bitcoin miner 100% cpu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 08:34

Prosím o kontrolu logu :)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:33:14, on 24. 6. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Michal\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Michal\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Users\Michal\AppData\Local\VNT\vntldr.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\BlueStacks\HD-Agent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Michal\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [VNT] "C:\Program Files (x86)\VNT\vntldr.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Michal\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Michal\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Windows] C:\Users\Public\Windows\downloadll.vbs
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{F81B8C36-60B7-44BB-9BDD-0401D1A5AAB6}: NameServer = 8.8.8.8,8.8.4.4
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyPublicWiFi Service (MyPublicWiFiService) - Unknown owner - C:\Program Files (x86)\MyPublicWiFi\PublicWiFiService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10608 bytes
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Reklama
Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod Orcus » 24 čer 2014 09:45

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 11:31

# AdwCleaner v3.213 - Report created 24/06/2014 at 11:27:54
# Updated 23/06/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Michal - MICHAL
# Running from : C:\Users\Michal\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : APNMCP

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\VNT
Folder Deleted : C:\Users\Michal\AppData\Local\VNT

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VNT]
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\AskPartnerNetwork

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?clien ... YYYYYCZ&q={searchTerms}

*************************

AdwCleaner[R0].txt - [1371 octets] - [24/06/2014 11:26:13]
AdwCleaner[R1].txt - [1679 octets] - [24/06/2014 11:27:10]
AdwCleaner[S0].txt - [1531 octets] - [24/06/2014 11:27:54]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1591 octets] ##########
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 12:06

MBAM za chvíli :)
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 12:12

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 24. 6. 2014
Scan Time: 12:02:03
Logfile: pc.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.06.24.04
Rootkit Database: v2014.06.23.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Michal

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 264425
Time Elapsed: 9 min, 42 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 4
Riskware.BitcoinMiner, C:\Users\Michal\Downloads\Minecraft-1.7.9.rar, , [083c86f6017a3cfa66eb57ef3fc2649c],
PUP.Optional.Softonic.A, C:\Users\Michal\Downloads\WinHotSpot_Downloader.exe, , [0e36de9e6516de58c7e0012306fbdd23],
Riskware.BitcoinMiner, C:\Users\Public\Windows\minerd.exe, , [b58ff98394e71f175ef3f74fdf225ca4],
PUP.Proxy.BCM, C:\Users\Public\Windows\mining_proxy.exe, , [d17380fce695be7859c00f07bc44ae52],

Physical Sectors: 0
(No malicious items detected)


(end)
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod jaro3 » 24 čer 2014 20:23

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 21:22

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 Pro x64
Ran by Michal on £t 24. 06. 2014 at 21:16:29,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on £t 24. 06. 2014 at 21:21:24,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 21:30

Nemělo by to ukázat trochu víc v tom logu? :D
A vypadlo mi, že musím exportovat log.. ale je to v karanténě všechno. Bude vadit hodně, když nebude ten log z mbam?
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 24 čer 2014 21:50

RogueKiller V9.1.0.0 (x64) [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal [Práva správce]
Mód : Kontrola -- Datum : 06/24/2014 21:49:33

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-297583467-298121306-1226466021-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-297583467-298121306-1226466021-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-297583467-298121306-1226466021-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-297583467-298121306-1226466021-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG MZMPA032HMCD-000L1 +++++
--- User ---
[MBR] ac7cd1e3d3bd4e24c585015da28eeb0a
[BSP] 00e3dee06cd109873edcd15ba7e75dee : Windows Vista/7/8 MBR Code
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod Orcus » 24 čer 2014 23:04

Nemusí mít v sobě nic, pokud není co vymazat. Pokud je vše v karanténě a nový scan MBAM nic nenajde, nemusíš dávat.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva" a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

====================================================

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Pokud se log nevejde do jedné zprávy, rozděl jej na více částí.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 25 čer 2014 11:53

RogueKiller V9.1.0.0 (x64) [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8.1 (6.3.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : Michal [Práva správce]
Mód : Odebrat -- Datum : 06/25/2014 07:38:07

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.4.1 217.198.113.10 192.168.10.1 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.4.1 217.198.113.10 192.168.10.1 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{36569C3B-167E-4124-BC0E-BBD31B0C79C3} | DhcpNameServer : 192.168.4.1 217.198.113.10 192.168.10.1 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{36569C3B-167E-4124-BC0E-BBD31B0C79C3} | DhcpNameServer : 192.168.4.1 217.198.113.10 192.168.10.1 -> NAHRAZENO ()

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 12 ¤¤¤
[CHROME:Addon] Default : Angry Birds [aknpkdffaafgjchaibgeefbgmgeghloj] -> VYMAZÁNO
[CHROME:Addon] Default : Google Docs [aohghmighlieiainnegkcijnfilokake] -> ERROR [2]
[CHROME:Addon] Default : Google Drive [apdfllckaahabafndbhieahigkjlhalf] -> ERROR [2]
[CHROME:Addon] Default : Google Voice Search Hotword (Beta) [bepbmhgboaologfdajaanbcjmnhjmhfn] -> ERROR [2]
[CHROME:Addon] Default : Turn Off the Lights [bfbmjmiodbnnpllbbbfblcplfjjepjdn] -> ERROR [2]
[CHROME:Addon] Default : YouTube [blpcfgokakmgnkcojhhkbfbldkacnbeo] -> ERROR [2]
[CHROME:Addon] Default : Battlefield Heroes [cehdakiococlfmjcbebbkjkfjhbieknh] -> ERROR [2]
[CHROME:Addon] Default : Adblock Plus [cfhdojbkjhnklbpkdaibdccddilifddb] -> ERROR [2]
[CHROME:Addon] Default : Google Search [coobgpohoikkiipiblmjeljniedjpjpf] -> ERROR [2]
[CHROME:Addon] Default : Yulia Brodskaya [jlgdloilieclkegafohackmhffbmdpko] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
[CHROME:Addon] Default : Gmail [pjkljhegncpnkpknbcohdijeoejaedia] -> ERROR [2]

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG MZMPA032HMCD-000L1 +++++
--- User ---
[MBR] ac7cd1e3d3bd4e24c585015da28eeb0a
[BSP] 00e3dee06cd109873edcd15ba7e75dee : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 2048 | Size: 15423 MB
1 - [ACTIVE] COMPAQ (0x12) [VISIBLE] Offset (sectors): 31590336 | Size: 15108 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: HITACHI HTS547575A9E384 +++++
--- User ---
[MBR] 2f2df61d977c8c4a78aaa15420ca2f87
[BSP] ef296ec7e91d460556a6dc243684a78c : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 411648 | Size: 715202 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_06242014_214933.log - RKreport_SCN_06252014_072209.log - RKreport_DEL_06252014_072259.log - RKreport_SCN_06252014_073517.log
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(

Uživatelský avatar
strikis
Level 4
Level 4
Příspěvky: 1013
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: bitcoin miner 100% cpu

