počítačová síť je zdrojem neobvyklého provozu..
--- Doplnění předchozího příspěvku (07 Dub 2014 10:24) ---
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:23:45, on 7.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\steam\Steam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Steam] "C:\Program Files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files\Common Files\BattlEye\BEService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 5271 bytes
thevalid
Level 1.5
Level 1.5
Věrnost fóru:
Věrnost fóruVěrnost fóru
Příspěvky: 125
Pohlaví: Muž
Prosím o kontrolu síť je zdrojem neobvyklého prov
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7.4.2014
Scan Time: 11:22:39
Logfile: ng.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.07.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: admin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 261061
Time Elapsed: 10 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
www.malwarebytes.org
Scan Date: 7.4.2014
Scan Time: 11:22:39
Logfile: ng.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.07.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: admin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 261061
Time Elapsed: 10 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
# AdwCleaner v3.023 - Report created 07/04/2014 at 11:24:29
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : admin - PC
# Running from : C:\Users\admin\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\ProgramData\ParetoLogic
Folder Found C:\Users\admin\AppData\Roaming\DriverCure
Folder Found C:\Users\admin\AppData\Roaming\ParetoLogic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\ParetoLogic
Key Found : HKLM\Software\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R4].txt - [847 octets] - [07/04/2014 11:24:29]
########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [906 octets] ##########
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : admin - PC
# Running from : C:\Users\admin\Downloads\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\ProgramData\ParetoLogic
Folder Found C:\Users\admin\AppData\Roaming\DriverCure
Folder Found C:\Users\admin\AppData\Roaming\ParetoLogic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\ParetoLogic
Key Found : HKLM\Software\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R4].txt - [847 octets] - [07/04/2014 11:24:29]
########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [906 octets] ##########
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
# AdwCleaner v3.023 - Report created 09/04/2014 at 15:52:58
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : admin - PC
# Running from : C:\Users\admin\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\Users\admin\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\admin\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\admin\AppData\Roaming\ParetoLogic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKLM\Software\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R4].txt - [985 octets] - [07/04/2014 11:24:29]
AdwCleaner[R5].txt - [1100 octets] - [09/04/2014 15:51:11]
AdwCleaner[S3].txt - [1042 octets] - [09/04/2014 15:52:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1102 octets] ##########
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : admin - PC
# Running from : C:\Users\admin\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\Users\admin\AppData\Roaming\DriverCure
Folder Deleted : C:\Users\admin\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\admin\AppData\Roaming\ParetoLogic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKLM\Software\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v33.0.1750.154
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R4].txt - [985 octets] - [07/04/2014 11:24:29]
AdwCleaner[R5].txt - [1100 octets] - [09/04/2014 15:51:11]
AdwCleaner[S3].txt - [1042 octets] - [09/04/2014 15:52:58]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1102 octets] ##########
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by admin on st 09.04.2014 at 15:58:08,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 09.04.2014 at 16:01:49,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by admin on st 09.04.2014 at 15:58:08,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 09.04.2014 at 16:01:49,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : admin [Admin rights]
Mode : Scan -- Date : 04/09/2014 16:11:00
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] EAT @explorer.exe (BeginBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742509AE)
[Address] EAT @explorer.exe (BeginBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742449A1)
[Address] EAT @explorer.exe (BeginPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74270731)
[Address] EAT @explorer.exe (BufferedPaintClear) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74246395)
[Address] EAT @explorer.exe (BufferedPaintInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424940E)
[Address] EAT @explorer.exe (BufferedPaintRenderAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742508ED)
[Address] EAT @explorer.exe (BufferedPaintSetAlpha) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425E6B3)
[Address] EAT @explorer.exe (BufferedPaintStopAllAnimations) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425D395)
[Address] EAT @explorer.exe (BufferedPaintUnInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742494AB)
[Address] EAT @explorer.exe (CloseThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74246A18)
[Address] EAT @explorer.exe (DrawThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243982)
[Address] EAT @explorer.exe (DrawThemeBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425D9DA)
[Address] EAT @explorer.exe (DrawThemeEdge) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263B52)
[Address] EAT @explorer.exe (DrawThemeIcon) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742735E7)
[Address] EAT @explorer.exe (DrawThemeParentBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742453E5)
[Address] EAT @explorer.exe (DrawThemeParentBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742451BF)
[Address] EAT @explorer.exe (DrawThemeText) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74244EA1)
[Address] EAT @explorer.exe (DrawThemeTextEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742463E6)
[Address] EAT @explorer.exe (EnableThemeDialogTexture) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424FCAF)
[Address] EAT @explorer.exe (EnableTheming) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272FEB)
[Address] EAT @explorer.exe (EndBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243F9A)
[Address] EAT @explorer.exe (EndBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243F9A)
[Address] EAT @explorer.exe (EndPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742706CC)
[Address] EAT @explorer.exe (GetBufferedPaintBits) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74244BAF)
[Address] EAT @explorer.exe (GetBufferedPaintDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742504BC)
[Address] EAT @explorer.exe (GetBufferedPaintTargetDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250473)
[Address] EAT @explorer.exe (GetBufferedPaintTargetRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272E7F)
[Address] EAT @explorer.exe (GetCurrentThemeName) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742505DD)
[Address] EAT @explorer.exe (GetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250FB1)
[Address] EAT @explorer.exe (GetThemeBackgroundContentRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424CD2E)
[Address] EAT @explorer.exe (GetThemeBackgroundExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F8BF)
[Address] EAT @explorer.exe (GetThemeBackgroundRegion) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425165D)
[Address] EAT @explorer.exe (GetThemeBitmap) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424BF93)
[Address] EAT @explorer.exe (GetThemeBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74247C1F)
[Address] EAT @explorer.exe (GetThemeColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeDocumentationProperty) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272932)
[Address] EAT @explorer.exe (GetThemeEnumValue) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeFilename) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272412)
[Address] EAT @explorer.exe (GetThemeFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424FF21)
[Address] EAT @explorer.exe (GetThemeInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeIntList) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742723B1)
[Address] EAT @explorer.exe (GetThemeMargins) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742486E9)
[Address] EAT @explorer.exe (GetThemeMetric) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742506E2)
[Address] EAT @explorer.exe (GetThemePartSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424CDB1)
[Address] EAT @explorer.exe (GetThemePosition) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272350)
[Address] EAT @explorer.exe (GetThemePropertyOrigin) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263FBB)
[Address] EAT @explorer.exe (GetThemeRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74253611)
[Address] EAT @explorer.exe (GetThemeStream) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742539D9)
[Address] EAT @explorer.exe (GetThemeString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742722E4)
[Address] EAT @explorer.exe (GetThemeSysBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74273172)
[Address] EAT @explorer.exe (GetThemeSysColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263274)
[Address] EAT @explorer.exe (GetThemeSysColorBrush) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427301E)
[Address] EAT @explorer.exe (GetThemeSysFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742729C4)
[Address] EAT @explorer.exe (GetThemeSysInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272BD3)
[Address] EAT @explorer.exe (GetThemeSysSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427320B)
[Address] EAT @explorer.exe (GetThemeSysString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272B3F)
[Address] EAT @explorer.exe (GetThemeTextExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74242D57)
[Address] EAT @explorer.exe (GetThemeTextMetrics) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F992)
[Address] EAT @explorer.exe (GetThemeTransitionDuration) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74251081)
[Address] EAT @explorer.exe (GetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424DF46)
[Address] EAT @explorer.exe (HitTestThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74253CE3)
[Address] EAT @explorer.exe (IsAppThemed) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F869)
[Address] EAT @explorer.exe (IsCompositionActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74242E9A)
[Address] EAT @explorer.exe (IsThemeActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F785)
[Address] EAT @explorer.exe (IsThemeBackgroundPartiallyTransparent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742460AB)
[Address] EAT @explorer.exe (IsThemeDialogTextureEnabled) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427312B)
[Address] EAT @explorer.exe (IsThemePartDefined) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742485B4)
[Address] EAT @explorer.exe (OpenThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742473D2)
[Address] EAT @explorer.exe (OpenThemeDataEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263D43)
[Address] EAT @explorer.exe (SetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74273296)
[Address] EAT @explorer.exe (SetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250134)
[Address] EAT @explorer.exe (SetWindowThemeAttribute) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425CFE6)
[Address] EAT @explorer.exe (ThemeInitApiHook) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424B176)
[Address] EAT @explorer.exe (UpdatePanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427068D)
[Address] EAT @explorer.exe (DllGetClassObject) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4CFAD)
[Address] EAT @explorer.exe (IEnumString_Next_WIC_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E059)
[Address] EAT @explorer.exe (IEnumString_Reset_WIC_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E082)
[Address] EAT @explorer.exe (IPropertyBag2_Write_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0A2)
[Address] EAT @explorer.exe (IWICBitmapClipper_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDA6)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportAnimation_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAD0)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportLossless_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAF3)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportMultiframe_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB16)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetContainerFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D855)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceManufacturer_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA2C)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceModels_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA55)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetFileExtensions_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAA7)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetMimeTypes_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA7E)
[Address] EAT @explorer.exe (IWICBitmapDecoder_CopyPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D832)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA03)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetDecoderInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrameCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrame_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D89B)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetMetadataQueryReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetPreview_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCF0)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D855)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC81)
[Address] EAT @explorer.exe (IWICBitmapEncoder_CreateNewFrame_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC03)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetEncoderInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DBDA)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DBAE)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC58)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC2F)
[Address] EAT @explorer.exe (IWICBitmapFlipRotator_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDA6)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetMetadataQueryReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8EA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA1E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DACA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E010)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB82)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA70)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetSize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA3E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB59)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_WriteSource_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DAED)
[Address] EAT @explorer.exe (IWICBitmapLock_GetDataPointer_STA_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICBitmapLock_GetStride_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICBitmapScaler_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD7A)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPixels_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCC4)
[Address] EAT @explorer.exe (IWICBitmapSource_GetPixelFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICBitmapSource_GetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICBitmapSource_GetSize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D950)
[Address] EAT @explorer.exe (IWICBitmap_Lock_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9DA)
[Address] EAT @explorer.exe (IWICBitmap_SetPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCF0)
[Address] EAT @explorer.exe (IWICBitmap_SetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD13)
[Address] EAT @explorer.exe (IWICColorContext_InitializeFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D976)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateMetadataWriterFromReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D7BA)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateQueryWriterFromBlockWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D7E3)
[Address] EAT @explorer.exe (IWICComponentInfo_GetAuthor_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9B1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetCLSID_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICComponentInfo_GetFriendlyName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA03)
[Address] EAT @explorer.exe (IWICComponentInfo_GetSpecVersion_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetVersion_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9DA)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D90D)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICFormatConverter_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD43)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapClipper_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D567)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFlipRotator_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D590)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHBITMAP_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D6CA)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHICON_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D6F6)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D666)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromSource_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D63D)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapScaler_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D53E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmap_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D69B)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateComponentInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D4E9)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFileHandle_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D4B1)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFilename_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D476)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D43E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateEncoder_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D5E2)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromDecoder_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D71C)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromFrameDecode_Prox1JVN0Jø"T) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D742)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFormatConverter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D515)
[Address] EAT @explorer.exe (IWICImagingFactory_CreatePalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB59)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriterFromReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D791)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D768)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D5B9)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetReaderByIndex_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetContainerFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E010)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetEnumerator_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetLocation_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0A2)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_RemoveMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_SetMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E033)
[Address] EAT @explorer.exe (IWICPalette_GetColorCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9C5)
[Address] EAT @explorer.exe (IWICPalette_GetColors_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICPalette_GetType_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D832)
[Address] EAT @explorer.exe (IWICPalette_HasAlpha_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICPalette_InitializeCustom_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D976)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromBitmap_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D99C)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICPalette_InitializePredefined_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D950)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetBitsPerPixel_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DACA)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB39)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelMask_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB5C)
[Address] EAT @explorer.exe (IWICStream_InitializeFromIStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB39)
[Address] EAT @explorer.exe (IWICStream_InitializeFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDCC)
[Address] EAT @explorer.exe (WICConvertBitmapSource) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DE11)
[Address] EAT @explorer.exe (WICCreateBitmapFromSection) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DFE6)
[Address] EAT @explorer.exe (WICCreateBitmapFromSectionEx) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DEE5)
[Address] EAT @explorer.exe (WICCreateColorContext_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB88)
[Address] EAT @explorer.exe (WICCreateImagingFactory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D03B)
[Address] EAT @explorer.exe (WICGetMetadataContentSize) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E676)
[Address] EAT @explorer.exe (WICMapGuidToShortName) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D0FC)
[Address] EAT @explorer.exe (WICMapSchemaToName) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D2F0)
