Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 12:43

Prosil bych o kontrolu logu, PC je nějaké zpomalené.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:41:52, on 23.5.2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\OSCAR Editor X7\OscarEditor.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

--
End of file - 4182 bytes

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 23 kvě 2013 12:53

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy, okna a prohlížeče
Spusť program poklepáním a klikni na „Search“
Po skenu se objeví log (jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 13:07

MbaM:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.05.23.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Maty :: MATY-PC [administrátor]

23.5.2013 13:02:29
mbam-log-2013-05-23 (13-02-29).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 192074
Uplynulý čas: 3 minut, 39 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 13:10

AdwCleaner:

# AdwCleaner v2.301 - Log vytvooen 23/05/2013 v 13:08:58
# Aktualizováno 16/05/2013 Xplode
# Operaení systém : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Uživatel : Maty - MATY-PC
# Spuštin systém : Normální
# Spuštino z : C:\Users\Maty\Downloads\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Nalezeno : C:\Users\Maty\AppData\LocalLow\Conduit

***** [Registry] *****

Klíe Nalezeno : HKCU\Software\APN PIP
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\Conduit
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\SmartBar
Klíe Nalezeno : HKLM\Software\Conduit
Klíe Nalezeno : HKLM\Software\PIP

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v9.0.8112.16483

[OK] Registry jsou eisté.

-\\ Google Chrome v24.0.1312.57

Soubor : C:\Users\Maty\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [970 octets] - [23/05/2013 13:08:58]

########## EOF - C:\AdwCleaner[R1].txt - [1029 octets] ##########

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 23 kvě 2013 13:30

V Adw nech vše smazat a dodej log po smazání

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

- Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 14:38

AdwCleaner po smazání:

# AdwCleaner v2.301 - Log vytvooen 23/05/2013 v 14:33:41
# Aktualizováno 16/05/2013 Xplode
# Operaení systém : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Uživatel : Maty - MATY-PC
# Spuštin systém : Normální
# Spuštino z : C:\Users\Maty\Downloads\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Vymazáno : C:\Users\Maty\AppData\LocalLow\Conduit

***** [Registry] *****

Klíe Vymazáno : HKCU\Software\APN PIP
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\Conduit
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\SmartBar
Klíe Vymazáno : HKLM\Software\Conduit
Klíe Vymazáno : HKLM\Software\PIP

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v9.0.8112.16483

[OK] Registry jsou eisté.

-\\ Google Chrome v24.0.1312.57

Soubor : C:\Users\Maty\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [1098 octets] - [23/05/2013 13:08:58]
AdwCleaner[R2].txt - [1159 octets] - [23/05/2013 14:32:48]
AdwCleaner[S1].txt - [1088 octets] - [23/05/2013 14:33:41]

########## EOF - C:\AdwCleaner[S1].txt - [1148 octets] ##########

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 14:42

RogueKiller:

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Maty [Práva správce]
Mód : Kontrola -- Datum : 05/23/2013 14:41:08
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> NALEZENO
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-00PSA0 ATA Device +++++
--- User ---
[MBR] 4cda754c8708adf8874e4aed7dea9e27
[BSP] 6606dc501e44795e5045819a21530670 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 152625 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1]_S_05232013_02d1441.txt >>
RKreport[1]_S_05232013_02d1441.txt

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Orcus » 23 kvě 2013 17:44

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání skončeno "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 18:08

RogueKiller po smazání:

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Maty [Práva správce]
Mód : Odebrat -- Datum : 05/23/2013 18:07:39
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> VYMAZÁNO
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-00PSA0 ATA Device +++++
--- User ---
[MBR] 4cda754c8708adf8874e4aed7dea9e27
[BSP] 6606dc501e44795e5045819a21530670 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 152625 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[3]_D_05232013_02d1807.txt >>
RKreport[1]_S_05232013_02d1441.txt ; RKreport[2]_S_05232013_02d1806.txt ; RKreport[3]_D_05232013_02d1807.txt

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 18:14

TDSSKiller:

