19:30:48.0416 4880 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
19:30:48.0416 4880 DPS - ok
19:30:48.0462 4880 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:30:48.0462 4880 drmkaud - ok
19:30:48.0509 4880 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
19:30:48.0509 4880 dtsoftbus01 - ok
19:30:48.0587 4880 [ 71BC35067CABC02C9453AEAA42B2E43E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:30:48.0587 4880 DXGKrnl - ok
19:30:48.0634 4880 [ 04238864710460C5682E260207D06192 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
19:30:48.0650 4880 eamonm - ok
19:30:48.0681 4880 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
19:30:48.0681 4880 EapHost - ok
19:30:48.0774 4880 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
19:30:48.0806 4880 ebdrv - ok
19:30:48.0837 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] EFS C:\Windows\System32\lsass.exe
19:30:48.0837 4880 EFS - ok
19:30:48.0868 4880 [ DEFF87F04AB5F6DD5EDF2B80853BBE10 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
19:30:48.0868 4880 ehdrv - ok
19:30:48.0962 4880 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:30:48.0962 4880 ehRecvr - ok
19:30:48.0993 4880 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
19:30:48.0993 4880 ehSched - ok
19:30:49.0071 4880 [ 3B944199F8EDD76BE94460C0361409AB ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe
19:30:49.0071 4880 ekrn - ok
19:30:49.0118 4880 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
19:30:49.0118 4880 elxstor - ok
19:30:49.0164 4880 [ 5BA193CA0AE31209AAA39939CE6736B2 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
19:30:49.0164 4880 epfw - ok
19:30:49.0180 4880 [ 9CEFD59C8E5EBFB48165AEF54617F539 ] EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys
19:30:49.0180 4880 EpfwLWF - ok
19:30:49.0196 4880 [ 7144A06AC105A2A7302944602E415EC1 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
19:30:49.0196 4880 epfwwfp - ok
19:30:49.0242 4880 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:30:49.0242 4880 ErrDev - ok
19:30:49.0274 4880 [ BCF41162944479C8111FD48AFC3181BD ] ETD C:\Windows\system32\DRIVERS\ETD.sys
19:30:49.0274 4880 ETD - ok
19:30:49.0305 4880 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
19:30:49.0320 4880 EventSystem - ok
19:30:49.0383 4880 [ 24C9E1E7A2C2B7E89E39F11011748343 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
19:30:49.0383 4880 EvtEng - ok
19:30:49.0398 4880 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
19:30:49.0398 4880 exfat - ok
19:30:49.0430 4880 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:30:49.0430 4880 fastfat - ok
19:30:49.0476 4880 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
19:30:49.0492 4880 Fax - ok
19:30:49.0508 4880 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
19:30:49.0508 4880 fdc - ok
19:30:49.0539 4880 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
19:30:49.0539 4880 fdPHost - ok
19:30:49.0554 4880 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
19:30:49.0554 4880 FDResPub - ok
19:30:49.0554 4880 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:30:49.0554 4880 FileInfo - ok
19:30:49.0570 4880 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:30:49.0570 4880 Filetrace - ok
19:30:49.0648 4880 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
19:30:49.0648 4880 FLEXnet Licensing Service - ok
19:30:49.0679 4880 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
19:30:49.0679 4880 flpydisk - ok
19:30:49.0695 4880 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:30:49.0695 4880 FltMgr - ok
19:30:49.0757 4880 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
19:30:49.0773 4880 FontCache - ok
19:30:49.0820 4880 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:30:49.0820 4880 FontCache3.0.0.0 - ok
19:30:49.0835 4880 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:30:49.0835 4880 FsDepends - ok
19:30:49.0882 4880 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:30:49.0882 4880 Fs_Rec - ok
19:30:49.0929 4880 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:30:49.0929 4880 fvevol - ok
19:30:49.0960 4880 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
19:30:49.0960 4880 gagp30kx - ok
19:30:49.0991 4880 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\Windows\system32\giveio.sys
19:30:49.0991 4880 giveio - ok
19:30:50.0038 4880 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
19:30:50.0054 4880 gpsvc - ok
19:30:50.0069 4880 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:30:50.0069 4880 hcw85cir - ok
19:30:50.0132 4880 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:30:50.0132 4880 HdAudAddService - ok
19:30:50.0163 4880 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
19:30:50.0163 4880 HDAudBus - ok
19:30:50.0179 4880 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
19:30:50.0179 4880 HidBatt - ok
19:30:50.0210 4880 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
19:30:50.0210 4880 HidBth - ok
19:30:50.0225 4880 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
19:30:50.0225 4880 HidIr - ok
19:30:50.0241 4880 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
19:30:50.0257 4880 hidserv - ok
19:30:50.0288 4880 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:30:50.0288 4880 HidUsb - ok
19:30:50.0335 4880 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:30:50.0335 4880 hkmsvc - ok
19:30:50.0381 4880 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:30:50.0397 4880 HomeGroupListener - ok
19:30:50.0444 4880 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:30:50.0444 4880 HomeGroupProvider - ok
19:30:50.0506 4880 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:30:50.0506 4880 HpSAMD - ok
19:30:50.0569 4880 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:30:50.0569 4880 HTTP - ok
19:30:50.0615 4880 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:30:50.0615 4880 hwpolicy - ok
19:30:50.0678 4880 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
19:30:50.0678 4880 i8042prt - ok
19:30:50.0709 4880 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:30:50.0709 4880 iaStorV - ok
19:30:50.0771 4880 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
19:30:50.0771 4880 IDriverT - ok
19:30:50.0849 4880 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:30:50.0865 4880 idsvc - ok
19:30:50.0865 4880 IEEtwCollectorService - ok
19:30:50.0974 4880 [ 8CC51204BCE551B90B45E97BE446C48B ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
19:30:51.0005 4880 igfx - ok
19:30:51.0037 4880 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
19:30:51.0037 4880 iirsp - ok
19:30:51.0083 4880 [ B9C54120F46392100478F58F374E5709 ] IKEEXT C:\Windows\System32\ikeext.dll
19:30:51.0099 4880 IKEEXT - ok
19:30:51.0130 4880 [ 7081EFE4EBF9CBBFF4EB5A3AC478DDC5 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
19:30:51.0130 4880 IntcDAud - ok
19:30:51.0177 4880 [ C86A9AA1CBC4C3C2C5C9DD0F6D939926 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
19:30:51.0177 4880 Intel(R) Capability Licensing Service Interface - ok
19:30:51.0193 4880 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
19:30:51.0193 4880 intelide - ok
19:30:51.0224 4880 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:30:51.0224 4880 intelppm - ok
19:30:51.0239 4880 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:30:51.0239 4880 IPBusEnum - ok
19:30:51.0271 4880 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:30:51.0271 4880 IpFilterDriver - ok
19:30:51.0333 4880 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:30:51.0333 4880 iphlpsvc - ok
19:30:51.0380 4880 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:30:51.0395 4880 IPMIDRV - ok
19:30:51.0411 4880 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:30:51.0411 4880 IPNAT - ok
19:30:51.0442 4880 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:30:51.0442 4880 IRENUM - ok
19:30:51.0489 4880 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:30:51.0489 4880 isapnp - ok
19:30:51.0520 4880 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:30:51.0520 4880 iScsiPrt - ok
19:30:51.0551 4880 [ B5170AD27CD5AEA07BF763FED91D2E07 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
19:30:51.0551 4880 iusb3hcs - ok
19:30:51.0583 4880 [ E2602F2D429F24E61EF77233A3FB0286 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
19:30:51.0583 4880 iusb3hub - ok
19:30:51.0614 4880 [ A228090BC88479270279C93DB791EFE9 ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
19:30:51.0614 4880 iusb3xhc - ok
19:30:51.0676 4880 [ 09CA717536671E0896E07D239EE6740F ] jhi_service C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
19:30:51.0676 4880 jhi_service - ok
19:30:51.0707 4880 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
19:30:51.0707 4880 kbdclass - ok
19:30:51.0754 4880 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
19:30:51.0754 4880 kbdhid - ok
19:30:51.0785 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] KeyIso C:\Windows\system32\lsass.exe
19:30:51.0785 4880 KeyIso - ok
19:30:51.0832 4880 [ F286830298323272260332D6ABC905C1 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:30:51.0832 4880 KSecDD - ok
19:30:51.0848 4880 [ D7C760D57B1656DD748B9E4AB6CB5A51 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:30:51.0848 4880 KSecPkg - ok
19:30:51.0879 4880 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
19:30:51.0895 4880 KtmRm - ok
19:30:51.0926 4880 [ ECADA96654BB95E05DC0963AA9764707 ] L1C C:\Windows\system32\DRIVERS\L1C62x86.sys
19:30:51.0926 4880 L1C - ok
19:30:51.0941 4880 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
19:30:51.0957 4880 LanmanServer - ok
19:30:52.0004 4880 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:30:52.0004 4880 LanmanWorkstation - ok
19:30:52.0035 4880 [ 8FF8B5F04AC4D57F9A965BB4DF07813E ] LHDmgr C:\Windows\system32\DRIVERS\LhdX86.sys
19:30:52.0035 4880 LHDmgr - ok
19:30:52.0066 4880 [ 4127E8B6DDB4090E815C1F8852C277D3 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
19:30:52.0066 4880 lirsgt - ok
19:30:52.0129 4880 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:30:52.0129 4880 lltdio - ok
19:30:52.0175 4880 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:30:52.0175 4880 lltdsvc - ok
19:30:52.0191 4880 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
19:30:52.0207 4880 lmhosts - ok
19:30:52.0238 4880 [ A60D56228FF3EE7EC1A56A908924680E ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:30:52.0253 4880 LMS - ok
19:30:52.0269 4880 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
19:30:52.0269 4880 LSI_FC - ok
19:30:52.0300 4880 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
19:30:52.0300 4880 LSI_SAS - ok
19:30:52.0316 4880 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:30:52.0316 4880 LSI_SAS2 - ok
19:30:52.0331 4880 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:30:52.0331 4880 LSI_SCSI - ok
19:30:52.0347 4880 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
19:30:52.0347 4880 luafv - ok
19:30:52.0378 4880 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
19:30:52.0378 4880 MBAMProtector - ok
19:30:52.0472 4880 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
19:30:52.0487 4880 MBAMScheduler - ok
19:30:52.0550 4880 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
19:30:52.0565 4880 MBAMService - ok
19:30:52.0597 4880 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:30:52.0612 4880 Mcx2Svc - ok
19:30:52.0643 4880 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
19:30:52.0643 4880 megasas - ok
19:30:52.0659 4880 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
