Ahoj seká se mě MMORPG hra Lineage 2. Někdy to jde dobře a někdy se to dost seká. Nevím jestli to může být způsobeno internetem. Internet mám 16/16 Mbps
Protože někdy se rychlost dost sníží klidně i na ani ne 512KB, ale i když to třeba naměří 3-4 Mbps tak se to seká. Děkuji za rady.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:38:19, on 25.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 6\Monitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
F:\Hry\Origin\Origin.exe
F:\Hry\Steam\Steam.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Programy\ts3client_win32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
F:\Hry\Lineage 2\Frost\LineageII.exe
F:\Stažené soubory\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=12454
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:21320
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: LemurLeap - {415419c3-dad0-4df1-ac37-22c72ad81878} - C:\Program Files\LemurLeap\LemurLeapbho.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NCUpdateHelper] F:\Hry\NCWest\NCLauncher\NCUpdateHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [icq] C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [EADM] "F:\Hry\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Steam] "F:\Hry\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [WTFast Tray] "C:\Program Files\WTFast\WTFast.exe" trayonly
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Show avast! EasyPass Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra 'Tools' menuitem: Show avast! EasyPass Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wtfastdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wtfastdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wtfastdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wtfastdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wtfastdrv.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: 4game-service - Innova Co S.a r.l. - C:\Program Files\4game\4game-service.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Disc Soft Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Update LemurLeap - LemurLeap - C:\Program Files\LemurLeap\updateLemurLeap.exe
--
End of file - 9631 bytes
Prosím o kontrolu. Sekání hry. Vyřešeno
Prosím o kontrolu. Sekání hry.
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu. Sekání hry.
Odinstaluj:
Spybot - Search & Destroy 2
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Spybot - Search & Destroy 2
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu. Sekání hry.
Tu je jeden log:
# AdwCleaner v3.005 - Report created 25/09/2013 at 22:34:32
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Lucaso - LUCASO-PC
# Running from : C:\Users\Lucaso\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\ProgramData\Babylon
Folder Found C:\Users\Lucaso\AppData\Roaming\Babylon
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\BI
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1309 octets] - [25/09/2013 22:34:32]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1369 octets] ##########
Druhý log:
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.25.07
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Lucaso :: LUCASO-PC [administrátor]
Ochrana: Povolena
25.9.2013 22:42:28
MBAM-log-2013-09-25 (22-46-43).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 184725
Uplynulý čas: 3 minut, 55 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 3
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{415419C3-DAD0-4DF1-AC37-22C72AD81878} (PUP.Optional.LemurLeap.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{415419C3-DAD0-4DF1-AC37-22C72AD81878} (PUP.Optional.LemurLeap.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
Nalezené složky: 1
C:\Users\Lucaso\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 1
C:\Users\Lucaso\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
(konec)
Akorád nešel odinstalovat Spybot - Search & Destroy 2 ani v ovládacích panelech přidat odebrat programy tam nebyl a ani v Uninstaller nebyl vidět. Tak jsem ho ručně smazal, ale nešel smazat celý, protože byl otevřený v programu, ale nikde nebylo vidět v kterým.
# AdwCleaner v3.005 - Report created 25/09/2013 at 22:34:32
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Lucaso - LUCASO-PC
# Running from : C:\Users\Lucaso\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\ProgramData\Babylon
Folder Found C:\Users\Lucaso\AppData\Roaming\Babylon
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\BI
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1309 octets] - [25/09/2013 22:34:32]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1369 octets] ##########
Druhý log:
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.25.07
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Lucaso :: LUCASO-PC [administrátor]
Ochrana: Povolena
25.9.2013 22:42:28
MBAM-log-2013-09-25 (22-46-43).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 184725
Uplynulý čas: 3 minut, 55 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 3
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{415419C3-DAD0-4DF1-AC37-22C72AD81878} (PUP.Optional.LemurLeap.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{415419C3-DAD0-4DF1-AC37-22C72AD81878} (PUP.Optional.LemurLeap.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.
Nalezené složky: 1
C:\Users\Lucaso\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 1
C:\Users\Lucaso\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
(konec)
Akorád nešel odinstalovat Spybot - Search & Destroy 2 ani v ovládacích panelech přidat odebrat programy tam nebyl a ani v Uninstaller nebyl vidět. Tak jsem ho ručně smazal, ale nešel smazat celý, protože byl otevřený v programu, ale nikde nebylo vidět v kterým.
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu. Sekání hry.
Zkusíme ho odstranit potom v Combofixu.
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu. Sekání hry.
Tu je log po opětovné kontrole
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.26.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Lucaso :: LUCASO-PC [administrátor]
Ochrana: Povolena
26.9.2013 16:40:45
mbam-log-2013-09-26 (16-40-45).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 185635
Uplynulý čas: 4 minut, 10 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
Druhý log:
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 06:18:19 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 09:40:36 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 10:46:15 +0200 LUCASO-PC Lucaso MESSAGE Executing scheduled update: Daily
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Starting database refresh
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Stopping IP protection
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Scheduled update executed successfully: database updated from version v2013.09.25.07 to version v2013.09.26.02
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE IP Protection stopped successfully
2013/09/26 10:46:29 +0200 LUCASO-PC Lucaso MESSAGE Database refreshed successfully
2013/09/26 10:46:29 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 10:46:34 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 16:23:03 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
ten druhý log nevím co je, ale radši ho sem dám.
Třetí log:
# AdwCleaner v3.005 - Report created 26/09/2013 at 06:16:57
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Lucaso - LUCASO-PC
# Running from : C:\Users\Lucaso\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKCU\Software\BI
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1449 octets] - [25/09/2013 22:34:32]
AdwCleaner[R1].txt - [1375 octets] - [26/09/2013 06:16:20]
AdwCleaner[S0].txt - [1316 octets] - [26/09/2013 06:16:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1376 octets] ##########
Čtvrtý log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Ultimate x86
Ran by Lucaso on źt 26.09.2013 at 16:52:01,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F08D8E66-8608-4A91-9820-615579AA75C9}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Lucaso\AppData\Roaming\software informer"
Successfully deleted: [Folder] "C:\Program Files\software informer"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 26.09.2013 at 16:55:36,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pátý log:
RogueKiller V8.6.12 [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Lucaso [Práva správce]
Mód : Kontrola -- Datum : 09/26/2013 17:02:56
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\Lucaso\AppData\Roaming\ICQM\ICQ\dll\mramenu.dll [x] -> ODEBRÁNO
¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3663190652-2704878265-732043386-1000\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> NALEZENO
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (localhost:21320) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP UNIC] Startup : F:\Stažené soubory\CPU Thermometer\CPUThermometer.exe [-] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD6400AARS-00Y5B1 ATA Device +++++
--- User ---
[MBR] b883a641c51ad1d3bd3ddd8132b5c9b3
[BSP] 49254b0f2b49e522907207dfdc0720bc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 46900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 96258048 | Size: 563477 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_09262013_170256.txt >>
Snad je to všechno a na nic jsem nezapoměl.
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.26.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Lucaso :: LUCASO-PC [administrátor]
Ochrana: Povolena
26.9.2013 16:40:45
mbam-log-2013-09-26 (16-40-45).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 185635
Uplynulý čas: 4 minut, 10 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
Druhý log:
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 06:18:15 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 06:18:19 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 09:40:29 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 09:40:36 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 10:46:15 +0200 LUCASO-PC Lucaso MESSAGE Executing scheduled update: Daily
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Starting database refresh
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Stopping IP protection
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE Scheduled update executed successfully: database updated from version v2013.09.25.07 to version v2013.09.26.02
2013/09/26 10:46:26 +0200 LUCASO-PC Lucaso MESSAGE IP Protection stopped successfully
2013/09/26 10:46:29 +0200 LUCASO-PC Lucaso MESSAGE Database refreshed successfully
2013/09/26 10:46:29 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 10:46:34 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Starting protection
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Protection started successfully
2013/09/26 16:22:59 +0200 LUCASO-PC Lucaso MESSAGE Starting IP protection
2013/09/26 16:23:03 +0200 LUCASO-PC Lucaso MESSAGE IP Protection started successfully
ten druhý log nevím co je, ale radši ho sem dám.
Třetí log:
# AdwCleaner v3.005 - Report created 26/09/2013 at 06:16:57
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Lucaso - LUCASO-PC
# Running from : C:\Users\Lucaso\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKCU\Software\BI
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Google Chrome v29.0.1547.76
[ File : C:\Users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1449 octets] - [25/09/2013 22:34:32]
AdwCleaner[R1].txt - [1375 octets] - [26/09/2013 06:16:20]
AdwCleaner[S0].txt - [1316 octets] - [26/09/2013 06:16:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1376 octets] ##########
Čtvrtý log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Ultimate x86
Ran by Lucaso on źt 26.09.2013 at 16:52:01,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F08D8E66-8608-4A91-9820-615579AA75C9}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Lucaso\AppData\Roaming\software informer"
Successfully deleted: [Folder] "C:\Program Files\software informer"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 26.09.2013 at 16:55:36,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pátý log:
RogueKiller V8.6.12 [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Lucaso [Práva správce]
Mód : Kontrola -- Datum : 09/26/2013 17:02:56
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\Lucaso\AppData\Roaming\ICQM\ICQ\dll\mramenu.dll [x] -> ODEBRÁNO
¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-3663190652-2704878265-732043386-1000\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> NALEZENO
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (localhost:21320) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP UNIC] Startup : F:\Stažené soubory\CPU Thermometer\CPUThermometer.exe [-] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD6400AARS-00Y5B1 ATA Device +++++
--- User ---
[MBR] b883a641c51ad1d3bd3ddd8132b5c9b3
[BSP] 49254b0f2b49e522907207dfdc0720bc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 46900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 96258048 | Size: 563477 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_09262013_170256.txt >>
Snad je to všechno a na nic jsem nezapoměl.
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu. Sekání hry.
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu. Sekání hry.
Tu je jeden log
RogueKiller V8.6.12 [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Lucaso [Práva správce]
Mód : Odebrat -- Datum : 09/27/2013 17:40:04
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 7 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-3663190652-2704878265-732043386-1000\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP UNIC] Startup : F:\Stažené soubory\CPU Thermometer\CPUThermometer.exe [-] -> VYMAZÁNO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD6400AARS-00Y5B1 ATA Device +++++
--- User ---
[MBR] b883a641c51ad1d3bd3ddd8132b5c9b3
[BSP] 49254b0f2b49e522907207dfdc0720bc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 46900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 96258048 | Size: 563477 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_09272013_174004.txt >>
RKreport[0]_S_09262013_170256.txt;RKreport[0]_S_09272013_173937.txt
RogueKiller V8.6.12 [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Lucaso [Práva správce]
Mód : Odebrat -- Datum : 09/27/2013 17:40:04
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 7 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-3663190652-2704878265-732043386-1000\[...]\Run : icq (C:\Users\Lucaso\AppData\Roaming\ICQM\icq.exe -CU [-]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 1 ¤¤¤
[V2][SUSP UNIC] Startup : F:\Stažené soubory\CPU Thermometer\CPUThermometer.exe [-] -> VYMAZÁNO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD6400AARS-00Y5B1 ATA Device +++++
--- User ---
[MBR] b883a641c51ad1d3bd3ddd8132b5c9b3
[BSP] 49254b0f2b49e522907207dfdc0720bc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 46900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 96258048 | Size: 563477 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_09272013_174004.txt >>
RKreport[0]_S_09262013_170256.txt;RKreport[0]_S_09272013_173937.txt
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
Re: Prosím o kontrolu. Sekání hry.
