C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
11:24:24.0331 4376 NetBIOS - ok
11:24:24.0337 4376 [ 0217532E19A748F0E5D569307363D5FD ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
11:24:24.0340 4376 NetBT - ok
11:24:24.0348 4376 [ F6F209DDB94959BA104FC8FC87C53759 ] Netlogon C:\WINDOWS\system32\lsass.exe
11:24:24.0349 4376 Netlogon - ok
11:24:24.0365 4376 [ B7AD851A21FEBA3BA214972627614207 ] Netman C:\WINDOWS\System32\netman.dll
11:24:24.0367 4376 Netman - ok
11:24:24.0387 4376 [ F0F0A372C2EF6358399C4936F91B6131 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
11:24:24.0390 4376 netprofm - ok
11:24:24.0429 4376 [ 1092B3190E69E0C5ECBCE90F171DE047 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:24:24.0430 4376 NetTcpPortSharing - ok
11:24:24.0459 4376 [ 70414DB660BFBB7BD58FCE8EA4364E1B ] netvsc C:\WINDOWS\system32\DRIVERS\netvsc63.sys
11:24:24.0460 4376 netvsc - ok
11:24:24.0476 4376 [ 3A280F3B3C7A46E29C404ACD46ECBF5E ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
11:24:24.0480 4376 NlaSvc - ok
11:24:24.0485 4376 [ 8F44A2F57C9F1A19AC9C6288C10FB351 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
11:24:24.0486 4376 Npfs - ok
11:24:24.0491 4376 [ CBDB4F0871C88DF930FC0E8588CA67FC ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
11:24:24.0491 4376 npsvctrig - ok
11:24:24.0498 4376 [ 6E2271ED0C3E95B8E29F3752B91B9E84 ] nsi C:\WINDOWS\system32\nsisvc.dll
11:24:24.0500 4376 nsi - ok
11:24:24.0503 4376 [ E490B459978CB87779E84C761D22B827 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
11:24:24.0504 4376 nsiproxy - ok
11:24:24.0545 4376 [ 4412D565C0278C401575E11072C7DCE3 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
11:24:24.0556 4376 Ntfs - ok
11:24:24.0566 4376 [ EF1B290FC9F0E47CC0B537292BEE5904 ] Null C:\WINDOWS\system32\drivers\Null.sys
11:24:24.0566 4376 Null - ok
11:24:24.0579 4376 [ 554964B900AE2954B8B589B6287034AC ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
11:24:24.0580 4376 NVHDA - ok
11:24:24.0763 4376 [ F554291C0A11F5B713B54C5886D4AA31 ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
11:24:24.0804 4376 nvlddmkm - ok
11:24:24.0821 4376 [ BC6B5942AFF25EBAF62DE43C3807EDF8 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
11:24:24.0822 4376 nvraid - ok
11:24:24.0825 4376 [ 1F43ABFFAC3D6CA356851D517392966E ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
11:24:24.0826 4376 nvstor - ok
11:24:25.0039 4376 [ 259A2A5AE440B5EC3F6DEA96AA90F3BF ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
11:24:25.0086 4376 NvStreamSvc - ok
11:24:25.0110 4376 [ 8E99BF264C1F20934A67E91BC9F4FB20 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
11:24:25.0114 4376 nvsvc - ok
11:24:25.0168 4376 [ 815290E27B7B7D12AF013638819BE1B6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
11:24:25.0182 4376 nvUpdatusService - ok
11:24:25.0188 4376 [ 31B16657118E439B77B0A527F7EA66CB ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
11:24:25.0188 4376 nvvad_WaveExtensible - ok
11:24:25.0198 4376 [ 6934A936A7369DFE37B7DBA93F5E5E49 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
11:24:25.0199 4376 nv_agp - ok
11:24:25.0277 4376 [ D02B9C22F789B320CD87A4A9D1C0FC09 ] OfficeSvc C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
11:24:25.0290 4376 OfficeSvc - ok
11:24:25.0321 4376 [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:24:25.0322 4376 ose - ok
