Prosím o kontrolu logu - tentokrát na stolním PC Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 24 dub 2014 22:58

Zdravím a prosím o kontrolu logu.
Nelze vůbec spustit Avast, lépe řečeno, program běží, ale všechny štíty jsou neaktivní, nelze provést aktualizace ani sken.
Zkoušel jsem body obnovy, ale nepomohly, lépe řečeno, vrátí se to do stavu, kde jsou v Avastu připraveny k nainstalování nějaké aktualizace, program vyžaduje restart počítače a pak je stav zpět nanovo.
Jinak PC občas vytuhne, případně se při startu odmítne načíst některý z požadovaných programů, nejčastěji LCD manažer.
V CCleaneru nelze provést některé změny (deaktivace programu při startu).

Díky moc.

PS: Z logu vidím, že je tam ZoneAlarm, sice trvale vyplej, ale ten odinstaluju.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:52:46, on 24.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)

FIREFOX: 27.0.1 (cs)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe
C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe
C:\Program Files (x86)\Memeo\AutoBackup\MemeoUpdater.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Michal&Leňa\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Protection ZoneAlarm Toolbar - {d7f26d0e-9801-45c3-a091-8a65e4ed73b5} - C:\Program Files (x86)\Protection_ZoneAlarm\prxtbProt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Protection ZoneAlarm - {d7f26d0e-9801-45c3-a091-8a65e4ed73b5} - C:\Program Files (x86)\Protection_ZoneAlarm\prxtbProt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Protection ZoneAlarm Toolbar - {d7f26d0e-9801-45c3-a091-8a65e4ed73b5} - C:\Program Files (x86)\Protection_ZoneAlarm\prxtbProt.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ScreenManager Pro for LCD] C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui
O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASHUTIL64_12_0_0_77_ACTIVEX.EXE -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: ColorMunki Gamma.lnk = C:\Program Files (x86)\X-Rite\ColorMunki Photo\Gamma\CalibrationLoader.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: X-Rite Device ColorMunki (ColorMunkiService) - X-Rite Inc. - C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe
O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\Windows\system32\spool\DRIVERS\x64\3\OPHPLDCS.EXE
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: X-Rite Device Manager (xritedeviced) - X-Rite Inc. - C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe

--
End of file - 11535 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod jaro3 » 25 dub 2014 09:49

Odinstaluj:
Spyware Terminator

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 26 dub 2014 22:04

V ATF Cleaner.exe jsem žádnou položku select all found nenašel.

Log AdwCleaner:

# AdwCleaner v3.203 - Report created 26/04/2014 at 21:38:39
# Updated 26/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Michal&Leňa - KOMPL
# Running from : C:\Users\Michal&Leňa\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Users\Michal&Leňa\AppData\Roaming\Mozilla\Firefox\Profiles\ftzg3a4h.default\Extensions\{d7f26d0e-9801-45c3-a091-8a65e4ed73b5}
Folder Found C:\Users\Michal&Leňa\AppData\LocalLow\Conduit

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2613520
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASMANCS
Key Found : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Michal&Leňa\AppData\Roaming\Mozilla\Firefox\Profiles\ftzg3a4h.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1776 octets] - [26/04/2014 21:38:39]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1836 octets] ##########

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 26 dub 2014 22:34

MAM provedl scan, ale při pokusu o uložení do chránky nebo o export logu vždy vytuhne a spadne. :-(
Co s tím?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod jaro3 » 27 dub 2014 09:55

MbAM , zkus ještě jednou , v nouz. režimu.

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.


Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 27 dub 2014 14:45

Tak MAM se chová úplně stejně i v nouzovým režimu. :-(

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 27 dub 2014 15:16

Log AdwCleaner:

# AdwCleaner v3.204 - Report created 27/04/2014 at 15:13:55
# Updated 26/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Michal&Leňa - KOMPL
# Running from : C:\Users\Michal&Leňa\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Michal&Leňa\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Michal&Leňa\AppData\Roaming\Mozilla\Firefox\Profiles\ftzg3a4h.default\Extensions\{d7f26d0e-9801-45c3-a091-8a65e4ed73b5}

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2613520
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_regcleaner_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v27.0.1 (cs)

[ File : C:\Users\Michal&Leňa\AppData\Roaming\Mozilla\Firefox\Profiles\ftzg3a4h.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1928 octets] - [26/04/2014 21:38:39]
AdwCleaner[R1].txt - [1990 octets] - [27/04/2014 15:10:55]
AdwCleaner[S0].txt - [1891 octets] - [27/04/2014 15:13:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1951 octets] ##########

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 27 dub 2014 15:29

Log JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d7f26d0e-9801-45c3-a091-8a65e4ed73b5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{d7f26d0e-9801-45c3-a091-8a65e4ed73b5}



~~~ Files



