Zdravím,v Pc mam podle mě nepořádek a potřeboval bych zkontrolovat log a poprípadě pomoct.A dnes jsem zjitim i to že pc se zničeho nic několikrát zamrzne po restartu nenaběhne Windows..
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:51:08, on 20.8.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Standard\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.claro-search.com/?affID= ... 2264230147
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Help the General-Search Project - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\Users\Standard\AppData\Roaming\MEDIAF~1\EXTENS~1\GENCRA~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11g_Plugin.exe -update plugin
O4 - Startup: Facebook Messenger.lnk = C:\Users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
--
End of file - 5284 bytes
Odstranění Claro + kontrola logu
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Odstranění Claro + kontrola logu
Fixni:
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.claro-search.com/?affID= ... 2264230147
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11g_Plugin.exe -update plugin
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Odstranění Claro + kontrola logu
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Verze databáze: v2012.08.21.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Standard :: STANDARD-PC [administrátor]
21.8.2012 16:37:58
mbam-log-2012-08-21 (16-46-23).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 198981
Uplynulý čas: 4 minut, 48 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 7
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\USERS\STANDARD\APPDATA\ROAMING\MEDIA FINDER\EXTENSIONS\GENCRAWLER_GC.DLL (Trojan.Downloader) -> Data: 1 -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\ProgramData\wxDfast (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\data (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
Nalezené soubory: 6
C:\Users\Standard\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\bhoclass.dll (PUP.DownloadnSave) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\background.html (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\content.js (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\phcighppelhaiahbflknbkpegleghgpl.crx (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\settings.ini (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
(konec)
tady je log z mbam a ATF Cleaner mi nesmazal nic z koše..
www.malwarebytes.org
Verze databáze: v2012.08.21.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Standard :: STANDARD-PC [administrátor]
21.8.2012 16:37:58
mbam-log-2012-08-21 (16-46-23).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 198981
Uplynulý čas: 4 minut, 48 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 7
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\USERS\STANDARD\APPDATA\ROAMING\MEDIA FINDER\EXTENSIONS\GENCRAWLER_GC.DLL (Trojan.Downloader) -> Data: 1 -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\ProgramData\wxDfast (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\data (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
Nalezené soubory: 6
C:\Users\Standard\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\bhoclass.dll (PUP.DownloadnSave) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\background.html (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\content.js (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\phcighppelhaiahbflknbkpegleghgpl.crx (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
C:\ProgramData\wxDfast\settings.ini (PUP.wxDfast) -> Žádná instrukce nebyla provedena.
(konec)
tady je log z mbam a ATF Cleaner mi nesmazal nic z koše..
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Odstranění Claro + kontrola logu
Znovu spusť MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Odstranění Claro + kontrola logu
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Verze databáze: v2012.08.21.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Standard :: STANDARD-PC [administrátor]
23.8.2012 15:34:32
mbam-log-2012-08-23 (15-34-32).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 198741
Uplynulý čas: 5 minut, 14 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 7
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Umístnění do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\USERS\STANDARD\APPDATA\ROAMING\MEDIA FINDER\EXTENSIONS\GENCRAWLER_GC.DLL (Trojan.Downloader) -> Data: 1 -> Umístnění do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\ProgramData\wxDfast (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\data (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
Nalezené soubory: 6
C:\Users\Standard\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\bhoclass.dll (PUP.DownloadnSave) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\background.html (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\content.js (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\phcighppelhaiahbflknbkpegleghgpl.crx (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\settings.ini (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
(konec)
ale z programu TDSSKiller nemůžu najít log,proběhla kontrola ale nic se nezobrazilo
www.malwarebytes.org
Verze databáze: v2012.08.21.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Standard :: STANDARD-PC [administrátor]
23.8.2012 15:34:32
mbam-log-2012-08-23 (15-34-32).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 198741
Uplynulý čas: 5 minut, 14 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 7
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Umístnění do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\USERS\STANDARD\APPDATA\ROAMING\MEDIA FINDER\EXTENSIONS\GENCRAWLER_GC.DLL (Trojan.Downloader) -> Data: 1 -> Umístnění do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\ProgramData\wxDfast (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\data (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
Nalezené soubory: 6
C:\Users\Standard\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\bhoclass.dll (PUP.DownloadnSave) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\background.html (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\content.js (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\phcighppelhaiahbflknbkpegleghgpl.crx (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
C:\ProgramData\wxDfast\settings.ini (PUP.wxDfast) -> Umístnění do karantény a smazání se zdařilo.
(konec)
ale z programu TDSSKiller nemůžu najít log,proběhla kontrola ale nic se nezobrazilo
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Odstranění Claro + kontrola logu
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Odstranění Claro + kontrola logu
už se mi zobrazil ten log..konečně
12:18:30.0800 4668 TDSS rootkit removing tool 2.8.7.0 Aug 20 2012 17:30:03
12:18:30.0940 4668 ============================================================
12:18:30.0940 4668 Current date / time: 2012/08/24 12:18:30.0940
12:18:30.0940 4668 SystemInfo:
12:18:30.0940 4668
12:18:30.0940 4668 OS Version: 6.0.6002 ServicePack: 2.0
12:18:30.0940 4668 Product type: Workstation
12:18:30.0940 4668 ComputerName: STANDARD-PC
12:18:30.0940 4668 UserName: Standard
12:18:30.0940 4668 Windows directory: C:\Windows
12:18:30.0940 4668 System windows directory: C:\Windows
12:18:30.0940 4668 Processor architecture: Intel x86
12:18:30.0940 4668 Number of processors: 4
12:18:30.0940 4668 Page size: 0x1000
12:18:30.0940 4668 Boot type: Normal boot
12:18:30.0940 4668 ============================================================
12:18:31.0330 4668 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
12:18:31.0424 4668 ============================================================
12:18:31.0424 4668 \Device\Harddisk0\DR0:
12:18:31.0424 4668 MBR partitions:
12:18:31.0424 4668 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x39F9D000
12:18:31.0424 4668 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x39F9D800, BlocksNum 0x3E8000
12:18:31.0424 4668 ============================================================
12:18:31.0549 4668 C: <-> \Device\Harddisk0\DR0\Partition1
12:18:31.0689 4668 D: <-> \Device\Harddisk0\DR0\Partition2
12:18:31.0689 4668 ============================================================
12:18:31.0689 4668 Initialize success
12:18:31.0689 4668 ============================================================
12:18:33.0686 3504 ============================================================
12:18:33.0686 3504 Scan started
12:18:33.0686 3504 Mode: Manual;
12:18:33.0686 3504 ============================================================
12:18:34.0279 3504 ================ Scan system memory ========================
12:18:34.0279 3504 System memory - ok
12:18:34.0279 3504 ================ Scan services =============================
12:18:35.0215 3504 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
12:18:35.0230 3504 ACPI - ok
12:18:35.0293 3504 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
12:18:35.0324 3504 adp94xx - ok
12:18:35.0355 3504 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
12:18:35.0371 3504 adpahci - ok
12:18:35.0386 3504 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
12:18:35.0386 3504 adpu160m - ok
12:18:35.0433 3504 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
12:18:35.0433 3504 adpu320 - ok
12:18:35.0464 3504 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:18:35.0464 3504 AeLookupSvc - ok
12:18:35.0480 3504 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
12:18:35.0496 3504 AFD - ok
12:18:35.0542 3504 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
12:18:35.0542 3504 agp440 - ok
12:18:35.0574 3504 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
12:18:35.0574 3504 aic78xx - ok
12:18:35.0589 3504 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
12:18:35.0589 3504 ALG - ok
12:18:35.0605 3504 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
12:18:35.0605 3504 aliide - ok
12:18:35.0714 3504 [ 50EBBB86E493BD9AB7DDF914A90EEF8E ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:18:35.0745 3504 AMD External Events Utility - ok
12:18:35.0792 3504 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
12:18:35.0792 3504 amdagp - ok
12:18:35.0808 3504 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
12:18:35.0808 3504 amdide - ok
12:18:35.0823 3504 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
12:18:35.0823 3504 AmdK7 - ok
12:18:35.0839 3504 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
12:18:35.0839 3504 AmdK8 - ok
12:18:36.0244 3504 [ 70EB74785AB7FC603FEF19D87B7A7946 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
12:18:36.0416 3504 amdkmdag - ok
12:18:36.0494 3504 [ BA99833BBDE9C4FF389FC8114FB14843 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
12:18:36.0510 3504 amdkmdap - ok
12:18:36.0556 3504 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
12:18:36.0556 3504 Appinfo - ok
12:18:36.0666 3504 [ 0FE769CAE5855B53C90E23F85E7E89FF ] AppMgmt C:\Windows\System32\appmgmts.dll
12:18:36.0666 3504 AppMgmt - ok
12:18:36.0697 3504 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
12:18:36.0697 3504 arc - ok
12:18:36.0775 3504 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
12:18:36.0775 3504 arcsas - ok
12:18:36.0806 3504 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:18:36.0806 3504 AsyncMac - ok
12:18:36.0822 3504 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
12:18:36.0822 3504 atapi - ok
12:18:36.0868 3504 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:18:36.0868 3504 AudioEndpointBuilder - ok
12:18:36.0868 3504 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
12:18:36.0884 3504 Audiosrv - ok
12:18:36.0900 3504 [ 502F1C30BD50B32D00CE4DCAECC3D3C7 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
12:18:36.0900 3504 b57nd60x - ok
12:18:37.0118 3504 [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
12:18:37.0118 3504 BcmSqlStartupSvc - ok
12:18:37.0149 3504 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
12:18:37.0149 3504 Beep - ok
12:18:37.0305 3504 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
12:18:37.0305 3504 BFE - ok
12:18:37.0368 3504 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
12:18:37.0383 3504 BITS - ok
12:18:37.0399 3504 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
12:18:37.0446 3504 blbdrive - ok
12:18:37.0492 3504 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:18:37.0524 3504 bowser - ok
12:18:37.0555 3504 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
12:18:37.0555 3504 BrFiltLo - ok
12:18:37.0570 3504 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
12:18:37.0570 3504 BrFiltUp - ok
12:18:37.0711 3504 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
12:18:37.0726 3504 Browser - ok
12:18:37.0758 3504 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
12:18:37.0758 3504 Brserid - ok
12:18:37.0789 3504 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
12:18:37.0836 3504 BrSerWdm - ok
12:18:37.0867 3504 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
12:18:37.0867 3504 BrUsbMdm - ok
12:18:37.0882 3504 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
12:18:37.0882 3504 BrUsbSer - ok
12:18:37.0898 3504 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
12:18:37.0898 3504 BTHMODEM - ok
12:18:37.0929 3504 catchme - ok
12:18:37.0945 3504 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:18:37.0945 3504 cdfs - ok
12:18:37.0976 3504 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
12:18:37.0976 3504 cdrom - ok
12:18:38.0054 3504 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
12:18:38.0101 3504 CertPropSvc - ok
12:18:38.0132 3504 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
12:18:38.0132 3504 circlass - ok
12:18:38.0179 3504 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
12:18:38.0179 3504 CLFS - ok
12:18:38.0304 3504 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:18:38.0335 3504 clr_optimization_v2.0.50727_32 - ok
12:18:38.0382 3504 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:18:38.0382 3504 clr_optimization_v4.0.30319_32 - ok
12:18:38.0413 3504 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
12:18:38.0413 3504 cmdide - ok
12:18:38.0428 3504 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
12:18:38.0428 3504 Compbatt - ok
12:18:38.0428 3504 COMSysApp - ok
12:18:38.0475 3504 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
12:18:38.0475 3504 crcdisk - ok
12:18:38.0491 3504 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
12:18:38.0491 3504 Crusoe - ok