Příspěvekod strikis » 25 čer 2014 12:00

11:55:54.0423 0x087c TDSS rootkit removing tool 3.0.0.39 Jun 5 2014 20:35:54
11:55:57.0896 0x087c ============================================================
11:55:57.0896 0x087c Current date / time: 2014/06/25 11:55:57.0896
11:55:57.0896 0x087c SystemInfo:
11:55:57.0896 0x087c
11:55:57.0896 0x087c OS Version: 6.3.9600 ServicePack: 0.0
11:55:57.0896 0x087c Product type: Workstation
11:55:57.0896 0x087c ComputerName: MICHAL
11:55:57.0896 0x087c UserName: Michal
11:55:57.0896 0x087c Windows directory: C:\Windows
11:55:57.0896 0x087c System windows directory: C:\Windows
11:55:57.0896 0x087c Running under WOW64
11:55:57.0896 0x087c Processor architecture: Intel x64
11:55:57.0896 0x087c Number of processors: 4
11:55:57.0896 0x087c Page size: 0x1000
11:55:57.0896 0x087c Boot type: Normal boot
11:55:57.0896 0x087c ============================================================
11:55:58.0488 0x087c KLMD registered as C:\Windows\system32\drivers\06875541.sys
11:55:59.0098 0x087c System UUID: {6862D26D-B8BD-A39F-5F62-322F0C8956B8}
11:55:59.0845 0x087c Drive \Device\Harddisk0\DR0 - Size: 0x7745D6000 ( 29.82 Gb ), SectorSize: 0x200, Cylinders: 0xF34, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:55:59.0863 0x087c Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 ( 698.64 Gb ), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:55:59.0878 0x087c ============================================================
11:55:59.0878 0x087c \Device\Harddisk0\DR0:
11:55:59.0878 0x087c MBR partitions:
11:55:59.0878 0x087c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1000, BlocksNum 0x1E1F000
11:55:59.0878 0x087c \Device\Harddisk1\DR1:
11:55:59.0879 0x087c MBR partitions:
11:55:59.0879 0x087c \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x574E1000
11:55:59.0879 0x087c ============================================================
11:55:59.0906 0x087c C: <-> \Device\Harddisk1\DR1\Partition1
11:55:59.0908 0x087c E: <-> \Device\Harddisk0\DR0\Partition1
11:55:59.0908 0x087c ============================================================
11:55:59.0908 0x087c Initialize success
11:55:59.0908 0x087c ============================================================
11:56:05.0915 0x03f4 ============================================================
11:56:05.0915 0x03f4 Scan started
11:56:05.0915 0x03f4 Mode: Manual;
11:56:05.0915 0x03f4 ============================================================
11:56:05.0915 0x03f4 KSN ping started
11:56:08.0233 0x03f4 KSN ping finished: true
11:56:09.0390 0x03f4 ================ Scan system memory ========================
11:56:09.0390 0x03f4 System memory - ok
11:56:09.0390 0x03f4 ================ Scan services =============================
11:56:09.0570 0x03f4 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
11:56:09.0578 0x03f4 1394ohci - ok
11:56:09.0620 0x03f4 [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware C:\Windows\system32\drivers\3ware.sys
11:56:09.0623 0x03f4 3ware - ok
11:56:09.0655 0x03f4 [ E19D921EBBD1A2CA4C48D7B5F1685B30, E14F6E48593E03DDAB4DF281755C0A5FC77D491AB8039D421AC84D306C38BCDA ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:56:09.0663 0x03f4 ACPI - ok
11:56:09.0685 0x03f4 [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex C:\Windows\system32\Drivers\acpiex.sys
11:56:09.0687 0x03f4 acpiex - ok
11:56:09.0712 0x03f4 [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
11:56:09.0713 0x03f4 acpipagr - ok
11:56:09.0730 0x03f4 [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
11:56:09.0731 0x03f4 AcpiPmi - ok
11:56:09.0735 0x03f4 [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime C:\Windows\System32\drivers\acpitime.sys
11:56:09.0736 0x03f4 acpitime - ok
11:56:09.0760 0x03f4 [ 5BBFF8B826EC38D32C26334E079C7EFC, 673D46409F0225A804B55FFB77E82AF34F8C7A93BEEF92DC3DFAC7EFCC5F09B6 ] ACPIVPC C:\Windows\System32\drivers\AcpiVpc.sys
11:56:09.0762 0x03f4 ACPIVPC - ok
11:56:09.0851 0x03f4 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:56:09.0853 0x03f4 AdobeARMservice - ok
11:56:09.0903 0x03f4 [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX C:\Windows\system32\drivers\ADP80XX.SYS
11:56:09.0921 0x03f4 ADP80XX - ok
11:56:09.0957 0x03f4 [ B19CA8E441D35AA2B1EE51C10B27DA1B, EBEB96EA44E665B2D4FCD1CC58621A20A17F036EA4A695340A2B65F94F69CDDC ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:56:09.0961 0x03f4 AeLookupSvc - ok
11:56:10.0001 0x03f4 [ 239268BAB58EAE9A3FF4E08334C00451, 13F927730DF9BAEDB3A7AB6F7238270A20E4CDEB3D5324A1C471DF2209F3D239 ] AFD C:\Windows\system32\drivers\afd.sys
11:56:10.0010 0x03f4 AFD - ok
11:56:10.0033 0x03f4 [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440 C:\Windows\system32\drivers\agp440.sys
11:56:10.0035 0x03f4 agp440 - ok
11:56:10.0056 0x03f4 [ 8E8E34B7BA059050EED827410D0697A2, 85B6684709F24729A6497563812A90A54068AC2DD9EEA03037CB1EEF5C85AAA9 ] ahcache C:\Windows\system32\DRIVERS\ahcache.sys
11:56:10.0059 0x03f4 ahcache - ok
11:56:10.0092 0x03f4 [ A91D8E1E433EFB32551BCE69037E1CE7, 41DFDD5B56918D19D09DFB3E4B07460AA85647A8647ABBBB906158D8D6653290 ] ALG C:\Windows\System32\alg.exe
11:56:10.0095 0x03f4 ALG - ok
11:56:10.0142 0x03f4 [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
11:56:10.0145 0x03f4 AmdK8 - ok
11:56:10.0162 0x03f4 [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
11:56:10.0166 0x03f4 AmdPPM - ok
11:56:10.0179 0x03f4 [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:56:10.0181 0x03f4 amdsata - ok
11:56:10.0194 0x03f4 [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
11:56:10.0200 0x03f4 amdsbs - ok
11:56:10.0237 0x03f4 [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:56:10.0239 0x03f4 amdxata - ok
11:56:10.0259 0x03f4 [ BE3BFEFD0EDA6AA4C3A81B0490B1F7F5, 4337C305B51E2EFC8F40357905BFD99CF48D82D2D7DCF7C92E2F4EF5EE6ADFD6 ] AppID C:\Windows\system32\drivers\appid.sys
11:56:10.0261 0x03f4 AppID - ok
11:56:10.0285 0x03f4 [ C0DC3F58214A227980AEB091CFD2F973, 0C3E8453C9F65ADA3E74C38C0E3AC3E0CBFD807B827097046265B38839E151E3 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:56:10.0287 0x03f4 AppIDSvc - ok
11:56:10.0305 0x03f4 [ 7E790DE2487CEDB349D1750B9E47F090, EDA4A87EA2F89ABD174E9590DD46E70B9E7E4B35BDFC3ED90D79CD594F8CB2CD ] Appinfo C:\Windows\System32\appinfo.dll
11:56:10.0307 0x03f4 Appinfo - ok
11:56:10.0327 0x03f4 [ 8176FBA685178FB0F52D46693474FA50, 69FE3692C7FE24289A479ADD74F2C782B59A099B7B07FE5ACFC4DA899E40BFDE ] AppMgmt C:\Windows\System32\appmgmts.dll
11:56:10.0332 0x03f4 AppMgmt - ok
11:56:10.0376 0x03f4 [ 550076AD22A72FF2C28FE2B19FB64C12, 9B8C758CFA57752A1B8057F9A854309B6411753B07134C0153CE47EC695B2100 ] AppReadiness C:\Windows\system32\AppReadiness.dll
11:56:10.0389 0x03f4 AppReadiness - ok
