qone8 - nedaří se ho zbavit

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 05 lis 2013 19:33

TDSS rozděluji na dvakrát, nevejde se to sem celý, přesahuje to počet povolených znaků. Díky

19:25:17.0323 5236 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
19:25:19.0975 5236 ============================================================
19:25:19.0975 5236 Current date / time: 2013/11/05 19:25:19.0975
19:25:19.0975 5236 SystemInfo:
19:25:19.0975 5236
19:25:19.0975 5236 OS Version: 6.1.7601 ServicePack: 1.0
19:25:19.0975 5236 Product type: Workstation
19:25:19.0975 5236 ComputerName: PLN-TRANGOS
19:25:19.0975 5236 UserName: PLTrangos
19:25:19.0975 5236 Windows directory: C:\Windows
19:25:19.0975 5236 System windows directory: C:\Windows
19:25:19.0975 5236 Processor architecture: Intel x86
19:25:19.0975 5236 Number of processors: 4
19:25:19.0975 5236 Page size: 0x1000
19:25:19.0975 5236 Boot type: Normal boot
19:25:19.0975 5236 ============================================================
19:25:20.0443 5236 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:25:20.0443 5236 ============================================================
19:25:20.0443 5236 \Device\Harddisk0\DR0:
19:25:20.0458 5236 MBR partitions:
19:25:20.0458 5236 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x178000
19:25:20.0458 5236 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x18C000, BlocksNum 0x252A2000
19:25:20.0458 5236 ============================================================
19:25:20.0474 5236 C: <-> \Device\Harddisk0\DR0\Partition2
19:25:20.0474 5236 ============================================================
19:25:20.0474 5236 Initialize success
19:25:20.0474 5236 ============================================================
19:25:21.0706 0568 ============================================================
19:25:21.0706 0568 Scan started
19:25:21.0706 0568 Mode: Manual;
19:25:21.0706 0568 ============================================================
19:25:22.0439 0568 ================ Scan system memory ========================
19:25:22.0439 0568 System memory - ok
19:25:22.0455 0568 ================ Scan services =============================
19:25:22.0627 0568 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
19:25:22.0627 0568 1394ohci - ok
19:25:22.0658 0568 [ EDC50031D6AB9180B3B3BD1C547C7D0A ] Acceler C:\Windows\system32\DRIVERS\accelern.sys
19:25:22.0658 0568 Acceler - ok
19:25:22.0689 0568 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
19:25:22.0689 0568 ACPI - ok
19:25:22.0705 0568 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
19:25:22.0705 0568 AcpiPmi - ok
19:25:22.0845 0568 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
19:25:22.0845 0568 AdobeARMservice - ok
19:25:22.0923 0568 [ A283108E14F3970432C21AF4C0CB1BCE ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
19:25:22.0939 0568 AdobeFlashPlayerUpdateSvc - ok
19:25:22.0970 0568 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
19:25:22.0970 0568 adp94xx - ok
19:25:23.0001 0568 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\drivers\adpahci.sys
19:25:23.0001 0568 adpahci - ok
19:25:23.0032 0568 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
19:25:23.0032 0568 adpu320 - ok
19:25:23.0048 0568 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:25:23.0048 0568 AeLookupSvc - ok
19:25:23.0095 0568 [ 827DBC22C96EECF6D36A13162FABAFD3 ] AESTFilters C:\Program Files\IDT\WDM\aestsrv.exe
19:25:23.0095 0568 AESTFilters - ok
19:25:23.0173 0568 [ F81BB7E487EDCEAB630A7EE66CF23913 ] AFD C:\Windows\system32\drivers\afd.sys
19:25:23.0173 0568 AFD - ok
19:25:23.0188 0568 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
19:25:23.0188 0568 agp440 - ok
19:25:23.0204 0568 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
19:25:23.0219 0568 aic78xx - ok
19:25:23.0251 0568 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
19:25:23.0251 0568 ALG - ok
19:25:23.0297 0568 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
19:25:23.0297 0568 aliide - ok
19:25:23.0313 0568 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
19:25:23.0313 0568 amdagp - ok
19:25:23.0360 0568 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
19:25:23.0375 0568 amdide - ok
19:25:23.0391 0568 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
19:25:23.0391 0568 AmdK8 - ok
19:25:23.0391 0568 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
19:25:23.0391 0568 AmdPPM - ok
19:25:23.0407 0568 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
19:25:23.0407 0568 amdsata - ok
19:25:23.0422 0568 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
19:25:23.0422 0568 amdsbs - ok
19:25:23.0438 0568 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
19:25:23.0438 0568 amdxata - ok
19:25:23.0469 0568 [ 476A6EFB2BB338D2854B3751367F8F71 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
19:25:23.0469 0568 ApfiltrService - ok
19:25:23.0500 0568 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
19:25:23.0500 0568 AppID - ok
19:25:23.0531 0568 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
19:25:23.0531 0568 AppIDSvc - ok
19:25:23.0578 0568 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
19:25:23.0578 0568 Appinfo - ok
19:25:23.0625 0568 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
19:25:23.0625 0568 AppMgmt - ok
19:25:23.0656 0568 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\drivers\arc.sys
19:25:23.0656 0568 arc - ok
19:25:23.0672 0568 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\drivers\arcsas.sys
19:25:23.0687 0568 arcsas - ok
19:25:23.0781 0568 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
19:25:23.0781 0568 aspnet_state - ok
19:25:23.0812 0568 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:25:23.0812 0568 AsyncMac - ok
19:25:23.0859 0568 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
19:25:23.0859 0568 atapi - ok
19:25:23.0921 0568 [ FF270313C14FC180B6C49BB0B302E0FB ] ATService C:\Program Files\Fingerprint Sensor\AtService.exe
19:25:23.0937 0568 ATService - ok
19:25:23.0984 0568 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:25:23.0984 0568 AudioEndpointBuilder - ok
19:25:24.0015 0568 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
19:25:24.0015 0568 Audiosrv - ok
19:25:24.0031 0568 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
19:25:24.0031 0568 AxInstSV - ok
19:25:24.0062 0568 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys
19:25:24.0077 0568 b06bdrv - ok
19:25:24.0109 0568 [ 68FB5AF4534AA98B364EA585703D2456 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
19:25:24.0109 0568 b57nd60x - ok
19:25:24.0171 0568 [ 87F3BCF82A63E900AF896CD930BF7E05 ] BBSvc C:\Program Files\Microsoft\BingBar\BBSvc.EXE
19:25:24.0171 0568 BBSvc - ok
19:25:24.0218 0568 [ 78779EE07231C658B483B1F38B5088DF ] BBUpdate C:\Program Files\Microsoft\BingBar\SeaPort.EXE
19:25:24.0218 0568 BBUpdate - ok
19:25:24.0249 0568 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
19:25:24.0249 0568 BDESVC - ok
19:25:24.0265 0568 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
19:25:24.0265 0568 Beep - ok
19:25:24.0296 0568 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
19:25:24.0311 0568 BFE - ok
19:25:24.0327 0568 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
19:25:24.0343 0568 BITS - ok
