Policejní vir?? Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Policejní vir??

Příspěvekod jaro3 » 10 úno 2015 00:15

Odinstaluj:
IObit (Advanced SystemCare 7 , IObit Uninstaller)

V logu nejsou ovladače a služby...

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\program files\ESET
c:\program files\Google\Update

DirLook::
c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 09:09

Omlouvám se, ale mám problém s tou rezidentní ochranou. Ani nevím, jestli mám antispyware nebo je součástí Aviry? A v Aviře jsem našla jedinou volbu k vypnutí jako Real-Time protection..Je to jednoduše ono? Díky

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Policejní vir??

Příspěvekod jaro3 » 10 úno 2015 09:24

Jo , to je ono.

antispyware je součástí Aviry.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 10:05

Tenhle restart byl naštěstí hladký. Řekněte prosím kdy mám ty antiviry a firewall zas zapnout..
Tady je log z combofixu a jdu na aswMBR

ComboFix 15-02-09.01 - Eva 10.02.2015 9:38.6.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.2814.1883 [GMT 1:00]
Spuštěný z: c:\users\Eva\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Eva\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ESET
c:\program files\Google\Update
c:\program files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdate.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdateComRegisterShell64.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.26.9\GoogleUpdateWebPlugin.exe
c:\program files\Google\Update\1.3.26.9\goopdate.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_am.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ar.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_bg.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_bn.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ca.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_cs.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_da.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_de.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_el.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_en.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_es.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_et.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_fa.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_fi.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_fil.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_fr.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_gu.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_hi.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_hr.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_hu.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_id.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_is.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_it.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_iw.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ja.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_kn.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ko.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_lt.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_lv.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ml.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_mr.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ms.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_nl.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_no.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_pl.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ro.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ru.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_sk.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_sl.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_sr.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_sv.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_sw.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ta.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_te.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_th.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_tr.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_uk.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_ur.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_vi.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.26.9\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.26.9\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.26.9\psmachine.dll
c:\program files\Google\Update\1.3.26.9\psmachine_64.dll
c:\program files\Google\Update\1.3.26.9\psuser.dll
c:\program files\Google\Update\1.3.26.9\psuser_64.dll
c:\program files\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\1.19.8406.6504\gsync.msi
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.26.9\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\40.0.2214.111\40.0.2214.111_40.0.2214.94_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Google\Update\Install\{1EE9DCC1-978C-43D8-A0E0-46A707D29AA0}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Install\{FDB77991-5179-4736-B460-68B55450BEA2}\40.0.2214.111_40.0.2214.94_chrome_updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate1ca8fd0faa33550
-------\Service_gupdatem
-------\Service_gupdate1ca8fd0faa33550
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-01-10 do 2015-02-10 )))))))))))))))))))))))))))))))
.
.
2015-02-10 08:51 . 2015-02-10 08:56 -------- d-----w- c:\users\Eva\AppData\Local\temp
2015-02-10 08:51 . 2015-02-10 08:51 -------- d-----w- c:\users\Public\AppData\Local\temp
2015-02-10 08:51 . 2015-02-10 08:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-09 21:47 . 2013-06-27 17:05 24384 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2015-02-09 21:06 . 2015-02-09 22:31 -------- d-----w- c:\programdata\ProductData
2015-02-09 21:06 . 2015-02-09 21:06 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2015-02-09 21:06 . 2015-02-09 22:31 -------- d-----w- c:\programdata\IObit
2015-02-09 21:06 . 2015-02-10 08:52 -------- d-----w- c:\program files\IObit
2015-02-09 21:05 . 2015-02-09 21:06 -------- d-----w- c:\users\Eva\AppData\Roaming\IObit
2015-02-09 19:30 . 2015-02-09 18:57 24064 ----a-w- c:\windows\zoek-delete.exe
2015-02-09 13:13 . 2015-02-09 13:13 -------- d-----w- c:\users\Eva\AppData\Local\Adobe
2015-02-03 11:37 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2015-02-03 11:37 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2015-02-03 11:37 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2015-02-03 11:37 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2015-02-03 11:36 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2015-02-03 11:36 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2015-02-03 11:36 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2015-02-03 11:36 . 2012-06-02 14:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2015-02-03 11:36 . 2012-06-02 14:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-02-02 18:12 . 2015-02-02 18:14 -------- d-----w- c:\windows\system32\ca-ES
2015-02-02 18:12 . 2015-02-02 18:14 -------- d-----w- c:\windows\system32\eu-ES
2015-02-02 18:12 . 2015-02-02 18:14 -------- d-----w- c:\windows\system32\vi-VN
2015-02-02 17:58 . 2015-02-02 17:58 -------- d-----w- c:\windows\system32\SPReview
2015-02-02 17:27 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2015-02-02 17:27 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2015-02-02 17:18 . 2009-04-10 22:28 69632 ----a-w- c:\windows\system32\sendmail.dll
2015-02-01 13:32 . 2015-02-01 13:32 -------- d-----w- C:\_OTL
2015-01-31 19:36 . 2015-01-31 19:36 -------- d-----w- c:\program files\Common Files\Java(2)
2015-01-31 19:33 . 2015-01-31 19:33 -------- d-----w- c:\programdata\Oracle
2015-01-31 19:13 . 2015-01-31 19:13 -------- d-----w- c:\program files\WhoCrashed
2015-01-31 16:46 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{397D3B12-F14F-427C-9152-2B2D9FE6ED5B}\mpengine.dll
2015-01-31 15:27 . 2015-02-09 19:27 -------- d-----w- C:\zoek_backup
2015-01-31 14:29 . 2015-02-09 18:24 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-01-31 14:29 . 2015-01-31 14:29 -------- d-----w- c:\programdata\RogueKiller
2015-01-31 13:28 . 2015-02-10 08:15 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-01-31 13:28 . 2014-11-21 05:14 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-01-31 13:28 . 2014-11-21 05:14 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-01-31 13:27 . 2015-01-31 13:28 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-01-21 12:15 . 2015-01-21 12:15 -------- d-----w- c:\users\Eva\AppData\Roaming\IsolatedStorage
2015-01-21 12:15 . 2015-01-21 12:15 -------- d-----w- c:\programdata\IsolatedStorage
2015-01-20 12:02 . 2015-01-20 12:13 -------- d-----w- C:\f6892f605d5bc72d80a4730675a1f3
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-31 13:59 . 2012-06-08 13:08 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-01-31 13:59 . 2011-11-23 18:17 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-12-22 23:50 . 2009-10-05 12:15 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-11-21 05:14 . 2013-07-05 14:12 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-07 15:45 . 2013-12-07 15:45 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-10-12 18:03 . 2009-11-29 10:46 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} ----
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2009-12-16 09:03 185344 ----a-w- c:\program files\Get Styles\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2015-01-15 23308256]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-01-20 5496600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-01-25 159744]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-01 6265376]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-05-08 864576]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-30 397312]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-12-16 702768]
"Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2015-01-19 126712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-4-13 791840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-10-12 18:03 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProductReg]
2008-11-17 07:47 135168 ----a-w- c:\program files\Acer\WR_PopUp\ProductReg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2008-08-01 05:42 1833504 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2013-05-03 17:09 802136 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-666440843-1538565178-2896567187-1003]
"EnableNotificationsRef"=dword:00000001
.
S2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-06 13:59 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-01-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-08 13:59]
.
.
------- Doplňkový sken -------
.
IE: Download video on this page - c:\program files\Tomabo\MP4 Player\YTVD_IE.dll/300
IE: Download video this links to - c:\program files\Tomabo\MP4 Player\YTVD_IE.dll/301
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\sx948fvr.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - c:\program files\IObit\IObit Uninstaller\UninstallExplorer32.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-02-10 09:55
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3852)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2015-02-10 10:02:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-02-10 09:02
ComboFix2.txt 2015-02-09 22:27
.
Před spuštěním: Volných bajtů: 31 004 835 840
Po spuštění: Volných bajtů: 30 735 704 064
.
- - End Of File - - F13B5E2321EFDA43152369FA5FC4669B
6FC6F9186C07BCA94E140F63BFE6E9B4

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 10:09

aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
Run date: 2015-02-10 10:06:38
-----------------------------
10:06:38.764 OS Version: Windows 6.0.6002 Service Pack 2
10:06:38.764 Number of processors: 2 586 0x301
10:06:38.779 ComputerName: EVA-PC UserName: Eva
10:06:40.792 Initialize success
10:06:40.916 VM: initialized successfully
10:06:40.916 VM: Amd CPU supported
10:06:58.853 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000067
10:06:58.869 Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 8
10:06:59.290 Disk 0 MBR read successfully
10:06:59.305 Disk 0 MBR scan
10:06:59.305 Disk 0 unknown MBR code
10:07:04.578 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048
10:07:04.625 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 147630 MB offset 20482048
10:07:04.656 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 147613 MB offset 322828288
10:07:04.703 Disk 0 scanning sectors +625139712
10:07:05.389 Disk 0 scanning C:\Windows\system32\drivers
10:07:20.943 Service scanning
10:08:00.769 Modules scanning
10:08:01.300 Disk 0 trace - called modules:
10:08:01.331 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys ahcix86s.sys
10:08:01.347 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86e659d8]
10:08:01.362 3 CLASSPNP.SYS[8a9ac8b3] -> nt!IofCallDriver -> [0x860069b0]
10:08:01.378 5 acpi.sys[8060a6bc] -> nt!IofCallDriver -> \Device\00000067[0x862e9c90]
10:08:01.409 Disk 0 statistics 105394/0/0 @ 3,17 MB/s
10:08:01.425 Scan finished successfully
10:08:32.079 Disk 0 MBR has been saved successfully to "C:\Users\Eva\Desktop\MBR.dat"
10:08:32.094 The log file has been saved successfully to "C:\Users\Eva\Desktop\aswMBR.txt"

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 10:13

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:12:42, on 10.2.2015
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19088)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download video on this page - res://C:\Program Files\Tomabo\MP4 Player\YTVD_IE.dll/300
O8 - Extra context menu item: Download video this links to - res://C:\Program Files\Tomabo\MP4 Player\YTVD_IE.dll/301
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8299 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Policejní vir??

Příspěvekod jaro3 » 10 úno 2015 10:23

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.


c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} --- smaž tuto označenou složku.

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků

Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt

Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 10:40

Došla jsem za smazání složky a musím teď do školy, zatím díky, logy pošlu kolem páté až se vrátím

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Policejní vir??