12:18:38.0553 3504 [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:18:38.0553 3504 CryptSvc - ok
12:18:38.0569 3504 [ 9BDB2E89BE8D0EF37B1F25C3D3FC192C ] CSC C:\Windows\system32\drivers\csc.sys
12:18:38.0569 3504 CSC - ok
12:18:38.0865 3504 [ 0A2095F92F6AE4FE6484D911B0C21E95 ] CscService C:\Windows\System32\cscsvc.dll
12:18:38.0896 3504 CscService - ok
12:18:39.0224 3504 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
12:18:39.0224 3504 DcomLaunch - ok
12:18:39.0302 3504 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
12:18:39.0302 3504 DfsC - ok
12:18:39.0380 3504 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
12:18:39.0411 3504 DFSR - ok
12:18:39.0458 3504 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
12:18:39.0458 3504 Dhcp - ok
12:18:39.0505 3504 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
12:18:39.0505 3504 disk - ok
12:18:39.0536 3504 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:18:39.0536 3504 Dnscache - ok
12:18:39.0567 3504 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
12:18:39.0583 3504 dot3svc - ok
12:18:39.0630 3504 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
12:18:39.0630 3504 DPS - ok
12:18:39.0661 3504 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:18:39.0661 3504 drmkaud - ok
12:18:39.0739 3504 [ FB38473835476A6FB272215A1D972AF9 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
12:18:39.0739 3504 dtsoftbus01 - ok
12:18:39.0864 3504 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:18:39.0864 3504 DXGKrnl - ok
12:18:40.0098 3504 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
12:18:40.0098 3504 E1G60 - ok
12:18:40.0176 3504 [ 668819862FFDE09028B975B74D376030 ] e1yexpress C:\Windows\system32\DRIVERS\e1y6032.sys
12:18:40.0176 3504 e1yexpress - ok
12:18:40.0254 3504 [ 8A45015E85A4DCE0086B9973F0FD9A20 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
12:18:40.0254 3504 eamonm - ok
12:18:40.0332 3504 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
12:18:40.0332 3504 EapHost - ok
12:18:40.0363 3504 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
12:18:40.0363 3504 Ecache - ok
12:18:40.0394 3504 [ 5412ED24FFFCA64E2F0168399B86C952 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
12:18:40.0394 3504 ehdrv - ok
12:18:41.0205 3504 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
12:18:41.0205 3504 ekrn - ok
12:18:41.0330 3504 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
12:18:41.0330 3504 elxstor - ok
12:18:41.0377 3504 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
12:18:41.0392 3504 EMDMgmt - ok
12:18:41.0408 3504 [ 0A587BB99A22F8DC3597471425D43314 ] epfwwfpr C:\Windows\system32\DRIVERS\epfwwfpr.sys
12:18:41.0470 3504 epfwwfpr - ok
12:18:41.0502 3504 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
12:18:41.0502 3504 ErrDev - ok
12:18:41.0564 3504 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
12:18:41.0564 3504 EventSystem - ok
12:18:41.0611 3504 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
12:18:41.0642 3504 exfat - ok
12:18:41.0689 3504 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:18:41.0689 3504 fastfat - ok
12:18:42.0016 3504 [ DFBA0F60FA301E5B1BFB1403A93EE23E ] Fax C:\Windows\system32\fxssvc.exe
12:18:42.0063 3504 Fax - ok
12:18:42.0188 3504 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
12:18:42.0188 3504 fdc - ok
12:18:42.0266 3504 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
12:18:42.0266 3504 fdPHost - ok
12:18:42.0344 3504 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
12:18:42.0344 3504 FDResPub - ok
12:18:42.0360 3504 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:18:42.0360 3504 FileInfo - ok
12:18:42.0375 3504 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:18:42.0375 3504 Filetrace - ok
12:18:42.0391 3504 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
12:18:42.0391 3504 flpydisk - ok
12:18:42.0406 3504 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:18:42.0406 3504 FltMgr - ok
12:18:42.0453 3504 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
12:18:42.0469 3504 FontCache - ok
12:18:42.0609 3504 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
12:18:42.0609 3504 FontCache3.0.0.0 - ok
12:18:42.0734 3504 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:18:42.0750 3504 Fs_Rec - ok
12:18:42.0874 3504 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
12:18:42.0921 3504 gagp30kx - ok
12:18:42.0968 3504 [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
12:18:42.0968 3504 ggflt - ok
12:18:42.0984 3504 [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
12:18:42.0984 3504 ggsemc - ok
12:18:43.0374 3504 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
12:18:43.0374 3504 gpsvc - ok
12:18:43.0545 3504 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
12:18:43.0545 3504 gupdate - ok
12:18:43.0545 3504 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
12:18:43.0545 3504 gupdatem - ok
12:18:43.0670 3504 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:18:43.0701 3504 HdAudAddService - ok
12:18:43.0748 3504 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
12:18:43.0764 3504 HDAudBus - ok
12:18:43.0810 3504 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
12:18:43.0810 3504 HidBth - ok
12:18:43.0826 3504 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
12:18:43.0826 3504 HidIr - ok
12:18:43.0888 3504 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
12:18:43.0888 3504 hidserv - ok
12:18:43.0966 3504 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
12:18:43.0966 3504 HidUsb - ok
12:18:44.0091 3504 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:18:44.0122 3504 hkmsvc - ok
12:18:44.0154 3504 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
12:18:44.0154 3504 HpCISSs - ok
12:18:44.0185 3504 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:18:44.0200 3504 HTTP - ok
12:18:44.0247 3504 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
12:18:44.0247 3504 i2omp - ok
12:18:44.0310 3504 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
12:18:44.0310 3504 i8042prt - ok
12:18:44.0325 3504 [ 42BE6406094936A23280D68D9AEC33D0 ] iaStor C:\Windows\system32\drivers\iastor.sys
12:18:44.0325 3504 iaStor - ok
12:18:44.0419 3504 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
12:18:44.0419 3504 iaStorV - ok
12:18:45.0027 3504 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:18:45.0058 3504 idsvc - ok
12:18:45.0121 3504 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
12:18:45.0121 3504 iirsp - ok
12:18:45.0386 3504 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
12:18:45.0386 3504 IKEEXT - ok
12:18:45.0542 3504 [ 0E70E4485F0ED782248E26353A08D312 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
12:18:45.0573 3504 IntcAzAudAddService - ok
12:18:45.0620 3504 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
12:18:45.0620 3504 intelide - ok
12:18:45.0651 3504 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
12:18:45.0651 3504 intelppm - ok
12:18:45.0682 3504 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
12:18:45.0682 3504 IPBusEnum - ok
12:18:45.0698 3504 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:18:45.0698 3504 IpFilterDriver - ok
12:18:45.0745 3504 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:18:45.0776 3504 iphlpsvc - ok
12:18:45.0807 3504 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
12:18:45.0807 3504 IPMIDRV - ok
12:18:45.0838 3504 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
12:18:45.0838 3504 IPNAT - ok
12:18:45.0916 3504 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:18:45.0948 3504 IRENUM - ok
12:18:45.0994 3504 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
12:18:45.0994 3504 isapnp - ok
12:18:46.0119 3504 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
12:18:46.0119 3504 iScsiPrt - ok
12:18:46.0213 3504 [ 76F9267AB1223A5EA5230625A0031BDC ] IT9135BDA C:\Windows\system32\Drivers\IT9135BDA.sys
12:18:46.0213 3504 IT9135BDA - ok
12:18:46.0260 3504 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
12:18:46.0291 3504 iteatapi - ok
12:18:46.0322 3504 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
12:18:46.0322 3504 iteraid - ok
12:18:46.0353 3504 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
12:18:46.0353 3504 kbdclass - ok
12:18:46.0369 3504 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
12:18:46.0369 3504 kbdhid - ok
12:18:46.0416 3504 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
12:18:46.0416 3504 KeyIso - ok
12:18:46.0759 3504 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:18:46.0759 3504 KSecDD - ok
12:18:47.0008 3504 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
12:18:47.0040 3504 KtmRm - ok
12:18:47.0102 3504 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
12:18:47.0102 3504 LanmanServer - ok
12:18:47.0118 3504 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:18:47.0118 3504 LanmanWorkstation - ok
12:18:47.0274 3504 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:18:47.0274 3504 lltdio - ok
12:18:47.0398 3504 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:18:47.0398 3504 lltdsvc - ok
12:18:47.0414 3504 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:18:47.0414 3504 lmhosts - ok
12:18:47.0461 3504 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
12:18:47.0461 3504 LSI_FC - ok
12:18:47.0523 3504 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
12:18:47.0554 3504 LSI_SAS - ok
12:18:47.0586 3504 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
12:18:47.0586 3504 LSI_SCSI - ok
12:18:47.0617 3504 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
12:18:47.0648 3504 luafv - ok
12:18:47.0710 3504 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
12:18:47.0742 3504 MBAMProtector - ok
12:18:47.0835 3504 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
12:18:47.0835 3504 MBAMService - ok
12:18:47.0929 3504 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
12:18:47.0960 3504 megasas - ok
12:18:47.0991 3504 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
12:18:47.0991 3504 MegaSR - ok
12:18:48.0038 3504 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
12:18:48.0038 3504 MMCSS - ok
12:18:48.0054 3504 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
12:18:48.0054 3504 Modem - ok
12:18:48.0132 3504 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:18:48.0132 3504 monitor - ok
12:18:48.0210 3504 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
12:18:48.0210 3504 mouclass - ok
12:18:48.0334 3504 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
12:18:48.0366 3504 mouhid - ok
12:18:48.0381 3504 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
12:18:48.0397 3504 MountMgr - ok
12:18:48.0459 3504 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
12:18:48.0459 3504 MozillaMaintenance - ok
12:18:48.0490 3504 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
12:18:48.0490 3504 mpio - ok
12:18:48.0522 3504 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:18:48.0522 3504 mpsdrv - ok
12:18:48.0818 3504 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
12:18:48.0849 3504 MpsSvc - ok
12:18:48.0896 3504 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
12:18:48.0912 3504 Mraid35x - ok
12:18:48.0927 3504 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:18:48.0927 3504 MRxDAV - ok
12:18:48.0943 3504 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:18:48.0943 3504 mrxsmb - ok
12:18:48.0958 3504 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:18:48.0958 3504 mrxsmb10 - ok
12:18:49.0036 3504 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:18:49.0036 3504 mrxsmb20 - ok
12:18:49.0130 3504 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
12:18:49.0130 3504 msahci - ok
12:18:49.0192 3504 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
12:18:49.0192 3504 msdsm - ok
12:18:49.0302 3504 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
12:18:49.0348 3504 MSDTC - ok
12:18:49.0380 3504 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:18:49.0380 3504 Msfs - ok
12:18:49.0411 3504 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
12:18:49.0411 3504 msisadrv - ok
12:18:49.0442 3504 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:18:49.0442 3504 MSiSCSI - ok
12:18:49.0458 3504 msiserver - ok
12:18:49.0489 3504 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:18:49.0489 3504 MSKSSRV - ok
12:18:49.0489 3504 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:18:49.0489 3504 MSPCLOCK - ok
12:18:49.0504 3504 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:18:49.0504 3504 MSPQM - ok
12:18:49.0520 3504 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:18:49.0520 3504 MsRPC - ok
12:18:49.0551 3504 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
12:18:49.0551 3504 mssmbios - ok
12:18:49.0879 3504 MSSQL$MSSMLBIZ - ok
12:18:50.0128 3504 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
12:18:50.0144 3504 MSSQLServerADHelper - ok
12:18:50.0175 3504 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:18:50.0175 3504 MSTEE - ok
12:18:50.0206 3504 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
12:18:50.0206 3504 Mup - ok
12:18:50.0238 3504 [ 03CA886BA148B6B9996BE1368DDC3FC0 ] NAL C:\Windows\system32\Drivers\iqvw32.sys
12:18:50.0238 3504 NAL - ok
12:18:50.0253 3504 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
12:18:50.0269 3504 napagent - ok
12:18:50.0347 3504 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:18:50.0347 3504 NativeWifiP - ok
12:18:50.0440 3504 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
12:18:50.0456 3504 NDIS - ok
12:18:50.0487 3504 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:18:50.0487 3504 NdisTapi - ok
12:18:50.0503 3504 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:18:50.0518 3504 Ndisuio - ok
12:18:50.0534 3504 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:18:50.0534 3504 NdisWan - ok
12:18:50.0550 3504 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:18:50.0550 3504 NDProxy - ok
12:18:50.0565 3504 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:18:50.0565 3504 NetBIOS - ok
12:18:50.0565 3504 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
12:18:50.0565 3504 netbt - ok
12:18:50.0581 3504 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
12:18:50.0581 3504 Netlogon - ok
12:18:50.0596 3504 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
12:18:50.0612 3504 Netman - ok
12:18:50.0628 3504 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
12:18:50.0628 3504 netprofm - ok