11:24:25.0355 4376 [ 3B510F20806B94E389784ED09DBD2111 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
11:24:25.0360 4376 p2pimsvc - ok
11:24:25.0376 4376 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B ] p2psvc C:\WINDOWS\system32\p2psvc.dll
11:24:25.0381 4376 p2psvc - ok
11:24:25.0409 4376 [ 764B1121867B2D9B31C491668AC72B2B ] Parport C:\WINDOWS\System32\drivers\parport.sys
11:24:25.0410 4376 Parport - ok
11:24:25.0425 4376 [ EF0C1749C9A8CEE9A457473D433CC00F ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
11:24:25.0426 4376 partmgr - ok
11:24:25.0447 4376 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
11:24:25.0452 4376 PcaSvc - ok
11:24:25.0469 4376 [ C0D3F3BC1C84B4BA746D9847314C1164 ] pci C:\WINDOWS\system32\drivers\pci.sys
11:24:25.0471 4376 pci - ok
11:24:25.0476 4376 [ 346E38FCC6859A727DD28AFAD1F0AFF4 ] pciide C:\WINDOWS\system32\drivers\pciide.sys
11:24:25.0476 4376 pciide - ok
11:24:25.0498 4376 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
11:24:25.0499 4376 pcmcia - ok
11:24:25.0503 4376 [ BF28771D1436C88BE1D297D3098B0F7D ] pcw C:\WINDOWS\system32\drivers\pcw.sys
11:24:25.0504 4376 pcw - ok
11:24:25.0525 4376 [ E170103E68329E9154A5EC383CD253ED ] pdc C:\WINDOWS\system32\drivers\pdc.sys
11:24:25.0526 4376 pdc - ok
11:24:25.0545 4376 [ BA50CC0BD19004AAB88BE37338B6FA0D ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
11:24:25.0550 4376 PEAUTH - ok
11:24:25.0612 4376 [ 8E3C640FFF5A963F570233AE99C0FFF3 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
11:24:25.0614 4376 PerfHost - ok
11:24:25.0656 4376 [ 928061178CD9856CA6B67FFFCE6BA766 ] pla C:\WINDOWS\system32\pla.dll
11:24:25.0665 4376 pla - ok
11:24:25.0679 4376 [ 752A457320A946E03C3AA86C3ACD735E ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
11:24:25.0681 4376 PlugPlay - ok
11:24:25.0684 4376 PnkBstrA - ok
11:24:25.0692 4376 [ 045EB4F260606A03BE340D09DEAF3BA4 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
11:24:25.0693 4376 PNRPAutoReg - ok
11:24:25.0704 4376 [ 3B510F20806B94E389784ED09DBD2111 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
11:24:25.0707 4376 PNRPsvc - ok
11:24:25.0739 4376 [ C16097D77A232A288D65F299E2E01105 ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
11:24:25.0742 4376 PolicyAgent - ok
11:24:25.0751 4376 [ 00E08B30E7F7C13ECE2CDF4F46A77311 ] Power C:\WINDOWS\system32\umpo.dll
11:24:25.0754 4376 Power - ok
11:24:25.0819 4376 [ B7DB57A000D46D4DE75BC0C563E58072 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
11:24:25.0829 4376 PrintNotify - ok
11:24:25.0852 4376 [ ECD373F9571C745894367CC2635EA44F ] Processor C:\WINDOWS\System32\drivers\processr.sys
11:24:25.0852 4376 Processor - ok
11:24:25.0870 4376 [ 8513A1E7AE4B9DC82C4B4F432C648A58 ] ProfSvc C:\WINDOWS\system32\profsvc.dll
11:24:25.0871 4376 ProfSvc - ok
11:24:25.0881 4376 [ 8528BB05E4D4E25945F78B00B2555FB7 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
11:24:25.0881 4376 Psched - ok
11:24:25.0897 4376 [ AF90BB44C99D6820BE52C9BBAA523283 ] QWAVE C:\WINDOWS\system32\qwave.dll
11:24:25.0899 4376 QWAVE - ok
11:24:25.0905 4376 [ 3FB466684609A4329858CF2EBD62E0FD ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
11:24:25.0906 4376 QWAVEdrv - ok
11:24:25.0913 4376 [ 2C56F0EE27E4EF70CA4B4983D3638905 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:24:25.0913 4376 RasAcd - ok
11:24:25.0928 4376 [ 5F061AC45266841A2860C1858ED863B8 ] RasAuto C:\WINDOWS\System32\rasauto.dll