18:09:26.0204 2952 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:09:26.0374 2952 ============================================================
18:09:26.0374 2952 Current date / time: 2013/05/23 18:09:26.0374
18:09:26.0374 2952 SystemInfo:
18:09:26.0374 2952
18:09:26.0374 2952 OS Version: 6.0.6002 ServicePack: 2.0
18:09:26.0374 2952 Product type: Workstation
18:09:26.0374 2952 ComputerName: MATY-PC
18:09:26.0374 2952 UserName: Maty
18:09:26.0374 2952 Windows directory: C:\Windows
18:09:26.0374 2952 System windows directory: C:\Windows
18:09:26.0374 2952 Processor architecture: Intel x86
18:09:26.0374 2952 Number of processors: 2
18:09:26.0374 2952 Page size: 0x1000
18:09:26.0374 2952 Boot type: Normal boot
18:09:26.0374 2952 ============================================================
18:09:28.0354 2952 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:09:28.0378 2952 ============================================================
18:09:28.0378 2952 \Device\Harddisk0\DR0:
18:09:28.0389 2952 MBR partitions:
18:09:28.0389 2952 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
18:09:28.0389 2952 ============================================================
18:09:28.0500 2952 C: <-> \Device\Harddisk0\DR0\Partition1
18:09:28.0500 2952 ============================================================
18:09:28.0500 2952 Initialize success
18:09:28.0500 2952 ============================================================
18:09:53.0360 0588 ============================================================
18:09:53.0360 0588 Scan started
18:09:53.0360 0588 Mode: Manual;
18:09:53.0360 0588 ============================================================
18:09:54.0552 0588 ================ Scan system memory ========================
18:09:54.0552 0588 System memory - ok
18:09:54.0552 0588 ================ Scan services =============================
18:09:55.0220 0588 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
18:09:55.0222 0588 ACPI - ok
18:09:55.0326 0588 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:09:55.0328 0588 AdobeFlashPlayerUpdateSvc - ok
18:09:55.0417 0588 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
18:09:55.0419 0588 adp94xx - ok
18:09:55.0461 0588 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
18:09:55.0462 0588 adpahci - ok
18:09:55.0475 0588 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
18:09:55.0476 0588 adpu160m - ok
18:09:55.0525 0588 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
18:09:55.0526 0588 adpu320 - ok
18:09:55.0595 0588 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:09:55.0596 0588 AeLookupSvc - ok
18:09:55.0688 0588 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
18:09:55.0689 0588 AFD - ok
18:09:55.0722 0588 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:09:55.0723 0588 agp440 - ok
18:09:55.0849 0588 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
18:09:55.0850 0588 aic78xx - ok
18:09:55.0898 0588 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
18:09:55.0937 0588 ALG - ok
18:09:55.0946 0588 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
18:09:55.0947 0588 aliide - ok
18:09:56.0105 0588 [ AEFEEE2E852F2774A4491C8EFA6C3B6E ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:09:56.0107 0588 AMD External Events Utility - ok
18:09:56.0153 0588 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:09:56.0154 0588 amdagp - ok
18:09:56.0176 0588 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
18:09:56.0176 0588 amdide - ok
18:09:56.0209 0588 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
18:09:56.0210 0588 AmdK7 - ok
18:09:56.0231 0588 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
18:09:56.0232 0588 AmdK8 - ok
18:09:57.0055 0588 [ D05CF4523E0C04EF82454ABFD84FDC1D ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:09:57.0092 0588 amdkmdag - ok
18:09:57.0149 0588 [ 92DC2E0AE49148F83B24D89C737B0C97 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
18:09:57.0151 0588 amdkmdap - ok
18:09:57.0216 0588 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
18:09:57.0217 0588 Appinfo - ok
18:09:57.0257 0588 [ F5F0F78286A849BC0E45E0E99065B04F ] AppleCharger C:\Windows\system32\DRIVERS\AppleCharger.sys
18:09:57.0258 0588 AppleCharger - ok
18:09:57.0266 0588 [ 95EF7247C50C7241FDAE39A9B3AFF4AE ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe
18:09:57.0267 0588 AppleChargerSrv - ok
18:09:57.0320 0588 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
18:09:57.0321 0588 arc - ok
18:09:57.0347 0588 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
18:09:57.0347 0588 arcsas - ok
18:09:57.0396 0588 [ 4AF5F360BA1E8794D32B366E45A64A0A ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
18:09:57.0396 0588 aswFsBlk - ok
18:09:57.0463 0588 [ 1F7094D4268D46F718C51286DC189791 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
18:09:57.0464 0588 aswMonFlt - ok
18:09:57.0516 0588 [ 7B43265F92257A21CBFD88E7A651044C ] AswRdr C:\Windows\system32\drivers\AswRdr.sys
18:09:57.0516 0588 AswRdr - ok
18:09:57.0594 0588 [ B680134BA1813B78B47FDD1DFF223CA5 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
18:09:57.0595 0588 aswRvrt - ok
18:09:57.0726 0588 [ 6CAB0A5991C5C0FC63F5E66593E71D7E ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
18:09:57.0730 0588 aswSnx - ok
18:09:57.0778 0588 [ 99102F60F344BEBAF4F6114514FD28D3 ] aswSP C:\Windows\system32\drivers\aswSP.sys
18:09:57.0780 0588 aswSP - ok
18:09:57.0804 0588 [ 1F71F170D90E42EFDE9633D81D5E12DC ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
18:09:57.0822 0588 aswTdi - ok
18:09:57.0855 0588 [ 16B8E3CD50A460EC32CA680C8210A0A9 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
18:09:57.0856 0588 aswVmm - ok
18:09:57.0900 0588 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:09:57.0901 0588 AsyncMac - ok
18:09:57.0935 0588 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
18:09:57.0935 0588 atapi - ok
18:09:57.0979 0588 [ 0C3C2E9136397E1AAA9033DCAE25CED2 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdLH3.sys
18:09:57.0980 0588 AtiHDAudioService - ok
18:09:58.0048 0588 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:09:58.0054 0588 AudioEndpointBuilder - ok
18:09:58.0059 0588 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:09:58.0061 0588 Audiosrv - ok
18:09:58.0202 0588 [ 28D6701C710AD7BA3CB95E75F8F1A9AA ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:09:58.0202 0588 avast! Antivirus - ok
18:09:58.0266 0588 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
18:09:58.0267 0588 Beep - ok
18:09:58.0307 0588 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
18:09:58.0312 0588 BFE - ok
18:09:58.0359 0588 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
18:09:58.0382 0588 BITS - ok
18:09:58.0385 0588 blbdrive - ok
