
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Esetem hlaseny Agent.SDG.Gen Trojsky kun
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Esetem hlaseny Agent.SDG.Gen Trojsky kun
Dobry den,
dnes rano me privitala hlaska od esetu (legalne zakoupen stejne jako os) ze MBR sektor1. fyzickeho disku je infiltrovan Win32/Agent.SDG.Gen trojsky kun. Tlacitko lecit nepomaha. Po spusteni kontroly stejnou hlasku hazi i pro disky 3 a 4.
Rad bych vas pozadal o radu jak postupovat.
Predem dekuji.
Log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jakub at 2012-01-08 10:09:40
Microsoft Windows 7 Professional
System drive C: has 30 GB (15%) free of 200 GB
Total RAM: 4095 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:09:44, on 8.1.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16912)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\SC2RARu10\SC2RAR\SC2RAR.exe
C:\Windows\SysWOW64\DeltaIITray.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\Jakub.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [MRUTray] C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: SC2RAR - Shortcut.lnk = C:\SC2RARu10\SC2RAR\SC2RAR.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware server\vsocklib.dll
O15 - Trusted IP range: http://127.0.0.1
O16 - DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574} (VMware Remote Console Plug-in 2.5.0.00000) -
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) -
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner - C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe
O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation - C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: OracleDBConsoleorcl - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe
O23 - Service: OracleOraDb11g_home1ClrAgent - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe
O23 - Service: OracleOraDb11g_home1TNSListener - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR.exe
O23 - Service: OracleOraDb11g_home2ClrAgent - Oracle Corporation - K:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe
O23 - Service: OracleOraDb11g_home2TNSListener - Oracle Corporation - K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR.exe
O23 - Service: OracleServiceORCL - Oracle Corporation - c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE
O23 - Service: OracleServiceORCL11 - Oracle Corporation - k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE
O23 - Service: Oracle ORCL VSS Writer Service (OracleVssWriterORCL) - Unknown owner - c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe
O23 - Service: Oracle ORCL11 VSS Writer Service (OracleVssWriterORCL11) - Unknown owner - k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10588 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
Ati2evxx.exe -Client
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe" -k runservice
C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe
C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe "OracleMTSRecoveryService"
\??\C:\Windows\system32\conhost.exe "-80325381-11333306271417005892989559031339049103-9331638921102959403-108127563
K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR
"C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe" -d "C:/Program Files (x86)/Marvell/raid/Apache2"
c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
cmd /c ""C:\app\Jakub\product\11.2.0\dbhome_1\bin\emctl.bat" istart dbconsole"
C:\app\Jakub\product\11.2.0\dbhome_1\\perl\bin\perl.exe C:\app\Jakub\product\11.2.0\dbhome_1\bin\emwd.pl dbconsole
C:\Windows\SysWOW64\vmnat.exe
"C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe" //RS//VMwareServerWebAccess
\??\C:\Windows\system32\conhost.exe "8598574491427828188-1063851766-2128205691320828558-410138486-963244062426114300
cmd /c "C:\app\Jakub\product\11.2.0\dbhome_1/bin/execjavatemp.bat"
C:\app\Jakub\product\11.2.0\dbhome_1\jdk/bin/java -server -Xmx192M -XX:MaxPermSize=200M -XX:MinHeapFreeRatio=20 -XX:MaxHeapFreeRatio=40 -DORACLE_HOME=C:\app\Jakub\product\11.2.0\dbhome_1 -Doracle.home=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j -Doracle.oc4j.localhome=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl/sysman -DEMSTATE=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl -Doracle.j2ee.dont.use.memory.archive=true -Djava.protocol.handler.pkgs=HTTPClient -Doracle.security.jazn.config=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/jazn.xml -Djava.security.policy=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/java2.policy -Djavax.net.ssl.KeyStore=C:\app\Jakub\product\11.2.0\dbhome_1/sysman/config/OCMTrustedCerts.txt-Djava.security.properties=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/home/config/jazn.security.props -DEMDROOT=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl -Dsysman.md5password=true -Drepapi.oracle.home=C:\app\Jakub\product\11.2.0\dbhome_1 -Ddisable.checkForUpdate=true -Doracle.sysman.ccr.ocmSDK.websvc.keystore=C:\app\Jakub\product\11.2.0\dbhome_1/jlib/emocmclnt.ks -Dice.pilots.html4.ignoreNonGenericFonts=true -Djava.awt.headless=true -jar C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/home/oc4j.jar -config C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/server.xml
"C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe"
"C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe"
C:\app\Jakub\product\11.2.0\dbhome_1/bin/emagent
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe" -u "C:\ProgramData\VMware\VMware Server\hostd\config.xml"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\SC2RARu10\SC2RAR\SC2RAR.exe"
"C:\Windows\System32\DeltaIITray.exe"
"C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
"C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\wuauclt.exe"
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --enable-print-preview --channel=4588.06174000.2036729946 /prefetch:3
C:\Windows\system32\rundll32.exe "C:\Users\Jakub\AppData\Local\Google\Chrome\APPLIC~1\160912~1.75\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Jakub\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll" --lang=cs --channel=4588.0A7F9000.895826943 --flash-broker=4152 /prefetch:4
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --enable-print-preview --channel=4588.05C7A480.224716698 /prefetch:3
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\log.txt
"C:\totalcmd\TOTALCMD.EXE"
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Jakub\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, {0493D792-5C92-440b-81A8-AD6CDFC75212}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609]
"Description"=12.0.1.609
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeploytk.dll
NPJinit13122.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-19 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-12-20 382720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-06-19 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-05-13 26192168]
"Google Update"=C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files (x86)\real\realplayer\Update\realsched.exe [2010-12-20 274608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Download Centre.lnk]
C:\PROGRA~2\YAMAHA~1\DIGITA~1\Common\DOWNLO~1\DOWNLO~1.EXE [2009-11-10 419160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
C:\PROGRA~2\APACHE~1\Apache2.2\bin\APACHE~1.EXE [2010-07-30 41051]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vpngui.exe.lnk]
C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe [2011-02-28 5120]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"=C:\Windows\system32\DeltaIITray.exe []
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"MRUTray"=C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe [2010-04-12 731176]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SC2RAR - Shortcut.lnk - C:\SC2RARu10\SC2RAR\SC2RAR.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-01-08 10:00:48 ----D---- C:\Program Files\trend micro
2012-01-08 10:00:47 ----D---- C:\rsit
2012-01-02 11:37:38 ----D---- C:\Program Files\Microsoft Games
2011-12-26 23:04:24 ----D---- C:\Users\Jakub\AppData\Roaming\Mumble
2011-12-26 23:03:51 ----D---- C:\Program Files (x86)\Mumble
2011-12-26 11:25:48 ----D---- C:\Users\Jakub\AppData\Roaming\calibre
2011-12-26 11:25:07 ----D---- C:\Program Files (x86)\Calibre2
2011-12-18 14:06:58 ----D---- C:\Users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 13:37:40 ----D---- C:\Program Files (x86)\QuickTime
2011-12-18 13:37:38 ----D---- C:\ProgramData\Apple Computer
2011-12-18 13:34:54 ----D---- C:\Program Files (x86)\Apple Software Update
2011-12-18 11:31:10 ----D---- C:\ProgramData\Apple
2011-12-14 12:11:14 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-14 12:11:12 ----A---- C:\Windows\system32\mshtml.dll
2011-12-14 12:11:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-14 12:11:09 ----A---- C:\Windows\system32\ieframe.dll
2011-12-14 12:11:04 ----A---- C:\Windows\system32\wininet.dll
2011-12-14 12:11:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-14 12:11:01 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-14 12:11:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-14 12:11:00 ----A---- C:\Windows\system32\urlmon.dll
2011-12-14 12:10:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\mstime.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\ieui.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\iertutil.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\iedkcs32.dll
2011-12-14 12:10:57 ----A---- C:\Windows\system32\iepeers.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\licmgr10.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-14 12:10:55 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-14 12:10:55 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-12-14 12:10:55 ----A---- C:\Windows\system32\url.dll
2011-12-14 12:10:55 ----A---- C:\Windows\system32\msfeedssync.exe
2011-12-14 12:10:36 ----A---- C:\Windows\system32\win32k.sys
2011-12-14 12:10:34 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-14 12:10:34 ----A---- C:\Windows\system32\EncDec.dll
2011-12-14 12:10:24 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-14 12:10:24 ----A---- C:\Windows\system32\tzres.dll
2011-12-12 21:27:16 ----D---- C:\Program Files (x86)\Edgard
======List of files/folders modified in the last 1 month======
2012-01-08 10:09:42 ----D---- C:\Windows\Temp
2012-01-08 10:09:38 ----D---- C:\TEMP
2012-01-08 10:00:58 ----D---- C:\Windows\Prefetch
2012-01-08 10:00:48 ----RD---- C:\Program Files
2012-01-08 09:52:31 ----D---- C:\Windows\system32\config
2012-01-08 09:51:52 ----D---- C:\Users\Jakub\AppData\Roaming\Skype
2012-01-08 09:51:47 ----D---- C:\Users\Jakub\AppData\Roaming\skypePM
2012-01-08 09:49:21 ----D---- C:\ProgramData\VMware
2012-01-08 00:51:06 ----D---- C:\Users\Jakub\AppData\Roaming\uTorrent
2012-01-08 00:02:08 ----D---- C:\Users\Jakub\AppData\Roaming\vlc
2012-01-06 19:09:15 ----SHD---- C:\System Volume Information
2012-01-03 13:16:56 ----D---- C:\Windows\rescache
2012-01-03 09:13:45 ----D---- C:\Windows\system32\catroot2
2012-01-02 11:37:49 ----D---- C:\Windows\winsxs
2012-01-02 11:37:39 ----D---- C:\Windows\system32\en-US
2012-01-02 11:37:39 ----D---- C:\Windows\System32
2011-12-31 21:25:42 ----D---- C:\Windows\inf
2011-12-31 21:25:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-26 23:03:57 ----SHD---- C:\Windows\Installer
2011-12-26 23:03:51 ----RD---- C:\Program Files (x86)
2011-12-26 23:03:51 ----D---- C:\Windows\SysWOW64
2011-12-21 16:38:38 ----D---- C:\Users\Jakub\AppData\Roaming\dvdcss
2011-12-19 12:41:37 ----D---- C:\Users\Jakub\AppData\Roaming\Clone2Go Video Converter Professional
2011-12-19 12:32:48 ----AD---- C:\ProgramData\TEMP
2011-12-18 13:37:38 ----HD---- C:\ProgramData
2011-12-18 13:35:25 ----D---- C:\Program Files (x86)\Common Files
2011-12-18 11:33:17 ----D---- C:\Windows\system32\Tasks
2011-12-16 10:53:41 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-14 18:28:12 ----D---- C:\Program Files\Internet Explorer
2011-12-14 18:28:12 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-14 18:28:11 ----D---- C:\Windows\SYSWOW64\migration
2011-12-14 18:28:11 ----D---- C:\Windows\system32\migration
2011-12-14 17:21:45 ----RSD---- C:\Windows\assembly
2011-12-14 17:21:44 ----D---- C:\ProgramData\Microsoft Help
2011-12-14 17:21:31 ----D---- C:\Windows\system32\catroot
2011-12-14 17:20:12 ----A---- C:\Windows\system32\MRT.exe
2011-12-14 17:18:10 ----D---- C:\Windows\SYSWOW64\en-US
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2009-10-27 22568]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2009-12-25 297512]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 91568]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2011-10-28 230864]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-09-23 359552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2009-10-20 38448]
R2 vmci;VMware vmci; \??\C:\Windows\system32\drivers\vmci.sys [2009-10-20 65072]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2009-10-20 38960]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2009-10-20 30256]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\drivers\vmx86.sys [2009-10-20 76336]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-02-11 5352960]
R3 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [2010-03-23 304784]
R3 DELTAII;Service for M-Audio Delta Driver (WDM); C:\Windows\system32\DRIVERS\MAudioDelta.sys [2009-07-27 392712]
R3 DNE;Deterministic Network Enhancer Miniport; C:\Windows\system32\DRIVERS\dne64x.sys [2008-11-16 157968]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtl8187.sys [2010-01-07 448512]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2009-10-20 20016]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S3 CVirtA;Cisco Systems VPN Adapter for 64-bit Windows; C:\Windows\system32\DRIVERS\CVirtA64.sys [2010-02-08 14992]
S3 grmnusb;Garmin USB Driver; C:\Windows\system32\drivers\grmnusb.sys [2009-05-08 20520]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [2007-05-14 27520]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WSDPrintDevice;WSD Print Support via UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2010-02-11 952320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe [2010-03-23 1528616]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 Marvell RAID;Marvell RAID Event Agent; C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
R2 MRUWebService;MRU Web Service; C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
R2 OracleDBConsoleorcl;OracleDBConsoleorcl; C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe [2010-03-02 35328]
R2 OracleMTSRecoveryService;OracleMTSRecoveryService; C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe [2010-03-12 81408]
R2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener; K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR []
R2 OracleServiceORCL;OracleServiceORCL; c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE [2010-03-30 134018048]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 VMAuthdService;VMware Authorization Service; C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe [2009-10-20 121392]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\syswow64\vmnetdhcp.exe [2009-10-20 326192]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\syswow64\vmnat.exe [2009-10-20 399920]
R2 VMwareHostd;VMware Host Agent; C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
R2 VMwareServerWebAccess;VMware Server Web Access; C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener; C:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 MsDtsServer100;SQL Server Integration Services 10.0; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
S3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08); C:\Program Files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
S3 MSSQL$SQL08;SQL Server (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
S3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent; C:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
S3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent; K:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
S3 OracleServiceORCL11;OracleServiceORCL11; k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE [2010-03-30 134018048]
S3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service; c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe [2010-03-30 192000]
S3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service; k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe [2010-03-30 192000]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ReportServer$SQL08;SQL Server Reporting Services (SQL08); C:\Program Files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
S3 SQLAgent$SQL08;SQL Server Agent (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S3 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-27 1255736]
S4 Apache2.2;Apache2.2; C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
S4 OracleJobSchedulerORCL;OracleJobSchedulerORCL; c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe [2010-03-30 45568]
S4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11; k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe [2010-03-30 45568]
-----------------EOF-----------------
dnes rano me privitala hlaska od esetu (legalne zakoupen stejne jako os) ze MBR sektor1. fyzickeho disku je infiltrovan Win32/Agent.SDG.Gen trojsky kun. Tlacitko lecit nepomaha. Po spusteni kontroly stejnou hlasku hazi i pro disky 3 a 4.
Rad bych vas pozadal o radu jak postupovat.
Predem dekuji.
Log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jakub at 2012-01-08 10:09:40
Microsoft Windows 7 Professional
System drive C: has 30 GB (15%) free of 200 GB
Total RAM: 4095 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:09:44, on 8.1.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16912)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\SC2RARu10\SC2RAR\SC2RAR.exe
C:\Windows\SysWOW64\DeltaIITray.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\Jakub.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [MRUTray] C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: SC2RAR - Shortcut.lnk = C:\SC2RARu10\SC2RAR\SC2RAR.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\vmware\vmware server\vsocklib.dll
O15 - Trusted IP range: http://127.0.0.1
O16 - DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574} (VMware Remote Console Plug-in 2.5.0.00000) -
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) -
O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - C:\COMMON~1\QUESTS~1\CODEXP~1\qcom.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner - C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe
O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation - C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: OracleDBConsoleorcl - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe
O23 - Service: OracleOraDb11g_home1ClrAgent - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe
O23 - Service: OracleOraDb11g_home1TNSListener - Oracle Corporation - C:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR.exe
O23 - Service: OracleOraDb11g_home2ClrAgent - Oracle Corporation - K:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe
O23 - Service: OracleOraDb11g_home2TNSListener - Oracle Corporation - K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR.exe
O23 - Service: OracleServiceORCL - Oracle Corporation - c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE
O23 - Service: OracleServiceORCL11 - Oracle Corporation - k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE
O23 - Service: Oracle ORCL VSS Writer Service (OracleVssWriterORCL) - Unknown owner - c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe
O23 - Service: Oracle ORCL11 VSS Writer Service (OracleVssWriterORCL11) - Unknown owner - k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10588 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
Ati2evxx.exe -Client
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe" -k runservice
C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe
C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe "OracleMTSRecoveryService"
\??\C:\Windows\system32\conhost.exe "-80325381-11333306271417005892989559031339049103-9331638921102959403-108127563
K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR
"C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe" -d "C:/Program Files (x86)/Marvell/raid/Apache2"
c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
cmd /c ""C:\app\Jakub\product\11.2.0\dbhome_1\bin\emctl.bat" istart dbconsole"
C:\app\Jakub\product\11.2.0\dbhome_1\\perl\bin\perl.exe C:\app\Jakub\product\11.2.0\dbhome_1\bin\emwd.pl dbconsole
C:\Windows\SysWOW64\vmnat.exe
"C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe" //RS//VMwareServerWebAccess
\??\C:\Windows\system32\conhost.exe "8598574491427828188-1063851766-2128205691320828558-410138486-963244062426114300
cmd /c "C:\app\Jakub\product\11.2.0\dbhome_1/bin/execjavatemp.bat"
C:\app\Jakub\product\11.2.0\dbhome_1\jdk/bin/java -server -Xmx192M -XX:MaxPermSize=200M -XX:MinHeapFreeRatio=20 -XX:MaxHeapFreeRatio=40 -DORACLE_HOME=C:\app\Jakub\product\11.2.0\dbhome_1 -Doracle.home=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j -Doracle.oc4j.localhome=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl/sysman -DEMSTATE=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl -Doracle.j2ee.dont.use.memory.archive=true -Djava.protocol.handler.pkgs=HTTPClient -Doracle.security.jazn.config=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/jazn.xml -Djava.security.policy=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/java2.policy -Djavax.net.ssl.KeyStore=C:\app\Jakub\product\11.2.0\dbhome_1/sysman/config/OCMTrustedCerts.txt-Djava.security.properties=C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/home/config/jazn.security.props -DEMDROOT=C:\app\Jakub\product\11.2.0\dbhome_1\localhost_orcl -Dsysman.md5password=true -Drepapi.oracle.home=C:\app\Jakub\product\11.2.0\dbhome_1 -Ddisable.checkForUpdate=true -Doracle.sysman.ccr.ocmSDK.websvc.keystore=C:\app\Jakub\product\11.2.0\dbhome_1/jlib/emocmclnt.ks -Dice.pilots.html4.ignoreNonGenericFonts=true -Djava.awt.headless=true -jar C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/home/oc4j.jar -config C:\app\Jakub\product\11.2.0\dbhome_1/oc4j/j2ee/OC4J_DBConsole_localhost_orcl/config/server.xml
"C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe"
"C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe"
C:\app\Jakub\product\11.2.0\dbhome_1/bin/emagent
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe" -u "C:\ProgramData\VMware\VMware Server\hostd\config.xml"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\SC2RARu10\SC2RAR\SC2RAR.exe"
"C:\Windows\System32\DeltaIITray.exe"
"C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
"C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\wuauclt.exe"
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --enable-print-preview --channel=4588.06174000.2036729946 /prefetch:3
C:\Windows\system32\rundll32.exe "C:\Users\Jakub\AppData\Local\Google\Chrome\APPLIC~1\160912~1.75\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Jakub\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll" --lang=cs --channel=4588.0A7F9000.895826943 --flash-broker=4152 /prefetch:4
"C:\Users\Jakub\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --enable-print-preview --channel=4588.05C7A480.224716698 /prefetch:3
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\log.txt
"C:\totalcmd\TOTALCMD.EXE"
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Jakub\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, {0493D792-5C92-440b-81A8-AD6CDFC75212}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609]
"Description"=12.0.1.609
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeploytk.dll
NPJinit13122.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-19 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-12-20 382720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-06-19 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-05-13 26192168]
"Google Update"=C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files (x86)\real\realplayer\Update\realsched.exe [2010-12-20 274608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Download Centre.lnk]
C:\PROGRA~2\YAMAHA~1\DIGITA~1\Common\DOWNLO~1\DOWNLO~1.EXE [2009-11-10 419160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
C:\PROGRA~2\APACHE~1\Apache2.2\bin\APACHE~1.EXE [2010-07-30 41051]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vpngui.exe.lnk]
C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe [2011-02-28 5120]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"=C:\Windows\system32\DeltaIITray.exe []
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"MRUTray"=C:\Program Files (x86)\Marvell\raid\tray\MarvellTray.exe [2010-04-12 731176]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SC2RAR - Shortcut.lnk - C:\SC2RARu10\SC2RAR\SC2RAR.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-01-08 10:00:48 ----D---- C:\Program Files\trend micro
2012-01-08 10:00:47 ----D---- C:\rsit
2012-01-02 11:37:38 ----D---- C:\Program Files\Microsoft Games
2011-12-26 23:04:24 ----D---- C:\Users\Jakub\AppData\Roaming\Mumble
2011-12-26 23:03:51 ----D---- C:\Program Files (x86)\Mumble
2011-12-26 11:25:48 ----D---- C:\Users\Jakub\AppData\Roaming\calibre