11:56:10.0473 0x03f4 [ 66D592883A272B75DA22873C94D1C99D, B272F9BAF6A7EA648470EE8AE3BF828FB808BED0634FA9647F84EFCE6052AE19 ] AppXSvc C:\Windows\system32\appxdeploymentserver.dll
11:56:10.0495 0x03f4 AppXSvc - ok
11:56:10.0524 0x03f4 [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas C:\Windows\system32\drivers\arcsas.sys
11:56:10.0527 0x03f4 arcsas - ok
11:56:10.0547 0x03f4 [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi C:\Windows\system32\drivers\atapi.sys
11:56:10.0548 0x03f4 atapi - ok
11:56:10.0579 0x03f4 [ 4903CBC14742B5AB4DCF7A92F7DEC483, B8491FDA1D1E767658ECC5C3C3DDFB3EB12A969F0F6ACF116C18300FF54075D5 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
11:56:10.0583 0x03f4 AudioEndpointBuilder - ok
11:56:10.0619 0x03f4 [ 86DD7884124D363A63CCE7A11FDEBBED, E7BAE477D964E395A96342E077774467AA9DE5D8112BFCDE27EEA1CB04A2A480 ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:56:10.0634 0x03f4 Audiosrv - ok
11:56:10.0655 0x03f4 [ 74FD4F3D4CCF7E0AD040BE0F70D916A5, 54BCBCC8F7F4DE7527538C5CDB2E07E6A6B6DDDFE780B489DDD5041A8E011105 ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:56:10.0658 0x03f4 AxInstSV - ok
11:56:10.0700 0x03f4 [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
11:56:10.0712 0x03f4 b06bdrv - ok
11:56:10.0737 0x03f4 [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
11:56:10.0739 0x03f4 BasicDisplay - ok
11:56:10.0752 0x03f4 [ 2748E116F8621A4DB0D39FCDD7318C01, DA2DEB7FE1D887B1EF5E2B5103270B72268D8ABDDA36C396627305C0BA90FC20 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
11:56:10.0753 0x03f4 BasicRender - ok
11:56:10.0772 0x03f4 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2 C:\Windows\System32\drivers\bcmfn2.sys
11:56:10.0773 0x03f4 bcmfn2 - ok
11:56:10.0801 0x03f4 [ BBE61A40665B83488901E41082A6097D, ADF750DB32E1295C57C03D587A60194529C8B83F90F433C3458288FB5E8F475B ] BDESVC C:\Windows\System32\bdesvc.dll
11:56:10.0808 0x03f4 BDESVC - ok
11:56:10.0827 0x03f4 [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep C:\Windows\system32\drivers\Beep.sys
11:56:10.0828 0x03f4 Beep - ok
11:56:10.0869 0x03f4 [ ACC04CBB75086D86031E0C63D0930B98, 70AD3E38FE63A2DC99C742B8E524B1A6E9BFB4D37139865EC234C6350D5D3103 ] BFE C:\Windows\System32\bfe.dll
11:56:10.0884 0x03f4 BFE - ok
11:56:10.0933 0x03f4 [ 15225081966C785A9192782401643FD4, E2BA0C8D044556FDD9DD7A25F7F71553DE7A2924E78F9284413C2AC46F0BF4EB ] BITS C:\Windows\System32\qmgr.dll
11:56:10.0950 0x03f4 BITS - ok
11:56:10.0969 0x03f4 [ 6B4FFFDDC618FCF64473CAA86E305697, 29EA66071D5822920F5C50533673ADAB5204F8B25C11027AD27450D881F1142D ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:56:10.0971 0x03f4 bowser - ok
11:56:10.0996 0x03f4 [ 85948475C7FFCA1B7A825BB7BE9A5E72, B4B6A1450FFC052E652A05F61FFF262FD5220DE71F4E16F60C3E219FC5F64285 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
11:56:11.0002 0x03f4 BrokerInfrastructure - ok
11:56:11.0019 0x03f4 [ D528D6A92D187777691993DD757AF19A, 2C79978310193431E5FC462368424A172858D5351C92D4815C2A7E35B5DDE50C ] Browser C:\Windows\System32\browser.dll
11:56:11.0022 0x03f4 Browser - ok
11:56:11.0042 0x03f4 [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
11:56:11.0044 0x03f4 BthAvrcpTg - ok
11:56:11.0063 0x03f4 [ 746B9F94214915AECDE4B7FEA5FF9664, EA2877D49DB4B7B9CE61653D63E8776DFF1CBCCAB12C14DB1D20DA44B8F06357 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
11:56:11.0065 0x03f4 BthHFEnum - ok
11:56:11.0074 0x03f4 [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
11:56:11.0076 0x03f4 bthhfhid - ok
11:56:11.0086 0x03f4 [ 07E33226AD218A2A162662A05CAFB52F, 0AC3D8B79EDA6DA232FA4E1CAF6592420A9EDE96350D1F0504C2434261684F0B ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
11:56:11.0088 0x03f4 BTHMODEM - ok
11:56:11.0115 0x03f4 [ E5E48FEED73D463175EAB1542495191C, 0A8182F5BA7B694AB1DD3680F1194E4A568FE40DBA4BFDFF2EA09BAD045FFB29 ] bthserv C:\Windows\system32\bthserv.dll
11:56:11.0118 0x03f4 bthserv - ok
11:56:11.0135 0x03f4 [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:56:11.0138 0x03f4 cdfs - ok
11:56:11.0159 0x03f4 [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom C:\Windows\System32\drivers\cdrom.sys
11:56:11.0165 0x03f4 cdrom - ok
11:56:11.0193 0x03f4 [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] CertPropSvc C:\Windows\System32\certprop.dll
11:56:11.0197 0x03f4 CertPropSvc - ok
11:56:11.0212 0x03f4 [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass C:\Windows\System32\drivers\circlass.sys
11:56:11.0214 0x03f4 circlass - ok
11:56:11.0246 0x03f4 [ 7F006813C2AFE622C13D7AF94F56CD07, 9F4AEEE19B44F4117BE036F1475CE2E91ED740EB7D8D38364F9724517F777482 ] CLFS C:\Windows\system32\drivers\CLFS.sys
11:56:11.0254 0x03f4 CLFS - ok
11:56:11.0297 0x03f4 [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
11:56:11.0299 0x03f4 CmBatt - ok
11:56:11.0343 0x03f4 [ 825BE21E6395E00698D8A23955A87972, 303F10C3BA72ABB3BA27D08968B10E8EB03FFB6951943B0E9DD35CF48BB72578 ] CNG C:\Windows\system32\Drivers\cng.sys
11:56:11.0356 0x03f4 CNG - ok
11:56:11.0386 0x03f4 [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
11:56:11.0388 0x03f4 CompositeBus - ok
11:56:11.0392 0x03f4 COMSysApp - ok
11:56:11.0403 0x03f4 [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv C:\Windows\system32\drivers\condrv.sys
11:56:11.0406 0x03f4 condrv - ok
11:56:11.0502 0x03f4 [ 40EA16A9D4437A51491B93B72FAB71FF, F236B2BC7FE2B7150D60E94202D691E9B91D91D7EE779B59922398DF0217B380 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
11:56:11.0509 0x03f4 cphs - ok
11:56:11.0541 0x03f4 [ 0EFE4B5884A8032617826A4D76F80969, 083D296CC623C83D36A97AEE343ADF819B17E490F931DBE4D161BD1E8C289E02 ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:56:11.0545 0x03f4 CryptSvc - ok
11:56:11.0577 0x03f4 [ EE2F3C0D6ADBC975D6B621EC15ACF4E2, D158C0FACA6344BCD77616EC3D23212F9FD76D7D0C834ACA51998B80162106D5 ] CSC C:\Windows\system32\drivers\csc.sys
11:56:11.0590 0x03f4 CSC - ok
11:56:11.0622 0x03f4 [ 936D9E2871CEEFF6A33695D98374367B, C30D42E870F196C4FA20AF95C7B9D9C9C5414D6DDE71268F88C3FC5BF372E61B ] CscService C:\Windows\System32\cscsvc.dll
11:56:11.0635 0x03f4 CscService - ok
11:56:11.0657 0x03f4 [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam C:\Windows\system32\drivers\dam.sys
11:56:11.0660 0x03f4 dam - ok
11:56:11.0710 0x03f4 [ 3FD5AE42EC87C6F532A931F96BE731DD, 8282823022391ACF65E23F461FCE5CAFFB5ADC077647FEF80B91BC4BC31EDFE2 ] DcomLaunch C:\Windows\system32\rpcss.dll
11:56:11.0724 0x03f4 DcomLaunch - ok
11:56:11.0800 0x03f4 [ F4CCAADC2C78F57E4F16B24C9201CE22, B76A5C487A814CB986FE8CC398FB7493C9EAB9ACC933A3C35384FA447092EF00 ] defragsvc C:\Windows\System32\defragsvc.dll
11:56:11.0809 0x03f4 defragsvc - ok
11:56:11.0830 0x03f4 [ 0BC71D4D3B5883903C37BF4E13B0F0C5, C5EC2AD001FB7E72D3D12DBADFE01C308ACCB7426E0B90CCB3ECE2DE49D5E7D4 ] DeviceAssociationService C:\Windows\system32\das.dll
11:56:11.0837 0x03f4 DeviceAssociationService - ok