18:09:58.0420 0588 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:09:58.0421 0588 bowser - ok
18:09:58.0464 0588 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
18:09:58.0465 0588 BrFiltLo - ok
18:09:58.0480 0588 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
18:09:58.0481 0588 BrFiltUp - ok
18:09:58.0524 0588 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
18:09:58.0526 0588 Browser - ok
18:09:58.0555 0588 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
18:09:58.0556 0588 Brserid - ok
18:09:58.0573 0588 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
18:09:58.0574 0588 BrSerWdm - ok
18:09:58.0585 0588 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
18:09:58.0586 0588 BrUsbMdm - ok
18:09:58.0597 0588 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
18:09:58.0598 0588 BrUsbSer - ok
18:09:58.0630 0588 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
18:09:58.0631 0588 BTHMODEM - ok
18:09:58.0650 0588 catchme - ok
18:09:58.0676 0588 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:09:58.0677 0588 cdfs - ok
18:09:58.0730 0588 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
18:09:58.0731 0588 cdrom - ok
18:09:58.0773 0588 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
18:09:58.0774 0588 CertPropSvc - ok
18:09:58.0788 0588 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
18:09:58.0789 0588 circlass - ok
18:09:58.0825 0588 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
18:09:58.0827 0588 CLFS - ok
18:09:59.0022 0588 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:09:59.0023 0588 clr_optimization_v2.0.50727_32 - ok
18:09:59.0236 0588 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:09:59.0237 0588 clr_optimization_v4.0.30319_32 - ok
18:09:59.0302 0588 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:09:59.0303 0588 cmdide - ok
18:09:59.0332 0588 [ 82B8C91D327CFECF76CB58716F7D4997 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
18:09:59.0333 0588 Compbatt - ok
18:09:59.0335 0588 COMSysApp - ok
18:09:59.0359 0588 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
18:09:59.0359 0588 crcdisk - ok
18:09:59.0396 0588 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
18:09:59.0396 0588 Crusoe - ok
18:09:59.0447 0588 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:09:59.0450 0588 CryptSvc - ok
18:09:59.0499 0588 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:09:59.0514 0588 DcomLaunch - ok
18:09:59.0573 0588 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:09:59.0574 0588 DfsC - ok
18:09:59.0850 0588 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
18:09:59.0863 0588 DFSR - ok
18:09:59.0926 0588 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
18:09:59.0928 0588 Dhcp - ok
18:09:59.0980 0588 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
18:09:59.0981 0588 disk - ok
18:10:00.0020 0588 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:10:00.0023 0588 Dnscache - ok
18:10:00.0047 0588 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
18:10:00.0051 0588 dot3svc - ok
18:10:00.0107 0588 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
18:10:00.0109 0588 DPS - ok
18:10:00.0153 0588 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:10:00.0153 0588 drmkaud - ok
18:10:00.0189 0588 [ 5DE0FAEC9E5D1AAE74F8568897891A01 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:10:00.0193 0588 DXGKrnl - ok
18:10:00.0236 0588 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
18:10:00.0237 0588 E1G60 - ok
18:10:00.0292 0588 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
18:10:00.0312 0588 EapHost - ok
18:10:00.0364 0588 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
18:10:00.0365 0588 Ecache - ok
18:10:00.0401 0588 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
18:10:00.0403 0588 elxstor - ok
18:10:00.0443 0588 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
18:10:00.0457 0588 EMDMgmt - ok
18:10:00.0499 0588 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
18:10:00.0501 0588 EventSystem - ok
18:10:00.0556 0588 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
18:10:00.0557 0588 exfat - ok
18:10:00.0598 0588 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:10:00.0599 0588 fastfat - ok
18:10:00.0633 0588 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:10:00.0634 0588 fdc - ok
18:10:00.0657 0588 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
18:10:00.0674 0588 fdPHost - ok
18:10:00.0696 0588 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
18:10:00.0698 0588 FDResPub - ok
18:10:00.0713 0588 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:10:00.0714 0588 FileInfo - ok
18:10:00.0717 0588 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:10:00.0718 0588 Filetrace - ok
18:10:00.0736 0588 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:10:00.0736 0588 flpydisk - ok
18:10:00.0770 0588 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:10:00.0771 0588 FltMgr - ok
18:10:00.0827 0588 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
18:10:00.0851 0588 FontCache - ok
18:10:00.0928 0588 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:10:00.0928 0588 FontCache3.0.0.0 - ok
18:10:00.0957 0588 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:10:00.0958 0588 Fs_Rec - ok
18:10:00.0992 0588 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
18:10:00.0993 0588 gagp30kx - ok
18:10:01.0015 0588 gdrv - ok
18:10:01.0051 0588 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
18:10:01.0065 0588 gpsvc - ok
18:10:01.0115 0588 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:10:01.0117 0588 HdAudAddService - ok
18:10:01.0166 0588 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
18:10:01.0169 0588 HDAudBus - ok
18:10:01.0187 0588 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
18:10:01.0188 0588 HidBth - ok
18:10:01.0210 0588 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
18:10:01.0210 0588 HidIr - ok
18:10:01.0263 0588 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
18:10:01.0284 0588 hidserv - ok
18:10:01.0318 0588 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:10:01.0318 0588 HidUsb - ok
18:10:01.0360 0588 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:10:01.0372 0588 hkmsvc - ok
18:10:01.0396 0588 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
18:10:01.0397 0588 HpCISSs - ok
18:10:01.0436 0588 [ 0EEECA26C8D4BDE2A4664DB058A81937 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:10:01.0439 0588 HTTP - ok
18:10:01.0463 0588 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
18:10:01.0463 0588 i2omp - ok
18:10:01.0531 0588 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
18:10:01.0532 0588 i8042prt - ok
18:10:01.0570 0588 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
18:10:01.0572 0588 iaStorV - ok