17:43:31.0588 3176 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
17:43:31.0822 3176 ============================================================
17:43:31.0822 3176 Current date / time: 2013/09/27 17:43:31.0822
17:43:31.0822 3176 SystemInfo:
17:43:31.0822 3176
17:43:31.0822 3176 OS Version: 6.1.7601 ServicePack: 1.0
17:43:31.0822 3176 Product type: Workstation
17:43:31.0822 3176 ComputerName: LUCASO-PC
17:43:31.0822 3176 UserName: Lucaso
17:43:31.0822 3176 Windows directory: C:\Windows
17:43:31.0822 3176 System windows directory: C:\Windows
17:43:31.0822 3176 Processor architecture: Intel x86
17:43:31.0822 3176 Number of processors: 2
17:43:31.0822 3176 Page size: 0x1000
17:43:31.0822 3176 Boot type: Normal boot
17:43:31.0822 3176 ============================================================
17:43:32.0977 3176 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x47B84, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050
17:43:32.0977 3176 ============================================================
17:43:32.0977 3176 \Device\Harddisk0\DR0:
17:43:32.0977 3176 MBR partitions:
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x5B9A000
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x5BCC800, BlocksNum 0x44C8A800
17:43:32.0977 3176 ============================================================
17:43:33.0008 3176 C: <-> \Device\Harddisk0\DR0\Partition2
17:43:33.0039 3176 F: <-> \Device\Harddisk0\DR0\Partition3
17:43:33.0039 3176 ============================================================
17:43:33.0039 3176 Initialize success
17:43:33.0039 3176 ============================================================
17:43:39.0357 5588 ============================================================
17:43:39.0357 5588 Scan started
17:43:39.0357 5588 Mode: Manual;
17:43:39.0357 5588 ============================================================
17:43:40.0200 5588 ================ Scan system memory ========================
17:43:40.0200 5588 System memory - ok
17:43:40.0200 5588 ================ Scan services =============================
17:43:40.0340 5588 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:43:40.0340 5588 1394ohci - ok
17:43:40.0402 5588 [ 0EEC6F1236660BE9A082F6D979074DFA ] 4game-service C:\Program Files\4game\4game-service.exe
17:43:40.0418 5588 4game-service - ok
17:43:40.0434 5588 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:43:40.0434 5588 ACPI - ok
17:43:40.0465 5588 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:43:40.0465 5588 AcpiPmi - ok
17:43:40.0496 5588 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:43:40.0496 5588 AdobeARMservice - ok
17:43:40.0543 5588 [ 24A0876D07EF356DCBC1D7A7929354AB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:43:40.0543 5588 AdobeFlashPlayerUpdateSvc - ok
17:43:40.0574 5588 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:43:40.0590 5588 adp94xx - ok
17:43:40.0605 5588 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:43:40.0605 5588 adpahci - ok
17:43:40.0621 5588 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:43:40.0621 5588 adpu320 - ok
17:43:40.0652 5588 [ 993F7B0BA5188A0007C085AA10257B8E ] AdvancedSystemCareService6 C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
17:43:40.0668 5588 AdvancedSystemCareService6 - ok
17:43:40.0683 5588 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:43:40.0683 5588 AeLookupSvc - ok
17:43:40.0714 5588 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
17:43:40.0714 5588 AFD - ok
17:43:40.0746 5588 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:43:40.0746 5588 agp440 - ok
17:43:40.0761 5588 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:43:40.0761 5588 aic78xx - ok
17:43:40.0777 5588 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:43:40.0792 5588 ALG - ok
17:43:40.0808 5588 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:43:40.0808 5588 aliide - ok
17:43:40.0839 5588 [ B19505648F033393E907E2E419FDE8B3 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:43:40.0839 5588 AMD External Events Utility - ok
17:43:40.0855 5588 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:43:40.0855 5588 amdagp - ok
17:43:40.0870 5588 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:43:40.0870 5588 amdide - ok
17:43:40.0886 5588 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:43:40.0886 5588 AmdK8 - ok
17:43:40.0902 5588 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:43:40.0902 5588 AmdPPM - ok
17:43:40.0917 5588 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:43:40.0917 5588 amdsata - ok
17:43:40.0933 5588 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:43:40.0933 5588 amdsbs - ok
17:43:40.0948 5588 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:43:40.0948 5588 amdxata - ok
17:43:40.0980 5588 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:43:40.0980 5588 AppID - ok
17:43:40.0980 5588 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:43:40.0980 5588 AppIDSvc - ok
17:43:40.0995 5588 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
17:43:41.0011 5588 Appinfo - ok
17:43:41.0042 5588 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:43:41.0042 5588 AppMgmt - ok
17:43:41.0042 5588 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:43:41.0058 5588 arc - ok
17:43:41.0058 5588 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:43:41.0058 5588 arcsas - ok
17:43:41.0120 5588 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:43:41.0136 5588 aspnet_state - ok
17:43:41.0151 5588 [ B9FE438B3CAD82B2014710349A2022F7 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
17:43:41.0151 5588 aswFsBlk - ok
17:43:41.0167 5588 [ 3FCA5C1A8F33CF9857220CC3A3076A3E ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
17:43:41.0182 5588 aswKbd - ok
17:43:41.0198 5588 [ AE5549DD21F6DE06406031EF1D51ACC3 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:43:41.0198 5588 aswMonFlt - ok
17:43:41.0198 5588 [ A29EF1A46E110F392588F7395BB55F32 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
17:43:41.0214 5588 aswRdr - ok
17:43:41.0245 5588 [ FA72FA503F580C3C628DD8C7D7622E37 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
17:43:41.0245 5588 aswRvrt - ok
17:43:41.0276 5588 [ 4D53349D848C6BADB3D4ACBE98C27676 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:43:41.0276 5588 aswSnx - ok
17:43:41.0307 5588 [ 813024DFD54A41B3AFAE2B1E2796CB80 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:43:41.0307 5588 aswSP - ok
17:43:41.0323 5588 [ 5E18413310134130D7772F0668698CB7 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:43:41.0323 5588 aswTdi - ok
17:43:41.0338 5588 [ A5F637D61719D37A5B4868C385E363C0 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
17:43:41.0338 5588 aswVmm - ok
17:43:41.0354 5588 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:43:41.0354 5588 AsyncMac - ok
17:43:41.0385 5588 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:43:41.0385 5588 atapi - ok
17:43:41.0401 5588 [ 0A5CCED52803D80ED4ECBC9616340862 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:43:41.0416 5588 Suspicious file (Forged): C:\Windows\system32\drivers\AtihdW73.sys. Real md5: 0A5CCED52803D80ED4ECBC9616340862, Fake md5: 5B2A6663E5B74919CF240FB5D81D531C
17:43:41.0416 5588 AtiHDAudioService ( ForgedFile.Multi.Generic ) - warning
17:43:41.0416 5588 AtiHDAudioService - detected ForgedFile.Multi.Generic (1)
17:43:41.0510 5588 [ 04F09923A393E4E0E8453A8F78361E73 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:43:41.0526 5588 atikmdag - ok
17:43:41.0572 5588 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:43:41.0572 5588 AudioEndpointBuilder - ok
17:43:41.0588 5588 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:43:41.0588 5588 Audiosrv - ok
17:43:41.0635 5588 [ 9330941C8F6DF417F6DBBE998DB6687E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:43:41.0635 5588 avast! Antivirus - ok
17:43:41.0650 5588 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:43:41.0650 5588 AxInstSV - ok
17:43:41.0682 5588 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:43:41.0682 5588 b06bdrv - ok
17:43:41.0697 5588 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:43:41.0697 5588 b57nd60x - ok
17:43:41.0713 5588 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:43:41.0713 5588 BDESVC - ok
17:43:41.0728 5588 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:43:41.0728 5588 Beep - ok
17:43:41.0760 5588 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:43:41.0760 5588 BFE - ok
17:43:41.0775 5588 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:43:41.0791 5588 BITS - ok
17:43:41.0791 5588 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:43:41.0791 5588 blbdrive - ok
17:43:41.0822 5588 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:43:41.0822 5588 bowser - ok
17:43:41.0838 5588 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:43:41.0838 5588 BrFiltLo - ok
17:43:41.0838 5588 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:43:41.0838 5588 BrFiltUp - ok
17:43:41.0853 5588 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:43:41.0853 5588 Browser - ok
17:43:41.0869 5588 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:43:41.0869 5588 Brserid - ok
17:43:41.0869 5588 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:43:41.0869 5588 BrSerWdm - ok
17:43:41.0884 5588 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:43:41.0884 5588 BrUsbMdm - ok
17:43:41.0884 5588 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:43:41.0884 5588 BrUsbSer - ok
17:43:41.0900 5588 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:43:41.0900 5588 BTHMODEM - ok
17:43:41.0916 5588 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:43:41.0916 5588 bthserv - ok
17:43:41.0931 5588 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:43:41.0931 5588 cdfs - ok
17:43:41.0947 5588 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:43:41.0947 5588 cdrom - ok
17:43:41.0962 5588 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:43:41.0962 5588 CertPropSvc - ok
17:43:41.0962 5588 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:43:41.0978 5588 circlass - ok
17:43:41.0978 5588 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:43:41.0978 5588 CLFS - ok
17:43:42.0025 5588 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:43:42.0025 5588 clr_optimization_v2.0.50727_32 - ok
17:43:42.0040 5588 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:43:42.0056 5588 clr_optimization_v4.0.30319_32 - ok
17:43:42.0087 5588 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:43:42.0087 5588 CmBatt - ok
17:43:42.0118 5588 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:43:42.0118 5588 cmdide - ok
17:43:42.0150 5588 [ 42F158036BD4C2FF3122BF142E60E6FD ] CNG C:\Windows\system32\Drivers\cng.sys
17:43:42.0150 5588 CNG - ok
17:43:42.0165 5588 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:43:42.0181 5588 Compbatt - ok
17:43:42.0196 5588 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:43:42.0196 5588 CompositeBus - ok
17:43:42.0196 5588 COMSysApp - ok
17:43:42.0212 5588 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:43:42.0212 5588 crcdisk - ok
17:43:42.0243 5588 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:43:42.0243 5588 CryptSvc - ok
17:43:42.0259 5588 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:43:42.0259 5588 CSC - ok
17:43:42.0274 5588 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:43:42.0274 5588 CscService - ok
17:43:42.0306 5588 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:43:42.0306 5588 DcomLaunch - ok
17:43:42.0321 5588 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:43:42.0321 5588 defragsvc - ok
17:43:42.0352 5588 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:43:42.0352 5588 DfsC - ok
17:43:42.0368 5588 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:43:42.0368 5588 Dhcp - ok
17:43:42.0415 5588 [ F4A9AC0561C9944CC262593C7161E0A8 ] Disc Soft Bus Service C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
17:43:42.0415 5588 Disc Soft Bus Service - ok
17:43:42.0430 5588 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:43:42.0430 5588 discache - ok
17:43:42.0446 5588 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:43:42.0446 5588 Disk - ok
17:43:42.0477 5588 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:43:42.0477 5588 Dnscache - ok
17:43:42.0493 5588 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:43:42.0493 5588 dot3svc - ok
17:43:42.0524 5588 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:43:42.0524 5588 DPS - ok
17:43:42.0540 5588 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:43:42.0540 5588 drmkaud - ok
17:43:42.0586 5588 [ 651554E483712B708EDE864D0CA1AA73 ] DrvAgent32 C:\Windows\system32\Drivers\DrvAgent32.sys
17:43:42.0586 5588 DrvAgent32 - ok
17:43:42.0602 5588 [ 50778FE9ED67AEB01EA99877B1B4A4DF ] dtscsibus C:\Windows\system32\DRIVERS\dtscsibus.sys
17:43:42.0602 5588 dtscsibus - ok
17:43:42.0633 5588 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:43:42.0649 5588 DXGKrnl - ok
17:43:42.0664 5588 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:43:42.0664 5588 EapHost - ok
17:43:42.0727 5588 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:43:42.0742 5588 ebdrv - ok
17:43:42.0774 5588 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
17:43:42.0774 5588 EFS - ok
17:43:42.0820 5588 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:43:42.0820 5588 ehRecvr - ok
17:43:42.0852 5588 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:43:42.0852 5588 ehSched - ok
17:43:42.0883 5588 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:43:42.0883 5588 elxstor - ok
17:43:42.0898 5588 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:43:42.0898 5588 ErrDev - ok
17:43:42.0930 5588 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:43:42.0930 5588 EventSystem - ok
17:43:42.0930 5588 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:43:42.0930 5588 exfat - ok
17:43:42.0945 5588 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:43:42.0945 5588 fastfat - ok
17:43:42.0992 5588 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:43:42.0992 5588 Fax - ok
17:43:43.0008 5588 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:43:43.0008 5588 fdc - ok
17:43:43.0008 5588 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:43:43.0023 5588 fdPHost - ok
17:43:43.0039 5588 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:43:43.0039 5588 FDResPub - ok
17:43:43.0054 5588 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:43:43.0054 5588 FileInfo - ok
17:43:43.0070 5588 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:43:43.0070 5588 Filetrace - ok
17:43:43.0070 5588 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:43:43.0070 5588 flpydisk - ok
17:43:43.0086 5588 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:43:43.0086 5588 FltMgr - ok
17:43:43.0117 5588 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
17:43:43.0132 5588 FontCache - ok
17:43:43.0179 5588 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:43:43.0179 5588 FontCache3.0.0.0 - ok
17:43:43.0195 5588 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:43:43.0195 5588 FsDepends - ok
17:43:43.0226 5588 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:43:43.0226 5588 Fs_Rec - ok
17:43:43.0257 5588 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:43:43.0257 5588 fvevol - ok
17:43:43.0273 5588 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:43:43.0273 5588 gagp30kx - ok
17:43:43.0288 5588 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\Windows\system32\giveio.sys
17:43:43.0288 5588 giveio - ok
17:43:43.0335 5588 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:43:43.0335 5588 gpsvc - ok
17:43:43.0382 5588 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
17:43:43.0382 5588 gupdate - ok
17:43:43.0398 5588 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
17:43:43.0398 5588 gupdatem - ok
17:43:43.0413 5588 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:43:43.0413 5588 hcw85cir - ok
17:43:43.0444 5588 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:43:43.0444 5588 HdAudAddService - ok
17:43:43.0460 5588 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:43:43.0460 5588 HDAudBus - ok
17:43:43.0476 5588 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:43:43.0476 5588 HidBatt - ok
17:43:43.0476 5588 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:43:43.0476 5588 HidBth - ok
17:43:43.0491 5588 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:43:43.0491 5588 HidIr - ok
17:43:43.0507 5588 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:43:43.0522 5588 hidserv - ok
17:43:43.0538 5588 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:43:43.0538 5588 HidUsb - ok
17:43:43.0554 5588 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:43:43.0554 5588 hkmsvc - ok
17:43:43.0585 5588 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:43:43.0585 5588 HomeGroupListener - ok
17:43:43.0632 5588 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:43:43.0632 5588 HomeGroupProvider - ok
17:43:43.0647 5588 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:43:43.0647 5588 HpSAMD - ok
17:43:43.0678 5588 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:43:43.0678 5588 HTTP - ok
17:43:43.0694 5588 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:43:43.0694 5588 hwpolicy - ok
17:43:43.0710 5588 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:43:43.0710 5588 i8042prt - ok
17:43:43.0741 5588 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:43:43.0741 5588 iaStorV - ok
17:43:43.0772 5588 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:43:43.0788 5588 idsvc - ok
17:43:43.0788 5588 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:43:43.0788 5588 iirsp - ok
17:43:43.0819 5588 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:43:43.0819 5588 IKEEXT - ok
17:43:43.0850 5588 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:43:43.0850 5588 intelide - ok
17:43:43.0866 5588 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:43:43.0866 5588 intelppm - ok
17:43:43.0881 5588 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:43:43.0881 5588 IPBusEnum - ok
17:43:43.0897 5588 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:43:43.0897 5588 IpFilterDriver - ok
17:43:43.0912 5588 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:43:43.0928 5588 iphlpsvc - ok
17:43:43.0944 5588 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:43:43.0944 5588 IPMIDRV - ok
17:43:43.0944 5588 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:43:43.0959 5588 IPNAT - ok
17:43:43.0959 5588 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:43:43.0959 5588 IRENUM - ok