[Address] EAT @explorer.exe (WICMapShortNameToGuid) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D227)
[Address] EAT @explorer.exe (WICMatchMetadataContent) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0CB)
[Address] EAT @explorer.exe (WICSerializeMetadataContent) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E20D)
[Address] EAT @explorer.exe (WICSetEncoderFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDF2)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD32 00AAKS-00B3A SCSI Disk Device +++++
--- User ---
[MBR] 2994c85755f6acff0cad4bd53275dcc6
[BSP] be92604706e2c7bc6e6fc7b708001c1d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Incorrect function. )
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Generic USB SD Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ USB) Generic USB CF Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive3: (\\.\PHYSICALDRIVE3 @ USB) Generic USB SM Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive4: (\\.\PHYSICALDRIVE4 @ USB) Generic USB MS Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
Finished : << RKreport[0]_S_04092014_161100.txt >>
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : admin [Admin rights]
Mode : Scan -- Date : 04/09/2014 16:11:00
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] EAT @explorer.exe (BeginBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742509AE)
[Address] EAT @explorer.exe (BeginBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742449A1)
[Address] EAT @explorer.exe (BeginPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74270731)
[Address] EAT @explorer.exe (BufferedPaintClear) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74246395)
[Address] EAT @explorer.exe (BufferedPaintInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424940E)
[Address] EAT @explorer.exe (BufferedPaintRenderAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742508ED)
[Address] EAT @explorer.exe (BufferedPaintSetAlpha) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425E6B3)
[Address] EAT @explorer.exe (BufferedPaintStopAllAnimations) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425D395)
[Address] EAT @explorer.exe (BufferedPaintUnInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742494AB)
[Address] EAT @explorer.exe (CloseThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74246A18)
[Address] EAT @explorer.exe (DrawThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243982)
[Address] EAT @explorer.exe (DrawThemeBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425D9DA)
[Address] EAT @explorer.exe (DrawThemeEdge) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263B52)
[Address] EAT @explorer.exe (DrawThemeIcon) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742735E7)
[Address] EAT @explorer.exe (DrawThemeParentBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742453E5)
[Address] EAT @explorer.exe (DrawThemeParentBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742451BF)
[Address] EAT @explorer.exe (DrawThemeText) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74244EA1)
[Address] EAT @explorer.exe (DrawThemeTextEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742463E6)
[Address] EAT @explorer.exe (EnableThemeDialogTexture) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424FCAF)
[Address] EAT @explorer.exe (EnableTheming) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272FEB)
[Address] EAT @explorer.exe (EndBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243F9A)
[Address] EAT @explorer.exe (EndBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74243F9A)
[Address] EAT @explorer.exe (EndPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742706CC)
[Address] EAT @explorer.exe (GetBufferedPaintBits) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74244BAF)
[Address] EAT @explorer.exe (GetBufferedPaintDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742504BC)
[Address] EAT @explorer.exe (GetBufferedPaintTargetDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250473)
[Address] EAT @explorer.exe (GetBufferedPaintTargetRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272E7F)
[Address] EAT @explorer.exe (GetCurrentThemeName) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742505DD)
[Address] EAT @explorer.exe (GetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250FB1)
[Address] EAT @explorer.exe (GetThemeBackgroundContentRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424CD2E)
[Address] EAT @explorer.exe (GetThemeBackgroundExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F8BF)
[Address] EAT @explorer.exe (GetThemeBackgroundRegion) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425165D)
[Address] EAT @explorer.exe (GetThemeBitmap) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424BF93)
[Address] EAT @explorer.exe (GetThemeBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74247C1F)
[Address] EAT @explorer.exe (GetThemeColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeDocumentationProperty) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272932)
[Address] EAT @explorer.exe (GetThemeEnumValue) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeFilename) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272412)
[Address] EAT @explorer.exe (GetThemeFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424FF21)
[Address] EAT @explorer.exe (GetThemeInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424616C)
[Address] EAT @explorer.exe (GetThemeIntList) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742723B1)
[Address] EAT @explorer.exe (GetThemeMargins) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742486E9)
[Address] EAT @explorer.exe (GetThemeMetric) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742506E2)
[Address] EAT @explorer.exe (GetThemePartSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424CDB1)
[Address] EAT @explorer.exe (GetThemePosition) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272350)
[Address] EAT @explorer.exe (GetThemePropertyOrigin) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263FBB)
[Address] EAT @explorer.exe (GetThemeRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74253611)
[Address] EAT @explorer.exe (GetThemeStream) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742539D9)
[Address] EAT @explorer.exe (GetThemeString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742722E4)
[Address] EAT @explorer.exe (GetThemeSysBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74273172)
[Address] EAT @explorer.exe (GetThemeSysColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263274)
[Address] EAT @explorer.exe (GetThemeSysColorBrush) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427301E)
[Address] EAT @explorer.exe (GetThemeSysFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742729C4)
[Address] EAT @explorer.exe (GetThemeSysInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272BD3)
[Address] EAT @explorer.exe (GetThemeSysSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427320B)
[Address] EAT @explorer.exe (GetThemeSysString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74272B3F)
[Address] EAT @explorer.exe (GetThemeTextExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74242D57)
[Address] EAT @explorer.exe (GetThemeTextMetrics) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F992)
[Address] EAT @explorer.exe (GetThemeTransitionDuration) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74251081)
[Address] EAT @explorer.exe (GetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424DF46)
[Address] EAT @explorer.exe (HitTestThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74253CE3)
[Address] EAT @explorer.exe (IsAppThemed) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F869)
[Address] EAT @explorer.exe (IsCompositionActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74242E9A)
[Address] EAT @explorer.exe (IsThemeActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424F785)
[Address] EAT @explorer.exe (IsThemeBackgroundPartiallyTransparent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742460AB)
[Address] EAT @explorer.exe (IsThemeDialogTextureEnabled) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427312B)
[Address] EAT @explorer.exe (IsThemePartDefined) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742485B4)
[Address] EAT @explorer.exe (OpenThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742473D2)
[Address] EAT @explorer.exe (OpenThemeDataEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74263D43)
[Address] EAT @explorer.exe (SetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74273296)
[Address] EAT @explorer.exe (SetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74250134)
[Address] EAT @explorer.exe (SetWindowThemeAttribute) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7425CFE6)
[Address] EAT @explorer.exe (ThemeInitApiHook) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7424B176)
[Address] EAT @explorer.exe (UpdatePanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7427068D)
[Address] EAT @explorer.exe (DllGetClassObject) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4CFAD)
[Address] EAT @explorer.exe (IEnumString_Next_WIC_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E059)
[Address] EAT @explorer.exe (IEnumString_Reset_WIC_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E082)
[Address] EAT @explorer.exe (IPropertyBag2_Write_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0A2)
[Address] EAT @explorer.exe (IWICBitmapClipper_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDA6)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportAnimation_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAD0)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportLossless_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAF3)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportMultiframe_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB16)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetContainerFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D855)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceManufacturer_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA2C)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceModels_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA55)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetFileExtensions_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EAA7)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetMimeTypes_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA7E)
[Address] EAT @explorer.exe (IWICBitmapDecoder_CopyPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D832)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA03)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetDecoderInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrameCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrame_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D89B)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetMetadataQueryReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetPreview_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCF0)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D855)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC81)
[Address] EAT @explorer.exe (IWICBitmapEncoder_CreateNewFrame_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC03)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetEncoderInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DBDA)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DBAE)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC58)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DC2F)
[Address] EAT @explorer.exe (IWICBitmapFlipRotator_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDA6)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetMetadataQueryReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8EA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA1E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DACA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E010)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetColorContexts_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB82)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA70)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetSize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DA3E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetThumbnail_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB59)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_WriteSource_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DAED)
[Address] EAT @explorer.exe (IWICBitmapLock_GetDataPointer_STA_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICBitmapLock_GetStride_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICBitmapScaler_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD7A)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPixels_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCC4)
[Address] EAT @explorer.exe (IWICBitmapSource_GetPixelFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICBitmapSource_GetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICBitmapSource_GetSize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D950)
[Address] EAT @explorer.exe (IWICBitmap_Lock_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9DA)
[Address] EAT @explorer.exe (IWICBitmap_SetPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCF0)
[Address] EAT @explorer.exe (IWICBitmap_SetResolution_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD13)
[Address] EAT @explorer.exe (IWICColorContext_InitializeFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D976)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateMetadataWriterFromReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D7BA)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateQueryWriterFromBlockWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D7E3)
[Address] EAT @explorer.exe (IWICComponentInfo_GetAuthor_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9B1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetCLSID_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICComponentInfo_GetFriendlyName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EA03)
[Address] EAT @explorer.exe (IWICComponentInfo_GetSpecVersion_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetVersion_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E9DA)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_Commit_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D90D)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_GetMetadataQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICFormatConverter_Initialize_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DD43)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapClipper_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D567)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFlipRotator_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D590)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHBITMAP_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D6CA)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHICON_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D6F6)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D666)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromSource_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D63D)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapScaler_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D53E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmap_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D69B)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateComponentInfo_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D4E9)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFileHandle_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D4B1)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFilename_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D476)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D43E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateEncoder_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D5E2)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromDecoder_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D71C)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromFrameDecode_Prox1JVN0Jø"T) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D742)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFormatConverter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D515)
[Address] EAT @explorer.exe (IWICImagingFactory_CreatePalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DB59)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriterFromReader_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D791)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriter_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D768)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D5B9)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D92D)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetReaderByIndex_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetContainerFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E010)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetEnumerator_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetLocation_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0A2)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_RemoveMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D878)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_SetMetadataByName_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E033)
[Address] EAT @explorer.exe (IWICPalette_GetColorCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9C5)
[Address] EAT @explorer.exe (IWICPalette_GetColors_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D8C1)
[Address] EAT @explorer.exe (IWICPalette_GetType_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D832)
[Address] EAT @explorer.exe (IWICPalette_HasAlpha_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D9FB)
[Address] EAT @explorer.exe (IWICPalette_InitializeCustom_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D976)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromBitmap_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D99C)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromPalette_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DCA1)
[Address] EAT @explorer.exe (IWICPalette_InitializePredefined_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D950)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetBitsPerPixel_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DACA)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelCount_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB39)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelMask_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB5C)
[Address] EAT @explorer.exe (IWICStream_InitializeFromIStream_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB39)
[Address] EAT @explorer.exe (IWICStream_InitializeFromMemory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDCC)
[Address] EAT @explorer.exe (WICConvertBitmapSource) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DE11)
[Address] EAT @explorer.exe (WICCreateBitmapFromSection) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DFE6)
[Address] EAT @explorer.exe (WICCreateBitmapFromSectionEx) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DEE5)
[Address] EAT @explorer.exe (WICCreateColorContext_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4EB88)
[Address] EAT @explorer.exe (WICCreateImagingFactory_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D03B)
[Address] EAT @explorer.exe (WICGetMetadataContentSize) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E676)
[Address] EAT @explorer.exe (WICMapGuidToShortName) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D0FC)
[Address] EAT @explorer.exe (WICMapSchemaToName) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D2F0)
[Address] EAT @explorer.exe (WICMapShortNameToGuid) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4D227)
[Address] EAT @explorer.exe (WICMatchMetadataContent) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E0CB)
[Address] EAT @explorer.exe (WICSerializeMetadataContent) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4E20D)
[Address] EAT @explorer.exe (WICSetEncoderFormat_Proxy) : AVRT.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73D4DDF2)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD32 00AAKS-00B3A SCSI Disk Device +++++
--- User ---
[MBR] 2994c85755f6acff0cad4bd53275dcc6
[BSP] be92604706e2c7bc6e6fc7b708001c1d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Incorrect function. )
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Generic USB SD Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ USB) Generic USB CF Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive3: (\\.\PHYSICALDRIVE3 @ USB) Generic USB SM Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive4: (\\.\PHYSICALDRIVE4 @ USB) Generic USB MS Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
Finished : << RKreport[0]_S_04092014_161100.txt >>
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : admin [Admin rights]
Mode : Scan -- Date : 04/10/2014 17:01:53
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] EAT @explorer.exe (BeginBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743009AE)
[Address] EAT @explorer.exe (BeginBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F49A1)
[Address] EAT @explorer.exe (BeginPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74320731)
[Address] EAT @explorer.exe (BufferedPaintClear) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F6395)
[Address] EAT @explorer.exe (BufferedPaintInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F940E)
[Address] EAT @explorer.exe (BufferedPaintRenderAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743008ED)
[Address] EAT @explorer.exe (BufferedPaintSetAlpha) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430E6B3)
[Address] EAT @explorer.exe (BufferedPaintStopAllAnimations) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430D395)
[Address] EAT @explorer.exe (BufferedPaintUnInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F94AB)
