Pomalý notebook Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod jaro3 » 02 úno 2015 10:26

Co zoek??

Vlož nový log z HJT + info o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 02 úno 2015 19:46

Zoek a další programy jsem ještě neprojížděl. Potřebuji vědět kdy mám zase zapnout antivir a firewall.
Jiří

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod jaro3 » 03 úno 2015 10:28

Jen před použitím těch nástrojů.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 22 úno 2015 23:06

Dobrý den.
Provedl jsem čištění pomocí RogueKiller, Zoek, TDSSKiller a zasílám logy.

RogueKiller V10.1.1.0 [Dec 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno : Normální režim
Uživatel : Jiří [Práva správce]
Mód : Smazat -- Datum : 02/01/2015 22:24:11

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 16 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Skytel : Skytel.exe [7] -> Smazáno
[PUM.HomePage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://cs.intl.acer.yahoo.com -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Internet Explorer\Main | Start Page : www.bing.com -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR -> Nahrazeno (http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6F039EFA-D312-45E8-90D9-4513515FFD2D} | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6F039EFA-D312-45E8-90D9-4513515FFD2D} | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{6F039EFA-D312-45E8-90D9-4513515FFD2D} | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{6F039EFA-D312-45E8-90D9-4513515FFD2D} | DhcpNameServer : 109.238.208.18 109.238.208.19 -> Nahrazeno ()
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nahrazeno (0)
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1 -> Nahrazeno (0)

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 2 (Driver: Nahrán) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\system32\drivers\irenum.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\CdRom0 : \Driver\NTIDrvr @ Unknown (\SystemRoot\system32\DRIVERS\nscirda.sys)

¤¤¤ Webové prohlížeče : 3 ¤¤¤
[IE:Addon] System : Acer eDataSecurity Management [{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}] -> Smazáno
[IE:Addon] System : Canon Easy-WebPrint EX [{759D9886-0C6F-4498-BAB6-4A5F47C6C72F}] -> Smazáno
[PUM.HomePage][FIREFX:Config] zayzvpsa.default : user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668"); -> Nahrazeno (about:home)

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS543216L9A300 ATA Device +++++
--- User ---
[MBR] e13c88a46374895a35d56e44569115e7
[BSP] c4f947b1e0e02fee12062a270984c703 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 10000 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 20482048 | Size: 71317 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 166539264 | Size: 71308 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_01042015_140930.log - RKreport_SCN_02012015_221656.log



Zoek.exe v5.0.0.0 Updated 22-February-2015
Tool run by Jiýˇ on ne 22.02.2015 at 21:34:02,92.
Microsoft® Windows Vista™ Home Basic 6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\JI12FF~1\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

22.2.2015 21:39:59 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Program Files\Trusted Software deleted successfully
C:\Program Files\Unknown File Assistant deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} deleted successfully
HKEY_USERS\S-1-5-21-3002898266-1157536913-712248487-1004\Software\Mozilla\Firefox\extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\JI12FF~1\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default\prefs.js:
user_pref("browser.search.defaulturl", "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
user_pref("browser.search.useDBForOrder", false);

Added to C:\Users\JI12FF~1\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\Program Files\Trusted Software not found
C:\Program Files\Unknown File Assistant not found
C:\Program Files\Uninstall Information deleted
C:\Program Files\ZipItFree deleted
C:\Program Files\PatchBeam deleted
C:\Windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\JI12FF~1\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default\Invalidprefs.js deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\JI12FF~1\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.01.2015 14:03]

==== Firefox Extensions ======================

ProfilePath: C:\Users\JI12FF~1\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Undetermined - wrc@avast.com

AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Chromium Look ======================

Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115)

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[13.12.2014 20:10]
jfmjfhklogoienhpfnppmbcbjfjnkonk - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx[03.06.2012 20:50]

YouTube - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
RealPlayer HTML5Video Downloader Extension - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk
Skype Click to Call - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

==== Chromium Startpages ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com",


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://cs.intl.acer.yahoo.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\JI12FF~1\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\JI12FF~1\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 deleted successfully

==== Empty IE Cache ======================

C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\JI12FF~1\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\JI12FF~1\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BXT8WQPN will be deleted at reboot
C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFYV1DT2 will be deleted at reboot
C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZI6ZHO21 will be deleted at reboot
C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\JI12FF~1\AppData\Local\Mozilla\Firefox\Profiles\zayzvpsa.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\JI12FF~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=11 folders=5 1287132 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\JI12FF~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\JI12FF~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BXT8WQPN" not found
"C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WFYV1DT2" not found
"C:\Users\JI12FF~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZI6ZHO21" not found

==== EOF on ne 22.02.2015 at 22:12:27,27 ======================




Log z TDSSKiller zašlu v další odpovědi. Má 30 stran.

Jiří Štěrba

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 22 úno 2015 23:13

Doplňuji log z TDSSKiller.

