jediný kde sem to našel bylo v registrech tady:
HKEY_CURRENT_USER\Software\Zone Labs\zonealarm
příliš mnoho svchost.exe a velké využití pameti. prosím help Vyřešeno
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
21:25:06.0863 3280 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
21:25:07.0066 3280 ============================================================
21:25:07.0066 3280 Current date / time: 2012/09/15 21:25:07.0066
21:25:07.0066 3280 SystemInfo:
21:25:07.0066 3280
21:25:07.0066 3280 OS Version: 6.1.7601 ServicePack: 1.0
21:25:07.0066 3280 Product type: Workstation
21:25:07.0066 3280 ComputerName: PETR-PC
21:25:07.0066 3280 UserName: Petr
21:25:07.0066 3280 Windows directory: C:\Windows
21:25:07.0066 3280 System windows directory: C:\Windows
21:25:07.0066 3280 Processor architecture: Intel x86
21:25:07.0066 3280 Number of processors: 8
21:25:07.0066 3280 Page size: 0x1000
21:25:07.0066 3280 Boot type: Normal boot
21:25:07.0066 3280 ============================================================
21:25:08.0283 3280 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
21:25:08.0283 3280 ============================================================
21:25:08.0283 3280 \Device\Harddisk0\DR0:
21:25:08.0298 3280 MBR partitions:
21:25:08.0298 3280 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384851
21:25:08.0298 3280 ============================================================
21:25:08.0298 3280 C: <-> \Device\Harddisk0\DR0\Partition1
21:25:08.0314 3280 ============================================================
21:25:08.0314 3280 Initialize success
21:25:08.0314 3280 ============================================================
21:25:12.0854 3636 ============================================================
21:25:12.0854 3636 Scan started
21:25:12.0854 3636 Mode: Manual;
21:25:12.0854 3636 ============================================================
21:25:13.0977 3636 ================ Scan system memory ========================
21:25:13.0977 3636 System memory - ok
21:25:13.0977 3636 ================ Scan services =============================
21:25:14.0164 3636 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
21:25:14.0180 3636 1394ohci - ok
21:25:14.0211 3636 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:25:14.0211 3636 ACPI - ok
21:25:14.0226 3636 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
21:25:14.0242 3636 AcpiPmi - ok
21:25:14.0273 3636 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
21:25:14.0304 3636 adp94xx - ok
21:25:14.0320 3636 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
21:25:14.0336 3636 adpahci - ok
21:25:14.0351 3636 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
21:25:14.0367 3636 adpu320 - ok
21:25:14.0382 3636 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:25:14.0382 3636 AeLookupSvc - ok
21:25:14.0414 3636 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
21:25:14.0429 3636 AFD - ok
21:25:14.0429 3636 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
21:25:14.0445 3636 agp440 - ok
21:25:14.0460 3636 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
21:25:14.0476 3636 aic78xx - ok
21:25:14.0492 3636 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
21:25:14.0492 3636 ALG - ok
21:25:14.0507 3636 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
21:25:14.0523 3636 aliide - ok
21:25:14.0523 3636 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
21:25:14.0538 3636 amdagp - ok
21:25:14.0538 3636 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
21:25:14.0554 3636 amdide - ok
21:25:14.0554 3636 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
21:25:14.0570 3636 AmdK8 - ok
21:25:14.0585 3636 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
21:25:14.0601 3636 AmdPPM - ok
21:25:14.0632 3636 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:25:14.0648 3636 amdsata - ok
21:25:14.0663 3636 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
21:25:14.0679 3636 amdsbs - ok
21:25:14.0694 3636 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:25:14.0710 3636 amdxata - ok
21:25:14.0741 3636 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
21:25:14.0757 3636 AppID - ok
21:25:14.0757 3636 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:25:14.0772 3636 AppIDSvc - ok
21:25:14.0788 3636 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
21:25:14.0788 3636 Appinfo - ok
21:25:14.0804 3636 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
21:25:14.0804 3636 AppMgmt - ok
21:25:14.0804 3636 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
21:25:14.0819 3636 arc - ok
21:25:14.0835 3636 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
21:25:14.0835 3636 arcsas - ok
21:25:14.0866 3636 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:25:14.0882 3636 AsyncMac - ok
21:25:14.0882 3636 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
21:25:14.0882 3636 atapi - ok
21:25:14.0897 3636 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:25:14.0913 3636 AudioEndpointBuilder - ok
21:25:14.0913 3636 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
21:25:14.0913 3636 Audiosrv - ok
21:25:14.0928 3636 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:25:14.0928 3636 AxInstSV - ok
21:25:14.0944 3636 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
21:25:14.0960 3636 b06bdrv - ok
21:25:14.0975 3636 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
21:25:15.0006 3636 b57nd60x - ok
21:25:15.0022 3636 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
21:25:15.0022 3636 BDESVC - ok
21:25:15.0038 3636 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
21:25:15.0053 3636 Beep - ok
21:25:15.0069 3636 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
21:25:15.0069 3636 BFE - ok
21:25:15.0131 3636 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
21:25:15.0147 3636 BITS - ok
21:25:15.0162 3636 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
21:25:15.0162 3636 blbdrive - ok
21:25:15.0178 3636 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:25:15.0194 3636 bowser - ok
21:25:15.0209 3636 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:25:15.0209 3636 BrFiltLo - ok
21:25:15.0209 3636 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:25:15.0225 3636 BrFiltUp - ok
21:25:15.0240 3636 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
21:25:15.0240 3636 Browser - ok
21:25:15.0256 3636 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
21:25:15.0272 3636 Brserid - ok
21:25:15.0287 3636 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
21:25:15.0287 3636 BrSerWdm - ok
21:25:15.0287 3636 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
21:25:15.0287 3636 BrUsbMdm - ok
21:25:15.0303 3636 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
21:25:15.0303 3636 BrUsbSer - ok
21:25:15.0318 3636 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
21:25:15.0334 3636 BTHMODEM - ok
21:25:15.0334 3636 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
21:25:15.0334 3636 bthserv - ok
21:25:15.0350 3636 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:25:15.0365 3636 cdfs - ok
21:25:15.0381 3636 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:25:15.0412 3636 cdrom - ok
21:25:15.0412 3636 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
21:25:15.0412 3636 CertPropSvc - ok
21:25:15.0443 3636 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
21:25:15.0443 3636 circlass - ok
21:25:15.0459 3636 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
21:25:15.0459 3636 CLFS - ok
21:25:15.0506 3636 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:25:15.0521 3636 clr_optimization_v2.0.50727_32 - ok
21:25:15.0568 3636 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:25:15.0584 3636 clr_optimization_v4.0.30319_32 - ok
21:25:15.0599 3636 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
21:25:15.0615 3636 CmBatt - ok
21:25:15.0630 3636 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
21:25:15.0646 3636 cmdide - ok
21:25:15.0693 3636 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
21:25:15.0708 3636 CNG - ok
21:25:15.0724 3636 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
21:25:15.0740 3636 Compbatt - ok
21:25:15.0755 3636 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
21:25:15.0755 3636 CompositeBus - ok
21:25:15.0755 3636 COMSysApp - ok
21:25:15.0771 3636 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
21:25:15.0802 3636 crcdisk - ok
21:25:15.0818 3636 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:25:15.0818 3636 CryptSvc - ok
21:25:15.0849 3636 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
21:25:15.0896 3636 CSC - ok
21:25:15.0911 3636 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
21:25:15.0927 3636 CscService - ok
21:25:15.0942 3636 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
21:25:15.0942 3636 DcomLaunch - ok
21:25:15.0958 3636 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
21:25:15.0958 3636 defragsvc - ok
21:25:15.0974 3636 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:25:15.0989 3636 DfsC - ok
21:25:16.0005 3636 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
21:25:16.0005 3636 Dhcp - ok
21:25:16.0020 3636 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
21:25:16.0036 3636 discache - ok
21:25:16.0036 3636 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
21:25:16.0052 3636 Disk - ok
21:25:16.0083 3636 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:25:16.0083 3636 Dnscache - ok
21:25:16.0098 3636 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
21:25:16.0098 3636 dot3svc - ok
21:25:16.0114 3636 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
21:25:16.0130 3636 DPS - ok
21:25:16.0145 3636 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:25:16.0161 3636 drmkaud - ok
21:25:16.0192 3636 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:25:16.0286 3636 DXGKrnl - ok
21:25:16.0301 3636 [ D78F1C5B7B01DF050E011B4FFFDB9048 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
21:25:16.0332 3636 eamonm - ok
21:25:16.0348 3636 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
21:25:16.0348 3636 EapHost - ok
21:25:16.0426 3636 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
21:25:16.0504 3636 ebdrv - ok
21:25:16.0520 3636 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
21:25:16.0520 3636 EFS - ok
21:25:16.0520 3636 [ 3C747A0D8CE29720302972AC6ED09733 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
21:25:16.0535 3636 ehdrv - ok
21:25:16.0644 3636 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:25:16.0660 3636 ehRecvr - ok
21:25:16.0676 3636 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
21:25:16.0691 3636 ehSched - ok
21:25:16.0769 3636 [ 679AD4AFCAF9520CC5607D204AE27CCE ] EhttpSrv C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
21:25:16.0785 3636 EhttpSrv - ok
21:25:16.0785 3636 [ 82A0EE1F5CCC82CC5453D24FF186E9B0 ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
21:25:16.0800 3636 ekrn - ok
21:25:16.0816 3636 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
21:25:16.0878 3636 elxstor - ok
21:25:16.0894 3636 [ 5680E2C38BA53693D724B796E67E8261 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
21:25:16.0925 3636 epfw - ok
21:25:16.0941 3636 [ D9585E144C31D409E28B205253459C3A ] Epfwndis C:\Windows\system32\DRIVERS\Epfwndis.sys
21:25:16.0956 3636 Epfwndis - ok
21:25:17.0003 3636 [ 80F1B9954907D59EE474790EEE11605F ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
21:25:17.0034 3636 epfwwfp - ok
21:25:17.0066 3636 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
21:25:17.0112 3636 ErrDev - ok
21:25:17.0128 3636 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
21:25:17.0128 3636 EventSystem - ok
21:25:17.0144 3636 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
21:25:17.0144 3636 exfat - ok
21:25:17.0159 3636 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:25:17.0175 3636 fastfat - ok
21:25:17.0206 3636 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
21:25:17.0206 3636 Fax - ok
21:25:17.0222 3636 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
21:25:17.0237 3636 fdc - ok
21:25:17.0253 3636 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
21:25:17.0253 3636 fdPHost - ok
21:25:17.0253 3636 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
21:25:17.0253 3636 FDResPub - ok
21:25:17.0268 3636 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:25:17.0284 3636 FileInfo - ok
21:25:17.0300 3636 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:25:17.0300 3636 Filetrace - ok
21:25:17.0315 3636 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
21:25:17.0331 3636 flpydisk - ok
21:25:17.0346 3636 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:25:17.0362 3636 FltMgr - ok
21:25:17.0378 3636 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
21:25:17.0378 3636 FontCache - ok
21:25:17.0409 3636 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:25:17.0409 3636 FontCache3.0.0.0 - ok