19:30:52.0659 4880 MegaSR - ok
19:30:52.0690 4880 [ 9E0A56C77E9244D2CAAC3811F4B47FCB ] MEI C:\Windows\system32\DRIVERS\HECI.sys
19:30:52.0690 4880 MEI - ok
19:30:52.0799 4880 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
19:30:52.0799 4880 Microsoft Office Groove Audit Service - ok
19:30:52.0846 4880 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
19:30:52.0846 4880 MMCSS - ok
19:30:52.0877 4880 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
19:30:52.0877 4880 Modem - ok
19:30:52.0909 4880 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:30:52.0909 4880 monitor - ok
19:30:52.0940 4880 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:30:52.0940 4880 mouclass - ok
19:30:52.0971 4880 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:30:52.0971 4880 mouhid - ok
19:30:53.0018 4880 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:30:53.0018 4880 mountmgr - ok
19:30:53.0049 4880 [ 3B9398E0146855B1DC0E3D9769C80F01 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
19:30:53.0049 4880 MozillaMaintenance - ok
19:30:53.0096 4880 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
19:30:53.0096 4880 mpio - ok
19:30:53.0143 4880 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:30:53.0143 4880 mpsdrv - ok
19:30:53.0205 4880 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:30:53.0221 4880 MpsSvc - ok
19:30:53.0252 4880 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:30:53.0252 4880 MRxDAV - ok
19:30:53.0299 4880 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:30:53.0299 4880 mrxsmb - ok
19:30:53.0314 4880 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:30:53.0314 4880 mrxsmb10 - ok
19:30:53.0330 4880 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:30:53.0330 4880 mrxsmb20 - ok
19:30:53.0377 4880 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
19:30:53.0377 4880 msahci - ok
19:30:53.0408 4880 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:30:53.0408 4880 msdsm - ok
19:30:53.0423 4880 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
19:30:53.0439 4880 MSDTC - ok
19:30:53.0470 4880 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:30:53.0470 4880 Msfs - ok
19:30:53.0486 4880 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:30:53.0486 4880 mshidkmdf - ok
19:30:53.0501 4880 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:30:53.0501 4880 msisadrv - ok
19:30:53.0548 4880 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:30:53.0548 4880 MSiSCSI - ok
19:30:53.0564 4880 msiserver - ok
19:30:53.0579 4880 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:30:53.0579 4880 MSKSSRV - ok
19:30:53.0595 4880 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:30:53.0595 4880 MSPCLOCK - ok
19:30:53.0611 4880 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:30:53.0611 4880 MSPQM - ok
19:30:53.0642 4880 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:30:53.0642 4880 MsRPC - ok
19:30:53.0673 4880 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
19:30:53.0673 4880 mssmbios - ok
19:30:53.0689 4880 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:30:53.0689 4880 MSTEE - ok
19:30:53.0704 4880 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
19:30:53.0704 4880 MTConfig - ok
19:30:53.0735 4880 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
19:30:53.0735 4880 Mup - ok
19:30:53.0751 4880 [ A1DFE4378C4F4EE6901C88EA3467F19A ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
19:30:53.0751 4880 MyWiFiDHCPDNS - ok
19:30:53.0798 4880 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
19:30:53.0813 4880 napagent - ok
19:30:53.0860 4880 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:30:53.0860 4880 NativeWifiP - ok
19:30:53.0923 4880 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:30:53.0938 4880 NDIS - ok
19:30:53.0954 4880 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:30:53.0954 4880 NdisCap - ok
19:30:53.0969 4880 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:30:53.0969 4880 NdisTapi - ok
19:30:54.0016 4880 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:30:54.0032 4880 Ndisuio - ok
19:30:54.0063 4880 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:30:54.0063 4880 NdisWan - ok
19:30:54.0110 4880 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:30:54.0110 4880 NDProxy - ok
19:30:54.0125 4880 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:30:54.0125 4880 NetBIOS - ok
19:30:54.0188 4880 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:30:54.0188 4880 NetBT - ok
19:30:54.0203 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] Netlogon C:\Windows\system32\lsass.exe
19:30:54.0219 4880 Netlogon - ok
19:30:54.0250 4880 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
19:30:54.0250 4880 Netman - ok
19:30:54.0313 4880 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:30:54.0313 4880 NetMsmqActivator - ok
19:30:54.0313 4880 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:30:54.0328 4880 NetPipeActivator - ok
19:30:54.0344 4880 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
19:30:54.0359 4880 netprofm - ok
19:30:54.0359 4880 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:30:54.0359 4880 NetTcpActivator - ok
19:30:54.0359 4880 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:30:54.0359 4880 NetTcpPortSharing - ok
19:30:54.0391 4880 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
19:30:54.0391 4880 nfrd960 - ok
19:30:54.0437 4880 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
19:30:54.0437 4880 NlaSvc - ok
19:30:54.0453 4880 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:30:54.0453 4880 Npfs - ok
19:30:54.0469 4880 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
19:30:54.0469 4880 nsi - ok
19:30:54.0484 4880 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:30:54.0484 4880 nsiproxy - ok
19:30:54.0562 4880 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:30:54.0578 4880 Ntfs - ok
19:30:54.0593 4880 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
19:30:54.0593 4880 Null - ok
19:30:54.0796 4880 [ C1E661888C719FC2E12C057F233FB238 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:30:54.0843 4880 nvlddmkm - ok
19:30:54.0890 4880 [ 9983B7DA550DDC7141C31E673A9397A9 ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
19:30:54.0890 4880 nvpciflt - ok
19:30:54.0905 4880 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:30:54.0921 4880 nvraid - ok
19:30:54.0952 4880 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:30:54.0952 4880 nvstor - ok
19:30:54.0999 4880 [ 31D7E63B62BC4680B5D1358F91DA104E ] nvsvc C:\Windows\system32\nvvsvc.exe
19:30:54.0999 4880 nvsvc - ok
19:30:55.0077 4880 [ 143B429F2D19A0F123ED8E4BCA8DB751 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
19:30:55.0093 4880 nvUpdatusService - ok
19:30:55.0124 4880 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:30:55.0124 4880 nv_agp - ok
19:30:55.0249 4880 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:30:55.0249 4880 odserv - ok
19:30:55.0295 4880 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:30:55.0295 4880 ohci1394 - ok
19:30:55.0342 4880 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:30:55.0342 4880 ose - ok
19:30:55.0389 4880 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:30:55.0405 4880 p2pimsvc - ok
19:30:55.0420 4880 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
19:30:55.0420 4880 p2psvc - ok
19:30:55.0451 4880 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
19:30:55.0451 4880 Parport - ok
19:30:55.0498 4880 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:30:55.0498 4880 partmgr - ok
19:30:55.0514 4880 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
19:30:55.0514 4880 Parvdm - ok
19:30:55.0529 4880 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:30:55.0529 4880 PcaSvc - ok
19:30:55.0576 4880 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
19:30:55.0592 4880 pci - ok
19:30:55.0592 4880 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
19:30:55.0592 4880 pciide - ok
19:30:55.0623 4880 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
19:30:55.0623 4880 pcmcia - ok
19:30:55.0639 4880 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
19:30:55.0639 4880 pcw - ok
19:30:55.0670 4880 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:30:55.0670 4880 PEAUTH - ok
19:30:55.0763 4880 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
19:30:55.0795 4880 pla - ok
19:30:55.0826 4880 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:30:55.0841 4880 PlugPlay - ok
19:30:55.0888 4880 [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
19:30:55.0888 4880 PnkBstrA - ok
19:30:55.0919 4880 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:30:55.0919 4880 PNRPAutoReg - ok
19:30:55.0935 4880 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:30:55.0951 4880 PNRPsvc - ok
19:30:55.0997 4880 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:30:56.0013 4880 PolicyAgent - ok
19:30:56.0060 4880 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
19:30:56.0075 4880 Power - ok
19:30:56.0107 4880 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:30:56.0107 4880 PptpMiniport - ok
19:30:56.0122 4880 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
19:30:56.0138 4880 Processor - ok
19:30:56.0185 4880 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
19:30:56.0185 4880 ProfSvc - ok
19:30:56.0200 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:30:56.0216 4880 ProtectedStorage - ok
19:30:56.0216 4880 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:30:56.0216 4880 Psched - ok
19:30:56.0263 4880 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
19:30:56.0278 4880 ql2300 - ok
19:30:56.0309 4880 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
19:30:56.0309 4880 ql40xx - ok
19:30:56.0341 4880 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
19:30:56.0356 4880 QWAVE - ok
19:30:56.0372 4880 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:30:56.0372 4880 QWAVEdrv - ok
19:30:56.0387 4880 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:30:56.0387 4880 RasAcd - ok
19:30:56.0419 4880 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:30:56.0419 4880 RasAgileVpn - ok
19:30:56.0434 4880 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
19:30:56.0450 4880 RasAuto - ok
19:30:56.0465 4880 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:30:56.0465 4880 Rasl2tp - ok
19:30:56.0512 4880 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
19:30:56.0528 4880 RasMan - ok
19:30:56.0543 4880 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:30:56.0543 4880 RasPppoe - ok
19:30:56.0559 4880 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:30:56.0575 4880 RasSstp - ok
19:30:56.0606 4880 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:30:56.0606 4880 rdbss - ok
19:30:56.0637 4880 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
19:30:56.0637 4880 rdpbus - ok
19:30:56.0668 4880 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:30:56.0668 4880 RDPCDD - ok
19:30:56.0684 4880 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:30:56.0684 4880 RDPENCDD - ok
19:30:56.0715 4880 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:30:56.0715 4880 RDPREFMP - ok
19:30:56.0762 4880 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:30:56.0762 4880 RDPWD - ok
19:30:56.0809 4880 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:30:56.0824 4880 rdyboost - ok
19:30:56.0871 4880 [ A397874E72238D56AADF41E36EE9ACA0 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