11:56:11.0875 0x03f4 [ 752A457320A946E03C3AA86C3ACD735E, 63946150581532D862F4220606E74FFC479209E1A36CD57AA78AC4AE34A26F49 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
11:56:11.0878 0x03f4 DeviceInstall - ok
11:56:11.0899 0x03f4 [ 5DB26D7E0216D0BF364A81D3829AD7B9, FD786D530EA9ADBCB48782FE091E926505A83F2BF3B4181A3D4EDFAA991C4E5E ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
11:56:11.0902 0x03f4 Dfsc - ok
11:56:11.0931 0x03f4 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
11:56:11.0934 0x03f4 dg_ssudbus - ok
11:56:11.0973 0x03f4 [ A40B5232D325AC0200E73329F7F19F54, EA420A5BDBDD60ADA05260904A96B5DED76EFF6F4B98D5FC904C83DCC66F797C ] Dhcp C:\Windows\system32\dhcpcore.dll
11:56:11.0979 0x03f4 Dhcp - ok
11:56:12.0017 0x03f4 [ 4D40C9B33F738797CF50E77CB7C53E85, 7BA341342A47DEB15B51971C97A5237ACD8BDAD9033F63DF0000892BE43F8E13 ] disk C:\Windows\system32\drivers\disk.sys
11:56:12.0020 0x03f4 disk - ok
11:56:12.0036 0x03f4 [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
11:56:12.0037 0x03f4 dmvsc - ok
11:56:12.0079 0x03f4 [ FBD2D7F491F3EBC5C54C5C4DB2564953, 1C053C28DB00ADF63BE317376395F5E32CBFD2C065A3756470BC54F44747965B ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:56:12.0084 0x03f4 Dnscache - ok
11:56:12.0100 0x03f4 [ 50288EA079BB520C2B8C8A154202D518, 8916A9180CA009D124FFDFB4CCF5FDFEF7FA2FD37CBCD49FAD4C68E051B4734D ] dot3svc C:\Windows\System32\dot3svc.dll
11:56:12.0107 0x03f4 dot3svc - ok
11:56:12.0127 0x03f4 [ 281BEE07BA97E3E98D12A822D923D0D8, 6EB482B2D4D6048D145C3738B2B6FA27A90B5EA53E9167447820F9981B004E63 ] DPS C:\Windows\system32\dps.dll
11:56:12.0131 0x03f4 DPS - ok
11:56:12.0149 0x03f4 [ DDC11A202207C0400CBE07315B8FDE5E, 3ED0CA3A714582D92001BA3BFF78BE082F4DC8021298D5A2632F3B2B0A1C09DC ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:56:12.0150 0x03f4 drmkaud - ok
11:56:12.0185 0x03f4 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8, B8223D73C3DE123759101F7D5D45C60BD12B221F09D349575A1044CE3F43CBC5 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
11:56:12.0189 0x03f4 DsmSvc - ok
11:56:12.0259 0x03f4 [ 5A5C2A5D961CADF49DDE26582B8ED1FA, B8CC8CB12F1BD8F4403E4751DB1399790377D191567B3C9E1EE107A22FEFAEB0 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:56:12.0291 0x03f4 DXGKrnl - ok
11:56:12.0356 0x03f4 [ FE96AA1A36E76588C80DF1040286DDE1, 86EED8A0B59CD1930E6282997537ED94333FC7D45E3FE5A4D82057E1C8E5C2CD ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
11:56:12.0362 0x03f4 eamonm - ok
11:56:12.0395 0x03f4 [ 6073537F250B45E1CB2A02E97F0FE1B2, 653F3F2F2019168EDF225944A88AFDBF8393B62AA076BD19980691778F3DB67D ] Eaphost C:\Windows\System32\eapsvc.dll
11:56:12.0398 0x03f4 Eaphost - ok
11:56:12.0517 0x03f4 [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv C:\Windows\system32\drivers\evbda.sys
11:56:12.0620 0x03f4 ebdrv - ok
11:56:12.0672 0x03f4 [ FD4BC52A6978A50A81B01E2C74D8737E, 5F12870CB83E7821F12A27E9BB30A80C58A7E81C36DA972194EBF333A5C90E62 ] edevmon C:\Windows\system32\DRIVERS\edevmon.sys
11:56:12.0678 0x03f4 edevmon - ok
11:56:12.0712 0x03f4 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] EFS C:\Windows\System32\lsass.exe
11:56:12.0714 0x03f4 EFS - ok
11:56:12.0766 0x03f4 [ 807BA90D47F8885C09E1D6AFBB706E18, A803FE639C9C87733CA73D8F6C04A8CEB28DC45EEEA6CEC01ED3D4124C8E48EA ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
11:56:12.0769 0x03f4 ehdrv - ok
11:56:12.0799 0x03f4 [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
11:56:12.0801 0x03f4 EhStorClass - ok
11:56:12.0832 0x03f4 [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
11:56:12.0836 0x03f4 EhStorTcgDrv - ok
11:56:12.0932 0x03f4 [ F1DB56A7C59278DC68DE7DBFE9F6C73B, B3E07DCF52D227BD4C22EDE5B895BC338A8F1EA4C86C1358EAC065454D80E76C ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
11:56:12.0954 0x03f4 ekrn - ok
11:56:12.0983 0x03f4 [ BE2902E13CA69383F449B6BF927844FB, F092785E305D8E1FE795AF98A7A7B7B4548A0D6687060568C9E078FFA8D65C1C ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
11:56:12.0985 0x03f4 ElbyCDIO - ok
11:56:13.0017 0x03f4 [ 00A81DC02BA17FB4BFCFA026DC47458F, 1B95BD51727E66B023BA4F2C9F57E69496790582CB272D57FE4BC15BA64952D8 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
11:56:13.0022 0x03f4 epfw - ok
11:56:13.0039 0x03f4 [ 3B085449438B2BCFD09CC84A0B90D1DB, 098DD64CC446E3960F93C0CDA495069DB6E7D9397CAC857E09E9FA323F5D31B2 ] EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys
11:56:13.0040 0x03f4 EpfwLWF - ok
11:56:13.0058 0x03f4 [ 91D54747A07F56ADCE1B6CFD3387AF60, 6F27AC896EA360284F6868BA1FEB55AE9325C914E54D73AECC5EBC8328650D41 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
11:56:13.0059 0x03f4 epfwwfp - ok
11:56:13.0076 0x03f4 [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev C:\Windows\System32\drivers\errdev.sys
11:56:13.0077 0x03f4 ErrDev - ok
11:56:13.0127 0x03f4 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3, 5264734F0572FAEDCCB008221C9982CCB7922C4FFC358605424EA413CDCDAE99 ] EventSystem C:\Windows\system32\es.dll
11:56:13.0139 0x03f4 EventSystem - ok
11:56:13.0176 0x03f4 [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat C:\Windows\system32\drivers\exfat.sys
11:56:13.0182 0x03f4 exfat - ok
11:56:13.0208 0x03f4 [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:56:13.0214 0x03f4 fastfat - ok
11:56:13.0255 0x03f4 [ 2BC8532ABF2B3756B78FA1DA54147DDE, DF65EE2AB0255A2CF3221085A6BE7C37E3DB6BFEED3BCADCDD69BB1049F6DCB1 ] Fax C:\Windows\system32\fxssvc.exe
11:56:13.0273 0x03f4 Fax - ok
11:56:13.0289 0x03f4 [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc C:\Windows\System32\drivers\fdc.sys
11:56:13.0291 0x03f4 fdc - ok
11:56:13.0316 0x03f4 [ DC1A78BCCCB7EE53D6FD3BD615A8E222, EE16B6853185AAE779D7135035983938009901658F76A8856AAC12EBA15BB34E ] fdPHost C:\Windows\system32\fdPHost.dll
11:56:13.0317 0x03f4 fdPHost - ok
11:56:13.0327 0x03f4 [ E5AD448F2DC84B1CF387FA7F2A3D1936, BBB29C79A085C503F5EFFB5144596D5DEC48A4EB34A049A4E7B38B27F6D92E0A ] FDResPub C:\Windows\system32\fdrespub.dll
11:56:13.0328 0x03f4 FDResPub - ok
11:56:13.0347 0x03f4 [ 0046E0BD031213D37123876B0D0FA61C, A4FE17D56F0BAFB70D0D421ED9D1B6E50AF8ADAA4B59328A41AEC5B4C068A3CB ] fhsvc C:\Windows\system32\fhsvc.dll
11:56:13.0351 0x03f4 fhsvc - ok
11:56:13.0378 0x03f4 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5, 85D1AC25CF8056FF303930A7E18DE5F7C3AEE429272CB791BD6F81F1DAFB7D8A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:56:13.0381 0x03f4 FileInfo - ok
11:56:13.0393 0x03f4 [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:56:13.0395 0x03f4 Filetrace - ok
11:56:13.0414 0x03f4 [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
11:56:13.0415 0x03f4 flpydisk - ok
11:56:13.0444 0x03f4 [ 60D5067FCE6D9433D35E04C01D8538B3, 2D97E9E8FF18CF564DE8E70F68B56F0177DC6C0E9EEB7E1C58BBDF42456CB0D8 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:56:13.0452 0x03f4 FltMgr - ok