Příspěvekod jaro3 » 10 úno 2015 10:55

Ok.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 13:52

13:31:58.0957 0x0664 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
13:32:38.0581 0x0664 ============================================================
13:32:38.0581 0x0664 Current date / time: 2015/02/10 13:32:38.0581
13:32:38.0581 0x0664 SystemInfo:
13:32:38.0581 0x0664
13:32:38.0581 0x0664 OS Version: 6.0.6002 ServicePack: 2.0
13:32:38.0581 0x0664 Product type: Workstation
13:32:38.0581 0x0664 ComputerName: EVA-PC
13:32:38.0581 0x0664 UserName: Eva
13:32:38.0581 0x0664 Windows directory: C:\Windows
13:32:38.0581 0x0664 System windows directory: C:\Windows
13:32:38.0581 0x0664 Processor architecture: Intel x86
13:32:38.0581 0x0664 Number of processors: 2
13:32:38.0581 0x0664 Page size: 0x1000
13:32:38.0581 0x0664 Boot type: Normal boot
13:32:38.0581 0x0664 ============================================================
13:32:40.0593 0x0664 KLMD registered as C:\Windows\system32\drivers\49165256.sys
13:32:40.0921 0x0664 System UUID: {213AE2C7-33E4-921A-35C4-3F51D167D8CA}
13:32:42.0200 0x0664 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:32:42.0216 0x0664 ============================================================
13:32:42.0216 0x0664 \Device\Harddisk0\DR0:
13:32:42.0231 0x0664 MBR partitions:
13:32:42.0231 0x0664 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1388800, BlocksNum 0x12057000
13:32:42.0231 0x0664 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x133DF800, BlocksNum 0x1204E800
13:32:42.0231 0x0664 ============================================================
13:32:42.0387 0x0664 C: <-> \Device\Harddisk0\DR0\Partition1
13:32:42.0450 0x0664 D: <-> \Device\Harddisk0\DR0\Partition2
13:32:42.0465 0x0664 ============================================================
13:32:42.0465 0x0664 Initialize success
13:32:42.0465 0x0664 ============================================================
13:37:31.0284 0x15a4 ============================================================
13:37:31.0284 0x15a4 Scan started
13:37:31.0284 0x15a4 Mode: Manual;
13:37:31.0284 0x15a4 ============================================================
13:37:31.0284 0x15a4 KSN ping started
13:37:33.0655 0x15a4 KSN ping finished: true
13:37:34.0841 0x15a4 ================ Scan system memory ========================
13:37:34.0841 0x15a4 System memory - ok
13:37:34.0841 0x15a4 ================ Scan services =============================
13:37:34.0981 0x15a4 [ F11D68E40ED62FDB7C460C445F1EC4E5, FE0C6B90209CFE4485176B977B26732F3E087961C75768EC7C33398309D334D9 ] 602XML Updater C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
13:37:34.0981 0x15a4 602XML Updater - ok
13:37:35.0168 0x15a4 [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:37:35.0199 0x15a4 ACPI - ok
13:37:35.0309 0x15a4 [ 4C72FDD915D62EAEF149BD9C73AB9CF4, 8EA45A1B88DFD819F0ADA3AF36D464E1BF52574269592370E0CC8D0490680E1F ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
13:37:35.0309 0x15a4 AdobeARMservice - ok
13:37:35.0387 0x15a4 [ A2A9C100FE1BE20A76C0B80D4CA44103, C34B4A31C8563E29EC6A3D318C40075F43C891C23D156F53EE2102C959B7887F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:37:35.0402 0x15a4 AdobeFlashPlayerUpdateSvc - ok
13:37:35.0465 0x15a4 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:37:35.0543 0x15a4 adp94xx - ok
13:37:35.0605 0x15a4 [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:37:35.0636 0x15a4 adpahci - ok
13:37:35.0667 0x15a4 [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:37:35.0699 0x15a4 adpu160m - ok
13:37:35.0730 0x15a4 [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:37:35.0777 0x15a4 adpu320 - ok
13:37:35.0823 0x15a4 [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:37:35.0839 0x15a4 AeLookupSvc - ok
13:37:35.0933 0x15a4 [ 3911B972B55FEA0478476B2E777B29FA, 62545B90C7DD3F73777E62CD8264E611A4D71B6956CABFD2D820D25F41F471FD ] AFD C:\Windows\system32\drivers\afd.sys
13:37:35.0948 0x15a4 AFD - ok
13:37:35.0964 0x15a4 [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:37:35.0979 0x15a4 agp440 - ok
13:37:36.0026 0x15a4 [ 9879FF9F6A04D660BC245788E1881B00, DDA92B699656B69EB0A31B67449682911CE0327886B649CDE66BC835379C5FE6 ] ahcix86s C:\Windows\system32\DRIVERS\ahcix86s.sys
13:37:36.0026 0x15a4 ahcix86s - ok
13:37:36.0073 0x15a4 [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:37:36.0073 0x15a4 aic78xx - ok
13:37:36.0104 0x15a4 [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG C:\Windows\System32\alg.exe
13:37:36.0120 0x15a4 ALG - ok
13:37:36.0151 0x15a4 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide C:\Windows\system32\drivers\aliide.sys
13:37:36.0151 0x15a4 aliide - ok
13:37:36.0182 0x15a4 [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:37:36.0198 0x15a4 amdagp - ok
13:37:36.0229 0x15a4 [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide C:\Windows\system32\drivers\amdide.sys
13:37:36.0245 0x15a4 amdide - ok
13:37:36.0276 0x15a4 [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:37:36.0276 0x15a4 AmdK7 - ok
13:37:36.0307 0x15a4 [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:37:36.0323 0x15a4 AmdK8 - ok
13:37:36.0463 0x15a4 [ C2700D35AA42311A32DF7EA09630B401, 35B305916DB91EBC86CA70AF23140684F57CF527A0ADE099A79610335C61E861 ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
13:37:36.0510 0x15a4 AntiVirSchedulerService - ok
13:37:36.0588 0x15a4 [ C2700D35AA42311A32DF7EA09630B401, 35B305916DB91EBC86CA70AF23140684F57CF527A0ADE099A79610335C61E861 ] AntiVirService C:\Program Files\Avira\AntiVir Desktop\avguard.exe
13:37:36.0619 0x15a4 AntiVirService - ok
13:37:36.0666 0x15a4 [ B90E6EC1C41E3C6CC4F69BAA9D74515C, B9328D7B9B0B3980B7046AAB5F22D8EF13D555C4BB9A256E1CA43D094B84D303 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
13:37:36.0681 0x15a4 ApfiltrService - ok
13:37:36.0713 0x15a4 [ C6D704C7F0434DC791AAC37CAC4B6E14, 35CF7D1895F97637E0C678A39F3049B871BCA9526D379C7793ED33B87D2EAC4C ] Appinfo C:\Windows\System32\appinfo.dll
13:37:36.0713 0x15a4 Appinfo - ok
13:37:36.0775 0x15a4 [ 0FE769CAE5855B53C90E23F85E7E89FF, 7163E364D33EDABCFC1E1B586D28FA906F34A764BF4B3031DF020043EAE0D3BF ] AppMgmt C:\Windows\System32\appmgmts.dll
13:37:36.0791 0x15a4 AppMgmt - ok
13:37:36.0822 0x15a4 [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc C:\Windows\system32\drivers\arc.sys
13:37:36.0853 0x15a4 arc - ok
13:37:36.0884 0x15a4 [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:37:36.0884 0x15a4 arcsas - ok
13:37:37.0056 0x15a4 [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:37:37.0056 0x15a4 aspnet_state - ok
13:37:37.0118 0x15a4 [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:37:37.0118 0x15a4 AsyncMac - ok
13:37:37.0165 0x15a4 [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi C:\Windows\system32\drivers\atapi.sys
13:37:37.0165 0x15a4 atapi - ok
13:37:37.0274 0x15a4 [ 99D78248BFD454BFA9B5BEC37350FADE, D15549EE426B0B42FD7E0EDF2C8C3C273D6023A27BDB5AD8F0FC4BC83961429F ] athr C:\Windows\system32\DRIVERS\athr.sys
13:37:37.0352 0x15a4 athr - ok
13:37:37.0539 0x15a4 [ F4B36684811CA991AA2385CB963CA56B, F34FF27ACD421F92598262F7C7B833069CE39E28C107D228EA33BCF2C1327E62 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
13:37:37.0586 0x15a4 Ati External Event Utility - ok
13:37:37.0914 0x15a4 [ D4129EDF159A9B352BB0D3E5CE0DAC04, 68C0B6030B3657FC7EAE1542DCCB3D9E504B5B632CF025E3F6CD378D738BBB5A ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:37:38.0226 0x15a4 atikmdag - ok
13:37:38.0397 0x15a4 [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:37:38.0429 0x15a4 AudioEndpointBuilder - ok
13:37:38.0491 0x15a4 [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:37:38.0507 0x15a4 Audiosrv - ok
13:37:38.0553 0x15a4 [ F581D2F3E30C1CA7206D660FB7689F98, 53647E017AE58788922F72285DD63E8CD2F9E922B31F7C6711E547BC6B360154 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
13:37:38.0569 0x15a4 avgntflt - ok
13:37:38.0631 0x15a4 [ A2EE407D6D3757A2FFD5095DD16AE1F2, BBFCC5DC116D6A3AF85591955541528DB0CB1FE81D353F717BE7CAD3F7F446F4 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
13:37:38.0647 0x15a4 avipbb - ok
13:37:38.0772 0x15a4 [ 8E6214E8C6100222BEB6A14F9B908A7E, 268279AE0D87E4B1CC227355DF12B7E8113F8355B1D20447AA723830D706021A ] Avira.OE.ServiceHost C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
13:37:38.0787 0x15a4 Avira.OE.ServiceHost - ok
13:37:38.0819 0x15a4 [ D8C712305F73CD34D1B344810E522728, 49A474FF6CA44E8427D7A8290B47395125B0148AF384CF2B3B1FA495A4718CBA ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
13:37:38.0834 0x15a4 avkmgr - ok
13:37:38.0897 0x15a4 [ 7D0F2BFA273831124FA08526AF48AF18, 7229D1BBD58027771378FC1893C9C27D42D3246B4B46B9FBE056E14B8B752D92 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
13:37:38.0912 0x15a4 b57nd60x - ok
13:37:38.0975 0x15a4 [ 6163664C7E9CD110AF70180C126C3FDC, 9A801295CDE2BDE4EE0E96C610E4C01F6915DBDA2104D0E8873AFF1BC34A0FA1 ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
13:37:38.0990 0x15a4 BcmSqlStartupSvc - ok
13:37:39.0021 0x15a4 [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep C:\Windows\system32\drivers\Beep.sys
13:37:39.0021 0x15a4 Beep - ok
13:37:39.0099 0x15a4 [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE C:\Windows\System32\bfe.dll
13:37:39.0131 0x15a4 BFE - ok
13:37:39.0271 0x15a4 [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS C:\Windows\System32\qmgr.dll
13:37:39.0318 0x15a4 BITS - ok
13:37:39.0380 0x15a4 [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:37:39.0396 0x15a4 blbdrive - ok
13:37:39.0489 0x15a4 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:37:39.0536 0x15a4 Bonjour Service - ok
13:37:39.0583 0x15a4 [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:37:39.0583 0x15a4 bowser - ok
13:37:39.0614 0x1030 Object required for P2P: [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI
13:37:39.0630 0x15a4 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:37:39.0630 0x15a4 BrFiltLo - ok
13:37:39.0661 0x15a4 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:37:39.0677 0x15a4 BrFiltUp - ok
13:37:39.0708 0x15a4 [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser C:\Windows\System32\browser.dll
13:37:39.0723 0x15a4 Browser - ok
13:37:39.0755 0x15a4 [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:37:39.0770 0x15a4 Brserid - ok
13:37:39.0801 0x15a4 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:37:39.0801 0x15a4 BrSerWdm - ok
13:37:39.0833 0x15a4 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:37:39.0833 0x15a4 BrUsbMdm - ok
13:37:39.0864 0x15a4 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:37:39.0864 0x15a4 BrUsbSer - ok
13:37:39.0911 0x15a4 [ 6D39C954799B63BA866910234CF7D726, 1D807C3410C01C76E5810D626F23C1CCED3C9C5A65F39267B770C494C8D64114 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
13:37:39.0926 0x15a4 BthEnum - ok
13:37:39.0957 0x15a4 [ 9A966A8E86D1771911AE34A20D11BFF3, FBD5F621A47A3530B325816E71F0C4BCE5CCE731C57DEBD42ACFC8BCAA258656 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:37:39.0957 0x15a4 BTHMODEM - ok
13:37:40.0004 0x15a4 [ 5904EFA25F829BF84EA6FB045134A1D8, 66E4160CC404744576BA6E9DD606B533F42B3D4A3E2FDD457DAA016CC72A81CC ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:37:40.0004 0x15a4 BthPan - ok
13:37:40.0067 0x15a4 [ 5A3ABAA2F8EECE7AEFB942773766E3DB, E10A284B8587EC3B033DDBEAAB9CF0FCC698088BEF4F3B1E6DFCBCD177AF126B ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
13:37:40.0098 0x15a4 BTHPORT - ok
