prosim o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

prosim o kontrolu logu

Příspěvekod Djubik » 24 zář 2013 21:01

po par minutach pouzivani PC mi prestanou fungovat USBcka,byla mi doporucena kontrola logu tak tady je
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:58:56, on 24.9.2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.185\deploy\LoLLauncher.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

--
End of file - 3046 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod jaro3 » 25 zář 2013 10:01

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod Djubik » 25 zář 2013 17:17

ADW Cleaner log:
# AdwCleaner v3.005 - Report created 25/09/2013 at 17:09:24
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Home Premium (32 bits)
# Username : Jakub - JAKUB-PC
# Running from : C:\Users\Jakub\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.16385


-\\ Google Chrome v

[ File : C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [733 octets] - [25/09/2013 17:05:56]
AdwCleaner[R1].txt - [654 octets] - [25/09/2013 17:09:24]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [713 octets] ##########

Malware bytes log:
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.09.25.04

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Jakub :: JAKUB-PC [administrátor]

Ochrana: Povolena

25.9.2013 17:12:44
mbam-log-2013-09-25 (17-12-44).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 177979
Uplynulý čas: 2 minut, 18 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod memphisto » 25 zář 2013 17:28

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Stáhni si Junkware Removal Tool

na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod Djubik » 25 zář 2013 17:43

RogueKiller V8.6.12 [Sep 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7600 ) 32 bits version
Spuštěno v : Normální režim
Uživatel : Jakub [Práva správce]
Mód : Kontrola -- Datum : 09/25/2013 17:39:11
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 2 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - ST1000DM003-1CH162 ATA Device +++++
--- User ---
[MBR] 23bddaf098b58d0d345252ec54f44549
[BSP] 27f602a16b5048109c68c994a19a366a : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_09252013_173911.txt >>



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.2 (09.22.2013:1)
OS: Windows 7 Home Premium x86
Ran by Jakub on st 25.09.2013 at 17:40:29,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 25.09.2013 at 17:41:42,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod jaro3 » 25 zář 2013 20:01

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.

Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod Djubik » 25 zář 2013 22:08

rogue killer:
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 4 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - ST1000DM003-1CH162 ATA Device +++++
--- User ---
[MBR] 23bddaf098b58d0d345252ec54f44549
[BSP] 27f602a16b5048109c68c994a19a366a : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_09252013_220405.txt >>
RKreport[0]_S_09252013_173911.txt;RKreport[0]_S_09252013_220353.txt

