Dobrý den
Rád bych o kontrolu logu, při instalaci FLV Player mi to nahlásilo malware + jsem nainstaloval aplikaci speedmycomputer o které jsem si pečetl až později, zatím je odinstalována z Ovládacích programů (přidap a odebrat), ale i tak bych rád o kontrolu PC jestli tam někde neni, nebo jestli se tam neukrývá ještě něco jiného. Děkuji
Log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:05:41, on 22. 2. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe
C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Vratislav\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss
O4 - HKCU\..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{9B62CFFF-6F48-4233-934F-32D83F9E6461}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 10449 bytes
Kontrola-podezření na malware Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola-podezření na malware
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Kontrola-podezření na malware
AdwCleaner:
# AdwCleaner v3.019 - Report created 23/02/2014 at 12:32:40
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Vratislav - AMPERCZ
# Running from : C:\Users\Vratislav\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\smarttweak
Key Found : HKCU\Software\Somoto
Key Found : [x64] HKCU\Software\smarttweak
Key Found : [x64] HKCU\Software\Somoto
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.117
[ File : C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1224 octets] - [23/02/2014 12:32:40]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1284 octets] ##########
Malwarebytes dodám za chvíli..
# AdwCleaner v3.019 - Report created 23/02/2014 at 12:32:40
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Vratislav - AMPERCZ
# Running from : C:\Users\Vratislav\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Folder Found C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\smarttweak
Key Found : HKCU\Software\Somoto
Key Found : [x64] HKCU\Software\smarttweak
Key Found : [x64] HKCU\Software\Somoto
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.117
[ File : C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1224 octets] - [23/02/2014 12:32:40]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1284 octets] ##########
Malwarebytes dodám za chvíli..
Re: Kontrola-podezření na malware
Malwarebytes:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2014.02.22.04
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16518
Vratislav :: AMPERCZ [administrátor]
23. 2. 2014 12:38:18
MBAM-log-2014-02-23 (12-42-24).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 213026
Uplynulý čas: 3 minut, 41 sekund
Nalezené procesy v paměti: 1
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> 3796 -> Nebyla provedena žádná instrukce.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\SOMOTO\SDP (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 1
HKCU\Software\Somoto\SDP|affid (PUP.Optional.Somoto.A) -> Data: network_smb_barcelona -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 4
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\uninstall.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Check for Updates.lnk (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
(konec)
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2014.02.22.04
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16518
Vratislav :: AMPERCZ [administrátor]
23. 2. 2014 12:38:18
MBAM-log-2014-02-23 (12-42-24).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 213026
Uplynulý čas: 3 minut, 41 sekund
Nalezené procesy v paměti: 1
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> 3796 -> Nebyla provedena žádná instrukce.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\SOMOTO\SDP (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 1
HKCU\Software\Somoto\SDP|affid (PUP.Optional.Somoto.A) -> Data: network_smb_barcelona -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 4
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\uninstall.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Check for Updates.lnk (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker\Uninstall.lnk (PUP.Optional.FilesFrog.A) -> Nebyla provedena žádná instrukce.
(konec)
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Kontrola-podezření na malware
V Mbam i adw nech vše smazat a dodej logy po smazání
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Kontrola-podezření na malware
Mbam:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2014.02.22.04
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16518
Vratislav :: AMPERCZ [administrátor]
23. 2. 2014 21:06:15
mbam-log-2014-02-23 (21-06-15).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 212090
Uplynulý čas: 3 minut, 16 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
AdwCleaner:
# AdwCleaner v3.019 - Report created 23/02/2014 at 20:59:57
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Vratislav - AMPERCZ
# Running from : C:\Users\Vratislav\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.117
[ File : C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1372 octets] - [23/02/2014 12:32:40]
AdwCleaner[R1].txt - [963 octets] - [23/02/2014 20:50:16]
AdwCleaner[R2].txt - [728 octets] - [23/02/2014 20:59:57]
AdwCleaner[S0].txt - [943 octets] - [23/02/2014 20:51:52]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [846 octets] ##########
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2014.02.22.04
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16518
Vratislav :: AMPERCZ [administrátor]
23. 2. 2014 21:06:15
mbam-log-2014-02-23 (21-06-15).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 212090
Uplynulý čas: 3 minut, 16 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
AdwCleaner:
# AdwCleaner v3.019 - Report created 23/02/2014 at 20:59:57
# Updated 17/02/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Vratislav - AMPERCZ
# Running from : C:\Users\Vratislav\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.117
[ File : C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1372 octets] - [23/02/2014 12:32:40]
AdwCleaner[R1].txt - [963 octets] - [23/02/2014 20:50:16]
AdwCleaner[R2].txt - [728 octets] - [23/02/2014 20:59:57]
AdwCleaner[S0].txt - [943 octets] - [23/02/2014 20:51:52]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [846 octets] ##########
Re: Kontrola-podezření na malware
JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 8.1 x64
Ran by Vratislav on ne 23. 02. 2014 at 21:23:14,16
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E8B90A0A-C9E4-401E-9CD9-4D214A71D2A7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Vratislav\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 23. 02. 2014 at 21:28:39,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller:
RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Vratislav [Práva správce]
Mód : Kontrola -- Datum : 02/23/2014 21:33:23
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 3 ¤¤¤
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szndesktop.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]
¤¤¤ ¤¤¤ Záznamy Registrů: : 10 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[DNS][PUM] HKLM\[...]\CCSet\[...]\{9B62CFFF-6F48-4233-934F-32D83F9E6461} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> NALEZENO
[DNS][PUM] HKLM\[...]\CS001\[...]\{9B62CFFF-6F48-4233-934F-32D83F9E6461} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP PATH] SomotoUpdateCheckerAutoStart : C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe - /auto [x] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] caffa00a89dc0c17279d2dc787b2b460
[BSP] f335661b0666fdcb2509bbe9cf6f3291 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_02232014_213323.txt >>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 8.1 x64
Ran by Vratislav on ne 23. 02. 2014 at 21:23:14,16
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E8B90A0A-C9E4-401E-9CD9-4D214A71D2A7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Vratislav\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 23. 02. 2014 at 21:28:39,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller:
RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Vratislav [Práva správce]
Mód : Kontrola -- Datum : 02/23/2014 21:33:23
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 3 ¤¤¤
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szndesktop.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]
¤¤¤ ¤¤¤ Záznamy Registrů: : 10 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[DNS][PUM] HKLM\[...]\CCSet\[...]\{9B62CFFF-6F48-4233-934F-32D83F9E6461} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> NALEZENO
[DNS][PUM] HKLM\[...]\CS001\[...]\{9B62CFFF-6F48-4233-934F-32D83F9E6461} : NameServer (8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 [UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - UNITED STATES (US) - PHILIPPINES (PH) - UNITED STATES (US)]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP PATH] SomotoUpdateCheckerAutoStart : C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe - /auto [x] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] caffa00a89dc0c17279d2dc787b2b460
[BSP] f335661b0666fdcb2509bbe9cf6f3291 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_02232014_213323.txt >>
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Kontrola-podezření na malware
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Kontrola-podezření na malware
Rogue:
RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Vratislav [Práva správce]
Mód : Odebrat -- Datum : 02/24/2014 16:28:49
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 4 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\32024libfoxloader-x64.dll [x] -> ODEBRÁNO
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szndesktop.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]
¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP PATH] SomotoUpdateCheckerAutoStart : C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe - /auto [x] -> VYMAZÁNO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] caffa00a89dc0c17279d2dc787b2b460
[BSP] f335661b0666fdcb2509bbe9cf6f3291 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_02242014_162849.txt >>
RKreport[0]_S_02232014_213323.txt;RKreport[0]_S_02242014_162538.txt
TDS dodám za chvíli..
RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Vratislav [Práva správce]
Mód : Odebrat -- Datum : 02/24/2014 16:28:49
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 4 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\32024libfoxloader-x64.dll [x] -> ODEBRÁNO
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] szndesktop.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]
¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[RUN][SUSP PATH] HKUS\S-1-5-21-3766751470-3940348720-3683109205-1001\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\Vratislav\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP PATH] SomotoUpdateCheckerAutoStart : C:\Users\Vratislav\AppData\Local\FilesFrog Update Checker\update_checker.exe - /auto [x] -> VYMAZÁNO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] caffa00a89dc0c17279d2dc787b2b460
[BSP] f335661b0666fdcb2509bbe9cf6f3291 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_02242014_162849.txt >>
RKreport[0]_S_02232014_213323.txt;RKreport[0]_S_02242014_162538.txt
TDS dodám za chvíli..
Re: Kontrola-podezření na malware
16:31:48.0494 1496 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
16:31:48.0494 1496 UEFI system
16:31:57.0932 1496 ============================================================
16:31:57.0932 1496 Current date / time: 2014/02/24 16:31:57.0932
16:31:57.0932 1496 SystemInfo:
16:31:57.0932 1496
16:31:57.0932 1496 OS Version: 6.2.9200 ServicePack: 0.0
16:31:57.0932 1496 Product type: Workstation
16:31:57.0932 1496 ComputerName: AMPERCZ
16:31:57.0932 1496 UserName: Vratislav
16:31:57.0932 1496 Windows directory: C:\WINDOWS
16:31:57.0932 1496 System windows directory: C:\WINDOWS
16:31:57.0932 1496 Running under WOW64
16:31:57.0932 1496 Processor architecture: Intel x64
16:31:57.0932 1496 Number of processors: 4
16:31:57.0932 1496 Page size: 0x1000
16:31:57.0932 1496 Boot type: Normal boot
16:31:57.0932 1496 ============================================================
16:31:58.0307 1496 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:31:58.0307 1496 ============================================================
16:31:58.0307 1496 \Device\Harddisk0\DR0:
16:31:58.0307 1496 GPT partitions:
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {AB79D1F6-8D1C-4FCE-B6C3-AD8A03C98C5F}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {B29C4277-6990-4561-ABF5-F1AF769604AA}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {5CBC3D80-69CE-4C23-8D66-C18542B2F1C2}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {155CC25F-B4C0-4DF6-A554-ECEA629DEE99}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {A66A7574-9D1B-4B3B-B328-4BB17EF2BBA9}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x6F2E4800
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {9EAB71AC-B112-4FA4-8DF6-A4FED6860AC8}, Name: , StartLBA 0x6F78F000, BlocksNum 0xAF000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {DA7A27B3-D9C5-45BE-87A0-F1E31B792FEA}, Name: , StartLBA 0x6F83E000, BlocksNum 0xAF000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition8: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {83FCD2D2-AA36-47E5-A27F-1FE1CD22315F}, Name: Basic data partition, StartLBA 0x6F8ED000, BlocksNum 0x3200000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition9: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {99942D14-4774-4812-B8BB-B755AD9ABFD3}, Name: Basic data partition, StartLBA 0x72AED000, BlocksNum 0x1C19800
16:31:58.0307 1496 MBR partitions:
16:31:58.0307 1496 ============================================================
16:31:58.0338 1496 C: <-> \Device\Harddisk0\DR0\Partition5
16:31:58.0369 1496 D: <-> \Device\Harddisk0\DR0\Partition8
16:31:58.0369 1496 ============================================================
16:31:58.0369 1496 Initialize success
16:31:58.0369 1496 ============================================================
16:32:09.0573 3168 ============================================================
16:32:09.0573 3168 Scan started
16:32:09.0573 3168 Mode: Manual;
16:32:09.0573 3168 ============================================================
16:32:10.0152 3168 ================ Scan system memory ========================
16:32:10.0152 3168 System memory - ok
16:32:10.0152 3168 ================ Scan services =============================
16:32:11.0448 3168 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
16:32:11.0464 3168 1394ohci - ok
16:32:11.0480 3168 [ AD508A1A46EC21B740AB31C28EFDFDB1 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
16:32:11.0480 3168 3ware - ok
16:32:11.0527 3168 [ 3D30878A269D934100FA5F972E53AF39 ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
16:32:11.0527 3168 ACPI - ok
16:32:11.0558 3168 [ AC8279D229398BCF05C3154ADCA86813 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
16:32:11.0558 3168 acpiex - ok
16:32:11.0573 3168 [ A8970D9BF23CD309E0403978A1B58F3F ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
16:32:11.0573 3168 acpipagr - ok
16:32:11.0589 3168 [ 111A89C99C5B4F1A7BCE5F643DD86F65 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
16:32:11.0589 3168 AcpiPmi - ok
16:32:11.0605 3168 [ 5758387D68A20AE7D3245011B07E36E7 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
16:32:11.0605 3168 acpitime - ok
16:32:11.0620 3168 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
16:32:11.0620 3168 ACPIVPC - ok
16:32:13.0324 3168 [ F7AB315A4D400CA876381D1E188A2E20 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:32:13.0339 3168 AdobeFlashPlayerUpdateSvc - ok
16:32:13.0370 3168 [ 7C1FDF1B48298CBA7CE4BDD4978951AD ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS
16:32:13.0370 3168 ADP80XX - ok
16:32:13.0402 3168 [ B19CA8E441D35AA2B1EE51C10B27DA1B ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll
16:32:13.0402 3168 AeLookupSvc - ok
16:32:13.0433 3168 [ 239268BAB58EAE9A3FF4E08334C00451 ] AFD C:\WINDOWS\system32\drivers\afd.sys
16:32:13.0433 3168 AFD - ok
16:32:13.0464 3168 [ 7DFAEBA9AD62D20102B576D5CAC45EC8 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys
16:32:13.0464 3168 agp440 - ok
16:32:13.0480 3168 [ 8E8E34B7BA059050EED827410D0697A2 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
16:32:13.0480 3168 ahcache - ok
16:32:13.0511 3168 [ A91D8E1E433EFB32551BCE69037E1CE7 ] ALG C:\WINDOWS\System32\alg.exe
16:32:13.0511 3168 ALG - ok
16:32:13.0542 3168 [ 66B54471B5856E314947881E28263A6D ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
16:32:13.0542 3168 AMD External Events Utility - ok
16:32:13.0558 3168 [ 7589DE749DB6F71A68489DCE04158729 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
16:32:13.0558 3168 AmdK8 - ok
16:32:13.0808 3168 [ FBB35875FEFE53D4280259842069ED72 ] amdkmdag C:\WINDOWS\system32\DRIVERS\atikmdag.sys
16:32:13.0870 3168 amdkmdag - ok
16:32:13.0886 3168 [ A32BCAD9377E3B75D034CAFBA463A0AE ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
16:32:13.0902 3168 amdkmdap - ok
16:32:13.0902 3168 [ 8A375CB3B6D1A56A2AEEE72A5F1D0926 ] amdkmpfd C:\WINDOWS\system32\drivers\amdkmpfd.sys
16:32:13.0902 3168 amdkmpfd - ok
16:32:13.0917 3168 [ B46D2D89AFF8A9490FA8C98C7A5616E3 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
16:32:13.0917 3168 AmdPPM - ok
16:32:13.0917 3168 [ D2BF2F94A47D332814910FD47C6BBCD2 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
16:32:13.0933 3168 amdsata - ok
16:32:13.0949 3168 [ A8E04943C7BBA7219AA50400272C3C6E ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
16:32:13.0949 3168 amdsbs - ok
16:32:13.0949 3168 [ CEA5F4F27CFC08E3A44D576811B35F50 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
16:32:13.0949 3168 amdxata - ok
16:32:13.0980 3168 [ 04951A9A937CBE28A2D3FEEA360B6D1F ] AppID C:\WINDOWS\system32\drivers\appid.sys
16:32:13.0980 3168 AppID - ok
16:32:14.0011 3168 [ C0DC3F58214A227980AEB091CFD2F973 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
16:32:14.0011 3168 AppIDSvc - ok
16:32:14.0011 3168 [ 7E790DE2487CEDB349D1750B9E47F090 ] Appinfo C:\WINDOWS\System32\appinfo.dll
16:32:14.0027 3168 Appinfo - ok
16:32:14.0042 3168 [ 4B964AE0DF433A3BFA7BD24713BC2E9B ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
16:32:14.0058 3168 AppReadiness - ok
16:32:14.0105 3168 [ 0B726D9ED75C787D6FFAF1E3873BCC70 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
16:32:14.0120 3168 AppXSvc - ok
16:32:14.0136 3168 [ 65045784366F7EC5FB4E71BCF923187B ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
16:32:14.0136 3168 arcsas - ok
16:32:14.0152 3168 [ 74B14192CF79A72F7536B27CB8814FBD ] atapi C:\WINDOWS\system32\drivers\atapi.sys
16:32:14.0152 3168 atapi - ok
16:32:14.0167 3168 [ 65DD42A358451920A703EEEC1AB4995B ] AthBTPort C:\WINDOWS\system32\DRIVERS\btath_flt.sys
16:32:14.0167 3168 AthBTPort - ok