22:27:27.0243 0x16f0 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
22:27:56.0493 0x16f0 ============================================================
22:27:56.0493 0x16f0 Current date / time: 2015/02/22 22:27:56.0493
22:27:56.0493 0x16f0 SystemInfo:
22:27:56.0493 0x16f0
22:27:56.0493 0x16f0 OS Version: 6.0.6002 ServicePack: 2.0
22:27:56.0493 0x16f0 Product type: Workstation
22:27:56.0493 0x16f0 ComputerName: MUDROCH11-PC
22:27:56.0493 0x16f0 UserName: Jiří
22:27:56.0493 0x16f0 Windows directory: C:\Windows
22:27:56.0493 0x16f0 System windows directory: C:\Windows
22:27:56.0493 0x16f0 Processor architecture: Intel x86
22:27:56.0493 0x16f0 Number of processors: 2
22:27:56.0493 0x16f0 Page size: 0x1000
22:27:56.0493 0x16f0 Boot type: Normal boot
22:27:56.0493 0x16f0 ============================================================
22:27:58.0271 0x16f0 KLMD registered as C:\Windows\system32\drivers\14839421.sys
22:27:58.0396 0x16f0 System UUID: {BAFAD27A-6769-0DAE-DFFE-1EED98A1BB6D}
22:27:59.0098 0x16f0 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:27:59.0098 0x16f0 ============================================================
22:27:59.0098 0x16f0 \Device\Harddisk0\DR0:
22:27:59.0098 0x16f0 MBR partitions:
22:27:59.0098 0x16f0 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1388800, BlocksNum 0x8B4A800
22:27:59.0098 0x16f0 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x9ED3000, BlocksNum 0x8B46000
22:27:59.0098 0x16f0 ============================================================
22:27:59.0145 0x16f0 C: <-> \Device\Harddisk0\DR0\Partition1
22:27:59.0207 0x16f0 D: <-> \Device\Harddisk0\DR0\Partition2
22:27:59.0207 0x16f0 ============================================================
22:27:59.0207 0x16f0 Initialize success
22:27:59.0207 0x16f0 ============================================================
22:29:02.0434 0x0b58 ============================================================
22:29:02.0434 0x0b58 Scan started
22:29:02.0434 0x0b58 Mode: Manual;
22:29:02.0434 0x0b58 ============================================================
22:29:02.0434 0x0b58 KSN ping started
22:29:04.0805 0x0b58 KSN ping finished: true
22:29:05.0647 0x0b58 ================ Scan system memory ========================
22:29:05.0647 0x0b58 System memory - ok
22:29:05.0647 0x0b58 ================ Scan services =============================
22:29:05.0881 0x0b58 [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI C:\Windows\system32\drivers\acpi.sys
22:29:05.0897 0x0b58 ACPI - ok
22:29:06.0053 0x0b58 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:29:06.0053 0x0b58 AdobeARMservice - ok
22:29:06.0162 0x0b58 [ 080255CDCB878813B481B8C348D47D8E, 75808821FBC732D0504795B8F85852E4C01D3B412989A1E597E1295CFF7B7A45 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:29:06.0162 0x0b58 AdobeFlashPlayerUpdateSvc - ok
22:29:06.0225 0x0b58 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
22:29:06.0240 0x0b58 adp94xx - ok
22:29:06.0271 0x0b58 [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci C:\Windows\system32\drivers\adpahci.sys
22:29:06.0287 0x0b58 adpahci - ok
22:29:06.0318 0x0b58 [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
22:29:06.0318 0x0b58 adpu160m - ok
22:29:06.0349 0x0b58 [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
22:29:06.0349 0x0b58 adpu320 - ok
22:29:06.0396 0x0b58 [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:29:06.0396 0x0b58 AeLookupSvc - ok
22:29:06.0474 0x0b58 [ F5272A105F59A7B3B345D9D6D87DA7AD, 9E84776994D04240BF2537330DBB555EDE16DFCFC59DEDCBA05A44ED7F70BEFA ] AFD C:\Windows\system32\drivers\afd.sys
22:29:06.0474 0x0b58 AFD - ok
22:29:06.0521 0x0b58 [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440 C:\Windows\system32\drivers\agp440.sys
22:29:06.0521 0x0b58 agp440 - ok
22:29:06.0568 0x0b58 [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
22:29:06.0583 0x0b58 aic78xx - ok
22:29:06.0599 0x0b58 [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG C:\Windows\System32\alg.exe
22:29:06.0599 0x0b58 ALG - ok
22:29:06.0615 0x0b58 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide C:\Windows\system32\drivers\aliide.sys
22:29:06.0615 0x0b58 aliide - ok
22:29:06.0646 0x0b58 [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp C:\Windows\system32\drivers\amdagp.sys
22:29:06.0646 0x0b58 amdagp - ok
22:29:06.0661 0x0b58 [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide C:\Windows\system32\drivers\amdide.sys
22:29:06.0661 0x0b58 amdide - ok
22:29:06.0693 0x0b58 [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
22:29:06.0693 0x0b58 AmdK7 - ok
22:29:06.0724 0x0b58 [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
22:29:06.0724 0x0b58 AmdK8 - ok
22:29:06.0786 0x0b58 [ 8F7D200717A58E9800D391F4C2101577, F07CF0F5636F46D8F3D5133284943E991E8739E5A644BCA5F18BB896B374620D ] Appinfo C:\Windows\System32\appinfo.dll
22:29:06.0786 0x0b58 Appinfo - ok
22:29:06.0880 0x0b58 [ 20F6F19FE9E753F2780DC2FA083AD597, 5106F0F9BA8A7DE49260A9B13BF8EC45ACA6A166FA8B10B4F69C3BB54F6840A1 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
22:29:06.0880 0x0b58 Apple Mobile Device - ok
22:29:06.0927 0x0b58 [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc C:\Windows\system32\drivers\arc.sys
22:29:06.0927 0x0b58 arc - ok
22:29:06.0958 0x0b58 [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas C:\Windows\system32\drivers\arcsas.sys
22:29:06.0958 0x0b58 arcsas - ok
22:29:07.0083 0x0b58 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
22:29:07.0083 0x0b58 aspnet_state - ok
22:29:07.0129 0x0b58 [ 9D23DE88C3B18BA87CD4587177CA6CEA, 46DBB867FC73E30320852F744F38B66906DD5B96C4EBB03F504CF33E867A8470 ] aswHwid C:\Windows\system32\drivers\aswHwid.sys
22:29:07.0129 0x0b58 aswHwid - ok
22:29:07.0161 0x0b58 [ 73A9014A9C4B19AA093DA05ED4246E27, F03C8433EB00229490BCD293CC97EF72452E156212D56C24BBA95C8E1B207D1A ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
22:29:07.0176 0x0b58 aswMonFlt - ok
22:29:07.0192 0x0b58 [ 0926775B8C3B32EE99921CCB0F85378E, 21A46B124B3E9F2569030E2DF591858B85AA640DDBB5C994B5C00A1E78C9EF67 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
22:29:07.0207 0x0b58 aswRdr - ok
22:29:07.0239 0x0b58 [ 6544697080421E62E97AAFBD0A8AA391, BB3F492BF828A147B82FDD1FC9EB9867D96DE0481554A59745D41C6BAB551700 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
22:29:07.0239 0x0b58 aswRvrt - ok
22:29:07.0317 0x0b58 [ E73CBE3420ECFA8FF7D0467E170E335D, B994342C92AE9167908B8CA3D03DC278E919C7073512461AFFD4C25E8D2D8D66 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
22:29:07.0348 0x0b58 aswSnx - ok
22:29:07.0379 0x0b58 [ 1624D5AD126B8AFE2B2E85E5B8364EB6, AB97A74C1CA9921F7753D98516D7E11750D5D3ACD143C83273B0B295625440A0 ] aswSP C:\Windows\system32\drivers\aswSP.sys
22:29:07.0395 0x0b58 aswSP - ok
22:29:07.0457 0x0b58 [ 4C0ECF1AFA6992904814C74B99DD36F9, AA0D9BA7FE829888C636EC9D72E8E2D987A1C3FF092F95A38EC607CEE25A91F8 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
22:29:07.0457 0x0b58 aswTdi - ok
22:29:07.0535 0x0b58 [ 0EFBC2962B156E8AC267F96D4D93EF06, 8A69672CE8B68A0A683D583287473BFAB7CF8B9771C22E398607CF2A151C7124 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
22:29:07.0551 0x0b58 aswVmm - ok
22:29:07.0582 0x0b58 [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:29:07.0582 0x0b58 AsyncMac - ok
22:29:07.0629 0x0b58 [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi C:\Windows\system32\drivers\atapi.sys
22:29:07.0629 0x0b58 atapi - ok
22:29:07.0707 0x0b58 [ 8E98A99187FF17FC1D48E6FAFFD870BE, 7C935191A0A2BA95CA9A9E450F7C8802E6184F73BC297E91908B59F34C22AB06 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:29:07.0722 0x0b58 AudioEndpointBuilder - ok
22:29:07.0753 0x0b58 [ 8E98A99187FF17FC1D48E6FAFFD870BE, 7C935191A0A2BA95CA9A9E450F7C8802E6184F73BC297E91908B59F34C22AB06 ] Audiosrv C:\Windows\System32\Audiosrv.dll
22:29:07.0753 0x0b58 Audiosrv - ok
22:29:07.0847 0x0b58 [ E3F7EC811923F3F1A77B185F22638E5E, 324041256314C1471B5F123FA8DECC8F374A6B497A6419D4CAF61E68E1733265 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:29:07.0847 0x0b58 avast! Antivirus - ok
22:29:07.0894 0x0b58 [ AA6B367CA7DA571DFC3374EC137D87A5, F63C3CD3E65D202DE0A9064720CC6FA9C2470FE86CC6B709202E5CA073899C8A ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
22:29:07.0894 0x0b58 b57nd60x - ok
22:29:07.0987 0x0b58 [ E22ABCAA7B6FF580FEB0D49545DC4263, FAED77D8B0C95AB4A37F070E82D4A763BAEF0BF7C169F220DE4DD07DC241551C ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
22:29:08.0034 0x0b58 BCM43XX - ok
22:29:08.0081 0x0b58 [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep C:\Windows\system32\drivers\Beep.sys
22:29:08.0081 0x0b58 Beep - ok
22:29:08.0159 0x0b58 [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE C:\Windows\System32\bfe.dll
22:29:08.0175 0x0b58 BFE - ok
22:29:08.0268 0x0b58 [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS C:\Windows\System32\qmgr.dll
22:29:08.0299 0x0b58 BITS - ok
22:29:08.0315 0x0b58 [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
22:29:08.0331 0x0b58 blbdrive - ok
22:29:08.0440 0x0b58 [ 1C87705CCB2F60172B0FC86B5D82F00D, C6413E6603AD7ECDA5107504E109F608154BA43DAFCE319793E8D8B47C2781A3 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:29:08.0455 0x0b58 Bonjour Service - ok
22:29:08.0502 0x0b58 [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:29:08.0518 0x0b58 bowser - ok
22:29:08.0565 0x0b58 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
22:29:08.0565 0x0b58 BrFiltLo - ok
22:29:08.0580 0x0b58 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
22:29:08.0580 0x0b58 BrFiltUp - ok
22:29:08.0611 0x0b58 [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser C:\Windows\System32\browser.dll
22:29:08.0627 0x0b58 Browser - ok
22:29:08.0643 0x0b58 [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid C:\Windows\system32\drivers\brserid.sys
22:29:08.0643 0x0b58 Brserid - ok
22:29:08.0658 0x0b58 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
22:29:08.0674 0x0b58 BrSerWdm - ok
22:29:08.0689 0x0b58 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
22:29:08.0689 0x0b58 BrUsbMdm - ok
22:29:08.0705 0x0b58 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
22:29:08.0705 0x0b58 BrUsbSer - ok
22:29:08.0767 0x0b58 [ 6D39C954799B63BA866910234CF7D726, 1D807C3410C01C76E5810D626F23C1CCED3C9C5A65F39267B770C494C8D64114 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
22:29:08.0783 0x0b58 BthEnum - ok
22:29:08.0830 0x0b58 [ AD07C1EC6665B8B35741AB91200C6B68, DCE1305A30D6713222A01C1F1D03ED0ADABE23C742CE1E82BB142531B82A3FF7 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
22:29:08.0830 0x0b58 BTHMODEM - ok
22:29:08.0877 0x0b58 [ 5904EFA25F829BF84EA6FB045134A1D8, 66E4160CC404744576BA6E9DD606B533F42B3D4A3E2FDD457DAA016CC72A81CC ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
22:29:08.0877 0x0b58 BthPan - ok
22:29:08.0986 0x0b58 [ 611FF3F2F095C8D4A6D4CFD9DCC09793, 2F27A1287ABCDB9C316EB720D1855100666240959CF969D5B2679C9ABCBD6050 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
22:29:09.0017 0x0b58 BTHPORT - ok
22:29:09.0111 0x0b58 [ A4C8377FA4A994E07075107DBE2E3DCE, C3CDAA7B83D130100044341C23897CC6C257FA075A8D08B8551F4A28AE8CE6C4 ] BthServ C:\Windows\System32\bthserv.dll
22:29:09.0111 0x0b58 BthServ - ok
22:29:09.0173 0x0b58 [ D330803EAB2A15CAEC7F011F1D4CB30E, 240FFF317C90AD8966DA9666F2748F98CEC3CB99C486F399D1C68FE0E393EE68 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
22:29:09.0173 0x0b58 BTHUSB - ok
22:29:09.0220 0x0b58 [ F2195899900E358614FA535EA503373E, 70D8530359FE579E2F380EBBB11AFC607FE93FAA8F5720AF17E0DFF9888AD15E ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
22:29:09.0235 0x0b58 btwaudio - ok
22:29:09.0282 0x0b58 [ 769DFBE72448B31221DB818A049760A5, 741D2924B45419707075F794E809C7525B47FAEBB89955ADF767EEA542157B1D ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
