Zdravím. Nefunguje mi internet v PC, s kamarádem přes PC jsme přišli na to, že to blokuje pravděpodobně nějaký virus... Proto žádám o pomoc s HJT. děkuji
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:24:47, on 17.11.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\BlueStacks\HD-Agent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe
D:\files\Zoner\Program32\ZPSTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
D:\Steam\steam.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
D:\files\Google\Chrome\Application\chrome.exe
C:\Users\Tomasacus\Desktop\HiJackThis.exe
F:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.206.14.26:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Allmyapps] "C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe" startup
O4 - HKCU\..\Run: [Allmyapps Update] "C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] D:\FILES\ZONER\Program32\ZPSTRAY.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-LogRotatorService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 6034 bytes
výpis z logu, děkuji za pomoc
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
výpis z logu, děkuji za pomoc
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
# AdwCleaner v3.012 - Report created 20/11/2013 at 18:46:26
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Tomasacus - TOMASACUS-PC
# Running from : D:\Download\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files\NCH Software
Folder Found C:\Users\Tomasacus\AppData\Local\eSupport.com
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\InstallCore
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16635
-\\ Mozilla Firefox v
[ File : C:\Users\Tomasacus\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
-\\ Google Chrome v
[ File : C:\Users\Tomasacus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [1693 octets] - [20/11/2013 18:46:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1753 octets] ##########
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Tomasacus
->Temp folder emptied: 22750237 bytes
->Temporary Internet Files folder emptied: 3019199 bytes
->Java cache emptied: 792118 bytes
->Google Chrome cache emptied: 97142297 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34072 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 30601446 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 203781 bytes
Process complete!
Total Files Cleaned = 147,00 mb
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 19:06:11
MBAM-log-2013-11-20 (19-13-39).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218396
Uplynulý čas: 6 minut,
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 4
C:\Windows\Installer\754160a.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541610.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541616.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\754161c.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
(konec)
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Tomasacus - TOMASACUS-PC
# Running from : D:\Download\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files\NCH Software
Folder Found C:\Users\Tomasacus\AppData\Local\eSupport.com
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\InstallCore
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16635
-\\ Mozilla Firefox v
[ File : C:\Users\Tomasacus\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
-\\ Google Chrome v
[ File : C:\Users\Tomasacus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [1693 octets] - [20/11/2013 18:46:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1753 octets] ##########
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Tomasacus
->Temp folder emptied: 22750237 bytes
->Temporary Internet Files folder emptied: 3019199 bytes
->Java cache emptied: 792118 bytes
->Google Chrome cache emptied: 97142297 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34072 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 30601446 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 203781 bytes
Process complete!
Total Files Cleaned = 147,00 mb
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 19:06:11
MBAM-log-2013-11-20 (19-13-39).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218396
Uplynulý čas: 6 minut,
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 4
C:\Windows\Installer\754160a.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541610.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541616.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\754161c.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
(konec)
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
# AdwCleaner v3.012 - Report created 20/11/2013 at 18:46:26
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Tomasacus - TOMASACUS-PC
# Running from : D:\Download\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files\NCH Software
Folder Found C:\Users\Tomasacus\AppData\Local\eSupport.com
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\InstallCore
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16635
-\\ Mozilla Firefox v
[ File : C:\Users\Tomasacus\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
-\\ Google Chrome v
[ File : C:\Users\Tomasacus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [1693 octets] - [20/11/2013 18:46:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1753 octets] ##########
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Tomasacus
->Temp folder emptied: 22750237 bytes
->Temporary Internet Files folder emptied: 3019199 bytes
->Java cache emptied: 792118 bytes
->Google Chrome cache emptied: 97142297 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34072 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 30601446 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 203781 bytes
Process complete!
Total Files Cleaned = 147,00 mb
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 19:06:11
MBAM-log-2013-11-20 (19-13-39).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218396
Uplynulý čas: 6 minut,
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 4
C:\Windows\Installer\754160a.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541610.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541616.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\754161c.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
(konec)
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Tomasacus - TOMASACUS-PC
# Running from : D:\Download\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Program Files\NCH Software
Folder Found C:\Users\Tomasacus\AppData\Local\eSupport.com
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\InstallCore
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16635
-\\ Mozilla Firefox v
[ File : C:\Users\Tomasacus\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Found : user_pref("browser.search.selectedEngine", "AVG Secure Search");
-\\ Google Chrome v
[ File : C:\Users\Tomasacus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
Found : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [1693 octets] - [20/11/2013 18:46:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1753 octets] ##########
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Tomasacus
->Temp folder emptied: 22750237 bytes
->Temporary Internet Files folder emptied: 3019199 bytes
->Java cache emptied: 792118 bytes
->Google Chrome cache emptied: 97142297 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34072 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 30601446 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 203781 bytes
Process complete!
Total Files Cleaned = 147,00 mb
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 19:06:11
MBAM-log-2013-11-20 (19-13-39).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218396
Uplynulý čas: 6 minut,
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 4
C:\Windows\Installer\754160a.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541610.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\7541616.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
C:\Windows\Installer\754161c.msi (PUP.Optional.SweetIM) -> Nebyla provedena žádná instrukce.
(konec)
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.
Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 20:23:21
mbam-log-2013-11-20 (20-23-21).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218633
Uplynulý čas: 5 minut, 15 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.0.7 (07.11.2013:1)
OS: Windows 7 Ultimate x86
Ran by Tomasacus on st 20.11.2013 at 20:20:32,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
Successfully deleted: [File] C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 20.11.2013 at 20:22:13,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Tomasacus [Práva správce]
Mód : Kontrola -- Datum : 11/20/2013 20:35:01
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Allmyapps ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe" startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : Allmyapps Update ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1898723742-3674319155-592853615-1001\[...]\Run : Allmyapps ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe" startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1898723742-3674319155-592853615-1001\[...]\Run : Allmyapps Update ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup [7][x]) -> NALEZENO
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (200.206.14.26:80 [Country: BRAZIL (BR), City: (Unknown city)]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 2 ¤¤¤
[V1][SUSP PATH] AllmyappsUpdateTask.job : C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe - check startup [7][x] -> NALEZENO
[V2][SUSP PATH] AllmyappsUpdateTask : c:\users\tomasacus\appdata\roaming\allmyapps\allmyappsupdater.exe - check startup [7][x] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HD322HJ ATA Device +++++
--- User ---
[MBR] c3a078dc0a9f110802fc0de0bd687c9c
[BSP] a026f864f28fd3ce5b1af5ad53716e3f : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 24999 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 51199155 | Size: 280235 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_11202013_203501.txt >>
www.malwarebytes.org
Verze: v2013.11.20.10
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Tomasacus :: TOMASACUS-PC [administrátor]
20.11.2013 20:23:21
mbam-log-2013-11-20 (20-23-21).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 218633
Uplynulý čas: 5 minut, 15 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)
(konec)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.0.7 (07.11.2013:1)
OS: Windows 7 Ultimate x86
Ran by Tomasacus on st 20.11.2013 at 20:20:32,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
Successfully deleted: [File] C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 20.11.2013 at 20:22:13,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Tomasacus [Práva správce]
Mód : Kontrola -- Datum : 11/20/2013 20:35:01
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Allmyapps ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe" startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : Allmyapps Update ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1898723742-3674319155-592853615-1001\[...]\Run : Allmyapps ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\Allmyapps.exe" startup [7][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1898723742-3674319155-592853615-1001\[...]\Run : Allmyapps Update ("C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup [7][x]) -> NALEZENO
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (200.206.14.26:80 [Country: BRAZIL (BR), City: (Unknown city)]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 2 ¤¤¤