11:56:13.0517 0x03f4 [ 183CA7699474FDE235853967D1DA4D9B, 8FBD5997F1E39AFFD8C4322520DF4D2227279B5149017D825C188D7411BA99AF ] FontCache C:\Windows\system32\FntCache.dll
11:56:13.0539 0x03f4 FontCache - ok
11:56:13.0656 0x03f4 [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:56:13.0658 0x03f4 FontCache3.0.0.0 - ok
11:56:13.0665 0x03f4 [ 35005534E600E993A90B036E4E599F2B, DA56FA3776FBD3D50276CB7410E0CB6F137DD8FCA84C0F3FEF8B1FEA5F6CA592 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:56:13.0668 0x03f4 FsDepends - ok
11:56:13.0682 0x03f4 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:56:13.0683 0x03f4 Fs_Rec - ok
11:56:13.0731 0x03f4 [ 818CF11786B2FA424E33A49E2CB79CC9, 2ABE9A4BA7E2AFD11CA69ACD0F292B29AD66A300B932FDF0D6084F1F63B4823B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:56:13.0743 0x03f4 fvevol - ok
11:56:13.0757 0x03f4 [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
11:56:13.0758 0x03f4 FxPPM - ok
11:56:13.0775 0x03f4 [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
11:56:13.0777 0x03f4 gagp30kx - ok
11:56:13.0805 0x03f4 [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
11:56:13.0806 0x03f4 gencounter - ok
11:56:13.0816 0x03f4 [ FDA72810CA2F8409D9B31E833C448E34, FC24350E875D2AF2A41DB5EF0BFE4F876DADEACCC0B34B9B9C9B2CA185CBAE87 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
11:56:13.0820 0x03f4 GPIOClx0101 - ok
11:56:13.0889 0x03f4 [ 0BDE0FCF597E9B65600121EF54FF8340, DA5C96E84E05AD09251C82B4BFEDE274342409803730CEBF24EEAD0DCD42DA7E ] gpsvc C:\Windows\System32\gpsvc.dll
11:56:13.0910 0x03f4 gpsvc - ok
11:56:13.0996 0x03f4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:13.0998 0x03f4 gupdate - ok
11:56:14.0003 0x03f4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:14.0005 0x03f4 gupdatem - ok
11:56:14.0036 0x03f4 [ 2FC9175526C26FF967B55C3590C0DDAF, 8DEB7E02E345DC987171C385623ECD95D3B71A58E9FF27B2BB48758119CD0E3D ] Hamachi C:\Windows\system32\DRIVERS\Hamdrv.sys
11:56:14.0037 0x03f4 Hamachi - ok
11:56:14.0079 0x03f4 [ 56F69F7C25FB67C970997D7066DBC593, 83E03A82237DCC5BCB3E722ACECACEF3510CAA619F33E0D7C4D902A482E90418 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:56:14.0091 0x03f4 HdAudAddService - ok
11:56:14.0118 0x03f4 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC, 42E631B23BB004F5C2128BAD334C21AB20FAD08AFED9E8191AE9373531BC73DD ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
11:56:14.0120 0x03f4 HDAudBus - ok
11:56:14.0134 0x03f4 [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
11:56:14.0136 0x03f4 HidBatt - ok
11:56:14.0144 0x03f4 [ 1EA1B4FABB8CC348E73CA90DBA22E104, 5C18C6BD499272F216DD4626B5E8D38181AEAC9AD917FBEB614A75B70467B258 ] HidBth C:\Windows\System32\drivers\hidbth.sys
11:56:14.0147 0x03f4 HidBth - ok
11:56:14.0166 0x03f4 [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
11:56:14.0168 0x03f4 hidi2c - ok
11:56:14.0179 0x03f4 [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr C:\Windows\System32\drivers\hidir.sys
11:56:14.0181 0x03f4 HidIr - ok
11:56:14.0207 0x03f4 [ 449A20A674AA3FAA7F0DD4E33EE2DC20, 28B9BDA306456E8640C355718DE3477537B0FAF8C37F633C709129AAB64D9873 ] hidserv C:\Windows\system32\hidserv.dll
11:56:14.0209 0x03f4 hidserv - ok
11:56:14.0222 0x03f4 [ F31397220D9687E11EB448649AA6E038, 671ACEAA8E00E0D4ED7E33D06A4558121DA4F56EB94F1CBC16FEB2EF3852F7A5 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
11:56:14.0224 0x03f4 HidUsb - ok
11:56:14.0244 0x03f4 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5, 5758A51FD2EBE67E6DBE3A298D714D351910F9E01C428D0C1359457C9242B298 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:56:14.0247 0x03f4 hkmsvc - ok
11:56:14.0272 0x03f4 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18, 46BF4A968E506DE17CA401401D716B444CDC10A5C60EB081890DD4B886AEDF5F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:56:14.0279 0x03f4 HomeGroupListener - ok
11:56:14.0321 0x03f4 [ BE5F89BAFBD4272D5A0C0A37B97865ED, 2F80CE6D123FEED9FA7B00ACF7547FF77E0E6FDC5243942E83BE308C46D414C6 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:56:14.0329 0x03f4 HomeGroupProvider - ok
11:56:14.0352 0x03f4 [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:56:14.0354 0x03f4 HpSAMD - ok
11:56:14.0396 0x03f4 [ 3502776E366C913D49C0DA928AE3E6CB, 3FB452F640B78AEDFBC09188F25C566949660163732A180331226A93DB08F26C ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:56:14.0412 0x03f4 HTTP - ok
11:56:14.0429 0x03f4 [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:56:14.0430 0x03f4 hwpolicy - ok
11:56:14.0448 0x03f4 [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
11:56:14.0450 0x03f4 hyperkbd - ok
11:56:14.0465 0x03f4 [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
11:56:14.0467 0x03f4 HyperVideo - ok
11:56:14.0507 0x03f4 [ 84CFC5EFA97D0C965EDE1D56F116A541, 0155EA62BF07D99D98D1C9B6559C8E3301B016A20D03DF1EF64B2FAB8C37403B ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
11:56:14.0510 0x03f4 i8042prt - ok
11:56:14.0526 0x03f4 [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO C:\Windows\System32\drivers\iaLPSSi_GPIO.sys
11:56:14.0527 0x03f4 iaLPSSi_GPIO - ok
11:56:14.0541 0x03f4 [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C C:\Windows\System32\drivers\iaLPSSi_I2C.sys
11:56:14.0544 0x03f4 iaLPSSi_I2C - ok
11:56:14.0591 0x03f4 [ 0FE66A51D81A25AACEAAE4C26308121D, C5553F7ABA74A8EB71A4ED0E8F2A6AA2892F871D164F2D4FADB035BE7D1A8C44 ] iaStorA C:\Windows\system32\drivers\iaStorA.sys
11:56:14.0601 0x03f4 iaStorA - ok
11:56:14.0651 0x03f4 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV C:\Windows\system32\drivers\iaStorAV.sys
11:56:14.0665 0x03f4 iaStorAV - ok
11:56:14.0745 0x03f4 [ 584068E03829BC5C63F54B05E6244E97, C075E8A4853C0DE09A9BF846338F9C8997FE7ACD604B4EC02AA89F0DAA1D985B ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
11:56:14.0746 0x03f4 IAStorDataMgrSvc - ok
11:56:14.0772 0x03f4 [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:56:14.0782 0x03f4 iaStorV - ok
11:56:14.0817 0x03f4 [ 83FF82FE209E7997067B375DAD6CF23D, E312DD068E51DBF96A8232D7D1C9F158652FDA23649655F1102928B320795091 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
11:56:14.0820 0x03f4 ICCS - ok
11:56:14.0823 0x03f4 IEEtwCollectorService - ok
11:56:15.0005 0x03f4 [ 0143C860F0D09B8465AE803FDDB47BE9, C11B079AC7338981BA844BF62B96FDC4FD83018E9F67CCA9ADE426978FCF2562 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
11:56:15.0164 0x03f4 igfx - ok
11:56:15.0228 0x03f4 [ F568467CD984714E1B849CA170358EC0, B6E3B62B174CE74D371CF5F2BBD4BB10C370945F1F4A56C483FD870B7A28AF34 ] IKEEXT C:\Windows\System32\ikeext.dll
11:56:15.0246 0x03f4 IKEEXT - ok
11:56:15.0452 0x03f4 [ FA2B7507CD49908B2260949E52F8B9FE, 0EA0B3B25A3B668CA18313E34138DADA5C9835E476A1BFC56588B946DF0A92E0 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:56:15.0564 0x03f4 IntcAzAudAddService - ok