19:25:24.0343 0568 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
19:25:24.0343 0568 blbdrive - ok
19:25:24.0374 0568 [ A1115D933E7E3588E6DD53B03219F808 ] Blfp C:\Windows\system32\DRIVERS\basp.sys
19:25:24.0374 0568 Blfp - ok
19:25:24.0421 0568 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:25:24.0421 0568 bowser - ok
19:25:24.0483 0568 [ E7CA80FA5A7E82ED87E8140E0BDFA13B ] BrcmMgmtAgent C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
19:25:24.0483 0568 BrcmMgmtAgent - ok
19:25:24.0499 0568 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
19:25:24.0499 0568 BrFiltLo - ok
19:25:24.0514 0568 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
19:25:24.0514 0568 BrFiltUp - ok
19:25:24.0561 0568 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
19:25:24.0561 0568 Browser - ok
19:25:24.0592 0568 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
19:25:24.0592 0568 Brserid - ok
19:25:24.0608 0568 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
19:25:24.0608 0568 BrSerWdm - ok
19:25:24.0623 0568 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
19:25:24.0623 0568 BrUsbMdm - ok
19:25:24.0623 0568 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
19:25:24.0623 0568 BrUsbSer - ok
19:25:24.0655 0568 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
19:25:24.0655 0568 BthEnum - ok
19:25:24.0670 0568 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
19:25:24.0670 0568 BTHMODEM - ok
19:25:24.0686 0568 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
19:25:24.0686 0568 BthPan - ok
19:25:24.0733 0568 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
19:25:24.0748 0568 BTHPORT - ok
19:25:24.0779 0568 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
19:25:24.0779 0568 bthserv - ok
19:25:24.0811 0568 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
19:25:24.0811 0568 BTHUSB - ok
19:25:24.0873 0568 [ 2A0DE6423D6BE95C96124FC66046176E ] BTWAMPFL C:\Windows\system32\DRIVERS\btwampfl.sys
19:25:24.0873 0568 BTWAMPFL - ok
19:25:24.0920 0568 [ CC0A5E69D19B5C1ECC6CF9BF3ACC3969 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
19:25:24.0920 0568 btwaudio - ok
19:25:24.0935 0568 [ 9ABEA4DC976E3F47DA2D4B169719CBAA ] btwavdt C:\Windows\system32\drivers\btwavdt.sys
19:25:24.0951 0568 btwavdt - ok
19:25:25.0029 0568 [ 2A6008A9511330B7864B30A8B455AD0A ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
19:25:25.0045 0568 btwdins - ok
19:25:25.0045 0568 [ C2C9AEB3F9525CBA2670D1F2BEB32A0A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
19:25:25.0045 0568 btwl2cap - ok
19:25:25.0060 0568 [ 1E5468447E4D18FBEA5F01267D6495A5 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
19:25:25.0060 0568 btwrchid - ok
19:25:25.0091 0568 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:25:25.0091 0568 cdfs - ok
19:25:25.0123 0568 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:25:25.0138 0568 cdrom - ok
19:25:25.0169 0568 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
19:25:25.0169 0568 CertPropSvc - ok
19:25:25.0185 0568 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\drivers\circlass.sys
19:25:25.0185 0568 circlass - ok
19:25:25.0216 0568 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
19:25:25.0216 0568 CLFS - ok
19:25:25.0279 0568 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:25:25.0279 0568 clr_optimization_v2.0.50727_32 - ok
19:25:25.0310 0568 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:25:25.0310 0568 clr_optimization_v4.0.30319_32 - ok
19:25:25.0325 0568 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
19:25:25.0325 0568 CmBatt - ok
19:25:25.0372 0568 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:25:25.0372 0568 cmdide - ok
19:25:25.0419 0568 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
19:25:25.0435 0568 CNG - ok
19:25:25.0450 0568 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
19:25:25.0450 0568 Compbatt - ok
19:25:25.0466 0568 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
19:25:25.0466 0568 CompositeBus - ok
19:25:25.0466 0568 COMSysApp - ok
19:25:25.0481 0568 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
19:25:25.0481 0568 crcdisk - ok
19:25:25.0544 0568 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:25:25.0544 0568 CryptSvc - ok
19:25:25.0591 0568 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
19:25:25.0591 0568 CSC - ok
19:25:25.0622 0568 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
19:25:25.0622 0568 CscService - ok
19:25:25.0669 0568 [ 0F538DF1673E5216F3BAACB6911D9D0F ] CtAudDrv C:\Windows\system32\Drivers\CtAudDrv.sys
19:25:25.0669 0568 CtAudDrv - ok
19:25:25.0715 0568 [ AA52C0B88C46D5037809D05DD826C61E ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
19:25:25.0715 0568 CtClsFlt - ok
19:25:25.0715 0568 CV2K1 - ok
19:25:25.0747 0568 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
19:25:25.0747 0568 DcomLaunch - ok
19:25:25.0778 0568 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
19:25:25.0778 0568 defragsvc - ok
19:25:25.0793 0568 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:25:25.0809 0568 DfsC - ok
19:25:25.0871 0568 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
19:25:25.0871 0568 Dhcp - ok
19:25:25.0887 0568 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
19:25:25.0887 0568 discache - ok
19:25:25.0934 0568 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\drivers\disk.sys
19:25:25.0934 0568 Disk - ok
19:25:25.0949 0568 [ 2A958EF85DB1B61FFCA65044FA4BCE9E ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
19:25:25.0965 0568 dmvsc - ok
19:25:25.0981 0568 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:25:25.0981 0568 Dnscache - ok
19:25:25.0996 0568 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
19:25:26.0012 0568 dot3svc - ok
19:25:26.0027 0568 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
19:25:26.0027 0568 DPS - ok
19:25:26.0059 0568 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:25:26.0059 0568 drmkaud - ok
19:25:26.0121 0568 [ 71BC35067CABC02C9453AEAA42B2E43E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:25:26.0137 0568 DXGKrnl - ok
19:25:26.0152 0568 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
19:25:26.0152 0568 EapHost - ok
19:25:26.0246 0568 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\drivers\evbdx.sys
19:25:26.0261 0568 ebdrv - ok
19:25:26.0277 0568 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
19:25:26.0277 0568 EFS - ok
19:25:26.0339 0568 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:25:26.0355 0568 ehRecvr - ok
19:25:26.0371 0568 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
19:25:26.0371 0568 ehSched - ok
19:25:26.0402 0568 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\drivers\elxstor.sys
19:25:26.0417 0568 elxstor - ok
19:25:26.0417 0568 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:25:26.0417 0568 ErrDev - ok
19:25:26.0495 0568 esgiguard - ok
19:25:26.0527 0568 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
19:25:26.0542 0568 EventSystem - ok
19:25:26.0636 0568 [ 816025E303A1DAE89E39D3D77CCBA2FB ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
19:25:26.0651 0568 EvtEng - ok
19:25:26.0698 0568 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
19:25:26.0698 0568 exfat - ok