TDSSKiller:
22:05:21.0451 3224 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:05:21.0794 3224 ============================================================
22:05:21.0794 3224 Current date / time: 2013/09/25 22:05:21.0794
22:05:21.0794 3224 SystemInfo:
22:05:21.0794 3224
22:05:21.0794 3224 OS Version: 6.1.7600 ServicePack: 0.0
22:05:21.0794 3224 Product type: Workstation
22:05:21.0794 3224 ComputerName: JAKUB-PC
22:05:21.0794 3224 UserName: Jakub
22:05:21.0794 3224 Windows directory: C:\Windows
22:05:21.0794 3224 System windows directory: C:\Windows
22:05:21.0794 3224 Processor architecture: Intel x86
22:05:21.0794 3224 Number of processors: 4
22:05:21.0794 3224 Page size: 0x1000
22:05:21.0794 3224 Boot type: Normal boot
22:05:21.0794 3224 ============================================================
22:05:23.0339 3224 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:05:23.0354 3224 ============================================================
22:05:23.0354 3224 \Device\Harddisk0\DR0:
22:05:23.0354 3224 MBR partitions:
22:05:23.0354 3224 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:05:23.0354 3224 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
22:05:23.0354 3224 ============================================================
22:05:23.0370 3224 C: <-> \Device\Harddisk0\DR0\Partition2
22:05:23.0370 3224 ============================================================
22:05:23.0370 3224 Initialize success
22:05:23.0370 3224 ============================================================
22:05:26.0115 1408 ============================================================
22:05:26.0115 1408 Scan started
22:05:26.0115 1408 Mode: Manual;
22:05:26.0115 1408 ============================================================
22:05:27.0129 1408 ================ Scan system memory ========================
22:05:27.0129 1408 System memory - ok
22:05:27.0129 1408 ================ Scan services =============================
22:05:27.0379 1408 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
22:05:27.0379 1408 1394ohci - ok
22:05:27.0395 1408 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
22:05:27.0395 1408 ACPI - ok
22:05:27.0395 1408 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
22:05:27.0395 1408 AcpiPmi - ok
22:05:27.0410 1408 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
22:05:27.0410 1408 adp94xx - ok
22:05:27.0426 1408 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
22:05:27.0426 1408 adpahci - ok
22:05:27.0426 1408 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
22:05:27.0426 1408 adpu320 - ok
22:05:27.0441 1408 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:05:27.0441 1408 AeLookupSvc - ok
22:05:27.0457 1408 [ DDC040FDB01EF1712A6B13E52AFB104C ] AFD C:\Windows\system32\drivers\afd.sys
22:05:27.0457 1408 AFD - ok
22:05:27.0457 1408 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
22:05:27.0457 1408 agp440 - ok
22:05:27.0473 1408 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
22:05:27.0473 1408 aic78xx - ok
22:05:27.0504 1408 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
22:05:27.0519 1408 ALG - ok
22:05:27.0519 1408 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
22:05:27.0519 1408 aliide - ok
22:05:27.0582 1408 [ F57EEBDDD89FF5469188461374CCA16F ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
22:05:27.0582 1408 AMD External Events Utility - ok
22:05:27.0660 1408 AMD FUEL Service - ok
22:05:27.0675 1408 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
22:05:27.0675 1408 amdagp - ok
22:05:27.0691 1408 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
22:05:27.0691 1408 amdide - ok
22:05:27.0691 1408 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:05:27.0707 1408 AmdK8 - ok
22:05:27.0816 1408 [ A05EC940EA938C5E7E6CBAC21B221CCA ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
22:05:27.0863 1408 amdkmdag - ok
22:05:27.0894 1408 [ 4EC044DA30CE8395B7813296EBFE4477 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
22:05:27.0894 1408 amdkmdap - ok
22:05:27.0909 1408 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
22:05:27.0909 1408 AmdPPM - ok
22:05:27.0909 1408 [ 2101A86C25C154F8314B24EF49D7FBC2 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
22:05:27.0909 1408 amdsata - ok
22:05:27.0909 1408 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
22:05:27.0909 1408 amdsbs - ok
22:05:27.0925 1408 [ B81C2B5616F6420A9941EA093A92B150 ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
22:05:27.0925 1408 amdxata - ok
22:05:27.0941 1408 [ 66F4DE5876DC1A47BA1ACE909FA9AEEF ] AODDriver4.2 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys
22:05:27.0941 1408 AODDriver4.2 - ok
22:05:27.0941 1408 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
22:05:27.0941 1408 AppID - ok
22:05:27.0972 1408 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:05:27.0972 1408 AppIDSvc - ok
22:05:27.0972 1408 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
22:05:27.0972 1408 Appinfo - ok
22:05:27.0972 1408 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
22:05:27.0987 1408 arc - ok
22:05:27.0987 1408 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
22:05:27.0987 1408 arcsas - ok
22:05:28.0003 1408 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:05:28.0003 1408 AsyncMac - ok
22:05:28.0003 1408 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
22:05:28.0003 1408 atapi - ok
22:05:28.0081 1408 [ 14F8D278988BC02B9B4BF202B5BB1115 ] athur C:\Windows\system32\DRIVERS\athur.sys
22:05:28.0112 1408 athur - ok
22:05:28.0143 1408 [ 9E65DC266E8289116790599DD7D69087 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
22:05:28.0143 1408 AtiHDAudioService - ok
22:05:28.0175 1408 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:05:28.0175 1408 AudioEndpointBuilder - ok
22:05:28.0175 1408 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
22:05:28.0175 1408 Audiosrv - ok
22:05:28.0190 1408 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:05:28.0190 1408 AxInstSV - ok
22:05:28.0221 1408 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
22:05:28.0221 1408 b06bdrv - ok
22:05:28.0221 1408 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
22:05:28.0221 1408 b57nd60x - ok
22:05:28.0237 1408 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
22:05:28.0237 1408 BDESVC - ok
22:05:28.0253 1408 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
22:05:28.0253 1408 Beep - ok
22:05:28.0268 1408 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
22:05:28.0268 1408 BFE - ok
22:05:28.0299 1408 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\System32\qmgr.dll
22:05:28.0299 1408 BITS - ok
22:05:28.0299 1408 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:05:28.0299 1408 blbdrive - ok
22:05:28.0315 1408 [ FCAFAEF6798D7B51FF029F99A9898961 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:05:28.0315 1408 bowser - ok
22:05:28.0315 1408 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:05:28.0315 1408 BrFiltLo - ok
22:05:28.0315 1408 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:05:28.0315 1408 BrFiltUp - ok
22:05:28.0331 1408 [ 598E1280E7FF3744F4B8329366CC5635 ] Browser C:\Windows\System32\browser.dll
22:05:28.0331 1408 Browser - ok
22:05:28.0346 1408 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:05:28.0346 1408 Brserid - ok
22:05:28.0346 1408 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:05:28.0346 1408 BrSerWdm - ok
22:05:28.0346 1408 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:05:28.0346 1408 BrUsbMdm - ok
22:05:28.0362 1408 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:05:28.0362 1408 BrUsbSer - ok
22:05:28.0362 1408 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
22:05:28.0362 1408 BTHMODEM - ok
22:05:28.0377 1408 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
22:05:28.0377 1408 bthserv - ok
22:05:28.0377 1408 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:05:28.0377 1408 cdfs - ok
22:05:28.0377 1408 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:05:28.0377 1408 cdrom - ok
22:05:28.0409 1408 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
22:05:28.0409 1408 CertPropSvc - ok
22:05:28.0409 1408 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
22:05:28.0409 1408 circlass - ok
22:05:28.0424 1408 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
22:05:28.0424 1408 CLFS - ok
22:05:28.0518 1408 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:05:28.0518 1408 clr_optimization_v2.0.50727_32 - ok
22:05:28.0533 1408 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:05:28.0533 1408 CmBatt - ok
22:05:28.0533 1408 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
22:05:28.0533 1408 cmdide - ok
22:05:28.0549 1408 [ 1B675691ED940766149C93E8F4488D68 ] CNG C:\Windows\system32\Drivers\cng.sys
22:05:28.0549 1408 CNG - ok
22:05:28.0549 1408 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:05:28.0565 1408 Compbatt - ok