11:56:15.0608 0x03f4 [ F5495B38BFB9149925F54F65AB40EFBF, 7CBB72C41E2343DACBFB967A39CA04788561EDECB289C41BC2D6A06B80882AC4 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
11:56:15.0615 0x03f4 IntcDAud - ok
11:56:15.0639 0x03f4 [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide C:\Windows\system32\drivers\intelide.sys
11:56:15.0640 0x03f4 intelide - ok
11:56:15.0663 0x03f4 [ 647CF2AB16D2A23F1C441A313BC39820, 7C8657F2171DDC7785BB167045100EC69C4C4E643AFFE1491A85797D297C9AF2 ] intelpep C:\Windows\system32\drivers\intelpep.sys
11:56:15.0663 0x03f4 intelpep - ok
11:56:15.0680 0x03f4 [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm C:\Windows\System32\drivers\intelppm.sys
11:56:15.0683 0x03f4 intelppm - ok
11:56:15.0700 0x03f4 [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:56:15.0703 0x03f4 IpFilterDriver - ok
11:56:15.0748 0x03f4 [ 201EDF3C5E674BF1FE44D28CC6A76EA2, 33DEA0C6DE9AE915C62794FBBA2625364E68AC5385C4B5FFDE889D90DA54C1AE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:56:15.0764 0x03f4 iphlpsvc - ok
11:56:15.0797 0x03f4 [ 9949A3C7590B8C536C05312205079A82, 9276A09D5F910AE8358A96505AB3F66C514870944D58B63B71D5E96567D1E6BB ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
11:56:15.0799 0x03f4 IPMIDRV - ok
11:56:15.0820 0x03f4 [ 0063040EFD7C5B81D67CF985BA35388A, 0AED6B7129F4E9CE8C309982EA46B24A3A67AA774CF573B449DB96062AC7DD67 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:56:15.0824 0x03f4 IPNAT - ok
11:56:15.0839 0x03f4 [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:56:15.0841 0x03f4 IRENUM - ok
11:56:15.0859 0x03f4 [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:56:15.0861 0x03f4 isapnp - ok
11:56:15.0891 0x03f4 [ 034D4BD9DC67C64F3A4C8A049B5173BF, C68AF5A5AD4092AA1C871BD38473AEF84EC3ECF4D06FBEB5F6C09972EF1B8A81 ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
11:56:15.0899 0x03f4 iScsiPrt - ok
11:56:15.0933 0x03f4 [ 45369E037410609D769852A1CE46A184, 752BE7BB167E602CD89D52E3A4382AF7C75033306E31884EC55872EF7A0A3EE2 ] k57nd60a C:\Windows\system32\DRIVERS\k57nd60a.sys
11:56:15.0941 0x03f4 k57nd60a - ok
11:56:15.0955 0x03f4 [ 8BE92376799B6B44D543E8D07CDCF885, 425B8BB1BAF62F735B3CB5A002E6055879F02E7207E55942BFD37F1784F5F368 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
11:56:15.0957 0x03f4 kbdclass - ok
11:56:15.0967 0x03f4 [ FB6E47E569D4872ABEB506BE03A45FBA, 5C4056CADA8F67587A119D9AE2A0EFAB30387CF6298F4019FF68AC92E2F6F54B ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
11:56:15.0969 0x03f4 kbdhid - ok
11:56:15.0983 0x03f4 [ DB7A09BC90DF20F44F16F8B0F9ED3491, 2DF5E042284D61368A5801B2557351B2C4B1044AA6F966DF4DDCE7B453D1B9AE ] kbldfltr C:\Windows\system32\drivers\kbldfltr.sys
11:56:15.0985 0x03f4 kbldfltr - ok
11:56:15.0997 0x03f4 [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
11:56:15.0998 0x03f4 kdnic - ok
11:56:16.0012 0x03f4 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] KeyIso C:\Windows\system32\lsass.exe
11:56:16.0014 0x03f4 KeyIso - ok
11:56:16.0038 0x03f4 [ 0AD1DF5AF3E1AEE66583F9718E892B50, E0CA8C029B8206F5F35D1ED636D0F54D10D199547A3F3D25BF2BD2E36A342DC9 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:56:16.0040 0x03f4 KSecDD - ok
11:56:16.0057 0x03f4 [ 7296EA420134EAC390798B3232D066A4, 1F5D51EEFD389706660DFB4DB4BF3EC570BEC7097CEB5CAE70EFFE35C3255346 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:56:16.0061 0x03f4 KSecPkg - ok
11:56:16.0079 0x03f4 [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
11:56:16.0080 0x03f4 ksthunk - ok
11:56:16.0110 0x03f4 [ 32B1A8351160F307A8C66BCB0F94A9C2, 52F1DEC2BBD4D5DDBB85ED20B99D96BBA7EB83304D76F183A11FDAFDA364E873 ] KtmRm C:\Windows\system32\msdtckrm.dll
11:56:16.0119 0x03f4 KtmRm - ok
11:56:16.0153 0x03f4 [ 27B58E16CF895AC1F1A97C04814C2239, D4336155331DDBF91952CDC6C446C68FF524F979099BA8D9B3A578758F97B2BE ] LanmanServer C:\Windows\system32\srvsvc.dll
11:56:16.0160 0x03f4 LanmanServer - ok
11:56:16.0193 0x03f4 [ D0D9C2ECA4D03A8F06DCD91236B90C98, E2D1144DC8040EA5FEB0602A20BA4CB920B4BC86AD5AD05FC0DF7D74DC95DC66 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:56:16.0198 0x03f4 LanmanWorkstation - ok
11:56:16.0236 0x03f4 [ 48C163706383C7319DC1F8E9D135D68E, 141368BC2DD6D712C2FCFE8219EFF56698A27815AD7C20001B06240BDB899357 ] lfsvc C:\Windows\System32\GeofenceMonitorService.dll
11:56:16.0246 0x03f4 lfsvc - ok
11:56:16.0274 0x03f4 [ BE166935083F9C38EDFDC21B9A7A679B, 89C64DBE58E1B974208AAAA5CC757C599B1439C205C3C48BF16BA054A06DBC94 ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
11:56:16.0275 0x03f4 LHDmgr - ok
11:56:16.0286 0x03f4 [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:56:16.0288 0x03f4 lltdio - ok
11:56:16.0316 0x03f4 [ 00E070FC0C673311AFD4B068D1242780, 50B0E0E625361145332C849709498FF444E46578DCAD2536E6D0289E0125580F ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:56:16.0323 0x03f4 lltdsvc - ok
11:56:16.0335 0x03f4 [ D113FAD71A5E67AA94B32A0F8828D265, 08DDB4BBDB570C59926DBF5E27FCF46DCDF8B8212BB9251E97837E0504516FB3 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:56:16.0337 0x03f4 lmhosts - ok
11:56:16.0371 0x03f4 [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
11:56:16.0374 0x03f4 LSI_SAS - ok
11:56:16.0388 0x03f4 [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
11:56:16.0391 0x03f4 LSI_SAS2 - ok
11:56:16.0407 0x03f4 [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3 C:\Windows\system32\drivers\lsi_sas3.sys
11:56:16.0409 0x03f4 LSI_SAS3 - ok
11:56:16.0432 0x03f4 [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
11:56:16.0434 0x03f4 LSI_SSS - ok
11:56:16.0484 0x03f4 [ B6B69FF200F68888A7FAFDF204D00C91, 4C9BA7B8646C74AE1E49F513EF426930C09969F29F1533D84D020B414BB1609B ] LSM C:\Windows\System32\lsm.dll
11:56:16.0497 0x03f4 LSM - ok
11:56:16.0527 0x03f4 [ 5EF604B0698F4FA962778285E8C5F1F2, 0465BDAB7EFBE9CC648E7E736B0B8BE152BD2FAB0917F6306675B9039C77F454 ] luafv C:\Windows\system32\drivers\luafv.sys
11:56:16.0530 0x03f4 luafv - ok
11:56:16.0568 0x03f4 [ F92B0E478C0FAA6D6661E6E977247E60, 8B26B57C2C60C98CD6273ACA126B2CD0356ADB13A59FEC12882357A6B973123C ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
11:56:16.0570 0x03f4 MBAMProtector - ok
11:56:16.0636 0x03f4 [ D84AEA3F3329D622DFC1297DDDF6163B, 316FE56CC30ED1473A917253F46B79EAA12F4ABD5B4B1ADB03929DFEE940F577 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
11:56:16.0664 0x03f4 MBAMScheduler - ok
11:56:16.0713 0x03f4 [ 4F45ED469906494F9BF754E476390DBD, D8FF6AFD73D8C191F5732DF9737E6F83B2B52B06A3A6CD4CC6EAC9464CBB2772 ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
11:56:16.0727 0x03f4 MBAMService - ok
11:56:16.0759 0x03f4 [ 8A50D5304E6AE48664CF5838EC32F647, C76943FABEE1B5E1B641AA610668CCD4227E2C4B191DD30B79D3AB31A9E8B5BE ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