13:37:40.0160 0x15a4 [ A4C8377FA4A994E07075107DBE2E3DCE, C3CDAA7B83D130100044341C23897CC6C257FA075A8D08B8551F4A28AE8CE6C4 ] BthServ C:\Windows\System32\bthserv.dll
13:37:40.0176 0x15a4 BthServ - ok
13:37:40.0223 0x15a4 [ 94E2941280E3756A5E0BCB467865C43A, 5A7B30F69D645881717BD78066E62337EB4A081F54E6B5898662C4BEBF59925F ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
13:37:40.0238 0x15a4 BTHUSB - ok
13:37:40.0301 0x15a4 [ F97A9C093E79BF117D9F26F2D31DCA5E, 40F423565749F0B642BD19EEAF43A73324209918784812A3EE2FCE7958E5A501 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
13:37:40.0301 0x15a4 btwaudio - ok
13:37:40.0332 0x15a4 [ 143C4C1EE6D131ECA8B4AB5F80B3F910, B390D7AAB54D634041F90C5B6AB5A8A16C568E58CC44231E8AF99D4D18362728 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
13:37:40.0347 0x15a4 btwavdt - ok
13:37:40.0425 0x15a4 [ B6C870EE321AA8678198EA003DCFBB02, 917486C72EA9F180CC9BCF3F8BE0A79FFB60C32CC6648B64C361F63C43BFEDCD ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
13:37:40.0457 0x15a4 btwdins - ok
13:37:40.0519 0x15a4 [ AAFD7CB76BA61FBB08E302DA208C974A, 1B342095E373ECCA1775B30E92CD337BECEB4BA9F821132C33507A646E6A341C ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
13:37:40.0519 0x15a4 btwl2cap - ok
13:37:40.0566 0x15a4 [ 97CF6C5D3B443344497F1F53E5D0ED50, 4420053603D65263090A7433C88357FAC3E1A41695266398777DBC0F8A8D0AA8 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
13:37:40.0566 0x15a4 btwrchid - ok
13:37:40.0628 0x15a4 [ 09E6AFFAE6C0E9158BF05C7D08D0107A, 05524526EBD5F42F58404A698F397CD7CBC2CBB5F7211AB6B5C2691A87983A24 ] BUNAgentSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
13:37:40.0628 0x15a4 BUNAgentSvc - ok
13:37:40.0659 0x15a4 [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:37:40.0675 0x15a4 cdfs - ok
13:37:40.0722 0x15a4 [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:37:40.0737 0x15a4 cdrom - ok
13:37:40.0784 0x15a4 [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc C:\Windows\System32\certprop.dll
13:37:40.0784 0x15a4 CertPropSvc - ok
13:37:40.0862 0x15a4 [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass C:\Windows\system32\drivers\circlass.sys
13:37:40.0862 0x15a4 circlass - ok
13:37:40.0909 0x15a4 [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS C:\Windows\system32\CLFS.sys
13:37:40.0940 0x15a4 CLFS - ok
13:37:41.0018 0x15a4 [ 8EE772032E2FE80A924F3B8DD5082194, B743DF91563A22CC15D9B44105804B5866A29D3DFC156DBE88DFAFEF903B94C0 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:37:41.0034 0x15a4 clr_optimization_v2.0.50727_32 - ok
13:37:41.0112 0x15a4 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:37:41.0112 0x15a4 clr_optimization_v4.0.30319_32 - ok
13:37:41.0143 0x15a4 [ 99AFC3795B58CC478FBBBCDC658FCB56, 0D1B27C42A058C5D56A0157B5ECA9A054254F6B9C8015D0321021A7EFCE10CE2 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:37:41.0159 0x15a4 CmBatt - ok
13:37:41.0205 0x15a4 [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:37:41.0205 0x15a4 cmdide - ok
13:37:41.0237 0x15a4 [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:37:41.0237 0x15a4 Compbatt - ok
13:37:41.0268 0x15a4 COMSysApp - ok
13:37:41.0299 0x15a4 [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:37:41.0315 0x15a4 crcdisk - ok
13:37:41.0346 0x15a4 [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:37:41.0346 0x15a4 Crusoe - ok
13:37:41.0424 0x15a4 [ FB27772BEAF8E1D28CCD825C09DA939B, D074A314FB3E6B2248F2DB0A734B98A110F618804449E055B4178BF414826982 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:37:41.0439 0x15a4 CryptSvc - ok
13:37:41.0486 0x15a4 [ 9BDB2E89BE8D0EF37B1F25C3D3FC192C, 95E3AA76DAF3F9EDE1AAE9B85C779F2716097266F492E0A8D361C6ED9A9AC8CC ] CSC C:\Windows\system32\drivers\csc.sys
13:37:41.0533 0x15a4 CSC - ok
13:37:41.0642 0x15a4 [ 0A2095F92F6AE4FE6484D911B0C21E95, 52E2E08107FEBD6B46E1C71B39ECA8AB1A0ECF18CA248D9172F831B6FAB99139 ] CscService C:\Windows\System32\cscsvc.dll
13:37:41.0689 0x15a4 CscService - ok
13:37:41.0798 0x15a4 [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:37:41.0845 0x15a4 DcomLaunch - ok
13:37:41.0907 0x15a4 [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:37:41.0923 0x15a4 DfsC - ok
13:37:42.0110 0x15a4 [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR C:\Windows\system32\DFSR.exe
13:37:42.0391 0x15a4 DFSR - ok
13:37:42.0547 0x15a4 [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:37:42.0563 0x15a4 Dhcp - ok
13:37:42.0594 0x15a4 [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk C:\Windows\system32\drivers\disk.sys
13:37:42.0594 0x15a4 disk - ok
13:37:42.0625 0x15a4 [ 73BAF270D24FE726B9CD7F80BB17A23D, 12ADFB26C16A7D3F623C1A6B72D4C6AB9163EBC93CF13CB2AC6897FB95E96105 ] DKbFltr C:\Windows\system32\DRIVERS\DKbFltr.sys
13:37:42.0625 0x15a4 DKbFltr - ok
13:37:42.0687 0x15a4 [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:37:42.0687 0x15a4 Dnscache - ok
13:37:42.0750 0x15a4 [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc C:\Windows\System32\dot3svc.dll
13:37:42.0765 0x15a4 dot3svc - ok
13:37:42.0812 0x15a4 [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS C:\Windows\system32\dps.dll
13:37:42.0828 0x15a4 DPS - ok
13:37:42.0843 0x15a4 [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:37:42.0875 0x15a4 drmkaud - ok
13:37:42.0953 0x15a4 [ FB85F7F69E9B109820409243F578CC4D, FBE0426E51B83DD973EC08ABA4E69E99F54B1C44995E0FD42B68A07549D52D7F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:37:42.0999 0x15a4 DXGKrnl - ok
13:37:43.0031 0x15a4 [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:37:43.0046 0x15a4 E1G60 - ok
13:37:43.0093 0x15a4 [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost C:\Windows\System32\eapsvc.dll
13:37:43.0109 0x15a4 EapHost - ok
13:37:43.0171 0x15a4 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache C:\Windows\system32\drivers\ecache.sys
13:37:43.0171 0x15a4 Ecache - ok
13:37:43.0311 0x15a4 [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:37:43.0327 0x15a4 elxstor - ok
13:37:43.0530 0x15a4 [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:37:43.0592 0x15a4 EMDMgmt - ok
13:37:43.0639 0x15a4 [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:37:43.0639 0x15a4 ErrDev - ok
13:37:43.0764 0x15a4 [ A51FD9DF23720485991F56741BBEFCFB, 8998926A056074963898FE5A9148FDCDA9C66607A7F534D69952E4CDDE10EDC5 ] ETService C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
13:37:43.0764 0x15a4 ETService - ok
13:37:43.0904 0x15a4 [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem C:\Windows\system32\es.dll
13:37:43.0920 0x15a4 EventSystem - ok
13:37:43.0951 0x15a4 [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat C:\Windows\system32\drivers\exfat.sys
13:37:43.0998 0x15a4 exfat - ok
13:37:44.0076 0x15a4 [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:37:44.0154 0x15a4 fastfat - ok
13:37:44.0310 0x15a4 [ DFBA0F60FA301E5B1BFB1403A93EE23E, 727A01AA77BFD6B6FEB394A4C4CCBDB785987A1904F8EED3739A5F6D03C15965 ] Fax C:\Windows\system32\fxssvc.exe
13:37:44.0357 0x15a4 Fax - ok
13:37:44.0419 0x15a4 [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:37:44.0419 0x15a4 fdc - ok
13:37:44.0481 0x15a4 [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost C:\Windows\system32\fdPHost.dll
13:37:44.0481 0x15a4 fdPHost - ok
13:37:44.0497 0x15a4 [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub C:\Windows\system32\fdrespub.dll
13:37:44.0528 0x15a4 FDResPub - ok
13:37:44.0559 0x15a4 [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:37:44.0575 0x15a4 FileInfo - ok
13:37:44.0606 0x15a4 [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:37:44.0606 0x15a4 Filetrace - ok
13:37:44.0762 0x15a4 [ 227846995AFEEFA70D328BF5334A86A5, B8EF22DE552B44E7DC352742C775BB6B4992B653AF4B66B231A60182CE7A7201 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:37:44.0809 0x15a4 FLEXnet Licensing Service - ok
13:37:44.0840 0x15a4 [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:37:44.0903 0x15a4 flpydisk - ok
13:37:44.0965 0x15a4 [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:37:44.0981 0x15a4 FltMgr - ok
13:37:45.0074 0x15a4 [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:37:45.0074 0x15a4 FontCache3.0.0.0 - ok
13:37:45.0105 0x15a4 [ 65EA8B77B5851854F0C55C43FA51A198, 150BE6C195094DBEAC4FD73CC1C31FF59B77A73944574E244D280EE2DE69DC2F ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:37:45.0137 0x15a4 Fs_Rec - ok
13:37:45.0199 0x15a4 [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:37:45.0199 0x15a4 gagp30kx - ok
13:37:45.0433 0x15a4 [ 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F, 6D2B301E77839FFF1C74425B37D02C3F3837CE50E856C21AE4CF7ABABB04ADDC ] GoogleDesktopManager-051210-111108 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
13:37:45.0433 0x15a4 GoogleDesktopManager-051210-111108 - ok
13:37:45.0636 0x15a4 [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc C:\Windows\System32\gpsvc.dll
13:37:45.0714 0x15a4 gpsvc - ok
13:37:45.0839 0x15a4 [ CB04C744BE0A61B1D648FAED182C3B59, 61DC0FF94325DAFCCB7B3980A48727EFBF1283FCF753EC16EF04C730525994C0 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:37:45.0885 0x15a4 HdAudAddService - ok
13:37:45.0995 0x15a4 [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:37:46.0041 0x15a4 HDAudBus - ok
13:37:46.0088 0x15a4 [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:37:46.0088 0x15a4 HidBth - ok
13:37:46.0135 0x15a4 [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr C:\Windows\system32\drivers\hidir.sys
13:37:46.0151 0x15a4 HidIr - ok
13:37:46.0260 0x15a4 [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv C:\Windows\System32\hidserv.dll
13:37:46.0275 0x15a4 hidserv - ok
13:37:46.0322 0x15a4 [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:37:46.0322 0x15a4 HidUsb - ok
13:37:46.0369 0x15a4 [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc C:\Windows\system32\kmsvc.dll
13:37:46.0385 0x15a4 hkmsvc - ok
13:37:46.0416 0x15a4 [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:37:46.0416 0x15a4 HpCISSs - ok
13:37:46.0478 0x15a4 [ 46D67209550973257601A533E2AC5785, 3C0D97781947BA8532344AA5D9F3B684761B5B3263A0A294F4593E76EE41DB0C ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
13:37:46.0478 0x15a4 HSFHWAZL - ok
13:37:46.0712 0x15a4 [ 7BC42C65B5C6281777C1A7605B253BA8, 71885EB4E8625450ECA4623466FB3D5437DAABE739A5DC3B5F4CF982A65F8A86 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
13:37:46.0868 0x15a4 HSF_DPV - ok
13:37:46.0931 0x15a4 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E, A11CE324DD8E8BDFFDF513429C32D3C16EC79DC9A7517048587759B26BF38583 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
13:37:46.0946 0x15a4 HSXHWAZL - ok
13:37:47.0118 0x15a4 [ F870AA3E254628EBEAFE754108D664DE, B0444E7D246AA1982094030ACB991690F6A7DD3FB07B1BB6A1BC0F3AA9718A70 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:37:47.0149 0x15a4 HTTP - ok
13:37:47.0196 0x15a4 [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:37:47.0196 0x15a4 i2omp - ok
13:37:47.0243 0x15a4 [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:37:47.0243 0x15a4 i8042prt - ok
13:37:47.0352 0x15a4 [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:37:47.0367 0x15a4 iaStorV - ok
13:37:47.0555 0x15a4 [ 98477B08E61945F974ED9FDC4CB6BDAB, C7E8F661F6FBF6AB493E950D2E70363496E155B1838CE7B490B981BD840B04FC ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:37:47.0617 0x15a4 idsvc - ok
13:37:47.0648 0x15a4 [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:37:47.0664 0x15a4 iirsp - ok
13:37:47.0882 0x15a4 [ 9908D8A397B76CD8D31D0D383C5773C9, FFA6996BE9F11A81CB63C849C2400EB44A07706D1EEB7A3502D4110DAC3684A2 ] IKEEXT C:\Windows\System32\ikeext.dll