19:25:26.0729 0568 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:25:26.0729 0568 fastfat - ok
19:25:26.0776 0568 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
19:25:26.0776 0568 Fax - ok
19:25:26.0792 0568 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\drivers\fdc.sys
19:25:26.0792 0568 fdc - ok
19:25:26.0823 0568 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
19:25:26.0823 0568 fdPHost - ok
19:25:26.0823 0568 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
19:25:26.0823 0568 FDResPub - ok
19:25:26.0839 0568 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:25:26.0839 0568 FileInfo - ok
19:25:26.0854 0568 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:25:26.0854 0568 Filetrace - ok
19:25:26.0854 0568 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
19:25:26.0854 0568 flpydisk - ok
19:25:26.0870 0568 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:25:26.0870 0568 FltMgr - ok
19:25:26.0932 0568 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
19:25:26.0948 0568 FontCache - ok
19:25:27.0010 0568 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:25:27.0010 0568 FontCache3.0.0.0 - ok
19:25:27.0026 0568 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:25:27.0026 0568 FsDepends - ok
19:25:27.0057 0568 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:25:27.0057 0568 Fs_Rec - ok
19:25:27.0104 0568 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:25:27.0119 0568 fvevol - ok
19:25:27.0151 0568 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
19:25:27.0151 0568 gagp30kx - ok
19:25:27.0182 0568 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
19:25:27.0197 0568 gpsvc - ok
19:25:27.0322 0568 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
19:25:27.0322 0568 gusvc - ok
19:25:27.0338 0568 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:25:27.0338 0568 hcw85cir - ok
19:25:27.0369 0568 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
19:25:27.0369 0568 HDAudBus - ok
19:25:27.0369 0568 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
19:25:27.0369 0568 HidBatt - ok
19:25:27.0385 0568 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\drivers\hidbth.sys
19:25:27.0400 0568 HidBth - ok
19:25:27.0416 0568 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\drivers\hidir.sys
19:25:27.0416 0568 HidIr - ok
19:25:27.0431 0568 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
19:25:27.0431 0568 hidserv - ok
19:25:27.0478 0568 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
19:25:27.0478 0568 HidUsb - ok
19:25:27.0509 0568 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:25:27.0509 0568 hkmsvc - ok
19:25:27.0525 0568 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:25:27.0525 0568 HomeGroupListener - ok
19:25:27.0556 0568 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:25:27.0556 0568 HomeGroupProvider - ok
19:25:27.0587 0568 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:25:27.0587 0568 HpSAMD - ok
19:25:27.0619 0568 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:25:27.0619 0568 HTTP - ok
19:25:27.0634 0568 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:25:27.0634 0568 hwpolicy - ok
19:25:27.0665 0568 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:25:27.0665 0568 i8042prt - ok
19:25:27.0712 0568 [ F4037A3FEDB92DD97C95F320766EA5C9 ] iaStor C:\Windows\system32\drivers\iaStor.sys
19:25:27.0712 0568 iaStor - ok
19:25:27.0743 0568 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:25:27.0743 0568 iaStorV - ok
19:25:27.0775 0568 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:25:27.0790 0568 idsvc - ok
19:25:27.0977 0568 [ 721A8D48B2DC8C1C58C61CB948491EA8 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
19:25:28.0024 0568 igfx - ok
19:25:28.0055 0568 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\drivers\iirsp.sys
19:25:28.0055 0568 iirsp - ok
19:25:28.0102 0568 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
19:25:28.0118 0568 IKEEXT - ok
19:25:28.0149 0568 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\Windows\system32\drivers\Impcd.sys
19:25:28.0149 0568 Impcd - ok
19:25:28.0180 0568 [ 5576AD2F0039D2BCCCA3567FC0BF981C ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
19:25:28.0180 0568 IntcDAud - ok
19:25:28.0227 0568 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
19:25:28.0227 0568 intelide - ok
19:25:28.0258 0568 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:25:28.0258 0568 intelppm - ok
19:25:28.0274 0568 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:25:28.0274 0568 IPBusEnum - ok
19:25:28.0289 0568 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:25:28.0305 0568 IpFilterDriver - ok
19:25:28.0352 0568 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:25:28.0352 0568 iphlpsvc - ok
19:25:28.0383 0568 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:25:28.0383 0568 IPMIDRV - ok
19:25:28.0383 0568 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:25:28.0383 0568 IPNAT - ok
19:25:28.0414 0568 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:25:28.0414 0568 IRENUM - ok
19:25:28.0430 0568 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:25:28.0430 0568 isapnp - ok
19:25:28.0445 0568 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:25:28.0445 0568 iScsiPrt - ok
19:25:28.0492 0568 [ 6C85719A21B3F62C2C76280F4BD36C7B ] jhi_service C:\Program Files\Intel\Services\IPT\jhi_service.exe
19:25:28.0492 0568 jhi_service - ok
19:25:28.0523 0568 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:25:28.0523 0568 kbdclass - ok
19:25:28.0539 0568 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
19:25:28.0539 0568 kbdhid - ok
19:25:28.0570 0568 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
19:25:28.0570 0568 KeyIso - ok
19:25:28.0601 0568 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:25:28.0601 0568 KSecDD - ok
19:25:28.0617 0568 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:25:28.0633 0568 KSecPkg - ok
19:25:28.0664 0568 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
19:25:28.0664 0568 KtmRm - ok
19:25:28.0695 0568 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
19:25:28.0695 0568 LanmanServer - ok
19:25:28.0711 0568 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:25:28.0711 0568 LanmanWorkstation - ok
19:25:28.0757 0568 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:25:28.0757 0568 lltdio - ok
19:25:28.0789 0568 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:25:28.0789 0568 lltdsvc - ok
19:25:28.0804 0568 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
19:25:28.0804 0568 lmhosts - ok
19:25:28.0851 0568 [ 5F5899711DF18A02162B6D518C17B0D7 ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:25:28.0851 0568 LMS - ok
19:25:28.0867 0568 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
19:25:28.0867 0568 LSI_FC - ok
19:25:28.0882 0568 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
19:25:28.0882 0568 LSI_SAS - ok
19:25:28.0882 0568 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
19:25:28.0882 0568 LSI_SAS2 - ok
19:25:28.0882 0568 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
19:25:28.0882 0568 LSI_SCSI - ok
19:25:28.0913 0568 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
19:25:28.0913 0568 luafv - ok
19:25:28.0945 0568 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