~~~ Folders



~~~ FireFox

Emptied folder: C:\Users\Michal&Leĺa\AppData\Roaming\mozilla\firefox\profiles\ftzg3a4h.default\minidumps [25 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 27.04.2014 at 15:26:31,70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 27 dub 2014 15:38

LOg RK:

RogueKiller V8.8.15 _x64_ [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal&Leňa [Práva správce]
Mód : Kontrola -- Datum : 04/27/2014 15:35:48
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[SCREENSVR][SUSP PATH] HKCU\[...]\Desktop : SCRNSAVE.EXE (C:\Windows\avastSS.scr [7]) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
[Address] EAT @explorer.exe (WlanAllocateMemory) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198AC8)
[Address] EAT @explorer.exe (WlanCloseHandle) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81938A0)
[Address] EAT @explorer.exe (WlanConnect) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195558)
[Address] EAT @explorer.exe (WlanDeleteProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196D10)
[Address] EAT @explorer.exe (WlanDisconnect) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81957E8)
[Address] EAT @explorer.exe (WlanEnumInterfaces) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193A80)
[Address] EAT @explorer.exe (WlanExtractPsdIEDataList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198394)
[Address] EAT @explorer.exe (WlanFreeMemory) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A5A0)
[Address] EAT @explorer.exe (WlanGetAvailableNetworkList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194F88)
[Address] EAT @explorer.exe (WlanGetFilterList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197F9C)
[Address] EAT @explorer.exe (WlanGetInterfaceCapability) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194188)
[Address] EAT @explorer.exe (WlanGetNetworkBssList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195268)
[Address] EAT @explorer.exe (WlanGetProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196A20)
[Address] EAT @explorer.exe (WlanGetProfileCustomUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197B1C)
[Address] EAT @explorer.exe (WlanGetProfileList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197404)
[Address] EAT @explorer.exe (WlanGetSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198D88)
[Address] EAT @explorer.exe (WlanHostedNetworkForceStart) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819935C)
[Address] EAT @explorer.exe (WlanHostedNetworkForceStop) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199418)
[Address] EAT @explorer.exe (WlanHostedNetworkInitSettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81999D8)
[Address] EAT @explorer.exe (WlanHostedNetworkQueryProperty) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81994D4)
[Address] EAT @explorer.exe (WlanHostedNetworkQuerySecondaryKey) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A020)
[Address] EAT @explorer.exe (WlanHostedNetworkQueryStatus) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199B50)
[Address] EAT @explorer.exe (WlanHostedNetworkRefreshSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199A94)
[Address] EAT @explorer.exe (WlanHostedNetworkSetProperty) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199744)
[Address] EAT @explorer.exe (WlanHostedNetworkSetSecondaryKey) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199D78)
[Address] EAT @explorer.exe (WlanHostedNetworkStartUsing) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81991EC)
[Address] EAT @explorer.exe (WlanHostedNetworkStopUsing) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81992A4)
[Address] EAT @explorer.exe (WlanIhvControl) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194A00)
[Address] EAT @explorer.exe (WlanOpenHandle) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8191960)
[Address] EAT @explorer.exe (WlanQueryAutoConfigParameter) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193EE8)
[Address] EAT @explorer.exe (WlanQueryInterface) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194668)
[Address] EAT @explorer.exe (WlanReasonCodeToString) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198A54)
[Address] EAT @explorer.exe (WlanRegisterNotification) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195A08)
[Address] EAT @explorer.exe (WlanRegisterVirtualStationNotification) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A358)
[Address] EAT @explorer.exe (WlanRenameProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196F4C)
[Address] EAT @explorer.exe (WlanSaveTemporaryProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81987D0)
[Address] EAT @explorer.exe (WlanScan) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194D40)
[Address] EAT @explorer.exe (WlanSetAutoConfigParameter) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193D10)
[Address] EAT @explorer.exe (WlanSetFilterList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197DCC)
[Address] EAT @explorer.exe (WlanSetInterface) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194470)
[Address] EAT @explorer.exe (WlanSetProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196760)
[Address] EAT @explorer.exe (WlanSetProfileCustomUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81978A4)
[Address] EAT @explorer.exe (WlanSetProfileEapUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195CC4)
[Address] EAT @explorer.exe (WlanSetProfileEapXmlUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195F9C)
[Address] EAT @explorer.exe (WlanSetProfileList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81971A8)
[Address] EAT @explorer.exe (WlanSetProfilePosition) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197644)
[Address] EAT @explorer.exe (WlanSetPsdIEDataList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81981B0)
[Address] EAT @explorer.exe (WlanSetSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198B58)

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000YS-01MPB0 ATA Device +++++