12:18:50.0674 3504 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:18:50.0674 3504 NetTcpPortSharing - ok
12:18:50.0721 3504 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
12:18:50.0752 3504 nfrd960 - ok
12:18:50.0784 3504 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:18:50.0784 3504 NlaSvc - ok
12:18:50.0815 3504 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:18:50.0815 3504 Npfs - ok
12:18:50.0893 3504 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
12:18:50.0924 3504 nsi - ok
12:18:50.0955 3504 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:18:50.0955 3504 nsiproxy - ok
12:18:51.0454 3504 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:18:51.0470 3504 Ntfs - ok
12:18:51.0501 3504 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
12:18:51.0501 3504 ntrigdigi - ok
12:18:51.0517 3504 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
12:18:51.0517 3504 Null - ok
12:18:51.0548 3504 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
12:18:51.0548 3504 nvraid - ok
12:18:51.0579 3504 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
12:18:51.0595 3504 nvstor - ok
12:18:51.0626 3504 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
12:18:51.0626 3504 nv_agp - ok
12:18:51.0735 3504 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:18:51.0751 3504 odserv - ok
12:18:51.0813 3504 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
12:18:51.0813 3504 ohci1394 - ok
12:18:51.0938 3504 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:18:51.0938 3504 ose - ok
12:18:51.0985 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
12:18:52.0000 3504 p2pimsvc - ok
12:18:52.0000 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
12:18:52.0016 3504 p2psvc - ok
12:18:52.0063 3504 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys
12:18:52.0078 3504 Parport - ok
12:18:52.0125 3504 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:18:52.0125 3504 partmgr - ok
12:18:52.0141 3504 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
12:18:52.0141 3504 Parvdm - ok
12:18:52.0156 3504 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
12:18:52.0156 3504 PcaSvc - ok
12:18:52.0188 3504 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
12:18:52.0188 3504 pci - ok
12:18:52.0297 3504 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
12:18:52.0328 3504 pciide - ok
12:18:52.0344 3504 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
12:18:52.0344 3504 pcmcia - ok
12:18:52.0390 3504 pdfcDispatcher - ok
12:18:52.0422 3504 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:18:52.0437 3504 PEAUTH - ok
12:18:52.0484 3504 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
12:18:52.0500 3504 pla - ok
12:18:52.0515 3504 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:18:52.0531 3504 PlugPlay - ok
12:18:52.0546 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
12:18:52.0546 3504 PNRPAutoReg - ok
12:18:52.0593 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
12:18:52.0593 3504 PNRPsvc - ok
12:18:52.0812 3504 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:18:52.0843 3504 PolicyAgent - ok
12:18:52.0874 3504 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:18:52.0874 3504 PptpMiniport - ok
12:18:52.0890 3504 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
12:18:52.0905 3504 Processor - ok
12:18:52.0921 3504 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
12:18:52.0921 3504 ProfSvc - ok
12:18:52.0936 3504 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
12:18:52.0936 3504 ProtectedStorage - ok
12:18:52.0999 3504 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
12:18:52.0999 3504 PSched - ok
12:18:53.0046 3504 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
12:18:53.0046 3504 ql2300 - ok
12:18:53.0092 3504 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
12:18:53.0092 3504 ql40xx - ok
12:18:53.0248 3504 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
12:18:53.0295 3504 QWAVE - ok
12:18:53.0311 3504 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:18:53.0311 3504 QWAVEdrv - ok
12:18:53.0326 3504 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:18:53.0342 3504 RasAcd - ok
12:18:53.0342 3504 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
12:18:53.0342 3504 RasAuto - ok
12:18:53.0358 3504 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:18:53.0358 3504 Rasl2tp - ok
12:18:53.0389 3504 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
12:18:53.0389 3504 RasMan - ok
12:18:53.0404 3504 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:18:53.0404 3504 RasPppoe - ok
12:18:53.0404 3504 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:18:53.0404 3504 RasSstp - ok
12:18:53.0420 3504 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:18:53.0420 3504 rdbss - ok
12:18:53.0420 3504 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:18:53.0420 3504 RDPCDD - ok
12:18:53.0451 3504 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys
12:18:53.0451 3504 rdpdr - ok
12:18:53.0467 3504 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:18:53.0467 3504 RDPENCDD - ok
12:18:53.0514 3504 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:18:53.0545 3504 RDPWD - ok
12:18:53.0592 3504 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:18:53.0592 3504 RemoteAccess - ok
12:18:53.0607 3504 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:18:53.0607 3504 RemoteRegistry - ok
12:18:53.0623 3504 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
12:18:53.0623 3504 RpcLocator - ok
12:18:53.0638 3504 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
12:18:53.0654 3504 RpcSs - ok
12:18:53.0670 3504 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:18:53.0670 3504 rspndr - ok
12:18:53.0685 3504 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
12:18:53.0685 3504 SamSs - ok
12:18:53.0732 3504 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
12:18:53.0779 3504 sbp2port - ok
12:18:53.0826 3504 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:18:53.0826 3504 SCardSvr - ok
12:18:53.0857 3504 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
12:18:53.0857 3504 Schedule - ok
12:18:53.0857 3504 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
12:18:53.0857 3504 SCPolicySvc - ok
12:18:53.0888 3504 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:18:53.0888 3504 SDRSVC - ok
12:18:53.0888 3504 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:18:53.0904 3504 secdrv - ok
12:18:53.0904 3504 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
12:18:53.0904 3504 seclogon - ok
12:18:53.0919 3504 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
12:18:53.0919 3504 SENS - ok
12:18:53.0950 3504 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:18:53.0950 3504 Serenum - ok
12:18:53.0982 3504 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:18:53.0982 3504 Serial - ok
12:18:54.0028 3504 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
12:18:54.0044 3504 sermouse - ok
12:18:54.0075 3504 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
12:18:54.0075 3504 SessionEnv - ok
12:18:54.0122 3504 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
12:18:54.0122 3504 sffdisk - ok
12:18:54.0138 3504 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
12:18:54.0138 3504 sffp_mmc - ok
12:18:54.0138 3504 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
12:18:54.0138 3504 sffp_sd - ok
12:18:54.0153 3504 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
12:18:54.0153 3504 sfloppy - ok
12:18:54.0184 3504 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:18:54.0184 3504 SharedAccess - ok
12:18:54.0247 3504 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:18:54.0247 3504 ShellHWDetection - ok
12:18:54.0278 3504 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
12:18:54.0278 3504 sisagp - ok
12:18:54.0294 3504 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
12:18:54.0294 3504 SiSRaid2 - ok
12:18:54.0340 3504 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
12:18:54.0340 3504 SiSRaid4 - ok
12:18:54.0528 3504 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
12:18:54.0559 3504 slsvc - ok
12:18:54.0606 3504 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
12:18:54.0606 3504 SLUINotify - ok
12:18:54.0621 3504 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:18:54.0621 3504 Smb - ok
12:18:54.0637 3504 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:18:54.0652 3504 SNMPTRAP - ok
12:18:54.0668 3504 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
12:18:54.0668 3504 spldr - ok
12:18:54.0684 3504 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
12:18:54.0699 3504 Spooler - ok
12:18:54.0715 3504 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
12:18:54.0715 3504 SQLBrowser - ok
12:18:54.0746 3504 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
12:18:54.0746 3504 SQLWriter - ok
12:18:54.0777 3504 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:18:54.0777 3504 srv - ok
12:18:54.0793 3504 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:18:54.0793 3504 srv2 - ok
12:18:54.0840 3504 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:18:54.0840 3504 srvnet - ok
12:18:54.0918 3504 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:18:54.0918 3504 SSDPSRV - ok
12:18:54.0933 3504 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:18:54.0933 3504 SstpSvc - ok
12:18:54.0996 3504 [ EF70B3D22B4BFFDA6EA851ECB063EFAA ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
12:18:54.0996 3504 StillCam - ok
12:18:55.0027 3504 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
12:18:55.0027 3504 stisvc - ok
12:18:55.0058 3504 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
12:18:55.0058 3504 swenum - ok
12:18:55.0074 3504 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
12:18:55.0089 3504 swprv - ok
12:18:55.0136 3504 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
12:18:55.0136 3504 Symc8xx - ok
12:18:55.0152 3504 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
12:18:55.0152 3504 Sym_hi - ok
12:18:55.0167 3504 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
12:18:55.0167 3504 Sym_u3 - ok
12:18:55.0214 3504 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
12:18:55.0214 3504 SysMain - ok
12:18:55.0245 3504 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:18:55.0245 3504 TabletInputService - ok
12:18:55.0276 3504 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
12:18:55.0276 3504 TapiSrv - ok
12:18:55.0276 3504 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
12:18:55.0276 3504 TBS - ok
12:18:55.0354 3504 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:18:55.0370 3504 Tcpip - ok
12:18:55.0386 3504 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
12:18:55.0386 3504 Tcpip6 - ok
12:18:55.0401 3504 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:18:55.0401 3504 tcpipreg - ok
12:18:55.0448 3504 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:18:55.0448 3504 TDPIPE - ok
12:18:55.0464 3504 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:18:55.0464 3504 TDTCP - ok
12:18:55.0510 3504 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:18:55.0510 3504 tdx - ok
12:18:55.0526 3504 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
12:18:55.0526 3504 TermDD - ok
12:18:55.0557 3504 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
12:18:55.0557 3504 TermService - ok
12:18:55.0604 3504 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
12:18:55.0604 3504 Themes - ok
12:18:55.0635 3504 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
12:18:55.0635 3504 THREADORDER - ok
12:18:55.0666 3504 [ CB258C2F726F1BE73C507022BE33EBB3 ] TPM C:\Windows\system32\drivers\tpm.sys
12:18:55.0666 3504 TPM - ok
12:18:55.0698 3504 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
12:18:55.0698 3504 TrkWks - ok
12:18:55.0729 3504 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:18:55.0729 3504 TrustedInstaller - ok
12:18:55.0760 3504 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:18:55.0760 3504 tssecsrv - ok
12:18:55.0791 3504 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
12:18:55.0791 3504 tunmp - ok
12:18:55.0838 3504 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:18:55.0838 3504 tunnel - ok
12:18:55.0869 3504 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
12:18:55.0869 3504 uagp35 - ok
12:18:55.0916 3504 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:18:55.0916 3504 udfs - ok
12:18:55.0947 3504 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:18:55.0947 3504 UI0Detect - ok
12:18:55.0994 3504 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:18:55.0994 3504 uliagpkx - ok
12:18:56.0025 3504 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
12:18:56.0025 3504 uliahci - ok
12:18:56.0072 3504 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
12:18:56.0072 3504 UlSata - ok
12:18:56.0103 3504 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
12:18:56.0103 3504 ulsata2 - ok
12:18:56.0134 3504 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
12:18:56.0134 3504 umbus - ok
12:18:56.0134 3504 [ 8A66360F38F81E960E2367B428CBD5D9 ] UmRdpService C:\Windows\System32\umrdp.dll
12:18:56.0134 3504 UmRdpService - ok
12:18:56.0197 3504 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
12:18:56.0197 3504 upnphost - ok
12:18:56.0259 3504 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
12:18:56.0259 3504 usbaudio - ok
12:18:56.0275 3504 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:18:56.0275 3504 usbccgp - ok
12:18:56.0322 3504 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
12:18:56.0322 3504 usbcir - ok
12:18:56.0353 3504 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:18:56.0353 3504 usbehci - ok
12:18:56.0368 3504 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:18:56.0384 3504 usbhub - ok
12:18:56.0400 3504 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
12:18:56.0400 3504 usbohci - ok
12:18:56.0446 3504 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:18:56.0462 3504 usbprint - ok
12:18:56.0509 3504 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
12:18:56.0509 3504 usbscan - ok
12:18:56.0540 3504 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:18:56.0540 3504 USBSTOR - ok
12:18:56.0556 3504 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
12:18:56.0556 3504 usbuhci - ok
12:18:56.0587 3504 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
12:18:56.0587 3504 usbvideo - ok
12:18:56.0634 3504 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
12:18:56.0634 3504 UxSms - ok
12:18:56.0665 3504 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