21:25:17.0424 3636 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:25:17.0440 3636 FsDepends - ok
21:25:17.0487 3636 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:25:17.0518 3636 Fs_Rec - ok
21:25:17.0518 3636 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:25:17.0534 3636 fvevol - ok
21:25:17.0534 3636 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
21:25:17.0549 3636 gagp30kx - ok
21:25:17.0565 3636 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
21:25:17.0580 3636 gpsvc - ok
21:25:17.0580 3636 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
21:25:17.0612 3636 hcw85cir - ok
21:25:17.0627 3636 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:25:17.0690 3636 HdAudAddService - ok
21:25:17.0690 3636 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
21:25:17.0705 3636 HDAudBus - ok
21:25:17.0705 3636 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
21:25:17.0721 3636 HidBatt - ok
21:25:17.0736 3636 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
21:25:17.0752 3636 HidBth - ok
21:25:17.0783 3636 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
21:25:17.0799 3636 HidIr - ok
21:25:17.0799 3636 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
21:25:17.0799 3636 hidserv - ok
21:25:17.0830 3636 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:25:17.0846 3636 HidUsb - ok
21:25:17.0892 3636 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:25:17.0892 3636 hkmsvc - ok
21:25:17.0924 3636 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:25:17.0924 3636 HomeGroupListener - ok
21:25:17.0986 3636 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:25:18.0002 3636 HomeGroupProvider - ok
21:25:18.0017 3636 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
21:25:18.0048 3636 HpSAMD - ok
21:25:18.0126 3636 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:25:18.0142 3636 HTTP - ok
21:25:18.0142 3636 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:25:18.0142 3636 hwpolicy - ok
21:25:18.0158 3636 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
21:25:18.0189 3636 i8042prt - ok
21:25:18.0204 3636 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:25:18.0220 3636 iaStorV - ok
21:25:18.0267 3636 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:25:18.0282 3636 idsvc - ok
21:25:18.0282 3636 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
21:25:18.0314 3636 iirsp - ok
21:25:18.0329 3636 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
21:25:18.0329 3636 IKEEXT - ok
21:25:18.0891 3636 [ 0DBEF9CD5A2CD71240DD5AFCEE56D073 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
21:25:18.0938 3636 IntcAzAudAddService - ok
21:25:18.0969 3636 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
21:25:18.0984 3636 intelide - ok
21:25:18.0984 3636 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
21:25:19.0000 3636 intelppm - ok
21:25:19.0016 3636 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:25:19.0016 3636 IPBusEnum - ok
21:25:19.0016 3636 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:25:19.0031 3636 IpFilterDriver - ok
21:25:19.0062 3636 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:25:19.0062 3636 iphlpsvc - ok
21:25:19.0078 3636 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
21:25:19.0109 3636 IPMIDRV - ok
21:25:19.0125 3636 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:25:19.0172 3636 IPNAT - ok
21:25:19.0187 3636 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:25:19.0203 3636 IRENUM - ok
21:25:19.0218 3636 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
21:25:19.0234 3636 isapnp - ok
21:25:19.0250 3636 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
21:25:19.0265 3636 iScsiPrt - ok
21:25:19.0296 3636 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
21:25:19.0312 3636 kbdclass - ok
21:25:19.0343 3636 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
21:25:19.0359 3636 kbdhid - ok
21:25:19.0374 3636 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
21:25:19.0374 3636 KeyIso - ok
21:25:19.0390 3636 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:25:19.0406 3636 KSecDD - ok
21:25:19.0452 3636 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:25:19.0499 3636 KSecPkg - ok
21:25:19.0593 3636 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
21:25:19.0608 3636 KtmRm - ok
21:25:19.0608 3636 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
21:25:19.0624 3636 LanmanServer - ok
21:25:19.0624 3636 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:25:19.0640 3636 LanmanWorkstation - ok
21:25:19.0733 3636 [ 3AF6B73A3AD1FC37C5933441F66CEB91 ] LBTServ C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
21:25:19.0749 3636 LBTServ - ok
21:25:19.0780 3636 [ 7F9C7B28CF1C859E1C42619EEA946DC8 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
21:25:19.0796 3636 LHidFilt - ok
21:25:19.0874 3636 [ C34411A244029F1C08687F7C752C4563 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
21:25:19.0874 3636 LightScribeService - ok
21:25:19.0889 3636 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:25:19.0905 3636 lltdio - ok
21:25:19.0952 3636 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:25:19.0952 3636 lltdsvc - ok
21:25:19.0967 3636 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
21:25:19.0967 3636 lmhosts - ok
21:25:19.0998 3636 [ AB33792A87285344F43B5CE23421BAB0 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
21:25:19.0998 3636 LMouFilt - ok
21:25:20.0014 3636 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
21:25:20.0030 3636 LSI_FC - ok
21:25:20.0045 3636 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
21:25:20.0061 3636 LSI_SAS - ok
21:25:20.0076 3636 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:25:20.0092 3636 LSI_SAS2 - ok
21:25:20.0108 3636 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:25:20.0123 3636 LSI_SCSI - ok
21:25:20.0139 3636 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
21:25:20.0154 3636 luafv - ok
21:25:20.0154 3636 [ 77030525CD86A93F1AF34FA9B96D33CE ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys
21:25:20.0170 3636 LUsbFilt - ok
21:25:20.0186 3636 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:25:20.0186 3636 Mcx2Svc - ok
21:25:20.0186 3636 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
21:25:20.0217 3636 megasas - ok
21:25:20.0217 3636 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
21:25:20.0232 3636 MegaSR - ok
21:25:20.0264 3636 Microsoft SharePoint Workspace Audit Service - ok
21:25:20.0279 3636 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
21:25:20.0279 3636 MMCSS - ok
21:25:20.0310 3636 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
21:25:20.0310 3636 Modem - ok
21:25:20.0342 3636 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:25:20.0388 3636 monitor - ok
21:25:20.0388 3636 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:25:20.0404 3636 mouclass - ok
21:25:20.0435 3636 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:25:20.0435 3636 mouhid - ok
21:25:20.0466 3636 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:25:20.0482 3636 mountmgr - ok
21:25:20.0498 3636 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
21:25:20.0544 3636 mpio - ok
21:25:20.0544 3636 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:25:20.0607 3636 mpsdrv - ok
21:25:20.0685 3636 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:25:20.0685 3636 MpsSvc - ok
21:25:20.0700 3636 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:25:20.0732 3636 MRxDAV - ok
21:25:20.0747 3636 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:25:20.0778 3636 mrxsmb - ok
21:25:20.0794 3636 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:25:20.0825 3636 mrxsmb10 - ok
21:25:20.0841 3636 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:25:20.0856 3636 mrxsmb20 - ok
21:25:20.0872 3636 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
21:25:20.0872 3636 msahci - ok
21:25:20.0888 3636 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
21:25:20.0903 3636 msdsm - ok
21:25:20.0919 3636 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
21:25:20.0919 3636 MSDTC - ok
21:25:20.0934 3636 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:25:20.0950 3636 Msfs - ok
21:25:20.0950 3636 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:25:20.0950 3636 mshidkmdf - ok
21:25:20.0981 3636 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:25:21.0012 3636 msisadrv - ok
21:25:21.0059 3636 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:25:21.0059 3636 MSiSCSI - ok
21:25:21.0075 3636 msiserver - ok
21:25:21.0090 3636 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:25:21.0090 3636 MSKSSRV - ok
21:25:21.0106 3636 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:25:21.0122 3636 MSPCLOCK - ok
21:25:21.0122 3636 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:25:21.0122 3636 MSPQM - ok
21:25:21.0153 3636 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:25:21.0168 3636 MsRPC - ok
21:25:21.0184 3636 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
21:25:21.0184 3636 mssmbios - ok
21:25:21.0184 3636 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:25:21.0200 3636 MSTEE - ok
21:25:21.0215 3636 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
21:25:21.0246 3636 MTConfig - ok
21:25:21.0262 3636 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
21:25:21.0278 3636 Mup - ok
21:25:21.0278 3636 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
21:25:21.0309 3636 napagent - ok
21:25:21.0324 3636 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:25:21.0356 3636 NativeWifiP - ok
21:25:21.0527 3636 [ 1BBBF640BC0E0B750537BAECE8D66C18 ] NAUpdate C:\Program Files\Nero\Update\NASvc.exe
21:25:21.0543 3636 NAUpdate - ok
21:25:21.0558 3636 [ E240F3204E86B7B6CCF266B2A2AD32B4 ] NBVol C:\Windows\system32\DRIVERS\NBVol.sys
21:25:21.0574 3636 NBVol - ok
21:25:21.0605 3636 [ C0CF3CCCCE3C75F7280C89029AB47866 ] NBVolUp C:\Windows\system32\DRIVERS\NBVolUp.sys
21:25:21.0621 3636 NBVolUp - ok
21:25:21.0714 3636 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:25:21.0714 3636 NDIS - ok
21:25:21.0730 3636 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:25:21.0746 3636 NdisCap - ok
21:25:21.0761 3636 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:25:21.0761 3636 NdisTapi - ok
21:25:21.0792 3636 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:25:21.0808 3636 Ndisuio - ok
21:25:21.0824 3636 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:25:21.0839 3636 NdisWan - ok
21:25:21.0839 3636 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:25:21.0870 3636 NDProxy - ok
21:25:21.0870 3636 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:25:21.0902 3636 NetBIOS - ok
21:25:21.0917 3636 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:25:21.0917 3636 NetBT - ok
21:25:21.0917 3636 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
21:25:21.0917 3636 Netlogon - ok
21:25:21.0948 3636 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
21:25:21.0948 3636 Netman - ok
21:25:21.0995 3636 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
21:25:22.0011 3636 netprofm - ok
21:25:22.0026 3636 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:25:22.0026 3636 NetTcpPortSharing - ok
21:25:22.0042 3636 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
21:25:22.0058 3636 nfrd960 - ok
21:25:22.0089 3636 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:25:22.0104 3636 NlaSvc - ok
21:25:22.0151 3636 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
21:25:22.0167 3636 nmwcd - ok
21:25:22.0198 3636 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
21:25:22.0198 3636 nmwcdc - ok
21:25:22.0198 3636 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:25:22.0214 3636 Npfs - ok
21:25:22.0229 3636 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
21:25:22.0229 3636 nsi - ok
21:25:22.0229 3636 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:25:22.0229 3636 nsiproxy - ok
21:25:22.0260 3636 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:25:22.0292 3636 Ntfs - ok
21:25:22.0307 3636 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
21:25:22.0323 3636 Null - ok
21:25:22.0806 3636 [ AFB33A823AABC112FC7BD62AFBCDB0CD ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
21:25:22.0947 3636 nvlddmkm - ok
21:25:22.0978 3636 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:25:22.0994 3636 nvraid - ok
21:25:23.0025 3636 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:25:23.0087 3636 nvstor - ok
21:25:23.0150 3636 [ 782945716AD010AC3D41758E8E52C735 ] nvsvc C:\Windows\system32\nvvsvc.exe
21:25:23.0150 3636 nvsvc - ok
21:25:23.0196 3636 [ A974E5C310B9B00894070CEB055D467F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
21:25:23.0228 3636 nvUpdatusService - ok
21:25:23.0274 3636 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:25:23.0306 3636 nv_agp - ok
21:25:23.0321 3636 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
21:25:23.0337 3636 ohci1394 - ok