22:29:09.0282 0x0b58 btwavdt - ok
22:29:09.0329 0x0b58 [ D02F4D18AA4A38F781BEEFEB1892E144, A2E4E40391CEC301DE5560F8118AD5B5946739AEA01E466AB3D0431DFFBE1009 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
22:29:09.0329 0x0b58 btwl2cap - ok
22:29:09.0360 0x0b58 [ 9FA7311CE621683AAB68A324E623F9B2, 14F97A9FD3B8CFCB472DBFCF186D7FE1C1DA01EAAEBED40AEE321ECBA4B64938 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
22:29:09.0360 0x0b58 btwrchid - ok
22:29:09.0391 0x0b58 [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:29:09.0407 0x0b58 cdfs - ok
22:29:09.0454 0x0b58 [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:29:09.0469 0x0b58 cdrom - ok
22:29:09.0563 0x0b58 [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc C:\Windows\System32\certprop.dll
22:29:09.0563 0x0b58 CertPropSvc - ok
22:29:09.0579 0x0b58 [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass C:\Windows\system32\drivers\circlass.sys
22:29:09.0594 0x0b58 circlass - ok
22:29:09.0657 0x0b58 [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS C:\Windows\system32\CLFS.sys
22:29:09.0672 0x0b58 CLFS - ok
22:29:09.0735 0x0b58 [ 6B6943A0CA56B47D6FB2EE476890854F, 6DA779879487F4A187DF54B0362642643D7871AA8F7E30992D781F558C50F052 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:29:09.0735 0x0b58 clr_optimization_v2.0.50727_32 - ok
22:29:09.0797 0x0b58 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:29:09.0797 0x0b58 clr_optimization_v4.0.30319_32 - ok
22:29:09.0844 0x0b58 [ 99AFC3795B58CC478FBBBCDC658FCB56, 0D1B27C42A058C5D56A0157B5ECA9A054254F6B9C8015D0321021A7EFCE10CE2 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:29:09.0844 0x0b58 CmBatt - ok
22:29:09.0875 0x0b58 [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:29:09.0875 0x0b58 cmdide - ok
22:29:09.0891 0x0b58 [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:29:09.0891 0x0b58 Compbatt - ok
22:29:09.0906 0x0b58 COMSysApp - ok
22:29:09.0922 0x0b58 [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
22:29:09.0922 0x0b58 crcdisk - ok
22:29:09.0937 0x0b58 [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe C:\Windows\system32\drivers\crusoe.sys
22:29:09.0937 0x0b58 Crusoe - ok
22:29:10.0031 0x0b58 [ 684C130BBC6DB681BAD4920A4C944AA5, DDE434B206984808351C98500824A33E6740B4326C455066027F8D549D4C3B92 ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:29:10.0031 0x0b58 CryptSvc - ok
22:29:10.0125 0x0b58 [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:29:10.0140 0x0b58 DcomLaunch - ok
22:29:10.0187 0x0b58 [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:29:10.0187 0x0b58 DfsC - ok
22:29:10.0530 0x0b58 [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR C:\Windows\system32\DFSR.exe
22:29:10.0702 0x0b58 DFSR - ok
22:29:10.0795 0x0b58 [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
22:29:10.0811 0x0b58 Dhcp - ok
22:29:10.0889 0x0b58 [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk C:\Windows\system32\drivers\disk.sys
22:29:10.0905 0x0b58 disk - ok
22:29:10.0951 0x0b58 [ 73BAF270D24FE726B9CD7F80BB17A23D, 12ADFB26C16A7D3F623C1A6B72D4C6AB9163EBC93CF13CB2AC6897FB95E96105 ] DKbFltr C:\Windows\system32\DRIVERS\DKbFltr.sys
22:29:10.0967 0x0b58 DKbFltr - ok
22:29:11.0029 0x0b58 [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:29:11.0045 0x0b58 Dnscache - ok
22:29:11.0092 0x0b58 [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc C:\Windows\System32\dot3svc.dll
22:29:11.0107 0x0b58 dot3svc - ok
22:29:11.0154 0x0b58 [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS C:\Windows\system32\dps.dll
22:29:11.0154 0x0b58 DPS - ok
22:29:11.0185 0x0b58 [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:29:11.0201 0x0b58 drmkaud - ok
22:29:11.0263 0x0b58 [ 5C2C209CDEFBC51D83D66E8A53B2BE89, 7AE68672A6BEEF601017BE28AA0BF3673318EFE97AA08E70F58A9391C54DF71F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:29:11.0295 0x0b58 DXGKrnl - ok
22:29:11.0341 0x0b58 [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
22:29:11.0341 0x0b58 E1G60 - ok
22:29:11.0388 0x0b58 [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost C:\Windows\System32\eapsvc.dll
22:29:11.0388 0x0b58 EapHost - ok
22:29:11.0435 0x0b58 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache C:\Windows\system32\drivers\ecache.sys
22:29:11.0451 0x0b58 Ecache - ok
22:29:11.0591 0x0b58 [ 668DCA122FFC7F10BECA6055E15FFABD, 2112DBABAAA76B4BD7580AF596B4EBC77821A66EAB4F4EFC274A5BA14061F66F ] eDataSecurity Service C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
22:29:11.0607 0x0b58 eDataSecurity Service - ok
22:29:11.0669 0x0b58 [ E28516FED46251119ADDAF4CF33BA401, 6CB6436F3214760C414D8897ED0A90EFF2F38C498271F3BC7E05D8414409286B ] eLockService C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
22:29:11.0669 0x0b58 eLockService - ok
22:29:11.0731 0x0b58 [ 5ED4141A6ABAB76841CD0BE16D8110BF, 6A70A9A9AAD38CCDB25CD87749319A925278D33BC9BA277095C67B2C10B82278 ] ElRawDisk C:\Windows\system32\drivers\ElRawDsk.sys
22:29:11.0747 0x0b58 ElRawDisk - ok
22:29:11.0794 0x0b58 [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor C:\Windows\system32\drivers\elxstor.sys
22:29:11.0794 0x0b58 elxstor - ok
22:29:12.0028 0x0b58 [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
22:29:12.0075 0x0b58 EMDMgmt - ok
22:29:12.0153 0x0b58 [ 44E8E86CEEB0D9F0F934B5EDC21E0444, 516C5B8A921131692AB456ED3D892463CE3FA500E6FB57718183C8B4E892A6AE ] eNet Service C:\Acer\Empowering Technology\eNet\eNet Service.exe
22:29:12.0168 0x0b58 eNet Service - ok
22:29:12.0199 0x0b58 [ 59FCCAF915BA89DD98CADF08DA91AFEE, 1286481DF42EBBE13C0FC18ABA514393544CDA17420E71518EF87ADD82D224CB ] eRecoveryService C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
22:29:12.0215 0x0b58 eRecoveryService - ok
22:29:12.0246 0x0b58 [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:29:12.0246 0x0b58 ErrDev - ok
22:29:12.0309 0x0b58 [ A9745687A57CDD71237915859ABA8DAC, DE21C397EBC822622B61189EC6CCF720C76AB6A249188987A10086252A9F26FD ] eSettingsService C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
22:29:12.0309 0x0b58 eSettingsService - ok
22:29:12.0402 0x0b58 [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem C:\Windows\system32\es.dll
22:29:12.0433 0x0b58 EventSystem - ok
22:29:12.0496 0x0b58 [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat C:\Windows\system32\drivers\exfat.sys
22:29:12.0496 0x0b58 exfat - ok
22:29:12.0527 0x0b58 [ 4E404505B3F62ECFBDBCBBCF0A72DBC5, 9F446ED06A31BFE52C4F1E8ACC400B8E3F47A3CC02FFC950DB861B2B3BA4C5B9 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:29:12.0543 0x0b58 fastfat - ok
22:29:12.0574 0x0b58 [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:29:12.0574 0x0b58 fdc - ok
22:29:12.0621 0x0b58 [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost C:\Windows\system32\fdPHost.dll
22:29:12.0652 0x0b58 fdPHost - ok
22:29:12.0667 0x0b58 [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub C:\Windows\system32\fdrespub.dll
22:29:12.0667 0x0b58 FDResPub - ok
22:29:12.0699 0x0b58 [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:29:12.0699 0x0b58 FileInfo - ok
22:29:12.0714 0x0b58 [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:29:12.0730 0x0b58 Filetrace - ok
22:29:12.0745 0x0b58 [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:29:12.0745 0x0b58 flpydisk - ok
22:29:12.0808 0x0b58 [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:29:12.0808 0x0b58 FltMgr - ok
22:29:12.0995 0x0b58 [ 2AFA3A46986AE935DAECEBC7E66314CF, 747FAF9B7F8291B83EE44B91E5708395E749DC87BD42CC3BF2CD41209C298F4D ] FontCache C:\Windows\system32\FntCache.dll
22:29:13.0026 0x0b58 FontCache - ok
22:29:13.0104 0x0b58 [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:29:13.0120 0x0b58 FontCache3.0.0.0 - ok
22:29:13.0167 0x0b58 [ B972A66758577E0BFD1DE0F91AAA27B5, E934034F3F740A83D4E7ABCD2C581845AC2945B0BCCAACF65CC3F99A1DBDE455 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:29:13.0167 0x0b58 Fs_Rec - ok
22:29:13.0213 0x0b58 [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
22:29:13.0213 0x0b58 gagp30kx - ok
22:29:13.0291 0x0b58 [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc C:\Windows\System32\gpsvc.dll
22:29:13.0307 0x0b58 gpsvc - ok
22:29:13.0416 0x0b58 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
22:29:13.0432 0x0b58 gupdate - ok
22:29:13.0447 0x0b58 [ 51508F0C2476177E50C31B0BBFBF1BDB, 3F62A05181D54711180C8727AC66D624AFA7FC816A4ACC4DC0CFCF2D2DBE7F87 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
22:29:13.0447 0x0b58 gupdatem - ok
22:29:13.0510 0x0b58 [ CB04C744BE0A61B1D648FAED182C3B59, 61DC0FF94325DAFCCB7B3980A48727EFBF1283FCF753EC16EF04C730525994C0 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:29:13.0525 0x0b58 HdAudAddService - ok
22:29:13.0572 0x0b58 [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:29:13.0603 0x0b58 HDAudBus - ok
22:29:13.0619 0x0b58 [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth C:\Windows\system32\drivers\hidbth.sys
22:29:13.0619 0x0b58 HidBth - ok
22:29:13.0666 0x0b58 [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr C:\Windows\system32\drivers\hidir.sys
22:29:13.0666 0x0b58 HidIr - ok
22:29:13.0713 0x0b58 [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv C:\Windows\system32\hidserv.dll
22:29:13.0713 0x0b58 hidserv - ok
22:29:13.0744 0x0b58 [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:29:13.0744 0x0b58 HidUsb - ok
22:29:13.0775 0x0b58 [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc C:\Windows\system32\kmsvc.dll
22:29:13.0791 0x0b58 hkmsvc - ok
22:29:13.0822 0x0b58 [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
22:29:13.0822 0x0b58 HpCISSs - ok
22:29:13.0900 0x0b58 [ 46D67209550973257601A533E2AC5785, 3C0D97781947BA8532344AA5D9F3B684761B5B3263A0A294F4593E76EE41DB0C ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:29:13.0915 0x0b58 HSFHWAZL - ok
22:29:13.0993 0x0b58 [ 7BC42C65B5C6281777C1A7605B253BA8, 71885EB4E8625450ECA4623466FB3D5437DAABE739A5DC3B5F4CF982A65F8A86 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
22:29:14.0040 0x0b58 HSF_DPV - ok
22:29:14.0103 0x0b58 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E, A11CE324DD8E8BDFFDF513429C32D3C16EC79DC9A7517048587759B26BF38583 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
22:29:14.0103 0x0b58 HSXHWAZL - ok
22:29:14.0181 0x0b58 [ 0EEECA26C8D4BDE2A4664DB058A81937, 6F88567A116B1420BE1C9C8888F34D05F51378092C805EF4E489635CF92D416B ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:29:14.0196 0x0b58 HTTP - ok
22:29:14.0227 0x0b58 [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
22:29:14.0243 0x0b58 i2omp - ok
22:29:14.0290 0x0b58 [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:29:14.0290 0x0b58 i8042prt - ok
22:29:14.0352 0x0b58 [ 72B53E9C8924949DEC8F3799BCBA2251, FA49C575A9FB45729A9A54CE9A78BD93BAA7A514B1488A8A5BD71489CE033D69 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
22:29:14.0368 0x0b58 IAANTMON - ok
22:29:14.0415 0x0b58 [ E5A0034847537EAEE3C00349D5C34C5F, 3E0F99512CDFF0B628E2FF5B91BB371CDEF65201B03C53182C97DDE34E26E04C ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
22:29:14.0430 0x0b58 iaStor - ok
22:29:14.0477 0x0b58 [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
22:29:14.0493 0x0b58 iaStorV - ok
22:29:14.0586 0x0b58 [ DD386C45D2B5863740166783448A2E7A, 10B912BA70306644BE73A53AF4DCDFF63880C4C5860FF6DBA92B0914EB566718 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:29:14.0633 0x0b58 idsvc - ok
22:29:14.0742 0x0b58 [ 04E385059DA704EC6659DDB1526C4193, 32AAB988AB3ADAFE649C5E32394853C423B424A3A1DCCAA823622CAAD2A9D864 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
22:29:14.0805 0x0b58 igfx - ok
22:29:14.0820 0x0b58 [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp C:\Windows\system32\drivers\iirsp.sys
22:29:14.0836 0x0b58 iirsp - ok
22:29:14.0898 0x0b58 [ 4687EE0C0DD2CE5F7AAA9C2E33C1DC78, FA8EBED2778D9F7560ADC1B563954EEF98AAE651C0553F2803372B37B122AEB3 ] IKEEXT C:\Windows\System32\ikeext.dll