17:43:43.0990 5588 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:43:43.0990 5588 isapnp - ok
17:43:43.0990 5588 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:43:44.0006 5588 iScsiPrt - ok
17:43:44.0006 5588 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:43:44.0006 5588 kbdclass - ok
17:43:44.0022 5588 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:43:44.0022 5588 kbdhid - ok
17:43:44.0037 5588 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
17:43:44.0037 5588 KeyIso - ok
17:43:44.0053 5588 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:43:44.0053 5588 KSecDD - ok
17:43:44.0084 5588 [ 5FE1ABF1AF591A3458C9CF24ED9A4D35 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:43:44.0084 5588 KSecPkg - ok
17:43:44.0100 5588 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:43:44.0115 5588 KtmRm - ok
17:43:44.0131 5588 [ BADB7F6173168DAC446F5035B4B66E18 ] L1C C:\Windows\system32\DRIVERS\L1C60x86.sys
17:43:44.0131 5588 L1C - ok
17:43:44.0146 5588 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:43:44.0146 5588 LanmanServer - ok
17:43:44.0178 5588 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:43:44.0178 5588 LanmanWorkstation - ok
17:43:44.0193 5588 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:43:44.0193 5588 lltdio - ok
17:43:44.0209 5588 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:43:44.0209 5588 lltdsvc - ok
17:43:44.0224 5588 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:43:44.0224 5588 lmhosts - ok
17:43:44.0256 5588 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:43:44.0256 5588 LSI_FC - ok
17:43:44.0256 5588 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:43:44.0271 5588 LSI_SAS - ok
17:43:44.0271 5588 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:43:44.0271 5588 LSI_SAS2 - ok
17:43:44.0287 5588 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:43:44.0287 5588 LSI_SCSI - ok
17:43:44.0318 5588 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:43:44.0318 5588 luafv - ok
17:43:44.0334 5588 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:43:44.0334 5588 MBAMProtector - ok
17:43:44.0349 5588 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:43:44.0365 5588 MBAMScheduler - ok
17:43:44.0380 5588 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:43:44.0380 5588 MBAMService - ok
17:43:44.0412 5588 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:43:44.0412 5588 Mcx2Svc - ok
17:43:44.0427 5588 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:43:44.0427 5588 megasas - ok
17:43:44.0443 5588 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:43:44.0443 5588 MegaSR - ok
17:43:44.0458 5588 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:43:44.0458 5588 MMCSS - ok
17:43:44.0474 5588 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:43:44.0474 5588 Modem - ok
17:43:44.0490 5588 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:43:44.0490 5588 monitor - ok
17:43:44.0505 5588 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:43:44.0505 5588 mouclass - ok
17:43:44.0521 5588 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:43:44.0521 5588 mouhid - ok
17:43:44.0536 5588 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:43:44.0536 5588 mountmgr - ok
17:43:44.0568 5588 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:43:44.0568 5588 mpio - ok
17:43:44.0583 5588 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:43:44.0583 5588 mpsdrv - ok
17:43:44.0692 5588 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:43:44.0739 5588 MpsSvc - ok
17:43:44.0755 5588 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:43:44.0770 5588 MRxDAV - ok
17:43:44.0817 5588 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:43:44.0817 5588 mrxsmb - ok
17:43:44.0911 5588 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:43:44.0911 5588 mrxsmb10 - ok
17:43:44.0942 5588 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:43:44.0942 5588 mrxsmb20 - ok
17:43:44.0958 5588 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:43:44.0958 5588 msahci - ok
17:43:44.0973 5588 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:43:44.0973 5588 msdsm - ok
17:43:44.0973 5588 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:43:44.0989 5588 MSDTC - ok
17:43:45.0004 5588 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:43:45.0004 5588 Msfs - ok
17:43:45.0004 5588 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:43:45.0004 5588 mshidkmdf - ok
17:43:45.0020 5588 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:43:45.0020 5588 msisadrv - ok
17:43:45.0036 5588 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:43:45.0036 5588 MSiSCSI - ok
17:43:45.0036 5588 msiserver - ok
17:43:45.0051 5588 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:43:45.0051 5588 MSKSSRV - ok
17:43:45.0067 5588 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:43:45.0067 5588 MSPCLOCK - ok
17:43:45.0098 5588 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:43:45.0098 5588 MSPQM - ok
17:43:45.0114 5588 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:43:45.0129 5588 MsRPC - ok
17:43:45.0129 5588 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:43:45.0129 5588 mssmbios - ok
17:43:45.0160 5588 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:43:45.0160 5588 MSTEE - ok
17:43:45.0160 5588 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:43:45.0160 5588 MTConfig - ok
17:43:45.0192 5588 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
17:43:45.0192 5588 MTsensor - ok
17:43:45.0207 5588 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:43:45.0207 5588 Mup - ok
17:43:45.0223 5588 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:43:45.0238 5588 napagent - ok
17:43:45.0254 5588 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:43:45.0254 5588 NativeWifiP - ok
17:43:45.0285 5588 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:43:45.0285 5588 NDIS - ok
17:43:45.0301 5588 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:43:45.0301 5588 NdisCap - ok
17:43:45.0316 5588 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:43:45.0316 5588 NdisTapi - ok
17:43:45.0348 5588 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:43:45.0348 5588 Ndisuio - ok
17:43:45.0379 5588 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:43:45.0379 5588 NdisWan - ok
17:43:45.0410 5588 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:43:45.0410 5588 NDProxy - ok
17:43:45.0410 5588 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:43:45.0410 5588 NetBIOS - ok
17:43:45.0441 5588 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:43:45.0441 5588 NetBT - ok
17:43:45.0472 5588 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
17:43:45.0472 5588 Netlogon - ok
17:43:45.0488 5588 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:43:45.0488 5588 Netman - ok
17:43:45.0519 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0535 5588 NetMsmqActivator - ok
17:43:45.0535 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0550 5588 NetPipeActivator - ok
17:43:45.0566 5588 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:43:45.0582 5588 netprofm - ok
17:43:45.0613 5588 [ 27EE4B406E2F26F6117A9A420BD4CB65 ] netr28u C:\Windows\system32\DRIVERS\netr28u.sys
17:43:45.0613 5588 netr28u - ok
17:43:45.0628 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0628 5588 NetTcpActivator - ok
17:43:45.0628 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0628 5588 NetTcpPortSharing - ok
17:43:45.0644 5588 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:43:45.0644 5588 nfrd960 - ok
17:43:45.0675 5588 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
17:43:45.0675 5588 NlaSvc - ok
17:43:45.0691 5588 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:43:45.0691 5588 Npfs - ok
17:43:45.0706 5588 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:43:45.0722 5588 nsi - ok
17:43:45.0722 5588 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:43:45.0722 5588 nsiproxy - ok
17:43:45.0769 5588 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:43:45.0784 5588 Ntfs - ok
17:43:45.0800 5588 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:43:45.0800 5588 Null - ok
17:43:45.0800 5588 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:43:45.0800 5588 nvraid - ok
17:43:45.0831 5588 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:43:45.0831 5588 nvstor - ok
17:43:45.0847 5588 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:43:45.0847 5588 nv_agp - ok
17:43:45.0847 5588 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:43:45.0847 5588 ohci1394 - ok
17:43:45.0878 5588 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:43:45.0878 5588 p2pimsvc - ok
17:43:45.0894 5588 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:43:45.0894 5588 p2psvc - ok
17:43:45.0909 5588 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:43:45.0909 5588 Parport - ok
17:43:45.0940 5588 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:43:45.0940 5588 partmgr - ok
17:43:45.0956 5588 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:43:45.0956 5588 Parvdm - ok
17:43:45.0972 5588 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:43:45.0972 5588 PcaSvc - ok
17:43:45.0987 5588 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:43:45.0987 5588 pci - ok
17:43:31.0822 3176 ============================================================
17:43:31.0822 3176 Current date / time: 2013/09/27 17:43:31.0822
17:43:31.0822 3176 SystemInfo:
17:43:31.0822 3176
17:43:31.0822 3176 OS Version: 6.1.7601 ServicePack: 1.0
17:43:31.0822 3176 Product type: Workstation
17:43:31.0822 3176 ComputerName: LUCASO-PC
17:43:31.0822 3176 UserName: Lucaso
17:43:31.0822 3176 Windows directory: C:\Windows
17:43:31.0822 3176 System windows directory: C:\Windows
17:43:31.0822 3176 Processor architecture: Intel x86
17:43:31.0822 3176 Number of processors: 2
17:43:31.0822 3176 Page size: 0x1000
17:43:31.0822 3176 Boot type: Normal boot
17:43:31.0822 3176 ============================================================
17:43:32.0977 3176 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x47B84, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050
17:43:32.0977 3176 ============================================================
17:43:32.0977 3176 \Device\Harddisk0\DR0:
17:43:32.0977 3176 MBR partitions:
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x5B9A000
17:43:32.0977 3176 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x5BCC800, BlocksNum 0x44C8A800
17:43:32.0977 3176 ============================================================
17:43:33.0008 3176 C: <-> \Device\Harddisk0\DR0\Partition2
17:43:33.0039 3176 F: <-> \Device\Harddisk0\DR0\Partition3
17:43:33.0039 3176 ============================================================
17:43:33.0039 3176 Initialize success
17:43:33.0039 3176 ============================================================
17:43:39.0357 5588 ============================================================
17:43:39.0357 5588 Scan started
17:43:39.0357 5588 Mode: Manual;
17:43:39.0357 5588 ============================================================
17:43:40.0200 5588 ================ Scan system memory ========================
17:43:40.0200 5588 System memory - ok
17:43:40.0200 5588 ================ Scan services =============================
17:43:40.0340 5588 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:43:40.0340 5588 1394ohci - ok
17:43:40.0402 5588 [ 0EEC6F1236660BE9A082F6D979074DFA ] 4game-service C:\Program Files\4game\4game-service.exe
17:43:40.0418 5588 4game-service - ok
17:43:40.0434 5588 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:43:40.0434 5588 ACPI - ok
17:43:40.0465 5588 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:43:40.0465 5588 AcpiPmi - ok
17:43:40.0496 5588 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:43:40.0496 5588 AdobeARMservice - ok
17:43:40.0543 5588 [ 24A0876D07EF356DCBC1D7A7929354AB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:43:40.0543 5588 AdobeFlashPlayerUpdateSvc - ok
17:43:40.0574 5588 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:43:40.0590 5588 adp94xx - ok
17:43:40.0605 5588 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:43:40.0605 5588 adpahci - ok
17:43:40.0621 5588 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:43:40.0621 5588 adpu320 - ok
17:43:40.0652 5588 [ 993F7B0BA5188A0007C085AA10257B8E ] AdvancedSystemCareService6 C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
17:43:40.0668 5588 AdvancedSystemCareService6 - ok
17:43:40.0683 5588 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:43:40.0683 5588 AeLookupSvc - ok
17:43:40.0714 5588 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
17:43:40.0714 5588 AFD - ok
17:43:40.0746 5588 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:43:40.0746 5588 agp440 - ok
17:43:40.0761 5588 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:43:40.0761 5588 aic78xx - ok
17:43:40.0777 5588 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:43:40.0792 5588 ALG - ok
17:43:40.0808 5588 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:43:40.0808 5588 aliide - ok
17:43:40.0839 5588 [ B19505648F033393E907E2E419FDE8B3 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
17:43:40.0839 5588 AMD External Events Utility - ok
17:43:40.0855 5588 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:43:40.0855 5588 amdagp - ok
17:43:40.0870 5588 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:43:40.0870 5588 amdide - ok
17:43:40.0886 5588 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:43:40.0886 5588 AmdK8 - ok
17:43:40.0902 5588 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:43:40.0902 5588 AmdPPM - ok
17:43:40.0917 5588 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:43:40.0917 5588 amdsata - ok
17:43:40.0933 5588 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:43:40.0933 5588 amdsbs - ok
17:43:40.0948 5588 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:43:40.0948 5588 amdxata - ok
17:43:40.0980 5588 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:43:40.0980 5588 AppID - ok
17:43:40.0980 5588 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:43:40.0980 5588 AppIDSvc - ok
17:43:40.0995 5588 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
17:43:41.0011 5588 Appinfo - ok
17:43:41.0042 5588 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:43:41.0042 5588 AppMgmt - ok
17:43:41.0042 5588 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:43:41.0058 5588 arc - ok
17:43:41.0058 5588 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:43:41.0058 5588 arcsas - ok
17:43:41.0120 5588 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:43:41.0136 5588 aspnet_state - ok
17:43:41.0151 5588 [ B9FE438B3CAD82B2014710349A2022F7 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
17:43:41.0151 5588 aswFsBlk - ok
17:43:41.0167 5588 [ 3FCA5C1A8F33CF9857220CC3A3076A3E ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
17:43:41.0182 5588 aswKbd - ok
17:43:41.0198 5588 [ AE5549DD21F6DE06406031EF1D51ACC3 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
17:43:41.0198 5588 aswMonFlt - ok
17:43:41.0198 5588 [ A29EF1A46E110F392588F7395BB55F32 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
17:43:41.0214 5588 aswRdr - ok
17:43:41.0245 5588 [ FA72FA503F580C3C628DD8C7D7622E37 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
17:43:41.0245 5588 aswRvrt - ok
17:43:41.0276 5588 [ 4D53349D848C6BADB3D4ACBE98C27676 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
17:43:41.0276 5588 aswSnx - ok
17:43:41.0307 5588 [ 813024DFD54A41B3AFAE2B1E2796CB80 ] aswSP C:\Windows\system32\drivers\aswSP.sys
17:43:41.0307 5588 aswSP - ok
17:43:41.0323 5588 [ 5E18413310134130D7772F0668698CB7 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
17:43:41.0323 5588 aswTdi - ok
17:43:41.0338 5588 [ A5F637D61719D37A5B4868C385E363C0 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
17:43:41.0338 5588 aswVmm - ok
17:43:41.0354 5588 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:43:41.0354 5588 AsyncMac - ok
17:43:41.0385 5588 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:43:41.0385 5588 atapi - ok
17:43:41.0401 5588 [ 0A5CCED52803D80ED4ECBC9616340862 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
17:43:41.0416 5588 Suspicious file (Forged): C:\Windows\system32\drivers\AtihdW73.sys. Real md5: 0A5CCED52803D80ED4ECBC9616340862, Fake md5: 5B2A6663E5B74919CF240FB5D81D531C
17:43:41.0416 5588 AtiHDAudioService ( ForgedFile.Multi.Generic ) - warning
17:43:41.0416 5588 AtiHDAudioService - detected ForgedFile.Multi.Generic (1)
17:43:41.0510 5588 [ 04F09923A393E4E0E8453A8F78361E73 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
17:43:41.0526 5588 atikmdag - ok
17:43:41.0572 5588 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:43:41.0572 5588 AudioEndpointBuilder - ok
17:43:41.0588 5588 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:43:41.0588 5588 Audiosrv - ok
17:43:41.0635 5588 [ 9330941C8F6DF417F6DBBE998DB6687E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
17:43:41.0635 5588 avast! Antivirus - ok
17:43:41.0650 5588 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:43:41.0650 5588 AxInstSV - ok
17:43:41.0682 5588 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:43:41.0682 5588 b06bdrv - ok
17:43:41.0697 5588 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:43:41.0697 5588 b57nd60x - ok
17:43:41.0713 5588 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:43:41.0713 5588 BDESVC - ok
17:43:41.0728 5588 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:43:41.0728 5588 Beep - ok
17:43:41.0760 5588 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:43:41.0760 5588 BFE - ok
17:43:41.0775 5588 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
17:43:41.0791 5588 BITS - ok
17:43:41.0791 5588 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:43:41.0791 5588 blbdrive - ok
17:43:41.0822 5588 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:43:41.0822 5588 bowser - ok
17:43:41.0838 5588 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:43:41.0838 5588 BrFiltLo - ok
17:43:41.0838 5588 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:43:41.0838 5588 BrFiltUp - ok
17:43:41.0853 5588 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
17:43:41.0853 5588 Browser - ok
17:43:41.0869 5588 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:43:41.0869 5588 Brserid - ok
17:43:41.0869 5588 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:43:41.0869 5588 BrSerWdm - ok
17:43:41.0884 5588 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:43:41.0884 5588 BrUsbMdm - ok