11:24:25.0929 4376 RasAuto - ok
11:24:25.0939 4376 [ BF3B17016764F20F9D28CF1A8DC210C0 ] RasMan C:\WINDOWS\System32\rasmans.dll
11:24:25.0942 4376 RasMan - ok
11:24:25.0958 4376 [ 5247F308C4103CDC4FE12AE1D235800A ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:24:25.0958 4376 RasPppoe - ok
11:24:25.0974 4376 [ B939A2A0F9D6C6C186721E268EB6FA93 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:24:25.0976 4376 rdbss - ok
11:24:25.0988 4376 [ 6B21EBF892CD8CACB71669B35AB5DE32 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
11:24:25.0989 4376 rdpbus - ok
11:24:26.0002 4376 [ 680C1DAE268B6FB67FA21B389A8B79EF ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
11:24:26.0003 4376 RDPDR - ok
11:24:26.0017 4376 [ 858776908AF838E3790F3261B799CDA6 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
11:24:26.0017 4376 RdpVideoMiniport - ok
11:24:26.0034 4376 [ 847C6A08912C3515807049C93E526D65 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
11:24:26.0035 4376 rdyboost - ok
11:24:26.0058 4376 [ 036746D54347FD2D0385668E2A4064E4 ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys
11:24:26.0062 4376 ReFS - ok
11:24:26.0094 4376 [ BFFB40FBE6D2C3469F8D06EE5E4934AB ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
11:24:26.0097 4376 RemoteAccess - ok
11:24:26.0108 4376 [ 4DCCABE03D06955ED61BABBD8EF9F30F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
11:24:26.0111 4376 RemoteRegistry - ok
11:24:26.0123 4376 [ D894CBD7DA753C881EE8D5E33B583225 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
11:24:26.0126 4376 RpcEptMapper - ok
11:24:26.0150 4376 [ 5CAE8F47B31D5CFC322B5B898C19E0FE ] RpcLocator C:\WINDOWS\system32\locator.exe
11:24:26.0152 4376 RpcLocator - ok
11:24:26.0170 4376 [ 3FD5AE42EC87C6F532A931F96BE731DD ] RpcSs C:\WINDOWS\system32\rpcss.dll
11:24:26.0177 4376 RpcSs - ok
11:24:26.0187 4376 [ 2D05A5508F4685412F2B89E8C2189ABC ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
11:24:26.0188 4376 rspndr - ok
11:24:26.0222 4376 [ 19764658C1468C2C0CEF133D28414A6B ] RTL8168 C:\WINDOWS\system32\DRIVERS\Rt630x64.sys
11:24:26.0226 4376 RTL8168 - ok
11:24:26.0239 4376 [ 1A063730F221B2746FF00457AE17E4F0 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
11:24:26.0240 4376 s3cap - ok
11:24:26.0271 4376 [ AEED412196AA928A752641E41F358464 ] SaiK1709 C:\WINDOWS\system32\DRIVERS\SaiK1709.sys
11:24:26.0273 4376 SaiK1709 - ok
11:24:26.0295 4376 [ B08581EDF3290210D3366CD2D992F6C2 ] SaiMini C:\WINDOWS\System32\drivers\SaiMini.sys
11:24:26.0296 4376 SaiMini - ok
11:24:26.0303 4376 [ D086C2F45D328C2F63FC6B4CD79FCB66 ] SaiNtBus C:\WINDOWS\system32\drivers\SaiBus.sys
11:24:26.0303 4376 SaiNtBus - ok
11:24:26.0310 4376 [ E0BB0A98692A8227A281ED0FA71F6AE4 ] SaiU1709 C:\WINDOWS\System32\drivers\SaiU1709.sys
11:24:26.0311 4376 SaiU1709 - ok
11:24:26.0323 4376 [ F6F209DDB94959BA104FC8FC87C53759 ] SamSs C:\WINDOWS\system32\lsass.exe
11:24:26.0325 4376 SamSs - ok
11:24:26.0347 4376 [ C624A1B32211C3166EDB3F4AB02A30B7 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
11:24:26.0348 4376 sbp2port - ok
11:24:26.0363 4376 [ 47C497FA4DDEA908633CAA60CEBE6805 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
11:24:26.0366 4376 SCardSvr - ok
11:24:26.0381 4376 [ E76C4E98302AE39CC6FA5D20FC8B5438 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
11:24:26.0384 4376 ScDeviceEnum - ok