12:18:56.0665 3504 vds - ok
12:18:56.0696 3504 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:18:56.0696 3504 vga - ok
12:18:56.0712 3504 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
12:18:56.0712 3504 VgaSave - ok
12:18:56.0743 3504 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
12:18:56.0743 3504 viaagp - ok
12:18:56.0758 3504 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
12:18:56.0758 3504 ViaC7 - ok
12:18:56.0774 3504 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
12:18:56.0774 3504 viaide - ok
12:18:56.0790 3504 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:18:56.0790 3504 volmgr - ok
12:18:56.0805 3504 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:18:56.0805 3504 volmgrx - ok
12:18:56.0836 3504 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:18:56.0836 3504 volsnap - ok
12:18:56.0868 3504 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
12:18:56.0868 3504 vsmraid - ok
12:18:56.0914 3504 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
12:18:56.0914 3504 VSS - ok
12:18:56.0930 3504 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
12:18:56.0946 3504 W32Time - ok
12:18:56.0961 3504 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
12:18:56.0961 3504 WacomPen - ok
12:18:56.0977 3504 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
12:18:56.0992 3504 Wanarp - ok
12:18:56.0992 3504 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:18:56.0992 3504 Wanarpv6 - ok
12:18:57.0008 3504 [ 20B23332885DFB93FE0185362EE811E9 ] wbengine C:\Windows\system32\wbengine.exe
12:18:57.0024 3504 wbengine - ok
12:18:57.0039 3504 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:18:57.0039 3504 wcncsvc - ok
12:18:57.0055 3504 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:18:57.0055 3504 WcsPlugInService - ok
12:18:57.0086 3504 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
12:18:57.0086 3504 Wd - ok
12:18:57.0117 3504 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:18:57.0117 3504 Wdf01000 - ok
12:18:57.0133 3504 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:18:57.0133 3504 WdiServiceHost - ok
12:18:57.0133 3504 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:18:57.0133 3504 WdiSystemHost - ok
12:18:57.0164 3504 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
12:18:57.0164 3504 WebClient - ok
12:18:57.0226 3504 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:18:57.0226 3504 Wecsvc - ok
12:18:57.0226 3504 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:18:57.0242 3504 wercplsupport - ok
12:18:57.0242 3504 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
12:18:57.0242 3504 WerSvc - ok
12:18:57.0273 3504 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
12:18:57.0289 3504 WinDefend - ok
12:18:57.0289 3504 WinHttpAutoProxySvc - ok
12:18:57.0336 3504 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:18:57.0336 3504 Winmgmt - ok
12:18:57.0367 3504 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
12:18:57.0382 3504 WinRM - ok
12:18:57.0445 3504 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
12:18:57.0460 3504 Wlansvc - ok
12:18:57.0492 3504 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
12:18:57.0492 3504 WmiAcpi - ok
12:18:57.0523 3504 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:18:57.0523 3504 wmiApSrv - ok
12:18:57.0570 3504 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
12:18:57.0570 3504 WMPNetworkSvc - ok
12:18:57.0601 3504 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:18:57.0601 3504 WPDBusEnum - ok
12:18:57.0663 3504 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:18:57.0679 3504 WPFFontCache_v0400 - ok
12:18:57.0710 3504 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:18:57.0710 3504 ws2ifsl - ok
12:18:57.0757 3504 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
12:18:57.0757 3504 wscsvc - ok
12:18:57.0757 3504 WSearch - ok
12:18:57.0835 3504 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
12:18:57.0850 3504 wuauserv - ok
12:18:57.0897 3504 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:18:57.0897 3504 WUDFRd - ok
12:18:57.0913 3504 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:18:57.0913 3504 wudfsvc - ok
12:18:57.0944 3504 ================ Scan global ===============================
12:18:57.0991 3504 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
12:18:58.0022 3504 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
12:18:58.0038 3504 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
12:18:58.0053 3504 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
12:18:58.0069 3504 [Global] - ok
12:18:58.0069 3504 ================ Scan MBR ==================================
12:18:58.0084 3504 [ 92A0110A64C3262C5F5DF2032E989DCE ] \Device\Harddisk0\DR0
12:18:58.0272 3504 \Device\Harddisk0\DR0 - ok
12:18:58.0272 3504 ================ Scan VBR ==================================
12:18:58.0272 3504 [ 4348B0676D9527DAC5368AFE0D679CC0 ] \Device\Harddisk0\DR0\Partition1
12:18:58.0272 3504 \Device\Harddisk0\DR0\Partition1 - ok
12:18:58.0303 3504 [ D4781209DAD0F5096D9B6E6CAEC44566 ] \Device\Harddisk0\DR0\Partition2
12:18:58.0303 3504 \Device\Harddisk0\DR0\Partition2 - ok
12:18:58.0303 3504 ============================================================
12:18:58.0303 3504 Scan finished
12:18:58.0303 3504 ============================================================
12:18:58.0318 5756 Detected object count: 0
12:18:58.0318 5756 Actual detected object count: 0
12:19:07.0210 4912 Deinitialize success
12:18:30.0800 4668 TDSS rootkit removing tool 2.8.7.0 Aug 20 2012 17:30:03
12:18:30.0940 4668 ============================================================
12:18:30.0940 4668 Current date / time: 2012/08/24 12:18:30.0940
12:18:30.0940 4668 SystemInfo:
12:18:30.0940 4668
12:18:30.0940 4668 OS Version: 6.0.6002 ServicePack: 2.0
12:18:30.0940 4668 Product type: Workstation
12:18:30.0940 4668 ComputerName: STANDARD-PC
12:18:30.0940 4668 UserName: Standard
12:18:30.0940 4668 Windows directory: C:\Windows
12:18:30.0940 4668 System windows directory: C:\Windows
12:18:30.0940 4668 Processor architecture: Intel x86
12:18:30.0940 4668 Number of processors: 4
12:18:30.0940 4668 Page size: 0x1000
12:18:30.0940 4668 Boot type: Normal boot
12:18:30.0940 4668 ============================================================
12:18:31.0330 4668 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
12:18:31.0424 4668 ============================================================
12:18:31.0424 4668 \Device\Harddisk0\DR0:
12:18:31.0424 4668 MBR partitions:
12:18:31.0424 4668 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x39F9D000
12:18:31.0424 4668 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x39F9D800, BlocksNum 0x3E8000
12:18:31.0424 4668 ============================================================
12:18:31.0549 4668 C: <-> \Device\Harddisk0\DR0\Partition1
12:18:31.0689 4668 D: <-> \Device\Harddisk0\DR0\Partition2
12:18:31.0689 4668 ============================================================
12:18:31.0689 4668 Initialize success
12:18:31.0689 4668 ============================================================
12:18:33.0686 3504 ============================================================
12:18:33.0686 3504 Scan started
12:18:33.0686 3504 Mode: Manual;
12:18:33.0686 3504 ============================================================
12:18:34.0279 3504 ================ Scan system memory ========================
12:18:34.0279 3504 System memory - ok
12:18:34.0279 3504 ================ Scan services =============================
12:18:35.0215 3504 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
12:18:35.0230 3504 ACPI - ok
12:18:35.0293 3504 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
12:18:35.0324 3504 adp94xx - ok
12:18:35.0355 3504 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
12:18:35.0371 3504 adpahci - ok
12:18:35.0386 3504 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
12:18:35.0386 3504 adpu160m - ok
12:18:35.0433 3504 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
12:18:35.0433 3504 adpu320 - ok
12:18:35.0464 3504 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:18:35.0464 3504 AeLookupSvc - ok
12:18:35.0480 3504 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
12:18:35.0496 3504 AFD - ok
12:18:35.0542 3504 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
12:18:35.0542 3504 agp440 - ok
12:18:35.0574 3504 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
12:18:35.0574 3504 aic78xx - ok
12:18:35.0589 3504 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
12:18:35.0589 3504 ALG - ok
12:18:35.0605 3504 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
12:18:35.0605 3504 aliide - ok
12:18:35.0714 3504 [ 50EBBB86E493BD9AB7DDF914A90EEF8E ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:18:35.0745 3504 AMD External Events Utility - ok
12:18:35.0792 3504 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
12:18:35.0792 3504 amdagp - ok
12:18:35.0808 3504 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
12:18:35.0808 3504 amdide - ok
12:18:35.0823 3504 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
12:18:35.0823 3504 AmdK7 - ok
12:18:35.0839 3504 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
12:18:35.0839 3504 AmdK8 - ok
12:18:36.0244 3504 [ 70EB74785AB7FC603FEF19D87B7A7946 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
12:18:36.0416 3504 amdkmdag - ok
12:18:36.0494 3504 [ BA99833BBDE9C4FF389FC8114FB14843 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
12:18:36.0510 3504 amdkmdap - ok
12:18:36.0556 3504 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
12:18:36.0556 3504 Appinfo - ok
12:18:36.0666 3504 [ 0FE769CAE5855B53C90E23F85E7E89FF ] AppMgmt C:\Windows\System32\appmgmts.dll
12:18:36.0666 3504 AppMgmt - ok
12:18:36.0697 3504 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
12:18:36.0697 3504 arc - ok
12:18:36.0775 3504 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
12:18:36.0775 3504 arcsas - ok
12:18:36.0806 3504 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:18:36.0806 3504 AsyncMac - ok
12:18:36.0822 3504 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
12:18:36.0822 3504 atapi - ok
12:18:36.0868 3504 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:18:36.0868 3504 AudioEndpointBuilder - ok
12:18:36.0868 3504 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
12:18:36.0884 3504 Audiosrv - ok
12:18:36.0900 3504 [ 502F1C30BD50B32D00CE4DCAECC3D3C7 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
12:18:36.0900 3504 b57nd60x - ok
12:18:37.0118 3504 [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
12:18:37.0118 3504 BcmSqlStartupSvc - ok
12:18:37.0149 3504 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
12:18:37.0149 3504 Beep - ok
12:18:37.0305 3504 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
12:18:37.0305 3504 BFE - ok
12:18:37.0368 3504 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
12:18:37.0383 3504 BITS - ok
12:18:37.0399 3504 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
12:18:37.0446 3504 blbdrive - ok
12:18:37.0492 3504 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:18:37.0524 3504 bowser - ok
12:18:37.0555 3504 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
12:18:37.0555 3504 BrFiltLo - ok
12:18:37.0570 3504 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
12:18:37.0570 3504 BrFiltUp - ok
12:18:37.0711 3504 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
12:18:37.0726 3504 Browser - ok
12:18:37.0758 3504 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
12:18:37.0758 3504 Brserid - ok
12:18:37.0789 3504 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
12:18:37.0836 3504 BrSerWdm - ok
12:18:37.0867 3504 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
12:18:37.0867 3504 BrUsbMdm - ok
12:18:37.0882 3504 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
12:18:37.0882 3504 BrUsbSer - ok
12:18:37.0898 3504 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
12:18:37.0898 3504 BTHMODEM - ok
12:18:37.0929 3504 catchme - ok
12:18:37.0945 3504 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:18:37.0945 3504 cdfs - ok
12:18:37.0976 3504 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
12:18:37.0976 3504 cdrom - ok
12:18:38.0054 3504 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
12:18:38.0101 3504 CertPropSvc - ok
12:18:38.0132 3504 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
12:18:38.0132 3504 circlass - ok
12:18:38.0179 3504 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
12:18:38.0179 3504 CLFS - ok
12:18:38.0304 3504 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:18:38.0335 3504 clr_optimization_v2.0.50727_32 - ok
12:18:38.0382 3504 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:18:38.0382 3504 clr_optimization_v4.0.30319_32 - ok
12:18:38.0413 3504 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
12:18:38.0413 3504 cmdide - ok
12:18:38.0428 3504 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
12:18:38.0428 3504 Compbatt - ok
12:18:38.0428 3504 COMSysApp - ok
12:18:38.0475 3504 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
12:18:38.0475 3504 crcdisk - ok
12:18:38.0491 3504 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
12:18:38.0491 3504 Crusoe - ok
12:18:38.0553 3504 [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:18:38.0553 3504 CryptSvc - ok
12:18:38.0569 3504 [ 9BDB2E89BE8D0EF37B1F25C3D3FC192C ] CSC C:\Windows\system32\drivers\csc.sys
12:18:38.0569 3504 CSC - ok
12:18:38.0865 3504 [ 0A2095F92F6AE4FE6484D911B0C21E95 ] CscService C:\Windows\System32\cscsvc.dll
12:18:38.0896 3504 CscService - ok
12:18:39.0224 3504 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
12:18:39.0224 3504 DcomLaunch - ok
12:18:39.0302 3504 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
12:18:39.0302 3504 DfsC - ok
12:18:39.0380 3504 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
12:18:39.0411 3504 DFSR - ok
12:18:39.0458 3504 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
12:18:39.0458 3504 Dhcp - ok
12:18:39.0505 3504 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
12:18:39.0505 3504 disk - ok
12:18:39.0536 3504 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:18:39.0536 3504 Dnscache - ok
12:18:39.0567 3504 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
12:18:39.0583 3504 dot3svc - ok
12:18:39.0630 3504 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
12:18:39.0630 3504 DPS - ok
12:18:39.0661 3504 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:18:39.0661 3504 drmkaud - ok