17:43:41.0884 5588 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:43:41.0884 5588 BrUsbSer - ok
17:43:41.0900 5588 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:43:41.0900 5588 BTHMODEM - ok
17:43:41.0916 5588 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:43:41.0916 5588 bthserv - ok
17:43:41.0931 5588 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:43:41.0931 5588 cdfs - ok
17:43:41.0947 5588 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:43:41.0947 5588 cdrom - ok
17:43:41.0962 5588 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:43:41.0962 5588 CertPropSvc - ok
17:43:41.0962 5588 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:43:41.0978 5588 circlass - ok
17:43:41.0978 5588 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:43:41.0978 5588 CLFS - ok
17:43:42.0025 5588 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:43:42.0025 5588 clr_optimization_v2.0.50727_32 - ok
17:43:42.0040 5588 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:43:42.0056 5588 clr_optimization_v4.0.30319_32 - ok
17:43:42.0087 5588 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:43:42.0087 5588 CmBatt - ok
17:43:42.0118 5588 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:43:42.0118 5588 cmdide - ok
17:43:42.0150 5588 [ 42F158036BD4C2FF3122BF142E60E6FD ] CNG C:\Windows\system32\Drivers\cng.sys
17:43:42.0150 5588 CNG - ok
17:43:42.0165 5588 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:43:42.0181 5588 Compbatt - ok
17:43:42.0196 5588 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:43:42.0196 5588 CompositeBus - ok
17:43:42.0196 5588 COMSysApp - ok
17:43:42.0212 5588 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:43:42.0212 5588 crcdisk - ok
17:43:42.0243 5588 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:43:42.0243 5588 CryptSvc - ok
17:43:42.0259 5588 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:43:42.0259 5588 CSC - ok
17:43:42.0274 5588 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:43:42.0274 5588 CscService - ok
17:43:42.0306 5588 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:43:42.0306 5588 DcomLaunch - ok
17:43:42.0321 5588 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:43:42.0321 5588 defragsvc - ok
17:43:42.0352 5588 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:43:42.0352 5588 DfsC - ok
17:43:42.0368 5588 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:43:42.0368 5588 Dhcp - ok
17:43:42.0415 5588 [ F4A9AC0561C9944CC262593C7161E0A8 ] Disc Soft Bus Service C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
17:43:42.0415 5588 Disc Soft Bus Service - ok
17:43:42.0430 5588 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:43:42.0430 5588 discache - ok
17:43:42.0446 5588 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:43:42.0446 5588 Disk - ok
17:43:42.0477 5588 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:43:42.0477 5588 Dnscache - ok
17:43:42.0493 5588 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:43:42.0493 5588 dot3svc - ok
17:43:42.0524 5588 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:43:42.0524 5588 DPS - ok
17:43:42.0540 5588 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:43:42.0540 5588 drmkaud - ok
17:43:42.0586 5588 [ 651554E483712B708EDE864D0CA1AA73 ] DrvAgent32 C:\Windows\system32\Drivers\DrvAgent32.sys
17:43:42.0586 5588 DrvAgent32 - ok
17:43:42.0602 5588 [ 50778FE9ED67AEB01EA99877B1B4A4DF ] dtscsibus C:\Windows\system32\DRIVERS\dtscsibus.sys
17:43:42.0602 5588 dtscsibus - ok
17:43:42.0633 5588 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:43:42.0649 5588 DXGKrnl - ok
17:43:42.0664 5588 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:43:42.0664 5588 EapHost - ok
17:43:42.0727 5588 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:43:42.0742 5588 ebdrv - ok
17:43:42.0774 5588 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
17:43:42.0774 5588 EFS - ok
17:43:42.0820 5588 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:43:42.0820 5588 ehRecvr - ok
17:43:42.0852 5588 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:43:42.0852 5588 ehSched - ok
17:43:42.0883 5588 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:43:42.0883 5588 elxstor - ok
17:43:42.0898 5588 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:43:42.0898 5588 ErrDev - ok
17:43:42.0930 5588 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:43:42.0930 5588 EventSystem - ok
17:43:42.0930 5588 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:43:42.0930 5588 exfat - ok
17:43:42.0945 5588 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:43:42.0945 5588 fastfat - ok
17:43:42.0992 5588 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:43:42.0992 5588 Fax - ok
17:43:43.0008 5588 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:43:43.0008 5588 fdc - ok
17:43:43.0008 5588 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:43:43.0023 5588 fdPHost - ok
17:43:43.0039 5588 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:43:43.0039 5588 FDResPub - ok
17:43:43.0054 5588 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:43:43.0054 5588 FileInfo - ok
17:43:43.0070 5588 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:43:43.0070 5588 Filetrace - ok
17:43:43.0070 5588 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:43:43.0070 5588 flpydisk - ok
17:43:43.0086 5588 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:43:43.0086 5588 FltMgr - ok
17:43:43.0117 5588 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
17:43:43.0132 5588 FontCache - ok
17:43:43.0179 5588 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:43:43.0179 5588 FontCache3.0.0.0 - ok
17:43:43.0195 5588 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:43:43.0195 5588 FsDepends - ok
17:43:43.0226 5588 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:43:43.0226 5588 Fs_Rec - ok
17:43:43.0257 5588 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:43:43.0257 5588 fvevol - ok
17:43:43.0273 5588 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:43:43.0273 5588 gagp30kx - ok
17:43:43.0288 5588 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\Windows\system32\giveio.sys
17:43:43.0288 5588 giveio - ok
17:43:43.0335 5588 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:43:43.0335 5588 gpsvc - ok
17:43:43.0382 5588 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
17:43:43.0382 5588 gupdate - ok
17:43:43.0398 5588 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
17:43:43.0398 5588 gupdatem - ok
17:43:43.0413 5588 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:43:43.0413 5588 hcw85cir - ok
17:43:43.0444 5588 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:43:43.0444 5588 HdAudAddService - ok
17:43:43.0460 5588 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:43:43.0460 5588 HDAudBus - ok
17:43:43.0476 5588 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:43:43.0476 5588 HidBatt - ok
17:43:43.0476 5588 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:43:43.0476 5588 HidBth - ok
17:43:43.0491 5588 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:43:43.0491 5588 HidIr - ok
17:43:43.0507 5588 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
17:43:43.0522 5588 hidserv - ok
17:43:43.0538 5588 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:43:43.0538 5588 HidUsb - ok
17:43:43.0554 5588 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:43:43.0554 5588 hkmsvc - ok
17:43:43.0585 5588 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:43:43.0585 5588 HomeGroupListener - ok
17:43:43.0632 5588 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:43:43.0632 5588 HomeGroupProvider - ok
17:43:43.0647 5588 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:43:43.0647 5588 HpSAMD - ok
17:43:43.0678 5588 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:43:43.0678 5588 HTTP - ok
17:43:43.0694 5588 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:43:43.0694 5588 hwpolicy - ok
17:43:43.0710 5588 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:43:43.0710 5588 i8042prt - ok
17:43:43.0741 5588 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:43:43.0741 5588 iaStorV - ok
17:43:43.0772 5588 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:43:43.0788 5588 idsvc - ok
17:43:43.0788 5588 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:43:43.0788 5588 iirsp - ok
17:43:43.0819 5588 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:43:43.0819 5588 IKEEXT - ok
17:43:43.0850 5588 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:43:43.0850 5588 intelide - ok
17:43:43.0866 5588 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:43:43.0866 5588 intelppm - ok
17:43:43.0881 5588 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:43:43.0881 5588 IPBusEnum - ok
17:43:43.0897 5588 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:43:43.0897 5588 IpFilterDriver - ok
17:43:43.0912 5588 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:43:43.0928 5588 iphlpsvc - ok
17:43:43.0944 5588 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:43:43.0944 5588 IPMIDRV - ok
17:43:43.0944 5588 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:43:43.0959 5588 IPNAT - ok
17:43:43.0959 5588 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:43:43.0959 5588 IRENUM - ok
17:43:43.0990 5588 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:43:43.0990 5588 isapnp - ok
17:43:43.0990 5588 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:43:44.0006 5588 iScsiPrt - ok
17:43:44.0006 5588 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:43:44.0006 5588 kbdclass - ok
17:43:44.0022 5588 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:43:44.0022 5588 kbdhid - ok
17:43:44.0037 5588 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
17:43:44.0037 5588 KeyIso - ok
17:43:44.0053 5588 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:43:44.0053 5588 KSecDD - ok
17:43:44.0084 5588 [ 5FE1ABF1AF591A3458C9CF24ED9A4D35 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:43:44.0084 5588 KSecPkg - ok
17:43:44.0100 5588 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:43:44.0115 5588 KtmRm - ok
17:43:44.0131 5588 [ BADB7F6173168DAC446F5035B4B66E18 ] L1C C:\Windows\system32\DRIVERS\L1C60x86.sys
17:43:44.0131 5588 L1C - ok
17:43:44.0146 5588 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
17:43:44.0146 5588 LanmanServer - ok
17:43:44.0178 5588 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:43:44.0178 5588 LanmanWorkstation - ok
17:43:44.0193 5588 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:43:44.0193 5588 lltdio - ok
17:43:44.0209 5588 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:43:44.0209 5588 lltdsvc - ok
17:43:44.0224 5588 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:43:44.0224 5588 lmhosts - ok
17:43:44.0256 5588 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:43:44.0256 5588 LSI_FC - ok
17:43:44.0256 5588 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:43:44.0271 5588 LSI_SAS - ok
17:43:44.0271 5588 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:43:44.0271 5588 LSI_SAS2 - ok
17:43:44.0287 5588 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:43:44.0287 5588 LSI_SCSI - ok
17:43:44.0318 5588 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:43:44.0318 5588 luafv - ok
17:43:44.0334 5588 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:43:44.0334 5588 MBAMProtector - ok
17:43:44.0349 5588 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:43:44.0365 5588 MBAMScheduler - ok
17:43:44.0380 5588 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:43:44.0380 5588 MBAMService - ok
17:43:44.0412 5588 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:43:44.0412 5588 Mcx2Svc - ok
17:43:44.0427 5588 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:43:44.0427 5588 megasas - ok
17:43:44.0443 5588 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:43:44.0443 5588 MegaSR - ok
17:43:44.0458 5588 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:43:44.0458 5588 MMCSS - ok
17:43:44.0474 5588 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:43:44.0474 5588 Modem - ok
17:43:44.0490 5588 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:43:44.0490 5588 monitor - ok
17:43:44.0505 5588 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:43:44.0505 5588 mouclass - ok
17:43:44.0521 5588 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:43:44.0521 5588 mouhid - ok
17:43:44.0536 5588 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:43:44.0536 5588 mountmgr - ok
17:43:44.0568 5588 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:43:44.0568 5588 mpio - ok
17:43:44.0583 5588 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:43:44.0583 5588 mpsdrv - ok
17:43:44.0692 5588 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:43:44.0739 5588 MpsSvc - ok
17:43:44.0755 5588 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:43:44.0770 5588 MRxDAV - ok
17:43:44.0817 5588 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:43:44.0817 5588 mrxsmb - ok
17:43:44.0911 5588 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:43:44.0911 5588 mrxsmb10 - ok
17:43:44.0942 5588 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:43:44.0942 5588 mrxsmb20 - ok
17:43:44.0958 5588 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:43:44.0958 5588 msahci - ok
17:43:44.0973 5588 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:43:44.0973 5588 msdsm - ok
17:43:44.0973 5588 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:43:44.0989 5588 MSDTC - ok
17:43:45.0004 5588 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:43:45.0004 5588 Msfs - ok
17:43:45.0004 5588 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:43:45.0004 5588 mshidkmdf - ok
17:43:45.0020 5588 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:43:45.0020 5588 msisadrv - ok
17:43:45.0036 5588 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:43:45.0036 5588 MSiSCSI - ok
17:43:45.0036 5588 msiserver - ok
17:43:45.0051 5588 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:43:45.0051 5588 MSKSSRV - ok
17:43:45.0067 5588 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:43:45.0067 5588 MSPCLOCK - ok
17:43:45.0098 5588 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:43:45.0098 5588 MSPQM - ok
17:43:45.0114 5588 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:43:45.0129 5588 MsRPC - ok
17:43:45.0129 5588 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:43:45.0129 5588 mssmbios - ok
17:43:45.0160 5588 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:43:45.0160 5588 MSTEE - ok
17:43:45.0160 5588 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:43:45.0160 5588 MTConfig - ok
17:43:45.0192 5588 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
17:43:45.0192 5588 MTsensor - ok
17:43:45.0207 5588 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:43:45.0207 5588 Mup - ok
17:43:45.0223 5588 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:43:45.0238 5588 napagent - ok
17:43:45.0254 5588 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:43:45.0254 5588 NativeWifiP - ok
17:43:45.0285 5588 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:43:45.0285 5588 NDIS - ok
17:43:45.0301 5588 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:43:45.0301 5588 NdisCap - ok
17:43:45.0316 5588 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:43:45.0316 5588 NdisTapi - ok
17:43:45.0348 5588 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:43:45.0348 5588 Ndisuio - ok
17:43:45.0379 5588 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:43:45.0379 5588 NdisWan - ok
17:43:45.0410 5588 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:43:45.0410 5588 NDProxy - ok
17:43:45.0410 5588 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:43:45.0410 5588 NetBIOS - ok
17:43:45.0441 5588 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:43:45.0441 5588 NetBT - ok
17:43:45.0472 5588 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
17:43:45.0472 5588 Netlogon - ok
17:43:45.0488 5588 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:43:45.0488 5588 Netman - ok
17:43:45.0519 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0535 5588 NetMsmqActivator - ok
17:43:45.0535 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0550 5588 NetPipeActivator - ok
17:43:45.0566 5588 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:43:45.0582 5588 netprofm - ok
17:43:45.0613 5588 [ 27EE4B406E2F26F6117A9A420BD4CB65 ] netr28u C:\Windows\system32\DRIVERS\netr28u.sys
17:43:45.0613 5588 netr28u - ok
17:43:45.0628 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0628 5588 NetTcpActivator - ok
17:43:45.0628 5588 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:43:45.0628 5588 NetTcpPortSharing - ok
17:43:45.0644 5588 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:43:45.0644 5588 nfrd960 - ok
17:43:45.0675 5588 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
17:43:45.0675 5588 NlaSvc - ok
17:43:45.0691 5588 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:43:45.0691 5588 Npfs - ok
17:43:45.0706 5588 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:43:45.0722 5588 nsi - ok
17:43:45.0722 5588 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:43:45.0722 5588 nsiproxy - ok
17:43:45.0769 5588 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:43:45.0784 5588 Ntfs - ok
17:43:45.0800 5588 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:43:45.0800 5588 Null - ok
17:43:45.0800 5588 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:43:45.0800 5588 nvraid - ok
17:43:45.0831 5588 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:43:45.0831 5588 nvstor - ok
17:43:45.0847 5588 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:43:45.0847 5588 nv_agp - ok
17:43:45.0847 5588 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:43:45.0847 5588 ohci1394 - ok
17:43:45.0878 5588 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:43:45.0878 5588 p2pimsvc - ok
17:43:45.0894 5588 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:43:45.0894 5588 p2psvc - ok
17:43:45.0909 5588 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:43:45.0909 5588 Parport - ok
17:43:45.0940 5588 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:43:45.0940 5588 partmgr - ok
17:43:45.0956 5588 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:43:45.0956 5588 Parvdm - ok
17:43:45.0972 5588 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:43:45.0972 5588 PcaSvc - ok
17:43:45.0987 5588 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:43:45.0987 5588 pci - ok
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
Re: Prosím o kontrolu. Sekání hry.