21:25:23.0384 3636 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:25:23.0399 3636 ose - ok
21:25:23.0524 3636 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:25:23.0633 3636 osppsvc - ok
21:25:23.0727 3636 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:25:23.0742 3636 p2pimsvc - ok
21:25:23.0758 3636 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
21:25:23.0774 3636 p2psvc - ok
21:25:23.0774 3636 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
21:25:23.0789 3636 Parport - ok
21:25:23.0820 3636 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:25:23.0852 3636 partmgr - ok
21:25:23.0867 3636 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
21:25:23.0883 3636 Parvdm - ok
21:25:23.0914 3636 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:25:23.0914 3636 PcaSvc - ok
21:25:23.0945 3636 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
21:25:23.0961 3636 pccsmcfd - ok
21:25:23.0976 3636 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
21:25:23.0992 3636 pci - ok
21:25:24.0023 3636 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
21:25:24.0039 3636 pciide - ok
21:25:24.0054 3636 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
21:25:24.0054 3636 pcmcia - ok
21:25:24.0070 3636 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
21:25:24.0101 3636 pcw - ok
21:25:24.0117 3636 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:25:24.0117 3636 PEAUTH - ok
21:25:24.0179 3636 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:25:24.0179 3636 PeerDistSvc - ok
21:25:24.0273 3636 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
21:25:24.0289 3636 pla - ok
21:25:24.0351 3636 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:25:24.0351 3636 PlugPlay - ok
21:25:24.0367 3636 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
21:25:24.0367 3636 PnkBstrA - ok
21:25:24.0367 3636 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:25:24.0367 3636 PNRPAutoReg - ok
21:25:24.0382 3636 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:25:24.0382 3636 PNRPsvc - ok
21:25:24.0382 3636 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:25:24.0398 3636 PolicyAgent - ok
21:25:24.0413 3636 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
21:25:24.0413 3636 Power - ok
21:25:24.0413 3636 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:25:24.0429 3636 PptpMiniport - ok
21:25:24.0445 3636 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
21:25:24.0460 3636 Processor - ok
21:25:24.0491 3636 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
21:25:24.0491 3636 ProfSvc - ok
21:25:24.0491 3636 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:25:24.0491 3636 ProtectedStorage - ok
21:25:24.0507 3636 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:25:24.0507 3636 Psched - ok
21:25:24.0538 3636 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
21:25:24.0538 3636 ql2300 - ok
21:25:24.0554 3636 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
21:25:24.0569 3636 ql40xx - ok
21:25:24.0585 3636 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
21:25:24.0585 3636 QWAVE - ok
21:25:24.0585 3636 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:25:24.0585 3636 QWAVEdrv - ok
21:25:24.0601 3636 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:25:24.0616 3636 RasAcd - ok
21:25:24.0632 3636 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:25:24.0647 3636 RasAgileVpn - ok
21:25:24.0647 3636 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
21:25:24.0663 3636 RasAuto - ok
21:25:24.0663 3636 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:25:24.0679 3636 Rasl2tp - ok
21:25:24.0710 3636 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
21:25:24.0710 3636 RasMan - ok
21:25:24.0710 3636 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:25:24.0725 3636 RasPppoe - ok
21:25:24.0741 3636 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:25:24.0757 3636 RasSstp - ok
21:25:24.0757 3636 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:25:24.0803 3636 rdbss - ok
21:25:24.0819 3636 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
21:25:24.0819 3636 rdpbus - ok
21:25:24.0850 3636 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:25:24.0850 3636 RDPCDD - ok
21:25:24.0866 3636 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:25:24.0866 3636 RDPDR - ok
21:25:24.0881 3636 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:25:24.0881 3636 RDPENCDD - ok
21:25:24.0897 3636 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
21:25:24.0897 3636 RDPREFMP - ok
21:25:24.0944 3636 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:25:24.0991 3636 RdpVideoMiniport - ok
21:25:25.0022 3636 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:25:25.0084 3636 RDPWD - ok
21:25:25.0147 3636 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:25:25.0193 3636 rdyboost - ok
21:25:25.0225 3636 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
21:25:25.0240 3636 RemoteAccess - ok
21:25:25.0287 3636 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:25:25.0303 3636 RemoteRegistry - ok
21:25:25.0318 3636 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:25:25.0318 3636 RpcEptMapper - ok
21:25:25.0334 3636 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
21:25:25.0334 3636 RpcLocator - ok
21:25:25.0396 3636 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
21:25:25.0412 3636 RpcSs - ok
21:25:25.0443 3636 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:25:25.0490 3636 rspndr - ok
21:25:25.0505 3636 [ 3983CEA05BB855351D75F5482B6C42CE ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
21:25:25.0521 3636 RTL8167 - ok
21:25:25.0552 3636 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
21:25:25.0552 3636 s3cap - ok
21:25:25.0552 3636 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
21:25:25.0552 3636 SamSs - ok
21:25:25.0568 3636 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:25:25.0568 3636 sbp2port - ok
21:25:25.0568 3636 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:25:25.0568 3636 SCardSvr - ok
21:25:25.0583 3636 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:25:25.0583 3636 scfilter - ok
21:25:25.0615 3636 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
21:25:25.0630 3636 Schedule - ok
21:25:25.0630 3636 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
21:25:25.0630 3636 SCPolicySvc - ok
21:25:25.0646 3636 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:25:25.0677 3636 SDRSVC - ok
21:25:25.0677 3636 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:25:25.0693 3636 secdrv - ok
21:25:25.0708 3636 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
21:25:25.0708 3636 seclogon - ok
21:25:25.0724 3636 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
21:25:25.0724 3636 SENS - ok
21:25:25.0739 3636 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:25:25.0739 3636 SensrSvc - ok
21:25:25.0755 3636 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
21:25:25.0755 3636 Serenum - ok
21:25:25.0755 3636 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
21:25:25.0771 3636 Serial - ok
21:25:25.0786 3636 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
21:25:25.0786 3636 sermouse - ok
21:25:25.0880 3636 [ C15B813F2FDB44F87F23312472C6E790 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
21:25:25.0880 3636 ServiceLayer - ok
21:25:25.0927 3636 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
21:25:25.0927 3636 SessionEnv - ok
21:25:25.0927 3636 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
21:25:25.0958 3636 sffdisk - ok
21:25:25.0958 3636 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
21:25:25.0989 3636 sffp_mmc - ok
21:25:25.0989 3636 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
21:25:26.0020 3636 sffp_sd - ok
21:25:26.0036 3636 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
21:25:26.0036 3636 sfloppy - ok
21:25:26.0067 3636 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:25:26.0067 3636 SharedAccess - ok
21:25:26.0098 3636 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:25:26.0098 3636 ShellHWDetection - ok
21:25:26.0114 3636 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
21:25:26.0129 3636 sisagp - ok
21:25:26.0145 3636 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:25:26.0176 3636 SiSRaid2 - ok
21:25:26.0192 3636 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
21:25:26.0192 3636 SiSRaid4 - ok
21:25:26.0410 3636 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
21:25:26.0441 3636 Skype C2C Service - ok
21:25:26.0488 3636 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
21:25:26.0519 3636 SkypeUpdate - ok
21:25:26.0519 3636 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:25:26.0551 3636 Smb - ok
21:25:26.0551 3636 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:25:26.0551 3636 SNMPTRAP - ok
21:25:26.0566 3636 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
21:25:26.0566 3636 spldr - ok
21:25:26.0582 3636 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
21:25:26.0597 3636 Spooler - ok
21:25:26.0660 3636 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
21:25:26.0707 3636 sppsvc - ok
21:25:26.0738 3636 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
21:25:26.0738 3636 sppuinotify - ok
21:25:26.0785 3636 [ 8EA0FD60A5B047E0C734D51AACE531C9 ] sptd C:\Windows\System32\Drivers\sptd.sys
21:25:26.0785 3636 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 8EA0FD60A5B047E0C734D51AACE531C9
21:25:26.0785 3636 sptd ( LockedFile.Multi.Generic ) - warning
21:25:26.0785 3636 sptd - detected LockedFile.Multi.Generic (1)
21:25:26.0800 3636 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:25:26.0831 3636 srv - ok
21:25:26.0847 3636 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:25:26.0894 3636 srv2 - ok
21:25:26.0894 3636 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:25:26.0925 3636 srvnet - ok
21:25:26.0941 3636 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:25:26.0941 3636 SSDPSRV - ok
21:25:26.0956 3636 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:25:26.0956 3636 SstpSvc - ok
21:25:26.0956 3636 Steam Client Service - ok
21:25:27.0034 3636 [ C354621B6B94E10AE7F5CDBE745FEB86 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
21:25:27.0034 3636 Stereo Service - ok
21:25:27.0050 3636 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
21:25:27.0065 3636 stexstor - ok
21:25:27.0081 3636 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
21:25:27.0081 3636 StiSvc - ok
21:25:27.0081 3636 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
21:25:27.0097 3636 storflt - ok
21:25:27.0112 3636 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
21:25:27.0128 3636 storvsc - ok
21:25:27.0128 3636 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
21:25:27.0128 3636 swenum - ok
21:25:27.0143 3636 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
21:25:27.0143 3636 swprv - ok
21:25:27.0159 3636 Synth3dVsc - ok
21:25:27.0175 3636 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
21:25:27.0190 3636 SysMain - ok
21:25:27.0206 3636 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:25:27.0206 3636 TabletInputService - ok
21:25:27.0268 3636 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
21:25:27.0284 3636 TapiSrv - ok
21:25:27.0284 3636 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
21:25:27.0284 3636 TBS - ok
21:25:27.0440 3636 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:25:27.0487 3636 Tcpip - ok
21:25:27.0502 3636 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:25:27.0518 3636 TCPIP6 - ok
21:25:27.0533 3636 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:25:27.0549 3636 tcpipreg - ok
21:25:27.0565 3636 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:25:27.0580 3636 TDPIPE - ok
21:25:27.0611 3636 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:25:27.0658 3636 TDTCP - ok
21:25:27.0674 3636 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:25:27.0705 3636 tdx - ok
21:25:27.0721 3636 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
21:25:27.0736 3636 TermDD - ok
21:25:27.0752 3636 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
21:25:27.0767 3636 TermService - ok
21:25:27.0767 3636 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
21:25:27.0783 3636 Themes - ok
21:25:27.0799 3636 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
21:25:27.0799 3636 THREADORDER - ok
21:25:27.0861 3636 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
21:25:27.0861 3636 TrkWks - ok
21:25:27.0908 3636 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:25:27.0908 3636 TrustedInstaller - ok
21:25:27.0923 3636 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:25:27.0923 3636 tssecsrv - ok
21:25:27.0939 3636 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
21:25:27.0955 3636 TsUsbFlt - ok
21:25:27.0970 3636 tsusbhub - ok
21:25:28.0001 3636 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:25:28.0017 3636 tunnel - ok