--- User ---
[MBR] 49b7b97f4fe489159da1f965165bd0b1
[BSP] d25c804e32aa00cc0c0490b75cb9eaed : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 100014 MB
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 204828750 | Size: 376923 MB
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD5000YS-01MPB1 ATA Device +++++
--- User ---
[MBR] 7f0dde73f072f2336f0751e276a60245
[BSP] 2c87dfe975b63f9c07f3b7bedbc3602a : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_04272014_153548.txt >>


Co dál, případně co s tím MAM?

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Orcus » 28 dub 2014 08:00

MBAM prozatím přeskočíme, ke konci se k němu vrátíme.

====================================================

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání- Finished "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

====================================================

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Pokud se log nevejde do jedné zprávy, rozděl jej na více částí.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 28 dub 2014 18:07

Log RK:

RogueKiller V8.8.15 _x64_ [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal&Leňa [Práva správce]
Mód : Odebrat -- Datum : 04/28/2014 18:04:53
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[SCREENSVR][SUSP PATH] HKCU\[...]\Desktop : SCRNSAVE.EXE (C:\Windows\avastSS.scr [7]) -> NAHRAZENO (C:\Windows\system32\logon.scr)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
[Address] EAT @explorer.exe (WlanAllocateMemory) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198AC8)
[Address] EAT @explorer.exe (WlanCloseHandle) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81938A0)
[Address] EAT @explorer.exe (WlanConnect) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195558)
[Address] EAT @explorer.exe (WlanDeleteProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196D10)
[Address] EAT @explorer.exe (WlanDisconnect) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81957E8)
[Address] EAT @explorer.exe (WlanEnumInterfaces) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193A80)
[Address] EAT @explorer.exe (WlanExtractPsdIEDataList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198394)
[Address] EAT @explorer.exe (WlanFreeMemory) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A5A0)
[Address] EAT @explorer.exe (WlanGetAvailableNetworkList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194F88)
[Address] EAT @explorer.exe (WlanGetFilterList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197F9C)
[Address] EAT @explorer.exe (WlanGetInterfaceCapability) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194188)
[Address] EAT @explorer.exe (WlanGetNetworkBssList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195268)
[Address] EAT @explorer.exe (WlanGetProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196A20)
[Address] EAT @explorer.exe (WlanGetProfileCustomUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197B1C)
[Address] EAT @explorer.exe (WlanGetProfileList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197404)
[Address] EAT @explorer.exe (WlanGetSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198D88)
[Address] EAT @explorer.exe (WlanHostedNetworkForceStart) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819935C)
[Address] EAT @explorer.exe (WlanHostedNetworkForceStop) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199418)
[Address] EAT @explorer.exe (WlanHostedNetworkInitSettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81999D8)
[Address] EAT @explorer.exe (WlanHostedNetworkQueryProperty) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81994D4)
[Address] EAT @explorer.exe (WlanHostedNetworkQuerySecondaryKey) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A020)
[Address] EAT @explorer.exe (WlanHostedNetworkQueryStatus) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199B50)
[Address] EAT @explorer.exe (WlanHostedNetworkRefreshSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199A94)
[Address] EAT @explorer.exe (WlanHostedNetworkSetProperty) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199744)
[Address] EAT @explorer.exe (WlanHostedNetworkSetSecondaryKey) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8199D78)
[Address] EAT @explorer.exe (WlanHostedNetworkStartUsing) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81991EC)
[Address] EAT @explorer.exe (WlanHostedNetworkStopUsing) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81992A4)
[Address] EAT @explorer.exe (WlanIhvControl) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194A00)
[Address] EAT @explorer.exe (WlanOpenHandle) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8191960)
[Address] EAT @explorer.exe (WlanQueryAutoConfigParameter) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193EE8)
[Address] EAT @explorer.exe (WlanQueryInterface) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194668)
[Address] EAT @explorer.exe (WlanReasonCodeToString) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198A54)
[Address] EAT @explorer.exe (WlanRegisterNotification) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195A08)
[Address] EAT @explorer.exe (WlanRegisterVirtualStationNotification) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF819A358)
[Address] EAT @explorer.exe (WlanRenameProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196F4C)
[Address] EAT @explorer.exe (WlanSaveTemporaryProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81987D0)
[Address] EAT @explorer.exe (WlanScan) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194D40)
[Address] EAT @explorer.exe (WlanSetAutoConfigParameter) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8193D10)
[Address] EAT @explorer.exe (WlanSetFilterList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197DCC)
[Address] EAT @explorer.exe (WlanSetInterface) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8194470)