12:18:39.0739 3504 [ FB38473835476A6FB272215A1D972AF9 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
12:18:39.0739 3504 dtsoftbus01 - ok
12:18:39.0864 3504 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:18:39.0864 3504 DXGKrnl - ok
12:18:40.0098 3504 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
12:18:40.0098 3504 E1G60 - ok
12:18:40.0176 3504 [ 668819862FFDE09028B975B74D376030 ] e1yexpress C:\Windows\system32\DRIVERS\e1y6032.sys
12:18:40.0176 3504 e1yexpress - ok
12:18:40.0254 3504 [ 8A45015E85A4DCE0086B9973F0FD9A20 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
12:18:40.0254 3504 eamonm - ok
12:18:40.0332 3504 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
12:18:40.0332 3504 EapHost - ok
12:18:40.0363 3504 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
12:18:40.0363 3504 Ecache - ok
12:18:40.0394 3504 [ 5412ED24FFFCA64E2F0168399B86C952 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
12:18:40.0394 3504 ehdrv - ok
12:18:41.0205 3504 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
12:18:41.0205 3504 ekrn - ok
12:18:41.0330 3504 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
12:18:41.0330 3504 elxstor - ok
12:18:41.0377 3504 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
12:18:41.0392 3504 EMDMgmt - ok
12:18:41.0408 3504 [ 0A587BB99A22F8DC3597471425D43314 ] epfwwfpr C:\Windows\system32\DRIVERS\epfwwfpr.sys
12:18:41.0470 3504 epfwwfpr - ok
12:18:41.0502 3504 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
12:18:41.0502 3504 ErrDev - ok
12:18:41.0564 3504 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
12:18:41.0564 3504 EventSystem - ok
12:18:41.0611 3504 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
12:18:41.0642 3504 exfat - ok
12:18:41.0689 3504 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:18:41.0689 3504 fastfat - ok
12:18:42.0016 3504 [ DFBA0F60FA301E5B1BFB1403A93EE23E ] Fax C:\Windows\system32\fxssvc.exe
12:18:42.0063 3504 Fax - ok
12:18:42.0188 3504 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
12:18:42.0188 3504 fdc - ok
12:18:42.0266 3504 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
12:18:42.0266 3504 fdPHost - ok
12:18:42.0344 3504 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
12:18:42.0344 3504 FDResPub - ok
12:18:42.0360 3504 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:18:42.0360 3504 FileInfo - ok
12:18:42.0375 3504 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:18:42.0375 3504 Filetrace - ok
12:18:42.0391 3504 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
12:18:42.0391 3504 flpydisk - ok
12:18:42.0406 3504 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:18:42.0406 3504 FltMgr - ok
12:18:42.0453 3504 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
12:18:42.0469 3504 FontCache - ok
12:18:42.0609 3504 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
12:18:42.0609 3504 FontCache3.0.0.0 - ok
12:18:42.0734 3504 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:18:42.0750 3504 Fs_Rec - ok
12:18:42.0874 3504 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
12:18:42.0921 3504 gagp30kx - ok
12:18:42.0968 3504 [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
12:18:42.0968 3504 ggflt - ok
12:18:42.0984 3504 [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
12:18:42.0984 3504 ggsemc - ok
12:18:43.0374 3504 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
12:18:43.0374 3504 gpsvc - ok
12:18:43.0545 3504 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
12:18:43.0545 3504 gupdate - ok
12:18:43.0545 3504 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
12:18:43.0545 3504 gupdatem - ok
12:18:43.0670 3504 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:18:43.0701 3504 HdAudAddService - ok
12:18:43.0748 3504 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
12:18:43.0764 3504 HDAudBus - ok
12:18:43.0810 3504 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
12:18:43.0810 3504 HidBth - ok
12:18:43.0826 3504 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
12:18:43.0826 3504 HidIr - ok
12:18:43.0888 3504 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
12:18:43.0888 3504 hidserv - ok
12:18:43.0966 3504 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
12:18:43.0966 3504 HidUsb - ok
12:18:44.0091 3504 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:18:44.0122 3504 hkmsvc - ok
12:18:44.0154 3504 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
12:18:44.0154 3504 HpCISSs - ok
12:18:44.0185 3504 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:18:44.0200 3504 HTTP - ok
12:18:44.0247 3504 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
12:18:44.0247 3504 i2omp - ok
12:18:44.0310 3504 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
12:18:44.0310 3504 i8042prt - ok
12:18:44.0325 3504 [ 42BE6406094936A23280D68D9AEC33D0 ] iaStor C:\Windows\system32\drivers\iastor.sys
12:18:44.0325 3504 iaStor - ok
12:18:44.0419 3504 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
12:18:44.0419 3504 iaStorV - ok
12:18:45.0027 3504 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:18:45.0058 3504 idsvc - ok
12:18:45.0121 3504 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
12:18:45.0121 3504 iirsp - ok
12:18:45.0386 3504 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
12:18:45.0386 3504 IKEEXT - ok
12:18:45.0542 3504 [ 0E70E4485F0ED782248E26353A08D312 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
12:18:45.0573 3504 IntcAzAudAddService - ok
12:18:45.0620 3504 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
12:18:45.0620 3504 intelide - ok
12:18:45.0651 3504 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
12:18:45.0651 3504 intelppm - ok
12:18:45.0682 3504 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
12:18:45.0682 3504 IPBusEnum - ok
12:18:45.0698 3504 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:18:45.0698 3504 IpFilterDriver - ok
12:18:45.0745 3504 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:18:45.0776 3504 iphlpsvc - ok
12:18:45.0807 3504 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
12:18:45.0807 3504 IPMIDRV - ok
12:18:45.0838 3504 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
12:18:45.0838 3504 IPNAT - ok
12:18:45.0916 3504 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:18:45.0948 3504 IRENUM - ok
12:18:45.0994 3504 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
12:18:45.0994 3504 isapnp - ok
12:18:46.0119 3504 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
12:18:46.0119 3504 iScsiPrt - ok
12:18:46.0213 3504 [ 76F9267AB1223A5EA5230625A0031BDC ] IT9135BDA C:\Windows\system32\Drivers\IT9135BDA.sys
12:18:46.0213 3504 IT9135BDA - ok
12:18:46.0260 3504 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
12:18:46.0291 3504 iteatapi - ok
12:18:46.0322 3504 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
12:18:46.0322 3504 iteraid - ok
12:18:46.0353 3504 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
12:18:46.0353 3504 kbdclass - ok
12:18:46.0369 3504 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
12:18:46.0369 3504 kbdhid - ok
12:18:46.0416 3504 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
12:18:46.0416 3504 KeyIso - ok
12:18:46.0759 3504 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:18:46.0759 3504 KSecDD - ok
12:18:47.0008 3504 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
12:18:47.0040 3504 KtmRm - ok
12:18:47.0102 3504 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
12:18:47.0102 3504 LanmanServer - ok
12:18:47.0118 3504 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:18:47.0118 3504 LanmanWorkstation - ok
12:18:47.0274 3504 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:18:47.0274 3504 lltdio - ok
12:18:47.0398 3504 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:18:47.0398 3504 lltdsvc - ok
12:18:47.0414 3504 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:18:47.0414 3504 lmhosts - ok
12:18:47.0461 3504 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
12:18:47.0461 3504 LSI_FC - ok
12:18:47.0523 3504 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
12:18:47.0554 3504 LSI_SAS - ok
12:18:47.0586 3504 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
12:18:47.0586 3504 LSI_SCSI - ok
12:18:47.0617 3504 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
12:18:47.0648 3504 luafv - ok
12:18:47.0710 3504 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
12:18:47.0742 3504 MBAMProtector - ok
12:18:47.0835 3504 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
12:18:47.0835 3504 MBAMService - ok
12:18:47.0929 3504 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
12:18:47.0960 3504 megasas - ok
12:18:47.0991 3504 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
12:18:47.0991 3504 MegaSR - ok
12:18:48.0038 3504 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
12:18:48.0038 3504 MMCSS - ok
12:18:48.0054 3504 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
12:18:48.0054 3504 Modem - ok
12:18:48.0132 3504 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:18:48.0132 3504 monitor - ok
12:18:48.0210 3504 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
12:18:48.0210 3504 mouclass - ok
12:18:48.0334 3504 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
12:18:48.0366 3504 mouhid - ok
12:18:48.0381 3504 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
12:18:48.0397 3504 MountMgr - ok
12:18:48.0459 3504 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
12:18:48.0459 3504 MozillaMaintenance - ok
12:18:48.0490 3504 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
12:18:48.0490 3504 mpio - ok
12:18:48.0522 3504 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:18:48.0522 3504 mpsdrv - ok
12:18:48.0818 3504 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
12:18:48.0849 3504 MpsSvc - ok
12:18:48.0896 3504 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
12:18:48.0912 3504 Mraid35x - ok
12:18:48.0927 3504 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:18:48.0927 3504 MRxDAV - ok
12:18:48.0943 3504 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:18:48.0943 3504 mrxsmb - ok
12:18:48.0958 3504 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:18:48.0958 3504 mrxsmb10 - ok
12:18:49.0036 3504 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:18:49.0036 3504 mrxsmb20 - ok
12:18:49.0130 3504 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
12:18:49.0130 3504 msahci - ok
12:18:49.0192 3504 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
12:18:49.0192 3504 msdsm - ok
12:18:49.0302 3504 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
12:18:49.0348 3504 MSDTC - ok
12:18:49.0380 3504 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:18:49.0380 3504 Msfs - ok
12:18:49.0411 3504 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
12:18:49.0411 3504 msisadrv - ok
12:18:49.0442 3504 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:18:49.0442 3504 MSiSCSI - ok
12:18:49.0458 3504 msiserver - ok
12:18:49.0489 3504 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:18:49.0489 3504 MSKSSRV - ok
12:18:49.0489 3504 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:18:49.0489 3504 MSPCLOCK - ok
12:18:49.0504 3504 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:18:49.0504 3504 MSPQM - ok
12:18:49.0520 3504 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:18:49.0520 3504 MsRPC - ok
12:18:49.0551 3504 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
12:18:49.0551 3504 mssmbios - ok
12:18:49.0879 3504 MSSQL$MSSMLBIZ - ok
12:18:50.0128 3504 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
12:18:50.0144 3504 MSSQLServerADHelper - ok
12:18:50.0175 3504 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:18:50.0175 3504 MSTEE - ok
12:18:50.0206 3504 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
12:18:50.0206 3504 Mup - ok
12:18:50.0238 3504 [ 03CA886BA148B6B9996BE1368DDC3FC0 ] NAL C:\Windows\system32\Drivers\iqvw32.sys
12:18:50.0238 3504 NAL - ok
12:18:50.0253 3504 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
12:18:50.0269 3504 napagent - ok
12:18:50.0347 3504 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:18:50.0347 3504 NativeWifiP - ok
12:18:50.0440 3504 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
12:18:50.0456 3504 NDIS - ok
12:18:50.0487 3504 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:18:50.0487 3504 NdisTapi - ok
12:18:50.0503 3504 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:18:50.0518 3504 Ndisuio - ok
12:18:50.0534 3504 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:18:50.0534 3504 NdisWan - ok
12:18:50.0550 3504 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:18:50.0550 3504 NDProxy - ok
12:18:50.0565 3504 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:18:50.0565 3504 NetBIOS - ok
12:18:50.0565 3504 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
12:18:50.0565 3504 netbt - ok
12:18:50.0581 3504 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
12:18:50.0581 3504 Netlogon - ok
12:18:50.0596 3504 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
12:18:50.0612 3504 Netman - ok
12:18:50.0628 3504 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
12:18:50.0628 3504 netprofm - ok
12:18:50.0674 3504 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:18:50.0674 3504 NetTcpPortSharing - ok
12:18:50.0721 3504 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
12:18:50.0752 3504 nfrd960 - ok
12:18:50.0784 3504 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:18:50.0784 3504 NlaSvc - ok
12:18:50.0815 3504 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:18:50.0815 3504 Npfs - ok
12:18:50.0893 3504 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
12:18:50.0924 3504 nsi - ok
12:18:50.0955 3504 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:18:50.0955 3504 nsiproxy - ok
12:18:51.0454 3504 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:18:51.0470 3504 Ntfs - ok
12:18:51.0501 3504 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
12:18:51.0501 3504 ntrigdigi - ok
12:18:51.0517 3504 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
12:18:51.0517 3504 Null - ok
12:18:51.0548 3504 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
12:18:51.0548 3504 nvraid - ok
12:18:51.0579 3504 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
12:18:51.0595 3504 nvstor - ok
12:18:51.0626 3504 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
12:18:51.0626 3504 nv_agp - ok
12:18:51.0735 3504 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:18:51.0751 3504 odserv - ok