21:25:28.0017 3636 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
21:25:28.0017 3636 uagp35 - ok
21:25:28.0033 3636 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:25:28.0079 3636 udfs - ok
21:25:28.0095 3636 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:25:28.0095 3636 UI0Detect - ok
21:25:28.0126 3636 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:25:28.0142 3636 uliagpkx - ok
21:25:28.0173 3636 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:25:28.0173 3636 umbus - ok
21:25:28.0204 3636 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
21:25:28.0220 3636 UmPass - ok
21:25:28.0235 3636 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
21:25:28.0251 3636 UmRdpService - ok
21:25:28.0251 3636 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
21:25:28.0267 3636 upnphost - ok
21:25:28.0282 3636 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
21:25:28.0282 3636 upperdev - ok
21:25:28.0298 3636 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
21:25:28.0329 3636 usbccgp - ok
21:25:28.0345 3636 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
21:25:28.0360 3636 usbcir - ok
21:25:28.0391 3636 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
21:25:28.0391 3636 usbehci - ok
21:25:28.0423 3636 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:25:28.0438 3636 usbhub - ok
21:25:28.0438 3636 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
21:25:28.0454 3636 usbohci - ok
21:25:28.0485 3636 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:25:28.0485 3636 usbprint - ok
21:25:28.0516 3636 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:25:28.0532 3636 usbscan - ok
21:25:28.0547 3636 [ 31181DE6190B39FC8007DFFD1A48FFD6 ] usbser C:\Windows\system32\drivers\usbser.sys
21:25:28.0547 3636 usbser - ok
21:25:28.0563 3636 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
21:25:28.0579 3636 UsbserFilt - ok
21:25:28.0594 3636 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:25:28.0594 3636 USBSTOR - ok
21:25:28.0610 3636 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
21:25:28.0625 3636 usbuhci - ok
21:25:28.0625 3636 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
21:25:28.0641 3636 UxSms - ok
21:25:28.0641 3636 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
21:25:28.0641 3636 VaultSvc - ok
21:25:28.0657 3636 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
21:25:28.0672 3636 vdrvroot - ok
21:25:28.0703 3636 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
21:25:28.0703 3636 vds - ok
21:25:28.0719 3636 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:25:28.0735 3636 vga - ok
21:25:28.0735 3636 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
21:25:28.0735 3636 VgaSave - ok
21:25:28.0750 3636 VGPU - ok
21:25:28.0766 3636 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
21:25:28.0766 3636 vhdmp - ok
21:25:28.0766 3636 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
21:25:28.0781 3636 viaagp - ok
21:25:28.0781 3636 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
21:25:28.0797 3636 ViaC7 - ok
21:25:28.0813 3636 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
21:25:28.0813 3636 viaide - ok
21:25:28.0828 3636 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
21:25:28.0828 3636 vmbus - ok
21:25:07.0066 3280 ============================================================
21:25:07.0066 3280 Current date / time: 2012/09/15 21:25:07.0066
21:25:07.0066 3280 SystemInfo:
21:25:07.0066 3280
21:25:07.0066 3280 OS Version: 6.1.7601 ServicePack: 1.0
21:25:07.0066 3280 Product type: Workstation
21:25:07.0066 3280 ComputerName: PETR-PC
21:25:07.0066 3280 UserName: Petr
21:25:07.0066 3280 Windows directory: C:\Windows
21:25:07.0066 3280 System windows directory: C:\Windows
21:25:07.0066 3280 Processor architecture: Intel x86
21:25:07.0066 3280 Number of processors: 8
21:25:07.0066 3280 Page size: 0x1000
21:25:07.0066 3280 Boot type: Normal boot
21:25:07.0066 3280 ============================================================
21:25:08.0283 3280 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
21:25:08.0283 3280 ============================================================
21:25:08.0283 3280 \Device\Harddisk0\DR0:
21:25:08.0298 3280 MBR partitions:
21:25:08.0298 3280 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384851
21:25:08.0298 3280 ============================================================
21:25:08.0298 3280 C: <-> \Device\Harddisk0\DR0\Partition1
21:25:08.0314 3280 ============================================================
21:25:08.0314 3280 Initialize success
21:25:08.0314 3280 ============================================================
21:25:12.0854 3636 ============================================================
21:25:12.0854 3636 Scan started
21:25:12.0854 3636 Mode: Manual;
21:25:12.0854 3636 ============================================================
21:25:13.0977 3636 ================ Scan system memory ========================
21:25:13.0977 3636 System memory - ok
21:25:13.0977 3636 ================ Scan services =============================
21:25:14.0164 3636 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
21:25:14.0180 3636 1394ohci - ok
21:25:14.0211 3636 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:25:14.0211 3636 ACPI - ok
21:25:14.0226 3636 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
21:25:14.0242 3636 AcpiPmi - ok
21:25:14.0273 3636 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
21:25:14.0304 3636 adp94xx - ok
21:25:14.0320 3636 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
21:25:14.0336 3636 adpahci - ok
21:25:14.0351 3636 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
21:25:14.0367 3636 adpu320 - ok
21:25:14.0382 3636 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:25:14.0382 3636 AeLookupSvc - ok
21:25:14.0414 3636 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
21:25:14.0429 3636 AFD - ok
21:25:14.0429 3636 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
21:25:14.0445 3636 agp440 - ok
21:25:14.0460 3636 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
21:25:14.0476 3636 aic78xx - ok
21:25:14.0492 3636 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
21:25:14.0492 3636 ALG - ok
21:25:14.0507 3636 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
21:25:14.0523 3636 aliide - ok
21:25:14.0523 3636 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
21:25:14.0538 3636 amdagp - ok
21:25:14.0538 3636 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
21:25:14.0554 3636 amdide - ok
21:25:14.0554 3636 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
21:25:14.0570 3636 AmdK8 - ok
21:25:14.0585 3636 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
21:25:14.0601 3636 AmdPPM - ok
21:25:14.0632 3636 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:25:14.0648 3636 amdsata - ok
21:25:14.0663 3636 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
21:25:14.0679 3636 amdsbs - ok
21:25:14.0694 3636 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:25:14.0710 3636 amdxata - ok
21:25:14.0741 3636 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
21:25:14.0757 3636 AppID - ok
21:25:14.0757 3636 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:25:14.0772 3636 AppIDSvc - ok
21:25:14.0788 3636 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
21:25:14.0788 3636 Appinfo - ok
21:25:14.0804 3636 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
21:25:14.0804 3636 AppMgmt - ok
21:25:14.0804 3636 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
21:25:14.0819 3636 arc - ok
21:25:14.0835 3636 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
21:25:14.0835 3636 arcsas - ok
21:25:14.0866 3636 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:25:14.0882 3636 AsyncMac - ok
21:25:14.0882 3636 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
21:25:14.0882 3636 atapi - ok
21:25:14.0897 3636 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:25:14.0913 3636 AudioEndpointBuilder - ok
21:25:14.0913 3636 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
21:25:14.0913 3636 Audiosrv - ok
21:25:14.0928 3636 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:25:14.0928 3636 AxInstSV - ok
21:25:14.0944 3636 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
21:25:14.0960 3636 b06bdrv - ok
21:25:14.0975 3636 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
21:25:15.0006 3636 b57nd60x - ok
21:25:15.0022 3636 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
21:25:15.0022 3636 BDESVC - ok
21:25:15.0038 3636 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
21:25:15.0053 3636 Beep - ok
21:25:15.0069 3636 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
21:25:15.0069 3636 BFE - ok
21:25:15.0131 3636 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
21:25:15.0147 3636 BITS - ok
21:25:15.0162 3636 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
21:25:15.0162 3636 blbdrive - ok
21:25:15.0178 3636 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:25:15.0194 3636 bowser - ok
21:25:15.0209 3636 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:25:15.0209 3636 BrFiltLo - ok
21:25:15.0209 3636 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:25:15.0225 3636 BrFiltUp - ok
21:25:15.0240 3636 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
21:25:15.0240 3636 Browser - ok
21:25:15.0256 3636 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
21:25:15.0272 3636 Brserid - ok
21:25:15.0287 3636 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
21:25:15.0287 3636 BrSerWdm - ok
21:25:15.0287 3636 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
21:25:15.0287 3636 BrUsbMdm - ok
21:25:15.0303 3636 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
21:25:15.0303 3636 BrUsbSer - ok
21:25:15.0318 3636 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
21:25:15.0334 3636 BTHMODEM - ok
21:25:15.0334 3636 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
21:25:15.0334 3636 bthserv - ok
21:25:15.0350 3636 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:25:15.0365 3636 cdfs - ok
21:25:15.0381 3636 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:25:15.0412 3636 cdrom - ok
21:25:15.0412 3636 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
21:25:15.0412 3636 CertPropSvc - ok
21:25:15.0443 3636 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
21:25:15.0443 3636 circlass - ok
21:25:15.0459 3636 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
21:25:15.0459 3636 CLFS - ok
21:25:15.0506 3636 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:25:15.0521 3636 clr_optimization_v2.0.50727_32 - ok
21:25:15.0568 3636 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:25:15.0584 3636 clr_optimization_v4.0.30319_32 - ok
21:25:15.0599 3636 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
21:25:15.0615 3636 CmBatt - ok
21:25:15.0630 3636 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
21:25:15.0646 3636 cmdide - ok
21:25:15.0693 3636 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
21:25:15.0708 3636 CNG - ok
21:25:15.0724 3636 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
21:25:15.0740 3636 Compbatt - ok
21:25:15.0755 3636 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
21:25:15.0755 3636 CompositeBus - ok
21:25:15.0755 3636 COMSysApp - ok
21:25:15.0771 3636 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
21:25:15.0802 3636 crcdisk - ok
21:25:15.0818 3636 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:25:15.0818 3636 CryptSvc - ok
21:25:15.0849 3636 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
21:25:15.0896 3636 CSC - ok
21:25:15.0911 3636 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
21:25:15.0927 3636 CscService - ok
21:25:15.0942 3636 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
21:25:15.0942 3636 DcomLaunch - ok
21:25:15.0958 3636 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
21:25:15.0958 3636 defragsvc - ok
21:25:15.0974 3636 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:25:15.0989 3636 DfsC - ok
21:25:16.0005 3636 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
21:25:16.0005 3636 Dhcp - ok
21:25:16.0020 3636 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
21:25:16.0036 3636 discache - ok
21:25:16.0036 3636 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
21:25:16.0052 3636 Disk - ok
21:25:16.0083 3636 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:25:16.0083 3636 Dnscache - ok
21:25:16.0098 3636 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
21:25:16.0098 3636 dot3svc - ok
21:25:16.0114 3636 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
21:25:16.0130 3636 DPS - ok
21:25:16.0145 3636 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:25:16.0161 3636 drmkaud - ok
21:25:16.0192 3636 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:25:16.0286 3636 DXGKrnl - ok
21:25:16.0301 3636 [ D78F1C5B7B01DF050E011B4FFFDB9048 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