[V1][SUSP PATH] AllmyappsUpdateTask.job : C:\Users\Tomasacus\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe - check startup [7][x] -> NALEZENO
[V2][SUSP PATH] AllmyappsUpdateTask : c:\users\tomasacus\appdata\roaming\allmyapps\allmyappsupdater.exe - check startup [7][x] -> NALEZENO
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HD322HJ ATA Device +++++
--- User ---
[MBR] c3a078dc0a9f110802fc0de0bd687c9c
[BSP] a026f864f28fd3ce5b1af5ad53716e3f : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 24999 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 51199155 | Size: 280235 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_S_11202013_203501.txt >>
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
RogueKiller V8.7.8 [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Tomasacus [Práva správce]
Mód : Odebrat -- Datum : 11/28/2013 18:48:03
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][ROGUE ST] HKLM\[...]\Run : 20131121 (C:\Program Files\AVAST Software\Avast\setup\emupdate\ef4f4dd5-8605-43f3-848e-bdd760435517.exe /check) -> VYMAZÁNO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Tomasacus [Práva správce]
Mód : Odebrat -- Datum : 11/28/2013 18:48:03
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][ROGUE ST] HKLM\[...]\Run : 20131121 (C:\Program Files\AVAST Software\Avast\setup\emupdate\ef4f4dd5-8605-43f3-848e-bdd760435517.exe /check) -> VYMAZÁNO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
¤¤¤ Kontrola MBR: ¤¤¤
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
-
- Level 3
- Příspěvky: 457
- Registrován: červenec 10
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
18:49:24.0969 1116 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:49:29.0805 1116 ============================================================
18:49:29.0805 1116 Current date / time: 2013/11/28 18:49:29.0805
18:49:29.0805 1116 SystemInfo:
18:49:29.0805 1116
18:49:29.0805 1116 OS Version: 6.1.7601 ServicePack: 1.0
18:49:29.0805 1116 Product type: Workstation
18:49:29.0805 1116 ComputerName: TOMASACUS-PC
18:49:29.0805 1116 UserName: Tomasacus
18:49:29.0805 1116 Windows directory: C:\Windows
18:49:29.0805 1116 System windows directory: C:\Windows
18:49:29.0805 1116 Processor architecture: Intel x86
18:49:29.0805 1116 Number of processors: 4
18:49:29.0805 1116 Page size: 0x1000
18:49:29.0805 1116 Boot type: Normal boot
18:49:29.0805 1116 ============================================================
18:49:31.0116 1116 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:49:31.0131 1116 ============================================================
18:49:31.0131 1116 \Device\Harddisk0\DR0:
18:49:31.0147 1116 MBR partitions:
18:49:31.0147 1116 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x30D3C74
18:49:31.0162 1116 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x30D3CF2, BlocksNum 0x22355B0E
18:49:31.0162 1116 ============================================================
18:49:31.0194 1116 D: <-> \Device\Harddisk0\DR0\Partition2
18:49:31.0287 1116 C: <-> \Device\Harddisk0\DR0\Partition1
18:49:31.0287 1116 ============================================================
18:49:31.0287 1116 Initialize success
18:49:31.0287 1116 ============================================================
18:49:34.0204 5808 ============================================================
18:49:34.0204 5808 Scan started
18:49:34.0204 5808 Mode: Manual;
18:49:34.0204 5808 ============================================================
18:49:35.0094 5808 ================ Scan system memory ==============
18:49:37.0075 5808 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:49:37.0075 5808 cdrom - ok
18:49:37.0106 5808 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
18:49:37.0106 5808 CertPropSvc - ok
18:49:37.0137 5808 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:49:37.0137 5808 circlass - ok
18:49:37.0153 5808 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
18:49:37.0169 5808 CLFS - ok
18:49:37.0184 5808 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:49:37.0200 5808 clr_optimization_v2.0.50727_32 - ok
18:49:37.0247 5808 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:49:37.0262 5808 clr_optimization_v4.0.30319_32 - ok
18:49:37.0278 5808 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:49:37.0278 5808 CmBatt - ok
18:49:37.0293 5808 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:49:37.0293 5808 cmdide - ok
18:49:37.0309 5808 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
18:49:37.0309 5808 CNG - ok
18:49:37.0325 5808 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:49:37.0325 5808 Compbatt - ok
18:49:37.0356 5808 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:49:37.0356 5808 CompositeBus - ok
18:49:37.0371 5808 COMSysApp - ok
18:49:37.0387 5808 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:49:37.0387 5808 crcdisk - ok
18:49:37.0418 5808 [ 3897DFF247D9ED0006190349DE264E14 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:49:37.0418 5808 CryptSvc - ok
18:49:37.0449 5808 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
18:49:37.0449 5808 CSC - ok
18:49:37.0465 5808 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
18:49:37.0465 5808 CscService - ok
18:49:37.0496 5808 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
18:49:37.0496 5808 DcomLaunch - ok
18:49:37.0543 5808 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
18:49:37.0543 5808 defragsvc - ok
18:49:37.0574 5808 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:49:37.0574 5808 DfsC - ok
18:49:37.0605 5808 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:49:37.0605 5808 Dhcp - ok
18:49:37.0621 5808 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
18:49:37.0621 5808 discache - ok
18:49:37.0652 5808 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:49:37.0652 5808 Disk - ok
18:49:37.0668 5808 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:49:37.0683 5808 Dnscache - ok
18:49:37.0699 5808 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
18:49:37.0715 5808 dot3svc - ok
18:49:37.0715 5808 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
18:49:37.0730 5808 DPS - ok
18:49:37.0746 5808 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:49:37.0746 5808 drmkaud - ok
18:49:37.0793 5808 [ 651554E483712B708EDE864D0CA1AA73 ] DrvAgent32 C:\Windows\system32\Drivers\DrvAgent32.sys
18:49:37.0793 5808 DrvAgent32 - ok
18:49:37.0839 5808 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
18:49:37.0839 5808 dtsoftbus01 - ok
18:49:37.0871 5808 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:49:37.0871 5808 DXGKrnl - ok
18:49:37.0902 5808 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
18:49:37.0902 5808 EapHost - ok
18:49:37.0964 5808 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
18:49:37.0980 5808 ebdrv - ok
18:49:38.0011 5808 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
18:49:38.0027 5808 EFS - ok
18:49:38.0073 5808 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:49:38.0089 5808 ehRecvr - ok
18:49:38.0105 5808 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
18:49:38.0105 5808 ehSched - ok
18:49:38.0120 5808 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:49:38.0136 5808 elxstor - ok
18:49:38.0151 5808 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:49:38.0151 5808 ErrDev - ok
18:49:38.0183 5808 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
18:49:38.0183 5808 EventSystem - ok
18:49:38.0214 5808 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
18:49:38.0214 5808 exfat - ok
18:49:38.0245 5808 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:49:38.0245 5808 fastfat - ok
18:49:38.0276 5808 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
18:49:38.0276 5808 Fax - ok
18:49:38.0292 5808 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:49:38.0292 5808 fdc - ok
18:49:38.0307 5808 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
18:49:38.0323 5808 fdPHost - ok
18:49:38.0323 5808 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
18:49:38.0323 5808 FDResPub - ok
18:49:38.0339 5808 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:49:38.0339 5808 FileInfo - ok
18:49:38.0354 5808 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:49:38.0354 5808 Filetrace - ok
18:49:38.0370 5808 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:49:38.0370 5808 flpydisk - ok
18:49:38.0385 5808 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:49:38.0385 5808 FltMgr - ok
18:49:38.0432 5808 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
18:49:38.0432 5808 FontCache - ok
18:49:38.0495 5808 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:49:38.0495 5808 FontCache3.0.0.0 - ok
18:49:38.0510 5808 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:49:38.0510 5808 FsDepends - ok
18:49:38.0541 5808 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:49:38.0541 5808 Fs_Rec - ok
18:49:38.0557 5808 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:49:38.0557 5808 fvevol - ok
18:49:38.0588 5808 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:49:38.0588 5808 gagp30kx - ok
18:49:38.0619 5808 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
18:49:38.0619 5808 gpsvc - ok
18:49:38.0651 5808 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:49:38.0651 5808 hcw85cir - ok
18:49:38.0697 5808 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:49:38.0697 5808 HdAudAddService - ok
18:49:38.0713 5808 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:49:38.0713 5808 HDAudBus - ok
18:49:38.0729 5808 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:49:38.0729 5808 HidBatt - ok
18:49:38.0744 5808 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:49:38.0744 5808 HidBth - ok
18:49:38.0775 5808 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:49:38.0775 5808 HidIr - ok
18:49:38.0791 5808 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
18:49:38.0807 5808 hidserv - ok
18:49:38.0838 5808 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:49:38.0838 5808 HidUsb - ok
18:49:38.0869 5808 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:49:38.0869 5808 hkmsvc - ok
18:49:38.0900 5808 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:49:38.0900 5808 HomeGroupListener - ok
18:49:38.0916 5808 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:49:38.0931 5808 HomeGroupProvider - ok
18:49:38.0947 5808 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:49:38.0947 5808 HpSAMD - ok
18:49:38.0994 5808 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:49:38.0994 5808 HTTP - ok
18:49:39.0009 5808 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:49:39.0025 5808 hwpolicy - ok
18:49:39.0056 5808 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:49:39.0056 5808 i8042prt - ok
18:49:39.0072 5808 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:49:39.0072 5808 iaStorV - ok
18:49:39.0134 5808 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:49:39.0134 5808 idsvc - ok
18:49:39.0165 5808 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:49:39.0165 5808 iirsp - ok
18:49:39.0197 5808 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
18:49:39.0197 5808 IKEEXT - ok
18:49:39.0290 5808 [ B35F19AFF279E08B567B281FB2E94291 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
18:49:39.0306 5808 IntcAzAudAddService - ok
18:49:39.0321 5808 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
18:49:39.0321 5808 intelide - ok
18:49:39.0337 5808 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:49:39.0337 5808 intelppm - ok
18:49:39.0353 5808 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:49:39.0368 5808 IPBusEnum - ok
18:49:39.0384 5808 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:49:39.0384 5808 IpFilterDriver - ok
18:49:39.0415 5808 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:49:39.0415 5808 iphlpsvc - ok