11:56:16.0761 0x03f4 MBAMSwissArmy - ok
11:56:16.0794 0x03f4 [ 0664F6335F108F38FE08C3CA747311EE, 04C5F31C57573DC4ABFC609D3F7C589835CE5C528AF5EE07FB25E35F72DF98A4 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
11:56:16.0795 0x03f4 MBAMWebAccessControl - ok
11:56:16.0805 0x03f4 [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas C:\Windows\system32\drivers\megasas.sys
11:56:16.0807 0x03f4 megasas - ok
11:56:16.0841 0x03f4 [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr C:\Windows\system32\drivers\megasr.sys
11:56:16.0853 0x03f4 megasr - ok
11:56:16.0878 0x03f4 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
11:56:16.0881 0x03f4 MEIx64 - ok
11:56:16.0907 0x03f4 [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] MMCSS C:\Windows\system32\mmcss.dll
11:56:16.0910 0x03f4 MMCSS - ok
11:56:16.0921 0x03f4 [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem C:\Windows\system32\drivers\modem.sys
11:56:16.0923 0x03f4 Modem - ok
11:56:16.0941 0x03f4 [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor C:\Windows\System32\drivers\monitor.sys
11:56:16.0942 0x03f4 monitor - ok
11:56:16.0951 0x03f4 [ CEAC6D40FE887CE8406C2393CF97DE06, 34E76908B802764FF0D7AB3AF89BE77BD35B44787983343FAD89891891C0A045 ] mouclass C:\Windows\System32\drivers\mouclass.sys
11:56:16.0953 0x03f4 mouclass - ok
11:56:16.0960 0x03f4 [ 02D98BF804084E9A0D69D1C69B02CCA9, EC5BC5D87043DFFD035FD4DD27B3D94E03119063519E4151BCC3522B613E2D7F ] mouhid C:\Windows\System32\drivers\mouhid.sys
11:56:16.0962 0x03f4 mouhid - ok
11:56:16.0983 0x03f4 [ 515549560D481138E6E21AF7C6998E56, C7E4B38D8CCAF15B9BDA63C8C8209F6193AD220DA02E1264F1B687AACD8F409F ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:56:16.0986 0x03f4 mountmgr - ok
11:56:17.0013 0x03f4 [ F170510BE94CF45E3C6274578F6204B2, 344C3DDE1D622607CA2ABECB2C47CB0166D2D258BD94A7960C45A5ADBB640566 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:56:17.0015 0x03f4 mpsdrv - ok
11:56:17.0065 0x03f4 [ D186C5844393252147BE934F3871DB7A, 30160F8268B9F46E82C5CB536867E0CF280DC98074A481595072E3320200E343 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:56:17.0080 0x03f4 MpsSvc - ok
11:56:17.0115 0x03f4 [ 59DCEC7499095DE5AED741358037AE2D, 60C4CEBCAE27C121E9D63BD2BC3E5863A91ABC77616C56C10618273A8F9B6F61 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:56:17.0119 0x03f4 MRxDAV - ok
11:56:17.0161 0x03f4 [ 405A2E5754DF76663CF0522B87D7929F, E1EB0F315278387C6107AEC5FBBFEF8F18CB8EDCAC5D865F75928A7226A0CC6F ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:56:17.0168 0x03f4 mrxsmb - ok
11:56:17.0191 0x03f4 [ 295771B092D4F7FCF2B62F80CCD14320, 53655B5ABA43A6A9114FE545B88F84E52319B905B8393A51BD97678D3F94A178 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:56:17.0199 0x03f4 mrxsmb10 - ok
11:56:17.0223 0x03f4 [ FFC548EABBB8271E979B0EEE0EA4D55B, B0A62CAF32C9C1FC46871532072915534D65C51A3F58E933D44D99BDB3827ABF ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:56:17.0228 0x03f4 mrxsmb20 - ok
11:56:17.0261 0x03f4 [ 4E888019078AC363076A5433E89AA4F8, 3DEBDA290230B3E83F956C902C960E39463B7EFE86439199521356762769FD91 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
11:56:17.0264 0x03f4 MsBridge - ok
11:56:17.0296 0x03f4 [ A082C17D14D0790E27D064EA4B138AE1, 9A565ED885782D9D5135C8399C11C356DBF9EBF3B8EB4B4504BD2604AD0B45E6 ] MSDTC C:\Windows\System32\msdtc.exe
11:56:17.0300 0x03f4 MSDTC - ok
11:56:17.0313 0x03f4 [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:56:17.0315 0x03f4 Msfs - ok
11:56:17.0327 0x03f4 [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
11:56:17.0329 0x03f4 msgpiowin32 - ok
11:56:17.0340 0x03f4 [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:56:17.0341 0x03f4 mshidkmdf - ok
11:56:17.0368 0x03f4 [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
11:56:17.0369 0x03f4 mshidumdf - ok
11:56:17.0381 0x03f4 [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:56:17.0382 0x03f4 msisadrv - ok
11:56:17.0406 0x03f4 [ 810F8A0A0680662BB0CE44D0E2CEF90C, 5631B07911B7EF378CB1583A480A3C5715E59A5488B33A528F4D7A2F849B9113 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:56:17.0410 0x03f4 MSiSCSI - ok
11:56:17.0413 0x03f4 msiserver - ok
11:56:17.0424 0x03f4 [ D22AE5313F6B7EFDDD8C117B5501F4A3, 1937EEE33BF9C4485F172B10FB17AEF3F3B8978371307F49C3338D74D96A8389 ] MsKeyboardFilter C:\Windows\System32\KeyboardFilterSvc.dll
11:56:17.0427 0x03f4 MsKeyboardFilter - ok
11:56:17.0442 0x03f4 [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:56:17.0443 0x03f4 MSKSSRV - ok
11:56:17.0465 0x03f4 [ 375E44168F2DFB91A68B8A3F619C5A7C, AC243E02E9A39D0B4DE9571F196941700EE6EB5E94F5B0BA8994FB551E73A7A8 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
11:56:17.0467 0x03f4 MsLldp - ok
11:56:17.0485 0x03f4 [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:56:17.0486 0x03f4 MSPCLOCK - ok
11:56:17.0496 0x03f4 [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:56:17.0497 0x03f4 MSPQM - ok
11:56:17.0535 0x03f4 [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:56:17.0543 0x03f4 MsRPC - ok
11:56:17.0564 0x03f4 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
11:56:17.0565 0x03f4 mssmbios - ok
11:56:17.0575 0x03f4 [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:56:17.0576 0x03f4 MSTEE - ok
11:56:17.0589 0x03f4 [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
11:56:17.0591 0x03f4 MTConfig - ok
11:56:17.0616 0x03f4 [ 619CA29326B82372621DB2C0964D8365, 4091F08E266DB45A6E33A4A8B1CE9FA78BB294B3111526AA9E3868620F30AFDF ] Mup C:\Windows\system32\Drivers\mup.sys
11:56:17.0619 0x03f4 Mup - ok
11:56:17.0638 0x03f4 [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis C:\Windows\system32\drivers\mvumis.sys
11:56:17.0640 0x03f4 mvumis - ok
11:56:17.0672 0x03f4 [ 41A45D2A75494EABF2806EA051E00376, EB2497561C8E33A4297C044604C717FF854C7F046882A9E4A400AE7679BF5467 ] napagent C:\Windows\system32\qagentRT.dll
11:56:17.0680 0x03f4 napagent - ok
11:56:17.0725 0x03f4 [ 869055F61568AA08E7DEE95EC82ED653, 52CDF4175824A748F6BE09A2922A24708F3AEA899220168B23364A70DBAFE818 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:56:17.0735 0x03f4 NativeWifiP - ok
11:56:17.0772 0x03f4 [ 71E3C0100AA19D11373CCEB2F51A6008, 58FBF35F5FE19BEABE483C11E9996BE93D76721C8C34465350FA98B465CA3672 ] NcaSvc C:\Windows\System32\ncasvc.dll
11:56:17.0777 0x03f4 NcaSvc - ok
11:56:17.0797 0x03f4 [ 51DF09CAB2CAC64FEE3E371D9028ED01, 9B81604D0D0359AF8F54FED6DA7116FFD2F40407895028EAD99FF1D7CFDC2D14 ] NcbService C:\Windows\System32\ncbservice.dll
11:56:17.0801 0x03f4 NcbService - ok
11:56:17.0817 0x03f4 [ 2586C4C167499210DCBF3ECFD8CCE210, D8129FEDE9918BF4FB0057CC58700D4E08457060E810B9CC25CA0F598506ADB8 ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
11:56:17.0820 0x03f4 NcdAutoSetup - ok