21:25:16.0332 3636 eamonm - ok
21:25:16.0348 3636 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
21:25:16.0348 3636 EapHost - ok
21:25:16.0426 3636 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
21:25:16.0504 3636 ebdrv - ok
21:25:16.0520 3636 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
21:25:16.0520 3636 EFS - ok
21:25:16.0520 3636 [ 3C747A0D8CE29720302972AC6ED09733 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
21:25:16.0535 3636 ehdrv - ok
21:25:16.0644 3636 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:25:16.0660 3636 ehRecvr - ok
21:25:16.0676 3636 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
21:25:16.0691 3636 ehSched - ok
21:25:16.0769 3636 [ 679AD4AFCAF9520CC5607D204AE27CCE ] EhttpSrv C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
21:25:16.0785 3636 EhttpSrv - ok
21:25:16.0785 3636 [ 82A0EE1F5CCC82CC5453D24FF186E9B0 ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
21:25:16.0800 3636 ekrn - ok
21:25:16.0816 3636 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
21:25:16.0878 3636 elxstor - ok
21:25:16.0894 3636 [ 5680E2C38BA53693D724B796E67E8261 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
21:25:16.0925 3636 epfw - ok
21:25:16.0941 3636 [ D9585E144C31D409E28B205253459C3A ] Epfwndis C:\Windows\system32\DRIVERS\Epfwndis.sys
21:25:16.0956 3636 Epfwndis - ok
21:25:17.0003 3636 [ 80F1B9954907D59EE474790EEE11605F ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
21:25:17.0034 3636 epfwwfp - ok
21:25:17.0066 3636 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
21:25:17.0112 3636 ErrDev - ok
21:25:17.0128 3636 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
21:25:17.0128 3636 EventSystem - ok
21:25:17.0144 3636 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
21:25:17.0144 3636 exfat - ok
21:25:17.0159 3636 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:25:17.0175 3636 fastfat - ok
21:25:17.0206 3636 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
21:25:17.0206 3636 Fax - ok
21:25:17.0222 3636 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
21:25:17.0237 3636 fdc - ok
21:25:17.0253 3636 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
21:25:17.0253 3636 fdPHost - ok
21:25:17.0253 3636 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
21:25:17.0253 3636 FDResPub - ok
21:25:17.0268 3636 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:25:17.0284 3636 FileInfo - ok
21:25:17.0300 3636 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:25:17.0300 3636 Filetrace - ok
21:25:17.0315 3636 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
21:25:17.0331 3636 flpydisk - ok
21:25:17.0346 3636 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:25:17.0362 3636 FltMgr - ok
21:25:17.0378 3636 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
21:25:17.0378 3636 FontCache - ok
21:25:17.0409 3636 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:25:17.0409 3636 FontCache3.0.0.0 - ok
21:25:17.0424 3636 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:25:17.0440 3636 FsDepends - ok
21:25:17.0487 3636 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:25:17.0518 3636 Fs_Rec - ok
21:25:17.0518 3636 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:25:17.0534 3636 fvevol - ok
21:25:17.0534 3636 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
21:25:17.0549 3636 gagp30kx - ok
21:25:17.0565 3636 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
21:25:17.0580 3636 gpsvc - ok
21:25:17.0580 3636 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
21:25:17.0612 3636 hcw85cir - ok
21:25:17.0627 3636 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:25:17.0690 3636 HdAudAddService - ok
21:25:17.0690 3636 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
21:25:17.0705 3636 HDAudBus - ok
21:25:17.0705 3636 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
21:25:17.0721 3636 HidBatt - ok
21:25:17.0736 3636 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
21:25:17.0752 3636 HidBth - ok
21:25:17.0783 3636 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
21:25:17.0799 3636 HidIr - ok
21:25:17.0799 3636 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
21:25:17.0799 3636 hidserv - ok
21:25:17.0830 3636 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:25:17.0846 3636 HidUsb - ok
21:25:17.0892 3636 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:25:17.0892 3636 hkmsvc - ok
21:25:17.0924 3636 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:25:17.0924 3636 HomeGroupListener - ok
21:25:17.0986 3636 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:25:18.0002 3636 HomeGroupProvider - ok
21:25:18.0017 3636 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
21:25:18.0048 3636 HpSAMD - ok
21:25:18.0126 3636 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:25:18.0142 3636 HTTP - ok
21:25:18.0142 3636 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:25:18.0142 3636 hwpolicy - ok
21:25:18.0158 3636 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
21:25:18.0189 3636 i8042prt - ok
21:25:18.0204 3636 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:25:18.0220 3636 iaStorV - ok
21:25:18.0267 3636 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:25:18.0282 3636 idsvc - ok
21:25:18.0282 3636 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
21:25:18.0314 3636 iirsp - ok
21:25:18.0329 3636 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
21:25:18.0329 3636 IKEEXT - ok
21:25:18.0891 3636 [ 0DBEF9CD5A2CD71240DD5AFCEE56D073 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
21:25:18.0938 3636 IntcAzAudAddService - ok
21:25:18.0969 3636 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
21:25:18.0984 3636 intelide - ok
21:25:18.0984 3636 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
21:25:19.0000 3636 intelppm - ok
21:25:19.0016 3636 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:25:19.0016 3636 IPBusEnum - ok
21:25:19.0016 3636 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:25:19.0031 3636 IpFilterDriver - ok
21:25:19.0062 3636 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:25:19.0062 3636 iphlpsvc - ok
21:25:19.0078 3636 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
21:25:19.0109 3636 IPMIDRV - ok
21:25:19.0125 3636 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:25:19.0172 3636 IPNAT - ok
21:25:19.0187 3636 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:25:19.0203 3636 IRENUM - ok
21:25:19.0218 3636 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
21:25:19.0234 3636 isapnp - ok
21:25:19.0250 3636 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
21:25:19.0265 3636 iScsiPrt - ok
21:25:19.0296 3636 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
21:25:19.0312 3636 kbdclass - ok
21:25:19.0343 3636 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
21:25:19.0359 3636 kbdhid - ok
21:25:19.0374 3636 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
21:25:19.0374 3636 KeyIso - ok
21:25:19.0390 3636 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:25:19.0406 3636 KSecDD - ok
21:25:19.0452 3636 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:25:19.0499 3636 KSecPkg - ok
21:25:19.0593 3636 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
21:25:19.0608 3636 KtmRm - ok
21:25:19.0608 3636 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
21:25:19.0624 3636 LanmanServer - ok
21:25:19.0624 3636 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:25:19.0640 3636 LanmanWorkstation - ok
21:25:19.0733 3636 [ 3AF6B73A3AD1FC37C5933441F66CEB91 ] LBTServ C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
21:25:19.0749 3636 LBTServ - ok
21:25:19.0780 3636 [ 7F9C7B28CF1C859E1C42619EEA946DC8 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
21:25:19.0796 3636 LHidFilt - ok
21:25:19.0874 3636 [ C34411A244029F1C08687F7C752C4563 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
21:25:19.0874 3636 LightScribeService - ok
21:25:19.0889 3636 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:25:19.0905 3636 lltdio - ok
21:25:19.0952 3636 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:25:19.0952 3636 lltdsvc - ok
21:25:19.0967 3636 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
21:25:19.0967 3636 lmhosts - ok
21:25:19.0998 3636 [ AB33792A87285344F43B5CE23421BAB0 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
21:25:19.0998 3636 LMouFilt - ok
21:25:20.0014 3636 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
21:25:20.0030 3636 LSI_FC - ok
21:25:20.0045 3636 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
21:25:20.0061 3636 LSI_SAS - ok
21:25:20.0076 3636 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:25:20.0092 3636 LSI_SAS2 - ok
21:25:20.0108 3636 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:25:20.0123 3636 LSI_SCSI - ok
21:25:20.0139 3636 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
21:25:20.0154 3636 luafv - ok
21:25:20.0154 3636 [ 77030525CD86A93F1AF34FA9B96D33CE ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys
21:25:20.0170 3636 LUsbFilt - ok
21:25:20.0186 3636 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:25:20.0186 3636 Mcx2Svc - ok
21:25:20.0186 3636 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
21:25:20.0217 3636 megasas - ok
21:25:20.0217 3636 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
21:25:20.0232 3636 MegaSR - ok
21:25:20.0264 3636 Microsoft SharePoint Workspace Audit Service - ok
21:25:20.0279 3636 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
21:25:20.0279 3636 MMCSS - ok
21:25:20.0310 3636 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
21:25:20.0310 3636 Modem - ok
21:25:20.0342 3636 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:25:20.0388 3636 monitor - ok
21:25:20.0388 3636 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:25:20.0404 3636 mouclass - ok
21:25:20.0435 3636 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:25:20.0435 3636 mouhid - ok
21:25:20.0466 3636 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:25:20.0482 3636 mountmgr - ok
21:25:20.0498 3636 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
21:25:20.0544 3636 mpio - ok
21:25:20.0544 3636 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:25:20.0607 3636 mpsdrv - ok
21:25:20.0685 3636 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:25:20.0685 3636 MpsSvc - ok
21:25:20.0700 3636 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:25:20.0732 3636 MRxDAV - ok
21:25:20.0747 3636 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:25:20.0778 3636 mrxsmb - ok
21:25:20.0794 3636 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:25:20.0825 3636 mrxsmb10 - ok
21:25:20.0841 3636 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:25:20.0856 3636 mrxsmb20 - ok
21:25:20.0872 3636 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
21:25:20.0872 3636 msahci - ok
21:25:20.0888 3636 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
21:25:20.0903 3636 msdsm - ok
21:25:20.0919 3636 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
21:25:20.0919 3636 MSDTC - ok
21:25:20.0934 3636 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:25:20.0950 3636 Msfs - ok
21:25:20.0950 3636 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:25:20.0950 3636 mshidkmdf - ok
21:25:20.0981 3636 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:25:21.0012 3636 msisadrv - ok
21:25:21.0059 3636 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:25:21.0059 3636 MSiSCSI - ok
21:25:21.0075 3636 msiserver - ok
21:25:21.0090 3636 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:25:21.0090 3636 MSKSSRV - ok
21:25:21.0106 3636 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:25:21.0122 3636 MSPCLOCK - ok
21:25:21.0122 3636 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:25:21.0122 3636 MSPQM - ok
21:25:21.0153 3636 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:25:21.0168 3636 MsRPC - ok
21:25:21.0184 3636 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
21:25:21.0184 3636 mssmbios - ok
21:25:21.0184 3636 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:25:21.0200 3636 MSTEE - ok
21:25:21.0215 3636 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
21:25:21.0246 3636 MTConfig - ok
21:25:21.0262 3636 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
21:25:21.0278 3636 Mup - ok
21:25:21.0278 3636 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
21:25:21.0309 3636 napagent - ok
21:25:21.0324 3636 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:25:21.0356 3636 NativeWifiP - ok
21:25:21.0527 3636 [ 1BBBF640BC0E0B750537BAECE8D66C18 ] NAUpdate C:\Program Files\Nero\Update\NASvc.exe
21:25:21.0543 3636 NAUpdate - ok
21:25:21.0558 3636 [ E240F3204E86B7B6CCF266B2A2AD32B4 ] NBVol C:\Windows\system32\DRIVERS\NBVol.sys
21:25:21.0574 3636 NBVol - ok
21:25:21.0605 3636 [ C0CF3CCCCE3C75F7280C89029AB47866 ] NBVolUp C:\Windows\system32\DRIVERS\NBVolUp.sys
21:25:21.0621 3636 NBVolUp - ok