22:29:14.0914 0x0b58 IKEEXT - ok
22:29:14.0961 0x0b58 [ C6E5276C00EBDEB096BB5EF4B797D1B6, 2620D2F7B5242E9DD0217FB4E0CBACF1DB8AB1B92187AD2847904948E1ABFEC1 ] int15 C:\Windows\system32\drivers\int15.sys
22:29:14.0961 0x0b58 int15 - ok
22:29:15.0117 0x0b58 [ B795745F7E51AA20D46753EC5A811ACA, 2FB13A725E5272A105CAB09D792F3001AE708187377E1C38192312A7D5FDA120 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
22:29:15.0241 0x0b58 IntcAzAudAddService - ok
22:29:15.0288 0x0b58 [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide C:\Windows\system32\drivers\intelide.sys
22:29:15.0288 0x0b58 intelide - ok
22:29:15.0335 0x0b58 [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:29:15.0335 0x0b58 intelppm - ok
22:29:15.0366 0x0b58 [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:29:15.0382 0x0b58 IPBusEnum - ok
22:29:15.0413 0x0b58 [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:29:15.0413 0x0b58 IpFilterDriver - ok
22:29:15.0460 0x0b58 [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:29:15.0491 0x0b58 iphlpsvc - ok
22:29:15.0491 0x0b58 IpInIp - ok
22:29:15.0522 0x0b58 [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
22:29:15.0538 0x0b58 IPMIDRV - ok
22:29:15.0553 0x0b58 [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
22:29:15.0553 0x0b58 IPNAT - ok
22:29:15.0600 0x0b58 [ E50A95179211B12946F7E035D60AF560, 69765E2548BA708FF35545EC944DBA1940AD4065AF90E53B97A7792AC231DCF7 ] irda C:\Windows\system32\DRIVERS\irda.sys
22:29:15.0600 0x0b58 irda - ok
22:29:15.0647 0x0b58 [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:29:15.0647 0x0b58 IRENUM - ok
22:29:15.0678 0x0b58 [ CBB0D940221A281BCFEAEA695BD1CDA5, D05D192019524A02FE3FAE6827B98A942FA1AD651BF7AA53530A8A6F4ADFB7EB ] Irmon C:\Windows\System32\irmon.dll
22:29:15.0709 0x0b58 Irmon - ok
22:29:15.0741 0x0b58 [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:29:15.0741 0x0b58 isapnp - ok
22:29:15.0787 0x0b58 [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
22:29:15.0803 0x0b58 iScsiPrt - ok
22:29:15.0834 0x0b58 [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
22:29:15.0834 0x0b58 iteatapi - ok
22:29:15.0865 0x0b58 [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid C:\Windows\system32\drivers\iteraid.sys
22:29:15.0865 0x0b58 iteraid - ok
22:29:15.0912 0x0b58 [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:29:15.0928 0x0b58 kbdclass - ok
22:29:16.0006 0x0b58 [ EDE59EC70E25C24581ADD1FBEC7325F7, 41B37778E9A12675FC0DF74606AAF18C652EB88513B3C4889C5C512E14587CEE ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:29:16.0021 0x0b58 kbdhid - ok
22:29:16.0068 0x0b58 [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso C:\Windows\system32\lsass.exe
22:29:16.0068 0x0b58 KeyIso - ok
22:29:16.0209 0x0b58 [ 5035EDF1F2E72F78BB1EC5BD9B97463F, 8AFAD580A96F002FFB22761B65D4B414917895C45B11B53089BB3E0331995EF7 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:29:16.0224 0x0b58 KSecDD - ok
22:29:16.0302 0x0b58 [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm C:\Windows\system32\msdtckrm.dll
22:29:16.0318 0x0b58 KtmRm - ok
22:29:16.0380 0x0b58 [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer C:\Windows\system32\srvsvc.dll
22:29:16.0396 0x0b58 LanmanServer - ok
22:29:16.0474 0x0b58 [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:29:16.0489 0x0b58 LanmanWorkstation - ok
22:29:16.0583 0x0b58 [ 793FF718477345CD5D232C50BED1E452, 1D39CF9F10742C79FF99B9B4E0361EAEA63B4FC545C58B54B55537D18C802941 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
22:29:16.0614 0x0b58 LightScribeService - ok
22:29:16.0645 0x0b58 [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:29:16.0661 0x0b58 lltdio - ok
22:29:16.0723 0x0b58 [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:29:16.0770 0x0b58 lltdsvc - ok
22:29:16.0801 0x0b58 [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:29:16.0801 0x0b58 lmhosts - ok
22:29:16.0833 0x0b58 [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
22:29:16.0833 0x0b58 LSI_FC - ok
22:29:16.0848 0x0b58 [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
22:29:16.0864 0x0b58 LSI_SAS - ok
22:29:16.0895 0x0b58 [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
22:29:16.0895 0x0b58 LSI_SCSI - ok
22:29:16.0926 0x0b58 [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv C:\Windows\system32\drivers\luafv.sys
22:29:16.0942 0x0b58 luafv - ok
22:29:16.0942 0x0b58 McNASvc - ok
22:29:17.0004 0x0b58 [ 0CEA2D0D3FA284B85ED5B68365114F76, E6FF0EC98FDC3F628438B613C356C237E68686E3B5B17A58A60C16F4B9A2B968 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
22:29:17.0004 0x0b58 mdmxsdk - ok
22:29:17.0035 0x0b58 [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas C:\Windows\system32\drivers\megasas.sys
22:29:17.0035 0x0b58 megasas - ok
22:29:17.0082 0x0b58 [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR C:\Windows\system32\drivers\megasr.sys
22:29:17.0098 0x0b58 MegaSR - ok
22:29:17.0129 0x0b58 [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS C:\Windows\system32\mmcss.dll
22:29:17.0145 0x0b58 MMCSS - ok
22:29:17.0191 0x0b58 MobilityService - ok
22:29:17.0254 0x0b58 [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem C:\Windows\system32\drivers\modem.sys
22:29:17.0285 0x0b58 Modem - ok
22:29:17.0301 0x0b58 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:29:17.0301 0x0b58 monitor - ok
22:29:17.0332 0x0b58 [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:29:17.0332 0x0b58 mouclass - ok
22:29:17.0363 0x0b58 [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:29:17.0379 0x0b58 mouhid - ok
22:29:17.0394 0x0b58 [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
22:29:17.0394 0x0b58 MountMgr - ok
22:29:17.0503 0x0b58 [ 345477F02C308B7480702767218C86A2, 98AFB5CF35BD82BA44B8F52CBC5FA3760506ADD7892C2AA1A77E8DF71FC8523F ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:29:17.0550 0x0b58 MozillaMaintenance - ok
22:29:17.0566 0x0b58 [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio C:\Windows\system32\drivers\mpio.sys
22:29:17.0566 0x0b58 mpio - ok
22:29:17.0613 0x0b58 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:29:17.0613 0x0b58 mpsdrv - ok
22:29:17.0675 0x0b58 [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:29:17.0691 0x0b58 MpsSvc - ok
22:29:17.0722 0x0b58 [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
22:29:17.0737 0x0b58 Mraid35x - ok
22:29:17.0784 0x0b58 [ B0584CA7DEF55929FDB5169BD28B2484, AF6A7E404FEB29F7F3428D0AF6682195E5E8ED106996A04E6947DBD575696546 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:29:17.0815 0x0b58 MRxDAV - ok
22:29:17.0862 0x0b58 [ 1E94971C4B446AB2290DEB71D01CF0C2, 4701AA1B419AEF735CB2DA34532B0F1844433272C36D79F4EB55807E39B923D1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:29:17.0862 0x0b58 mrxsmb - ok
22:29:17.0925 0x0b58 [ 4FCCB34D793B116423209C0F8B7A3B03, 7A483AEB691ADBE82779F12F0BB1CCCBFFD7E92902EC1ADC99AB7D129F887143 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:29:17.0956 0x0b58 mrxsmb10 - ok
22:29:17.0987 0x0b58 [ C3CB1B40AD4A0124D617A1199B0B9D7C, B975A39DE6D324C6274B6E3B883F36082A958F028335CEB3A37F44481EB284B3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:29:18.0003 0x0b58 mrxsmb20 - ok
22:29:18.0034 0x0b58 [ 28023E86F17001F7CD9B15A5BC9AE07D, FC7EAA592C5F796E3BCD7F7EF261709CD899B33FC8486E594A480F143D0D6320 ] msahci C:\Windows\system32\drivers\msahci.sys
22:29:18.0034 0x0b58 msahci - ok
22:29:18.0081 0x0b58 [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:29:18.0096 0x0b58 msdsm - ok
22:29:18.0127 0x0b58 [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC C:\Windows\System32\msdtc.exe
22:29:18.0127 0x0b58 MSDTC - ok
22:29:18.0159 0x0b58 [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:29:18.0174 0x0b58 Msfs - ok
22:29:18.0190 0x0b58 [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:29:18.0190 0x0b58 msisadrv - ok
22:29:18.0237 0x0b58 [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:29:18.0252 0x0b58 MSiSCSI - ok
22:29:18.0268 0x0b58 msiserver - ok
22:29:18.0315 0x0b58 [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:29:18.0315 0x0b58 MSKSSRV - ok
22:29:18.0361 0x0b58 [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:29:18.0377 0x0b58 MSPCLOCK - ok
22:29:18.0393 0x0b58 [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:29:18.0393 0x0b58 MSPQM - ok
22:29:18.0439 0x0b58 [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:29:18.0439 0x0b58 MsRPC - ok
22:29:18.0471 0x0b58 [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
22:29:18.0471 0x0b58 mssmbios - ok
22:29:18.0502 0x0b58 [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:29:18.0502 0x0b58 MSTEE - ok
22:29:18.0517 0x0b58 [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup C:\Windows\system32\Drivers\mup.sys
22:29:18.0517 0x0b58 Mup - ok
22:29:18.0627 0x0b58 [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent C:\Windows\system32\qagentRT.dll
22:29:18.0673 0x0b58 napagent - ok
22:29:18.0720 0x0b58 [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:29:18.0751 0x0b58 NativeWifiP - ok
22:29:18.0861 0x0b58 [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:29:18.0892 0x0b58 NDIS - ok
22:29:18.0939 0x0b58 [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:29:18.0954 0x0b58 NdisTapi - ok
22:29:18.0970 0x0b58 [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:29:18.0985 0x0b58 Ndisuio - ok
22:29:19.0032 0x0b58 [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:29:19.0048 0x0b58 NdisWan - ok
22:29:19.0079 0x0b58 [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:29:19.0095 0x0b58 NDProxy - ok
22:29:19.0110 0x0b58 [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:29:19.0126 0x0b58 NetBIOS - ok
22:29:19.0173 0x0b58 [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt C:\Windows\system32\DRIVERS\netbt.sys
22:29:19.0188 0x0b58 netbt - ok
22:29:19.0204 0x0b58 [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon C:\Windows\system32\lsass.exe
22:29:19.0219 0x0b58 Netlogon - ok
22:29:19.0313 0x0b58 [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman C:\Windows\System32\netman.dll
22:29:19.0344 0x0b58 Netman - ok
22:29:19.0422 0x0b58 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:29:19.0438 0x0b58 NetMsmqActivator - ok
22:29:19.0453 0x0b58 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:29:19.0453 0x0b58 NetPipeActivator - ok
22:29:19.0500 0x0b58 [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm C:\Windows\System32\netprofm.dll
22:29:19.0516 0x0b58 netprofm - ok
22:29:19.0531 0x0b58 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:29:19.0531 0x0b58 NetTcpActivator - ok
22:29:19.0547 0x0b58 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:29:19.0563 0x0b58 NetTcpPortSharing - ok
22:29:19.0765 0x0b58 [ 35D5458D9A1B26B2005ABFFBF4C1C5E7, EE044FB7A49336FEDA1BDBBD2AD7A4A163C780A6A464B7712688E0BA0B4E6C40 ] NETw3v32 C:\Windows\system32\DRIVERS\NETw3v32.sys
22:29:19.0890 0x0b58 NETw3v32 - ok
22:29:19.0937 0x0b58 [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
22:29:19.0937 0x0b58 nfrd960 - ok
22:29:19.0999 0x0b58 [ C96411DD46AABC0D6F3CF06D0E0E7E14, 0D36F322AF1B923D96735BFFCAC3FDB0B282E59220BADAB8B49AC178A6765380 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:29:19.0999 0x0b58 NlaSvc - ok
22:29:20.0062 0x0b58 [ F6C40E0A565EE3CE5AEEB325E10054F2, 30C8BA41B1C235ECB2C7F29CD76C8F41B8D705BE7DD44F66666C28275EA56BAC ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
22:29:20.0062 0x0b58 nmwcd - ok
22:29:20.0093 0x0b58 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B, 879BE61C4256C9B855AA269C241A0D24E9ECE3CA0F3AFFB2E11D9340C0428D31 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
22:29:20.0093 0x0b58 nmwcdc - ok
22:29:20.0140 0x0b58 [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:29:20.0155 0x0b58 Npfs - ok