13:37:47.0929 0x15a4 IKEEXT - ok
13:37:47.0991 0x15a4 [ C6E5276C00EBDEB096BB5EF4B797D1B6, 2620D2F7B5242E9DD0217FB4E0CBACF1DB8AB1B92187AD2847904948E1ABFEC1 ] int15 C:\Windows\system32\drivers\int15.sys
13:37:47.0991 0x15a4 int15 - ok
13:37:48.0413 0x15a4 [ A963D32AB87A83445E7D21BD5620539A, 108D4E91531F4494F1F86D498322EA42742250C4CF632EBD3B304E40D50E677D ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:37:49.0208 0x15a4 IntcAzAudAddService - ok
13:37:49.0255 0x15a4 [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide C:\Windows\system32\drivers\intelide.sys
13:37:49.0349 0x15a4 intelide - ok
13:37:49.0380 0x15a4 [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:37:49.0442 0x15a4 intelppm - ok
13:37:49.0489 0x15a4 [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:37:49.0505 0x15a4 IPBusEnum - ok
13:37:49.0536 0x15a4 [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:37:49.0551 0x15a4 IpFilterDriver - ok
13:37:49.0676 0x15a4 [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:37:49.0692 0x15a4 iphlpsvc - ok
13:37:49.0707 0x15a4 IpInIp - ok
13:37:49.0739 0x15a4 [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:37:49.0754 0x15a4 IPMIDRV - ok
13:37:49.0817 0x15a4 [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:37:49.0832 0x15a4 IPNAT - ok
13:37:49.0863 0x15a4 [ E50A95179211B12946F7E035D60AF560, 69765E2548BA708FF35545EC944DBA1940AD4065AF90E53B97A7792AC231DCF7 ] irda C:\Windows\system32\DRIVERS\irda.sys
13:37:49.0863 0x15a4 irda - ok
13:37:49.0941 0x15a4 [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:37:49.0957 0x15a4 IRENUM - ok
13:37:50.0222 0x15a4 [ CBB0D940221A281BCFEAEA695BD1CDA5, D05D192019524A02FE3FAE6827B98A942FA1AD651BF7AA53530A8A6F4ADFB7EB ] Irmon C:\Windows\System32\irmon.dll
13:37:50.0222 0x15a4 Irmon - ok
13:37:50.0253 0x15a4 [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:37:50.0253 0x15a4 isapnp - ok
13:37:50.0378 0x15a4 [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:37:50.0394 0x15a4 iScsiPrt - ok
13:37:50.0425 0x15a4 [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:37:50.0425 0x15a4 iteatapi - ok
13:37:50.0456 0x15a4 [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:37:50.0456 0x15a4 iteraid - ok
13:37:50.0550 0x15a4 [ 213822072085B5BBAD9AF30AB577D817, 2C373B804D840933EC3A5F3ABFC43E47C2636CDB2431AB51846C565077B7C468 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
13:37:50.0565 0x15a4 IviRegMgr - ok
13:37:50.0628 0x15a4 [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:37:50.0628 0x15a4 kbdclass - ok
13:37:50.0659 0x15a4 [ 18247836959BA67E3511B62846B9C2E0, 9623FF990A1C11A707C358CC9FDD4306C2992A8C766A50DAFC9534A283AA011D ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
13:37:50.0659 0x15a4 kbdhid - ok
13:37:50.0706 0x15a4 [ 3978F3540329E16C0AC3BCF677E5669F, 2CC9F1C9D9E33F8A0DA72490D74BED9E746FB142EDF78DE2F2A33A34B76D9868 ] KeyIso C:\Windows\system32\lsass.exe
13:37:50.0706 0x15a4 KeyIso - ok
13:37:50.0784 0x15a4 [ 86165728AF9BF72D6442A894FDFB4F8B, 97A95C1856C761C93F43B177995749E45FA066C7FF6E93E6C3F34C1593ED2FB7 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:37:50.0846 0x15a4 KSecDD - ok
13:37:50.0971 0x15a4 [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:37:50.0987 0x15a4 KtmRm - ok
13:37:51.0080 0x15a4 [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer C:\Windows\System32\srvsvc.dll
13:37:51.0096 0x15a4 LanmanServer - ok
13:37:51.0143 0x15a4 [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:37:51.0189 0x15a4 LanmanWorkstation - ok
13:37:51.0252 0x15a4 [ 793FF718477345CD5D232C50BED1E452, 1D39CF9F10742C79FF99B9B4E0361EAEA63B4FC545C58B54B55537D18C802941 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:37:51.0252 0x15a4 LightScribeService - ok
13:37:51.0314 0x15a4 [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:37:51.0314 0x15a4 lltdio - ok
13:37:51.0361 0x15a4 [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:37:51.0377 0x15a4 lltdsvc - ok
13:37:51.0408 0x15a4 [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:37:51.0408 0x15a4 lmhosts - ok
13:37:51.0455 0x15a4 [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:37:51.0533 0x15a4 LSI_FC - ok
13:37:51.0564 0x15a4 [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:37:51.0564 0x15a4 LSI_SAS - ok
13:37:51.0595 0x15a4 [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:37:51.0611 0x15a4 LSI_SCSI - ok
13:37:51.0657 0x15a4 [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv C:\Windows\system32\drivers\luafv.sys
13:37:51.0673 0x15a4 luafv - ok
13:37:51.0689 0x15a4 massfilter - ok
13:37:51.0751 0x15a4 [ A3F4391DFDF2F9E9FE4EAD193265A5AD, A60A1A345622F4758181FB0B6EE784B0B718105FEE7B0F6FEDE5AD59FE448EE1 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:37:51.0751 0x15a4 MBAMProtector - ok
13:37:52.0266 0x15a4 [ 0BB29DE40C9D9529793DCDB59A43CF5B, 251001A407D32EF22F64915EEFFAAEC229073C4549BF7D9D1D4209B7D15B4681 ] MBAMScheduler C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
13:37:52.0547 0x15a4 MBAMScheduler - ok
13:37:52.0921 0x15a4 [ 5F82D8188B370B0CF185D4AE2B9B4A0E, 549B53DD989A069E1C38347C4CEF5283DF9B428CE102799B06A20D3D8F23825F ] MBAMService C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
13:37:53.0030 0x15a4 MBAMService - ok
13:37:53.0093 0x15a4 [ 6D2DB74A8CF2DDFE372FFF9C73E8F0EF, D18E800D46932795FD0169B5F9A2AAED5684977D0D78B2D1178C9906491CEC7A ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
13:37:53.0093 0x15a4 MBAMWebAccessControl - ok
13:37:53.0124 0x15a4 [ 0CEA2D0D3FA284B85ED5B68365114F76, E6FF0EC98FDC3F628438B613C356C237E68686E3B5B17A58A60C16F4B9A2B968 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
13:37:53.0124 0x15a4 mdmxsdk - ok
13:37:53.0155 0x15a4 [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas C:\Windows\system32\drivers\megasas.sys
13:37:53.0155 0x15a4 megasas - ok
13:37:53.0217 0x15a4 [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:37:53.0311 0x15a4 MegaSR - ok
13:37:53.0498 0x15a4 [ FAFE367D032ED82E9332B4C741A20216, 7B123766E360570E0FCB211835B7910D6A1806C25A06BCA9227AB9E993376CA8 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
13:37:53.0498 0x15a4 Microsoft Office Groove Audit Service - ok
13:37:53.0561 0x15a4 [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS C:\Windows\system32\mmcss.dll
13:37:53.0561 0x15a4 MMCSS - ok
13:37:53.0639 0x15a4 MobilityService - ok
13:37:53.0701 0x15a4 [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem C:\Windows\system32\drivers\modem.sys
13:37:53.0701 0x15a4 Modem - ok
13:37:53.0732 0x15a4 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:37:53.0732 0x15a4 monitor - ok
13:37:53.0763 0x15a4 [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:37:53.0763 0x15a4 mouclass - ok
13:37:53.0795 0x15a4 [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:37:53.0795 0x15a4 mouhid - ok
13:37:53.0826 0x15a4 [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:37:53.0841 0x15a4 MountMgr - ok
13:37:53.0888 0x15a4 [ 96AA8BA23142CC8E2B30F3CAE0C80254, C65380761373DAD16425211FBA0B4E15F260F79A1FF328B1314076D732EE6F0E ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:37:53.0888 0x15a4 MozillaMaintenance - ok
13:37:53.0935 0x15a4 [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio C:\Windows\system32\drivers\mpio.sys
13:37:53.0935 0x15a4 mpio - ok
13:37:53.0966 0x15a4 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:37:53.0982 0x15a4 mpsdrv - ok
13:37:54.0169 0x15a4 [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc C:\Windows\system32\mpssvc.dll
13:37:54.0216 0x15a4 MpsSvc - ok
13:37:54.0247 0x15a4 [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:37:54.0294 0x15a4 Mraid35x - ok
13:37:54.0372 0x15a4 [ 82CEA0395524AACFEB58BA1448E8325C, 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:37:54.0372 0x15a4 MRxDAV - ok
13:37:54.0450 0x15a4 [ 1E94971C4B446AB2290DEB71D01CF0C2, 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:37:54.0465 0x15a4 mrxsmb - ok
13:37:54.0543 0x15a4 [ 4FCCB34D793B116423209C0F8B7A3B03, 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:37:54.0590 0x15a4 mrxsmb10 - ok
13:37:54.0637 0x15a4 [ C3CB1B40AD4A0124D617A1199B0B9D7C, B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:37:54.0637 0x15a4 mrxsmb20 - ok
13:37:54.0699 0x15a4 [ F70590424EEFBF5C27A40C67AFDB8383, 1F2AC1DA12F7E6F09D8F6622EF1366ABD4B86EBE51DD1915E803D56A568A3412 ] msahci C:\Windows\system32\drivers\msahci.sys
13:37:54.0809 0x15a4 msahci - ok
13:37:54.0840 0x15a4 [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:37:54.0840 0x15a4 msdsm - ok
13:37:54.0871 0x15a4 [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC C:\Windows\System32\msdtc.exe
13:37:54.0887 0x15a4 MSDTC - ok
13:37:54.0918 0x15a4 [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:37:54.0980 0x15a4 Msfs - ok
13:37:55.0136 0x15a4 [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:37:55.0214 0x15a4 msisadrv - ok
13:37:55.0292 0x15a4 [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:37:55.0308 0x15a4 MSiSCSI - ok
13:37:55.0323 0x15a4 msiserver - ok
13:37:55.0355 0x15a4 [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:37:55.0355 0x15a4 MSKSSRV - ok
13:37:55.0401 0x15a4 [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:37:55.0448 0x15a4 MSPCLOCK - ok
13:37:55.0479 0x15a4 [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:37:55.0479 0x15a4 MSPQM - ok
13:37:55.0604 0x15a4 [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:37:55.0620 0x15a4 MsRPC - ok
13:37:55.0651 0x15a4 [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:37:55.0651 0x15a4 mssmbios - ok
13:37:55.0760 0x15a4 MSSQL$MSSMLBIZ - ok
13:37:55.0901 0x15a4 [ ADAF062116B4E6D96E44D26486A87AF6, 1A2EE7C4598E8442F24A5C97FEBF7AC6A20703F7EA9097B6E48BE4A05E231D8C ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
13:37:55.0979 0x15a4 MSSQLServerADHelper - ok
13:37:56.0041 0x15a4 [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:37:56.0041 0x15a4 MSTEE - ok
13:37:56.0103 0x15a4 [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup C:\Windows\system32\Drivers\mup.sys
13:37:56.0103 0x15a4 Mup - ok
13:37:56.0228 0x15a4 [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent C:\Windows\system32\qagentRT.dll
13:37:56.0259 0x15a4 napagent - ok
13:37:56.0306 0x15a4 [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:37:56.0322 0x15a4 NativeWifiP - ok
13:37:56.0400 0x15a4 [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:37:56.0447 0x15a4 NDIS - ok
13:37:56.0493 0x15a4 [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:37:56.0493 0x15a4 NdisTapi - ok
13:37:56.0571 0x15a4 [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:37:56.0571 0x15a4 Ndisuio - ok
13:37:56.0618 0x15a4 [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:37:56.0634 0x15a4 NdisWan - ok
13:37:56.0665 0x15a4 [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:37:56.0681 0x15a4 NDProxy - ok
13:37:56.0868 0x15a4 [ 7D2633295EB6FF2B938185874884059D, B3A4E52ABCB2E2720D8ADB0B68C222D4AB98E838D40B6A731D15EB1D6C9DEA15 ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
13:37:56.0930 0x15a4 Nero BackItUp Scheduler 4.0 - ok
13:37:56.0977 0x15a4 [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:37:56.0977 0x15a4 NetBIOS - ok
13:37:57.0071 0x15a4 [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:37:57.0211 0x15a4 netbt - ok
13:37:57.0258 0x15a4 [ 3978F3540329E16C0AC3BCF677E5669F, 2CC9F1C9D9E33F8A0DA72490D74BED9E746FB142EDF78DE2F2A33A34B76D9868 ] Netlogon C:\Windows\system32\lsass.exe