2011-12-26 11:25:07 ----D---- C:\Program Files (x86)\Calibre2
2011-12-18 14:06:58 ----D---- C:\Users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 13:37:40 ----D---- C:\Program Files (x86)\QuickTime
2011-12-18 13:37:38 ----D---- C:\ProgramData\Apple Computer
2011-12-18 13:34:54 ----D---- C:\Program Files (x86)\Apple Software Update
2011-12-18 11:31:10 ----D---- C:\ProgramData\Apple
2011-12-14 12:11:14 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-14 12:11:12 ----A---- C:\Windows\system32\mshtml.dll
2011-12-14 12:11:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-14 12:11:09 ----A---- C:\Windows\system32\ieframe.dll
2011-12-14 12:11:04 ----A---- C:\Windows\system32\wininet.dll
2011-12-14 12:11:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-14 12:11:01 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-14 12:11:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-14 12:11:00 ----A---- C:\Windows\system32\urlmon.dll
2011-12-14 12:10:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-14 12:10:58 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\mstime.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\ieui.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\iertutil.dll
2011-12-14 12:10:58 ----A---- C:\Windows\system32\iedkcs32.dll
2011-12-14 12:10:57 ----A---- C:\Windows\system32\iepeers.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-14 12:10:56 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\licmgr10.dll
2011-12-14 12:10:56 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-14 12:10:55 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-14 12:10:55 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-12-14 12:10:55 ----A---- C:\Windows\system32\url.dll
2011-12-14 12:10:55 ----A---- C:\Windows\system32\msfeedssync.exe
2011-12-14 12:10:36 ----A---- C:\Windows\system32\win32k.sys
2011-12-14 12:10:34 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-14 12:10:34 ----A---- C:\Windows\system32\EncDec.dll
2011-12-14 12:10:24 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-14 12:10:24 ----A---- C:\Windows\system32\tzres.dll
2011-12-12 21:27:16 ----D---- C:\Program Files (x86)\Edgard
======List of files/folders modified in the last 1 month======
2012-01-08 10:09:42 ----D---- C:\Windows\Temp
2012-01-08 10:09:38 ----D---- C:\TEMP
2012-01-08 10:00:58 ----D---- C:\Windows\Prefetch
2012-01-08 10:00:48 ----RD---- C:\Program Files
2012-01-08 09:52:31 ----D---- C:\Windows\system32\config
2012-01-08 09:51:52 ----D---- C:\Users\Jakub\AppData\Roaming\Skype
2012-01-08 09:51:47 ----D---- C:\Users\Jakub\AppData\Roaming\skypePM
2012-01-08 09:49:21 ----D---- C:\ProgramData\VMware
2012-01-08 00:51:06 ----D---- C:\Users\Jakub\AppData\Roaming\uTorrent
2012-01-08 00:02:08 ----D---- C:\Users\Jakub\AppData\Roaming\vlc
2012-01-06 19:09:15 ----SHD---- C:\System Volume Information
2012-01-03 13:16:56 ----D---- C:\Windows\rescache
2012-01-03 09:13:45 ----D---- C:\Windows\system32\catroot2
2012-01-02 11:37:49 ----D---- C:\Windows\winsxs
2012-01-02 11:37:39 ----D---- C:\Windows\system32\en-US
2012-01-02 11:37:39 ----D---- C:\Windows\System32
2011-12-31 21:25:42 ----D---- C:\Windows\inf
2011-12-31 21:25:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-26 23:03:57 ----SHD---- C:\Windows\Installer
2011-12-26 23:03:51 ----RD---- C:\Program Files (x86)
2011-12-26 23:03:51 ----D---- C:\Windows\SysWOW64
2011-12-21 16:38:38 ----D---- C:\Users\Jakub\AppData\Roaming\dvdcss
2011-12-19 12:41:37 ----D---- C:\Users\Jakub\AppData\Roaming\Clone2Go Video Converter Professional
2011-12-19 12:32:48 ----AD---- C:\ProgramData\TEMP
2011-12-18 13:37:38 ----HD---- C:\ProgramData
2011-12-18 13:35:25 ----D---- C:\Program Files (x86)\Common Files
2011-12-18 11:33:17 ----D---- C:\Windows\system32\Tasks
2011-12-16 10:53:41 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-14 18:28:12 ----D---- C:\Program Files\Internet Explorer
2011-12-14 18:28:12 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-14 18:28:11 ----D---- C:\Windows\SYSWOW64\migration
2011-12-14 18:28:11 ----D---- C:\Windows\system32\migration
2011-12-14 17:21:45 ----RSD---- C:\Windows\assembly
2011-12-14 17:21:44 ----D---- C:\ProgramData\Microsoft Help
2011-12-14 17:21:31 ----D---- C:\Windows\system32\catroot
2011-12-14 17:20:12 ----A---- C:\Windows\system32\MRT.exe
2011-12-14 17:18:10 ----D---- C:\Windows\SYSWOW64\en-US
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2009-10-27 22568]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2009-12-25 297512]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 91568]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2011-10-28 230864]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-09-23 359552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2009-10-20 38448]
R2 vmci;VMware vmci; \??\C:\Windows\system32\drivers\vmci.sys [2009-10-20 65072]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2009-10-20 38960]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2009-10-20 30256]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\drivers\vmx86.sys [2009-10-20 76336]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-02-11 5352960]
R3 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [2010-03-23 304784]
R3 DELTAII;Service for M-Audio Delta Driver (WDM); C:\Windows\system32\DRIVERS\MAudioDelta.sys [2009-07-27 392712]
R3 DNE;Deterministic Network Enhancer Miniport; C:\Windows\system32\DRIVERS\dne64x.sys [2008-11-16 157968]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtl8187.sys [2010-01-07 448512]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2009-10-20 20016]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S3 CVirtA;Cisco Systems VPN Adapter for 64-bit Windows; C:\Windows\system32\DRIVERS\CVirtA64.sys [2010-02-08 14992]
S3 grmnusb;Garmin USB Driver; C:\Windows\system32\drivers\grmnusb.sys [2009-05-08 20520]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [2007-05-14 27520]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WSDPrintDevice;WSD Print Support via UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2010-02-11 952320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe [2010-03-23 1528616]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 Marvell RAID;Marvell RAID Event Agent; C:\Program Files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
R2 MRUWebService;MRU Web Service; C:\Program Files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
R2 OracleDBConsoleorcl;OracleDBConsoleorcl; C:\app\Jakub\product\11.2.0\dbhome_1\bin\nmesrvc.exe [2010-03-02 35328]
R2 OracleMTSRecoveryService;OracleMTSRecoveryService; C:\app\Jakub\product\11.2.0\dbhome_1\bin\omtsreco.exe [2010-03-12 81408]
R2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener; K:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR []
R2 OracleServiceORCL;OracleServiceORCL; c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE [2010-03-30 134018048]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 VMAuthdService;VMware Authorization Service; C:\Program Files (x86)\VMware\VMware Server\vmware-authd.exe [2009-10-20 121392]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\syswow64\vmnetdhcp.exe [2009-10-20 326192]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\syswow64\vmnat.exe [2009-10-20 399920]
R2 VMwareHostd;VMware Host Agent; C:\Program Files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
R2 VMwareServerWebAccess;VMware Server Web Access; C:\Program Files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener; C:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 MsDtsServer100;SQL Server Integration Services 10.0; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
S3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08); C:\Program Files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
S3 MSSQL$SQL08;SQL Server (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
S3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent; C:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
S3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent; K:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
S3 OracleServiceORCL11;OracleServiceORCL11; k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE [2010-03-30 134018048]
S3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service; c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe [2010-03-30 192000]
S3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service; k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe [2010-03-30 192000]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ReportServer$SQL08;SQL Server Reporting Services (SQL08); C:\Program Files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
S3 SQLAgent$SQL08;SQL Server Agent (SQL08); C:\Program Files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S3 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-27 1255736]
S4 Apache2.2;Apache2.2; C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
S4 OracleJobSchedulerORCL;OracleJobSchedulerORCL; c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe [2010-03-30 45568]
S4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11; k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe [2010-03-30 45568]
-----------------EOF-----------------
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Zdravim a pekny den preji
Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe


- Kliknete na volbu Change parametrs
- V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
- Kliknete na OK
- Utilite prikazte, at skenuje - klik na Start Scan
- Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
- Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
- Pokud mate vsude Skip, kliknete na Continue
- Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte

- Ukoncete vsechny programy
- Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
- Zvolte moznost 2 a potvrte enterem
- Utilita provede svou cinnost a da log - ten sem vlozte
- Nyni znovu, ale zvolte moznost 3 log opet vlozte
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
TDSSKiller log:
10:57:36.0430 5556 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
10:57:37.0018 5556 ============================================================
10:57:37.0018 5556 Current date / time: 2012/01/08 10:57:37.0018
10:57:37.0018 5556 SystemInfo:
10:57:37.0018 5556
10:57:37.0018 5556 OS Version: 6.1.7600 ServicePack: 0.0
10:57:37.0018 5556 Product type: Workstation
10:57:37.0018 5556 ComputerName: COHENW7
10:57:37.0018 5556 UserName: Jakub
10:57:37.0018 5556 Windows directory: C:\Windows
10:57:37.0018 5556 System windows directory: C:\Windows
10:57:37.0018 5556 Running under WOW64
10:57:37.0018 5556 Processor architecture: Intel x64
10:57:37.0018 5556 Number of processors: 4
10:57:37.0018 5556 Page size: 0x1000
10:57:37.0018 5556 Boot type: Normal boot
10:57:37.0018 5556 ============================================================
10:57:38.0995 5556 Initialize success
10:57:59.0840 5684 ============================================================
10:57:59.0840 5684 Scan started
10:57:59.0840 5684 Mode: Manual; SigCheck; TDLFS;
10:57:59.0840 5684 ============================================================
10:58:01.0485 5684 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
10:58:01.0602 5684 1394ohci - ok
10:58:01.0635 5684 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
10:58:01.0652 5684 ACPI - ok
10:58:01.0811 5684 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
10:58:02.0263 5684 AcpiPmi - ok
10:58:02.0452 5684 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
10:58:02.0523 5684 adp94xx - ok
10:58:02.0640 5684 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
10:58:02.0730 5684 adpahci - ok
10:58:02.0808 5684 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
10:58:02.0857 5684 adpu320 - ok
10:58:03.0102 5684 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
10:58:03.0309 5684 AFD - ok
10:58:03.0465 5684 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
10:58:03.0551 5684 agp440 - ok
10:58:03.0780 5684 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
10:58:03.0849 5684 aliide - ok
10:58:03.0980 5684 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
10:58:04.0057 5684 amdide - ok
10:58:04.0254 5684 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
10:58:04.0374 5684 AmdK8 - ok
10:58:04.0487 5684 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
10:58:04.0574 5684 AmdPPM - ok
10:58:04.0793 5684 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
10:58:04.0860 5684 amdsata - ok
10:58:05.0017 5684 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
10:58:05.0075 5684 amdsbs - ok
10:58:05.0180 5684 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
10:58:05.0221 5684 amdxata - ok
10:58:05.0529 5684 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
10:58:06.0113 5684 AppID - ok
10:58:06.0321 5684 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
10:58:06.0352 5684 arc - ok
10:58:06.0463 5684 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
10:58:06.0496 5684 arcsas - ok
10:58:06.0634 5684 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
10:58:07.0805 5684 AsyncMac - ok
10:58:08.0176 5684 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
10:58:08.0186 5684 atapi - ok
10:58:09.0261 5684 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
10:58:09.0833 5684 atikmdag - ok
10:58:10.0383 5684 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
10:58:10.0568 5684 b06bdrv - ok
10:58:10.0594 5684 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
10:58:10.0660 5684 b57nd60a - ok
10:58:10.0717 5684 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
10:58:10.0778 5684 Beep - ok
10:58:10.0926 5684 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
10:58:11.0023 5684 blbdrive - ok
10:58:11.0195 5684 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
10:58:11.0451 5684 bowser - ok
10:58:11.0565 5684 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:58:11.0614 5684 BrFiltLo - ok
10:58:11.0664 5684 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:58:11.0691 5684 BrFiltUp - ok
10:58:11.0789 5684 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
10:58:11.0947 5684 Brserid - ok
10:58:12.0038 5684 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
10:58:12.0125 5684 BrSerWdm - ok
10:58:12.0278 5684 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:58:12.0397 5684 BrUsbMdm - ok
10:58:12.0478 5684 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
10:58:12.0517 5684 BrUsbSer - ok
10:58:12.0752 5684 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
10:58:12.0826 5684 BTHMODEM - ok
10:58:12.0891 5684 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
10:58:12.0996 5684 cdfs - ok
10:58:13.0156 5684 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
10:58:13.0224 5684 cdrom - ok
10:58:13.0269 5684 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
10:58:13.0308 5684 circlass - ok
10:58:13.0338 5684 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
10:58:13.0386 5684 CLFS - ok
10:58:13.0442 5684 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
10:58:13.0475 5684 CmBatt - ok
10:58:13.0483 5684 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
10:58:13.0509 5684 cmdide - ok
10:58:13.0551 5684 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
10:58:13.0629 5684 CNG - ok
10:58:13.0648 5684 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
10:58:13.0671 5684 Compbatt - ok
10:58:13.0748 5684 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
10:58:13.0787 5684 CompositeBus - ok
10:58:13.0811 5684 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
10:58:13.0823 5684 crcdisk - ok
10:58:13.0901 5684 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
10:58:14.0014 5684 CSC - ok
10:58:14.0047 5684 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
10:58:14.0076 5684 CVirtA - ok
10:58:14.0156 5684 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
10:58:14.0170 5684 CVPNDRVA - ok
10:58:14.0262 5684 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
10:58:14.0291 5684 DELTAII - ok
10:58:14.0344 5684 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
10:58:14.0499 5684 DfsC - ok
10:58:14.0848 5684 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
10:58:15.0056 5684 discache - ok
10:58:15.0363 5684 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
10:58:15.0392 5684 Disk - ok
10:58:15.0724 5684 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
10:58:15.0777 5684 DNE - ok
10:58:16.0223 5684 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
10:58:16.0325 5684 drmkaud - ok
10:58:17.0084 5684 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
10:58:17.0249 5684 DXGKrnl - ok
10:58:17.0659 5684 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
10:58:17.0737 5684 eamon - ok
10:58:18.0850 5684 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
10:58:19.0054 5684 ebdrv - ok
10:58:19.0304 5684 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
10:58:19.0337 5684 ehdrv - ok
10:58:19.0594 5684 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
10:58:19.0620 5684 elxstor - ok
10:58:19.0657 5684 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
10:58:19.0669 5684 epfwwfpr - ok
10:58:19.0704 5684 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
10:58:19.0774 5684 ErrDev - ok
10:58:19.0906 5684 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
10:58:20.0033 5684 exfat - ok
10:58:20.0057 5684 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
10:58:20.0126 5684 fastfat - ok
10:58:20.0168 5684 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
10:58:20.0242 5684 fdc - ok
10:58:20.0334 5684 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
10:58:20.0362 5684 FileInfo - ok
10:58:20.0376 5684 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
10:58:20.0467 5684 Filetrace - ok
10:58:20.0491 5684 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
10:58:20.0533 5684 flpydisk - ok
10:58:20.0581 5684 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
10:58:20.0613 5684 FltMgr - ok
10:58:20.0632 5684 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
10:58:20.0658 5684 FsDepends - ok
10:58:20.0681 5684 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
10:58:20.0707 5684 Fs_Rec - ok
10:58:20.0742 5684 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
10:58:20.0758 5684 fvevol - ok
10:58:20.0789 5684 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:58:20.0846 5684 gagp30kx - ok
10:58:20.0886 5684 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
10:58:20.0907 5684 grmnusb - ok
10:58:20.0952 5684 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
10:58:20.0975 5684 hcmon - ok
10:58:21.0006 5684 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
10:58:21.0092 5684 hcw85cir - ok
10:58:21.0316 5684 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
10:58:22.0412 5684 HdAudAddService - ok
10:58:22.0463 5684 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
10:58:22.0509 5684 HDAudBus - ok
10:58:22.0527 5684 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
10:58:22.0584 5684 HidBatt - ok
10:58:22.0593 5684 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
10:58:22.0638 5684 HidBth - ok
10:58:22.0657 5684 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
10:58:22.0936 5684 HidIr - ok
10:58:23.0023 5684 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
10:58:23.0051 5684 HidUsb - ok
10:58:23.0097 5684 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
10:58:23.0124 5684 HpSAMD - ok
10:58:23.0162 5684 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
10:58:23.0232 5684 HTTP - ok
10:58:23.0276 5684 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
10:58:23.0315 5684 hwpolicy - ok
10:58:23.0396 5684 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
10:58:23.0427 5684 i8042prt - ok
10:58:23.0739 5684 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
10:58:23.0833 5684 iaStorV - ok
10:58:23.0935 5684 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
10:58:23.0947 5684 iirsp - ok
10:58:24.0026 5684 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
10:58:24.0037 5684 intelide - ok
10:58:24.0183 5684 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
10:58:24.0219 5684 intelppm - ok
10:58:24.0261 5684 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:58:24.0334 5684 IpFilterDriver - ok
10:58:24.0374 5684 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
10:58:24.0410 5684 IPMIDRV - ok
10:58:24.0513 5684 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
10:58:24.0585 5684 IPNAT - ok
10:58:24.0630 5684 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
10:58:24.0679 5684 IRENUM - ok
10:58:24.0696 5684 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
10:58:24.0722 5684 isapnp - ok
10:58:24.0764 5684 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
10:58:33.0908 5684 iScsiPrt - ok
10:58:33.0961 5684 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
10:58:33.0973 5684 kbdclass - ok
10:58:34.0025 5684 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
10:58:34.0051 5684 kbdhid - ok
10:58:34.0092 5684 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
10:58:34.0104 5684 KSecDD - ok
10:58:34.0156 5684 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
10:58:34.0168 5684 KSecPkg - ok
10:58:34.0203 5684 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
10:58:34.0262 5684 ksthunk - ok
10:58:34.0312 5684 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
10:58:34.0381 5684 lltdio - ok
10:58:34.0431 5684 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
10:58:34.0460 5684 LSI_FC - ok
10:58:34.0476 5684 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
10:58:34.0504 5684 LSI_SAS - ok
10:58:34.0531 5684 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:58:34.0560 5684 LSI_SAS2 - ok
10:58:34.0616 5684 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:58:34.0644 5684 LSI_SCSI - ok
10:58:34.0675 5684 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
10:58:34.0722 5684 luafv - ok
10:58:34.0781 5684 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
10:58:34.0831 5684 MarvinBus - ok
10:58:34.0840 5684 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
10:58:34.0887 5684 megasas - ok
10:58:34.0901 5684 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
10:58:34.0940 5684 MegaSR - ok
10:58:34.0969 5684 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
10:58:35.0034 5684 Modem - ok
10:58:35.0057 5684 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
10:58:35.0080 5684 monitor - ok
10:58:35.0102 5684 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
10:58:35.0115 5684 mouclass - ok
10:58:35.0131 5684 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
10:58:35.0164 5684 mouhid - ok
10:58:35.0186 5684 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
10:58:35.0213 5684 mountmgr - ok
10:58:35.0230 5684 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
10:58:35.0248 5684 mpio - ok
10:58:35.0270 5684 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
10:58:35.0341 5684 mpsdrv - ok
10:58:35.0377 5684 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
10:58:35.0408 5684 MRxDAV - ok
10:58:35.0465 5684 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:58:35.0532 5684 mrxsmb - ok
10:58:35.0571 5684 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:58:35.0589 5684 mrxsmb10 - ok
10:58:35.0621 5684 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:58:35.0680 5684 mrxsmb20 - ok
10:58:35.0724 5684 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
10:58:35.0765 5684 msahci - ok
10:58:35.0788 5684 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
10:58:35.0816 5684 msdsm - ok
10:58:35.0837 5684 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
10:58:35.0872 5684 Msfs - ok
10:58:35.0880 5684 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
10:58:35.0939 5684 mshidkmdf - ok
10:58:35.0947 5684 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
10:58:35.0974 5684 msisadrv - ok
10:58:36.0000 5684 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
10:58:36.0044 5684 MSKSSRV - ok
10:58:36.0060 5684 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
10:58:36.0108 5684 MSPCLOCK - ok
10:58:36.0116 5684 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
10:58:36.0177 5684 MSPQM - ok
10:58:36.0203 5684 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
10:58:36.0230 5684 MsRPC - ok
10:58:36.0253 5684 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
10:58:36.0266 5684 mssmbios - ok
10:58:36.0406 5684 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
10:58:36.0447 5684 MSTEE - ok
10:58:36.0454 5684 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
10:58:36.0472 5684 MTConfig - ok
10:58:36.0525 5684 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
10:58:36.0578 5684 MTsensor - ok
10:58:36.0593 5684 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
10:58:36.0619 5684 Mup - ok
10:58:36.0661 5684 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
10:58:36.0670 5684 mv91cons - ok
10:58:36.0713 5684 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
10:58:36.0723 5684 mv91xx - ok
10:58:36.0789 5684 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
10:58:36.0860 5684 NativeWifiP - ok
10:58:36.0905 5684 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
10:58:36.0934 5684 NDIS - ok
10:58:36.0948 5684 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