18:10:01.0723 0588 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:10:01.0746 0588 idsvc - ok
18:10:01.0763 0588 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
18:10:01.0764 0588 iirsp - ok
18:10:01.0794 0588 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
18:10:01.0803 0588 IKEEXT - ok
18:10:01.0910 0588 [ F179FEB1B15AAD94C6BF082C0356DF16 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
18:10:01.0932 0588 IntcAzAudAddService - ok
18:10:01.0949 0588 [ 97469037714070E45194ED318D636401 ] intelide C:\Windows\system32\drivers\intelide.sys
18:10:01.0949 0588 intelide - ok
18:10:02.0009 0588 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:10:02.0009 0588 intelppm - ok
18:10:02.0054 0588 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:10:02.0066 0588 IPBusEnum - ok
18:10:02.0097 0588 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:10:02.0098 0588 IpFilterDriver - ok
18:10:02.0158 0588 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:10:02.0170 0588 iphlpsvc - ok
18:10:02.0173 0588 IpInIp - ok
18:10:02.0191 0588 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
18:10:02.0192 0588 IPMIDRV - ok
18:10:02.0216 0588 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
18:10:02.0218 0588 IPNAT - ok
18:10:02.0231 0588 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:10:02.0232 0588 IRENUM - ok
18:10:02.0266 0588 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:10:02.0267 0588 isapnp - ok
18:10:02.0345 0588 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
18:10:02.0346 0588 iScsiPrt - ok
18:10:02.0389 0588 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
18:10:02.0389 0588 iteatapi - ok
18:10:02.0428 0588 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
18:10:02.0428 0588 iteraid - ok
18:10:02.0489 0588 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
18:10:02.0490 0588 kbdclass - ok
18:10:02.0541 0588 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
18:10:02.0542 0588 kbdhid - ok
18:10:02.0569 0588 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
18:10:02.0582 0588 KeyIso - ok
18:10:02.0621 0588 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:10:02.0624 0588 KSecDD - ok
18:10:02.0706 0588 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
18:10:02.0727 0588 KtmRm - ok
18:10:02.0777 0588 [ 3DB114D4729B8FF7FCF5801F9489CD2C ] L1C C:\Windows\system32\DRIVERS\L1C60x86.sys
18:10:02.0778 0588 L1C - ok
18:10:02.0800 0588 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
18:10:02.0804 0588 LanmanServer - ok
18:10:02.0868 0588 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:10:02.0893 0588 LanmanWorkstation - ok
18:10:02.0926 0588 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:10:02.0927 0588 lltdio - ok
18:10:02.0966 0588 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:10:02.0983 0588 lltdsvc - ok
18:10:03.0018 0588 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:10:03.0021 0588 lmhosts - ok
18:10:03.0153 0588 [ 0803906D607A9B83184447B75B60ECC2 ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:10:03.0155 0588 LMS - ok
18:10:03.0177 0588 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
18:10:03.0178 0588 LSI_FC - ok
18:10:03.0201 0588 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
18:10:03.0202 0588 LSI_SAS - ok
18:10:03.0228 0588 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
18:10:03.0229 0588 LSI_SCSI - ok
18:10:03.0270 0588 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
18:10:03.0271 0588 luafv - ok
18:10:03.0288 0588 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
18:10:03.0288 0588 megasas - ok
18:10:03.0300 0588 [ CFCB18986426A2D8E66F1992636221D0 ] MEI C:\Windows\system32\DRIVERS\HECI.sys
18:10:03.0300 0588 MEI - ok
18:10:03.0328 0588 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
18:10:03.0330 0588 MMCSS - ok
18:10:03.0344 0588 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
18:10:03.0345 0588 Modem - ok
18:10:03.0373 0588 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:10:03.0374 0588 monitor - ok
18:10:03.0407 0588 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:10:03.0408 0588 mouclass - ok
18:10:03.0460 0588 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:10:03.0460 0588 mouhid - ok
18:10:03.0482 0588 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
18:10:03.0483 0588 MountMgr - ok
18:10:03.0521 0588 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
18:10:03.0522 0588 mpio - ok
18:10:03.0532 0588 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:10:03.0533 0588 mpsdrv - ok
18:10:03.0649 0588 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
18:10:03.0664 0588 MpsSvc - ok
18:10:03.0679 0588 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
18:10:03.0680 0588 Mraid35x - ok
18:10:03.0712 0588 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:10:03.0713 0588 MRxDAV - ok
18:10:03.0765 0588 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:10:03.0766 0588 mrxsmb - ok
18:10:03.0802 0588 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:10:03.0803 0588 mrxsmb10 - ok
18:10:03.0816 0588 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:10:03.0817 0588 mrxsmb20 - ok
18:10:03.0839 0588 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
18:10:03.0840 0588 msahci - ok
18:10:03.0851 0588 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:10:03.0852 0588 msdsm - ok
18:10:03.0883 0588 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
18:10:03.0886 0588 MSDTC - ok
18:10:03.0932 0588 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:10:03.0933 0588 Msfs - ok
18:10:03.0935 0588 MSICDSetup - ok
18:10:03.0988 0588 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:10:03.0989 0588 msisadrv - ok
18:10:04.0056 0588 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:10:04.0059 0588 MSiSCSI - ok
18:10:04.0061 0588 msiserver - ok
18:10:04.0070 0588 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:10:04.0070 0588 MSKSSRV - ok
18:10:04.0101 0588 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:10:04.0102 0588 MSPCLOCK - ok
18:10:04.0110 0588 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:10:04.0110 0588 MSPQM - ok
18:10:04.0138 0588 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:10:04.0139 0588 MsRPC - ok
18:10:04.0154 0588 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
18:10:04.0154 0588 mssmbios - ok
18:10:04.0166 0588 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:10:04.0166 0588 MSTEE - ok
18:10:04.0186 0588 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
18:10:04.0186 0588 Mup - ok
18:10:04.0226 0588 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
18:10:04.0233 0588 napagent - ok
18:10:04.0255 0588 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:10:04.0257 0588 NativeWifiP - ok