12:18:51.0813 3504 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
12:18:51.0813 3504 ohci1394 - ok
12:18:51.0938 3504 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:18:51.0938 3504 ose - ok
12:18:51.0985 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
12:18:52.0000 3504 p2pimsvc - ok
12:18:52.0000 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
12:18:52.0016 3504 p2psvc - ok
12:18:52.0063 3504 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys
12:18:52.0078 3504 Parport - ok
12:18:52.0125 3504 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:18:52.0125 3504 partmgr - ok
12:18:52.0141 3504 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
12:18:52.0141 3504 Parvdm - ok
12:18:52.0156 3504 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
12:18:52.0156 3504 PcaSvc - ok
12:18:52.0188 3504 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
12:18:52.0188 3504 pci - ok
12:18:52.0297 3504 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
12:18:52.0328 3504 pciide - ok
12:18:52.0344 3504 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
12:18:52.0344 3504 pcmcia - ok
12:18:52.0390 3504 pdfcDispatcher - ok
12:18:52.0422 3504 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:18:52.0437 3504 PEAUTH - ok
12:18:52.0484 3504 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
12:18:52.0500 3504 pla - ok
12:18:52.0515 3504 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:18:52.0531 3504 PlugPlay - ok
12:18:52.0546 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
12:18:52.0546 3504 PNRPAutoReg - ok
12:18:52.0593 3504 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
12:18:52.0593 3504 PNRPsvc - ok
12:18:52.0812 3504 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:18:52.0843 3504 PolicyAgent - ok
12:18:52.0874 3504 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:18:52.0874 3504 PptpMiniport - ok
12:18:52.0890 3504 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
12:18:52.0905 3504 Processor - ok
12:18:52.0921 3504 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
12:18:52.0921 3504 ProfSvc - ok
12:18:52.0936 3504 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
12:18:52.0936 3504 ProtectedStorage - ok
12:18:52.0999 3504 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
12:18:52.0999 3504 PSched - ok
12:18:53.0046 3504 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
12:18:53.0046 3504 ql2300 - ok
12:18:53.0092 3504 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
12:18:53.0092 3504 ql40xx - ok
12:18:53.0248 3504 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
12:18:53.0295 3504 QWAVE - ok
12:18:53.0311 3504 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:18:53.0311 3504 QWAVEdrv - ok
12:18:53.0326 3504 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:18:53.0342 3504 RasAcd - ok
12:18:53.0342 3504 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
12:18:53.0342 3504 RasAuto - ok
12:18:53.0358 3504 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:18:53.0358 3504 Rasl2tp - ok
12:18:53.0389 3504 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
12:18:53.0389 3504 RasMan - ok
12:18:53.0404 3504 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:18:53.0404 3504 RasPppoe - ok
12:18:53.0404 3504 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:18:53.0404 3504 RasSstp - ok
12:18:53.0420 3504 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:18:53.0420 3504 rdbss - ok
12:18:53.0420 3504 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:18:53.0420 3504 RDPCDD - ok
12:18:53.0451 3504 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys
12:18:53.0451 3504 rdpdr - ok
12:18:53.0467 3504 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:18:53.0467 3504 RDPENCDD - ok
12:18:53.0514 3504 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:18:53.0545 3504 RDPWD - ok
12:18:53.0592 3504 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:18:53.0592 3504 RemoteAccess - ok
12:18:53.0607 3504 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:18:53.0607 3504 RemoteRegistry - ok
12:18:53.0623 3504 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
12:18:53.0623 3504 RpcLocator - ok
12:18:53.0638 3504 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
12:18:53.0654 3504 RpcSs - ok
12:18:53.0670 3504 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:18:53.0670 3504 rspndr - ok
12:18:53.0685 3504 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
12:18:53.0685 3504 SamSs - ok
12:18:53.0732 3504 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
12:18:53.0779 3504 sbp2port - ok
12:18:53.0826 3504 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:18:53.0826 3504 SCardSvr - ok
12:18:53.0857 3504 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
12:18:53.0857 3504 Schedule - ok
12:18:53.0857 3504 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
12:18:53.0857 3504 SCPolicySvc - ok
12:18:53.0888 3504 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:18:53.0888 3504 SDRSVC - ok
12:18:53.0888 3504 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:18:53.0904 3504 secdrv - ok
12:18:53.0904 3504 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
12:18:53.0904 3504 seclogon - ok
12:18:53.0919 3504 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
12:18:53.0919 3504 SENS - ok
12:18:53.0950 3504 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:18:53.0950 3504 Serenum - ok
12:18:53.0982 3504 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:18:53.0982 3504 Serial - ok
12:18:54.0028 3504 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
12:18:54.0044 3504 sermouse - ok
12:18:54.0075 3504 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
12:18:54.0075 3504 SessionEnv - ok
12:18:54.0122 3504 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
12:18:54.0122 3504 sffdisk - ok
12:18:54.0138 3504 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
12:18:54.0138 3504 sffp_mmc - ok
12:18:54.0138 3504 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
12:18:54.0138 3504 sffp_sd - ok
12:18:54.0153 3504 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
12:18:54.0153 3504 sfloppy - ok
12:18:54.0184 3504 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:18:54.0184 3504 SharedAccess - ok
12:18:54.0247 3504 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:18:54.0247 3504 ShellHWDetection - ok
12:18:54.0278 3504 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
12:18:54.0278 3504 sisagp - ok
12:18:54.0294 3504 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
12:18:54.0294 3504 SiSRaid2 - ok
12:18:54.0340 3504 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
12:18:54.0340 3504 SiSRaid4 - ok
12:18:54.0528 3504 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
12:18:54.0559 3504 slsvc - ok
12:18:54.0606 3504 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
12:18:54.0606 3504 SLUINotify - ok
12:18:54.0621 3504 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:18:54.0621 3504 Smb - ok
12:18:54.0637 3504 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:18:54.0652 3504 SNMPTRAP - ok
12:18:54.0668 3504 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
12:18:54.0668 3504 spldr - ok
12:18:54.0684 3504 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
12:18:54.0699 3504 Spooler - ok
12:18:54.0715 3504 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
12:18:54.0715 3504 SQLBrowser - ok
12:18:54.0746 3504 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
12:18:54.0746 3504 SQLWriter - ok
12:18:54.0777 3504 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:18:54.0777 3504 srv - ok
12:18:54.0793 3504 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:18:54.0793 3504 srv2 - ok
12:18:54.0840 3504 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:18:54.0840 3504 srvnet - ok
12:18:54.0918 3504 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:18:54.0918 3504 SSDPSRV - ok
12:18:54.0933 3504 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:18:54.0933 3504 SstpSvc - ok
12:18:54.0996 3504 [ EF70B3D22B4BFFDA6EA851ECB063EFAA ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
12:18:54.0996 3504 StillCam - ok
12:18:55.0027 3504 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
12:18:55.0027 3504 stisvc - ok
12:18:55.0058 3504 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
12:18:55.0058 3504 swenum - ok
12:18:55.0074 3504 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
12:18:55.0089 3504 swprv - ok
12:18:55.0136 3504 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
12:18:55.0136 3504 Symc8xx - ok
12:18:55.0152 3504 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
12:18:55.0152 3504 Sym_hi - ok
12:18:55.0167 3504 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
12:18:55.0167 3504 Sym_u3 - ok
12:18:55.0214 3504 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
12:18:55.0214 3504 SysMain - ok
12:18:55.0245 3504 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:18:55.0245 3504 TabletInputService - ok
12:18:55.0276 3504 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
12:18:55.0276 3504 TapiSrv - ok
12:18:55.0276 3504 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
12:18:55.0276 3504 TBS - ok
12:18:55.0354 3504 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:18:55.0370 3504 Tcpip - ok
12:18:55.0386 3504 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
12:18:55.0386 3504 Tcpip6 - ok
12:18:55.0401 3504 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:18:55.0401 3504 tcpipreg - ok
12:18:55.0448 3504 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:18:55.0448 3504 TDPIPE - ok
12:18:55.0464 3504 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:18:55.0464 3504 TDTCP - ok
12:18:55.0510 3504 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:18:55.0510 3504 tdx - ok
12:18:55.0526 3504 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
12:18:55.0526 3504 TermDD - ok
12:18:55.0557 3504 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
12:18:55.0557 3504 TermService - ok
12:18:55.0604 3504 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
12:18:55.0604 3504 Themes - ok
12:18:55.0635 3504 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
12:18:55.0635 3504 THREADORDER - ok
12:18:55.0666 3504 [ CB258C2F726F1BE73C507022BE33EBB3 ] TPM C:\Windows\system32\drivers\tpm.sys
12:18:55.0666 3504 TPM - ok
12:18:55.0698 3504 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
12:18:55.0698 3504 TrkWks - ok
12:18:55.0729 3504 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:18:55.0729 3504 TrustedInstaller - ok
12:18:55.0760 3504 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:18:55.0760 3504 tssecsrv - ok
12:18:55.0791 3504 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
12:18:55.0791 3504 tunmp - ok
12:18:55.0838 3504 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:18:55.0838 3504 tunnel - ok
12:18:55.0869 3504 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
12:18:55.0869 3504 uagp35 - ok
12:18:55.0916 3504 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:18:55.0916 3504 udfs - ok
12:18:55.0947 3504 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:18:55.0947 3504 UI0Detect - ok
12:18:55.0994 3504 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:18:55.0994 3504 uliagpkx - ok
12:18:56.0025 3504 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
12:18:56.0025 3504 uliahci - ok
12:18:56.0072 3504 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
12:18:56.0072 3504 UlSata - ok
12:18:56.0103 3504 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
12:18:56.0103 3504 ulsata2 - ok
12:18:56.0134 3504 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
12:18:56.0134 3504 umbus - ok
12:18:56.0134 3504 [ 8A66360F38F81E960E2367B428CBD5D9 ] UmRdpService C:\Windows\System32\umrdp.dll
12:18:56.0134 3504 UmRdpService - ok
12:18:56.0197 3504 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
12:18:56.0197 3504 upnphost - ok
12:18:56.0259 3504 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
12:18:56.0259 3504 usbaudio - ok
12:18:56.0275 3504 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:18:56.0275 3504 usbccgp - ok
12:18:56.0322 3504 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
12:18:56.0322 3504 usbcir - ok
12:18:56.0353 3504 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:18:56.0353 3504 usbehci - ok
12:18:56.0368 3504 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:18:56.0384 3504 usbhub - ok
12:18:56.0400 3504 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
12:18:56.0400 3504 usbohci - ok
12:18:56.0446 3504 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:18:56.0462 3504 usbprint - ok
12:18:56.0509 3504 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
12:18:56.0509 3504 usbscan - ok
12:18:56.0540 3504 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:18:56.0540 3504 USBSTOR - ok
12:18:56.0556 3504 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
12:18:56.0556 3504 usbuhci - ok
12:18:56.0587 3504 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
12:18:56.0587 3504 usbvideo - ok
12:18:56.0634 3504 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
12:18:56.0634 3504 UxSms - ok
12:18:56.0665 3504 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
12:18:56.0665 3504 vds - ok
12:18:56.0696 3504 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:18:56.0696 3504 vga - ok
12:18:56.0712 3504 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
12:18:56.0712 3504 VgaSave - ok
12:18:56.0743 3504 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
12:18:56.0743 3504 viaagp - ok
12:18:56.0758 3504 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
12:18:56.0758 3504 ViaC7 - ok
12:18:56.0774 3504 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
12:18:56.0774 3504 viaide - ok
12:18:56.0790 3504 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:18:56.0790 3504 volmgr - ok
12:18:56.0805 3504 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:18:56.0805 3504 volmgrx - ok
12:18:56.0836 3504 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:18:56.0836 3504 volsnap - ok
12:18:56.0868 3504 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
12:18:56.0868 3504 vsmraid - ok
12:18:56.0914 3504 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
12:18:56.0914 3504 VSS - ok
12:18:56.0930 3504 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
12:18:56.0946 3504 W32Time - ok
12:18:56.0961 3504 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
12:18:56.0961 3504 WacomPen - ok
12:18:56.0977 3504 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