[Address] EAT @explorer.exe (CloseThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F6A18)
[Address] EAT @explorer.exe (DrawThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3982)
[Address] EAT @explorer.exe (DrawThemeBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430D9DA)
[Address] EAT @explorer.exe (DrawThemeEdge) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313B52)
[Address] EAT @explorer.exe (DrawThemeIcon) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743235E7)
[Address] EAT @explorer.exe (DrawThemeParentBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F53E5)
[Address] EAT @explorer.exe (DrawThemeParentBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F51BF)
[Address] EAT @explorer.exe (DrawThemeText) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F4EA1)
[Address] EAT @explorer.exe (DrawThemeTextEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F63E6)
[Address] EAT @explorer.exe (EnableThemeDialogTexture) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FFCAF)
[Address] EAT @explorer.exe (EnableTheming) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322FEB)
[Address] EAT @explorer.exe (EndBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3F9A)
[Address] EAT @explorer.exe (EndBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3F9A)
[Address] EAT @explorer.exe (EndPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743206CC)
[Address] EAT @explorer.exe (GetBufferedPaintBits) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F4BAF)
[Address] EAT @explorer.exe (GetBufferedPaintDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743004BC)
[Address] EAT @explorer.exe (GetBufferedPaintTargetDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300473)
[Address] EAT @explorer.exe (GetBufferedPaintTargetRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322E7F)
[Address] EAT @explorer.exe (GetCurrentThemeName) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743005DD)
[Address] EAT @explorer.exe (GetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300FB1)
[Address] EAT @explorer.exe (GetThemeBackgroundContentRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FCD2E)
[Address] EAT @explorer.exe (GetThemeBackgroundExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF8BF)
[Address] EAT @explorer.exe (GetThemeBackgroundRegion) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430165D)
[Address] EAT @explorer.exe (GetThemeBitmap) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FBF93)
[Address] EAT @explorer.exe (GetThemeBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F7C1F)
[Address] EAT @explorer.exe (GetThemeColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeDocumentationProperty) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322932)
[Address] EAT @explorer.exe (GetThemeEnumValue) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeFilename) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322412)
[Address] EAT @explorer.exe (GetThemeFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FFF21)
[Address] EAT @explorer.exe (GetThemeInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeIntList) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743223B1)
[Address] EAT @explorer.exe (GetThemeMargins) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F86E9)
[Address] EAT @explorer.exe (GetThemeMetric) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743006E2)
[Address] EAT @explorer.exe (GetThemePartSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FCDB1)
[Address] EAT @explorer.exe (GetThemePosition) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322350)
[Address] EAT @explorer.exe (GetThemePropertyOrigin) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313FBB)
[Address] EAT @explorer.exe (GetThemeRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74303611)
[Address] EAT @explorer.exe (GetThemeStream) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743039D9)
[Address] EAT @explorer.exe (GetThemeString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743222E4)
[Address] EAT @explorer.exe (GetThemeSysBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74323172)
[Address] EAT @explorer.exe (GetThemeSysColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313274)
[Address] EAT @explorer.exe (GetThemeSysColorBrush) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432301E)
[Address] EAT @explorer.exe (GetThemeSysFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743229C4)
[Address] EAT @explorer.exe (GetThemeSysInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322BD3)
[Address] EAT @explorer.exe (GetThemeSysSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432320B)
[Address] EAT @explorer.exe (GetThemeSysString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322B3F)
[Address] EAT @explorer.exe (GetThemeTextExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F2D57)
[Address] EAT @explorer.exe (GetThemeTextMetrics) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF992)
[Address] EAT @explorer.exe (GetThemeTransitionDuration) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74301081)
[Address] EAT @explorer.exe (GetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FDF46)
[Address] EAT @explorer.exe (HitTestThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74303CE3)
[Address] EAT @explorer.exe (IsAppThemed) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF869)
[Address] EAT @explorer.exe (IsCompositionActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F2E9A)
[Address] EAT @explorer.exe (IsThemeActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF785)
[Address] EAT @explorer.exe (IsThemeBackgroundPartiallyTransparent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F60AB)
[Address] EAT @explorer.exe (IsThemeDialogTextureEnabled) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432312B)
[Address] EAT @explorer.exe (IsThemePartDefined) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F85B4)
[Address] EAT @explorer.exe (OpenThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F73D2)
[Address] EAT @explorer.exe (OpenThemeDataEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313D43)
[Address] EAT @explorer.exe (SetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74323296)
[Address] EAT @explorer.exe (SetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300134)
[Address] EAT @explorer.exe (SetWindowThemeAttribute) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430CFE6)
[Address] EAT @explorer.exe (ThemeInitApiHook) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FB176)
[Address] EAT @explorer.exe (UpdatePanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432068D)
[Address] EAT @explorer.exe (DllGetClassObject) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8CFAD)
[Address] EAT @explorer.exe (IEnumString_Next_WIC_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E059)
[Address] EAT @explorer.exe (IEnumString_Reset_WIC_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E082)
[Address] EAT @explorer.exe (IPropertyBag2_Write_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0A2)
[Address] EAT @explorer.exe (IWICBitmapClipper_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDA6)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportAnimation_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAD0)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportLossless_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAF3)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportMultiframe_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB16)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetContainerFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D855)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceManufacturer_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA2C)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceModels_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA55)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetFileExtensions_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAA7)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetMimeTypes_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA7E)
[Address] EAT @explorer.exe (IWICBitmapDecoder_CopyPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D832)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA03)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetDecoderInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrameCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrame_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D89B)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetMetadataQueryReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetPreview_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCF0)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D855)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC81)
[Address] EAT @explorer.exe (IWICBitmapEncoder_CreateNewFrame_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC03)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetEncoderInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DBDA)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DBAE)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC58)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC2F)
[Address] EAT @explorer.exe (IWICBitmapFlipRotator_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDA6)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetMetadataQueryReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8EA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA1E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DACA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E010)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB82)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA70)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetSize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA3E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB59)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_WriteSource_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DAED)
[Address] EAT @explorer.exe (IWICBitmapLock_GetDataPointer_STA_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICBitmapLock_GetStride_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICBitmapScaler_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD7A)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPixels_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCC4)
[Address] EAT @explorer.exe (IWICBitmapSource_GetPixelFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICBitmapSource_GetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICBitmapSource_GetSize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D950)
[Address] EAT @explorer.exe (IWICBitmap_Lock_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9DA)
[Address] EAT @explorer.exe (IWICBitmap_SetPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCF0)
[Address] EAT @explorer.exe (IWICBitmap_SetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD13)
[Address] EAT @explorer.exe (IWICColorContext_InitializeFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D976)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateMetadataWriterFromReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D7BA)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateQueryWriterFromBlockWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D7E3)
[Address] EAT @explorer.exe (IWICComponentInfo_GetAuthor_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9B1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetCLSID_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICComponentInfo_GetFriendlyName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA03)
[Address] EAT @explorer.exe (IWICComponentInfo_GetSpecVersion_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetVersion_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9DA)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D90D)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICFormatConverter_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD43)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapClipper_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D567)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFlipRotator_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D590)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHBITMAP_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D6CA)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHICON_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D6F6)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D666)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromSource_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D63D)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapScaler_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D53E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmap_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D69B)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateComponentInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D4E9)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFileHandle_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D4B1)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFilename_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D476)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D43E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateEncoder_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D5E2)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromDecoder_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D71C)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromFrameDecode_Prox~Æ^�?qø"5ÿÿÿÿÌqtD*ÞÆ^B) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D742)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFormatConverter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D515)
[Address] EAT @explorer.exe (IWICImagingFactory_CreatePalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB59)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriterFromReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D791)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D768)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D5B9)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetReaderByIndex_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetContainerFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E010)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetEnumerator_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetLocation_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0A2)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_RemoveMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_SetMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E033)
[Address] EAT @explorer.exe (IWICPalette_GetColorCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9C5)
[Address] EAT @explorer.exe (IWICPalette_GetColors_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICPalette_GetType_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D832)
[Address] EAT @explorer.exe (IWICPalette_HasAlpha_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICPalette_InitializeCustom_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D976)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromBitmap_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D99C)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICPalette_InitializePredefined_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D950)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetBitsPerPixel_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DACA)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB39)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelMask_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB5C)
[Address] EAT @explorer.exe (IWICStream_InitializeFromIStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB39)
[Address] EAT @explorer.exe (IWICStream_InitializeFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDCC)
[Address] EAT @explorer.exe (WICConvertBitmapSource) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DE11)
[Address] EAT @explorer.exe (WICCreateBitmapFromSection) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DFE6)
[Address] EAT @explorer.exe (WICCreateBitmapFromSectionEx) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DEE5)
[Address] EAT @explorer.exe (WICCreateColorContext_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB88)
[Address] EAT @explorer.exe (WICCreateImagingFactory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D03B)
[Address] EAT @explorer.exe (WICGetMetadataContentSize) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E676)
[Address] EAT @explorer.exe (WICMapGuidToShortName) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D0FC)
[Address] EAT @explorer.exe (WICMapSchemaToName) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D2F0)
[Address] EAT @explorer.exe (WICMapShortNameToGuid) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D227)
[Address] EAT @explorer.exe (WICMatchMetadataContent) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0CB)
[Address] EAT @explorer.exe (WICSerializeMetadataContent) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E20D)
[Address] EAT @explorer.exe (WICSetEncoderFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDF2)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD32 00AAKS-00B3A SCSI Disk Device +++++
--- User ---
[MBR] 2994c85755f6acff0cad4bd53275dcc6
[BSP] be92604706e2c7bc6e6fc7b708001c1d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Incorrect function. )
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Generic USB SD Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ USB) Generic USB CF Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive3: (\\.\PHYSICALDRIVE3 @ USB) Generic USB SM Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive4: (\\.\PHYSICALDRIVE4 @ USB) Generic USB MS Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
Finished : << RKreport[0]_S_04102014_170153.txt >>
RKreport[0]_S_04092014_161100.txt
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : admin [Admin rights]
Mode : Scan -- Date : 04/10/2014 17:01:53
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 6 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] EAT @explorer.exe (BeginBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743009AE)
[Address] EAT @explorer.exe (BeginBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F49A1)
[Address] EAT @explorer.exe (BeginPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74320731)
[Address] EAT @explorer.exe (BufferedPaintClear) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F6395)
[Address] EAT @explorer.exe (BufferedPaintInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F940E)
[Address] EAT @explorer.exe (BufferedPaintRenderAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743008ED)
[Address] EAT @explorer.exe (BufferedPaintSetAlpha) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430E6B3)
[Address] EAT @explorer.exe (BufferedPaintStopAllAnimations) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430D395)
[Address] EAT @explorer.exe (BufferedPaintUnInit) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F94AB)
[Address] EAT @explorer.exe (CloseThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F6A18)
[Address] EAT @explorer.exe (DrawThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3982)
[Address] EAT @explorer.exe (DrawThemeBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430D9DA)
[Address] EAT @explorer.exe (DrawThemeEdge) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313B52)
[Address] EAT @explorer.exe (DrawThemeIcon) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743235E7)
[Address] EAT @explorer.exe (DrawThemeParentBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F53E5)
[Address] EAT @explorer.exe (DrawThemeParentBackgroundEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F51BF)
[Address] EAT @explorer.exe (DrawThemeText) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F4EA1)
[Address] EAT @explorer.exe (DrawThemeTextEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F63E6)
[Address] EAT @explorer.exe (EnableThemeDialogTexture) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FFCAF)
[Address] EAT @explorer.exe (EnableTheming) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322FEB)
[Address] EAT @explorer.exe (EndBufferedAnimation) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3F9A)
[Address] EAT @explorer.exe (EndBufferedPaint) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F3F9A)
[Address] EAT @explorer.exe (EndPanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743206CC)
[Address] EAT @explorer.exe (GetBufferedPaintBits) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F4BAF)
[Address] EAT @explorer.exe (GetBufferedPaintDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743004BC)
[Address] EAT @explorer.exe (GetBufferedPaintTargetDC) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300473)
[Address] EAT @explorer.exe (GetBufferedPaintTargetRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322E7F)
[Address] EAT @explorer.exe (GetCurrentThemeName) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743005DD)
[Address] EAT @explorer.exe (GetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300FB1)
[Address] EAT @explorer.exe (GetThemeBackgroundContentRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FCD2E)
[Address] EAT @explorer.exe (GetThemeBackgroundExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF8BF)
[Address] EAT @explorer.exe (GetThemeBackgroundRegion) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430165D)
[Address] EAT @explorer.exe (GetThemeBitmap) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FBF93)
[Address] EAT @explorer.exe (GetThemeBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F7C1F)
[Address] EAT @explorer.exe (GetThemeColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeDocumentationProperty) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322932)
[Address] EAT @explorer.exe (GetThemeEnumValue) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeFilename) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322412)
[Address] EAT @explorer.exe (GetThemeFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FFF21)
[Address] EAT @explorer.exe (GetThemeInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F616C)
