Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 13:57

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:56:31, on 18.11.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19328)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\matej\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ZyngaGamesAgent] "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [STCAgent] "C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Splashtop Connect Service (SCBackService) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Connect\BackService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Splashtop Connect Firefox Software Updater Service (WCUService_STC_FF) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe

--
End of file - 5937 bytes

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Žbeky » 18 lis 2012 14:01

Problémy?

Fixni:

Kód: Vybrat vše

O4 - HKLM\..\Run: [ZyngaGamesAgent] "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 14:18

PC je zpomalené, zdá se mi, že se pomaleji vypíná i zapíná.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.11.18.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19328
matej :: MATEJ-PC [administrátor]

18.11.2012 14:11:42
mbam-log-2012-11-18 (14-15-44).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 191242
Uplynulý čas: 3 minut, 33 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Žádná instrukce nebyla provedena.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Orcus » 18 lis 2012 15:59

Znovu spusť MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

====================================================

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

====================================================

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 17:12

Mbam

Ty položky jsem smazal.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.11.18.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19328
matej :: MATEJ-PC [administrátor]

18.11.2012 17:07:19
mbam-log-2012-11-18 (17-07-19).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 191257
Uplynulý čas: 3 minut,

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Umístnění do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 17:18

TDSSKiller


17:13:47.0444 5980 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:13:47.0616 5980 ============================================================
17:13:47.0616 5980 Current date / time: 2012/11/18 17:13:47.0616
17:13:47.0616 5980 SystemInfo:
17:13:47.0616 5980
17:13:47.0616 5980 OS Version: 6.0.6002 ServicePack: 2.0
17:13:47.0616 5980 Product type: Workstation
17:13:47.0616 5980 ComputerName: MATEJ-PC
17:13:47.0616 5980 UserName: matej
17:13:47.0616 5980 Windows directory: C:\Windows
17:13:47.0616 5980 System windows directory: C:\Windows
17:13:47.0616 5980 Processor architecture: Intel x86
17:13:47.0616 5980 Number of processors: 2
17:13:47.0616 5980 Page size: 0x1000
17:13:47.0616 5980 Boot type: Normal boot
17:13:47.0616 5980 ============================================================
17:13:48.0739 5980 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:13:48.0770 5980 ============================================================
17:13:48.0770 5980 \Device\Harddisk0\DR0:
17:13:48.0770 5980 MBR partitions:
17:13:48.0770 5980 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
17:13:48.0770 5980 ============================================================
17:13:48.0801 5980 C: <-> \Device\Harddisk0\DR0\Partition1
17:13:48.0817 5980 ============================================================
17:13:48.0817 5980 Initialize success
17:13:48.0817 5980 ============================================================
17:13:55.0697 5792 ============================================================
17:13:55.0697 5792 Scan started
17:13:55.0697 5792 Mode: Manual;
17:13:55.0697 5792 ============================================================
17:13:56.0523 5792 ================ Scan system memory ========================
17:13:56.0523 5792 System memory - ok
17:13:56.0523 5792 ================ Scan services =============================
17:13:56.0679 5792 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
17:13:56.0679 5792 ACPI - ok
17:13:56.0711 5792 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:13:56.0726 5792 AdobeFlashPlayerUpdateSvc - ok
17:13:56.0757 5792 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
17:13:56.0773 5792 adp94xx - ok
17:13:56.0789 5792 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
17:13:56.0789 5792 adpahci - ok
17:13:56.0804 5792 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
17:13:56.0804 5792 adpu160m - ok
17:13:56.0820 5792 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
17:13:56.0820 5792 adpu320 - ok
17:13:56.0867 5792 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:13:56.0867 5792 AeLookupSvc - ok
17:13:56.0913 5792 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
17:13:56.0913 5792 AFD - ok
17:13:56.0945 5792 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
17:13:56.0945 5792 agp440 - ok
17:13:56.0976 5792 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
17:13:56.0976 5792 aic78xx - ok
17:13:56.0991 5792 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
17:13:57.0007 5792 ALG - ok
17:13:57.0023 5792 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
17:13:57.0023 5792 aliide - ok
17:13:57.0147 5792 ALSysIO - ok
17:13:57.0194 5792 [ AEFEEE2E852F2774A4491C8EFA6C3B6E ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:13:57.0194 5792 AMD External Events Utility - ok
17:13:57.0210 5792 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:13:57.0210 5792 amdagp - ok
17:13:57.0225 5792 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
17:13:57.0225 5792 amdide - ok
17:13:57.0257 5792 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
17:13:57.0257 5792 AmdK7 - ok
17:13:57.0288 5792 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:13:57.0303 5792 AmdK8 - ok
17:13:57.0615 5792 [ D05CF4523E0C04EF82454ABFD84FDC1D ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:13:57.0662 5792 amdkmdag - ok
17:13:57.0678 5792 [ 92DC2E0AE49148F83B24D89C737B0C97 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
17:13:57.0678 5792 amdkmdap - ok
17:13:57.0725 5792 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
17:13:57.0725 5792 Appinfo - ok