22:05:28.0565 1408 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
22:05:28.0565 1408 CompositeBus - ok
22:05:28.0565 1408 COMSysApp - ok
22:05:28.0611 1408 cpuz135 - ok
22:05:28.0627 1408 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
22:05:28.0627 1408 crcdisk - ok
22:05:28.0658 1408 [ 9C231178CE4FB385F4B54B0A9080B8A4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:05:28.0658 1408 CryptSvc - ok
22:05:28.0689 1408 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
22:05:28.0705 1408 DcomLaunch - ok
22:05:28.0736 1408 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
22:05:28.0736 1408 defragsvc - ok
22:05:28.0752 1408 [ 8E09E52EE2E3CEB199EF3DD99CF9E3FB ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:05:28.0752 1408 DfsC - ok
22:05:28.0767 1408 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
22:05:28.0783 1408 Dhcp - ok
22:05:28.0783 1408 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
22:05:28.0783 1408 discache - ok
22:05:28.0799 1408 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
22:05:28.0799 1408 Disk - ok
22:05:28.0814 1408 [ D0722E963D3C6145446874241401B209 ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:05:28.0830 1408 Dnscache - ok
22:05:28.0830 1408 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
22:05:28.0830 1408 dot3svc - ok
22:05:28.0830 1408 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
22:05:28.0845 1408 DPS - ok
22:05:28.0877 1408 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:05:28.0877 1408 drmkaud - ok
22:05:28.0892 1408 [ 39806CFEDDCC55E686A49BCCD2972F23 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:05:28.0908 1408 DXGKrnl - ok
22:05:28.0923 1408 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
22:05:28.0939 1408 EapHost - ok
22:05:29.0001 1408 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
22:05:29.0017 1408 ebdrv - ok
22:05:29.0033 1408 [ F42309C4191C506B71DB5D1126D26318 ] EFS C:\Windows\System32\lsass.exe
22:05:29.0033 1408 EFS - ok
22:05:29.0142 1408 [ 3A74A6E33685662B125A3269B1F2114F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:05:29.0142 1408 ehRecvr - ok
22:05:29.0157 1408 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
22:05:29.0173 1408 ehSched - ok
22:05:29.0189 1408 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
22:05:29.0204 1408 elxstor - ok
22:05:29.0204 1408 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
22:05:29.0204 1408 ErrDev - ok
22:05:29.0235 1408 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
22:05:29.0235 1408 EventSystem - ok
22:05:29.0251 1408 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
22:05:29.0251 1408 exfat - ok
22:05:29.0251 1408 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:05:29.0251 1408 fastfat - ok
22:05:29.0282 1408 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
22:05:29.0282 1408 Fax - ok
22:05:29.0282 1408 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:05:29.0282 1408 fdc - ok
22:05:29.0298 1408 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
22:05:29.0298 1408 fdPHost - ok
22:05:29.0329 1408 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
22:05:29.0329 1408 FDResPub - ok
22:05:29.0329 1408 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:05:29.0345 1408 FileInfo - ok
22:05:29.0345 1408 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:05:29.0345 1408 Filetrace - ok
22:05:29.0360 1408 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:05:29.0360 1408 flpydisk - ok
22:05:29.0360 1408 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:05:29.0360 1408 FltMgr - ok
22:05:29.0376 1408 [ B6512A85815FDC3D560C3705F5BDB93D ] FontCache C:\Windows\system32\FntCache.dll
22:05:29.0391 1408 FontCache - ok
22:05:29.0423 1408 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:05:29.0423 1408 FontCache3.0.0.0 - ok
22:05:29.0423 1408 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:05:29.0423 1408 FsDepends - ok
22:05:29.0423 1408 [ A574B4360E438977038AAE4BF60D79A2 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:05:29.0423 1408 Fs_Rec - ok
22:05:29.0438 1408 [ 5592F5DBA26282D24D2B080EB438A4D7 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:05:29.0438 1408 fvevol - ok
22:05:29.0454 1408 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
22:05:29.0454 1408 gagp30kx - ok
22:05:29.0485 1408 getbus - ok
22:05:29.0516 1408 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
22:05:29.0532 1408 gpsvc - ok
22:05:29.0547 1408 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:05:29.0547 1408 hcw85cir - ok
22:05:29.0563 1408 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:05:29.0563 1408 HdAudAddService - ok
22:05:29.0579 1408 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:05:29.0579 1408 HDAudBus - ok
22:05:29.0579 1408 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
22:05:29.0579 1408 HidBatt - ok
22:05:29.0594 1408 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
22:05:29.0594 1408 HidBth - ok
22:05:29.0594 1408 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
22:05:29.0594 1408 HidIr - ok
22:05:29.0610 1408 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
22:05:29.0610 1408 hidserv - ok
22:05:29.0610 1408 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:05:29.0610 1408 HidUsb - ok
22:05:29.0625 1408 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:05:29.0625 1408 hkmsvc - ok
22:05:29.0641 1408 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:05:29.0641 1408 HomeGroupListener - ok
22:05:29.0657 1408 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:05:29.0657 1408 HomeGroupProvider - ok
22:05:29.0657 1408 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
22:05:29.0657 1408 HpSAMD - ok
22:05:29.0657 1408 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:05:29.0672 1408 HTTP - ok
22:05:29.0672 1408 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:05:29.0672 1408 hwpolicy - ok
22:05:29.0672 1408 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:05:29.0672 1408 i8042prt - ok
22:05:29.0688 1408 [ 934AF4D7C5F457B9F0743F4299B77B67 ] iaStorV C:\Windows\system32\DRIVERS\iaStorV.sys
22:05:29.0688 1408 iaStorV - ok
22:05:29.0735 1408 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:05:29.0750 1408 idsvc - ok
22:05:29.0766 1408 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
22:05:29.0766 1408 iirsp - ok
22:05:29.0781 1408 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
22:05:29.0797 1408 IKEEXT - ok
22:05:29.0797 1408 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
22:05:29.0797 1408 intelide - ok
22:05:29.0797 1408 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:05:29.0813 1408 intelppm - ok
22:05:29.0813 1408 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:05:29.0813 1408 IPBusEnum - ok
22:05:29.0813 1408 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:05:29.0813 1408 IpFilterDriver - ok
22:05:29.0828 1408 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:05:29.0844 1408 iphlpsvc - ok
22:05:29.0859 1408 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:05:29.0859 1408 IPMIDRV - ok
22:05:29.0859 1408 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:05:29.0859 1408 IPNAT - ok
22:05:29.0859 1408 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:05:29.0859 1408 IRENUM - ok
22:05:29.0859 1408 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
22:05:29.0859 1408 isapnp - ok
22:05:29.0875 1408 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
22:05:29.0875 1408 iScsiPrt - ok
22:05:29.0875 1408 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:05:29.0875 1408 kbdclass - ok
22:05:29.0891 1408 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:05:29.0891 1408 kbdhid - ok
22:05:29.0891 1408 [ F42309C4191C506B71DB5D1126D26318 ] KeyIso C:\Windows\system32\lsass.exe
22:05:29.0891 1408 KeyIso - ok
22:05:29.0922 1408 [ E36A061EC11B373826905B21BE10948F ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:05:29.0922 1408 KSecDD - ok
22:05:29.0922 1408 [ 26C046977E85B95036453D7B88BA1820 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:05:29.0922 1408 KSecPkg - ok
22:05:29.0937 1408 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
22:05:29.0937 1408 KtmRm - ok
22:05:29.0969 1408 [ 6C32BFEAB708915D6BBF4B20D4F3EF7B ] L1C C:\Windows\system32\DRIVERS\L1C62x86.sys
22:05:29.0969 1408 L1C - ok
22:05:29.0984 1408 [ BCA92CB047A4326925ECEF759DBAA233 ] LanmanServer C:\Windows\system32\srvsvc.dll
22:05:29.0984 1408 LanmanServer - ok
22:05:30.0000 1408 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:05:30.0000 1408 LanmanWorkstation - ok
22:05:30.0015 1408 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:05:30.0015 1408 lltdio - ok
22:05:30.0031 1408 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:05:30.0031 1408 lltdsvc - ok
22:05:30.0031 1408 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