[Address] EAT @explorer.exe (WlanSetProfile) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8196760)
[Address] EAT @explorer.exe (WlanSetProfileCustomUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81978A4)
[Address] EAT @explorer.exe (WlanSetProfileEapUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195CC4)
[Address] EAT @explorer.exe (WlanSetProfileEapXmlUserData) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8195F9C)
[Address] EAT @explorer.exe (WlanSetProfileList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81971A8)
[Address] EAT @explorer.exe (WlanSetProfilePosition) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8197644)
[Address] EAT @explorer.exe (WlanSetPsdIEDataList) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF81981B0)
[Address] EAT @explorer.exe (WlanSetSecuritySettings) : SYNCENG.dll -> HOOKED (C:\Windows\system32\Wlanapi.dll @ 0xF8198B58)

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000YS-01MPB0 ATA Device +++++
--- User ---
[MBR] 49b7b97f4fe489159da1f965165bd0b1
[BSP] d25c804e32aa00cc0c0490b75cb9eaed : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 100014 MB
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 204828750 | Size: 376923 MB
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD5000YS-01MPB1 ATA Device +++++
--- User ---
[MBR] 7f0dde73f072f2336f0751e276a60245
[BSP] 2c87dfe975b63f9c07f3b7bedbc3602a : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_04282014_180453.txt >>
RKreport[0]_S_04272014_153548.txt;RKreport[0]_S_04282014_175945.txt

Vercingetorix
Level 2
Level 2
Příspěvky: 200
Registrován: březen 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - tentokrát na stolním PC

Příspěvekod Vercingetorix » 28 dub 2014 18:16

Log TDSSKiller:

18:10:03.0243 0x0c40 TDSS rootkit removing tool 3.0.0.33 Apr 24 2014 14:02:50
18:10:07.0486 0x0c40 ============================================================
18:10:07.0486 0x0c40 Current date / time: 2014/04/28 18:10:07.0486
18:10:07.0486 0x0c40 SystemInfo:
18:10:07.0486 0x0c40
18:10:07.0486 0x0c40 OS Version: 6.1.7601 ServicePack: 1.0
18:10:07.0486 0x0c40 Product type: Workstation
18:10:07.0486 0x0c40 ComputerName: KOMPL
18:10:07.0486 0x0c40 UserName: Michal&Leňa
18:10:07.0486 0x0c40 Windows directory: C:\Windows
18:10:07.0486 0x0c40 System windows directory: C:\Windows
18:10:07.0486 0x0c40 Running under WOW64
18:10:07.0486 0x0c40 Processor architecture: Intel x64
18:10:07.0486 0x0c40 Number of processors: 2
18:10:07.0486 0x0c40 Page size: 0x1000
18:10:07.0486 0x0c40 Boot type: Normal boot
18:10:07.0486 0x0c40 ============================================================
18:10:09.0187 0x0c40 KLMD registered as C:\Windows\system32\drivers\01462243.sys
18:10:09.0296 0x0c40 System UUID: {44718978-C394-E84D-A112-B982083350F5}
18:10:10.0045 0x0c40 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:10:10.0560 0x0c40 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:10:10.0575 0x0c40 ============================================================
18:10:10.0575 0x0c40 \Device\Harddisk0\DR0:
18:10:10.0575 0x0c40 MBR partitions:
18:10:10.0575 0x0c40 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC35700F
18:10:10.0591 0x0c40 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC35708D, BlocksNum 0x2E02DBB4
18:10:10.0591 0x0c40 \Device\Harddisk1\DR1:
18:10:10.0591 0x0c40 MBR partitions:
18:10:10.0591 0x0c40 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
18:10:10.0591 0x0c40 ============================================================
18:10:10.0606 0x0c40 C: <-> \Device\Harddisk0\DR0\Partition1
18:10:10.0606 0x0c40 E: <-> \Device\Harddisk1\DR1\Partition1
18:10:10.0638 0x0c40 D: <-> \Device\Harddisk0\DR0\Partition2
18:10:10.0638 0x0c40 ============================================================
18:10:10.0638 0x0c40 Initialize success
18:10:10.0638 0x0c40 ============================================================
18:10:14.0194 0x0f14 ============================================================
18:10:14.0194 0x0f14 Scan started
18:10:14.0194 0x0f14 Mode: Manual;
18:10:14.0194 0x0f14 ============================================================
18:10:14.0194 0x0f14 KSN ping started
18:10:17.0002 0x0f14 KSN ping finished: true
18:10:17.0595 0x0f14 ================ Scan system memory ========================
18:10:17.0595 0x0f14 System memory - ok
18:10:17.0595 0x0f14 ================ Scan services =============================
18:10:17.0767 0x0f14 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:10:17.0782 0x0f14 1394ohci - ok
18:10:17.0860 0x0f14 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:10:17.0876 0x0f14 ACPI - ok
18:10:17.0876 0x0f14 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:10:17.0876 0x0f14 AcpiPmi - ok
18:10:18.0001 0x0f14 [ 047BD1EB681453A7FE492A71802AC9F3, C7401A815D4604CA341EEEAE17C7256401A8D725D27E068E67E791CAD6461445 ] AdobeActiveFileMonitor10.0 C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
18:10:18.0016 0x0f14 AdobeActiveFileMonitor10.0 - ok
18:10:18.0079 0x0f14 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
18:10:18.0094 0x0f14 AdobeARMservice - ok
18:10:18.0157 0x0f14 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:10:18.0172 0x0f14 adp94xx - ok
18:10:18.0219 0x0f14 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:10:18.0235 0x0f14 adpahci - ok
18:10:18.0250 0x0f14 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:10:18.0266 0x0f14 adpu320 - ok
18:10:18.0282 0x0f14 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:10:18.0282 0x0f14 AeLookupSvc - ok
18:10:18.0360 0x0f14 [ 79059559E89D06E8B80CE2944BE20228, 6E041D2FED2D0C3D8E16E56CB61D3245F9144EA92F5BDC9A4AA30598D1C8E6EE ] AFD C:\Windows\system32\drivers\afd.sys
18:10:18.0375 0x0f14 AFD - ok
18:10:18.0391 0x0f14 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys
18:10:18.0391 0x0f14 agp440 - ok
18:10:18.0406 0x0f14 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe
18:10:18.0406 0x0f14 ALG - ok
18:10:18.0438 0x0f14 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys
