Prosím o preventivní kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 03 led 2015 13:27

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:17:02, on 3.1.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Documents and Settings\Vašek\Dokumenty\Downloads\hijackthis (2).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKUS\S-1-5-21-1614895754-838170752-725345543-1009\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

--
End of file - 5110 bytes

Reklama
vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 03 led 2015 13:28

PC se chová dobře.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod Orcus » 03 led 2015 18:18

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 03 led 2015 22:52

# AdwCleaner v4.106 - Report created 03/01/2015 at 22:46:49
# Updated 21/12/2014 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Vašek - VP-613748361AB3
# Running from : C:\Documents and Settings\Vašek\Plocha\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Documents and Settings\Vašek\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\user.js
Folder Found : C:\Documents and Settings\Vašek\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\Extensions\ascsurfingprotection@iobit.com

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\5e55dedfb33eed42
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92A9ACF4-9333-43AE-9698-DB283326F87F}
Key Found : HKCU\Software\Myfree Codec
Key Found : HKCU\Software\SBConvert
Key Found : HKCU\Software\StartSearch
Key Found : HKCU\Software\vShare.tv
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1500}

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v


-\\ Google Chrome v

[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://asksearch.ask.com/redirect?clien ... apn_ptnrs=^AM3&apn_dtid=^YYYYYY^XE^CZ&apn_dbr=ie_8.0.6001.18702&&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://home.speedbit.com/search.aspx?site=web&q={searchTerms}&sa=++Search++
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.sweetim.com/search.asp?q={searchTerms}&ln=en&src=95&barid=%7B4ece6b13-2200-11e2-8f16-0024215e5161%7D&sf=0
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.certified-toolbar.com?si= ... -860260&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.certified-toolbar.com?si= ... -860260&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=28AFC0143DD349F8
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss&mntrId=28AFC0143DD349F8&affID=124589&tsp=5000
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss&mntrId=28AFC0143DD349F8&affID=124589&tsp=5000
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392

*************************

AdwCleaner[R0].txt - [29286 octets] - [02/01/2015 12:05:49]
AdwCleaner[R1].txt - [25389 octets] - [02/01/2015 17:53:20]
AdwCleaner[R2].txt - [4675 octets] - [03/01/2015 22:46:49]
AdwCleaner[S0].txt - [25601 octets] - [02/01/2015 17:56:31]

########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [4796 octets] ##########

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 03 led 2015 22:54

Mám XP, MbAM nejde spustit.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod jaro3 » 04 led 2015 10:09

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 04 led 2015 14:07

# AdwCleaner v4.106 - Report created 04/01/2015 at 14:01:31
# Updated 21/12/2014 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Vašek - VP-613748361AB3
# Running from : C:\Documents and Settings\Vašek\Plocha\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\Vašek\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\Extensions\ascsurfingprotection@iobit.com
File Deleted : C:\Documents and Settings\Vašek\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\user.js

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\5e55dedfb33eed42
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92A9ACF4-9333-43AE-9698-DB283326F87F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Myfree Codec
Key Deleted : HKCU\Software\SBConvert
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\vShare.tv
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1500}

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v


-\\ Google Chrome v

[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://asksearch.ask.com/redirect?clien ... apn_ptnrs=^AM3&apn_dtid=^YYYYYY^XE^CZ&apn_dbr=ie_8.0.6001.18702&&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com?si= ... -860260&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com?si= ... -860260&q={searchTerms}
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=28AFC0143DD349F8
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss&mntrId=28AFC0143DD349F8&affID=124589&tsp=5000
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&babsrc=SP_ss&mntrId=28AFC0143DD349F8&affID=124589&tsp=5000
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://home.speedbit.com/search.aspx?site=web&q={searchTerms}&sa=++Search++
[C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.sweetim.com/search.asp?q={searchTerms}&ln=en&src=95&barid=%7B4ece6b13-2200-11e2-8f16-0024215e5161%7D&sf=0

*************************

AdwCleaner[R0].txt - [29286 octets] - [02/01/2015 12:05:49]
AdwCleaner[R1].txt - [25389 octets] - [02/01/2015 17:53:20]
AdwCleaner[R2].txt - [4876 octets] - [03/01/2015 22:46:49]
AdwCleaner[R3].txt - [4936 octets] - [04/01/2015 13:49:42]
AdwCleaner[S0].txt - [25601 octets] - [02/01/2015 17:56:31]
AdwCleaner[S1].txt - [4909 octets] - [04/01/2015 14:01:31]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4969 octets] ##########

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 04 led 2015 14:17

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Microsoft Windows XP x86
Ran by Vašek on ne 04.01.2015 at 14:11:51,46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 04.01.2015 at 14:15:02,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 04 led 2015 14:32

RogueKiller V10.1.1.0 [Dec 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno : Normální režim
Uživatel : Vašek [Práva správce]
Mód : Prohledat -- Datum : 01/04/2015 14:28:49

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: WDC WD50 00AAKS-00UU3 SCSI Disk Device +++++
--- User ---
[MBR] dc7ef553548c6efaa28e5e94fb21f5bb
[BSP] 7363671c331a0444e6f8ec011529cd90 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 60000 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 122881185 | Size: 416936 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )


============================================
RKreport_DEL_01032015_111621.log - RKreport_DEL_01032015_113448.log - RKreport_SCN_01022015_191135.log - RKreport_SCN_01032015_111530.log
RKreport_SCN_01032015_111818.log

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod Orcus » 04 led 2015 19:10

Stáhni
Zoek.exe

a ulož si ho na plochu.
Zavři všechny ostatní programy, okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor, náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


Klikni na Run Script
Program provede sken, opravu, sken i oprava může trvat i více minut, je třeba posečkat do konce. Do okna neklikej!
rogram nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů, jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

====================================================

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Pokud se log nevejde do jedné zprávy, rozděl jej na více částí.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 05 led 2015 20:51

Zoek.exe v5.0.0.0 Updated 31-12-2014
Tool run by Vašek on po 05.01.2015 at 20:22:21,50.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Vašek\Plocha\zoek\zoek.exe.com [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-01-03-115300.log 16260 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Documents and Settings\VAEK~1\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Documents and Settings\VAEK~1\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Start and Search pages ======================

ProfilePath: C:\Documents and Settings\VAEK~1\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.12.2014 21:26]

==== Firefox Extensions ======================

ProfilePath: C:\Documents and Settings\VAEK~1\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default
- Undetermined - C:\Documents and Settings\Vašek\Data aplikací\Mozilla\Firefox\Profiles\u4ev608i.default\extensions\ascsurfingprotection@iobit.com

==== Firefox Plugins ======================


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[27.12.2014 21:26]

avast WebRep - Andrea\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
Seznam Li\u0161ti\u010Dka - Email - Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Sticky Board - Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\clgkphifhohebfokmfiekobchoebldlf
AdBlock - Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Seznam LištiÄŤka - Rychlá volba - Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz="