22:05:30.0031 1408 lmhosts - ok
22:05:30.0031 1408 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
22:05:30.0047 1408 LSI_FC - ok
22:05:30.0047 1408 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
22:05:30.0047 1408 LSI_SAS - ok
22:05:30.0047 1408 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:05:30.0047 1408 LSI_SAS2 - ok
22:05:30.0047 1408 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:05:30.0047 1408 LSI_SCSI - ok
22:05:30.0047 1408 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
22:05:30.0047 1408 luafv - ok
22:05:30.0093 1408 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
22:05:30.0093 1408 MBAMProtector - ok
22:05:30.0140 1408 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
22:05:30.0140 1408 MBAMScheduler - ok
22:05:30.0156 1408 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
22:05:30.0156 1408 MBAMService - ok
22:05:30.0171 1408 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:05:30.0171 1408 Mcx2Svc - ok
22:05:30.0187 1408 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
22:05:30.0187 1408 megasas - ok
22:05:30.0187 1408 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
22:05:30.0187 1408 MegaSR - ok
22:05:30.0187 1408 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
22:05:30.0203 1408 MMCSS - ok
22:05:30.0203 1408 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
22:05:30.0203 1408 Modem - ok
22:05:30.0203 1408 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:05:30.0203 1408 monitor - ok
22:05:30.0203 1408 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:05:30.0203 1408 mouclass - ok
22:05:30.0218 1408 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:05:30.0218 1408 mouhid - ok
22:05:30.0218 1408 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:05:30.0218 1408 mountmgr - ok
22:05:30.0218 1408 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
22:05:30.0218 1408 mpio - ok
22:05:30.0218 1408 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:05:30.0218 1408 mpsdrv - ok
22:05:30.0249 1408 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
22:05:30.0249 1408 MpsSvc - ok
22:05:30.0249 1408 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:05:30.0249 1408 MRxDAV - ok
22:05:30.0265 1408 [ F4A054BE78AF7F410129C4B64B07DC9B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:05:30.0265 1408 mrxsmb - ok
22:05:30.0265 1408 [ DEFFA295BD1895C6ED8E3078412AC60B ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:05:30.0265 1408 mrxsmb10 - ok
22:05:30.0281 1408 [ 24D76ABE5DCAD22F19D105F76FDF0CE1 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:05:30.0281 1408 mrxsmb20 - ok
22:05:30.0281 1408 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
22:05:30.0281 1408 msahci - ok
22:05:30.0281 1408 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
22:05:30.0281 1408 msdsm - ok
22:05:30.0296 1408 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
22:05:30.0296 1408 MSDTC - ok
22:05:30.0296 1408 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:05:30.0296 1408 Msfs - ok
22:05:30.0296 1408 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:05:30.0296 1408 mshidkmdf - ok
22:05:30.0312 1408 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
22:05:30.0312 1408 msisadrv - ok
22:05:30.0312 1408 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:05:30.0312 1408 MSiSCSI - ok
22:05:30.0327 1408 msiserver - ok
22:05:30.0327 1408 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:05:30.0327 1408 MSKSSRV - ok
22:05:30.0327 1408 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:05:30.0327 1408 MSPCLOCK - ok
22:05:30.0343 1408 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:05:30.0343 1408 MSPQM - ok
22:05:30.0343 1408 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:05:30.0343 1408 MsRPC - ok
22:05:30.0343 1408 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
22:05:30.0343 1408 mssmbios - ok
22:05:30.0343 1408 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:05:30.0343 1408 MSTEE - ok
22:05:30.0359 1408 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
22:05:30.0359 1408 MTConfig - ok
22:05:30.0359 1408 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
22:05:30.0359 1408 Mup - ok
22:05:30.0374 1408 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
22:05:30.0374 1408 napagent - ok
22:05:30.0390 1408 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:05:30.0390 1408 NativeWifiP - ok
22:05:30.0405 1408 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:05:30.0405 1408 NDIS - ok
22:05:30.0405 1408 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:05:30.0405 1408 NdisCap - ok
22:05:30.0405 1408 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:05:30.0421 1408 NdisTapi - ok
22:05:30.0421 1408 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:05:30.0421 1408 Ndisuio - ok
22:05:30.0421 1408 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:05:30.0421 1408 NdisWan - ok
22:05:30.0421 1408 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:05:30.0421 1408 NDProxy - ok
22:05:30.0421 1408 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:05:30.0421 1408 NetBIOS - ok
22:05:30.0437 1408 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:05:30.0437 1408 NetBT - ok
22:05:30.0437 1408 [ F42309C4191C506B71DB5D1126D26318 ] Netlogon C:\Windows\system32\lsass.exe
22:05:30.0452 1408 Netlogon - ok
22:05:30.0468 1408 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
22:05:30.0468 1408 Netman - ok
22:05:30.0468 1408 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
22:05:30.0468 1408 netprofm - ok
22:05:30.0499 1408 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:05:30.0499 1408 NetTcpPortSharing - ok
22:05:30.0499 1408 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
22:05:30.0499 1408 nfrd960 - ok
22:05:30.0515 1408 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
22:05:30.0515 1408 NlaSvc - ok
22:05:30.0515 1408 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:05:30.0515 1408 Npfs - ok
22:05:30.0530 1408 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
22:05:30.0530 1408 nsi - ok
22:05:30.0530 1408 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:05:30.0530 1408 nsiproxy - ok
22:05:30.0546 1408 [ 3795DCD21F740EE799FB7223234215AF ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:05:30.0546 1408 Ntfs - ok
22:05:30.0561 1408 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
22:05:30.0561 1408 Null - ok
22:05:30.0561 1408 [ 3F3D04B1D08D43C16EA7963954EC768D ] nvraid C:\Windows\system32\DRIVERS\nvraid.sys
22:05:30.0561 1408 nvraid - ok
22:05:30.0577 1408 [ C99F251A5DE63C6F129CF71933ACED0F ] nvstor C:\Windows\system32\DRIVERS\nvstor.sys
22:05:30.0577 1408 nvstor - ok
22:05:30.0577 1408 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
22:05:30.0577 1408 nv_agp - ok
22:05:30.0577 1408 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
22:05:30.0577 1408 ohci1394 - ok
22:05:30.0593 1408 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:05:30.0593 1408 p2pimsvc - ok
22:05:30.0608 1408 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
22:05:30.0608 1408 p2psvc - ok
22:05:30.0608 1408 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
22:05:30.0608 1408 Parport - ok
22:05:30.0608 1408 [ FF4218952B51DE44FE910953A3E686B9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:05:30.0608 1408 partmgr - ok
22:05:30.0624 1408 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
22:05:30.0624 1408 Parvdm - ok
22:05:30.0624 1408 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
22:05:30.0624 1408 PcaSvc - ok
22:05:30.0624 1408 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
22:05:30.0624 1408 pci - ok
22:05:30.0639 1408 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
22:05:30.0639 1408 pciide - ok
22:05:30.0639 1408 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
22:05:30.0639 1408 pcmcia - ok
22:05:30.0639 1408 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
22:05:30.0639 1408 pcw - ok
22:05:30.0655 1408 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:05:30.0655 1408 PEAUTH - ok
22:05:30.0686 1408 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
22:05:30.0686 1408 pla - ok
22:05:30.0702 1408 [ 2CC2008F1296968FBA162ED9F9AFE328 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:05:30.0717 1408 PlugPlay - ok
22:05:30.0717 1408 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:05:30.0717 1408 PNRPAutoReg - ok
22:05:30.0733 1408 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:05:30.0733 1408 PNRPsvc - ok
22:05:30.0749 1408 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:05:30.0749 1408 PolicyAgent - ok
22:05:30.0764 1408 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
22:05:30.0764 1408 Power - ok
22:05:30.0764 1408 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:05:30.0764 1408 PptpMiniport - ok
22:05:30.0764 1408 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