[Address] EAT @explorer.exe (GetThemeIntList) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743223B1)
[Address] EAT @explorer.exe (GetThemeMargins) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F86E9)
[Address] EAT @explorer.exe (GetThemeMetric) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743006E2)
[Address] EAT @explorer.exe (GetThemePartSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FCDB1)
[Address] EAT @explorer.exe (GetThemePosition) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322350)
[Address] EAT @explorer.exe (GetThemePropertyOrigin) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313FBB)
[Address] EAT @explorer.exe (GetThemeRect) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74303611)
[Address] EAT @explorer.exe (GetThemeStream) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743039D9)
[Address] EAT @explorer.exe (GetThemeString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743222E4)
[Address] EAT @explorer.exe (GetThemeSysBool) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74323172)
[Address] EAT @explorer.exe (GetThemeSysColor) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313274)
[Address] EAT @explorer.exe (GetThemeSysColorBrush) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432301E)
[Address] EAT @explorer.exe (GetThemeSysFont) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x743229C4)
[Address] EAT @explorer.exe (GetThemeSysInt) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322BD3)
[Address] EAT @explorer.exe (GetThemeSysSize) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432320B)
[Address] EAT @explorer.exe (GetThemeSysString) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74322B3F)
[Address] EAT @explorer.exe (GetThemeTextExtent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F2D57)
[Address] EAT @explorer.exe (GetThemeTextMetrics) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF992)
[Address] EAT @explorer.exe (GetThemeTransitionDuration) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74301081)
[Address] EAT @explorer.exe (GetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FDF46)
[Address] EAT @explorer.exe (HitTestThemeBackground) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74303CE3)
[Address] EAT @explorer.exe (IsAppThemed) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF869)
[Address] EAT @explorer.exe (IsCompositionActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F2E9A)
[Address] EAT @explorer.exe (IsThemeActive) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FF785)
[Address] EAT @explorer.exe (IsThemeBackgroundPartiallyTransparent) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F60AB)
[Address] EAT @explorer.exe (IsThemeDialogTextureEnabled) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432312B)
[Address] EAT @explorer.exe (IsThemePartDefined) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F85B4)
[Address] EAT @explorer.exe (OpenThemeData) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742F73D2)
[Address] EAT @explorer.exe (OpenThemeDataEx) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74313D43)
[Address] EAT @explorer.exe (SetThemeAppProperties) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74323296)
[Address] EAT @explorer.exe (SetWindowTheme) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x74300134)
[Address] EAT @explorer.exe (SetWindowThemeAttribute) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7430CFE6)
[Address] EAT @explorer.exe (ThemeInitApiHook) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x742FB176)
[Address] EAT @explorer.exe (UpdatePanningFeedback) : PROPSYS.dll -> HOOKED (C:\Windows\system32\UxTheme.dll @ 0x7432068D)
[Address] EAT @explorer.exe (DllGetClassObject) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8CFAD)
[Address] EAT @explorer.exe (IEnumString_Next_WIC_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E059)
[Address] EAT @explorer.exe (IEnumString_Reset_WIC_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E082)
[Address] EAT @explorer.exe (IPropertyBag2_Write_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0A2)
[Address] EAT @explorer.exe (IWICBitmapClipper_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDA6)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportAnimation_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAD0)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportLossless_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAF3)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_DoesSupportMultiframe_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB16)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetContainerFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D855)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceManufacturer_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA2C)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetDeviceModels_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA55)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetFileExtensions_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EAA7)
[Address] EAT @explorer.exe (IWICBitmapCodecInfo_GetMimeTypes_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA7E)
[Address] EAT @explorer.exe (IWICBitmapDecoder_CopyPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D832)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA03)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetDecoderInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrameCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetFrame_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D89B)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetMetadataQueryReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetPreview_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCF0)
[Address] EAT @explorer.exe (IWICBitmapDecoder_GetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D855)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC81)
[Address] EAT @explorer.exe (IWICBitmapEncoder_CreateNewFrame_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC03)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetEncoderInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DBDA)
[Address] EAT @explorer.exe (IWICBitmapEncoder_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICBitmapEncoder_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DBAE)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC58)
[Address] EAT @explorer.exe (IWICBitmapEncoder_SetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DC2F)
[Address] EAT @explorer.exe (IWICBitmapFlipRotator_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDA6)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetMetadataQueryReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICBitmapFrameDecode_GetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8EA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA1E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DACA)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E010)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetColorContexts_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB82)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA70)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetSize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DA3E)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_SetThumbnail_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB59)
[Address] EAT @explorer.exe (IWICBitmapFrameEncode_WriteSource_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DAED)
[Address] EAT @explorer.exe (IWICBitmapLock_GetDataPointer_STA_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICBitmapLock_GetStride_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICBitmapScaler_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD7A)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICBitmapSource_CopyPixels_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCC4)
[Address] EAT @explorer.exe (IWICBitmapSource_GetPixelFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICBitmapSource_GetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICBitmapSource_GetSize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D950)
[Address] EAT @explorer.exe (IWICBitmap_Lock_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9DA)
[Address] EAT @explorer.exe (IWICBitmap_SetPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCF0)
[Address] EAT @explorer.exe (IWICBitmap_SetResolution_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD13)
[Address] EAT @explorer.exe (IWICColorContext_InitializeFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D976)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateMetadataWriterFromReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D7BA)
[Address] EAT @explorer.exe (IWICComponentFactory_CreateQueryWriterFromBlockWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D7E3)
[Address] EAT @explorer.exe (IWICComponentInfo_GetAuthor_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9B1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetCLSID_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICComponentInfo_GetFriendlyName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EA03)
[Address] EAT @explorer.exe (IWICComponentInfo_GetSpecVersion_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICComponentInfo_GetVersion_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E9DA)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_Commit_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D90D)
[Address] EAT @explorer.exe (IWICFastMetadataEncoder_GetMetadataQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICFormatConverter_Initialize_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DD43)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapClipper_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D567)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFlipRotator_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D590)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHBITMAP_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D6CA)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromHICON_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D6F6)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D666)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapFromSource_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D63D)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmapScaler_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D53E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateBitmap_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D69B)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateComponentInfo_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D4E9)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFileHandle_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D4B1)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromFilename_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D476)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateDecoderFromStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D43E)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateEncoder_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D5E2)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromDecoder_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D71C)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFastMetadataEncoderFromFrameDecode_Prox~Æ^�?qø"5ÿÿÿÿÌqtD*ÞÆ^B) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D742)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateFormatConverter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D515)
[Address] EAT @explorer.exe (IWICImagingFactory_CreatePalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DB59)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriterFromReader_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D791)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateQueryWriter_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D768)
[Address] EAT @explorer.exe (IWICImagingFactory_CreateStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D5B9)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D92D)
[Address] EAT @explorer.exe (IWICMetadataBlockReader_GetReaderByIndex_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetContainerFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E010)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetEnumerator_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetLocation_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0A2)
[Address] EAT @explorer.exe (IWICMetadataQueryReader_GetMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D80C)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_RemoveMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D878)
[Address] EAT @explorer.exe (IWICMetadataQueryWriter_SetMetadataByName_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E033)
[Address] EAT @explorer.exe (IWICPalette_GetColorCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9C5)
[Address] EAT @explorer.exe (IWICPalette_GetColors_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D8C1)
[Address] EAT @explorer.exe (IWICPalette_GetType_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D832)
[Address] EAT @explorer.exe (IWICPalette_HasAlpha_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D9FB)
[Address] EAT @explorer.exe (IWICPalette_InitializeCustom_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D976)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromBitmap_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D99C)
[Address] EAT @explorer.exe (IWICPalette_InitializeFromPalette_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DCA1)
[Address] EAT @explorer.exe (IWICPalette_InitializePredefined_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D950)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetBitsPerPixel_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DACA)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelCount_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB39)
[Address] EAT @explorer.exe (IWICPixelFormatInfo_GetChannelMask_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB5C)
[Address] EAT @explorer.exe (IWICStream_InitializeFromIStream_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB39)
[Address] EAT @explorer.exe (IWICStream_InitializeFromMemory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDCC)
[Address] EAT @explorer.exe (WICConvertBitmapSource) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DE11)
[Address] EAT @explorer.exe (WICCreateBitmapFromSection) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DFE6)
[Address] EAT @explorer.exe (WICCreateBitmapFromSectionEx) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DEE5)
[Address] EAT @explorer.exe (WICCreateColorContext_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8EB88)
[Address] EAT @explorer.exe (WICCreateImagingFactory_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D03B)
[Address] EAT @explorer.exe (WICGetMetadataContentSize) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E676)
[Address] EAT @explorer.exe (WICMapGuidToShortName) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D0FC)
[Address] EAT @explorer.exe (WICMapSchemaToName) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D2F0)
[Address] EAT @explorer.exe (WICMapShortNameToGuid) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8D227)
[Address] EAT @explorer.exe (WICMatchMetadataContent) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E0CB)
[Address] EAT @explorer.exe (WICSerializeMetadataContent) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8E20D)
[Address] EAT @explorer.exe (WICSetEncoderFormat_Proxy) : XmlLite.dll -> HOOKED (C:\Windows\system32\WindowsCodecs.dll @ 0x73E8DDF2)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD32 00AAKS-00B3A SCSI Disk Device +++++
--- User ---
[MBR] 2994c85755f6acff0cad4bd53275dcc6
[BSP] be92604706e2c7bc6e6fc7b708001c1d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 305243 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Incorrect function. )
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Generic USB SD Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ USB) Generic USB CF Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive3: (\\.\PHYSICALDRIVE3 @ USB) Generic USB SM Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
+++++ PhysicalDrive4: (\\.\PHYSICALDRIVE4 @ USB) Generic USB MS Reader USB Device +++++
Error reading User MBR! ([0x15] The device is not ready. )
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )
Finished : << RKreport[0]_S_04102014_170153.txt >>
RKreport[0]_S_04092014_161100.txt
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
17:06:58.0692 5692 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
17:07:01.0381 5692 ============================================================
17:07:01.0381 5692 Current date / time: 2014/04/10 17:07:01.0381
17:07:01.0381 5692 SystemInfo:
17:07:01.0381 5692
17:07:01.0381 5692 OS Version: 6.1.7601 ServicePack: 1.0
17:07:01.0381 5692 Product type: Workstation
17:07:01.0381 5692 ComputerName: PC
17:07:01.0382 5692 UserName: admin
17:07:01.0382 5692 Windows directory: C:\Windows
17:07:01.0382 5692 System windows directory: C:\Windows
17:07:01.0382 5692 Processor architecture: Intel x86
17:07:01.0382 5692 Number of processors: 2
17:07:01.0382 5692 Page size: 0x1000
17:07:01.0382 5692 Boot type: Normal boot
17:07:01.0382 5692 ============================================================
17:07:02.0403 5692 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:07:02.0421 5692 ============================================================
17:07:02.0421 5692 \Device\Harddisk0\DR0:
17:07:02.0422 5692 MBR partitions:
17:07:02.0422 5692 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2542D800
17:07:02.0422 5692 ============================================================
17:07:02.0440 5692 C: <-> \Device\Harddisk0\DR0\Partition1
17:07:02.0440 5692 ============================================================
17:07:02.0441 5692 Initialize success
17:07:02.0441 5692 ============================================================
17:07:03.0807 4344 ============================================================
17:07:03.0807 4344 Scan started
17:07:03.0807 4344 Mode: Manual;
17:07:03.0807 4344 ============================================================
17:07:04.0502 4344 ================ Scan system memory ========================
17:07:04.0502 4344 System memory - ok
17:07:04.0502 4344 ================ Scan services =============================
17:07:04.0731 4344 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:07:04.0733 4344 1394ohci - ok
17:07:04.0777 4344 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:07:04.0779 4344 ACPI - ok
17:07:04.0827 4344 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:07:04.0828 4344 AcpiPmi - ok
17:07:04.0994 4344 [ B362181ED3771DC03B4141927C80F801 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:07:04.0995 4344 AdobeARMservice - ok
17:07:05.0095 4344 [ 9D96B0D5855FD1B98023B3EEC9F06786 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:07:05.0099 4344 AdobeFlashPlayerUpdateSvc - ok
17:07:05.0279 4344 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:07:05.0283 4344 adp94xx - ok
17:07:05.0303 4344 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:07:05.0306 4344 adpahci - ok
17:07:05.0326 4344 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:07:05.0328 4344 adpu320 - ok
17:07:05.0388 4344 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:07:05.0390 4344 AeLookupSvc - ok
17:07:05.0443 4344 [ F81BB7E487EDCEAB630A7EE66CF23913 ] AFD C:\Windows\system32\drivers\afd.sys
17:07:05.0447 4344 AFD - ok
17:07:05.0490 4344 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:07:05.0491 4344 agp440 - ok
17:07:05.0537 4344 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:07:05.0539 4344 aic78xx - ok
17:07:05.0568 4344 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:07:05.0570 4344 ALG - ok
17:07:05.0619 4344 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:07:05.0620 4344 aliide - ok
17:07:05.0667 4344 [ DE697CA5522739901B17D60E18A48B57 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:07:05.0669 4344 AMD External Events Utility - ok
17:07:05.0739 4344 AMD FUEL Service - ok
17:07:05.0780 4344 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:07:05.0781 4344 amdagp - ok
17:07:05.0798 4344 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:07:05.0799 4344 amdide - ok
17:07:05.0815 4344 amdiox86 - ok
17:07:05.0869 4344 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:07:05.0870 4344 AmdK8 - ok
17:07:06.0068 4344 [ A5DE11C167222FB7F73588530F851784 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:07:06.0142 4344 amdkmdag - ok
17:07:06.0169 4344 [ 354D38ECA8452AB6D3489CAD80BCFF25 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
17:07:06.0174 4344 amdkmdap - ok
17:07:06.0191 4344 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:07:06.0192 4344 AmdPPM - ok
17:07:06.0232 4344 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:07:06.0234 4344 amdsata - ok
17:07:06.0253 4344 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:07:06.0255 4344 amdsbs - ok
17:07:06.0275 4344 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:07:06.0276 4344 amdxata - ok
17:07:06.0328 4344 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:07:06.0329 4344 AppID - ok
17:07:06.0387 4344 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:07:06.0388 4344 AppIDSvc - ok
17:07:06.0428 4344 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
17:07:06.0429 4344 Appinfo - ok
17:07:06.0446 4344 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:07:06.0450 4344 AppMgmt - ok
17:07:06.0463 4344 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:07:06.0464 4344 arc - ok
17:07:06.0485 4344 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:07:06.0487 4344 arcsas - ok
17:07:06.0616 4344 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:07:06.0635 4344 aspnet_state - ok
17:07:06.0697 4344 [ 4691B3FE3717F9D9C64A5282C8543D4D ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
17:07:06.0699 4344 aswKbd - ok
17:07:06.0753 4344 [ B347D2FEAE2D063943F16EC98634AB89 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:07:06.0754 4344 aswMonFlt - ok