Pokračování logu je v další odpovědi.

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 22 úno 2015 23:14

Druhá část logu z TDSSKiller:

22:29:20.0187 0x0b58 [ 6D8D2E5652FC2442C810C5D8BE784148, 013FF4FA03CA2E066B1946CC09889616B243068BA0FB2E58D4C1435BF66FBC87 ] NSCIRDA C:\Windows\system32\DRIVERS\nscirda.sys
22:29:20.0187 0x0b58 NSCIRDA - ok
22:29:20.0218 0x0b58 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi C:\Windows\system32\nsisvc.dll
22:29:20.0218 0x0b58 nsi - ok
22:29:20.0249 0x0b58 [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:29:20.0265 0x0b58 nsiproxy - ok
22:29:20.0389 0x0b58 [ 2C1121F2B87E9A6B12485DF53CD848C7, E580428F3BA7B201C6C7CFADF1F44A6ECA4F589EDB034DA14260136236195936 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:29:20.0467 0x0b58 Ntfs - ok
22:29:20.0499 0x0b58 [ 7F1C1F78D709C4A54CBB46EDE7E0B48D, 52135D41983A9E9E1DCA250A63017076AE22AA06D77CCF2E5EF41154F958584A ] NTIDrvr C:\Windows\system32\DRIVERS\NTIDrvr.sys
22:29:20.0514 0x0b58 NTIDrvr - ok
22:29:20.0530 0x0b58 [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
22:29:20.0530 0x0b58 ntrigdigi - ok
22:29:20.0561 0x0b58 [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null C:\Windows\system32\drivers\Null.sys
22:29:20.0561 0x0b58 Null - ok
22:29:20.0592 0x0b58 [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:29:20.0592 0x0b58 nvraid - ok
22:29:20.0623 0x0b58 [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:29:20.0623 0x0b58 nvstor - ok
22:29:20.0655 0x0b58 [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:29:20.0655 0x0b58 nv_agp - ok
22:29:20.0670 0x0b58 NwlnkFlt - ok
22:29:20.0670 0x0b58 NwlnkFwd - ok
22:29:20.0748 0x0b58 [ 6F310E890D46E246E0E261A63D9B36B4, 7050B0C43CC0DF2DDAD3EB8D2FF9EEE425A627C68654CBB154D55A4B1A47AA08 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
22:29:20.0748 0x0b58 ohci1394 - ok
22:29:20.0904 0x0b58 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc C:\Windows\system32\p2psvc.dll
22:29:20.0967 0x0b58 p2pimsvc - ok
22:29:21.0013 0x0b58 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc C:\Windows\system32\p2psvc.dll
22:29:21.0029 0x0b58 p2psvc - ok
22:29:21.0107 0x0b58 [ 0FA9B5055484649D63C303FE404E5F4D, ABF357001A5E7B21621560E74FA538E2D899C5111A6AAC784B5B12D9D819C6CD ] Parport C:\Windows\system32\drivers\parport.sys
22:29:21.0123 0x0b58 Parport - ok
22:29:21.0154 0x0b58 [ B9C2B89F08670E159F7181891E449CD9, BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:29:21.0169 0x0b58 partmgr - ok
22:29:21.0185 0x0b58 [ 4F9A6A8A31413180D0FCB279AD5D8112, DCE48BC6E3447403521BB9FBF727E629DEE45B69B8AE8CFEE1A67FECAE3CB9D3 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
22:29:21.0185 0x0b58 Parvdm - ok
22:29:21.0216 0x0b58 [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc C:\Windows\System32\pcasvc.dll
22:29:21.0232 0x0b58 PcaSvc - ok
22:29:21.0279 0x0b58 [ FD2041E9BA03DB7764B2248F02475079, DECEED110524BF83B4097188BF24BF0DDE1CE838DF7748B0DC807ABE351EB20A ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
22:29:21.0294 0x0b58 pccsmcfd - ok
22:29:21.0341 0x0b58 [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci C:\Windows\system32\drivers\pci.sys
22:29:21.0357 0x0b58 pci - ok
22:29:21.0372 0x0b58 [ FC175F5DDAB666D7F4D17449A547626F, 7D6108213D1AD3F97A3B83E491BCCC7D6F5BC72C32A182BDDE8736851A26C8D2 ] pciide C:\Windows\system32\drivers\pciide.sys
22:29:21.0372 0x0b58 pciide - ok
22:29:21.0403 0x0b58 [ 3BB2244F343B610C29C98035504C9B75, DA61EC2600199DFA32020D0484E9BBF5E0742E7C8C952370BF6FAF91C914A999 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
22:29:21.0403 0x0b58 pcmcia - ok
22:29:21.0559 0x0b58 [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:29:21.0622 0x0b58 PEAUTH - ok
22:29:21.0778 0x0b58 [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla C:\Windows\system32\pla.dll
22:29:21.0856 0x0b58 pla - ok
22:29:21.0949 0x0b58 [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:29:21.0965 0x0b58 PlugPlay - ok
22:29:22.0012 0x0b58 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
22:29:22.0027 0x0b58 PNRPAutoReg - ok
22:29:22.0059 0x0b58 [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc C:\Windows\system32\p2psvc.dll
22:29:22.0090 0x0b58 PNRPsvc - ok
22:29:22.0152 0x0b58 [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:29:22.0168 0x0b58 PolicyAgent - ok
22:29:22.0215 0x0b58 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:29:22.0215 0x0b58 PptpMiniport - ok
22:29:22.0230 0x0b58 [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor C:\Windows\system32\drivers\processr.sys
22:29:22.0246 0x0b58 Processor - ok
22:29:22.0277 0x0b58 [ 0D5DAD610D7EA1627581ED06FB2BAA9A, 6E27CF3A1624AE10EECB8B5F38E03D76A6AABE4E75DD66DEDD67E0773935A396 ] ProfSvc C:\Windows\system32\profsvc.dll
22:29:22.0293 0x0b58 ProfSvc - ok
22:29:22.0308 0x0b58 [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe
22:29:22.0308 0x0b58 ProtectedStorage - ok
22:29:22.0355 0x0b58 [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
22:29:22.0371 0x0b58 PSched - ok
22:29:22.0402 0x0b58 [ 18DE162F9B83079C24CD96F59292F5ED, 9832289F2F7C8DC3A8B4C7FBD90E0FDDFD41D0A0E6E40D90F98CFD6E8E93C974 ] PSDFilter C:\Windows\system32\DRIVERS\psdfilter.sys
22:29:22.0402 0x0b58 PSDFilter - ok
22:29:22.0433 0x0b58 [ BC1457A28E76AB3106D43802AC22A627, 450F7E8D6990A7089905E23F9B0BA239A25E45778C57FB4E8909E15196D09A26 ] PSDNServ C:\Windows\system32\DRIVERS\PSDNServ.sys
22:29:22.0449 0x0b58 PSDNServ - ok
22:29:22.0480 0x0b58 [ AC151E5B0943304E368C98EC78B5FC4F, 6CFC7668BE7632FC72C9D8FF45F061557F768EE23FDF7AD63CA82035E03E5F1B ] psdvdisk C:\Windows\system32\DRIVERS\PSDVdisk.sys
22:29:22.0480 0x0b58 psdvdisk - ok
22:29:22.0558 0x0b58 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300 C:\Windows\system32\drivers\ql2300.sys
22:29:22.0605 0x0b58 ql2300 - ok
22:29:22.0636 0x0b58 [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
22:29:22.0636 0x0b58 ql40xx - ok
22:29:22.0698 0x0b58 [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE C:\Windows\system32\qwave.dll
22:29:22.0714 0x0b58 QWAVE - ok
22:29:22.0729 0x0b58 [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:29:22.0729 0x0b58 QWAVEdrv - ok
22:29:22.0745 0x0b58 [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:29:22.0745 0x0b58 RasAcd - ok
22:29:22.0776 0x0b58 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto C:\Windows\System32\rasauto.dll
22:29:22.0792 0x0b58 RasAuto - ok
22:29:22.0807 0x0b58 [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:29:22.0823 0x0b58 Rasl2tp - ok
22:29:22.0885 0x0b58 [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan C:\Windows\System32\rasmans.dll
22:29:22.0901 0x0b58 RasMan - ok
22:29:22.0948 0x0b58 [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:29:22.0948 0x0b58 RasPppoe - ok
22:29:22.0995 0x0b58 [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:29:22.0995 0x0b58 RasSstp - ok
22:29:23.0041 0x0b58 [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:29:23.0057 0x0b58 rdbss - ok
22:29:23.0088 0x0b58 [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:29:23.0088 0x0b58 RDPCDD - ok
22:29:23.0119 0x0b58 [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
22:29:23.0135 0x0b58 rdpdr - ok
22:29:23.0151 0x0b58 [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:29:23.0151 0x0b58 RDPENCDD - ok
22:29:23.0213 0x0b58 [ C127EBD5AFAB31524662C48DFCEB773A, 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:29:23.0213 0x0b58 RDPWD - ok
22:29:23.0260 0x0b58 [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess C:\Windows\System32\mprdim.dll
22:29:23.0260 0x0b58 RemoteAccess - ok
22:29:23.0307 0x0b58 [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:29:23.0322 0x0b58 RemoteRegistry - ok
22:29:23.0385 0x0b58 [ 6482707F9F4DA0ECBAB43B2E0398A101, 7D57FC36577121D7E26A4F2D46DCA8725D55EC9F75B91DF994DB742BC4FB89C2 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
22:29:23.0400 0x0b58 RFCOMM - ok
22:29:23.0431 0x0b58 [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator C:\Windows\system32\locator.exe
22:29:23.0431 0x0b58 RpcLocator - ok
22:29:23.0494 0x0b58 [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs C:\Windows\system32\rpcss.dll
22:29:23.0509 0x0b58 RpcSs - ok
22:29:23.0541 0x0b58 [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:29:23.0541 0x0b58 rspndr - ok
22:29:23.0556 0x0b58 [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs C:\Windows\system32\lsass.exe
22:29:23.0556 0x0b58 SamSs - ok
22:29:23.0603 0x0b58 [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:29:23.0619 0x0b58 sbp2port - ok
22:29:23.0775 0x0b58 [ 794D4B48DFB6E999537C7C3947863463, 93DA8AA20D6B02A3360E7F56150F126E75266E9372E6409D42B89DA588EF49C3 ] SBSDWSCService C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
22:29:23.0821 0x0b58 SBSDWSCService - ok
22:29:23.0884 0x0b58 [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:29:23.0899 0x0b58 SCardSvr - ok
22:29:23.0993 0x0b58 [ 1A58069DB21D05EB2AB58EE5753EBE8D, EED8111EB613F4C93D1638C74FDB0A6DC6694E1B108DCD0D794B5B5F9B8C6EE4 ] Schedule C:\Windows\system32\schedsvc.dll
22:29:24.0024 0x0b58 Schedule - ok
22:29:24.0055 0x0b58 [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc C:\Windows\System32\certprop.dll
22:29:24.0055 0x0b58 SCPolicySvc - ok
22:29:24.0118 0x0b58 [ 8F36B54688C31EED4580129040C6A3D3, DC150689CBAEEC94B9DE0CA6A633FAD16CDDDC452521232E0C2A44BAE61E08D9 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
22:29:24.0133 0x0b58 sdbus - ok
22:29:24.0180 0x0b58 [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:29:24.0180 0x0b58 SDRSVC - ok
22:29:24.0211 0x0b58 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:29:24.0211 0x0b58 secdrv - ok
22:29:24.0243 0x0b58 [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon C:\Windows\system32\seclogon.dll
22:29:24.0258 0x0b58 seclogon - ok
22:29:24.0274 0x0b58 [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS C:\Windows\System32\sens.dll
22:29:24.0274 0x0b58 SENS - ok
22:29:24.0305 0x0b58 [ 68E44E331D46F0FB38F0863A84CD1A31, 0778D85B6869CE2610820DC9724360538BFE832426E898AEBC34E53D2AB4322B ] Serenum C:\Windows\system32\drivers\serenum.sys
22:29:24.0321 0x0b58 Serenum - ok
22:29:24.0336 0x0b58 [ C70D69A918B178D3C3B06339B40C2E1B, 40BEEECA4C797A3355F4B01C57C2763C33028F27826315062320789A496D0810 ] Serial C:\Windows\system32\drivers\serial.sys
22:29:24.0352 0x0b58 Serial - ok
22:29:24.0367 0x0b58 [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse C:\Windows\system32\drivers\sermouse.sys
22:29:24.0367 0x0b58 sermouse - ok
22:29:24.0508 0x0b58 [ E802089FEC30A95FDFD218995308F9B3, A340D22E7E1D8EC7AE324C05D995AD34797B2D899DFD902A822B38109FAC6437 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
22:29:24.0539 0x0b58 ServiceLayer - ok
22:29:24.0601 0x0b58 [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv C:\Windows\system32\sessenv.dll
22:29:24.0617 0x0b58 SessionEnv - ok
22:29:24.0633 0x0b58 [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
22:29:24.0633 0x0b58 sffdisk - ok
22:29:24.0679 0x0b58 [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:29:24.0679 0x0b58 sffp_mmc - ok
22:29:24.0711 0x0b58 [ 9F66A46C55D6F1CCABC79BB7AFCCC545, 029115C69315D2298F7FC944A53EF7F120FF74919208EB5ABC190022176D9B16 ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
22:29:24.0711 0x0b58 sffp_sd - ok