22:05:30.0764 1408 Processor - ok
22:05:30.0780 1408 [ 630CF26F0227498B7D5A92B12548960F ] ProfSvc C:\Windows\system32\profsvc.dll
22:05:30.0780 1408 ProfSvc - ok
22:05:30.0795 1408 [ F42309C4191C506B71DB5D1126D26318 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:05:30.0795 1408 ProtectedStorage - ok
22:05:30.0811 1408 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:05:30.0811 1408 Psched - ok
22:05:30.0827 1408 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
22:05:30.0827 1408 ql2300 - ok
22:05:30.0842 1408 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
22:05:30.0842 1408 ql40xx - ok
22:05:30.0842 1408 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
22:05:30.0842 1408 QWAVE - ok
22:05:30.0858 1408 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:05:30.0858 1408 QWAVEdrv - ok
22:05:30.0858 1408 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:05:30.0858 1408 RasAcd - ok
22:05:30.0858 1408 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:05:30.0858 1408 RasAgileVpn - ok
22:05:30.0873 1408 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
22:05:30.0873 1408 RasAuto - ok
22:05:30.0873 1408 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:05:30.0873 1408 Rasl2tp - ok
22:05:30.0905 1408 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
22:05:30.0905 1408 RasMan - ok
22:05:30.0905 1408 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:05:30.0905 1408 RasPppoe - ok
22:05:30.0905 1408 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:05:30.0905 1408 RasSstp - ok
22:05:30.0920 1408 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:05:30.0920 1408 rdbss - ok
22:05:30.0920 1408 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
22:05:30.0920 1408 rdpbus - ok
22:05:30.0920 1408 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:05:30.0920 1408 RDPCDD - ok
22:05:30.0920 1408 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:05:30.0920 1408 RDPENCDD - ok
22:05:30.0936 1408 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:05:30.0936 1408 RDPREFMP - ok
22:05:30.0936 1408 [ 801371BA9782282892D00AADB08EE367 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:05:30.0936 1408 RDPWD - ok
22:05:30.0951 1408 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:05:30.0951 1408 rdyboost - ok
22:05:30.0967 1408 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
22:05:30.0967 1408 RemoteAccess - ok
22:05:30.0983 1408 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:05:30.0983 1408 RemoteRegistry - ok
22:05:30.0998 1408 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:05:30.0998 1408 RpcEptMapper - ok
22:05:31.0014 1408 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
22:05:31.0014 1408 RpcLocator - ok
22:05:31.0029 1408 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
22:05:31.0029 1408 RpcSs - ok
22:05:31.0029 1408 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:05:31.0029 1408 rspndr - ok
22:05:31.0045 1408 [ F42309C4191C506B71DB5D1126D26318 ] SamSs C:\Windows\system32\lsass.exe
22:05:31.0045 1408 SamSs - ok
22:05:31.0061 1408 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
22:05:31.0061 1408 sbp2port - ok
22:05:31.0076 1408 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:05:31.0076 1408 SCardSvr - ok
22:05:31.0076 1408 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:05:31.0076 1408 scfilter - ok
22:05:31.0092 1408 [ 3E8B0C453E25613A1F59762A5C42AA75 ] Schedule C:\Windows\system32\schedsvc.dll
22:05:31.0092 1408 Schedule - ok
22:05:31.0107 1408 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
22:05:31.0107 1408 SCPolicySvc - ok
22:05:31.0123 1408 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:05:31.0123 1408 SDRSVC - ok
22:05:31.0123 1408 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:05:31.0123 1408 secdrv - ok
22:05:31.0123 1408 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
22:05:31.0139 1408 seclogon - ok
22:05:31.0139 1408 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
22:05:31.0139 1408 SENS - ok
22:05:31.0139 1408 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:05:31.0139 1408 SensrSvc - ok
22:05:31.0154 1408 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
22:05:31.0154 1408 Serenum - ok
22:05:31.0154 1408 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
22:05:31.0154 1408 Serial - ok
22:05:31.0154 1408 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
22:05:31.0154 1408 sermouse - ok
22:05:31.0170 1408 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
22:05:31.0170 1408 SessionEnv - ok
22:05:31.0185 1408 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
22:05:31.0185 1408 sffdisk - ok
22:05:31.0185 1408 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:05:31.0185 1408 sffp_mmc - ok
22:05:31.0185 1408 [ 4F1E5B0FE7C8050668DBFADE8999AEFB ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
22:05:31.0185 1408 sffp_sd - ok
22:05:31.0185 1408 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
22:05:31.0185 1408 sfloppy - ok
22:05:31.0201 1408 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:05:31.0201 1408 SharedAccess - ok
22:05:31.0217 1408 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:05:31.0217 1408 ShellHWDetection - ok
22:05:31.0217 1408 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
22:05:31.0217 1408 sisagp - ok
22:05:31.0232 1408 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:05:31.0232 1408 SiSRaid2 - ok
22:05:31.0232 1408 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
22:05:31.0232 1408 SiSRaid4 - ok
22:05:31.0232 1408 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:05:31.0232 1408 Smb - ok
22:05:31.0248 1408 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:05:31.0248 1408 SNMPTRAP - ok
22:05:31.0248 1408 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
22:05:31.0248 1408 spldr - ok
22:05:31.0263 1408 [ 49B6DD6AB3715B7A67965F17194E98A9 ] Spooler C:\Windows\System32\spoolsv.exe
22:05:31.0263 1408 Spooler - ok
22:05:31.0341 1408 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
22:05:31.0357 1408 sppsvc - ok
22:05:31.0373 1408 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:05:31.0373 1408 sppuinotify - ok
22:05:31.0388 1408 [ 2BA4EBC7DFBA845A1EDBE1F75913BE33 ] srv C:\Windows\system32\DRIVERS\srv.sys
22:05:31.0388 1408 srv - ok
22:05:31.0388 1408 [ DCE7E10FEAABD4CAE95948B3DE5340BB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:05:31.0388 1408 srv2 - ok
22:05:31.0404 1408 [ B5665BAA2120B8A54E22E9CD07C05106 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:05:31.0404 1408 srvnet - ok
22:05:31.0404 1408 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:05:31.0404 1408 SSDPSRV - ok
22:05:31.0404 1408 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:05:31.0419 1408 SstpSvc - ok
22:05:31.0419 1408 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
22:05:31.0419 1408 stexstor - ok
22:05:31.0435 1408 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
22:05:31.0435 1408 StiSvc - ok
22:05:31.0435 1408 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
22:05:31.0435 1408 swenum - ok
22:05:31.0451 1408 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
22:05:31.0451 1408 swprv - ok
22:05:31.0466 1408 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
22:05:31.0482 1408 SysMain - ok
22:05:31.0497 1408 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:05:31.0497 1408 TabletInputService - ok
22:05:31.0513 1408 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
22:05:31.0513 1408 TapiSrv - ok
22:05:31.0513 1408 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
22:05:31.0513 1408 TBS - ok
22:05:31.0529 1408 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:05:31.0544 1408 Tcpip - ok
22:05:31.0560 1408 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:05:31.0560 1408 TCPIP6 - ok
22:05:31.0575 1408 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:05:31.0575 1408 tcpipreg - ok
22:05:31.0575 1408 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:05:31.0575 1408 TDPIPE - ok
22:05:31.0575 1408 [ 7551E91EA999EE9A8E9C331D5A9C31F3 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:05:31.0575 1408 TDTCP - ok
22:05:31.0591 1408 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:05:31.0591 1408 tdx - ok
22:05:31.0591 1408 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
22:05:31.0591 1408 TermDD - ok
22:05:31.0607 1408 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\Windows\System32\termsrv.dll
22:05:31.0622 1408 TermService - ok
22:05:31.0622 1408 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
22:05:31.0638 1408 Themes - ok
22:05:31.0638 1408 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
22:05:31.0638 1408 THREADORDER - ok
22:05:31.0653 1408 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
22:05:31.0653 1408 TrkWks - ok