19:30:56.0887 4880 RegSrvc - ok
19:30:56.0918 4880 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
19:30:56.0918 4880 RemoteAccess - ok
19:30:56.0949 4880 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:30:56.0965 4880 RemoteRegistry - ok
19:30:56.0980 4880 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
19:30:56.0996 4880 RFCOMM - ok
19:30:57.0011 4880 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:30:57.0011 4880 RpcEptMapper - ok
19:30:57.0027 4880 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
19:30:57.0027 4880 RpcLocator - ok
19:30:57.0089 4880 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
19:30:57.0105 4880 RpcSs - ok
19:30:57.0136 4880 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:30:57.0136 4880 rspndr - ok
19:30:57.0167 4880 [ 71A589952B9DA1A54ADDEAE052DDB04E ] RSUSBVSTOR C:\Windows\system32\Drivers\RtsUVStor.sys
19:30:57.0167 4880 RSUSBVSTOR - ok
19:30:57.0183 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] SamSs C:\Windows\system32\lsass.exe
19:30:57.0183 4880 SamSs - ok
19:30:57.0214 4880 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:30:57.0214 4880 sbp2port - ok
19:30:57.0261 4880 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:30:57.0261 4880 SCardSvr - ok
19:30:57.0308 4880 [ F441BA47BD8610CB9536965BD7D1F943 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
19:30:57.0308 4880 SCDEmu - ok
19:30:57.0339 4880 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:30:57.0339 4880 scfilter - ok
19:30:57.0401 4880 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
19:30:57.0417 4880 Schedule - ok
19:30:57.0464 4880 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:30:57.0464 4880 SCPolicySvc - ok
19:30:57.0479 4880 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:30:57.0495 4880 SDRSVC - ok
19:30:57.0526 4880 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:30:57.0526 4880 secdrv - ok
19:30:57.0542 4880 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
19:30:57.0557 4880 seclogon - ok
19:30:57.0573 4880 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
19:30:57.0589 4880 SENS - ok
19:30:57.0620 4880 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:30:57.0620 4880 SensrSvc - ok
19:30:57.0651 4880 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
19:30:57.0651 4880 Serenum - ok
19:30:57.0667 4880 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
19:30:57.0667 4880 Serial - ok
19:30:57.0682 4880 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
19:30:57.0682 4880 sermouse - ok
19:30:57.0729 4880 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
19:30:57.0745 4880 SessionEnv - ok
19:30:57.0776 4880 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:30:57.0776 4880 sffdisk - ok
19:30:57.0791 4880 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:30:57.0791 4880 sffp_mmc - ok
19:30:57.0807 4880 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:30:57.0807 4880 sffp_sd - ok
19:30:57.0823 4880 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
19:30:57.0823 4880 sfloppy - ok
19:30:57.0854 4880 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:30:57.0854 4880 SharedAccess - ok
19:30:57.0901 4880 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:30:57.0916 4880 ShellHWDetection - ok
19:30:57.0932 4880 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
19:30:57.0932 4880 sisagp - ok
19:30:57.0947 4880 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:30:57.0963 4880 SiSRaid2 - ok
19:30:57.0979 4880 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
19:30:57.0979 4880 SiSRaid4 - ok
19:30:57.0994 4880 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:30:57.0994 4880 Smb - ok
19:30:58.0025 4880 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:30:58.0025 4880 SNMPTRAP - ok
19:30:58.0072 4880 [ DC8D2952FB6FFBAEC67BD1B93A34DF11 ] speedfan C:\Windows\system32\speedfan.sys
19:30:58.0072 4880 speedfan - ok
19:30:58.0088 4880 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
19:30:58.0088 4880 spldr - ok
19:30:58.0135 4880 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
19:30:58.0135 4880 Spooler - ok
19:30:58.0244 4880 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
19:30:58.0275 4880 sppsvc - ok
19:30:58.0322 4880 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:30:58.0322 4880 sppuinotify - ok
19:30:58.0369 4880 [ 0C1DAD75274CB6E31F053CE3E08BF9C3 ] sptd C:\Windows\system32\Drivers\sptd.sys
19:30:58.0384 4880 sptd - ok
19:30:58.0447 4880 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
19:30:58.0447 4880 srv - ok
19:30:58.0478 4880 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:30:58.0478 4880 srv2 - ok
19:30:58.0493 4880 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:30:58.0509 4880 srvnet - ok
19:30:58.0540 4880 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:30:58.0540 4880 SSDPSRV - ok
19:30:58.0556 4880 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:30:58.0571 4880 SstpSvc - ok
19:30:58.0587 4880 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
19:30:58.0587 4880 stexstor - ok
19:30:58.0649 4880 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
19:30:58.0649 4880 StiSvc - ok
19:30:58.0696 4880 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
19:30:58.0696 4880 swenum - ok
19:30:58.0712 4880 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
19:30:58.0727 4880 swprv - ok
19:30:58.0790 4880 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
19:30:58.0805 4880 SysMain - ok
19:30:58.0852 4880 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:30:58.0868 4880 TabletInputService - ok
19:30:58.0915 4880 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
19:30:58.0930 4880 TapiSrv - ok
19:30:58.0946 4880 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
19:30:58.0946 4880 TBS - ok
19:30:59.0024 4880 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:30:59.0024 4880 Tcpip - ok
19:30:59.0055 4880 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:30:59.0055 4880 TCPIP6 - ok
19:30:59.0102 4880 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:30:59.0102 4880 tcpipreg - ok
19:30:59.0133 4880 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:30:59.0133 4880 TDPIPE - ok
19:30:59.0149 4880 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:30:59.0149 4880 TDTCP - ok
19:30:59.0195 4880 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:30:59.0195 4880 tdx - ok
19:30:59.0211 4880 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
19:30:59.0211 4880 TermDD - ok
19:30:59.0273 4880 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
19:30:59.0273 4880 TermService - ok
19:30:59.0305 4880 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
19:30:59.0305 4880 Themes - ok
19:30:59.0320 4880 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
19:30:59.0320 4880 THREADORDER - ok
19:30:59.0336 4880 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
19:30:59.0351 4880 TrkWks - ok
19:30:59.0398 4880 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:30:59.0398 4880 TrustedInstaller - ok
19:30:59.0445 4880 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:30:59.0445 4880 tssecsrv - ok
19:30:59.0476 4880 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:30:59.0492 4880 TsUsbFlt - ok
19:30:59.0523 4880 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:30:59.0523 4880 tunnel - ok
19:30:59.0554 4880 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
19:30:59.0554 4880 uagp35 - ok
19:30:59.0601 4880 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:30:59.0617 4880 udfs - ok
19:30:59.0663 4880 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:30:59.0663 4880 UI0Detect - ok
19:30:59.0695 4880 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:30:59.0710 4880 uliagpkx - ok
19:30:59.0710 4880 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
19:30:59.0726 4880 umbus - ok
19:30:59.0741 4880 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
19:30:59.0741 4880 UmPass - ok
19:30:59.0804 4880 [ A0153CC9D28568A10BDAEE5EC612CFC8 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:30:59.0819 4880 UNS - ok
19:30:59.0835 4880 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
19:30:59.0851 4880 upnphost - ok
19:30:59.0897 4880 [ A1977C315BF5691DA99235AA4A6907AF ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
19:30:59.0897 4880 usbaudio - ok
19:30:59.0929 4880 [ 0803FBA9FE829D61AE26EC0BCC910C46 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:30:59.0929 4880 usbccgp - ok
19:30:59.0975 4880 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:30:59.0975 4880 usbcir - ok
19:31:00.0022 4880 [ D40855F89B69305140BBD7E9A3BA2DA6 ] usbehci C:\Windows\system32\drivers\usbehci.sys
19:31:00.0022 4880 usbehci - ok
19:31:00.0069 4880 [ EDF2DF71C4F1E13A6AC75F5224DE655A ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:31:00.0069 4880 usbhub - ok
19:31:00.0100 4880 [ 9828C8D14CC2676421778F0DE638CF97 ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:31:00.0116 4880 usbohci - ok
19:31:00.0147 4880 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:31:00.0147 4880 usbprint - ok
19:31:00.0163 4880 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:31:00.0163 4880 USBSTOR - ok
19:31:00.0194 4880 [ 800AABFD625EEFF899F7E5496BDE37AB ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:31:00.0194 4880 usbuhci - ok
19:31:00.0209 4880 [ DE014425522610BEDCA3821BB8C0F1D5 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
19:31:00.0209 4880 usbvideo - ok
19:31:00.0241 4880 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
19:31:00.0241 4880 UxSms - ok
19:31:00.0256 4880 [ 803B370865D907EA21DC0C2B6A8936B5 ] VaultSvc C:\Windows\system32\lsass.exe
19:31:00.0256 4880 VaultSvc - ok
19:31:00.0303 4880 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:31:00.0303 4880 vdrvroot - ok
19:31:00.0350 4880 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
19:31:00.0365 4880 vds - ok
19:31:00.0397 4880 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:31:00.0397 4880 vga - ok
19:31:00.0412 4880 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
19:31:00.0412 4880 VgaSave - ok
19:31:00.0459 4880 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:31:00.0459 4880 vhdmp - ok
19:31:00.0490 4880 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
19:31:00.0490 4880 viaagp - ok
19:31:00.0506 4880 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
19:31:00.0506 4880 ViaC7 - ok
19:31:00.0537 4880 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
19:31:00.0537 4880 viaide - ok
19:31:00.0584 4880 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:31:00.0584 4880 volmgr - ok
19:31:00.0599 4880 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:31:00.0615 4880 volmgrx - ok
19:31:00.0631 4880 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:31:00.0631 4880 volsnap - ok
19:31:00.0646 4880 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
19:31:00.0646 4880 vsmraid - ok
19:31:00.0709 4880 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
19:31:00.0724 4880 VSS - ok
19:31:00.0740 4880 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:31:00.0740 4880 vwifibus - ok
19:31:00.0755 4880 [ 7090D3436EEB4E7DA3373090A23448F7 ] VWiFiFlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:31:00.0755 4880 VWiFiFlt - ok
19:31:00.0755 4880 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
19:31:00.0771 4880 vwifimp - ok
19:31:00.0802 4880 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
19:31:00.0802 4880 W32Time - ok