22:29:24.0742 0x0b58 [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
22:29:24.0757 0x0b58 sfloppy - ok
22:29:24.0804 0x0b58 [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:29:24.0820 0x0b58 SharedAccess - ok
22:29:24.0882 0x0b58 [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:29:24.0898 0x0b58 ShellHWDetection - ok
22:29:24.0929 0x0b58 [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp C:\Windows\system32\drivers\sisagp.sys
22:29:24.0945 0x0b58 sisagp - ok
22:29:24.0976 0x0b58 [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
22:29:24.0976 0x0b58 SiSRaid2 - ok
22:29:25.0007 0x0b58 [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
22:29:25.0007 0x0b58 SiSRaid4 - ok
22:29:25.0116 0x0b58 [ 050A4112B00BCA2E13314CDE48C1DEEE, 86C679CD494DEEB984372BF954EFBB8982AC7995FBF89FCF83BC228991D1B825 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:29:25.0132 0x0b58 SkypeUpdate - ok
22:29:25.0350 0x0b58 [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc C:\Windows\system32\SLsvc.exe
22:29:25.0506 0x0b58 slsvc - ok
22:29:25.0584 0x0b58 [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify C:\Windows\system32\SLUINotify.dll
22:29:25.0584 0x0b58 SLUINotify - ok
22:29:25.0631 0x0b58 [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:29:25.0647 0x0b58 Smb - ok
22:29:25.0678 0x0b58 [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:29:25.0693 0x0b58 SNMPTRAP - ok
22:29:25.0740 0x0b58 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr C:\Windows\system32\drivers\spldr.sys
22:29:25.0740 0x0b58 spldr - ok
22:29:25.0787 0x0b58 [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler C:\Windows\System32\spoolsv.exe
22:29:25.0803 0x0b58 Spooler - ok
22:29:25.0849 0x0b58 [ 9263C8898732E2B890F7E954E7729AB7, DEBFD81E702893427972A6565A9AAA54A09B9F7F30CA9391011C6F7FB758A3F4 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
22:29:25.0865 0x0b58 SQLWriter - ok
22:29:25.0927 0x0b58 [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv C:\Windows\system32\DRIVERS\srv.sys
22:29:25.0943 0x0b58 srv - ok
22:29:25.0990 0x0b58 [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:29:25.0990 0x0b58 srv2 - ok
22:29:26.0021 0x0b58 [ 7605C0E1D01A08F3ECD743F38B834A44, 83A77E31004BCF83443F30EFC290E04BB1A2F332E8DFD614AB6E25B527C92299 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:29:26.0021 0x0b58 srvnet - ok
22:29:26.0068 0x0b58 [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:29:26.0083 0x0b58 SSDPSRV - ok
22:29:26.0099 0x0b58 [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:29:26.0115 0x0b58 SstpSvc - ok
22:29:26.0177 0x0b58 [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc C:\Windows\System32\wiaservc.dll
22:29:26.0193 0x0b58 stisvc - ok
22:29:26.0224 0x0b58 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum C:\Windows\system32\DRIVERS\swenum.sys
22:29:26.0239 0x0b58 swenum - ok
22:29:26.0286 0x0b58 [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv C:\Windows\System32\swprv.dll
22:29:26.0317 0x0b58 swprv - ok
22:29:26.0333 0x0b58 [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
22:29:26.0333 0x0b58 Symc8xx - ok
22:29:26.0349 0x0b58 [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
22:29:26.0349 0x0b58 Sym_hi - ok
22:29:26.0380 0x0b58 [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
22:29:26.0380 0x0b58 Sym_u3 - ok
22:29:26.0427 0x0b58 [ C5F25D490D0915732508FD421BF76D93, 9DDF1CBC69C3A1D157073F897AE797ECA257F1CC9659A75F6DFF0C30594C06DD ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
22:29:26.0427 0x0b58 SynTP - ok
22:29:26.0489 0x0b58 [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain C:\Windows\system32\sysmain.dll
22:29:26.0520 0x0b58 SysMain - ok
22:29:26.0567 0x0b58 [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:29:26.0567 0x0b58 TabletInputService - ok
22:29:26.0629 0x0b58 [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv C:\Windows\System32\tapisrv.dll
22:29:26.0645 0x0b58 TapiSrv - ok
22:29:26.0661 0x0b58 [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS C:\Windows\System32\tbssvc.dll
22:29:26.0676 0x0b58 TBS - ok
22:29:26.0770 0x0b58 [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:29:26.0801 0x0b58 Tcpip - ok
22:29:26.0848 0x0b58 [ C7B0746FCD576D7EEBA6A2530B0B2966, F8ADAED40AA12BF8427482A00CCF8374458FEA95C3C381AEF59EC057A2791550 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
22:29:26.0863 0x0b58 Tcpip6 - ok
22:29:26.0910 0x0b58 [ 608C345A255D82A6289C2D468EB41FD7, 74ECFDD45DC3EB3AFAEF9C42B546241AA1D6ACB2F6591A76DDB8BB1768545889 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:29:26.0910 0x0b58 tcpipreg - ok
22:29:26.0941 0x0b58 [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:29:26.0957 0x0b58 TDPIPE - ok
22:29:26.0973 0x0b58 [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:29:26.0973 0x0b58 TDTCP - ok
22:29:27.0019 0x0b58 [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:29:27.0019 0x0b58 tdx - ok
22:29:27.0051 0x0b58 [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
22:29:27.0051 0x0b58 TermDD - ok
22:29:27.0129 0x0b58 [ DBD84E59D631569EC3E756EF144E8431, 9E58629EC762584A2D294A619593620626F7CBE467045AD0F920B6CF1D4B4724 ] TermService C:\Windows\System32\termsrv.dll
22:29:27.0144 0x0b58 TermService - ok
22:29:27.0175 0x0b58 [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes C:\Windows\system32\shsvcs.dll
22:29:27.0191 0x0b58 Themes - ok
22:29:27.0207 0x0b58 [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER C:\Windows\system32\mmcss.dll
22:29:27.0222 0x0b58 THREADORDER - ok
22:29:27.0269 0x0b58 [ 78213F01CE781F93180BEF5EB5B3AD81, D036E406775DAC1DEEEF283D98CEEC3D0A75C178FDAE783A5ED1383F662288AA ] tifm21 C:\Windows\system32\drivers\tifm21.sys
22:29:27.0285 0x0b58 tifm21 - ok
22:29:27.0316 0x0b58 [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks C:\Windows\System32\trkwks.dll
22:29:27.0331 0x0b58 TrkWks - ok
22:29:27.0394 0x0b58 [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:29:27.0394 0x0b58 TrustedInstaller - ok
22:29:27.0441 0x0b58 [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3, 1CBB5106A32362ABDEE73BF170E205FE64DDBF826C5F6DFFCCD229F220B9C85E ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:29:27.0441 0x0b58 tssecsrv - ok
22:29:27.0472 0x0b58 [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
22:29:27.0472 0x0b58 tunmp - ok
22:29:27.0503 0x0b58 [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:29:27.0503 0x0b58 tunnel - ok
22:29:27.0550 0x0b58 [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
22:29:27.0550 0x0b58 uagp35 - ok
22:29:27.0597 0x0b58 [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:29:27.0612 0x0b58 udfs - ok
22:29:27.0659 0x0b58 [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:29:27.0675 0x0b58 UI0Detect - ok
22:29:27.0690 0x0b58 [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:29:27.0706 0x0b58 uliagpkx - ok
22:29:27.0737 0x0b58 [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci C:\Windows\system32\drivers\uliahci.sys
22:29:27.0753 0x0b58 uliahci - ok
22:29:27.0784 0x0b58 [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata C:\Windows\system32\drivers\ulsata.sys
22:29:27.0784 0x0b58 UlSata - ok
22:29:27.0815 0x0b58 [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
22:29:27.0815 0x0b58 ulsata2 - ok
22:29:27.0846 0x0b58 [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
22:29:27.0846 0x0b58 umbus - ok
22:29:27.0893 0x0b58 [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost C:\Windows\System32\upnphost.dll
22:29:27.0909 0x0b58 upnphost - ok
22:29:27.0971 0x0b58 [ 47F5F9D837D80FFD5882A14DB9DA0A67, 3B32E69B77E21CF98ED6E97B231B9633BE39D74328152EDFA7656FB16E3FF93A ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
22:29:27.0971 0x0b58 upperdev - ok
22:29:28.0033 0x0b58 [ AAB0B5F72D2D726FBFDC895A2902DE1D, 7824AF6E2ADEA23F208526F3A62AD1BACDBBDB23E58EB5806890B0761529C50F ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:29:28.0033 0x0b58 usbccgp - ok
22:29:28.0065 0x0b58 [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:29:28.0080 0x0b58 usbcir - ok
22:29:28.0096 0x0b58 [ 153E8515CB86F8BB5D1A8B478EBF4BB2, 0F1F79BA7C32ACAAE69184A56E67D6E18E2E2F07E0BE23F266401431169DAE14 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:29:28.0111 0x0b58 usbehci - ok
22:29:28.0143 0x0b58 [ 2AE6BCEBD85D31317E433733DAF25888, 7B2C0E8703D0275A620160E479166EB7AA31B0F146507603535CEBF0BA4684A4 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:29:28.0143 0x0b58 usbhub - ok
22:29:28.0174 0x0b58 [ 38DBC7DD6CC5A72011F187425384388B, 456CFCD190035C3033709C8DC0F6DC4352BBF751D57C0C52DD04F8C301FEBACD ] usbohci C:\Windows\system32\drivers\usbohci.sys
22:29:28.0174 0x0b58 usbohci - ok
22:29:28.0205 0x0b58 [ E75C4B5269091D15A2E7DC0B6D35F2F5, B0A4141B69B66276890836DE98EB8BC790D35CE59FA503060593E8CC12AA106B ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:29:28.0205 0x0b58 usbprint - ok
22:29:28.0267 0x0b58 [ 1D714B8497CD68307806D5D3F60A5169, 1914D92ECE39995168E3C8F5A7694B7A94954DB299410A2781D1321C8E60C3D9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
22:29:28.0267 0x0b58 usbscan - ok
22:29:28.0299 0x0b58 [ 8E6C378A885D6FFDA8F05E8D27B95C0E, 351F20B1CB510F7B6B9321EB6C7A97446EF963A89F19F7E7A9CF41381B4B19FF ] usbser C:\Windows\system32\DRIVERS\usbser.sys
22:29:28.0299 0x0b58 usbser - ok
22:29:28.0361 0x0b58 [ E44F0D17BE0908B58DCC99CCB99C6C32, 6C5E62A688CD3A299FBE2C8CD87F2A860340CDE4616348D83C6FB3DDB561E6C9 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
22:29:28.0361 0x0b58 UsbserFilt - ok
22:29:28.0408 0x0b58 [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:29:28.0408 0x0b58 USBSTOR - ok
22:29:28.0470 0x0b58 [ 44056325428A8E4C755830426E29878F, 95F182047746D352B7DC2B22298D5E58738E1B787C110D1DE841C026FB8A67EB ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
22:29:28.0470 0x0b58 usbuhci - ok
22:29:28.0533 0x0b58 [ 73FF24E21B690625A58109637DDA0DF7, 62B1F9CD82678E2110D4BB5CC86EE8A7AB0757681443916620B6AAA1EF0DECEB ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
22:29:28.0533 0x0b58 usbvideo - ok
22:29:28.0595 0x0b58 [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms C:\Windows\System32\uxsms.dll
22:29:28.0611 0x0b58 UxSms - ok
22:29:28.0657 0x0b58 [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds C:\Windows\System32\vds.exe
22:29:28.0689 0x0b58 vds - ok
22:29:28.0720 0x0b58 [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:29:28.0735 0x0b58 vga - ok
22:29:28.0751 0x0b58 [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave C:\Windows\System32\drivers\vga.sys
22:29:28.0767 0x0b58 VgaSave - ok
22:29:28.0782 0x0b58 [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp C:\Windows\system32\drivers\viaagp.sys
22:29:28.0782 0x0b58 viaagp - ok
22:29:28.0813 0x0b58 [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
22:29:28.0813 0x0b58 ViaC7 - ok
22:29:28.0845 0x0b58 [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide C:\Windows\system32\drivers\viaide.sys
22:29:28.0845 0x0b58 viaide - ok
22:29:28.0876 0x0b58 [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:29:28.0876 0x0b58 volmgr - ok
22:29:28.0938 0x0b58 [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:29:28.0954 0x0b58 volmgrx - ok
22:29:29.0016 0x0b58 [ 786DB5771F05EF300390399F626BF30A, 4A07BE5AEDBA4C15C2F9A91250F0488A0B0305C67BB7A037508D5CBF86D4E1B7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:29:29.0032 0x0b58 volsnap - ok