18:10:18.0438 0x0f14 aliide - ok
18:10:18.0469 0x0f14 [ D696F317BD465A602566F8E1DCCE15F7, 6CE77CD4221C0854986F760D1944DF9F4255192D99630D43A0527A6D58D83406 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:10:18.0469 0x0f14 AMD External Events Utility - ok
18:10:18.0516 0x0f14 AMD FUEL Service - ok
18:10:18.0531 0x0f14 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys
18:10:18.0531 0x0f14 amdide - ok
18:10:18.0562 0x0f14 [ 6A2EEB0C4133B20773BB3DD0B7B377B4, E4CB35C6937C70A145A13E5AE5B34A271B49101DA623171ACBFDA8601E5A70EA ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
18:10:18.0562 0x0f14 amdiox64 - ok
18:10:18.0609 0x0f14 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:10:18.0609 0x0f14 AmdK8 - ok
18:10:18.0640 0x0f14 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:10:18.0640 0x0f14 AmdPPM - ok
18:10:18.0687 0x0f14 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:10:18.0687 0x0f14 amdsata - ok
18:10:18.0703 0x0f14 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:10:18.0703 0x0f14 amdsbs - ok
18:10:18.0718 0x0f14 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:10:18.0718 0x0f14 amdxata - ok
18:10:18.0750 0x0f14 [ 5B25D1A753CC3A3EDB909BB759AC1098, 1B931342D8D36C8D177D6D9BFFFD8CDC0C6E6F82BA552DC8E5CDC1CAF528D0B0 ] AODDriver4.1 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
18:10:18.0750 0x0f14 AODDriver4.1 - ok
18:10:18.0781 0x0f14 [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID C:\Windows\system32\drivers\appid.sys
18:10:18.0781 0x0f14 AppID - ok
18:10:18.0812 0x0f14 [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:10:18.0812 0x0f14 AppIDSvc - ok
18:10:18.0859 0x0f14 [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo C:\Windows\System32\appinfo.dll
18:10:18.0859 0x0f14 Appinfo - ok
18:10:18.0890 0x0f14 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\DRIVERS\arc.sys
18:10:18.0890 0x0f14 arc - ok
18:10:18.0921 0x0f14 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:10:18.0921 0x0f14 arcsas - ok
18:10:19.0015 0x0f14 [ 68726474C69B738EAC3A62E06B33ADDC, C470C9DB58840149CE002F3E6003382ECF740884A683BAE8F9D10831BE218FA2 ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
18:10:19.0015 0x0f14 AsIO - ok
18:10:19.0342 0x0f14 [ 9A262EDD17F8473B91B333D6B031A901, 05DFBD3A7D83FDE1D062EA719ACA9EC48CB7FD42D17DDD88B82E5D25469ADD23 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
18:10:19.0358 0x0f14 aspnet_state - ok
18:10:19.0405 0x0f14 [ 5C49AB607897C94E123EC8364FF4BF61, 77F69B00DDE1433C115AA617E0063CB93EE29B3E8D168EF2497E31DD573D5A13 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
18:10:19.0405 0x0f14 aswMonFlt - ok
18:10:19.0436 0x0f14 [ 679712B7A353EE665B9301592164A172, CA3C918106A355BAFD0833BB493DF2CCBC2D0F90CA7EBF5E27CC088C7170B0E0 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys
18:10:19.0436 0x0f14 aswRdr - ok
18:10:19.0467 0x0f14 [ C04F7B373881009D7994D9BF55D24AB4, 5DEEA804F4F9862024F40A204E88DBCFFBDD2DC87CA86145E3FB649CFCCDC624 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
18:10:19.0467 0x0f14 aswRvrt - ok
18:10:19.0545 0x0f14 [ 1BA60C77EB3CDB6129DAD25BAF675F43, 1D5BB6B427E065494C8A363996974048C890F9DBBEEF305B7034873696DFD969 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
18:10:19.0576 0x0f14 aswSnx - ok
18:10:19.0608 0x0f14 [ 79ADA401A6E2054F110E7FBDFAC71942, 0E551FB9E5FE598900036E872E16EB407F7F63FD7A8A0AFAB5094D9DFA75CFCF ] aswSP C:\Windows\system32\drivers\aswSP.sys
18:10:19.0623 0x0f14 aswSP - ok
18:10:19.0623 0x0f14 aswStm - ok
18:10:19.0654 0x0f14 [ 59787B95DD9CA44CB139D96863438587, C36E1A812931BBEACE38BF1E621C950439144979E31961C016AD1AE323579058 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
18:10:19.0654 0x0f14 aswVmm - ok
18:10:19.0670 0x0f14 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:10:19.0670 0x0f14 AsyncMac - ok
18:10:19.0701 0x0f14 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys
18:10:19.0701 0x0f14 atapi - ok
18:10:19.0732 0x0f14 [ 24464B908E143D2561E9E452FEE97309, F5A24FEBAD1B1795A075130F7FFDD4EB76C8F1855FA1628A29CAFAF03C1C9183 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
18:10:19.0732 0x0f14 AtiHDAudioService - ok
18:10:19.0982 0x0f14 [ 52BD95CAA9CAE8977FE043E9AD6D2D0E, E96DD29A2FCE1403340CB29D34F657DF17F483F62A2E8E24890F9BC4812B2971 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:10:20.0076 0x0f14 atikmdag - ok
18:10:20.0154 0x0f14 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:10:20.0169 0x0f14 AudioEndpointBuilder - ok
18:10:20.0200 0x0f14 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv C:\Windows\System32\Audiosrv.dll
18:10:20.0216 0x0f14 AudioSrv - ok
18:10:20.0247 0x0f14 [ 4D41D30E2FAB3307967C7A0B045DC874, 620482D08544478862C78285E17DEE9BC3466DF8B62BD502B0C17AE6501D2B5E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:10:20.0247 0x0f14 avast! Antivirus - ok
18:10:20.0294 0x0f14 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:10:20.0294 0x0f14 AxInstSV - ok
18:10:20.0372 0x0f14 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
18:10:20.0403 0x0f14 b06bdrv - ok
18:10:20.0450 0x0f14 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
18:10:20.0450 0x0f14 b57nd60a - ok
18:10:20.0497 0x0f14 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll
18:10:20.0497 0x0f14 BDESVC - ok
18:10:20.0528 0x0f14 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys
18:10:20.0528 0x0f14 Beep - ok
18:10:20.0606 0x0f14 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll
18:10:20.0622 0x0f14 BFE - ok
18:10:20.0668 0x0f14 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll
18:10:20.0684 0x0f14 BITS - ok
18:10:20.0700 0x0f14 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:10:20.0700 0x0f14 blbdrive - ok
18:10:20.0762 0x0f14 [ F832F1505AD8B83474BD9A5B1B985E01, 205D9F237DD50FDF84F57CC53476B5ADB218A03A8B68B017AFF7CBD0DCAC71C4 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
18:10:20.0793 0x0f14 Bonjour Service - ok
18:10:20.0809 0x0f14 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:10:20.0824 0x0f14 bowser - ok