19:25:28.0960 0568 MBAMProtector - ok
19:25:29.0054 0568 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:25:29.0054 0568 MBAMScheduler - ok
19:25:29.0085 0568 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:25:29.0101 0568 MBAMService - ok
19:25:29.0147 0568 [ E4DFBE4C4A9C2BD87C1430F445F3E3CB ] McComponentHostService C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
19:25:29.0147 0568 McComponentHostService - ok
19:25:29.0179 0568 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:25:29.0179 0568 Mcx2Svc - ok
19:25:29.0241 0568 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
19:25:29.0257 0568 MDM - ok
19:25:29.0272 0568 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\drivers\megasas.sys
19:25:29.0272 0568 megasas - ok
19:25:29.0303 0568 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
19:25:29.0303 0568 MegaSR - ok
19:25:29.0350 0568 [ D86AC00883B9C98B570E7643AAF8E554 ] MEI C:\Windows\system32\DRIVERS\HECI.sys
19:25:29.0350 0568 MEI - ok
19:25:29.0381 0568 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
19:25:29.0381 0568 MMCSS - ok
19:25:29.0397 0568 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
19:25:29.0397 0568 Modem - ok
19:25:29.0413 0568 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:25:29.0428 0568 monitor - ok
19:25:29.0428 0568 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:25:29.0428 0568 mouclass - ok
19:25:29.0459 0568 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:25:29.0459 0568 mouhid - ok
19:25:29.0475 0568 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:25:29.0475 0568 mountmgr - ok
19:25:29.0537 0568 [ 5D494509432897338AFC19DB78A76DCB ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
19:25:29.0537 0568 MozillaMaintenance - ok
19:25:29.0553 0568 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
19:25:29.0553 0568 mpio - ok
19:25:29.0569 0568 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:25:29.0584 0568 mpsdrv - ok
19:25:29.0615 0568 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:25:29.0631 0568 MpsSvc - ok
19:25:29.0647 0568 [ 21F4B24ACFC79A483515BD986DD9043F ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:25:29.0647 0568 MRxDAV - ok
19:25:29.0662 0568 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:25:29.0662 0568 mrxsmb - ok
19:25:29.0678 0568 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:25:29.0678 0568 mrxsmb10 - ok
19:25:29.0693 0568 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:25:29.0709 0568 mrxsmb20 - ok
19:25:29.0740 0568 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
19:25:29.0740 0568 msahci - ok
19:25:29.0771 0568 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:25:29.0771 0568 msdsm - ok
19:25:29.0803 0568 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
19:25:29.0803 0568 MSDTC - ok
19:25:29.0834 0568 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:25:29.0834 0568 Msfs - ok
19:25:29.0834 0568 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:25:29.0849 0568 mshidkmdf - ok
19:25:29.0865 0568 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:25:29.0865 0568 msisadrv - ok
19:25:29.0881 0568 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:25:29.0881 0568 MSiSCSI - ok
19:25:29.0896 0568 msiserver - ok
19:25:29.0927 0568 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:25:29.0927 0568 MSKSSRV - ok
19:25:29.0927 0568 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:25:29.0927 0568 MSPCLOCK - ok
19:25:29.0943 0568 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:25:29.0943 0568 MSPQM - ok
19:25:29.0959 0568 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:25:29.0959 0568 MsRPC - ok
19:25:29.0974 0568 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
19:25:29.0974 0568 mssmbios - ok
19:25:29.0974 0568 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:25:29.0974 0568 MSTEE - ok
19:25:29.0974 0568 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
19:25:29.0974 0568 MTConfig - ok
19:25:29.0990 0568 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
19:25:29.0990 0568 Mup - ok
19:25:30.0021 0568 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
19:25:30.0021 0568 napagent - ok
19:25:30.0052 0568 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:25:30.0052 0568 NativeWifiP - ok
19:25:30.0115 0568 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:25:30.0115 0568 NDIS - ok
19:25:30.0161 0568 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:25:30.0161 0568 NdisCap - ok
19:25:30.0161 0568 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:25:30.0161 0568 NdisTapi - ok
19:25:30.0177 0568 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:25:30.0177 0568 Ndisuio - ok
19:25:30.0193 0568 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:25:30.0193 0568 NdisWan - ok
19:25:30.0224 0568 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:25:30.0224 0568 NDProxy - ok
19:25:30.0224 0568 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:25:30.0224 0568 NetBIOS - ok
19:25:30.0255 0568 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:25:30.0255 0568 NetBT - ok
19:25:30.0271 0568 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
19:25:30.0271 0568 Netlogon - ok
19:25:30.0317 0568 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
19:25:30.0317 0568 Netman - ok
19:25:30.0364 0568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:25:30.0364 0568 NetMsmqActivator - ok
19:25:30.0380 0568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:25:30.0380 0568 NetPipeActivator - ok
19:25:30.0395 0568 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
19:25:30.0411 0568 netprofm - ok
19:25:30.0411 0568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:25:30.0411 0568 NetTcpActivator - ok
19:25:30.0427 0568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:25:30.0427 0568 NetTcpPortSharing - ok
19:25:30.0567 0568 [ 814596469BBE40EF99CCFD582A375B83 ] NETwNs32 C:\Windows\system32\DRIVERS\NETwNs32.sys
19:25:30.0614 0568 NETwNs32 - ok
19:25:30.0629 0568 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
19:25:30.0629 0568 nfrd960 - ok
19:25:30.0676 0568 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
19:25:30.0692 0568 NlaSvc - ok
19:25:30.0692 0568 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:25:30.0692 0568 Npfs - ok
19:25:30.0723 0568 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
19:25:30.0723 0568 nsi - ok
19:25:30.0739 0568 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:25:30.0739 0568 nsiproxy - ok
19:25:30.0801 0568 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:25:30.0832 0568 Ntfs - ok
19:25:30.0832 0568 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
19:25:30.0832 0568 Null - ok
19:25:30.0879 0568 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:25:30.0879 0568 nvraid - ok
19:25:30.0895 0568 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:25:30.0895 0568 nvstor - ok
19:25:30.0910 0568 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:25:30.0910 0568 nv_agp - ok
19:25:30.0957 0568 [ 4E37455DB16AEC75862B1D0BC35B589E ] O2FLASH C:\Windows\system32\DRIVERS\o2flash.exe
19:25:30.0957 0568 O2FLASH - ok
19:25:30.0973 0568 [ 5F63917FCC257ED11E828230BE594194 ] O2MDFRDR C:\Windows\system32\drivers\O2MDFw7.sys
19:25:30.0973 0568 O2MDFRDR - ok