18:49:39.0446 5808 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:49:39.0446 5808 IPMIDRV - ok
18:49:39.0462 5808 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:49:39.0462 5808 IPNAT - ok
18:49:39.0493 5808 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:49:39.0493 5808 IRENUM - ok
18:49:39.0509 5808 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:49:39.0509 5808 isapnp - ok
18:49:39.0524 5808 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:49:39.0524 5808 iScsiPrt - ok
18:49:39.0555 5808 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:49:39.0555 5808 kbdclass - ok
18:49:39.0587 5808 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:49:39.0587 5808 kbdhid - ok
18:49:39.0602 5808 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
18:49:39.0602 5808 KeyIso - ok
18:49:39.0633 5808 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:49:39.0633 5808 KSecDD - ok
18:49:39.0649 5808 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:49:39.0649 5808 KSecPkg - ok
18:49:39.0680 5808 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
18:49:39.0680 5808 KtmRm - ok
18:49:39.0696 5808 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
18:49:39.0711 5808 LanmanServer - ok
18:49:39.0727 5808 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:49:39.0727 5808 LanmanWorkstation - ok
18:49:39.0774 5808 [ 975B6CF65F44E95883F3855BAE8CECAF ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
18:49:39.0774 5808 lirsgt - ok
18:49:39.0789 5808 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:49:39.0789 5808 lltdio - ok
18:49:39.0805 5808 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:49:39.0821 5808 lltdsvc - ok
18:49:39.0821 5808 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
18:49:39.0821 5808 lmhosts - ok
18:49:39.0852 5808 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:49:39.0852 5808 LSI_FC - ok
18:49:39.0867 5808 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:49:39.0867 5808 LSI_SAS - ok
18:49:39.0883 5808 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:49:39.0883 5808 LSI_SAS2 - ok
18:49:39.0899 5808 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:49:39.0899 5808 LSI_SCSI - ok
18:49:39.0914 5808 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
18:49:39.0914 5808 luafv - ok
18:49:39.0945 5808 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
18:49:39.0945 5808 MBAMProtector - ok
18:49:39.0992 5808 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:49:39.0992 5808 MBAMScheduler - ok
18:49:40.0023 5808 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:49:40.0023 5808 MBAMService - ok
18:49:40.0055 5808 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:49:40.0055 5808 Mcx2Svc - ok
18:49:40.0070 5808 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:49:40.0070 5808 megasas - ok
18:49:40.0086 5808 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:49:40.0101 5808 MegaSR - ok
18:49:40.0117 5808 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
18:49:40.0117 5808 MMCSS - ok
18:49:40.0117 5808 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
18:49:40.0133 5808 Modem - ok
18:49:40.0148 5808 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:49:40.0148 5808 monitor - ok
18:49:40.0179 5808 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:49:40.0195 5808 mouclass - ok
18:49:40.0211 5808 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:49:40.0211 5808 mouhid - ok
18:49:40.0242 5808 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:49:40.0242 5808 mountmgr - ok
18:49:40.0273 5808 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
18:49:40.0273 5808 mpio - ok
18:49:40.0289 5808 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:49:40.0304 5808 mpsdrv - ok
18:49:40.0382 5808 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:49:40.0413 5808 MpsSvc - ok
18:49:40.0429 5808 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:49:40.0429 5808 MRxDAV - ok
18:49:40.0476 5808 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:49:40.0476 5808 mrxsmb - ok
18:49:40.0507 5808 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:49:40.0507 5808 mrxsmb10 - ok
18:49:40.0507 5808 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:49:40.0507 5808 mrxsmb20 - ok
18:49:40.0538 5808 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
18:49:40.0538 5808 msahci - ok
18:49:40.0554 5808 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:49:40.0554 5808 msdsm - ok
18:49:40.0585 5808 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
18:49:40.0585 5808 MSDTC - ok
18:49:40.0601 5808 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:49:40.0601 5808 Msfs - ok
18:49:40.0616 5808 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:49:40.0616 5808 mshidkmdf - ok
18:49:40.0632 5808 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:49:40.0632 5808 msisadrv - ok
18:49:40.0663 5808 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:49:40.0663 5808 MSiSCSI - ok
18:49:40.0663 5808 msiserver - ok
18:49:40.0694 5808 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:49:40.0694 5808 MSKSSRV - ok
18:49:40.0710 5808 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:49:40.0710 5808 MSPCLOCK - ok
18:49:40.0710 5808 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:49:40.0710 5808 MSPQM - ok
18:49:40.0725 5808 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:49:40.0725 5808 MsRPC - ok
18:49:40.0741 5808 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:49:40.0741 5808 mssmbios - ok
18:49:40.0757 5808 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:49:40.0757 5808 MSTEE - ok
18:49:40.0772 5808 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:49:40.0772 5808 MTConfig - ok
18:49:40.0788 5808 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
18:49:40.0788 5808 Mup - ok
18:49:40.0819 5808 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
18:49:40.0819 5808 napagent - ok
18:49:40.0866 5808 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:49:40.0866 5808 NativeWifiP - ok
18:49:40.0897 5808 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:49:40.0897 5808 NDIS - ok
18:49:40.0913 5808 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:49:40.0913 5808 NdisCap - ok
18:49:40.0944 5808 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:49:40.0944 5808 NdisTapi - ok
18:49:40.0959 5808 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:49:40.0959 5808 Ndisuio - ok
18:49:41.0006 5808 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:49:41.0006 5808 NdisWan - ok
18:49:41.0022 5808 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:49:41.0037 5808 NDProxy - ok
18:49:41.0037 5808 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:49:41.0053 5808 NetBIOS - ok
18:49:41.0069 5808 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:49:41.0069 5808 NetBT - ok
18:49:41.0084 5808 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
18:49:41.0084 5808 Netlogon - ok
18:49:41.0131 5808 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
18:49:41.0131 5808 Netman - ok
18:49:41.0162 5808 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
18:49:41.0162 5808 netprofm - ok
18:49:41.0193 5808 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:49:41.0193 5808 NetTcpPortSharing - ok
18:49:41.0209 5808 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:49:41.0209 5808 nfrd960 - ok
18:49:41.0240 5808 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
18:49:41.0240 5808 NlaSvc - ok
18:49:41.0256 5808 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:49:41.0256 5808 Npfs - ok
18:49:41.0287 5808 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
18:49:41.0287 5808 nsi - ok
18:49:41.0303 5808 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:49:41.0303 5808 nsiproxy - ok
18:49:41.0349 5808 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:49:41.0349 5808 Ntfs - ok
18:49:41.0365 5808 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
18:49:41.0365 5808 Null - ok
18:49:41.0537 5808 [ B69E6F70CE1151C8D62ABC9DEF64DFBE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
18:49:41.0583 5808 nvlddmkm - ok
18:49:41.0615 5808 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:49:41.0615 5808 nvraid - ok
18:49:41.0630 5808 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:49:41.0646 5808 nvstor - ok
18:49:41.0693 5808 [ E4284FCF99FEA13A7E1836F87AE356F6 ] nvsvc C:\Windows\system32\nvvsvc.exe
18:49:41.0708 5808 nvsvc - ok
18:49:41.0771 5808 [ 03E60E0BFA53ED15DC984FA34B44BB0F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
18:49:41.0771 5808 nvUpdatusService - ok
18:49:41.0802 5808 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:49:41.0802 5808 nv_agp - ok
18:49:41.0864 5808 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:49:41.0880 5808 odserv - ok
18:49:41.0895 5808 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:49:41.0911 5808 ohci1394 - ok
18:49:41.0927 5808 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:49:41.0942 5808 ose - ok
18:49:42.0067 5808 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:49:42.0114 5808 osppsvc - ok
18:49:42.0145 5808 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:49:42.0161 5808 p2pimsvc - ok
18:49:42.0176 5808 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
18:49:42.0192 5808 p2psvc - ok
18:49:42.0223 5808 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:49:42.0223 5808 Parport - ok
18:49:42.0254 5808 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:49:42.0254 5808 partmgr - ok
18:49:42.0270 5808 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:49:42.0270 5808 Parvdm - ok
18:49:42.0270 5808 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:49:42.0285 5808 PcaSvc - ok
18:49:42.0301 5808 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
18:49:42.0301 5808 pci - ok
18:49:42.0332 5808 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
18:49:42.0332 5808 pciide - ok
18:49:42.0348 5808 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:49:42.0348 5808 pcmcia - ok
18:49:42.0348 5808 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
18:49:42.0348 5808 pcw - ok
18:49:42.0395 5808 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:49:42.0395 5808 PEAUTH - ok
18:49:42.0441 5808 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
18:49:42.0457 5808 PeerDistSvc - ok
18:49:42.0519 5808 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
18:49:42.0535 5808 pla - ok
18:49:42.0566 5808 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:49:42.0566 5808 PlugPlay - ok
18:49:42.0613 5808 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
18:49:42.0613 5808 PnkBstrA - ok
18:49:42.0629 5808 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:49:42.0629 5808 PNRPAutoReg - ok
18:49:42.0660 5808 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:49:42.0675 5808 PNRPsvc - ok
18:49:42.0707 5808 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:49:42.0707 5808 PolicyAgent - ok
18:49:42.0722 5808 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
18:49:42.0738 5808 Power - ok
18:49:42.0753 5808 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:49:42.0769 5808 PptpMiniport - ok
18:49:42.0785 5808 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:49:42.0785 5808 Processor - ok
18:49:42.0816 5808 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
18:49:42.0831 5808 ProfSvc - ok
18:49:42.0847 5808 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:49:42.0847 5808 ProtectedStorage - ok
18:49:42.0863 5808 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:49:42.0863 5808 Psched - ok
18:49:42.0909 5808 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:49:42.0909 5808 ql2300 - ok
18:49:42.0925 5808 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:49:42.0941 5808 ql40xx - ok
18:49:42.0972 5808 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