18:10:20.0824 0x0f14 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:10:20.0824 0x0f14 BrFiltLo - ok
18:10:20.0840 0x0f14 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:10:20.0840 0x0f14 BrFiltUp - ok
18:10:20.0856 0x0f14 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll
18:10:20.0856 0x0f14 Browser - ok
18:10:20.0887 0x0f14 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:10:20.0887 0x0f14 Brserid - ok
18:10:20.0902 0x0f14 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:10:20.0902 0x0f14 BrSerWdm - ok
18:10:20.0918 0x0f14 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:10:20.0918 0x0f14 BrUsbMdm - ok
18:10:20.0918 0x0f14 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:10:20.0918 0x0f14 BrUsbSer - ok
18:10:20.0934 0x0f14 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:10:20.0934 0x0f14 BTHMODEM - ok
18:10:20.0949 0x0f14 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll
18:10:20.0965 0x0f14 bthserv - ok
18:10:20.0965 0x0f14 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:10:20.0980 0x0f14 cdfs - ok
18:10:21.0012 0x0f14 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
18:10:21.0012 0x0f14 cdrom - ok
18:10:21.0043 0x0f14 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll
18:10:21.0043 0x0f14 CertPropSvc - ok
18:10:21.0074 0x0f14 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:10:21.0074 0x0f14 circlass - ok
18:10:21.0136 0x0f14 [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys
18:10:21.0152 0x0f14 CLFS - ok
18:10:21.0199 0x0f14 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:10:21.0214 0x0f14 clr_optimization_v2.0.50727_32 - ok
18:10:21.0261 0x0f14 [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:10:21.0261 0x0f14 clr_optimization_v2.0.50727_64 - ok
18:10:21.0339 0x0f14 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:10:21.0355 0x0f14 clr_optimization_v4.0.30319_32 - ok
18:10:21.0386 0x0f14 [ 4AEDAB50F83580D0B4D6CF78191F92AA, D113C47013B018B45161911B96E93AF96A2F3B34FA47061BF6E7A71FBA03194A ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:10:21.0386 0x0f14 clr_optimization_v4.0.30319_64 - ok
18:10:21.0402 0x0f14 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:10:21.0402 0x0f14 CmBatt - ok
18:10:21.0433 0x0f14 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:10:21.0433 0x0f14 cmdide - ok
18:10:21.0464 0x0f14 [ EBF28856F69CF094A902F884CF989706, AD6C9F0BC20AA49EEE5478DA0F856F0EA2B414B63208C5FFB03C9D7F5B59765F ] CNG C:\Windows\system32\Drivers\cng.sys
18:10:21.0480 0x0f14 CNG - ok
18:10:21.0526 0x0f14 [ 5C4219C10B5887DFF85E1D2779AED55B, AD0B71103C42D3E4F2E76B949D986FCFE0717CF99D0F14CE4A4F07625C87F094 ] colormunki C:\Windows\system32\Drivers\colormunki_x64.sys
18:10:21.0526 0x0f14 colormunki - ok
18:10:21.0620 0x0f14 [ 7FC158B2A6BF8F07143839E6EF0E4256, C3E1027769EB34269760BF98EE5D7F0C4BC2C0767E57CA603215E94AFA9DC07D ] ColorMunkiService C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe
18:10:21.0636 0x0f14 ColorMunkiService - ok
18:10:21.0667 0x0f14 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:10:21.0667 0x0f14 Compbatt - ok
18:10:21.0698 0x0f14 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:10:21.0714 0x0f14 CompositeBus - ok
18:10:21.0729 0x0f14 COMSysApp - ok
18:10:21.0760 0x0f14 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:10:21.0760 0x0f14 crcdisk - ok
18:10:21.0792 0x0f14 [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:10:21.0807 0x0f14 CryptSvc - ok
18:10:21.0885 0x0f14 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:10:21.0901 0x0f14 DcomLaunch - ok
18:10:21.0963 0x0f14 [ D7C3889835416BF79AEC987713F15310, BB845576A6C260773D20C08850DAC763D3BA471862F3E5AD02765783CCEE5582 ] DCSLoader C:\Windows\system32\spool\DRIVERS\x64\3\OPHPLDCS.EXE
18:10:21.0963 0x0f14 DCSLoader - ok
18:10:22.0010 0x0f14 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll
18:10:22.0026 0x0f14 defragsvc - ok
18:10:22.0057 0x0f14 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:10:22.0057 0x0f14 DfsC - ok
18:10:22.0088 0x0f14 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:10:22.0104 0x0f14 Dhcp - ok
18:10:22.0104 0x0f14 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys
18:10:22.0119 0x0f14 discache - ok
18:10:22.0150 0x0f14 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:10:22.0150 0x0f14 Disk - ok
18:10:22.0197 0x0f14 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:10:22.0213 0x0f14 Dnscache - ok
18:10:22.0244 0x0f14 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll
18:10:22.0260 0x0f14 dot3svc - ok
18:10:22.0306 0x0f14 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll
18:10:22.0306 0x0f14 DPS - ok
18:10:22.0338 0x0f14 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:10:22.0338 0x0f14 drmkaud - ok
18:10:22.0650 0x0f14 [ 88612F1CE3BF42256913BF6E61C70D52, 7CF190F83FA8F15C33008EB381D3E345CEF37CBC046227DED26B36799EF4D9A7 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:10:22.0665 0x0f14 DXGKrnl - ok
18:10:22.0696 0x0f14 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll
18:10:22.0696 0x0f14 EapHost - ok
18:10:22.0852 0x0f14 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
18:10:22.0899 0x0f14 ebdrv - ok
18:10:22.0930 0x0f14 [ 4D71227301DD8D09097B9E4CC6527E5A, 193D47ADCB722B581CC0F29B794AB3E455B6E9BEA367CE9A5216A09E055B7F1E ] EFS C:\Windows\System32\lsass.exe
18:10:22.0946 0x0f14 EFS - ok
18:10:23.0040 0x0f14 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:10:23.0055 0x0f14 ehRecvr - ok
18:10:23.0071 0x0f14 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe
18:10:23.0071 0x0f14 ehSched - ok
18:10:23.0102 0x0f14 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:10:23.0118 0x0f14 elxstor - ok
18:10:23.0133 0x0f14 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:10:23.0133 0x0f14 ErrDev - ok
18:10:23.0211 0x0f14 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll
18:10:23.0227 0x0f14 EventSystem - ok
18:10:23.0258 0x0f14 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys
18:10:23.0258 0x0f14 exfat - ok