Reklama
trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 05 lis 2013 19:33

19:25:30.0988 0568 [ FDC901900D9B1B671B3388C3023BD2EA ] O2MDRRDR C:\Windows\system32\DRIVERS\O2MDRw7.sys
19:25:30.0988 0568 O2MDRRDR - ok
19:25:31.0019 0568 [ 4635935FC972C582632BF45C26BFCB0E ] O2SDIOAssist c:\Windows\system32\srvany.exe
19:25:31.0019 0568 O2SDIOAssist - ok
19:25:31.0035 0568 [ D5A27C1ECD36564FED061EFB78BD0A62 ] O2SDJRDR C:\Windows\system32\DRIVERS\o2sdjw7.sys
19:25:31.0035 0568 O2SDJRDR - ok
19:25:31.0051 0568 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:25:31.0051 0568 ohci1394 - ok
19:25:31.0082 0568 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:25:31.0082 0568 ose - ok
19:25:31.0113 0568 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:25:31.0113 0568 p2pimsvc - ok
19:25:31.0160 0568 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
19:25:31.0160 0568 p2psvc - ok
19:25:31.0191 0568 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
19:25:31.0191 0568 Parport - ok
19:25:31.0238 0568 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:25:31.0238 0568 partmgr - ok
19:25:31.0253 0568 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
19:25:31.0253 0568 Parvdm - ok
19:25:31.0269 0568 [ 4088C1ECD1F54281A92FA663B0FDC36F ] PBADRV C:\Windows\system32\DRIVERS\PBADRV.sys
19:25:31.0285 0568 PBADRV - ok
19:25:31.0300 0568 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:25:31.0300 0568 PcaSvc - ok
19:25:31.0331 0568 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
19:25:31.0331 0568 pci - ok
19:25:31.0378 0568 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
19:25:31.0378 0568 pciide - ok
19:25:31.0394 0568 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
19:25:31.0394 0568 pcmcia - ok
19:25:31.0409 0568 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
19:25:31.0409 0568 pcw - ok
19:25:31.0441 0568 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:25:31.0456 0568 PEAUTH - ok
19:25:31.0487 0568 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
19:25:31.0503 0568 PeerDistSvc - ok
19:25:31.0581 0568 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
19:25:31.0597 0568 pla - ok
19:25:31.0628 0568 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:25:31.0628 0568 PlugPlay - ok
19:25:31.0643 0568 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:25:31.0643 0568 PNRPAutoReg - ok
19:25:31.0659 0568 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:25:31.0675 0568 PNRPsvc - ok
19:25:31.0706 0568 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:25:31.0706 0568 PolicyAgent - ok
19:25:31.0737 0568 [ AC42F771CC29727BD1663F211E9AC507 ] Power C:\Windows\system32\umpo.dll
19:25:31.0737 0568 Power - ok
19:25:31.0768 0568 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:25:31.0768 0568 PptpMiniport - ok
19:25:31.0784 0568 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys
19:25:31.0784 0568 Processor - ok
19:25:31.0831 0568 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
19:25:31.0831 0568 ProfSvc - ok
19:25:31.0846 0568 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:25:31.0846 0568 ProtectedStorage - ok
19:25:31.0877 0568 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:25:31.0877 0568 Psched - ok
19:25:31.0893 0568 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
19:25:31.0893 0568 PxHelp20 - ok
19:25:31.0940 0568 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
19:25:31.0955 0568 ql2300 - ok
19:25:31.0971 0568 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
19:25:31.0971 0568 ql40xx - ok
19:25:32.0002 0568 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
19:25:32.0002 0568 QWAVE - ok
19:25:32.0018 0568 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:25:32.0018 0568 QWAVEdrv - ok
19:25:32.0033 0568 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:25:32.0033 0568 RasAcd - ok
19:25:32.0065 0568 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:25:32.0065 0568 RasAgileVpn - ok
19:25:32.0080 0568 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
19:25:32.0080 0568 RasAuto - ok
19:25:32.0096 0568 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:25:32.0096 0568 Rasl2tp - ok
19:25:32.0127 0568 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
19:25:32.0127 0568 RasMan - ok
19:25:32.0158 0568 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:25:32.0158 0568 RasPppoe - ok
19:25:32.0174 0568 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:25:32.0174 0568 RasSstp - ok
19:25:32.0189 0568 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:25:32.0189 0568 rdbss - ok
19:25:32.0205 0568 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
19:25:32.0205 0568 rdpbus - ok
19:25:32.0221 0568 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:25:32.0221 0568 RDPCDD - ok
19:25:32.0236 0568 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
19:25:32.0236 0568 RDPDR - ok
19:25:32.0252 0568 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:25:32.0252 0568 RDPENCDD - ok
19:25:32.0267 0568 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:25:32.0267 0568 RDPREFMP - ok
19:25:32.0314 0568 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:25:32.0314 0568 RDPWD - ok
19:25:32.0345 0568 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:25:32.0345 0568 rdyboost - ok
19:25:32.0408 0568 [ B064FC671688A9A1C5F46AE06E87F70D ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
19:25:32.0408 0568 RegSrvc - ok
19:25:32.0439 0568 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
19:25:32.0439 0568 RemoteAccess - ok
19:25:32.0470 0568 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:25:32.0470 0568 RemoteRegistry - ok
19:25:32.0501 0568 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
19:25:32.0501 0568 RFCOMM - ok
19:25:32.0595 0568 [ 3C957189B31C34D3AD21967B12B6AED7 ] RoxMediaDB12OEM C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
19:25:32.0611 0568 RoxMediaDB12OEM - ok
19:25:32.0626 0568 [ 2B73088CC2CA757A172B425C9398E5BC ] RoxWatch12 C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
19:25:32.0626 0568 RoxWatch12 - ok
19:25:32.0657 0568 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:25:32.0657 0568 RpcEptMapper - ok
19:25:32.0689 0568 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
19:25:32.0689 0568 RpcLocator - ok
19:25:32.0704 0568 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
19:25:32.0720 0568 RpcSs - ok
19:25:32.0751 0568 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:25:32.0751 0568 rspndr - ok
19:25:32.0767 0568 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
19:25:32.0767 0568 s3cap - ok
19:25:32.0782 0568 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
19:25:32.0782 0568 SamSs - ok
19:25:32.0813 0568 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:25:32.0813 0568 sbp2port - ok
19:25:32.0829 0568 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:25:32.0845 0568 SCardSvr - ok
19:25:32.0860 0568 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:25:32.0860 0568 scfilter - ok
19:25:32.0876 0568 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
19:25:32.0891 0568 Schedule - ok
19:25:32.0907 0568 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:25:32.0907 0568 SCPolicySvc - ok
19:25:32.0923 0568 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:25:32.0923 0568 SDRSVC - ok
19:25:32.0938 0568 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:25:32.0938 0568 secdrv - ok
19:25:32.0954 0568 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
19:25:32.0954 0568 seclogon - ok
19:25:33.0094 0568 [ 889C97ACB58C78B9DB6F94FAEDA05B70 ] SecureStorageService C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe
19:25:33.0125 0568 SecureStorageService - ok
19:25:33.0141 0568 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
19:25:33.0141 0568 SENS - ok
19:25:33.0172 0568 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:25:33.0172 0568 SensrSvc - ok
19:25:33.0188 0568 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\drivers\serenum.sys
19:25:33.0188 0568 Serenum - ok