17:13:57.0771 5792 [ F5F0F78286A849BC0E45E0E99065B04F ] AppleCharger C:\Windows\system32\DRIVERS\AppleCharger.sys
17:13:57.0771 5792 AppleCharger - ok
17:13:57.0787 5792 [ 95EF7247C50C7241FDAE39A9B3AFF4AE ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe
17:13:57.0787 5792 AppleChargerSrv - ok
17:13:57.0834 5792 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
17:13:57.0834 5792 arc - ok
17:13:57.0865 5792 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
17:13:57.0865 5792 arcsas - ok
17:13:57.0912 5792 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
17:13:57.0912 5792 aswFsBlk - ok
17:13:57.0943 5792 [ 62F9DCEC95F91B8E0203E85D344A7E65 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:13:57.0943 5792 aswMonFlt - ok
17:13:57.0959 5792 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
17:13:57.0959 5792 aswRdr - ok
17:13:58.0005 5792 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:13:58.0005 5792 aswSnx - ok
17:13:58.0037 5792 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:13:58.0037 5792 aswSP - ok
17:13:58.0068 5792 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:13:58.0068 5792 aswTdi - ok
17:13:58.0099 5792 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:13:58.0099 5792 AsyncMac - ok
17:13:58.0130 5792 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
17:13:58.0130 5792 atapi - ok
17:13:58.0177 5792 [ 0C3C2E9136397E1AAA9033DCAE25CED2 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdLH3.sys
17:13:58.0177 5792 AtiHDAudioService - ok
17:13:58.0224 5792 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:13:58.0224 5792 AudioEndpointBuilder - ok
17:13:58.0224 5792 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:13:58.0224 5792 Audiosrv - ok
17:13:58.0302 5792 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:13:58.0302 5792 avast! Antivirus - ok
17:13:58.0333 5792 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
17:13:58.0333 5792 Beep - ok
17:13:58.0364 5792 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
17:13:58.0364 5792 BFE - ok
17:13:58.0411 5792 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
17:13:58.0411 5792 BITS - ok
17:13:58.0427 5792 blbdrive - ok
17:13:58.0442 5792 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:13:58.0442 5792 bowser - ok
17:13:58.0473 5792 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
17:13:58.0473 5792 BrFiltLo - ok
17:13:58.0489 5792 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
17:13:58.0489 5792 BrFiltUp - ok
17:13:58.0505 5792 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
17:13:58.0505 5792 Browser - ok
17:13:58.0536 5792 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
17:13:58.0536 5792 Brserid - ok
17:13:58.0551 5792 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
17:13:58.0551 5792 BrSerWdm - ok
17:13:58.0567 5792 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
17:13:58.0567 5792 BrUsbMdm - ok
17:13:58.0567 5792 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
17:13:58.0567 5792 BrUsbSer - ok
17:13:58.0598 5792 [ CC10AA1A0BFA24E3316833D4742C53E8 ] BT848 C:\Windows\system32\drivers\wf2kvcap.sys
17:13:58.0598 5792 BT848 - ok
17:13:58.0614 5792 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
17:13:58.0614 5792 BTHMODEM - ok
17:13:58.0645 5792 catchme - ok
17:13:58.0676 5792 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:13:58.0676 5792 cdfs - ok
17:13:58.0707 5792 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:13:58.0707 5792 cdrom - ok
17:13:58.0739 5792 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
17:13:58.0739 5792 CertPropSvc - ok
17:13:58.0754 5792 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
17:13:58.0754 5792 circlass - ok
17:13:58.0785 5792 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
17:13:58.0785 5792 CLFS - ok
17:13:58.0848 5792 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:13:58.0848 5792 clr_optimization_v2.0.50727_32 - ok
17:13:58.0910 5792 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:13:58.0926 5792 clr_optimization_v4.0.30319_32 - ok
17:13:58.0926 5792 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:13:58.0926 5792 cmdide - ok
17:13:58.0941 5792 [ 82B8C91D327CFECF76CB58716F7D4997 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
17:13:58.0941 5792 Compbatt - ok
17:13:58.0941 5792 COMSysApp - ok
17:13:58.0957 5792 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
17:13:58.0957 5792 crcdisk - ok
17:13:58.0973 5792 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
17:13:58.0973 5792 Crusoe - ok
17:13:59.0019 5792 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:13:59.0019 5792 CryptSvc - ok
17:13:59.0051 5792 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
17:13:59.0066 5792 DcomLaunch - ok
17:13:59.0082 5792 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:13:59.0082 5792 DfsC - ok
17:13:59.0144 5792 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
17:13:59.0175 5792 DFSR - ok
17:13:59.0222 5792 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
17:13:59.0222 5792 Dhcp - ok
17:13:59.0253 5792 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
17:13:59.0253 5792 disk - ok
17:13:59.0285 5792 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:13:59.0285 5792 Dnscache - ok
17:13:59.0300 5792 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
17:13:59.0316 5792 dot3svc - ok
17:13:59.0331 5792 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
17:13:59.0347 5792 DPS - ok
17:13:59.0363 5792 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:13:59.0363 5792 drmkaud - ok
17:13:59.0394 5792 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:13:59.0394 5792 DXGKrnl - ok
17:13:59.0425 5792 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
17:13:59.0425 5792 E1G60 - ok
17:13:59.0472 5792 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
17:13:59.0472 5792 EapHost - ok
17:13:59.0503 5792 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
17:13:59.0503 5792 Ecache - ok
17:13:59.0534 5792 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
17:13:59.0534 5792 elxstor - ok
17:13:59.0581 5792 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
17:13:59.0581 5792 EMDMgmt - ok
17:13:59.0612 5792 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
17:13:59.0612 5792 EventSystem - ok
17:13:59.0659 5792 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