16:32:14.0230 3168 [ FA11394E380D2D1B62669BCBC208EA17 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
16:32:14.0245 3168 AtherosSvc - ok
16:32:14.0308 3168 [ 2C7676F892E88FD190F08D98048C7C6C ] athr C:\WINDOWS\system32\DRIVERS\athw8x.sys
16:32:14.0339 3168 athr - ok
16:32:14.0370 3168 [ 4903CBC14742B5AB4DCF7A92F7DEC483 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
16:32:14.0370 3168 AudioEndpointBuilder - ok
16:32:14.0402 3168 [ EF276593AD1BDF5A99032F62D6272848 ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
16:32:14.0417 3168 Audiosrv - ok
16:32:14.0433 3168 [ 96E8CAF20FC4B6C31CAD7816A801EB78 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
16:32:14.0433 3168 AxInstSV - ok
16:32:14.0464 3168 [ A4A73F631FE2AA2826FBE4A399B04DEF ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
16:32:14.0480 3168 b06bdrv - ok
16:32:14.0495 3168 [ 8CC7F7E4AFCBA605921B137ED7992C68 ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
16:32:14.0495 3168 BasicDisplay - ok
16:32:14.0511 3168 [ 2748E116F8621A4DB0D39FCDD7318C01 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
16:32:14.0511 3168 BasicRender - ok
16:32:14.0527 3168 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21 ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys
16:32:14.0527 3168 bcmfn2 - ok
16:32:14.0542 3168 [ BBE61A40665B83488901E41082A6097D ] BDESVC C:\WINDOWS\System32\bdesvc.dll
16:32:14.0558 3168 BDESVC - ok
16:32:14.0589 3168 [ EC19013E4CF87609534165DF897274D6 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
16:32:14.0589 3168 Beep - ok
16:32:14.0620 3168 [ 6468B696C65775D51A06615830E0E79D ] BFE C:\WINDOWS\System32\bfe.dll
16:32:14.0636 3168 BFE - ok
16:32:14.0714 3168 [ F14F048B4D05FBCE536250EA74BF9FDC ] BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140214.001\BHDrvx64.sys
16:32:14.0730 3168 BHDrvx64 - ok
16:32:14.0761 3168 [ 15225081966C785A9192782401643FD4 ] BITS C:\WINDOWS\System32\qmgr.dll
16:32:14.0777 3168 BITS - ok
16:32:14.0777 3168 [ 6B4FFFDDC618FCF64473CAA86E305697 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
16:32:14.0777 3168 bowser - ok
16:32:14.0792 3168 [ A6207A88B596F726DE558425F3B7E592 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
16:32:14.0808 3168 BrokerInfrastructure - ok
16:32:14.0824 3168 [ D528D6A92D187777691993DD757AF19A ] Browser C:\WINDOWS\System32\browser.dll
16:32:14.0824 3168 Browser - ok
16:32:14.0870 3168 [ BCDB654338FA6C4BEE20A8EA47092171 ] BTATH_A2DP C:\WINDOWS\system32\drivers\btath_a2dp.sys
16:32:14.0870 3168 BTATH_A2DP - ok
16:32:14.0870 3168 [ A71E33AEF3289BE2BA6CAD032BF9BFBA ] btath_avdt C:\WINDOWS\system32\drivers\btath_avdt.sys
16:32:14.0870 3168 btath_avdt - ok
16:32:14.0902 3168 [ 4AF7C20F94DAC343C01ED671C82DCB99 ] BTATH_HCRP C:\WINDOWS\System32\drivers\btath_hcrp.sys
16:32:14.0902 3168 BTATH_HCRP - ok
16:32:14.0917 3168 [ 785C38070043BEEE9E9D591DE4067244 ] BTATH_LWFLT C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys
16:32:14.0917 3168 BTATH_LWFLT - ok
16:32:14.0933 3168 [ 31EC5FC3FC5CB273F2709AAF4AD88ED4 ] BTATH_RCP C:\WINDOWS\System32\drivers\btath_rcp.sys
16:32:14.0949 3168 BTATH_RCP - ok
16:32:14.0964 3168 [ 90A7BDDC5B48E94F999FA66645DBBF91 ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
16:32:14.0980 3168 BtFilter - ok
16:32:14.0996 3168 [ A8F23D453A424FF4DE04989C4727ECC7 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
16:32:14.0996 3168 BthAvrcpTg - ok
16:32:15.0011 3168 [ 131F1C8573E7BFB41C54FBF5309CCD94 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys
16:32:15.0011 3168 BthEnum - ok
16:32:15.0027 3168 [ 746B9F94214915AECDE4B7FEA5FF9664 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
16:32:15.0027 3168 BthHFEnum - ok
16:32:15.0058 3168 [ 71FE2A48E4C93DDB9798C024880B6C07 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
16:32:15.0058 3168 bthhfhid - ok
16:32:15.0074 3168 [ FCD8BD17B7193CFFF18C332D1A381D7F ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
16:32:15.0074 3168 BthLEEnum - ok
16:32:15.0089 3168 [ 07E33226AD218A2A162662A05CAFB52F ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
16:32:15.0105 3168 BTHMODEM - ok
16:32:15.0121 3168 [ 3AFE71D80EDF5D4DE0C5731352905669 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
16:32:15.0121 3168 BthPan - ok
16:32:15.0152 3168 [ 10EDF9E0838BA4578FFFFF274632D454 ] BTHPORT C:\WINDOWS\System32\Drivers\BTHport.sys
16:32:15.0152 3168 BTHPORT - ok
16:32:15.0167 3168 [ E5E48FEED73D463175EAB1542495191C ] bthserv C:\WINDOWS\system32\bthserv.dll
16:32:15.0167 3168 bthserv - ok
16:32:15.0183 3168 [ 0E7FA34B975764C33B5DBC6F8C401627 ] BTHUSB C:\WINDOWS\System32\Drivers\BTHUSB.sys
16:32:15.0183 3168 BTHUSB - ok
16:32:15.0230 3168 [ 0510396A957E9FD7205BA62D3CAE4528 ] ccSet_NIS C:\WINDOWS\system32\drivers\NISx64\1501000.012\ccSetx64.sys
16:32:15.0246 3168 ccSet_NIS - ok
16:32:15.0277 3168 [ 2FA6510E33F7DEFEC03658B74101A9B9 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
16:32:15.0277 3168 cdfs - ok
16:32:15.0277 3168 [ C6796EA22B513E3457514D92DCDB1A3D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
16:32:15.0277 3168 cdrom - ok
16:32:15.0308 3168 [ AB285CE3431FF3D2ACE669245874C1C7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
16:32:15.0308 3168 CertPropSvc - ok
16:32:15.0339 3168 [ BE9936EDD3267FAAFF94A7835867F00B ] circlass C:\WINDOWS\System32\drivers\circlass.sys
16:32:15.0339 3168 circlass - ok
16:32:15.0355 3168 [ 7F006813C2AFE622C13D7AF94F56CD07 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
16:32:15.0371 3168 CLFS - ok
16:32:15.0402 3168 [ EF6EF85DADC3184A10D8F2F7159973CB ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
16:32:15.0402 3168 CmBatt - ok
16:32:15.0417 3168 [ 825BE21E6395E00698D8A23955A87972 ] CNG C:\WINDOWS\system32\Drivers\cng.sys
16:32:15.0417 3168 CNG - ok
16:32:15.0464 3168 [ E9BCC890CC2692F29A209B6A14AFAF35 ] CnxtHdAudService C:\WINDOWS\system32\drivers\CHDRT64.sys
16:32:15.0480 3168 CnxtHdAudService - ok
16:32:15.0496 3168 [ 03AAED827C36F35D70900558B8274905 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys
16:32:15.0496 3168 CompositeBus - ok
16:32:15.0496 3168 COMSysApp - ok
16:32:15.0511 3168 [ A1FF7DFBFBE164CF92603C651D304DD2 ] condrv C:\WINDOWS\system32\drivers\condrv.sys
16:32:15.0511 3168 condrv - ok
16:32:17.0214 3168 [ D5F868A46AED8E7CAD6C30E0599DD100 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
16:32:17.0230 3168 cphs - ok
16:32:17.0246 3168 [ 0EFE4B5884A8032617826A4D76F80969 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
16:32:17.0246 3168 CryptSvc - ok
16:32:17.0292 3168 [ 0BF56545D2E82A48579A633DC65B9494 ] CxAudMsg C:\windows\system32\CxAudMsg64.exe
16:32:17.0292 3168 CxAudMsg - ok
16:32:17.0308 3168 [ 315BA4BC19316D72B2E037534E048B93 ] dam C:\WINDOWS\system32\drivers\dam.sys
16:32:17.0308 3168 dam - ok
16:32:17.0324 3168 [ 3FD5AE42EC87C6F532A931F96BE731DD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
16:32:17.0339 3168 DcomLaunch - ok
16:32:17.0339 3168 [ F4CCAADC2C78F57E4F16B24C9201CE22 ] defragsvc C:\WINDOWS\System32\defragsvc.dll
16:32:17.0339 3168 defragsvc - ok
16:32:17.0386 3168 [ 0BC71D4D3B5883903C37BF4E13B0F0C5 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
16:32:17.0386 3168 DeviceAssociationService - ok
16:32:17.0402 3168 [ 752A457320A946E03C3AA86C3ACD735E ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
16:32:17.0402 3168 DeviceInstall - ok
16:32:17.0417 3168 [ 5DB26D7E0216D0BF364A81D3829AD7B9 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
16:32:17.0417 3168 Dfsc - ok
16:32:17.0433 3168 [ 8B107F55FD61654A6C9F1B819AEC5FC4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
16:32:17.0433 3168 Dhcp - ok
16:32:17.0449 3168 [ 4D40C9B33F738797CF50E77CB7C53E85 ] disk C:\WINDOWS\system32\drivers\disk.sys
16:32:17.0449 3168 disk - ok
16:32:17.0464 3168 [ EB70A894708D1BC176AFD690FF06085F ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
16:32:17.0464 3168 dmvsc - ok
16:32:17.0480 3168 [ 5BAF7714E68F93515A937A3FA8587EF9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
16:32:17.0480 3168 Dnscache - ok
16:32:17.0496 3168 [ 50288EA079BB520C2B8C8A154202D518 ] dot3svc C:\WINDOWS\System32\dot3svc.dll
16:32:17.0511 3168 dot3svc - ok
16:32:17.0527 3168 [ 281BEE07BA97E3E98D12A822D923D0D8 ] DPS C:\WINDOWS\system32\dps.dll
16:32:17.0527 3168 DPS - ok
16:32:17.0542 3168 [ DDC11A202207C0400CBE07315B8FDE5E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
16:32:17.0542 3168 drmkaud - ok
16:32:17.0558 3168 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
16:32:17.0558 3168 DsmSvc - ok
16:32:17.0605 3168 [ A3D1CB64DF885ACE126543E6D7067348 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
16:32:17.0605 3168 DXGKrnl - ok
16:32:17.0621 3168 [ 6073537F250B45E1CB2A02E97F0FE1B2 ] Eaphost C:\WINDOWS\System32\eapsvc.dll
16:32:17.0636 3168 Eaphost - ok
16:32:17.0699 3168 [ 114BCFDF367FF37C3F1B0A96AF542E4D ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
16:32:17.0730 3168 ebdrv - ok
16:32:17.0777 3168 [ 1B7AA375F711F66D5FF2B855F9EC987F ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
16:32:17.0777 3168 eeCtrl - ok
16:32:17.0792 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] EFS C:\WINDOWS\System32\lsass.exe
16:32:17.0792 3168 EFS - ok
16:32:17.0808 3168 [ 43531A5993380CC5113242C29D265FD9 ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
16:32:17.0808 3168 EhStorClass - ok
16:32:17.0824 3168 [ 6F8E738A9505A388B1157FDDE7B3101B ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
16:32:17.0824 3168 EhStorTcgDrv - ok
16:32:17.0839 3168 [ 7230C8B80DDE1F0524C353240B78CC0E ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
16:32:17.0839 3168 EraserUtilRebootDrv - ok
16:32:17.0839 3168 [ DFFFAE1442BA4076E18EED5E406FA0D3 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
16:32:17.0839 3168 ErrDev - ok
16:32:17.0855 3168 esgiguard - ok
16:32:17.0902 3168 [ 9CBBFB1953562BCAE1B1F351F17E32D8 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
16:32:17.0902 3168 ETD - ok
16:32:17.0949 3168 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3 ] EventSystem C:\WINDOWS\system32\es.dll
16:32:17.0949 3168 EventSystem - ok
16:32:17.0964 3168 [ 7729D294A555C7AEB281ED8E4D0E01E4 ] exfat C:\WINDOWS\system32\drivers\exfat.sys
16:32:17.0964 3168 exfat - ok
16:32:17.0980 3168 [ 7C4E0D5900B2A1D11EDD626D6DDB937B ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
16:32:17.0980 3168 fastfat - ok
16:32:18.0011 3168 [ 2BC8532ABF2B3756B78FA1DA54147DDE ] Fax C:\WINDOWS\system32\fxssvc.exe
16:32:18.0011 3168 Fax - ok
16:32:18.0027 3168 [ 5D8402613E778B3BD45E687A8372710B ] fdc C:\WINDOWS\System32\drivers\fdc.sys
16:32:18.0027 3168 fdc - ok
16:32:18.0058 3168 [ DC1A78BCCCB7EE53D6FD3BD615A8E222 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
16:32:18.0058 3168 fdPHost - ok
16:32:18.0058 3168 [ E5AD448F2DC84B1CF387FA7F2A3D1936 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
16:32:18.0058 3168 FDResPub - ok
16:32:18.0074 3168 [ 0046E0BD031213D37123876B0D0FA61C ] fhsvc C:\WINDOWS\system32\fhsvc.dll
16:32:18.0089 3168 fhsvc - ok
16:32:18.0121 3168 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
16:32:18.0121 3168 FileInfo - ok
16:32:18.0121 3168 [ A1A66C4FDAFD6B0289523232AFB7D8AF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
16:32:18.0136 3168 Filetrace - ok
16:32:18.0136 3168 [ BE743083CF7063C486A4398E3AEFE59A ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
16:32:18.0136 3168 flpydisk - ok
16:32:18.0293 3168 [ 60D5067FCE6D9433D35E04C01D8538B3 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
16:32:18.0293 3168 FltMgr - ok
16:32:18.0339 3168 [ 183CA7699474FDE235853967D1DA4D9B ] FontCache C:\WINDOWS\system32\FntCache.dll
16:32:18.0355 3168 FontCache - ok
16:32:18.0449 3168 [ 1C52387BF5A127F5F3BFB31288F30D93 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:32:18.0449 3168 FontCache3.0.0.0 - ok
16:32:18.0464 3168 [ 35005534E600E993A90B036E4E599F2B ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
16:32:18.0464 3168 FsDepends - ok
16:32:18.0480 3168 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:32:18.0480 3168 Fs_Rec - ok
16:32:18.0527 3168 [ 83E1F0983B02A6F8EC764D18E24ECF10 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
16:32:18.0527 3168 fvevol - ok
16:32:18.0543 3168 [ 9591D0B9351ED489EAFD9D1CE52A8015 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys
16:32:18.0543 3168 FxPPM - ok
16:32:18.0558 3168 [ FC3EF65EE20D39F8749C2218DBA681CA ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys
16:32:18.0558 3168 gagp30kx - ok
16:32:18.0574 3168 [ 0BF5CAD281E25F1418E5B8875DC5ADD1 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
16:32:18.0574 3168 gencounter - ok
16:32:18.0589 3168 [ FDA72810CA2F8409D9B31E833C448E34 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
16:32:18.0589 3168 GPIOClx0101 - ok
16:32:18.0636 3168 [ 0BDE0FCF597E9B65600121EF54FF8340 ] gpsvc C:\WINDOWS\System32\gpsvc.dll
16:32:18.0652 3168 gpsvc - ok
16:32:18.0668 3168 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:32:18.0668 3168 gupdate - ok
16:32:18.0668 3168 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:32:18.0668 3168 gupdatem - ok
16:32:18.0668 3168 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
16:32:18.0683 3168 HDAudBus - ok
16:32:18.0699 3168 [ 10A70BC1871CD955D85CD88372724906 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
16:32:18.0699 3168 HidBatt - ok
16:32:18.0714 3168 [ 1EA1B4FABB8CC348E73CA90DBA22E104 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
16:32:18.0714 3168 HidBth - ok
16:32:18.0730 3168 [ C241A8BAFBBFC90176EA0F5240EACC17 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
16:32:18.0730 3168 hidi2c - ok
16:32:18.0746 3168 [ 9BDDEE26255421017E161CCB9D5EDA95 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
16:32:18.0746 3168 HidIr - ok
16:32:18.0761 3168 [ 449A20A674AA3FAA7F0DD4E33EE2DC20 ] hidserv C:\WINDOWS\system32\hidserv.dll
16:32:18.0761 3168 hidserv - ok
16:32:18.0777 3168 [ F31397220D9687E11EB448649AA6E038 ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
16:32:18.0777 3168 HidUsb - ok
16:32:18.0793 3168 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll
16:32:18.0808 3168 hkmsvc - ok
16:32:18.0839 3168 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
16:32:18.0839 3168 HomeGroupListener - ok
16:32:18.0871 3168 [ BE5F89BAFBD4272D5A0C0A37B97865ED ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
16:32:18.0886 3168 HomeGroupProvider - ok
16:32:18.0886 3168 [ A6AACEA4C785789BDA5912AD1FEDA80D ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
16:32:18.0886 3168 HpSAMD - ok
16:32:18.0902 3168 [ 3502776E366C913D49C0DA928AE3E6CB ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
16:32:18.0918 3168 HTTP - ok
16:32:18.0933 3168 [ 90656C0B3864804B090434EFC582404F ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
16:32:18.0933 3168 hwpolicy - ok
16:32:18.0949 3168 [ 6D6F9E3BF0484967E52F7E846BFF1CA1 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
16:32:18.0949 3168 hyperkbd - ok
16:32:18.0964 3168 [ 907C870F8C31F8DDD6F090857B46AB25 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
16:32:18.0964 3168 HyperVideo - ok
16:32:18.0980 3168 [ 84CFC5EFA97D0C965EDE1D56F116A541 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
16:32:18.0980 3168 i8042prt - ok
16:32:18.0996 3168 [ 5D90E32E36CE5D4C535D17CE08AEAF05 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
16:32:18.0996 3168 iaLPSSi_GPIO - ok
16:32:19.0011 3168 [ DD05E7E80F52ADE9AEB292819920F32C ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
16:32:19.0011 3168 iaLPSSi_I2C - ok
16:32:19.0043 3168 [ FA4C48E36F0B24E7E33D3E7E1844B9C9 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
16:32:19.0058 3168 iaStorA - ok
16:32:19.0074 3168 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys
16:32:19.0089 3168 iaStorAV - ok
16:32:19.0183 3168 [ D5854F77CEEAFC5A8405F8ECCBEC09DF ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
16:32:19.0183 3168 IAStorDataMgrSvc - ok
16:32:19.0199 3168 [ A2200C3033FA4EF249FC096A7A7D02A2 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
16:32:19.0199 3168 iaStorV - ok
16:32:19.0246 3168 [ 83FF82FE209E7997067B375DAD6CF23D ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
16:32:19.0246 3168 ICCS - ok
16:32:19.0308 3168 [ 777612849691B0D9EE064F93481FEFF1 ] IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140221.001\IDSvia64.sys
16:32:19.0324 3168 IDSVia64 - ok
16:32:19.0324 3168 IEEtwCollectorService - ok
16:32:19.0589 3168 [ 4F6363C26B4A3DDBC9FAFCBA68602B01 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
16:32:19.0605 3168 igfx - ok
16:32:19.0652 3168 [ B82255670D270B75D2D2F0F8747D1443 ] IKEEXT C:\WINDOWS\System32\ikeext.dll
16:32:19.0668 3168 IKEEXT - ok
16:32:19.0699 3168 [ 4011430BC9DA46ADFAE9915EFEC312FB ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
16:32:19.0699 3168 intaud_WaveExtensible - ok
16:32:19.0714 3168 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
16:32:19.0714 3168 IntcDAud - ok
16:32:19.0746 3168 [ B353F1834FCD36D77BE3F74992C147D4 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
16:32:19.0746 3168 Intel(R) Capability Licensing Service Interface - ok
16:32:19.0761 3168 [ 4E448FCFFD00E8D657CD9E48D3E47157 ] intelide C:\WINDOWS\system32\drivers\intelide.sys
16:32:19.0761 3168 intelide - ok
16:32:19.0793 3168 [ 139CFCDCD36B1B1782FD8C0014AC9B0E ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
16:32:19.0793 3168 intelpep - ok
16:32:19.0808 3168 [ 47E74A8E53C7C24DCE38311E1451C1D9 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
16:32:19.0808 3168 intelppm - ok
16:32:19.0824 3168 [ 9DB76D7F9E4E53EFE5DD8C53DE837514 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:32:19.0824 3168 IpFilterDriver - ok
16:32:19.0855 3168 [ DFC4050D58565ADBEE793A8D4AEBDAE6 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
16:32:19.0871 3168 iphlpsvc - ok
16:32:19.0886 3168 [ 9949A3C7590B8C536C05312205079A82 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
16:32:19.0886 3168 IPMIDRV - ok
16:32:19.0918 3168 [ B7342B3C58E91107F6E946A93D9D4EFD ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
16:32:19.0918 3168 IPNAT - ok
16:32:19.0933 3168 [ AE44C526AB5F8A487D941CEB57B10C97 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
16:32:19.0933 3168 IRENUM - ok
16:32:19.0964 3168 [ 8AFEEA3955AA43616A60F133B1D25F21 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
16:32:19.0964 3168 isapnp - ok
16:32:19.0980 3168 [ 034D4BD9DC67C64F3A4C8A049B5173BF ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
16:32:19.0980 3168 iScsiPrt - ok
16:32:19.0996 3168 [ EE03564B7FAFE2E44EDA33D52E83B4A3 ] iwdbus C:\WINDOWS\System32\drivers\iwdbus.sys
16:32:19.0996 3168 iwdbus - ok
16:32:20.0043 3168 [ 5B14FDE79871F83A5E0DCDC01F78BECF ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
16:32:20.0058 3168 jhi_service - ok
16:32:20.0074 3168 [ 8BE92376799B6B44D543E8D07CDCF885 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
16:32:20.0074 3168 kbdclass - ok
16:32:20.0090 3168 [ FB6E47E569D4872ABEB506BE03A45FBA ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