22:29:29.0063 0x0b58 [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
22:29:29.0079 0x0b58 vsmraid - ok
22:29:29.0172 0x0b58 [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS C:\Windows\system32\vssvc.exe
22:29:29.0219 0x0b58 VSS - ok
22:29:29.0281 0x0b58 [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time C:\Windows\system32\w32time.dll
22:29:29.0297 0x0b58 W32Time - ok
22:29:29.0344 0x0b58 [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
22:29:29.0344 0x0b58 WacomPen - ok
22:29:29.0375 0x0b58 [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
22:29:29.0375 0x0b58 Wanarp - ok
22:29:29.0375 0x0b58 [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:29:29.0391 0x0b58 Wanarpv6 - ok
22:29:29.0422 0x0b58 [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:29:29.0453 0x0b58 wcncsvc - ok
22:29:29.0484 0x0b58 [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:29:29.0531 0x0b58 WcsPlugInService - ok
22:29:29.0562 0x0b58 [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd C:\Windows\system32\drivers\wd.sys
22:29:29.0562 0x0b58 Wd - ok
22:29:29.0640 0x0b58 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:29:29.0656 0x0b58 Wdf01000 - ok
22:29:29.0703 0x0b58 [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:29:29.0703 0x0b58 WdiServiceHost - ok
22:29:29.0718 0x0b58 [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:29:29.0718 0x0b58 WdiSystemHost - ok
22:29:29.0749 0x0b58 [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient C:\Windows\System32\webclnt.dll
22:29:29.0765 0x0b58 WebClient - ok
22:29:29.0827 0x0b58 [ AE3736E7E8892241C23E4EBBB7453B60, 0F998116CC07CD719CB237EAE53BB16B2EDD6973828B9C1055EB981AEA0453D1 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:29:29.0859 0x0b58 Wecsvc - ok
22:29:29.0890 0x0b58 [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:29:29.0905 0x0b58 wercplsupport - ok
22:29:29.0952 0x0b58 [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc C:\Windows\System32\WerSvc.dll
22:29:29.0952 0x0b58 WerSvc - ok
22:29:30.0015 0x0b58 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA, 711DD957AF98F1B835ECE0FEBCCF8FCC7763F1DAA232F1C9E80DE6DA123C7F33 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
22:29:30.0046 0x0b58 winachsf - ok
22:29:30.0093 0x0b58 [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
22:29:30.0108 0x0b58 WinDefend - ok
22:29:30.0124 0x0b58 WinHttpAutoProxySvc - ok
22:29:30.0202 0x0b58 [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:29:30.0217 0x0b58 Winmgmt - ok
22:29:30.0311 0x0b58 [ 7CFE68BDC065E55AA5E8421607037511, C2CE76D52AD4E31FC4216E94457DC16ABF65A5F3E883F0BD97AD387FB7574533 ] WinRM C:\Windows\system32\WsmSvc.dll
22:29:30.0373 0x0b58 WinRM - ok
22:29:30.0420 0x0b58 WisINT15 - ok
22:29:30.0483 0x0b58 [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc C:\Windows\System32\wlansvc.dll
22:29:30.0529 0x0b58 Wlansvc - ok
22:29:30.0561 0x0b58 [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
22:29:30.0576 0x0b58 WmiAcpi - ok
22:29:30.0639 0x0b58 [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:29:30.0639 0x0b58 wmiApSrv - ok
22:29:30.0701 0x0b58 [ C8F8AAC50B5B0BF821AB7D7126056B30, 9E392A6198B941FEBF3AE509626887C68457C7349866AB9B719B15FE52659C29 ] WMIService C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
22:29:30.0701 0x0b58 WMIService - ok
22:29:30.0779 0x0b58 [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
22:29:30.0810 0x0b58 WMPNetworkSvc - ok
22:29:30.0873 0x0b58 [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:29:30.0888 0x0b58 WPCSvc - ok
22:29:30.0919 0x0b58 [ 801FBDB89D472B3C467EB112A0FC9246, C24053FA12732089384D3AF06C676FF201D282FC5AD56A42B6EE8BAED4379CB2 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:29:30.0935 0x0b58 WPDBusEnum - ok
22:29:30.0982 0x0b58 [ DE9D36F91A4DF3D911626643DEBF11EA, 8029ECE76E29276BFB6ED3387AC560A9A779AAF683A4416E96334FAF7BDBADA0 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
22:29:30.0997 0x0b58 WpdUsb - ok
22:29:31.0107 0x0b58 [ C108DC20ACE05072350DBB6934E277FB, 548E6ABE4C4ADE48260FFDC7BADFD1697972EA3AE94D6576498C8A183D8CE0C8 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
22:29:31.0138 0x0b58 WPFFontCache_v0400 - ok
22:29:31.0169 0x0b58 [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:29:31.0169 0x0b58 ws2ifsl - ok
22:29:31.0216 0x0b58 [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc C:\Windows\System32\wscsvc.dll
22:29:31.0231 0x0b58 wscsvc - ok
22:29:31.0247 0x0b58 WSearch - ok
22:29:31.0372 0x0b58 [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
22:29:31.0450 0x0b58 wuauserv - ok
22:29:31.0512 0x0b58 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:29:31.0512 0x0b58 WudfPf - ok
22:29:31.0543 0x0b58 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:29:31.0559 0x0b58 WUDFRd - ok
22:29:31.0575 0x0b58 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:29:31.0590 0x0b58 wudfsvc - ok
22:29:31.0621 0x0b58 [ 88AF537264F2B818DA15479CEEAF5D7C, E0F95D6448FFB77351BB63ED444238F891B16748FD09F8BCCA23BEC4E341A96B ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
22:29:31.0621 0x0b58 XAudio - ok
22:29:31.0668 0x0b58 [ 15A317674A08DF26BE65164D959E9203, 6EEE0D1711F37936D157651E265A65137BCBFBDA17F066C844BAA0D53558F86A ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
22:29:31.0684 0x0b58 XAudioService - ok
22:29:31.0699 0x0b58 ================ Scan global ===============================
22:29:31.0731 0x0b58 [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll
22:29:31.0809 0x0b58 [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
22:29:31.0840 0x0b58 [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
22:29:31.0949 0x0b58 [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe
22:29:31.0965 0x0b58 [ Global ] - ok
22:29:31.0965 0x0b58 ================ Scan MBR ==================================
22:29:31.0996 0x0b58 [ A863475757CC50891AA8458C415E4B25 ] \Device\Harddisk0\DR0
22:29:34.0991 0x0b58 \Device\Harddisk0\DR0 - ok
22:29:34.0991 0x0b58 ================ Scan VBR ==================================
22:29:35.0007 0x0b58 [ 4C95A5F23337EA1555C76049A4DFF0DA ] \Device\Harddisk0\DR0\Partition1
22:29:35.0038 0x0b58 \Device\Harddisk0\DR0\Partition1 - ok
22:29:35.0053 0x0b58 [ C6555EA719F93BD873B9EC7CDED32779 ] \Device\Harddisk0\DR0\Partition2
22:29:35.0116 0x0b58 \Device\Harddisk0\DR0\Partition2 - ok
22:29:35.0116 0x0b58 ================ Scan generic autorun ======================
22:29:35.0428 0x0b58 [ 44ADDA5FB88EE14F57A246285775AC2F, 2776225BA9F22C553453541DA0285E093B4F2019DB6FE640D033BA45045299C8 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
22:29:35.0693 0x0b58 AvastUI.exe - ok
22:29:35.0849 0x0b58 [ 0D392EDE3B97E0B3131B2F63EF1DB94E, 3EDA280F91097293E00BF984D377E1111CFDE1FC81B30A3FDEB38F321EF82BB6 ] C:\Program Files\Windows Defender\MSASCui.exe
22:29:35.0880 0x0b58 Windows Defender - ok
22:29:35.0927 0x0b58 [ 5A2A87028CB479FFA3ABBDCC98B09C47, 6FEFA20F8C450A28A027BDC5E3D657F3074A23928EEBD47806B91E143BC6DD25 ] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
22:29:35.0943 0x0b58 WarReg_PopUp - ok
22:29:35.0974 0x0b58 [ EED2120454E74AA5C257947986B4D068, 1E68F6DF831941B8F3C5F2B0A67AB5F9A9C94901DD37B31654D91DE38110B9E0 ] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
22:29:35.0974 0x0b58 SynTPStart - ok
22:29:36.0239 0x0b58 [ 811AC69DB60ACB7F7B802434AA3E37E2, FCA8BF49E612C00D183A1202A6579D3AE596F6A227595729571CDD989EBE3A07 ] C:\Windows\RtHDVCpl.exe
22:29:36.0457 0x0b58 RtHDVCpl - ok
22:29:36.0504 0x0b58 [ 583385D05FCA7A0470C675B90B4CF063, C5470FA8701E3CFC1D0C9ECBB86C8B6BBF3DF1F4F89AEC05707ECFDACFF0D4F1 ] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
22:29:36.0504 0x0b58 RemoteControl - ok
22:29:36.0551 0x0b58 [ 2AC7F8B8BF0D5D327A3A2A00453222C4, F71B6CFA7F4AE2A13C8DDF296631EF26C72E7C0387D88B9701577DAE133EC583 ] C:\Windows\PLFSetI.exe
22:29:36.0551 0x0b58 PLFSetI - ok
22:29:36.0582 0x0b58 [ FF51AA0D606326B9842EA5A3F02060D5, F661EA2647C27BFF7D476FD724A4919C2029DDA75948C5B43E43ADC77130EB16 ] C:\Windows\system32\igfxpers.exe
22:29:36.0598 0x0b58 Persistence - ok
22:29:36.0660 0x0b58 [ D1638A3F76C8D24731DF8D14F7905101, 15EABC642121B62F96DA90A10AF784C7749195FD7D765A0F326DD70633701971 ] C:\PROGRA~1\LAUNCH~1\LManager.exe
22:29:36.0676 0x0b58 LManager - ok
22:29:36.0723 0x0b58 [ D5529678A1D92D125B43E3C2A308223E, 51D4C7EFFC7084FC3B12BD1FEB7C2D26BBDE9C5B27697ABEDA4D1217743A7C40 ] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
22:29:36.0723 0x0b58 LanguageShortcut - ok
22:29:36.0754 0x0b58 [ 9F5F8F97D5F18AE35F986CE593F7D01B, C612933B52113B5B0935EE845050F4CC9A7FBFCCECE20170D314AEB4C1E3CD7C ] C:\Windows\system32\igfxtray.exe
22:29:36.0754 0x0b58 IgfxTray - ok
22:29:36.0816 0x0b58 [ EC9B27B37D8E9D361C38E8D364F09611, A2405EEB4599FB7C225A334B83B09A049DD0D665A07BEC5CFD87AE2320AABD0B ] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
22:29:36.0816 0x0b58 IAAnotif - ok
22:29:36.0832 0x0b58 [ 55750597BAA561644674C6F673C08302, 602209C1EDD60F73CE2E05A0DF74C66D783B685E74EC569EED6EEB08771C359B ] C:\Windows\system32\hkcmd.exe
22:29:36.0847 0x0b58 HotKeysCmds - ok
22:29:36.0910 0x0b58 [ DF463A854EA0D19E94EFAF0FAC9E9CB9, 4326977EACBA3FF409B3447104165CB2E7ACB8E9EE9F9C0F3C5C574E42DF7984 ] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
22:29:36.0941 0x0b58 eDataSecurity Loader - ok
22:29:37.0050 0x0b58 [ 223AD0CA4092AEFFE0D0DE25502A3DB6, D7A0E5639D329C8245515712125C7C489645B70A06A4F6D1DBE06BA7BD3C96DC ] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe
22:29:37.0081 0x0b58 CanonSolutionMenu - ok
22:29:37.0222 0x0b58 [ 0282F454BF380AF26EFC3913C6D435FF, 8E5EB6EBE7044381B3F3E703F3B60F073649856B74A2BEC99A669F1F77C8C5BA ] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
22:29:37.0284 0x0b58 CanonMyPrinter - ok
22:29:37.0300 0x0b58 Adobe Reader Speed Launcher - ok
22:29:37.0425 0x0b58 [ 47EA5F76FAB723C61AB4A0D79BAD512C, A7A38EB0A7068B160E6949945EF639F999A06AE35746F6E79C7350745798E5C9 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
22:29:37.0456 0x0b58 Adobe ARM - ok
22:29:37.0565 0x0b58 [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
22:29:37.0612 0x0b58 Sidebar - ok
22:29:37.0612 0x0b58 WindowsWelcomeCenter - ok
22:29:37.0659 0x0b58 [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
22:29:37.0690 0x0b58 Sidebar - ok
22:29:37.0705 0x0b58 WindowsWelcomeCenter - ok
22:29:37.0721 0x0b58 [ 35937EAD711207544E219C2A19A78A7D, EE6E5EAE00F577D7C3FFB8C0D8EE484552A337CEAA27FCB107174A9879FE7362 ] C:\Program Files\Windows Media Player\WMPNSCFG.exe
22:29:37.0737 0x0b58 WMPNSCFG - ok
22:29:37.0737 0x0b58 Waiting for KSN requests completion. In queue: 20
22:29:38.0751 0x0b58 Waiting for KSN requests completion. In queue: 20
22:29:39.0765 0x0b58 Waiting for KSN requests completion. In queue: 20
22:29:40.0841 0x0b58 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.0.2208.712 ), 0x40000 ( disabled : updated )
22:29:40.0841 0x0b58 Win FW state via NFP2: disabled
22:29:43.0243 0x0b58 ============================================================
22:29:43.0243 0x0b58 Scan finished
22:29:43.0243 0x0b58 ============================================================
22:29:43.0259 0x0b30 Detected object count: 0
22:29:43.0259 0x0b30 Actual detected object count: 0
22:30:49.0185 0x0f8c Deinitialize success