11:56:17.0876 0x03f4 [ 424B0796F85BB0DADD4438EAFFADA133, 664D064849C123210057A400C3FB64A6A2D1DF7E6B34DE3D189D2FE2A6CD9D9B ] NDIS C:\Windows\system32\drivers\ndis.sys
11:56:17.0895 0x03f4 NDIS - ok
11:56:17.0917 0x03f4 [ C6BB12BC35D1637CA17AE16D3A4725EB, 01C1D9FA738886A195166F88207EEB6715A1DE0608978ED6C5DC738AF5C02513 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:56:17.0918 0x03f4 NdisCap - ok
11:56:17.0935 0x03f4 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37, CCD99962917BBE256F64AE14CCC9FD12433C72B5DB98E0E57CA8F212A11B3C8F ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
11:56:17.0938 0x03f4 NdisImPlatform - ok
11:56:17.0977 0x03f4 [ 9423421E735BD5394351E0C47C76BB92, 763E5D06F896C0EF8AD52515464F28BA85DB7A1560E451857AC9AA68FAFCBC66 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:56:17.0978 0x03f4 NdisTapi - ok
11:56:17.0988 0x03f4 [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:56:17.0990 0x03f4 Ndisuio - ok
11:56:18.0005 0x03f4 [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys
11:56:18.0006 0x03f4 NdisVirtualBus - ok
11:56:18.0041 0x03f4 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:56:18.0046 0x03f4 NdisWan - ok
11:56:18.0053 0x03f4 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWanLegacy C:\Windows\system32\DRIVERS\ndiswan.sys
11:56:18.0057 0x03f4 NdisWanLegacy - ok
11:56:18.0069 0x03f4 [ A5BD69A8812FA79D1A487691DD3FB244, 67B5EDE101943E0E8B8041DB2353D20C8B9F2D253E77964761CFE8F136C0BBC7 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:56:18.0072 0x03f4 NDProxy - ok
11:56:18.0086 0x03f4 [ 5A072F0B90C29C5233D78BE33EF5ED78, B32ED76A674B1FC743361FB7BBD4C915A78B14132AB056AADD445D5995AD4F32 ] Ndu C:\Windows\system32\drivers\Ndu.sys
11:56:18.0089 0x03f4 Ndu - ok
11:56:18.0106 0x03f4 [ A83D67D347A684F10B7D3019C8A6380C, 2B86832967981C8C786BF24C1CF8E13E01745ACE3333CF5C821DD93D623B96E4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:56:18.0108 0x03f4 NetBIOS - ok
11:56:18.0126 0x03f4 [ 0217532E19A748F0E5D569307363D5FD, C40C2E7AFA276057E7327A7BB173122689D6CEC9AE443C3850C3F94AF03DFBF5 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:56:18.0133 0x03f4 NetBT - ok
11:56:18.0146 0x03f4 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] Netlogon C:\Windows\system32\lsass.exe
11:56:18.0148 0x03f4 Netlogon - ok
11:56:18.0179 0x03f4 [ B7AD851A21FEBA3BA214972627614207, 29605320CCC3DAAD062CAECF0009DACBC2F6D28ED4E8AF7CE76132129F5572A0 ] Netman C:\Windows\System32\netman.dll
11:56:18.0184 0x03f4 Netman - ok
11:56:18.0211 0x03f4 [ F0F0A372C2EF6358399C4936F91B6131, CE596C71EB4D1A5E104D3148F2D0D8789882C59FD198DCF33CCAC7A08B50E4EE ] netprofm C:\Windows\System32\netprofmsvc.dll
11:56:18.0220 0x03f4 netprofm - ok
11:56:18.0267 0x03f4 [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:18.0270 0x03f4 NetTcpPortSharing - ok
11:56:18.0305 0x03f4 [ 70414DB660BFBB7BD58FCE8EA4364E1B, 6DFB3897CD55E22BA1EDF0AE672F4D7A6A1F512F8A0A26AF106765E6B1CF65AC ] netvsc C:\Windows\system32\DRIVERS\netvsc63.sys
11:56:18.0308 0x03f4 netvsc - ok
11:56:18.0632 0x03f4 [ 272BB8C52BE106B5CC69171AF1D281D4, 3D65A772C15440DF5895843185241D890CCDECA0E02DD6CF32CCB9B5849E31A4 ] NETwNs64 C:\Windows\system32\DRIVERS\Netwsw00.sys
11:56:18.0936 0x03f4 NETwNs64 - ok
11:56:18.0994 0x03f4 [ 3A280F3B3C7A46E29C404ACD46ECBF5E, 81C3367A2A212DBCC65B8A0166FD092E3205AB31A146B4B737061335CEC51F9D ] NlaSvc C:\Windows\System32\nlasvc.dll
11:56:19.0002 0x03f4 NlaSvc - ok
11:56:19.0023 0x03f4 [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:56:19.0025 0x03f4 Npfs - ok
11:56:19.0042 0x03f4 [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
11:56:19.0044 0x03f4 npsvctrig - ok
11:56:19.0087 0x03f4 [ 6E2271ED0C3E95B8E29F3752B91B9E84, 44026AD9757EA82967D7F7578455802FAD7FE0057EAC088E0AE207C15F594B86 ] nsi C:\Windows\system32\nsisvc.dll
11:56:19.0089 0x03f4 nsi - ok
11:56:19.0099 0x03f4 [ E490B459978CB87779E84C761D22B827, 1E5CA38626E41618E4CA16DD0C70EB2FA86E986F0CF21A749BDE2A17015DEEC6 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:56:19.0100 0x03f4 nsiproxy - ok
11:56:19.0183 0x03f4 [ 4412D565C0278C401575E11072C7DCE3, 82A0E9AA88750900EA0E9983157345456B418745C8BA62FAF339640E759C0418 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:56:19.0225 0x03f4 Ntfs - ok
11:56:19.0249 0x03f4 [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null C:\Windows\system32\drivers\Null.sys
11:56:19.0250 0x03f4 Null - ok
11:56:19.0606 0x03f4 [ 757ACE4D4C9FF0571F86AA5D586B45E8, E7F23CC1DE26E2DAA690B78B05FC001EE0051F0ED9B9BCE9E7FA4E9684D4F3D4 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
11:56:19.0941 0x03f4 nvlddmkm - ok
11:56:20.0052 0x03f4 [ 048C6FACA905A7DF0A86D3CC31D7E6AE, 7222B301DBBDFF15B038E13FEA076759D8AC392F5145ECD60A640BDA6CFABE8C ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
11:56:20.0077 0x03f4 NvNetworkService - ok
11:56:20.0093 0x03f4 [ 445422B928D2FE322BB6B956EA77DC7B, 101D940D323BE6086FE0743B34C8717C573B07566334843E571CE6365BEE16D4 ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
11:56:20.0094 0x03f4 nvpciflt - ok
11:56:20.0116 0x03f4 [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:56:20.0120 0x03f4 nvraid - ok
11:56:20.0146 0x03f4 [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:56:20.0150 0x03f4 nvstor - ok
11:56:20.0216 0x03f4 [ 3ABCD8F8853FEB12B961E9A48FC12133, 58255D53E810EE0D89FA2F1DC9D6208BF44F3C0FDE74A9264FB740024F1EDD44 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
11:56:20.0217 0x03f4 NvStreamKms - ok
11:56:20.0220 0x03f4 NvStreamSvc - ok
11:56:20.0279 0x03f4 [ 1C7CC708AC4A02A3BE8915539780534A, 0EBDE100880963BF1EC05002BA244CA7700693E958D1974CDD2AC3927D93224F ] nvsvc C:\Windows\system32\nvvsvc.exe
11:56:20.0294 0x03f4 nvsvc - ok
11:56:20.0317 0x03f4 [ 75034A4D7C02327D150B617571D4196A, 8E7DAFEC4307E883D52BD0B5F0732E26E019C953770B52ACBBAD3074A66393CB ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
11:56:20.0318 0x03f4 nvvad_WaveExtensible - ok
11:56:20.0333 0x03f4 [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:56:20.0337 0x03f4 nv_agp - ok
11:56:20.0384 0x03f4 [ 4965B005492CBA7719E82B71E3245495, 52AD72C05FACC1E0E416A1FA25F34FDD3CB274FAB973BEAAE911A2FACA42B650 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:56:20.0396 0x03f4 ose64 - ok
11:56:20.0576 0x03f4 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:56:20.0653 0x03f4 osppsvc - ok
11:56:20.0699 0x03f4 [ 3B510F20806B94E389784ED09DBD2111, EF8896C500B3AA3A811FDE97BC322EF3295E9BD0DE236715D4A4C52CF63727E1 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:56:20.0708 0x03f4 p2pimsvc - ok
NTB : Lenovo Y570
Intel Core i5-2450M (Sandy Bridge, 2.5GHz, TB až 3.2GHz)
Nvidia GeForce GT555M 2GB
HDD: 750GB / SSD 32GB
RAM : 8GB 1333 MHZ
Windows 7 Ultimate 64-bit OEM :(


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 118 hostů