19:25:33.0219 0568 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\drivers\serial.sys
19:25:33.0219 0568 Serial - ok
19:25:33.0250 0568 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys
19:25:33.0250 0568 sermouse - ok
19:25:33.0266 0568 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
19:25:33.0266 0568 SessionEnv - ok
19:25:33.0281 0568 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:25:33.0281 0568 sffdisk - ok
19:25:33.0281 0568 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:25:33.0281 0568 sffp_mmc - ok
19:25:33.0281 0568 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:25:33.0281 0568 sffp_sd - ok
19:25:33.0297 0568 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
19:25:33.0297 0568 sfloppy - ok
19:25:33.0313 0568 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:25:33.0313 0568 SharedAccess - ok
19:25:33.0328 0568 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:25:33.0344 0568 ShellHWDetection - ok
19:25:33.0359 0568 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
19:25:33.0359 0568 sisagp - ok
19:25:33.0359 0568 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
19:25:33.0359 0568 SiSRaid2 - ok
19:25:33.0375 0568 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
19:25:33.0375 0568 SiSRaid4 - ok
19:25:33.0562 0568 [ 9F712B26EE3B0242DE997A42FD302E2C ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
19:25:33.0578 0568 Skype C2C Service - ok
19:25:33.0656 0568 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
19:25:33.0656 0568 SkypeUpdate - ok
19:25:33.0687 0568 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:25:33.0687 0568 Smb - ok
19:25:33.0718 0568 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:25:33.0718 0568 SNMPTRAP - ok
19:25:33.0734 0568 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
19:25:33.0734 0568 spldr - ok
19:25:33.0765 0568 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
19:25:33.0781 0568 Spooler - ok
19:25:33.0874 0568 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
19:25:33.0890 0568 sppsvc - ok
19:25:33.0921 0568 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:25:33.0921 0568 sppuinotify - ok
19:25:33.0937 0568 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
19:25:33.0952 0568 srv - ok
19:25:33.0968 0568 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:25:33.0968 0568 srv2 - ok
19:25:33.0983 0568 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:25:33.0983 0568 srvnet - ok
19:25:33.0999 0568 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:25:33.0999 0568 SSDPSRV - ok
19:25:34.0015 0568 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:25:34.0015 0568 SstpSvc - ok
19:25:34.0061 0568 [ A97FCA92BE4E62BC589371058CBC769E ] STacSV C:\Program Files\IDT\WDM\STacSV.exe
19:25:34.0061 0568 STacSV - ok
19:25:34.0093 0568 [ D8FC8D47FBFCB3852E40F5D5058ABC6A ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys
19:25:34.0093 0568 stdcfltn - ok
19:25:34.0124 0568 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys
19:25:34.0124 0568 stexstor - ok
19:25:34.0155 0568 [ D5D73B49D53FCC47E2828D6805DFA0F6 ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys
19:25:34.0155 0568 STHDA - ok
19:25:34.0186 0568 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
19:25:34.0186 0568 StiSvc - ok
19:25:34.0217 0568 [ 7731F46EC0D687A931CBA063E8F90EF0 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
19:25:34.0217 0568 stllssvr - ok
19:25:34.0264 0568 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
19:25:34.0264 0568 storflt - ok
19:25:34.0280 0568 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll
19:25:34.0280 0568 StorSvc - ok
19:25:34.0295 0568 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
19:25:34.0295 0568 storvsc - ok
19:25:34.0311 0568 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
19:25:34.0311 0568 swenum - ok
19:25:34.0342 0568 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
19:25:34.0342 0568 swprv - ok
19:25:34.0373 0568 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
19:25:34.0389 0568 SysMain - ok
19:25:34.0389 0568 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:25:34.0389 0568 TabletInputService - ok
19:25:34.0405 0568 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
19:25:34.0420 0568 TapiSrv - ok
19:25:34.0420 0568 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
19:25:34.0436 0568 TBS - ok
19:25:34.0514 0568 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:25:34.0529 0568 Tcpip - ok
19:25:34.0561 0568 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:25:34.0576 0568 TCPIP6 - ok
19:25:34.0623 0568 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:25:34.0639 0568 tcpipreg - ok
19:25:34.0717 0568 [ 3D52B206D9F6F3ECFDB5D676614E47B6 ] tcsd_win32.exe C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
19:25:34.0732 0568 tcsd_win32.exe - ok
19:25:34.0810 0568 [ 0BAD1BC9BA31218B682455182134537D ] TdmService C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
19:25:34.0826 0568 TdmService - ok
19:25:34.0857 0568 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:25:34.0857 0568 TDPIPE - ok
19:25:34.0888 0568 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:25:34.0888 0568 TDTCP - ok
19:25:34.0904 0568 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:25:34.0904 0568 tdx - ok
19:25:34.0919 0568 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
19:25:34.0935 0568 TermDD - ok
19:25:34.0966 0568 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
19:25:34.0982 0568 TermService - ok
19:25:34.0997 0568 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
19:25:34.0997 0568 Themes - ok
19:25:35.0013 0568 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
19:25:35.0013 0568 THREADORDER - ok
19:25:35.0044 0568 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
19:25:35.0044 0568 TrkWks - ok
19:25:35.0091 0568 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:25:35.0091 0568 TrustedInstaller - ok
19:25:35.0138 0568 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:25:35.0138 0568 tssecsrv - ok
19:25:35.0153 0568 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:25:35.0153 0568 TsUsbFlt - ok
19:25:35.0169 0568 [ 01246F0BAAD7B68EC0F472AA41E33282 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
19:25:35.0169 0568 TsUsbGD - ok
19:25:35.0200 0568 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:25:35.0200 0568 tunnel - ok
19:25:35.0200 0568 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys
19:25:35.0200 0568 uagp35 - ok
19:25:35.0216 0568 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:25:35.0231 0568 udfs - ok
19:25:35.0263 0568 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:25:35.0263 0568 UI0Detect - ok
19:25:35.0278 0568 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:25:35.0278 0568 uliagpkx - ok
19:25:35.0294 0568 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:25:35.0294 0568 umbus - ok
19:25:35.0309 0568 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys
19:25:35.0309 0568 UmPass - ok
19:25:35.0341 0568 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
19:25:35.0341 0568 UmRdpService - ok
19:25:35.0419 0568 [ F7A1F83F28B125AA3737BC06EABB0CD5 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:25:35.0434 0568 UNS - ok
19:25:35.0497 0568 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
19:25:35.0512 0568 upnphost - ok
19:25:35.0528 0568 [ E4EC748EAB50E6BC7FD7E4F5D507A639 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:25:35.0528 0568 usbccgp - ok
19:25:35.0575 0568 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:25:35.0575 0568 usbcir - ok
19:25:35.0621 0568 [ CCB7E9F2963089872036B8F29D067D82 ] usbehci C:\Windows\system32\drivers\usbehci.sys
19:25:35.0621 0568 usbehci - ok
19:25:35.0684 0568 [ D61EC91F6F46C6B5C20413B9C09DF06F ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:25:35.0684 0568 usbhub - ok
19:25:35.0746 0568 [ B991B37A1C8977B6D4967E067E7C950B ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:25:35.0746 0568 usbohci - ok
19:25:35.0762 0568 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\drivers\usbprint.sys