18:49:42.0972 5808 QWAVE - ok
18:49:42.0987 5808 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:49:42.0987 5808 QWAVEdrv - ok
18:49:43.0003 5808 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:49:43.0003 5808 RasAcd - ok
18:49:43.0019 5808 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:49:43.0019 5808 RasAgileVpn - ok
18:49:43.0050 5808 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
18:49:43.0050 5808 RasAuto - ok
18:49:43.0065 5808 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:49:43.0065 5808 Rasl2tp - ok
18:49:43.0097 5808 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
18:49:43.0112 5808 RasMan - ok
18:49:43.0112 5808 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:49:43.0112 5808 RasPppoe - ok
18:49:43.0128 5808 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:49:43.0128 5808 RasSstp - ok
18:49:43.0159 5808 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:49:43.0159 5808 rdbss - ok
18:49:43.0175 5808 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:49:43.0175 5808 rdpbus - ok
18:49:43.0206 5808 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:49:43.0206 5808 RDPCDD - ok
18:49:43.0221 5808 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
18:49:43.0221 5808 RDPDR - ok
18:49:43.0237 5808 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:49:43.0237 5808 RDPENCDD - ok
18:49:43.0253 5808 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:49:43.0253 5808 RDPREFMP - ok
18:49:43.0284 5808 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
18:49:43.0284 5808 RdpVideoMiniport - ok
18:49:43.0315 5808 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:49:43.0315 5808 RDPWD - ok
18:49:43.0331 5808 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:49:43.0346 5808 rdyboost - ok
18:49:43.0362 5808 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
18:49:43.0377 5808 RemoteAccess - ok
18:49:43.0393 5808 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:49:43.0393 5808 RemoteRegistry - ok
18:49:43.0424 5808 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:49:43.0424 5808 RpcEptMapper - ok
18:49:43.0440 5808 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
18:49:43.0440 5808 RpcLocator - ok
18:49:43.0471 5808 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
18:49:43.0471 5808 RpcSs - ok
18:49:43.0487 5808 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:49:43.0487 5808 rspndr - ok
18:49:43.0518 5808 [ EB7BFAED454FD2A280B9EDF05F5BCBE9 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
18:49:43.0518 5808 RTL8167 - ok
18:49:43.0533 5808 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
18:49:43.0549 5808 s3cap - ok
18:49:43.0549 5808 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
18:49:43.0565 5808 SamSs - ok
18:49:43.0596 5808 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:49:43.0596 5808 sbp2port - ok
18:49:43.0643 5808 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:49:43.0643 5808 SCardSvr - ok
18:49:43.0658 5808 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:49:43.0658 5808 scfilter - ok
18:49:43.0705 5808 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
18:49:43.0705 5808 Schedule - ok
18:49:43.0721 5808 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:49:43.0721 5808 SCPolicySvc - ok
18:49:43.0767 5808 [ A689D522EEDF89401E1DA2FE883AA7EC ] SCREAMINGBDRIVER C:\Windows\system32\drivers\ScreamingBAudio.sys
18:49:43.0767 5808 SCREAMINGBDRIVER - ok
18:49:43.0783 5808 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:49:43.0783 5808 SDRSVC - ok
18:49:43.0814 5808 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:49:43.0814 5808 secdrv - ok
18:49:43.0830 5808 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
18:49:43.0830 5808 seclogon - ok
18:49:43.0845 5808 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
18:49:43.0861 5808 SENS - ok
18:49:43.0877 5808 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:49:43.0892 5808 SensrSvc - ok
18:49:43.0908 5808 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:49:43.0908 5808 Serenum - ok
18:49:43.0923 5808 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:49:43.0923 5808 Serial - ok
18:49:43.0939 5808 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:49:43.0939 5808 sermouse - ok
18:49:43.0970 5808 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
18:49:43.0970 5808 SessionEnv - ok
18:49:43.0986 5808 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:49:43.0986 5808 sffdisk - ok
18:49:44.0001 5808 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:49:44.0001 5808 sffp_mmc - ok
18:49:44.0017 5808 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:49:44.0017 5808 sffp_sd - ok
18:49:44.0033 5808 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:49:44.0033 5808 sfloppy - ok
18:49:44.0064 5808 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:49:44.0064 5808 SharedAccess - ok
18:49:44.0095 5808 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:49:44.0095 5808 ShellHWDetection - ok
18:49:44.0111 5808 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:49:44.0111 5808 sisagp - ok
18:49:44.0142 5808 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:49:44.0142 5808 SiSRaid2 - ok
18:49:44.0157 5808 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:49:44.0157 5808 SiSRaid4 - ok
18:49:44.0220 5808 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:49:44.0220 5808 SkypeUpdate - ok
18:49:44.0235 5808 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:49:44.0235 5808 Smb - ok
18:49:44.0282 5808 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:49:44.0298 5808 SNMPTRAP - ok
18:49:44.0313 5808 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
18:49:44.0313 5808 spldr - ok
18:49:44.0360 5808 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
18:49:44.0360 5808 Spooler - ok
18:49:44.0423 5808 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
18:49:44.0454 5808 sppsvc - ok
18:49:44.0469 5808 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:49:44.0485 5808 sppuinotify - ok
18:49:44.0501 5808 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:49:44.0516 5808 srv - ok
18:49:44.0532 5808 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:49:44.0532 5808 srv2 - ok
18:49:44.0547 5808 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:49:44.0547 5808 srvnet - ok
18:49:44.0563 5808 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:49:44.0579 5808 SSDPSRV - ok
18:49:44.0594 5808 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:49:44.0594 5808 SstpSvc - ok
18:49:44.0657 5808 [ DB0768632C680B7C0D3AA92D80416893 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
18:49:44.0672 5808 Steam Client Service - ok
18:49:44.0719 5808 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
18:49:44.0719 5808 Stereo Service - ok
18:49:44.0750 5808 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:49:44.0750 5808 stexstor - ok
18:49:44.0781 5808 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
18:49:44.0797 5808 StiSvc - ok
18:49:44.0828 5808 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
18:49:44.0828 5808 storflt - ok
18:49:44.0859 5808 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
18:49:44.0859 5808 storvsc - ok
18:49:44.0875 5808 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
18:49:44.0875 5808 swenum - ok
18:49:44.0891 5808 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
18:49:44.0906 5808 swprv - ok
18:49:44.0922 5808 Synth3dVsc - ok
18:49:44.0953 5808 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
18:49:44.0969 5808 SysMain - ok
18:49:44.0984 5808 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:49:44.0984 5808 TabletInputService - ok
18:49:45.0015 5808 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
18:49:45.0015 5808 TapiSrv - ok
18:49:45.0047 5808 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
18:49:45.0047 5808 TBS - ok
18:49:45.0093 5808 [ D32FDAC73FCD76B85389C39BC1087F2A ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:49:45.0109 5808 Tcpip - ok
18:49:45.0125 5808 [ D32FDAC73FCD76B85389C39BC1087F2A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:49:45.0140 5808 TCPIP6 - ok
18:49:45.0156 5808 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:49:45.0156 5808 tcpipreg - ok
18:49:45.0187 5808 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:49:45.0187 5808 TDPIPE - ok
18:49:45.0203 5808 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:49:45.0203 5808 TDTCP - ok
18:49:45.0234 5808 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:49:45.0234 5808 tdx - ok
18:49:45.0249 5808 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:49:45.0249 5808 TermDD - ok
18:49:45.0296 5808 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
18:49:45.0296 5808 TermService - ok
18:49:45.0327 5808 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
18:49:45.0327 5808 Themes - ok
18:49:45.0327 5808 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
18:49:45.0343 5808 THREADORDER - ok
18:49:45.0374 5808 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
18:49:45.0374 5808 TrkWks - ok
18:49:45.0405 5808 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:49:45.0421 5808 TrustedInstaller - ok
18:49:45.0437 5808 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:49:45.0437 5808 tssecsrv - ok
18:49:45.0452 5808 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:49:45.0452 5808 TsUsbFlt - ok
18:49:45.0468 5808 tsusbhub - ok
18:49:45.0499 5808 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:49:45.0499 5808 tunnel - ok
18:49:45.0530 5808 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:49:45.0530 5808 uagp35 - ok
18:49:45.0546 5808 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:49:45.0546 5808 udfs - ok
18:49:45.0577 5808 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:49:45.0577 5808 UI0Detect - ok
18:49:45.0593 5808 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:49:45.0593 5808 uliagpkx - ok
18:49:45.0624 5808 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
18:49:45.0624 5808 umbus - ok
18:49:45.0639 5808 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:49:45.0639 5808 UmPass - ok
18:49:45.0686 5808 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
18:49:45.0702 5808 UmRdpService - ok
18:49:45.0733 5808 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
18:49:45.0733 5808 upnphost - ok
18:49:45.0749 5808 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:49:45.0749 5808 usbccgp - ok
18:49:45.0795 5808 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:49:45.0795 5808 usbcir - ok
18:49:45.0811 5808 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:49:45.0811 5808 usbehci - ok
18:49:45.0842 5808 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:49:45.0842 5808 usbhub - ok
18:49:45.0858 5808 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:49:45.0858 5808 usbohci - ok
18:49:45.0873 5808 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:49:45.0873 5808 usbprint - ok
18:49:45.0920 5808 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
18:49:45.0920 5808 usbscan - ok
18:49:45.0936 5808 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
18:49:45.0936 5808 USBSTOR - ok
18:49:45.0951 5808 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:49:45.0951 5808 usbuhci - ok
18:49:45.0967 5808 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
18:49:45.0967 5808 UxSms - ok
18:49:45.0983 5808 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
18:49:45.0983 5808 VaultSvc - ok
18:49:45.0998 5808 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:49:45.0998 5808 vdrvroot - ok
18:49:46.0045 5808 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
18:49:46.0045 5808 vds - ok
18:49:46.0076 5808 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:49:46.0076 5808 vga - ok