10:58:36.0997 5684 NdisCap - ok
10:58:37.0020 5684 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
10:58:37.0067 5684 NdisTapi - ok
10:58:37.0096 5684 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
10:58:37.0144 5684 Ndisuio - ok
10:58:37.0161 5684 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
10:58:37.0221 5684 NdisWan - ok
10:58:37.0246 5684 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
10:58:37.0307 5684 NDProxy - ok
10:58:37.0323 5684 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
10:58:37.0372 5684 NetBIOS - ok
10:58:37.0393 5684 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
10:58:37.0449 5684 NetBT - ok
10:58:37.0486 5684 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
10:58:37.0527 5684 nfrd960 - ok
10:58:37.0549 5684 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
10:58:37.0605 5684 Npfs - ok
10:58:37.0630 5684 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
10:58:37.0688 5684 nsiproxy - ok
10:58:37.0743 5684 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
10:58:37.0816 5684 Ntfs - ok
10:58:37.0842 5684 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
10:58:37.0916 5684 Null - ok
10:58:37.0964 5684 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
10:58:37.0992 5684 nvraid - ok
10:58:38.0020 5684 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
10:58:38.0071 5684 nvstor - ok
10:58:38.0088 5684 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
10:58:38.0116 5684 nv_agp - ok
10:58:38.0138 5684 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
10:58:38.0176 5684 ohci1394 - ok
10:58:38.0239 5684 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
10:58:38.0268 5684 Parport - ok
10:58:38.0290 5684 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
10:58:38.0317 5684 partmgr - ok
10:58:38.0353 5684 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
10:58:38.0382 5684 pci - ok
10:58:38.0397 5684 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
10:58:38.0432 5684 pciide - ok
10:58:38.0497 5684 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
10:58:38.0526 5684 pcmcia - ok
10:58:38.0541 5684 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
10:58:38.0567 5684 pcw - ok
10:58:38.0592 5684 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
10:58:38.0652 5684 PEAUTH - ok
10:58:38.0704 5684 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
10:58:38.0766 5684 PptpMiniport - ok
10:58:38.0792 5684 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
10:58:38.0846 5684 Processor - ok
10:58:38.0896 5684 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
10:58:38.0937 5684 Psched - ok
10:58:39.0008 5684 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
10:58:39.0056 5684 ql2300 - ok
10:58:39.0076 5684 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
10:58:39.0090 5684 ql40xx - ok
10:58:39.0120 5684 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
10:58:39.0228 5684 QWAVEdrv - ok
10:58:39.0501 5684 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
10:58:39.0603 5684 RasAcd - ok
10:58:39.0695 5684 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:58:39.0737 5684 RasAgileVpn - ok
10:58:39.0775 5684 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:58:43.0133 5684 Rasl2tp - ok
10:58:43.0252 5684 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
10:58:43.0293 5684 RasPppoe - ok
10:58:43.0309 5684 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
10:58:43.0367 5684 RasSstp - ok
10:58:43.0393 5684 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
10:58:43.0449 5684 rdbss - ok
10:58:43.0477 5684 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
10:58:43.0529 5684 rdpbus - ok
10:58:43.0549 5684 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:58:43.0585 5684 RDPCDD - ok
10:58:43.0626 5684 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
10:58:43.0828 5684 RDPDR - ok
10:58:44.0048 5684 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
10:58:44.0136 5684 RDPENCDD - ok
10:58:44.0173 5684 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
10:58:44.0208 5684 RDPREFMP - ok
10:58:44.0402 5684 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
10:58:44.0540 5684 RDPWD - ok
10:58:44.0633 5684 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
10:58:44.0752 5684 rdyboost - ok
10:58:45.0223 5684 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
10:58:45.0431 5684 RimUsb - ok
10:58:45.0857 5684 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
10:58:46.0048 5684 RsFx0103 - ok
10:58:46.0452 5684 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
10:58:46.0526 5684 rspndr - ok
10:58:46.0750 5684 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
10:58:46.0897 5684 RTL8167 - ok
10:58:47.0185 5684 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
10:58:47.0250 5684 RTL8187 - ok
10:58:47.0324 5684 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
10:58:47.0495 5684 s3cap - ok
10:58:47.0536 5684 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
10:58:47.0564 5684 sbp2port - ok
10:58:47.0637 5684 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
10:58:47.0677 5684 SCDEmu - ok
10:58:47.0701 5684 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
10:58:47.0763 5684 scfilter - ok
10:58:47.0815 5684 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
10:58:47.0880 5684 secdrv - ok
10:58:47.0940 5684 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
10:58:47.0993 5684 Serenum - ok
10:58:48.0109 5684 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
10:58:48.0219 5684 Serial - ok
10:58:48.0256 5684 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
10:58:48.0307 5684 sermouse - ok
10:58:48.0451 5684 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
10:58:48.0516 5684 sffdisk - ok
10:58:48.0591 5684 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
10:58:48.0634 5684 sffp_mmc - ok
10:58:48.0653 5684 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
10:58:48.0669 5684 sffp_sd - ok
10:58:48.0680 5684 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
10:58:48.0725 5684 sfloppy - ok
10:58:48.0758 5684 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:58:48.0801 5684 SiSRaid2 - ok
10:58:48.0825 5684 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
10:58:48.0888 5684 SiSRaid4 - ok
10:58:48.0933 5684 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
10:58:49.0000 5684 Smb - ok
10:58:49.0051 5684 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
10:58:49.0076 5684 spldr - ok
10:58:49.0136 5684 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
10:58:49.0197 5684 srv - ok
10:58:49.0273 5684 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
10:58:49.0315 5684 srv2 - ok
10:58:49.0344 5684 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
10:58:49.0371 5684 srvnet - ok
10:58:49.0404 5684 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
10:58:49.0424 5684 stexstor - ok
10:58:49.0457 5684 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
10:58:49.0470 5684 storflt - ok
10:58:49.0490 5684 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
10:58:49.0516 5684 storvsc - ok
10:58:49.0540 5684 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
10:58:49.0572 5684 swenum - ok
10:58:49.0652 5684 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
10:58:49.0714 5684 Tcpip - ok
10:58:49.0781 5684 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
10:58:49.0819 5684 TCPIP6 - ok
10:58:49.0844 5684 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
10:58:49.0880 5684 tcpipreg - ok
10:58:49.0940 5684 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
10:58:50.0005 5684 TDPIPE - ok
10:58:50.0014 5684 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
10:58:50.0080 5684 TDTCP - ok
10:58:50.0121 5684 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
10:58:50.0223 5684 tdx - ok
10:58:50.0255 5684 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
10:58:50.0276 5684 TermDD - ok
10:58:50.0372 5684 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
10:58:50.0389 5684 truecrypt - ok
10:58:50.0428 5684 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:58:50.0475 5684 tssecsrv - ok
10:58:50.0512 5684 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
10:58:50.0568 5684 tunnel - ok
10:58:50.0579 5684 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
10:58:50.0606 5684 uagp35 - ok
10:58:50.0643 5684 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
10:58:50.0706 5684 udfs - ok
10:58:50.0752 5684 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
10:58:50.0782 5684 uliagpkx - ok
10:58:50.0807 5684 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
10:58:50.0846 5684 umbus - ok
10:58:50.0859 5684 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
10:58:50.0897 5684 UmPass - ok
10:58:50.0936 5684 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
10:58:50.0997 5684 usbccgp - ok
10:58:51.0010 5684 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
10:58:51.0033 5684 usbcir - ok
10:58:51.0060 5684 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
10:58:51.0112 5684 usbehci - ok
10:58:51.0145 5684 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
10:58:51.0186 5684 usbhub - ok
10:58:51.0217 5684 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
10:58:51.0283 5684 usbohci - ok
10:58:51.0307 5684 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
10:58:51.0349 5684 usbprint - ok
10:58:51.0381 5684 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:58:51.0456 5684 USBSTOR - ok
10:58:51.0492 5684 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
10:58:51.0520 5684 usbuhci - ok
10:58:51.0563 5684 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
10:58:51.0604 5684 vdrvroot - ok
10:58:51.0630 5684 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
10:58:51.0647 5684 vga - ok
10:58:51.0673 5684 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
10:58:51.0740 5684 VgaSave - ok
10:58:51.0781 5684 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
10:58:51.0814 5684 vhdmp - ok
10:58:51.0828 5684 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
10:58:51.0855 5684 viaide - ok
10:58:51.0926 5684 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
10:58:51.0993 5684 vmbus - ok
10:58:52.0025 5684 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
10:58:52.0063 5684 VMBusHID - ok
10:58:52.0133 5684 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
10:58:52.0224 5684 vmci - ok
10:58:52.0248 5684 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
10:58:52.0262 5684 VMnetAdapter - ok
10:58:52.0308 5684 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
10:58:52.0346 5684 VMnetBridge - ok
10:58:52.0450 5684 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
10:58:52.0464 5684 VMnetuserif - ok
10:58:52.0530 5684 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
10:58:52.0540 5684 vmx86 - ok
10:58:52.0560 5684 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
10:58:52.0602 5684 volmgr - ok
10:58:52.0723 5684 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
10:58:52.0809 5684 volmgrx - ok
10:58:53.0009 5684 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
10:58:53.0075 5684 volsnap - ok
10:58:53.0109 5684 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
10:58:53.0170 5684 vpcbus - ok
10:58:53.0227 5684 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
10:58:53.0255 5684 vpcnfltr - ok
10:58:53.0292 5684 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
10:58:53.0359 5684 vpcusb - ok
10:58:53.0398 5684 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
10:58:53.0414 5684 vpcvmm - ok
10:58:53.0458 5684 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
10:58:53.0492 5684 vsmraid - ok
10:58:53.0513 5684 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
10:58:53.0543 5684 vwifibus - ok
10:58:53.0596 5684 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
10:58:53.0697 5684 vwififlt - ok
10:58:53.0721 5684 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
10:58:53.0755 5684 WacomPen - ok
10:58:53.0844 5684 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
10:58:53.0936 5684 WANARP - ok
10:58:53.0967 5684 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
10:58:54.0001 5684 Wanarpv6 - ok
10:58:54.0034 5684 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
10:58:54.0046 5684 Wd - ok
10:58:54.0070 5684 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
10:58:54.0096 5684 Wdf01000 - ok
10:58:54.0138 5684 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
10:58:54.0191 5684 WfpLwf - ok
10:58:54.0200 5684 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
10:58:54.0227 5684 WIMMount - ok
10:58:54.0257 5684 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
10:58:54.0310 5684 WmiAcpi - ok
10:58:54.0335 5684 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
10:58:54.0387 5684 ws2ifsl - ok
10:58:54.0427 5684 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
10:58:54.0470 5684 WSDPrintDevice - ok
10:58:54.0498 5684 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
10:58:54.0586 5684 WudfPf - ok
10:58:54.0635 5684 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:58:54.0713 5684 WUDFRd - ok
10:58:54.0765 5684 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
10:58:54.0798 5684 yukonw7 - ok
10:58:54.0859 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
10:58:54.0949 5684 \Device\Harddisk5\DR5 - ok
10:58:54.0962 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
10:58:55.0072 5684 \Device\Harddisk6\DR6 - ok
10:58:55.0076 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:58:55.0149 5684 \Device\Harddisk0\DR0 - ok
10:58:55.0154 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk1\DR1
10:58:55.0154 5684 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
10:58:55.0154 5684 \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a (0)
10:58:55.0324 5684 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
10:58:56.0340 5684 \Device\Harddisk2\DR2 - ok
10:58:56.0344 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk4\DR4
10:58:56.0344 5684 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - infected
10:58:56.0344 5684 \Device\Harddisk4\DR4 - detected Rootkit.Boot.Wistler.a (0)
10:58:56.0390 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk3\DR3
10:58:56.0391 5684 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - infected
10:58:56.0391 5684 \Device\Harddisk3\DR3 - detected Rootkit.Boot.Wistler.a (0)
10:58:56.0535 5684 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
10:58:56.0536 5684 \Device\Harddisk5\DR5\Partition0 - ok
10:58:56.0539 5684 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
10:58:56.0540 5684 \Device\Harddisk6\DR6\Partition0 - ok
10:58:56.0546 5684 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
10:58:56.0546 5684 \Device\Harddisk0\DR0\Partition0 - ok
10:58:56.0563 5684 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
10:58:56.0564 5684 \Device\Harddisk0\DR0\Partition1 - ok
10:58:56.0566 5684 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
10:58:56.0567 5684 \Device\Harddisk1\DR1\Partition0 - ok
10:58:56.0581 5684 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
10:58:56.0582 5684 \Device\Harddisk2\DR2\Partition0 - ok
10:58:56.0596 5684 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
10:58:56.0623 5684 \Device\Harddisk2\DR2\Partition1 - ok
10:58:56.0646 5684 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
10:58:56.0659 5684 \Device\Harddisk2\DR2\Partition2 - ok
10:58:56.0663 5684 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
10:58:56.0663 5684 \Device\Harddisk4\DR4\Partition0 - ok
10:58:56.0737 5684 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
10:58:56.0739 5684 \Device\Harddisk3\DR3\Partition0 - ok
10:58:56.0742 5684 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
10:58:56.0743 5684 \Device\Harddisk3\DR3\Partition1 - ok
10:58:56.0743 5684 ============================================================
10:58:56.0743 5684 Scan finished
10:58:56.0743 5684 ============================================================
10:58:56.0776 5676 Detected object count: 3
10:58:56.0776 5676 Actual detected object count: 3
10:59:33.0453 5676 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0454 5676 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
10:59:33.0455 5676 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0455 5676 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
10:59:33.0456 5676 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0456 5676 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
11:00:18.0172 5548 Deinitialize success
10:57:36.0430 5556 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
10:57:37.0018 5556 ============================================================
10:57:37.0018 5556 Current date / time: 2012/01/08 10:57:37.0018
10:57:37.0018 5556 SystemInfo:
10:57:37.0018 5556
10:57:37.0018 5556 OS Version: 6.1.7600 ServicePack: 0.0
10:57:37.0018 5556 Product type: Workstation
10:57:37.0018 5556 ComputerName: COHENW7
10:57:37.0018 5556 UserName: Jakub
10:57:37.0018 5556 Windows directory: C:\Windows
10:57:37.0018 5556 System windows directory: C:\Windows
10:57:37.0018 5556 Running under WOW64
10:57:37.0018 5556 Processor architecture: Intel x64
10:57:37.0018 5556 Number of processors: 4
10:57:37.0018 5556 Page size: 0x1000
10:57:37.0018 5556 Boot type: Normal boot
10:57:37.0018 5556 ============================================================
10:57:38.0995 5556 Initialize success
10:57:59.0840 5684 ============================================================
10:57:59.0840 5684 Scan started
10:57:59.0840 5684 Mode: Manual; SigCheck; TDLFS;
10:57:59.0840 5684 ============================================================
10:58:01.0485 5684 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
10:58:01.0602 5684 1394ohci - ok
10:58:01.0635 5684 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
10:58:01.0652 5684 ACPI - ok
10:58:01.0811 5684 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
10:58:02.0263 5684 AcpiPmi - ok
10:58:02.0452 5684 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
10:58:02.0523 5684 adp94xx - ok
10:58:02.0640 5684 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
10:58:02.0730 5684 adpahci - ok
10:58:02.0808 5684 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
10:58:02.0857 5684 adpu320 - ok
10:58:03.0102 5684 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
10:58:03.0309 5684 AFD - ok
10:58:03.0465 5684 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
10:58:03.0551 5684 agp440 - ok
10:58:03.0780 5684 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
10:58:03.0849 5684 aliide - ok
10:58:03.0980 5684 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
10:58:04.0057 5684 amdide - ok
10:58:04.0254 5684 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
10:58:04.0374 5684 AmdK8 - ok
10:58:04.0487 5684 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
10:58:04.0574 5684 AmdPPM - ok
10:58:04.0793 5684 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
10:58:04.0860 5684 amdsata - ok
10:58:05.0017 5684 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
10:58:05.0075 5684 amdsbs - ok
10:58:05.0180 5684 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
10:58:05.0221 5684 amdxata - ok
10:58:05.0529 5684 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
10:58:06.0113 5684 AppID - ok
10:58:06.0321 5684 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
10:58:06.0352 5684 arc - ok
10:58:06.0463 5684 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
10:58:06.0496 5684 arcsas - ok
10:58:06.0634 5684 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
10:58:07.0805 5684 AsyncMac - ok
10:58:08.0176 5684 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
10:58:08.0186 5684 atapi - ok
10:58:09.0261 5684 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
10:58:09.0833 5684 atikmdag - ok
10:58:10.0383 5684 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
10:58:10.0568 5684 b06bdrv - ok
10:58:10.0594 5684 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
10:58:10.0660 5684 b57nd60a - ok
10:58:10.0717 5684 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
10:58:10.0778 5684 Beep - ok
10:58:10.0926 5684 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
10:58:11.0023 5684 blbdrive - ok
10:58:11.0195 5684 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
10:58:11.0451 5684 bowser - ok
10:58:11.0565 5684 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:58:11.0614 5684 BrFiltLo - ok
10:58:11.0664 5684 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:58:11.0691 5684 BrFiltUp - ok
10:58:11.0789 5684 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
10:58:11.0947 5684 Brserid - ok
10:58:12.0038 5684 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
10:58:12.0125 5684 BrSerWdm - ok
10:58:12.0278 5684 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:58:12.0397 5684 BrUsbMdm - ok
10:58:12.0478 5684 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
10:58:12.0517 5684 BrUsbSer - ok
10:58:12.0752 5684 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
10:58:12.0826 5684 BTHMODEM - ok
10:58:12.0891 5684 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
10:58:12.0996 5684 cdfs - ok
10:58:13.0156 5684 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
10:58:13.0224 5684 cdrom - ok
10:58:13.0269 5684 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
10:58:13.0308 5684 circlass - ok
10:58:13.0338 5684 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
10:58:13.0386 5684 CLFS - ok
10:58:13.0442 5684 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
10:58:13.0475 5684 CmBatt - ok
10:58:13.0483 5684 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
10:58:13.0509 5684 cmdide - ok
10:58:13.0551 5684 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
10:58:13.0629 5684 CNG - ok
10:58:13.0648 5684 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
10:58:13.0671 5684 Compbatt - ok
10:58:13.0748 5684 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
10:58:13.0787 5684 CompositeBus - ok
10:58:13.0811 5684 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
10:58:13.0823 5684 crcdisk - ok
10:58:13.0901 5684 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
10:58:14.0014 5684 CSC - ok
10:58:14.0047 5684 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
10:58:14.0076 5684 CVirtA - ok
10:58:14.0156 5684 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
10:58:14.0170 5684 CVPNDRVA - ok
10:58:14.0262 5684 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
10:58:14.0291 5684 DELTAII - ok
10:58:14.0344 5684 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
10:58:14.0499 5684 DfsC - ok
10:58:14.0848 5684 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
10:58:15.0056 5684 discache - ok
10:58:15.0363 5684 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
10:58:15.0392 5684 Disk - ok
10:58:15.0724 5684 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
10:58:15.0777 5684 DNE - ok
10:58:16.0223 5684 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
10:58:16.0325 5684 drmkaud - ok
10:58:17.0084 5684 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
10:58:17.0249 5684 DXGKrnl - ok
10:58:17.0659 5684 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
10:58:17.0737 5684 eamon - ok
10:58:18.0850 5684 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
10:58:19.0054 5684 ebdrv - ok
10:58:19.0304 5684 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
10:58:19.0337 5684 ehdrv - ok
10:58:19.0594 5684 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
10:58:19.0620 5684 elxstor - ok
10:58:19.0657 5684 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
10:58:19.0669 5684 epfwwfpr - ok
10:58:19.0704 5684 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
10:58:19.0774 5684 ErrDev - ok
10:58:19.0906 5684 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
10:58:20.0033 5684 exfat - ok
10:58:20.0057 5684 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
10:58:20.0126 5684 fastfat - ok
10:58:20.0168 5684 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
10:58:20.0242 5684 fdc - ok
10:58:20.0334 5684 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
10:58:20.0362 5684 FileInfo - ok
10:58:20.0376 5684 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
10:58:20.0467 5684 Filetrace - ok
10:58:20.0491 5684 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
10:58:20.0533 5684 flpydisk - ok
10:58:20.0581 5684 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
10:58:20.0613 5684 FltMgr - ok
10:58:20.0632 5684 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
10:58:20.0658 5684 FsDepends - ok
10:58:20.0681 5684 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
10:58:20.0707 5684 Fs_Rec - ok
10:58:20.0742 5684 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
10:58:20.0758 5684 fvevol - ok
10:58:20.0789 5684 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:58:20.0846 5684 gagp30kx - ok
10:58:20.0886 5684 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
10:58:20.0907 5684 grmnusb - ok
10:58:20.0952 5684 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
10:58:20.0975 5684 hcmon - ok
10:58:21.0006 5684 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
10:58:21.0092 5684 hcw85cir - ok
10:58:21.0316 5684 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
10:58:22.0412 5684 HdAudAddService - ok