17:07:06.0787 4344 [ 769C65057212FB5004679E02EF8145C0 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys
17:07:06.0788 4344 aswRdr - ok
17:07:06.0813 4344 [ 84B4C00AE8CDFC52CF68F322D821F34C ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
17:07:06.0815 4344 aswRvrt - ok
17:07:06.0839 4344 [ 3A50AD6AE8D8A0F78F03316F5B93FE45 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:07:06.0844 4344 aswSnx - ok
17:07:06.0897 4344 [ B6381B4DC603C558419641BA969930E0 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:07:06.0901 4344 aswSP - ok
17:07:06.0909 4344 [ 9529E946B8496C1605A9188FFD49DED8 ] aswStm C:\Windows\system32\drivers\aswStm.sys
17:07:06.0911 4344 aswStm - ok
17:07:06.0937 4344 [ 660D572C1452ADCBE200A3EA26AD6404 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:07:06.0939 4344 aswTdi - ok
17:07:06.0956 4344 [ 680448905E27BBC6587ADB28597640D6 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
17:07:06.0959 4344 aswVmm - ok
17:07:06.0980 4344 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:07:06.0981 4344 AsyncMac - ok
17:07:07.0034 4344 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:07:07.0035 4344 atapi - ok
17:07:07.0100 4344 [ 4D201D8B576BE4473405B2A86A2D28B3 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:07:07.0102 4344 AtiHDAudioService - ok
17:07:07.0158 4344 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:07:07.0174 4344 AudioEndpointBuilder - ok
17:07:07.0185 4344 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:07:07.0189 4344 Audiosrv - ok
17:07:07.0257 4344 [ BEA8D0FA8805CC2E6BB49728166699C7 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:07:07.0258 4344 avast! Antivirus - ok
17:07:07.0306 4344 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:07:07.0309 4344 AxInstSV - ok
17:07:07.0338 4344 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:07:07.0343 4344 b06bdrv - ok
17:07:07.0370 4344 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:07:07.0372 4344 b57nd60x - ok
17:07:07.0424 4344 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:07:07.0426 4344 BDESVC - ok
17:07:07.0441 4344 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:07:07.0442 4344 Beep - ok
17:07:07.0479 4344 [ B1359701847FF1FF415FA083F1610F48 ] BEService C:\Program Files\Common Files\BattlEye\BEService.exe
17:07:07.0481 4344 BEService - ok
17:07:07.0538 4344 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:07:07.0556 4344 BFE - ok
17:07:07.0604 4344 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:07:07.0621 4344 BITS - ok
17:07:07.0633 4344 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:07:07.0634 4344 blbdrive - ok
17:07:07.0683 4344 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:07:07.0684 4344 bowser - ok
17:07:07.0700 4344 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:07:07.0701 4344 BrFiltLo - ok
17:07:07.0719 4344 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:07:07.0720 4344 BrFiltUp - ok
17:07:07.0764 4344 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:07:07.0767 4344 Browser - ok
17:07:07.0795 4344 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:07:07.0798 4344 Brserid - ok
17:07:07.0819 4344 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:07:07.0821 4344 BrSerWdm - ok
17:07:07.0838 4344 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:07:07.0839 4344 BrUsbMdm - ok
17:07:07.0862 4344 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:07:07.0863 4344 BrUsbSer - ok
17:07:07.0877 4344 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:07:07.0878 4344 BTHMODEM - ok
17:07:07.0936 4344 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:07:07.0938 4344 bthserv - ok
17:07:07.0960 4344 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:07:07.0961 4344 cdfs - ok
17:07:08.0016 4344 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:07:08.0018 4344 cdrom - ok
17:07:08.0075 4344 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:07:08.0078 4344 CertPropSvc - ok
17:07:08.0091 4344 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:07:08.0093 4344 circlass - ok
17:07:08.0148 4344 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:07:08.0152 4344 CLFS - ok
17:07:08.0207 4344 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:07:08.0210 4344 clr_optimization_v2.0.50727_32 - ok
17:07:08.0253 4344 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:07:08.0298 4344 clr_optimization_v4.0.30319_32 - ok
17:07:08.0312 4344 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:07:08.0313 4344 CmBatt - ok
17:07:08.0364 4344 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:07:08.0365 4344 cmdide - ok
17:07:08.0453 4344 [ 85449EEBE8F8EBD6481EFBF0F352B4EB ] CNG C:\Windows\system32\Drivers\cng.sys
17:07:08.0456 4344 CNG - ok
17:07:08.0505 4344 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:07:08.0507 4344 Compbatt - ok
17:07:08.0560 4344 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:07:08.0561 4344 CompositeBus - ok
17:07:08.0568 4344 COMSysApp - ok
17:07:08.0584 4344 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:07:08.0585 4344 crcdisk - ok
17:07:08.0634 4344 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:07:08.0638 4344 CryptSvc - ok
17:07:08.0686 4344 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:07:08.0690 4344 CSC - ok
17:07:08.0740 4344 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:07:08.0757 4344 CscService - ok
17:07:08.0780 4344 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:07:08.0788 4344 DcomLaunch - ok
17:07:08.0837 4344 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:07:08.0842 4344 defragsvc - ok
17:07:08.0911 4344 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:07:08.0912 4344 DfsC - ok
17:07:08.0978 4344 [ EDF7F8387C2072205ABCF105F14B13B4 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
17:07:08.0980 4344 dg_ssudbus - ok
17:07:09.0039 4344 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:07:09.0044 4344 Dhcp - ok
17:07:09.0056 4344 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:07:09.0058 4344 discache - ok
17:07:09.0090 4344 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:07:09.0091 4344 Disk - ok
17:07:09.0132 4344 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:07:09.0176 4344 Dnscache - ok
17:07:09.0243 4344 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:07:09.0335 4344 dot3svc - ok
17:07:09.0388 4344 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:07:09.0393 4344 DPS - ok
17:07:09.0449 4344 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:07:09.0450 4344 drmkaud - ok
17:07:09.0504 4344 [ 71BC35067CABC02C9453AEAA42B2E43E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:07:09.0509 4344 DXGKrnl - ok
17:07:09.0556 4344 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:07:09.0560 4344 EapHost - ok
17:07:09.0629 4344 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:07:09.0650 4344 ebdrv - ok
17:07:09.0694 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] EFS C:\Windows\System32\lsass.exe
17:07:09.0698 4344 EFS - ok
17:07:09.0749 4344 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:07:09.0766 4344 ehRecvr - ok
17:07:09.0788 4344 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:07:09.0791 4344 ehSched - ok
17:07:09.0834 4344 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:07:09.0839 4344 elxstor - ok
17:07:09.0878 4344 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:07:09.0879 4344 ErrDev - ok
17:07:09.0917 4344 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:07:09.0923 4344 EventSystem - ok
17:07:09.0948 4344 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:07:09.0950 4344 exfat - ok
17:07:09.0969 4344 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:07:09.0971 4344 fastfat - ok
17:07:10.0033 4344 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:07:10.0050 4344 Fax - ok
17:07:10.0061 4344 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:07:10.0062 4344 fdc - ok
17:07:10.0103 4344 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:07:10.0106 4344 fdPHost - ok
17:07:10.0119 4344 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:07:10.0122 4344 FDResPub - ok
17:07:10.0137 4344 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:07:10.0138 4344 FileInfo - ok
17:07:10.0144 4344 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:07:10.0146 4344 Filetrace - ok
17:07:10.0157 4344 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:07:10.0158 4344 flpydisk - ok
17:07:10.0181 4344 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:07:10.0183 4344 FltMgr - ok
17:07:10.0246 4344 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
17:07:10.0264 4344 FontCache - ok
17:07:10.0369 4344 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:07:10.0371 4344 FontCache3.0.0.0 - ok
17:07:10.0377 4344 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:07:10.0379 4344 FsDepends - ok
17:07:10.0420 4344 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:07:10.0421 4344 Fs_Rec - ok
17:07:10.0467 4344 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:07:10.0469 4344 fvevol - ok
17:07:10.0499 4344 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:07:10.0501 4344 gagp30kx - ok
17:07:10.0548 4344 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:07:10.0566 4344 gpsvc - ok
17:07:10.0638 4344 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
17:07:10.0640 4344 gupdate - ok
17:07:10.0645 4344 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
17:07:10.0648 4344 gupdatem - ok
17:07:10.0690 4344 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:07:10.0691 4344 hcw85cir - ok
17:07:10.0755 4344 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:07:10.0758 4344 HdAudAddService - ok
17:07:10.0784 4344 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:07:10.0786 4344 HDAudBus - ok
17:07:10.0800 4344 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:07:10.0801 4344 HidBatt - ok
17:07:10.0819 4344 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:07:10.0821 4344 HidBth - ok
17:07:10.0860 4344 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:07:10.0861 4344 HidIr - ok
17:07:10.0904 4344 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:07:10.0907 4344 hidserv - ok
17:07:10.0967 4344 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
17:07:10.0969 4344 HidUsb - ok
17:07:11.0010 4344 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:07:11.0015 4344 hkmsvc - ok
17:07:11.0057 4344 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:07:11.0063 4344 HomeGroupListener - ok
17:07:11.0111 4344 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:07:11.0128 4344 HomeGroupProvider - ok
17:07:11.0176 4344 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:07:11.0178 4344 HpSAMD - ok
17:07:11.0246 4344 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:07:11.0250 4344 HTTP - ok
17:07:11.0305 4344 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:07:11.0306 4344 hwpolicy - ok
17:07:11.0352 4344 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:07:11.0353 4344 i8042prt - ok
17:07:11.0411 4344 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:07:11.0415 4344 iaStorV - ok
17:07:11.0482 4344 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:07:11.0500 4344 idsvc - ok
17:07:11.0528 4344 IEEtwCollectorService - ok
17:07:11.0555 4344 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:07:11.0556 4344 iirsp - ok
17:07:11.0611 4344 [ B9C54120F46392100478F58F374E5709 ] IKEEXT C:\Windows\System32\ikeext.dll
17:07:11.0629 4344 IKEEXT - ok
17:07:11.0709 4344 [ BC9B2C44139B4E103105F024D00B46D5 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
17:07:11.0729 4344 IntcAzAudAddService - ok
17:07:11.0745 4344 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:07:11.0746 4344 intelide - ok
17:07:11.0766 4344 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:07:11.0768 4344 intelppm - ok
17:07:11.0819 4344 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:07:11.0823 4344 IPBusEnum - ok
17:07:11.0841 4344 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:07:11.0842 4344 IpFilterDriver - ok
17:07:11.0891 4344 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:07:11.0908 4344 iphlpsvc - ok
17:07:11.0959 4344 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:07:11.0960 4344 IPMIDRV - ok
17:07:11.0976 4344 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:07:11.0978 4344 IPNAT - ok
17:07:11.0999 4344 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:07:12.0000 4344 IRENUM - ok
17:07:12.0037 4344 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:07:12.0039 4344 isapnp - ok
17:07:12.0086 4344 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:07:12.0089 4344 iScsiPrt - ok
17:07:12.0109 4344 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:07:12.0110 4344 kbdclass - ok
17:07:12.0161 4344 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
17:07:12.0163 4344 kbdhid - ok
17:07:12.0169 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] KeyIso C:\Windows\system32\lsass.exe
17:07:12.0173 4344 KeyIso - ok
17:07:12.0218 4344 [ F286830298323272260332D6ABC905C1 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:07:12.0219 4344 KSecDD - ok
17:07:12.0232 4344 [ D7C760D57B1656DD748B9E4AB6CB5A51 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:07:12.0234 4344 KSecPkg - ok
17:07:12.0287 4344 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:07:12.0304 4344 KtmRm - ok
17:07:12.0358 4344 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:07:12.0375 4344 LanmanServer - ok
17:07:12.0430 4344 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:07:12.0437 4344 LanmanWorkstation - ok
17:07:12.0464 4344 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:07:12.0465 4344 lltdio - ok
17:07:12.0507 4344 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:07:12.0513 4344 lltdsvc - ok
17:07:12.0531 4344 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:07:12.0535 4344 lmhosts - ok
17:07:12.0555 4344 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:07:12.0557 4344 LSI_FC - ok
17:07:12.0590 4344 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:07:12.0592 4344 LSI_SAS - ok
17:07:12.0611 4344 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:07:12.0612 4344 LSI_SAS2 - ok
17:07:12.0626 4344 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:07:12.0628 4344 LSI_SCSI - ok
17:07:12.0641 4344 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:07:12.0643 4344 luafv - ok
17:07:12.0686 4344 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:07:12.0691 4344 Mcx2Svc - ok
17:07:12.0713 4344 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:07:12.0714 4344 megasas - ok
17:07:12.0737 4344 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:07:12.0740 4344 MegaSR - ok
17:07:12.0779 4344 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:07:12.0784 4344 MMCSS - ok
17:07:12.0800 4344 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:07:12.0801 4344 Modem - ok
17:07:12.0821 4344 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:07:12.0822 4344 monitor - ok
17:07:12.0866 4344 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:07:12.0868 4344 mouclass - ok
17:07:12.0878 4344 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:07:12.0879 4344 mouhid - ok
17:07:12.0923 4344 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:07:12.0925 4344 mountmgr - ok
17:07:12.0966 4344 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:07:12.0968 4344 mpio - ok
17:07:12.0998 4344 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:07:12.0999 4344 mpsdrv - ok
17:07:13.0093 4344 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:07:13.0112 4344 MpsSvc - ok
17:07:13.0158 4344 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:07:13.0159 4344 MRxDAV - ok
17:07:13.0198 4344 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:07:13.0200 4344 mrxsmb - ok
17:07:13.0212 4344 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:07:13.0215 4344 mrxsmb10 - ok
17:07:13.0258 4344 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:07:13.0259 4344 mrxsmb20 - ok
17:07:13.0299 4344 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:07:13.0300 4344 msahci - ok
17:07:13.0339 4344 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:07:13.0341 4344 msdsm - ok
17:07:13.0358 4344 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:07:13.0364 4344 MSDTC - ok
17:07:13.0404 4344 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:07:13.0406 4344 Msfs - ok
17:07:13.0417 4344 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:07:13.0418 4344 mshidkmdf - ok
17:07:13.0465 4344 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:07:13.0466 4344 msisadrv - ok
17:07:13.0505 4344 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:07:13.0510 4344 MSiSCSI - ok
17:07:13.0516 4344 msiserver - ok
17:07:13.0547 4344 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:07:13.0549 4344 MSKSSRV - ok
17:07:13.0572 4344 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:07:13.0573 4344 MSPCLOCK - ok
17:07:13.0592 4344 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:07:13.0593 4344 MSPQM - ok
17:07:13.0615 4344 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:07:13.0617 4344 MsRPC - ok
17:07:13.0632 4344 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:07:13.0633 4344 mssmbios - ok
17:07:13.0652 4344 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:07:13.0653 4344 MSTEE - ok
17:07:13.0696 4344 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:07:13.0697 4344 MTConfig - ok
17:07:13.0704 4344 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:07:13.0706 4344 Mup - ok
17:07:13.0755 4344 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:07:13.0772 4344 napagent - ok
17:07:13.0793 4344 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:07:13.0797 4344 NativeWifiP - ok
17:07:13.0860 4344 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:07:13.0866 4344 NDIS - ok
17:07:13.0886 4344 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:07:13.0888 4344 NdisCap - ok
17:07:13.0910 4344 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:07:13.0911 4344 NdisTapi - ok
17:07:13.0949 4344 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:07:13.0950 4344 Ndisuio - ok
17:07:13.0987 4344 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:07:13.0988 4344 NdisWan - ok
17:07:14.0034 4344 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:07:14.0035 4344 NDProxy - ok
17:07:14.0049 4344 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:07:14.0051 4344 NetBIOS - ok
17:07:14.0101 4344 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:07:14.0104 4344 NetBT - ok
17:07:14.0120 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] Netlogon C:\Windows\system32\lsass.exe
17:07:14.0124 4344 Netlogon - ok
17:07:14.0179 4344 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:07:14.0196 4344 Netman - ok
17:07:14.0228 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0240 4344 NetMsmqActivator - ok
17:07:14.0246 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0249 4344 NetPipeActivator - ok
17:07:14.0271 4344 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:07:14.0278 4344 netprofm - ok
17:07:14.0285 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0287 4344 NetTcpActivator - ok
17:07:14.0293 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0296 4344 NetTcpPortSharing - ok
17:07:14.0322 4344 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:07:14.0324 4344 nfrd960 - ok
17:07:14.0367 4344 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
17:07:14.0384 4344 NlaSvc - ok
17:07:14.0393 4344 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:07:14.0395 4344 Npfs - ok
17:07:14.0441 4344 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:07:14.0446 4344 nsi - ok
17:07:14.0459 4344 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:07:14.0460 4344 nsiproxy - ok
17:07:14.0530 4344 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:07:14.0538 4344 Ntfs - ok
17:07:14.0575 4344 NTIOLib_1_0_3 - ok
17:07:14.0589 4344 NTIOLib_1_0_4 - ok
17:07:14.0605 4344 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:07:14.0607 4344 Null - ok
17:07:14.0666 4344 [ B5E37E31C053BC9950455A257526514B ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x32.sys
17:07:14.0669 4344 NVENETFD - ok
17:07:14.0703 4344 [ 1DE923088878B495CD4219E47BA34EB8 ] NVNET C:\Windows\system32\DRIVERS\nvmf6232.sys
17:07:14.0706 4344 NVNET - ok
17:07:14.0749 4344 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:07:14.0751 4344 nvraid - ok
17:07:14.0768 4344 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:07:14.0770 4344 nvstor - ok
17:07:14.0814 4344 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:07:14.0816 4344 nv_agp - ok
17:07:14.0876 4344 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:07:14.0878 4344 ohci1394 - ok
17:07:14.0924 4344 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:07:14.0941 4344 p2pimsvc - ok
17:07:14.0996 4344 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:07:15.0013 4344 p2psvc - ok
17:07:15.0034 4344 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:07:15.0036 4344 Parport - ok
17:07:15.0076 4344 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:07:15.0077 4344 partmgr - ok
17:07:15.0088 4344 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:07:15.0089 4344 Parvdm - ok
17:07:15.0104 4344 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:07:15.0111 4344 PcaSvc - ok
17:07:15.0137 4344 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:07:15.0139 4344 pci - ok
17:07:15.0151 4344 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:07:15.0152 4344 pciide - ok
17:07:15.0216 4344 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:07:15.0219 4344 pcmcia - ok
17:07:15.0240 4344 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:07:15.0241 4344 pcw - ok
17:07:15.0287 4344 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:07:15.0292 4344 PEAUTH - ok
17:07:15.0343 4344 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:07:15.0377 4344 PeerDistSvc - ok
17:07:15.0577 4344 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:07:15.0604 4344 pla - ok
17:07:15.0713 4344 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:07:15.0727 4344 PlugPlay - ok
17:07:15.0782 4344 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:07:15.0791 4344 PNRPAutoReg - ok
17:07:15.0811 4344 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:07:15.0818 4344 PNRPsvc - ok
17:07:15.0850 4344 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:07:15.0857 4344 PolicyAgent - ok