17:43:46.0018 5588 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:43:46.0018 5588 pciide - ok
17:43:46.0018 5588 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:43:46.0034 5588 pcmcia - ok
17:43:46.0050 5588 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:43:46.0050 5588 pcw - ok
17:43:46.0065 5588 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:43:46.0065 5588 PEAUTH - ok
17:43:46.0112 5588 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:43:46.0128 5588 PeerDistSvc - ok
17:43:46.0174 5588 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:43:46.0206 5588 pla - ok
17:43:46.0221 5588 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:43:46.0221 5588 PlugPlay - ok
17:43:46.0237 5588 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:43:46.0252 5588 PnkBstrA - ok
17:43:46.0252 5588 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:43:46.0252 5588 PNRPAutoReg - ok
17:43:46.0268 5588 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:43:46.0268 5588 PNRPsvc - ok
17:43:46.0284 5588 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:43:46.0299 5588 PolicyAgent - ok
17:43:46.0330 5588 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:43:46.0330 5588 Power - ok
17:43:46.0330 5588 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:43:46.0346 5588 PptpMiniport - ok
17:43:46.0346 5588 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:43:46.0346 5588 Processor - ok
17:43:46.0362 5588 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:43:46.0362 5588 ProfSvc - ok
17:43:46.0362 5588 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:43:46.0362 5588 ProtectedStorage - ok
17:43:46.0377 5588 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:43:46.0393 5588 Psched - ok
17:43:46.0424 5588 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:43:46.0424 5588 ql2300 - ok
17:43:46.0440 5588 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:43:46.0440 5588 ql40xx - ok
17:43:46.0440 5588 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:43:46.0455 5588 QWAVE - ok
17:43:46.0471 5588 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:43:46.0471 5588 QWAVEdrv - ok
17:43:46.0471 5588 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:43:46.0471 5588 RasAcd - ok
17:43:46.0486 5588 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:43:46.0486 5588 RasAgileVpn - ok
17:43:46.0502 5588 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:43:46.0502 5588 RasAuto - ok
17:43:46.0533 5588 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:43:46.0533 5588 Rasl2tp - ok
17:43:46.0564 5588 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:43:46.0564 5588 RasMan - ok
17:43:46.0596 5588 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:43:46.0596 5588 RasPppoe - ok
17:43:46.0596 5588 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:43:46.0611 5588 RasSstp - ok
17:43:46.0627 5588 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:43:46.0642 5588 rdbss - ok
17:43:46.0658 5588 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:43:46.0658 5588 rdpbus - ok
17:43:46.0674 5588 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:43:46.0674 5588 RDPCDD - ok
17:43:46.0689 5588 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:43:46.0705 5588 RDPDR - ok
17:43:46.0705 5588 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:43:46.0720 5588 RDPENCDD - ok
17:43:46.0720 5588 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:43:46.0720 5588 RDPREFMP - ok
17:43:46.0752 5588 [ 65375DF758CA1872AB7EBBBA457FD5E6 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:43:46.0752 5588 RdpVideoMiniport - ok
17:43:46.0783 5588 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:43:46.0783 5588 RDPWD - ok
17:43:46.0814 5588 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:43:46.0814 5588 rdyboost - ok
17:43:46.0830 5588 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:43:46.0830 5588 RemoteAccess - ok
17:43:46.0845 5588 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:43:46.0861 5588 RemoteRegistry - ok
17:43:46.0861 5588 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:43:46.0876 5588 RpcEptMapper - ok
17:43:46.0892 5588 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:43:46.0892 5588 RpcLocator - ok
17:43:46.0892 5588 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:43:46.0908 5588 RpcSs - ok
17:43:46.0908 5588 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:43:46.0908 5588 rspndr - ok
17:43:46.0923 5588 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:43:46.0923 5588 s3cap - ok
17:43:46.0939 5588 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
17:43:46.0939 5588 SamSs - ok
17:43:46.0954 5588 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:43:46.0970 5588 sbp2port - ok
17:43:46.0970 5588 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:43:46.0970 5588 SCardSvr - ok
17:43:46.0986 5588 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:43:46.0986 5588 scfilter - ok
17:43:47.0032 5588 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:43:47.0048 5588 Schedule - ok
17:43:47.0064 5588 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:43:47.0064 5588 SCPolicySvc - ok
17:43:47.0079 5588 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:43:47.0079 5588 SDRSVC - ok
17:43:47.0157 5588 [ 95AA9E165C7DE1B64A11E8B18E91E499 ] SDScannerService C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
17:43:47.0173 5588 SDScannerService - ok
17:43:47.0204 5588 [ D31398D4BB4907B517B6E784C2100C4A ] SDUpdateService C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
17:43:47.0204 5588 SDUpdateService - ok
17:43:47.0220 5588 [ 6AE8E702D1027A9627DDE2B77BB9992B ] SDWSCService C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
17:43:47.0235 5588 SDWSCService - ok
17:43:47.0235 5588 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:43:47.0251 5588 secdrv - ok
17:43:47.0266 5588 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:43:47.0266 5588 seclogon - ok
17:43:47.0282 5588 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:43:47.0282 5588 SENS - ok
17:43:47.0282 5588 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:43:47.0282 5588 SensrSvc - ok
17:43:47.0298 5588 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:43:47.0298 5588 Serenum - ok
17:43:47.0313 5588 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:43:47.0313 5588 Serial - ok
17:43:47.0313 5588 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:43:47.0329 5588 sermouse - ok
17:43:47.0360 5588 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:43:47.0360 5588 SessionEnv - ok
17:43:47.0376 5588 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:43:47.0376 5588 sffdisk - ok
17:43:47.0376 5588 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:43:47.0376 5588 sffp_mmc - ok
17:43:47.0391 5588 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:43:47.0391 5588 sffp_sd - ok
17:43:47.0407 5588 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:43:47.0422 5588 sfloppy - ok
17:43:47.0422 5588 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:43:47.0438 5588 SharedAccess - ok
17:43:47.0454 5588 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:43:47.0469 5588 ShellHWDetection - ok
17:43:47.0485 5588 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:43:47.0485 5588 sisagp - ok
17:43:47.0500 5588 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:43:47.0500 5588 SiSRaid2 - ok
17:43:47.0516 5588 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:43:47.0516 5588 SiSRaid4 - ok
17:43:47.0516 5588 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:43:47.0516 5588 Smb - ok
17:43:47.0547 5588 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:43:47.0547 5588 SNMPTRAP - ok
17:43:47.0563 5588 [ DC8D2952FB6FFBAEC67BD1B93A34DF11 ] speedfan C:\Windows\system32\speedfan.sys
17:43:47.0578 5588 speedfan - ok
17:43:47.0578 5588 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:43:47.0594 5588 spldr - ok
17:43:47.0610 5588 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:43:47.0610 5588 Spooler - ok
17:43:47.0703 5588 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:43:47.0734 5588 sppsvc - ok
17:43:47.0750 5588 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:43:47.0750 5588 sppuinotify - ok
17:43:47.0766 5588 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:43:47.0781 5588 srv - ok
17:43:47.0781 5588 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:43:47.0781 5588 srv2 - ok
17:43:47.0781 5588 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:43:47.0797 5588 srvnet - ok
17:43:47.0797 5588 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:43:47.0797 5588 SSDPSRV - ok
17:43:47.0812 5588 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:43:47.0812 5588 SstpSvc - ok
17:43:47.0859 5588 [ 3DBF9D2E5DE3A72B37AB27ABB79FEE69 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
17:43:47.0859 5588 Steam Client Service - ok
17:43:47.0890 5588 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:43:47.0890 5588 stexstor - ok
17:43:47.0906 5588 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:43:47.0922 5588 StiSvc - ok
17:43:47.0922 5588 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:43:47.0922 5588 storflt - ok
17:43:47.0953 5588 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:43:47.0953 5588 storvsc - ok
17:43:47.0968 5588 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:43:47.0968 5588 swenum - ok
17:43:47.0984 5588 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:43:48.0000 5588 swprv - ok
17:43:48.0000 5588 Synth3dVsc - ok
17:43:48.0031 5588 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:43:48.0046 5588 SysMain - ok
17:43:48.0062 5588 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:43:48.0062 5588 TabletInputService - ok
17:43:48.0078 5588 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:43:48.0093 5588 TapiSrv - ok
17:43:48.0109 5588 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:43:48.0109 5588 TBS - ok
17:43:48.0156 5588 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:43:48.0156 5588 Tcpip - ok
17:43:48.0187 5588 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:43:48.0187 5588 TCPIP6 - ok
17:43:48.0218 5588 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:43:48.0218 5588 tcpipreg - ok
17:43:48.0249 5588 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:43:48.0249 5588 TDPIPE - ok
17:43:48.0249 5588 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:43:48.0249 5588 TDTCP - ok
17:43:48.0280 5588 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:43:48.0280 5588 tdx - ok
17:43:48.0280 5588 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:43:48.0296 5588 TermDD - ok
17:43:48.0327 5588 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:43:48.0327 5588 TermService - ok
17:43:48.0343 5588 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:43:48.0358 5588 Themes - ok
17:43:48.0374 5588 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:43:48.0374 5588 THREADORDER - ok
17:43:48.0390 5588 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:43:48.0390 5588 TrkWks - ok
17:43:48.0436 5588 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:43:48.0436 5588 TrustedInstaller - ok
17:43:48.0452 5588 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:43:48.0452 5588 tssecsrv - ok
17:43:48.0499 5588 [ 9CE253214ACAA5A7D323327D2055EFAA ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:43:48.0499 5588 TsUsbFlt - ok
17:43:48.0499 5588 tsusbhub - ok
17:43:48.0530 5588 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:43:48.0530 5588 tunnel - ok
17:43:48.0546 5588 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:43:48.0546 5588 uagp35 - ok
17:43:48.0577 5588 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:43:48.0577 5588 udfs - ok
17:43:48.0592 5588 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:43:48.0592 5588 UI0Detect - ok
17:43:48.0639 5588 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:43:48.0639 5588 uliagpkx - ok
17:43:48.0639 5588 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:43:48.0639 5588 umbus - ok
17:43:48.0655 5588 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:43:48.0655 5588 UmPass - ok
17:43:48.0670 5588 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:43:48.0670 5588 UmRdpService - ok
17:43:48.0702 5588 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:43:48.0702 5588 upnphost - ok
17:43:48.0717 5588 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:43:48.0717 5588 usbccgp - ok
17:43:48.0733 5588 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:43:48.0733 5588 usbcir - ok
17:43:48.0748 5588 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:43:48.0748 5588 usbehci - ok
17:43:48.0764 5588 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:43:48.0764 5588 usbhub - ok
17:43:48.0780 5588 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
17:43:48.0780 5588 usbohci - ok
17:43:48.0811 5588 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:43:48.0811 5588 usbprint - ok
17:43:48.0826 5588 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
17:43:48.0826 5588 USBSTOR - ok
17:43:48.0842 5588 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:43:48.0842 5588 usbuhci - ok
17:43:48.0842 5588 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:43:48.0858 5588 UxSms - ok
17:43:48.0873 5588 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
17:43:48.0873 5588 VaultSvc - ok
17:43:48.0889 5588 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:43:48.0889 5588 vdrvroot - ok
17:43:48.0904 5588 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:43:48.0920 5588 vds - ok
17:43:48.0920 5588 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:43:48.0920 5588 vga - ok
17:43:48.0936 5588 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:43:48.0936 5588 VgaSave - ok
17:43:48.0936 5588 VGPU - ok
17:43:48.0951 5588 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:43:48.0967 5588 vhdmp - ok
17:43:48.0967 5588 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:43:48.0967 5588 viaagp - ok
17:43:48.0982 5588 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:43:48.0982 5588 ViaC7 - ok
17:43:48.0998 5588 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:43:48.0998 5588 viaide - ok
17:43:49.0029 5588 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:43:49.0029 5588 vmbus - ok
17:43:49.0045 5588 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:43:49.0045 5588 VMBusHID - ok
17:43:49.0060 5588 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:43:49.0060 5588 volmgr - ok
17:43:49.0076 5588 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:43:49.0076 5588 volmgrx - ok
17:43:49.0092 5588 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:43:49.0092 5588 volsnap - ok
17:43:49.0123 5588 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:43:49.0123 5588 vsmraid - ok
17:43:49.0154 5588 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:43:49.0170 5588 VSS - ok
17:43:49.0170 5588 vtany - ok
17:43:49.0185 5588 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
17:43:49.0185 5588 vwifibus - ok
17:43:49.0201 5588 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
17:43:49.0201 5588 vwififlt - ok
17:43:49.0216 5588 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:43:49.0216 5588 W32Time - ok
17:43:49.0232 5588 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:43:49.0232 5588 WacomPen - ok
17:43:49.0263 5588 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:43:49.0263 5588 WANARP - ok
17:43:49.0263 5588 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:43:49.0263 5588 Wanarpv6 - ok
17:43:49.0310 5588 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:43:49.0341 5588 WatAdminSvc - ok
17:43:49.0372 5588 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:43:49.0388 5588 wbengine - ok
17:43:49.0404 5588 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:43:49.0419 5588 WbioSrvc - ok
17:43:49.0435 5588 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:43:49.0435 5588 wcncsvc - ok
17:43:49.0435 5588 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:43:49.0450 5588 WcsPlugInService - ok
17:43:49.0450 5588 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:43:49.0450 5588 Wd - ok
17:43:49.0482 5588 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:43:49.0497 5588 Wdf01000 - ok
17:43:49.0513 5588 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:43:49.0513 5588 WdiServiceHost - ok
17:43:49.0513 5588 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:43:49.0528 5588 WdiSystemHost - ok
17:43:49.0560 5588 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:43:49.0560 5588 WebClient - ok
17:43:49.0575 5588 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:43:49.0591 5588 Wecsvc - ok
17:43:49.0591 5588 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:43:49.0606 5588 wercplsupport - ok
17:43:49.0622 5588 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:43:49.0622 5588 WerSvc - ok
17:43:49.0622 5588 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:43:49.0638 5588 WfpLwf - ok
17:43:49.0638 5588 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:43:49.0638 5588 WIMMount - ok
17:43:49.0684 5588 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:43:49.0700 5588 WinDefend - ok
17:43:49.0716 5588 WinHttpAutoProxySvc - ok
17:43:49.0762 5588 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:43:49.0762 5588 Winmgmt - ok
17:43:49.0809 5588 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:43:49.0840 5588 WinRM - ok
17:43:49.0856 5588 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:43:49.0856 5588 WinUsb - ok
17:43:49.0887 5588 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:43:49.0903 5588 Wlansvc - ok
17:43:49.0934 5588 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:43:49.0934 5588 WmiAcpi - ok
17:43:49.0965 5588 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:43:49.0981 5588 wmiApSrv - ok
17:43:50.0012 5588 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:43:50.0012 5588 WMPNetworkSvc - ok
17:43:50.0028 5588 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:43:50.0028 5588 WPCSvc - ok
17:43:50.0059 5588 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:43:50.0059 5588 WPDBusEnum - ok
17:43:50.0074 5588 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:43:50.0074 5588 ws2ifsl - ok
17:43:50.0090 5588 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:43:50.0106 5588 wscsvc - ok
17:43:50.0106 5588 WSearch - ok
17:43:50.0168 5588 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:43:50.0215 5588 wuauserv - ok
17:43:50.0246 5588 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:43:50.0246 5588 WudfPf - ok
17:43:50.0262 5588 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:43:50.0262 5588 WUDFRd - ok
17:43:50.0277 5588 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:43:50.0277 5588 wudfsvc - ok
17:43:50.0308 5588 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:43:50.0308 5588 WwanSvc - ok
17:43:50.0308 5588 xhunter1 - ok
17:43:50.0324 5588 ================ Scan global ===============================
17:43:50.0371 5588 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:43:50.0402 5588 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:43:50.0418 5588 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:43:50.0433 5588 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:43:50.0449 5588 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:43:50.0449 5588 [Global] - ok
17:43:50.0449 5588 ================ Scan MBR ==================================
17:43:50.0464 5588 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:43:50.0792 5588 \Device\Harddisk0\DR0 - ok
17:43:50.0792 5588 ================ Scan VBR ==================================
17:43:50.0792 5588 [ 677B9C87783CE2B92FCF11384DAF47AA ] \Device\Harddisk0\DR0\Partition1
17:43:50.0792 5588 \Device\Harddisk0\DR0\Partition1 - ok
17:43:50.0808 5588 [ 4C165A511D7F207A7936D01FB3D41CE3 ] \Device\Harddisk0\DR0\Partition2
17:43:50.0808 5588 \Device\Harddisk0\DR0\Partition2 - ok
17:43:50.0823 5588 [ D18286C5CB960DAA341C86F023E18845 ] \Device\Harddisk0\DR0\Partition3
17:43:50.0823 5588 \Device\Harddisk0\DR0\Partition3 - ok
17:43:50.0823 5588 ============================================================
17:43:50.0823 5588 Scan finished
17:43:50.0823 5588 ============================================================
17:43:50.0839 2620 Detected object count: 1
17:43:50.0839 2620 Actual detected object count: 1
17:43:56.0361 2620 AtiHDAudioService ( ForgedFile.Multi.Generic ) - skipped by user
17:43:56.0361 2620 AtiHDAudioService ( ForgedFile.Multi.Generic ) - User select action: Skip
17:44:01.0993 2612 Deinitialize success
17:43:46.0018 5588 pciide - ok