12:18:56.0992 3504 Wanarp - ok
12:18:56.0992 3504 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:18:56.0992 3504 Wanarpv6 - ok
12:18:57.0008 3504 [ 20B23332885DFB93FE0185362EE811E9 ] wbengine C:\Windows\system32\wbengine.exe
12:18:57.0024 3504 wbengine - ok
12:18:57.0039 3504 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:18:57.0039 3504 wcncsvc - ok
12:18:57.0055 3504 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:18:57.0055 3504 WcsPlugInService - ok
12:18:57.0086 3504 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
12:18:57.0086 3504 Wd - ok
12:18:57.0117 3504 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:18:57.0117 3504 Wdf01000 - ok
12:18:57.0133 3504 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:18:57.0133 3504 WdiServiceHost - ok
12:18:57.0133 3504 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:18:57.0133 3504 WdiSystemHost - ok
12:18:57.0164 3504 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
12:18:57.0164 3504 WebClient - ok
12:18:57.0226 3504 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:18:57.0226 3504 Wecsvc - ok
12:18:57.0226 3504 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:18:57.0242 3504 wercplsupport - ok
12:18:57.0242 3504 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
12:18:57.0242 3504 WerSvc - ok
12:18:57.0273 3504 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
12:18:57.0289 3504 WinDefend - ok
12:18:57.0289 3504 WinHttpAutoProxySvc - ok
12:18:57.0336 3504 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:18:57.0336 3504 Winmgmt - ok
12:18:57.0367 3504 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
12:18:57.0382 3504 WinRM - ok
12:18:57.0445 3504 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
12:18:57.0460 3504 Wlansvc - ok
12:18:57.0492 3504 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
12:18:57.0492 3504 WmiAcpi - ok
12:18:57.0523 3504 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:18:57.0523 3504 wmiApSrv - ok
12:18:57.0570 3504 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
12:18:57.0570 3504 WMPNetworkSvc - ok
12:18:57.0601 3504 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:18:57.0601 3504 WPDBusEnum - ok
12:18:57.0663 3504 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:18:57.0679 3504 WPFFontCache_v0400 - ok
12:18:57.0710 3504 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:18:57.0710 3504 ws2ifsl - ok
12:18:57.0757 3504 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
12:18:57.0757 3504 wscsvc - ok
12:18:57.0757 3504 WSearch - ok
12:18:57.0835 3504 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
12:18:57.0850 3504 wuauserv - ok
12:18:57.0897 3504 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:18:57.0897 3504 WUDFRd - ok
12:18:57.0913 3504 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:18:57.0913 3504 wudfsvc - ok
12:18:57.0944 3504 ================ Scan global ===============================
12:18:57.0991 3504 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
12:18:58.0022 3504 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
12:18:58.0038 3504 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
12:18:58.0053 3504 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
12:18:58.0069 3504 [Global] - ok
12:18:58.0069 3504 ================ Scan MBR ==================================
12:18:58.0084 3504 [ 92A0110A64C3262C5F5DF2032E989DCE ] \Device\Harddisk0\DR0
12:18:58.0272 3504 \Device\Harddisk0\DR0 - ok
12:18:58.0272 3504 ================ Scan VBR ==================================
12:18:58.0272 3504 [ 4348B0676D9527DAC5368AFE0D679CC0 ] \Device\Harddisk0\DR0\Partition1
12:18:58.0272 3504 \Device\Harddisk0\DR0\Partition1 - ok
12:18:58.0303 3504 [ D4781209DAD0F5096D9B6E6CAEC44566 ] \Device\Harddisk0\DR0\Partition2
12:18:58.0303 3504 \Device\Harddisk0\DR0\Partition2 - ok
12:18:58.0303 3504 ============================================================
12:18:58.0303 3504 Scan finished
12:18:58.0303 3504 ============================================================
12:18:58.0318 5756 Detected object count: 0
12:18:58.0318 5756 Actual detected object count: 0
12:19:07.0210 4912 Deinitialize success
Re: Odstranění Claro + kontrola logu
a eště ten log z ComboFix
ComboFix 12-08-22.03 - Standard 24.08.2012 12:42:02.2.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3582.2457 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\DEBUG.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-24 do 2012-08-24 )))))))))))))))))))))))))))))))
.
.
2012-08-24 10:47 . 2012-08-24 10:47 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-08-24 10:47 . 2012-08-24 10:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-24 09:58 . 2012-08-24 09:58 -------- d-----w- C:\f622229cfb5b32792188015ee46077
2012-08-21 14:36 . 2012-08-21 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-21 14:36 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-21 14:31 . 2012-08-01 22:51 7023536 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2EF97298-35AA-4E20-9D7B-F7569604A18E}\mpengine.dll
2012-08-20 14:40 . 2012-08-20 14:40 388096 ----a-r- c:\users\Standard\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-19 16:05 . 2012-08-19 16:23 -------- d-----w- c:\program files\PROTOTYPE 2
2012-08-19 09:48 . 2012-08-19 09:48 -------- d-----w- c:\program files\Microsoft Silverlight
2012-08-18 09:14 . 2012-08-18 09:17 -------- d-----w- c:\users\Standard\AppData\Roaming\Masque
2012-08-18 09:14 . 2012-08-18 09:14 -------- d-----w- c:\programdata\Masque
2012-08-17 07:46 . 2012-08-17 07:46 -------- d-----w- c:\program files\ESET
2012-08-15 03:26 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Apps
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Deployment
2012-08-10 10:28 . 2012-08-10 10:28 -------- d-----w- C:\655105609b22e1eb093711a4369c
2012-08-05 06:54 . 2012-08-05 06:54 -------- d-----w- c:\program files\Mafia II
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-12 08:55 . 2012-03-27 06:46 5842 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2012-06-24 14:42 . 2012-06-24 08:01 11099 ----a-w- c:\users\Standard\AppData\Roaming\TheHunterSettings_live.bin
2012-06-15 10:32 . 2012-06-11 15:28 283416 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-06-11 19:11 . 2011-12-23 11:05 283416 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-06-11 19:06 . 2012-06-11 15:23 138904 ----a-w- c:\users\Standard\AppData\Roaming\PnkBstrK.sys
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 16:47 . 2012-07-11 14:03 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-11 14:03 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-11 14:03 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-23 06:34 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 06:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 06:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 06:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-23 06:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-23 06:34 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-23 06:34 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-23 06:34 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-23 06:34 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-11 14:03 278528 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-11 14:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-05-31 10:25 . 2011-06-30 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-18 15:57 . 2012-05-07 02:48 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-27 742264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-04-07 318488]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-06-30 74752]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-02-26 295728]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003UA.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 15:07]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 15:07]
.
.
------- Doplňkový sken -------
.
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10011
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.search.selectedEngine - Claro Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://isearch.claro-search.com/?affID= ... 4230147&q=
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113480
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.hardId - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15493
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1714:08
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.claro.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.claro.instlDay - 15567
FF - user.js: extensions.claro.vrsn - 1.6.4.1
FF - user.js: extensions.claro.vrsni - 1.6.4.1
FF - user.js: extensions.claro_i.vrsnTs - 1.6.4.118:48
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - iclaro
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-24 12:48
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:73,c9,e9,0c,4d,8d,a4,7d,4d,f2,f4,13,1a,12,49,17,0a,e7,a2,18,ce,
53,62,a4,6e,17,74,91,b4,90,42,fa,86,88,79,95,bf,81,5d,92,7e,96,3a,61,31,e0,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
Celkový čas: 2012-08-24 12:50:13
ComboFix-quarantined-files.txt 2012-08-24 10:50
ComboFix2.txt 2012-03-18 14:00
ComboFix3.txt 2012-03-18 12:29
ComboFix4.txt 2012-03-18 09:33
.
Před spuštěním: Volných bajtů: 141 798 035 456
Po spuštění: Volných bajtů: 142 183 354 368
.
- - End Of File - - 3D6673F116F7E68651A7999F4BA5078F
ComboFix 12-08-22.03 - Standard 24.08.2012 12:42:02.2.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3582.2457 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\DEBUG.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-24 do 2012-08-24 )))))))))))))))))))))))))))))))
.
.
2012-08-24 10:47 . 2012-08-24 10:47 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-08-24 10:47 . 2012-08-24 10:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-24 09:58 . 2012-08-24 09:58 -------- d-----w- C:\f622229cfb5b32792188015ee46077
2012-08-21 14:36 . 2012-08-21 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-21 14:36 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-21 14:31 . 2012-08-01 22:51 7023536 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2EF97298-35AA-4E20-9D7B-F7569604A18E}\mpengine.dll
2012-08-20 14:40 . 2012-08-20 14:40 388096 ----a-r- c:\users\Standard\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-19 16:05 . 2012-08-19 16:23 -------- d-----w- c:\program files\PROTOTYPE 2
2012-08-19 09:48 . 2012-08-19 09:48 -------- d-----w- c:\program files\Microsoft Silverlight
2012-08-18 09:14 . 2012-08-18 09:17 -------- d-----w- c:\users\Standard\AppData\Roaming\Masque
2012-08-18 09:14 . 2012-08-18 09:14 -------- d-----w- c:\programdata\Masque
2012-08-17 07:46 . 2012-08-17 07:46 -------- d-----w- c:\program files\ESET
2012-08-15 03:26 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Apps
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Deployment
2012-08-10 10:28 . 2012-08-10 10:28 -------- d-----w- C:\655105609b22e1eb093711a4369c
2012-08-05 06:54 . 2012-08-05 06:54 -------- d-----w- c:\program files\Mafia II
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-12 08:55 . 2012-03-27 06:46 5842 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2012-06-24 14:42 . 2012-06-24 08:01 11099 ----a-w- c:\users\Standard\AppData\Roaming\TheHunterSettings_live.bin
2012-06-15 10:32 . 2012-06-11 15:28 283416 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-06-11 19:11 . 2011-12-23 11:05 283416 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-06-11 19:06 . 2012-06-11 15:23 138904 ----a-w- c:\users\Standard\AppData\Roaming\PnkBstrK.sys
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 16:47 . 2012-07-11 14:03 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-11 14:03 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-11 14:03 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-23 06:34 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 06:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 06:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 06:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-23 06:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-23 06:34 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-23 06:34 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-23 06:34 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-23 06:34 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-11 14:03 278528 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-11 14:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-05-31 10:25 . 2011-06-30 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-18 15:57 . 2012-05-07 02:48 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-27 742264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-04-07 318488]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-06-30 74752]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-02-26 295728]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003UA.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 15:07]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 15:07]
.
.
------- Doplňkový sken -------
.
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10011
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.search.selectedEngine - Claro Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://isearch.claro-search.com/?affID= ... 4230147&q=
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113480
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.hardId - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15493
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1714:08
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.claro.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.claro.instlDay - 15567
FF - user.js: extensions.claro.vrsn - 1.6.4.1
FF - user.js: extensions.claro.vrsni - 1.6.4.1
FF - user.js: extensions.claro_i.vrsnTs - 1.6.4.118:48
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - iclaro
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-24 12:48
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:73,c9,e9,0c,4d,8d,a4,7d,4d,f2,f4,13,1a,12,49,17,0a,e7,a2,18,ce,
53,62,a4,6e,17,74,91,b4,90,42,fa,86,88,79,95,bf,81,5d,92,7e,96,3a,61,31,e0,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
Celkový čas: 2012-08-24 12:50:13
ComboFix-quarantined-files.txt 2012-08-24 10:50
ComboFix2.txt 2012-03-18 14:00
ComboFix3.txt 2012-03-18 12:29
ComboFix4.txt 2012-03-18 09:33
.
Před spuštěním: Volných bajtů: 141 798 035 456
Po spuštění: Volných bajtů: 142 183 354 368
.