10:58:22.0463 5684 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
10:58:22.0509 5684 HDAudBus - ok
10:58:22.0527 5684 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
10:58:22.0584 5684 HidBatt - ok
10:58:22.0593 5684 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
10:58:22.0638 5684 HidBth - ok
10:58:22.0657 5684 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
10:58:22.0936 5684 HidIr - ok
10:58:23.0023 5684 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
10:58:23.0051 5684 HidUsb - ok
10:58:23.0097 5684 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
10:58:23.0124 5684 HpSAMD - ok
10:58:23.0162 5684 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
10:58:23.0232 5684 HTTP - ok
10:58:23.0276 5684 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
10:58:23.0315 5684 hwpolicy - ok
10:58:23.0396 5684 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
10:58:23.0427 5684 i8042prt - ok
10:58:23.0739 5684 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
10:58:23.0833 5684 iaStorV - ok
10:58:23.0935 5684 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
10:58:23.0947 5684 iirsp - ok
10:58:24.0026 5684 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
10:58:24.0037 5684 intelide - ok
10:58:24.0183 5684 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
10:58:24.0219 5684 intelppm - ok
10:58:24.0261 5684 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:58:24.0334 5684 IpFilterDriver - ok
10:58:24.0374 5684 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
10:58:24.0410 5684 IPMIDRV - ok
10:58:24.0513 5684 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
10:58:24.0585 5684 IPNAT - ok
10:58:24.0630 5684 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
10:58:24.0679 5684 IRENUM - ok
10:58:24.0696 5684 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
10:58:24.0722 5684 isapnp - ok
10:58:24.0764 5684 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
10:58:33.0908 5684 iScsiPrt - ok
10:58:33.0961 5684 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
10:58:33.0973 5684 kbdclass - ok
10:58:34.0025 5684 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
10:58:34.0051 5684 kbdhid - ok
10:58:34.0092 5684 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
10:58:34.0104 5684 KSecDD - ok
10:58:34.0156 5684 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
10:58:34.0168 5684 KSecPkg - ok
10:58:34.0203 5684 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
10:58:34.0262 5684 ksthunk - ok
10:58:34.0312 5684 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
10:58:34.0381 5684 lltdio - ok
10:58:34.0431 5684 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
10:58:34.0460 5684 LSI_FC - ok
10:58:34.0476 5684 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
10:58:34.0504 5684 LSI_SAS - ok
10:58:34.0531 5684 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:58:34.0560 5684 LSI_SAS2 - ok
10:58:34.0616 5684 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:58:34.0644 5684 LSI_SCSI - ok
10:58:34.0675 5684 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
10:58:34.0722 5684 luafv - ok
10:58:34.0781 5684 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
10:58:34.0831 5684 MarvinBus - ok
10:58:34.0840 5684 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
10:58:34.0887 5684 megasas - ok
10:58:34.0901 5684 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
10:58:34.0940 5684 MegaSR - ok
10:58:34.0969 5684 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
10:58:35.0034 5684 Modem - ok
10:58:35.0057 5684 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
10:58:35.0080 5684 monitor - ok
10:58:35.0102 5684 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
10:58:35.0115 5684 mouclass - ok
10:58:35.0131 5684 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
10:58:35.0164 5684 mouhid - ok
10:58:35.0186 5684 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
10:58:35.0213 5684 mountmgr - ok
10:58:35.0230 5684 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
10:58:35.0248 5684 mpio - ok
10:58:35.0270 5684 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
10:58:35.0341 5684 mpsdrv - ok
10:58:35.0377 5684 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
10:58:35.0408 5684 MRxDAV - ok
10:58:35.0465 5684 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:58:35.0532 5684 mrxsmb - ok
10:58:35.0571 5684 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:58:35.0589 5684 mrxsmb10 - ok
10:58:35.0621 5684 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:58:35.0680 5684 mrxsmb20 - ok
10:58:35.0724 5684 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
10:58:35.0765 5684 msahci - ok
10:58:35.0788 5684 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
10:58:35.0816 5684 msdsm - ok
10:58:35.0837 5684 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
10:58:35.0872 5684 Msfs - ok
10:58:35.0880 5684 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
10:58:35.0939 5684 mshidkmdf - ok
10:58:35.0947 5684 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
10:58:35.0974 5684 msisadrv - ok
10:58:36.0000 5684 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
10:58:36.0044 5684 MSKSSRV - ok
10:58:36.0060 5684 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
10:58:36.0108 5684 MSPCLOCK - ok
10:58:36.0116 5684 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
10:58:36.0177 5684 MSPQM - ok
10:58:36.0203 5684 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
10:58:36.0230 5684 MsRPC - ok
10:58:36.0253 5684 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
10:58:36.0266 5684 mssmbios - ok
10:58:36.0406 5684 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
10:58:36.0447 5684 MSTEE - ok
10:58:36.0454 5684 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
10:58:36.0472 5684 MTConfig - ok
10:58:36.0525 5684 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
10:58:36.0578 5684 MTsensor - ok
10:58:36.0593 5684 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
10:58:36.0619 5684 Mup - ok
10:58:36.0661 5684 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
10:58:36.0670 5684 mv91cons - ok
10:58:36.0713 5684 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
10:58:36.0723 5684 mv91xx - ok
10:58:36.0789 5684 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
10:58:36.0860 5684 NativeWifiP - ok
10:58:36.0905 5684 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
10:58:36.0934 5684 NDIS - ok
10:58:36.0948 5684 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
10:58:36.0997 5684 NdisCap - ok
10:58:37.0020 5684 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
10:58:37.0067 5684 NdisTapi - ok
10:58:37.0096 5684 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
10:58:37.0144 5684 Ndisuio - ok
10:58:37.0161 5684 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
10:58:37.0221 5684 NdisWan - ok
10:58:37.0246 5684 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
10:58:37.0307 5684 NDProxy - ok
10:58:37.0323 5684 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
10:58:37.0372 5684 NetBIOS - ok
10:58:37.0393 5684 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
10:58:37.0449 5684 NetBT - ok
10:58:37.0486 5684 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
10:58:37.0527 5684 nfrd960 - ok
10:58:37.0549 5684 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
10:58:37.0605 5684 Npfs - ok
10:58:37.0630 5684 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
10:58:37.0688 5684 nsiproxy - ok
10:58:37.0743 5684 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
10:58:37.0816 5684 Ntfs - ok
10:58:37.0842 5684 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
10:58:37.0916 5684 Null - ok
10:58:37.0964 5684 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
10:58:37.0992 5684 nvraid - ok
10:58:38.0020 5684 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
10:58:38.0071 5684 nvstor - ok
10:58:38.0088 5684 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
10:58:38.0116 5684 nv_agp - ok
10:58:38.0138 5684 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
10:58:38.0176 5684 ohci1394 - ok
10:58:38.0239 5684 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
10:58:38.0268 5684 Parport - ok
10:58:38.0290 5684 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
10:58:38.0317 5684 partmgr - ok
10:58:38.0353 5684 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
10:58:38.0382 5684 pci - ok
10:58:38.0397 5684 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
10:58:38.0432 5684 pciide - ok
10:58:38.0497 5684 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
10:58:38.0526 5684 pcmcia - ok
10:58:38.0541 5684 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
10:58:38.0567 5684 pcw - ok
10:58:38.0592 5684 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
10:58:38.0652 5684 PEAUTH - ok
10:58:38.0704 5684 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
10:58:38.0766 5684 PptpMiniport - ok
10:58:38.0792 5684 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
10:58:38.0846 5684 Processor - ok
10:58:38.0896 5684 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
10:58:38.0937 5684 Psched - ok
10:58:39.0008 5684 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
10:58:39.0056 5684 ql2300 - ok
10:58:39.0076 5684 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
10:58:39.0090 5684 ql40xx - ok
10:58:39.0120 5684 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
10:58:39.0228 5684 QWAVEdrv - ok
10:58:39.0501 5684 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
10:58:39.0603 5684 RasAcd - ok
10:58:39.0695 5684 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:58:39.0737 5684 RasAgileVpn - ok
10:58:39.0775 5684 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:58:43.0133 5684 Rasl2tp - ok
10:58:43.0252 5684 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
10:58:43.0293 5684 RasPppoe - ok
10:58:43.0309 5684 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
10:58:43.0367 5684 RasSstp - ok
10:58:43.0393 5684 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
10:58:43.0449 5684 rdbss - ok
10:58:43.0477 5684 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
10:58:43.0529 5684 rdpbus - ok
10:58:43.0549 5684 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:58:43.0585 5684 RDPCDD - ok
10:58:43.0626 5684 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
10:58:43.0828 5684 RDPDR - ok
10:58:44.0048 5684 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
10:58:44.0136 5684 RDPENCDD - ok
10:58:44.0173 5684 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
10:58:44.0208 5684 RDPREFMP - ok
10:58:44.0402 5684 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
10:58:44.0540 5684 RDPWD - ok
10:58:44.0633 5684 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
10:58:44.0752 5684 rdyboost - ok
10:58:45.0223 5684 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
10:58:45.0431 5684 RimUsb - ok
10:58:45.0857 5684 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
10:58:46.0048 5684 RsFx0103 - ok
10:58:46.0452 5684 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
10:58:46.0526 5684 rspndr - ok
10:58:46.0750 5684 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
10:58:46.0897 5684 RTL8167 - ok
10:58:47.0185 5684 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
10:58:47.0250 5684 RTL8187 - ok
10:58:47.0324 5684 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
10:58:47.0495 5684 s3cap - ok
10:58:47.0536 5684 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
10:58:47.0564 5684 sbp2port - ok
10:58:47.0637 5684 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
10:58:47.0677 5684 SCDEmu - ok
10:58:47.0701 5684 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
10:58:47.0763 5684 scfilter - ok
10:58:47.0815 5684 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
10:58:47.0880 5684 secdrv - ok
10:58:47.0940 5684 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
10:58:47.0993 5684 Serenum - ok
10:58:48.0109 5684 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
10:58:48.0219 5684 Serial - ok
10:58:48.0256 5684 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
10:58:48.0307 5684 sermouse - ok
10:58:48.0451 5684 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
10:58:48.0516 5684 sffdisk - ok
10:58:48.0591 5684 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
10:58:48.0634 5684 sffp_mmc - ok
10:58:48.0653 5684 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
10:58:48.0669 5684 sffp_sd - ok
10:58:48.0680 5684 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
10:58:48.0725 5684 sfloppy - ok
10:58:48.0758 5684 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:58:48.0801 5684 SiSRaid2 - ok
10:58:48.0825 5684 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
10:58:48.0888 5684 SiSRaid4 - ok
10:58:48.0933 5684 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
10:58:49.0000 5684 Smb - ok
10:58:49.0051 5684 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
10:58:49.0076 5684 spldr - ok
10:58:49.0136 5684 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
10:58:49.0197 5684 srv - ok
10:58:49.0273 5684 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
10:58:49.0315 5684 srv2 - ok
10:58:49.0344 5684 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
10:58:49.0371 5684 srvnet - ok
10:58:49.0404 5684 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
10:58:49.0424 5684 stexstor - ok
10:58:49.0457 5684 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
10:58:49.0470 5684 storflt - ok
10:58:49.0490 5684 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
10:58:49.0516 5684 storvsc - ok
10:58:49.0540 5684 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
10:58:49.0572 5684 swenum - ok
10:58:49.0652 5684 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
10:58:49.0714 5684 Tcpip - ok
10:58:49.0781 5684 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
10:58:49.0819 5684 TCPIP6 - ok
10:58:49.0844 5684 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
10:58:49.0880 5684 tcpipreg - ok
10:58:49.0940 5684 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
10:58:50.0005 5684 TDPIPE - ok
10:58:50.0014 5684 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
10:58:50.0080 5684 TDTCP - ok
10:58:50.0121 5684 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
10:58:50.0223 5684 tdx - ok
10:58:50.0255 5684 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
10:58:50.0276 5684 TermDD - ok
10:58:50.0372 5684 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
10:58:50.0389 5684 truecrypt - ok
10:58:50.0428 5684 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:58:50.0475 5684 tssecsrv - ok
10:58:50.0512 5684 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
10:58:50.0568 5684 tunnel - ok
10:58:50.0579 5684 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
10:58:50.0606 5684 uagp35 - ok
10:58:50.0643 5684 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
10:58:50.0706 5684 udfs - ok
10:58:50.0752 5684 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
10:58:50.0782 5684 uliagpkx - ok
10:58:50.0807 5684 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
10:58:50.0846 5684 umbus - ok
10:58:50.0859 5684 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
10:58:50.0897 5684 UmPass - ok
10:58:50.0936 5684 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
10:58:50.0997 5684 usbccgp - ok
10:58:51.0010 5684 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
10:58:51.0033 5684 usbcir - ok
10:58:51.0060 5684 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
10:58:51.0112 5684 usbehci - ok
10:58:51.0145 5684 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
10:58:51.0186 5684 usbhub - ok
10:58:51.0217 5684 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
10:58:51.0283 5684 usbohci - ok
10:58:51.0307 5684 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
10:58:51.0349 5684 usbprint - ok
10:58:51.0381 5684 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:58:51.0456 5684 USBSTOR - ok
10:58:51.0492 5684 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
10:58:51.0520 5684 usbuhci - ok
10:58:51.0563 5684 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
10:58:51.0604 5684 vdrvroot - ok
10:58:51.0630 5684 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
10:58:51.0647 5684 vga - ok
10:58:51.0673 5684 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
10:58:51.0740 5684 VgaSave - ok
10:58:51.0781 5684 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
10:58:51.0814 5684 vhdmp - ok
10:58:51.0828 5684 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
10:58:51.0855 5684 viaide - ok
10:58:51.0926 5684 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
10:58:51.0993 5684 vmbus - ok
10:58:52.0025 5684 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
10:58:52.0063 5684 VMBusHID - ok
10:58:52.0133 5684 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
10:58:52.0224 5684 vmci - ok
10:58:52.0248 5684 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
10:58:52.0262 5684 VMnetAdapter - ok
10:58:52.0308 5684 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
10:58:52.0346 5684 VMnetBridge - ok
10:58:52.0450 5684 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
10:58:52.0464 5684 VMnetuserif - ok
10:58:52.0530 5684 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
10:58:52.0540 5684 vmx86 - ok
10:58:52.0560 5684 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
10:58:52.0602 5684 volmgr - ok
10:58:52.0723 5684 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
10:58:52.0809 5684 volmgrx - ok
10:58:53.0009 5684 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
10:58:53.0075 5684 volsnap - ok
10:58:53.0109 5684 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
10:58:53.0170 5684 vpcbus - ok
10:58:53.0227 5684 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
10:58:53.0255 5684 vpcnfltr - ok
10:58:53.0292 5684 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
10:58:53.0359 5684 vpcusb - ok
10:58:53.0398 5684 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
10:58:53.0414 5684 vpcvmm - ok
10:58:53.0458 5684 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
10:58:53.0492 5684 vsmraid - ok
10:58:53.0513 5684 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
10:58:53.0543 5684 vwifibus - ok
10:58:53.0596 5684 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
10:58:53.0697 5684 vwififlt - ok
10:58:53.0721 5684 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
10:58:53.0755 5684 WacomPen - ok
10:58:53.0844 5684 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
10:58:53.0936 5684 WANARP - ok
10:58:53.0967 5684 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
10:58:54.0001 5684 Wanarpv6 - ok
10:58:54.0034 5684 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
10:58:54.0046 5684 Wd - ok
10:58:54.0070 5684 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
10:58:54.0096 5684 Wdf01000 - ok
10:58:54.0138 5684 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
10:58:54.0191 5684 WfpLwf - ok
10:58:54.0200 5684 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
10:58:54.0227 5684 WIMMount - ok
10:58:54.0257 5684 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
10:58:54.0310 5684 WmiAcpi - ok
10:58:54.0335 5684 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
10:58:54.0387 5684 ws2ifsl - ok
10:58:54.0427 5684 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
10:58:54.0470 5684 WSDPrintDevice - ok
10:58:54.0498 5684 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
10:58:54.0586 5684 WudfPf - ok
10:58:54.0635 5684 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:58:54.0713 5684 WUDFRd - ok
10:58:54.0765 5684 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
10:58:54.0798 5684 yukonw7 - ok
10:58:54.0859 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
10:58:54.0949 5684 \Device\Harddisk5\DR5 - ok
10:58:54.0962 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
10:58:55.0072 5684 \Device\Harddisk6\DR6 - ok
10:58:55.0076 5684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:58:55.0149 5684 \Device\Harddisk0\DR0 - ok
10:58:55.0154 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk1\DR1
10:58:55.0154 5684 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
10:58:55.0154 5684 \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a (0)
10:58:55.0324 5684 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
10:58:56.0340 5684 \Device\Harddisk2\DR2 - ok
10:58:56.0344 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk4\DR4
10:58:56.0344 5684 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - infected
10:58:56.0344 5684 \Device\Harddisk4\DR4 - detected Rootkit.Boot.Wistler.a (0)
10:58:56.0390 5684 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk3\DR3
10:58:56.0391 5684 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - infected
10:58:56.0391 5684 \Device\Harddisk3\DR3 - detected Rootkit.Boot.Wistler.a (0)
10:58:56.0535 5684 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
10:58:56.0536 5684 \Device\Harddisk5\DR5\Partition0 - ok
10:58:56.0539 5684 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
10:58:56.0540 5684 \Device\Harddisk6\DR6\Partition0 - ok
10:58:56.0546 5684 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
10:58:56.0546 5684 \Device\Harddisk0\DR0\Partition0 - ok
10:58:56.0563 5684 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
10:58:56.0564 5684 \Device\Harddisk0\DR0\Partition1 - ok
10:58:56.0566 5684 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
10:58:56.0567 5684 \Device\Harddisk1\DR1\Partition0 - ok
10:58:56.0581 5684 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
10:58:56.0582 5684 \Device\Harddisk2\DR2\Partition0 - ok
10:58:56.0596 5684 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
10:58:56.0623 5684 \Device\Harddisk2\DR2\Partition1 - ok
10:58:56.0646 5684 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
10:58:56.0659 5684 \Device\Harddisk2\DR2\Partition2 - ok
10:58:56.0663 5684 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
10:58:56.0663 5684 \Device\Harddisk4\DR4\Partition0 - ok
10:58:56.0737 5684 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
10:58:56.0739 5684 \Device\Harddisk3\DR3\Partition0 - ok
10:58:56.0742 5684 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
10:58:56.0743 5684 \Device\Harddisk3\DR3\Partition1 - ok
10:58:56.0743 5684 ============================================================
10:58:56.0743 5684 Scan finished
10:58:56.0743 5684 ============================================================
10:58:56.0776 5676 Detected object count: 3
10:58:56.0776 5676 Actual detected object count: 3
10:59:33.0453 5676 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0454 5676 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
10:59:33.0455 5676 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0455 5676 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
10:59:33.0456 5676 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - skipped by user
10:59:33.0456 5676 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
11:00:18.0172 5548 Deinitialize success
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
RKreport[1]:
RogueKiller V6.2.2 [12/31/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Jakub [Admin rights]
Mode: Remove -- Date : 01/08/2012 11:05:01
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 7633887b291907a284fbb7451c866db6
[BSP] f0e7e370818e8ac90042ffb8b531804c : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 524287 Mo
1 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 1023999165 | Size: 475914 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] 7f905702b103936fd73fdc1064e6028d
[BSP] c84c99b363412d0cebd7760df9edb6c4 : Whistler MBR Code!
Partition table:
0 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 1000202 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RKreport[2]:
RogueKiller V6.2.2 [12/31/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Jakub [Admin rights]
Mode: HOSTSFix -- Date : 01/08/2012 11:05:39
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Dekuji.
RogueKiller V6.2.2 [12/31/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Jakub [Admin rights]
Mode: Remove -- Date : 01/08/2012 11:05:01
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 7633887b291907a284fbb7451c866db6
[BSP] f0e7e370818e8ac90042ffb8b531804c : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 63 | Size: 524287 Mo
1 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 1023999165 | Size: 475914 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] 7f905702b103936fd73fdc1064e6028d
[BSP] c84c99b363412d0cebd7760df9edb6c4 : Whistler MBR Code!
Partition table:
0 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 1000202 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RKreport[2]:
RogueKiller V6.2.2 [12/31/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Jakub [Admin rights]
Mode: HOSTSFix -- Date : 01/08/2012 11:05:39
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Dekuji.
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Znovu spustte TDSSKiller a kde bude moznost Cure, tak ji ponechte - bude zrejme pozadovan restart, po restartu bude log, ten rad uvidim
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Ted si nejsem jist zda chcete log, ktery byl vytvoren pri leceni a nebo mam zpustit tdsskiller po nastartovani a dat sem log?