18:49:46.0092 5808 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
18:49:46.0092 5808 VgaSave - ok
18:49:46.0107 5808 VGPU - ok
18:49:46.0139 5808 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:49:46.0139 5808 vhdmp - ok
18:49:46.0154 5808 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:49:46.0154 5808 viaagp - ok
18:49:46.0185 5808 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
18:49:46.0185 5808 ViaC7 - ok
18:49:46.0201 5808 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
18:49:46.0201 5808 viaide - ok
18:49:46.0232 5808 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
18:49:46.0232 5808 vmbus - ok
18:49:46.0248 5808 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
18:49:46.0248 5808 VMBusHID - ok
18:49:46.0263 5808 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:49:46.0263 5808 volmgr - ok
18:49:46.0279 5808 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:49:46.0279 5808 volmgrx - ok
18:49:46.0295 5808 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:49:46.0295 5808 volsnap - ok
18:49:46.0326 5808 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:49:46.0326 5808 vsmraid - ok
18:49:46.0357 5808 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
18:49:46.0373 5808 VSS - ok
18:49:46.0388 5808 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
18:49:46.0388 5808 vwifibus - ok
18:49:46.0419 5808 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
18:49:46.0435 5808 W32Time - ok
18:49:46.0451 5808 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:49:46.0451 5808 WacomPen - ok
18:49:46.0482 5808 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:49:46.0482 5808 WANARP - ok
18:49:46.0482 5808 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:49:46.0482 5808 Wanarpv6 - ok
18:49:46.0544 5808 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:49:46.0560 5808 WatAdminSvc - ok
18:49:46.0591 5808 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
18:49:46.0607 5808 wbengine - ok
18:49:46.0622 5808 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:49:46.0622 5808 WbioSrvc - ok
18:49:46.0653 5808 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:49:46.0653 5808 wcncsvc - ok
18:49:46.0669 5808 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:49:46.0685 5808 WcsPlugInService - ok
18:49:46.0700 5808 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:49:46.0700 5808 Wd - ok
18:49:46.0731 5808 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:49:46.0731 5808 Wdf01000 - ok
18:49:46.0747 5808 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:49:46.0747 5808 WdiServiceHost - ok
18:49:46.0763 5808 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:49:46.0763 5808 WdiSystemHost - ok
18:49:46.0778 5808 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
18:49:46.0794 5808 WebClient - ok
18:49:46.0809 5808 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:49:46.0825 5808 Wecsvc - ok
18:49:46.0825 5808 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:49:46.0841 5808 wercplsupport - ok
18:49:46.0856 5808 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
18:49:46.0856 5808 WerSvc - ok
18:49:46.0887 5808 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:49:46.0887 5808 WfpLwf - ok
18:49:46.0903 5808 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:49:46.0903 5808 WIMMount - ok
18:49:46.0965 5808 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:49:46.0981 5808 WinDefend - ok
18:49:46.0981 5808 WinHttpAutoProxySvc - ok
18:49:47.0043 5808 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:49:47.0043 5808 Winmgmt - ok
18:49:47.0090 5808 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
18:49:47.0106 5808 WinRM - ok
18:49:47.0137 5808 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:49:47.0153 5808 WinUsb - ok
18:49:47.0184 5808 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:49:47.0199 5808 Wlansvc - ok
18:49:47.0215 5808 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:49:47.0215 5808 WmiAcpi - ok
18:49:47.0231 5808 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:49:47.0231 5808 wmiApSrv - ok
18:49:47.0277 5808 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:49:47.0293 5808 WMPNetworkSvc - ok
18:49:47.0309 5808 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:49:47.0309 5808 WPCSvc - ok
18:49:47.0340 5808 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:49:47.0340 5808 WPDBusEnum - ok
18:49:47.0355 5808 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:49:47.0355 5808 ws2ifsl - ok
18:49:47.0371 5808 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
18:49:47.0371 5808 wscsvc - ok
18:49:47.0387 5808 WSearch - ok
18:49:47.0433 5808 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
18:49:47.0465 5808 wuauserv - ok
18:49:47.0480 5808 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:49:47.0480 5808 WudfPf - ok
18:49:47.0511 5808 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:49:47.0511 5808 WUDFRd - ok
18:49:47.0543 5808 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:49:47.0543 5808 wudfsvc - ok
18:49:47.0574 5808 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
18:49:47.0589 5808 WwanSvc - ok
18:49:47.0589 5808 ================ Scan global ===============================
18:49:47.0621 5808 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
18:49:47.0636 5808 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
18:49:47.0652 5808 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
18:49:47.0683 5808 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
18:49:47.0699 5808 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
18:49:47.0699 5808 [Global] - ok
18:49:47.0699 5808 ================ Scan MBR ==================================
18:49:47.0714 5808 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
18:49:48.0042 5808 \Device\Harddisk0\DR0 - ok
18:49:48.0042 5808 ================ Scan VBR ==================================
18:49:48.0042 5808 [ 1EF2E35208D508E010BD69E2D85FDE05 ] \Device\Harddisk0\DR0\Partition1
18:49:48.0057 5808 \Device\Harddisk0\DR0\Partition1 - ok
18:49:48.0073 5808 [ 9735078439B7E1771EFF8E5EDA4893BC ] \Device\Harddisk0\DR0\Partition2
18:49:48.0073 5808 \Device\Harddisk0\DR0\Partition2 - ok
18:49:48.0073 5808 ============================================================
18:49:48.0073 5808 Scan finished
18:49:48.0073 5808 ============================================================
18:49:48.0073 4400 Detected object count: 0
18:49:48.0073 4400 Actual detected object count: 0
18:49:29.0805 1116 ============================================================
18:49:29.0805 1116 Current date / time: 2013/11/28 18:49:29.0805
18:49:29.0805 1116 SystemInfo:
18:49:29.0805 1116
18:49:29.0805 1116 OS Version: 6.1.7601 ServicePack: 1.0
18:49:29.0805 1116 Product type: Workstation
18:49:29.0805 1116 ComputerName: TOMASACUS-PC
18:49:29.0805 1116 UserName: Tomasacus
18:49:29.0805 1116 Windows directory: C:\Windows
18:49:29.0805 1116 System windows directory: C:\Windows
18:49:29.0805 1116 Processor architecture: Intel x86
18:49:29.0805 1116 Number of processors: 4
18:49:29.0805 1116 Page size: 0x1000
18:49:29.0805 1116 Boot type: Normal boot
18:49:29.0805 1116 ============================================================
18:49:31.0116 1116 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:49:31.0131 1116 ============================================================
18:49:31.0131 1116 \Device\Harddisk0\DR0:
18:49:31.0147 1116 MBR partitions:
18:49:31.0147 1116 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x30D3C74
18:49:31.0162 1116 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x30D3CF2, BlocksNum 0x22355B0E
18:49:31.0162 1116 ============================================================
18:49:31.0194 1116 D: <-> \Device\Harddisk0\DR0\Partition2
18:49:31.0287 1116 C: <-> \Device\Harddisk0\DR0\Partition1
18:49:31.0287 1116 ============================================================
18:49:31.0287 1116 Initialize success
18:49:31.0287 1116 ============================================================
18:49:34.0204 5808 ============================================================
18:49:34.0204 5808 Scan started
18:49:34.0204 5808 Mode: Manual;
18:49:34.0204 5808 ============================================================
18:49:35.0094 5808 ================ Scan system memory ==============
18:49:37.0075 5808 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:49:37.0075 5808 cdrom - ok
18:49:37.0106 5808 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
18:49:37.0106 5808 CertPropSvc - ok
18:49:37.0137 5808 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:49:37.0137 5808 circlass - ok
18:49:37.0153 5808 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
18:49:37.0169 5808 CLFS - ok
18:49:37.0184 5808 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:49:37.0200 5808 clr_optimization_v2.0.50727_32 - ok
18:49:37.0247 5808 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:49:37.0262 5808 clr_optimization_v4.0.30319_32 - ok
18:49:37.0278 5808 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:49:37.0278 5808 CmBatt - ok
18:49:37.0293 5808 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:49:37.0293 5808 cmdide - ok
18:49:37.0309 5808 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
18:49:37.0309 5808 CNG - ok
18:49:37.0325 5808 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:49:37.0325 5808 Compbatt - ok
18:49:37.0356 5808 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:49:37.0356 5808 CompositeBus - ok
18:49:37.0371 5808 COMSysApp - ok
18:49:37.0387 5808 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:49:37.0387 5808 crcdisk - ok
18:49:37.0418 5808 [ 3897DFF247D9ED0006190349DE264E14 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:49:37.0418 5808 CryptSvc - ok
18:49:37.0449 5808 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
18:49:37.0449 5808 CSC - ok
18:49:37.0465 5808 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
18:49:37.0465 5808 CscService - ok
18:49:37.0496 5808 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
18:49:37.0496 5808 DcomLaunch - ok
18:49:37.0543 5808 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
18:49:37.0543 5808 defragsvc - ok
18:49:37.0574 5808 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:49:37.0574 5808 DfsC - ok
18:49:37.0605 5808 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:49:37.0605 5808 Dhcp - ok
18:49:37.0621 5808 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
18:49:37.0621 5808 discache - ok
18:49:37.0652 5808 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:49:37.0652 5808 Disk - ok
18:49:37.0668 5808 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:49:37.0683 5808 Dnscache - ok
18:49:37.0699 5808 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
18:49:37.0715 5808 dot3svc - ok
18:49:37.0715 5808 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
18:49:37.0730 5808 DPS - ok
18:49:37.0746 5808 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:49:37.0746 5808 drmkaud - ok
18:49:37.0793 5808 [ 651554E483712B708EDE864D0CA1AA73 ] DrvAgent32 C:\Windows\system32\Drivers\DrvAgent32.sys
18:49:37.0793 5808 DrvAgent32 - ok
18:49:37.0839 5808 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
18:49:37.0839 5808 dtsoftbus01 - ok
18:49:37.0871 5808 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:49:37.0871 5808 DXGKrnl - ok
18:49:37.0902 5808 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
18:49:37.0902 5808 EapHost - ok
18:49:37.0964 5808 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
18:49:37.0980 5808 ebdrv - ok
18:49:38.0011 5808 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
18:49:38.0027 5808 EFS - ok
18:49:38.0073 5808 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:49:38.0089 5808 ehRecvr - ok