17:07:15.0912 4344 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:07:15.0920 4344 Power - ok
17:07:15.0975 4344 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:07:15.0976 4344 PptpMiniport - ok
17:07:15.0991 4344 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:07:15.0993 4344 Processor - ok
17:07:16.0033 4344 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:07:16.0050 4344 ProfSvc - ok
17:07:16.0062 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:07:16.0066 4344 ProtectedStorage - ok
17:07:16.0086 4344 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:07:16.0088 4344 Psched - ok
17:07:16.0158 4344 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:07:16.0169 4344 ql2300 - ok
17:07:16.0196 4344 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:07:16.0198 4344 ql40xx - ok
17:07:16.0207 4344 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:07:16.0216 4344 QWAVE - ok
17:07:16.0238 4344 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:07:16.0239 4344 QWAVEdrv - ok
17:07:16.0263 4344 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:07:16.0264 4344 RasAcd - ok
17:07:16.0312 4344 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:07:16.0313 4344 RasAgileVpn - ok
17:07:16.0319 4344 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:07:16.0326 4344 RasAuto - ok
17:07:16.0336 4344 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:07:16.0338 4344 Rasl2tp - ok
17:07:16.0391 4344 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:07:16.0408 4344 RasMan - ok
17:07:16.0424 4344 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:07:16.0426 4344 RasPppoe - ok
17:07:16.0452 4344 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:07:16.0453 4344 RasSstp - ok
17:07:16.0508 4344 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:07:16.0511 4344 rdbss - ok
17:07:16.0526 4344 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:07:16.0527 4344 rdpbus - ok
17:07:16.0575 4344 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:07:16.0576 4344 RDPCDD - ok
17:07:16.0625 4344 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:07:16.0627 4344 RDPDR - ok
17:07:16.0641 4344 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:07:16.0642 4344 RDPENCDD - ok
17:07:16.0662 4344 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:07:16.0664 4344 RDPREFMP - ok
17:07:16.0722 4344 [ 65375DF758CA1872AB7EBBBA457FD5E6 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:07:16.0723 4344 RdpVideoMiniport - ok
17:07:16.0767 4344 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:07:16.0769 4344 RDPWD - ok
17:07:16.0814 4344 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:07:16.0817 4344 rdyboost - ok
17:07:16.0861 4344 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:07:16.0866 4344 RemoteAccess - ok
17:07:16.0909 4344 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:07:16.0916 4344 RemoteRegistry - ok
17:07:16.0926 4344 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:07:16.0933 4344 RpcEptMapper - ok
17:07:16.0980 4344 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:07:16.0984 4344 RpcLocator - ok
17:07:16.0997 4344 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:07:17.0006 4344 RpcSs - ok
17:07:17.0021 4344 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:07:17.0023 4344 rspndr - ok
17:07:17.0065 4344 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:07:17.0066 4344 s3cap - ok
17:07:17.0072 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] SamSs C:\Windows\system32\lsass.exe
17:07:01.0381 5692 ============================================================
17:07:01.0381 5692 Current date / time: 2014/04/10 17:07:01.0381
17:07:01.0381 5692 SystemInfo:
17:07:01.0381 5692
17:07:01.0381 5692 OS Version: 6.1.7601 ServicePack: 1.0
17:07:01.0381 5692 Product type: Workstation
17:07:01.0381 5692 ComputerName: PC
17:07:01.0382 5692 UserName: admin
17:07:01.0382 5692 Windows directory: C:\Windows
17:07:01.0382 5692 System windows directory: C:\Windows
17:07:01.0382 5692 Processor architecture: Intel x86
17:07:01.0382 5692 Number of processors: 2
17:07:01.0382 5692 Page size: 0x1000
17:07:01.0382 5692 Boot type: Normal boot
17:07:01.0382 5692 ============================================================
17:07:02.0403 5692 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:07:02.0421 5692 ============================================================
17:07:02.0421 5692 \Device\Harddisk0\DR0:
17:07:02.0422 5692 MBR partitions:
17:07:02.0422 5692 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2542D800
17:07:02.0422 5692 ============================================================
17:07:02.0440 5692 C: <-> \Device\Harddisk0\DR0\Partition1
17:07:02.0440 5692 ============================================================
17:07:02.0441 5692 Initialize success
17:07:02.0441 5692 ============================================================
17:07:03.0807 4344 ============================================================
17:07:03.0807 4344 Scan started
17:07:03.0807 4344 Mode: Manual;
17:07:03.0807 4344 ============================================================
17:07:04.0502 4344 ================ Scan system memory ========================
17:07:04.0502 4344 System memory - ok
17:07:04.0502 4344 ================ Scan services =============================
17:07:04.0731 4344 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:07:04.0733 4344 1394ohci - ok
17:07:04.0777 4344 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:07:04.0779 4344 ACPI - ok
17:07:04.0827 4344 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:07:04.0828 4344 AcpiPmi - ok
17:07:04.0994 4344 [ B362181ED3771DC03B4141927C80F801 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:07:04.0995 4344 AdobeARMservice - ok
17:07:05.0095 4344 [ 9D96B0D5855FD1B98023B3EEC9F06786 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:07:05.0099 4344 AdobeFlashPlayerUpdateSvc - ok
17:07:05.0279 4344 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:07:05.0283 4344 adp94xx - ok
17:07:05.0303 4344 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:07:05.0306 4344 adpahci - ok
17:07:05.0326 4344 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:07:05.0328 4344 adpu320 - ok
17:07:05.0388 4344 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:07:05.0390 4344 AeLookupSvc - ok
17:07:05.0443 4344 [ F81BB7E487EDCEAB630A7EE66CF23913 ] AFD C:\Windows\system32\drivers\afd.sys
17:07:05.0447 4344 AFD - ok
17:07:05.0490 4344 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:07:05.0491 4344 agp440 - ok
17:07:05.0537 4344 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:07:05.0539 4344 aic78xx - ok
17:07:05.0568 4344 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:07:05.0570 4344 ALG - ok
17:07:05.0619 4344 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:07:05.0620 4344 aliide - ok
17:07:05.0667 4344 [ DE697CA5522739901B17D60E18A48B57 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:07:05.0669 4344 AMD External Events Utility - ok
17:07:05.0739 4344 AMD FUEL Service - ok
17:07:05.0780 4344 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:07:05.0781 4344 amdagp - ok
17:07:05.0798 4344 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:07:05.0799 4344 amdide - ok
17:07:05.0815 4344 amdiox86 - ok
17:07:05.0869 4344 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:07:05.0870 4344 AmdK8 - ok
17:07:06.0068 4344 [ A5DE11C167222FB7F73588530F851784 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:07:06.0142 4344 amdkmdag - ok
17:07:06.0169 4344 [ 354D38ECA8452AB6D3489CAD80BCFF25 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
17:07:06.0174 4344 amdkmdap - ok
17:07:06.0191 4344 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:07:06.0192 4344 AmdPPM - ok
17:07:06.0232 4344 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:07:06.0234 4344 amdsata - ok
17:07:06.0253 4344 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:07:06.0255 4344 amdsbs - ok
17:07:06.0275 4344 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:07:06.0276 4344 amdxata - ok
17:07:06.0328 4344 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:07:06.0329 4344 AppID - ok
17:07:06.0387 4344 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:07:06.0388 4344 AppIDSvc - ok
17:07:06.0428 4344 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
17:07:06.0429 4344 Appinfo - ok
17:07:06.0446 4344 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:07:06.0450 4344 AppMgmt - ok
17:07:06.0463 4344 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:07:06.0464 4344 arc - ok
17:07:06.0485 4344 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:07:06.0487 4344 arcsas - ok
17:07:06.0616 4344 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:07:06.0635 4344 aspnet_state - ok
17:07:06.0697 4344 [ 4691B3FE3717F9D9C64A5282C8543D4D ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
17:07:06.0699 4344 aswKbd - ok
17:07:06.0753 4344 [ B347D2FEAE2D063943F16EC98634AB89 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:07:06.0754 4344 aswMonFlt - ok
17:07:06.0787 4344 [ 769C65057212FB5004679E02EF8145C0 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys
17:07:06.0788 4344 aswRdr - ok
17:07:06.0813 4344 [ 84B4C00AE8CDFC52CF68F322D821F34C ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
17:07:06.0815 4344 aswRvrt - ok
17:07:06.0839 4344 [ 3A50AD6AE8D8A0F78F03316F5B93FE45 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:07:06.0844 4344 aswSnx - ok
17:07:06.0897 4344 [ B6381B4DC603C558419641BA969930E0 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:07:06.0901 4344 aswSP - ok
17:07:06.0909 4344 [ 9529E946B8496C1605A9188FFD49DED8 ] aswStm C:\Windows\system32\drivers\aswStm.sys
17:07:06.0911 4344 aswStm - ok
17:07:06.0937 4344 [ 660D572C1452ADCBE200A3EA26AD6404 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:07:06.0939 4344 aswTdi - ok
17:07:06.0956 4344 [ 680448905E27BBC6587ADB28597640D6 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
17:07:06.0959 4344 aswVmm - ok
17:07:06.0980 4344 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:07:06.0981 4344 AsyncMac - ok
17:07:07.0034 4344 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:07:07.0035 4344 atapi - ok
17:07:07.0100 4344 [ 4D201D8B576BE4473405B2A86A2D28B3 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:07:07.0102 4344 AtiHDAudioService - ok
17:07:07.0158 4344 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:07:07.0174 4344 AudioEndpointBuilder - ok
17:07:07.0185 4344 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:07:07.0189 4344 Audiosrv - ok
17:07:07.0257 4344 [ BEA8D0FA8805CC2E6BB49728166699C7 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:07:07.0258 4344 avast! Antivirus - ok
17:07:07.0306 4344 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:07:07.0309 4344 AxInstSV - ok
17:07:07.0338 4344 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:07:07.0343 4344 b06bdrv - ok
17:07:07.0370 4344 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:07:07.0372 4344 b57nd60x - ok
17:07:07.0424 4344 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:07:07.0426 4344 BDESVC - ok
17:07:07.0441 4344 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:07:07.0442 4344 Beep - ok
17:07:07.0479 4344 [ B1359701847FF1FF415FA083F1610F48 ] BEService C:\Program Files\Common Files\BattlEye\BEService.exe
17:07:07.0481 4344 BEService - ok
17:07:07.0538 4344 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:07:07.0556 4344 BFE - ok
17:07:07.0604 4344 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:07:07.0621 4344 BITS - ok
17:07:07.0633 4344 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:07:07.0634 4344 blbdrive - ok
17:07:07.0683 4344 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:07:07.0684 4344 bowser - ok
17:07:07.0700 4344 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:07:07.0701 4344 BrFiltLo - ok
17:07:07.0719 4344 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:07:07.0720 4344 BrFiltUp - ok
17:07:07.0764 4344 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:07:07.0767 4344 Browser - ok
17:07:07.0795 4344 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:07:07.0798 4344 Brserid - ok
17:07:07.0819 4344 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:07:07.0821 4344 BrSerWdm - ok
17:07:07.0838 4344 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:07:07.0839 4344 BrUsbMdm - ok
17:07:07.0862 4344 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:07:07.0863 4344 BrUsbSer - ok
17:07:07.0877 4344 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:07:07.0878 4344 BTHMODEM - ok
17:07:07.0936 4344 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:07:07.0938 4344 bthserv - ok
17:07:07.0960 4344 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:07:07.0961 4344 cdfs - ok
17:07:08.0016 4344 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:07:08.0018 4344 cdrom - ok
17:07:08.0075 4344 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:07:08.0078 4344 CertPropSvc - ok
17:07:08.0091 4344 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:07:08.0093 4344 circlass - ok
17:07:08.0148 4344 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:07:08.0152 4344 CLFS - ok
17:07:08.0207 4344 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:07:08.0210 4344 clr_optimization_v2.0.50727_32 - ok
17:07:08.0253 4344 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:07:08.0298 4344 clr_optimization_v4.0.30319_32 - ok
17:07:08.0312 4344 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:07:08.0313 4344 CmBatt - ok
17:07:08.0364 4344 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:07:08.0365 4344 cmdide - ok
17:07:08.0453 4344 [ 85449EEBE8F8EBD6481EFBF0F352B4EB ] CNG C:\Windows\system32\Drivers\cng.sys
17:07:08.0456 4344 CNG - ok
17:07:08.0505 4344 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:07:08.0507 4344 Compbatt - ok
17:07:08.0560 4344 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:07:08.0561 4344 CompositeBus - ok
17:07:08.0568 4344 COMSysApp - ok
17:07:08.0584 4344 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:07:08.0585 4344 crcdisk - ok
17:07:08.0634 4344 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:07:08.0638 4344 CryptSvc - ok
17:07:08.0686 4344 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:07:08.0690 4344 CSC - ok
17:07:08.0740 4344 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:07:08.0757 4344 CscService - ok
17:07:08.0780 4344 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:07:08.0788 4344 DcomLaunch - ok
17:07:08.0837 4344 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:07:08.0842 4344 defragsvc - ok
17:07:08.0911 4344 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:07:08.0912 4344 DfsC - ok
17:07:08.0978 4344 [ EDF7F8387C2072205ABCF105F14B13B4 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
17:07:08.0980 4344 dg_ssudbus - ok
17:07:09.0039 4344 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:07:09.0044 4344 Dhcp - ok
17:07:09.0056 4344 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:07:09.0058 4344 discache - ok
17:07:09.0090 4344 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:07:09.0091 4344 Disk - ok
17:07:09.0132 4344 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:07:09.0176 4344 Dnscache - ok
17:07:09.0243 4344 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:07:09.0335 4344 dot3svc - ok
17:07:09.0388 4344 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:07:09.0393 4344 DPS - ok
17:07:09.0449 4344 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:07:09.0450 4344 drmkaud - ok
17:07:09.0504 4344 [ 71BC35067CABC02C9453AEAA42B2E43E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:07:09.0509 4344 DXGKrnl - ok
17:07:09.0556 4344 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:07:09.0560 4344 EapHost - ok
17:07:09.0629 4344 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:07:09.0650 4344 ebdrv - ok
17:07:09.0694 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] EFS C:\Windows\System32\lsass.exe
17:07:09.0698 4344 EFS - ok
17:07:09.0749 4344 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:07:09.0766 4344 ehRecvr - ok
17:07:09.0788 4344 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:07:09.0791 4344 ehSched - ok
17:07:09.0834 4344 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:07:09.0839 4344 elxstor - ok
17:07:09.0878 4344 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:07:09.0879 4344 ErrDev - ok
17:07:09.0917 4344 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:07:09.0923 4344 EventSystem - ok
17:07:09.0948 4344 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:07:09.0950 4344 exfat - ok
17:07:09.0969 4344 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:07:09.0971 4344 fastfat - ok
17:07:10.0033 4344 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:07:10.0050 4344 Fax - ok
17:07:10.0061 4344 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:07:10.0062 4344 fdc - ok
17:07:10.0103 4344 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:07:10.0106 4344 fdPHost - ok
17:07:10.0119 4344 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:07:10.0122 4344 FDResPub - ok
17:07:10.0137 4344 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:07:10.0138 4344 FileInfo - ok
17:07:10.0144 4344 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:07:10.0146 4344 Filetrace - ok
17:07:10.0157 4344 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:07:10.0158 4344 flpydisk - ok
17:07:10.0181 4344 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:07:10.0183 4344 FltMgr - ok
17:07:10.0246 4344 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
17:07:10.0264 4344 FontCache - ok
17:07:10.0369 4344 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:07:10.0371 4344 FontCache3.0.0.0 - ok
17:07:10.0377 4344 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:07:10.0379 4344 FsDepends - ok
17:07:10.0420 4344 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:07:10.0421 4344 Fs_Rec - ok
17:07:10.0467 4344 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:07:10.0469 4344 fvevol - ok
17:07:10.0499 4344 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:07:10.0501 4344 gagp30kx - ok
17:07:10.0548 4344 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:07:10.0566 4344 gpsvc - ok
17:07:10.0638 4344 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
17:07:10.0640 4344 gupdate - ok
17:07:10.0645 4344 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
17:07:10.0648 4344 gupdatem - ok
17:07:10.0690 4344 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:07:10.0691 4344 hcw85cir - ok
17:07:10.0755 4344 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:07:10.0758 4344 HdAudAddService - ok
17:07:10.0784 4344 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:07:10.0786 4344 HDAudBus - ok
17:07:10.0800 4344 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:07:10.0801 4344 HidBatt - ok
17:07:10.0819 4344 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:07:10.0821 4344 HidBth - ok
17:07:10.0860 4344 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:07:10.0861 4344 HidIr - ok
17:07:10.0904 4344 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:07:10.0907 4344 hidserv - ok
17:07:10.0967 4344 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
17:07:10.0969 4344 HidUsb - ok
17:07:11.0010 4344 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:07:11.0015 4344 hkmsvc - ok
17:07:11.0057 4344 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:07:11.0063 4344 HomeGroupListener - ok
17:07:11.0111 4344 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:07:11.0128 4344 HomeGroupProvider - ok
17:07:11.0176 4344 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:07:11.0178 4344 HpSAMD - ok
17:07:11.0246 4344 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:07:11.0250 4344 HTTP - ok
17:07:11.0305 4344 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:07:11.0306 4344 hwpolicy - ok
17:07:11.0352 4344 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:07:11.0353 4344 i8042prt - ok
17:07:11.0411 4344 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:07:11.0415 4344 iaStorV - ok
17:07:11.0482 4344 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:07:11.0500 4344 idsvc - ok
17:07:11.0528 4344 IEEtwCollectorService - ok
17:07:11.0555 4344 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:07:11.0556 4344 iirsp - ok
17:07:11.0611 4344 [ B9C54120F46392100478F58F374E5709 ] IKEEXT C:\Windows\System32\ikeext.dll
17:07:11.0629 4344 IKEEXT - ok
17:07:11.0709 4344 [ BC9B2C44139B4E103105F024D00B46D5 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
17:07:11.0729 4344 IntcAzAudAddService - ok
17:07:11.0745 4344 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:07:11.0746 4344 intelide - ok
17:07:11.0766 4344 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:07:11.0768 4344 intelppm - ok
17:07:11.0819 4344 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:07:11.0823 4344 IPBusEnum - ok
17:07:11.0841 4344 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:07:11.0842 4344 IpFilterDriver - ok
17:07:11.0891 4344 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:07:11.0908 4344 iphlpsvc - ok
17:07:11.0959 4344 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:07:11.0960 4344 IPMIDRV - ok
17:07:11.0976 4344 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:07:11.0978 4344 IPNAT - ok
17:07:11.0999 4344 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:07:12.0000 4344 IRENUM - ok
17:07:12.0037 4344 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:07:12.0039 4344 isapnp - ok
17:07:12.0086 4344 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:07:12.0089 4344 iScsiPrt - ok
17:07:12.0109 4344 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:07:12.0110 4344 kbdclass - ok
17:07:12.0161 4344 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
17:07:12.0163 4344 kbdhid - ok
17:07:12.0169 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] KeyIso C:\Windows\system32\lsass.exe
17:07:12.0173 4344 KeyIso - ok
17:07:12.0218 4344 [ F286830298323272260332D6ABC905C1 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:07:12.0219 4344 KSecDD - ok
17:07:12.0232 4344 [ D7C760D57B1656DD748B9E4AB6CB5A51 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:07:12.0234 4344 KSecPkg - ok
17:07:12.0287 4344 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:07:12.0304 4344 KtmRm - ok