19:31:00.0833 4880 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
19:31:00.0833 4880 WacomPen - ok
19:31:00.0880 4880 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:31:00.0896 4880 WANARP - ok
19:31:00.0896 4880 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:31:00.0896 4880 Wanarpv6 - ok
19:31:00.0958 4880 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
19:31:00.0989 4880 WatAdminSvc - ok
19:31:01.0052 4880 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
19:31:01.0067 4880 wbengine - ok
19:31:01.0099 4880 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:31:01.0099 4880 WbioSrvc - ok
19:31:01.0145 4880 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:31:01.0161 4880 wcncsvc - ok
19:31:01.0177 4880 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:31:01.0177 4880 WcsPlugInService - ok
19:31:01.0208 4880 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
19:31:01.0208 4880 Wd - ok
19:31:01.0255 4880 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:31:01.0270 4880 Wdf01000 - ok
19:31:01.0301 4880 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:31:01.0301 4880 WdiServiceHost - ok
19:31:01.0301 4880 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:31:01.0317 4880 WdiSystemHost - ok
19:31:01.0364 4880 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
19:31:01.0364 4880 WebClient - ok
19:31:01.0395 4880 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:31:01.0395 4880 Wecsvc - ok
19:31:01.0411 4880 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:31:01.0411 4880 wercplsupport - ok
19:31:01.0426 4880 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
19:31:01.0442 4880 WerSvc - ok
19:31:01.0442 4880 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:31:01.0442 4880 WfpLwf - ok
19:31:01.0457 4880 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:31:01.0457 4880 WIMMount - ok
19:31:01.0535 4880 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
19:31:01.0551 4880 WinDefend - ok
19:31:01.0567 4880 WinHttpAutoProxySvc - ok
19:31:01.0613 4880 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:31:01.0613 4880 Winmgmt - ok
19:31:01.0676 4880 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
19:31:01.0691 4880 WinRM - ok
19:31:01.0738 4880 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
19:31:01.0738 4880 WinUsb - ok
19:31:01.0769 4880 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
19:31:01.0801 4880 Wlansvc - ok
19:31:01.0832 4880 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:31:01.0832 4880 WmiAcpi - ok
19:31:01.0863 4880 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:31:01.0863 4880 wmiApSrv - ok
19:31:01.0941 4880 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
19:31:01.0957 4880 WMPNetworkSvc - ok
19:31:01.0972 4880 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:31:01.0988 4880 WPCSvc - ok
19:31:02.0019 4880 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:31:02.0019 4880 WPDBusEnum - ok
19:31:02.0050 4880 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:31:02.0050 4880 ws2ifsl - ok
19:31:02.0066 4880 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
19:31:02.0066 4880 wscsvc - ok
19:31:02.0066 4880 WSearch - ok
19:31:02.0097 4880 [ BAEDC491374DEFD5E76336901D6D397D ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys
19:31:02.0097 4880 wsvd - ok
19:31:02.0175 4880 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
19:31:02.0191 4880 wuauserv - ok
19:31:02.0237 4880 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:31:02.0237 4880 WudfPf - ok
19:31:02.0269 4880 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:31:02.0269 4880 WUDFRd - ok
19:31:02.0284 4880 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:31:02.0300 4880 wudfsvc - ok
19:31:02.0331 4880 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
19:31:02.0331 4880 WwanSvc - ok
19:31:02.0409 4880 [ 2B39B3198C3C0AFFD92A1CBDE9E80833 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
19:31:02.0409 4880 ZeroConfigService - ok
19:31:02.0425 4880 ================ Scan global ===============================
19:31:02.0471 4880 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
19:31:02.0518 4880 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
19:31:02.0534 4880 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
19:31:02.0565 4880 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
19:31:02.0596 4880 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
19:31:02.0612 4880 [Global] - ok
19:31:02.0612 4880 ================ Scan MBR ==================================
19:31:02.0612 4880 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:31:02.0752 4880 \Device\Harddisk0\DR0 - ok
19:31:02.0752 4880 ================ Scan VBR ==================================
19:31:02.0752 4880 [ 1052F447AA01C91B1C6E32252CEEA529 ] \Device\Harddisk0\DR0\Partition1
19:31:02.0752 4880 \Device\Harddisk0\DR0\Partition1 - ok
19:31:02.0752 4880 ============================================================
19:31:02.0752 4880 Scan finished
19:31:02.0752 4880 ============================================================
19:31:02.0768 5224 Detected object count: 0
19:31:02.0768 5224 Actual detected object count: 0
prosím o kontrolu logu, zamrzají aplikace
Re: prosím o kontrolu logu, zamrzají aplikace
memtest jsem zkoušel včera a po minimálně 2 hodinách běhu ukazoval 0 errors
----------------------------------------------------------------------------
CrystalDiskInfo 6.1.0 (C) 2008-2014 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x86)
Date : 2014/02/05 19:56:00
-- Controller Map ----------------------------------------------------------
- ATA Channel 0 (0) [ATA]
- ATA Channel 1 (1) [ATA]
+ ATA Channel 0 (0) [ATA]
- ST500LM012 HN-M500MBB ATA Device
- Optiarc DVD RW AD-7740H ATA Device
- ATA Channel 1 (1) [ATA]
+ Intel(R) 7 Series/C216 Chipset Family 4 port Serial ATA Storage Controller - 1E01 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Intel(R) 7 Series/C216 Chipset Family 2 port Serial ATA Storage Controller - 1E09 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
-- Disk List ---------------------------------------------------------------
(1) ST500LM012 HN-M500MBB : 500,1 GB [0/0/0, pd1] - st
----------------------------------------------------------------------------
(1) ST500LM012 HN-M500MBB
----------------------------------------------------------------------------
Model : ST500LM012 HN-M500MBB
Firmware : 2AR10001
Serial Number : S2U3J9DC617738
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300 | SATA/300
Power On Hours : 3356 hod.
Power On Count : 464 krát
Temparature : 43 C (109 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _51 000000000034 Počet chyb čtení
02 252 252 __0 000000000000 Průchodnost disku
03 _91 _91 _25 000000000B2B Čas na roztočení ploten
04 100 100 __0 0000000001CA Počet spuštění/zastavení
05 252 252 _10 000000000000 Počet přemapovaných sektorů
07 252 252 _51 000000000000 Počet chybných hledání
08 252 252 _15 000000000000 Čas potřebný na vyhledání
09 100 100 __0 000000000D1C Hodin v činnosti
0A 252 252 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000055 Počet pokusů o překalibrování
0C 100 100 __0 0000000001D0 Počet cyklů zapnutí zařízení
BF 100 100 __0 00000000000A Počet udalostí zaznamenaných otřesovým senzorem
C0 252 252 __0 000000000000 Počet vypnutí disku
C2 _57 _43 __0 00390010002B Teplota
C3 100 100 __0 000000000000 Počet oprav chybného čtení
C4 252 252 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 252 252 __0 000000000000 Počet podezřelých sektorů
C6 252 252 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 100 __0 000000004AFF Počet chyb při zápisu sektorů
DF 100 100 __0 000000000055 Zatížení budiče magnetických hlav způsobené opakovanými úkony
E1 _96 _96 __0 00000000AAD0 Počet cyklů načítání/vymazání
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5332 5533 4A39 4443 3631 3737 3338 2020 2020 2020
020: 0000 4000 0004 3241 5231 3030 3031 5354 3530 304C
030: 4D30 3132 2048 4E2D 4D35 3030 4D42 4220 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0006 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0F06 0004 004C 0040
080: 01FF 0028 746B 7D09 6123 7469 BC09 6123 203F 0033
090: 0033 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 6003 0000 5000 4CF2
110: 07BD 1C3A 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003F 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0400 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 0DA5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 64 64 34 00 00 00 00 00 00 02 26
010: 00 FC FC 00 00 00 00 00 00 00 03 23 00 5B 5B 2B
020: 0B 00 00 00 00 00 04 32 00 64 64 CA 01 00 00 00
030: 00 00 05 33 00 FC FC 00 00 00 00 00 00 00 07 2E
040: 00 FC FC 00 00 00 00 00 00 00 08 24 00 FC FC 00
050: 00 00 00 00 00 00 09 32 00 64 64 1C 0D 00 00 00
060: 00 00 0A 32 00 FC FC 00 00 00 00 00 00 00 0B 32
070: 00 64 64 55 00 00 00 00 00 00 0C 32 00 64 64 D0
080: 01 00 00 00 00 00 BF 22 00 64 64 0A 00 00 00 00
090: 00 00 C0 22 00 FC FC 00 00 00 00 00 00 00 C2 02
0A0: 00 39 2B 2B 00 10 00 39 00 00 C3 3A 00 64 64 00
0B0: 00 00 00 00 00 00 C4 32 00 FC FC 00 00 00 00 00
0C0: 00 00 C5 32 00 FC FC 00 00 00 00 00 00 00 C6 30
0D0: 00 FC FC 00 00 00 00 00 00 00 C7 36 00 C8 C8 00
0E0: 00 00 00 00 00 00 C8 2A 00 64 64 FF 4A 00 00 00
0F0: 00 00 DF 32 00 64 64 55 00 00 00 00 00 00 E1 32
100: 00 60 60 D0 AA 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 D8 18 00 5B
170: 03 00 01 00 02 6A 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 00 00 00 00 00 00 00 00 00 00 02 00
010: 00 00 00 00 00 00 00 00 00 00 03 19 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 0A 00 00 00 00 00 00 00 00 00 00 07 33
040: 00 00 00 00 00 00 00 00 00 00 08 0F 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 33 00 00 00 00 00 00 00 00 00 00 0B 00
070: 00 00 00 00 00 00 00 00 00 00 0C 00 00 00 00 00
080: 00 00 00 00 00 00 BF 00 00 00 00 00 00 00 00 00
090: 00 00 C0 00 00 00 00 00 00 00 00 00 00 00 C2 00
0A0: 00 00 00 00 00 00 00 00 00 00 C3 00 00 00 00 00
0B0: 00 00 00 00 00 00 C4 00 00 00 00 00 00 00 00 00
0C0: 00 00 C5 00 00 00 00 00 00 00 00 00 00 00 C6 00
0D0: 00 00 00 00 00 00 00 00 00 00 C7 00 00 00 00 00
0E0: 00 00 00 00 00 00 C8 00 00 00 00 00 00 00 00 00
0F0: 00 00 DF 00 00 00 00 00 00 00 00 00 00 00 E1 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3B
----------------------------------------------------------------------------
CrystalDiskInfo 6.1.0 (C) 2008-2014 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x86)
Date : 2014/02/05 19:56:00
-- Controller Map ----------------------------------------------------------
- ATA Channel 0 (0) [ATA]
- ATA Channel 1 (1) [ATA]
+ ATA Channel 0 (0) [ATA]
- ST500LM012 HN-M500MBB ATA Device
- Optiarc DVD RW AD-7740H ATA Device
- ATA Channel 1 (1) [ATA]
+ Intel(R) 7 Series/C216 Chipset Family 4 port Serial ATA Storage Controller - 1E01 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Intel(R) 7 Series/C216 Chipset Family 2 port Serial ATA Storage Controller - 1E09 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
-- Disk List ---------------------------------------------------------------
(1) ST500LM012 HN-M500MBB : 500,1 GB [0/0/0, pd1] - st
----------------------------------------------------------------------------
(1) ST500LM012 HN-M500MBB
----------------------------------------------------------------------------
Model : ST500LM012 HN-M500MBB
Firmware : 2AR10001
Serial Number : S2U3J9DC617738
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300 | SATA/300
Power On Hours : 3356 hod.