18:49:38.0105 5808 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
18:49:38.0105 5808 ehSched - ok
18:49:38.0120 5808 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:49:38.0136 5808 elxstor - ok
18:49:38.0151 5808 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:49:38.0151 5808 ErrDev - ok
18:49:38.0183 5808 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
18:49:38.0183 5808 EventSystem - ok
18:49:38.0214 5808 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
18:49:38.0214 5808 exfat - ok
18:49:38.0245 5808 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:49:38.0245 5808 fastfat - ok
18:49:38.0276 5808 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
18:49:38.0276 5808 Fax - ok
18:49:38.0292 5808 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:49:38.0292 5808 fdc - ok
18:49:38.0307 5808 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
18:49:38.0323 5808 fdPHost - ok
18:49:38.0323 5808 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
18:49:38.0323 5808 FDResPub - ok
18:49:38.0339 5808 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:49:38.0339 5808 FileInfo - ok
18:49:38.0354 5808 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:49:38.0354 5808 Filetrace - ok
18:49:38.0370 5808 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:49:38.0370 5808 flpydisk - ok
18:49:38.0385 5808 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:49:38.0385 5808 FltMgr - ok
18:49:38.0432 5808 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
18:49:38.0432 5808 FontCache - ok
18:49:38.0495 5808 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:49:38.0495 5808 FontCache3.0.0.0 - ok
18:49:38.0510 5808 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:49:38.0510 5808 FsDepends - ok
18:49:38.0541 5808 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:49:38.0541 5808 Fs_Rec - ok
18:49:38.0557 5808 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:49:38.0557 5808 fvevol - ok
18:49:38.0588 5808 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:49:38.0588 5808 gagp30kx - ok
18:49:38.0619 5808 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
18:49:38.0619 5808 gpsvc - ok
18:49:38.0651 5808 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:49:38.0651 5808 hcw85cir - ok
18:49:38.0697 5808 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:49:38.0697 5808 HdAudAddService - ok
18:49:38.0713 5808 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:49:38.0713 5808 HDAudBus - ok
18:49:38.0729 5808 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:49:38.0729 5808 HidBatt - ok
18:49:38.0744 5808 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:49:38.0744 5808 HidBth - ok
18:49:38.0775 5808 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:49:38.0775 5808 HidIr - ok
18:49:38.0791 5808 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
18:49:38.0807 5808 hidserv - ok
18:49:38.0838 5808 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:49:38.0838 5808 HidUsb - ok
18:49:38.0869 5808 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:49:38.0869 5808 hkmsvc - ok
18:49:38.0900 5808 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:49:38.0900 5808 HomeGroupListener - ok
18:49:38.0916 5808 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:49:38.0931 5808 HomeGroupProvider - ok
18:49:38.0947 5808 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:49:38.0947 5808 HpSAMD - ok
18:49:38.0994 5808 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:49:38.0994 5808 HTTP - ok
18:49:39.0009 5808 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:49:39.0025 5808 hwpolicy - ok
18:49:39.0056 5808 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:49:39.0056 5808 i8042prt - ok
18:49:39.0072 5808 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:49:39.0072 5808 iaStorV - ok
18:49:39.0134 5808 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:49:39.0134 5808 idsvc - ok
18:49:39.0165 5808 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:49:39.0165 5808 iirsp - ok
18:49:39.0197 5808 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
18:49:39.0197 5808 IKEEXT - ok
18:49:39.0290 5808 [ B35F19AFF279E08B567B281FB2E94291 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
18:49:39.0306 5808 IntcAzAudAddService - ok
18:49:39.0321 5808 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
18:49:39.0321 5808 intelide - ok
18:49:39.0337 5808 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:49:39.0337 5808 intelppm - ok
18:49:39.0353 5808 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:49:39.0368 5808 IPBusEnum - ok
18:49:39.0384 5808 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:49:39.0384 5808 IpFilterDriver - ok
18:49:39.0415 5808 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:49:39.0415 5808 iphlpsvc - ok
18:49:39.0446 5808 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:49:39.0446 5808 IPMIDRV - ok
18:49:39.0462 5808 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:49:39.0462 5808 IPNAT - ok
18:49:39.0493 5808 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:49:39.0493 5808 IRENUM - ok
18:49:39.0509 5808 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:49:39.0509 5808 isapnp - ok
18:49:39.0524 5808 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:49:39.0524 5808 iScsiPrt - ok
18:49:39.0555 5808 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:49:39.0555 5808 kbdclass - ok
18:49:39.0587 5808 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:49:39.0587 5808 kbdhid - ok
18:49:39.0602 5808 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
18:49:39.0602 5808 KeyIso - ok
18:49:39.0633 5808 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:49:39.0633 5808 KSecDD - ok
18:49:39.0649 5808 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:49:39.0649 5808 KSecPkg - ok
18:49:39.0680 5808 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
18:49:39.0680 5808 KtmRm - ok
18:49:39.0696 5808 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
18:49:39.0711 5808 LanmanServer - ok
18:49:39.0727 5808 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:49:39.0727 5808 LanmanWorkstation - ok
18:49:39.0774 5808 [ 975B6CF65F44E95883F3855BAE8CECAF ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
18:49:39.0774 5808 lirsgt - ok
18:49:39.0789 5808 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:49:39.0789 5808 lltdio - ok
18:49:39.0805 5808 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:49:39.0821 5808 lltdsvc - ok
18:49:39.0821 5808 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
18:49:39.0821 5808 lmhosts - ok
18:49:39.0852 5808 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:49:39.0852 5808 LSI_FC - ok
18:49:39.0867 5808 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:49:39.0867 5808 LSI_SAS - ok
18:49:39.0883 5808 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:49:39.0883 5808 LSI_SAS2 - ok
18:49:39.0899 5808 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:49:39.0899 5808 LSI_SCSI - ok
18:49:39.0914 5808 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
18:49:39.0914 5808 luafv - ok
18:49:39.0945 5808 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
18:49:39.0945 5808 MBAMProtector - ok
18:49:39.0992 5808 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:49:39.0992 5808 MBAMScheduler - ok
18:49:40.0023 5808 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:49:40.0023 5808 MBAMService - ok
18:49:40.0055 5808 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:49:40.0055 5808 Mcx2Svc - ok
18:49:40.0070 5808 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:49:40.0070 5808 megasas - ok
18:49:40.0086 5808 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:49:40.0101 5808 MegaSR - ok
18:49:40.0117 5808 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
18:49:40.0117 5808 MMCSS - ok
18:49:40.0117 5808 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
18:49:40.0133 5808 Modem - ok
18:49:40.0148 5808 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:49:40.0148 5808 monitor - ok
18:49:40.0179 5808 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:49:40.0195 5808 mouclass - ok
18:49:40.0211 5808 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:49:40.0211 5808 mouhid - ok
18:49:40.0242 5808 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:49:40.0242 5808 mountmgr - ok
18:49:40.0273 5808 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
18:49:40.0273 5808 mpio - ok
18:49:40.0289 5808 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:49:40.0304 5808 mpsdrv - ok
18:49:40.0382 5808 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:49:40.0413 5808 MpsSvc - ok
18:49:40.0429 5808 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:49:40.0429 5808 MRxDAV - ok
18:49:40.0476 5808 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:49:40.0476 5808 mrxsmb - ok
18:49:40.0507 5808 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:49:40.0507 5808 mrxsmb10 - ok
18:49:40.0507 5808 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:49:40.0507 5808 mrxsmb20 - ok
18:49:40.0538 5808 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
18:49:40.0538 5808 msahci - ok
18:49:40.0554 5808 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:49:40.0554 5808 msdsm - ok
18:49:40.0585 5808 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
18:49:40.0585 5808 MSDTC - ok
18:49:40.0601 5808 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:49:40.0601 5808 Msfs - ok
18:49:40.0616 5808 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:49:40.0616 5808 mshidkmdf - ok
18:49:40.0632 5808 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:49:40.0632 5808 msisadrv - ok
18:49:40.0663 5808 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:49:40.0663 5808 MSiSCSI - ok
18:49:40.0663 5808 msiserver - ok
18:49:40.0694 5808 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:49:40.0694 5808 MSKSSRV - ok
18:49:40.0710 5808 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:49:40.0710 5808 MSPCLOCK - ok
18:49:40.0710 5808 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:49:40.0710 5808 MSPQM - ok
18:49:40.0725 5808 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:49:40.0725 5808 MsRPC - ok
18:49:40.0741 5808 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:49:40.0741 5808 mssmbios - ok
18:49:40.0757 5808 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:49:40.0757 5808 MSTEE - ok
18:49:40.0772 5808 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:49:40.0772 5808 MTConfig - ok
18:49:40.0788 5808 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
18:49:40.0788 5808 Mup - ok
18:49:40.0819 5808 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
18:49:40.0819 5808 napagent - ok
18:49:40.0866 5808 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:49:40.0866 5808 NativeWifiP - ok
18:49:40.0897 5808 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:49:40.0897 5808 NDIS - ok
18:49:40.0913 5808 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:49:40.0913 5808 NdisCap - ok
18:49:40.0944 5808 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:49:40.0944 5808 NdisTapi - ok
18:49:40.0959 5808 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:49:40.0959 5808 Ndisuio - ok
18:49:41.0006 5808 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:49:41.0006 5808 NdisWan - ok
18:49:41.0022 5808 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:49:41.0037 5808 NDProxy - ok
18:49:41.0037 5808 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:49:41.0053 5808 NetBIOS - ok
18:49:41.0069 5808 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:49:41.0069 5808 NetBT - ok
18:49:41.0084 5808 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
18:49:41.0084 5808 Netlogon - ok