17:13:59.0659 5792 exfat - ok
17:13:59.0706 5792 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:13:59.0706 5792 fastfat - ok
17:13:59.0753 5792 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:13:59.0753 5792 fdc - ok
17:13:59.0784 5792 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
17:13:59.0784 5792 fdPHost - ok
17:13:59.0799 5792 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
17:13:59.0815 5792 FDResPub - ok
17:13:59.0831 5792 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:13:59.0831 5792 FileInfo - ok
17:13:59.0862 5792 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:13:59.0862 5792 Filetrace - ok
17:13:59.0877 5792 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:13:59.0877 5792 flpydisk - ok
17:13:59.0909 5792 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:13:59.0924 5792 FltMgr - ok
17:13:59.0971 5792 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
17:13:59.0987 5792 FontCache - ok
17:14:00.0049 5792 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:14:00.0049 5792 FontCache3.0.0.0 - ok
17:14:00.0065 5792 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:14:00.0065 5792 Fs_Rec - ok
17:14:00.0096 5792 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
17:14:00.0096 5792 gagp30kx - ok
17:14:00.0143 5792 [ C6E3105B8C68C35CC1EB26A00FD1A8C6 ] gdrv C:\Windows\gdrv.sys
17:14:00.0143 5792 gdrv - ok
17:14:00.0158 5792 GMSIPCI - ok
17:14:00.0189 5792 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
17:14:00.0189 5792 gpsvc - ok
17:14:00.0236 5792 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:14:00.0236 5792 HdAudAddService - ok
17:14:00.0283 5792 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
17:14:00.0283 5792 HDAudBus - ok
17:14:00.0299 5792 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
17:14:00.0299 5792 HidBth - ok
17:14:00.0314 5792 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
17:14:00.0314 5792 HidIr - ok
17:14:00.0345 5792 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
17:14:00.0345 5792 hidserv - ok
17:14:00.0361 5792 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:14:00.0361 5792 HidUsb - ok
17:14:00.0377 5792 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:14:00.0377 5792 hkmsvc - ok
17:14:00.0408 5792 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
17:14:00.0408 5792 HpCISSs - ok
17:14:00.0439 5792 [ 0EEECA26C8D4BDE2A4664DB058A81937 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:14:00.0439 5792 HTTP - ok
17:14:00.0470 5792 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
17:14:00.0470 5792 i2omp - ok
17:14:00.0501 5792 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:14:00.0501 5792 i8042prt - ok
17:14:00.0533 5792 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
17:14:00.0533 5792 iaStorV - ok
17:14:00.0579 5792 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
17:14:00.0579 5792 IDriverT - ok
17:14:00.0642 5792 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:14:00.0657 5792 idsvc - ok
17:14:00.0704 5792 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
17:14:00.0720 5792 iirsp - ok
17:14:00.0751 5792 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
17:14:00.0751 5792 IKEEXT - ok
17:14:00.0876 5792 [ F179FEB1B15AAD94C6BF082C0356DF16 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
17:14:00.0891 5792 IntcAzAudAddService - ok
17:14:00.0954 5792 [ 97469037714070E45194ED318D636401 ] intelide C:\Windows\system32\drivers\intelide.sys
17:14:00.0954 5792 intelide - ok
17:14:01.0001 5792 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:14:01.0001 5792 intelppm - ok
17:14:01.0032 5792 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:14:01.0032 5792 IPBusEnum - ok
17:14:01.0063 5792 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:14:01.0063 5792 IpFilterDriver - ok
17:14:01.0079 5792 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:14:01.0079 5792 iphlpsvc - ok
17:14:01.0094 5792 IpInIp - ok
17:14:01.0110 5792 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
17:14:01.0110 5792 IPMIDRV - ok
17:14:01.0141 5792 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
17:14:01.0141 5792 IPNAT - ok
17:14:01.0172 5792 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:14:01.0172 5792 IRENUM - ok
17:14:01.0203 5792 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:14:01.0203 5792 isapnp - ok
17:14:01.0235 5792 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
17:14:01.0235 5792 iScsiPrt - ok
17:14:01.0266 5792 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
17:14:01.0266 5792 iteatapi - ok
17:14:01.0266 5792 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
17:14:01.0266 5792 iteraid - ok
17:14:01.0297 5792 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:14:01.0297 5792 kbdclass - ok
17:14:01.0328 5792 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
17:14:01.0328 5792 kbdhid - ok
17:14:01.0344 5792 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
17:14:01.0344 5792 KeyIso - ok
17:14:01.0391 5792 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:14:01.0391 5792 KSecDD - ok
17:14:01.0422 5792 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
17:14:01.0422 5792 KtmRm - ok
17:14:01.0453 5792 [ 3DB114D4729B8FF7FCF5801F9489CD2C ] L1C C:\Windows\system32\DRIVERS\L1C60x86.sys
17:14:01.0453 5792 L1C - ok
17:14:01.0484 5792 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
17:14:01.0484 5792 LanmanServer - ok
17:14:01.0515 5792 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:14:01.0515 5792 LanmanWorkstation - ok
17:14:01.0547 5792 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:14:01.0547 5792 lltdio - ok
17:14:01.0578 5792 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:14:01.0578 5792 lltdsvc - ok
17:14:01.0609 5792 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:14:01.0609 5792 lmhosts - ok
17:14:01.0656 5792 [ 0803906D607A9B83184447B75B60ECC2 ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
17:14:01.0656 5792 LMS - ok
17:14:01.0687 5792 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
17:14:01.0687 5792 LSI_FC - ok
17:14:01.0703 5792 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
17:14:01.0703 5792 LSI_SAS - ok
17:14:01.0718 5792 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
17:14:01.0718 5792 LSI_SCSI - ok
17:14:01.0749 5792 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