17:43:46.0018 5588 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:43:46.0034 5588 pcmcia - ok
17:43:46.0050 5588 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:43:46.0050 5588 pcw - ok
17:43:46.0065 5588 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:43:46.0065 5588 PEAUTH - ok
17:43:46.0112 5588 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:43:46.0128 5588 PeerDistSvc - ok
17:43:46.0174 5588 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:43:46.0206 5588 pla - ok
17:43:46.0221 5588 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:43:46.0221 5588 PlugPlay - ok
17:43:46.0237 5588 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
17:43:46.0252 5588 PnkBstrA - ok
17:43:46.0252 5588 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:43:46.0252 5588 PNRPAutoReg - ok
17:43:46.0268 5588 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:43:46.0268 5588 PNRPsvc - ok
17:43:46.0284 5588 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:43:46.0299 5588 PolicyAgent - ok
17:43:46.0330 5588 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:43:46.0330 5588 Power - ok
17:43:46.0330 5588 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:43:46.0346 5588 PptpMiniport - ok
17:43:46.0346 5588 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:43:46.0346 5588 Processor - ok
17:43:46.0362 5588 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:43:46.0362 5588 ProfSvc - ok
17:43:46.0362 5588 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:43:46.0362 5588 ProtectedStorage - ok
17:43:46.0377 5588 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:43:46.0393 5588 Psched - ok
17:43:46.0424 5588 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:43:46.0424 5588 ql2300 - ok
17:43:46.0440 5588 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:43:46.0440 5588 ql40xx - ok
17:43:46.0440 5588 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:43:46.0455 5588 QWAVE - ok
17:43:46.0471 5588 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:43:46.0471 5588 QWAVEdrv - ok
17:43:46.0471 5588 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:43:46.0471 5588 RasAcd - ok
17:43:46.0486 5588 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:43:46.0486 5588 RasAgileVpn - ok
17:43:46.0502 5588 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:43:46.0502 5588 RasAuto - ok
17:43:46.0533 5588 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:43:46.0533 5588 Rasl2tp - ok
17:43:46.0564 5588 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:43:46.0564 5588 RasMan - ok
17:43:46.0596 5588 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:43:46.0596 5588 RasPppoe - ok
17:43:46.0596 5588 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:43:46.0611 5588 RasSstp - ok
17:43:46.0627 5588 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:43:46.0642 5588 rdbss - ok
17:43:46.0658 5588 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:43:46.0658 5588 rdpbus - ok
17:43:46.0674 5588 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:43:46.0674 5588 RDPCDD - ok
17:43:46.0689 5588 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:43:46.0705 5588 RDPDR - ok
17:43:46.0705 5588 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:43:46.0720 5588 RDPENCDD - ok
17:43:46.0720 5588 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:43:46.0720 5588 RDPREFMP - ok
17:43:46.0752 5588 [ 65375DF758CA1872AB7EBBBA457FD5E6 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:43:46.0752 5588 RdpVideoMiniport - ok
17:43:46.0783 5588 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:43:46.0783 5588 RDPWD - ok
17:43:46.0814 5588 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:43:46.0814 5588 rdyboost - ok
17:43:46.0830 5588 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:43:46.0830 5588 RemoteAccess - ok
17:43:46.0845 5588 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:43:46.0861 5588 RemoteRegistry - ok
17:43:46.0861 5588 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:43:46.0876 5588 RpcEptMapper - ok
17:43:46.0892 5588 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:43:46.0892 5588 RpcLocator - ok
17:43:46.0892 5588 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:43:46.0908 5588 RpcSs - ok
17:43:46.0908 5588 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:43:46.0908 5588 rspndr - ok
17:43:46.0923 5588 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:43:46.0923 5588 s3cap - ok
17:43:46.0939 5588 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
17:43:46.0939 5588 SamSs - ok
17:43:46.0954 5588 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:43:46.0970 5588 sbp2port - ok
17:43:46.0970 5588 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:43:46.0970 5588 SCardSvr - ok
17:43:46.0986 5588 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:43:46.0986 5588 scfilter - ok
17:43:47.0032 5588 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:43:47.0048 5588 Schedule - ok
17:43:47.0064 5588 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:43:47.0064 5588 SCPolicySvc - ok
17:43:47.0079 5588 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:43:47.0079 5588 SDRSVC - ok
17:43:47.0157 5588 [ 95AA9E165C7DE1B64A11E8B18E91E499 ] SDScannerService C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
17:43:47.0173 5588 SDScannerService - ok
17:43:47.0204 5588 [ D31398D4BB4907B517B6E784C2100C4A ] SDUpdateService C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
17:43:47.0204 5588 SDUpdateService - ok
17:43:47.0220 5588 [ 6AE8E702D1027A9627DDE2B77BB9992B ] SDWSCService C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
17:43:47.0235 5588 SDWSCService - ok
17:43:47.0235 5588 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:43:47.0251 5588 secdrv - ok
17:43:47.0266 5588 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:43:47.0266 5588 seclogon - ok
17:43:47.0282 5588 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
17:43:47.0282 5588 SENS - ok
17:43:47.0282 5588 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:43:47.0282 5588 SensrSvc - ok
17:43:47.0298 5588 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:43:47.0298 5588 Serenum - ok
17:43:47.0313 5588 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:43:47.0313 5588 Serial - ok
17:43:47.0313 5588 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:43:47.0329 5588 sermouse - ok
17:43:47.0360 5588 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:43:47.0360 5588 SessionEnv - ok
17:43:47.0376 5588 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:43:47.0376 5588 sffdisk - ok
17:43:47.0376 5588 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:43:47.0376 5588 sffp_mmc - ok
17:43:47.0391 5588 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:43:47.0391 5588 sffp_sd - ok
17:43:47.0407 5588 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:43:47.0422 5588 sfloppy - ok
17:43:47.0422 5588 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:43:47.0438 5588 SharedAccess - ok
17:43:47.0454 5588 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:43:47.0469 5588 ShellHWDetection - ok
17:43:47.0485 5588 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:43:47.0485 5588 sisagp - ok
17:43:47.0500 5588 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:43:47.0500 5588 SiSRaid2 - ok
17:43:47.0516 5588 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:43:47.0516 5588 SiSRaid4 - ok
17:43:47.0516 5588 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:43:47.0516 5588 Smb - ok
17:43:47.0547 5588 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:43:47.0547 5588 SNMPTRAP - ok
17:43:47.0563 5588 [ DC8D2952FB6FFBAEC67BD1B93A34DF11 ] speedfan C:\Windows\system32\speedfan.sys
17:43:47.0578 5588 speedfan - ok
17:43:47.0578 5588 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:43:47.0594 5588 spldr - ok
17:43:47.0610 5588 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
17:43:47.0610 5588 Spooler - ok
17:43:47.0703 5588 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:43:47.0734 5588 sppsvc - ok
17:43:47.0750 5588 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:43:47.0750 5588 sppuinotify - ok
17:43:47.0766 5588 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:43:47.0781 5588 srv - ok
17:43:47.0781 5588 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:43:47.0781 5588 srv2 - ok
17:43:47.0781 5588 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:43:47.0797 5588 srvnet - ok
17:43:47.0797 5588 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:43:47.0797 5588 SSDPSRV - ok
17:43:47.0812 5588 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:43:47.0812 5588 SstpSvc - ok
17:43:47.0859 5588 [ 3DBF9D2E5DE3A72B37AB27ABB79FEE69 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
17:43:47.0859 5588 Steam Client Service - ok
17:43:47.0890 5588 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:43:47.0890 5588 stexstor - ok
17:43:47.0906 5588 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:43:47.0922 5588 StiSvc - ok
17:43:47.0922 5588 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:43:47.0922 5588 storflt - ok
17:43:47.0953 5588 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:43:47.0953 5588 storvsc - ok
17:43:47.0968 5588 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:43:47.0968 5588 swenum - ok
17:43:47.0984 5588 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:43:48.0000 5588 swprv - ok
17:43:48.0000 5588 Synth3dVsc - ok
17:43:48.0031 5588 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:43:48.0046 5588 SysMain - ok
17:43:48.0062 5588 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:43:48.0062 5588 TabletInputService - ok
17:43:48.0078 5588 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:43:48.0093 5588 TapiSrv - ok
17:43:48.0109 5588 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:43:48.0109 5588 TBS - ok
17:43:48.0156 5588 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:43:48.0156 5588 Tcpip - ok
17:43:48.0187 5588 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:43:48.0187 5588 TCPIP6 - ok
17:43:48.0218 5588 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:43:48.0218 5588 tcpipreg - ok
17:43:48.0249 5588 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:43:48.0249 5588 TDPIPE - ok
17:43:48.0249 5588 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:43:48.0249 5588 TDTCP - ok
17:43:48.0280 5588 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:43:48.0280 5588 tdx - ok
17:43:48.0280 5588 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:43:48.0296 5588 TermDD - ok
17:43:48.0327 5588 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:43:48.0327 5588 TermService - ok
17:43:48.0343 5588 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:43:48.0358 5588 Themes - ok
17:43:48.0374 5588 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:43:48.0374 5588 THREADORDER - ok
17:43:48.0390 5588 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:43:48.0390 5588 TrkWks - ok
17:43:48.0436 5588 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:43:48.0436 5588 TrustedInstaller - ok
17:43:48.0452 5588 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:43:48.0452 5588 tssecsrv - ok
17:43:48.0499 5588 [ 9CE253214ACAA5A7D323327D2055EFAA ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:43:48.0499 5588 TsUsbFlt - ok
17:43:48.0499 5588 tsusbhub - ok
17:43:48.0530 5588 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:43:48.0530 5588 tunnel - ok
17:43:48.0546 5588 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:43:48.0546 5588 uagp35 - ok
17:43:48.0577 5588 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:43:48.0577 5588 udfs - ok
17:43:48.0592 5588 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:43:48.0592 5588 UI0Detect - ok
17:43:48.0639 5588 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:43:48.0639 5588 uliagpkx - ok
17:43:48.0639 5588 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:43:48.0639 5588 umbus - ok
17:43:48.0655 5588 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:43:48.0655 5588 UmPass - ok
17:43:48.0670 5588 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:43:48.0670 5588 UmRdpService - ok
17:43:48.0702 5588 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:43:48.0702 5588 upnphost - ok
17:43:48.0717 5588 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:43:48.0717 5588 usbccgp - ok
17:43:48.0733 5588 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:43:48.0733 5588 usbcir - ok
17:43:48.0748 5588 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:43:48.0748 5588 usbehci - ok
17:43:48.0764 5588 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:43:48.0764 5588 usbhub - ok
17:43:48.0780 5588 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
17:43:48.0780 5588 usbohci - ok
17:43:48.0811 5588 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:43:48.0811 5588 usbprint - ok
17:43:48.0826 5588 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
17:43:48.0826 5588 USBSTOR - ok
17:43:48.0842 5588 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:43:48.0842 5588 usbuhci - ok
17:43:48.0842 5588 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:43:48.0858 5588 UxSms - ok
17:43:48.0873 5588 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
17:43:48.0873 5588 VaultSvc - ok
17:43:48.0889 5588 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:43:48.0889 5588 vdrvroot - ok
17:43:48.0904 5588 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:43:48.0920 5588 vds - ok
17:43:48.0920 5588 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:43:48.0920 5588 vga - ok
17:43:48.0936 5588 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:43:48.0936 5588 VgaSave - ok
17:43:48.0936 5588 VGPU - ok
17:43:48.0951 5588 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:43:48.0967 5588 vhdmp - ok
17:43:48.0967 5588 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:43:48.0967 5588 viaagp - ok
17:43:48.0982 5588 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:43:48.0982 5588 ViaC7 - ok
17:43:48.0998 5588 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:43:48.0998 5588 viaide - ok
17:43:49.0029 5588 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:43:49.0029 5588 vmbus - ok
17:43:49.0045 5588 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:43:49.0045 5588 VMBusHID - ok
17:43:49.0060 5588 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:43:49.0060 5588 volmgr - ok
17:43:49.0076 5588 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:43:49.0076 5588 volmgrx - ok
17:43:49.0092 5588 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:43:49.0092 5588 volsnap - ok
17:43:49.0123 5588 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:43:49.0123 5588 vsmraid - ok
17:43:49.0154 5588 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:43:49.0170 5588 VSS - ok
17:43:49.0170 5588 vtany - ok
17:43:49.0185 5588 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
17:43:49.0185 5588 vwifibus - ok
17:43:49.0201 5588 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
17:43:49.0201 5588 vwififlt - ok
17:43:49.0216 5588 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:43:49.0216 5588 W32Time - ok
17:43:49.0232 5588 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:43:49.0232 5588 WacomPen - ok
17:43:49.0263 5588 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:43:49.0263 5588 WANARP - ok
17:43:49.0263 5588 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:43:49.0263 5588 Wanarpv6 - ok
17:43:49.0310 5588 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:43:49.0341 5588 WatAdminSvc - ok
17:43:49.0372 5588 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:43:49.0388 5588 wbengine - ok
17:43:49.0404 5588 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:43:49.0419 5588 WbioSrvc - ok
17:43:49.0435 5588 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:43:49.0435 5588 wcncsvc - ok
17:43:49.0435 5588 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:43:49.0450 5588 WcsPlugInService - ok
17:43:49.0450 5588 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:43:49.0450 5588 Wd - ok
17:43:49.0482 5588 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:43:49.0497 5588 Wdf01000 - ok
17:43:49.0513 5588 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:43:49.0513 5588 WdiServiceHost - ok
17:43:49.0513 5588 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:43:49.0528 5588 WdiSystemHost - ok
17:43:49.0560 5588 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:43:49.0560 5588 WebClient - ok
17:43:49.0575 5588 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:43:49.0591 5588 Wecsvc - ok
17:43:49.0591 5588 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:43:49.0606 5588 wercplsupport - ok
17:43:49.0622 5588 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:43:49.0622 5588 WerSvc - ok
17:43:49.0622 5588 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:43:49.0638 5588 WfpLwf - ok
17:43:49.0638 5588 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:43:49.0638 5588 WIMMount - ok
17:43:49.0684 5588 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:43:49.0700 5588 WinDefend - ok
17:43:49.0716 5588 WinHttpAutoProxySvc - ok
17:43:49.0762 5588 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:43:49.0762 5588 Winmgmt - ok
17:43:49.0809 5588 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:43:49.0840 5588 WinRM - ok
17:43:49.0856 5588 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:43:49.0856 5588 WinUsb - ok
17:43:49.0887 5588 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:43:49.0903 5588 Wlansvc - ok
17:43:49.0934 5588 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:43:49.0934 5588 WmiAcpi - ok
17:43:49.0965 5588 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:43:49.0981 5588 wmiApSrv - ok
17:43:50.0012 5588 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:43:50.0012 5588 WMPNetworkSvc - ok
17:43:50.0028 5588 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:43:50.0028 5588 WPCSvc - ok
17:43:50.0059 5588 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:43:50.0059 5588 WPDBusEnum - ok
17:43:50.0074 5588 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:43:50.0074 5588 ws2ifsl - ok
17:43:50.0090 5588 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
17:43:50.0106 5588 wscsvc - ok
17:43:50.0106 5588 WSearch - ok
17:43:50.0168 5588 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:43:50.0215 5588 wuauserv - ok
17:43:50.0246 5588 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:43:50.0246 5588 WudfPf - ok
17:43:50.0262 5588 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:43:50.0262 5588 WUDFRd - ok
17:43:50.0277 5588 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:43:50.0277 5588 wudfsvc - ok
17:43:50.0308 5588 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:43:50.0308 5588 WwanSvc - ok
17:43:50.0308 5588 xhunter1 - ok
17:43:50.0324 5588 ================ Scan global ===============================
17:43:50.0371 5588 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:43:50.0402 5588 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:43:50.0418 5588 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
17:43:50.0433 5588 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:43:50.0449 5588 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:43:50.0449 5588 [Global] - ok
17:43:50.0449 5588 ================ Scan MBR ==================================
17:43:50.0464 5588 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:43:50.0792 5588 \Device\Harddisk0\DR0 - ok
17:43:50.0792 5588 ================ Scan VBR ==================================
17:43:50.0792 5588 [ 677B9C87783CE2B92FCF11384DAF47AA ] \Device\Harddisk0\DR0\Partition1
17:43:50.0792 5588 \Device\Harddisk0\DR0\Partition1 - ok
17:43:50.0808 5588 [ 4C165A511D7F207A7936D01FB3D41CE3 ] \Device\Harddisk0\DR0\Partition2
17:43:50.0808 5588 \Device\Harddisk0\DR0\Partition2 - ok
17:43:50.0823 5588 [ D18286C5CB960DAA341C86F023E18845 ] \Device\Harddisk0\DR0\Partition3
17:43:50.0823 5588 \Device\Harddisk0\DR0\Partition3 - ok
17:43:50.0823 5588 ============================================================
17:43:50.0823 5588 Scan finished
17:43:50.0823 5588 ============================================================
17:43:50.0839 2620 Detected object count: 1
17:43:50.0839 2620 Actual detected object count: 1
17:43:56.0361 2620 AtiHDAudioService ( ForgedFile.Multi.Generic ) - skipped by user
17:43:56.0361 2620 AtiHDAudioService ( ForgedFile.Multi.Generic ) - User select action: Skip
17:44:01.0993 2612 Deinitialize success
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
Re: Prosím o kontrolu. Sekání hry.