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 13:53

13:37:57.0258 0x15a4 Netlogon - ok
13:37:57.0383 0x15a4 [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman C:\Windows\System32\netman.dll
13:37:57.0398 0x15a4 Netman - ok
13:37:57.0570 0x15a4 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:37:57.0570 0x15a4 NetMsmqActivator - ok
13:37:57.0601 0x15a4 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:37:57.0601 0x15a4 NetPipeActivator - ok
13:37:57.0726 0x15a4 [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm C:\Windows\System32\netprofm.dll
13:37:57.0757 0x15a4 netprofm - ok
13:37:57.0788 0x15a4 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:37:57.0788 0x15a4 NetTcpActivator - ok
13:37:57.0835 0x15a4 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:37:57.0851 0x15a4 NetTcpPortSharing - ok
13:37:57.0929 0x15a4 [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:37:57.0929 0x15a4 nfrd960 - ok
13:37:58.0022 0x15a4 [ 2997B15415F9BBE05B5A4C1C85E0C6A2, 5455536515FE740E18E090329FDCC40288724372AD18ACDB2CB4BB9D85CF681E ] NlaSvc C:\Windows\System32\nlasvc.dll
13:37:58.0069 0x15a4 NlaSvc - ok
13:37:58.0163 0x15a4 [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:37:58.0225 0x15a4 Npfs - ok
13:37:58.0272 0x15a4 [ 6D8D2E5652FC2442C810C5D8BE784148, 013FF4FA03CA2E066B1946CC09889616B243068BA0FB2E58D4C1435BF66FBC87 ] NSCIRDA C:\Windows\system32\DRIVERS\nscirda.sys
13:37:58.0272 0x15a4 NSCIRDA - ok
13:37:58.0334 0x15a4 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi C:\Windows\system32\nsisvc.dll
13:37:58.0334 0x15a4 nsi - ok
13:37:58.0365 0x15a4 [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:37:58.0365 0x15a4 nsiproxy - ok
13:37:58.0506 0x15a4 [ 6A4A98CEE84CF9E99564510DDA4BAA47, 18C3D8C0F12761D3B7FC43D9413CF4C4CEBF8CA9BEC521381F40D241B35EA779 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:37:58.0802 0x15a4 Ntfs - ok
13:37:58.0865 0x15a4 [ CB76F68BA0D57C5D25B538981B1C611C, D078ADEFCF1559EA86AFBD3F6766065EE12B85CF44736A87D4140FB0C480215E ] NTIBackupSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
13:37:58.0896 0x15a4 NTIBackupSvc - ok
13:37:59.0083 0x15a4 [ 2757D2BA59AEE155209E24942AB127C9, 60C8571D548901A68591F1C7C548B40FA1086D21D23B8CB1083A8AE50760FE87 ] NTIDrvr C:\Windows\system32\DRIVERS\NTIDrvr.sys
13:37:59.0083 0x15a4 NTIDrvr - ok
13:37:59.0130 0x15a4 [ DF1C10A75DF7E50195FC417F88A33227, 1551A6243236FD46F34C6F2443A3CC78D5424D9BCECB8576227A9E0AC91EC804 ] NTISchedulerSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
13:37:59.0130 0x15a4 NTISchedulerSvc - ok
13:37:59.0208 0x15a4 [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:37:59.0208 0x15a4 ntrigdigi - ok
13:37:59.0301 0x15a4 [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null C:\Windows\system32\drivers\Null.sys
13:37:59.0348 0x15a4 Null - ok
13:37:59.0395 0x15a4 [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:37:59.0395 0x15a4 nvraid - ok
13:37:59.0442 0x15a4 [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:37:59.0442 0x15a4 nvstor - ok
13:37:59.0504 0x15a4 [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:37:59.0504 0x15a4 nv_agp - ok
13:37:59.0520 0x15a4 NwlnkFlt - ok
13:37:59.0535 0x15a4 NwlnkFwd - ok
13:37:59.0598 0x15a4 [ D955D5DE998DB2476BF0892BE3A96C26, 3828FC1D4A4F9CD685E6D938B92370A602B84A3ACE2C9A674B3B59E633B0AE07 ] o2flash C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
13:37:59.0629 0x1030 Object send P2P result: false
13:37:59.0629 0x1030 Object required for P2P: [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx
13:37:59.0660 0x15a4 o2flash - ok
13:37:59.0707 0x15a4 [ 16DFA5EFF3F104C1D66BCB60C06A101F, CD4545BC9B10C2291A33B8B62AE79C84C24E64776E09B360EE68AA6ADFADD661 ] O2MDRDR C:\Windows\system32\DRIVERS\o2media.sys
13:37:59.0707 0x15a4 O2MDRDR - ok
13:37:59.0738 0x15a4 [ 6E590C91F97AE5E3408453C8AE9A3000, E1205C1C83D462519300DE2A34564F86C9362414711D5CCF2C4FC70166C83B3B ] O2SDRDR C:\Windows\system32\DRIVERS\o2sd.sys
13:37:59.0754 0x15a4 O2SDRDR - ok
13:37:59.0910 0x15a4 [ E54AA592A65F317390EEE386A8821692, 7997F8C07802F6C49F06620B35C4C382ADD5419EA8BE02CD7AF0F2EF42A93E53 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:37:59.0941 0x15a4 odserv - ok
13:38:00.0003 0x15a4 [ 790E27C3DB53410B40FF9EF2FD10A1D9, FD06F2702B8F7E04ECF1B6E88602F14301E7AE7FC44AD114282E580FAD530A9C ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
13:38:00.0003 0x15a4 ohci1394 - ok
13:38:00.0050 0x15a4 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:38:00.0050 0x15a4 ose - ok
13:38:00.0237 0x15a4 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:38:00.0300 0x15a4 p2pimsvc - ok
13:38:00.0393 0x15a4 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc C:\Windows\system32\p2psvc.dll
13:38:00.0425 0x15a4 p2psvc - ok
13:38:00.0503 0x15a4 [ 0FA9B5055484649D63C303FE404E5F4D, ABF357001A5E7B21621560E74FA538E2D899C5111A6AAC784B5B12D9D819C6CD ] Parport C:\Windows\system32\drivers\parport.sys
13:38:00.0503 0x15a4 Parport - ok
13:38:00.0581 0x15a4 [ 57389FA59A36D96B3EB09D0CB91E9CDC, 05A3E2B155789990517CCFDC57FC3D1E9A596E4F31D86350B8BF0C043DE5EE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:38:00.0581 0x15a4 partmgr - ok
13:38:00.0612 0x15a4 [ 4F9A6A8A31413180D0FCB279AD5D8112, DCE48BC6E3447403521BB9FBF727E629DEE45B69B8AE8CFEE1A67FECAE3CB9D3 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:38:00.0627 0x15a4 Parvdm - ok
13:38:00.0674 0x15a4 [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc C:\Windows\System32\pcasvc.dll
13:38:00.0690 0x15a4 PcaSvc - ok
13:38:00.0752 0x15a4 [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci C:\Windows\system32\drivers\pci.sys
13:38:00.0768 0x15a4 pci - ok
13:38:00.0815 0x15a4 [ FC175F5DDAB666D7F4D17449A547626F, 7D6108213D1AD3F97A3B83E491BCCC7D6F5BC72C32A182BDDE8736851A26C8D2 ] pciide C:\Windows\system32\drivers\pciide.sys
13:38:00.0861 0x15a4 pciide - ok
13:38:00.0986 0x15a4 [ 3BB2244F343B610C29C98035504C9B75, DA61EC2600199DFA32020D0484E9BBF5E0742E7C8C952370BF6FAF91C914A999 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:38:01.0002 0x15a4 pcmcia - ok
13:38:01.0064 0x15a4 [ 5B6C11DE7E839C05248CED8825470FEF, DB57DFD02C18461B1B383DF759730FFEE9C7FA8577E1679FD4740A590303EE79 ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
13:38:01.0064 0x15a4 pcouffin - ok
13:38:01.0158 0x15a4 [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:38:01.0501 0x15a4 PEAUTH - ok
13:38:01.0953 0x15a4 [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla C:\Windows\system32\pla.dll
13:38:02.0078 0x15a4 pla - ok
13:38:02.0203 0x15a4 [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:38:02.0250 0x15a4 PlugPlay - ok
13:38:02.0437 0x15a4 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:38:02.0484 0x15a4 PNRPAutoReg - ok
13:38:02.0531 0x15a4 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:38:02.0577 0x15a4 PNRPsvc - ok
13:38:02.0765 0x15a4 [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:38:02.0780 0x15a4 PolicyAgent - ok
13:38:02.0858 0x15a4 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:38:02.0858 0x15a4 PptpMiniport - ok
13:38:02.0889 0x15a4 [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:38:02.0905 0x15a4 Processor - ok
13:38:02.0983 0x15a4 [ 0508FAA222D28835310B7BFCA7A77346, 3AE2340C6E365F137CC00D9560069501DD2724756EA9EBF7A6CDFFC91B43709C ] ProfSvc C:\Windows\system32\profsvc.dll
13:38:03.0014 0x15a4 ProfSvc - ok
13:38:03.0045 0x15a4 [ 3978F3540329E16C0AC3BCF677E5669F, 2CC9F1C9D9E33F8A0DA72490D74BED9E746FB142EDF78DE2F2A33A34B76D9868 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:38:03.0045 0x15a4 ProtectedStorage - ok
13:38:03.0123 0x15a4 [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:38:03.0123 0x15a4 PSched - ok
13:38:03.0295 0x15a4 [ A6A7AD767BF5141665F5C675F671B3E1, 11D43F732C3B82679E53516F83E675B60B0EFEDE3F4EE3C42AC752AD8D5155AF ] PSI_SVC_2 C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
13:38:03.0295 0x15a4 PSI_SVC_2 - ok
13:38:03.0404 0x15a4 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:38:03.0794 0x15a4 ql2300 - ok
13:38:03.0919 0x15a4 [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:38:03.0935 0x15a4 ql40xx - ok
13:38:03.0997 0x15a4 [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE C:\Windows\system32\qwave.dll
13:38:04.0059 0x15a4 QWAVE - ok
13:38:04.0091 0x15a4 [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:38:04.0091 0x15a4 QWAVEdrv - ok
13:38:04.0137 0x15a4 [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:38:04.0137 0x15a4 RasAcd - ok
13:38:04.0200 0x15a4 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto C:\Windows\System32\rasauto.dll
13:38:04.0215 0x15a4 RasAuto - ok
13:38:04.0247 0x15a4 [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:38:04.0262 0x15a4 Rasl2tp - ok
13:38:04.0434 0x15a4 [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan C:\Windows\System32\rasmans.dll
13:38:04.0465 0x15a4 RasMan - ok
13:38:04.0543 0x15a4 [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:38:04.0543 0x15a4 RasPppoe - ok
13:38:04.0590 0x15a4 [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:38:04.0605 0x15a4 RasSstp - ok
13:38:04.0699 0x15a4 [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:38:04.0715 0x15a4 rdbss - ok
13:38:04.0777 0x15a4 [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:38:04.0777 0x15a4 RDPCDD - ok
13:38:04.0917 0x15a4 [ 943B18305EAE3935598A9B4A3D560B4C, E083FA4B9CA1A24031FF23A54942372D7FB3F02F62EE3580F01BEC3229DB2101 ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys
13:38:04.0933 0x15a4 rdpdr - ok
13:38:04.0980 0x15a4 [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:38:04.0980 0x15a4 RDPENCDD - ok
13:38:05.0089 0x15a4 [ 30BFBDFB7F95559EDE971F9DDB9A00BA, 1BDD3FD0ABCF5EA2C4D2618E76AC782894E5A7132700BA4C4226E1F9C7CE547B ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:38:05.0214 0x15a4 RDPWD - ok
13:38:05.0261 0x15a4 [ 001B4278407F4303EFC902A2B16F2453, 92A95B0EFAAE7ADC6380D5207C86CB45BEEAE6974417A13669484A9D179E69AC ] regi C:\Windows\system32\drivers\regi.sys
13:38:05.0261 0x15a4 regi - ok
13:38:05.0323 0x15a4 [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess C:\Windows\System32\mprdim.dll
13:38:05.0339 0x15a4 RemoteAccess - ok
13:38:05.0432 0x15a4 [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:38:05.0448 0x15a4 RemoteRegistry - ok
13:38:05.0495 0x15a4 [ 6482707F9F4DA0ECBAB43B2E0398A101, 7D57FC36577121D7E26A4F2D46DCA8725D55EC9F75B91DF994DB742BC4FB89C2 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
13:38:05.0510 0x15a4 RFCOMM - ok
13:38:05.0573 0x15a4 [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator C:\Windows\system32\locator.exe
13:38:05.0573 0x15a4 RpcLocator - ok
13:38:05.0791 0x15a4 [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs C:\Windows\system32\rpcss.dll
13:38:05.0822 0x15a4 RpcSs - ok
13:38:05.0869 0x15a4 [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:38:05.0931 0x15a4 rspndr - ok
13:38:05.0978 0x15a4 [ 5DFAA39D44E2EB090940351A85B891B8, 2E0FC52273B5BD761CB8090F63DB70B1CF59E9D6967EE588A998C42FFA679B71 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIV.sys
13:38:05.0994 0x15a4 RTHDMIAzAudService - ok
13:38:06.0056 0x15a4 [ 3978F3540329E16C0AC3BCF677E5669F, 2CC9F1C9D9E33F8A0DA72490D74BED9E746FB142EDF78DE2F2A33A34B76D9868 ] SamSs C:\Windows\system32\lsass.exe
13:38:06.0056 0x15a4 SamSs - ok
13:38:06.0056 0x15a4 SANDRA - ok
13:38:06.0119 0x15a4 [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:38:06.0181 0x15a4 sbp2port - ok
13:38:06.0259 0x15a4 [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:38:06.0259 0x15a4 SCardSvr - ok
13:38:06.0446 0x15a4 [ 1A58069DB21D05EB2AB58EE5753EBE8D, EED8111EB613F4C93D1638C74FDB0A6DC6694E1B108DCD0D794B5B5F9B8C6EE4 ] Schedule C:\Windows\system32\schedsvc.dll
13:38:06.0524 0x15a4 Schedule - ok
13:38:06.0633 0x15a4 [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc C:\Windows\System32\certprop.dll
13:38:06.0633 0x15a4 SCPolicySvc - ok
13:38:06.0665 0x15a4 [ 126EA89BCC413EE45E3004FB0764888F, 367BE2B56113177AE867E00D019C707C6449E0FC4A642101B11036A0534D6901 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
13:38:06.0680 0x15a4 sdbus - ok
13:38:06.0758 0x15a4 [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:38:06.0774 0x15a4 SDRSVC - ok
13:38:06.0805 0x15a4 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:38:06.0836 0x15a4 secdrv - ok
13:38:06.0883 0x15a4 [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon C:\Windows\system32\seclogon.dll
13:38:06.0883 0x15a4 seclogon - ok
13:38:06.0914 0x15a4 [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS C:\Windows\system32\sens.dll
13:38:06.0930 0x15a4 SENS - ok
13:38:06.0977 0x15a4 [ 68E44E331D46F0FB38F0863A84CD1A31, 0778D85B6869CE2610820DC9724360538BFE832426E898AEBC34E53D2AB4322B ] Serenum C:\Windows\system32\drivers\serenum.sys
13:38:07.0008 0x15a4 Serenum - ok
13:38:07.0039 0x15a4 [ C70D69A918B178D3C3B06339B40C2E1B, 40BEEECA4C797A3355F4B01C57C2763C33028F27826315062320789A496D0810 ] Serial C:\Windows\system32\drivers\serial.sys
13:38:07.0055 0x15a4 Serial - ok
13:38:07.0086 0x15a4 [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:38:07.0086 0x15a4 sermouse - ok