==== Reset Google Chrome ======================

C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Documents and Settings\Andrea\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Documents and Settings\Michal\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Documents and Settings\Naďa\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Vašek\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\Andrea\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\Michal\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\Naďa\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\Vašek\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=947 folders=333 29634753 bytes)

==== Empty Temp Folders ======================

C:\Documents and Settings\Administrator\Local Settings\temp emptied successfully
C:\Documents and Settings\Andrea\Local Settings\temp emptied successfully
C:\Documents and Settings\Default User\Local Settings\temp emptied successfully
C:\Documents and Settings\LocalService\Local Settings\temp emptied successfully
C:\Documents and Settings\Michal\Local Settings\temp emptied successfully
C:\Documents and Settings\Naďa\Local Settings\temp emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\temp emptied successfully
C:\Documents and Settings\UpdatusUser\Local Settings\temp emptied successfully
C:\Documents and Settings\Vašek\Local Settings\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\VAEK~1\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\Vašek\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on po 05.01.2015 at 20:48:58,09 ======================

vašekp
Level 3
Level 3
Příspěvky: 430
Registrován: listopad 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o preventivní kontrolu logu

Příspěvekod vašekp » 05 led 2015 22:10

20:54:54.0640 0x086c TDSS rootkit removing tool 3.0.0.42 Dec 12 2014 00:35:20
20:55:01.0218 0x086c ============================================================
20:55:01.0218 0x086c Current date / time: 2015/01/05 20:55:01.0218
20:55:01.0218 0x086c SystemInfo:
20:55:01.0218 0x086c
20:55:01.0218 0x086c OS Version: 5.1.2600 ServicePack: 3.0
20:55:01.0218 0x086c Product type: Workstation
20:55:01.0218 0x086c ComputerName: VP-613748361AB3
20:55:01.0218 0x086c UserName: Vašek
20:55:01.0218 0x086c Windows directory: C:\WINDOWS
20:55:01.0218 0x086c System windows directory: C:\WINDOWS
20:55:01.0218 0x086c Processor architecture: Intel x86
20:55:01.0218 0x086c Number of processors: 1
20:55:01.0218 0x086c Page size: 0x1000
20:55:01.0218 0x086c Boot type: Normal boot
20:55:01.0218 0x086c ============================================================
20:55:01.0421 0x086c KLMD registered as C:\WINDOWS\system32\drivers\92578635.sys
20:55:01.0625 0x086c System UUID: {F417A658-58D7-1649-13BA-0D249C6FDD64}
20:55:02.0187 0x086c Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
20:55:02.0203 0x086c ============================================================
20:55:02.0203 0x086c \Device\Harddisk0\DR0:
20:55:02.0203 0x086c MBR partitions:
20:55:02.0203 0x086c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x7530462
20:55:02.0203 0x086c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x75304A1, BlocksNum 0x32E547A0
20:55:02.0203 0x086c ============================================================
20:55:02.0218 0x086c C: <-> \Device\Harddisk0\DR0\Partition1
20:55:02.0281 0x086c E: <-> \Device\Harddisk0\DR0\Partition2
20:55:02.0281 0x086c ============================================================
20:55:02.0281 0x086c Initialize success
20:55:02.0281 0x086c ============================================================
20:55:04.0046 0x0f98 ============================================================
20:55:04.0046 0x0f98 Scan started
20:55:04.0046 0x0f98 Mode: Manual;
20:55:04.0046 0x0f98 ============================================================
20:55:04.0046 0x0f98 KSN ping started
20:55:06.0531 0x0f98 KSN ping finished: true
20:55:07.0312 0x0f98 ================ Scan system memory ========================
20:55:07.0312 0x0f98 System memory - ok
20:55:07.0312 0x0f98 ================ Scan services =============================
20:55:07.0421 0x0f98 [ B33CF4DE909A5B30F526D82053A63C8E, ABF5BB962C038E545C18B96E686E072D780C907096C7BB341297AF31D3703ABD ] ABBYY.Licensing.FineReader.Sprint.9.0 C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
20:55:07.0453 0x0f98 ABBYY.Licensing.FineReader.Sprint.9.0 - ok
20:55:07.0609 0x0f98 Abiosdsk - ok
20:55:07.0609 0x0f98 abp480n5 - ok
20:55:07.0656 0x0f98 [ 4FE34F1F3126B61FCC6B2043AA8112C9, DE370865E47A5D2A4B227EEFFB42384F67F08D622BF936A9C9CEF70CC47F324B ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:55:07.0671 0x0f98 ACPI - ok
20:55:07.0703 0x0f98 [ AFDFF022A01F0B11C776F0860C3B282F, 135E5257B62D921B76271014301E9EA1E2383D5DBB04E475DC3A7EFFD2561F56 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:55:07.0703 0x0f98 ACPIEC - ok
20:55:07.0750 0x0f98 [ 4E48A7DF7ECACB38C686B2BEBAA687A3, D4DEE6BD464855B24A6D40BC6A9279B2041099615C6A319D869DA113AD896EA3 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:55:07.0765 0x0f98 AdobeFlashPlayerUpdateSvc - ok
20:55:07.0765 0x0f98 adpu160m - ok
20:55:07.0812 0x0f98 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:55:07.0812 0x0f98 aec - ok
20:55:07.0843 0x0f98 [ FE3EA6E9AFC1A78E6EDCA121E006AFB7, B596ABBAC058D93C505C9DBF8685049C88E4364195A4092DB580D2D44FA8C23C ] Afc C:\WINDOWS\system32\drivers\Afc.sys
20:55:07.0843 0x0f98 Afc - ok
20:55:07.0875 0x0f98 [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:55:07.0890 0x0f98 AFD - ok