18:49:41.0131 5808 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
18:49:41.0131 5808 Netman - ok
18:49:41.0162 5808 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
18:49:41.0162 5808 netprofm - ok
18:49:41.0193 5808 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:49:41.0193 5808 NetTcpPortSharing - ok
18:49:41.0209 5808 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:49:41.0209 5808 nfrd960 - ok
18:49:41.0240 5808 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
18:49:41.0240 5808 NlaSvc - ok
18:49:41.0256 5808 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:49:41.0256 5808 Npfs - ok
18:49:41.0287 5808 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
18:49:41.0287 5808 nsi - ok
18:49:41.0303 5808 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:49:41.0303 5808 nsiproxy - ok
18:49:41.0349 5808 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:49:41.0349 5808 Ntfs - ok
18:49:41.0365 5808 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
18:49:41.0365 5808 Null - ok
18:49:41.0537 5808 [ B69E6F70CE1151C8D62ABC9DEF64DFBE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
18:49:41.0583 5808 nvlddmkm - ok
18:49:41.0615 5808 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:49:41.0615 5808 nvraid - ok
18:49:41.0630 5808 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:49:41.0646 5808 nvstor - ok
18:49:41.0693 5808 [ E4284FCF99FEA13A7E1836F87AE356F6 ] nvsvc C:\Windows\system32\nvvsvc.exe
18:49:41.0708 5808 nvsvc - ok
18:49:41.0771 5808 [ 03E60E0BFA53ED15DC984FA34B44BB0F ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
18:49:41.0771 5808 nvUpdatusService - ok
18:49:41.0802 5808 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:49:41.0802 5808 nv_agp - ok
18:49:41.0864 5808 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:49:41.0880 5808 odserv - ok
18:49:41.0895 5808 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:49:41.0911 5808 ohci1394 - ok
18:49:41.0927 5808 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:49:41.0942 5808 ose - ok
18:49:42.0067 5808 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:49:42.0114 5808 osppsvc - ok
18:49:42.0145 5808 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:49:42.0161 5808 p2pimsvc - ok
18:49:42.0176 5808 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
18:49:42.0192 5808 p2psvc - ok
18:49:42.0223 5808 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:49:42.0223 5808 Parport - ok
18:49:42.0254 5808 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:49:42.0254 5808 partmgr - ok
18:49:42.0270 5808 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:49:42.0270 5808 Parvdm - ok
18:49:42.0270 5808 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:49:42.0285 5808 PcaSvc - ok
18:49:42.0301 5808 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
18:49:42.0301 5808 pci - ok
18:49:42.0332 5808 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
18:49:42.0332 5808 pciide - ok
18:49:42.0348 5808 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:49:42.0348 5808 pcmcia - ok
18:49:42.0348 5808 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
18:49:42.0348 5808 pcw - ok
18:49:42.0395 5808 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:49:42.0395 5808 PEAUTH - ok
18:49:42.0441 5808 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
18:49:42.0457 5808 PeerDistSvc - ok
18:49:42.0519 5808 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
18:49:42.0535 5808 pla - ok
18:49:42.0566 5808 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:49:42.0566 5808 PlugPlay - ok
18:49:42.0613 5808 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
18:49:42.0613 5808 PnkBstrA - ok
18:49:42.0629 5808 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:49:42.0629 5808 PNRPAutoReg - ok
18:49:42.0660 5808 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:49:42.0675 5808 PNRPsvc - ok
18:49:42.0707 5808 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:49:42.0707 5808 PolicyAgent - ok
18:49:42.0722 5808 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
18:49:42.0738 5808 Power - ok
18:49:42.0753 5808 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:49:42.0769 5808 PptpMiniport - ok
18:49:42.0785 5808 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:49:42.0785 5808 Processor - ok
18:49:42.0816 5808 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
18:49:42.0831 5808 ProfSvc - ok
18:49:42.0847 5808 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:49:42.0847 5808 ProtectedStorage - ok
18:49:42.0863 5808 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:49:42.0863 5808 Psched - ok
18:49:42.0909 5808 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:49:42.0909 5808 ql2300 - ok
18:49:42.0925 5808 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:49:42.0941 5808 ql40xx - ok
18:49:42.0972 5808 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
18:49:42.0972 5808 QWAVE - ok
18:49:42.0987 5808 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:49:42.0987 5808 QWAVEdrv - ok
18:49:43.0003 5808 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:49:43.0003 5808 RasAcd - ok
18:49:43.0019 5808 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:49:43.0019 5808 RasAgileVpn - ok
18:49:43.0050 5808 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
18:49:43.0050 5808 RasAuto - ok
18:49:43.0065 5808 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:49:43.0065 5808 Rasl2tp - ok
18:49:43.0097 5808 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
18:49:43.0112 5808 RasMan - ok
18:49:43.0112 5808 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:49:43.0112 5808 RasPppoe - ok
18:49:43.0128 5808 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:49:43.0128 5808 RasSstp - ok
18:49:43.0159 5808 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:49:43.0159 5808 rdbss - ok
18:49:43.0175 5808 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:49:43.0175 5808 rdpbus - ok
18:49:43.0206 5808 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:49:43.0206 5808 RDPCDD - ok
18:49:43.0221 5808 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
18:49:43.0221 5808 RDPDR - ok
18:49:43.0237 5808 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:49:43.0237 5808 RDPENCDD - ok
18:49:43.0253 5808 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:49:43.0253 5808 RDPREFMP - ok
18:49:43.0284 5808 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
18:49:43.0284 5808 RdpVideoMiniport - ok
18:49:43.0315 5808 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:49:43.0315 5808 RDPWD - ok
18:49:43.0331 5808 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:49:43.0346 5808 rdyboost - ok
18:49:43.0362 5808 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
18:49:43.0377 5808 RemoteAccess - ok
18:49:43.0393 5808 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:49:43.0393 5808 RemoteRegistry - ok
18:49:43.0424 5808 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:49:43.0424 5808 RpcEptMapper - ok
18:49:43.0440 5808 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
18:49:43.0440 5808 RpcLocator - ok
18:49:43.0471 5808 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
18:49:43.0471 5808 RpcSs - ok
18:49:43.0487 5808 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:49:43.0487 5808 rspndr - ok
18:49:43.0518 5808 [ EB7BFAED454FD2A280B9EDF05F5BCBE9 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
18:49:43.0518 5808 RTL8167 - ok
18:49:43.0533 5808 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
18:49:43.0549 5808 s3cap - ok
18:49:43.0549 5808 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
18:49:43.0565 5808 SamSs - ok
18:49:43.0596 5808 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:49:43.0596 5808 sbp2port - ok
18:49:43.0643 5808 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:49:43.0643 5808 SCardSvr - ok
18:49:43.0658 5808 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:49:43.0658 5808 scfilter - ok
18:49:43.0705 5808 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
18:49:43.0705 5808 Schedule - ok
18:49:43.0721 5808 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:49:43.0721 5808 SCPolicySvc - ok
18:49:43.0767 5808 [ A689D522EEDF89401E1DA2FE883AA7EC ] SCREAMINGBDRIVER C:\Windows\system32\drivers\ScreamingBAudio.sys
18:49:43.0767 5808 SCREAMINGBDRIVER - ok
18:49:43.0783 5808 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:49:43.0783 5808 SDRSVC - ok
18:49:43.0814 5808 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:49:43.0814 5808 secdrv - ok
18:49:43.0830 5808 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
18:49:43.0830 5808 seclogon - ok
18:49:43.0845 5808 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
18:49:43.0861 5808 SENS - ok
18:49:43.0877 5808 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:49:43.0892 5808 SensrSvc - ok
18:49:43.0908 5808 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:49:43.0908 5808 Serenum - ok
18:49:43.0923 5808 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:49:43.0923 5808 Serial - ok
18:49:43.0939 5808 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:49:43.0939 5808 sermouse - ok
18:49:43.0970 5808 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
18:49:43.0970 5808 SessionEnv - ok
18:49:43.0986 5808 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:49:43.0986 5808 sffdisk - ok
18:49:44.0001 5808 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:49:44.0001 5808 sffp_mmc - ok
18:49:44.0017 5808 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:49:44.0017 5808 sffp_sd - ok
18:49:44.0033 5808 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:49:44.0033 5808 sfloppy - ok
18:49:44.0064 5808 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:49:44.0064 5808 SharedAccess - ok
18:49:44.0095 5808 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:49:44.0095 5808 ShellHWDetection - ok
18:49:44.0111 5808 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:49:44.0111 5808 sisagp - ok
18:49:44.0142 5808 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:49:44.0142 5808 SiSRaid2 - ok
18:49:44.0157 5808 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:49:44.0157 5808 SiSRaid4 - ok
18:49:44.0220 5808 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:49:44.0220 5808 SkypeUpdate - ok
18:49:44.0235 5808 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:49:44.0235 5808 Smb - ok
18:49:44.0282 5808 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:49:44.0298 5808 SNMPTRAP - ok
18:49:44.0313 5808 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
18:49:44.0313 5808 spldr - ok
18:49:44.0360 5808 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
18:49:44.0360 5808 Spooler - ok
18:49:44.0423 5808 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
18:49:44.0454 5808 sppsvc - ok
18:49:44.0469 5808 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:49:44.0485 5808 sppuinotify - ok
18:49:44.0501 5808 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:49:44.0516 5808 srv - ok
18:49:44.0532 5808 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:49:44.0532 5808 srv2 - ok
18:49:44.0547 5808 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:49:44.0547 5808 srvnet - ok
18:49:44.0563 5808 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:49:44.0579 5808 SSDPSRV - ok
18:49:44.0594 5808 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:49:44.0594 5808 SstpSvc - ok
18:49:44.0657 5808 [ DB0768632C680B7C0D3AA92D80416893 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
18:49:44.0672 5808 Steam Client Service - ok
18:49:44.0719 5808 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
18:49:44.0719 5808 Stereo Service - ok
18:49:44.0750 5808 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:49:44.0750 5808 stexstor - ok