21:25:21.0714 3636 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:25:21.0714 3636 NDIS - ok
21:25:21.0730 3636 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:25:21.0746 3636 NdisCap - ok
21:25:21.0761 3636 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:25:21.0761 3636 NdisTapi - ok
21:25:21.0792 3636 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:25:21.0808 3636 Ndisuio - ok
21:25:21.0824 3636 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:25:21.0839 3636 NdisWan - ok
21:25:21.0839 3636 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:25:21.0870 3636 NDProxy - ok
21:25:21.0870 3636 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:25:21.0902 3636 NetBIOS - ok
21:25:21.0917 3636 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:25:21.0917 3636 NetBT - ok
21:25:21.0917 3636 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
21:25:21.0917 3636 Netlogon - ok
21:25:21.0948 3636 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
21:25:21.0948 3636 Netman - ok
21:25:21.0995 3636 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
21:25:22.0011 3636 netprofm - ok
21:25:22.0026 3636 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:25:22.0026 3636 NetTcpPortSharing - ok
21:25:22.0042 3636 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
21:25:22.0058 3636 nfrd960 - ok
21:25:22.0089 3636 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:25:22.0104 3636 NlaSvc - ok
21:25:22.0151 3636 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
21:25:22.0167 3636 nmwcd - ok
21:25:22.0198 3636 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
21:25:22.0198 3636 nmwcdc - ok
21:25:22.0198 3636 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:25:22.0214 3636 Npfs - ok
21:25:22.0229 3636 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
21:25:22.0229 3636 nsi - ok
21:25:22.0229 3636 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:25:22.0229 3636 nsiproxy - ok
21:25:22.0260 3636 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:25:22.0292 3636 Ntfs - ok
21:25:22.0307 3636 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
21:25:22.0323 3636 Null - ok
21:25:22.0806 3636 [ AFB33A823AABC112FC7BD62AFBCDB0CD ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
21:25:22.0947 3636 nvlddmkm - ok
21:25:22.0978 3636 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:25:22.0994 3636 nvraid - ok
21:25:23.0025 3636 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:25:23.0087 3636 nvstor - ok
21:25:23.0150 3636 [ 782945716AD010AC3D41758E8E52C735 ] nvsvc C:\Windows\system32\nvvsvc.exe
21:25:23.0150 3636 nvsvc - ok
21:25:23.0196 3636 [ A974E5C310B9B00894070CEB055D467F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
21:25:23.0228 3636 nvUpdatusService - ok
21:25:23.0274 3636 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:25:23.0306 3636 nv_agp - ok
21:25:23.0321 3636 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
21:25:23.0337 3636 ohci1394 - ok
21:25:23.0384 3636 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:25:23.0399 3636 ose - ok
21:25:23.0524 3636 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:25:23.0633 3636 osppsvc - ok
21:25:23.0727 3636 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:25:23.0742 3636 p2pimsvc - ok
21:25:23.0758 3636 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
21:25:23.0774 3636 p2psvc - ok
21:25:23.0774 3636 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
21:25:23.0789 3636 Parport - ok
21:25:23.0820 3636 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:25:23.0852 3636 partmgr - ok
21:25:23.0867 3636 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
21:25:23.0883 3636 Parvdm - ok
21:25:23.0914 3636 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:25:23.0914 3636 PcaSvc - ok
21:25:23.0945 3636 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
21:25:23.0961 3636 pccsmcfd - ok
21:25:23.0976 3636 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
21:25:23.0992 3636 pci - ok
21:25:24.0023 3636 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
21:25:24.0039 3636 pciide - ok
21:25:24.0054 3636 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
21:25:24.0054 3636 pcmcia - ok
21:25:24.0070 3636 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
21:25:24.0101 3636 pcw - ok
21:25:24.0117 3636 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:25:24.0117 3636 PEAUTH - ok
21:25:24.0179 3636 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:25:24.0179 3636 PeerDistSvc - ok
21:25:24.0273 3636 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
21:25:24.0289 3636 pla - ok
21:25:24.0351 3636 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:25:24.0351 3636 PlugPlay - ok
21:25:24.0367 3636 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
21:25:24.0367 3636 PnkBstrA - ok
21:25:24.0367 3636 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:25:24.0367 3636 PNRPAutoReg - ok
21:25:24.0382 3636 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:25:24.0382 3636 PNRPsvc - ok
21:25:24.0382 3636 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:25:24.0398 3636 PolicyAgent - ok
21:25:24.0413 3636 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
21:25:24.0413 3636 Power - ok
21:25:24.0413 3636 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:25:24.0429 3636 PptpMiniport - ok
21:25:24.0445 3636 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
21:25:24.0460 3636 Processor - ok
21:25:24.0491 3636 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
21:25:24.0491 3636 ProfSvc - ok
21:25:24.0491 3636 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:25:24.0491 3636 ProtectedStorage - ok
21:25:24.0507 3636 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:25:24.0507 3636 Psched - ok
21:25:24.0538 3636 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
21:25:24.0538 3636 ql2300 - ok
21:25:24.0554 3636 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
21:25:24.0569 3636 ql40xx - ok
21:25:24.0585 3636 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
21:25:24.0585 3636 QWAVE - ok
21:25:24.0585 3636 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:25:24.0585 3636 QWAVEdrv - ok
21:25:24.0601 3636 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:25:24.0616 3636 RasAcd - ok
21:25:24.0632 3636 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:25:24.0647 3636 RasAgileVpn - ok
21:25:24.0647 3636 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
21:25:24.0663 3636 RasAuto - ok
21:25:24.0663 3636 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:25:24.0679 3636 Rasl2tp - ok
21:25:24.0710 3636 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
21:25:24.0710 3636 RasMan - ok
21:25:24.0710 3636 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:25:24.0725 3636 RasPppoe - ok
21:25:24.0741 3636 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:25:24.0757 3636 RasSstp - ok
21:25:24.0757 3636 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:25:24.0803 3636 rdbss - ok
21:25:24.0819 3636 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
21:25:24.0819 3636 rdpbus - ok
21:25:24.0850 3636 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:25:24.0850 3636 RDPCDD - ok
21:25:24.0866 3636 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:25:24.0866 3636 RDPDR - ok
21:25:24.0881 3636 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:25:24.0881 3636 RDPENCDD - ok
21:25:24.0897 3636 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
21:25:24.0897 3636 RDPREFMP - ok
21:25:24.0944 3636 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:25:24.0991 3636 RdpVideoMiniport - ok
21:25:25.0022 3636 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:25:25.0084 3636 RDPWD - ok
21:25:25.0147 3636 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:25:25.0193 3636 rdyboost - ok
21:25:25.0225 3636 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
21:25:25.0240 3636 RemoteAccess - ok
21:25:25.0287 3636 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:25:25.0303 3636 RemoteRegistry - ok
21:25:25.0318 3636 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:25:25.0318 3636 RpcEptMapper - ok
21:25:25.0334 3636 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
21:25:25.0334 3636 RpcLocator - ok
21:25:25.0396 3636 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
21:25:25.0412 3636 RpcSs - ok
21:25:25.0443 3636 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:25:25.0490 3636 rspndr - ok
21:25:25.0505 3636 [ 3983CEA05BB855351D75F5482B6C42CE ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
21:25:25.0521 3636 RTL8167 - ok
21:25:25.0552 3636 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
21:25:25.0552 3636 s3cap - ok
21:25:25.0552 3636 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
21:25:25.0552 3636 SamSs - ok
21:25:25.0568 3636 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:25:25.0568 3636 sbp2port - ok
21:25:25.0568 3636 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:25:25.0568 3636 SCardSvr - ok
21:25:25.0583 3636 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:25:25.0583 3636 scfilter - ok
21:25:25.0615 3636 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
21:25:25.0630 3636 Schedule - ok
21:25:25.0630 3636 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
21:25:25.0630 3636 SCPolicySvc - ok
21:25:25.0646 3636 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:25:25.0677 3636 SDRSVC - ok
21:25:25.0677 3636 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:25:25.0693 3636 secdrv - ok
21:25:25.0708 3636 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
21:25:25.0708 3636 seclogon - ok
21:25:25.0724 3636 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
21:25:25.0724 3636 SENS - ok
21:25:25.0739 3636 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:25:25.0739 3636 SensrSvc - ok
21:25:25.0755 3636 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
21:25:25.0755 3636 Serenum - ok
21:25:25.0755 3636 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
21:25:25.0771 3636 Serial - ok
21:25:25.0786 3636 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
21:25:25.0786 3636 sermouse - ok
21:25:25.0880 3636 [ C15B813F2FDB44F87F23312472C6E790 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
21:25:25.0880 3636 ServiceLayer - ok
21:25:25.0927 3636 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
21:25:25.0927 3636 SessionEnv - ok
21:25:25.0927 3636 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
21:25:25.0958 3636 sffdisk - ok
21:25:25.0958 3636 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
21:25:25.0989 3636 sffp_mmc - ok
21:25:25.0989 3636 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
21:25:26.0020 3636 sffp_sd - ok
21:25:26.0036 3636 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
21:25:26.0036 3636 sfloppy - ok
21:25:26.0067 3636 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:25:26.0067 3636 SharedAccess - ok
21:25:26.0098 3636 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:25:26.0098 3636 ShellHWDetection - ok
21:25:26.0114 3636 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
21:25:26.0129 3636 sisagp - ok
21:25:26.0145 3636 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:25:26.0176 3636 SiSRaid2 - ok
21:25:26.0192 3636 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
21:25:26.0192 3636 SiSRaid4 - ok
21:25:26.0410 3636 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
21:25:26.0441 3636 Skype C2C Service - ok
21:25:26.0488 3636 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
21:25:26.0519 3636 SkypeUpdate - ok
21:25:26.0519 3636 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:25:26.0551 3636 Smb - ok
21:25:26.0551 3636 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:25:26.0551 3636 SNMPTRAP - ok
21:25:26.0566 3636 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
21:25:26.0566 3636 spldr - ok
21:25:26.0582 3636 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
21:25:26.0597 3636 Spooler - ok
21:25:26.0660 3636 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
21:25:26.0707 3636 sppsvc - ok
21:25:26.0738 3636 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
21:25:26.0738 3636 sppuinotify - ok
21:25:26.0785 3636 [ 8EA0FD60A5B047E0C734D51AACE531C9 ] sptd C:\Windows\System32\Drivers\sptd.sys
21:25:26.0785 3636 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 8EA0FD60A5B047E0C734D51AACE531C9
21:25:26.0785 3636 sptd ( LockedFile.Multi.Generic ) - warning
21:25:26.0785 3636 sptd - detected LockedFile.Multi.Generic (1)
21:25:26.0800 3636 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:25:26.0831 3636 srv - ok
21:25:26.0847 3636 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:25:26.0894 3636 srv2 - ok
21:25:26.0894 3636 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:25:26.0925 3636 srvnet - ok
21:25:26.0941 3636 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:25:26.0941 3636 SSDPSRV - ok