20:55:07.0890 0x0f98 Aha154x - ok
20:55:07.0906 0x0f98 aic78u2 - ok
20:55:07.0906 0x0f98 aic78xx - ok
20:55:07.0937 0x0f98 [ E0A6FA244B8624D78FE5FF6F56A33BAE, 26B828FDB03AE4A4F1DC7A1792F9BAD69CF947897D47F5E567F24F4B6D5CB541 ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:55:07.0937 0x0f98 Alerter - ok
20:55:07.0953 0x0f98 [ 88842DE939A827577BF24243699AC80A, A49C9A6A9941F3A2FBBCFE1F6DB48B632739D00670AC98ECCCBC7FD9E786B21A ] ALG C:\WINDOWS\System32\alg.exe
20:55:07.0953 0x0f98 ALG - ok
20:55:07.0968 0x0f98 AliIde - ok
20:55:08.0062 0x0f98 [ F6AF59D6EEE5E1C304F7F73706AD11D8, F5D39EF40CDB5102A84C8594CFC54DDBD5060E193E6D07421A9003D2ABC63E30 ] Ambfilt C:\WINDOWS\system32\drivers\Ambfilt.sys
20:55:08.0156 0x0f98 Ambfilt - ok
20:55:08.0171 0x0f98 [ FCFFA85CFD4BF7A4711012847048DCA3, 89599AC5EBBA580B202F78ED0D6A7D741CE65B6C3FBCD81244CD170766316033 ] AmdK8 C:\WINDOWS\system32\DRIVERS\AmdK8.sys
20:55:08.0187 0x0f98 AmdK8 - ok
20:55:08.0187 0x0f98 amsint - ok
20:55:08.0218 0x0f98 [ 6B8E7A90E576D4FE308F97C69060A171, 6CE49BC78715737D78E05DECAC23E26A5672ACD2CF3D10154FEA9D47B318D47C ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:55:08.0234 0x0f98 AppMgmt - ok
20:55:08.0234 0x0f98 asc - ok
20:55:08.0250 0x0f98 asc3350p - ok
20:55:08.0250 0x0f98 asc3550 - ok
20:55:08.0328 0x0f98 [ 4EABF511B1AF176A971C3271E48FA3A8, D9F5A700BDC670CD59BFCBFC45F7F90D63F46B9B86AA129B8A18C0066F2A07A0 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:55:08.0343 0x0f98 aspnet_state - ok
20:55:08.0390 0x0f98 [ 9D23DE88C3B18BA87CD4587177CA6CEA, 46DBB867FC73E30320852F744F38B66906DD5B96C4EBB03F504CF33E867A8470 ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys
20:55:08.0390 0x0f98 aswHwid - ok
20:55:08.0421 0x0f98 [ 73A9014A9C4B19AA093DA05ED4246E27, F03C8433EB00229490BCD293CC97EF72452E156212D56C24BBA95C8E1B207D1A ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
20:55:08.0421 0x0f98 aswMonFlt - ok
20:55:08.0453 0x0f98 [ 0926775B8C3B32EE99921CCB0F85378E, 21A46B124B3E9F2569030E2DF591858B85AA640DDBB5C994B5C00A1E78C9EF67 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
20:55:08.0468 0x0f98 aswRdr - ok
20:55:08.0468 0x0f98 [ 6544697080421E62E97AAFBD0A8AA391, BB3F492BF828A147B82FDD1FC9EB9867D96DE0481554A59745D41C6BAB551700 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
20:55:08.0468 0x0f98 aswRvrt - ok
20:55:08.0515 0x0f98 [ E73CBE3420ECFA8FF7D0467E170E335D, B994342C92AE9167908B8CA3D03DC278E919C7073512461AFFD4C25E8D2D8D66 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
20:55:08.0546 0x0f98 aswSnx - ok
20:55:08.0593 0x0f98 [ 1624D5AD126B8AFE2B2E85E5B8364EB6, AB97A74C1CA9921F7753D98516D7E11750D5D3ACD143C83273B0B295625440A0 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
20:55:08.0609 0x0f98 aswSP - ok
20:55:08.0640 0x0f98 [ 4C0ECF1AFA6992904814C74B99DD36F9, AA0D9BA7FE829888C636EC9D72E8E2D987A1C3FF092F95A38EC607CEE25A91F8 ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
20:55:08.0640 0x0f98 aswTdi - ok
20:55:08.0671 0x0f98 [ 0EFBC2962B156E8AC267F96D4D93EF06, 8A69672CE8B68A0A683D583287473BFAB7CF8B9771C22E398607CF2A151C7124 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
20:55:08.0671 0x0f98 aswVmm - ok
20:55:08.0687 0x0f98 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:55:08.0703 0x0f98 AsyncMac - ok
20:55:08.0703 0x0f98 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:55:08.0718 0x0f98 atapi - ok
20:55:08.0718 0x0f98 Atdisk - ok
20:55:08.0734 0x0f98 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:55:08.0765 0x0f98 Atmarpc - ok
20:55:08.0796 0x0f98 [ DE31B88962A8645DBA5A37B993E7B0F1, CA93F25A3FD0CE68BB9B8E3AB6B813BF38DE3EDDFC990291B3957FAA59B2B274 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:55:08.0812 0x0f98 AudioSrv - ok
20:55:08.0843 0x0f98 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:55:08.0843 0x0f98 audstub - ok
20:55:08.0906 0x0f98 [ E3F7EC811923F3F1A77B185F22638E5E, 324041256314C1471B5F123FA8DECC8F374A6B497A6419D4CAF61E68E1733265 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:55:08.0906 0x0f98 avast! Antivirus - ok
20:55:08.0937 0x0f98 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:55:08.0937 0x0f98 Beep - ok
20:55:08.0984 0x0f98 [ 19395D092FD85DDC2D9C7729CF5A2AC8, 7640F36BA19698EE8A6257BF78A8C57DD9D734BED9CA6BB9B68603BAEA092412 ] BITS C:\WINDOWS\system32\qmgr.dll
20:55:09.0046 0x0f98 BITS - ok
20:55:09.0093 0x0f98 [ 89E739BBA5F636297EA5B5F811189E06, 151B32B12F5DD0D388134DA2471FE9741CF22B9C408DA58FEF8019D3C4EC836B ] Browser C:\WINDOWS\System32\browser.dll
20:55:09.0093 0x0f98 Browser - ok
20:55:09.0109 0x0f98 [ B279426E3C0C344893ED78A613A73BDE, 30B29ED5DCFF0C180B806A5FBC705E1CAF6B0F525298CDA79A77FC2AF6E5AAA7 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys
20:55:09.0109 0x0f98 BthEnum - ok
20:55:09.0125 0x0f98 [ FCA6F069597B62D42495191ACE3FC6C1, 23A4EAA542547AC48BCB19DEC9C8E1C1D7D83F199F045DA4682C33292F011CE9 ] BTHMODEM C:\WINDOWS\system32\DRIVERS\bthmodem.sys
20:55:09.0140 0x0f98 BTHMODEM - ok
20:55:09.0156 0x0f98 [ 80602B8746D3738F5886CE3D67EF06B6, 15ABAA8106C42A4453763EEB92B291844580168C934088DB1E22B2065DC238E9 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
20:55:09.0156 0x0f98 BthPan - ok
20:55:09.0203 0x0f98 [ F338662A6C1FC11DD9508F6DFF2C06A2, 650993B9F641D05F34FB2E5771FB834A7EEDBD60C284FD1703043C297A6577F2 ] BTHPORT C:\WINDOWS\system32\Drivers\BTHport.sys
20:55:09.0218 0x0f98 BTHPORT - ok
20:55:09.0265 0x0f98 [ 70CA4B3F634C9DCA200832F8DA76E009, ACDAD55D6D94143B41E71685CDD8ADB2DA35635AE588EAED12BBDAA858ABF79E ] BthServ C:\WINDOWS\System32\bthserv.dll