16:32:20.0090 3168 kbdhid - ok
16:32:20.0105 3168 [ 813871C7D402A05F2E3A7075F9584A05 ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys
16:32:20.0105 3168 kdnic - ok
16:32:20.0121 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] KeyIso C:\WINDOWS\system32\lsass.exe
16:32:20.0121 3168 KeyIso - ok
16:32:20.0136 3168 [ ADDECBCC777665BD113BED437E602AB0 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
16:32:20.0136 3168 KSecDD - ok
16:32:20.0152 3168 [ 7296EA420134EAC390798B3232D066A4 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
16:32:20.0168 3168 KSecPkg - ok
16:32:20.0183 3168 [ 11AFB527AA370B1DAFD5C36F35F6D45F ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
16:32:20.0183 3168 ksthunk - ok
16:32:20.0199 3168 [ 32B1A8351160F307A8C66BCB0F94A9C2 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
16:32:20.0214 3168 KtmRm - ok
16:32:20.0230 3168 [ 50AECF8C21AB2A6428A6E1E10549D8E5 ] L1C C:\WINDOWS\system32\DRIVERS\L1C63x64.sys
16:32:20.0230 3168 L1C - ok
16:32:20.0261 3168 [ 27B58E16CF895AC1F1A97C04814C2239 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
16:32:20.0261 3168 LanmanServer - ok
16:32:20.0277 3168 [ D0D9C2ECA4D03A8F06DCD91236B90C98 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
16:32:20.0277 3168 LanmanWorkstation - ok
16:32:20.0308 3168 [ EE289BD147FDFF95EF1B9BD65D3B974A ] lfsvc C:\WINDOWS\System32\GeofenceMonitorService.dll
16:32:20.0324 3168 lfsvc - ok
16:32:20.0355 3168 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\WINDOWS\system32\DRIVERS\LhdX64.sys
16:32:20.0355 3168 LHDmgr - ok
16:32:20.0371 3168 [ C09010B3680860131631F53E8FE7BAD8 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys
16:32:20.0371 3168 lltdio - ok
16:32:20.0402 3168 [ 00E070FC0C673311AFD4B068D1242780 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
16:32:20.0418 3168 lltdsvc - ok
16:32:20.0433 3168 [ D113FAD71A5E67AA94B32A0F8828D265 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
16:32:20.0433 3168 lmhosts - ok
16:32:20.0480 3168 [ 3974B7CE015A6EEF30DA4ADD5F1203D0 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
16:32:20.0480 3168 LMS - ok
16:32:20.0496 3168 [ C755AE4635457AA2A11F79C0DF857ABC ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
16:32:20.0496 3168 LSI_SAS - ok
16:32:20.0511 3168 [ ADAC09CBE7A2040B7F68B5E5C9A75141 ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys
16:32:20.0511 3168 LSI_SAS2 - ok
16:32:20.0527 3168 [ 04D1274BB9BBCCF12BD12374002AA191 ] LSI_SAS3 C:\WINDOWS\system32\drivers\lsi_sas3.sys
16:32:20.0527 3168 LSI_SAS3 - ok
16:32:20.0543 3168 [ 327469EEF3833D0C584B7E88A76AEC0C ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
16:32:20.0543 3168 LSI_SSS - ok
16:32:20.0574 3168 [ B6B69FF200F68888A7FAFDF204D00C91 ] LSM C:\WINDOWS\System32\lsm.dll
16:32:20.0590 3168 LSM - ok
16:32:20.0605 3168 [ 5EF604B0698F4FA962778285E8C5F1F2 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
16:32:20.0605 3168 luafv - ok
16:32:20.0621 3168 [ EB5C03A070F30D64A6DF80E53B22F53F ] megasas C:\WINDOWS\system32\drivers\megasas.sys
16:31:48.0494 1496 UEFI system
16:31:57.0932 1496 ============================================================
16:31:57.0932 1496 Current date / time: 2014/02/24 16:31:57.0932
16:31:57.0932 1496 SystemInfo:
16:31:57.0932 1496
16:31:57.0932 1496 OS Version: 6.2.9200 ServicePack: 0.0
16:31:57.0932 1496 Product type: Workstation
16:31:57.0932 1496 ComputerName: AMPERCZ
16:31:57.0932 1496 UserName: Vratislav
16:31:57.0932 1496 Windows directory: C:\WINDOWS
16:31:57.0932 1496 System windows directory: C:\WINDOWS
16:31:57.0932 1496 Running under WOW64
16:31:57.0932 1496 Processor architecture: Intel x64
16:31:57.0932 1496 Number of processors: 4
16:31:57.0932 1496 Page size: 0x1000
16:31:57.0932 1496 Boot type: Normal boot
16:31:57.0932 1496 ============================================================
16:31:58.0307 1496 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:31:58.0307 1496 ============================================================
16:31:58.0307 1496 \Device\Harddisk0\DR0:
16:31:58.0307 1496 GPT partitions:
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {AB79D1F6-8D1C-4FCE-B6C3-AD8A03C98C5F}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {B29C4277-6990-4561-ABF5-F1AF769604AA}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {5CBC3D80-69CE-4C23-8D66-C18542B2F1C2}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {155CC25F-B4C0-4DF6-A554-ECEA629DEE99}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {A66A7574-9D1B-4B3B-B328-4BB17EF2BBA9}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x6F2E4800
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {9EAB71AC-B112-4FA4-8DF6-A4FED6860AC8}, Name: , StartLBA 0x6F78F000, BlocksNum 0xAF000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {DA7A27B3-D9C5-45BE-87A0-F1E31B792FEA}, Name: , StartLBA 0x6F83E000, BlocksNum 0xAF000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition8: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {83FCD2D2-AA36-47E5-A27F-1FE1CD22315F}, Name: Basic data partition, StartLBA 0x6F8ED000, BlocksNum 0x3200000
16:31:58.0307 1496 \Device\Harddisk0\DR0\Partition9: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {99942D14-4774-4812-B8BB-B755AD9ABFD3}, Name: Basic data partition, StartLBA 0x72AED000, BlocksNum 0x1C19800
16:31:58.0307 1496 MBR partitions:
16:31:58.0307 1496 ============================================================
16:31:58.0338 1496 C: <-> \Device\Harddisk0\DR0\Partition5
16:31:58.0369 1496 D: <-> \Device\Harddisk0\DR0\Partition8
16:31:58.0369 1496 ============================================================
16:31:58.0369 1496 Initialize success
16:31:58.0369 1496 ============================================================
16:32:09.0573 3168 ============================================================
16:32:09.0573 3168 Scan started
16:32:09.0573 3168 Mode: Manual;
16:32:09.0573 3168 ============================================================
16:32:10.0152 3168 ================ Scan system memory ========================
16:32:10.0152 3168 System memory - ok
16:32:10.0152 3168 ================ Scan services =============================
16:32:11.0448 3168 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
16:32:11.0464 3168 1394ohci - ok
16:32:11.0480 3168 [ AD508A1A46EC21B740AB31C28EFDFDB1 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
16:32:11.0480 3168 3ware - ok
16:32:11.0527 3168 [ 3D30878A269D934100FA5F972E53AF39 ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
16:32:11.0527 3168 ACPI - ok
16:32:11.0558 3168 [ AC8279D229398BCF05C3154ADCA86813 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
16:32:11.0558 3168 acpiex - ok
16:32:11.0573 3168 [ A8970D9BF23CD309E0403978A1B58F3F ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
16:32:11.0573 3168 acpipagr - ok
16:32:11.0589 3168 [ 111A89C99C5B4F1A7BCE5F643DD86F65 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
16:32:11.0589 3168 AcpiPmi - ok
16:32:11.0605 3168 [ 5758387D68A20AE7D3245011B07E36E7 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
16:32:11.0605 3168 acpitime - ok
16:32:11.0620 3168 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
16:32:11.0620 3168 ACPIVPC - ok
16:32:13.0324 3168 [ F7AB315A4D400CA876381D1E188A2E20 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:32:13.0339 3168 AdobeFlashPlayerUpdateSvc - ok
16:32:13.0370 3168 [ 7C1FDF1B48298CBA7CE4BDD4978951AD ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS
16:32:13.0370 3168 ADP80XX - ok
16:32:13.0402 3168 [ B19CA8E441D35AA2B1EE51C10B27DA1B ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll
16:32:13.0402 3168 AeLookupSvc - ok
16:32:13.0433 3168 [ 239268BAB58EAE9A3FF4E08334C00451 ] AFD C:\WINDOWS\system32\drivers\afd.sys
16:32:13.0433 3168 AFD - ok
16:32:13.0464 3168 [ 7DFAEBA9AD62D20102B576D5CAC45EC8 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys
16:32:13.0464 3168 agp440 - ok
16:32:13.0480 3168 [ 8E8E34B7BA059050EED827410D0697A2 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
16:32:13.0480 3168 ahcache - ok
16:32:13.0511 3168 [ A91D8E1E433EFB32551BCE69037E1CE7 ] ALG C:\WINDOWS\System32\alg.exe
16:32:13.0511 3168 ALG - ok
16:32:13.0542 3168 [ 66B54471B5856E314947881E28263A6D ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
16:32:13.0542 3168 AMD External Events Utility - ok
16:32:13.0558 3168 [ 7589DE749DB6F71A68489DCE04158729 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
16:32:13.0558 3168 AmdK8 - ok
16:32:13.0808 3168 [ FBB35875FEFE53D4280259842069ED72 ] amdkmdag C:\WINDOWS\system32\DRIVERS\atikmdag.sys
16:32:13.0870 3168 amdkmdag - ok
16:32:13.0886 3168 [ A32BCAD9377E3B75D034CAFBA463A0AE ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
16:32:13.0902 3168 amdkmdap - ok
16:32:13.0902 3168 [ 8A375CB3B6D1A56A2AEEE72A5F1D0926 ] amdkmpfd C:\WINDOWS\system32\drivers\amdkmpfd.sys
16:32:13.0902 3168 amdkmpfd - ok
16:32:13.0917 3168 [ B46D2D89AFF8A9490FA8C98C7A5616E3 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
16:32:13.0917 3168 AmdPPM - ok
16:32:13.0917 3168 [ D2BF2F94A47D332814910FD47C6BBCD2 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
16:32:13.0933 3168 amdsata - ok
16:32:13.0949 3168 [ A8E04943C7BBA7219AA50400272C3C6E ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
16:32:13.0949 3168 amdsbs - ok
16:32:13.0949 3168 [ CEA5F4F27CFC08E3A44D576811B35F50 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
16:32:13.0949 3168 amdxata - ok
16:32:13.0980 3168 [ 04951A9A937CBE28A2D3FEEA360B6D1F ] AppID C:\WINDOWS\system32\drivers\appid.sys
16:32:13.0980 3168 AppID - ok
16:32:14.0011 3168 [ C0DC3F58214A227980AEB091CFD2F973 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
16:32:14.0011 3168 AppIDSvc - ok
16:32:14.0011 3168 [ 7E790DE2487CEDB349D1750B9E47F090 ] Appinfo C:\WINDOWS\System32\appinfo.dll
16:32:14.0027 3168 Appinfo - ok
16:32:14.0042 3168 [ 4B964AE0DF433A3BFA7BD24713BC2E9B ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
16:32:14.0058 3168 AppReadiness - ok
16:32:14.0105 3168 [ 0B726D9ED75C787D6FFAF1E3873BCC70 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
16:32:14.0120 3168 AppXSvc - ok
16:32:14.0136 3168 [ 65045784366F7EC5FB4E71BCF923187B ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
16:32:14.0136 3168 arcsas - ok
16:32:14.0152 3168 [ 74B14192CF79A72F7536B27CB8814FBD ] atapi C:\WINDOWS\system32\drivers\atapi.sys
16:32:14.0152 3168 atapi - ok
16:32:14.0167 3168 [ 65DD42A358451920A703EEEC1AB4995B ] AthBTPort C:\WINDOWS\system32\DRIVERS\btath_flt.sys
16:32:14.0167 3168 AthBTPort - ok
16:32:14.0230 3168 [ FA11394E380D2D1B62669BCBC208EA17 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
16:32:14.0245 3168 AtherosSvc - ok
16:32:14.0308 3168 [ 2C7676F892E88FD190F08D98048C7C6C ] athr C:\WINDOWS\system32\DRIVERS\athw8x.sys
16:32:14.0339 3168 athr - ok
16:32:14.0370 3168 [ 4903CBC14742B5AB4DCF7A92F7DEC483 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
16:32:14.0370 3168 AudioEndpointBuilder - ok
16:32:14.0402 3168 [ EF276593AD1BDF5A99032F62D6272848 ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
16:32:14.0417 3168 Audiosrv - ok
16:32:14.0433 3168 [ 96E8CAF20FC4B6C31CAD7816A801EB78 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
16:32:14.0433 3168 AxInstSV - ok
16:32:14.0464 3168 [ A4A73F631FE2AA2826FBE4A399B04DEF ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
16:32:14.0480 3168 b06bdrv - ok
16:32:14.0495 3168 [ 8CC7F7E4AFCBA605921B137ED7992C68 ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
16:32:14.0495 3168 BasicDisplay - ok
16:32:14.0511 3168 [ 2748E116F8621A4DB0D39FCDD7318C01 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
16:32:14.0511 3168 BasicRender - ok
16:32:14.0527 3168 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21 ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys
16:32:14.0527 3168 bcmfn2 - ok
16:32:14.0542 3168 [ BBE61A40665B83488901E41082A6097D ] BDESVC C:\WINDOWS\System32\bdesvc.dll
16:32:14.0558 3168 BDESVC - ok
16:32:14.0589 3168 [ EC19013E4CF87609534165DF897274D6 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
16:32:14.0589 3168 Beep - ok
16:32:14.0620 3168 [ 6468B696C65775D51A06615830E0E79D ] BFE C:\WINDOWS\System32\bfe.dll
16:32:14.0636 3168 BFE - ok
16:32:14.0714 3168 [ F14F048B4D05FBCE536250EA74BF9FDC ] BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140214.001\BHDrvx64.sys
16:32:14.0730 3168 BHDrvx64 - ok
16:32:14.0761 3168 [ 15225081966C785A9192782401643FD4 ] BITS C:\WINDOWS\System32\qmgr.dll
16:32:14.0777 3168 BITS - ok
16:32:14.0777 3168 [ 6B4FFFDDC618FCF64473CAA86E305697 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
16:32:14.0777 3168 bowser - ok
16:32:14.0792 3168 [ A6207A88B596F726DE558425F3B7E592 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
16:32:14.0808 3168 BrokerInfrastructure - ok
16:32:14.0824 3168 [ D528D6A92D187777691993DD757AF19A ] Browser C:\WINDOWS\System32\browser.dll
16:32:14.0824 3168 Browser - ok
16:32:14.0870 3168 [ BCDB654338FA6C4BEE20A8EA47092171 ] BTATH_A2DP C:\WINDOWS\system32\drivers\btath_a2dp.sys
16:32:14.0870 3168 BTATH_A2DP - ok
16:32:14.0870 3168 [ A71E33AEF3289BE2BA6CAD032BF9BFBA ] btath_avdt C:\WINDOWS\system32\drivers\btath_avdt.sys
16:32:14.0870 3168 btath_avdt - ok
16:32:14.0902 3168 [ 4AF7C20F94DAC343C01ED671C82DCB99 ] BTATH_HCRP C:\WINDOWS\System32\drivers\btath_hcrp.sys
16:32:14.0902 3168 BTATH_HCRP - ok
16:32:14.0917 3168 [ 785C38070043BEEE9E9D591DE4067244 ] BTATH_LWFLT C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys
16:32:14.0917 3168 BTATH_LWFLT - ok
16:32:14.0933 3168 [ 31EC5FC3FC5CB273F2709AAF4AD88ED4 ] BTATH_RCP C:\WINDOWS\System32\drivers\btath_rcp.sys
16:32:14.0949 3168 BTATH_RCP - ok
16:32:14.0964 3168 [ 90A7BDDC5B48E94F999FA66645DBBF91 ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
16:32:14.0980 3168 BtFilter - ok
16:32:14.0996 3168 [ A8F23D453A424FF4DE04989C4727ECC7 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
16:32:14.0996 3168 BthAvrcpTg - ok
16:32:15.0011 3168 [ 131F1C8573E7BFB41C54FBF5309CCD94 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys
16:32:15.0011 3168 BthEnum - ok
16:32:15.0027 3168 [ 746B9F94214915AECDE4B7FEA5FF9664 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
16:32:15.0027 3168 BthHFEnum - ok
16:32:15.0058 3168 [ 71FE2A48E4C93DDB9798C024880B6C07 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
16:32:15.0058 3168 bthhfhid - ok
16:32:15.0074 3168 [ FCD8BD17B7193CFFF18C332D1A381D7F ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
16:32:15.0074 3168 BthLEEnum - ok
16:32:15.0089 3168 [ 07E33226AD218A2A162662A05CAFB52F ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
16:32:15.0105 3168 BTHMODEM - ok
16:32:15.0121 3168 [ 3AFE71D80EDF5D4DE0C5731352905669 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
16:32:15.0121 3168 BthPan - ok
16:32:15.0152 3168 [ 10EDF9E0838BA4578FFFFF274632D454 ] BTHPORT C:\WINDOWS\System32\Drivers\BTHport.sys
16:32:15.0152 3168 BTHPORT - ok
16:32:15.0167 3168 [ E5E48FEED73D463175EAB1542495191C ] bthserv C:\WINDOWS\system32\bthserv.dll
16:32:15.0167 3168 bthserv - ok
16:32:15.0183 3168 [ 0E7FA34B975764C33B5DBC6F8C401627 ] BTHUSB C:\WINDOWS\System32\Drivers\BTHUSB.sys
16:32:15.0183 3168 BTHUSB - ok
16:32:15.0230 3168 [ 0510396A957E9FD7205BA62D3CAE4528 ] ccSet_NIS C:\WINDOWS\system32\drivers\NISx64\1501000.012\ccSetx64.sys
16:32:15.0246 3168 ccSet_NIS - ok
16:32:15.0277 3168 [ 2FA6510E33F7DEFEC03658B74101A9B9 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
16:32:15.0277 3168 cdfs - ok
16:32:15.0277 3168 [ C6796EA22B513E3457514D92DCDB1A3D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
16:32:15.0277 3168 cdrom - ok
16:32:15.0308 3168 [ AB285CE3431FF3D2ACE669245874C1C7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
16:32:15.0308 3168 CertPropSvc - ok
16:32:15.0339 3168 [ BE9936EDD3267FAAFF94A7835867F00B ] circlass C:\WINDOWS\System32\drivers\circlass.sys
16:32:15.0339 3168 circlass - ok
16:32:15.0355 3168 [ 7F006813C2AFE622C13D7AF94F56CD07 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
16:32:15.0371 3168 CLFS - ok
16:32:15.0402 3168 [ EF6EF85DADC3184A10D8F2F7159973CB ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
16:32:15.0402 3168 CmBatt - ok
16:32:15.0417 3168 [ 825BE21E6395E00698D8A23955A87972 ] CNG C:\WINDOWS\system32\Drivers\cng.sys
16:32:15.0417 3168 CNG - ok
16:32:15.0464 3168 [ E9BCC890CC2692F29A209B6A14AFAF35 ] CnxtHdAudService C:\WINDOWS\system32\drivers\CHDRT64.sys
16:32:15.0480 3168 CnxtHdAudService - ok
16:32:15.0496 3168 [ 03AAED827C36F35D70900558B8274905 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys
16:32:15.0496 3168 CompositeBus - ok
16:32:15.0496 3168 COMSysApp - ok
16:32:15.0511 3168 [ A1FF7DFBFBE164CF92603C651D304DD2 ] condrv C:\WINDOWS\system32\drivers\condrv.sys
16:32:15.0511 3168 condrv - ok
16:32:17.0214 3168 [ D5F868A46AED8E7CAD6C30E0599DD100 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
16:32:17.0230 3168 cphs - ok
16:32:17.0246 3168 [ 0EFE4B5884A8032617826A4D76F80969 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
16:32:17.0246 3168 CryptSvc - ok
16:32:17.0292 3168 [ 0BF56545D2E82A48579A633DC65B9494 ] CxAudMsg C:\windows\system32\CxAudMsg64.exe
16:32:17.0292 3168 CxAudMsg - ok
16:32:17.0308 3168 [ 315BA4BC19316D72B2E037534E048B93 ] dam C:\WINDOWS\system32\drivers\dam.sys
16:32:17.0308 3168 dam - ok
16:32:17.0324 3168 [ 3FD5AE42EC87C6F532A931F96BE731DD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
16:32:17.0339 3168 DcomLaunch - ok
16:32:17.0339 3168 [ F4CCAADC2C78F57E4F16B24C9201CE22 ] defragsvc C:\WINDOWS\System32\defragsvc.dll
16:32:17.0339 3168 defragsvc - ok
16:32:17.0386 3168 [ 0BC71D4D3B5883903C37BF4E13B0F0C5 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
16:32:17.0386 3168 DeviceAssociationService - ok
16:32:17.0402 3168 [ 752A457320A946E03C3AA86C3ACD735E ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
16:32:17.0402 3168 DeviceInstall - ok
16:32:17.0417 3168 [ 5DB26D7E0216D0BF364A81D3829AD7B9 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
16:32:17.0417 3168 Dfsc - ok
16:32:17.0433 3168 [ 8B107F55FD61654A6C9F1B819AEC5FC4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
16:32:17.0433 3168 Dhcp - ok
16:32:17.0449 3168 [ 4D40C9B33F738797CF50E77CB7C53E85 ] disk C:\WINDOWS\system32\drivers\disk.sys
16:32:17.0449 3168 disk - ok
16:32:17.0464 3168 [ EB70A894708D1BC176AFD690FF06085F ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
16:32:17.0464 3168 dmvsc - ok
16:32:17.0480 3168 [ 5BAF7714E68F93515A937A3FA8587EF9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
16:32:17.0480 3168 Dnscache - ok
16:32:17.0496 3168 [ 50288EA079BB520C2B8C8A154202D518 ] dot3svc C:\WINDOWS\System32\dot3svc.dll
16:32:17.0511 3168 dot3svc - ok
16:32:17.0527 3168 [ 281BEE07BA97E3E98D12A822D923D0D8 ] DPS C:\WINDOWS\system32\dps.dll
16:32:17.0527 3168 DPS - ok
16:32:17.0542 3168 [ DDC11A202207C0400CBE07315B8FDE5E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
16:32:17.0542 3168 drmkaud - ok