13:38:07.0179 0x15a4 [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv C:\Windows\system32\sessenv.dll
13:38:07.0195 0x15a4 SessionEnv - ok
13:38:07.0242 0x15a4 [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:38:07.0273 0x15a4 sffdisk - ok
13:38:07.0289 0x15a4 [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:38:07.0335 0x15a4 sffp_mmc - ok
13:38:07.0367 0x15a4 [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:38:07.0367 0x15a4 sffp_sd - ok
13:38:07.0413 0x15a4 [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:38:07.0476 0x15a4 sfloppy - ok
13:38:07.0616 0x15a4 [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:38:07.0647 0x15a4 SharedAccess - ok
13:38:07.0803 0x15a4 [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:38:07.0850 0x15a4 ShellHWDetection - ok
13:38:07.0897 0x15a4 [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:38:07.0897 0x15a4 sisagp - ok
13:38:07.0959 0x15a4 [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:38:08.0022 0x15a4 SiSRaid2 - ok
13:38:08.0053 0x15a4 [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:38:08.0100 0x15a4 SiSRaid4 - ok
13:38:08.0646 0x15a4 [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc C:\Windows\system32\SLsvc.exe
13:38:09.0878 0x15a4 slsvc - ok
13:38:09.0972 0x15a4 [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:38:09.0987 0x15a4 SLUINotify - ok
13:38:10.0019 0x15a4 [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:38:10.0034 0x15a4 Smb - ok
13:38:10.0097 0x15a4 [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:38:10.0097 0x15a4 SNMPTRAP - ok
13:38:10.0159 0x15a4 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr C:\Windows\system32\drivers\spldr.sys
13:38:10.0206 0x15a4 spldr - ok
13:38:10.0268 0x15a4 [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler C:\Windows\System32\spoolsv.exe
13:38:10.0284 0x15a4 Spooler - ok
13:38:10.0331 0x15a4 [ 5673E79BBB62A4C35B10D821FF1B4ACA, 26B809F1AC8B988E8DA86522A11DE03DF6FDBC09A09F3A359306DAAFBA4038FD ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
13:38:10.0409 0x15a4 SQLBrowser - ok
13:38:10.0471 0x15a4 [ 9263C8898732E2B890F7E954E7729AB7, DEBFD81E702893427972A6565A9AAA54A09B9F7F30CA9391011C6F7FB758A3F4 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
13:38:10.0533 0x15a4 SQLWriter - ok
13:38:10.0689 0x15a4 [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv C:\Windows\system32\DRIVERS\srv.sys
13:38:10.0721 0x15a4 srv - ok
13:38:10.0814 0x15a4 [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:38:10.0814 0x15a4 srv2 - ok
13:38:10.0892 0x15a4 [ 7605C0E1D01A08F3ECD743F38B834A44, 83A77E31004BCF83443F30EFC290E04BB1A2F332E8DFD614AB6E25B527C92299 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:38:10.0970 0x15a4 srvnet - ok
13:38:11.0095 0x15a4 [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:38:11.0142 0x15a4 SSDPSRV - ok
13:38:11.0189 0x15a4 [ A36EE93698802CD899F98BFD553D8185, 224CFED921EA230FF8025D259E34968FD2C0FD34BB3A918FB4B9B8BA42BEA5D3 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys
13:38:11.0189 0x15a4 ssmdrv - ok
13:38:11.0235 0x15a4 [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:38:11.0251 0x15a4 SstpSvc - ok
13:38:11.0391 0x15a4 [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc C:\Windows\System32\wiaservc.dll
13:38:11.0438 0x15a4 stisvc - ok
13:38:11.0485 0x15a4 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:38:11.0485 0x15a4 swenum - ok
13:38:11.0594 0x15a4 [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv C:\Windows\System32\swprv.dll
13:38:11.0625 0x15a4 swprv - ok
13:38:11.0672 0x15a4 [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:38:11.0672 0x15a4 Symc8xx - ok
13:38:11.0719 0x15a4 [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:38:11.0719 0x15a4 Sym_hi - ok
13:38:11.0750 0x15a4 [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:38:11.0766 0x15a4 Sym_u3 - ok
13:38:11.0891 0x15a4 [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain C:\Windows\system32\sysmain.dll
13:38:11.0953 0x15a4 SysMain - ok
13:38:12.0015 0x15a4 [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:38:12.0047 0x15a4 TabletInputService - ok
13:38:12.0125 0x15a4 [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:38:12.0140 0x15a4 TapiSrv - ok
13:38:12.0187 0x15a4 [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS C:\Windows\System32\tbssvc.dll
13:38:12.0203 0x15a4 TBS - ok
13:38:12.0327 0x15a4 [ A474879AFA4A596B3A531F3E69730DBF, 54D6810BC6A4C50D1E5F081E2499C7A409C9A0E3D03B5B12782457635BDA8A07 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:38:12.0468 0x15a4 Tcpip - ok
13:38:12.0671 0x15a4 [ A474879AFA4A596B3A531F3E69730DBF, 54D6810BC6A4C50D1E5F081E2499C7A409C9A0E3D03B5B12782457635BDA8A07 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:38:12.0717 0x15a4 Tcpip6 - ok
13:38:12.0795 0x15a4 [ 608C345A255D82A6289C2D468EB41FD7, 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:38:12.0795 0x15a4 tcpipreg - ok
13:38:12.0842 0x15a4 [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:38:12.0842 0x15a4 TDPIPE - ok
13:38:12.0858 0x15a4 [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:38:12.0873 0x15a4 TDTCP - ok
13:38:12.0936 0x15a4 [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:38:12.0936 0x15a4 tdx - ok
13:38:12.0983 0x15a4 [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:38:12.0983 0x15a4 TermDD - ok
13:38:13.0139 0x15a4 [ BB95DA09BEF6E7A131BFF3BA5032090D, BAF6997F8D944F85F0553957677866C7F22E72AA434BA45FFFB6CC41041070DC ] TermService C:\Windows\System32\termsrv.dll
13:38:13.0185 0x15a4 TermService - ok
13:38:13.0232 0x15a4 [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes C:\Windows\system32\shsvcs.dll
13:38:13.0248 0x15a4 Themes - ok
13:38:13.0279 0x15a4 [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER C:\Windows\system32\mmcss.dll
13:38:13.0279 0x15a4 THREADORDER - ok
13:38:13.0326 0x15a4 [ 3AFFF25EAE28188FA4ECD292658BE31B, 018CEC0AAA70042C6D23F582CDE818F7C7E7AB1876D4145566A179595605401C ] TpChoice C:\Windows\system32\DRIVERS\TpChoice.sys
13:38:13.0388 0x15a4 TpChoice - ok
13:38:13.0435 0x15a4 [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks C:\Windows\System32\trkwks.dll
13:38:13.0466 0x15a4 TrkWks - ok
13:38:13.0575 0x15a4 [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:38:13.0575 0x15a4 TrustedInstaller - ok
13:38:13.0638 0x15a4 [ DCF0F056A2E4F52287264F5AB29CF206, D9F770BD65AE4320A8C130DEA1D093AA4E37FCA573BBE6A59D6D045452EA711D ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:38:13.0669 0x15a4 tssecsrv - ok
13:38:13.0716 0x15a4 [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:38:13.0716 0x15a4 tunmp - ok
13:38:13.0763 0x15a4 [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:38:13.0763 0x15a4 tunnel - ok
13:38:13.0794 0x15a4 [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:38:13.0856 0x15a4 uagp35 - ok
13:38:13.0887 0x15a4 [ F763E070843EE2803DE1395002B42938, 0060F5D7AD091D7F0CC25C98AB9DD8258A9837958AFE845971CD04E29A6A8658 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
13:38:13.0981 0x15a4 UBHelper - ok
13:38:14.0090 0x15a4 [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:38:14.0121 0x15a4 udfs - ok
13:38:14.0199 0x15a4 [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:38:14.0199 0x15a4 UI0Detect - ok
13:38:14.0277 0x15a4 [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:38:14.0277 0x15a4 uliagpkx - ok
13:38:14.0355 0x15a4 [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:38:14.0371 0x15a4 uliahci - ok
13:38:14.0433 0x15a4 [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:38:14.0433 0x15a4 UlSata - ok
13:38:14.0480 0x15a4 [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:38:14.0480 0x15a4 ulsata2 - ok
13:38:14.0511 0x15a4 [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:38:14.0511 0x15a4 umbus - ok
13:38:14.0605 0x15a4 [ 8A66360F38F81E960E2367B428CBD5D9, 349A39BD63E1FF3C3D0249A3BE834D62F3EFC5EA4416269421AF03F10356D3E5 ] UmRdpService C:\Windows\System32\umrdp.dll
13:38:14.0636 0x15a4 UmRdpService - ok
13:38:14.0808 0x15a4 [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost C:\Windows\System32\upnphost.dll
13:38:14.0870 0x15a4 upnphost - ok
13:38:14.0933 0x15a4 [ CAF811AE4C147FFCD5B51750C7F09142, BD670CF88D8F932AD1C6BA91FB68A7204BC473657C6A057C92AFB84D164D393C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:38:14.0933 0x15a4 usbccgp - ok
13:38:14.0979 0x15a4 [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:38:15.0057 0x15a4 usbcir - ok
13:38:15.0120 0x15a4 [ 79E96C23A97CE7B8F14D310DA2DB0C9B, EB441D3B93965CD927E0C181031AD1082F59F9885BF35CABFDCA08C6C76B0DAF ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:38:15.0120 0x15a4 usbehci - ok
13:38:15.0167 0x15a4 [ EDCA5124B54BCF04E5C0538AA397A9C1, 1886B6758D2967051103B904BD23C8A2B89171F3BA48C328081069D049B34323 ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys
13:38:15.0167 0x15a4 usbfilter - ok
13:38:15.0245 0x15a4 [ 4673BBCB006AF60E7ABDDBE7A130BA42, 0B7DED0D887A3530AA5497FDBCB69389486FB9E2B6FAE3163E33713256D575BA ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:38:15.0260 0x15a4 usbhub - ok
13:38:15.0338 0x15a4 [ CE697FEE0D479290D89BEC80DFE793B7, D10F6BAD0467672CCE4F97C7F2E13437CE89AC754C895EAE05F0726B6DC617B1 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:38:15.0354 0x15a4 usbohci - ok
13:38:15.0447 0x15a4 [ E75C4B5269091D15A2E7DC0B6D35F2F5, B0A4141B69B66276890836DE98EB8BC790D35CE59FA503060593E8CC12AA106B ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:38:15.0447 0x15a4 usbprint - ok
13:38:15.0510 0x15a4 [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:38:15.0525 0x15a4 USBSTOR - ok
13:38:15.0572 0x15a4 [ 814D653EFC4D48BE3B04A307ECEFF56F, D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:38:15.0588 0x15a4 usbuhci - ok
13:38:15.0635 0x15a4 [ E67998E8F14CB0627A769F6530BCB352, 60982F168E9BF13954328C728F55F4D3ADDC572CACB65289B0E895A63DAA08C1 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:38:15.0759 0x15a4 usbvideo - ok
13:38:15.0806 0x15a4 [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms C:\Windows\System32\uxsms.dll
13:38:15.0822 0x15a4 UxSms - ok
13:38:15.0900 0x15a4 [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds C:\Windows\System32\vds.exe
13:38:15.0931 0x15a4 vds - ok
13:38:15.0993 0x15a4 [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:38:16.0071 0x15a4 vga - ok
13:38:16.0103 0x15a4 [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave C:\Windows\System32\drivers\vga.sys
13:38:16.0103 0x15a4 VgaSave - ok
13:38:16.0118 0x15a4 [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:38:16.0181 0x15a4 viaagp - ok
13:38:16.0227 0x15a4 [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:38:16.0274 0x15a4 ViaC7 - ok
13:38:16.0321 0x15a4 [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide C:\Windows\system32\drivers\viaide.sys
13:38:16.0321 0x15a4 viaide - ok
13:38:16.0368 0x15a4 [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:38:16.0368 0x15a4 volmgr - ok
13:38:16.0508 0x15a4 [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:38:16.0586 0x15a4 volmgrx - ok
13:38:16.0711 0x15a4 [ 147281C01FCB1DF9252DE2A10D5E7093, DF5DCF6FD472F21863DC10B62F7647420B9686607857D08286B618D585E50219 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:38:16.0742 0x15a4 volsnap - ok
13:38:16.0789 0x15a4 [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:38:16.0805 0x15a4 vsmraid - ok
13:38:17.0085 0x15a4 [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS C:\Windows\system32\vssvc.exe
13:38:17.0148 0x15a4 VSS - ok
13:38:17.0304 0x15a4 [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time C:\Windows\system32\w32time.dll
13:38:17.0366 0x15a4 W32Time - ok
13:38:17.0429 0x15a4 [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:38:17.0429 0x15a4 WacomPen - ok
13:38:17.0475 0x15a4 [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:38:17.0553 0x15a4 Wanarp - ok
13:38:17.0553 0x15a4 [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:38:17.0569 0x15a4 Wanarpv6 - ok
13:38:17.0756 0x15a4 [ 20B23332885DFB93FE0185362EE811E9, 67B8026E8285FEB6E3939DEEE4E0F2FD0FA0917E0ED0F1FAE56B7841AF74C8F8 ] wbengine C:\Windows\system32\wbengine.exe
13:38:17.0834 0x15a4 wbengine - ok
13:38:17.0943 0x15a4 [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:38:18.0006 0x15a4 wcncsvc - ok
13:38:18.0068 0x15a4 [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:38:18.0084 0x15a4 WcsPlugInService - ok
13:38:18.0115 0x15a4 [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd C:\Windows\system32\drivers\wd.sys
13:38:18.0224 0x15a4 Wd - ok
13:38:18.0474 0x15a4 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96, 6A6EFFDB538DE1E201058A00F3E056F1256E92EED943FBFBCE28E54BE751E33D ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:38:18.0583 0x15a4 Wdf01000 - ok
13:38:18.0692 0x15a4 [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:38:18.0708 0x15a4 WdiServiceHost - ok
13:38:18.0723 0x15a4 [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:38:18.0739 0x15a4 WdiSystemHost - ok