17:07:12.0358 4344 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:07:12.0375 4344 LanmanServer - ok
17:07:12.0430 4344 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:07:12.0437 4344 LanmanWorkstation - ok
17:07:12.0464 4344 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:07:12.0465 4344 lltdio - ok
17:07:12.0507 4344 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:07:12.0513 4344 lltdsvc - ok
17:07:12.0531 4344 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:07:12.0535 4344 lmhosts - ok
17:07:12.0555 4344 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:07:12.0557 4344 LSI_FC - ok
17:07:12.0590 4344 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:07:12.0592 4344 LSI_SAS - ok
17:07:12.0611 4344 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:07:12.0612 4344 LSI_SAS2 - ok
17:07:12.0626 4344 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:07:12.0628 4344 LSI_SCSI - ok
17:07:12.0641 4344 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:07:12.0643 4344 luafv - ok
17:07:12.0686 4344 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:07:12.0691 4344 Mcx2Svc - ok
17:07:12.0713 4344 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:07:12.0714 4344 megasas - ok
17:07:12.0737 4344 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:07:12.0740 4344 MegaSR - ok
17:07:12.0779 4344 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:07:12.0784 4344 MMCSS - ok
17:07:12.0800 4344 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:07:12.0801 4344 Modem - ok
17:07:12.0821 4344 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:07:12.0822 4344 monitor - ok
17:07:12.0866 4344 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:07:12.0868 4344 mouclass - ok
17:07:12.0878 4344 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:07:12.0879 4344 mouhid - ok
17:07:12.0923 4344 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:07:12.0925 4344 mountmgr - ok
17:07:12.0966 4344 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:07:12.0968 4344 mpio - ok
17:07:12.0998 4344 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:07:12.0999 4344 mpsdrv - ok
17:07:13.0093 4344 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:07:13.0112 4344 MpsSvc - ok
17:07:13.0158 4344 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:07:13.0159 4344 MRxDAV - ok
17:07:13.0198 4344 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:07:13.0200 4344 mrxsmb - ok
17:07:13.0212 4344 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:07:13.0215 4344 mrxsmb10 - ok
17:07:13.0258 4344 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:07:13.0259 4344 mrxsmb20 - ok
17:07:13.0299 4344 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:07:13.0300 4344 msahci - ok
17:07:13.0339 4344 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:07:13.0341 4344 msdsm - ok
17:07:13.0358 4344 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:07:13.0364 4344 MSDTC - ok
17:07:13.0404 4344 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:07:13.0406 4344 Msfs - ok
17:07:13.0417 4344 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:07:13.0418 4344 mshidkmdf - ok
17:07:13.0465 4344 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:07:13.0466 4344 msisadrv - ok
17:07:13.0505 4344 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:07:13.0510 4344 MSiSCSI - ok
17:07:13.0516 4344 msiserver - ok
17:07:13.0547 4344 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:07:13.0549 4344 MSKSSRV - ok
17:07:13.0572 4344 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:07:13.0573 4344 MSPCLOCK - ok
17:07:13.0592 4344 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:07:13.0593 4344 MSPQM - ok
17:07:13.0615 4344 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:07:13.0617 4344 MsRPC - ok
17:07:13.0632 4344 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:07:13.0633 4344 mssmbios - ok
17:07:13.0652 4344 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:07:13.0653 4344 MSTEE - ok
17:07:13.0696 4344 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:07:13.0697 4344 MTConfig - ok
17:07:13.0704 4344 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:07:13.0706 4344 Mup - ok
17:07:13.0755 4344 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:07:13.0772 4344 napagent - ok
17:07:13.0793 4344 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:07:13.0797 4344 NativeWifiP - ok
17:07:13.0860 4344 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:07:13.0866 4344 NDIS - ok
17:07:13.0886 4344 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:07:13.0888 4344 NdisCap - ok
17:07:13.0910 4344 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:07:13.0911 4344 NdisTapi - ok
17:07:13.0949 4344 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:07:13.0950 4344 Ndisuio - ok
17:07:13.0987 4344 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:07:13.0988 4344 NdisWan - ok
17:07:14.0034 4344 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:07:14.0035 4344 NDProxy - ok
17:07:14.0049 4344 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:07:14.0051 4344 NetBIOS - ok
17:07:14.0101 4344 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:07:14.0104 4344 NetBT - ok
17:07:14.0120 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] Netlogon C:\Windows\system32\lsass.exe
17:07:14.0124 4344 Netlogon - ok
17:07:14.0179 4344 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:07:14.0196 4344 Netman - ok
17:07:14.0228 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0240 4344 NetMsmqActivator - ok
17:07:14.0246 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0249 4344 NetPipeActivator - ok
17:07:14.0271 4344 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:07:14.0278 4344 netprofm - ok
17:07:14.0285 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0287 4344 NetTcpActivator - ok
17:07:14.0293 4344 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:07:14.0296 4344 NetTcpPortSharing - ok
17:07:14.0322 4344 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:07:14.0324 4344 nfrd960 - ok
17:07:14.0367 4344 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
17:07:14.0384 4344 NlaSvc - ok
17:07:14.0393 4344 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:07:14.0395 4344 Npfs - ok
17:07:14.0441 4344 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:07:14.0446 4344 nsi - ok
17:07:14.0459 4344 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:07:14.0460 4344 nsiproxy - ok
17:07:14.0530 4344 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:07:14.0538 4344 Ntfs - ok
17:07:14.0575 4344 NTIOLib_1_0_3 - ok
17:07:14.0589 4344 NTIOLib_1_0_4 - ok
17:07:14.0605 4344 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:07:14.0607 4344 Null - ok
17:07:14.0666 4344 [ B5E37E31C053BC9950455A257526514B ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x32.sys
17:07:14.0669 4344 NVENETFD - ok
17:07:14.0703 4344 [ 1DE923088878B495CD4219E47BA34EB8 ] NVNET C:\Windows\system32\DRIVERS\nvmf6232.sys
17:07:14.0706 4344 NVNET - ok
17:07:14.0749 4344 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:07:14.0751 4344 nvraid - ok
17:07:14.0768 4344 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:07:14.0770 4344 nvstor - ok
17:07:14.0814 4344 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:07:14.0816 4344 nv_agp - ok
17:07:14.0876 4344 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:07:14.0878 4344 ohci1394 - ok
17:07:14.0924 4344 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:07:14.0941 4344 p2pimsvc - ok
17:07:14.0996 4344 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:07:15.0013 4344 p2psvc - ok
17:07:15.0034 4344 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:07:15.0036 4344 Parport - ok
17:07:15.0076 4344 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:07:15.0077 4344 partmgr - ok
17:07:15.0088 4344 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:07:15.0089 4344 Parvdm - ok
17:07:15.0104 4344 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:07:15.0111 4344 PcaSvc - ok
17:07:15.0137 4344 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:07:15.0139 4344 pci - ok
17:07:15.0151 4344 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:07:15.0152 4344 pciide - ok
17:07:15.0216 4344 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:07:15.0219 4344 pcmcia - ok
17:07:15.0240 4344 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:07:15.0241 4344 pcw - ok
17:07:15.0287 4344 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:07:15.0292 4344 PEAUTH - ok
17:07:15.0343 4344 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:07:15.0377 4344 PeerDistSvc - ok
17:07:15.0577 4344 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:07:15.0604 4344 pla - ok
17:07:15.0713 4344 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:07:15.0727 4344 PlugPlay - ok
17:07:15.0782 4344 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:07:15.0791 4344 PNRPAutoReg - ok
17:07:15.0811 4344 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:07:15.0818 4344 PNRPsvc - ok
17:07:15.0850 4344 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:07:15.0857 4344 PolicyAgent - ok
17:07:15.0912 4344 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:07:15.0920 4344 Power - ok
17:07:15.0975 4344 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:07:15.0976 4344 PptpMiniport - ok
17:07:15.0991 4344 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:07:15.0993 4344 Processor - ok
17:07:16.0033 4344 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:07:16.0050 4344 ProfSvc - ok
17:07:16.0062 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:07:16.0066 4344 ProtectedStorage - ok
17:07:16.0086 4344 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:07:16.0088 4344 Psched - ok
17:07:16.0158 4344 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:07:16.0169 4344 ql2300 - ok
17:07:16.0196 4344 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:07:16.0198 4344 ql40xx - ok
17:07:16.0207 4344 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:07:16.0216 4344 QWAVE - ok
17:07:16.0238 4344 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:07:16.0239 4344 QWAVEdrv - ok
17:07:16.0263 4344 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:07:16.0264 4344 RasAcd - ok
17:07:16.0312 4344 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:07:16.0313 4344 RasAgileVpn - ok
17:07:16.0319 4344 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:07:16.0326 4344 RasAuto - ok
17:07:16.0336 4344 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:07:16.0338 4344 Rasl2tp - ok
17:07:16.0391 4344 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:07:16.0408 4344 RasMan - ok
17:07:16.0424 4344 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:07:16.0426 4344 RasPppoe - ok
17:07:16.0452 4344 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:07:16.0453 4344 RasSstp - ok
17:07:16.0508 4344 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:07:16.0511 4344 rdbss - ok
17:07:16.0526 4344 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:07:16.0527 4344 rdpbus - ok
17:07:16.0575 4344 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:07:16.0576 4344 RDPCDD - ok
17:07:16.0625 4344 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:07:16.0627 4344 RDPDR - ok
17:07:16.0641 4344 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:07:16.0642 4344 RDPENCDD - ok
17:07:16.0662 4344 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:07:16.0664 4344 RDPREFMP - ok
17:07:16.0722 4344 [ 65375DF758CA1872AB7EBBBA457FD5E6 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:07:16.0723 4344 RdpVideoMiniport - ok
17:07:16.0767 4344 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:07:16.0769 4344 RDPWD - ok
17:07:16.0814 4344 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:07:16.0817 4344 rdyboost - ok
17:07:16.0861 4344 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:07:16.0866 4344 RemoteAccess - ok
17:07:16.0909 4344 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:07:16.0916 4344 RemoteRegistry - ok
17:07:16.0926 4344 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:07:16.0933 4344 RpcEptMapper - ok
17:07:16.0980 4344 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:07:16.0984 4344 RpcLocator - ok
17:07:16.0997 4344 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:07:17.0006 4344 RpcSs - ok
17:07:17.0021 4344 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:07:17.0023 4344 rspndr - ok
17:07:17.0065 4344 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:07:17.0066 4344 s3cap - ok
17:07:17.0072 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] SamSs C:\Windows\system32\lsass.exe
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
17:07:17.0076 4344 SamSs - ok
17:07:17.0130 4344 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:07:17.0132 4344 sbp2port - ok
17:07:17.0139 4344 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:07:17.0147 4344 SCardSvr - ok
17:07:17.0169 4344 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:07:17.0170 4344 scfilter - ok
17:07:17.0223 4344 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:07:17.0249 4344 Schedule - ok
17:07:17.0268 4344 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:07:17.0270 4344 SCPolicySvc - ok
17:07:17.0318 4344 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:07:17.0325 4344 SDRSVC - ok
17:07:17.0346 4344 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:07:17.0348 4344 secdrv - ok
17:07:17.0389 4344 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:07:17.0395 4344 seclogon - ok
17:07:17.0421 4344 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:07:17.0428 4344 SENS - ok
17:07:17.0434 4344 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:07:17.0442 4344 SensrSvc - ok
17:07:17.0448 4344 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:07:17.0451 4344 Serenum - ok
17:07:17.0467 4344 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:07:17.0469 4344 Serial - ok
17:07:17.0508 4344 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:07:17.0510 4344 sermouse - ok
17:07:17.0565 4344 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:07:17.0572 4344 SessionEnv - ok
17:07:17.0617 4344 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:07:17.0619 4344 sffdisk - ok
17:07:17.0626 4344 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:07:17.0628 4344 sffp_mmc - ok
17:07:17.0648 4344 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:07:17.0649 4344 sffp_sd - ok
17:07:17.0665 4344 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:07:17.0666 4344 sfloppy - ok
17:07:17.0708 4344 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:07:17.0725 4344 SharedAccess - ok
17:07:17.0766 4344 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:07:17.0783 4344 ShellHWDetection - ok
17:07:17.0826 4344 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:07:17.0828 4344 sisagp - ok
17:07:17.0859 4344 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:07:17.0861 4344 SiSRaid2 - ok
17:07:17.0879 4344 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:07:17.0881 4344 SiSRaid4 - ok
17:07:17.0924 4344 [ 50D9949020E02B847CD48F1243FCB895 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:07:17.0926 4344 SkypeUpdate - ok
17:07:17.0956 4344 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:07:17.0958 4344 Smb - ok
17:07:18.0015 4344 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:07:18.0022 4344 SNMPTRAP - ok
17:07:18.0068 4344 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:07:18.0069 4344 spldr - ok
17:07:18.0119 4344 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:07:18.0127 4344 Spooler - ok
17:07:18.0194 4344 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:07:18.0253 4344 sppsvc - ok
17:07:18.0301 4344 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:07:18.0307 4344 sppuinotify - ok
17:07:18.0351 4344 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:07:18.0354 4344 srv - ok
17:07:18.0371 4344 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:07:18.0374 4344 srv2 - ok
17:07:18.0416 4344 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:07:18.0418 4344 srvnet - ok
17:07:18.0458 4344 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:07:18.0475 4344 SSDPSRV - ok
17:07:18.0489 4344 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:07:18.0496 4344 SstpSvc - ok
17:07:18.0552 4344 [ 24F5F92263E3B461A1105FE370D53D1C ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
17:07:18.0554 4344 ssudmdm - ok
17:07:18.0630 4344 [ 2F3B5A3567FFB343D8867C3D34C687F1 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
17:07:18.0634 4344 Steam Client Service - ok
17:07:18.0651 4344 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:07:18.0653 4344 stexstor - ok
17:07:18.0699 4344 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:07:18.0716 4344 StiSvc - ok
17:07:18.0764 4344 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:07:18.0766 4344 storflt - ok
17:07:18.0811 4344 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:07:18.0812 4344 storvsc - ok
17:07:18.0861 4344 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:07:18.0862 4344 swenum - ok
17:07:18.0876 4344 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:07:18.0893 4344 swprv - ok
17:07:18.0904 4344 Synth3dVsc - ok
17:07:18.0966 4344 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:07:18.0993 4344 SysMain - ok
17:07:19.0040 4344 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:07:19.0047 4344 TabletInputService - ok
17:07:19.0088 4344 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:07:19.0106 4344 TapiSrv - ok
17:07:19.0162 4344 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:07:19.0169 4344 TBS - ok
17:07:19.0234 4344 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:07:19.0244 4344 Tcpip - ok
17:07:19.0276 4344 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:07:19.0285 4344 TCPIP6 - ok
17:07:19.0326 4344 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:07:19.0328 4344 tcpipreg - ok
17:07:19.0378 4344 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:07:19.0379 4344 TDPIPE - ok
17:07:19.0417 4344 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:07:19.0419 4344 TDTCP - ok
17:07:19.0461 4344 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:07:19.0463 4344 tdx - ok
17:07:19.0475 4344 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:07:19.0477 4344 TermDD - ok
17:07:19.0528 4344 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:07:19.0546 4344 TermService - ok
17:07:19.0561 4344 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:07:19.0568 4344 Themes - ok
17:07:19.0580 4344 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:07:19.0584 4344 THREADORDER - ok
17:07:19.0597 4344 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:07:19.0604 4344 TrkWks - ok
17:07:19.0692 4344 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:07:19.0694 4344 TrustedInstaller - ok
17:07:19.0741 4344 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:07:19.0743 4344 tssecsrv - ok
17:07:19.0793 4344 [ 9CE253214ACAA5A7D323327D2055EFAA ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:07:19.0795 4344 TsUsbFlt - ok
17:07:19.0811 4344 tsusbhub - ok
17:07:19.0861 4344 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:07:19.0863 4344 tunnel - ok
17:07:19.0909 4344 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:07:19.0911 4344 uagp35 - ok
17:07:19.0960 4344 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:07:19.0963 4344 udfs - ok
17:07:20.0010 4344 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:07:20.0017 4344 UI0Detect - ok
17:07:20.0056 4344 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:07:20.0058 4344 uliagpkx - ok
17:07:20.0117 4344 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:07:20.0119 4344 umbus - ok
17:07:20.0146 4344 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:07:20.0147 4344 UmPass - ok
17:07:20.0200 4344 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:07:20.0217 4344 UmRdpService - ok
17:07:20.0267 4344 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:07:20.0284 4344 upnphost - ok
17:07:20.0336 4344 [ A1977C315BF5691DA99235AA4A6907AF ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
17:07:20.0338 4344 usbaudio - ok
17:07:20.0357 4344 [ 0803FBA9FE829D61AE26EC0BCC910C46 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:07:20.0359 4344 usbccgp - ok
17:07:20.0401 4344 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:07:20.0403 4344 usbcir - ok
17:07:20.0422 4344 [ D40855F89B69305140BBD7E9A3BA2DA6 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:07:20.0423 4344 usbehci - ok
17:07:20.0442 4344 [ EDF2DF71C4F1E13A6AC75F5224DE655A ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:07:20.0445 4344 usbhub - ok
17:07:20.0460 4344 [ 9828C8D14CC2676421778F0DE638CF97 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:07:20.0462 4344 usbohci - ok
17:07:20.0482 4344 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:07:20.0483 4344 usbprint - ok
17:07:20.0528 4344 [ FC6B21DB4B5B398AB93DBE59CBF11036 ] usbscan C:\Windows\system32\drivers\usbscan.sys
17:07:20.0529 4344 usbscan - ok
17:07:20.0584 4344 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:07:20.0586 4344 USBSTOR - ok
17:07:20.0609 4344 [ 800AABFD625EEFF899F7E5496BDE37AB ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:07:20.0611 4344 usbuhci - ok
17:07:20.0630 4344 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:07:20.0637 4344 UxSms - ok
17:07:20.0645 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] VaultSvc C:\Windows\system32\lsass.exe
17:07:20.0649 4344 VaultSvc - ok
17:07:20.0695 4344 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:07:20.0696 4344 vdrvroot - ok
17:07:20.0801 4344 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:07:20.0851 4344 vds - ok
17:07:20.0896 4344 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:07:20.0897 4344 vga - ok
17:07:20.0912 4344 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:07:20.0914 4344 VgaSave - ok
17:07:20.0920 4344 VGPU - ok
17:07:20.0967 4344 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:07:20.0970 4344 vhdmp - ok
17:07:20.0984 4344 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:07:20.0986 4344 viaagp - ok
17:07:21.0001 4344 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:07:21.0002 4344 ViaC7 - ok
17:07:21.0038 4344 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:07:21.0040 4344 viaide - ok
17:07:21.0082 4344 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:07:21.0084 4344 vmbus - ok