17:14:01.0749 5792 luafv - ok
17:14:01.0765 5792 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
17:14:01.0765 5792 megasas - ok
17:14:01.0796 5792 [ CFCB18986426A2D8E66F1992636221D0 ] MEI C:\Windows\system32\DRIVERS\HECI.sys
17:14:01.0796 5792 MEI - ok
17:14:01.0843 5792 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
17:14:01.0843 5792 Microsoft Office Groove Audit Service - ok
17:14:01.0874 5792 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
17:14:01.0874 5792 MMCSS - ok
17:14:01.0905 5792 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
17:14:01.0905 5792 Modem - ok
17:14:01.0921 5792 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:14:01.0921 5792 monitor - ok
17:14:01.0937 5792 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:14:01.0937 5792 mouclass - ok
17:14:01.0952 5792 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:14:01.0952 5792 mouhid - ok
17:14:01.0952 5792 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
17:14:01.0952 5792 MountMgr - ok
17:14:01.0983 5792 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
17:14:01.0983 5792 mpio - ok
17:14:02.0015 5792 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:14:02.0015 5792 mpsdrv - ok
17:14:02.0046 5792 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
17:14:02.0046 5792 MpsSvc - ok
17:14:02.0061 5792 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
17:14:02.0061 5792 Mraid35x - ok
17:14:02.0093 5792 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:14:02.0093 5792 MRxDAV - ok
17:14:02.0108 5792 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:14:02.0108 5792 mrxsmb - ok
17:14:02.0124 5792 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:14:02.0124 5792 mrxsmb10 - ok
17:14:02.0124 5792 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:14:02.0124 5792 mrxsmb20 - ok
17:14:02.0139 5792 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
17:14:02.0139 5792 msahci - ok
17:14:02.0155 5792 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:14:02.0155 5792 msdsm - ok
17:14:02.0186 5792 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
17:14:02.0186 5792 MSDTC - ok
17:14:02.0217 5792 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:14:02.0217 5792 Msfs - ok
17:14:02.0217 5792 MSICDSetup - ok
17:14:02.0249 5792 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:14:02.0249 5792 msisadrv - ok
17:14:02.0280 5792 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:14:02.0280 5792 MSiSCSI - ok
17:14:02.0295 5792 msiserver - ok
17:14:02.0327 5792 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:14:02.0327 5792 MSKSSRV - ok
17:14:02.0373 5792 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:14:02.0373 5792 MSPCLOCK - ok
17:14:02.0373 5792 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:14:02.0373 5792 MSPQM - ok
17:14:02.0405 5792 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:14:02.0405 5792 MsRPC - ok
17:14:02.0420 5792 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:14:02.0420 5792 mssmbios - ok
17:14:02.0436 5792 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:14:02.0451 5792 MSTEE - ok
17:14:02.0467 5792 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
17:14:02.0467 5792 Mup - ok
17:14:02.0483 5792 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
17:14:02.0483 5792 napagent - ok
17:14:02.0514 5792 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:14:02.0514 5792 NativeWifiP - ok
17:14:02.0576 5792 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:14:02.0592 5792 NDIS - ok
17:14:02.0654 5792 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:14:02.0654 5792 NdisTapi - ok
17:14:02.0717 5792 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:14:02.0717 5792 Ndisuio - ok
17:14:02.0763 5792 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:14:02.0763 5792 NdisWan - ok
17:14:02.0841 5792 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:14:02.0841 5792 NDProxy - ok
17:14:02.0873 5792 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:14:02.0873 5792 NetBIOS - ok
17:14:02.0904 5792 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
17:14:02.0904 5792 netbt - ok
17:14:02.0904 5792 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
17:14:02.0904 5792 Netlogon - ok
17:14:02.0935 5792 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
17:14:02.0935 5792 Netman - ok
17:14:02.0966 5792 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
17:14:02.0966 5792 netprofm - ok
17:14:02.0997 5792 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:14:02.0997 5792 NetTcpPortSharing - ok
17:14:03.0029 5792 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
17:14:03.0029 5792 nfrd960 - ok
17:14:03.0060 5792 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:14:03.0060 5792 NlaSvc - ok
17:14:03.0091 5792 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:14:03.0091 5792 Npfs - ok
17:14:03.0122 5792 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
17:14:03.0122 5792 nsi - ok
17:14:03.0122 5792 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:14:03.0122 5792 nsiproxy - ok
17:14:03.0153 5792 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:14:03.0169 5792 Ntfs - ok
17:14:03.0185 5792 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
17:14:03.0185 5792 ntrigdigi - ok
17:14:03.0200 5792 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
17:14:03.0216 5792 Null - ok
17:14:03.0263 5792 [ C7859D19648D45EE888666C044ECAB23 ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
17:14:03.0278 5792 NVENETFD - ok
17:14:03.0419 5792 [ 640088B163AFD252AF717698945662E2 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:14:03.0434 5792 nvlddmkm - ok
17:14:03.0465 5792 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:14:03.0465 5792 nvraid - ok
17:14:03.0481 5792 [ 4A5FCAB82D9BF6AF8A023A66802FE9E9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:14:03.0497 5792 nvstor - ok
17:14:03.0512 5792 [ 4C93D50BCA15B3BFCAB07306B258B248 ] nvstor32 C:\Windows\system32\DRIVERS\nvstor32.sys
17:14:03.0512 5792 nvstor32 - ok
17:14:03.0528 5792 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:14:03.0528 5792 nv_agp - ok
17:14:03.0543 5792 NwlnkFlt - ok
17:14:03.0543 5792 NwlnkFwd - ok
17:14:03.0590 5792 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:14:03.0606 5792 odserv - ok