Musel jsem to rozdělit nevešlo se to do jedné.
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu. Sekání hry.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu. Sekání hry.
Akorád dělal problémy ten Spybot - Search and Destroy. Psalo to, že byl zapnutý, ale nikde jsem ho neviděl a ani ve správci úloh.
ComboFix 13-09-26.03 - Lucaso 27.09.2013 22:47:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3583.2607 [GMT 2:00]
Spuštěný z: c:\users\Lucaso\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\Preferences
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-27 do 2013-09-27 )))))))))))))))))))))))))))))))
.
.
2013-09-27 07:45 . 2013-09-05 05:02 7328304 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB2332CC-2252-49F0-A1AF-921FF6557963}\mpengine.dll
2013-09-26 15:02 . 2013-09-26 15:02 -------- d-----w- c:\windows\snack
2013-09-26 14:51 . 2013-09-26 14:51 -------- d-----w- c:\windows\ERUNT
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\users\Lucaso\AppData\Roaming\Malwarebytes
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\programdata\Malwarebytes
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-25 20:41 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-25 20:33 . 2013-09-26 04:17 -------- d-----w- C:\AdwCleaner
2013-09-25 20:33 . 2013-09-25 20:33 -------- d-----w- c:\users\Lucaso\AppData\Local\AAA_Internet_Publishing,_
2013-09-25 12:26 . 2013-02-01 05:39 72296 ----a-w- c:\windows\system32\WTFastDrv.dll
2013-09-25 12:26 . 2013-02-01 05:39 11264 ----a-w- c:\windows\system32\SPORDER.DLL
2013-09-25 12:26 . 2013-09-25 12:26 -------- d-----w- c:\program files\WTFast
2013-09-20 08:18 . 2013-09-20 08:18 -------- d-----w- c:\users\Lucaso\AppData\Local\TERA
2013-09-20 07:20 . 2013-09-21 07:24 -------- d-----w- c:\programdata\HappyCloud
2013-09-18 17:50 . 2013-09-18 17:50 -------- d-----w- c:\program files\GPU-Z
2013-09-17 21:35 . 2013-09-17 21:35 -------- d-----w- c:\users\Lucaso\AppData\Roaming\JAM Software
2013-09-17 21:35 . 2013-09-17 21:35 -------- d-----w- c:\program files\JAM Software
2013-09-16 08:55 . 2013-09-16 08:55 -------- d-----w- C:\Temp
2013-09-16 08:14 . 2013-09-16 08:14 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-09-16 08:14 . 2013-09-16 08:14 -------- d-----w- c:\users\Lucaso\AppData\Local\eSupport.com
2013-09-16 08:13 . 2013-09-16 08:13 -------- d-----w- c:\program files\CPUID
2013-09-15 07:04 . 2013-09-15 07:04 -------- d-----w- c:\programdata\Bohemia Interactive
2013-09-14 09:40 . 2013-09-14 09:40 -------- d-----w- c:\programdata\Package Cache
2013-09-13 11:15 . 2013-09-13 11:15 -------- d-----w- c:\programdata\Aiseesoft Studio
2013-09-13 11:15 . 2013-09-13 11:15 -------- d-----w- c:\program files\Aiseesoft Studio
2013-09-10 20:47 . 2013-09-18 15:39 -------- d-----w- c:\program files\SpeedFan
2013-09-10 20:40 . 2013-09-10 20:40 -------- d-----w- c:\windows\system32\wbem\Framework
2013-09-07 17:47 . 2013-09-27 20:43 -------- d-----w- c:\program files\Common Files\Steam
2013-09-02 07:52 . 2013-09-02 07:52 -------- d-----w- c:\programdata\Steam
2013-09-02 07:25 . 2013-09-02 07:25 -------- d-----w- c:\program files\NVIDIA Corporation
2013-09-02 07:25 . 2013-09-02 07:25 -------- d-----w- c:\program files\AGEIA Technologies
2013-09-02 07:21 . 2008-10-15 04:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2013-09-02 07:21 . 2008-10-15 04:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2013-09-02 07:21 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2013-09-02 07:21 . 2013-09-02 07:21 -------- d-----w- c:\users\Lucaso\AppData\Local\DTClient
2013-09-02 06:30 . 2013-09-02 06:30 24704 ----a-w- c:\windows\system32\drivers\dtscsibus.sys
2013-09-02 06:30 . 2013-09-02 06:31 -------- d-----w- c:\users\Lucaso\AppData\Roaming\DAEMON Tools Ultra
2013-09-02 06:29 . 2013-09-02 06:30 -------- d-----w- c:\program files\DAEMON Tools Ultra
2013-09-02 06:29 . 2013-09-03 11:45 -------- d-----w- c:\programdata\DAEMON Tools Ultra
2013-09-02 05:47 . 2013-09-02 05:47 -------- d-----w- C:\AMD
2013-09-01 13:36 . 2013-09-02 05:58 -------- d-----w- c:\users\Lucaso\AppData\Roaming\EoN
2013-09-01 13:36 . 2013-09-20 07:21 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-01 13:36 . 2013-09-20 07:21 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-01 13:36 . 2013-09-01 13:36 -------- d-----w- c:\windows\system32\Macromed
2013-08-31 13:42 . 2013-08-31 13:42 -------- d-----w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-30 07:48 . 2013-08-20 10:49 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-08-20 10:49 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-08-20 10:48 177864 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2013-08-20 10:49 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2013-08-20 10:49 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2013-08-20 10:48 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-08-20 10:49 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2013-08-20 10:48 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2013-08-20 10:48 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2013-08-20 10:48 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-27 20:47 . 2013-08-27 19:33 139424 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-08-27 20:47 . 2013-08-27 19:33 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-08-27 20:47 . 2013-08-27 20:43 282104 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-08-27 20:47 . 2013-08-27 19:33 282104 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-08-27 19:33 . 2013-08-27 19:33 138056 ----a-w- c:\users\Lucaso\AppData\Roaming\PnkBstrK.sys
2013-08-27 11:22 . 2013-08-27 11:22 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-08-27 08:02 . 2013-08-27 08:02 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-27 08:02 . 2013-08-27 08:02 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-27 08:02 . 2013-08-27 08:02 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-17 07:04 . 2013-08-17 07:04 56320 ----a-w- c:\windows\system32\TSWbPrxy.exe
2013-08-17 07:04 . 2013-08-17 07:04 49664 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2013-08-17 07:04 . 2013-08-17 07:04 4916224 ----a-w- c:\windows\system32\mstscax.dll
2013-08-17 07:04 . 2013-08-17 07:04 46592 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2013-08-17 07:04 . 2013-08-17 07:04 37376 ----a-w- c:\windows\system32\tsgqec.dll
2013-08-17 07:04 . 2013-08-17 07:04 32768 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2013-08-17 07:04 . 2013-08-17 07:04 317440 ----a-w- c:\windows\system32\wksprt.exe
2013-08-17 07:04 . 2013-08-17 07:04 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2013-08-17 07:04 . 2013-08-17 07:04 2739712 ----a-w- c:\windows\system32\rdpcorets.dll
2013-08-17 07:04 . 2013-08-17 07:04 269312 ----a-w- c:\windows\system32\aaclient.dll
2013-08-17 07:04 . 2013-08-17 07:04 221184 ----a-w- c:\windows\system32\rdpudd.dll
2013-08-17 07:04 . 2013-08-17 07:04 192000 ----a-w- c:\windows\system32\rdpendp_winip.dll
2013-08-17 07:04 . 2013-08-17 07:04 16896 ----a-w- c:\windows\system32\wksprtPS.dll
2013-08-17 07:04 . 2013-08-17 07:04 14848 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2013-08-17 07:04 . 2013-08-17 07:04 13312 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-17 07:04 . 2013-08-17 07:04 12800 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2013-08-17 07:04 . 2013-08-17 07:04 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-17 07:04 . 2013-08-17 07:04 1048064 ----a-w- c:\windows\system32\mstsc.exe
2013-08-17 07:04 . 2013-08-17 07:04 369856 ----a-w- c:\windows\system32\drivers\cng.sys
2013-08-17 07:04 . 2013-08-17 07:04 247808 ----a-w- c:\windows\system32\schannel.dll
2013-08-17 07:04 . 2013-08-17 07:04 136560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-08-17 07:04 . 2013-08-17 07:04 1039360 ----a-w- c:\windows\system32\lsasrv.dll
2013-08-17 07:02 . 2013-08-17 07:02 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-08-13 01:04 . 2013-08-13 01:04 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-13 01:04 . 2013-08-13 01:04 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-13 01:04 . 2013-08-13 01:04 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-13 01:04 . 2013-08-13 01:04 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-08-13 01:04 . 2013-08-13 01:04 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-08-13 01:04 . 2013-08-13 01:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-13 01:04 . 2013-08-13 01:04 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-08-13 01:04 . 2013-08-13 01:04 361984 ----a-w- c:\windows\system32\html.iec
2013-08-13 01:04 . 2013-08-13 01:04 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-13 01:04 . 2013-08-13 01:04 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-08-13 01:04 . 2013-08-13 01:04 158720 ----a-w- c:\windows\system32\msls31.dll
2013-08-13 01:04 . 2013-08-13 01:04 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-08-13 01:04 . 2013-08-13 01:04 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-13 01:04 . 2013-08-13 01:04 138752 ----a-w- c:\windows\system32\wextract.exe
2013-08-13 01:04 . 2013-08-13 01:04 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-13 01:04 . 2013-08-13 01:04 12800 ----a-w- c:\windows\system32\mshta.exe
2013-08-13 01:04 . 2013-08-13 01:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-13 01:03 . 2013-08-13 01:03 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-08-13 01:03 . 2013-08-13 01:03 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 906240 ----a-w- c:\windows\system32\FntCache.dll
2013-08-13 01:03 . 2013-08-13 01:03 604160 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-13 01:03 . 2013-08-13 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-13 01:03 . 2013-08-13 01:03 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 364544 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-13 01:03 . 2013-08-13 01:03 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 3419136 ----a-w- c:\windows\system32\d2d1.dll
2013-08-13 01:03 . 2013-08-13 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 293376 ----a-w- c:\windows\system32\dxgi.dll
2013-08-13 01:03 . 2013-08-13 01:03 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 249856 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-13 01:03 . 2013-08-13 01:03 2284544 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-08-13 01:03 . 2013-08-13 01:03 220160 ----a-w- c:\windows\system32\d3d10core.dll
2013-08-13 01:03 . 2013-08-13 01:03 207872 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-08-13 01:03 . 2013-08-13 01:03 1988096 ----a-w- c:\windows\system32\d3d10warp.dll
2013-08-13 01:03 . 2013-08-13 01:03 187392 ----a-w- c:\windows\system32\UIAnimation.dll
2013-08-13 01:03 . 2013-08-13 01:03 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2013-08-13 01:03 . 2013-08-13 01:03 1158144 ----a-w- c:\windows\system32\XpsPrint.dll
2013-08-13 01:03 . 2013-08-13 01:03 1080832 ----a-w- c:\windows\system32\d3d10.dll
2013-08-13 01:03 . 2013-08-13 01:03 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-12 06:03 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-08-07 02:22 . 2013-08-10 09:50 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-07-25 08:57 . 2013-08-14 05:15 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-19 01:41 . 2013-08-14 05:15 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-09 05:03 . 2013-08-14 05:15 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-09 05:03 . 2013-08-14 05:15 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-09 04:53 . 2013-08-14 05:15 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-07-09 04:52 . 2013-08-14 05:15 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 04:50 . 2013-08-14 05:15 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 04:46 . 2013-08-14 05:15 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 04:46 . 2013-08-14 05:15 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 05:15 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-06 05:05 . 2013-08-14 05:15 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2012-09-24 490880]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-08-20 96056]
"DAEMON Tools Ultra Agent"="c:\program files\DAEMON Tools Ultra\DTAgent.exe" [2013-06-25 3128352]
"Steam"="f:\hry\Steam\Steam.exe" [2013-09-21 1814440]
"WTFast Tray"="c:\program files\WTFast\WTFast.exe" [2013-09-24 2484696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"NCUpdateHelper"="f:\hry\NCWest\NCLauncher\NCUpdateHelper.exe" [2013-08-20 528360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-08-11 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
2013-05-16 13:25 1062472 ----a-w- c:\users\Lucaso\AppData\Roaming\Seznam.cz\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
2013-04-12 08:10 92664 ----a-w- c:\users\Lucaso\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-08-11 08:11 27676008 ----a-w- c:\users\Lucaso\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
2013-05-16 13:25 1062472 ----a-w- c:\program files\Seznam.cz\distribution\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R3 4game-service;4game-service;c:\program files\4game\4game-service.exe [2013-05-23 1133056]
R3 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-11-06 84992]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2013-09-16 23456]
R3 netr28u;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-08-17 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-08-17 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vtany;vtany; [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-08-10 1343400]
R3 xhunter1;xhunter1; [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [2012-10-31 464256]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-08-30 66336]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
S3 Disc Soft Bus Service;Disc Soft Bus Service;c:\program files\DAEMON Tools Ultra\DiscSoftBusService.exe [2013-06-25 632352]
S3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys [2013-09-02 24704]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C60x86.sys [2011-04-19 68208]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 02:31 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-01 07:21]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 09:24]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 09:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/?clid=12454
uInternet Settings,ProxyServer = localhost:21320
uInternet Settings,ProxyOverride = <local>
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
LSP: %SystemRoot%\system32\WTFastDrv.dll
Trusted Zone: 4game.com
TCP: DhcpNameServer = 8.8.8.8 84.21.107.121
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-PlayNC Launcher - (no file)
Notify-SDWinLogon - SDWinLogon.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3663190652-2704878265-732043386-1000\Software\SecuROM\License information*]
"datasecu"=hex:4e,f0,22,e1,a5,9d,67,d6,5c,4c,1b,03,95,a7,2d,e1,87,5f,8d,20,57,
04,78,68,6f,a7,89,ef,05,d2,7f,2d,79,70,2d,d2,74,7f,0b,80,bb,4d,d0,aa,a2,d7,\
"rkeysecu"=hex:59,1f,72,b8,97,96,b9,1c,00,e1,86,eb,2d,c3,dd,2a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\taskhost.exe
c:\program files\IObit\Advanced SystemCare 6\Monitor.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Steam\SteamService.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2013-09-27 22:57:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-27 20:57
.