Log vytvoreny pri leceni:
11:37:41.0292 5352 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
11:37:41.0870 5352 ============================================================
11:37:41.0870 5352 Current date / time: 2012/01/08 11:37:41.0870
11:37:41.0870 5352 SystemInfo:
11:37:41.0870 5352
11:37:41.0870 5352 OS Version: 6.1.7600 ServicePack: 0.0
11:37:41.0870 5352 Product type: Workstation
11:37:41.0870 5352 ComputerName: COHENW7
11:37:41.0870 5352 UserName: Jakub
11:37:41.0870 5352 Windows directory: C:\Windows
11:37:41.0870 5352 System windows directory: C:\Windows
11:37:41.0870 5352 Running under WOW64
11:37:41.0870 5352 Processor architecture: Intel x64
11:37:41.0870 5352 Number of processors: 4
11:37:41.0870 5352 Page size: 0x1000
11:37:41.0870 5352 Boot type: Normal boot
11:37:41.0870 5352 ============================================================
11:37:42.0759 5352 Initialize success
11:38:12.0826 4428 ============================================================
11:38:12.0826 4428 Scan started
11:38:12.0826 4428 Mode: Manual; SigCheck; TDLFS;
11:38:12.0826 4428 ============================================================
11:38:14.0106 4428 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
11:38:14.0226 4428 1394ohci - ok
11:38:14.0256 4428 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
11:38:14.0276 4428 ACPI - ok
11:38:14.0286 4428 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
11:38:14.0346 4428 AcpiPmi - ok
11:38:14.0376 4428 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:38:14.0386 4428 adp94xx - ok
11:38:14.0416 4428 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:38:14.0466 4428 adpahci - ok
11:38:14.0486 4428 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:38:14.0506 4428 adpu320 - ok
11:38:14.0556 4428 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
11:38:14.0616 4428 AFD - ok
11:38:14.0636 4428 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
11:38:14.0646 4428 agp440 - ok
11:38:14.0786 4428 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
11:38:14.0836 4428 aliide - ok
11:38:14.0916 4428 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
11:38:14.0956 4428 amdide - ok
11:38:15.0056 4428 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:38:15.0096 4428 AmdK8 - ok
11:38:15.0206 4428 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:38:15.0286 4428 AmdPPM - ok
11:38:15.0406 4428 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
11:38:15.0416 4428 amdsata - ok
11:38:15.0516 4428 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:38:15.0556 4428 amdsbs - ok
11:38:15.0646 4428 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
11:38:15.0676 4428 amdxata - ok
11:38:15.0746 4428 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
11:38:15.0796 4428 AppID - ok
11:38:15.0826 4428 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:38:15.0856 4428 arc - ok
11:38:15.0866 4428 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:38:15.0876 4428 arcsas - ok
11:38:15.0926 4428 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:38:16.0036 4428 AsyncMac - ok
11:38:16.0046 4428 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
11:38:16.0056 4428 atapi - ok
11:38:16.0186 4428 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
11:38:16.0326 4428 atikmdag - ok
11:38:16.0376 4428 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:38:16.0406 4428 b06bdrv - ok
11:38:16.0436 4428 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:38:16.0476 4428 b57nd60a - ok
11:38:16.0506 4428 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:38:16.0546 4428 Beep - ok
11:38:16.0586 4428 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:38:16.0626 4428 blbdrive - ok
11:38:16.0666 4428 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
11:38:16.0726 4428 bowser - ok
11:38:16.0736 4428 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:38:16.0756 4428 BrFiltLo - ok
11:38:16.0766 4428 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:38:16.0776 4428 BrFiltUp - ok
11:38:16.0806 4428 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:38:16.0856 4428 Brserid - ok
11:38:16.0856 4428 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:38:16.0896 4428 BrSerWdm - ok
11:38:16.0906 4428 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:38:16.0946 4428 BrUsbMdm - ok
11:38:16.0956 4428 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:38:16.0966 4428 BrUsbSer - ok
11:38:16.0976 4428 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:38:17.0006 4428 BTHMODEM - ok
11:38:17.0036 4428 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:38:17.0076 4428 cdfs - ok
11:38:17.0096 4428 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
11:38:17.0146 4428 cdrom - ok
11:38:17.0156 4428 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:38:17.0166 4428 circlass - ok
11:38:17.0196 4428 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:38:17.0246 4428 CLFS - ok
11:38:17.0276 4428 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:38:17.0306 4428 CmBatt - ok
11:38:17.0306 4428 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
11:38:17.0336 4428 cmdide - ok
11:38:17.0356 4428 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
11:38:17.0416 4428 CNG - ok
11:38:17.0436 4428 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:38:17.0446 4428 Compbatt - ok
11:38:17.0476 4428 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
11:38:17.0506 4428 CompositeBus - ok
11:38:17.0516 4428 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:38:17.0526 4428 crcdisk - ok
11:38:17.0566 4428 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
11:38:17.0616 4428 CSC - ok
11:38:17.0646 4428 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
11:38:17.0676 4428 CVirtA - ok
11:38:17.0706 4428 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
11:38:17.0726 4428 CVPNDRVA - ok
11:38:17.0776 4428 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
11:38:17.0806 4428 DELTAII - ok
11:38:17.0836 4428 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
11:38:17.0866 4428 DfsC - ok
11:38:17.0886 4428 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:38:17.0966 4428 discache - ok
11:38:18.0006 4428 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:38:18.0016 4428 Disk - ok
11:38:18.0026 4428 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
11:38:18.0046 4428 DNE - ok
11:38:18.0086 4428 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:38:18.0106 4428 drmkaud - ok
11:38:18.0166 4428 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
11:38:18.0196 4428 DXGKrnl - ok
11:38:18.0236 4428 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
11:38:18.0256 4428 eamon - ok
11:38:18.0326 4428 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:38:18.0406 4428 ebdrv - ok
11:38:18.0436 4428 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
11:38:18.0446 4428 ehdrv - ok
11:38:18.0476 4428 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:38:18.0496 4428 elxstor - ok
11:38:18.0516 4428 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
11:38:18.0526 4428 epfwwfpr - ok
11:38:18.0536 4428 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
11:38:18.0576 4428 ErrDev - ok
11:38:18.0586 4428 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:38:18.0656 4428 exfat - ok
11:38:18.0676 4428 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:38:18.0746 4428 fastfat - ok
11:38:18.0756 4428 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:38:18.0806 4428 fdc - ok
11:38:18.0826 4428 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:38:18.0856 4428 FileInfo - ok
11:38:18.0866 4428 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:38:18.0926 4428 Filetrace - ok
11:38:18.0946 4428 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:38:18.0956 4428 flpydisk - ok
11:38:18.0986 4428 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
11:38:19.0016 4428 FltMgr - ok
11:38:19.0026 4428 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:38:19.0056 4428 FsDepends - ok
11:38:19.0066 4428 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:38:19.0096 4428 Fs_Rec - ok
11:38:19.0116 4428 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:38:19.0136 4428 fvevol - ok
11:38:19.0146 4428 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:38:19.0156 4428 gagp30kx - ok
11:38:19.0196 4428 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
11:38:19.0206 4428 grmnusb - ok
11:38:19.0246 4428 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
11:38:19.0266 4428 hcmon - ok
11:38:19.0286 4428 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:38:19.0316 4428 hcw85cir - ok
11:38:19.0346 4428 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
11:38:19.0376 4428 HdAudAddService - ok
11:38:19.0406 4428 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
11:38:19.0426 4428 HDAudBus - ok
11:38:19.0436 4428 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:38:19.0496 4428 HidBatt - ok
11:38:19.0516 4428 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:38:19.0566 4428 HidBth - ok
11:38:19.0576 4428 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:38:19.0626 4428 HidIr - ok
11:38:19.0656 4428 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
11:38:19.0666 4428 HidUsb - ok
11:38:19.0696 4428 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
11:38:19.0706 4428 HpSAMD - ok
11:38:19.0756 4428 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
11:38:19.0806 4428 HTTP - ok
11:38:19.0826 4428 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
11:38:19.0836 4428 hwpolicy - ok
11:38:19.0876 4428 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
11:38:19.0906 4428 i8042prt - ok
11:38:19.0936 4428 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
11:38:19.0956 4428 iaStorV - ok
11:38:19.0976 4428 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:38:19.0986 4428 iirsp - ok
11:38:19.0996 4428 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
11:38:20.0006 4428 intelide - ok
11:38:20.0026 4428 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:38:20.0046 4428 intelppm - ok
11:38:20.0066 4428 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:38:20.0106 4428 IpFilterDriver - ok
11:38:20.0116 4428 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
11:38:20.0146 4428 IPMIDRV - ok
11:38:20.0146 4428 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:38:20.0196 4428 IPNAT - ok
11:38:20.0196 4428 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:38:20.0246 4428 IRENUM - ok
11:38:20.0256 4428 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
11:38:20.0276 4428 isapnp - ok
11:38:20.0296 4428 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
11:38:20.0316 4428 iScsiPrt - ok
11:38:20.0326 4428 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
11:38:20.0346 4428 kbdclass - ok
11:38:20.0366 4428 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
11:38:20.0386 4428 kbdhid - ok
11:38:20.0406 4428 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
11:38:20.0416 4428 KSecDD - ok
11:38:20.0446 4428 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
11:38:20.0456 4428 KSecPkg - ok
11:38:20.0476 4428 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:38:20.0526 4428 ksthunk - ok
11:38:20.0556 4428 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:38:20.0616 4428 lltdio - ok
11:38:20.0646 4428 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:38:20.0676 4428 LSI_FC - ok
11:38:20.0676 4428 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:38:20.0706 4428 LSI_SAS - ok
11:38:20.0716 4428 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:38:20.0726 4428 LSI_SAS2 - ok
11:38:20.0746 4428 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:38:20.0756 4428 LSI_SCSI - ok
11:38:20.0776 4428 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:38:20.0826 4428 luafv - ok
11:38:20.0886 4428 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
11:38:20.0926 4428 MarvinBus - ok
11:38:20.0966 4428 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:38:21.0026 4428 megasas - ok
11:38:21.0066 4428 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:38:21.0106 4428 MegaSR - ok
11:38:21.0116 4428 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:38:21.0146 4428 Modem - ok
11:38:21.0166 4428 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:38:21.0186 4428 monitor - ok
11:38:21.0196 4428 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:38:21.0206 4428 mouclass - ok
11:38:21.0226 4428 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:38:21.0256 4428 mouhid - ok
11:38:21.0276 4428 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
11:38:21.0296 4428 mountmgr - ok
11:38:21.0306 4428 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
11:38:21.0326 4428 mpio - ok
11:38:21.0346 4428 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:38:21.0406 4428 mpsdrv - ok
11:38:21.0426 4428 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
11:38:21.0456 4428 MRxDAV - ok
11:38:21.0476 4428 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:38:21.0516 4428 mrxsmb - ok
11:38:21.0556 4428 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:38:21.0576 4428 mrxsmb10 - ok
11:38:21.0606 4428 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:38:21.0636 4428 mrxsmb20 - ok
11:38:21.0656 4428 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
11:38:21.0676 4428 msahci - ok
11:38:21.0696 4428 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
11:38:21.0706 4428 msdsm - ok
11:38:21.0726 4428 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:38:21.0756 4428 Msfs - ok
11:38:21.0766 4428 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:38:21.0826 4428 mshidkmdf - ok
11:38:21.0836 4428 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
11:38:21.0856 4428 msisadrv - ok
11:38:21.0886 4428 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:38:21.0926 4428 MSKSSRV - ok
11:38:21.0936 4428 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:38:21.0986 4428 MSPCLOCK - ok
11:38:21.0996 4428 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:38:22.0036 4428 MSPQM - ok
11:38:22.0056 4428 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
11:38:22.0076 4428 MsRPC - ok
11:38:22.0096 4428 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
11:38:22.0106 4428 mssmbios - ok
11:38:22.0136 4428 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:38:22.0176 4428 MSTEE - ok
11:38:22.0186 4428 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:38:22.0206 4428 MTConfig - ok
11:38:22.0236 4428 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
11:38:22.0266 4428 MTsensor - ok
11:38:22.0296 4428 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:38:22.0316 4428 Mup - ok
11:38:22.0336 4428 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
11:38:22.0346 4428 mv91cons - ok
11:38:22.0366 4428 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
11:38:22.0376 4428 mv91xx - ok
11:38:22.0416 4428 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:38:22.0476 4428 NativeWifiP - ok
11:38:22.0516 4428 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
11:38:22.0536 4428 NDIS - ok
11:38:22.0556 4428 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:38:22.0606 4428 NdisCap - ok
11:38:22.0626 4428 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:38:22.0676 4428 NdisTapi - ok
11:38:22.0706 4428 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
11:38:22.0746 4428 Ndisuio - ok
11:38:22.0766 4428 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
11:38:22.0826 4428 NdisWan - ok
11:38:22.0846 4428 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
11:38:22.0906 4428 NDProxy - ok
11:38:22.0926 4428 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:38:22.0966 4428 NetBIOS - ok
11:38:22.0986 4428 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
11:38:23.0036 4428 NetBT - ok
11:38:23.0076 4428 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:38:23.0086 4428 nfrd960 - ok
11:38:23.0106 4428 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:38:23.0146 4428 Npfs - ok
11:38:23.0166 4428 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:38:23.0216 4428 nsiproxy - ok
11:38:23.0276 4428 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
11:38:23.0316 4428 Ntfs - ok
11:38:23.0336 4428 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:38:23.0386 4428 Null - ok
11:38:23.0416 4428 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
11:38:23.0426 4428 nvraid - ok
11:38:23.0446 4428 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
11:38:23.0456 4428 nvstor - ok
11:38:23.0476 4428 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
11:38:23.0496 4428 nv_agp - ok
11:38:23.0516 4428 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
11:38:23.0556 4428 ohci1394 - ok
11:38:23.0596 4428 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:38:23.0626 4428 Parport - ok
11:38:23.0636 4428 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
11:38:23.0666 4428 partmgr - ok
11:38:23.0696 4428 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
11:38:23.0726 4428 pci - ok
11:38:23.0726 4428 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
11:38:23.0756 4428 pciide - ok
11:38:23.0776 4428 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:38:23.0796 4428 pcmcia - ok
11:38:23.0806 4428 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:38:23.0836 4428 pcw - ok
11:38:23.0866 4428 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:38:23.0926 4428 PEAUTH - ok
11:38:23.0976 4428 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
11:38:24.0036 4428 PptpMiniport - ok
11:38:24.0056 4428 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:38:24.0106 4428 Processor - ok
11:38:24.0126 4428 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
11:38:24.0166 4428 Psched - ok
11:38:24.0216 4428 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:38:24.0256 4428 ql2300 - ok
11:38:24.0266 4428 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:38:24.0276 4428 ql40xx - ok
11:38:24.0296 4428 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:38:24.0336 4428 QWAVEdrv - ok
11:38:24.0346 4428 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:38:24.0376 4428 RasAcd - ok
11:38:24.0416 4428 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:38:24.0456 4428 RasAgileVpn - ok
11:38:24.0476 4428 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:38:24.0536 4428 Rasl2tp - ok
11:38:24.0566 4428 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:38:24.0606 4428 RasPppoe - ok
11:38:24.0616 4428 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:38:24.0656 4428 RasSstp - ok
11:38:24.0676 4428 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
11:38:24.0726 4428 rdbss - ok
11:38:24.0736 4428 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:38:24.0786 4428 rdpbus - ok
11:38:24.0806 4428 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:38:24.0836 4428 RDPCDD - ok
11:38:24.0866 4428 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
11:38:24.0916 4428 RDPDR - ok
11:38:24.0936 4428 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:38:24.0986 4428 RDPENCDD - ok
11:38:24.0986 4428 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:38:25.0026 4428 RDPREFMP - ok
11:38:25.0046 4428 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
11:38:25.0086 4428 RDPWD - ok
11:38:25.0106 4428 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
11:38:25.0116 4428 rdyboost - ok
11:38:25.0166 4428 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
11:38:25.0196 4428 RimUsb - ok
11:38:25.0246 4428 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
11:38:25.0256 4428 RsFx0103 - ok
11:38:25.0286 4428 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:38:25.0336 4428 rspndr - ok
11:38:25.0386 4428 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
11:38:25.0396 4428 RTL8167 - ok
11:38:25.0456 4428 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
11:38:25.0486 4428 RTL8187 - ok
11:38:25.0516 4428 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
11:38:25.0546 4428 s3cap - ok
11:38:25.0576 4428 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
11:38:25.0596 4428 sbp2port - ok
11:38:25.0636 4428 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
11:38:25.0646 4428 SCDEmu - ok
11:38:25.0676 4428 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
11:38:25.0736 4428 scfilter - ok
11:38:25.0766 4428 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:38:25.0836 4428 secdrv - ok
11:38:25.0856 4428 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:38:25.0896 4428 Serenum - ok
11:38:25.0906 4428 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:38:25.0976 4428 Serial - ok
11:38:25.0986 4428 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:38:26.0016 4428 sermouse - ok
11:38:26.0026 4428 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
11:38:26.0046 4428 sffdisk - ok
11:38:26.0066 4428 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
11:38:26.0086 4428 sffp_mmc - ok
11:38:26.0096 4428 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
11:38:26.0106 4428 sffp_sd - ok
11:38:26.0116 4428 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:38:26.0136 4428 sfloppy - ok
11:38:26.0166 4428 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:38:26.0176 4428 SiSRaid2 - ok
11:38:26.0176 4428 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:38:26.0206 4428 SiSRaid4 - ok
11:38:26.0226 4428 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:38:26.0266 4428 Smb - ok
11:38:26.0286 4428 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:38:26.0316 4428 spldr - ok
11:38:26.0376 4428 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
11:38:26.0416 4428 srv - ok
11:38:26.0436 4428 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
11:38:26.0476 4428 srv2 - ok
11:38:26.0496 4428 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
11:38:26.0526 4428 srvnet - ok
11:38:26.0546 4428 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:38:26.0556 4428 stexstor - ok
11:38:26.0596 4428 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
11:38:26.0606 4428 storflt - ok
11:38:26.0626 4428 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
11:38:26.0656 4428 storvsc - ok
11:38:26.0676 4428 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
11:38:26.0706 4428 swenum - ok
11:38:26.0776 4428 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
11:38:26.0816 4428 Tcpip - ok
11:38:26.0846 4428 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
11:38:26.0886 4428 TCPIP6 - ok
11:38:26.0906 4428 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
11:38:26.0936 4428 tcpipreg - ok
11:38:26.0956 4428 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:38:27.0006 4428 TDPIPE - ok
11:38:27.0016 4428 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:38:27.0056 4428 TDTCP - ok
11:38:27.0066 4428 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
11:38:27.0166 4428 tdx - ok
11:38:27.0176 4428 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
11:38:27.0186 4428 TermDD - ok
11:38:27.0266 4428 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
11:38:27.0276 4428 truecrypt - ok
11:38:27.0296 4428 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:38:27.0336 4428 tssecsrv - ok
11:38:27.0376 4428 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
11:38:27.0436 4428 tunnel - ok
11:38:27.0446 4428 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:38:27.0466 4428 uagp35 - ok
11:38:27.0496 4428 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
11:38:27.0526 4428 udfs - ok
11:38:27.0546 4428 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
11:38:27.0556 4428 uliagpkx - ok
11:38:27.0576 4428 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
11:38:27.0606 4428 umbus - ok
11:38:27.0636 4428 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:38:27.0666 4428 UmPass - ok
11:38:27.0696 4428 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
11:38:27.0736 4428 usbccgp - ok
11:38:27.0746 4428 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
11:38:27.0766 4428 usbcir - ok
11:38:27.0806 4428 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
11:38:27.0836 4428 usbehci - ok
11:38:27.0866 4428 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
11:38:27.0906 4428 usbhub - ok
11:38:27.0946 4428 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
11:38:27.0986 4428 usbohci - ok
11:38:27.0996 4428 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:38:28.0016 4428 usbprint - ok
11:38:28.0036 4428 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:38:28.0076 4428 USBSTOR - ok
11:38:28.0096 4428 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
11:38:28.0116 4428 usbuhci - ok
11:38:28.0146 4428 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
11:38:28.0186 4428 vdrvroot - ok
11:38:28.0196 4428 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:38:28.0226 4428 vga - ok
11:38:28.0226 4428 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:38:28.0276 4428 VgaSave - ok
11:38:28.0286 4428 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
11:38:28.0316 4428 vhdmp - ok
11:38:28.0326 4428 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
11:38:28.0356 4428 viaide - ok
11:38:28.0396 4428 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
11:38:28.0456 4428 vmbus - ok
11:38:28.0486 4428 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
11:38:28.0526 4428 VMBusHID - ok
11:38:28.0556 4428 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
11:38:28.0576 4428 vmci - ok
11:38:28.0596 4428 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
11:38:28.0606 4428 VMnetAdapter - ok
11:38:28.0626 4428 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
11:38:28.0646 4428 VMnetBridge - ok
11:38:28.0676 4428 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
11:38:28.0686 4428 VMnetuserif - ok
11:38:28.0736 4428 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
11:38:28.0746 4428 vmx86 - ok
11:38:28.0766 4428 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
11:38:28.0806 4428 volmgr - ok
11:38:28.0816 4428 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
11:38:28.0836 4428 volmgrx - ok
11:38:28.0856 4428 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
11:38:28.0916 4428 volsnap - ok
11:38:28.0946 4428 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
11:38:28.0976 4428 vpcbus - ok
11:38:29.0016 4428 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:38:29.0026 4428 vpcnfltr - ok