19:25:35.0762 0568 usbprint - ok
19:25:35.0793 0568 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:25:35.0793 0568 USBSTOR - ok
19:25:35.0809 0568 [ BF11C0D7A8D2AEB3A010C28DF7B15B75 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:25:35.0809 0568 usbuhci - ok
19:25:35.0887 0568 [ DE014425522610BEDCA3821BB8C0F1D5 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
19:25:35.0887 0568 usbvideo - ok
19:25:35.0902 0568 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
19:25:35.0902 0568 UxSms - ok
19:25:35.0918 0568 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
19:25:35.0933 0568 VaultSvc - ok
19:25:35.0949 0568 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:25:35.0949 0568 vdrvroot - ok
19:25:35.0980 0568 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
19:25:35.0980 0568 vds - ok
19:25:36.0011 0568 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:25:36.0011 0568 vga - ok
19:25:36.0027 0568 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
19:25:36.0027 0568 VgaSave - ok
19:25:36.0043 0568 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:25:36.0058 0568 vhdmp - ok
19:25:36.0074 0568 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
19:25:36.0074 0568 viaagp - ok
19:25:36.0089 0568 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
19:25:36.0089 0568 ViaC7 - ok
19:25:36.0136 0568 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
19:25:36.0136 0568 viaide - ok
19:25:36.0167 0568 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
19:25:36.0167 0568 vmbus - ok
19:25:36.0183 0568 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
19:25:36.0183 0568 VMBusHID - ok
19:25:36.0183 0568 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:25:36.0199 0568 volmgr - ok
19:25:36.0214 0568 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:25:36.0214 0568 volmgrx - ok
19:25:36.0230 0568 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:25:36.0230 0568 volsnap - ok
19:25:36.0245 0568 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
19:25:36.0245 0568 vsmraid - ok
19:25:36.0292 0568 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
19:25:36.0308 0568 VSS - ok
19:25:36.0355 0568 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:25:36.0355 0568 vwifibus - ok
19:25:36.0386 0568 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:25:36.0386 0568 vwififlt - ok
19:25:36.0401 0568 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
19:25:36.0417 0568 W32Time - ok
19:25:36.0417 0568 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
19:25:36.0417 0568 WacomPen - ok
19:25:36.0464 0568 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:25:36.0464 0568 WANARP - ok
19:25:36.0479 0568 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:25:36.0479 0568 Wanarpv6 - ok
19:25:36.0557 0568 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
19:25:36.0573 0568 WatAdminSvc - ok
19:25:36.0620 0568 [ 79E2E832DE566CFEDBF4E6DAFE73B959 ] Wave Authentication Manager Service C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
19:25:36.0635 0568 Wave Authentication Manager Service - ok
19:25:36.0698 0568 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
19:25:36.0713 0568 wbengine - ok
19:25:36.0760 0568 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:25:36.0776 0568 WbioSrvc - ok
19:25:36.0791 0568 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:25:36.0791 0568 wcncsvc - ok
19:25:36.0807 0568 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:25:36.0807 0568 WcsPlugInService - ok
19:25:36.0823 0568 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys
19:25:36.0823 0568 Wd - ok
19:25:36.0885 0568 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:25:36.0885 0568 Wdf01000 - ok
19:25:36.0901 0568 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:25:36.0901 0568 WdiServiceHost - ok
19:25:36.0901 0568 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:25:36.0901 0568 WdiSystemHost - ok
19:25:36.0947 0568 [ 75E8EBD7040CE238684333F97014762A ] WebClient C:\Windows\System32\webclnt.dll
19:25:36.0947 0568 WebClient - ok
19:25:36.0963 0568 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:25:36.0979 0568 Wecsvc - ok
19:25:36.0994 0568 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:25:36.0994 0568 wercplsupport - ok
19:25:37.0010 0568 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
19:25:37.0010 0568 WerSvc - ok
19:25:37.0041 0568 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:25:37.0041 0568 WfpLwf - ok
19:25:37.0041 0568 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:25:37.0041 0568 WIMMount - ok
19:25:37.0119 0568 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
19:25:37.0119 0568 WinDefend - ok
19:25:37.0135 0568 WinHttpAutoProxySvc - ok
19:25:37.0197 0568 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:25:37.0197 0568 Winmgmt - ok
19:25:37.0244 0568 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
19:25:37.0275 0568 WinRM - ok
19:25:37.0306 0568 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
19:25:37.0306 0568 Wlansvc - ok
19:25:37.0353 0568 [ 6067ACEF367E79914AF628FA1E9B5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
19:25:37.0353 0568 wlcrasvc - ok
19:25:37.0415 0568 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:25:37.0415 0568 wlidsvc - ok
19:25:37.0447 0568 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
19:25:37.0447 0568 WmiAcpi - ok
19:25:37.0478 0568 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:25:37.0478 0568 wmiApSrv - ok
19:25:37.0540 0568 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
19:25:37.0556 0568 WMPNetworkSvc - ok
19:25:37.0571 0568 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:25:37.0571 0568 WPCSvc - ok
19:25:37.0587 0568 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:25:37.0587 0568 WPDBusEnum - ok
19:25:37.0587 0568 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:25:37.0587 0568 ws2ifsl - ok
19:25:37.0603 0568 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
19:25:37.0603 0568 wscsvc - ok
19:25:37.0618 0568 WSearch - ok
19:25:37.0681 0568 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
19:25:37.0696 0568 wuauserv - ok
19:25:37.0727 0568 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:25:37.0727 0568 WudfPf - ok
19:25:37.0774 0568 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:25:37.0774 0568 WUDFRd - ok
19:25:37.0821 0568 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:25:37.0821 0568 wudfsvc - ok
19:25:37.0899 0568 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
19:25:37.0899 0568 WwanSvc - ok
19:25:37.0961 0568 [ 4F5D56FF81B8C0294E22DCC62136F253 ] ZcfgSvc7 C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe
19:25:37.0977 0568 ZcfgSvc7 - ok
19:25:37.0993 0568 ================ Scan global ===============================
19:25:38.0024 0568 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
19:25:38.0071 0568 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
19:25:38.0086 0568 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
19:25:38.0117 0568 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
19:25:38.0149 0568 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
19:25:38.0149 0568 [Global] - ok
19:25:38.0149 0568 ================ Scan MBR ==================================
19:25:38.0164 0568 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
19:25:38.0461 0568 \Device\Harddisk0\DR0 - ok
19:25:38.0461 0568 ================ Scan VBR ==================================
19:25:38.0476 0568 [ 8FA6273447A11A1F7EB33ACED096AD88 ] \Device\Harddisk0\DR0\Partition1
19:25:38.0476 0568 \Device\Harddisk0\DR0\Partition1 - ok
19:25:38.0492 0568 [ EABE9459B5512DB38D3218EA937C77F5 ] \Device\Harddisk0\DR0\Partition2
19:25:38.0507 0568 \Device\Harddisk0\DR0\Partition2 - ok
19:25:38.0507 0568 ============================================================
19:25:38.0507 0568 Scan finished
19:25:38.0507 0568 ============================================================
19:25:38.0523 1212 Detected object count: 0
19:25:38.0523 1212 Actual detected object count: 0
19:25:41.0752 4540 Deinitialize success