11:24:26.0393 4376 [ ABD0237B15DBD2B4695F4B7D734A58F7 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
11:24:26.0394 4376 scfilter - ok
11:24:26.0423 4376 [ 888A30EAB651502352C18745367FD179 ] Schedule C:\WINDOWS\system32\schedsvc.dll
11:24:26.0433 4376 Schedule - ok
11:24:26.0465 4376 [ AB285CE3431FF3D2ACE669245874C1C7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
11:24:26.0466 4376 SCPolicySvc - ok
11:24:26.0506 4376 [ 2F9A3380B8C0380E5608E29C7AA66899 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
11:24:26.0508 4376 sdbus - ok
11:24:26.0542 4376 [ 4EAF4DCF9DBD9A56952A58F56D61C005 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
11:24:26.0543 4376 sdstor - ok
11:24:26.0557 4376 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
11:24:26.0558 4376 secdrv - ok
11:24:26.0572 4376 [ C49009F897BA4F2F4F31043663AA1485 ] seclogon C:\WINDOWS\system32\seclogon.dll
11:24:26.0574 4376 seclogon - ok
11:24:26.0585 4376 [ A88882E64BDC1D8E8D6E727B71CCCC53 ] SENS C:\WINDOWS\System32\sens.dll
11:24:26.0587 4376 SENS - ok
11:24:26.0601 4376 [ E66A7C8CE7ED22DED6DF1CA479FB4790 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
11:24:26.0604 4376 SensrSvc - ok
11:24:26.0616 4376 [ DB2FF24CE0BDD15FE75870AFE312BA89 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
11:24:26.0617 4376 SerCx - ok
11:24:26.0628 4376 [ 53BDBF04ECAF943CBF6359E3BCB2445E ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
11:24:26.0630 4376 SerCx2 - ok
11:24:26.0641 4376 [ 3CD600C089C1251BEEB4CD4CD5164F9E ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
11:24:26.0642 4376 Serenum - ok
11:24:26.0648 4376 [ D864381BC9C725FAB01D94C060660166 ] Serial C:\WINDOWS\System32\drivers\serial.sys
11:24:26.0649 4376 Serial - ok
11:24:26.0664 4376 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
11:24:26.0665 4376 sermouse - ok
11:24:26.0686 4376 [ 441E6FF1F34D7A942946DB42A15FB519 ] SessionEnv C:\WINDOWS\system32\sessenv.dll
11:24:26.0690 4376 SessionEnv - ok
11:24:26.0697 4376 [ 472B7A5AC181C050888DB454663DD764 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
11:24:26.0698 4376 sfloppy - ok
11:24:26.0717 4376 [ F4414F57DF2CECB8FC969AA43A6B0D50 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
11:24:26.0721 4376 SharedAccess - ok
11:24:26.0741 4376 [ 0D190D8B4B20446BE6299AC734DFADF1 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
11:24:26.0748 4376 ShellHWDetection - ok
11:24:26.0760 4376 [ 2F518D13DD6F3053837FE606F1A2EA1F ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
11:24:26.0761 4376 SiSRaid2 - ok
11:24:26.0775 4376 [ 1AC9A200A9C49C4508F04AAFFCA34A3F ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
11:24:26.0777 4376 SiSRaid4 - ok
11:24:26.0792 4376 [ 587ACA15210D1B01FBF272E07A08F91A ] smphost C:\WINDOWS\System32\smphost.dll
11:24:26.0794 4376 smphost - ok
11:24:26.0806 4376 [ 49EEB92DE930B8566EF615D600781DB4 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
11:24:26.0808 4376 SNMPTRAP - ok
11:24:26.0826 4376 [ 8A2F723010B77C79898836784032BFF7 ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
11:24:26.0829 4376 spaceport - ok
11:24:26.0844 4376 [ F337BE11071818FC3F5DC2940B6BDE34 ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
11:24:26.0845 4376 SpbCx - ok
11:24:26.0871 4376 [ FE0CB40F36D3FCDD3A1B312EF72C38D5 ] Spooler C:\WINDOWS\System32\spoolsv.exe
11:24:26.0878 4376 Spooler - ok