Power On Count : 464 krát
Temparature : 43 C (109 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _51 000000000034 Počet chyb čtení
02 252 252 __0 000000000000 Průchodnost disku
03 _91 _91 _25 000000000B2B Čas na roztočení ploten
04 100 100 __0 0000000001CA Počet spuštění/zastavení
05 252 252 _10 000000000000 Počet přemapovaných sektorů
07 252 252 _51 000000000000 Počet chybných hledání
08 252 252 _15 000000000000 Čas potřebný na vyhledání
09 100 100 __0 000000000D1C Hodin v činnosti
0A 252 252 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000055 Počet pokusů o překalibrování
0C 100 100 __0 0000000001D0 Počet cyklů zapnutí zařízení
BF 100 100 __0 00000000000A Počet udalostí zaznamenaných otřesovým senzorem
C0 252 252 __0 000000000000 Počet vypnutí disku
C2 _57 _43 __0 00390010002B Teplota
C3 100 100 __0 000000000000 Počet oprav chybného čtení
C4 252 252 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 252 252 __0 000000000000 Počet podezřelých sektorů
C6 252 252 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 100 __0 000000004AFF Počet chyb při zápisu sektorů
DF 100 100 __0 000000000055 Zatížení budiče magnetických hlav způsobené opakovanými úkony
E1 _96 _96 __0 00000000AAD0 Počet cyklů načítání/vymazání
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5332 5533 4A39 4443 3631 3737 3338 2020 2020 2020
020: 0000 4000 0004 3241 5231 3030 3031 5354 3530 304C
030: 4D30 3132 2048 4E2D 4D35 3030 4D42 4220 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0006 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0F06 0004 004C 0040
080: 01FF 0028 746B 7D09 6123 7469 BC09 6123 203F 0033
090: 0033 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 6003 0000 5000 4CF2
110: 07BD 1C3A 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003F 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0400 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 0DA5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 64 64 34 00 00 00 00 00 00 02 26
010: 00 FC FC 00 00 00 00 00 00 00 03 23 00 5B 5B 2B
020: 0B 00 00 00 00 00 04 32 00 64 64 CA 01 00 00 00
030: 00 00 05 33 00 FC FC 00 00 00 00 00 00 00 07 2E
040: 00 FC FC 00 00 00 00 00 00 00 08 24 00 FC FC 00
050: 00 00 00 00 00 00 09 32 00 64 64 1C 0D 00 00 00
060: 00 00 0A 32 00 FC FC 00 00 00 00 00 00 00 0B 32
070: 00 64 64 55 00 00 00 00 00 00 0C 32 00 64 64 D0
080: 01 00 00 00 00 00 BF 22 00 64 64 0A 00 00 00 00
090: 00 00 C0 22 00 FC FC 00 00 00 00 00 00 00 C2 02
0A0: 00 39 2B 2B 00 10 00 39 00 00 C3 3A 00 64 64 00
0B0: 00 00 00 00 00 00 C4 32 00 FC FC 00 00 00 00 00
0C0: 00 00 C5 32 00 FC FC 00 00 00 00 00 00 00 C6 30
0D0: 00 FC FC 00 00 00 00 00 00 00 C7 36 00 C8 C8 00
0E0: 00 00 00 00 00 00 C8 2A 00 64 64 FF 4A 00 00 00
0F0: 00 00 DF 32 00 64 64 55 00 00 00 00 00 00 E1 32
100: 00 60 60 D0 AA 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 D8 18 00 5B
170: 03 00 01 00 02 6A 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 00 00 00 00 00 00 00 00 00 00 02 00
010: 00 00 00 00 00 00 00 00 00 00 03 19 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 0A 00 00 00 00 00 00 00 00 00 00 07 33
040: 00 00 00 00 00 00 00 00 00 00 08 0F 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 33 00 00 00 00 00 00 00 00 00 00 0B 00
070: 00 00 00 00 00 00 00 00 00 00 0C 00 00 00 00 00
080: 00 00 00 00 00 00 BF 00 00 00 00 00 00 00 00 00
090: 00 00 C0 00 00 00 00 00 00 00 00 00 00 00 C2 00
0A0: 00 00 00 00 00 00 00 00 00 00 C3 00 00 00 00 00
0B0: 00 00 00 00 00 00 C4 00 00 00 00 00 00 00 00 00
0C0: 00 00 C5 00 00 00 00 00 00 00 00 00 00 00 C6 00
0D0: 00 00 00 00 00 00 00 00 00 00 C7 00 00 00 00 00
0E0: 00 00 00 00 00 00 C8 00 00 00 00 00 00 00 00 00
0F0: 00 00 DF 00 00 00 00 00 00 00 00 00 00 00 E1 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3B
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu, zamrzají aplikace
Disk OK , jen vyšší teplota , víc chladit.
00000000000A Počet udalostí zaznamenaných otřesovým senzorem
pár otřesů.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
00000000000A Počet udalostí zaznamenaných otřesovým senzorem
pár otřesů.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu, zamrzají aplikace
ComboFix 14-02-05.02 - Jirka 06.02.2014 15:15:22.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2982.1935 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\system32\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-06 do 2014-02-06 )))))))))))))))))))))))))))))))
.
.
2014-02-05 18:47 . 2014-02-05 18:48 -------- d-----w- c:\program files\CrystalDiskInfo
2014-02-04 10:59 . 2014-02-04 11:00 81382 ----a-w- c:\windows\system32\cc_20140204_115943.reg
2014-01-24 23:25 . 2014-02-02 23:11 -------- d-----w- c:\users\Jirka\AppData\Roaming\Mumble
2014-01-24 23:21 . 2014-01-24 23:21 -------- d-----w- c:\program files\Mumble
2014-01-24 19:28 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F51708E-326D-436A-BF44-0F477C96776E}\mpengine.dll
2014-01-15 10:09 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 10:09 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 10:09 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 10:09 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 10:09 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 10:09 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 10:09 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 10:09 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-09 11:16 . 2014-01-09 11:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Red Alert 3 Uprising
2014-01-09 11:16 . 2014-01-09 11:16 -------- d--h--r- c:\users\Jirka\AppData\Roaming\SecuROM
2014-01-07 15:08 . 2014-01-07 15:11 -------- d-----w- c:\program files\Origin Games
2014-01-07 14:58 . 2014-01-09 10:00 -------- d-----w- c:\users\Jirka\AppData\Roaming\Origin
2014-01-07 14:57 . 2014-01-07 15:08 -------- d-----w- c:\users\Jirka\AppData\Local\Origin
2014-01-07 14:54 . 2014-01-07 15:11 -------- d-----w- c:\programdata\Origin
2014-01-07 14:53 . 2014-01-07 14:53 -------- d-----w- c:\programdata\Electronic Arts
2014-01-07 14:53 . 2014-01-15 12:06 -------- d-----w- c:\program files\Origin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:41 . 2012-11-10 20:54 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-05 18:41 . 2012-11-10 20:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-04 22:33 . 2012-11-13 18:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-02-04 22:33 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-02-04 22:04 . 2012-11-13 16:25 139832 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-02-04 22:04 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-12-10 23:05 . 2013-12-10 23:05 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-10 23:05 . 2013-12-10 23:05 194048 ----a-w- c:\windows\system32\elshyph.dll
2013-12-10 23:05 . 2013-12-10 23:05 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-10 23:05 . 2013-12-10 23:05 645120 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-10 23:05 . 2013-12-10 23:05 182272 ----a-w- c:\windows\system32\msls31.dll
2013-12-10 23:05 . 2013-12-10 23:05 62464 ----a-w- c:\windows\system32\tdc.ocx
2013-12-10 23:05 . 2013-12-10 23:05 454656 ----a-w- c:\windows\system32\vbscript.dll
2013-12-10 23:05 . 2013-12-10 23:05 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 23:05 . 2013-12-10 23:05 337408 ----a-w- c:\windows\system32\html.iec
2013-12-10 23:05 . 2013-12-10 23:05 24576 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-10 23:05 . 2013-12-10 23:05 151552 ----a-w- c:\windows\system32\iexpress.exe
2013-12-10 23:05 . 2013-12-10 23:05 139264 ----a-w- c:\windows\system32\wextract.exe
2013-12-10 23:05 . 2013-12-10 23:05 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-10 23:05 . 2013-12-10 23:05 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-10 23:05 . 2013-12-10 23:05 36352 ----a-w- c:\windows\system32\imgutil.dll
2013-12-10 23:05 . 2013-12-10 23:05 13312 ----a-w- c:\windows\system32\mshta.exe
2013-12-10 23:05 . 2013-12-10 23:05 86016 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-10 23:05 . 2013-12-10 23:05 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-10 23:05 . 2013-12-10 23:05 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-10 23:05 . 2013-12-10 23:05 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-10 23:04 . 2013-12-10 23:04 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-12-10 23:04 . 2013-12-10 23:04 619520 ----a-w- c:\windows\system32\tdh.dll
2013-12-10 23:04 . 2013-12-10 23:04 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-12-10 23:04 . 2013-12-10 23:04 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-12-10 23:04 . 2013-12-10 23:04 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-12-10 23:03 . 2013-12-10 23:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-12-10 23:03 . 2013-12-10 23:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-12-10 23:03 . 2013-12-10 23:03 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-12-10 23:03 . 2013-12-10 23:03 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-11-26 09:23 . 2013-12-11 23:26 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 09:22 . 2013-12-11 23:26 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 08:53 . 2013-12-11 23:26 61952 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 08:52 . 2013-12-11 23:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 08:29 . 2013-12-11 23:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 08:29 . 2013-12-11 23:26 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 08:28 . 2013-12-11 23:26 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:16 . 2013-12-11 23:26 4243968 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 07:32 . 2013-12-11 23:26 1928192 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 06:33 . 2013-12-11 23:26 1820160 ----a-w- c:\windows\system32\wininet.dll
2013-11-12 02:07 . 2013-12-11 11:39 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-27 291608]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2011-12-15 520320]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2011-12-06 1654400]
"Dolby Advanced Audio v2"="c:\program files\Dolby Advanced Audio v2\pcee4.exe" [2011-12-20 507744]
"ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2012-01-16 2181120]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2012-02-21 7992320]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\Utility.exe" [2012-02-21 5931008]
"LockKey"="c:\program files\LockKey\LockKey.exe" [2011-08-25 337776]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-08 3076144]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
.