18:10:04.0293 0588 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:10:04.0296 0588 NDIS - ok
18:10:04.0327 0588 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:10:04.0328 0588 NdisTapi - ok
18:10:04.0341 0588 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:10:04.0342 0588 Ndisuio - ok
18:10:04.0360 0588 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:10:04.0361 0588 NdisWan - ok
18:10:04.0377 0588 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:10:04.0378 0588 NDProxy - ok
18:10:04.0401 0588 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:10:04.0402 0588 NetBIOS - ok
18:10:04.0462 0588 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
18:10:04.0464 0588 netbt - ok
18:10:04.0477 0588 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
18:10:04.0479 0588 Netlogon - ok
18:10:04.0579 0588 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
18:10:04.0589 0588 Netman - ok
18:10:04.0619 0588 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
18:10:04.0625 0588 netprofm - ok
18:10:04.0655 0588 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:10:04.0656 0588 NetTcpPortSharing - ok
18:10:04.0712 0588 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
18:10:04.0713 0588 nfrd960 - ok
18:10:04.0800 0588 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:10:04.0805 0588 NlaSvc - ok
18:10:04.0827 0588 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:10:04.0828 0588 Npfs - ok
18:10:04.0853 0588 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
18:10:04.0869 0588 nsi - ok
18:10:04.0880 0588 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:10:04.0881 0588 nsiproxy - ok
18:10:04.0985 0588 [ 2C1121F2B87E9A6B12485DF53CD848C7 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:10:04.0992 0588 Ntfs - ok
18:10:05.0009 0588 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
18:10:05.0010 0588 ntrigdigi - ok
18:10:05.0034 0588 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
18:10:05.0034 0588 Null - ok
18:10:05.0050 0588 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:10:05.0051 0588 nvraid - ok
18:10:05.0063 0588 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:10:05.0064 0588 nvstor - ok
18:10:05.0073 0588 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:10:05.0075 0588 nv_agp - ok
18:10:05.0077 0588 NwlnkFlt - ok
18:10:05.0080 0588 NwlnkFwd - ok
18:10:05.0130 0588 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:10:05.0131 0588 ohci1394 - ok
18:10:05.0184 0588 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
18:10:05.0200 0588 p2pimsvc - ok
18:10:05.0209 0588 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
18:10:05.0215 0588 p2psvc - ok
18:10:05.0281 0588 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:10:05.0282 0588 Parport - ok
18:10:05.0309 0588 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:10:05.0310 0588 partmgr - ok
18:10:05.0328 0588 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:10:05.0329 0588 Parvdm - ok
18:10:05.0347 0588 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
18:10:05.0351 0588 PcaSvc - ok
18:10:05.0381 0588 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
18:10:05.0383 0588 pci - ok
18:10:05.0396 0588 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
18:10:05.0397 0588 pciide - ok
18:10:05.0426 0588 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
18:10:05.0427 0588 pcmcia - ok
18:10:05.0452 0588 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:10:05.0458 0588 PEAUTH - ok
18:10:05.0640 0588 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
18:10:05.0673 0588 pla - ok
18:10:05.0768 0588 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:10:05.0784 0588 PlugPlay - ok
18:10:05.0821 0588 [ A1DD33D16F277CE34124EE52AB2C0F14 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
18:10:05.0824 0588 PnkBstrA - ok
18:10:05.0851 0588 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
18:10:05.0858 0588 PNRPAutoReg - ok
18:10:05.0876 0588 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
18:10:05.0883 0588 PNRPsvc - ok
18:10:05.0966 0588 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:10:05.0983 0588 PolicyAgent - ok
18:10:06.0026 0588 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:10:06.0027 0588 PptpMiniport - ok
18:10:06.0092 0588 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
18:10:06.0093 0588 Processor - ok
18:10:06.0166 0588 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
18:10:06.0173 0588 ProfSvc - ok
18:10:06.0186 0588 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
18:10:06.0188 0588 ProtectedStorage - ok
18:10:06.0211 0588 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
18:10:06.0212 0588 PSched - ok
18:10:06.0260 0588 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
18:10:06.0267 0588 ql2300 - ok
18:10:06.0299 0588 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
18:10:06.0300 0588 ql40xx - ok
18:10:06.0361 0588 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
18:10:06.0369 0588 QWAVE - ok
18:10:06.0416 0588 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:10:06.0417 0588 QWAVEdrv - ok
18:10:06.0434 0588 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:10:06.0435 0588 RasAcd - ok
18:10:06.0460 0588 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
18:10:06.0476 0588 RasAuto - ok
18:10:06.0509 0588 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:10:06.0510 0588 Rasl2tp - ok
18:10:06.0539 0588 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
18:10:06.0548 0588 RasMan - ok
18:10:06.0579 0588 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:10:06.0580 0588 RasPppoe - ok
18:10:06.0626 0588 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:10:06.0628 0588 RasSstp - ok
18:10:06.0707 0588 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:10:06.0710 0588 rdbss - ok
18:10:06.0727 0588 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:10:06.0728 0588 RDPCDD - ok
18:10:06.0789 0588 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
18:10:06.0792 0588 rdpdr - ok
18:10:06.0801 0588 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:10:06.0802 0588 RDPENCDD - ok
18:10:06.0872 0588 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:10:06.0874 0588 RDPWD - ok
18:10:06.0924 0588 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:10:06.0928 0588 RemoteAccess - ok
18:10:06.0955 0588 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:10:06.0974 0588 RemoteRegistry - ok
18:10:07.0000 0588 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
18:10:07.0002 0588 RpcLocator - ok
18:10:07.0132 0588 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
18:10:07.0138 0588 RpcSs - ok
18:10:07.0209 0588 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:10:07.0210 0588 rspndr - ok
18:10:07.0244 0588 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