11:24:26.0960 4376 [ E6DEC72A2A23FAA53EB9FEC3C7E29D66 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
11:24:26.0996 4376 sppsvc - ok
11:24:27.0039 4376 [ 2B78788A1485F9B99A578A299DF42C02 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
11:24:27.0041 4376 srv - ok
11:24:27.0061 4376 [ C1AE59C0B0817236EC083A91C396005A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
11:24:27.0064 4376 srv2 - ok
11:24:27.0076 4376 [ 77195C32175FC63D6054EBA5A066D727 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
11:24:27.0077 4376 srvnet - ok
11:24:27.0112 4376 [ BB9ED3EDD8E85008215A7250D325A72E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
11:24:27.0115 4376 SSDPSRV - ok
11:24:27.0123 4376 [ 3911418AFDE10EA6823B7799E4815524 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
11:24:27.0125 4376 SstpSvc - ok
11:24:27.0189 4376 [ 7DE35FB26617D9AEF44CEFE9FAC5C51A ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
11:24:27.0193 4376 Steam Client Service - ok
11:24:27.0252 4376 [ 49D9C17FDDFAC66F27FA735E94923216 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
11:24:27.0255 4376 Stereo Service - ok
11:24:27.0266 4376 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
11:24:27.0266 4376 stexstor - ok
11:24:27.0290 4376 [ 2A997C64F9B2584D81FA6749FE36A887 ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
11:24:27.0291 4376 StillCam - ok
11:24:27.0326 4376 [ D638904FE86A5FE542A1BA13A9D68E5C ] stisvc C:\WINDOWS\System32\wiaservc.dll
11:24:27.0332 4376 stisvc - ok
11:24:27.0345 4376 [ 0ED2E318ABB68C1A35A8B8038BDB4C90 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
11:24:27.0346 4376 storahci - ok
11:24:27.0360 4376 [ 7A08CEE1535F5A448215634C5EA74E50 ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
11:24:27.0361 4376 storflt - ok
11:24:27.0375 4376 [ 6B06E2D11E604BE2B1A406C4CB3B90DE ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
11:24:27.0376 4376 stornvme - ok
11:24:27.0386 4376 [ 3118058E3D07021A55324A943C6D722B ] StorSvc C:\WINDOWS\system32\storsvc.dll
11:24:27.0388 4376 StorSvc - ok
11:24:27.0399 4376 [ 548759755BC73DAD663250239D7E0B9F ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
11:24:27.0399 4376 storvsc - ok
11:24:27.0403 4376 [ D8E1AE075AB3E8AD56F69C44AA978596 ] svsvc C:\WINDOWS\system32\svsvc.dll
11:24:27.0405 4376 svsvc - ok
11:24:27.0417 4376 [ 84E0F5D41C138C5CC975137A2A98F6D3 ] swenum C:\WINDOWS\System32\drivers\swenum.sys
11:24:27.0417 4376 swenum - ok
11:24:27.0438 4376 [ A5DC2E63F5E5D3C0B843307374998479 ] swprv C:\WINDOWS\System32\swprv.dll
11:24:27.0445 4376 swprv - ok
11:24:27.0476 4376 [ E45DA7CBBA34510C8B9473AD7D4FFD0B ] SysMain C:\WINDOWS\system32\sysmain.dll
11:24:27.0486 4376 SysMain - ok
11:24:27.0540 4376 [ 373382005ACB27CB16ED16722FBE946A ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
11:24:27.0544 4376 SystemEventsBroker - ok
11:24:27.0556 4376 [ BA6DD39266A5E15515C8C14DA2DA3E5C ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
11:24:27.0558 4376 TabletInputService - ok
11:24:27.0585 4376 [ B517410F157693043DACA21B19B258A6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
11:24:27.0589 4376 TapiSrv - ok
11:24:27.0633 4376 [ 6617F44D2432C529B2249A0498B6B40A ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
11:24:27.0643 4376 Tcpip - ok
11:24:27.0673 4376 [ 6617F44D2432C529B2249A0498B6B40A ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:24:27.0682 4376 TCPIP6 - ok