22:05:31.0685 1408 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:05:31.0700 1408 TrustedInstaller - ok
22:05:31.0700 1408 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:05:31.0700 1408 tssecsrv - ok
22:05:31.0716 1408 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:05:31.0716 1408 tunnel - ok
22:05:31.0716 1408 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
22:05:31.0716 1408 uagp35 - ok
22:05:31.0716 1408 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:05:31.0716 1408 udfs - ok
22:05:31.0731 1408 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:05:31.0731 1408 UI0Detect - ok
22:05:31.0747 1408 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
22:05:31.0747 1408 uliagpkx - ok
22:05:31.0747 1408 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
22:05:31.0747 1408 umbus - ok
22:05:31.0763 1408 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
22:05:31.0763 1408 UmPass - ok
22:05:31.0778 1408 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
22:05:31.0778 1408 upnphost - ok
22:05:31.0778 1408 [ 8455C4ED038EFD09E99327F9D2D48FFA ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:05:31.0778 1408 usbccgp - ok
22:05:31.0778 1408 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
22:05:31.0778 1408 usbcir - ok
22:05:31.0778 1408 [ 1C333BFD60F2FED2C7AD5DAF533CB742 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:05:31.0778 1408 usbehci - ok
22:05:31.0794 1408 [ EE6EF93CCFA94FAE8C6AB298273D8AE2 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:05:31.0794 1408 usbhub - ok
22:05:31.0794 1408 [ A6FB7957EA7AFB1165991E54CE934B74 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
22:05:31.0809 1408 usbohci - ok
22:05:31.0809 1408 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:05:31.0809 1408 usbprint - ok
22:05:31.0809 1408 [ D8889D56E0D27E57ED4591837FE71D27 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:05:31.0809 1408 USBSTOR - ok
22:05:31.0809 1408 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
22:05:31.0809 1408 usbuhci - ok
22:05:31.0825 1408 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
22:05:31.0825 1408 UxSms - ok
22:05:31.0841 1408 [ F42309C4191C506B71DB5D1126D26318 ] VaultSvc C:\Windows\system32\lsass.exe
22:05:31.0841 1408 VaultSvc - ok
22:05:31.0856 1408 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
22:05:31.0856 1408 vdrvroot - ok
22:05:31.0872 1408 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
22:05:31.0872 1408 vds - ok
22:05:31.0872 1408 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:05:31.0887 1408 vga - ok
22:05:31.0887 1408 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
22:05:31.0887 1408 VgaSave - ok
22:05:31.0887 1408 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
22:05:31.0887 1408 vhdmp - ok
22:05:31.0887 1408 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
22:05:31.0887 1408 viaagp - ok
22:05:31.0887 1408 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
22:05:31.0887 1408 ViaC7 - ok
22:05:31.0903 1408 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
22:05:31.0903 1408 viaide - ok
22:05:31.0903 1408 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
22:05:31.0903 1408 volmgr - ok
22:05:31.0903 1408 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:05:31.0903 1408 volmgrx - ok
22:05:31.0919 1408 [ 58DF9D2481A56EDDE167E51B334D44FD ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
22:05:31.0919 1408 volsnap - ok
22:05:31.0919 1408 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
22:05:31.0919 1408 vsmraid - ok
22:05:31.0950 1408 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
22:05:31.0950 1408 VSS - ok
22:05:31.0965 1408 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
22:05:31.0965 1408 vwifibus - ok
22:05:31.0965 1408 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
22:05:31.0965 1408 vwififlt - ok
22:05:31.0965 1408 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
22:05:31.0965 1408 W32Time - ok
22:05:31.0981 1408 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
22:05:31.0981 1408 WacomPen - ok
22:05:31.0981 1408 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:05:31.0981 1408 WANARP - ok
22:05:31.0981 1408 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:05:31.0981 1408 Wanarpv6 - ok
22:05:31.0997 1408 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
22:05:32.0012 1408 wbengine - ok
22:05:32.0012 1408 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:05:32.0028 1408 WbioSrvc - ok
22:05:32.0028 1408 [ D0F88AA11EE1A62BCC6D6A8A7783CA11 ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:05:32.0028 1408 wcncsvc - ok
22:05:32.0028 1408 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:05:32.0028 1408 WcsPlugInService - ok
22:05:32.0043 1408 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
22:05:32.0043 1408 Wd - ok
22:05:32.0043 1408 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:05:32.0043 1408 Wdf01000 - ok
22:05:32.0043 1408 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:05:32.0043 1408 WdiServiceHost - ok
22:05:32.0059 1408 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:05:32.0059 1408 WdiSystemHost - ok
22:05:32.0059 1408 [ D87C7D2C517F82A5AB7A73E203063D9E ] WebClient C:\Windows\System32\webclnt.dll
22:05:32.0059 1408 WebClient - ok
22:05:32.0075 1408 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:05:32.0075 1408 Wecsvc - ok
22:05:32.0075 1408 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:05:32.0090 1408 wercplsupport - ok
22:05:32.0090 1408 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
22:05:32.0090 1408 WerSvc - ok
22:05:32.0090 1408 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:05:32.0090 1408 WfpLwf - ok
22:05:32.0090 1408 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:05:32.0090 1408 WIMMount - ok
22:05:32.0137 1408 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
22:05:32.0137 1408 WinDefend - ok
22:05:32.0153 1408 WinHttpAutoProxySvc - ok
22:05:32.0262 1408 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:05:32.0262 1408 Winmgmt - ok
22:05:32.0293 1408 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
22:05:32.0309 1408 WinRM - ok
22:05:32.0340 1408 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
22:05:32.0340 1408 Wlansvc - ok
22:05:32.0355 1408 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
22:05:32.0355 1408 WmiAcpi - ok
22:05:32.0355 1408 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:05:32.0371 1408 wmiApSrv - ok
22:05:32.0387 1408 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
22:05:32.0387 1408 WMPNetworkSvc - ok
22:05:32.0402 1408 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:05:32.0402 1408 WPCSvc - ok
22:05:32.0402 1408 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:05:32.0418 1408 WPDBusEnum - ok
22:05:32.0418 1408 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:05:32.0418 1408 ws2ifsl - ok
22:05:32.0433 1408 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
22:05:32.0433 1408 wscsvc - ok
22:05:32.0433 1408 WSearch - ok
22:05:32.0465 1408 [ A33408CC036F9C08142B11BE5E93F0A1 ] wuauserv C:\Windows\system32\wuaueng.dll
22:05:32.0465 1408 wuauserv - ok
22:05:32.0480 1408 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:05:32.0480 1408 WudfPf - ok
22:05:32.0496 1408 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:05:32.0496 1408 WUDFRd - ok
22:05:32.0496 1408 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:05:32.0496 1408 wudfsvc - ok
22:05:32.0511 1408 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
22:05:32.0511 1408 WwanSvc - ok
22:05:32.0527 1408 ================ Scan global ===============================
22:05:32.0543 1408 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
22:05:32.0558 1408 [ 827E4F75901CA3F990B1487D3301841E ] C:\Windows\system32\winsrv.dll
22:05:32.0574 1408 [ 827E4F75901CA3F990B1487D3301841E ] C:\Windows\system32\winsrv.dll
22:05:32.0605 1408 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
22:05:32.0621 1408 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
22:05:32.0621 1408 [Global] - ok
22:05:32.0621 1408 ================ Scan MBR ==================================
22:05:32.0636 1408 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:05:32.0886 1408 \Device\Harddisk0\DR0 - ok
22:05:32.0886 1408 ================ Scan VBR ==================================
22:05:32.0886 1408 [ 948E260F0DC71536D4B84E108B8F8C76 ] \Device\Harddisk0\DR0\Partition1
22:05:32.0886 1408 \Device\Harddisk0\DR0\Partition1 - ok
22:05:32.0917 1408 [ 42E82E78DBAC61397760B1DE176B4458 ] \Device\Harddisk0\DR0\Partition2
22:05:32.0917 1408 \Device\Harddisk0\DR0\Partition2 - ok
22:05:32.0917 1408 ============================================================
22:05:32.0917 1408 Scan finished
22:05:32.0917 1408 ============================================================
22:05:32.0917 1788 Detected object count: 0
22:05:32.0917 1788 Actual detected object count: 0