20:55:09.0265 0x0f98 BthServ - ok
20:55:09.0281 0x0f98 [ 61364CD71EF63B0F038B7E9DF00F1EFA, FB44D02B4379A8AF7DD8B0B22B53888B758903700142BFE45A412709294CE88A ] BTHUSB C:\WINDOWS\system32\Drivers\BTHUSB.sys
20:55:09.0296 0x0f98 BTHUSB - ok
20:55:09.0296 0x0f98 catchme - ok
20:55:09.0343 0x0f98 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
20:55:09.0343 0x0f98 cbidf2k - ok
20:55:09.0359 0x0f98 cd20xrnt - ok
20:55:09.0375 0x0f98 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:55:09.0375 0x0f98 Cdaudio - ok
20:55:09.0406 0x0f98 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:55:09.0421 0x0f98 Cdfs - ok
20:55:09.0437 0x0f98 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:55:09.0437 0x0f98 Cdrom - ok
20:55:09.0437 0x0f98 Changer - ok
20:55:09.0484 0x0f98 [ E390DC1D7C461D7D56EC53402F329928, FB37F84E71353CD83FCDDD39C898C6D84C05130C5F1BEF022E3DFDE160398C0E ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:55:09.0484 0x0f98 CiSvc - ok
20:55:09.0500 0x0f98 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA, 1725067BC759484A7185A4F1A44ED3CBE481529D187FE98EF279425B79177EB1 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:55:09.0515 0x0f98 ClipSrv - ok
20:55:09.0531 0x0f98 [ 234B1BC2796483E1F5C3F26649FB3388, F412B31340B11418698F263A60C78CB086F3D973EDA0C15DF12331971EB3C9DC ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:55:09.0578 0x0f98 clr_optimization_v2.0.50727_32 - ok
20:55:09.0625 0x0f98 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:55:09.0640 0x0f98 clr_optimization_v4.0.30319_32 - ok
20:55:09.0640 0x0f98 CmdIde - ok
20:55:09.0656 0x0f98 COMSysApp - ok
20:55:09.0671 0x0f98 Cpqarray - ok
20:55:09.0687 0x0f98 [ F3AB0933CBD166D271992F411C27CCAF, 50E01F3B058F814BE914FA5050B2D972E8584A467719A5ABCF9D9EBD596A54A7 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:55:09.0687 0x0f98 CryptSvc - ok
20:55:09.0687 0x0f98 dac2w2k - ok
20:55:09.0703 0x0f98 dac960nt - ok
20:55:09.0734 0x0f98 [ C868F3AE15CF71A93F2AA3A32856D839, 7F08E40AE8F4F15F110550775183EDA690DBADAC95CF859C98A99B3DF308C8F5 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:55:09.0765 0x0f98 DcomLaunch - ok
20:55:09.0812 0x0f98 [ 6216FD7FD227DE454238A702B218CEC7, 5699FDD253754AE274B8624A41CBE778D74383E95D5167785A48A51AAD67FC70 ] dgderdrv C:\WINDOWS\system32\drivers\dgderdrv.sys
20:55:09.0812 0x0f98 dgderdrv - ok
20:55:09.0843 0x0f98 [ 6CC6C4B9D7B906A151AA094CA087B9F0, 5D06DC2FCAF86C256792D541D5581AF5AFEDA247814E07C6017BEE92284CAA56 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
20:55:09.0875 0x0f98 dg_ssudbus - ok
20:55:09.0906 0x0f98 [ 8C9A53E285AC5E6704844D0459EC85BE, 9E86AF4C06CEC007C9B1590B6E056319603E4D79BED0C2471C6F1BC251B380CF ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:55:09.0921 0x0f98 Dhcp - ok
20:55:09.0953 0x0f98 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:55:09.0953 0x0f98 Disk - ok
20:55:09.0953 0x0f98 dmadmin - ok
20:55:10.0000 0x0f98 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C, 46074FBBC5E4A40A7B3A45636089DEDD2A619778C7DCD797571C2BB64D775F7E ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:55:10.0046 0x0f98 dmboot - ok
20:55:10.0062 0x0f98 [ FFF1720AF51171F32F1EAD5CF71F2810, 2E40D63DC7670C1E88A532DB8923A98ABC8481C351C4D915C2753E10BA77F36D ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:55:10.0062 0x0f98 dmio - ok
20:55:10.0078 0x0f98 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:55:10.0078 0x0f98 dmload - ok
20:55:10.0109 0x0f98 [ 2BFEFE9E865655A76982F050450B9591, 15C7D093D638770519AA43E7D8897310F32AB1F217027F5750D799494A985C35 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:55:10.0109 0x0f98 dmserver - ok
20:55:10.0140 0x0f98 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:55:10.0140 0x0f98 DMusic - ok
20:55:10.0187 0x0f98 [ DFAA406BF19F4EE806A6F8D4342137F7, EE2C11B3E37565FC009E323607B2F5F148F9219012EDF848CEFC1B273DAA98A9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:55:10.0187 0x0f98 Dnscache - ok
20:55:10.0218 0x0f98 [ 4A3E2BD20157A0946751229E92EB8621, D8C00CC2C18C517F7262EBC3C511C062E5ABA797056AEB22AC5DEB306BA8C526 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:55:10.0218 0x0f98 Dot3svc - ok
20:55:10.0234 0x0f98 dpti2o - ok
20:55:10.0234 0x0f98 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:55:10.0234 0x0f98 drmkaud - ok
20:55:10.0265 0x0f98 [ 0887D9C2BE8D940778CAD1E3B85F2A41, 2E30DC06D46A5E174B7CAA2D70BDB697015495942572E90425E2EE7AC541BCF4 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:55:10.0265 0x0f98 EapHost - ok
20:55:10.0281 0x0f98 [ A2A4912798F2BE706ABADD3D30800D16, CCCCA389D22525D984DE9B59E4CEBE0EEEF315F725176EB5C4DC1A5B6157234A ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:55:10.0296 0x0f98 ERSvc - ok
20:55:10.0328 0x0f98 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] Eventlog C:\WINDOWS\system32\services.exe
20:55:10.0328 0x0f98 Eventlog - ok
20:55:10.0375 0x0f98 [ 260C69FD67687B0DC062FC3D31655857, A491071B09A726BC77FB134D59FF4FAB3EF1E09F785D86E49142B3A25A96C192 ] EventSystem C:\WINDOWS\system32\es.dll
20:55:10.0390 0x0f98 EventSystem - ok
20:55:10.0421 0x0f98 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:55:10.0421 0x0f98 Fastfat - ok
20:55:10.0453 0x0f98 [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:55:10.0453 0x0f98 FastUserSwitchingCompatibility - ok
20:55:10.0468 0x0f98 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
20:55:10.0468 0x0f98 Fdc - ok