11:24:27.0692 4376 [ 33A7D83EEB15431773A6E186CFAABA21 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
11:24:27.0692 4376 tcpipreg - ok
11:24:27.0696 4376 [ FFF28F9F6823EB1756C60F1649560BBF ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
11:24:27.0696 4376 tdx - ok
11:24:27.0706 4376 [ 232D185D2337F141311D0CF1983E1431 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
11:24:27.0706 4376 terminpt - ok
11:24:27.0725 4376 [ 2C77831737491F4D684D315B95C62883 ] TermService C:\WINDOWS\System32\termsrv.dll
11:24:27.0729 4376 TermService - ok
11:24:27.0731 4376 [ 05FBE1F7C13E87AF7A414CDF288B1F62 ] Themes C:\WINDOWS\system32\themeservice.dll
11:24:27.0732 4376 Themes - ok
11:24:27.0759 4376 [ FD788C2D96EA91469A3C1D13E80D7473 ] THREADORDER C:\WINDOWS\system32\mmcss.dll
11:24:27.0759 4376 THREADORDER - ok
11:24:27.0765 4376 [ 347A3E49CE18402305B8119A6EC7CFEB ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
11:24:27.0767 4376 TimeBroker - ok
11:24:27.0806 4376 [ 82F909359600D3603FE852DB7F135626 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
11:24:27.0806 4376 TPM - ok
11:24:27.0839 4376 [ C97E14BB6A196B0554D6EB67D8818175 ] TrkWks C:\WINDOWS\System32\trkwks.dll
11:24:27.0840 4376 TrkWks - ok
11:24:27.0872 4376 [ DA56FFA46030E6FEB215E3D5DAA65B11 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
11:24:27.0873 4376 TrustedInstaller - ok
11:24:27.0885 4376 [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
11:24:27.0886 4376 TsUsbFlt - ok
11:24:27.0888 4376 [ E0088068DCE2EE82897027DDB8E05254 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
11:24:27.0888 4376 TsUsbGD - ok
11:24:27.0901 4376 [ C8E0E78B5D284C2FF59BDFFDAF997242 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
11:24:27.0901 4376 tunnel - ok
11:24:27.0912 4376 [ F6EEAD052943B5A3104C1405BB856C54 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
11:24:27.0912 4376 uagp35 - ok
11:24:27.0938 4376 [ FE6067B1FD4E63650C667B33D080565B ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
11:24:27.0939 4376 UASPStor - ok
11:24:27.0961 4376 [ 5D1B430EA11064C56E7C8F84B90DEB6A ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
11:24:27.0961 4376 UCX01000 - ok
11:24:27.0974 4376 [ 1EC649F112896FAE33250F0B97AC5D0B ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
11:24:27.0975 4376 udfs - ok
11:24:27.0990 4376 [ 9578691F297E1B1F519970FE6D47CB21 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
11:24:27.0990 4376 UEFI - ok
11:24:28.0014 4376 [ 320878AFECDBBD61BBE98624A6CAAC08 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
11:24:28.0015 4376 UI0Detect - ok
11:24:28.0017 4376 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
11:24:28.0017 4376 uliagpkx - ok
11:24:28.0032 4376 [ DA34C39A18E60E7C3FA0630566408034 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
11:24:28.0032 4376 umbus - ok
11:24:28.0044 4376 [ AE8294875E5446E359B1E8035D40C05E ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
11:24:28.0044 4376 UmPass - ok
11:24:28.0052 4376 [ E3DDF7D43E05784FAA5E042605EEE528 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
11:24:28.0054 4376 UmRdpService - ok
Moje zlatíčko: CPU i5-3570, MB: MSI Z77MA-G45, RAM Corsair Ventage 2x8GB, GPU: Gigabyte GTX680 OC 2GB, Zdroj: CoolerMaster 650W GX serie, HDD: Seagate Baracuda 7200.14 1TB server , CASE Zalman Z11,


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 107 hostů