16:32:17.0558 3168 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
16:32:17.0558 3168 DsmSvc - ok
16:32:17.0605 3168 [ A3D1CB64DF885ACE126543E6D7067348 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
16:32:17.0605 3168 DXGKrnl - ok
16:32:17.0621 3168 [ 6073537F250B45E1CB2A02E97F0FE1B2 ] Eaphost C:\WINDOWS\System32\eapsvc.dll
16:32:17.0636 3168 Eaphost - ok
16:32:17.0699 3168 [ 114BCFDF367FF37C3F1B0A96AF542E4D ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
16:32:17.0730 3168 ebdrv - ok
16:32:17.0777 3168 [ 1B7AA375F711F66D5FF2B855F9EC987F ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
16:32:17.0777 3168 eeCtrl - ok
16:32:17.0792 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] EFS C:\WINDOWS\System32\lsass.exe
16:32:17.0792 3168 EFS - ok
16:32:17.0808 3168 [ 43531A5993380CC5113242C29D265FD9 ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
16:32:17.0808 3168 EhStorClass - ok
16:32:17.0824 3168 [ 6F8E738A9505A388B1157FDDE7B3101B ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
16:32:17.0824 3168 EhStorTcgDrv - ok
16:32:17.0839 3168 [ 7230C8B80DDE1F0524C353240B78CC0E ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
16:32:17.0839 3168 EraserUtilRebootDrv - ok
16:32:17.0839 3168 [ DFFFAE1442BA4076E18EED5E406FA0D3 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
16:32:17.0839 3168 ErrDev - ok
16:32:17.0855 3168 esgiguard - ok
16:32:17.0902 3168 [ 9CBBFB1953562BCAE1B1F351F17E32D8 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
16:32:17.0902 3168 ETD - ok
16:32:17.0949 3168 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3 ] EventSystem C:\WINDOWS\system32\es.dll
16:32:17.0949 3168 EventSystem - ok
16:32:17.0964 3168 [ 7729D294A555C7AEB281ED8E4D0E01E4 ] exfat C:\WINDOWS\system32\drivers\exfat.sys
16:32:17.0964 3168 exfat - ok
16:32:17.0980 3168 [ 7C4E0D5900B2A1D11EDD626D6DDB937B ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
16:32:17.0980 3168 fastfat - ok
16:32:18.0011 3168 [ 2BC8532ABF2B3756B78FA1DA54147DDE ] Fax C:\WINDOWS\system32\fxssvc.exe
16:32:18.0011 3168 Fax - ok
16:32:18.0027 3168 [ 5D8402613E778B3BD45E687A8372710B ] fdc C:\WINDOWS\System32\drivers\fdc.sys
16:32:18.0027 3168 fdc - ok
16:32:18.0058 3168 [ DC1A78BCCCB7EE53D6FD3BD615A8E222 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
16:32:18.0058 3168 fdPHost - ok
16:32:18.0058 3168 [ E5AD448F2DC84B1CF387FA7F2A3D1936 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
16:32:18.0058 3168 FDResPub - ok
16:32:18.0074 3168 [ 0046E0BD031213D37123876B0D0FA61C ] fhsvc C:\WINDOWS\system32\fhsvc.dll
16:32:18.0089 3168 fhsvc - ok
16:32:18.0121 3168 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
16:32:18.0121 3168 FileInfo - ok
16:32:18.0121 3168 [ A1A66C4FDAFD6B0289523232AFB7D8AF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
16:32:18.0136 3168 Filetrace - ok
16:32:18.0136 3168 [ BE743083CF7063C486A4398E3AEFE59A ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
16:32:18.0136 3168 flpydisk - ok
16:32:18.0293 3168 [ 60D5067FCE6D9433D35E04C01D8538B3 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
16:32:18.0293 3168 FltMgr - ok
16:32:18.0339 3168 [ 183CA7699474FDE235853967D1DA4D9B ] FontCache C:\WINDOWS\system32\FntCache.dll
16:32:18.0355 3168 FontCache - ok
16:32:18.0449 3168 [ 1C52387BF5A127F5F3BFB31288F30D93 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:32:18.0449 3168 FontCache3.0.0.0 - ok
16:32:18.0464 3168 [ 35005534E600E993A90B036E4E599F2B ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
16:32:18.0464 3168 FsDepends - ok
16:32:18.0480 3168 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:32:18.0480 3168 Fs_Rec - ok
16:32:18.0527 3168 [ 83E1F0983B02A6F8EC764D18E24ECF10 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
16:32:18.0527 3168 fvevol - ok
16:32:18.0543 3168 [ 9591D0B9351ED489EAFD9D1CE52A8015 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys
16:32:18.0543 3168 FxPPM - ok
16:32:18.0558 3168 [ FC3EF65EE20D39F8749C2218DBA681CA ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys
16:32:18.0558 3168 gagp30kx - ok
16:32:18.0574 3168 [ 0BF5CAD281E25F1418E5B8875DC5ADD1 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
16:32:18.0574 3168 gencounter - ok
16:32:18.0589 3168 [ FDA72810CA2F8409D9B31E833C448E34 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
16:32:18.0589 3168 GPIOClx0101 - ok
16:32:18.0636 3168 [ 0BDE0FCF597E9B65600121EF54FF8340 ] gpsvc C:\WINDOWS\System32\gpsvc.dll
16:32:18.0652 3168 gpsvc - ok
16:32:18.0668 3168 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:32:18.0668 3168 gupdate - ok
16:32:18.0668 3168 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:32:18.0668 3168 gupdatem - ok
16:32:18.0668 3168 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
16:32:18.0683 3168 HDAudBus - ok
16:32:18.0699 3168 [ 10A70BC1871CD955D85CD88372724906 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
16:32:18.0699 3168 HidBatt - ok
16:32:18.0714 3168 [ 1EA1B4FABB8CC348E73CA90DBA22E104 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
16:32:18.0714 3168 HidBth - ok
16:32:18.0730 3168 [ C241A8BAFBBFC90176EA0F5240EACC17 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
16:32:18.0730 3168 hidi2c - ok
16:32:18.0746 3168 [ 9BDDEE26255421017E161CCB9D5EDA95 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
16:32:18.0746 3168 HidIr - ok
16:32:18.0761 3168 [ 449A20A674AA3FAA7F0DD4E33EE2DC20 ] hidserv C:\WINDOWS\system32\hidserv.dll
16:32:18.0761 3168 hidserv - ok
16:32:18.0777 3168 [ F31397220D9687E11EB448649AA6E038 ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
16:32:18.0777 3168 HidUsb - ok
16:32:18.0793 3168 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll
16:32:18.0808 3168 hkmsvc - ok
16:32:18.0839 3168 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
16:32:18.0839 3168 HomeGroupListener - ok
16:32:18.0871 3168 [ BE5F89BAFBD4272D5A0C0A37B97865ED ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
16:32:18.0886 3168 HomeGroupProvider - ok
16:32:18.0886 3168 [ A6AACEA4C785789BDA5912AD1FEDA80D ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
16:32:18.0886 3168 HpSAMD - ok
16:32:18.0902 3168 [ 3502776E366C913D49C0DA928AE3E6CB ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
16:32:18.0918 3168 HTTP - ok
16:32:18.0933 3168 [ 90656C0B3864804B090434EFC582404F ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
16:32:18.0933 3168 hwpolicy - ok
16:32:18.0949 3168 [ 6D6F9E3BF0484967E52F7E846BFF1CA1 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
16:32:18.0949 3168 hyperkbd - ok
16:32:18.0964 3168 [ 907C870F8C31F8DDD6F090857B46AB25 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
16:32:18.0964 3168 HyperVideo - ok
16:32:18.0980 3168 [ 84CFC5EFA97D0C965EDE1D56F116A541 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
16:32:18.0980 3168 i8042prt - ok
16:32:18.0996 3168 [ 5D90E32E36CE5D4C535D17CE08AEAF05 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
16:32:18.0996 3168 iaLPSSi_GPIO - ok
16:32:19.0011 3168 [ DD05E7E80F52ADE9AEB292819920F32C ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
16:32:19.0011 3168 iaLPSSi_I2C - ok
16:32:19.0043 3168 [ FA4C48E36F0B24E7E33D3E7E1844B9C9 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
16:32:19.0058 3168 iaStorA - ok
16:32:19.0074 3168 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys
16:32:19.0089 3168 iaStorAV - ok
16:32:19.0183 3168 [ D5854F77CEEAFC5A8405F8ECCBEC09DF ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
16:32:19.0183 3168 IAStorDataMgrSvc - ok
16:32:19.0199 3168 [ A2200C3033FA4EF249FC096A7A7D02A2 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
16:32:19.0199 3168 iaStorV - ok
16:32:19.0246 3168 [ 83FF82FE209E7997067B375DAD6CF23D ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
16:32:19.0246 3168 ICCS - ok
16:32:19.0308 3168 [ 777612849691B0D9EE064F93481FEFF1 ] IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140221.001\IDSvia64.sys
16:32:19.0324 3168 IDSVia64 - ok
16:32:19.0324 3168 IEEtwCollectorService - ok
16:32:19.0589 3168 [ 4F6363C26B4A3DDBC9FAFCBA68602B01 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
16:32:19.0605 3168 igfx - ok
16:32:19.0652 3168 [ B82255670D270B75D2D2F0F8747D1443 ] IKEEXT C:\WINDOWS\System32\ikeext.dll
16:32:19.0668 3168 IKEEXT - ok
16:32:19.0699 3168 [ 4011430BC9DA46ADFAE9915EFEC312FB ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
16:32:19.0699 3168 intaud_WaveExtensible - ok
16:32:19.0714 3168 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
16:32:19.0714 3168 IntcDAud - ok
16:32:19.0746 3168 [ B353F1834FCD36D77BE3F74992C147D4 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
16:32:19.0746 3168 Intel(R) Capability Licensing Service Interface - ok
16:32:19.0761 3168 [ 4E448FCFFD00E8D657CD9E48D3E47157 ] intelide C:\WINDOWS\system32\drivers\intelide.sys
16:32:19.0761 3168 intelide - ok
16:32:19.0793 3168 [ 139CFCDCD36B1B1782FD8C0014AC9B0E ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
16:32:19.0793 3168 intelpep - ok
16:32:19.0808 3168 [ 47E74A8E53C7C24DCE38311E1451C1D9 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
16:32:19.0808 3168 intelppm - ok
16:32:19.0824 3168 [ 9DB76D7F9E4E53EFE5DD8C53DE837514 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:32:19.0824 3168 IpFilterDriver - ok
16:32:19.0855 3168 [ DFC4050D58565ADBEE793A8D4AEBDAE6 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
16:32:19.0871 3168 iphlpsvc - ok
16:32:19.0886 3168 [ 9949A3C7590B8C536C05312205079A82 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
16:32:19.0886 3168 IPMIDRV - ok
16:32:19.0918 3168 [ B7342B3C58E91107F6E946A93D9D4EFD ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
16:32:19.0918 3168 IPNAT - ok
16:32:19.0933 3168 [ AE44C526AB5F8A487D941CEB57B10C97 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
16:32:19.0933 3168 IRENUM - ok
16:32:19.0964 3168 [ 8AFEEA3955AA43616A60F133B1D25F21 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
16:32:19.0964 3168 isapnp - ok
16:32:19.0980 3168 [ 034D4BD9DC67C64F3A4C8A049B5173BF ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
16:32:19.0980 3168 iScsiPrt - ok
16:32:19.0996 3168 [ EE03564B7FAFE2E44EDA33D52E83B4A3 ] iwdbus C:\WINDOWS\System32\drivers\iwdbus.sys
16:32:19.0996 3168 iwdbus - ok
16:32:20.0043 3168 [ 5B14FDE79871F83A5E0DCDC01F78BECF ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
16:32:20.0058 3168 jhi_service - ok
16:32:20.0074 3168 [ 8BE92376799B6B44D543E8D07CDCF885 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
16:32:20.0074 3168 kbdclass - ok
16:32:20.0090 3168 [ FB6E47E569D4872ABEB506BE03A45FBA ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
16:32:20.0090 3168 kbdhid - ok
16:32:20.0105 3168 [ 813871C7D402A05F2E3A7075F9584A05 ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys
16:32:20.0105 3168 kdnic - ok
16:32:20.0121 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] KeyIso C:\WINDOWS\system32\lsass.exe
16:32:20.0121 3168 KeyIso - ok
16:32:20.0136 3168 [ ADDECBCC777665BD113BED437E602AB0 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
16:32:20.0136 3168 KSecDD - ok
16:32:20.0152 3168 [ 7296EA420134EAC390798B3232D066A4 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
16:32:20.0168 3168 KSecPkg - ok
16:32:20.0183 3168 [ 11AFB527AA370B1DAFD5C36F35F6D45F ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
16:32:20.0183 3168 ksthunk - ok
16:32:20.0199 3168 [ 32B1A8351160F307A8C66BCB0F94A9C2 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
16:32:20.0214 3168 KtmRm - ok
16:32:20.0230 3168 [ 50AECF8C21AB2A6428A6E1E10549D8E5 ] L1C C:\WINDOWS\system32\DRIVERS\L1C63x64.sys
16:32:20.0230 3168 L1C - ok
16:32:20.0261 3168 [ 27B58E16CF895AC1F1A97C04814C2239 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
16:32:20.0261 3168 LanmanServer - ok
16:32:20.0277 3168 [ D0D9C2ECA4D03A8F06DCD91236B90C98 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
16:32:20.0277 3168 LanmanWorkstation - ok
16:32:20.0308 3168 [ EE289BD147FDFF95EF1B9BD65D3B974A ] lfsvc C:\WINDOWS\System32\GeofenceMonitorService.dll
16:32:20.0324 3168 lfsvc - ok
16:32:20.0355 3168 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\WINDOWS\system32\DRIVERS\LhdX64.sys
16:32:20.0355 3168 LHDmgr - ok
16:32:20.0371 3168 [ C09010B3680860131631F53E8FE7BAD8 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys
16:32:20.0371 3168 lltdio - ok
16:32:20.0402 3168 [ 00E070FC0C673311AFD4B068D1242780 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
16:32:20.0418 3168 lltdsvc - ok
16:32:20.0433 3168 [ D113FAD71A5E67AA94B32A0F8828D265 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
16:32:20.0433 3168 lmhosts - ok
16:32:20.0480 3168 [ 3974B7CE015A6EEF30DA4ADD5F1203D0 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
16:32:20.0480 3168 LMS - ok
16:32:20.0496 3168 [ C755AE4635457AA2A11F79C0DF857ABC ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
16:32:20.0496 3168 LSI_SAS - ok
16:32:20.0511 3168 [ ADAC09CBE7A2040B7F68B5E5C9A75141 ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys
16:32:20.0511 3168 LSI_SAS2 - ok
16:32:20.0527 3168 [ 04D1274BB9BBCCF12BD12374002AA191 ] LSI_SAS3 C:\WINDOWS\system32\drivers\lsi_sas3.sys
16:32:20.0527 3168 LSI_SAS3 - ok
16:32:20.0543 3168 [ 327469EEF3833D0C584B7E88A76AEC0C ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
16:32:20.0543 3168 LSI_SSS - ok
16:32:20.0574 3168 [ B6B69FF200F68888A7FAFDF204D00C91 ] LSM C:\WINDOWS\System32\lsm.dll
16:32:20.0590 3168 LSM - ok
16:32:20.0605 3168 [ 5EF604B0698F4FA962778285E8C5F1F2 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
16:32:20.0605 3168 luafv - ok
16:32:20.0621 3168 [ EB5C03A070F30D64A6DF80E53B22F53F ] megasas C:\WINDOWS\system32\drivers\megasas.sys
Re: Kontrola-podezření na malware
16:32:20.0621 3168 megasas - ok
16:32:20.0636 3168 [ F6F13533196DE7A582D422B0241E4363 ] megasr C:\WINDOWS\system32\drivers\megasr.sys
16:32:20.0652 3168 megasr - ok
16:32:20.0683 3168 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
16:32:20.0683 3168 MEIx64 - ok
16:32:20.0715 3168 [ FD788C2D96EA91469A3C1D13E80D7473 ] MMCSS C:\WINDOWS\system32\mmcss.dll
16:32:20.0715 3168 MMCSS - ok
16:32:20.0730 3168 [ 8B38C44F69259987C95135C9627E2378 ] Modem C:\WINDOWS\system32\drivers\modem.sys
16:32:20.0730 3168 Modem - ok
16:32:20.0761 3168 [ 601589000CC90F0DF8DA2CC254A3CCC9 ] monitor C:\WINDOWS\System32\drivers\monitor.sys
16:32:20.0761 3168 monitor - ok
16:32:20.0761 3168 [ CEAC6D40FE887CE8406C2393CF97DE06 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys
16:32:20.0761 3168 mouclass - ok
16:32:20.0777 3168 [ 02D98BF804084E9A0D69D1C69B02CCA9 ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys
16:32:20.0793 3168 mouhid - ok
16:32:20.0793 3168 [ 515549560D481138E6E21AF7C6998E56 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys
16:32:20.0793 3168 mountmgr - ok
16:32:20.0808 3168 [ F170510BE94CF45E3C6274578F6204B2 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys
16:32:20.0808 3168 mpsdrv - ok
16:32:20.0824 3168 [ D186C5844393252147BE934F3871DB7A ] MpsSvc C:\WINDOWS\system32\mpssvc.dll
16:32:20.0840 3168 MpsSvc - ok
16:32:20.0855 3168 [ 59DCEC7499095DE5AED741358037AE2D ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
16:32:20.0871 3168 MRxDAV - ok
16:32:20.0886 3168 [ 79B6F3DF7CDFD12159871FF71464F0CE ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:32:20.0886 3168 mrxsmb - ok
16:32:20.0902 3168 [ 295771B092D4F7FCF2B62F80CCD14320 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
16:32:20.0918 3168 mrxsmb10 - ok
16:32:20.0918 3168 [ AAF56E4E84D35411B4E446C445732DFE ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
16:32:20.0918 3168 mrxsmb20 - ok
16:32:20.0933 3168 [ 4E888019078AC363076A5433E89AA4F8 ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys
16:32:20.0933 3168 MsBridge - ok
16:32:20.0965 3168 [ A082C17D14D0790E27D064EA4B138AE1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
16:32:20.0965 3168 MSDTC - ok
16:32:20.0996 3168 [ D13329FBF8345B28AB30F44CC247DC08 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
16:32:20.0996 3168 Msfs - ok
16:32:21.0011 3168 [ C6B474E46F9E543B875981ED3FFE6ADD ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
16:32:21.0011 3168 msgpiowin32 - ok
16:32:21.0027 3168 [ 65C92EB9D08DB5C69F28C7FFD4E84E31 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys
16:32:21.0027 3168 mshidkmdf - ok
16:32:21.0043 3168 [ 52299F086AC2DAFD100DD5DC4A8614BA ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
16:32:21.0043 3168 mshidumdf - ok
16:32:21.0043 3168 [ 36D92AF3343C3A3E57FEF11C449AEA4C ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys
16:32:21.0043 3168 msisadrv - ok
16:32:21.0058 3168 [ 810F8A0A0680662BB0CE44D0E2CEF90C ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll
16:32:21.0058 3168 MSiSCSI - ok
16:32:21.0074 3168 msiserver - ok
16:32:21.0090 3168 [ A9BBBD2BAE6142253B9195E949AC2E8D ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:32:21.0090 3168 MSKSSRV - ok
16:32:21.0105 3168 [ 375E44168F2DFB91A68B8A3F619C5A7C ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys
16:32:21.0105 3168 MsLldp - ok
16:32:21.0121 3168 [ 7B2128EB875DCBC006E6A913211006D6 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:32:21.0121 3168 MSPCLOCK - ok
16:32:21.0136 3168 [ 1E88171579B218115C7A772F8DE04BD8 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
16:32:21.0136 3168 MSPQM - ok
16:32:21.0152 3168 [ BBE2A455053E63BECBF42C2F9B21FAE0 ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys
16:32:21.0152 3168 MsRPC - ok
16:32:21.0168 3168 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys
16:32:21.0168 3168 mssmbios - ok
16:32:21.0183 3168 [ 115019AE01E0EB9C048530D2928AB4A2 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
16:32:21.0183 3168 MSTEE - ok
16:32:21.0199 3168 [ 96D604A35070360F0DD4A7A8AF410B5E ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
16:32:21.0199 3168 MTConfig - ok
16:32:21.0215 3168 [ 619CA29326B82372621DB2C0964D8365 ] Mup C:\WINDOWS\system32\Drivers\mup.sys
16:32:21.0215 3168 Mup - ok
16:32:21.0230 3168 [ B8C35C94DCB2DFEAF03BB42131F2F77F ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
16:32:21.0230 3168 mvumis - ok
16:32:21.0261 3168 [ 41A45D2A75494EABF2806EA051E00376 ] napagent C:\WINDOWS\system32\qagentRT.dll
16:32:21.0261 3168 napagent - ok
16:32:21.0293 3168 [ CF8B989D89D6807B887690F2CF24EFD9 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
16:32:21.0293 3168 NativeWifiP - ok
16:32:21.0340 3168 [ 702E07EC32F96ACDB873E9A5465D4401 ] NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140223.018\ENG64.SYS
16:32:21.0340 3168 NAVENG - ok
16:32:21.0386 3168 [ 302EA314A1AF0D7CEF0A3D0195F79561 ] NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140223.018\EX64.SYS
16:32:21.0418 3168 NAVEX15 - ok
16:32:21.0433 3168 [ 71E3C0100AA19D11373CCEB2F51A6008 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
16:32:21.0449 3168 NcaSvc - ok
16:32:21.0449 3168 [ 51DF09CAB2CAC64FEE3E371D9028ED01 ] NcbService C:\WINDOWS\System32\ncbservice.dll
16:32:21.0465 3168 NcbService - ok