13:38:18.0848 0x15a4 [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient C:\Windows\System32\webclnt.dll
13:38:18.0864 0x15a4 WebClient - ok
13:38:18.0926 0x15a4 [ AE3736E7E8892241C23E4EBBB7453B60, 0F998116CC07CD719CB237EAE53BB16B2EDD6973828B9C1055EB981AEA0453D1 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:38:18.0942 0x15a4 Wecsvc - ok
13:38:18.0989 0x15a4 [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:38:18.0989 0x15a4 wercplsupport - ok
13:38:19.0051 0x15a4 [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc C:\Windows\System32\WerSvc.dll
13:38:19.0082 0x15a4 WerSvc - ok
13:38:19.0223 0x15a4 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA, 711DD957AF98F1B835ECE0FEBCCF8FCC7763F1DAA232F1C9E80DE6DA123C7F33 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
13:38:19.0269 0x15a4 winachsf - ok
13:38:19.0472 0x15a4 [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:38:19.0566 0x15a4 WinDefend - ok
13:38:19.0597 0x15a4 WinHttpAutoProxySvc - ok
13:38:19.0691 0x1030 Object send P2P result: false
13:38:19.0722 0x1030 Object required for P2P: [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m
13:38:19.0862 0x15a4 [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:38:19.0878 0x15a4 Winmgmt - ok
13:38:20.0252 0x15a4 [ 7CFE68BDC065E55AA5E8421607037511, C2CE76D52AD4E31FC4216E94457DC16ABF65A5F3E883F0BD97AD387FB7574533 ] WinRM C:\Windows\system32\WsmSvc.dll
13:38:20.0361 0x15a4 WinRM - ok
13:38:20.0455 0x15a4 WisINT15 - ok
13:38:20.0564 0x15a4 [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:38:20.0627 0x15a4 Wlansvc - ok
13:38:20.0673 0x15a4 [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:38:20.0673 0x15a4 WmiAcpi - ok
13:38:20.0720 0x15a4 [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:38:20.0736 0x15a4 wmiApSrv - ok
13:38:20.0939 0x15a4 [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:38:20.0985 0x15a4 WMPNetworkSvc - ok
13:38:21.0079 0x15a4 [ 396D406292B0CD26E3504FFE82784702, 5F9015BB515AC13D4DFE8F4B532352CF2C5B61DEFD3D0D61BCD82C781D36E7AF ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:38:21.0079 0x15a4 WPDBusEnum - ok
13:38:21.0141 0x15a4 [ 0CEC23084B51B8288099EB710224E955, E1AAB1E08E1745313D0A149A645AA878148D2DBE5CCC23C4ECCFC5003945C22B ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:38:21.0157 0x15a4 WpdUsb - ok
13:38:21.0547 0x15a4 [ DCF3E3EDF5109EE8BC02FE6E1F045795, 4B8E14B1CFB095982D34DAEC336114F5039D7793080FB787DC95A63B6B945DD0 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:38:21.0625 0x15a4 WPFFontCache_v0400 - ok
13:38:21.0687 0x15a4 [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:38:21.0687 0x15a4 ws2ifsl - ok
13:38:21.0750 0x15a4 [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc C:\Windows\system32\wscsvc.dll
13:38:21.0765 0x15a4 wscsvc - ok
13:38:21.0765 0x15a4 WSearch - ok
13:38:22.0405 0x15a4 [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
13:38:22.0873 0x15a4 wuauserv - ok
13:38:22.0951 0x15a4 [ AC13CB789D93412106B0FB6C7EB2BCB6, 8F5B0BD0CBBAB182A400F8994D4727BC0C978D749B6429A2D41B412AE97428B6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:38:22.0967 0x15a4 WUDFRd - ok
13:38:23.0029 0x15a4 [ 575A4190D989F64732119E4114045A4F, 373C344B106AFDB1E6125A21DFE28CA6CFC77FA87FE904656A4F209DB2ED69C7 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:38:23.0045 0x15a4 wudfsvc - ok
13:38:23.0107 0x15a4 [ 88AF537264F2B818DA15479CEEAF5D7C, E0F95D6448FFB77351BB63ED444238F891B16748FD09F8BCCA23BEC4E341A96B ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
13:38:23.0154 0x15a4 XAudio - ok
13:38:23.0279 0x15a4 [ 15A317674A08DF26BE65164D959E9203, 6EEE0D1711F37936D157651E265A65137BCBFBDA17F066C844BAA0D53558F86A ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
13:38:23.0310 0x15a4 XAudioService - ok
13:38:23.0341 0x15a4 ZTEusbmdm6k - ok
13:38:23.0341 0x15a4 ZTEusbnmea - ok
13:38:23.0372 0x15a4 ZTEusbser6k - ok
13:38:23.0388 0x15a4 ================ Scan global ===============================
13:38:23.0466 0x15a4 [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll
13:38:23.0544 0x15a4 [ 5DF01708D214FDC0075AD197F1889557, 7E9ABB5C1F873AD3CE4FDB66CA6E2278F966F238CB4E78994D6A2014B10BCAC4 ] C:\Windows\system32\winsrv.dll
13:38:23.0669 0x15a4 [ 5DF01708D214FDC0075AD197F1889557, 7E9ABB5C1F873AD3CE4FDB66CA6E2278F966F238CB4E78994D6A2014B10BCAC4 ] C:\Windows\system32\winsrv.dll
13:38:23.0809 0x15a4 [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe
13:38:23.0840 0x15a4 [ Global ] - ok
13:38:23.0840 0x15a4 ================ Scan MBR ==================================
13:38:23.0871 0x15a4 [ 6FC6F9186C07BCA94E140F63BFE6E9B4 ] \Device\Harddisk0\DR0
13:38:30.0189 0x15a4 \Device\Harddisk0\DR0 - ok
13:38:30.0189 0x15a4 ================ Scan VBR ==================================
13:38:30.0205 0x15a4 [ BB8E108A58BB6DDC1E05B35E336686C0 ] \Device\Harddisk0\DR0\Partition1
13:38:30.0283 0x15a4 \Device\Harddisk0\DR0\Partition1 - ok
13:38:30.0314 0x15a4 [ 028E40081BAF8911F0D2B2D9B25269D9 ] \Device\Harddisk0\DR0\Partition2
13:38:30.0439 0x15a4 \Device\Harddisk0\DR0\Partition2 - ok
13:38:30.0439 0x15a4 ================ Scan generic autorun ======================
13:38:30.0486 0x15a4 [ 6882D187F65ECA79110848A68FDEB2BF, 1BE59945F6D5040E9675DC31C27AD230D4C2C02B84BD4E16AB459D04D9B9E7B4 ] C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
13:38:30.0486 0x15a4 BkupTray - ok
13:38:30.0548 0x15a4 [ D594369762386D744BE48EC4768BF849, 6E6D9B879930F03A963545B8C309B2A39A254C2E0F7ECEA5635E4BE272F1D03E ] C:\Program Files\Apoint2K\Apoint.exe
13:38:30.0564 0x15a4 Apoint - ok
13:38:31.0250 0x15a4 [ BEBB6AB834C32E1E05735C6FE7F3859E, 86E2DA8548BB8E4AFFF3F543FCED5096DF58E8721B352821A354DBEB81D59232 ] C:\Windows\RtHDVCpl.exe
13:38:31.0609 0x15a4 RtHDVCpl - ok
13:38:31.0749 0x15a4 [ 2F2DF068BED6E62E4C007DF7446B4F19, 96FE78E2B8BD067B7378ECDF1E74939C71EFFBF09B2C184361650DBF4ED0FCC3 ] C:\Windows\PLFSetI.exe
13:38:31.0749 0x15a4 PLFSetI - ok
13:38:31.0937 0x15a4 [ 669F8E48DFF76902CB77A0A4673CB2CE, 8CDD984033D8B6943A965889EC5CB81BE50333520FD7B0909E001DABFE597AB7 ] C:\PROGRA~1\LAUNCH~1\LManager.exe
13:38:32.0015 0x15a4 LManager - ok
13:38:32.0264 0x15a4 [ 5ECD387396379945400EECDFF982898B, 6A1F6E346FF8A7160866B0343324B44ACE531A49EF8CDBBDCC2EE2DAFD9920DE ] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
13:38:32.0280 0x15a4 ePower_DMC - ok
13:38:32.0467 0x15a4 [ 38D198A2DD54A67120040566A38103BA, 01604BD91A5B2C0DDC7B52036511F8219952626716E75979D8464F2C56BA0114 ] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
13:38:32.0483 0x15a4 GrooveMonitor - ok
13:38:32.0763 0x15a4 [ A162B967A88BF374A81E01EF6E7A2655, 3616D7DDF72964EB1C7C40E45CCEFD7116252607068AEB9FB093F20064FB5BA2 ] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
13:38:32.0795 0x15a4 avgnt - ok
13:38:32.0982 0x15a4 [ BB10E34B162FBEAE5636474A79026A0D, 700629C7497ED01E5B7DF99F0D8F56FF30BBA067ED65AC7A0D77B3765C596ECB ] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
13:38:32.0982 0x15a4 Avira Systray - ok
13:38:33.0107 0x15a4 GoogleDriveSync - ok
13:38:33.0746 0x0fc8 Object required for P2P: [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx
13:38:33.0887 0x01f8 Object required for P2P: [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ
13:38:34.0604 0x1030 Object send P2P result: false
13:38:34.0604 0x1030 Object required for P2P: [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320
13:38:34.0604 0x1030 Object send P2P result: false
13:38:34.0604 0x1030 Object required for P2P: [ 5D2888182FB46632511ACEE92FDAD522 ] arc
13:38:34.0620 0x1030 Object send P2P result: false
13:38:35.0135 0x15a4 [ 9A1F3AEA8D61AA67D90F1B336C00984E, CE652BB13364BAA585340CD44E884F51BA314056B9E8221D34848C0B0C52F19A ] C:\Program Files\CCleaner\CCleaner.exe
13:38:35.0712 0x15a4 CCleaner Monitoring - ok
13:38:35.0743 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:36.0757 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:37.0771 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:38.0785 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:39.0799 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:40.0813 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:41.0827 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:42.0841 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:43.0855 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:44.0869 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:45.0883 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:46.0897 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:47.0911 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:48.0925 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:49.0939 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:50.0953 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:51.0967 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:52.0981 0x15a4 Waiting for KSN requests completion. In queue: 348
13:38:53.0777 0x0fc8 Object send P2P result: false
13:38:53.0777 0x0fc8 Object required for P2P: [ 587253E09325E6BF226B299774B728A9 ] vsmraid
13:38:53.0777 0x0fc8 Object send P2P result: false
13:38:53.0777 0x0fc8 Object required for P2P: [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc
13:38:53.0792 0x0fc8 Object send P2P result: false
13:38:53.0792 0x0fc8 Object required for P2P: [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400
13:38:53.0823 0x0fc8 Object send P2P result: false
13:38:53.0823 0x0fc8 Object required for P2P: [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl
13:38:53.0823 0x0fc8 Object send P2P result: false
13:38:53.0901 0x01f8 Object send P2P result: false
13:38:53.0901 0x01f8 Object required for P2P: [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk
13:38:53.0901 0x01f8 Object send P2P result: false
13:38:53.0917 0x01f8 Object required for P2P: [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV
13:38:53.0917 0x01f8 Object send P2P result: false
13:38:53.0917 0x01f8 Object required for P2P: [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid
13:38:53.0917 0x01f8 Object send P2P result: false
13:38:53.0933 0x01f8 Object required for P2P: [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid
13:38:53.0933 0x01f8 Object send P2P result: false
13:38:53.0933 0x01f8 Object required for P2P: [ A3F4391DFDF2F9E9FE4EAD193265A5AD ] MBAMProtector
13:38:53.0933 0x01f8 Object send P2P result: false
13:38:53.0948 0x01f8 Object required for P2P: [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent
13:38:53.0948 0x01f8 Object send P2P result: false
13:38:53.0948 0x01f8 Object required for P2P: [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp
13:38:53.0964 0x01f8 Object send P2P result: false
13:38:53.0964 0x01f8 Object required for P2P: [ 941DC1D19E7E8620F40BBC206981EFDB ] pci
13:38:53.0979 0x01f8 Object send P2P result: false
13:38:53.0979 0x01f8 Object required for P2P: [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent
13:38:53.0979 0x01f8 Object send P2P result: false
13:38:53.0979 0x01f8 Object required for P2P: [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched
13:38:53.0995 0x15a4 Waiting for KSN requests completion. In queue: 104
13:38:53.0995 0x01f8 Object send P2P result: false
13:38:53.0995 0x01f8 Object required for P2P: [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx
13:38:53.0995 0x01f8 Object send P2P result: false
13:38:53.0995 0x01f8 Object required for P2P: [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr
13:38:54.0011 0x01f8 Object send P2P result: false
13:38:54.0011 0x01f8 Object required for P2P: [ 3CE8F073A557E172B330109436984E30 ] sbp2port
13:38:54.0011 0x01f8 Object send P2P result: false
13:38:54.0011 0x01f8 Object required for P2P: [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2
13:38:54.0026 0x01f8 Object send P2P result: false
13:38:54.0026 0x01f8 Object required for P2P: [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc
13:38:54.0042 0x01f8 Object send P2P result: false
13:38:54.0042 0x01f8 Object required for P2P: [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi
13:38:54.0042 0x01f8 Object send P2P result: false
13:38:54.0042 0x01f8 Object required for P2P: [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain
13:38:54.0073 0x01f8 Object send P2P result: false
13:38:54.0073 0x01f8 Object required for P2P: [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv
13:38:54.0073 0x01f8 Object send P2P result: false
13:38:54.0073 0x01f8 Object required for P2P: [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP
13:38:54.0089 0x01f8 Object send P2P result: false
13:38:55.0040 0x15a4 AV detected via SS2: Avira Desktop, C:\Program Files\Avira\AntiVir Desktop\wsctool.exe ( 14.0.7.440 ), 0x40000 ( disabled : updated )
13:38:55.0056 0x15a4 Win FW state via NFP2: disabled
13:38:55.0056 0x15a4 ============================================================
13:38:55.0056 0x15a4 Scan finished
13:38:55.0056 0x15a4 ============================================================
13:38:55.0087 0x10d8 Detected object count: 0
13:38:55.0087 0x10d8 Actual detected object count: 0
13:39:50.0483 0x10b8 Deinitialize success