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2012-2-1 1102624]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-20 715248]
R3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 141312]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 143528]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 522280]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 33832]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 241936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [2011-11-15 232040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-11 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 50624]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-02-27 13592]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-12-03 24936]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-21 242240]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 33656]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 509440]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 104208]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg32.exe [2010-12-17 190592]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-08 974944]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 458464]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-29 161560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-29 363800]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 722704]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-12-15 24672]
S3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 141312]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-01-15 177960]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 280576]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-02-27 348440]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-02-27 792856]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2012-03-02 91248]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-07-17 55104]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-10 18:41]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-12-18 23:24; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3561304199-1950879549-2677905013-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,68,65,d4,00,4d,57,89,0b,9b,21,8c,99,59,57,f6,d1,1e,40,1e,00,
96,a6,48,99,6f,3b,85,f7,bd,ce,ea,05,7d,b5,5d,58,ea,66,19,0c,30,af,62,df,d1,\
"rkeysecu"=hex:fc,1e,7d,3e,ce,52,1c,ee,5b,1d,a6,c8,9f,16,ab,2f
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-02-06 15:34:48
ComboFix-quarantined-files.txt 2014-02-06 14:34
.
Před spuštěním: Volných bajtů: 243 101 822 976
Po spuštění: Volných bajtů: 243 003 101 184
.
- - End Of File - - FAF1650C1C262D3F2EF7770A6E6D2547
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2982.1935 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\system32\frapsvid.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-06 do 2014-02-06 )))))))))))))))))))))))))))))))
.
.
2014-02-05 18:47 . 2014-02-05 18:48 -------- d-----w- c:\program files\CrystalDiskInfo
2014-02-04 10:59 . 2014-02-04 11:00 81382 ----a-w- c:\windows\system32\cc_20140204_115943.reg
2014-01-24 23:25 . 2014-02-02 23:11 -------- d-----w- c:\users\Jirka\AppData\Roaming\Mumble
2014-01-24 23:21 . 2014-01-24 23:21 -------- d-----w- c:\program files\Mumble
2014-01-24 19:28 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F51708E-326D-436A-BF44-0F477C96776E}\mpengine.dll
2014-01-15 10:09 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 10:09 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 10:09 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 10:09 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 10:09 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 10:09 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 10:09 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 10:09 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-09 11:16 . 2014-01-09 11:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Red Alert 3 Uprising
2014-01-09 11:16 . 2014-01-09 11:16 -------- d--h--r- c:\users\Jirka\AppData\Roaming\SecuROM
2014-01-07 15:08 . 2014-01-07 15:11 -------- d-----w- c:\program files\Origin Games
2014-01-07 14:58 . 2014-01-09 10:00 -------- d-----w- c:\users\Jirka\AppData\Roaming\Origin
2014-01-07 14:57 . 2014-01-07 15:08 -------- d-----w- c:\users\Jirka\AppData\Local\Origin
2014-01-07 14:54 . 2014-01-07 15:11 -------- d-----w- c:\programdata\Origin
2014-01-07 14:53 . 2014-01-07 14:53 -------- d-----w- c:\programdata\Electronic Arts
2014-01-07 14:53 . 2014-01-15 12:06 -------- d-----w- c:\program files\Origin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:41 . 2012-11-10 20:54 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-05 18:41 . 2012-11-10 20:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-04 22:33 . 2012-11-13 18:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-02-04 22:33 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-02-04 22:04 . 2012-11-13 16:25 139832 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-02-04 22:04 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-12-10 23:05 . 2013-12-10 23:05 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-10 23:05 . 2013-12-10 23:05 194048 ----a-w- c:\windows\system32\elshyph.dll
2013-12-10 23:05 . 2013-12-10 23:05 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-10 23:05 . 2013-12-10 23:05 645120 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-10 23:05 . 2013-12-10 23:05 182272 ----a-w- c:\windows\system32\msls31.dll
2013-12-10 23:05 . 2013-12-10 23:05 62464 ----a-w- c:\windows\system32\tdc.ocx
2013-12-10 23:05 . 2013-12-10 23:05 454656 ----a-w- c:\windows\system32\vbscript.dll
2013-12-10 23:05 . 2013-12-10 23:05 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 23:05 . 2013-12-10 23:05 337408 ----a-w- c:\windows\system32\html.iec
2013-12-10 23:05 . 2013-12-10 23:05 24576 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-10 23:05 . 2013-12-10 23:05 151552 ----a-w- c:\windows\system32\iexpress.exe
2013-12-10 23:05 . 2013-12-10 23:05 139264 ----a-w- c:\windows\system32\wextract.exe
2013-12-10 23:05 . 2013-12-10 23:05 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-10 23:05 . 2013-12-10 23:05 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-10 23:05 . 2013-12-10 23:05 36352 ----a-w- c:\windows\system32\imgutil.dll
2013-12-10 23:05 . 2013-12-10 23:05 13312 ----a-w- c:\windows\system32\mshta.exe
2013-12-10 23:05 . 2013-12-10 23:05 86016 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-10 23:05 . 2013-12-10 23:05 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-10 23:05 . 2013-12-10 23:05 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-10 23:05 . 2013-12-10 23:05 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-10 23:04 . 2013-12-10 23:04 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-12-10 23:04 . 2013-12-10 23:04 619520 ----a-w- c:\windows\system32\tdh.dll
2013-12-10 23:04 . 2013-12-10 23:04 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-12-10 23:04 . 2013-12-10 23:04 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-12-10 23:04 . 2013-12-10 23:04 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-12-10 23:03 . 2013-12-10 23:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-12-10 23:03 . 2013-12-10 23:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-12-10 23:03 . 2013-12-10 23:03 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-12-10 23:03 . 2013-12-10 23:03 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-11-26 09:23 . 2013-12-11 23:26 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 09:22 . 2013-12-11 23:26 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 08:53 . 2013-12-11 23:26 61952 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 08:52 . 2013-12-11 23:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 08:29 . 2013-12-11 23:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 08:29 . 2013-12-11 23:26 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 08:28 . 2013-12-11 23:26 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:16 . 2013-12-11 23:26 4243968 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 07:32 . 2013-12-11 23:26 1928192 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 06:33 . 2013-12-11 23:26 1820160 ----a-w- c:\windows\system32\wininet.dll
2013-11-12 02:07 . 2013-12-11 11:39 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-27 291608]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2011-12-15 520320]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2011-12-06 1654400]
"Dolby Advanced Audio v2"="c:\program files\Dolby Advanced Audio v2\pcee4.exe" [2011-12-20 507744]
"ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2012-01-16 2181120]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2012-02-21 7992320]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\Utility.exe" [2012-02-21 5931008]
"LockKey"="c:\program files\LockKey\LockKey.exe" [2011-08-25 337776]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-08 3076144]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
.
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2012-2-1 1102624]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-20 715248]
R3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 141312]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 143528]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 522280]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 33832]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 241936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [2011-11-15 232040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-11 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 50624]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-02-27 13592]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-12-03 24936]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-21 242240]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 33656]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 509440]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 104208]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg32.exe [2010-12-17 190592]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-08 974944]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 458464]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-29 161560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-29 363800]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 722704]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-12-15 24672]
S3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 141312]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-01-15 177960]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 280576]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-02-27 348440]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-02-27 792856]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2012-03-02 91248]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-07-17 55104]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-10 18:41]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-12-18 23:24; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3561304199-1950879549-2677905013-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,68,65,d4,00,4d,57,89,0b,9b,21,8c,99,59,57,f6,d1,1e,40,1e,00,
96,a6,48,99,6f,3b,85,f7,bd,ce,ea,05,7d,b5,5d,58,ea,66,19,0c,30,af,62,df,d1,\
"rkeysecu"=hex:fc,1e,7d,3e,ce,52,1c,ee,5b,1d,a6,c8,9f,16,ab,2f
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-02-06 15:34:48
ComboFix-quarantined-files.txt 2014-02-06 14:34
.