18:10:07.0246 0588 SamSs - ok
18:10:07.0320 0588 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:10:07.0321 0588 sbp2port - ok
18:10:07.0359 0588 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:10:07.0363 0588 SCardSvr - ok
18:10:07.0403 0588 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
18:10:07.0440 0588 Schedule - ok
18:10:07.0472 0588 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
18:10:07.0473 0588 SCPolicySvc - ok
18:10:07.0557 0588 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:10:07.0576 0588 SDRSVC - ok
18:10:07.0601 0588 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:10:07.0601 0588 secdrv - ok
18:10:07.0624 0588 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
18:10:07.0636 0588 seclogon - ok
18:10:07.0675 0588 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
18:10:07.0678 0588 SENS - ok
18:10:07.0690 0588 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:10:07.0691 0588 Serenum - ok
18:10:07.0744 0588 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:10:07.0745 0588 Serial - ok
18:10:07.0787 0588 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
18:10:07.0788 0588 sermouse - ok
18:10:07.0809 0588 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
18:10:07.0813 0588 SessionEnv - ok
18:10:07.0833 0588 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:10:07.0833 0588 sffdisk - ok
18:10:07.0844 0588 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:10:07.0845 0588 sffp_mmc - ok
18:10:07.0848 0588 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:10:07.0849 0588 sffp_sd - ok
18:10:07.0862 0588 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
18:10:07.0863 0588 sfloppy - ok
18:10:07.0960 0588 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:10:07.0979 0588 SharedAccess - ok
18:10:08.0019 0588 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:10:08.0026 0588 ShellHWDetection - ok
18:10:08.0044 0588 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:10:08.0045 0588 sisagp - ok
18:10:08.0048 0588 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
18:10:08.0049 0588 SiSRaid2 - ok
18:10:08.0085 0588 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
18:10:08.0086 0588 SiSRaid4 - ok
18:10:08.0150 0588 [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:10:08.0152 0588 SkypeUpdate - ok
18:10:08.0825 0588 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
18:10:08.0844 0588 slsvc - ok
18:10:08.0905 0588 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
18:10:08.0918 0588 SLUINotify - ok
18:10:08.0943 0588 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:10:08.0944 0588 Smb - ok
18:10:09.0003 0588 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:10:09.0005 0588 SNMPTRAP - ok
18:10:09.0073 0588 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
18:10:09.0073 0588 spldr - ok
18:10:09.0132 0588 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
18:10:09.0135 0588 Spooler - ok
18:10:09.0257 0588 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:10:09.0259 0588 srv - ok
18:10:09.0342 0588 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:10:09.0344 0588 srv2 - ok
18:10:09.0388 0588 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:10:09.0389 0588 srvnet - ok
18:10:09.0449 0588 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:10:09.0471 0588 SSDPSRV - ok
18:10:09.0510 0588 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:10:09.0515 0588 SstpSvc - ok
18:10:09.0555 0588 Steam Client Service - ok
18:10:09.0586 0588 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
18:10:09.0600 0588 stisvc - ok
18:10:09.0640 0588 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
18:10:09.0641 0588 swenum - ok
18:10:09.0669 0588 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
18:10:09.0687 0588 swprv - ok
18:10:09.0710 0588 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
18:10:09.0711 0588 Symc8xx - ok
18:10:09.0720 0588 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
18:10:09.0720 0588 Sym_hi - ok
18:10:09.0731 0588 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
18:10:09.0732 0588 Sym_u3 - ok
18:10:09.0768 0588 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
18:10:09.0782 0588 SysMain - ok
18:10:09.0838 0588 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:10:09.0842 0588 TabletInputService - ok
18:10:09.0877 0588 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
18:10:09.0883 0588 TapiSrv - ok
18:10:09.0907 0588 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
18:10:09.0911 0588 TBS - ok
18:10:09.0959 0588 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:10:09.0964 0588 Tcpip - ok
18:10:09.0993 0588 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
18:10:09.0998 0588 Tcpip6 - ok
18:10:10.0058 0588 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:10:10.0058 0588 tcpipreg - ok
18:10:10.0088 0588 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:10:10.0089 0588 TDPIPE - ok
18:10:10.0133 0588 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:10:10.0134 0588 TDTCP - ok
18:10:10.0186 0588 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:10:10.0187 0588 tdx - ok
18:10:10.0206 0588 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
18:10:10.0207 0588 TermDD - ok
18:10:10.0329 0588 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
18:10:10.0334 0588 TermService - ok
18:10:10.0361 0588 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
18:10:10.0364 0588 Themes - ok
18:10:10.0402 0588 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
18:10:10.0404 0588 THREADORDER - ok
18:10:10.0472 0588 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
18:10:10.0486 0588 TrkWks - ok
18:10:10.0533 0588 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:10:10.0534 0588 TrustedInstaller - ok
18:10:10.0576 0588 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:10:10.0577 0588 tssecsrv - ok
18:10:10.0606 0588 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
18:10:10.0607 0588 tunmp - ok
18:10:10.0619 0588 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:10:10.0620 0588 tunnel - ok
18:10:10.0646 0588 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
18:10:10.0646 0588 uagp35 - ok
18:10:10.0738 0588 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:10:10.0739 0588 udfs - ok
18:10:10.0798 0588 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:10:10.0801 0588 UI0Detect - ok
18:10:10.0817 0588 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:10:10.0817 0588 uliagpkx - ok
18:10:10.0835 0588 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
18:10:10.0837 0588 uliahci - ok
18:10:10.0869 0588 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
18:10:10.0870 0588 UlSata - ok
18:10:10.0881 0588 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