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod jaro3 » 25 zář 2013 22:57

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod Djubik » 25 zář 2013 23:17

ComboFix 13-09-24.02 - Jakub 25.09.2013 23:11:36.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3327.2495 [GMT 2:00]
Spuštěný z: c:\users\Jakub\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-25 do 2013-09-25 )))))))))))))))))))))))))))))))
.
.
2013-09-25 21:13 . 2013-09-25 21:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-25 15:40 . 2013-09-25 15:40 -------- d-----w- c:\windows\ERUNT
2013-09-25 15:11 . 2013-09-25 15:11 -------- d-----w- c:\programdata\Malwarebytes
2013-09-25 15:11 . 2013-09-25 15:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-09-25 15:11 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-25 15:05 . 2013-09-25 15:09 -------- d-----w- C:\AdwCleaner
2013-09-24 18:55 . 2013-09-24 18:55 -------- d-----w- c:\program files\Trend Micro
2013-09-24 16:40 . 2013-09-24 16:40 -------- d-----w- c:\program files\HWiNFO32
2013-09-24 16:29 . 2013-09-24 15:38 -------- d-----w- c:\windows\Panther
2013-09-24 16:12 . 2013-09-24 16:12 -------- d-----w- c:\program files\CCleaner
2013-09-24 16:09 . 2008-07-31 08:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2013-09-24 16:09 . 2008-07-31 08:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2013-09-24 16:09 . 2008-07-12 06:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2013-09-24 16:09 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2013-09-24 16:09 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2013-09-24 16:09 . 2013-09-24 16:09 -------- d-----w- C:\Riot Games
2013-09-24 16:07 . 2013-09-25 09:53 -------- d-----w- c:\programdata\PMB Files
2013-09-24 16:07 . 2013-09-24 16:07 -------- d-----w- c:\program files\Pando Networks
2013-09-24 16:04 . 2013-09-24 16:04 0 ----a-w- c:\windows\ativpsrm.bin
2013-09-24 16:03 . 2013-09-24 16:03 -------- d-----w- c:\program files\AMD AVT
2013-09-24 16:03 . 2013-09-24 16:03 -------- d-----w- c:\program files\Common Files\ATI Technologies
2013-09-24 16:02 . 2013-09-24 16:03 -------- d-----w- c:\programdata\AMD
2013-09-24 16:01 . 2013-09-24 18:55 -------- d-sh--w- c:\windows\Installer
2013-09-24 16:01 . 2013-09-24 16:01 -------- d-----w- c:\program files\ATI
2013-09-24 16:01 . 2013-09-24 16:02 -------- d-----w- c:\program files\ATI Technologies
2013-09-24 16:00 . 2013-09-24 16:00 -------- d-----w- C:\AMD
2013-09-24 15:56 . 2013-09-15 22:50 7328304 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FF642D15-EDC6-42F9-8E63-421165F163F4}\mpengine.dll
2013-09-24 15:56 . 2013-08-07 02:22 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-09-24 15:51 . 2011-04-20 01:06 1570304 ----a-w- c:\windows\system32\drivers\athur.sys
2013-09-24 15:51 . 2011-04-20 01:06 1570304 ----a-w- c:\windows\system32\athur.sys
2013-09-24 15:41 . 2013-09-25 21:13 -------- d-----w- c:\windows\system32\wbem\Performance
2013-09-24 15:40 . 2013-09-24 15:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2013-09-24 15:40 . 2013-09-24 15:40 -------- d-----w- c:\program files\TP-LINK
2013-09-24 15:40 . 2013-09-24 15:40 -------- d-----w- c:\programdata\TP-LINK
2013-09-24 15:38 . 2013-09-24 15:39 -------- d-----w- c:\users\Jakub
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-16 642656]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TP-LINK Wireless Configuration Utility.lnk - c:\program files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [2013-9-24 788992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 cpuz135;cpuz135;c:\users\Jakub\AppData\Local\Temp\cpuz135\cpuz135_x32.sys [x]
R3 getbus;getbus;c:\users\Jakub\AppData\Local\Temp\getbus.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2013-04-16 219136]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-04-16 291840]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2011-04-20 1570304]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-13 50688]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837358304-967544611-1234612887-1000Core.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-24 15:54]
.
2013-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837358304-967544611-1234612887-1000UA.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-24 15:54]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 192.168.0.1
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-09-25 23:14:48
ComboFix-quarantined-files.txt 2013-09-25 21:14
.
Před spuštěním: Volných bajtů: 977 844 973 568
Po spuštění: Volných bajtů: 977 764 581 376
.
- - End Of File - - B09F748152C96A304F4ED1F943FAC8CA
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod jaro3 » 26 zář 2013 09:14