21:25:26.0956 3636 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:25:26.0956 3636 SstpSvc - ok
21:25:26.0956 3636 Steam Client Service - ok
21:25:27.0034 3636 [ C354621B6B94E10AE7F5CDBE745FEB86 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
21:25:27.0034 3636 Stereo Service - ok
21:25:27.0050 3636 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
21:25:27.0065 3636 stexstor - ok
21:25:27.0081 3636 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
21:25:27.0081 3636 StiSvc - ok
21:25:27.0081 3636 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
21:25:27.0097 3636 storflt - ok
21:25:27.0112 3636 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
21:25:27.0128 3636 storvsc - ok
21:25:27.0128 3636 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
21:25:27.0128 3636 swenum - ok
21:25:27.0143 3636 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
21:25:27.0143 3636 swprv - ok
21:25:27.0159 3636 Synth3dVsc - ok
21:25:27.0175 3636 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
21:25:27.0190 3636 SysMain - ok
21:25:27.0206 3636 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:25:27.0206 3636 TabletInputService - ok
21:25:27.0268 3636 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
21:25:27.0284 3636 TapiSrv - ok
21:25:27.0284 3636 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
21:25:27.0284 3636 TBS - ok
21:25:27.0440 3636 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:25:27.0487 3636 Tcpip - ok
21:25:27.0502 3636 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:25:27.0518 3636 TCPIP6 - ok
21:25:27.0533 3636 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:25:27.0549 3636 tcpipreg - ok
21:25:27.0565 3636 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:25:27.0580 3636 TDPIPE - ok
21:25:27.0611 3636 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:25:27.0658 3636 TDTCP - ok
21:25:27.0674 3636 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:25:27.0705 3636 tdx - ok
21:25:27.0721 3636 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
21:25:27.0736 3636 TermDD - ok
21:25:27.0752 3636 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
21:25:27.0767 3636 TermService - ok
21:25:27.0767 3636 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
21:25:27.0783 3636 Themes - ok
21:25:27.0799 3636 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
21:25:27.0799 3636 THREADORDER - ok
21:25:27.0861 3636 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
21:25:27.0861 3636 TrkWks - ok
21:25:27.0908 3636 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:25:27.0908 3636 TrustedInstaller - ok
21:25:27.0923 3636 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:25:27.0923 3636 tssecsrv - ok
21:25:27.0939 3636 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
21:25:27.0955 3636 TsUsbFlt - ok
21:25:27.0970 3636 tsusbhub - ok
21:25:28.0001 3636 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:25:28.0017 3636 tunnel - ok
21:25:28.0017 3636 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
21:25:28.0017 3636 uagp35 - ok
21:25:28.0033 3636 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:25:28.0079 3636 udfs - ok
21:25:28.0095 3636 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:25:28.0095 3636 UI0Detect - ok
21:25:28.0126 3636 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:25:28.0142 3636 uliagpkx - ok
21:25:28.0173 3636 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:25:28.0173 3636 umbus - ok
21:25:28.0204 3636 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
21:25:28.0220 3636 UmPass - ok
21:25:28.0235 3636 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
21:25:28.0251 3636 UmRdpService - ok
21:25:28.0251 3636 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
21:25:28.0267 3636 upnphost - ok
21:25:28.0282 3636 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
21:25:28.0282 3636 upperdev - ok
21:25:28.0298 3636 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
21:25:28.0329 3636 usbccgp - ok
21:25:28.0345 3636 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
21:25:28.0360 3636 usbcir - ok
21:25:28.0391 3636 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
21:25:28.0391 3636 usbehci - ok
21:25:28.0423 3636 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:25:28.0438 3636 usbhub - ok
21:25:28.0438 3636 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
21:25:28.0454 3636 usbohci - ok
21:25:28.0485 3636 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:25:28.0485 3636 usbprint - ok
21:25:28.0516 3636 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:25:28.0532 3636 usbscan - ok
21:25:28.0547 3636 [ 31181DE6190B39FC8007DFFD1A48FFD6 ] usbser C:\Windows\system32\drivers\usbser.sys
21:25:28.0547 3636 usbser - ok
21:25:28.0563 3636 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
21:25:28.0579 3636 UsbserFilt - ok
21:25:28.0594 3636 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:25:28.0594 3636 USBSTOR - ok
21:25:28.0610 3636 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
21:25:28.0625 3636 usbuhci - ok
21:25:28.0625 3636 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
21:25:28.0641 3636 UxSms - ok
21:25:28.0641 3636 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
21:25:28.0641 3636 VaultSvc - ok
21:25:28.0657 3636 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
21:25:28.0672 3636 vdrvroot - ok
21:25:28.0703 3636 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
21:25:28.0703 3636 vds - ok
21:25:28.0719 3636 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:25:28.0735 3636 vga - ok
21:25:28.0735 3636 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
21:25:28.0735 3636 VgaSave - ok
21:25:28.0750 3636 VGPU - ok
21:25:28.0766 3636 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
21:25:28.0766 3636 vhdmp - ok
21:25:28.0766 3636 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
21:25:28.0781 3636 viaagp - ok
21:25:28.0781 3636 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
21:25:28.0797 3636 ViaC7 - ok
21:25:28.0813 3636 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
21:25:28.0813 3636 viaide - ok
21:25:28.0828 3636 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
21:25:28.0828 3636 vmbus - ok
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
21:25:28.0844 3636 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
21:25:28.0844 3636 VMBusHID - ok
21:25:28.0844 3636 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:25:28.0875 3636 volmgr - ok
21:25:28.0891 3636 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:25:28.0891 3636 volmgrx - ok
21:25:28.0906 3636 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:25:28.0937 3636 volsnap - ok
21:25:28.0953 3636 vsmon - ok
21:25:28.0969 3636 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
21:25:28.0969 3636 vsmraid - ok
21:25:29.0000 3636 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
21:25:29.0000 3636 VSS - ok
21:25:29.0015 3636 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
21:25:29.0031 3636 vwifibus - ok
21:25:29.0047 3636 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
21:25:29.0047 3636 W32Time - ok
21:25:29.0062 3636 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
21:25:29.0078 3636 WacomPen - ok
21:25:29.0093 3636 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
21:25:29.0093 3636 WANARP - ok
21:25:29.0109 3636 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:25:29.0109 3636 Wanarpv6 - ok
21:25:29.0140 3636 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
21:25:29.0156 3636 WatAdminSvc - ok
21:25:29.0187 3636 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
21:25:29.0218 3636 wbengine - ok
21:25:29.0234 3636 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:25:29.0234 3636 WbioSrvc - ok
21:25:29.0249 3636 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:25:29.0249 3636 wcncsvc - ok
21:25:29.0265 3636 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:25:29.0265 3636 WcsPlugInService - ok
21:25:29.0281 3636 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
21:25:29.0296 3636 Wd - ok
21:25:29.0312 3636 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:25:29.0343 3636 Wdf01000 - ok
21:25:29.0359 3636 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:25:29.0359 3636 WdiServiceHost - ok
21:25:29.0359 3636 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:25:29.0359 3636 WdiSystemHost - ok
21:25:29.0374 3636 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
21:25:29.0390 3636 WebClient - ok
21:25:29.0405 3636 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:25:29.0405 3636 Wecsvc - ok
21:25:29.0437 3636 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:25:29.0437 3636 wercplsupport - ok
21:25:29.0452 3636 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
21:25:29.0468 3636 WerSvc - ok
21:25:29.0468 3636 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
21:25:29.0499 3636 WfpLwf - ok
21:25:29.0515 3636 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:25:29.0530 3636 WIMMount - ok
21:25:29.0577 3636 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
21:25:29.0577 3636 WinDefend - ok
21:25:29.0593 3636 WinHttpAutoProxySvc - ok
21:25:29.0624 3636 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:25:29.0639 3636 Winmgmt - ok
21:25:29.0686 3636 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
21:25:29.0686 3636 WinRM - ok
21:25:29.0749 3636 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
21:25:29.0764 3636 WinUsb - ok
21:25:29.0795 3636 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
21:25:29.0795 3636 Wlansvc - ok
21:25:29.0811 3636 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
21:25:29.0827 3636 WmiAcpi - ok
21:25:29.0842 3636 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:25:29.0842 3636 wmiApSrv - ok
21:25:29.0889 3636 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
21:25:29.0905 3636 WMPNetworkSvc - ok
21:25:29.0905 3636 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:25:29.0920 3636 WPCSvc - ok
21:25:29.0936 3636 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:25:29.0936 3636 WPDBusEnum - ok
21:25:29.0951 3636 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:25:29.0951 3636 ws2ifsl - ok
21:25:29.0967 3636 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
21:25:29.0967 3636 wscsvc - ok
21:25:29.0967 3636 WSearch - ok
21:25:30.0061 3636 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
21:25:30.0092 3636 wuauserv - ok
21:25:30.0107 3636 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:25:30.0139 3636 WudfPf - ok
21:25:30.0170 3636 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:25:30.0185 3636 WUDFRd - ok
21:25:30.0201 3636 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:25:30.0201 3636 wudfsvc - ok
21:25:30.0217 3636 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
21:25:30.0217 3636 WwanSvc - ok
21:25:30.0232 3636 ================ Scan global ===============================
21:25:30.0232 3636 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
21:25:30.0263 3636 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
21:25:30.0295 3636 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
21:25:30.0310 3636 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
21:25:30.0326 3636 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
21:25:30.0326 3636 [Global] - ok
21:25:30.0326 3636 ================ Scan MBR ==================================
21:25:30.0341 3636 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:25:30.0825 3636 \Device\Harddisk0\DR0 - ok
21:25:30.0825 3636 ================ Scan VBR ==================================
21:25:30.0841 3636 [ E99E739AF82445A5E2D186C0C342B497 ] \Device\Harddisk0\DR0\Partition1
21:25:30.0856 3636 \Device\Harddisk0\DR0\Partition1 - ok
21:25:30.0856 3636 ============================================================
21:25:30.0856 3636 Scan finished
21:25:30.0856 3636 ============================================================
21:25:30.0872 3948 Detected object count: 1
21:25:30.0872 3948 Actual detected object count: 1
21:25:44.0506 3948 sptd ( LockedFile.Multi.Generic ) - skipped by user
21:25:44.0506 3948 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
21:25:50.0777 3808 Deinitialize success
21:25:28.0844 3636 VMBusHID - ok
21:25:28.0844 3636 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:25:28.0875 3636 volmgr - ok
21:25:28.0891 3636 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:25:28.0891 3636 volmgrx - ok
21:25:28.0906 3636 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:25:28.0937 3636 volsnap - ok
21:25:28.0953 3636 vsmon - ok
21:25:28.0969 3636 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
21:25:28.0969 3636 vsmraid - ok
21:25:29.0000 3636 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
21:25:29.0000 3636 VSS - ok
21:25:29.0015 3636 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