20:55:10.0484 0x0f98 [ AC366695A0796560AA37215AD5762AAF, 6ADC7443EA42D77199D4879AF3C33A07914116C69A34B895D8CB8444EE50077F ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:55:10.0484 0x0f98 Fips - ok
20:55:10.0500 0x0f98 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
20:55:10.0515 0x0f98 Flpydisk - ok
20:55:10.0531 0x0f98 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:55:10.0546 0x0f98 FltMgr - ok
20:55:10.0578 0x0f98 [ DDEE99DC54EFA20BD5A442CD733C4462, 941D6C5D91F6419198F1A53BF7D33AA2D9118CEAC028B6ED8E5308751810B9B5 ] FsUsbExDisk C:\WINDOWS\system32\FsUsbExDisk.SYS
20:55:10.0578 0x0f98 FsUsbExDisk - ok
20:55:10.0625 0x0f98 [ 0796C1E47ADB9825269E64B9DAB4E741, A9E476278428824FAE8B63B2B2CAC683EABD28E5B514925F6379593CB6CAB968 ] FsUsbExService C:\WINDOWS\system32\FsUsbExService.Exe
20:55:10.0625 0x0f98 FsUsbExService - ok
20:55:10.0640 0x0f98 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:55:10.0640 0x0f98 Fs_Rec - ok
20:55:10.0656 0x0f98 [ 4E664D8541DB4A66B73A24257E322E1F, 17A2140AFE2B41E579FCCAFB82532853AD90A6EDBCB13DE80741DAE0AD5B4CC9 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:55:10.0671 0x0f98 Ftdisk - ok
20:55:10.0671 0x0f98 GMSIPCI - ok
20:55:10.0703 0x0f98 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:55:10.0718 0x0f98 Gpc - ok
20:55:10.0734 0x0f98 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:55:10.0734 0x0f98 HDAudBus - ok
20:55:10.0812 0x0f98 [ FCFE31FB75F8A6295B6B0AF87A626282, 6BA385797DBC73EB29EFE3293B80C21B1B8A1E9B87A462476E73C526C9565E5F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:55:10.0812 0x0f98 helpsvc - ok
20:55:10.0859 0x0f98 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:55:10.0859 0x0f98 HidUsb - ok
20:55:10.0890 0x0f98 [ 7A6B320928F86BC851530D63C82965D9, 1F628759D31098DFBC05244735B5A62ACD8E45DBC5C9D236260D68EB8F1E28F5 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:55:10.0890 0x0f98 hkmsvc - ok
20:55:10.0890 0x0f98 hpn - ok
20:55:10.0953 0x0f98 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:55:10.0953 0x0f98 HTTP - ok
20:55:10.0984 0x0f98 [ 58FE2F2DA3BC5573F4A35B3760D3125F, B241ACCE426402EC64DC34C49CECB8CDC0851986D54BFCCED7040D6C43F5787A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:55:11.0000 0x0f98 HTTPFilter - ok
20:55:11.0000 0x0f98 i2omgmt - ok
20:55:11.0015 0x0f98 i2omp - ok
20:55:11.0031 0x0f98 [ C528E27945367191E7BAE364930B6932, 1B95C7B49B4CAE734DC6C9EC22555C5356EEC856B8491C761C777479264CF854 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:55:11.0031 0x0f98 i8042prt - ok
20:55:11.0046 0x0f98 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:55:11.0046 0x0f98 Imapi - ok
20:55:11.0078 0x0f98 [ F7B93AAFAD33B2320954C17E26C8D361, 8CFDB11A68B59E195F280BE08B25FA59F1F70833832919B8BECCE17616999934 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:55:11.0078 0x0f98 ImapiService - ok
20:55:11.0093 0x0f98 ini910u - ok
20:55:11.0296 0x0f98 [ 1AE3CFF80017EF89DA959350724C7194, 009A95FBF37EB73173682A87BB46681EAE7C8673F89AC4AE1608590D864244DB ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:55:11.0484 0x0f98 IntcAzAudAddService - ok
20:55:11.0500 0x0f98 IntelIde - ok
20:55:11.0531 0x0f98 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:55:11.0531 0x0f98 Ip6Fw - ok
20:55:11.0562 0x0f98 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:55:11.0562 0x0f98 IpFilterDriver - ok
20:55:11.0578 0x0f98 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:55:11.0578 0x0f98 IpInIp - ok
20:55:11.0609 0x0f98 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:55:11.0609 0x0f98 IpNat - ok
20:55:11.0625 0x0f98 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:55:11.0625 0x0f98 IPSec - ok
20:55:11.0625 0x0f98 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:55:11.0640 0x0f98 IRENUM - ok
20:55:11.0656 0x0f98 [ CC9F8A2D60AED1A51A3AC34C59B987AE, CBF69817BE3D9A4617390B1A3306074CB8581F21562CD1357D32BC3E542F3CEE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:55:11.0656 0x0f98 isapnp - ok
20:55:11.0718 0x0f98 [ DBDB1A25291B2D18C614F5CA963156A8, C8EA730A6A5BCBE7952AAA22F212C244014F206D2F4A274E29384C09F1F10A66 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
20:55:11.0734 0x0f98 JavaQuickStarterService - ok
20:55:11.0750 0x0f98 [ 1B6162FE7F66B1A71A4B70F941C4AA9B, C2EA494BAB0513A6027414FB1E75834F980A77852D0DC8559E8942FC222A075A ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:55:11.0750 0x0f98 Kbdclass - ok
20:55:11.0765 0x0f98 [ 86C8F23616C6C6E5B2776901C17B945B, 211B63FC405A2DDB126D204D61E779D66C7211882CC0374521926C633E180B91 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:55:11.0781 0x0f98 kbdhid - ok
20:55:11.0812 0x0f98 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:55:11.0828 0x0f98 kmixer - ok
20:55:11.0843 0x0f98 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:55:11.0843 0x0f98 KSecDD - ok
20:55:11.0875 0x0f98 [ 3428E8F86F8ADD36B42FB23542C7B3E4, 9CF643D1A70AF08407ACD5FD6FE4B8777521DDF41B5E63C2E6E1E4CAAC69A403 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:55:11.0890 0x0f98 lanmanserver - ok
20:55:11.0921 0x0f98 [ 936C1D110232D23B621CB0196E4F80F0, 2DE3AF93E20F1DC7A6FF31B18054EA4D2350387E4DA91C4B16D451384F0C57E2 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:55:11.0937 0x0f98 lanmanworkstation - ok
20:55:11.0937 0x0f98 lbrtfdc - ok
20:55:11.0953 0x0f98 lmaih - ok
20:55:12.0000 0x0f98 [ 0AB159F536E3E8F7F07113702A07CCA5, 3218C553183E6697C663B6D12790E09756B50505590858DD5AC62411D37CDD7C ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:55:12.0000 0x0f98 LmHosts - ok
20:55:12.0031 0x0f98 [ 11F714F85530A2BD134074DC30E99FCA, BDB5FD3B2DF4ADD19B31965B3E789768B59E872B3EA85912B1FFB32B2AF9D5D8 ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