17:14:03.0621 5792 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:14:03.0621 5792 ohci1394 - ok
17:14:03.0668 5792 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:14:03.0668 5792 ose - ok
17:14:03.0715 5792 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
17:14:03.0715 5792 p2pimsvc - ok
17:14:03.0731 5792 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
17:14:03.0746 5792 p2psvc - ok
17:14:03.0777 5792 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:14:03.0777 5792 Parport - ok
17:14:03.0793 5792 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:14:03.0793 5792 partmgr - ok
17:14:03.0809 5792 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:14:03.0809 5792 Parvdm - ok
17:14:03.0840 5792 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
17:14:03.0840 5792 PcaSvc - ok
17:14:03.0871 5792 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
17:14:03.0871 5792 pci - ok
17:14:03.0871 5792 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
17:14:03.0871 5792 pciide - ok
17:14:03.0902 5792 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:14:03.0902 5792 pcmcia - ok
17:14:03.0933 5792 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:14:03.0933 5792 PEAUTH - ok
17:14:03.0996 5792 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
17:14:04.0011 5792 pla - ok
17:14:04.0043 5792 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:14:04.0043 5792 PlugPlay - ok
17:14:04.0058 5792 [ A1DD33D16F277CE34124EE52AB2C0F14 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:14:04.0058 5792 PnkBstrA - ok
17:14:04.0089 5792 [ 7C01817ADF3207FB65A4B56E6D5AD833 ] PnkBstrB C:\Windows\system32\PnkBstrB.exe
17:14:04.0089 5792 PnkBstrB - ok
17:14:04.0105 5792 [ F4BA8E3E515A3DD9DD29A031D6F94E02 ] PnkBstrK C:\Windows\system32\drivers\PnkBstrK.sys
17:14:04.0105 5792 PnkBstrK - ok
17:14:04.0136 5792 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
17:14:04.0136 5792 PNRPAutoReg - ok
17:14:04.0152 5792 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
17:14:04.0167 5792 PNRPsvc - ok
17:14:04.0199 5792 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:14:04.0199 5792 PolicyAgent - ok
17:14:04.0230 5792 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:14:04.0230 5792 PptpMiniport - ok
17:14:04.0261 5792 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
17:14:04.0261 5792 Processor - ok
17:14:04.0277 5792 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
17:14:04.0277 5792 ProfSvc - ok
17:14:04.0292 5792 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
17:14:04.0292 5792 ProtectedStorage - ok
17:14:04.0323 5792 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
17:14:04.0323 5792 PSched - ok
17:14:04.0370 5792 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:14:04.0370 5792 ql2300 - ok
17:14:04.0386 5792 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:14:04.0386 5792 ql40xx - ok
17:14:04.0417 5792 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
17:14:04.0417 5792 QWAVE - ok
17:14:04.0433 5792 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:14:04.0433 5792 QWAVEdrv - ok
17:14:04.0448 5792 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:14:04.0448 5792 RasAcd - ok
17:14:04.0464 5792 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
17:14:04.0464 5792 RasAuto - ok
17:14:04.0495 5792 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:14:04.0495 5792 Rasl2tp - ok
17:14:04.0526 5792 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
17:14:04.0526 5792 RasMan - ok
17:14:04.0542 5792 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:14:04.0542 5792 RasPppoe - ok
17:14:04.0557 5792 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:14:04.0557 5792 RasSstp - ok
17:14:04.0589 5792 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:14:04.0589 5792 rdbss - ok
17:14:04.0604 5792 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:14:04.0620 5792 RDPCDD - ok
17:14:04.0651 5792 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
17:14:04.0651 5792 rdpdr - ok
17:14:04.0667 5792 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:14:04.0667 5792 RDPENCDD - ok
17:14:04.0698 5792 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:14:04.0698 5792 RDPWD - ok
17:14:04.0729 5792 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
17:14:04.0745 5792 RemoteAccess - ok
17:14:04.0760 5792 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:14:04.0760 5792 RemoteRegistry - ok
17:14:04.0791 5792 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
17:14:04.0791 5792 RpcLocator - ok
17:14:04.0807 5792 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
17:14:04.0807 5792 RpcSs - ok
17:14:04.0838 5792 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:14:04.0838 5792 rspndr - ok
17:14:04.0854 5792 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
17:14:04.0854 5792 SamSs - ok
17:14:04.0869 5792 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:14:04.0869 5792 sbp2port - ok
17:14:04.0916 5792 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:14:04.0916 5792 SCardSvr - ok
17:14:04.0963 5792 [ 8475E746EB72D04F1015E6F091F50E09 ] SCBackService C:\Program Files\Splashtop\Splashtop Connect\BackService.exe
17:14:04.0963 5792 SCBackService - ok
17:14:04.0994 5792 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
17:14:05.0010 5792 Schedule - ok
17:14:05.0025 5792 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
17:14:05.0025 5792 SCPolicySvc - ok
17:14:05.0041 5792 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:14:05.0041 5792 SDRSVC - ok
17:14:05.0057 5792 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:14:05.0057 5792 secdrv - ok
17:14:05.0072 5792 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
17:14:05.0072 5792 seclogon - ok
17:14:05.0088 5792 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
17:14:05.0088 5792 SENS - ok
17:14:05.0103 5792 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:14:05.0103 5792 Serenum - ok
17:14:05.0135 5792 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:14:05.0135 5792 Serial - ok
17:14:05.0150 5792 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:14:05.0150 5792 sermouse - ok
17:14:05.0181 5792 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
17:14:05.0181 5792 SessionEnv - ok
17:14:05.0213 5792 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:14:05.0213 5792 sffdisk - ok