21:25:29.0031 3636 vwifibus - ok
21:25:29.0047 3636 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
21:25:29.0047 3636 W32Time - ok
21:25:29.0062 3636 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
21:25:29.0078 3636 WacomPen - ok
21:25:29.0093 3636 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
21:25:29.0093 3636 WANARP - ok
21:25:29.0109 3636 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:25:29.0109 3636 Wanarpv6 - ok
21:25:29.0140 3636 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
21:25:29.0156 3636 WatAdminSvc - ok
21:25:29.0187 3636 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
21:25:29.0218 3636 wbengine - ok
21:25:29.0234 3636 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:25:29.0234 3636 WbioSrvc - ok
21:25:29.0249 3636 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:25:29.0249 3636 wcncsvc - ok
21:25:29.0265 3636 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:25:29.0265 3636 WcsPlugInService - ok
21:25:29.0281 3636 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
21:25:29.0296 3636 Wd - ok
21:25:29.0312 3636 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:25:29.0343 3636 Wdf01000 - ok
21:25:29.0359 3636 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:25:29.0359 3636 WdiServiceHost - ok
21:25:29.0359 3636 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:25:29.0359 3636 WdiSystemHost - ok
21:25:29.0374 3636 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
21:25:29.0390 3636 WebClient - ok
21:25:29.0405 3636 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:25:29.0405 3636 Wecsvc - ok
21:25:29.0437 3636 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:25:29.0437 3636 wercplsupport - ok
21:25:29.0452 3636 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
21:25:29.0468 3636 WerSvc - ok
21:25:29.0468 3636 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
21:25:29.0499 3636 WfpLwf - ok
21:25:29.0515 3636 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:25:29.0530 3636 WIMMount - ok
21:25:29.0577 3636 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
21:25:29.0577 3636 WinDefend - ok
21:25:29.0593 3636 WinHttpAutoProxySvc - ok
21:25:29.0624 3636 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:25:29.0639 3636 Winmgmt - ok
21:25:29.0686 3636 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
21:25:29.0686 3636 WinRM - ok
21:25:29.0749 3636 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
21:25:29.0764 3636 WinUsb - ok
21:25:29.0795 3636 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
21:25:29.0795 3636 Wlansvc - ok
21:25:29.0811 3636 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
21:25:29.0827 3636 WmiAcpi - ok
21:25:29.0842 3636 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:25:29.0842 3636 wmiApSrv - ok
21:25:29.0889 3636 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
21:25:29.0905 3636 WMPNetworkSvc - ok
21:25:29.0905 3636 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:25:29.0920 3636 WPCSvc - ok
21:25:29.0936 3636 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:25:29.0936 3636 WPDBusEnum - ok
21:25:29.0951 3636 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:25:29.0951 3636 ws2ifsl - ok
21:25:29.0967 3636 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
21:25:29.0967 3636 wscsvc - ok
21:25:29.0967 3636 WSearch - ok
21:25:30.0061 3636 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
21:25:30.0092 3636 wuauserv - ok
21:25:30.0107 3636 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:25:30.0139 3636 WudfPf - ok
21:25:30.0170 3636 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:25:30.0185 3636 WUDFRd - ok
21:25:30.0201 3636 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:25:30.0201 3636 wudfsvc - ok
21:25:30.0217 3636 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
21:25:30.0217 3636 WwanSvc - ok
21:25:30.0232 3636 ================ Scan global ===============================
21:25:30.0232 3636 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
21:25:30.0263 3636 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
21:25:30.0295 3636 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
21:25:30.0310 3636 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
21:25:30.0326 3636 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
21:25:30.0326 3636 [Global] - ok
21:25:30.0326 3636 ================ Scan MBR ==================================
21:25:30.0341 3636 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:25:30.0825 3636 \Device\Harddisk0\DR0 - ok
21:25:30.0825 3636 ================ Scan VBR ==================================
21:25:30.0841 3636 [ E99E739AF82445A5E2D186C0C342B497 ] \Device\Harddisk0\DR0\Partition1
21:25:30.0856 3636 \Device\Harddisk0\DR0\Partition1 - ok
21:25:30.0856 3636 ============================================================
21:25:30.0856 3636 Scan finished
21:25:30.0856 3636 ============================================================
21:25:30.0872 3948 Detected object count: 1
21:25:30.0872 3948 Actual detected object count: 1
21:25:44.0506 3948 sptd ( LockedFile.Multi.Generic ) - skipped by user
21:25:44.0506 3948 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
21:25:50.0777 3808 Deinitialize success
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
naslo mi to jeden objekt..ale nic sem s tím raději nedelal
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
zde výpis z comba:
omboFix 12-09-15.02 - Petr 15.09.2012 21:42:50.1.8 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2326 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 19:46 . 2012-09-15 19:47 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 19:46 . 2012-09-15 19:46 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-15 19:46 . 2012-09-15 19:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
AddRemove-{1AA94747-3BF6-4237-9E1A-7B3067738FE1} - c:\program files (x86)\InstallShield Installation Information\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}\setup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-15 21:48:31
ComboFix-quarantined-files.txt 2012-09-15 19:48
.
Před spuštěním: Volných bajtů: 270 869 020 672
Po spuštění: Volných bajtů: 271 247 527 936
.
- - End Of File - - 7D62937BF76594486E24517C0AB5EC16
omboFix 12-09-15.02 - Petr 15.09.2012 21:42:50.1.8 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2326 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 19:46 . 2012-09-15 19:47 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 19:46 . 2012-09-15 19:46 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-15 19:46 . 2012-09-15 19:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
AddRemove-{1AA94747-3BF6-4237-9E1A-7B3067738FE1} - c:\program files (x86)\InstallShield Installation Information\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}\setup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-09-15 21:48:31
ComboFix-quarantined-files.txt 2012-09-15 19:48
.
Před spuštěním: Volných bajtů: 270 869 020 672
Po spuštění: Volných bajtů: 271 247 527 936
.
- - End Of File - - 7D62937BF76594486E24517C0AB5EC16
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
co mám delat s tím 1 objektem z tdss ? a pak co s tím zone alarmem v registrech mi ho to furt nachazí
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
Driver::
SkypeUpdate
Folder::
c:\program files\Skype\Updater
Firefox::
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: network.proxy.type - 0
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
ComboFix 12-09-15.02 - Petr 15.09.2012 22:05:39.2.8 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2333 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 20:10 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21A72CAC-0318-414C-82D3-EC688D2BC050}\mpengine.dll
2012-09-15 20:09 . 2012-09-15 20:10 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 20:09 . 2012-09-15 20:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2000)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-15 22:14:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-15 20:14
.
Před spuštěním: Volných bajtů: 271 309 160 448
Po spuštění: Volných bajtů: 271 063 511 040
.
- - End Of File - - 25BA13D7405A5A95BE147B8A50CB4748
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2333 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 20:10 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21A72CAC-0318-414C-82D3-EC688D2BC050}\mpengine.dll
2012-09-15 20:09 . 2012-09-15 20:10 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 20:09 . 2012-09-15 20:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2000)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-15 22:14:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-15 20:14
.
Před spuštěním: Volných bajtů: 271 309 160 448
Po spuštění: Volných bajtů: 271 063 511 040
.
- - End Of File - - 25BA13D7405A5A95BE147B8A50CB4748
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
ComboFix 12-09-15.02 - Petr 15.09.2012 22:05:39.2.8 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2333 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 20:10 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21A72CAC-0318-414C-82D3-EC688D2BC050}\mpengine.dll
2012-09-15 20:09 . 2012-09-15 20:10 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 20:09 . 2012-09-15 20:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2000)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-15 22:14:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-15 20:14
.
Před spuštěním: Volných bajtů: 271 309 160 448
Po spuštění: Volných bajtů: 271 063 511 040
.
- - End Of File - - 25BA13D7405A5A95BE147B8A50CB4748
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3326.2333 [GMT 2:00]
Spuštěný z: c:\users\Petr\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.exe
c:\users\Petr\Desktop\Internet Explorer.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 20:10 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21A72CAC-0318-414C-82D3-EC688D2BC050}\mpengine.dll
2012-09-15 20:09 . 2012-09-15 20:10 -------- d-----w- c:\users\Petr\AppData\Local\temp
2012-09-15 20:09 . 2012-09-15 20:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-14 10:12 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2DEC1525-90CC-4960-9256-F4FE4C206C2B}\mpengine.dll
2012-09-13 22:56 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 22:56 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 22:56 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 22:56 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 22:56 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 22:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 14:06 . 2012-01-26 07:38 140800 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-09-15 14:06 . 2012-01-26 07:38 283304 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-09-15 14:06 . 2011-06-25 15:54 283304 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-15 14:06 . 2012-01-26 07:38 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-09-07 15:04 . 2011-06-26 20:44 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-18 17:47 . 2012-08-15 12:07 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:14 . 2012-08-15 12:07 41984 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:14 . 2012-08-15 12:07 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 00:16 . 2012-08-15 12:07 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 12:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 12:07 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 12:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 12:07 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-21 07:39 . 2012-01-18 10:10 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-08-17 4527424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-04-07 2145000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-24 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 11:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\xghqpkwy.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2000)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-09-15 22:14:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-15 20:14
.
Před spuštěním: Volných bajtů: 271 309 160 448
Po spuštění: Volných bajtů: 271 063 511 040
.
- - End Of File - - 25BA13D7405A5A95BE147B8A50CB4748
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
co mám delat s tím TDSS jak mi to tam naslo ten jeden objekt _?
- MiliNess
- člen BSOD týmu
-
Master Level 9.5
- Příspěvky: 9112
- Registrován: říjen 09
- Bydliště: Cheb
- Pohlaví:
- Stav:
Offline
Re: příliš mnoho svchost.exe a velké využití pameti. prosím
Nic. Ten ovladač sptd.sys je v pořádku. Je to falešná detekce. Používá trochu nestandardní metody začlenění se do systému, proto je někdy označován jako malware.
-každý má svou pravdu a ta se nemusí vždycky shodovat s tvou vlastní
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 100 hostů