11:38:29.0056 4428 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
11:38:29.0076 4428 vpcusb - ok
11:38:29.0106 4428 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
11:38:29.0116 4428 vpcvmm - ok
11:38:29.0146 4428 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:38:29.0176 4428 vsmraid - ok
11:38:29.0196 4428 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:38:29.0226 4428 vwifibus - ok
11:38:29.0236 4428 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
11:38:29.0266 4428 vwififlt - ok
11:38:29.0286 4428 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:38:29.0306 4428 WacomPen - ok
11:38:29.0336 4428 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:38:29.0396 4428 WANARP - ok
11:38:29.0396 4428 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:38:29.0436 4428 Wanarpv6 - ok
11:38:29.0456 4428 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:38:29.0466 4428 Wd - ok
11:38:29.0486 4428 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:38:29.0506 4428 Wdf01000 - ok
11:38:29.0536 4428 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:38:29.0586 4428 WfpLwf - ok
11:38:29.0596 4428 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:38:29.0606 4428 WIMMount - ok
11:38:29.0626 4428 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
11:38:29.0646 4428 WmiAcpi - ok
11:38:29.0666 4428 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:38:29.0696 4428 ws2ifsl - ok
11:38:29.0746 4428 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
11:38:29.0776 4428 WSDPrintDevice - ok
11:38:29.0796 4428 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
11:38:29.0866 4428 WudfPf - ok
11:38:29.0896 4428 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:38:29.0936 4428 WUDFRd - ok
11:38:29.0986 4428 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
11:38:30.0016 4428 yukonw7 - ok
11:38:30.0046 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
11:38:30.0086 4428 \Device\Harddisk5\DR5 - ok
11:38:30.0086 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
11:38:30.0146 4428 \Device\Harddisk6\DR6 - ok
11:38:30.0146 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
11:38:30.0176 4428 \Device\Harddisk0\DR0 - ok
11:38:30.0176 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk1\DR1
11:38:30.0176 4428 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0176 4428 \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0206 4428 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
11:38:30.0416 4428 \Device\Harddisk2\DR2 - ok
11:38:30.0426 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk4\DR4
11:38:30.0426 4428 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0426 4428 \Device\Harddisk4\DR4 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0466 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk3\DR3
11:38:30.0466 4428 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0466 4428 \Device\Harddisk3\DR3 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0496 4428 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk7\DR8
11:38:30.0646 4428 \Device\Harddisk7\DR8 - ok
11:38:30.0676 4428 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
11:38:30.0676 4428 \Device\Harddisk5\DR5\Partition0 - ok
11:38:30.0696 4428 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
11:38:30.0696 4428 \Device\Harddisk6\DR6\Partition0 - ok
11:38:30.0696 4428 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
11:38:30.0696 4428 \Device\Harddisk0\DR0\Partition0 - ok
11:38:30.0706 4428 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
11:38:30.0706 4428 \Device\Harddisk0\DR0\Partition1 - ok
11:38:30.0706 4428 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
11:38:30.0706 4428 \Device\Harddisk1\DR1\Partition0 - ok
11:38:30.0716 4428 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
11:38:30.0716 4428 \Device\Harddisk2\DR2\Partition0 - ok
11:38:30.0746 4428 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
11:38:30.0746 4428 \Device\Harddisk2\DR2\Partition1 - ok
11:38:30.0756 4428 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
11:38:30.0756 4428 \Device\Harddisk2\DR2\Partition2 - ok
11:38:30.0766 4428 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
11:38:30.0766 4428 \Device\Harddisk4\DR4\Partition0 - ok
11:38:30.0766 4428 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
11:38:30.0766 4428 \Device\Harddisk3\DR3\Partition0 - ok
11:38:30.0766 4428 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
11:38:30.0766 4428 \Device\Harddisk3\DR3\Partition1 - ok
11:38:30.0776 4428 Boot (0x1200) (25ff27d159e9969e1e7185601b29aff5) \Device\Harddisk7\DR8\Partition0
11:38:30.0776 4428 \Device\Harddisk7\DR8\Partition0 - ok
11:38:30.0776 4428 ============================================================
11:38:30.0776 4428 Scan finished
11:38:30.0776 4428 ============================================================
11:38:30.0786 3888 Detected object count: 3
11:38:30.0786 3888 Actual detected object count: 3
11:39:35.0206 3888 \Device\Harddisk1\DR1 - processing error
11:39:40.0616 3888 \Device\Harddisk1\DR1 - will be restored on reboot
11:39:40.0616 3888 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:39:40.0616 3888 \Device\Harddisk4\DR4 - processing error
11:39:56.0106 3888 \Device\Harddisk4\DR4 - will be restored on reboot
11:39:56.0106 3888 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:39:56.0106 3888 \Device\Harddisk3\DR3 - processing error
11:39:58.0536 3888 \Device\Harddisk3\DR3 - will be restored on reboot
11:39:58.0536 3888 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:40:06.0182 3404 Deinitialize success
Log vytvoreny pri leceni:
11:37:41.0292 5352 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
11:37:41.0870 5352 ============================================================
11:37:41.0870 5352 Current date / time: 2012/01/08 11:37:41.0870
11:37:41.0870 5352 SystemInfo:
11:37:41.0870 5352
11:37:41.0870 5352 OS Version: 6.1.7600 ServicePack: 0.0
11:37:41.0870 5352 Product type: Workstation
11:37:41.0870 5352 ComputerName: COHENW7
11:37:41.0870 5352 UserName: Jakub
11:37:41.0870 5352 Windows directory: C:\Windows
11:37:41.0870 5352 System windows directory: C:\Windows
11:37:41.0870 5352 Running under WOW64
11:37:41.0870 5352 Processor architecture: Intel x64
11:37:41.0870 5352 Number of processors: 4
11:37:41.0870 5352 Page size: 0x1000
11:37:41.0870 5352 Boot type: Normal boot
11:37:41.0870 5352 ============================================================
11:37:42.0759 5352 Initialize success
11:38:12.0826 4428 ============================================================
11:38:12.0826 4428 Scan started
11:38:12.0826 4428 Mode: Manual; SigCheck; TDLFS;
11:38:12.0826 4428 ============================================================
11:38:14.0106 4428 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
11:38:14.0226 4428 1394ohci - ok
11:38:14.0256 4428 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
11:38:14.0276 4428 ACPI - ok
11:38:14.0286 4428 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
11:38:14.0346 4428 AcpiPmi - ok
11:38:14.0376 4428 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:38:14.0386 4428 adp94xx - ok
11:38:14.0416 4428 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:38:14.0466 4428 adpahci - ok
11:38:14.0486 4428 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:38:14.0506 4428 adpu320 - ok
11:38:14.0556 4428 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
11:38:14.0616 4428 AFD - ok
11:38:14.0636 4428 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
11:38:14.0646 4428 agp440 - ok
11:38:14.0786 4428 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
11:38:14.0836 4428 aliide - ok
11:38:14.0916 4428 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
11:38:14.0956 4428 amdide - ok
11:38:15.0056 4428 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:38:15.0096 4428 AmdK8 - ok
11:38:15.0206 4428 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:38:15.0286 4428 AmdPPM - ok
11:38:15.0406 4428 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
11:38:15.0416 4428 amdsata - ok
11:38:15.0516 4428 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:38:15.0556 4428 amdsbs - ok
11:38:15.0646 4428 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
11:38:15.0676 4428 amdxata - ok
11:38:15.0746 4428 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
11:38:15.0796 4428 AppID - ok
11:38:15.0826 4428 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:38:15.0856 4428 arc - ok
11:38:15.0866 4428 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:38:15.0876 4428 arcsas - ok
11:38:15.0926 4428 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:38:16.0036 4428 AsyncMac - ok
11:38:16.0046 4428 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
11:38:16.0056 4428 atapi - ok
11:38:16.0186 4428 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
11:38:16.0326 4428 atikmdag - ok
11:38:16.0376 4428 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:38:16.0406 4428 b06bdrv - ok
11:38:16.0436 4428 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:38:16.0476 4428 b57nd60a - ok
11:38:16.0506 4428 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:38:16.0546 4428 Beep - ok
11:38:16.0586 4428 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:38:16.0626 4428 blbdrive - ok
11:38:16.0666 4428 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
11:38:16.0726 4428 bowser - ok
11:38:16.0736 4428 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:38:16.0756 4428 BrFiltLo - ok
11:38:16.0766 4428 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:38:16.0776 4428 BrFiltUp - ok
11:38:16.0806 4428 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:38:16.0856 4428 Brserid - ok
11:38:16.0856 4428 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:38:16.0896 4428 BrSerWdm - ok
11:38:16.0906 4428 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:38:16.0946 4428 BrUsbMdm - ok
11:38:16.0956 4428 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:38:16.0966 4428 BrUsbSer - ok
11:38:16.0976 4428 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:38:17.0006 4428 BTHMODEM - ok
11:38:17.0036 4428 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:38:17.0076 4428 cdfs - ok
11:38:17.0096 4428 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
11:38:17.0146 4428 cdrom - ok
11:38:17.0156 4428 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:38:17.0166 4428 circlass - ok
11:38:17.0196 4428 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:38:17.0246 4428 CLFS - ok
11:38:17.0276 4428 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:38:17.0306 4428 CmBatt - ok
11:38:17.0306 4428 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
11:38:17.0336 4428 cmdide - ok
11:38:17.0356 4428 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
11:38:17.0416 4428 CNG - ok
11:38:17.0436 4428 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:38:17.0446 4428 Compbatt - ok
11:38:17.0476 4428 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
11:38:17.0506 4428 CompositeBus - ok
11:38:17.0516 4428 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:38:17.0526 4428 crcdisk - ok
11:38:17.0566 4428 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
11:38:17.0616 4428 CSC - ok
11:38:17.0646 4428 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
11:38:17.0676 4428 CVirtA - ok
11:38:17.0706 4428 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
11:38:17.0726 4428 CVPNDRVA - ok
11:38:17.0776 4428 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
11:38:17.0806 4428 DELTAII - ok
11:38:17.0836 4428 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
11:38:17.0866 4428 DfsC - ok
11:38:17.0886 4428 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:38:17.0966 4428 discache - ok
11:38:18.0006 4428 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:38:18.0016 4428 Disk - ok
11:38:18.0026 4428 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
11:38:18.0046 4428 DNE - ok
11:38:18.0086 4428 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:38:18.0106 4428 drmkaud - ok
11:38:18.0166 4428 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
11:38:18.0196 4428 DXGKrnl - ok
11:38:18.0236 4428 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
11:38:18.0256 4428 eamon - ok
11:38:18.0326 4428 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:38:18.0406 4428 ebdrv - ok
11:38:18.0436 4428 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
11:38:18.0446 4428 ehdrv - ok
11:38:18.0476 4428 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:38:18.0496 4428 elxstor - ok
11:38:18.0516 4428 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
11:38:18.0526 4428 epfwwfpr - ok
11:38:18.0536 4428 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
11:38:18.0576 4428 ErrDev - ok
11:38:18.0586 4428 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:38:18.0656 4428 exfat - ok
11:38:18.0676 4428 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:38:18.0746 4428 fastfat - ok
11:38:18.0756 4428 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:38:18.0806 4428 fdc - ok
11:38:18.0826 4428 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:38:18.0856 4428 FileInfo - ok
11:38:18.0866 4428 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:38:18.0926 4428 Filetrace - ok
11:38:18.0946 4428 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:38:18.0956 4428 flpydisk - ok
11:38:18.0986 4428 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
11:38:19.0016 4428 FltMgr - ok
11:38:19.0026 4428 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:38:19.0056 4428 FsDepends - ok
11:38:19.0066 4428 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:38:19.0096 4428 Fs_Rec - ok
11:38:19.0116 4428 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:38:19.0136 4428 fvevol - ok
11:38:19.0146 4428 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:38:19.0156 4428 gagp30kx - ok
11:38:19.0196 4428 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
11:38:19.0206 4428 grmnusb - ok
11:38:19.0246 4428 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
11:38:19.0266 4428 hcmon - ok
11:38:19.0286 4428 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:38:19.0316 4428 hcw85cir - ok
11:38:19.0346 4428 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
11:38:19.0376 4428 HdAudAddService - ok
11:38:19.0406 4428 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
11:38:19.0426 4428 HDAudBus - ok
11:38:19.0436 4428 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:38:19.0496 4428 HidBatt - ok
11:38:19.0516 4428 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:38:19.0566 4428 HidBth - ok
11:38:19.0576 4428 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:38:19.0626 4428 HidIr - ok
11:38:19.0656 4428 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
11:38:19.0666 4428 HidUsb - ok
11:38:19.0696 4428 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
11:38:19.0706 4428 HpSAMD - ok
11:38:19.0756 4428 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
11:38:19.0806 4428 HTTP - ok
11:38:19.0826 4428 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
11:38:19.0836 4428 hwpolicy - ok
11:38:19.0876 4428 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
11:38:19.0906 4428 i8042prt - ok
11:38:19.0936 4428 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
11:38:19.0956 4428 iaStorV - ok
11:38:19.0976 4428 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:38:19.0986 4428 iirsp - ok
11:38:19.0996 4428 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
11:38:20.0006 4428 intelide - ok
11:38:20.0026 4428 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:38:20.0046 4428 intelppm - ok
11:38:20.0066 4428 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:38:20.0106 4428 IpFilterDriver - ok
11:38:20.0116 4428 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
11:38:20.0146 4428 IPMIDRV - ok
11:38:20.0146 4428 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:38:20.0196 4428 IPNAT - ok
11:38:20.0196 4428 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:38:20.0246 4428 IRENUM - ok
11:38:20.0256 4428 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
11:38:20.0276 4428 isapnp - ok
11:38:20.0296 4428 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
11:38:20.0316 4428 iScsiPrt - ok
11:38:20.0326 4428 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
11:38:20.0346 4428 kbdclass - ok
11:38:20.0366 4428 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
11:38:20.0386 4428 kbdhid - ok
11:38:20.0406 4428 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
11:38:20.0416 4428 KSecDD - ok
11:38:20.0446 4428 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
11:38:20.0456 4428 KSecPkg - ok
11:38:20.0476 4428 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:38:20.0526 4428 ksthunk - ok
11:38:20.0556 4428 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:38:20.0616 4428 lltdio - ok
11:38:20.0646 4428 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:38:20.0676 4428 LSI_FC - ok
11:38:20.0676 4428 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:38:20.0706 4428 LSI_SAS - ok
11:38:20.0716 4428 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:38:20.0726 4428 LSI_SAS2 - ok
11:38:20.0746 4428 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:38:20.0756 4428 LSI_SCSI - ok
11:38:20.0776 4428 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:38:20.0826 4428 luafv - ok
11:38:20.0886 4428 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
11:38:20.0926 4428 MarvinBus - ok
11:38:20.0966 4428 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:38:21.0026 4428 megasas - ok
11:38:21.0066 4428 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:38:21.0106 4428 MegaSR - ok
11:38:21.0116 4428 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:38:21.0146 4428 Modem - ok
11:38:21.0166 4428 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:38:21.0186 4428 monitor - ok
11:38:21.0196 4428 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:38:21.0206 4428 mouclass - ok
11:38:21.0226 4428 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:38:21.0256 4428 mouhid - ok
11:38:21.0276 4428 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
11:38:21.0296 4428 mountmgr - ok
11:38:21.0306 4428 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
11:38:21.0326 4428 mpio - ok
11:38:21.0346 4428 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:38:21.0406 4428 mpsdrv - ok
11:38:21.0426 4428 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
11:38:21.0456 4428 MRxDAV - ok
11:38:21.0476 4428 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:38:21.0516 4428 mrxsmb - ok
11:38:21.0556 4428 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:38:21.0576 4428 mrxsmb10 - ok
11:38:21.0606 4428 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:38:21.0636 4428 mrxsmb20 - ok
11:38:21.0656 4428 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
11:38:21.0676 4428 msahci - ok
11:38:21.0696 4428 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
11:38:21.0706 4428 msdsm - ok
11:38:21.0726 4428 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:38:21.0756 4428 Msfs - ok
11:38:21.0766 4428 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:38:21.0826 4428 mshidkmdf - ok
11:38:21.0836 4428 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
11:38:21.0856 4428 msisadrv - ok
11:38:21.0886 4428 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:38:21.0926 4428 MSKSSRV - ok
11:38:21.0936 4428 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:38:21.0986 4428 MSPCLOCK - ok
11:38:21.0996 4428 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:38:22.0036 4428 MSPQM - ok
11:38:22.0056 4428 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
11:38:22.0076 4428 MsRPC - ok
11:38:22.0096 4428 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
11:38:22.0106 4428 mssmbios - ok
11:38:22.0136 4428 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:38:22.0176 4428 MSTEE - ok
11:38:22.0186 4428 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:38:22.0206 4428 MTConfig - ok
11:38:22.0236 4428 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
11:38:22.0266 4428 MTsensor - ok
11:38:22.0296 4428 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:38:22.0316 4428 Mup - ok
11:38:22.0336 4428 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
11:38:22.0346 4428 mv91cons - ok
11:38:22.0366 4428 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
11:38:22.0376 4428 mv91xx - ok
11:38:22.0416 4428 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:38:22.0476 4428 NativeWifiP - ok
11:38:22.0516 4428 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
11:38:22.0536 4428 NDIS - ok
11:38:22.0556 4428 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:38:22.0606 4428 NdisCap - ok
11:38:22.0626 4428 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:38:22.0676 4428 NdisTapi - ok
11:38:22.0706 4428 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
11:38:22.0746 4428 Ndisuio - ok
11:38:22.0766 4428 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
11:38:22.0826 4428 NdisWan - ok
11:38:22.0846 4428 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
11:38:22.0906 4428 NDProxy - ok
11:38:22.0926 4428 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:38:22.0966 4428 NetBIOS - ok
11:38:22.0986 4428 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
11:38:23.0036 4428 NetBT - ok
11:38:23.0076 4428 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:38:23.0086 4428 nfrd960 - ok
11:38:23.0106 4428 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:38:23.0146 4428 Npfs - ok
11:38:23.0166 4428 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:38:23.0216 4428 nsiproxy - ok
11:38:23.0276 4428 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
11:38:23.0316 4428 Ntfs - ok
11:38:23.0336 4428 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:38:23.0386 4428 Null - ok
11:38:23.0416 4428 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
11:38:23.0426 4428 nvraid - ok
11:38:23.0446 4428 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
11:38:23.0456 4428 nvstor - ok
11:38:23.0476 4428 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
11:38:23.0496 4428 nv_agp - ok
11:38:23.0516 4428 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
11:38:23.0556 4428 ohci1394 - ok
11:38:23.0596 4428 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:38:23.0626 4428 Parport - ok
11:38:23.0636 4428 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
11:38:23.0666 4428 partmgr - ok
11:38:23.0696 4428 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
11:38:23.0726 4428 pci - ok
11:38:23.0726 4428 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
11:38:23.0756 4428 pciide - ok
11:38:23.0776 4428 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:38:23.0796 4428 pcmcia - ok
11:38:23.0806 4428 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:38:23.0836 4428 pcw - ok
11:38:23.0866 4428 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:38:23.0926 4428 PEAUTH - ok
11:38:23.0976 4428 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
11:38:24.0036 4428 PptpMiniport - ok
11:38:24.0056 4428 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:38:24.0106 4428 Processor - ok
11:38:24.0126 4428 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
11:38:24.0166 4428 Psched - ok
11:38:24.0216 4428 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:38:24.0256 4428 ql2300 - ok
11:38:24.0266 4428 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:38:24.0276 4428 ql40xx - ok
11:38:24.0296 4428 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:38:24.0336 4428 QWAVEdrv - ok
11:38:24.0346 4428 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:38:24.0376 4428 RasAcd - ok
11:38:24.0416 4428 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:38:24.0456 4428 RasAgileVpn - ok
11:38:24.0476 4428 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:38:24.0536 4428 Rasl2tp - ok
11:38:24.0566 4428 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:38:24.0606 4428 RasPppoe - ok
11:38:24.0616 4428 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:38:24.0656 4428 RasSstp - ok
11:38:24.0676 4428 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
11:38:24.0726 4428 rdbss - ok
11:38:24.0736 4428 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:38:24.0786 4428 rdpbus - ok
11:38:24.0806 4428 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:38:24.0836 4428 RDPCDD - ok
11:38:24.0866 4428 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
11:38:24.0916 4428 RDPDR - ok
11:38:24.0936 4428 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:38:24.0986 4428 RDPENCDD - ok
11:38:24.0986 4428 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:38:25.0026 4428 RDPREFMP - ok
11:38:25.0046 4428 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
11:38:25.0086 4428 RDPWD - ok
11:38:25.0106 4428 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
11:38:25.0116 4428 rdyboost - ok
11:38:25.0166 4428 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
11:38:25.0196 4428 RimUsb - ok
11:38:25.0246 4428 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
11:38:25.0256 4428 RsFx0103 - ok
11:38:25.0286 4428 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:38:25.0336 4428 rspndr - ok
11:38:25.0386 4428 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
11:38:25.0396 4428 RTL8167 - ok
11:38:25.0456 4428 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
11:38:25.0486 4428 RTL8187 - ok
11:38:25.0516 4428 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
11:38:25.0546 4428 s3cap - ok
11:38:25.0576 4428 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
11:38:25.0596 4428 sbp2port - ok
11:38:25.0636 4428 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
11:38:25.0646 4428 SCDEmu - ok
11:38:25.0676 4428 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
11:38:25.0736 4428 scfilter - ok
11:38:25.0766 4428 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:38:25.0836 4428 secdrv - ok
11:38:25.0856 4428 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:38:25.0896 4428 Serenum - ok
11:38:25.0906 4428 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:38:25.0976 4428 Serial - ok
11:38:25.0986 4428 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:38:26.0016 4428 sermouse - ok