16:32:21.0465 3168 [ 2586C4C167499210DCBF3ECFD8CCE210 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
16:32:21.0480 3168 NcdAutoSetup - ok
16:32:21.0512 3168 [ ED39D676080A1AEA755F1DEC1A8DF1A4 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
16:32:21.0512 3168 NDIS - ok
16:32:21.0527 3168 [ C6BB12BC35D1637CA17AE16D3A4725EB ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
16:32:21.0527 3168 NdisCap - ok
16:32:21.0527 3168 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
16:32:21.0527 3168 NdisImPlatform - ok
16:32:21.0527 3168 [ 9423421E735BD5394351E0C47C76BB92 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:32:21.0527 3168 NdisTapi - ok
16:32:21.0543 3168 [ B832B35055BA2B7B4181861FF94D8E59 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:32:21.0543 3168 Ndisuio - ok
16:32:21.0558 3168 [ 1F58E48EF75F34C35D8E93A0DC535CFE ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
16:32:21.0558 3168 NdisVirtualBus - ok
16:32:21.0574 3168 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:32:21.0574 3168 NdisWan - ok
16:32:21.0574 3168 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWanLegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:32:21.0574 3168 NdisWanLegacy - ok
16:32:21.0590 3168 [ A5BD69A8812FA79D1A487691DD3FB244 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
16:32:21.0590 3168 NDProxy - ok
16:32:21.0605 3168 [ 5A072F0B90C29C5233D78BE33EF5ED78 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
16:32:21.0605 3168 Ndu - ok
16:32:21.0621 3168 [ A83D67D347A684F10B7D3019C8A6380C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
16:32:21.0621 3168 NetBIOS - ok
16:32:21.0637 3168 [ 0217532E19A748F0E5D569307363D5FD ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
16:32:21.0637 3168 NetBT - ok
16:32:21.0652 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] Netlogon C:\WINDOWS\system32\lsass.exe
16:32:21.0652 3168 Netlogon - ok
16:32:21.0683 3168 [ B7AD851A21FEBA3BA214972627614207 ] Netman C:\WINDOWS\System32\netman.dll
16:32:21.0699 3168 Netman - ok
16:32:21.0715 3168 [ F0F0A372C2EF6358399C4936F91B6131 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
16:32:21.0715 3168 netprofm - ok
16:32:21.0746 3168 [ 1092B3190E69E0C5ECBCE90F171DE047 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:32:21.0746 3168 NetTcpPortSharing - ok
16:32:21.0762 3168 [ 70414DB660BFBB7BD58FCE8EA4364E1B ] netvsc C:\WINDOWS\system32\DRIVERS\netvsc63.sys
16:32:21.0762 3168 netvsc - ok
16:32:21.0871 3168 [ C87442B6D17912785DC143CEDCA508C9 ] NIS C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
16:32:21.0871 3168 NIS - ok
16:32:21.0902 3168 [ 3A280F3B3C7A46E29C404ACD46ECBF5E ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
16:32:21.0902 3168 NlaSvc - ok
16:32:21.0918 3168 [ 8F44A2F57C9F1A19AC9C6288C10FB351 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
16:32:21.0918 3168 Npfs - ok
16:32:21.0949 3168 [ CBDB4F0871C88DF930FC0E8588CA67FC ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
16:32:21.0949 3168 npsvctrig - ok
16:32:21.0949 3168 [ 6E2271ED0C3E95B8E29F3752B91B9E84 ] nsi C:\WINDOWS\system32\nsisvc.dll
16:32:21.0949 3168 nsi - ok
16:32:21.0965 3168 [ E490B459978CB87779E84C761D22B827 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
16:32:21.0965 3168 nsiproxy - ok
16:32:22.0012 3168 [ 4412D565C0278C401575E11072C7DCE3 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
16:32:22.0027 3168 Ntfs - ok
16:32:22.0043 3168 [ EF1B290FC9F0E47CC0B537292BEE5904 ] Null C:\WINDOWS\system32\drivers\Null.sys
16:32:22.0043 3168 Null - ok
16:32:22.0058 3168 [ BC6B5942AFF25EBAF62DE43C3807EDF8 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
16:32:22.0058 3168 nvraid - ok
16:32:22.0090 3168 [ 1F43ABFFAC3D6CA356851D517392966E ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
16:32:22.0090 3168 nvstor - ok
16:32:22.0105 3168 [ 6934A936A7369DFE37B7DBA93F5E5E49 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
16:32:22.0105 3168 nv_agp - ok
16:32:22.0137 3168 [ 3B510F20806B94E389784ED09DBD2111 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
16:32:22.0152 3168 p2pimsvc - ok
16:32:22.0183 3168 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B ] p2psvc C:\WINDOWS\system32\p2psvc.dll
16:32:22.0183 3168 p2psvc - ok
16:32:22.0215 3168 [ 764B1121867B2D9B31C491668AC72B2B ] Parport C:\WINDOWS\System32\drivers\parport.sys
16:32:22.0215 3168 Parport - ok
16:32:22.0230 3168 [ EF0C1749C9A8CEE9A457473D433CC00F ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
16:32:22.0230 3168 partmgr - ok
16:32:22.0246 3168 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
16:32:22.0262 3168 PcaSvc - ok
16:32:22.0277 3168 [ C0D3F3BC1C84B4BA746D9847314C1164 ] pci C:\WINDOWS\system32\drivers\pci.sys
16:32:22.0277 3168 pci - ok
16:32:22.0293 3168 [ 346E38FCC6859A727DD28AFAD1F0AFF4 ] pciide C:\WINDOWS\system32\drivers\pciide.sys
16:32:22.0293 3168 pciide - ok
16:32:22.0308 3168 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
16:32:22.0308 3168 pcmcia - ok
16:32:22.0308 3168 [ BF28771D1436C88BE1D297D3098B0F7D ] pcw C:\WINDOWS\system32\drivers\pcw.sys
16:32:22.0308 3168 pcw - ok
16:32:22.0324 3168 [ B9D968D8E2B0F9C6301CEB39CFC9B9E4 ] pdc C:\WINDOWS\system32\drivers\pdc.sys
16:32:22.0324 3168 pdc - ok
16:32:22.0340 3168 [ BA50CC0BD19004AAB88BE37338B6FA0D ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
16:32:22.0340 3168 PEAUTH - ok
16:32:24.0074 3168 [ 8E3C640FFF5A963F570233AE99C0FFF3 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
16:32:24.0074 3168 PerfHost - ok
16:32:24.0137 3168 [ 928061178CD9856CA6B67FFFCE6BA766 ] pla C:\WINDOWS\system32\pla.dll
16:32:24.0152 3168 pla - ok
16:32:24.0168 3168 [ 752A457320A946E03C3AA86C3ACD735E ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
16:32:24.0184 3168 PlugPlay - ok
16:32:24.0184 3168 [ 045EB4F260606A03BE340D09DEAF3BA4 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
16:32:24.0199 3168 PNRPAutoReg - ok
16:32:24.0215 3168 [ 3B510F20806B94E389784ED09DBD2111 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
16:32:24.0215 3168 PNRPsvc - ok
16:32:24.0230 3168 [ C16097D77A232A288D65F299E2E01105 ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
16:32:24.0230 3168 PolicyAgent - ok
16:32:24.0246 3168 [ 00E08B30E7F7C13ECE2CDF4F46A77311 ] Power C:\WINDOWS\system32\umpo.dll
16:32:24.0246 3168 Power - ok
16:32:24.0324 3168 [ B7DB57A000D46D4DE75BC0C563E58072 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
16:32:24.0355 3168 PrintNotify - ok
16:32:24.0371 3168 [ ECD373F9571C745894367CC2635EA44F ] Processor C:\WINDOWS\System32\drivers\processr.sys
16:32:24.0371 3168 Processor - ok
16:32:24.0387 3168 [ 8513A1E7AE4B9DC82C4B4F432C648A58 ] ProfSvc C:\WINDOWS\system32\profsvc.dll
16:32:24.0387 3168 ProfSvc - ok
16:32:24.0402 3168 [ 8528BB05E4D4E25945F78B00B2555FB7 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
16:32:24.0402 3168 Psched - ok
16:32:24.0449 3168 [ AF90BB44C99D6820BE52C9BBAA523283 ] QWAVE C:\WINDOWS\system32\qwave.dll
16:32:24.0449 3168 QWAVE - ok
16:32:24.0465 3168 [ 3FB466684609A4329858CF2EBD62E0FD ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
16:32:24.0465 3168 QWAVEdrv - ok
16:32:24.0480 3168 [ 2C56F0EE27E4EF70CA4B4983D3638905 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:32:24.0480 3168 RasAcd - ok
16:32:24.0496 3168 [ 5F061AC45266841A2860C1858ED863B8 ] RasAuto C:\WINDOWS\System32\rasauto.dll
16:32:24.0496 3168 RasAuto - ok
16:32:24.0512 3168 [ BF3B17016764F20F9D28CF1A8DC210C0 ] RasMan C:\WINDOWS\System32\rasmans.dll
16:32:24.0527 3168 RasMan - ok
16:32:24.0543 3168 [ 5247F308C4103CDC4FE12AE1D235800A ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:32:24.0543 3168 RasPppoe - ok
16:32:24.0590 3168 [ B939A2A0F9D6C6C186721E268EB6FA93 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:32:24.0605 3168 rdbss - ok
16:32:24.0621 3168 [ 6B21EBF892CD8CACB71669B35AB5DE32 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
16:32:24.0621 3168 rdpbus - ok
16:32:24.0637 3168 [ 680C1DAE268B6FB67FA21B389A8B79EF ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
16:32:24.0637 3168 RDPDR - ok
16:32:24.0652 3168 [ 858776908AF838E3790F3261B799CDA6 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
16:32:24.0652 3168 RdpVideoMiniport - ok
16:32:24.0668 3168 [ 847C6A08912C3515807049C93E526D65 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
16:32:24.0684 3168 rdyboost - ok
16:32:24.0715 3168 [ 036746D54347FD2D0385668E2A4064E4 ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys
16:32:24.0715 3168 ReFS - ok
16:32:24.0746 3168 [ BFFB40FBE6D2C3469F8D06EE5E4934AB ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
16:32:24.0762 3168 RemoteAccess - ok
16:32:24.0777 3168 [ 4DCCABE03D06955ED61BABBD8EF9F30F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
16:32:24.0777 3168 RemoteRegistry - ok
16:32:24.0793 3168 [ 02307C86CB24769306B0DFA0C751952E ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys
16:32:24.0809 3168 RFCOMM - ok
16:32:24.0824 3168 [ D894CBD7DA753C881EE8D5E33B583225 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
16:32:24.0824 3168 RpcEptMapper - ok
16:32:24.0840 3168 [ 5CAE8F47B31D5CFC322B5B898C19E0FE ] RpcLocator C:\WINDOWS\system32\locator.exe
16:32:24.0840 3168 RpcLocator - ok
16:32:24.0871 3168 [ 3FD5AE42EC87C6F532A931F96BE731DD ] RpcSs C:\WINDOWS\system32\rpcss.dll
16:32:24.0871 3168 RpcSs - ok
16:32:24.0902 3168 [ 2D05A5508F4685412F2B89E8C2189ABC ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
16:32:24.0902 3168 rspndr - ok
16:32:24.0934 3168 [ E7B780F2E7A124264AA487C13107BDFF ] RSUSBVSTOR C:\WINDOWS\System32\Drivers\RtsUVStor.sys
16:32:24.0949 3168 RSUSBVSTOR - ok
16:32:25.0105 3168 [ 4733E843D221C608E1EC8FC4B18F0555 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
16:32:25.0137 3168 rtsuvc - ok
16:32:25.0168 3168 [ 1A063730F221B2746FF00457AE17E4F0 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
16:32:25.0168 3168 s3cap - ok
16:32:25.0199 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] SamSs C:\WINDOWS\system32\lsass.exe
16:32:25.0199 3168 SamSs - ok
16:32:25.0199 3168 [ C624A1B32211C3166EDB3F4AB02A30B7 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
16:32:25.0199 3168 sbp2port - ok
16:32:25.0215 3168 [ 47C497FA4DDEA908633CAA60CEBE6805 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
16:32:25.0230 3168 SCardSvr - ok
16:32:25.0230 3168 [ E76C4E98302AE39CC6FA5D20FC8B5438 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
16:32:25.0246 3168 ScDeviceEnum - ok
16:32:25.0246 3168 [ ABD0237B15DBD2B4695F4B7D734A58F7 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
16:32:25.0246 3168 scfilter - ok
16:32:25.0277 3168 [ 888A30EAB651502352C18745367FD179 ] Schedule C:\WINDOWS\system32\schedsvc.dll
16:32:25.0277 3168 Schedule - ok
16:32:25.0309 3168 [ AB285CE3431FF3D2ACE669245874C1C7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
16:32:25.0309 3168 SCPolicySvc - ok
16:32:25.0324 3168 [ 2F9A3380B8C0380E5608E29C7AA66899 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
16:32:25.0340 3168 sdbus - ok
16:32:25.0340 3168 [ 4EAF4DCF9DBD9A56952A58F56D61C005 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
16:32:25.0340 3168 sdstor - ok
16:32:25.0340 3168 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
16:32:25.0340 3168 secdrv - ok
16:32:25.0355 3168 [ C49009F897BA4F2F4F31043663AA1485 ] seclogon C:\WINDOWS\system32\seclogon.dll
16:32:25.0371 3168 seclogon - ok
16:32:25.0371 3168 [ A88882E64BDC1D8E8D6E727B71CCCC53 ] SENS C:\WINDOWS\System32\sens.dll
16:32:25.0371 3168 SENS - ok
16:32:25.0402 3168 [ E66A7C8CE7ED22DED6DF1CA479FB4790 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
16:32:25.0402 3168 SensrSvc - ok
16:32:25.0418 3168 [ DB2FF24CE0BDD15FE75870AFE312BA89 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
16:32:25.0418 3168 SerCx - ok
16:32:25.0449 3168 [ 0044B31F93946D5D41982314381FE431 ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
16:32:25.0449 3168 SerCx2 - ok
16:32:25.0449 3168 [ 3CD600C089C1251BEEB4CD4CD5164F9E ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
16:32:25.0449 3168 Serenum - ok
16:32:25.0465 3168 [ D864381BC9C725FAB01D94C060660166 ] Serial C:\WINDOWS\System32\drivers\serial.sys
16:32:25.0465 3168 Serial - ok
16:32:25.0465 3168 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
16:32:25.0465 3168 sermouse - ok
16:32:25.0480 3168 [ 441E6FF1F34D7A942946DB42A15FB519 ] SessionEnv C:\WINDOWS\system32\sessenv.dll
16:32:25.0496 3168 SessionEnv - ok
16:32:25.0496 3168 [ 472B7A5AC181C050888DB454663DD764 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
16:32:25.0496 3168 sfloppy - ok
16:32:25.0527 3168 [ F4414F57DF2CECB8FC969AA43A6B0D50 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
16:32:25.0543 3168 SharedAccess - ok
16:32:25.0574 3168 [ 0D190D8B4B20446BE6299AC734DFADF1 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
16:32:25.0574 3168 ShellHWDetection - ok
16:32:25.0574 3168 [ 2F518D13DD6F3053837FE606F1A2EA1F ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
16:32:25.0574 3168 SiSRaid2 - ok
16:32:25.0574 3168 [ 1AC9A200A9C49C4508F04AAFFCA34A3F ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
16:32:25.0574 3168 SiSRaid4 - ok
16:32:25.0590 3168 [ 587ACA15210D1B01FBF272E07A08F91A ] smphost C:\WINDOWS\System32\smphost.dll
16:32:25.0605 3168 smphost - ok
16:32:25.0637 3168 [ 49EEB92DE930B8566EF615D600781DB4 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
16:32:25.0637 3168 SNMPTRAP - ok
16:32:25.0668 3168 [ F6EBE514D13ECE7EDC23440039CDF9AB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
16:32:25.0668 3168 spaceport - ok
16:32:25.0668 3168 [ F337BE11071818FC3F5DC2940B6BDE34 ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
16:32:25.0668 3168 SpbCx - ok
16:32:25.0684 3168 [ FE0CB40F36D3FCDD3A1B312EF72C38D5 ] Spooler C:\WINDOWS\System32\spoolsv.exe
16:32:25.0699 3168 Spooler - ok
16:32:25.0809 3168 [ E6DEC72A2A23FAA53EB9FEC3C7E29D66 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
16:32:25.0840 3168 sppsvc - ok
16:32:25.0949 3168 [ 8BFD1752AAA15BF47D668E9AC5AF96FB ] SRTSP C:\WINDOWS\system32\drivers\NISx64\1501000.012\SRTSP64.SYS
16:32:25.0949 3168 SRTSP - ok
16:32:25.0949 3168 [ B18CE01B9C09C59422BA7C7064248B35 ] SRTSPX C:\WINDOWS\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS
16:32:25.0965 3168 SRTSPX - ok
16:32:25.0996 3168 [ 2B78788A1485F9B99A578A299DF42C02 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
16:32:25.0996 3168 srv - ok
16:32:26.0012 3168 [ C1AE59C0B0817236EC083A91C396005A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
16:32:26.0027 3168 srv2 - ok
16:32:26.0043 3168 [ 77195C32175FC63D6054EBA5A066D727 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
16:32:26.0043 3168 srvnet - ok
16:32:26.0074 3168 [ BB9ED3EDD8E85008215A7250D325A72E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
16:32:26.0090 3168 SSDPSRV - ok
16:32:26.0090 3168 [ 3911418AFDE10EA6823B7799E4815524 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
16:32:26.0106 3168 SstpSvc - ok
16:32:26.0121 3168 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
16:32:26.0121 3168 stexstor - ok
16:32:26.0199 3168 [ D638904FE86A5FE542A1BA13A9D68E5C ] stisvc C:\WINDOWS\System32\wiaservc.dll
16:32:26.0215 3168 stisvc - ok
16:32:26.0215 3168 [ 0ED2E318ABB68C1A35A8B8038BDB4C90 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
16:32:26.0215 3168 storahci - ok
16:32:26.0246 3168 [ 7A08CEE1535F5A448215634C5EA74E50 ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
16:32:26.0246 3168 storflt - ok
16:32:26.0262 3168 [ 6B06E2D11E604BE2B1A406C4CB3B90DE ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
16:32:26.0262 3168 stornvme - ok
16:32:26.0277 3168 [ 3118058E3D07021A55324A943C6D722B ] StorSvc C:\WINDOWS\system32\storsvc.dll
16:32:26.0277 3168 StorSvc - ok
16:32:26.0277 3168 [ 548759755BC73DAD663250239D7E0B9F ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
16:32:26.0277 3168 storvsc - ok
16:32:26.0293 3168 [ D8E1AE075AB3E8AD56F69C44AA978596 ] svsvc C:\WINDOWS\system32\svsvc.dll
16:32:26.0293 3168 svsvc - ok
16:32:26.0309 3168 [ 84E0F5D41C138C5CC975137A2A98F6D3 ] swenum C:\WINDOWS\System32\drivers\swenum.sys
16:32:26.0309 3168 swenum - ok
16:32:26.0324 3168 [ A5DC2E63F5E5D3C0B843307374998479 ] swprv C:\WINDOWS\System32\swprv.dll
16:32:26.0340 3168 swprv - ok
16:32:26.0402 3168 [ 5C9EE2303CA7F267665D75237862B39C ] SymDS C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMDS64.SYS
16:32:26.0402 3168 SymDS - ok
16:32:26.0481 3168 [ 08AF51153E441687130B759A8F6892ED ] SymEFA C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMEFA64.SYS
16:32:26.0496 3168 SymEFA - ok
16:32:26.0512 3168 [ 20F758E6339A16F97DD83389D582E09A ] SymELAM C:\WINDOWS\system32\drivers\NISx64\1501000.012\SymELAM.sys
16:32:26.0512 3168 SymELAM - ok
16:32:26.0527 3168 [ 97E11C50CE52277B377396EA8838E539 ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
16:32:26.0527 3168 SymEvent - ok
16:32:26.0559 3168 [ 48C2934683CBD06F662B088EEF49EF6A ] SymIRON C:\WINDOWS\system32\drivers\NISx64\1501000.012\Ironx64.SYS
16:32:26.0559 3168 SymIRON - ok
16:32:26.0606 3168 [ 78A2F073AD9EA5EBC04A70931EA36C9A ] SymNetS C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMNETS.SYS
16:32:26.0621 3168 SymNetS - ok
16:32:26.0652 3168 [ E45DA7CBBA34510C8B9473AD7D4FFD0B ] SysMain C:\WINDOWS\system32\sysmain.dll
16:32:26.0668 3168 SysMain - ok
16:32:26.0699 3168 [ D65B1C952AEB864C2BAC7A770B17ECCE ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
16:32:26.0715 3168 SystemEventsBroker - ok
16:32:26.0746 3168 [ BA6DD39266A5E15515C8C14DA2DA3E5C ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
16:32:26.0746 3168 TabletInputService - ok
16:32:26.0746 3168 [ B517410F157693043DACA21B19B258A6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
16:32:26.0762 3168 TapiSrv - ok
16:32:26.0824 3168 [ 3D9A5AC880D7AA2305812D665D24ED23 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
16:32:26.0840 3168 Tcpip - ok
16:32:26.0887 3168 [ 3D9A5AC880D7AA2305812D665D24ED23 ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:32:26.0902 3168 TCPIP6 - ok
16:32:26.0934 3168 [ 33A7D83EEB15431773A6E186CFAABA21 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
16:32:26.0934 3168 tcpipreg - ok
16:32:26.0965 3168 [ FFF28F9F6823EB1756C60F1649560BBF ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
16:32:26.0965 3168 tdx - ok
16:32:26.0981 3168 [ 232D185D2337F141311D0CF1983E1431 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
16:32:26.0981 3168 terminpt - ok
16:32:26.0996 3168 [ 2C77831737491F4D684D315B95C62883 ] TermService C:\WINDOWS\System32\termsrv.dll
16:32:27.0043 3168 TermService - ok
16:32:27.0059 3168 [ 05FBE1F7C13E87AF7A414CDF288B1F62 ] Themes C:\WINDOWS\system32\themeservice.dll
16:32:27.0059 3168 Themes - ok
16:32:27.0090 3168 [ FD788C2D96EA91469A3C1D13E80D7473 ] THREADORDER C:\WINDOWS\system32\mmcss.dll
16:32:27.0090 3168 THREADORDER - ok
16:32:27.0121 3168 [ 347A3E49CE18402305B8119A6EC7CFEB ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
16:32:27.0121 3168 TimeBroker - ok