Zatím mohu říct, že start počítače se významně neurychlil i když asi o trochu ano. Možná mi trochu rychleji překlikávají stránky na internetu.

Zdraví
Jiří Štěrba

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod jaro3 » 23 úno 2015 10:13

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 23 úno 2015 23:04

Aplikoval jsem ComboFix a přikládám log:

ComboFix 15-02-16.01 - Jiří 23.02.2015 22:08:08.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2038.956 [GMT 1:00]
Spuštěný z: c:\users\Ji°Ý\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\PFRO.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-01-23 do 2015-02-23 )))))))))))))))))))))))))))))))
.
.
2015-02-23 21:21 . 2015-02-23 21:21 -------- d-----w- c:\users\Jiří\AppData\Local\temp
2015-02-23 21:21 . 2015-02-23 21:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-23 12:16 . 2015-02-23 12:16 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28A09C95-35A0-4358-B1B3-436D24344B6F}\offreg.dll
2015-02-22 21:04 . 2015-02-22 20:33 24064 ----a-w- c:\windows\zoek-delete.exe
2015-02-22 20:25 . 2015-02-22 21:00 -------- d-----w- C:\zoek_backup
2015-02-20 06:48 . 2015-01-29 09:49 9041640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28A09C95-35A0-4358-B1B3-436D24344B6F}\mpengine.dll
2015-02-12 14:11 . 2015-02-22 21:11 -------- d-----w- c:\program files\Mozilla Maintenance Service
2015-02-12 07:08 . 2015-01-23 03:00 1810944 ----a-w- c:\windows\system32\jscript9.dll
2015-02-11 12:32 . 2014-11-26 02:05 564224 ----a-w- c:\windows\system32\oleaut32.dll
2015-02-11 12:31 . 2015-01-09 00:20 2063360 ----a-w- c:\windows\system32\win32k.sys
2015-02-11 12:31 . 2015-01-13 01:39 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-11 12:30 . 2015-01-15 04:13 440760 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-02-11 12:30 . 2014-12-08 01:59 306176 ----a-w- c:\windows\system32\scesrv.dll
2015-02-06 20:57 . 2015-02-06 20:57 -------- d-----w- c:\users\Jiří\Mělník-město parků a zeleně
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-05 15:41 . 2012-05-15 18:02 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-02-05 15:41 . 2011-06-07 06:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-01 20:56 . 2015-01-04 12:58 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-01-30 15:57 . 2015-01-03 13:09 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-22 23:50 . 2010-11-13 08:16 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 00:25 . 2015-01-14 22:33 115200 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-13 19:12 . 2014-12-13 19:11 787800 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-12-13 19:12 . 2014-12-13 19:11 423784 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-12-13 19:11 . 2014-12-13 19:11 57928 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-12-13 19:11 . 2014-12-13 19:11 206248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-12-13 19:11 . 2014-12-13 19:11 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-12-13 19:11 . 2014-12-13 19:11 70384 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-12-13 19:11 . 2014-12-13 19:11 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-12-13 19:11 . 2014-12-13 19:11 55240 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-12-13 19:11 . 2014-12-13 19:11 291352 ----a-w- c:\windows\system32\aswBoot.exe
2014-12-13 19:11 . 2014-12-13 19:11 43152 ----a-w- c:\windows\avastSS.scr
2014-12-06 03:14 . 2015-01-14 22:27 153600 ----a-w- c:\windows\system32\profsvc.dll
2014-12-06 03:14 . 2015-01-14 22:27 48640 ----a-w- c:\windows\system32\nlaapi.dll
2014-12-06 03:14 . 2015-01-14 22:27 174080 ----a-w- c:\windows\system32\nlasvc.dll
2014-12-06 03:14 . 2015-01-14 22:27 93184 ----a-w- c:\windows\system32\ncsi.dll
2014-12-03 02:06 . 2014-12-10 21:32 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-12-13 19:10 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 01:00 39472 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-08 4853760]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2008-01-22 81920]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-01-07 858632]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 62760]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-01-03 521776]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-8-28 739880]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe 9999 [2008-4-27 535336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-19 19:35 1084744 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-02-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-15 15:41]
.
2015-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-30 06:48]
.
2015-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-30 06:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 109.238.208.18 109.238.208.19
FF - ProfilePath - c:\users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default\
FF - prefs.js: browser.startup.homepage - about:home
.
.
------- Asociace souborů -------
.
.txt=STDUViewerFile.TXT
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
c:\users\Jiří\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PCCDisabled\OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-CardWorks - c:\program files\NCH Software\CardWorks\uninst.exe
AddRemove-PatchBeam_is1 - c:\program files\PatchBeam\unins000.exe
AddRemove-{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029 - c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\CSY\\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-02-23 22:21
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2015-02-23 22:25:04
ComboFix-quarantined-files.txt 2015-02-23 21:25
.
Před spuštěním: 3 104 862 208
Po spuštění: 3 322 626 048
.
- - End Of File - - 7D3640CDC4EDF27AAAA557B9E233DD48
A863475757CC50891AA8458C415E4B25

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 23 úno 2015 23:21

Ještě se chci zeptat, jestli není problém v tom, že v klidovém stavu počítače, kdy je najetý, ustálený, připojený k internetu ale není spuštěna žádná aplikace, je paměť využitá na cca 45 %. Mám 2 GB fyzickou paměť a ta mi ukazuje ve správci úloh 45%.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod jaro3 » 24 úno 2015 10:49

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::
KillAll::
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000



Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Jiri1952
nováček
Příspěvky: 29
Registrován: únor 14
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod Jiri1952 » 01 bře 2015 16:29

Provedl jsem činnosti dle pokynů a přikládám logy:

ComboFix 15-02-16.01 - Jiří 01.03.2015 12:19:56.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2038.1059 [GMT 1:00]
Spuštěný z: c:\users\Ji°Ý\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Ji°Ý\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-02-01 do 2015-03-01 )))))))))))))))))))))))))))))))
.
.
2015-03-01 11:34 . 2015-03-01 11:34 -------- d-----w- c:\users\Jiří\AppData\Local\temp
2015-03-01 11:34 . 2015-03-01 11:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-27 07:45 . 2015-01-29 09:49 9041640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C8BE0AE2-B2D8-4C52-87AB-664AC780FC5D}\mpengine.dll
2015-02-22 21:04 . 2015-02-22 20:33 24064 ----a-w- c:\windows\zoek-delete.exe
2015-02-22 20:25 . 2015-02-22 21:00 -------- d-----w- C:\zoek_backup
2015-02-12 14:11 . 2015-02-22 21:11 -------- d-----w- c:\program files\Mozilla Maintenance Service
2015-02-12 07:08 . 2015-01-23 03:00 1810944 ----a-w- c:\windows\system32\jscript9.dll
2015-02-11 12:32 . 2014-11-26 02:05 564224 ----a-w- c:\windows\system32\oleaut32.dll
2015-02-11 12:31 . 2015-01-09 00:20 2063360 ----a-w- c:\windows\system32\win32k.sys
2015-02-11 12:31 . 2015-01-13 01:39 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-11 12:30 . 2015-01-15 04:13 440760 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-02-11 12:30 . 2014-12-08 01:59 306176 ----a-w- c:\windows\system32\scesrv.dll
2015-02-06 20:57 . 2015-02-06 20:57 -------- d-----w- c:\users\Jiří\Mělník-město parků a zeleně
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-05 15:41 . 2012-05-15 18:02 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-02-05 15:41 . 2011-06-07 06:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-01 20:56 . 2015-01-04 12:58 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-01-30 15:57 . 2015-01-03 13:09 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-22 23:50 . 2010-11-13 08:16 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 00:25 . 2015-01-14 22:33 115200 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-13 19:12 . 2014-12-13 19:11 787800 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-12-13 19:12 . 2014-12-13 19:11 423784 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-12-13 19:11 . 2014-12-13 19:11 57928 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-12-13 19:11 . 2014-12-13 19:11 206248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-12-13 19:11 . 2014-12-13 19:11 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-12-13 19:11 . 2014-12-13 19:11 70384 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-12-13 19:11 . 2014-12-13 19:11 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-12-13 19:11 . 2014-12-13 19:11 55240 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-12-13 19:11 . 2014-12-13 19:11 291352 ----a-w- c:\windows\system32\aswBoot.exe
2014-12-13 19:11 . 2014-12-13 19:11 43152 ----a-w- c:\windows\avastSS.scr
2014-12-06 03:14 . 2015-01-14 22:27 153600 ----a-w- c:\windows\system32\profsvc.dll
2014-12-06 03:14 . 2015-01-14 22:27 48640 ----a-w- c:\windows\system32\nlaapi.dll
2014-12-06 03:14 . 2015-01-14 22:27 174080 ----a-w- c:\windows\system32\nlasvc.dll
2014-12-06 03:14 . 2015-01-14 22:27 93184 ----a-w- c:\windows\system32\ncsi.dll
2014-12-03 02:06 . 2014-12-10 21:32 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-12-13 19:10 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 01:00 39472 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-08 4853760]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2008-01-22 81920]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-01-07 858632]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 62760]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-01-03 521776]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-8-28 739880]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe 9999 [2008-4-27 535336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-19 19:35 1084744 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-03-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-15 15:41]
.
2015-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-30 06:48]
.
2015-03-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-30 06:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 109.238.208.18 109.238.208.19
FF - ProfilePath - c:\users\Jiří\AppData\Roaming\Mozilla\Firefox\Profiles\zayzvpsa.default\
FF - prefs.js: browser.startup.homepage - about:home
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-03-01 12:34
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4792)
c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\system32\btmmhook.dll
c:\acer\Empowering Technology\EPOWER\SysHook.dll
.
Celkový čas: 2015-03-01 12:38:19
ComboFix-quarantined-files.txt 2015-03-01 11:38
ComboFix2.txt 2015-02-23 21:25
.
Před spuštěním: 3 889 815 552
Po spuštění: 3 728 486 400
.
- - End Of File - - 1F394E7CF5544B296690547D821BBAAB
A863475757CC50891AA8458C415E4B25





Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:55:26, on 1.3.2015
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16609)

FIREFOX: 35.0.1 (x86 cs)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Users\Jiří\Desktop\HijackThis(2).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: PCCDisabled
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8146 bytes





aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
Run date: 2015-03-01 14:08:04
-----------------------------
14:08:04.813 OS Version: Windows 6.0.6002 Service Pack 2
14:08:04.813 Number of processors: 2 586 0xF0D
14:08:04.813 ComputerName: MUDROCH11-PC UserName: Jiří
14:08:09.212 Initialize success
14:08:09.244 VM: initialized successfully
14:08:09.244 VM: Intel CPU virtualization not supported
14:08:15.109 AVAST engine defs: 15030100
14:09:25.637 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
14:09:25.637 Disk 0 Vendor: Hitachi_HTS543216L9A300 FB2OC40C Size: 152627MB BusType: 3
14:09:25.808 Disk 0 MBR read successfully
14:09:25.824 Disk 0 MBR scan
14:09:25.824 Disk 0 unknown MBR code
14:09:26.479 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048
14:09:26.495 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 71317 MB offset 20482048
14:09:26.526 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 71308 MB offset 166539264
14:09:26.557 Disk 0 scanning sectors +312578048
14:09:26.776 Disk 0 scanning C:\Windows\system32\drivers
14:09:39.302 Service scanning
14:10:13.841 Modules scanning
14:10:13.856 Disk 0 trace - called modules:
14:10:13.888 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
14:10:13.888 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d54ac8]
14:10:13.903 3 CLASSPNP.SYS[889a38b3] -> nt!IofCallDriver -> [0x8569ea30]
14:10:13.903 5 acpi.sys[806a06bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x856a8b98]
14:10:14.387 AVAST engine scan C:\Windows
14:10:18.505 AVAST engine scan C:\Windows\system32
14:13:37.982 AVAST engine scan C:\Windows\system32\drivers
14:13:55.813 AVAST engine scan C:\Users\Jiří
14:27:43.580 AVAST engine scan C:\ProgramData
14:29:41.454 Disk 0 statistics 2847865/0/0 @ 1,36 MB/s
14:29:41.470 Scan finished successfully
14:30:37.552 Disk 0 MBR has been saved successfully to "C:\Users\Jiří\Desktop\MBR.dat"
14:30:37.552 The log file has been saved successfully to "C:\Users\Jiří\Desktop\aswMBR01032015.txt"


Zdraví
Jiří Štěrba

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook

Příspěvekod jaro3 » 02 bře 2015 09:25

Odinstaluj:
Spybot - Search & Destroy

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: PCCDisabled
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)


Script v Combofixu udělej znovu , v noz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Majestic-12 [Bot] a 89 hostů