20:55:12.0046 0x0f98 MDM - ok
20:55:12.0078 0x0f98 [ 221CD1C815B8A6B79389C3F5D1018DE8, 6D0D25D6669C4F9452F74EC72C6138A41D9408E01AF5FD01C08F27BE7BC9C905 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:55:12.0078 0x0f98 Messenger - ok
20:55:12.0093 0x0f98 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:55:12.0109 0x0f98 mnmdd - ok
20:55:12.0140 0x0f98 [ 9A57D046F88F4B69751B11FD40088A61, 62F65433024CE411F111A88723747B8A83B31076FBAF4CFF40FD02A53D7FF7DF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:55:12.0140 0x0f98 mnmsrvc - ok
20:55:12.0156 0x0f98 [ 44032B0C6D9954D3FD26438330B99EE7, A49749A4C00D50F57170AA5DA9E2DEECC8C524A48B144C8B784894F2C202FBEE ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:55:12.0156 0x0f98 Modem - ok
20:55:12.0218 0x0f98 [ 9FA7207D1B1ADEAD88AE8EED9CDBBAA5, 2AC3875B2E7D9B0692253A9867B940CF214DE03574808B42C3702843BC1D5696 ] Monfilt C:\WINDOWS\system32\drivers\Monfilt.sys
20:55:12.0265 0x0f98 Monfilt - ok
20:55:12.0296 0x0f98 [ 4CB582831DBDE63CE43B45D771218374, 6D470B26197C5B388983D9213D48D2CDE934C9591572876DC7790FE4B59E0845 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:55:12.0296 0x0f98 Mouclass - ok
20:55:12.0328 0x0f98 [ BB269EBA740737AB749B214D568B6812, ABF41D9B521EBBE674E76981CAD31F8FD05976DE7070266C3956FDB67C83C4C2 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:55:12.0343 0x0f98 mouhid - ok
20:55:12.0343 0x0f98 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:55:12.0359 0x0f98 MountMgr - ok
20:55:12.0359 0x0f98 mraid35x - ok
20:55:12.0390 0x0f98 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:55:12.0406 0x0f98 MRxDAV - ok
20:55:12.0421 0x0f98 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:55:12.0437 0x0f98 MRxSmb - ok
20:55:12.0468 0x0f98 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D, 78D63EE2C0B0852F0771071C099643242EBC9F4DA28847B93BCE9C3CC1091938 ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:55:12.0468 0x0f98 MSDTC - ok
20:55:12.0484 0x0f98 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:55:12.0484 0x0f98 Msfs - ok
20:55:12.0500 0x0f98 MSIServer - ok
20:55:12.0515 0x0f98 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:55:12.0515 0x0f98 MSKSSRV - ok
20:55:12.0546 0x0f98 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:55:12.0546 0x0f98 MSPCLOCK - ok
20:55:12.0562 0x0f98 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:55:12.0562 0x0f98 MSPQM - ok
20:55:12.0578 0x0f98 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:55:12.0578 0x0f98 mssmbios - ok
20:55:12.0609 0x0f98 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:55:12.0609 0x0f98 Mup - ok
20:55:12.0640 0x0f98 [ 6EA362E9DB03D44F6B996F4D8BE237E9, FE6B4C546D26C4A2832CF4CB280B86B1723E10E46A3C24AF6C9856FCCAE9D1FC ] napagent C:\WINDOWS\System32\qagentrt.dll
20:55:12.0656 0x0f98 napagent - ok
20:55:12.0671 0x0f98 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:55:12.0687 0x0f98 NDIS - ok
20:55:12.0718 0x0f98 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:55:12.0718 0x0f98 NdisTapi - ok
20:55:12.0750 0x0f98 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:55:12.0750 0x0f98 Ndisuio - ok
20:55:12.0765 0x0f98 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:55:12.0765 0x0f98 NdisWan - ok
20:55:12.0781 0x0f98 [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:55:12.0796 0x0f98 NDProxy - ok
20:55:12.0796 0x0f98 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:55:12.0796 0x0f98 NetBIOS - ok
20:55:12.0843 0x0f98 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:55:12.0843 0x0f98 NetBT - ok
20:55:12.0875 0x0f98 [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDE C:\WINDOWS\system32\netdde.exe
20:55:12.0890 0x0f98 NetDDE - ok
20:55:12.0890 0x0f98 [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:55:12.0906 0x0f98 NetDDEdsdm - ok
20:55:12.0937 0x0f98 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:55:12.0937 0x0f98 Netlogon - ok
20:55:12.0953 0x0f98 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40, 588C8BA14A7255FD36A88960CBE34341301773765ECF2A9A0F1760A509A08A5B ] Netman C:\WINDOWS\System32\netman.dll
20:55:12.0968 0x0f98 Netman - ok
20:55:13.0000 0x0f98 [ 39EE7C3BFBC64BA87CC8CF67386E814C, B93CCB625CE370D9A49C9374D24C939D7C9FEF81401F4F822C51E12677D77E01 ] Nla C:\WINDOWS\System32\mswsock.dll
20:55:13.0015 0x0f98 Nla - ok
20:55:13.0031 0x0f98 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:55:13.0031 0x0f98 Npfs - ok
20:55:13.0078 0x0f98 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:55:13.0109 0x0f98 Ntfs - ok
20:55:13.0109 0x0f98 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:55:13.0125 0x0f98 NtLmSsp - ok
20:55:13.0156 0x0f98 [ 023DD70573D644F3D9C8B1258A7BFD08, 9A1D3210ED5FD8BEDF92ED577A9B30E37035408A73EB66A8C950B75AB7539B83 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:55:13.0187 0x0f98 NtmsSvc - ok
20:55:13.0203 0x0f98 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
20:55:13.0203 0x0f98 Null - ok
20:55:13.0671 0x0f98 [ 4B54DCD6ADEE535DF80F07C59DDD8F14, 6E425F8881547A4C96B36B4D99FFD7EE9330F1C1AD34276F039218A4C2613521 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:55:14.0093 0x0f98 nv - ok
20:55:14.0140 0x0f98 [ 7D275ECDA4628318912F6C945D5CF963, 78C5125F5A9B5EE1A5AC394BB0D9EDA954EB35103B588B6A98D41E2C32354A96 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
20:55:14.0140 0x0f98 NVENETFD - ok
20:55:14.0171 0x0f98 [ 75E2E77C5497F34E60491D27BF03F1CB, E8989FD0A54E40B211E4BA95C916CE602BD3283C8465A312114EB0EC61C12768 ] nvgts C:\WINDOWS\system32\DRIVERS\nvgts.sys