16:32:27.0137 3168 [ 82F909359600D3603FE852DB7F135626 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
16:32:27.0152 3168 TPM - ok
16:32:27.0168 3168 [ C97E14BB6A196B0554D6EB67D8818175 ] TrkWks C:\WINDOWS\System32\trkwks.dll
16:32:27.0168 3168 TrkWks - ok
16:32:27.0215 3168 [ DA56FFA46030E6FEB215E3D5DAA65B11 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
16:32:27.0215 3168 TrustedInstaller - ok
16:32:27.0231 3168 [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
16:32:27.0231 3168 TsUsbFlt - ok
16:32:27.0246 3168 [ E0088068DCE2EE82897027DDB8E05254 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
16:32:27.0246 3168 TsUsbGD - ok
16:32:27.0262 3168 [ C8E0E78B5D284C2FF59BDFFDAF997242 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
16:32:27.0277 3168 tunnel - ok
16:32:27.0277 3168 [ F6EEAD052943B5A3104C1405BB856C54 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
16:32:27.0277 3168 uagp35 - ok
16:32:27.0293 3168 [ FE6067B1FD4E63650C667B33D080565B ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
16:32:27.0293 3168 UASPStor - ok
16:32:27.0293 3168 [ 5D1B430EA11064C56E7C8F84B90DEB6A ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
16:32:27.0309 3168 UCX01000 - ok
16:32:27.0309 3168 [ 1EC649F112896FAE33250F0B97AC5D0B ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
16:32:27.0309 3168 udfs - ok
16:32:27.0324 3168 [ 9578691F297E1B1F519970FE6D47CB21 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
16:32:27.0324 3168 UEFI - ok
16:32:27.0356 3168 [ 320878AFECDBBD61BBE98624A6CAAC08 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
16:32:27.0356 3168 UI0Detect - ok
16:32:27.0356 3168 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
16:32:27.0356 3168 uliagpkx - ok
16:32:27.0371 3168 [ DA34C39A18E60E7C3FA0630566408034 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
16:32:27.0371 3168 umbus - ok
16:32:27.0418 3168 [ AE8294875E5446E359B1E8035D40C05E ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
16:32:27.0418 3168 UmPass - ok
16:32:27.0449 3168 [ E3DDF7D43E05784FAA5E042605EEE528 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
16:32:27.0481 3168 UmRdpService - ok
16:32:27.0606 3168 [ 1E9A5658E0EBDBC381F52123363F74CB ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
16:32:27.0606 3168 UNS - ok
16:32:27.0621 3168 [ 4A2FFDAC45F317E17DF642C7160EB633 ] upnphost C:\WINDOWS\System32\upnphost.dll
16:32:27.0637 3168 upnphost - ok
16:32:27.0652 3168 [ 433ECDE01A52691FA7ACA51C10C09B70 ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
16:32:27.0652 3168 usbccgp - ok
16:32:27.0668 3168 [ B3D6457D841A0CAEF4C52D88621715F2 ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
16:32:27.0668 3168 usbcir - ok
16:32:27.0699 3168 [ 5477D6E27C7D266EF8C152B9A25ADE5E ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
16:32:27.0699 3168 usbehci - ok
16:32:27.0715 3168 [ DF56C2C04EFA328D7A66B69007130266 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
16:32:27.0731 3168 usbhub - ok
16:32:27.0746 3168 [ C0E33820326199CE3CFD3B9F27F81D99 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
16:32:27.0746 3168 USBHUB3 - ok
16:32:27.0762 3168 [ 3019097FB6C985EF24C058090FF3BDBD ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
16:32:27.0762 3168 usbohci - ok
16:32:27.0793 3168 [ 4D655E3B684BE9B0F7FFD8A2935C348C ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
16:32:27.0793 3168 usbprint - ok
16:32:27.0809 3168 [ 4628B415A84EA9D4D396A56F1D0CB6C6 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
16:32:27.0824 3168 USBSTOR - ok
16:32:27.0824 3168 [ BA4FA655E0FC577DB7436FC963932CE4 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
16:32:27.0824 3168 usbuhci - ok
16:32:27.0840 3168 [ 3B44CB989757428208CCFCC028C13110 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
16:32:27.0856 3168 USBXHCI - ok
16:32:27.0871 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] VaultSvc C:\WINDOWS\system32\lsass.exe
16:32:27.0871 3168 VaultSvc - ok
16:32:27.0871 3168 [ FEB26E3B8345A7E8D62F945C4AE86562 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
16:32:27.0871 3168 vdrvroot - ok
16:32:28.0012 3168 [ CFBAD6B48EDFAA0828A52646B7C4C08D ] vds C:\WINDOWS\System32\vds.exe
16:32:28.0027 3168 vds - ok
16:32:28.0074 3168 [ F7579733F4E8FF9B534C3F7D38F25C2C ] VeriFaceSrv C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
16:32:28.0074 3168 VeriFaceSrv - ok
16:32:28.0090 3168 [ A026EDEAA5EECAE0B08E2748B616D4BD ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
16:32:28.0090 3168 VerifierExt - ok
16:32:28.0121 3168 [ 041D3EF364E624DBB2703A64A5AADF89 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
16:32:28.0137 3168 vhdmp - ok
16:32:28.0137 3168 [ 06D38968028E9AB19DE9B618C7B6D199 ] viaide C:\WINDOWS\system32\drivers\viaide.sys
16:32:28.0137 3168 viaide - ok
16:32:28.0152 3168 [ C6305BDFC4F7CE51F72BB072C03D4ACE ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
16:32:28.0152 3168 vmbus - ok
16:32:28.0152 3168 [ DA40BEA0A863CE768C940CA9723BF81F ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
16:32:28.0152 3168 VMBusHID - ok
16:32:28.0184 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
16:32:28.0184 3168 vmicguestinterface - ok
16:32:28.0199 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll
16:32:28.0199 3168 vmicheartbeat - ok
16:32:28.0215 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
16:32:28.0231 3168 vmickvpexchange - ok
16:32:28.0231 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicrdv C:\WINDOWS\System32\ICSvc.dll
16:32:28.0231 3168 vmicrdv - ok
16:32:28.0246 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll
16:32:28.0246 3168 vmicshutdown - ok
16:32:28.0246 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmictimesync C:\WINDOWS\System32\ICSvc.dll
16:32:28.0262 3168 vmictimesync - ok
16:32:28.0262 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicvss C:\WINDOWS\System32\ICSvc.dll
16:32:28.0262 3168 vmicvss - ok
16:32:28.0293 3168 [ 55D7D963DE85162F1C49721E502F9744 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
16:32:28.0293 3168 volmgr - ok
16:32:28.0293 3168 [ CCB9E901F7254BF96D28EB1B0E5329B7 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
16:32:28.0293 3168 volmgrx - ok
16:32:28.0309 3168 [ 9F9CE33B50611A1C61A46B8911E0B30B ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
16:32:28.0309 3168 volsnap - ok
16:32:28.0324 3168 [ 01355C98B5C3ED1EC446743CDA848FCE ] vpci C:\WINDOWS\System32\drivers\vpci.sys
16:32:28.0324 3168 vpci - ok
16:32:28.0340 3168 [ 4539F45F9F4C9757A86A56C949421E07 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
16:32:28.0340 3168 vsmraid - ok
16:32:28.0387 3168 [ D51D7EF1EA5ED2BB01E9D07E6E0533BC ] VSS C:\WINDOWS\system32\vssvc.exe
16:32:28.0387 3168 VSS - ok
16:32:28.0402 3168 [ 0849B7260F26FE05EA56DED0672E2F4B ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
16:32:28.0402 3168 VSTXRAID - ok
16:32:28.0402 3168 [ BE970C369E43B509C1EDA2B8FA7CECB0 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
16:32:28.0402 3168 vwifibus - ok
16:32:28.0434 3168 [ 6B26AD573CCDD5209DF4397438B76354 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys
16:32:28.0434 3168 vwififlt - ok
16:32:28.0434 3168 [ 0B48E0DFB44EE475F4FD8A8EE599AF30 ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys
16:32:28.0434 3168 vwifimp - ok
16:32:28.0465 3168 [ 7599E582CA3A6AAA95A18FFE1172D339 ] W32Time C:\WINDOWS\system32\w32time.dll
16:32:28.0465 3168 W32Time - ok
16:32:28.0481 3168 [ 0910AB9ED404C1434E2D0376C2AD5D8B ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
16:32:28.0481 3168 WacomPen - ok
16:32:28.0512 3168 [ 92BF4B3EBD6F163B94B7A20C65E7B698 ] wbengine C:\WINDOWS\system32\wbengine.exe
16:32:28.0528 3168 wbengine - ok
16:32:28.0559 3168 [ 58F28103889817C93E5B5AFABC87E709 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
16:32:28.0559 3168 WbioSrvc - ok
16:32:28.0606 3168 [ 772365894F14652D376B2E5030179DC9 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
16:32:28.0606 3168 Wcmsvc - ok
16:32:28.0637 3168 [ D2726823DF7E19F213F4805A9D6D145F ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
16:32:28.0637 3168 wcncsvc - ok
16:32:28.0653 3168 [ 846C02A8B48CBD921A3D6AB521AA0DC4 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
16:32:28.0668 3168 WcsPlugInService - ok
16:32:28.0684 3168 [ 694B28DE12AD47031FFB4B052662131A ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
16:32:28.0684 3168 WdBoot - ok
16:32:28.0715 3168 [ CB6C63FF8342B467E2EF76E98D5B934D ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
16:32:28.0715 3168 Wdf01000 - ok
16:32:28.0762 3168 [ 0B99529A3BECC3528D865DDECB62503B ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
16:32:28.0762 3168 WdFilter - ok
16:32:28.0778 3168 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
16:32:28.0778 3168 WdiServiceHost - ok
16:32:28.0778 3168 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
16:32:28.0778 3168 WdiSystemHost - ok
16:32:28.0809 3168 [ 282E7D46310338FF4A6B7680440EB0DA ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
16:32:28.0809 3168 WdNisDrv - ok
16:32:28.0840 3168 WdNisSvc - ok
16:32:28.0856 3168 [ 6588A957873326361AB1CAC4E76F8394 ] WebClient C:\WINDOWS\System32\webclnt.dll
16:32:28.0871 3168 WebClient - ok
16:32:28.0887 3168 [ 3274312F263882B51B964329FAF49734 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
16:32:28.0903 3168 Wecsvc - ok
16:32:28.0903 3168 [ 7CDD84E0023A0C5C230B06A7965EC65E ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
16:32:28.0918 3168 WEPHOSTSVC - ok
16:32:28.0934 3168 [ AA1315B87D9B2E39584165318A59F15D ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
16:32:28.0934 3168 wercplsupport - ok
16:32:28.0934 3168 [ 22B4C24AB921BFF7827FFBCA1F4E1BB3 ] WerSvc C:\WINDOWS\System32\WerSvc.dll
16:32:28.0934 3168 WerSvc - ok
16:32:28.0949 3168 [ 2E3E82D7B1076B90F4E228A8EF17B261 ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
16:32:28.0949 3168 WFPLWFS - ok
16:32:28.0965 3168 [ E06AFE2F94BA7CFA2FE4FD2A449E60E2 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
16:32:28.0965 3168 WiaRpc - ok
16:32:28.0981 3168 [ 867BCC69ED9C31C501465EB0E8BA9DFA ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
16:32:28.0981 3168 WIMMount - ok
16:32:28.0981 3168 WinDefend - ok
16:32:28.0996 3168 [ DD079EC8F44DCA3A176B345C6ADEFB66 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
16:32:29.0012 3168 WinHttpAutoProxySvc - ok
16:32:29.0028 3168 [ 9DB490F3E823C5C3C070644B96CB9D59 ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
16:32:29.0028 3168 Winmgmt - ok
16:32:29.0090 3168 [ 690C3FC5C9DBD6B9AEDF8341EC720E41 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
16:32:29.0153 3168 WinRM - ok
16:32:29.0168 3168 [ AC263C2F66405589528995AA41040599 ] WinUsb C:\WINDOWS\system32\DRIVERS\WinUsb.sys
16:32:29.0168 3168 WinUsb - ok
16:32:29.0231 3168 [ 728D3349FAB251B0265EFA55C67DCA2D ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
16:32:29.0246 3168 WlanSvc - ok
16:32:29.0293 3168 [ C2838466CCC44FAEF2C3D4C1E5971ECB ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
16:32:29.0309 3168 wlidsvc - ok
16:32:29.0324 3168 [ 2834D9D3B4F554A39C72F00EA3F0E128 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
16:32:29.0324 3168 WmiAcpi - ok
16:32:29.0356 3168 [ 7AFAC828F52D62F304A911EC32F42EEE ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
16:32:29.0356 3168 wmiApSrv - ok
16:32:29.0356 3168 WMPNetworkSvc - ok
16:32:29.0403 3168 [ E178371E493BF17EB90FE71ABA8BE643 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
16:32:29.0418 3168 workfolderssvc - ok
16:32:29.0434 3168 [ E746BCDBA2E02CF6B8D6B26FB167FBE0 ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
16:32:29.0434 3168 wpcfltr - ok
16:32:29.0449 3168 [ 4E6A0F60DA7EF050D3D26417CD4D24E9 ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll
16:32:29.0449 3168 WPCSvc - ok
16:32:29.0465 3168 [ D27491CFCE452C154CECFA155AD0EBC8 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
16:32:29.0465 3168 WPDBusEnum - ok
16:32:29.0481 3168 [ 9F2904B55F6CECCD1A8D986B5CE2609A ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
16:32:29.0481 3168 WpdUpFltr - ok
16:32:29.0496 3168 [ AE072B0339D0A18E455DC21666CAD572 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
16:32:29.0496 3168 ws2ifsl - ok
16:32:29.0528 3168 [ 5CFA46C4ACB2FD70572017052378DAE5 ] wscsvc C:\WINDOWS\System32\wscsvc.dll
16:32:29.0528 3168 wscsvc - ok
16:32:29.0543 3168 WSearch - ok
16:32:29.0637 3168 [ D8E3A4701376CCFD0BE542D745FA4809 ] WSService C:\WINDOWS\System32\WSService.dll
16:32:29.0653 3168 WSService - ok
16:32:29.0684 3168 [ 72B4E9DF6456C43C42A1419B09486045 ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
16:32:29.0684 3168 wsvd - ok
16:32:29.0746 3168 [ 86D0BF4F792053A50D6EE43DFA5837A5 ] wuauserv C:\WINDOWS\system32\wuaueng.dll
16:32:29.0778 3168 wuauserv - ok
16:32:29.0793 3168 [ 2FEAE33E9B2B56104596E1BA444405A9 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
16:32:29.0793 3168 WudfPf - ok
16:32:29.0809 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
16:32:29.0809 3168 WUDFRd - ok
16:32:29.0825 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFSensorLP C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
16:32:29.0825 3168 WUDFSensorLP - ok
16:32:29.0825 3168 [ BB73CBC65AABC4EA0A5C6A1474A0A743 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
16:32:29.0825 3168 wudfsvc - ok
16:32:29.0840 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFWpdMtp C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
16:32:29.0840 3168 WUDFWpdMtp - ok
16:32:29.0856 3168 [ 2FA9794CA36147756F3FDFD6CA29B46F ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
16:32:29.0871 3168 WwanSvc - ok
16:32:29.0903 3168 [ 86B8B1F5C1189D68B07666784BE882FE ] ZAtheros Bt and Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
16:32:29.0903 3168 ZAtheros Bt and Wlan Coex Agent - ok
16:32:29.0918 3168 ================ Scan global ===============================
16:32:29.0950 3168 [ C89780A6F58D113C28A96D85D1261DC5 ] C:\WINDOWS\system32\basesrv.dll
16:32:29.0981 3168 [ 599F1244C60E3D6C28A8DA7FBA7A2C13 ] C:\WINDOWS\system32\winsrv.dll
16:32:29.0996 3168 [ 9C1833ABD62876856836C5AE55C7CE86 ] C:\WINDOWS\system32\sxssrv.dll
16:32:30.0090 3168 [ B4B610BBCB002EC478C6FD80CF915697 ] C:\WINDOWS\system32\services.exe
16:32:30.0090 3168 [Global] - ok
16:32:30.0090 3168 ================ Scan MBR ==================================
16:32:30.0106 3168 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
16:32:30.0121 3168 \Device\Harddisk0\DR0 - ok
16:32:30.0121 3168 ================ Scan VBR ==================================
16:32:30.0121 3168 [ 564233D5182AE6F663AE432F0571B61E ] \Device\Harddisk0\DR0\Partition1
16:32:30.0121 3168 \Device\Harddisk0\DR0\Partition1 - ok
16:32:30.0137 3168 [ 414F0F65AD0C871F7C724204A77B2C17 ] \Device\Harddisk0\DR0\Partition2
16:32:30.0137 3168 \Device\Harddisk0\DR0\Partition2 - ok
16:32:30.0153 3168 [ EB0DF7FB23D6D22E10F054E0FB5E003A ] \Device\Harddisk0\DR0\Partition3
16:32:30.0168 3168 \Device\Harddisk0\DR0\Partition3 - ok
16:32:30.0168 3168 [ 0E20DB2A5F00AE784F89D72EBA659C2F ] \Device\Harddisk0\DR0\Partition4
16:32:30.0168 3168 \Device\Harddisk0\DR0\Partition4 - ok
16:32:30.0184 3168 [ 54B62297428F339212560A25A7499830 ] \Device\Harddisk0\DR0\Partition5
16:32:30.0184 3168 \Device\Harddisk0\DR0\Partition5 - ok
16:32:30.0184 3168 [ 7952E93AC6BF3FBF23A7B3DD78954351 ] \Device\Harddisk0\DR0\Partition6
16:32:30.0184 3168 \Device\Harddisk0\DR0\Partition6 - ok
16:32:30.0184 3168 [ 49C6E2D658C1BD80C846671C86651369 ] \Device\Harddisk0\DR0\Partition7
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition7 - ok
16:32:30.0200 3168 [ 8BC430BEF14630750F2FEF42E69BFBF3 ] \Device\Harddisk0\DR0\Partition8
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition8 - ok
16:32:30.0200 3168 [ B7898B01A1CC24AB2442799C6B9A1309 ] \Device\Harddisk0\DR0\Partition9
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition9 - ok
16:32:30.0200 3168 ============================================================
16:32:30.0200 3168 Scan finished
16:32:30.0200 3168 ============================================================
16:32:30.0215 0672 Detected object count: 0
16:32:30.0215 0672 Actual detected object count: 0
16:32:41.0747 4020 Deinitialize success
16:32:20.0636 3168 [ F6F13533196DE7A582D422B0241E4363 ] megasr C:\WINDOWS\system32\drivers\megasr.sys
16:32:20.0652 3168 megasr - ok
16:32:20.0683 3168 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
16:32:20.0683 3168 MEIx64 - ok
16:32:20.0715 3168 [ FD788C2D96EA91469A3C1D13E80D7473 ] MMCSS C:\WINDOWS\system32\mmcss.dll
16:32:20.0715 3168 MMCSS - ok
16:32:20.0730 3168 [ 8B38C44F69259987C95135C9627E2378 ] Modem C:\WINDOWS\system32\drivers\modem.sys
16:32:20.0730 3168 Modem - ok
16:32:20.0761 3168 [ 601589000CC90F0DF8DA2CC254A3CCC9 ] monitor C:\WINDOWS\System32\drivers\monitor.sys
16:32:20.0761 3168 monitor - ok
16:32:20.0761 3168 [ CEAC6D40FE887CE8406C2393CF97DE06 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys
16:32:20.0761 3168 mouclass - ok
16:32:20.0777 3168 [ 02D98BF804084E9A0D69D1C69B02CCA9 ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys
16:32:20.0793 3168 mouhid - ok
16:32:20.0793 3168 [ 515549560D481138E6E21AF7C6998E56 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys
16:32:20.0793 3168 mountmgr - ok
16:32:20.0808 3168 [ F170510BE94CF45E3C6274578F6204B2 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys
16:32:20.0808 3168 mpsdrv - ok
16:32:20.0824 3168 [ D186C5844393252147BE934F3871DB7A ] MpsSvc C:\WINDOWS\system32\mpssvc.dll
16:32:20.0840 3168 MpsSvc - ok
16:32:20.0855 3168 [ 59DCEC7499095DE5AED741358037AE2D ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
16:32:20.0871 3168 MRxDAV - ok
16:32:20.0886 3168 [ 79B6F3DF7CDFD12159871FF71464F0CE ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:32:20.0886 3168 mrxsmb - ok
16:32:20.0902 3168 [ 295771B092D4F7FCF2B62F80CCD14320 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
16:32:20.0918 3168 mrxsmb10 - ok
16:32:20.0918 3168 [ AAF56E4E84D35411B4E446C445732DFE ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
16:32:20.0918 3168 mrxsmb20 - ok
16:32:20.0933 3168 [ 4E888019078AC363076A5433E89AA4F8 ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys
16:32:20.0933 3168 MsBridge - ok
16:32:20.0965 3168 [ A082C17D14D0790E27D064EA4B138AE1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
16:32:20.0965 3168 MSDTC - ok
16:32:20.0996 3168 [ D13329FBF8345B28AB30F44CC247DC08 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
16:32:20.0996 3168 Msfs - ok
16:32:21.0011 3168 [ C6B474E46F9E543B875981ED3FFE6ADD ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
16:32:21.0011 3168 msgpiowin32 - ok
16:32:21.0027 3168 [ 65C92EB9D08DB5C69F28C7FFD4E84E31 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys
16:32:21.0027 3168 mshidkmdf - ok
16:32:21.0043 3168 [ 52299F086AC2DAFD100DD5DC4A8614BA ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
16:32:21.0043 3168 mshidumdf - ok