18:49:44.0781 5808 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
18:49:44.0797 5808 StiSvc - ok
18:49:44.0828 5808 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
18:49:44.0828 5808 storflt - ok
18:49:44.0859 5808 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
18:49:44.0859 5808 storvsc - ok
18:49:44.0875 5808 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
18:49:44.0875 5808 swenum - ok
18:49:44.0891 5808 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
18:49:44.0906 5808 swprv - ok
18:49:44.0922 5808 Synth3dVsc - ok
18:49:44.0953 5808 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
18:49:44.0969 5808 SysMain - ok
18:49:44.0984 5808 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:49:44.0984 5808 TabletInputService - ok
18:49:45.0015 5808 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
18:49:45.0015 5808 TapiSrv - ok
18:49:45.0047 5808 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
18:49:45.0047 5808 TBS - ok
18:49:45.0093 5808 [ D32FDAC73FCD76B85389C39BC1087F2A ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:49:45.0109 5808 Tcpip - ok
18:49:45.0125 5808 [ D32FDAC73FCD76B85389C39BC1087F2A ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:49:45.0140 5808 TCPIP6 - ok
18:49:45.0156 5808 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:49:45.0156 5808 tcpipreg - ok
18:49:45.0187 5808 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:49:45.0187 5808 TDPIPE - ok
18:49:45.0203 5808 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:49:45.0203 5808 TDTCP - ok
18:49:45.0234 5808 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:49:45.0234 5808 tdx - ok
18:49:45.0249 5808 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:49:45.0249 5808 TermDD - ok
18:49:45.0296 5808 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
18:49:45.0296 5808 TermService - ok
18:49:45.0327 5808 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
18:49:45.0327 5808 Themes - ok
18:49:45.0327 5808 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
18:49:45.0343 5808 THREADORDER - ok
18:49:45.0374 5808 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
18:49:45.0374 5808 TrkWks - ok
18:49:45.0405 5808 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:49:45.0421 5808 TrustedInstaller - ok
18:49:45.0437 5808 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:49:45.0437 5808 tssecsrv - ok
18:49:45.0452 5808 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:49:45.0452 5808 TsUsbFlt - ok
18:49:45.0468 5808 tsusbhub - ok
18:49:45.0499 5808 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:49:45.0499 5808 tunnel - ok
18:49:45.0530 5808 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:49:45.0530 5808 uagp35 - ok
18:49:45.0546 5808 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:49:45.0546 5808 udfs - ok
18:49:45.0577 5808 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:49:45.0577 5808 UI0Detect - ok
18:49:45.0593 5808 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:49:45.0593 5808 uliagpkx - ok
18:49:45.0624 5808 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
18:49:45.0624 5808 umbus - ok
18:49:45.0639 5808 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:49:45.0639 5808 UmPass - ok
18:49:45.0686 5808 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
18:49:45.0702 5808 UmRdpService - ok
18:49:45.0733 5808 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
18:49:45.0733 5808 upnphost - ok
18:49:45.0749 5808 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:49:45.0749 5808 usbccgp - ok
18:49:45.0795 5808 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:49:45.0795 5808 usbcir - ok
18:49:45.0811 5808 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:49:45.0811 5808 usbehci - ok
18:49:45.0842 5808 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:49:45.0842 5808 usbhub - ok
18:49:45.0858 5808 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:49:45.0858 5808 usbohci - ok
18:49:45.0873 5808 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:49:45.0873 5808 usbprint - ok
18:49:45.0920 5808 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
18:49:45.0920 5808 usbscan - ok
18:49:45.0936 5808 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
18:49:45.0936 5808 USBSTOR - ok
18:49:45.0951 5808 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:49:45.0951 5808 usbuhci - ok
18:49:45.0967 5808 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
18:49:45.0967 5808 UxSms - ok
18:49:45.0983 5808 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
18:49:45.0983 5808 VaultSvc - ok
18:49:45.0998 5808 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:49:45.0998 5808 vdrvroot - ok
18:49:46.0045 5808 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
18:49:46.0045 5808 vds - ok
18:49:46.0076 5808 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:49:46.0076 5808 vga - ok
18:49:46.0092 5808 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
18:49:46.0092 5808 VgaSave - ok
18:49:46.0107 5808 VGPU - ok
18:49:46.0139 5808 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:49:46.0139 5808 vhdmp - ok
18:49:46.0154 5808 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:49:46.0154 5808 viaagp - ok
18:49:46.0185 5808 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
18:49:46.0185 5808 ViaC7 - ok
18:49:46.0201 5808 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
18:49:46.0201 5808 viaide - ok
18:49:46.0232 5808 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
18:49:46.0232 5808 vmbus - ok
18:49:46.0248 5808 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
18:49:46.0248 5808 VMBusHID - ok
18:49:46.0263 5808 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:49:46.0263 5808 volmgr - ok
18:49:46.0279 5808 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:49:46.0279 5808 volmgrx - ok
18:49:46.0295 5808 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:49:46.0295 5808 volsnap - ok
18:49:46.0326 5808 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:49:46.0326 5808 vsmraid - ok
18:49:46.0357 5808 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
18:49:46.0373 5808 VSS - ok
18:49:46.0388 5808 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
18:49:46.0388 5808 vwifibus - ok
18:49:46.0419 5808 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
18:49:46.0435 5808 W32Time - ok
18:49:46.0451 5808 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:49:46.0451 5808 WacomPen - ok
18:49:46.0482 5808 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:49:46.0482 5808 WANARP - ok
18:49:46.0482 5808 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:49:46.0482 5808 Wanarpv6 - ok
18:49:46.0544 5808 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:49:46.0560 5808 WatAdminSvc - ok
18:49:46.0591 5808 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
18:49:46.0607 5808 wbengine - ok
18:49:46.0622 5808 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:49:46.0622 5808 WbioSrvc - ok
18:49:46.0653 5808 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:49:46.0653 5808 wcncsvc - ok
18:49:46.0669 5808 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:49:46.0685 5808 WcsPlugInService - ok
18:49:46.0700 5808 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:49:46.0700 5808 Wd - ok
18:49:46.0731 5808 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:49:46.0731 5808 Wdf01000 - ok
18:49:46.0747 5808 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:49:46.0747 5808 WdiServiceHost - ok
18:49:46.0763 5808 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:49:46.0763 5808 WdiSystemHost - ok
18:49:46.0778 5808 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
18:49:46.0794 5808 WebClient - ok
18:49:46.0809 5808 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:49:46.0825 5808 Wecsvc - ok
18:49:46.0825 5808 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:49:46.0841 5808 wercplsupport - ok
18:49:46.0856 5808 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
18:49:46.0856 5808 WerSvc - ok
18:49:46.0887 5808 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:49:46.0887 5808 WfpLwf - ok
18:49:46.0903 5808 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:49:46.0903 5808 WIMMount - ok
18:49:46.0965 5808 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:49:46.0981 5808 WinDefend - ok
18:49:46.0981 5808 WinHttpAutoProxySvc - ok
18:49:47.0043 5808 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:49:47.0043 5808 Winmgmt - ok
18:49:47.0090 5808 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
18:49:47.0106 5808 WinRM - ok
18:49:47.0137 5808 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:49:47.0153 5808 WinUsb - ok
18:49:47.0184 5808 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:49:47.0199 5808 Wlansvc - ok
18:49:47.0215 5808 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:49:47.0215 5808 WmiAcpi - ok
18:49:47.0231 5808 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:49:47.0231 5808 wmiApSrv - ok
18:49:47.0277 5808 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:49:47.0293 5808 WMPNetworkSvc - ok
18:49:47.0309 5808 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:49:47.0309 5808 WPCSvc - ok
18:49:47.0340 5808 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:49:47.0340 5808 WPDBusEnum - ok
18:49:47.0355 5808 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:49:47.0355 5808 ws2ifsl - ok
18:49:47.0371 5808 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
18:49:47.0371 5808 wscsvc - ok
18:49:47.0387 5808 WSearch - ok
18:49:47.0433 5808 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
18:49:47.0465 5808 wuauserv - ok
18:49:47.0480 5808 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:49:47.0480 5808 WudfPf - ok
18:49:47.0511 5808 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:49:47.0511 5808 WUDFRd - ok
18:49:47.0543 5808 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:49:47.0543 5808 wudfsvc - ok
18:49:47.0574 5808 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
18:49:47.0589 5808 WwanSvc - ok
18:49:47.0589 5808 ================ Scan global ===============================
18:49:47.0621 5808 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
18:49:47.0636 5808 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
18:49:47.0652 5808 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
18:49:47.0683 5808 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
18:49:47.0699 5808 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
18:49:47.0699 5808 [Global] - ok
18:49:47.0699 5808 ================ Scan MBR ==================================
18:49:47.0714 5808 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
18:49:48.0042 5808 \Device\Harddisk0\DR0 - ok
18:49:48.0042 5808 ================ Scan VBR ==================================
18:49:48.0042 5808 [ 1EF2E35208D508E010BD69E2D85FDE05 ] \Device\Harddisk0\DR0\Partition1
18:49:48.0057 5808 \Device\Harddisk0\DR0\Partition1 - ok
18:49:48.0073 5808 [ 9735078439B7E1771EFF8E5EDA4893BC ] \Device\Harddisk0\DR0\Partition2
18:49:48.0073 5808 \Device\Harddisk0\DR0\Partition2 - ok
18:49:48.0073 5808 ============================================================
18:49:48.0073 5808 Scan finished
18:49:48.0073 5808 ============================================================
18:49:48.0073 4400 Detected object count: 0
18:49:48.0073 4400 Actual detected object count: 0
Windows 10 Pro 64-bit
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
Intel Core i5 4460 @ 3.20GHz
16,00GB Dual-Channel DDR3
MSI B85-G43
NVIDIA GeForce GTX 970 (Gigabyte), LCD Monitor
SAMSUNG 23,6" S24D390
Zdroj: Seasonic S12II-620 - 620W
111GB KINGSTON (SSD)
931GB Seagate (SATA)
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: výpis z logu, děkuji za pomoc
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 73 hostů