18:10:23.0289 0x0f14 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:10:23.0289 0x0f14 fastfat - ok
18:10:23.0336 0x0f14 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe
18:10:23.0336 0x0f14 Fax - ok
18:10:23.0352 0x0f14 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:10:23.0352 0x0f14 fdc - ok
18:10:23.0383 0x0f14 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll
18:10:23.0383 0x0f14 fdPHost - ok
18:10:23.0383 0x0f14 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll
18:10:23.0383 0x0f14 FDResPub - ok
18:10:23.0398 0x0f14 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:10:23.0398 0x0f14 FileInfo - ok
18:10:23.0414 0x0f14 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:10:23.0414 0x0f14 Filetrace - ok
18:10:23.0414 0x0f14 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:10:23.0414 0x0f14 flpydisk - ok
18:10:23.0476 0x0f14 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:10:23.0492 0x0f14 FltMgr - ok
18:10:23.0554 0x0f14 [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache C:\Windows\system32\FntCache.dll
18:10:23.0570 0x0f14 FontCache - ok
18:10:23.0617 0x0f14 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:10:23.0617 0x0f14 FontCache3.0.0.0 - ok
18:10:23.0648 0x0f14 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:10:23.0664 0x0f14 FsDepends - ok
18:10:23.0679 0x0f14 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:10:23.0695 0x0f14 Fs_Rec - ok
18:10:23.0757 0x0f14 [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:10:23.0773 0x0f14 fvevol - ok
18:10:23.0788 0x0f14 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:10:23.0804 0x0f14 gagp30kx - ok
18:10:23.0851 0x0f14 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll
18:10:23.0866 0x0f14 gpsvc - ok
18:10:23.0882 0x0f14 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:10:23.0882 0x0f14 hcw85cir - ok
18:10:23.0929 0x0f14 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:10:23.0944 0x0f14 HdAudAddService - ok
18:10:23.0960 0x0f14 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:10:23.0960 0x0f14 HDAudBus - ok
18:10:23.0960 0x0f14 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:10:23.0960 0x0f14 HidBatt - ok
18:10:23.0976 0x0f14 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:10:23.0976 0x0f14 HidBth - ok
18:10:23.0991 0x0f14 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:10:23.0991 0x0f14 HidIr - ok
18:10:24.0007 0x0f14 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll
18:10:24.0022 0x0f14 hidserv - ok
18:10:24.0054 0x0f14 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\drivers\hidusb.sys
18:10:24.0054 0x0f14 HidUsb - ok
18:10:24.0085 0x0f14 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:10:24.0100 0x0f14 hkmsvc - ok
18:10:24.0132 0x0f14 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:10:24.0147 0x0f14 HomeGroupListener - ok
18:10:24.0178 0x0f14 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:10:24.0194 0x0f14 HomeGroupProvider - ok
18:10:24.0225 0x0f14 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:10:24.0225 0x0f14 HpSAMD - ok
18:10:24.0272 0x0f14 [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:10:24.0303 0x0f14 HTTP - ok
18:10:24.0303 0x0f14 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:10:24.0319 0x0f14 hwpolicy - ok
18:10:24.0334 0x0f14 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:10:24.0350 0x0f14 i8042prt - ok
18:10:24.0381 0x0f14 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:10:24.0397 0x0f14 iaStorV - ok
18:10:24.0475 0x0f14 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:10:24.0506 0x0f14 idsvc - ok
18:10:24.0537 0x0f14 IEEtwCollectorService - ok
18:10:24.0553 0x0f14 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:10:24.0553 0x0f14 iirsp - ok
18:10:24.0631 0x0f14 [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll
18:10:24.0678 0x0f14 IKEEXT - ok
18:10:24.0709 0x0f14 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys
18:10:24.0709 0x0f14 intelide - ok
18:10:24.0740 0x0f14 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:10:24.0740 0x0f14 intelppm - ok
18:10:24.0787 0x0f14 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:10:24.0787 0x0f14 IPBusEnum - ok
18:10:24.0834 0x0f14 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:10:24.0834 0x0f14 IpFilterDriver - ok
18:10:24.0896 0x0f14 [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:10:24.0943 0x0f14 iphlpsvc - ok
18:10:24.0958 0x0f14 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:10:24.0958 0x0f14 IPMIDRV - ok
18:10:24.0974 0x0f14 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:10:24.0974 0x0f14 IPNAT - ok
18:10:24.0990 0x0f14 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:10:24.0990 0x0f14 IRENUM - ok
18:10:25.0021 0x0f14 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:10:25.0021 0x0f14 isapnp - ok
18:10:25.0068 0x0f14 [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:10:25.0083 0x0f14 iScsiPrt - ok
18:10:25.0114 0x0f14 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
18:10:25.0114 0x0f14 kbdclass - ok
18:10:25.0130 0x0f14 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
18:10:25.0130 0x0f14 kbdhid - ok
18:10:25.0130 0x0f14 [ 4D71227301DD8D09097B9E4CC6527E5A, 193D47ADCB722B581CC0F29B794AB3E455B6E9BEA367CE9A5216A09E055B7F1E ] KeyIso C:\Windows\system32\lsass.exe
18:10:25.0146 0x0f14 KeyIso - ok
18:10:25.0177 0x0f14 [ 8F489706472F7E9A06BAAA198703FA64, F020406690FB38EABD82D63B91D33039CC93ED52A5497AE12BAF475F22D0B08A ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:10:25.0177 0x0f14 KSecDD - ok
18:10:25.0192 0x0f14 [ 868A2CAAB12EFC7A021682BCA0EEC54C, 12C4925B5B3D6EA7B6410C01F33158C6EAB50CBD6AF445F8B04ED9899720C2DD ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:10:25.0192 0x0f14 KSecPkg - ok
18:10:25.0208 0x0f14 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
18:10:25.0208 0x0f14 ksthunk - ok
18:10:25.0239 0x0f14 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll
18:10:25.0255 0x0f14 KtmRm - ok