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod jaro3 » 06 lis 2013 09:43

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 06 lis 2013 11:51

RogueKiller V8.7.6 [Oct 28 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : PLTrangos [Práva správce]
Mód : Kontrola -- Datum : 11/06/2013 11:48:46
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\libfoxloader.dll [x] -> ODEBRÁNO
[SUSP PATH] szndesktop.exe -- C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1503772570-1702865764-714516373-1000\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1503772570-1702865764-714516373-1000\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST320LT014-9YK142 +++++
--- User ---
[MBR] f45a549f5d6aa7a0addfd4f019ee5223
[BSP] 27751762a5aabce0e495c8e22b4c69aa : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 752 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1622016 | Size: 304452 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_11062013_114846.txt >>

trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 06 lis 2013 12:02

ComboFix 13-11-04.01 - PLTrangos 06.11.2013 11:54:34.1.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3241.2024 [GMT 1:00]
Spuštěný z: c:\users\PLTrangos\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - system32: deleted 24 bytes in 2 streams.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-06 do 2013-11-06 )))))))))))))))))))))))))))))))
.
.
2013-11-06 10:58 . 2013-11-06 10:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-06 06:46 . 2013-11-06 06:46 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7299C01D-B174-4407-A69E-525EA6BA420B}\offreg.dll
2013-11-06 05:50 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7299C01D-B174-4407-A69E-525EA6BA420B}\mpengine.dll
2013-11-05 18:08 . 2013-11-05 18:08 -------- d-----w- c:\windows\ERUNT
2013-11-04 17:32 . 2013-11-04 17:47 -------- d-----w- C:\AdwCleaner
2013-11-03 17:09 . 2013-11-03 17:09 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-11-03 16:40 . 2013-11-03 16:40 -------- d-----w- c:\users\PLTrangos\AppData\Roaming\BACS.exe
2013-11-03 15:20 . 2013-11-03 15:20 -------- d-----w- c:\users\PLTrangos\AppData\Roaming\Malwarebytes
2013-11-03 15:20 . 2013-11-03 15:20 -------- d-----w- c:\programdata\Malwarebytes
2013-11-03 15:19 . 2013-11-03 15:19 -------- d-----w- c:\users\PLTrangos\AppData\Local\Programs
2013-11-03 14:11 . 2013-11-03 14:11 -------- d-----w- c:\program files\Enigma Software Group
2013-11-03 14:10 . 2013-11-03 14:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2013-11-03 10:46 . 2013-11-03 10:46 -------- d-----w- c:\users\PLTrangos\AppData\Roaming\TuneUp Software
2013-11-03 10:45 . 2013-11-05 18:04 -------- d-----w- c:\programdata\AVG2014
2013-11-03 10:38 . 2013-11-05 18:04 -------- d-----w- c:\programdata\MFAData
2013-11-03 10:38 . 2013-11-03 10:38 -------- d--h--w- c:\programdata\Common Files
2013-11-03 10:38 . 2013-11-03 10:38 -------- d-----w- c:\users\PLTrangos\AppData\Local\MFAData
2013-11-03 08:15 . 2013-11-03 08:15 -------- d-----w- c:\users\PLTrangos\AppData\Local\DarkRoom
2013-11-02 11:40 . 2013-11-02 11:40 -------- d-----w- C:\SoundCloud Downloads
2013-10-22 16:42 . 2013-10-22 16:42 -------- d-----w- c:\programdata\Creative
2013-10-22 16:29 . 2013-11-06 10:44 -------- d-----w- c:\users\PLTrangos\AppData\Roaming\Skype
2013-10-22 16:29 . 2013-10-22 16:30 -------- d-----r- c:\program files\Skype
2013-10-22 16:29 . 2013-10-22 16:29 -------- d-----w- c:\program files\Common Files\Skype
2013-10-22 16:29 . 2013-10-22 16:30 -------- d-----w- c:\programdata\Skype
2013-10-12 12:05 . 2013-09-04 01:19 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-12 12:05 . 2013-09-04 01:18 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-12 12:05 . 2013-09-04 01:18 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-12 12:05 . 2013-09-04 01:18 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-12 12:05 . 2013-09-04 01:18 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-12 12:05 . 2013-09-04 01:18 24576 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-12 12:05 . 2013-09-04 01:18 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-11 05:24 . 2013-07-04 11:50 530432 ----a-w- c:\windows\system32\comctl32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-09 08:00 . 2012-07-31 22:26 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-09 08:00 . 2012-03-28 12:03 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-03 12:35 . 2012-07-15 15:07 238872 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2011-05-27 22:38 120184 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2011-05-27 22:38 120184 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20474528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-07-20 505720]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2011-01-25 536668]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-28 142616]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-28 177432]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-28 176408]
"IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-23 1210640]
"FreeFallProtection"="c:\program files\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2011-07-25 686704]
"TdmNotify"="c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe" [2011-05-27 214384]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-03-12 462993]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2010-10-01 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-17 50472]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2012-06-28 74752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-2-8 840992]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2012-3-28 50688]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 273296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2010-09-15 16:11 1971536 ----a-w- c:\program files\Common Files\SPBA\homefus2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 O2SDIOAssist;O2SDIOAssist;c:\windows\system32\srvany.exe [2003-04-19 8192]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2012-03-28 302120]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-03-28 33832]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\Drivers\CtAudDrv.sys [2009-05-28 134144]
R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 132480]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [2013-09-06 235216]
R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7.sys [2011-01-04 60904]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-15 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2011-07-15 17904]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\aestsrv.exe [2009-03-03 81920]
S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2010-05-10 1803584]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2010-06-29 127488]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-03 2656280]
S2 Wave Authentication Manager Service;Wave Authentication Manager Service;c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2011-07-01 1131520]
S2 ZcfgSvc7;Intel(R) PROSet/Wireless ZeroConfig Service;c:\program files\Intel\WiFi\bin\ZCfgSvc7.exe [2010-12-23 577536]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\accelern.sys [2011-07-22 44144]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-09-16 144576]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 269824]
S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-10-20 41088]
S3 NETwNs32;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 32 Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-12-21 7434240]
S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\DRIVERS\O2MDRw7.sys [2011-01-04 62440]
S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7.sys [2011-03-23 63976]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - TrueSight
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-31 08:00]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.109.151.1 10.109.255.254
FF - ProfilePath - c:\users\PLTrangos\AppData\Roaming\Mozilla\Firefox\Profiles\c7eo6ekx.default\
FF - ExtSQL: 2013-10-22 18:30; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2013-10-22 20:48; toolbar@centrumholdings.com; c:\users\PLTrangos\AppData\Roaming\Mozilla\Firefox\Profiles\c7eo6ekx.default\extensions\toolbar@centrumholdings.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
AddRemove-HLSW_is1 - c:\program files\HLSW\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(568)
c:\windows\system32\wvauth.DLL
.
- - - - - - - > 'Explorer.exe'(2468)
c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Celkový čas: 2013-11-06 11:59:39
ComboFix-quarantined-files.txt 2013-11-06 10:59
.
Před spuštěním: Volných bajtů: 183 127 318 528
Po spuštění: Volných bajtů: 183 621 824 512
.
- - End Of File - - DB8426B53C57014D3E6A1505B4B8E326
5C616939100B85E558DA92B899A0FC36

trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 06 lis 2013 12:07

RogueKiller V8.7.6 [Oct 28 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : PLTrangos [Práva správce]
Mód : Odebrat -- Datum : 11/06/2013 11:49:00
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[SUSP PATH][DLL] explorer.exe -- C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\libfoxloader.dll [x] -> ODEBRÁNO
[SUSP PATH] szndesktop.exe -- C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-1503772570-1702865764-714516373-1000\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[RUN][SUSP PATH] HKUS\S-1-5-21-1503772570-1702865764-714516373-1000\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\PLTrangos\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NAHRAZENO (2)
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST320LT014-9YK142 +++++
--- User ---
[MBR] f45a549f5d6aa7a0addfd4f019ee5223
[BSP] 27751762a5aabce0e495c8e22b4c69aa : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 752 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1622016 | Size: 304452 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_11062013_114900.txt >>
RKreport[0]_S_11062013_114846.txt

trangi
nováček
Příspěvky: 15
Registrován: listopad 13
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod trangi » 06 lis 2013 15:31

Tak nevím, jestli je tímto vše vyřešeno, každopádně ráno odlítám na měsíc a půl do Nepálu. Tak mi snad za tu dobu vir počítač schovaný ve skříni nesežere. Járo díky za pomoc.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: qone8 - nedaří se ho zbavit

Příspěvekod jaro3 » 07 lis 2013 10:21

Nemáš zač.

Až přiletíš zpět:

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
File::
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

Folder::
c:\program files\Skype\Updater
c:\program files\Seznam.cz
c:\program files\McAfee Security Scan

Driver::
SkypeUpdate
McComponentHostService

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=-

Firefox::
FF - ProfilePath - c:\users\PLTrangos\AppData\Roaming\Mozilla\Firefox\Profiles\c7eo6ekx.default\
FF - ExtSQL: 2013-10-22 18:30; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - ExtSQL: 2013-10-22 20:48; toolbar@centrumholdings.com; c:\users\PLTrangos\AppData\Roaming\Mozilla\Firefox\Profiles\c7eo6ekx.default\extensions\toolbar@centrumholdings.com
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 0 hostů