11:38:26.0026 4428 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
11:38:26.0046 4428 sffdisk - ok
11:38:26.0066 4428 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
11:38:26.0086 4428 sffp_mmc - ok
11:38:26.0096 4428 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
11:38:26.0106 4428 sffp_sd - ok
11:38:26.0116 4428 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:38:26.0136 4428 sfloppy - ok
11:38:26.0166 4428 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:38:26.0176 4428 SiSRaid2 - ok
11:38:26.0176 4428 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:38:26.0206 4428 SiSRaid4 - ok
11:38:26.0226 4428 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:38:26.0266 4428 Smb - ok
11:38:26.0286 4428 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:38:26.0316 4428 spldr - ok
11:38:26.0376 4428 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
11:38:26.0416 4428 srv - ok
11:38:26.0436 4428 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
11:38:26.0476 4428 srv2 - ok
11:38:26.0496 4428 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
11:38:26.0526 4428 srvnet - ok
11:38:26.0546 4428 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:38:26.0556 4428 stexstor - ok
11:38:26.0596 4428 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
11:38:26.0606 4428 storflt - ok
11:38:26.0626 4428 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
11:38:26.0656 4428 storvsc - ok
11:38:26.0676 4428 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
11:38:26.0706 4428 swenum - ok
11:38:26.0776 4428 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
11:38:26.0816 4428 Tcpip - ok
11:38:26.0846 4428 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
11:38:26.0886 4428 TCPIP6 - ok
11:38:26.0906 4428 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
11:38:26.0936 4428 tcpipreg - ok
11:38:26.0956 4428 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:38:27.0006 4428 TDPIPE - ok
11:38:27.0016 4428 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:38:27.0056 4428 TDTCP - ok
11:38:27.0066 4428 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
11:38:27.0166 4428 tdx - ok
11:38:27.0176 4428 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
11:38:27.0186 4428 TermDD - ok
11:38:27.0266 4428 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
11:38:27.0276 4428 truecrypt - ok
11:38:27.0296 4428 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:38:27.0336 4428 tssecsrv - ok
11:38:27.0376 4428 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
11:38:27.0436 4428 tunnel - ok
11:38:27.0446 4428 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:38:27.0466 4428 uagp35 - ok
11:38:27.0496 4428 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
11:38:27.0526 4428 udfs - ok
11:38:27.0546 4428 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
11:38:27.0556 4428 uliagpkx - ok
11:38:27.0576 4428 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
11:38:27.0606 4428 umbus - ok
11:38:27.0636 4428 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:38:27.0666 4428 UmPass - ok
11:38:27.0696 4428 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
11:38:27.0736 4428 usbccgp - ok
11:38:27.0746 4428 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
11:38:27.0766 4428 usbcir - ok
11:38:27.0806 4428 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
11:38:27.0836 4428 usbehci - ok
11:38:27.0866 4428 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
11:38:27.0906 4428 usbhub - ok
11:38:27.0946 4428 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
11:38:27.0986 4428 usbohci - ok
11:38:27.0996 4428 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:38:28.0016 4428 usbprint - ok
11:38:28.0036 4428 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:38:28.0076 4428 USBSTOR - ok
11:38:28.0096 4428 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
11:38:28.0116 4428 usbuhci - ok
11:38:28.0146 4428 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
11:38:28.0186 4428 vdrvroot - ok
11:38:28.0196 4428 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:38:28.0226 4428 vga - ok
11:38:28.0226 4428 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:38:28.0276 4428 VgaSave - ok
11:38:28.0286 4428 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
11:38:28.0316 4428 vhdmp - ok
11:38:28.0326 4428 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
11:38:28.0356 4428 viaide - ok
11:38:28.0396 4428 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
11:38:28.0456 4428 vmbus - ok
11:38:28.0486 4428 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
11:38:28.0526 4428 VMBusHID - ok
11:38:28.0556 4428 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
11:38:28.0576 4428 vmci - ok
11:38:28.0596 4428 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
11:38:28.0606 4428 VMnetAdapter - ok
11:38:28.0626 4428 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
11:38:28.0646 4428 VMnetBridge - ok
11:38:28.0676 4428 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
11:38:28.0686 4428 VMnetuserif - ok
11:38:28.0736 4428 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
11:38:28.0746 4428 vmx86 - ok
11:38:28.0766 4428 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
11:38:28.0806 4428 volmgr - ok
11:38:28.0816 4428 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
11:38:28.0836 4428 volmgrx - ok
11:38:28.0856 4428 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
11:38:28.0916 4428 volsnap - ok
11:38:28.0946 4428 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
11:38:28.0976 4428 vpcbus - ok
11:38:29.0016 4428 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:38:29.0026 4428 vpcnfltr - ok
11:38:29.0056 4428 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
11:38:29.0076 4428 vpcusb - ok
11:38:29.0106 4428 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
11:38:29.0116 4428 vpcvmm - ok
11:38:29.0146 4428 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:38:29.0176 4428 vsmraid - ok
11:38:29.0196 4428 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:38:29.0226 4428 vwifibus - ok
11:38:29.0236 4428 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
11:38:29.0266 4428 vwififlt - ok
11:38:29.0286 4428 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:38:29.0306 4428 WacomPen - ok
11:38:29.0336 4428 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:38:29.0396 4428 WANARP - ok
11:38:29.0396 4428 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:38:29.0436 4428 Wanarpv6 - ok
11:38:29.0456 4428 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:38:29.0466 4428 Wd - ok
11:38:29.0486 4428 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:38:29.0506 4428 Wdf01000 - ok
11:38:29.0536 4428 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:38:29.0586 4428 WfpLwf - ok
11:38:29.0596 4428 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:38:29.0606 4428 WIMMount - ok
11:38:29.0626 4428 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
11:38:29.0646 4428 WmiAcpi - ok
11:38:29.0666 4428 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:38:29.0696 4428 ws2ifsl - ok
11:38:29.0746 4428 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
11:38:29.0776 4428 WSDPrintDevice - ok
11:38:29.0796 4428 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
11:38:29.0866 4428 WudfPf - ok
11:38:29.0896 4428 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:38:29.0936 4428 WUDFRd - ok
11:38:29.0986 4428 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
11:38:30.0016 4428 yukonw7 - ok
11:38:30.0046 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
11:38:30.0086 4428 \Device\Harddisk5\DR5 - ok
11:38:30.0086 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
11:38:30.0146 4428 \Device\Harddisk6\DR6 - ok
11:38:30.0146 4428 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
11:38:30.0176 4428 \Device\Harddisk0\DR0 - ok
11:38:30.0176 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk1\DR1
11:38:30.0176 4428 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0176 4428 \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0206 4428 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
11:38:30.0416 4428 \Device\Harddisk2\DR2 - ok
11:38:30.0426 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk4\DR4
11:38:30.0426 4428 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0426 4428 \Device\Harddisk4\DR4 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0466 4428 MBR (0x1B8) (96da2e9d711c32cfdf422f4261a4987a) \Device\Harddisk3\DR3
11:38:30.0466 4428 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - infected
11:38:30.0466 4428 \Device\Harddisk3\DR3 - detected Rootkit.Boot.Wistler.a (0)
11:38:30.0496 4428 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk7\DR8
11:38:30.0646 4428 \Device\Harddisk7\DR8 - ok
11:38:30.0676 4428 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
11:38:30.0676 4428 \Device\Harddisk5\DR5\Partition0 - ok
11:38:30.0696 4428 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
11:38:30.0696 4428 \Device\Harddisk6\DR6\Partition0 - ok
11:38:30.0696 4428 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
11:38:30.0696 4428 \Device\Harddisk0\DR0\Partition0 - ok
11:38:30.0706 4428 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
11:38:30.0706 4428 \Device\Harddisk0\DR0\Partition1 - ok
11:38:30.0706 4428 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
11:38:30.0706 4428 \Device\Harddisk1\DR1\Partition0 - ok
11:38:30.0716 4428 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
11:38:30.0716 4428 \Device\Harddisk2\DR2\Partition0 - ok
11:38:30.0746 4428 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
11:38:30.0746 4428 \Device\Harddisk2\DR2\Partition1 - ok
11:38:30.0756 4428 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
11:38:30.0756 4428 \Device\Harddisk2\DR2\Partition2 - ok
11:38:30.0766 4428 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
11:38:30.0766 4428 \Device\Harddisk4\DR4\Partition0 - ok
11:38:30.0766 4428 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
11:38:30.0766 4428 \Device\Harddisk3\DR3\Partition0 - ok
11:38:30.0766 4428 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
11:38:30.0766 4428 \Device\Harddisk3\DR3\Partition1 - ok
11:38:30.0776 4428 Boot (0x1200) (25ff27d159e9969e1e7185601b29aff5) \Device\Harddisk7\DR8\Partition0
11:38:30.0776 4428 \Device\Harddisk7\DR8\Partition0 - ok
11:38:30.0776 4428 ============================================================
11:38:30.0776 4428 Scan finished
11:38:30.0776 4428 ============================================================
11:38:30.0786 3888 Detected object count: 3
11:38:30.0786 3888 Actual detected object count: 3
11:39:35.0206 3888 \Device\Harddisk1\DR1 - processing error
11:39:40.0616 3888 \Device\Harddisk1\DR1 - will be restored on reboot
11:39:40.0616 3888 \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:39:40.0616 3888 \Device\Harddisk4\DR4 - processing error
11:39:56.0106 3888 \Device\Harddisk4\DR4 - will be restored on reboot
11:39:56.0106 3888 \Device\Harddisk4\DR4 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:39:56.0106 3888 \Device\Harddisk3\DR3 - processing error
11:39:58.0536 3888 \Device\Harddisk3\DR3 - will be restored on reboot
11:39:58.0536 3888 \Device\Harddisk3\DR3 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
11:40:06.0182 3404 Deinitialize success
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Kdyz pustim TDSSKiller znova nyni tak se mi uz neobjevi moznost lecit ani eset uz nic nehlasi.
LOG:
11:45:54.0092 4284 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
11:45:54.0663 4284 ============================================================
11:45:54.0663 4284 Current date / time: 2012/01/08 11:45:54.0663
11:45:54.0663 4284 SystemInfo:
11:45:54.0663 4284
11:45:54.0663 4284 OS Version: 6.1.7600 ServicePack: 0.0
11:45:54.0663 4284 Product type: Workstation
11:45:54.0663 4284 ComputerName: COHENW7
11:45:54.0663 4284 UserName: Jakub
11:45:54.0663 4284 Windows directory: C:\Windows
11:45:54.0663 4284 System windows directory: C:\Windows
11:45:54.0663 4284 Running under WOW64
11:45:54.0663 4284 Processor architecture: Intel x64
11:45:54.0663 4284 Number of processors: 4
11:45:54.0663 4284 Page size: 0x1000
11:45:54.0663 4284 Boot type: Normal boot
11:45:54.0663 4284 ============================================================
11:45:56.0686 4284 Initialize success
11:46:02.0926 1060 ============================================================
11:46:02.0926 1060 Scan started
11:46:02.0926 1060 Mode: Manual; SigCheck; TDLFS;
11:46:02.0926 1060 ============================================================
11:46:04.0299 1060 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
11:46:04.0381 1060 1394ohci - ok
11:46:04.0408 1060 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
11:46:04.0424 1060 ACPI - ok
11:46:04.0442 1060 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
11:46:04.0518 1060 AcpiPmi - ok
11:46:04.0544 1060 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:46:04.0592 1060 adp94xx - ok
11:46:04.0625 1060 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:46:04.0670 1060 adpahci - ok
11:46:04.0693 1060 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:46:04.0708 1060 adpu320 - ok
11:46:04.0763 1060 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
11:46:04.0838 1060 AFD - ok
11:46:04.0853 1060 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
11:46:04.0883 1060 agp440 - ok
11:46:04.0913 1060 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
11:46:04.0947 1060 aliide - ok
11:46:04.0953 1060 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
11:46:04.0979 1060 amdide - ok
11:46:04.0987 1060 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:46:05.0032 1060 AmdK8 - ok
11:46:05.0044 1060 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:46:05.0097 1060 AmdPPM - ok
11:46:05.0119 1060 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
11:46:05.0161 1060 amdsata - ok
11:46:05.0170 1060 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:46:05.0204 1060 amdsbs - ok
11:46:05.0341 1060 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
11:46:05.0366 1060 amdxata - ok
11:46:05.0549 1060 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
11:46:06.0047 1060 AppID - ok
11:46:06.0193 1060 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:46:06.0247 1060 arc - ok
11:46:06.0387 1060 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:46:06.0420 1060 arcsas - ok
11:46:06.0580 1060 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:46:07.0869 1060 AsyncMac - ok
11:46:07.0998 1060 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
11:46:08.0007 1060 atapi - ok
11:46:08.0661 1060 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
11:46:08.0846 1060 atikmdag - ok
11:46:09.0052 1060 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:46:09.0170 1060 b06bdrv - ok
11:46:09.0346 1060 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:46:09.0436 1060 b57nd60a - ok
11:46:09.0610 1060 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:46:09.0675 1060 Beep - ok
11:46:09.0860 1060 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:46:09.0911 1060 blbdrive - ok
11:46:10.0071 1060 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
11:46:10.0211 1060 bowser - ok
11:46:10.0350 1060 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:46:10.0404 1060 BrFiltLo - ok
11:46:10.0508 1060 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:46:10.0544 1060 BrFiltUp - ok
11:46:10.0641 1060 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:46:10.0790 1060 Brserid - ok
11:46:10.0896 1060 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:46:11.0028 1060 BrSerWdm - ok
11:46:11.0154 1060 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:46:11.0240 1060 BrUsbMdm - ok
11:46:11.0343 1060 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:46:11.0402 1060 BrUsbSer - ok
11:46:11.0542 1060 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:46:11.0634 1060 BTHMODEM - ok
11:46:11.0754 1060 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:46:11.0821 1060 cdfs - ok
11:46:11.0974 1060 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
11:46:12.0066 1060 cdrom - ok
11:46:12.0263 1060 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:46:12.0298 1060 circlass - ok
11:46:12.0446 1060 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:46:12.0524 1060 CLFS - ok
11:46:12.0755 1060 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:46:12.0840 1060 CmBatt - ok
11:46:12.0964 1060 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
11:46:13.0009 1060 cmdide - ok
11:46:13.0149 1060 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
11:46:13.0262 1060 CNG - ok
11:46:13.0378 1060 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:46:13.0422 1060 Compbatt - ok
11:46:13.0570 1060 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
11:46:13.0650 1060 CompositeBus - ok
11:46:13.0783 1060 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:46:13.0817 1060 crcdisk - ok
11:46:14.0011 1060 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
11:46:14.0166 1060 CSC - ok
11:46:14.0315 1060 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
11:46:14.0370 1060 CVirtA - ok
11:46:14.0598 1060 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
11:46:14.0609 1060 CVPNDRVA - ok
11:46:14.0813 1060 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
11:46:14.0838 1060 DELTAII - ok
11:46:14.0977 1060 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
11:46:15.0032 1060 DfsC - ok
11:46:15.0150 1060 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:46:15.0288 1060 discache - ok
11:46:15.0441 1060 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:46:15.0451 1060 Disk - ok
11:46:15.0616 1060 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
11:46:15.0625 1060 DNE - ok
11:46:15.0778 1060 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:46:15.0838 1060 drmkaud - ok
11:46:16.0118 1060 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
11:46:16.0142 1060 DXGKrnl - ok
11:46:16.0307 1060 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
11:46:16.0331 1060 eamon - ok
11:46:16.0696 1060 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:46:16.0867 1060 ebdrv - ok
11:46:17.0010 1060 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
11:46:17.0033 1060 ehdrv - ok
11:46:17.0275 1060 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:46:17.0371 1060 elxstor - ok
11:46:17.0488 1060 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
11:46:17.0497 1060 epfwwfpr - ok
11:46:17.0611 1060 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
11:46:17.0696 1060 ErrDev - ok
11:46:17.0848 1060 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:46:17.0978 1060 exfat - ok
11:46:18.0101 1060 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:46:18.0217 1060 fastfat - ok
11:46:18.0344 1060 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:46:18.0437 1060 fdc - ok
11:46:18.0604 1060 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:46:18.0636 1060 FileInfo - ok
11:46:18.0759 1060 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:46:18.0852 1060 Filetrace - ok
11:46:18.0968 1060 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:46:19.0004 1060 flpydisk - ok
11:46:19.0141 1060 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
11:46:19.0199 1060 FltMgr - ok
11:46:19.0323 1060 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:46:19.0377 1060 FsDepends - ok
11:46:19.0507 1060 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:46:19.0531 1060 Fs_Rec - ok
11:46:19.0692 1060 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:46:19.0751 1060 fvevol - ok
11:46:19.0896 1060 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:46:19.0956 1060 gagp30kx - ok
11:46:20.0109 1060 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
11:46:20.0160 1060 grmnusb - ok
11:46:20.0316 1060 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
11:46:20.0339 1060 hcmon - ok
11:46:20.0470 1060 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:46:20.0548 1060 hcw85cir - ok
11:46:20.0722 1060 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
11:46:20.0796 1060 HdAudAddService - ok
11:46:20.0982 1060 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
11:46:21.0028 1060 HDAudBus - ok
11:46:21.0170 1060 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:46:21.0260 1060 HidBatt - ok
11:46:21.0376 1060 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:46:21.0447 1060 HidBth - ok
11:46:21.0558 1060 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:46:21.0645 1060 HidIr - ok
11:46:21.0807 1060 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
11:46:21.0859 1060 HidUsb - ok
11:46:22.0035 1060 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
11:46:22.0081 1060 HpSAMD - ok
11:46:22.0253 1060 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
11:46:22.0372 1060 HTTP - ok
11:46:22.0491 1060 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
11:46:22.0516 1060 hwpolicy - ok
11:46:22.0669 1060 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
11:46:22.0731 1060 i8042prt - ok
11:46:22.0996 1060 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
11:46:23.0115 1060 iaStorV - ok
11:46:23.0267 1060 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:46:23.0311 1060 iirsp - ok
11:46:23.0425 1060 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
11:46:23.0455 1060 intelide - ok
11:46:23.0598 1060 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:46:23.0647 1060 intelppm - ok
11:46:23.0790 1060 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:46:23.0884 1060 IpFilterDriver - ok
11:46:23.0989 1060 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
11:46:24.0056 1060 IPMIDRV - ok
11:46:24.0164 1060 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:46:24.0249 1060 IPNAT - ok
11:46:24.0358 1060 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:46:24.0395 1060 IRENUM - ok
11:46:24.0511 1060 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
11:46:24.0556 1060 isapnp - ok
11:46:24.0685 1060 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
11:46:24.0797 1060 iScsiPrt - ok
11:46:24.0933 1060 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
11:46:24.0945 1060 kbdclass - ok
11:46:25.0055 1060 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
11:46:25.0105 1060 kbdhid - ok
11:46:25.0238 1060 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
11:46:25.0309 1060 KSecDD - ok
11:46:25.0435 1060 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
11:46:25.0467 1060 KSecPkg - ok
11:46:25.0615 1060 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:46:25.0677 1060 ksthunk - ok
11:46:25.0865 1060 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:46:25.0975 1060 lltdio - ok
11:46:26.0123 1060 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:46:26.0181 1060 LSI_FC - ok
11:46:26.0299 1060 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:46:26.0344 1060 LSI_SAS - ok
11:46:26.0482 1060 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:46:26.0526 1060 LSI_SAS2 - ok
11:46:26.0650 1060 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:46:26.0701 1060 LSI_SCSI - ok
11:46:26.0824 1060 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:46:26.0896 1060 luafv - ok
11:46:27.0097 1060 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
11:46:27.0180 1060 MarvinBus - ok
11:46:27.0284 1060 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:46:27.0344 1060 megasas - ok
11:46:27.0463 1060 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:46:27.0567 1060 MegaSR - ok
11:46:27.0679 1060 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:46:27.0770 1060 Modem - ok
11:46:27.0895 1060 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:46:27.0943 1060 monitor - ok
11:46:28.0073 1060 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:46:28.0084 1060 mouclass - ok
11:46:28.0193 1060 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:46:28.0243 1060 mouhid - ok
11:46:28.0356 1060 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
11:46:28.0414 1060 mountmgr - ok
11:46:28.0526 1060 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
11:46:28.0570 1060 mpio - ok
11:46:28.0664 1060 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:46:28.0761 1060 mpsdrv - ok
11:46:28.0932 1060 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
11:46:29.0043 1060 MRxDAV - ok
11:46:29.0174 1060 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:46:29.0283 1060 mrxsmb - ok
11:46:29.0429 1060 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:46:29.0518 1060 mrxsmb10 - ok
11:46:29.0662 1060 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:46:29.0728 1060 mrxsmb20 - ok
11:46:29.0839 1060 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
11:46:29.0864 1060 msahci - ok
11:46:29.0970 1060 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
11:46:30.0032 1060 msdsm - ok
11:46:30.0145 1060 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:46:30.0200 1060 Msfs - ok
11:46:30.0291 1060 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:46:30.0378 1060 mshidkmdf - ok
11:46:30.0486 1060 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
11:46:30.0511 1060 msisadrv - ok
11:46:30.0704 1060 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:46:30.0776 1060 MSKSSRV - ok
11:46:30.0913 1060 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:46:30.0996 1060 MSPCLOCK - ok
11:46:31.0161 1060 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:46:31.0244 1060 MSPQM - ok
11:46:31.0487 1060 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
11:46:31.0556 1060 MsRPC - ok
11:46:31.0753 1060 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
11:46:31.0763 1060 mssmbios - ok
11:46:32.0230 1060 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:46:32.0342 1060 MSTEE - ok
11:46:32.0556 1060 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:46:32.0652 1060 MTConfig - ok
11:46:32.0988 1060 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
11:46:33.0090 1060 MTsensor - ok
11:46:33.0279 1060 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:46:33.0305 1060 Mup - ok
11:46:33.0513 1060 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
11:46:33.0521 1060 mv91cons - ok
11:46:33.0732 1060 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
11:46:33.0742 1060 mv91xx - ok
11:46:33.0965 1060 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:46:34.0077 1060 NativeWifiP - ok