17:14:05.0228 5792 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:14:05.0228 5792 sffp_mmc - ok
17:14:05.0228 5792 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:14:05.0228 5792 sffp_sd - ok
17:14:05.0244 5792 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
17:14:05.0244 5792 sfloppy - ok
17:14:05.0275 5792 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:14:05.0291 5792 SharedAccess - ok
17:14:05.0306 5792 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:14:05.0306 5792 ShellHWDetection - ok
17:14:05.0322 5792 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:14:05.0322 5792 sisagp - ok
17:14:05.0337 5792 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
17:14:05.0337 5792 SiSRaid2 - ok
17:14:05.0337 5792 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:14:05.0353 5792 SiSRaid4 - ok
17:14:05.0400 5792 [ C70AEBD3608ED9FCEA2A1BAE83567FFC ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:14:05.0400 5792 SkypeUpdate - ok
17:14:05.0493 5792 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
17:14:05.0603 5792 slsvc - ok
17:14:05.0618 5792 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
17:14:05.0618 5792 SLUINotify - ok
17:14:05.0649 5792 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:14:05.0649 5792 Smb - ok
17:14:05.0681 5792 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:14:05.0681 5792 SNMPTRAP - ok
17:14:05.0696 5792 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
17:14:05.0696 5792 spldr - ok
17:14:05.0712 5792 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
17:14:05.0727 5792 Spooler - ok
17:14:05.0774 5792 [ D15DA1BA189770D93EEA2D7E18F95AF9 ] sptd C:\Windows\system32\Drivers\sptd.sys
17:14:05.0774 5792 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: D15DA1BA189770D93EEA2D7E18F95AF9
17:14:05.0774 5792 sptd ( LockedFile.Multi.Generic ) - warning
17:14:05.0774 5792 sptd - detected LockedFile.Multi.Generic (1)
17:14:05.0790 5792 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:14:05.0790 5792 srv - ok
17:14:05.0821 5792 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:14:05.0821 5792 srv2 - ok
17:14:05.0837 5792 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:14:05.0837 5792 srvnet - ok
17:14:05.0852 5792 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:14:05.0868 5792 SSDPSRV - ok
17:14:05.0899 5792 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:14:05.0899 5792 SstpSvc - ok
17:14:05.0930 5792 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
17:14:05.0930 5792 stisvc - ok
17:14:05.0946 5792 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:14:05.0946 5792 swenum - ok
17:14:05.0977 5792 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
17:14:05.0977 5792 swprv - ok
17:14:06.0008 5792 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
17:14:06.0008 5792 Symc8xx - ok
17:14:06.0024 5792 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
17:14:06.0024 5792 Sym_hi - ok
17:14:06.0024 5792 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
17:14:06.0024 5792 Sym_u3 - ok
17:14:06.0071 5792 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
17:14:06.0071 5792 SysMain - ok
17:14:06.0086 5792 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:14:06.0102 5792 TabletInputService - ok
17:14:06.0117 5792 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
17:14:06.0117 5792 TapiSrv - ok
17:14:06.0149 5792 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
17:14:06.0149 5792 TBS - ok
17:14:06.0195 5792 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:14:06.0195 5792 Tcpip - ok
17:14:06.0227 5792 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
17:14:06.0242 5792 Tcpip6 - ok
17:14:06.0273 5792 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:14:06.0273 5792 tcpipreg - ok
17:14:06.0305 5792 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:14:06.0305 5792 TDPIPE - ok
17:14:06.0336 5792 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:14:06.0336 5792 TDTCP - ok
17:14:06.0367 5792 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:14:06.0367 5792 tdx - ok
17:14:06.0398 5792 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:14:06.0398 5792 TermDD - ok
17:14:06.0414 5792 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
17:14:06.0414 5792 TermService - ok
17:14:06.0429 5792 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
17:14:06.0445 5792 Themes - ok
17:14:06.0445 5792 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
17:14:06.0445 5792 THREADORDER - ok
17:14:06.0476 5792 tizekdrv - ok
17:14:06.0507 5792 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
17:14:06.0507 5792 TrkWks - ok
17:14:06.0539 5792 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:14:06.0539 5792 TrustedInstaller - ok
17:14:06.0570 5792 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:14:06.0570 5792 tssecsrv - ok
17:14:06.0601 5792 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
17:14:06.0601 5792 tunmp - ok
17:14:06.0617 5792 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:14:06.0617 5792 tunnel - ok
17:14:06.0648 5792 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:14:06.0648 5792 uagp35 - ok
17:14:06.0663 5792 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:14:06.0663 5792 udfs - ok
17:14:06.0710 5792 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:14:06.0710 5792 UI0Detect - ok
17:14:06.0726 5792 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:14:06.0726 5792 uliagpkx - ok
17:14:06.0741 5792 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
17:14:06.0741 5792 uliahci - ok
17:14:06.0757 5792 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
17:14:06.0757 5792 UlSata - ok
17:14:06.0773 5792 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
17:14:06.0773 5792 ulsata2 - ok
17:14:06.0804 5792 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:14:06.0804 5792 umbus - ok
17:14:06.0897 5792 [ EB79C6C91A99930015EF29AE7FA802D1 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
17:14:06.0944 5792 UNS - ok
17:14:07.0022 5792 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
17:14:07.0022 5792 upnphost - ok
17:14:07.0038 5792 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:14:07.0038 5792 usbccgp - ok
17:14:07.0069 5792 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:14:07.0069 5792 usbcir - ok