17:07:21.0130 4344 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:07:21.0131 4344 VMBusHID - ok
17:07:21.0173 4344 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:07:21.0174 4344 volmgr - ok
17:07:21.0193 4344 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:07:21.0196 4344 volmgrx - ok
17:07:21.0241 4344 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:07:21.0244 4344 volsnap - ok
17:07:21.0296 4344 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:07:21.0298 4344 vsmraid - ok
17:07:21.0353 4344 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:07:21.0387 4344 VSS - ok
17:07:21.0411 4344 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:07:21.0413 4344 vwifibus - ok
17:07:21.0465 4344 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:07:21.0482 4344 W32Time - ok
17:07:21.0500 4344 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:07:21.0502 4344 WacomPen - ok
17:07:21.0548 4344 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:07:21.0550 4344 WANARP - ok
17:07:21.0555 4344 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:07:21.0557 4344 Wanarpv6 - ok
17:07:21.0590 4344 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:07:21.0625 4344 wbengine - ok
17:07:21.0641 4344 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:07:21.0658 4344 WbioSrvc - ok
17:07:21.0701 4344 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:07:21.0719 4344 wcncsvc - ok
17:07:21.0728 4344 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:07:21.0736 4344 WcsPlugInService - ok
17:07:21.0752 4344 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:07:21.0754 4344 Wd - ok
17:07:21.0803 4344 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:07:21.0808 4344 Wdf01000 - ok
17:07:21.0822 4344 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:07:21.0829 4344 WdiServiceHost - ok
17:07:21.0834 4344 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:07:21.0842 4344 WdiSystemHost - ok
17:07:21.0886 4344 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:07:21.0904 4344 WebClient - ok
17:07:21.0944 4344 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:07:21.0961 4344 Wecsvc - ok
17:07:21.0970 4344 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:07:21.0977 4344 wercplsupport - ok
17:07:22.0002 4344 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:07:22.0009 4344 WerSvc - ok
17:07:22.0028 4344 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:07:22.0030 4344 WfpLwf - ok
17:07:22.0047 4344 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:07:22.0048 4344 WIMMount - ok
17:07:22.0135 4344 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:07:22.0152 4344 WinDefend - ok
17:07:22.0163 4344 WinHttpAutoProxySvc - ok
17:07:22.0217 4344 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:07:22.0220 4344 Winmgmt - ok
17:07:22.0282 4344 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:07:22.0316 4344 WinRM - ok
17:07:22.0387 4344 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:07:22.0412 4344 Wlansvc - ok
17:07:22.0503 4344 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:07:22.0514 4344 wlidsvc - ok
17:07:22.0558 4344 [ 5D410936831F7FB58EFF941EAC3F6D3D ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
17:07:22.0560 4344 WmBEnum - ok
17:07:22.0621 4344 [ 7A13CFDE92956CA61A0927D766C5AD4F ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
17:07:22.0622 4344 WmFilter - ok
17:07:22.0656 4344 [ 1F596392149CAC51F7C095AF7D533934 ] WmHidLo C:\Windows\system32\drivers\WmHidLo.sys
17:07:22.0658 4344 WmHidLo - ok
17:07:22.0700 4344 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:07:22.0701 4344 WmiAcpi - ok
17:07:22.0723 4344 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:07:22.0726 4344 wmiApSrv - ok
17:07:22.0795 4344 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:07:22.0822 4344 WMPNetworkSvc - ok
17:07:22.0843 4344 [ 6F04646BC690F8BBFC344BE32A60796D ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
17:07:22.0844 4344 WmVirHid - ok
17:07:22.0867 4344 [ 1D6CA43D562333F4DFB40BCEF2453F3A ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
17:07:22.0869 4344 WmXlCore - ok
17:07:22.0884 4344 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:07:22.0891 4344 WPCSvc - ok
17:07:22.0933 4344 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:07:22.0941 4344 WPDBusEnum - ok
17:07:22.0980 4344 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:07:22.0981 4344 ws2ifsl - ok
17:07:22.0995 4344 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:07:23.0003 4344 wscsvc - ok
17:07:23.0009 4344 WSearch - ok
17:07:23.0089 4344 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:07:23.0132 4344 wuauserv - ok
17:07:23.0183 4344 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:07:23.0185 4344 WudfPf - ok
17:07:23.0202 4344 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:07:23.0204 4344 WUDFRd - ok
17:07:23.0254 4344 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:07:23.0262 4344 wudfsvc - ok
17:07:23.0275 4344 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:07:23.0292 4344 WwanSvc - ok
17:07:23.0299 4344 ================ Scan global ===============================
17:07:23.0326 4344 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:07:23.0365 4344 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:07:23.0388 4344 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:07:23.0439 4344 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:07:23.0456 4344 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:07:23.0463 4344 [Global] - ok
17:07:23.0464 4344 ================ Scan MBR ==================================
17:07:23.0472 4344 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:07:23.0852 4344 \Device\Harddisk0\DR0 - ok
17:07:23.0853 4344 ================ Scan VBR ==================================
17:07:23.0853 4344 [ F73CE8B171A06FE391DC473EC1FE5C88 ] \Device\Harddisk0\DR0\Partition1
17:07:23.0855 4344 \Device\Harddisk0\DR0\Partition1 - ok
17:07:23.0857 4344 ============================================================
17:07:23.0857 4344 Scan finished
17:07:23.0857 4344 ============================================================
17:07:23.0874 4516 Detected object count: 0
17:07:23.0874 4516 Actual detected object count: 0
17:07:17.0130 4344 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:07:17.0132 4344 sbp2port - ok
17:07:17.0139 4344 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:07:17.0147 4344 SCardSvr - ok
17:07:17.0169 4344 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:07:17.0170 4344 scfilter - ok
17:07:17.0223 4344 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:07:17.0249 4344 Schedule - ok
17:07:17.0268 4344 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:07:17.0270 4344 SCPolicySvc - ok
17:07:17.0318 4344 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:07:17.0325 4344 SDRSVC - ok
17:07:17.0346 4344 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:07:17.0348 4344 secdrv - ok
17:07:17.0389 4344 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:07:17.0395 4344 seclogon - ok
17:07:17.0421 4344 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:07:17.0428 4344 SENS - ok
17:07:17.0434 4344 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:07:17.0442 4344 SensrSvc - ok
17:07:17.0448 4344 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:07:17.0451 4344 Serenum - ok
17:07:17.0467 4344 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:07:17.0469 4344 Serial - ok
17:07:17.0508 4344 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:07:17.0510 4344 sermouse - ok
17:07:17.0565 4344 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:07:17.0572 4344 SessionEnv - ok
17:07:17.0617 4344 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:07:17.0619 4344 sffdisk - ok
17:07:17.0626 4344 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:07:17.0628 4344 sffp_mmc - ok
17:07:17.0648 4344 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:07:17.0649 4344 sffp_sd - ok
17:07:17.0665 4344 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:07:17.0666 4344 sfloppy - ok
17:07:17.0708 4344 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:07:17.0725 4344 SharedAccess - ok
17:07:17.0766 4344 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:07:17.0783 4344 ShellHWDetection - ok
17:07:17.0826 4344 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:07:17.0828 4344 sisagp - ok
17:07:17.0859 4344 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:07:17.0861 4344 SiSRaid2 - ok
17:07:17.0879 4344 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:07:17.0881 4344 SiSRaid4 - ok
17:07:17.0924 4344 [ 50D9949020E02B847CD48F1243FCB895 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:07:17.0926 4344 SkypeUpdate - ok
17:07:17.0956 4344 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:07:17.0958 4344 Smb - ok
17:07:18.0015 4344 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:07:18.0022 4344 SNMPTRAP - ok
17:07:18.0068 4344 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:07:18.0069 4344 spldr - ok
17:07:18.0119 4344 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:07:18.0127 4344 Spooler - ok
17:07:18.0194 4344 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:07:18.0253 4344 sppsvc - ok
17:07:18.0301 4344 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:07:18.0307 4344 sppuinotify - ok
17:07:18.0351 4344 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:07:18.0354 4344 srv - ok
17:07:18.0371 4344 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:07:18.0374 4344 srv2 - ok
17:07:18.0416 4344 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:07:18.0418 4344 srvnet - ok
17:07:18.0458 4344 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:07:18.0475 4344 SSDPSRV - ok
17:07:18.0489 4344 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:07:18.0496 4344 SstpSvc - ok
17:07:18.0552 4344 [ 24F5F92263E3B461A1105FE370D53D1C ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
17:07:18.0554 4344 ssudmdm - ok
17:07:18.0630 4344 [ 2F3B5A3567FFB343D8867C3D34C687F1 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
17:07:18.0634 4344 Steam Client Service - ok
17:07:18.0651 4344 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:07:18.0653 4344 stexstor - ok
17:07:18.0699 4344 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:07:18.0716 4344 StiSvc - ok
17:07:18.0764 4344 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:07:18.0766 4344 storflt - ok
17:07:18.0811 4344 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:07:18.0812 4344 storvsc - ok
17:07:18.0861 4344 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:07:18.0862 4344 swenum - ok
17:07:18.0876 4344 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:07:18.0893 4344 swprv - ok
17:07:18.0904 4344 Synth3dVsc - ok
17:07:18.0966 4344 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:07:18.0993 4344 SysMain - ok
17:07:19.0040 4344 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:07:19.0047 4344 TabletInputService - ok
17:07:19.0088 4344 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:07:19.0106 4344 TapiSrv - ok
17:07:19.0162 4344 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:07:19.0169 4344 TBS - ok
17:07:19.0234 4344 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:07:19.0244 4344 Tcpip - ok
17:07:19.0276 4344 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:07:19.0285 4344 TCPIP6 - ok
17:07:19.0326 4344 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:07:19.0328 4344 tcpipreg - ok
17:07:19.0378 4344 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:07:19.0379 4344 TDPIPE - ok
17:07:19.0417 4344 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:07:19.0419 4344 TDTCP - ok
17:07:19.0461 4344 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:07:19.0463 4344 tdx - ok
17:07:19.0475 4344 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:07:19.0477 4344 TermDD - ok
17:07:19.0528 4344 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:07:19.0546 4344 TermService - ok
17:07:19.0561 4344 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:07:19.0568 4344 Themes - ok
17:07:19.0580 4344 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:07:19.0584 4344 THREADORDER - ok
17:07:19.0597 4344 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:07:19.0604 4344 TrkWks - ok
17:07:19.0692 4344 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:07:19.0694 4344 TrustedInstaller - ok
17:07:19.0741 4344 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:07:19.0743 4344 tssecsrv - ok
17:07:19.0793 4344 [ 9CE253214ACAA5A7D323327D2055EFAA ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:07:19.0795 4344 TsUsbFlt - ok
17:07:19.0811 4344 tsusbhub - ok
17:07:19.0861 4344 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:07:19.0863 4344 tunnel - ok
17:07:19.0909 4344 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:07:19.0911 4344 uagp35 - ok
17:07:19.0960 4344 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:07:19.0963 4344 udfs - ok
17:07:20.0010 4344 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:07:20.0017 4344 UI0Detect - ok
17:07:20.0056 4344 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:07:20.0058 4344 uliagpkx - ok
17:07:20.0117 4344 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:07:20.0119 4344 umbus - ok
17:07:20.0146 4344 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:07:20.0147 4344 UmPass - ok
17:07:20.0200 4344 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:07:20.0217 4344 UmRdpService - ok
17:07:20.0267 4344 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:07:20.0284 4344 upnphost - ok
17:07:20.0336 4344 [ A1977C315BF5691DA99235AA4A6907AF ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
17:07:20.0338 4344 usbaudio - ok
17:07:20.0357 4344 [ 0803FBA9FE829D61AE26EC0BCC910C46 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:07:20.0359 4344 usbccgp - ok
17:07:20.0401 4344 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:07:20.0403 4344 usbcir - ok
17:07:20.0422 4344 [ D40855F89B69305140BBD7E9A3BA2DA6 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:07:20.0423 4344 usbehci - ok
17:07:20.0442 4344 [ EDF2DF71C4F1E13A6AC75F5224DE655A ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:07:20.0445 4344 usbhub - ok
17:07:20.0460 4344 [ 9828C8D14CC2676421778F0DE638CF97 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:07:20.0462 4344 usbohci - ok
17:07:20.0482 4344 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:07:20.0483 4344 usbprint - ok
17:07:20.0528 4344 [ FC6B21DB4B5B398AB93DBE59CBF11036 ] usbscan C:\Windows\system32\drivers\usbscan.sys
17:07:20.0529 4344 usbscan - ok
17:07:20.0584 4344 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:07:20.0586 4344 USBSTOR - ok
17:07:20.0609 4344 [ 800AABFD625EEFF899F7E5496BDE37AB ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:07:20.0611 4344 usbuhci - ok
17:07:20.0630 4344 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:07:20.0637 4344 UxSms - ok
17:07:20.0645 4344 [ 803B370865D907EA21DC0C2B6A8936B5 ] VaultSvc C:\Windows\system32\lsass.exe
17:07:20.0649 4344 VaultSvc - ok
17:07:20.0695 4344 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:07:20.0696 4344 vdrvroot - ok
17:07:20.0801 4344 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:07:20.0851 4344 vds - ok
17:07:20.0896 4344 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:07:20.0897 4344 vga - ok
17:07:20.0912 4344 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:07:20.0914 4344 VgaSave - ok
17:07:20.0920 4344 VGPU - ok
17:07:20.0967 4344 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:07:20.0970 4344 vhdmp - ok
17:07:20.0984 4344 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:07:20.0986 4344 viaagp - ok
17:07:21.0001 4344 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:07:21.0002 4344 ViaC7 - ok
17:07:21.0038 4344 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:07:21.0040 4344 viaide - ok
17:07:21.0082 4344 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:07:21.0084 4344 vmbus - ok
17:07:21.0130 4344 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:07:21.0131 4344 VMBusHID - ok
17:07:21.0173 4344 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:07:21.0174 4344 volmgr - ok
17:07:21.0193 4344 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:07:21.0196 4344 volmgrx - ok
17:07:21.0241 4344 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:07:21.0244 4344 volsnap - ok
17:07:21.0296 4344 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:07:21.0298 4344 vsmraid - ok
17:07:21.0353 4344 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:07:21.0387 4344 VSS - ok
17:07:21.0411 4344 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:07:21.0413 4344 vwifibus - ok
17:07:21.0465 4344 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:07:21.0482 4344 W32Time - ok
17:07:21.0500 4344 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:07:21.0502 4344 WacomPen - ok
17:07:21.0548 4344 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:07:21.0550 4344 WANARP - ok
17:07:21.0555 4344 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:07:21.0557 4344 Wanarpv6 - ok
17:07:21.0590 4344 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:07:21.0625 4344 wbengine - ok
17:07:21.0641 4344 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:07:21.0658 4344 WbioSrvc - ok
17:07:21.0701 4344 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:07:21.0719 4344 wcncsvc - ok
17:07:21.0728 4344 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:07:21.0736 4344 WcsPlugInService - ok
17:07:21.0752 4344 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:07:21.0754 4344 Wd - ok
17:07:21.0803 4344 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:07:21.0808 4344 Wdf01000 - ok
17:07:21.0822 4344 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:07:21.0829 4344 WdiServiceHost - ok
17:07:21.0834 4344 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:07:21.0842 4344 WdiSystemHost - ok
17:07:21.0886 4344 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:07:21.0904 4344 WebClient - ok
17:07:21.0944 4344 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:07:21.0961 4344 Wecsvc - ok
17:07:21.0970 4344 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:07:21.0977 4344 wercplsupport - ok
17:07:22.0002 4344 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:07:22.0009 4344 WerSvc - ok
17:07:22.0028 4344 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:07:22.0030 4344 WfpLwf - ok
17:07:22.0047 4344 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:07:22.0048 4344 WIMMount - ok
17:07:22.0135 4344 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:07:22.0152 4344 WinDefend - ok
17:07:22.0163 4344 WinHttpAutoProxySvc - ok
17:07:22.0217 4344 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:07:22.0220 4344 Winmgmt - ok
17:07:22.0282 4344 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:07:22.0316 4344 WinRM - ok
17:07:22.0387 4344 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:07:22.0412 4344 Wlansvc - ok
17:07:22.0503 4344 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:07:22.0514 4344 wlidsvc - ok
17:07:22.0558 4344 [ 5D410936831F7FB58EFF941EAC3F6D3D ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
17:07:22.0560 4344 WmBEnum - ok
17:07:22.0621 4344 [ 7A13CFDE92956CA61A0927D766C5AD4F ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
17:07:22.0622 4344 WmFilter - ok
17:07:22.0656 4344 [ 1F596392149CAC51F7C095AF7D533934 ] WmHidLo C:\Windows\system32\drivers\WmHidLo.sys
17:07:22.0658 4344 WmHidLo - ok
17:07:22.0700 4344 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:07:22.0701 4344 WmiAcpi - ok
17:07:22.0723 4344 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:07:22.0726 4344 wmiApSrv - ok
17:07:22.0795 4344 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:07:22.0822 4344 WMPNetworkSvc - ok
17:07:22.0843 4344 [ 6F04646BC690F8BBFC344BE32A60796D ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
17:07:22.0844 4344 WmVirHid - ok
17:07:22.0867 4344 [ 1D6CA43D562333F4DFB40BCEF2453F3A ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
17:07:22.0869 4344 WmXlCore - ok
17:07:22.0884 4344 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:07:22.0891 4344 WPCSvc - ok
17:07:22.0933 4344 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:07:22.0941 4344 WPDBusEnum - ok
17:07:22.0980 4344 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:07:22.0981 4344 ws2ifsl - ok
17:07:22.0995 4344 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:07:23.0003 4344 wscsvc - ok
17:07:23.0009 4344 WSearch - ok
17:07:23.0089 4344 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:07:23.0132 4344 wuauserv - ok
17:07:23.0183 4344 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:07:23.0185 4344 WudfPf - ok
17:07:23.0202 4344 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:07:23.0204 4344 WUDFRd - ok
17:07:23.0254 4344 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:07:23.0262 4344 wudfsvc - ok
17:07:23.0275 4344 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:07:23.0292 4344 WwanSvc - ok
17:07:23.0299 4344 ================ Scan global ===============================
17:07:23.0326 4344 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:07:23.0365 4344 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:07:23.0388 4344 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:07:23.0439 4344 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:07:23.0456 4344 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:07:23.0463 4344 [Global] - ok
17:07:23.0464 4344 ================ Scan MBR ==================================
17:07:23.0472 4344 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:07:23.0852 4344 \Device\Harddisk0\DR0 - ok
17:07:23.0853 4344 ================ Scan VBR ==================================
17:07:23.0853 4344 [ F73CE8B171A06FE391DC473EC1FE5C88 ] \Device\Harddisk0\DR0\Partition1
17:07:23.0855 4344 \Device\Harddisk0\DR0\Partition1 - ok
17:07:23.0857 4344 ============================================================
17:07:23.0857 4344 Scan finished
17:07:23.0857 4344 ============================================================
17:07:23.0874 4516 Detected object count: 0
17:07:23.0874 4516 Actual detected object count: 0
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu síť je zdrojem neobvyklého prov
Ještě jednou:
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 86 hostů