Před spuštěním: Volných bajtů: 23 398 027 264
Po spuštění: Volných bajtů: 23 187 648 512
.
- - End Of File - - E548BB69A2E9E2F1617E529CDDFEB578
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 13-09-26.03 - Lucaso 27.09.2013 22:47:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3583.2607 [GMT 2:00]
Spuštěný z: c:\users\Lucaso\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lucaso\AppData\Local\Google\Chrome\User Data\Default\Preferences
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-27 do 2013-09-27 )))))))))))))))))))))))))))))))
.
.
2013-09-27 07:45 . 2013-09-05 05:02 7328304 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB2332CC-2252-49F0-A1AF-921FF6557963}\mpengine.dll
2013-09-26 15:02 . 2013-09-26 15:02 -------- d-----w- c:\windows\snack
2013-09-26 14:51 . 2013-09-26 14:51 -------- d-----w- c:\windows\ERUNT
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\users\Lucaso\AppData\Roaming\Malwarebytes
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\programdata\Malwarebytes
2013-09-25 20:41 . 2013-09-25 20:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-25 20:41 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-25 20:33 . 2013-09-26 04:17 -------- d-----w- C:\AdwCleaner
2013-09-25 20:33 . 2013-09-25 20:33 -------- d-----w- c:\users\Lucaso\AppData\Local\AAA_Internet_Publishing,_
2013-09-25 12:26 . 2013-02-01 05:39 72296 ----a-w- c:\windows\system32\WTFastDrv.dll
2013-09-25 12:26 . 2013-02-01 05:39 11264 ----a-w- c:\windows\system32\SPORDER.DLL
2013-09-25 12:26 . 2013-09-25 12:26 -------- d-----w- c:\program files\WTFast
2013-09-20 08:18 . 2013-09-20 08:18 -------- d-----w- c:\users\Lucaso\AppData\Local\TERA
2013-09-20 07:20 . 2013-09-21 07:24 -------- d-----w- c:\programdata\HappyCloud
2013-09-18 17:50 . 2013-09-18 17:50 -------- d-----w- c:\program files\GPU-Z
2013-09-17 21:35 . 2013-09-17 21:35 -------- d-----w- c:\users\Lucaso\AppData\Roaming\JAM Software
2013-09-17 21:35 . 2013-09-17 21:35 -------- d-----w- c:\program files\JAM Software
2013-09-16 08:55 . 2013-09-16 08:55 -------- d-----w- C:\Temp
2013-09-16 08:14 . 2013-09-16 08:14 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-09-16 08:14 . 2013-09-16 08:14 -------- d-----w- c:\users\Lucaso\AppData\Local\eSupport.com
2013-09-16 08:13 . 2013-09-16 08:13 -------- d-----w- c:\program files\CPUID
2013-09-15 07:04 . 2013-09-15 07:04 -------- d-----w- c:\programdata\Bohemia Interactive
2013-09-14 09:40 . 2013-09-14 09:40 -------- d-----w- c:\programdata\Package Cache
2013-09-13 11:15 . 2013-09-13 11:15 -------- d-----w- c:\programdata\Aiseesoft Studio
2013-09-13 11:15 . 2013-09-13 11:15 -------- d-----w- c:\program files\Aiseesoft Studio
2013-09-10 20:47 . 2013-09-18 15:39 -------- d-----w- c:\program files\SpeedFan
2013-09-10 20:40 . 2013-09-10 20:40 -------- d-----w- c:\windows\system32\wbem\Framework
2013-09-07 17:47 . 2013-09-27 20:43 -------- d-----w- c:\program files\Common Files\Steam
2013-09-02 07:52 . 2013-09-02 07:52 -------- d-----w- c:\programdata\Steam
2013-09-02 07:25 . 2013-09-02 07:25 -------- d-----w- c:\program files\NVIDIA Corporation
2013-09-02 07:25 . 2013-09-02 07:25 -------- d-----w- c:\program files\AGEIA Technologies
2013-09-02 07:21 . 2008-10-15 04:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2013-09-02 07:21 . 2008-10-15 04:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2013-09-02 07:21 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2013-09-02 07:21 . 2013-09-02 07:21 -------- d-----w- c:\users\Lucaso\AppData\Local\DTClient
2013-09-02 06:30 . 2013-09-02 06:30 24704 ----a-w- c:\windows\system32\drivers\dtscsibus.sys
2013-09-02 06:30 . 2013-09-02 06:31 -------- d-----w- c:\users\Lucaso\AppData\Roaming\DAEMON Tools Ultra
2013-09-02 06:29 . 2013-09-02 06:30 -------- d-----w- c:\program files\DAEMON Tools Ultra
2013-09-02 06:29 . 2013-09-03 11:45 -------- d-----w- c:\programdata\DAEMON Tools Ultra
2013-09-02 05:47 . 2013-09-02 05:47 -------- d-----w- C:\AMD
2013-09-01 13:36 . 2013-09-02 05:58 -------- d-----w- c:\users\Lucaso\AppData\Roaming\EoN
2013-09-01 13:36 . 2013-09-20 07:21 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-01 13:36 . 2013-09-20 07:21 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-01 13:36 . 2013-09-01 13:36 -------- d-----w- c:\windows\system32\Macromed
2013-08-31 13:42 . 2013-08-31 13:42 -------- d-----w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-30 07:48 . 2013-08-20 10:49 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-08-20 10:49 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-08-20 10:48 177864 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2013-08-20 10:49 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2013-08-20 10:49 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2013-08-20 10:48 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-08-20 10:49 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2013-08-20 10:48 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2013-08-20 10:48 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2013-08-20 10:48 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-27 20:47 . 2013-08-27 19:33 139424 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-08-27 20:47 . 2013-08-27 19:33 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-08-27 20:47 . 2013-08-27 20:43 282104 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-08-27 20:47 . 2013-08-27 19:33 282104 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-08-27 19:33 . 2013-08-27 19:33 138056 ----a-w- c:\users\Lucaso\AppData\Roaming\PnkBstrK.sys
2013-08-27 11:22 . 2013-08-27 11:22 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-08-27 08:02 . 2013-08-27 08:02 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-27 08:02 . 2013-08-27 08:02 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-27 08:02 . 2013-08-27 08:02 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-17 07:04 . 2013-08-17 07:04 56320 ----a-w- c:\windows\system32\TSWbPrxy.exe
2013-08-17 07:04 . 2013-08-17 07:04 49664 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2013-08-17 07:04 . 2013-08-17 07:04 4916224 ----a-w- c:\windows\system32\mstscax.dll
2013-08-17 07:04 . 2013-08-17 07:04 46592 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2013-08-17 07:04 . 2013-08-17 07:04 37376 ----a-w- c:\windows\system32\tsgqec.dll
2013-08-17 07:04 . 2013-08-17 07:04 32768 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2013-08-17 07:04 . 2013-08-17 07:04 317440 ----a-w- c:\windows\system32\wksprt.exe
2013-08-17 07:04 . 2013-08-17 07:04 3072 ----a-w- c:\windows\system32\drivers\en-US\tsusbflt.sys.mui
2013-08-17 07:04 . 2013-08-17 07:04 2739712 ----a-w- c:\windows\system32\rdpcorets.dll
2013-08-17 07:04 . 2013-08-17 07:04 269312 ----a-w- c:\windows\system32\aaclient.dll
2013-08-17 07:04 . 2013-08-17 07:04 221184 ----a-w- c:\windows\system32\rdpudd.dll
2013-08-17 07:04 . 2013-08-17 07:04 192000 ----a-w- c:\windows\system32\rdpendp_winip.dll
2013-08-17 07:04 . 2013-08-17 07:04 16896 ----a-w- c:\windows\system32\wksprtPS.dll
2013-08-17 07:04 . 2013-08-17 07:04 14848 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2013-08-17 07:04 . 2013-08-17 07:04 13312 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-17 07:04 . 2013-08-17 07:04 12800 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2013-08-17 07:04 . 2013-08-17 07:04 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-08-17 07:04 . 2013-08-17 07:04 1048064 ----a-w- c:\windows\system32\mstsc.exe
2013-08-17 07:04 . 2013-08-17 07:04 369856 ----a-w- c:\windows\system32\drivers\cng.sys
2013-08-17 07:04 . 2013-08-17 07:04 247808 ----a-w- c:\windows\system32\schannel.dll
2013-08-17 07:04 . 2013-08-17 07:04 136560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-08-17 07:04 . 2013-08-17 07:04 1039360 ----a-w- c:\windows\system32\lsasrv.dll
2013-08-17 07:02 . 2013-08-17 07:02 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-08-13 01:04 . 2013-08-13 01:04 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-13 01:04 . 2013-08-13 01:04 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-13 01:04 . 2013-08-13 01:04 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-13 01:04 . 2013-08-13 01:04 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-08-13 01:04 . 2013-08-13 01:04 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-08-13 01:04 . 2013-08-13 01:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-13 01:04 . 2013-08-13 01:04 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-08-13 01:04 . 2013-08-13 01:04 361984 ----a-w- c:\windows\system32\html.iec
2013-08-13 01:04 . 2013-08-13 01:04 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-13 01:04 . 2013-08-13 01:04 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-08-13 01:04 . 2013-08-13 01:04 158720 ----a-w- c:\windows\system32\msls31.dll
2013-08-13 01:04 . 2013-08-13 01:04 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-08-13 01:04 . 2013-08-13 01:04 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-13 01:04 . 2013-08-13 01:04 138752 ----a-w- c:\windows\system32\wextract.exe
2013-08-13 01:04 . 2013-08-13 01:04 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-13 01:04 . 2013-08-13 01:04 12800 ----a-w- c:\windows\system32\mshta.exe
2013-08-13 01:04 . 2013-08-13 01:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-13 01:03 . 2013-08-13 01:03 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-08-13 01:03 . 2013-08-13 01:03 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 906240 ----a-w- c:\windows\system32\FntCache.dll
2013-08-13 01:03 . 2013-08-13 01:03 604160 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-13 01:03 . 2013-08-13 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-13 01:03 . 2013-08-13 01:03 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 364544 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-13 01:03 . 2013-08-13 01:03 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 3419136 ----a-w- c:\windows\system32\d2d1.dll
2013-08-13 01:03 . 2013-08-13 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 293376 ----a-w- c:\windows\system32\dxgi.dll
2013-08-13 01:03 . 2013-08-13 01:03 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-08-13 01:03 . 2013-08-13 01:03 249856 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-13 01:03 . 2013-08-13 01:03 2284544 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-08-13 01:03 . 2013-08-13 01:03 220160 ----a-w- c:\windows\system32\d3d10core.dll
2013-08-13 01:03 . 2013-08-13 01:03 207872 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-08-13 01:03 . 2013-08-13 01:03 1988096 ----a-w- c:\windows\system32\d3d10warp.dll
2013-08-13 01:03 . 2013-08-13 01:03 187392 ----a-w- c:\windows\system32\UIAnimation.dll
2013-08-13 01:03 . 2013-08-13 01:03 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2013-08-13 01:03 . 2013-08-13 01:03 1158144 ----a-w- c:\windows\system32\XpsPrint.dll
2013-08-13 01:03 . 2013-08-13 01:03 1080832 ----a-w- c:\windows\system32\d3d10.dll
2013-08-13 01:03 . 2013-08-13 01:03 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-08-12 06:03 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-08-07 02:22 . 2013-08-10 09:50 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-07-25 08:57 . 2013-08-14 05:15 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-19 01:41 . 2013-08-14 05:15 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-09 05:03 . 2013-08-14 05:15 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-09 05:03 . 2013-08-14 05:15 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-09 04:53 . 2013-08-14 05:15 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-07-09 04:52 . 2013-08-14 05:15 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 04:50 . 2013-08-14 05:15 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 04:46 . 2013-08-14 05:15 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 04:46 . 2013-08-14 05:15 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 05:15 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-06 05:05 . 2013-08-14 05:15 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2012-09-24 490880]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-08-20 96056]
"DAEMON Tools Ultra Agent"="c:\program files\DAEMON Tools Ultra\DTAgent.exe" [2013-06-25 3128352]
"Steam"="f:\hry\Steam\Steam.exe" [2013-09-21 1814440]
"WTFast Tray"="c:\program files\WTFast\WTFast.exe" [2013-09-24 2484696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"NCUpdateHelper"="f:\hry\NCWest\NCLauncher\NCUpdateHelper.exe" [2013-08-20 528360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-08-11 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
2013-05-16 13:25 1062472 ----a-w- c:\users\Lucaso\AppData\Roaming\Seznam.cz\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
2013-04-12 08:10 92664 ----a-w- c:\users\Lucaso\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
2013-08-11 08:11 27676008 ----a-w- c:\users\Lucaso\AppData\Roaming\ICQM\icq.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
2013-05-16 13:25 1062472 ----a-w- c:\program files\Seznam.cz\distribution\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R3 4game-service;4game-service;c:\program files\4game\4game-service.exe [2013-05-23 1133056]
R3 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-11-06 84992]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2013-09-16 23456]
R3 netr28u;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-08-17 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-08-17 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vtany;vtany; [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-08-10 1343400]
R3 xhunter1;xhunter1; [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [2012-10-31 464256]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-08-30 66336]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
S3 Disc Soft Bus Service;Disc Soft Bus Service;c:\program files\DAEMON Tools Ultra\DiscSoftBusService.exe [2013-06-25 632352]
S3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys [2013-09-02 24704]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C60x86.sys [2011-04-19 68208]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 02:31 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-01 07:21]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 09:24]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 09:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/?clid=12454
uInternet Settings,ProxyServer = localhost:21320
uInternet Settings,ProxyOverride = <local>
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
LSP: %SystemRoot%\system32\WTFastDrv.dll
Trusted Zone: 4game.com
TCP: DhcpNameServer = 8.8.8.8 84.21.107.121
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-PlayNC Launcher - (no file)
Notify-SDWinLogon - SDWinLogon.dll
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3663190652-2704878265-732043386-1000\Software\SecuROM\License information*]
"datasecu"=hex:4e,f0,22,e1,a5,9d,67,d6,5c,4c,1b,03,95,a7,2d,e1,87,5f,8d,20,57,
04,78,68,6f,a7,89,ef,05,d2,7f,2d,79,70,2d,d2,74,7f,0b,80,bb,4d,d0,aa,a2,d7,\
"rkeysecu"=hex:59,1f,72,b8,97,96,b9,1c,00,e1,86,eb,2d,c3,dd,2a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\taskhost.exe
c:\program files\IObit\Advanced SystemCare 6\Monitor.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Steam\SteamService.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2013-09-27 22:57:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-27 20:57
.
Před spuštěním: Volných bajtů: 23 398 027 264
Po spuštění: Volných bajtů: 23 187 648 512
.
- - End Of File - - E548BB69A2E9E2F1617E529CDDFEB578
A36C5E4F47E84449FF07ED3517B43A31
CPU: Intel Core i5 10400F 2,9GHz
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
OP: 16GB Kingston 2666MHz
GFX: ASUS Dual Radeon RX 7600 V2 OC Edition, 8GB GDDR6
MB: GIGABYTE B460M DS3H - Intel B460
HDD: Seagate Barracuda 7200.14 1TB
SSD: Samsung 860 EVO 500GB
Zdroj: CHIEFTEC zdroj GPS-600A8 600W
Case: Evolveo Ray 4
OS: Windows 10 64bit
Chladič: Arctic Cooling Freezer 7 Pro Rev.2
Kdo je online
Uživatelé prohlížející si toto fórum: Google [Bot] a 97 hostů