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\users\Jakub\AppData\Local\Temp\getbus.sys

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/

Stáhni si aswMBR
http://files.avast.com/files/rootkit-scanner/aswmbr.exe
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Djubik
Level 2
Level 2
Příspěvky: 156
Registrován: květen 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod Djubik » 26 zář 2013 09:28

soubor getbus.sys v té složce nemám,ani nikde jinde když sem ho dal hledat,a zobrazovani skrytych souboru a složek sem povolil a skrýt chráněne soubory OS sem odšrktnul

tady je log z aswMBR
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-09-26 09:24:58
-----------------------------
09:24:58.542 OS Version: Windows 6.1.7600
09:24:58.542 Number of processors: 4 586 0x403
09:24:58.542 ComputerName: JAKUB-PC UserName: Jakub
09:24:59.571 Initialize success
09:25:16.218 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-7
09:25:16.218 Disk 0 Vendor: ST1000DM003-1CH162 CC47 Size: 953869MB BusType: 3
09:25:16.312 Disk 0 MBR read successfully
09:25:16.312 Disk 0 MBR scan
09:25:16.327 Disk 0 Windows 7 default MBR code
09:25:16.327 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
09:25:16.343 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
09:25:16.358 Disk 0 scanning sectors +1953521664
09:25:16.405 Disk 0 scanning C:\Windows\system32\drivers
09:25:18.199 Service scanning
09:25:24.548 Modules scanning
09:25:28.776 Disk 0 trace - called modules:
09:25:28.792 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
09:25:28.792 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85fba658]
09:25:28.807 3 CLASSPNP.SYS[8bb8159e] -> nt!IofCallDriver -> [0x85a49890]
09:25:28.807 5 ACPI.sys[8b59f3b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-7[0x85194908]
09:25:28.823 Scan finished successfully
09:26:00.522 Disk 0 MBR has been saved successfully to "C:\Users\Jakub\Desktop\MBR.dat"
09:26:00.569 The log file has been saved successfully to "C:\Users\Jakub\Desktop\aswMBR.txt"

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosim o kontrolu logu

Příspěvekod jaro3 » 27 zář 2013 09:09

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

CleaJavaCache::

KillAll::
Collect::
c:\users\Jakub\AppData\Local\Temp\getbus.sys

File::
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837358304-967544611-1234612887-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837358304-967544611-1234612887-1000UA.job

Folder::
c:\users\Jakub\AppData\Local\Google\Update

Driver::
getbus

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 107 hostů