Před spuštěním: Volných bajtů: 243 101 822 976
Po spuštění: Volných bajtů: 243 003 101 184
.
- - End Of File - - FAF1650C1C262D3F2EF7770A6E6D2547
A36C5E4F47E84449FF07ED3517B43A31
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu, zamrzají aplikace
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearjavaCache::
KillAll::
File::
c:\windows\system32\cc_20140204_115943.reg
RegLock::
[HKEY_USERS\S-1-5-21-3561304199-1950879549-2677905013-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,68,65,d4,00,4d,57,89,0b,9b,21,8c,99,59,57,f6,d1,1e,40,1e,00,
96,a6,48,99,6f,3b,85,f7,bd,ce,ea,05,7d,b5,5d,58,ea,66,19,0c,30,af,62,df,d1,\
"rkeysecu"=hex:fc,1e,7d,3e,ce,52,1c,ee,5b,1d,a6,c8,9f,16,ab,2f
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu, zamrzají aplikace
ComboFix 14-02-05.02 - Jirka 06.02.2014 16:40:41.2.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2982.2044 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jirka\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\cc_20140204_115943.reg"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\cc_20140204_115943.reg
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-06 do 2014-02-06 )))))))))))))))))))))))))))))))
.
.
2014-02-06 15:59 . 2014-02-06 16:02 -------- d-----w- c:\users\Jirka\AppData\Local\temp
2014-02-06 15:59 . 2014-02-06 15:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-06 15:59 . 2014-02-06 15:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-05 18:47 . 2014-02-05 18:48 -------- d-----w- c:\program files\CrystalDiskInfo
2014-01-24 23:25 . 2014-02-02 23:11 -------- d-----w- c:\users\Jirka\AppData\Roaming\Mumble
2014-01-24 23:21 . 2014-01-24 23:21 -------- d-----w- c:\program files\Mumble
2014-01-24 19:28 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F51708E-326D-436A-BF44-0F477C96776E}\mpengine.dll
2014-01-15 10:09 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 10:09 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 10:09 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 10:09 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 10:09 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 10:09 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 10:09 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 10:09 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-09 11:16 . 2014-01-09 11:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Red Alert 3 Uprising
2014-01-09 11:16 . 2014-01-09 11:16 -------- d--h--r- c:\users\Jirka\AppData\Roaming\SecuROM
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:41 . 2012-11-10 20:54 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-05 18:41 . 2012-11-10 20:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-04 22:33 . 2012-11-13 18:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-02-04 22:33 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-02-04 22:04 . 2012-11-13 16:25 139832 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-02-04 22:04 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-12-10 23:05 . 2013-12-10 23:05 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-10 23:05 . 2013-12-10 23:05 194048 ----a-w- c:\windows\system32\elshyph.dll
2013-12-10 23:05 . 2013-12-10 23:05 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-10 23:05 . 2013-12-10 23:05 645120 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-10 23:05 . 2013-12-10 23:05 182272 ----a-w- c:\windows\system32\msls31.dll
2013-12-10 23:05 . 2013-12-10 23:05 62464 ----a-w- c:\windows\system32\tdc.ocx
2013-12-10 23:05 . 2013-12-10 23:05 454656 ----a-w- c:\windows\system32\vbscript.dll
2013-12-10 23:05 . 2013-12-10 23:05 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 23:05 . 2013-12-10 23:05 337408 ----a-w- c:\windows\system32\html.iec
2013-12-10 23:05 . 2013-12-10 23:05 24576 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-10 23:05 . 2013-12-10 23:05 151552 ----a-w- c:\windows\system32\iexpress.exe
2013-12-10 23:05 . 2013-12-10 23:05 139264 ----a-w- c:\windows\system32\wextract.exe
2013-12-10 23:05 . 2013-12-10 23:05 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-10 23:05 . 2013-12-10 23:05 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-10 23:05 . 2013-12-10 23:05 36352 ----a-w- c:\windows\system32\imgutil.dll
2013-12-10 23:05 . 2013-12-10 23:05 13312 ----a-w- c:\windows\system32\mshta.exe
2013-12-10 23:05 . 2013-12-10 23:05 86016 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-10 23:05 . 2013-12-10 23:05 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-10 23:05 . 2013-12-10 23:05 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-10 23:05 . 2013-12-10 23:05 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-10 23:04 . 2013-12-10 23:04 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-12-10 23:04 . 2013-12-10 23:04 619520 ----a-w- c:\windows\system32\tdh.dll
2013-12-10 23:04 . 2013-12-10 23:04 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-12-10 23:04 . 2013-12-10 23:04 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-12-10 23:04 . 2013-12-10 23:04 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-12-10 23:03 . 2013-12-10 23:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-12-10 23:03 . 2013-12-10 23:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-12-10 23:03 . 2013-12-10 23:03 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-12-10 23:03 . 2013-12-10 23:03 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-11-26 09:23 . 2013-12-11 23:26 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 09:22 . 2013-12-11 23:26 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 08:53 . 2013-12-11 23:26 61952 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 08:52 . 2013-12-11 23:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 08:29 . 2013-12-11 23:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 08:29 . 2013-12-11 23:26 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 08:28 . 2013-12-11 23:26 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:16 . 2013-12-11 23:26 4243968 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 07:32 . 2013-12-11 23:26 1928192 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 06:33 . 2013-12-11 23:26 1820160 ----a-w- c:\windows\system32\wininet.dll
2013-11-12 02:07 . 2013-12-11 11:39 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-27 291608]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2011-12-15 520320]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2011-12-06 1654400]
"Dolby Advanced Audio v2"="c:\program files\Dolby Advanced Audio v2\pcee4.exe" [2011-12-20 507744]
"ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2012-01-16 2181120]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2012-02-21 7992320]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\Utility.exe" [2012-02-21 5931008]
"LockKey"="c:\program files\LockKey\LockKey.exe" [2011-08-25 337776]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-08 3076144]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
.
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2012-2-1 1102624]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-20 715248]
R3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 141312]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 143528]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 522280]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 33832]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 241936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [2011-11-15 232040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-11 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 50624]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-02-27 13592]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-12-03 24936]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-21 242240]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 33656]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 509440]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 104208]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg32.exe [2010-12-17 190592]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-08 974944]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 458464]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-29 161560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-29 363800]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 722704]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-12-15 24672]
S3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 141312]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-01-15 177960]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 280576]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-02-27 348440]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-02-27 792856]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2012-03-02 91248]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-07-17 55104]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-10 18:41]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-12-18 23:24; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3561304199-1950879549-2677905013-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,68,65,d4,00,4d,57,89,0b,9b,21,8c,99,59,57,f6,d1,1e,40,1e,00,
96,a6,48,99,6f,3b,85,f7,bd,ce,ea,05,7d,b5,5d,58,ea,66,19,0c,30,af,62,df,d1,\
"rkeysecu"=hex:fc,1e,7d,3e,ce,52,1c,ee,5b,1d,a6,c8,9f,16,ab,2f
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Lenovo\Bluetooth Software\btwdins.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\AUDIODG.EXE
.
**************************************************************************
.
Celkový čas: 2014-02-06 17:24:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-02-06 16:24
ComboFix2.txt 2014-02-06 14:34
.
Před spuštěním: Volných bajtů: 243 111 124 992
Po spuštění: Volných bajtů: 242 925 084 672
.
- - End Of File - - 0ECF9716A9F09339AF39D6FCEB4C1DD3
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2982.2044 [GMT 1:00]
Spuštěný z: c:\users\Jirka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jirka\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\cc_20140204_115943.reg"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\cc_20140204_115943.reg
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-06 do 2014-02-06 )))))))))))))))))))))))))))))))
.
.
2014-02-06 15:59 . 2014-02-06 16:02 -------- d-----w- c:\users\Jirka\AppData\Local\temp
2014-02-06 15:59 . 2014-02-06 15:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-06 15:59 . 2014-02-06 15:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-05 18:47 . 2014-02-05 18:48 -------- d-----w- c:\program files\CrystalDiskInfo
2014-01-24 23:25 . 2014-02-02 23:11 -------- d-----w- c:\users\Jirka\AppData\Roaming\Mumble
2014-01-24 23:21 . 2014-01-24 23:21 -------- d-----w- c:\program files\Mumble
2014-01-24 19:28 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F51708E-326D-436A-BF44-0F477C96776E}\mpengine.dll
2014-01-15 10:09 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 10:09 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 10:09 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 10:09 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 10:09 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 10:09 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 10:09 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 10:09 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-09 11:16 . 2014-01-09 11:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Red Alert 3 Uprising
2014-01-09 11:16 . 2014-01-09 11:16 -------- d--h--r- c:\users\Jirka\AppData\Roaming\SecuROM
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:41 . 2012-11-10 20:54 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-05 18:41 . 2012-11-10 20:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-04 22:33 . 2012-11-13 18:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-02-04 22:33 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-02-04 22:04 . 2012-11-13 16:25 139832 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-02-04 22:04 . 2012-11-13 16:24 281768 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-12-10 23:05 . 2013-12-10 23:05 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-10 23:05 . 2013-12-10 23:05 194048 ----a-w- c:\windows\system32\elshyph.dll
2013-12-10 23:05 . 2013-12-10 23:05 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-10 23:05 . 2013-12-10 23:05 645120 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-10 23:05 . 2013-12-10 23:05 182272 ----a-w- c:\windows\system32\msls31.dll
2013-12-10 23:05 . 2013-12-10 23:05 62464 ----a-w- c:\windows\system32\tdc.ocx
2013-12-10 23:05 . 2013-12-10 23:05 454656 ----a-w- c:\windows\system32\vbscript.dll
2013-12-10 23:05 . 2013-12-10 23:05 34816 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 23:05 . 2013-12-10 23:05 337408 ----a-w- c:\windows\system32\html.iec
2013-12-10 23:05 . 2013-12-10 23:05 24576 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-10 23:05 . 2013-12-10 23:05 151552 ----a-w- c:\windows\system32\iexpress.exe
2013-12-10 23:05 . 2013-12-10 23:05 139264 ----a-w- c:\windows\system32\wextract.exe
2013-12-10 23:05 . 2013-12-10 23:05 1051136 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-10 23:05 . 2013-12-10 23:05 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-10 23:05 . 2013-12-10 23:05 36352 ----a-w- c:\windows\system32\imgutil.dll
2013-12-10 23:05 . 2013-12-10 23:05 13312 ----a-w- c:\windows\system32\mshta.exe
2013-12-10 23:05 . 2013-12-10 23:05 86016 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-10 23:05 . 2013-12-10 23:05 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-10 23:05 . 2013-12-10 23:05 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-10 23:05 . 2013-12-10 23:05 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-10 23:04 . 2013-12-10 23:04 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-12-10 23:04 . 2013-12-10 23:04 619520 ----a-w- c:\windows\system32\tdh.dll
2013-12-10 23:04 . 2013-12-10 23:04 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-12-10 23:04 . 2013-12-10 23:04 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-12-10 23:04 . 2013-12-10 23:04 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-12-10 23:03 . 2013-12-10 23:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-12-10 23:03 . 2013-12-10 23:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-12-10 23:03 . 2013-12-10 23:03 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-12-10 23:03 . 2013-12-10 23:03 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-11-26 09:23 . 2013-12-11 23:26 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 09:22 . 2013-12-11 23:26 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 08:53 . 2013-12-11 23:26 61952 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 08:52 . 2013-12-11 23:26 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 08:29 . 2013-12-11 23:26 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 08:29 . 2013-12-11 23:26 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 08:28 . 2013-12-11 23:26 553472 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:16 . 2013-12-11 23:26 4243968 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 07:32 . 2013-12-11 23:26 1928192 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 06:33 . 2013-12-11 23:26 1820160 ----a-w- c:\windows\system32\wininet.dll
2013-11-12 02:07 . 2013-12-11 11:39 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-27 291608]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2011-12-15 520320]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2011-12-06 1654400]
"Dolby Advanced Audio v2"="c:\program files\Dolby Advanced Audio v2\pcee4.exe" [2011-12-20 507744]
"ETDCtrl"="c:\program files\Elantech\ETDCtrl.exe" [2012-01-16 2181120]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2012-02-21 7992320]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\Utility.exe" [2012-02-21 5931008]
"LockKey"="c:\program files\LockKey\LockKey.exe" [2011-08-25 337776]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-08 3076144]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 146032]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 181360]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 190064]
.