vcelin
nováček
Příspěvky: 24
Registrován: únor 15
Pohlaví: Žena
Stav:
Offline

Re: Policejní vir??

Příspěvekod vcelin » 10 úno 2015 14:24

Tady ještě OTL, nakonec jsem to stihla mezi hodinama
OTL logfile created on: 10.2.2015 13:58:02 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Eva\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,75 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 67,85% Memory free
5,73 Gb Paging File | 4,56 Gb Available in Paging File | 79,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,17 Gb Total Space | 29,96 Gb Free Space | 20,78% Space Free | Partition Type: NTFS
Drive D: | 144,15 Gb Total Space | 4,58 Gb Free Space | 3,18% Space Free | Partition Type: NTFS

Computer Name: EVA-PC | User Name: Eva | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Eva\AppData\Local\temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Users\Eva\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
PRC - C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe (Software602 a.s.)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
PRC - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Acer\Mobility Center\MobilityService.exe ()
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Apoint2K\Hidfind.exe (Alps Electric Co., Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_ssl.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._gdi_.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\PyWinTypes27.dll ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_multiprocessing.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\hashobjs_ext.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._controls_.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._windows_.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_hashlib.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\unicodedata.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\pyexpat.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32inet.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32pdh.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32pipe.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32event.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\select.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._core_.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\windows._lib_cacheinvalidation.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\pythoncom27.dll ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32com.shell.shell.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32gui.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_elementtree.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32file.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32security.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32api.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_ctypes.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._animate.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._html2.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\_socket.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32ts.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32profile.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._misc_.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32crypt.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\wx._wizard.pyd ()
MOD - C:\Users\Eva\AppData\Local\temp\_MEI31602\win32process.pyd ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e515919524c6be56f55ad12fbdd23c19\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\b0be4ac8da47fbf783dabd1505e6c55e\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\07e39e61fd6133a92333a2c98f2ffeb7\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\35f20a6b69d5c7033b4b1873456e5074\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\34942db56010e4225825bfae8a27559f\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3aac7b97549d4ccf0c7dca3d1777f9b4\mscorlib.ni.dll ()
MOD - C:\Program Files\CCleaner\Lang\lang-1029.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\840f9b4d51622f9f29888aae168a196c\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\dc31b22f78cb510bf470f0ab5ef65816\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\02c1363d5beb2ae5c5722bc8f6c5b77a\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\0df91adfb9c0e51b7b967d61e8151b78\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\b9f7f5b0b28dd57cb5400c437c388545\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\b028b6680f5a3b315320a5bf7b659518\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ce480f313eb8be9a3a4dd6d7902325\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\ff20e15edfa14ce628b0502173347062\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\19f85a4f6faaeb87a9055ccf23a9f8b7\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\6e6f321459aa81611031cfb582e77cc6\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b61b31d1f518e9663fc204e7de21215a\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\b11b842599889fe730da493d0c5e1857\System.Data.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\15f169fe8bb8f4cf564093b812c46959\System.ComponentModel.Composition.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\2250ddb1626087da27fb00f46a679ff5\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7cc17b90932adaad5651ceb526cade44\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\618e6d3cd8824d6d72ae1767acaa1078\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f3e016a2e799cfe233b13d88e90c0e0b\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ca8307311e87b234b2faa5ee08332722\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\53591520988a6ee49924e1efc911df30\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\0d4cdd1b911d6e28b4fd5c43ab39f7ea\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\3154b66d01dcd674b256e03d5f359fac\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\5a8bf6ab1a6ba60e7355fa4cc61fd0c5\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\6bff4a4db9703b01e7495f5f9e0f2baf\System.Numerics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\74353039393f68f4c068cc37f759e5be\mscorlib.ni.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Windows\PLFSetI.exe ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3006.0__4df5dcab8860d239\Framework.Utility.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3006.0__3036420f80dd6947\Framework.Library.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3006.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll ()
MOD - C:\Windows\System32\SysHook.dll ()
MOD - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\WinRAR\rarlng.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Avira.OE.ServiceHost) -- C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (602XML Updater) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe (Software602 a.s.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (ETService) -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe ()
SRV - (PSI_SVC_2) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (o2flash) -- C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (ZTEusbser6k) -- system32\DRIVERS\ZTEusbser6k.sys File not found
DRV - (ZTEusbnmea) -- system32\DRIVERS\ZTEusbnmea.sys File not found
DRV - (ZTEusbmdm6k) -- system32\DRIVERS\ZTEusbmdm6k.sys File not found
DRV - (WisINT15) -- C:\Elements\1stboot\WisINT15.SYS File not found
DRV - (SANDRA) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP5\WNt500x86\Sandra.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (massfilter) -- system32\drivers\massfilter.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (MBAMWebAccessControl) -- C:\Windows\System32\drivers\mwac.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTHDMIAzAudService) -- C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (O2SDRDR) -- C:\Windows\System32\drivers\o2sd.sys (O2Micro )
DRV - (ahcix86s) -- C:\Windows\System32\drivers\ahcix86s.sys (AMD Technologies Inc.)
DRV - (usbfilter) -- C:\Windows\System32\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (O2MDRDR) -- C:\Windows\System32\drivers\o2media.sys (O2Micro )
DRV - (int15) -- C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (TpChoice) -- C:\Windows\System32\drivers\TpChoice.sys (Alps Electric Co., Ltd.)
DRV - (regi) -- C:\Windows\System32\drivers\regi.sys (InterVideo)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D4D9186-AE9B-40B5-89D4-BE4FDF138A94}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACAW_csCZ345CZ345
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_csCZ345CZ345
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:home"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.09.24 06:51:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext [2010.01.07 20:41:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{55A8EC97-6AF6-442c-877F-11C51DBD162D}: C:\Program Files\Tomabo\MP4 Player\YTVD_FF.xpi [2013.05.13 11:09:18 | 000,009,989 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.12.07 16:45:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2015.01.31 13:47:12 | 000,000,000 | ---D | M]

[2015.02.04 20:57:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva\AppData\Roaming\Mozilla\Extensions
[2015.02.09 23:35:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eva\AppData\Roaming\Mozilla\Firefox\Profiles\sx948fvr.default\extensions
[2015.02.09 14:29:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.12.07 16:45:40 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.10.12 19:03:09 | 000,119,808 | ---- | M] (Google) -- C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
[2007.04.10 17:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2009.07.17 09:40:12 | 000,704,512 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2014.12.03 19:06:20 | 000,188,304 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2010.01.07 20:40:59 | 000,140,864 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2010.01.07 20:41:15 | 000,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2010.01.07 20:40:48 | 000,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2013.12.07 16:45:37 | 000,003,413 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2010.10.12 19:03:11 | 000,002,020 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
[2013.12.07 16:45:37 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2013.12.07 16:45:37 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2013.07.05 21:51:37 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2013.12.07 16:45:37 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2013.12.07 16:45:37 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2013.12.07 16:45:37 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\Eva\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2015.02.10 09:51:20 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (GdfrDUEn Class) - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll (TODO: <Company name>)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BkupTray] C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Download video on this page - C:\Program Files\Tomabo\MP4 Player\YTVD_IE.dll (Tomabo)
O8 - Extra context menu item: Download video this links to - C:\Program Files\Tomabo\MP4 Player\YTVD_IE.dll (Tomabo)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html File not found
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Společnost Microsoft)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 128 hostů