18:10:25.0302 0x0f14 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll
18:10:25.0317 0x0f14 LanmanServer - ok
18:10:25.0348 0x0f14 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:10:25.0348 0x0f14 LanmanWorkstation - ok
18:10:25.0395 0x0f14 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:10:25.0395 0x0f14 lltdio - ok
18:10:25.0426 0x0f14 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:10:25.0442 0x0f14 lltdsvc - ok
18:10:25.0458 0x0f14 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:10:25.0458 0x0f14 lmhosts - ok
18:10:25.0489 0x0f14 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:10:25.0489 0x0f14 LSI_FC - ok
18:10:25.0504 0x0f14 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:10:25.0504 0x0f14 LSI_SAS - ok
18:10:25.0520 0x0f14 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:10:25.0520 0x0f14 LSI_SAS2 - ok
18:10:25.0536 0x0f14 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:10:25.0536 0x0f14 LSI_SCSI - ok
18:10:25.0551 0x0f14 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys
18:10:25.0551 0x0f14 luafv - ok
18:10:25.0816 0x0f14 [ 6140163BFE9D8F2DFDBA088ED5521C13, B7B501F0D1527A15B1610D133E97AB431574502F0553734009627488D0007595 ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
18:10:25.0832 0x0f14 MBAMSwissArmy - ok
18:10:25.0863 0x0f14 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:10:25.0879 0x0f14 Mcx2Svc - ok
18:10:25.0894 0x0f14 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:10:25.0894 0x0f14 megasas - ok
18:10:25.0926 0x0f14 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:10:25.0926 0x0f14 MegaSR - ok
18:10:25.0972 0x0f14 [ 21A2F24477A262E774B38947FE600CBD, B8AEC06AD863BD5399E3ADEA132F017996362EC91A1A1F264C13785A5488E639 ] MemeoBackgroundService C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
18:10:25.0972 0x0f14 MemeoBackgroundService - ok
18:10:26.0004 0x0f14 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll
18:10:26.0004 0x0f14 MMCSS - ok
18:10:26.0035 0x0f14 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys
18:10:26.0035 0x0f14 Modem - ok
18:10:26.0066 0x0f14 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:10:26.0066 0x0f14 monitor - ok
18:10:26.0066 0x0f14 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:10:26.0082 0x0f14 mouclass - ok
18:10:26.0113 0x0f14 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:10:26.0113 0x0f14 mouhid - ok
18:10:26.0160 0x0f14 [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:10:26.0160 0x0f14 mountmgr - ok
18:10:26.0222 0x0f14 [ 338037EFA0E8E8699B2667D57B751574, 59E0D39806D0C4EB57913AA013242837FD39AD378726AEE42D250CBA87C1C3BF ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
18:10:26.0238 0x0f14 MozillaMaintenance - ok
18:10:26.0269 0x0f14 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys
18:10:26.0269 0x0f14 mpio - ok
18:10:26.0300 0x0f14 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:10:26.0300 0x0f14 mpsdrv - ok
18:10:26.0378 0x0f14 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:10:26.0394 0x0f14 MpsSvc - ok
18:10:26.0425 0x0f14 [ 1A4F75E63C9FB84B85DFFC6B63FD5404, 01AFA6DBB4CDE55FE4EA05BBE8F753A4266F8D072EA1EE01DB79F5126780C21F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:10:26.0425 0x0f14 MRxDAV - ok
18:10:26.0440 0x0f14 [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:10:26.0440 0x0f14 mrxsmb - ok
18:10:26.0456 0x0f14 [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:10:26.0472 0x0f14 mrxsmb10 - ok
18:10:26.0472 0x0f14 [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:10:26.0487 0x0f14 mrxsmb20 - ok
18:10:26.0503 0x0f14 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys
18:10:26.0503 0x0f14 msahci - ok
18:10:26.0518 0x0f14 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:10:26.0518 0x0f14 msdsm - ok
18:10:26.0534 0x0f14 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe
18:10:26.0534 0x0f14 MSDTC - ok
18:10:26.0581 0x0f14 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:10:26.0581 0x0f14 Msfs - ok
18:10:26.0596 0x0f14 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:10:26.0596 0x0f14 mshidkmdf - ok
18:10:26.0628 0x0f14 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:10:26.0628 0x0f14 msisadrv - ok
18:10:26.0659 0x0f14 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:10:26.0674 0x0f14 MSiSCSI - ok
18:10:26.0674 0x0f14 msiserver - ok
18:10:26.0706 0x0f14 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:10:26.0706 0x0f14 MSKSSRV - ok
18:10:26.0721 0x0f14 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:10:26.0721 0x0f14 MSPCLOCK - ok
18:10:26.0737 0x0f14 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:10:26.0737 0x0f14 MSPQM - ok
18:10:26.0768 0x0f14 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:10:26.0784 0x0f14 MsRPC - ok
18:10:26.0799 0x0f14 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:10:26.0799 0x0f14 mssmbios - ok
18:10:26.0799 0x0f14 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:10:26.0815 0x0f14 MSTEE - ok
18:10:26.0815 0x0f14 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:10:26.0815 0x0f14 MTConfig - ok
18:10:26.0862 0x0f14 [ 2219A3D695405E7BA2186BA6B9EDE14A, 8B99BD22DACB56FF544ED922962FE4EC1172BF90987A46E3A5F62A3B4E720B0C ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
18:10:26.0862 0x0f14 MTsensor - ok
18:10:26.0862 0x0f14 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys
18:10:26.0877 0x0f14 Mup - ok
18:10:26.0940 0x0f14 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll
18:10:26.0955 0x0f14 napagent - ok
18:10:27.0002 0x0f14 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:10:27.0018 0x0f14 NativeWifiP - ok
18:10:27.0096 0x0f14 [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS C:\Windows\system32\drivers\ndis.sys
18:10:27.0111 0x0f14 NDIS - ok
18:10:27.0142 0x0f14 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:10:27.0142 0x0f14 NdisCap - ok
18:10:27.0174 0x0f14 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:10:27.0174 0x0f14 NdisTapi - ok


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 82 hostů