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2012-2-1 1102624]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Lenovo\Bluetooth Software\BtwProximityCP.dll
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-20 715248]
R3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\amppal.sys [2011-12-05 141312]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-02-02 143528]
R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2012-02-02 522280]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2012-02-02 33832]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-12-08 241936]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [2011-11-15 232040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-11 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 50624]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-02-27 13592]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-12-03 24936]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-21 242240]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 33656]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-12-05 509440]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-12-05 104208]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg32.exe [2010-12-17 190592]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-09-08 974944]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 458464]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-29 161560]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-29 363800]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2011-12-08 722704]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-12-15 24672]
S3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-12-05 141312]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-01-15 177960]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 280576]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-02-27 348440]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-02-27 792856]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2012-03-02 91248]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-07-17 55104]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-10 18:41]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-12-18 23:24; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\nrjfe96z.default-1387405457014\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3561304199-1950879549-2677905013-1000\Software\SecuROM\License information*]
"datasecu"=hex:f5,68,65,d4,00,4d,57,89,0b,9b,21,8c,99,59,57,f6,d1,1e,40,1e,00,
96,a6,48,99,6f,3b,85,f7,bd,ce,ea,05,7d,b5,5d,58,ea,66,19,0c,30,af,62,df,d1,\
"rkeysecu"=hex:fc,1e,7d,3e,ce,52,1c,ee,5b,1d,a6,c8,9f,16,ab,2f
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Lenovo\Bluetooth Software\btwdins.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\AUDIODG.EXE
.
**************************************************************************
.
Celkový čas: 2014-02-06 17:24:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-02-06 16:24
ComboFix2.txt 2014-02-06 14:34
.
Před spuštěním: Volných bajtů: 243 111 124 992
Po spuštění: Volných bajtů: 242 925 084 672
.
- - End Of File - - 0ECF9716A9F09339AF39D6FCEB4C1DD3
A36C5E4F47E84449FF07ED3517B43A31
Re: prosím o kontrolu logu, zamrzají aplikace
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:36:52, on 6.2.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent.exe
C:\Program Files\Dolby Advanced Audio v2\pcee4.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Users\Jirka\Downloads\kontrola PC\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t
O4 - HKLM\..\Run: [Dolby Advanced Audio v2] "C:\Program Files\Dolby Advanced Audio v2\pcee4.exe" -autostart
O4 - HKLM\..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\Utility.exe
O4 - HKLM\..\Run: [LockKey] C:\Program Files\LockKey\LockKey.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\nvinit.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg32.exe,-100 (CxAudMsg) - Conexant Systems Inc. - C:\Windows\system32\CxAudMsg32.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 8439 bytes
Scan saved at 17:36:52, on 6.2.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent.exe
C:\Program Files\Dolby Advanced Audio v2\pcee4.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Users\Jirka\Downloads\kontrola PC\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t
O4 - HKLM\..\Run: [Dolby Advanced Audio v2] "C:\Program Files\Dolby Advanced Audio v2\pcee4.exe" -autostart
O4 - HKLM\..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\Utility.exe
O4 - HKLM\..\Run: [LockKey] C:\Program Files\LockKey\LockKey.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\nvinit.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg32.exe,-100 (CxAudMsg) - Conexant Systems Inc. - C:\Windows\system32\CxAudMsg32.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 8439 bytes
Re: prosím o kontrolu logu, zamrzají aplikace
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-02-06 17:39:19
-----------------------------
17:39:19.869 OS Version: Windows 6.1.7601 Service Pack 1
17:39:19.869 Number of processors: 4 586 0x2A07
17:39:19.870 ComputerName: JIRKA-PC UserName: Jirka
17:39:24.715 Initialize success
17:39:52.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:39:52.972 Disk 0 Vendor: ST500LM012_HN-M500MBB 2AR10001 Size: 476940MB BusType: 3
17:39:53.201 Disk 0 MBR read successfully
17:39:53.204 Disk 0 MBR scan
17:39:53.207 Disk 0 Windows 7 default MBR code
17:39:53.210 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
17:39:53.215 Disk 0 scanning sectors +976752000
17:39:53.358 Disk 0 scanning C:\Windows\system32\drivers
17:40:04.770 Service scanning
17:40:24.239 Modules scanning
17:40:47.842 Module: C:\Windows\System32\user32.dll **SUSPICIOUS**
17:40:51.336 Disk 0 trace - called modules:
17:40:51.352 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
17:40:51.368 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863c2030]
17:40:51.368 3 CLASSPNP.SYS[8b5b759e] -> nt!IofCallDriver -> [0x862887e0]
17:40:51.368 5 ACPI.sys[833c13d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85559908]
17:40:51.368 Scan finished successfully
17:41:10.540 Disk 0 MBR has been saved successfully to "C:\Users\Jirka\Downloads\kontrola PC\MBR.dat"
17:41:20.524 The log file has been saved successfully to "C:\Users\Jirka\Downloads\kontrola PC\aswMBR.txt"
Run date: 2014-02-06 17:39:19
-----------------------------
17:39:19.869 OS Version: Windows 6.1.7601 Service Pack 1
17:39:19.869 Number of processors: 4 586 0x2A07
17:39:19.870 ComputerName: JIRKA-PC UserName: Jirka
17:39:24.715 Initialize success
17:39:52.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:39:52.972 Disk 0 Vendor: ST500LM012_HN-M500MBB 2AR10001 Size: 476940MB BusType: 3
17:39:53.201 Disk 0 MBR read successfully
17:39:53.204 Disk 0 MBR scan
17:39:53.207 Disk 0 Windows 7 default MBR code
17:39:53.210 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
17:39:53.215 Disk 0 scanning sectors +976752000
17:39:53.358 Disk 0 scanning C:\Windows\system32\drivers
17:40:04.770 Service scanning
17:40:24.239 Modules scanning
17:40:47.842 Module: C:\Windows\System32\user32.dll **SUSPICIOUS**
17:40:51.336 Disk 0 trace - called modules:
17:40:51.352 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
17:40:51.368 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863c2030]
17:40:51.368 3 CLASSPNP.SYS[8b5b759e] -> nt!IofCallDriver -> [0x862887e0]
17:40:51.368 5 ACPI.sys[833c13d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85559908]
17:40:51.368 Scan finished successfully
17:41:10.540 Disk 0 MBR has been saved successfully to "C:\Users\Jirka\Downloads\kontrola PC\MBR.dat"
17:41:20.524 The log file has been saved successfully to "C:\Users\Jirka\Downloads\kontrola PC\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu, zamrzají aplikace
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
C:\Windows\System32\user32.dll
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Návod
Kód: Vybrat vše
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
C:\Windows\System32\user32.dll
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu, zamrzají aplikace
v HJT fixnuto (sice jsem to musel fixnout asi 3x, ale potom už se to v logu neobjevovalo)
test souboru:
https://www.virustotal.com/cs/file/4809 ... 391715174/
http://r.virscan.org/report/393096d1d81 ... ca56f.html
test souboru:
https://www.virustotal.com/cs/file/4809 ... 391715174/
http://r.virscan.org/report/393096d1d81 ... ca56f.html
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu, zamrzají aplikace
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Co problémy?
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu, zamrzají aplikace
problémy pořád stejné jako jsou popsané v prvním příspěvku + přiložené screenshoty :/
teď mě napadlo že když zapnu NB tak mam využití ramek na cca 1GB až 1,25GB (44%) žádné aplikace nemam zaplé, a stejně to neklesne ani po 10 minutách a dříve to využití RAM bylo okolo cca 33 %
teď mě napadlo že když zapnu NB tak mam využití ramek na cca 1GB až 1,25GB (44%) žádné aplikace nemam zaplé, a stejně to neklesne ani po 10 minutách a dříve to využití RAM bylo okolo cca 33 %
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 94 hostů