17:14:07.0116 5792 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:14:07.0116 5792 usbehci - ok
17:14:07.0131 5792 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:14:07.0131 5792 usbhub - ok
17:14:07.0163 5792 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:14:07.0163 5792 usbohci - ok
17:14:07.0178 5792 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
17:14:07.0178 5792 usbprint - ok
17:14:07.0194 5792 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:14:07.0194 5792 USBSTOR - ok
17:14:07.0209 5792 [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:14:07.0209 5792 usbuhci - ok
17:14:07.0225 5792 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
17:14:07.0241 5792 UxSms - ok
17:14:07.0256 5792 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
17:14:07.0256 5792 vds - ok
17:14:07.0287 5792 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:14:07.0287 5792 vga - ok
17:14:07.0319 5792 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
17:14:07.0319 5792 VgaSave - ok
17:14:07.0334 5792 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:14:07.0334 5792 viaagp - ok
17:14:07.0350 5792 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:14:07.0350 5792 ViaC7 - ok
17:14:07.0365 5792 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
17:14:07.0365 5792 viaide - ok
17:14:07.0381 5792 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:14:07.0381 5792 volmgr - ok
17:14:07.0397 5792 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:14:07.0412 5792 volmgrx - ok
17:14:07.0412 5792 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:14:07.0412 5792 volsnap - ok
17:14:07.0428 5792 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:14:07.0428 5792 vsmraid - ok
17:14:07.0475 5792 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
17:14:07.0475 5792 VSS - ok
17:14:07.0490 5792 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
17:14:07.0490 5792 W32Time - ok
17:14:07.0506 5792 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:14:07.0506 5792 WacomPen - ok
17:14:07.0553 5792 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
17:14:07.0553 5792 Wanarp - ok
17:14:07.0553 5792 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:14:07.0553 5792 Wanarpv6 - ok
17:14:07.0568 5792 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:14:07.0568 5792 wcncsvc - ok
17:14:07.0599 5792 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:14:07.0599 5792 WcsPlugInService - ok
17:14:07.0631 5792 [ DBF0D60BA1FB075A25884B65071B1B82 ] WCUService_STC_FF C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe
17:14:07.0631 5792 WCUService_STC_FF - ok
17:14:07.0646 5792 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
17:14:07.0646 5792 Wd - ok
17:14:07.0677 5792 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:14:07.0693 5792 Wdf01000 - ok
17:14:07.0709 5792 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:14:07.0709 5792 WdiServiceHost - ok
17:14:07.0709 5792 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:14:07.0724 5792 WdiSystemHost - ok
17:14:07.0755 5792 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
17:14:07.0755 5792 WebClient - ok
17:14:07.0787 5792 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:14:07.0787 5792 Wecsvc - ok
17:14:07.0802 5792 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:14:07.0802 5792 wercplsupport - ok
17:14:07.0865 5792 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
17:14:07.0865 5792 WerSvc - ok
17:14:07.0896 5792 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:14:07.0896 5792 WinDefend - ok
17:14:07.0911 5792 WinHttpAutoProxySvc - ok
17:14:07.0943 5792 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:14:07.0943 5792 Winmgmt - ok
17:14:07.0989 5792 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
17:14:07.0989 5792 WinRM - ok
17:14:08.0052 5792 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:14:08.0067 5792 Wlansvc - ok
17:14:08.0083 5792 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:14:08.0083 5792 WmiAcpi - ok
17:14:08.0114 5792 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:14:08.0114 5792 wmiApSrv - ok
17:14:08.0145 5792 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:14:08.0177 5792 WMPNetworkSvc - ok
17:14:08.0177 5792 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:14:08.0192 5792 WPCSvc - ok
17:14:08.0208 5792 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:14:08.0208 5792 WPDBusEnum - ok
17:14:08.0301 5792 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
17:14:08.0317 5792 WPFFontCache_v0400 - ok
17:14:08.0348 5792 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:14:08.0348 5792 ws2ifsl - ok
17:14:08.0379 5792 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
17:14:08.0379 5792 wscsvc - ok
17:14:08.0379 5792 WSearch - ok
17:14:08.0457 5792 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:14:08.0473 5792 wuauserv - ok
17:14:08.0504 5792 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:14:08.0504 5792 WUDFRd - ok
17:14:08.0520 5792 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:14:08.0520 5792 wudfsvc - ok
17:14:08.0535 5792 ================ Scan global ===============================
17:14:08.0551 5792 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
17:14:08.0567 5792 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
17:14:08.0582 5792 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
17:14:08.0629 5792 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
17:14:08.0629 5792 [Global] - ok
17:14:08.0629 5792 ================ Scan MBR ==================================
17:14:08.0629 5792 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
17:14:08.0941 5792 \Device\Harddisk0\DR0 - ok
17:14:08.0941 5792 ================ Scan VBR ==================================
17:14:08.0941 5792 [ F3BD246E5E4E57A40874EAF8B723E140 ] \Device\Harddisk0\DR0\Partition1
17:14:08.0941 5792 \Device\Harddisk0\DR0\Partition1 - ok
17:14:08.0941 5792 ============================================================
17:14:08.0941 5792 Scan finished
17:14:08.0941 5792 ============================================================
17:14:08.0957 5956 Detected object count: 1
17:14:08.0957 5956 Actual detected object count: 1
17:14:21.0234 5956 sptd ( LockedFile.Multi.Generic ) - skipped by user
17:14:21.0234 5956 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
17:14:23.0933 4844 Deinitialize success