- - End Of File - - 3D6673F116F7E68651A7999F4BA5078F
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Odstranění Claro + kontrola logu
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
DirLook::
C:\f622229cfb5b32792188015ee46077
C:\655105609b22e1eb093711a4369c
Folder::
c:\program files\Google\Update
File::
c:\windows\system32\PerfStringBackup.TMP
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003UA.job
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
DDS::
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10011
Firefox::
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.search.selectedEngine - Claro Search
FF - prefs.js: keyword.URL - hxxp://isearch.claro-search.com/?affID= ... 4230147&q=
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113480
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.hardId - 7e3ada3c000000000000002264230147
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15493
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1714:08
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.claro.id - 7e3ada3c000000000000002264230147
FF - user.js: extensions.claro.instlDay - 15567
FF - user.js: extensions.claro.vrsn - 1.6.4.1
FF - user.js: extensions.claro.vrsni - 1.6.4.1
FF - user.js: extensions.claro_i.vrsnTs - 1.6.4.118:48
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - iclaro
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Odstranění Claro + kontrola logu
ComboFix 12-08-25.01 - Standard 25.08.2012 8:15.2.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3582.2416 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Standard\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\PerfStringBackup.TMP"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.115\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.115\goopdate.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.115\psmachine.dll
c:\program files\Google\Update\1.3.21.115\psuser.dll
c:\program files\Google\Update\Download\{3DF95965-E589-4FAF-978A-5B79B98532B9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\21.0.1180.83\21.0.1180.83_21.0.1180.79_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\system32\PerfStringBackup.TMP
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-25 do 2012-08-25 )))))))))))))))))))))))))))))))
.
.
2012-08-25 06:20 . 2012-08-25 06:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-08-25 06:20 . 2012-08-25 06:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-24 09:58 . 2012-08-24 09:58 -------- d-----w- C:\f622229cfb5b32792188015ee46077
2012-08-21 14:36 . 2012-08-21 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-21 14:36 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-21 14:31 . 2012-08-01 22:51 7023536 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2EF97298-35AA-4E20-9D7B-F7569604A18E}\mpengine.dll
2012-08-20 14:40 . 2012-08-20 14:40 388096 ----a-r- c:\users\Standard\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-19 16:05 . 2012-08-19 16:23 -------- d-----w- c:\program files\PROTOTYPE 2
2012-08-19 09:48 . 2012-08-19 09:48 -------- d-----w- c:\program files\Microsoft Silverlight
2012-08-18 09:14 . 2012-08-18 09:17 -------- d-----w- c:\users\Standard\AppData\Roaming\Masque
2012-08-18 09:14 . 2012-08-18 09:14 -------- d-----w- c:\programdata\Masque
2012-08-17 07:46 . 2012-08-17 07:46 -------- d-----w- c:\program files\ESET
2012-08-15 03:26 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Apps
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Deployment
2012-08-10 10:28 . 2012-08-10 10:28 -------- d-----w- C:\655105609b22e1eb093711a4369c
2012-08-05 06:54 . 2012-08-05 06:54 -------- d-----w- c:\program files\Mafia II
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-24 14:42 . 2012-06-24 08:01 11099 ----a-w- c:\users\Standard\AppData\Roaming\TheHunterSettings_live.bin
2012-06-15 10:32 . 2012-06-11 15:28 283416 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-06-11 19:11 . 2011-12-23 11:05 283416 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-06-11 19:06 . 2012-06-11 15:23 138904 ----a-w- c:\users\Standard\AppData\Roaming\PnkBstrK.sys
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 16:47 . 2012-07-11 14:03 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-11 14:03 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-11 14:03 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-23 06:34 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 06:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 06:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 06:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-23 06:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-23 06:34 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-23 06:34 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-23 06:34 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-23 06:34 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-11 14:03 278528 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-11 14:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-05-31 10:25 . 2011-06-30 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-18 15:57 . 2012-05-07 02:48 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\655105609b22e1eb093711a4369c ----
.
2012-08-10 10:28 . 2012-08-10 10:28 788 ---ha-w- c:\655105609b22e1eb093711a4369c\$shtdwn$.req
2012-08-09 17:02 . 2012-08-09 17:02 736824 ----a-w- c:\655105609b22e1eb093711a4369c\mpasdlta.vdm
2012-07-16 00:42 . 2012-07-16 00:42 14648352 ----a-w- c:\655105609b22e1eb093711a4369c\mpasbase.vdm
.
---- Directory of C:\f622229cfb5b32792188015ee46077 ----
.
2012-08-24 09:58 . 2012-08-24 09:58 387632 ----a-w- c:\f622229cfb5b32792188015ee46077\mpasdlta.vdm
2012-08-24 09:58 . 2012-08-24 09:58 788 ---ha-w- c:\f622229cfb5b32792188015ee46077\$shtdwn$.req
2012-08-23 18:50 . 2012-08-23 18:50 369610 ----a-w- c:\f622229cfb5b32792188015ee46077\1.133.47.0_to_1.133.277.0_mpasdlta.vdm._p
2012-05-31 10:25 . 2012-05-31 10:25 25696 ----a-w- c:\f622229cfb5b32792188015ee46077\MpMiniSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-27 742264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-04-07 318488]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-06-30 74752]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-02-26 295728]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003UA.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
.
------- Doplňkový sken -------
.
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-25 08:21
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:73,c9,e9,0c,4d,8d,a4,7d,4d,f2,f4,13,1a,12,49,17,0a,e7,a2,18,ce,
53,62,a4,6e,17,74,91,b4,90,42,fa,86,88,79,95,bf,81,5d,92,7e,96,3a,61,31,e0,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\windows\System32\lpksetup.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\PDF Complete\pdfsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\WUDFHost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Celkový čas: 2012-08-25 08:27:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-25 06:27
ComboFix2.txt 2012-08-24 10:50
ComboFix3.txt 2012-03-18 14:00
ComboFix4.txt 2012-03-18 12:29
ComboFix5.txt 2012-08-25 06:12
.
Před spuštěním: Volných bajtů: 142 914 297 856
Po spuštění: Volných bajtů: 142 696 841 216
.
- - End Of File - - 51BD575C6932F113008F4DFC11D529ED
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3582.2416 [GMT 2:00]
Spuštěný z: c:\users\Standard\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Standard\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Disabled/Outdated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\PerfStringBackup.TMP"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.115\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.115\goopdate.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.115\psmachine.dll
c:\program files\Google\Update\1.3.21.115\psuser.dll
c:\program files\Google\Update\Download\{3DF95965-E589-4FAF-978A-5B79B98532B9}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\21.0.1180.83\21.0.1180.83_21.0.1180.79_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\system32\PerfStringBackup.TMP
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003Core.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-25 do 2012-08-25 )))))))))))))))))))))))))))))))
.
.
2012-08-25 06:20 . 2012-08-25 06:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-08-25 06:20 . 2012-08-25 06:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-24 09:58 . 2012-08-24 09:58 -------- d-----w- C:\f622229cfb5b32792188015ee46077
2012-08-21 14:36 . 2012-08-21 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-21 14:36 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-21 14:31 . 2012-08-01 22:51 7023536 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2EF97298-35AA-4E20-9D7B-F7569604A18E}\mpengine.dll
2012-08-20 14:40 . 2012-08-20 14:40 388096 ----a-r- c:\users\Standard\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-19 16:05 . 2012-08-19 16:23 -------- d-----w- c:\program files\PROTOTYPE 2
2012-08-19 09:48 . 2012-08-19 09:48 -------- d-----w- c:\program files\Microsoft Silverlight
2012-08-18 09:14 . 2012-08-18 09:17 -------- d-----w- c:\users\Standard\AppData\Roaming\Masque
2012-08-18 09:14 . 2012-08-18 09:14 -------- d-----w- c:\programdata\Masque
2012-08-17 07:46 . 2012-08-17 07:46 -------- d-----w- c:\program files\ESET
2012-08-15 03:26 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Apps
2012-08-14 13:51 . 2012-08-14 13:51 -------- d-----w- c:\users\Standard\AppData\Local\Deployment
2012-08-10 10:28 . 2012-08-10 10:28 -------- d-----w- C:\655105609b22e1eb093711a4369c
2012-08-05 06:54 . 2012-08-05 06:54 -------- d-----w- c:\program files\Mafia II
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-24 14:42 . 2012-06-24 08:01 11099 ----a-w- c:\users\Standard\AppData\Roaming\TheHunterSettings_live.bin
2012-06-15 10:32 . 2012-06-11 15:28 283416 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-06-11 19:11 . 2011-12-23 11:05 283416 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-06-11 19:06 . 2012-06-11 15:23 138904 ----a-w- c:\users\Standard\AppData\Roaming\PnkBstrK.sys
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 16:47 . 2012-07-11 14:03 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-11 14:03 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-11 14:03 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-23 06:34 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-23 06:34 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-23 06:34 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-23 06:34 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-23 06:34 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-23 06:34 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-23 06:34 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-23 06:34 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-23 06:34 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 00:04 . 2012-07-11 14:03 278528 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-11 14:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-05-31 10:25 . 2011-06-30 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-18 15:57 . 2012-05-07 02:48 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\655105609b22e1eb093711a4369c ----
.
2012-08-10 10:28 . 2012-08-10 10:28 788 ---ha-w- c:\655105609b22e1eb093711a4369c\$shtdwn$.req
2012-08-09 17:02 . 2012-08-09 17:02 736824 ----a-w- c:\655105609b22e1eb093711a4369c\mpasdlta.vdm
2012-07-16 00:42 . 2012-07-16 00:42 14648352 ----a-w- c:\655105609b22e1eb093711a4369c\mpasbase.vdm
.
---- Directory of C:\f622229cfb5b32792188015ee46077 ----
.
2012-08-24 09:58 . 2012-08-24 09:58 387632 ----a-w- c:\f622229cfb5b32792188015ee46077\mpasdlta.vdm
2012-08-24 09:58 . 2012-08-24 09:58 788 ---ha-w- c:\f622229cfb5b32792188015ee46077\$shtdwn$.req
2012-08-23 18:50 . 2012-08-23 18:50 369610 ----a-w- c:\f622229cfb5b32792188015ee46077\1.133.47.0_to_1.133.277.0_mpasdlta.vdm._p
2012-05-31 10:25 . 2012-05-31 10:25 25696 ----a-w- c:\f622229cfb5b32792188015ee46077\MpMiniSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-27 742264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-04-07 318488]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-06-30 74752]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-02-26 295728]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-626282612-4174701310-2186174446-1003]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-626282612-4174701310-2186174446-1003UA.job
- c:\users\Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-29 15:41]
.
.
------- Doplňkový sken -------
.
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-25 08:21
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-626282612-4174701310-2186174446-1003\Software\SecuROM\License information*]
"datasecu"=hex:73,c9,e9,0c,4d,8d,a4,7d,4d,f2,f4,13,1a,12,49,17,0a,e7,a2,18,ce,
53,62,a4,6e,17,74,91,b4,90,42,fa,86,88,79,95,bf,81,5d,92,7e,96,3a,61,31,e0,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\windows\System32\lpksetup.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\PDF Complete\pdfsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\WUDFHost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Celkový čas: 2012-08-25 08:27:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-25 06:27
ComboFix2.txt 2012-08-24 10:50
ComboFix3.txt 2012-03-18 14:00
ComboFix4.txt 2012-03-18 12:29
ComboFix5.txt 2012-08-25 06:12
.
Před spuštěním: Volných bajtů: 142 914 297 856
Po spuštění: Volných bajtů: 142 696 841 216
.
- - End Of File - - 51BD575C6932F113008F4DFC11D529ED
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Odstranění Claro + kontrola logu
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš
pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG , Avast,Avira či Microsoft Security Essentials následně T-Cleaner smaž a zapni si AVG , Avast, Avira či Microsoft Security Essentials
+ Nový log z HJT
Jak se chová PC?
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš
pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG , Avast,Avira či Microsoft Security Essentials následně T-Cleaner smaž a zapni si AVG , Avast, Avira či Microsoft Security Essentials
+ Nový log z HJT
Jak se chová PC?
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Odstranění Claro + kontrola logu
po použití T-Cleaner mi to najde v Pc položku C:\Windows\nircmd.exe. nepomáhá když to odsouhlasím a nebo dám N.. a pc je oněco rychlejší ale hned po dnešním startu sde mi hned x zaseknul a následně mi to vyhodilo modrou obrazovku s textem..Collecting data for crash dump... Cnitialozing disk for crash dump... .A ComboFix nejde odinstalovat.píše mi to že nebyla nalezena složka s ComboFixem.A to Claro mi v Pc straší furt..
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:28:26, on 27.8.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Standard\Downloads\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11g_Plugin.exe -update plugin
O4 - Startup: Facebook Messenger.lnk = C:\Users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
--
End of file - 4561 bytes
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:28:26, on 27.8.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Standard\Downloads\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil11g_Plugin.exe -update plugin
O4 - Startup: Facebook Messenger.lnk = C:\Users\Standard\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
--
End of file - 4561 bytes
Kdo je online
Uživatelé prohlížející si toto fórum: Google [Bot] a 54 hostů