20:55:14.0171 0x0f98 nvgts - ok
20:55:14.0187 0x0f98 [ B64AACEFAD2BE5BFF5353FE681253C67, A4D81BF67E6D4DBD559C27C8103277D30DA5B37269E0FD6571FC273DA21E892F ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
20:55:14.0187 0x0f98 nvnetbus - ok
20:55:14.0218 0x0f98 [ 2A085AEC3AB2B1211611D2A7B9E22456, 4EDEAA43E1BC1EB2C5179E3EDA43526B26CBB278CEF58E32F0F1A4A4639E50A0 ] nvsmu C:\WINDOWS\system32\DRIVERS\nvsmu.sys
20:55:14.0218 0x0f98 nvsmu - ok
20:55:14.0234 0x0f98 [ 0573C75A2895D973EA6EF2495620BA49, 0C1A1C23B735B91E3026A64AE7A0CBB8828BC2888B50FEBA574BA10D92D92BEE ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
20:55:14.0250 0x0f98 NVSvc - ok
20:55:14.0359 0x0f98 [ 9C84945FEEE40EA42D3BCA5C22250D47, F7403C038753DD8AC35558014085AAA8473726B7D1FAC5B3D95B461A313815ED ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
20:55:14.0437 0x0f98 nvUpdatusService - ok
20:55:14.0484 0x0f98 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:55:14.0500 0x0f98 NwlnkFlt - ok
20:55:14.0515 0x0f98 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:55:14.0515 0x0f98 NwlnkFwd - ok
20:55:14.0546 0x0f98 [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:55:14.0546 0x0f98 ose - ok
20:55:14.0562 0x0f98 [ 46F8DB73B4A53E543F8E371DC7C75BAE, F6C5E7DE4B4AE0ED785DB075BE14EA6A0FC9050C95669B26DEF2B82D7B7D3B2C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
20:55:14.0578 0x0f98 Parport - ok
20:55:14.0593 0x0f98 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:55:14.0593 0x0f98 PartMgr - ok
20:55:14.0625 0x0f98 [ 1FAE19D0457176318BBA4A8795656EBC, 5F3D6CABA203A0485D67F63A6A81151724EE200BE49ED095CFCB1EF29C19D19F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:55:14.0625 0x0f98 ParVdm - ok
20:55:14.0640 0x0f98 [ 6CE351D149CB4BEFC702951E471E1730, 758327683BB45F01D5AE550AF21856822B4CF55E17F2A4F452F559088D242B37 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:55:14.0640 0x0f98 PCI - ok
20:55:14.0640 0x0f98 PCIDump - ok
20:55:14.0656 0x0f98 [ 2DA4EC85E0EA7A45C6B2A05820492D5A, A8C6BD93D3BC33A5B36EB523997EF9E0783B6E6EAFB6E7F58BCC2629009BDCF9 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:55:14.0671 0x0f98 PCIIde - ok
20:55:14.0687 0x0f98 [ 4FC31E6C19A5CE5198B1ABFF94CAE758, A031E21EC1F15DA5E8429269F435337FA961C3C06D535DAFD448C7355F33FD0C ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:55:14.0687 0x0f98 Pcmcia - ok
20:55:14.0703 0x0f98 PDCOMP - ok
20:55:14.0718 0x0f98 PDFRAME - ok
20:55:14.0718 0x0f98 PDRELI - ok
20:55:14.0734 0x0f98 PDRFRAME - ok
20:55:14.0734 0x0f98 perc2 - ok
20:55:14.0750 0x0f98 perc2hib - ok
20:55:14.0781 0x0f98 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] PlugPlay C:\WINDOWS\system32\services.exe
20:55:14.0796 0x0f98 PlugPlay - ok
20:55:14.0796 0x0f98 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:55:14.0812 0x0f98 PolicyAgent - ok
20:55:14.0828 0x0f98 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:55:14.0843 0x0f98 PptpMiniport - ok
20:55:14.0843 0x0f98 [ 7EB15DCE4EC3A0220BD796A15C18186E, E06C572F3FE4F3377D8AF74E8EF15478E71B4C61F944E48E8C35534BEF086110 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
20:55:14.0859 0x0f98 Processor - ok
20:55:14.0859 0x0f98 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:55:14.0875 0x0f98 ProtectedStorage - ok
20:55:14.0875 0x0f98 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:55:14.0875 0x0f98 PSched - ok
20:55:14.0890 0x0f98 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:55:14.0890 0x0f98 Ptilink - ok
20:55:14.0906 0x0f98 ql1080 - ok
20:55:14.0906 0x0f98 Ql10wnt - ok
20:55:14.0921 0x0f98 ql12160 - ok
20:55:14.0921 0x0f98 ql1240 - ok
20:55:14.0937 0x0f98 ql1280 - ok
20:55:14.0953 0x0f98 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:55:14.0953 0x0f98 RasAcd - ok
20:55:14.0984 0x0f98 [ 2B5E44EA009F2F374B980E1E9A70635D, 62D8FDB80C8ACBA2C42C12760B785587C43BEDFE015EC5C41B25F2BB735EFEB0 ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:55:14.0984 0x0f98 RasAuto - ok
20:55:15.0000 0x0f98 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:55:15.0015 0x0f98 Rasl2tp - ok
20:55:15.0046 0x0f98 [ D57554C664B64604BD1EE13EA2C07E77, B090C05B91EA602BFF9A5E89AB1A0FFDE869611961FF749DA8B3F4D00F04E756 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:55:15.0062 0x0f98 RasMan - ok
20:55:15.0062 0x0f98 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:55:15.0078 0x0f98 RasPppoe - ok
20:55:15.0078 0x0f98 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:55:15.0093 0x0f98 Raspti - ok
20:55:15.0109 0x0f98 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:55:15.0109 0x0f98 Rdbss - ok
20:55:15.0125 0x0f98 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:55:15.0125 0x0f98 RDPCDD - ok
20:55:15.0140 0x0f98 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:55:15.0156 0x0f98 rdpdr - ok
20:55:15.0187 0x0f98 [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:55:15.0203 0x0f98 RDPWD - ok
20:55:15.0234 0x0f98 [ C0D9D9711CB74EE9BC66353D8CBDAB0E, F1AF9A26910707E76BF213D8DE5C902B0088D8A29EBDFF72DE6A4D867E298CC8 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:55:15.0234 0x0f98 RDSessMgr - ok
20:55:15.0265 0x0f98 [ 611BFD220305BE3A85AE876EA47D4AA5, FDF87878EB3886649025E5A12F1C3FC9072D66CCD3217944710085C1F8A4512E ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:55:15.0265 0x0f98 redbook - ok
20:55:15.0312 0x0f98 [ 127C26B5371651043450E52542099ABA, 98AADAD8D5211CB894AA7C59B6299861B1F44B6D8F46AB5837E7D2F5B615B14A ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:55:15.0312 0x0f98 RemoteAccess - ok