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 17:31

Combo Fix


ComboFix 12-11-16.02 - matej 18.11.2012 17:24:16.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3563.2425 [GMT 1:00]
Spuštěný z: c:\users\matej\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-18 do 2012-11-18 )))))))))))))))))))))))))))))))
.
.
2012-11-18 16:28 . 2012-11-18 16:28 -------- d-----w- c:\users\matej\AppData\Local\temp
2012-11-18 16:28 . 2012-11-18 16:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-18 13:24 . 2012-11-18 13:24 -------- d-----w- c:\users\matej\AppData\Local\ATI
2012-11-18 13:10 . 2012-11-18 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-18 13:10 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-17 09:12 . 2012-10-12 05:56 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DB2BECA5-6B88-43F8-B370-DC348DF941D7}\mpengine.dll
2012-11-14 05:12 . 2012-09-25 16:19 75776 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 05:12 . 2012-10-12 14:29 2047488 ----a-w- c:\windows\system32\win32k.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-18 15:28 . 2001-12-31 23:01 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-11-18 15:28 . 2012-03-12 12:27 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-11-18 15:28 . 2011-10-02 09:11 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-11-18 08:37 . 2012-07-09 06:41 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-18 08:37 . 2011-09-22 17:34 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-30 22:51 . 2011-09-22 17:44 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2011-09-22 17:44 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2011-09-22 17:44 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2011-09-22 17:44 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2011-09-22 17:44 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-30 22:51 . 2011-09-22 17:44 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2011-09-22 17:39 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 22:50 . 2011-09-22 17:39 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-09-24 21:16 . 2012-09-14 17:03 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-24 21:16 . 2012-09-14 17:03 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-13 13:28 . 2012-10-10 04:21 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-10 11:49 . 2012-03-23 00:52 16608 ----a-w- c:\windows\gdrv.sys
2012-08-29 11:27 . 2012-10-10 04:21 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-29 11:27 . 2012-10-10 04:21 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-25 11:50 . 2012-09-22 09:11 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-25 11:44 . 2012-09-22 09:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-25 11:44 . 2012-09-22 09:11 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-25 11:44 . 2012-09-22 09:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2012-08-25 11:44 . 2012-09-22 09:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2012-08-25 10:11 . 2012-09-22 09:11 385024 ----a-w- c:\windows\system32\html.iec
2012-08-25 08:31 . 2012-09-22 09:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-25 08:29 . 2012-09-22 09:11 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-24 15:53 . 2012-10-10 04:21 172544 ----a-w- c:\windows\system32\wintrust.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files\ICQ7.6\ICQ.exe" [2011-10-10 127040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-11-18 11483752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-19 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-19 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-19 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"ZyngaGamesAgent"="c:\program files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GamePark klient 2.lnk - c:\program files\GamePark2\gpcl.exe [2012-7-8 409088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - MBAMSwissArmy
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-09 08:37]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-STCAgent - c:\program files\Splashtop\Splashtop Connect IE\STCAgent.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-18 17:28
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2012-11-18 17:29:51
ComboFix-quarantined-files.txt 2012-11-18 16:29
.
Před spuštěním: Volných bajtů: 55 016 984 576
Po spuštění: Volných bajtů: 54 980 759 552
.
- - End Of File - - 6867762D9E6735551DE8758A938F8058

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 18 lis 2012 18:27

CF ok

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj AVG , Avast,Avira či Microsoft Security Essentials následně T-Cleaner smaž a zapni si AVG , Avast, Avira či Microsoft Security Essentials

+ Nový log z HJT

Jak se chová PC?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 18 lis 2012 18:55

Řekl bych, že PC se chovaá tak jak má + není v tom TDSSKiller nějaký soubor na odstranění ?

Nový log z HJT


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:53:49, on 18.11.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19328)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conime.exe
C:\Users\matej\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\matej\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ZyngaGamesAgent] "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [STCAgent] "C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Splashtop Connect Service (SCBackService) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Connect\BackService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Splashtop Connect Firefox Software Updater Service (WCUService_STC_FF) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe

--
End of file - 5779 bytes

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 18 lis 2012 22:41

To sptd v TDDS je v pořádku. Detekuje jej to pokaždé. HJT je taky Ok. Pokud nejsou problémy, můžeš to tu zavřít :-)
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu  Vyřešeno

Příspěvekod Mety » 19 lis 2012 06:50

Dobře, děkuji mockrát.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 105 hostů