18:10:10.0882 0588 ulsata2 - ok
18:10:10.0908 0588 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
18:10:10.0909 0588 umbus - ok
18:10:11.0536 0588 [ EB79C6C91A99930015EF29AE7FA802D1 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
18:10:11.0549 0588 UNS - ok
18:10:11.0596 0588 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
18:10:11.0602 0588 upnphost - ok
18:10:11.0634 0588 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:10:11.0635 0588 usbccgp - ok
18:10:11.0662 0588 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:10:11.0663 0588 usbcir - ok
18:10:11.0715 0588 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:10:11.0716 0588 usbehci - ok
18:10:11.0753 0588 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:10:11.0755 0588 usbhub - ok
18:10:11.0777 0588 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:10:11.0778 0588 usbohci - ok
18:10:11.0786 0588 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
18:10:11.0787 0588 usbprint - ok
18:10:11.0809 0588 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:10:11.0810 0588 USBSTOR - ok
18:10:11.0829 0588 [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:10:11.0829 0588 usbuhci - ok
18:10:11.0854 0588 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
18:10:11.0857 0588 UxSms - ok
18:10:11.0888 0588 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
18:10:11.0892 0588 vds - ok
18:10:11.0912 0588 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:10:11.0913 0588 vga - ok
18:10:11.0934 0588 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
18:10:11.0934 0588 VgaSave - ok
18:10:11.0951 0588 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:10:11.0952 0588 viaagp - ok
18:10:11.0964 0588 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
18:10:11.0965 0588 ViaC7 - ok
18:10:11.0984 0588 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
18:10:11.0985 0588 viaide - ok
18:10:12.0019 0588 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:10:12.0020 0588 volmgr - ok
18:10:12.0048 0588 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:10:12.0050 0588 volmgrx - ok
18:10:12.0078 0588 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:10:12.0080 0588 volsnap - ok
18:10:12.0101 0588 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
18:10:12.0102 0588 vsmraid - ok
18:10:12.0154 0588 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
18:10:12.0162 0588 VSS - ok
18:10:12.0194 0588 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
18:10:12.0201 0588 W32Time - ok
18:10:12.0218 0588 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
18:10:12.0219 0588 WacomPen - ok
18:10:12.0255 0588 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
18:10:12.0255 0588 Wanarp - ok
18:10:12.0258 0588 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:10:12.0259 0588 Wanarpv6 - ok
18:10:12.0276 0588 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:10:12.0285 0588 wcncsvc - ok
18:10:12.0310 0588 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:10:12.0314 0588 WcsPlugInService - ok
18:10:12.0324 0588 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
18:10:12.0325 0588 Wd - ok
18:10:12.0368 0588 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:10:12.0371 0588 Wdf01000 - ok
18:10:12.0401 0588 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:10:12.0406 0588 WdiServiceHost - ok
18:10:12.0408 0588 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:10:12.0412 0588 WdiSystemHost - ok
18:10:12.0458 0588 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
18:10:12.0462 0588 WebClient - ok
18:10:12.0497 0588 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:10:12.0502 0588 Wecsvc - ok
18:10:12.0540 0588 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:10:12.0544 0588 wercplsupport - ok
18:10:12.0570 0588 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
18:10:12.0575 0588 WerSvc - ok
18:10:12.0624 0588 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:10:12.0628 0588 WinDefend - ok
18:10:12.0631 0588 WinHttpAutoProxySvc - ok
18:10:12.0796 0588 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:10:12.0798 0588 Winmgmt - ok
18:10:12.0851 0588 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
18:10:12.0884 0588 WinRM - ok
18:10:13.0047 0588 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:10:13.0066 0588 Wlansvc - ok
18:10:13.0085 0588 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:10:13.0086 0588 WmiAcpi - ok
18:10:13.0114 0588 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:10:13.0115 0588 wmiApSrv - ok
18:10:13.0187 0588 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:10:13.0192 0588 WMPNetworkSvc - ok
18:10:13.0208 0588 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:10:13.0213 0588 WPCSvc - ok
18:10:13.0243 0588 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:10:13.0248 0588 WPDBusEnum - ok
18:10:13.0346 0588 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:10:13.0350 0588 WPFFontCache_v0400 - ok
18:10:13.0393 0588 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:10:13.0393 0588 ws2ifsl - ok
18:10:13.0453 0588 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
18:10:13.0469 0588 wscsvc - ok
18:10:13.0472 0588 WSearch - ok
18:10:13.0576 0588 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
18:10:13.0630 0588 wuauserv - ok
18:10:13.0674 0588 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:10:13.0675 0588 WudfPf - ok
18:10:13.0713 0588 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:10:13.0714 0588 WUDFRd - ok
18:10:13.0740 0588 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:10:13.0743 0588 wudfsvc - ok
18:10:13.0746 0588 ================ Scan global ===============================
18:10:13.0798 0588 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
18:10:13.0830 0588 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
18:10:13.0847 0588 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
18:10:13.0919 0588 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
18:10:13.0923 0588 [Global] - ok
18:10:13.0923 0588 ================ Scan MBR ==================================
18:10:13.0942 0588 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
18:10:14.0867 0588 \Device\Harddisk0\DR0 - ok
18:10:14.0867 0588 ================ Scan VBR ==================================
18:10:14.0896 0588 [ 1AA4F33F9DD2FDF08DC3F286C8E4A406 ] \Device\Harddisk0\DR0\Partition1
18:10:14.0911 0588 \Device\Harddisk0\DR0\Partition1 - ok
18:10:14.0911 0588 ============================================================
18:10:14.0911 0588 Scan finished
18:10:14.0911 0588 ============================================================
18:10:14.0917 3216 Detected object count: 0
18:10:14.0917 3216 Actual detected object count: 0
18:10:22.0288 3456 Deinitialize success