20:55:15.0359 0x0f98 [ 8F31505484A190D5B22274708799F4EC, 170FF8193C95CEE73B9342B6FB7D83DF4E80B2CCBB27DF41F4AB5F2FB9AF60E1 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:55:15.0359 0x0f98 RemoteRegistry - ok
20:55:15.0390 0x0f98 [ 851C30DF2807FCFA21E4C681A7D6440E, C2269B8ED4E831664B83F8F3BE33E5A340206A9E07F89CDF6707EAD8F280FBE9 ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys
20:55:15.0390 0x0f98 RFCOMM - ok
20:55:15.0421 0x0f98 [ 718B3BDC0BC3C2F7D065A53D26202AF9, 9E58243628F1E1396AB82A80D046FF50803A230EE07B007E0CA5D744C77B091A ] RpcLocator C:\WINDOWS\system32\locator.exe
20:55:15.0421 0x0f98 RpcLocator - ok
20:55:15.0453 0x0f98 [ C868F3AE15CF71A93F2AA3A32856D839, 7F08E40AE8F4F15F110550775183EDA690DBADAC95CF859C98A99B3DF308C8F5 ] RpcSs C:\WINDOWS\System32\rpcss.dll
20:55:15.0468 0x0f98 RpcSs - ok
20:55:15.0515 0x0f98 [ 09AB2E71E58B078038E3BFDBA7FFC984, 8CA277DEEF6376B0F48C6BA5DBBC3E8AF2245983BA9AF6AB83D1A920D35FAF93 ] RSVP C:\WINDOWS\system32\rsvp.exe
20:55:15.0515 0x0f98 RSVP - ok
20:55:15.0546 0x0f98 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] SamSs C:\WINDOWS\system32\lsass.exe
20:55:15.0546 0x0f98 SamSs - ok
20:55:15.0578 0x0f98 [ 410046E401EB11E1E6749E9DEEA41D4A, 9507268ACD24EF51E994DC418E8EB3E10DEDE61EE892226A22A5DA7662397E25 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:55:15.0593 0x0f98 SCardSvr - ok
20:55:15.0609 0x0f98 [ 3FF232A7731621B8902D81D42418C93C, 2030C9A843D9555170179883BD4CC1E978D5FC5EC0D7FCA56518224E428BE421 ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:55:15.0625 0x0f98 Schedule - ok
20:55:15.0656 0x0f98 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:55:15.0656 0x0f98 Secdrv - ok
20:55:15.0671 0x0f98 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6, 82EEB2345AC19050FAB202DE76C2CDD93E753F5AB67789A86A1726D3040C02E5 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:55:15.0671 0x0f98 seclogon - ok
20:55:15.0703 0x0f98 [ A530B75C10C23C9AB28FDB6CE719E21F, 14568DF6457758E2F534A46A8E6245C364895C3993BEF2B5A889B98DBB201A27 ] SENS C:\WINDOWS\system32\sens.dll
20:55:15.0703 0x0f98 SENS - ok
20:55:15.0750 0x0f98 [ B842729337C9B921615C40D3C1A1AF96, 503670A56423B996C6ED6AE95F07FB88910767C4A2041A4BE9070C57A016E7FA ] Serial C:\WINDOWS\system32\drivers\Serial.sys
20:55:15.0750 0x0f98 Serial - ok
20:55:15.0781 0x0f98 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:55:15.0781 0x0f98 Sfloppy - ok
20:55:15.0828 0x0f98 [ F58FACA9621D2DB01BD0927D9A0A208E, 239C87E09261BC9D1DBE99DABCFC4787D42289E8769563A5EFB323BE6F177C9A ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:55:15.0859 0x0f98 SharedAccess - ok
20:55:15.0875 0x0f98 [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:55:15.0890 0x0f98 ShellHWDetection - ok
20:55:15.0906 0x0f98 Simbad - ok
20:55:15.0906 0x0f98 Sparrow - ok
20:55:15.0937 0x0f98 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:55:15.0937 0x0f98 splitter - ok
20:55:15.0968 0x0f98 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:55:15.0984 0x0f98 Spooler - ok
20:55:16.0015 0x0f98 [ 94610C8653635E4459316A0050D55CE7, D148D33B3D2B0757060531C526F2161504A8D7C4E5957D092C7EBDB007271339 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:55:16.0015 0x0f98 sr - ok
20:55:16.0031 0x0f98 [ 35B91147124F64AC8081A2EDB9EA4DEE, 1609D19156DAC6EE3C2D2350B062966B64D9CDC289E9B8FEB6D244AAEBE90BBF ] srservice C:\WINDOWS\system32\srsvc.dll
20:55:16.0046 0x0f98 srservice - ok
20:55:16.0078 0x0f98 [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:55:16.0093 0x0f98 Srv - ok
20:55:16.0109 0x0f98 [ BECD5271DC4E3B7C3D035F790FCBC1E5, D63B9DB81332553C963EC5057D241CE2287AF652387333C1FD79AF8C9B5F2BA7 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:55:16.0125 0x0f98 SSDPSRV - ok
20:55:16.0171 0x0f98 [ 5CB8CE3CB1BB8A205DA6311509188668, 7F2718B92CE063FD653B03E4BC5C23E1EA378CF1423619A11ED19EADB4E553AD ] ssdudfu C:\WINDOWS\system32\DRIVERS\ssdudfu.sys
20:55:16.0171 0x0f98 ssdudfu - ok
20:55:16.0203 0x0f98 [ EF3458337D7341A05169CEFC73709264, C9D0AE966CFA02F7B72586C2A6E2AFA9818C9F4856A4E9625B79BC5A886FC193 ] SSPORT C:\WINDOWS\system32\Drivers\SSPORT.sys
20:55:16.0203 0x0f98 SSPORT - ok
20:55:16.0250 0x0f98 [ 359FEE084F1173FFFFD7F9CCBD43D47F, 197EE7267D0565E426368868233C35F6FD29A0432D75630F8365336E061318D7 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
20:55:16.0250 0x0f98 ssudmdm - ok
20:55:16.0265 0x0f98 [ D74ED4825E554148E8DD684E16D8D239, 05BF2C0FB274D91A4A94F4BDD75A8A77A8A0A216C7C1C30CFB577505E7DA6E28 ] ssudserd C:\WINDOWS\system32\DRIVERS\ssudserd.sys
20:55:16.0281 0x0f98 ssudserd - ok
20:55:16.0312 0x0f98 [ 54946449A0EB74915A4BB34F7EE51A5A, 4C9EFC564520FD5E082A8066B0FCFDC9FCC5050DC26518810E57ECF3B90EF248 ] ss_bus C:\WINDOWS\system32\DRIVERS\ss_bus.sys
20:55:16.0312 0x0f98 ss_bus - ok
20:55:16.0343 0x0f98 [ 4450BC0B2E9D7D9B90E3C3DE4EA00A78, 4AE89D25F4D3B061D8CBD31329EDD3D5BAD9ED5D24ECC49FBC263B4DFE6760AB ] ss_mdfl C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
20:55:16.0343 0x0f98 ss_mdfl - ok
20:55:16.0359 0x0f98 [ 30B8D0DD01EAD1243F329CAF7D7D1517, A4BC52064E3C6140175BF403ED396C1718BF5EB996CB050989051532D0D79C71 ] ss_mdm C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
20:55:16.0375 0x0f98 ss_mdm - ok
20:55:16.0406 0x0f98 [ 306521935042FC0A6988D528643619B3, 6FCC06EA71F5C83A8C3A8B7152E9FF48BCFBD35ED8C134A0879735F9135BB20C ] StarOpen C:\WINDOWS\system32\drivers\StarOpen.sys
20:55:16.0406 0x0f98 StarOpen - ok


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 126 hostů