16:32:21.0043 3168 [ 36D92AF3343C3A3E57FEF11C449AEA4C ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys
16:32:21.0043 3168 msisadrv - ok
16:32:21.0058 3168 [ 810F8A0A0680662BB0CE44D0E2CEF90C ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll
16:32:21.0058 3168 MSiSCSI - ok
16:32:21.0074 3168 msiserver - ok
16:32:21.0090 3168 [ A9BBBD2BAE6142253B9195E949AC2E8D ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:32:21.0090 3168 MSKSSRV - ok
16:32:21.0105 3168 [ 375E44168F2DFB91A68B8A3F619C5A7C ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys
16:32:21.0105 3168 MsLldp - ok
16:32:21.0121 3168 [ 7B2128EB875DCBC006E6A913211006D6 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:32:21.0121 3168 MSPCLOCK - ok
16:32:21.0136 3168 [ 1E88171579B218115C7A772F8DE04BD8 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
16:32:21.0136 3168 MSPQM - ok
16:32:21.0152 3168 [ BBE2A455053E63BECBF42C2F9B21FAE0 ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys
16:32:21.0152 3168 MsRPC - ok
16:32:21.0168 3168 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys
16:32:21.0168 3168 mssmbios - ok
16:32:21.0183 3168 [ 115019AE01E0EB9C048530D2928AB4A2 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
16:32:21.0183 3168 MSTEE - ok
16:32:21.0199 3168 [ 96D604A35070360F0DD4A7A8AF410B5E ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
16:32:21.0199 3168 MTConfig - ok
16:32:21.0215 3168 [ 619CA29326B82372621DB2C0964D8365 ] Mup C:\WINDOWS\system32\Drivers\mup.sys
16:32:21.0215 3168 Mup - ok
16:32:21.0230 3168 [ B8C35C94DCB2DFEAF03BB42131F2F77F ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
16:32:21.0230 3168 mvumis - ok
16:32:21.0261 3168 [ 41A45D2A75494EABF2806EA051E00376 ] napagent C:\WINDOWS\system32\qagentRT.dll
16:32:21.0261 3168 napagent - ok
16:32:21.0293 3168 [ CF8B989D89D6807B887690F2CF24EFD9 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
16:32:21.0293 3168 NativeWifiP - ok
16:32:21.0340 3168 [ 702E07EC32F96ACDB873E9A5465D4401 ] NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140223.018\ENG64.SYS
16:32:21.0340 3168 NAVENG - ok
16:32:21.0386 3168 [ 302EA314A1AF0D7CEF0A3D0195F79561 ] NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140223.018\EX64.SYS
16:32:21.0418 3168 NAVEX15 - ok
16:32:21.0433 3168 [ 71E3C0100AA19D11373CCEB2F51A6008 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
16:32:21.0449 3168 NcaSvc - ok
16:32:21.0449 3168 [ 51DF09CAB2CAC64FEE3E371D9028ED01 ] NcbService C:\WINDOWS\System32\ncbservice.dll
16:32:21.0465 3168 NcbService - ok
16:32:21.0465 3168 [ 2586C4C167499210DCBF3ECFD8CCE210 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
16:32:21.0480 3168 NcdAutoSetup - ok
16:32:21.0512 3168 [ ED39D676080A1AEA755F1DEC1A8DF1A4 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
16:32:21.0512 3168 NDIS - ok
16:32:21.0527 3168 [ C6BB12BC35D1637CA17AE16D3A4725EB ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
16:32:21.0527 3168 NdisCap - ok
16:32:21.0527 3168 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
16:32:21.0527 3168 NdisImPlatform - ok
16:32:21.0527 3168 [ 9423421E735BD5394351E0C47C76BB92 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:32:21.0527 3168 NdisTapi - ok
16:32:21.0543 3168 [ B832B35055BA2B7B4181861FF94D8E59 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:32:21.0543 3168 Ndisuio - ok
16:32:21.0558 3168 [ 1F58E48EF75F34C35D8E93A0DC535CFE ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
16:32:21.0558 3168 NdisVirtualBus - ok
16:32:21.0574 3168 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:32:21.0574 3168 NdisWan - ok
16:32:21.0574 3168 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWanLegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:32:21.0574 3168 NdisWanLegacy - ok
16:32:21.0590 3168 [ A5BD69A8812FA79D1A487691DD3FB244 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
16:32:21.0590 3168 NDProxy - ok
16:32:21.0605 3168 [ 5A072F0B90C29C5233D78BE33EF5ED78 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
16:32:21.0605 3168 Ndu - ok
16:32:21.0621 3168 [ A83D67D347A684F10B7D3019C8A6380C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
16:32:21.0621 3168 NetBIOS - ok
16:32:21.0637 3168 [ 0217532E19A748F0E5D569307363D5FD ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
16:32:21.0637 3168 NetBT - ok
16:32:21.0652 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] Netlogon C:\WINDOWS\system32\lsass.exe
16:32:21.0652 3168 Netlogon - ok
16:32:21.0683 3168 [ B7AD851A21FEBA3BA214972627614207 ] Netman C:\WINDOWS\System32\netman.dll
16:32:21.0699 3168 Netman - ok
16:32:21.0715 3168 [ F0F0A372C2EF6358399C4936F91B6131 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
16:32:21.0715 3168 netprofm - ok
16:32:21.0746 3168 [ 1092B3190E69E0C5ECBCE90F171DE047 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:32:21.0746 3168 NetTcpPortSharing - ok
16:32:21.0762 3168 [ 70414DB660BFBB7BD58FCE8EA4364E1B ] netvsc C:\WINDOWS\system32\DRIVERS\netvsc63.sys
16:32:21.0762 3168 netvsc - ok
16:32:21.0871 3168 [ C87442B6D17912785DC143CEDCA508C9 ] NIS C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
16:32:21.0871 3168 NIS - ok
16:32:21.0902 3168 [ 3A280F3B3C7A46E29C404ACD46ECBF5E ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
16:32:21.0902 3168 NlaSvc - ok
16:32:21.0918 3168 [ 8F44A2F57C9F1A19AC9C6288C10FB351 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
16:32:21.0918 3168 Npfs - ok
16:32:21.0949 3168 [ CBDB4F0871C88DF930FC0E8588CA67FC ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
16:32:21.0949 3168 npsvctrig - ok
16:32:21.0949 3168 [ 6E2271ED0C3E95B8E29F3752B91B9E84 ] nsi C:\WINDOWS\system32\nsisvc.dll
16:32:21.0949 3168 nsi - ok
16:32:21.0965 3168 [ E490B459978CB87779E84C761D22B827 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
16:32:21.0965 3168 nsiproxy - ok
16:32:22.0012 3168 [ 4412D565C0278C401575E11072C7DCE3 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
16:32:22.0027 3168 Ntfs - ok
16:32:22.0043 3168 [ EF1B290FC9F0E47CC0B537292BEE5904 ] Null C:\WINDOWS\system32\drivers\Null.sys
16:32:22.0043 3168 Null - ok
16:32:22.0058 3168 [ BC6B5942AFF25EBAF62DE43C3807EDF8 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
16:32:22.0058 3168 nvraid - ok
16:32:22.0090 3168 [ 1F43ABFFAC3D6CA356851D517392966E ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
16:32:22.0090 3168 nvstor - ok
16:32:22.0105 3168 [ 6934A936A7369DFE37B7DBA93F5E5E49 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
16:32:22.0105 3168 nv_agp - ok
16:32:22.0137 3168 [ 3B510F20806B94E389784ED09DBD2111 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
16:32:22.0152 3168 p2pimsvc - ok
16:32:22.0183 3168 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B ] p2psvc C:\WINDOWS\system32\p2psvc.dll
16:32:22.0183 3168 p2psvc - ok
16:32:22.0215 3168 [ 764B1121867B2D9B31C491668AC72B2B ] Parport C:\WINDOWS\System32\drivers\parport.sys
16:32:22.0215 3168 Parport - ok
16:32:22.0230 3168 [ EF0C1749C9A8CEE9A457473D433CC00F ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
16:32:22.0230 3168 partmgr - ok
16:32:22.0246 3168 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
16:32:22.0262 3168 PcaSvc - ok
16:32:22.0277 3168 [ C0D3F3BC1C84B4BA746D9847314C1164 ] pci C:\WINDOWS\system32\drivers\pci.sys
16:32:22.0277 3168 pci - ok
16:32:22.0293 3168 [ 346E38FCC6859A727DD28AFAD1F0AFF4 ] pciide C:\WINDOWS\system32\drivers\pciide.sys
16:32:22.0293 3168 pciide - ok
16:32:22.0308 3168 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
16:32:22.0308 3168 pcmcia - ok
16:32:22.0308 3168 [ BF28771D1436C88BE1D297D3098B0F7D ] pcw C:\WINDOWS\system32\drivers\pcw.sys
16:32:22.0308 3168 pcw - ok
16:32:22.0324 3168 [ B9D968D8E2B0F9C6301CEB39CFC9B9E4 ] pdc C:\WINDOWS\system32\drivers\pdc.sys
16:32:22.0324 3168 pdc - ok
16:32:22.0340 3168 [ BA50CC0BD19004AAB88BE37338B6FA0D ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
16:32:22.0340 3168 PEAUTH - ok
16:32:24.0074 3168 [ 8E3C640FFF5A963F570233AE99C0FFF3 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
16:32:24.0074 3168 PerfHost - ok
16:32:24.0137 3168 [ 928061178CD9856CA6B67FFFCE6BA766 ] pla C:\WINDOWS\system32\pla.dll
16:32:24.0152 3168 pla - ok
16:32:24.0168 3168 [ 752A457320A946E03C3AA86C3ACD735E ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
16:32:24.0184 3168 PlugPlay - ok
16:32:24.0184 3168 [ 045EB4F260606A03BE340D09DEAF3BA4 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
16:32:24.0199 3168 PNRPAutoReg - ok
16:32:24.0215 3168 [ 3B510F20806B94E389784ED09DBD2111 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
16:32:24.0215 3168 PNRPsvc - ok
16:32:24.0230 3168 [ C16097D77A232A288D65F299E2E01105 ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
16:32:24.0230 3168 PolicyAgent - ok
16:32:24.0246 3168 [ 00E08B30E7F7C13ECE2CDF4F46A77311 ] Power C:\WINDOWS\system32\umpo.dll
16:32:24.0246 3168 Power - ok
16:32:24.0324 3168 [ B7DB57A000D46D4DE75BC0C563E58072 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
16:32:24.0355 3168 PrintNotify - ok
16:32:24.0371 3168 [ ECD373F9571C745894367CC2635EA44F ] Processor C:\WINDOWS\System32\drivers\processr.sys
16:32:24.0371 3168 Processor - ok
16:32:24.0387 3168 [ 8513A1E7AE4B9DC82C4B4F432C648A58 ] ProfSvc C:\WINDOWS\system32\profsvc.dll
16:32:24.0387 3168 ProfSvc - ok
16:32:24.0402 3168 [ 8528BB05E4D4E25945F78B00B2555FB7 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
16:32:24.0402 3168 Psched - ok
16:32:24.0449 3168 [ AF90BB44C99D6820BE52C9BBAA523283 ] QWAVE C:\WINDOWS\system32\qwave.dll
16:32:24.0449 3168 QWAVE - ok
16:32:24.0465 3168 [ 3FB466684609A4329858CF2EBD62E0FD ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
16:32:24.0465 3168 QWAVEdrv - ok
16:32:24.0480 3168 [ 2C56F0EE27E4EF70CA4B4983D3638905 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:32:24.0480 3168 RasAcd - ok
16:32:24.0496 3168 [ 5F061AC45266841A2860C1858ED863B8 ] RasAuto C:\WINDOWS\System32\rasauto.dll
16:32:24.0496 3168 RasAuto - ok
16:32:24.0512 3168 [ BF3B17016764F20F9D28CF1A8DC210C0 ] RasMan C:\WINDOWS\System32\rasmans.dll
16:32:24.0527 3168 RasMan - ok
16:32:24.0543 3168 [ 5247F308C4103CDC4FE12AE1D235800A ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:32:24.0543 3168 RasPppoe - ok
16:32:24.0590 3168 [ B939A2A0F9D6C6C186721E268EB6FA93 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:32:24.0605 3168 rdbss - ok
16:32:24.0621 3168 [ 6B21EBF892CD8CACB71669B35AB5DE32 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
16:32:24.0621 3168 rdpbus - ok
16:32:24.0637 3168 [ 680C1DAE268B6FB67FA21B389A8B79EF ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
16:32:24.0637 3168 RDPDR - ok
16:32:24.0652 3168 [ 858776908AF838E3790F3261B799CDA6 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
16:32:24.0652 3168 RdpVideoMiniport - ok
16:32:24.0668 3168 [ 847C6A08912C3515807049C93E526D65 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
16:32:24.0684 3168 rdyboost - ok
16:32:24.0715 3168 [ 036746D54347FD2D0385668E2A4064E4 ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys
16:32:24.0715 3168 ReFS - ok
16:32:24.0746 3168 [ BFFB40FBE6D2C3469F8D06EE5E4934AB ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
16:32:24.0762 3168 RemoteAccess - ok
16:32:24.0777 3168 [ 4DCCABE03D06955ED61BABBD8EF9F30F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
16:32:24.0777 3168 RemoteRegistry - ok
16:32:24.0793 3168 [ 02307C86CB24769306B0DFA0C751952E ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys
16:32:24.0809 3168 RFCOMM - ok
16:32:24.0824 3168 [ D894CBD7DA753C881EE8D5E33B583225 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
16:32:24.0824 3168 RpcEptMapper - ok
16:32:24.0840 3168 [ 5CAE8F47B31D5CFC322B5B898C19E0FE ] RpcLocator C:\WINDOWS\system32\locator.exe
16:32:24.0840 3168 RpcLocator - ok
16:32:24.0871 3168 [ 3FD5AE42EC87C6F532A931F96BE731DD ] RpcSs C:\WINDOWS\system32\rpcss.dll
16:32:24.0871 3168 RpcSs - ok
16:32:24.0902 3168 [ 2D05A5508F4685412F2B89E8C2189ABC ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
16:32:24.0902 3168 rspndr - ok
16:32:24.0934 3168 [ E7B780F2E7A124264AA487C13107BDFF ] RSUSBVSTOR C:\WINDOWS\System32\Drivers\RtsUVStor.sys
16:32:24.0949 3168 RSUSBVSTOR - ok
16:32:25.0105 3168 [ 4733E843D221C608E1EC8FC4B18F0555 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
16:32:25.0137 3168 rtsuvc - ok
16:32:25.0168 3168 [ 1A063730F221B2746FF00457AE17E4F0 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
16:32:25.0168 3168 s3cap - ok
16:32:25.0199 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] SamSs C:\WINDOWS\system32\lsass.exe
16:32:25.0199 3168 SamSs - ok
16:32:25.0199 3168 [ C624A1B32211C3166EDB3F4AB02A30B7 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
16:32:25.0199 3168 sbp2port - ok
16:32:25.0215 3168 [ 47C497FA4DDEA908633CAA60CEBE6805 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
16:32:25.0230 3168 SCardSvr - ok
16:32:25.0230 3168 [ E76C4E98302AE39CC6FA5D20FC8B5438 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
16:32:25.0246 3168 ScDeviceEnum - ok
16:32:25.0246 3168 [ ABD0237B15DBD2B4695F4B7D734A58F7 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
16:32:25.0246 3168 scfilter - ok
16:32:25.0277 3168 [ 888A30EAB651502352C18745367FD179 ] Schedule C:\WINDOWS\system32\schedsvc.dll
16:32:25.0277 3168 Schedule - ok
16:32:25.0309 3168 [ AB285CE3431FF3D2ACE669245874C1C7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
16:32:25.0309 3168 SCPolicySvc - ok
16:32:25.0324 3168 [ 2F9A3380B8C0380E5608E29C7AA66899 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
16:32:25.0340 3168 sdbus - ok
16:32:25.0340 3168 [ 4EAF4DCF9DBD9A56952A58F56D61C005 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
16:32:25.0340 3168 sdstor - ok
16:32:25.0340 3168 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
16:32:25.0340 3168 secdrv - ok
16:32:25.0355 3168 [ C49009F897BA4F2F4F31043663AA1485 ] seclogon C:\WINDOWS\system32\seclogon.dll
16:32:25.0371 3168 seclogon - ok
16:32:25.0371 3168 [ A88882E64BDC1D8E8D6E727B71CCCC53 ] SENS C:\WINDOWS\System32\sens.dll
16:32:25.0371 3168 SENS - ok
16:32:25.0402 3168 [ E66A7C8CE7ED22DED6DF1CA479FB4790 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
16:32:25.0402 3168 SensrSvc - ok
16:32:25.0418 3168 [ DB2FF24CE0BDD15FE75870AFE312BA89 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
16:32:25.0418 3168 SerCx - ok
16:32:25.0449 3168 [ 0044B31F93946D5D41982314381FE431 ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
16:32:25.0449 3168 SerCx2 - ok
16:32:25.0449 3168 [ 3CD600C089C1251BEEB4CD4CD5164F9E ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
16:32:25.0449 3168 Serenum - ok
16:32:25.0465 3168 [ D864381BC9C725FAB01D94C060660166 ] Serial C:\WINDOWS\System32\drivers\serial.sys
16:32:25.0465 3168 Serial - ok
16:32:25.0465 3168 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
16:32:25.0465 3168 sermouse - ok
16:32:25.0480 3168 [ 441E6FF1F34D7A942946DB42A15FB519 ] SessionEnv C:\WINDOWS\system32\sessenv.dll
16:32:25.0496 3168 SessionEnv - ok
16:32:25.0496 3168 [ 472B7A5AC181C050888DB454663DD764 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
16:32:25.0496 3168 sfloppy - ok
16:32:25.0527 3168 [ F4414F57DF2CECB8FC969AA43A6B0D50 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
16:32:25.0543 3168 SharedAccess - ok
16:32:25.0574 3168 [ 0D190D8B4B20446BE6299AC734DFADF1 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
16:32:25.0574 3168 ShellHWDetection - ok
16:32:25.0574 3168 [ 2F518D13DD6F3053837FE606F1A2EA1F ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
16:32:25.0574 3168 SiSRaid2 - ok
16:32:25.0574 3168 [ 1AC9A200A9C49C4508F04AAFFCA34A3F ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
16:32:25.0574 3168 SiSRaid4 - ok
16:32:25.0590 3168 [ 587ACA15210D1B01FBF272E07A08F91A ] smphost C:\WINDOWS\System32\smphost.dll
16:32:25.0605 3168 smphost - ok
16:32:25.0637 3168 [ 49EEB92DE930B8566EF615D600781DB4 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
16:32:25.0637 3168 SNMPTRAP - ok
16:32:25.0668 3168 [ F6EBE514D13ECE7EDC23440039CDF9AB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
16:32:25.0668 3168 spaceport - ok
16:32:25.0668 3168 [ F337BE11071818FC3F5DC2940B6BDE34 ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
16:32:25.0668 3168 SpbCx - ok
16:32:25.0684 3168 [ FE0CB40F36D3FCDD3A1B312EF72C38D5 ] Spooler C:\WINDOWS\System32\spoolsv.exe
16:32:25.0699 3168 Spooler - ok
16:32:25.0809 3168 [ E6DEC72A2A23FAA53EB9FEC3C7E29D66 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
16:32:25.0840 3168 sppsvc - ok
16:32:25.0949 3168 [ 8BFD1752AAA15BF47D668E9AC5AF96FB ] SRTSP C:\WINDOWS\system32\drivers\NISx64\1501000.012\SRTSP64.SYS
16:32:25.0949 3168 SRTSP - ok
16:32:25.0949 3168 [ B18CE01B9C09C59422BA7C7064248B35 ] SRTSPX C:\WINDOWS\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS
16:32:25.0965 3168 SRTSPX - ok
16:32:25.0996 3168 [ 2B78788A1485F9B99A578A299DF42C02 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
16:32:25.0996 3168 srv - ok
16:32:26.0012 3168 [ C1AE59C0B0817236EC083A91C396005A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
16:32:26.0027 3168 srv2 - ok
16:32:26.0043 3168 [ 77195C32175FC63D6054EBA5A066D727 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
16:32:26.0043 3168 srvnet - ok
16:32:26.0074 3168 [ BB9ED3EDD8E85008215A7250D325A72E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
16:32:26.0090 3168 SSDPSRV - ok
16:32:26.0090 3168 [ 3911418AFDE10EA6823B7799E4815524 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
16:32:26.0106 3168 SstpSvc - ok
16:32:26.0121 3168 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
16:32:26.0121 3168 stexstor - ok
16:32:26.0199 3168 [ D638904FE86A5FE542A1BA13A9D68E5C ] stisvc C:\WINDOWS\System32\wiaservc.dll
16:32:26.0215 3168 stisvc - ok
16:32:26.0215 3168 [ 0ED2E318ABB68C1A35A8B8038BDB4C90 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
16:32:26.0215 3168 storahci - ok
16:32:26.0246 3168 [ 7A08CEE1535F5A448215634C5EA74E50 ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
16:32:26.0246 3168 storflt - ok
16:32:26.0262 3168 [ 6B06E2D11E604BE2B1A406C4CB3B90DE ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
16:32:26.0262 3168 stornvme - ok
16:32:26.0277 3168 [ 3118058E3D07021A55324A943C6D722B ] StorSvc C:\WINDOWS\system32\storsvc.dll
16:32:26.0277 3168 StorSvc - ok
16:32:26.0277 3168 [ 548759755BC73DAD663250239D7E0B9F ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
16:32:26.0277 3168 storvsc - ok
16:32:26.0293 3168 [ D8E1AE075AB3E8AD56F69C44AA978596 ] svsvc C:\WINDOWS\system32\svsvc.dll
16:32:26.0293 3168 svsvc - ok
16:32:26.0309 3168 [ 84E0F5D41C138C5CC975137A2A98F6D3 ] swenum C:\WINDOWS\System32\drivers\swenum.sys
16:32:26.0309 3168 swenum - ok
16:32:26.0324 3168 [ A5DC2E63F5E5D3C0B843307374998479 ] swprv C:\WINDOWS\System32\swprv.dll
16:32:26.0340 3168 swprv - ok
16:32:26.0402 3168 [ 5C9EE2303CA7F267665D75237862B39C ] SymDS C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMDS64.SYS
16:32:26.0402 3168 SymDS - ok