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 326
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Mety » 23 kvě 2013 18:30

ComboFix:

ComboFix 13-05-23.02 - Maty 23.05.2013 18:17:44.3.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3563.2571 [GMT 2:00]
Spuštěný z: c:\users\Maty\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TEMP\sigD97C.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-04-23 do 2013-05-23 )))))))))))))))))))))))))))))))
.
.
2013-05-23 16:23 . 2013-05-23 16:23 -------- d-----w- c:\users\Maty\AppData\Local\temp
2013-05-23 16:23 . 2013-05-23 16:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-23 11:09 . 2013-05-23 11:09 -------- d-----w- c:\users\Maty\AppData\Local\ATI
2013-05-23 10:39 . 2013-05-23 10:39 388096 ----a-r- c:\users\Maty\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-05-23 10:39 . 2013-05-23 10:39 -------- d-----w- c:\program files\Trend Micro
2013-05-21 09:53 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D7D80058-6E7C-4EE0-81E3-D8474B4D464E}\mpengine.dll
2013-05-16 03:54 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-05-16 03:39 . 2013-04-15 14:20 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-16 03:39 . 2013-04-13 10:56 37376 ----a-w- c:\windows\system32\cdd.dll
2013-05-16 03:39 . 2013-04-09 01:36 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-05-13 15:29 . 2013-05-13 15:48 -------- d-----w- c:\users\Maty\AppData\Roaming\vlc
2013-05-13 15:28 . 2013-05-13 15:28 -------- d-----w- c:\program files\VideoLAN
2013-05-12 18:48 . 2013-05-20 13:44 -------- d-----w- c:\users\Maty\AppData\Roaming\Skype
2013-05-12 18:48 . 2013-05-12 18:48 -------- d-----w- c:\program files\Common Files\Skype
2013-05-12 18:48 . 2013-05-12 18:48 -------- d-----r- c:\program files\Skype
2013-05-12 18:48 . 2013-05-12 18:48 -------- d-----w- c:\programdata\Skype
2013-05-06 12:48 . 2013-05-06 15:34 -------- d-----w- c:\program files\World of Warcraft - Cataclysm
2013-04-23 21:21 . 2013-04-23 21:21 -------- d-----w- c:\program files\Common Files\Java
2013-04-23 21:21 . 2013-04-04 03:35 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-15 04:48 . 2012-12-22 08:53 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-15 04:48 . 2012-12-22 08:53 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-09 08:59 . 2013-03-13 18:25 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-05-09 08:59 . 2013-03-13 18:25 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2012-12-21 22:36 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-05-09 08:59 . 2012-12-21 22:36 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2012-12-21 22:36 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-05-09 08:59 . 2012-12-21 22:36 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-05-09 08:59 . 2012-12-21 22:36 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:59 . 2012-12-21 22:36 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:58 . 2012-12-21 22:34 41664 ----a-w- c:\windows\avastSS.scr
2013-05-09 08:58 . 2012-12-21 22:34 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-05-02 00:06 . 2012-12-21 23:07 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-21 17:35 . 2012-12-22 12:34 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-04-21 17:35 . 2012-12-22 12:34 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-04-21 17:35 . 2012-12-22 12:34 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-03-30 16:37 . 2013-03-28 12:56 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-30 16:37 . 2013-03-28 12:56 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-11 13:25 . 2013-04-10 20:44 3603816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-11 13:25 . 2013-04-10 20:44 3551080 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-09 03:45 . 2013-04-10 20:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-09 01:28 . 2013-04-10 20:44 64000 ----a-w- c:\windows\system32\smss.exe
2013-03-08 03:53 . 2013-04-10 20:44 376320 ----a-w- c:\windows\system32\winsrv.dll
2013-03-08 03:52 . 2013-04-10 20:44 2067968 ----a-w- c:\windows\system32\mstscax.dll
2013-03-03 19:07 . 2013-04-10 20:44 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files\OSCAR Editor X7\OscarEditor.exe" [2012-03-20 3340288]
"Steam"="c:\program files\Steam\steam.exe" [2013-05-03 1635752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-11-18 11483752]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-01 07:43 1607120 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-05-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-22 04:48]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-23 18:23
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2013-05-23 18:24:53
ComboFix-quarantined-files.txt 2013-05-23 16:24
.
Před spuštěním: Volných bajtů: 40 040 902 656
Po spuštění: Volných bajtů: 40 008 409 088
.
- - End Of File - - 4524D3E5FA80425E7E079F28EFDEE0DE

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod memphisto » 23 kvě 2013 21:48

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

+ Nový log z HJT

Jak se chová PC?
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 120 hostů