16:32:26.0481 3168 [ 08AF51153E441687130B759A8F6892ED ] SymEFA C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMEFA64.SYS
16:32:26.0496 3168 SymEFA - ok
16:32:26.0512 3168 [ 20F758E6339A16F97DD83389D582E09A ] SymELAM C:\WINDOWS\system32\drivers\NISx64\1501000.012\SymELAM.sys
16:32:26.0512 3168 SymELAM - ok
16:32:26.0527 3168 [ 97E11C50CE52277B377396EA8838E539 ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
16:32:26.0527 3168 SymEvent - ok
16:32:26.0559 3168 [ 48C2934683CBD06F662B088EEF49EF6A ] SymIRON C:\WINDOWS\system32\drivers\NISx64\1501000.012\Ironx64.SYS
16:32:26.0559 3168 SymIRON - ok
16:32:26.0606 3168 [ 78A2F073AD9EA5EBC04A70931EA36C9A ] SymNetS C:\WINDOWS\system32\drivers\NISx64\1501000.012\SYMNETS.SYS
16:32:26.0621 3168 SymNetS - ok
16:32:26.0652 3168 [ E45DA7CBBA34510C8B9473AD7D4FFD0B ] SysMain C:\WINDOWS\system32\sysmain.dll
16:32:26.0668 3168 SysMain - ok
16:32:26.0699 3168 [ D65B1C952AEB864C2BAC7A770B17ECCE ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
16:32:26.0715 3168 SystemEventsBroker - ok
16:32:26.0746 3168 [ BA6DD39266A5E15515C8C14DA2DA3E5C ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
16:32:26.0746 3168 TabletInputService - ok
16:32:26.0746 3168 [ B517410F157693043DACA21B19B258A6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
16:32:26.0762 3168 TapiSrv - ok
16:32:26.0824 3168 [ 3D9A5AC880D7AA2305812D665D24ED23 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
16:32:26.0840 3168 Tcpip - ok
16:32:26.0887 3168 [ 3D9A5AC880D7AA2305812D665D24ED23 ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:32:26.0902 3168 TCPIP6 - ok
16:32:26.0934 3168 [ 33A7D83EEB15431773A6E186CFAABA21 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
16:32:26.0934 3168 tcpipreg - ok
16:32:26.0965 3168 [ FFF28F9F6823EB1756C60F1649560BBF ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
16:32:26.0965 3168 tdx - ok
16:32:26.0981 3168 [ 232D185D2337F141311D0CF1983E1431 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
16:32:26.0981 3168 terminpt - ok
16:32:26.0996 3168 [ 2C77831737491F4D684D315B95C62883 ] TermService C:\WINDOWS\System32\termsrv.dll
16:32:27.0043 3168 TermService - ok
16:32:27.0059 3168 [ 05FBE1F7C13E87AF7A414CDF288B1F62 ] Themes C:\WINDOWS\system32\themeservice.dll
16:32:27.0059 3168 Themes - ok
16:32:27.0090 3168 [ FD788C2D96EA91469A3C1D13E80D7473 ] THREADORDER C:\WINDOWS\system32\mmcss.dll
16:32:27.0090 3168 THREADORDER - ok
16:32:27.0121 3168 [ 347A3E49CE18402305B8119A6EC7CFEB ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
16:32:27.0121 3168 TimeBroker - ok
16:32:27.0137 3168 [ 82F909359600D3603FE852DB7F135626 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
16:32:27.0152 3168 TPM - ok
16:32:27.0168 3168 [ C97E14BB6A196B0554D6EB67D8818175 ] TrkWks C:\WINDOWS\System32\trkwks.dll
16:32:27.0168 3168 TrkWks - ok
16:32:27.0215 3168 [ DA56FFA46030E6FEB215E3D5DAA65B11 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
16:32:27.0215 3168 TrustedInstaller - ok
16:32:27.0231 3168 [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
16:32:27.0231 3168 TsUsbFlt - ok
16:32:27.0246 3168 [ E0088068DCE2EE82897027DDB8E05254 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
16:32:27.0246 3168 TsUsbGD - ok
16:32:27.0262 3168 [ C8E0E78B5D284C2FF59BDFFDAF997242 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
16:32:27.0277 3168 tunnel - ok
16:32:27.0277 3168 [ F6EEAD052943B5A3104C1405BB856C54 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
16:32:27.0277 3168 uagp35 - ok
16:32:27.0293 3168 [ FE6067B1FD4E63650C667B33D080565B ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
16:32:27.0293 3168 UASPStor - ok
16:32:27.0293 3168 [ 5D1B430EA11064C56E7C8F84B90DEB6A ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
16:32:27.0309 3168 UCX01000 - ok
16:32:27.0309 3168 [ 1EC649F112896FAE33250F0B97AC5D0B ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
16:32:27.0309 3168 udfs - ok
16:32:27.0324 3168 [ 9578691F297E1B1F519970FE6D47CB21 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
16:32:27.0324 3168 UEFI - ok
16:32:27.0356 3168 [ 320878AFECDBBD61BBE98624A6CAAC08 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
16:32:27.0356 3168 UI0Detect - ok
16:32:27.0356 3168 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
16:32:27.0356 3168 uliagpkx - ok
16:32:27.0371 3168 [ DA34C39A18E60E7C3FA0630566408034 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
16:32:27.0371 3168 umbus - ok
16:32:27.0418 3168 [ AE8294875E5446E359B1E8035D40C05E ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
16:32:27.0418 3168 UmPass - ok
16:32:27.0449 3168 [ E3DDF7D43E05784FAA5E042605EEE528 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
16:32:27.0481 3168 UmRdpService - ok
16:32:27.0606 3168 [ 1E9A5658E0EBDBC381F52123363F74CB ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
16:32:27.0606 3168 UNS - ok
16:32:27.0621 3168 [ 4A2FFDAC45F317E17DF642C7160EB633 ] upnphost C:\WINDOWS\System32\upnphost.dll
16:32:27.0637 3168 upnphost - ok
16:32:27.0652 3168 [ 433ECDE01A52691FA7ACA51C10C09B70 ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
16:32:27.0652 3168 usbccgp - ok
16:32:27.0668 3168 [ B3D6457D841A0CAEF4C52D88621715F2 ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
16:32:27.0668 3168 usbcir - ok
16:32:27.0699 3168 [ 5477D6E27C7D266EF8C152B9A25ADE5E ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
16:32:27.0699 3168 usbehci - ok
16:32:27.0715 3168 [ DF56C2C04EFA328D7A66B69007130266 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
16:32:27.0731 3168 usbhub - ok
16:32:27.0746 3168 [ C0E33820326199CE3CFD3B9F27F81D99 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
16:32:27.0746 3168 USBHUB3 - ok
16:32:27.0762 3168 [ 3019097FB6C985EF24C058090FF3BDBD ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
16:32:27.0762 3168 usbohci - ok
16:32:27.0793 3168 [ 4D655E3B684BE9B0F7FFD8A2935C348C ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
16:32:27.0793 3168 usbprint - ok
16:32:27.0809 3168 [ 4628B415A84EA9D4D396A56F1D0CB6C6 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
16:32:27.0824 3168 USBSTOR - ok
16:32:27.0824 3168 [ BA4FA655E0FC577DB7436FC963932CE4 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
16:32:27.0824 3168 usbuhci - ok
16:32:27.0840 3168 [ 3B44CB989757428208CCFCC028C13110 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
16:32:27.0856 3168 USBXHCI - ok
16:32:27.0871 3168 [ F6F209DDB94959BA104FC8FC87C53759 ] VaultSvc C:\WINDOWS\system32\lsass.exe
16:32:27.0871 3168 VaultSvc - ok
16:32:27.0871 3168 [ FEB26E3B8345A7E8D62F945C4AE86562 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
16:32:27.0871 3168 vdrvroot - ok
16:32:28.0012 3168 [ CFBAD6B48EDFAA0828A52646B7C4C08D ] vds C:\WINDOWS\System32\vds.exe
16:32:28.0027 3168 vds - ok
16:32:28.0074 3168 [ F7579733F4E8FF9B534C3F7D38F25C2C ] VeriFaceSrv C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
16:32:28.0074 3168 VeriFaceSrv - ok
16:32:28.0090 3168 [ A026EDEAA5EECAE0B08E2748B616D4BD ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
16:32:28.0090 3168 VerifierExt - ok
16:32:28.0121 3168 [ 041D3EF364E624DBB2703A64A5AADF89 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
16:32:28.0137 3168 vhdmp - ok
16:32:28.0137 3168 [ 06D38968028E9AB19DE9B618C7B6D199 ] viaide C:\WINDOWS\system32\drivers\viaide.sys
16:32:28.0137 3168 viaide - ok
16:32:28.0152 3168 [ C6305BDFC4F7CE51F72BB072C03D4ACE ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
16:32:28.0152 3168 vmbus - ok
16:32:28.0152 3168 [ DA40BEA0A863CE768C940CA9723BF81F ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
16:32:28.0152 3168 VMBusHID - ok
16:32:28.0184 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
16:32:28.0184 3168 vmicguestinterface - ok
16:32:28.0199 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll
16:32:28.0199 3168 vmicheartbeat - ok
16:32:28.0215 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
16:32:28.0231 3168 vmickvpexchange - ok
16:32:28.0231 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicrdv C:\WINDOWS\System32\ICSvc.dll
16:32:28.0231 3168 vmicrdv - ok
16:32:28.0246 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll
16:32:28.0246 3168 vmicshutdown - ok
16:32:28.0246 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmictimesync C:\WINDOWS\System32\ICSvc.dll
16:32:28.0262 3168 vmictimesync - ok
16:32:28.0262 3168 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicvss C:\WINDOWS\System32\ICSvc.dll
16:32:28.0262 3168 vmicvss - ok
16:32:28.0293 3168 [ 55D7D963DE85162F1C49721E502F9744 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
16:32:28.0293 3168 volmgr - ok
16:32:28.0293 3168 [ CCB9E901F7254BF96D28EB1B0E5329B7 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
16:32:28.0293 3168 volmgrx - ok
16:32:28.0309 3168 [ 9F9CE33B50611A1C61A46B8911E0B30B ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
16:32:28.0309 3168 volsnap - ok
16:32:28.0324 3168 [ 01355C98B5C3ED1EC446743CDA848FCE ] vpci C:\WINDOWS\System32\drivers\vpci.sys
16:32:28.0324 3168 vpci - ok
16:32:28.0340 3168 [ 4539F45F9F4C9757A86A56C949421E07 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
16:32:28.0340 3168 vsmraid - ok
16:32:28.0387 3168 [ D51D7EF1EA5ED2BB01E9D07E6E0533BC ] VSS C:\WINDOWS\system32\vssvc.exe
16:32:28.0387 3168 VSS - ok
16:32:28.0402 3168 [ 0849B7260F26FE05EA56DED0672E2F4B ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
16:32:28.0402 3168 VSTXRAID - ok
16:32:28.0402 3168 [ BE970C369E43B509C1EDA2B8FA7CECB0 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
16:32:28.0402 3168 vwifibus - ok
16:32:28.0434 3168 [ 6B26AD573CCDD5209DF4397438B76354 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys
16:32:28.0434 3168 vwififlt - ok
16:32:28.0434 3168 [ 0B48E0DFB44EE475F4FD8A8EE599AF30 ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys
16:32:28.0434 3168 vwifimp - ok
16:32:28.0465 3168 [ 7599E582CA3A6AAA95A18FFE1172D339 ] W32Time C:\WINDOWS\system32\w32time.dll
16:32:28.0465 3168 W32Time - ok
16:32:28.0481 3168 [ 0910AB9ED404C1434E2D0376C2AD5D8B ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
16:32:28.0481 3168 WacomPen - ok
16:32:28.0512 3168 [ 92BF4B3EBD6F163B94B7A20C65E7B698 ] wbengine C:\WINDOWS\system32\wbengine.exe
16:32:28.0528 3168 wbengine - ok
16:32:28.0559 3168 [ 58F28103889817C93E5B5AFABC87E709 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
16:32:28.0559 3168 WbioSrvc - ok
16:32:28.0606 3168 [ 772365894F14652D376B2E5030179DC9 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
16:32:28.0606 3168 Wcmsvc - ok
16:32:28.0637 3168 [ D2726823DF7E19F213F4805A9D6D145F ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
16:32:28.0637 3168 wcncsvc - ok
16:32:28.0653 3168 [ 846C02A8B48CBD921A3D6AB521AA0DC4 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
16:32:28.0668 3168 WcsPlugInService - ok
16:32:28.0684 3168 [ 694B28DE12AD47031FFB4B052662131A ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
16:32:28.0684 3168 WdBoot - ok
16:32:28.0715 3168 [ CB6C63FF8342B467E2EF76E98D5B934D ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
16:32:28.0715 3168 Wdf01000 - ok
16:32:28.0762 3168 [ 0B99529A3BECC3528D865DDECB62503B ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
16:32:28.0762 3168 WdFilter - ok
16:32:28.0778 3168 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
16:32:28.0778 3168 WdiServiceHost - ok
16:32:28.0778 3168 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
16:32:28.0778 3168 WdiSystemHost - ok
16:32:28.0809 3168 [ 282E7D46310338FF4A6B7680440EB0DA ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
16:32:28.0809 3168 WdNisDrv - ok
16:32:28.0840 3168 WdNisSvc - ok
16:32:28.0856 3168 [ 6588A957873326361AB1CAC4E76F8394 ] WebClient C:\WINDOWS\System32\webclnt.dll
16:32:28.0871 3168 WebClient - ok
16:32:28.0887 3168 [ 3274312F263882B51B964329FAF49734 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
16:32:28.0903 3168 Wecsvc - ok
16:32:28.0903 3168 [ 7CDD84E0023A0C5C230B06A7965EC65E ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
16:32:28.0918 3168 WEPHOSTSVC - ok
16:32:28.0934 3168 [ AA1315B87D9B2E39584165318A59F15D ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
16:32:28.0934 3168 wercplsupport - ok
16:32:28.0934 3168 [ 22B4C24AB921BFF7827FFBCA1F4E1BB3 ] WerSvc C:\WINDOWS\System32\WerSvc.dll
16:32:28.0934 3168 WerSvc - ok
16:32:28.0949 3168 [ 2E3E82D7B1076B90F4E228A8EF17B261 ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
16:32:28.0949 3168 WFPLWFS - ok
16:32:28.0965 3168 [ E06AFE2F94BA7CFA2FE4FD2A449E60E2 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
16:32:28.0965 3168 WiaRpc - ok
16:32:28.0981 3168 [ 867BCC69ED9C31C501465EB0E8BA9DFA ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
16:32:28.0981 3168 WIMMount - ok
16:32:28.0981 3168 WinDefend - ok
16:32:28.0996 3168 [ DD079EC8F44DCA3A176B345C6ADEFB66 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
16:32:29.0012 3168 WinHttpAutoProxySvc - ok
16:32:29.0028 3168 [ 9DB490F3E823C5C3C070644B96CB9D59 ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
16:32:29.0028 3168 Winmgmt - ok
16:32:29.0090 3168 [ 690C3FC5C9DBD6B9AEDF8341EC720E41 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
16:32:29.0153 3168 WinRM - ok
16:32:29.0168 3168 [ AC263C2F66405589528995AA41040599 ] WinUsb C:\WINDOWS\system32\DRIVERS\WinUsb.sys
16:32:29.0168 3168 WinUsb - ok
16:32:29.0231 3168 [ 728D3349FAB251B0265EFA55C67DCA2D ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
16:32:29.0246 3168 WlanSvc - ok
16:32:29.0293 3168 [ C2838466CCC44FAEF2C3D4C1E5971ECB ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
16:32:29.0309 3168 wlidsvc - ok
16:32:29.0324 3168 [ 2834D9D3B4F554A39C72F00EA3F0E128 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
16:32:29.0324 3168 WmiAcpi - ok
16:32:29.0356 3168 [ 7AFAC828F52D62F304A911EC32F42EEE ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
16:32:29.0356 3168 wmiApSrv - ok
16:32:29.0356 3168 WMPNetworkSvc - ok
16:32:29.0403 3168 [ E178371E493BF17EB90FE71ABA8BE643 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
16:32:29.0418 3168 workfolderssvc - ok
16:32:29.0434 3168 [ E746BCDBA2E02CF6B8D6B26FB167FBE0 ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
16:32:29.0434 3168 wpcfltr - ok
16:32:29.0449 3168 [ 4E6A0F60DA7EF050D3D26417CD4D24E9 ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll
16:32:29.0449 3168 WPCSvc - ok
16:32:29.0465 3168 [ D27491CFCE452C154CECFA155AD0EBC8 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
16:32:29.0465 3168 WPDBusEnum - ok
16:32:29.0481 3168 [ 9F2904B55F6CECCD1A8D986B5CE2609A ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
16:32:29.0481 3168 WpdUpFltr - ok
16:32:29.0496 3168 [ AE072B0339D0A18E455DC21666CAD572 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
16:32:29.0496 3168 ws2ifsl - ok
16:32:29.0528 3168 [ 5CFA46C4ACB2FD70572017052378DAE5 ] wscsvc C:\WINDOWS\System32\wscsvc.dll
16:32:29.0528 3168 wscsvc - ok
16:32:29.0543 3168 WSearch - ok
16:32:29.0637 3168 [ D8E3A4701376CCFD0BE542D745FA4809 ] WSService C:\WINDOWS\System32\WSService.dll
16:32:29.0653 3168 WSService - ok
16:32:29.0684 3168 [ 72B4E9DF6456C43C42A1419B09486045 ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
16:32:29.0684 3168 wsvd - ok
16:32:29.0746 3168 [ 86D0BF4F792053A50D6EE43DFA5837A5 ] wuauserv C:\WINDOWS\system32\wuaueng.dll
16:32:29.0778 3168 wuauserv - ok
16:32:29.0793 3168 [ 2FEAE33E9B2B56104596E1BA444405A9 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
16:32:29.0793 3168 WudfPf - ok
16:32:29.0809 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
16:32:29.0809 3168 WUDFRd - ok
16:32:29.0825 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFSensorLP C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
16:32:29.0825 3168 WUDFSensorLP - ok
16:32:29.0825 3168 [ BB73CBC65AABC4EA0A5C6A1474A0A743 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
16:32:29.0825 3168 wudfsvc - ok
16:32:29.0840 3168 [ 19240C13F526125554B5370566F21A0A ] WUDFWpdMtp C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
16:32:29.0840 3168 WUDFWpdMtp - ok
16:32:29.0856 3168 [ 2FA9794CA36147756F3FDFD6CA29B46F ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
16:32:29.0871 3168 WwanSvc - ok
16:32:29.0903 3168 [ 86B8B1F5C1189D68B07666784BE882FE ] ZAtheros Bt and Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
16:32:29.0903 3168 ZAtheros Bt and Wlan Coex Agent - ok
16:32:29.0918 3168 ================ Scan global ===============================
16:32:29.0950 3168 [ C89780A6F58D113C28A96D85D1261DC5 ] C:\WINDOWS\system32\basesrv.dll
16:32:29.0981 3168 [ 599F1244C60E3D6C28A8DA7FBA7A2C13 ] C:\WINDOWS\system32\winsrv.dll
16:32:29.0996 3168 [ 9C1833ABD62876856836C5AE55C7CE86 ] C:\WINDOWS\system32\sxssrv.dll
16:32:30.0090 3168 [ B4B610BBCB002EC478C6FD80CF915697 ] C:\WINDOWS\system32\services.exe
16:32:30.0090 3168 [Global] - ok
16:32:30.0090 3168 ================ Scan MBR ==================================
16:32:30.0106 3168 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
16:32:30.0121 3168 \Device\Harddisk0\DR0 - ok
16:32:30.0121 3168 ================ Scan VBR ==================================
16:32:30.0121 3168 [ 564233D5182AE6F663AE432F0571B61E ] \Device\Harddisk0\DR0\Partition1
16:32:30.0121 3168 \Device\Harddisk0\DR0\Partition1 - ok
16:32:30.0137 3168 [ 414F0F65AD0C871F7C724204A77B2C17 ] \Device\Harddisk0\DR0\Partition2
16:32:30.0137 3168 \Device\Harddisk0\DR0\Partition2 - ok
16:32:30.0153 3168 [ EB0DF7FB23D6D22E10F054E0FB5E003A ] \Device\Harddisk0\DR0\Partition3
16:32:30.0168 3168 \Device\Harddisk0\DR0\Partition3 - ok
16:32:30.0168 3168 [ 0E20DB2A5F00AE784F89D72EBA659C2F ] \Device\Harddisk0\DR0\Partition4
16:32:30.0168 3168 \Device\Harddisk0\DR0\Partition4 - ok
16:32:30.0184 3168 [ 54B62297428F339212560A25A7499830 ] \Device\Harddisk0\DR0\Partition5
16:32:30.0184 3168 \Device\Harddisk0\DR0\Partition5 - ok
16:32:30.0184 3168 [ 7952E93AC6BF3FBF23A7B3DD78954351 ] \Device\Harddisk0\DR0\Partition6
16:32:30.0184 3168 \Device\Harddisk0\DR0\Partition6 - ok
16:32:30.0184 3168 [ 49C6E2D658C1BD80C846671C86651369 ] \Device\Harddisk0\DR0\Partition7
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition7 - ok
16:32:30.0200 3168 [ 8BC430BEF14630750F2FEF42E69BFBF3 ] \Device\Harddisk0\DR0\Partition8
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition8 - ok
16:32:30.0200 3168 [ B7898B01A1CC24AB2442799C6B9A1309 ] \Device\Harddisk0\DR0\Partition9
16:32:30.0200 3168 \Device\Harddisk0\DR0\Partition9 - ok
16:32:30.0200 3168 ============================================================
16:32:30.0200 3168 Scan finished
16:32:30.0200 3168 ============================================================
16:32:30.0215 0672 Detected object count: 0
16:32:30.0215 0672 Actual detected object count: 0
16:32:41.0747 4020 Deinitialize success
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Kontrola-podezření na malware
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
Pokud budou problémy , spusť v nouz. režimu.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 129 hostů