11:46:34.0396 1060 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
11:46:34.0458 1060 NDIS - ok
11:46:34.0555 1060 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:46:34.0645 1060 NdisCap - ok
11:46:34.0801 1060 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:46:34.0906 1060 NdisTapi - ok
11:46:35.0075 1060 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
11:46:35.0155 1060 Ndisuio - ok
11:46:35.0279 1060 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
11:46:35.0408 1060 NdisWan - ok
11:46:35.0532 1060 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
11:46:35.0635 1060 NDProxy - ok
11:46:35.0725 1060 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:46:35.0809 1060 NetBIOS - ok
11:46:35.0911 1060 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
11:46:36.0009 1060 NetBT - ok
11:46:36.0195 1060 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:46:36.0236 1060 nfrd960 - ok
11:46:36.0366 1060 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:46:36.0455 1060 Npfs - ok
11:46:36.0604 1060 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:46:36.0696 1060 nsiproxy - ok
11:46:36.0957 1060 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
11:46:37.0099 1060 Ntfs - ok
11:46:37.0223 1060 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:46:37.0288 1060 Null - ok
11:46:37.0469 1060 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
11:46:37.0580 1060 nvraid - ok
11:46:37.0733 1060 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
11:46:37.0832 1060 nvstor - ok
11:46:37.0950 1060 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
11:46:38.0003 1060 nv_agp - ok
11:46:38.0169 1060 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
11:46:38.0238 1060 ohci1394 - ok
11:46:38.0639 1060 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:46:38.0668 1060 Parport - ok
11:46:38.0791 1060 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
11:46:38.0825 1060 partmgr - ok
11:46:38.0986 1060 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
11:46:39.0028 1060 pci - ok
11:46:39.0155 1060 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
11:46:39.0179 1060 pciide - ok
11:46:39.0312 1060 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:46:39.0377 1060 pcmcia - ok
11:46:39.0464 1060 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:46:39.0490 1060 pcw - ok
11:46:39.0640 1060 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:46:39.0744 1060 PEAUTH - ok
11:46:39.0909 1060 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
11:46:39.0991 1060 PptpMiniport - ok
11:46:40.0122 1060 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:46:40.0181 1060 Processor - ok
11:46:40.0342 1060 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
11:46:40.0408 1060 Psched - ok
11:46:40.0644 1060 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:46:40.0749 1060 ql2300 - ok
11:46:40.0874 1060 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:46:40.0909 1060 ql40xx - ok
11:46:41.0089 1060 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:46:41.0180 1060 QWAVEdrv - ok
11:46:41.0347 1060 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:46:41.0405 1060 RasAcd - ok
11:46:41.0606 1060 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:46:41.0715 1060 RasAgileVpn - ok
11:46:41.0893 1060 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:46:41.0975 1060 Rasl2tp - ok
11:46:42.0045 1060 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:46:42.0119 1060 RasPppoe - ok
11:46:42.0253 1060 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:46:42.0333 1060 RasSstp - ok
11:46:42.0452 1060 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
11:46:42.0561 1060 rdbss - ok
11:46:42.0660 1060 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:46:42.0720 1060 rdpbus - ok
11:46:42.0848 1060 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:46:42.0911 1060 RDPCDD - ok
11:46:43.0099 1060 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
11:46:43.0227 1060 RDPDR - ok
11:46:43.0371 1060 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:46:43.0426 1060 RDPENCDD - ok
11:46:43.0530 1060 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:46:43.0571 1060 RDPREFMP - ok
11:46:43.0676 1060 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
11:46:43.0781 1060 RDPWD - ok
11:46:43.0882 1060 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
11:46:43.0942 1060 rdyboost - ok
11:46:44.0075 1060 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
11:46:44.0141 1060 RimUsb - ok
11:46:44.0286 1060 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
11:46:44.0374 1060 RsFx0103 - ok
11:46:44.0532 1060 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:46:44.0623 1060 rspndr - ok
11:46:44.0780 1060 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
11:46:44.0855 1060 RTL8167 - ok
11:46:45.0050 1060 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
11:46:45.0156 1060 RTL8187 - ok
11:46:45.0272 1060 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
11:46:45.0357 1060 s3cap - ok
11:46:45.0458 1060 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
11:46:45.0490 1060 sbp2port - ok
11:46:45.0651 1060 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
11:46:45.0676 1060 SCDEmu - ok
11:46:45.0815 1060 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
11:46:45.0901 1060 scfilter - ok
11:46:46.0061 1060 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:46:46.0134 1060 secdrv - ok
11:46:46.0277 1060 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:46:46.0321 1060 Serenum - ok
11:46:46.0458 1060 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:46:46.0533 1060 Serial - ok
11:46:46.0749 1060 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:46:46.0818 1060 sermouse - ok
11:46:46.0948 1060 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
11:46:47.0044 1060 sffdisk - ok
11:46:47.0138 1060 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
11:46:47.0204 1060 sffp_mmc - ok
11:46:47.0287 1060 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
11:46:47.0325 1060 sffp_sd - ok
11:46:47.0420 1060 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:46:47.0509 1060 sfloppy - ok
11:46:47.0630 1060 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:46:47.0718 1060 SiSRaid2 - ok
11:46:47.0853 1060 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:46:47.0893 1060 SiSRaid4 - ok
11:46:48.0012 1060 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:46:48.0106 1060 Smb - ok
11:46:48.0217 1060 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:46:48.0242 1060 spldr - ok
11:46:48.0444 1060 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
11:46:48.0540 1060 srv - ok
11:46:48.0705 1060 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
11:46:48.0809 1060 srv2 - ok
11:46:48.0933 1060 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
11:46:48.0994 1060 srvnet - ok
11:46:49.0143 1060 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:46:49.0176 1060 stexstor - ok
11:46:49.0271 1060 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
11:46:49.0281 1060 storflt - ok
11:46:49.0319 1060 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
11:46:49.0345 1060 storvsc - ok
11:46:49.0385 1060 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
11:46:49.0410 1060 swenum - ok
11:46:50.0002 1060 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
11:46:50.0090 1060 Tcpip - ok
11:46:50.0290 1060 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
11:46:50.0324 1060 TCPIP6 - ok
11:46:50.0420 1060 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
11:46:50.0453 1060 tcpipreg - ok
11:46:50.0556 1060 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:46:50.0646 1060 TDPIPE - ok
11:46:50.0740 1060 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:46:50.0813 1060 TDTCP - ok
11:46:50.0928 1060 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
11:46:51.0104 1060 tdx - ok
11:46:51.0167 1060 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
11:46:51.0179 1060 TermDD - ok
11:46:51.0304 1060 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
11:46:51.0316 1060 truecrypt - ok
11:46:51.0393 1060 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:46:51.0465 1060 tssecsrv - ok
11:46:51.0552 1060 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
11:46:51.0608 1060 tunnel - ok
11:46:51.0616 1060 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:46:51.0643 1060 uagp35 - ok
11:46:51.0666 1060 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
11:46:51.0714 1060 udfs - ok
11:46:51.0729 1060 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
11:46:51.0756 1060 uliagpkx - ok
11:46:51.0772 1060 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
11:46:51.0809 1060 umbus - ok
11:46:51.0817 1060 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:46:51.0845 1060 UmPass - ok
11:46:51.0876 1060 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
11:46:51.0928 1060 usbccgp - ok
11:46:51.0944 1060 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
11:46:51.0962 1060 usbcir - ok
11:46:51.0992 1060 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
11:46:52.0026 1060 usbehci - ok
11:46:52.0068 1060 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
11:46:52.0109 1060 usbhub - ok
11:46:52.0148 1060 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
11:46:52.0190 1060 usbohci - ok
11:46:52.0214 1060 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:46:52.0251 1060 usbprint - ok
11:46:52.0279 1060 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:46:52.0303 1060 USBSTOR - ok
11:46:52.0340 1060 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
11:46:52.0369 1060 usbuhci - ok
11:46:52.0395 1060 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
11:46:52.0436 1060 vdrvroot - ok
11:46:52.0447 1060 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:46:52.0464 1060 vga - ok
11:46:52.0477 1060 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:46:52.0538 1060 VgaSave - ok
11:46:52.0549 1060 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
11:46:52.0582 1060 vhdmp - ok
11:46:52.0590 1060 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
11:46:52.0616 1060 viaide - ok
11:46:52.0684 1060 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
11:46:52.0789 1060 vmbus - ok
11:46:52.0815 1060 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
11:46:52.0853 1060 VMBusHID - ok
11:46:52.0899 1060 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
11:46:52.0923 1060 vmci - ok
11:46:52.0948 1060 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
11:46:52.0972 1060 VMnetAdapter - ok
11:46:53.0000 1060 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
11:46:53.0023 1060 VMnetBridge - ok
11:46:53.0075 1060 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
11:46:53.0084 1060 VMnetuserif - ok
11:46:53.0155 1060 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
11:46:53.0164 1060 vmx86 - ok
11:46:53.0226 1060 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
11:46:53.0267 1060 volmgr - ok
11:46:53.0298 1060 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
11:46:53.0318 1060 volmgrx - ok
11:46:53.0344 1060 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
11:46:53.0410 1060 volsnap - ok
11:46:53.0444 1060 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
11:46:53.0545 1060 vpcbus - ok
11:46:53.0586 1060 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:46:53.0613 1060 vpcnfltr - ok
11:46:53.0685 1060 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
11:46:53.0769 1060 vpcusb - ok
11:46:53.0823 1060 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
11:46:53.0837 1060 vpcvmm - ok
11:46:53.0892 1060 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:46:53.0922 1060 vsmraid - ok
11:46:53.0947 1060 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:46:53.0979 1060 vwifibus - ok
11:46:54.0005 1060 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
11:46:54.0040 1060 vwififlt - ok
11:46:54.0074 1060 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:46:54.0173 1060 WacomPen - ok
11:46:54.0280 1060 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:46:54.0352 1060 WANARP - ok
11:46:54.0357 1060 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:46:54.0394 1060 Wanarpv6 - ok
11:46:54.0435 1060 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:46:54.0449 1060 Wd - ok
11:46:54.0479 1060 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:46:54.0506 1060 Wdf01000 - ok
11:46:54.0565 1060 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:46:54.0632 1060 WfpLwf - ok
11:46:54.0653 1060 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:46:54.0687 1060 WIMMount - ok
11:46:54.0764 1060 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
11:46:54.0807 1060 WmiAcpi - ok
11:46:54.0838 1060 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:46:54.0894 1060 ws2ifsl - ok
11:46:54.0944 1060 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
11:46:54.0987 1060 WSDPrintDevice - ok
11:46:55.0024 1060 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
11:46:55.0098 1060 WudfPf - ok
11:46:55.0169 1060 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:46:55.0229 1060 WUDFRd - ok
11:46:55.0307 1060 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
11:46:55.0327 1060 yukonw7 - ok
11:46:55.0387 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
11:46:55.0496 1060 \Device\Harddisk5\DR5 - ok
11:46:55.0500 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
11:46:55.0612 1060 \Device\Harddisk6\DR6 - ok
11:46:55.0623 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
11:46:55.0838 1060 \Device\Harddisk0\DR0 - ok
11:46:55.0842 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
11:46:55.0906 1060 \Device\Harddisk1\DR1 - ok
11:46:55.0924 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
11:46:56.0393 1060 \Device\Harddisk2\DR2 - ok
11:46:56.0397 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk4\DR4
11:46:56.0447 1060 \Device\Harddisk4\DR4 - ok
11:46:56.0514 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk3\DR3
11:46:56.0649 1060 \Device\Harddisk3\DR3 - ok
11:46:56.0696 1060 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk7\DR7
11:46:56.0838 1060 \Device\Harddisk7\DR7 - ok
11:46:56.0842 1060 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
11:46:56.0842 1060 \Device\Harddisk5\DR5\Partition0 - ok
11:46:56.0852 1060 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
11:46:56.0853 1060 \Device\Harddisk6\DR6\Partition0 - ok
11:46:56.0857 1060 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
11:46:56.0857 1060 \Device\Harddisk0\DR0\Partition0 - ok
11:46:56.0874 1060 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
11:46:56.0875 1060 \Device\Harddisk0\DR0\Partition1 - ok
11:46:56.0878 1060 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
11:46:56.0879 1060 \Device\Harddisk1\DR1\Partition0 - ok
11:46:56.0893 1060 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
11:46:56.0894 1060 \Device\Harddisk2\DR2\Partition0 - ok
11:46:56.0906 1060 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
11:46:56.0907 1060 \Device\Harddisk2\DR2\Partition1 - ok
11:46:56.0923 1060 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
11:46:56.0923 1060 \Device\Harddisk2\DR2\Partition2 - ok
11:46:56.0927 1060 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
11:46:56.0928 1060 \Device\Harddisk4\DR4\Partition0 - ok
11:46:56.0932 1060 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
11:46:56.0933 1060 \Device\Harddisk3\DR3\Partition0 - ok
11:46:56.0937 1060 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
11:46:56.0938 1060 \Device\Harddisk3\DR3\Partition1 - ok
11:46:56.0942 1060 Boot (0x1200) (25ff27d159e9969e1e7185601b29aff5) \Device\Harddisk7\DR7\Partition0
11:46:56.0944 1060 \Device\Harddisk7\DR7\Partition0 - ok
11:46:56.0944 1060 ============================================================
11:46:56.0944 1060 Scan finished
11:46:56.0944 1060 ============================================================
11:46:56.0960 1120 Detected object count: 0
11:46:56.0960 1120 Actual detected object count: 0
11:48:04.0523 3168 Deinitialize success
LOG:
11:45:54.0092 4284 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
11:45:54.0663 4284 ============================================================
11:45:54.0663 4284 Current date / time: 2012/01/08 11:45:54.0663
11:45:54.0663 4284 SystemInfo:
11:45:54.0663 4284
11:45:54.0663 4284 OS Version: 6.1.7600 ServicePack: 0.0
11:45:54.0663 4284 Product type: Workstation
11:45:54.0663 4284 ComputerName: COHENW7
11:45:54.0663 4284 UserName: Jakub
11:45:54.0663 4284 Windows directory: C:\Windows
11:45:54.0663 4284 System windows directory: C:\Windows
11:45:54.0663 4284 Running under WOW64
11:45:54.0663 4284 Processor architecture: Intel x64
11:45:54.0663 4284 Number of processors: 4
11:45:54.0663 4284 Page size: 0x1000
11:45:54.0663 4284 Boot type: Normal boot
11:45:54.0663 4284 ============================================================
11:45:56.0686 4284 Initialize success
11:46:02.0926 1060 ============================================================
11:46:02.0926 1060 Scan started
11:46:02.0926 1060 Mode: Manual; SigCheck; TDLFS;
11:46:02.0926 1060 ============================================================
11:46:04.0299 1060 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
11:46:04.0381 1060 1394ohci - ok
11:46:04.0408 1060 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
11:46:04.0424 1060 ACPI - ok
11:46:04.0442 1060 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
11:46:04.0518 1060 AcpiPmi - ok
11:46:04.0544 1060 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:46:04.0592 1060 adp94xx - ok
11:46:04.0625 1060 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:46:04.0670 1060 adpahci - ok
11:46:04.0693 1060 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:46:04.0708 1060 adpu320 - ok
11:46:04.0763 1060 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
11:46:04.0838 1060 AFD - ok
11:46:04.0853 1060 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
11:46:04.0883 1060 agp440 - ok
11:46:04.0913 1060 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
11:46:04.0947 1060 aliide - ok
11:46:04.0953 1060 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
11:46:04.0979 1060 amdide - ok
11:46:04.0987 1060 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:46:05.0032 1060 AmdK8 - ok
11:46:05.0044 1060 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:46:05.0097 1060 AmdPPM - ok
11:46:05.0119 1060 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
11:46:05.0161 1060 amdsata - ok
11:46:05.0170 1060 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:46:05.0204 1060 amdsbs - ok
11:46:05.0341 1060 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
11:46:05.0366 1060 amdxata - ok
11:46:05.0549 1060 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
11:46:06.0047 1060 AppID - ok
11:46:06.0193 1060 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:46:06.0247 1060 arc - ok
11:46:06.0387 1060 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:46:06.0420 1060 arcsas - ok
11:46:06.0580 1060 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:46:07.0869 1060 AsyncMac - ok
11:46:07.0998 1060 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
11:46:08.0007 1060 atapi - ok
11:46:08.0661 1060 atikmdag (aeae4abe6419923c037a0b2a157e1fc6) C:\Windows\system32\DRIVERS\atikmdag.sys
11:46:08.0846 1060 atikmdag - ok
11:46:09.0052 1060 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:46:09.0170 1060 b06bdrv - ok
11:46:09.0346 1060 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:46:09.0436 1060 b57nd60a - ok
11:46:09.0610 1060 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:46:09.0675 1060 Beep - ok
11:46:09.0860 1060 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:46:09.0911 1060 blbdrive - ok
11:46:10.0071 1060 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
11:46:10.0211 1060 bowser - ok
11:46:10.0350 1060 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:46:10.0404 1060 BrFiltLo - ok
11:46:10.0508 1060 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:46:10.0544 1060 BrFiltUp - ok
11:46:10.0641 1060 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:46:10.0790 1060 Brserid - ok
11:46:10.0896 1060 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:46:11.0028 1060 BrSerWdm - ok
11:46:11.0154 1060 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:46:11.0240 1060 BrUsbMdm - ok
11:46:11.0343 1060 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:46:11.0402 1060 BrUsbSer - ok
11:46:11.0542 1060 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:46:11.0634 1060 BTHMODEM - ok
11:46:11.0754 1060 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:46:11.0821 1060 cdfs - ok
11:46:11.0974 1060 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
11:46:12.0066 1060 cdrom - ok
11:46:12.0263 1060 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:46:12.0298 1060 circlass - ok
11:46:12.0446 1060 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:46:12.0524 1060 CLFS - ok
11:46:12.0755 1060 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:46:12.0840 1060 CmBatt - ok
11:46:12.0964 1060 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
11:46:13.0009 1060 cmdide - ok
11:46:13.0149 1060 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
11:46:13.0262 1060 CNG - ok
11:46:13.0378 1060 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:46:13.0422 1060 Compbatt - ok
11:46:13.0570 1060 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
11:46:13.0650 1060 CompositeBus - ok
11:46:13.0783 1060 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:46:13.0817 1060 crcdisk - ok
11:46:14.0011 1060 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
11:46:14.0166 1060 CSC - ok
11:46:14.0315 1060 CVirtA (44bddeb03c84a1c993c992ffb5700357) C:\Windows\system32\DRIVERS\CVirtA64.sys
11:46:14.0370 1060 CVirtA - ok
11:46:14.0598 1060 CVPNDRVA (cc8e52daa9826064ba464dbe531f2bb5) C:\Windows\system32\Drivers\CVPNDRVA.sys
11:46:14.0609 1060 CVPNDRVA - ok
11:46:14.0813 1060 DELTAII (877c5f051024231f5774bf8184c78d4a) C:\Windows\system32\DRIVERS\MAudioDelta.sys
11:46:14.0838 1060 DELTAII - ok
11:46:14.0977 1060 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
11:46:15.0032 1060 DfsC - ok
11:46:15.0150 1060 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:46:15.0288 1060 discache - ok
11:46:15.0441 1060 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:46:15.0451 1060 Disk - ok
11:46:15.0616 1060 DNE (05cb5910b3ca6019fc3cca815ee06ffb) C:\Windows\system32\DRIVERS\dne64x.sys
11:46:15.0625 1060 DNE - ok
11:46:15.0778 1060 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:46:15.0838 1060 drmkaud - ok
11:46:16.0118 1060 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
11:46:16.0142 1060 DXGKrnl - ok
11:46:16.0307 1060 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
11:46:16.0331 1060 eamon - ok
11:46:16.0696 1060 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:46:16.0867 1060 ebdrv - ok
11:46:17.0010 1060 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
11:46:17.0033 1060 ehdrv - ok
11:46:17.0275 1060 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:46:17.0371 1060 elxstor - ok
11:46:17.0488 1060 epfwwfpr (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
11:46:17.0497 1060 epfwwfpr - ok
11:46:17.0611 1060 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
11:46:17.0696 1060 ErrDev - ok
11:46:17.0848 1060 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:46:17.0978 1060 exfat - ok
11:46:18.0101 1060 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:46:18.0217 1060 fastfat - ok
11:46:18.0344 1060 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:46:18.0437 1060 fdc - ok
11:46:18.0604 1060 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:46:18.0636 1060 FileInfo - ok
11:46:18.0759 1060 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:46:18.0852 1060 Filetrace - ok
11:46:18.0968 1060 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:46:19.0004 1060 flpydisk - ok
11:46:19.0141 1060 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
11:46:19.0199 1060 FltMgr - ok
11:46:19.0323 1060 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:46:19.0377 1060 FsDepends - ok
11:46:19.0507 1060 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:46:19.0531 1060 Fs_Rec - ok
11:46:19.0692 1060 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:46:19.0751 1060 fvevol - ok
11:46:19.0896 1060 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:46:19.0956 1060 gagp30kx - ok
11:46:20.0109 1060 grmnusb (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
11:46:20.0160 1060 grmnusb - ok
11:46:20.0316 1060 hcmon (edb09f2df76c352b7af56d0b473049d6) C:\Windows\system32\drivers\hcmon.sys
11:46:20.0339 1060 hcmon - ok
11:46:20.0470 1060 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:46:20.0548 1060 hcw85cir - ok
11:46:20.0722 1060 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
11:46:20.0796 1060 HdAudAddService - ok
11:46:20.0982 1060 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
11:46:21.0028 1060 HDAudBus - ok
11:46:21.0170 1060 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:46:21.0260 1060 HidBatt - ok
11:46:21.0376 1060 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:46:21.0447 1060 HidBth - ok
11:46:21.0558 1060 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:46:21.0645 1060 HidIr - ok
11:46:21.0807 1060 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
11:46:21.0859 1060 HidUsb - ok
11:46:22.0035 1060 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
11:46:22.0081 1060 HpSAMD - ok
11:46:22.0253 1060 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
11:46:22.0372 1060 HTTP - ok
11:46:22.0491 1060 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
11:46:22.0516 1060 hwpolicy - ok
11:46:22.0669 1060 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
11:46:22.0731 1060 i8042prt - ok
11:46:22.0996 1060 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
11:46:23.0115 1060 iaStorV - ok
11:46:23.0267 1060 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:46:23.0311 1060 iirsp - ok
11:46:23.0425 1060 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
11:46:23.0455 1060 intelide - ok
11:46:23.0598 1060 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:46:23.0647 1060 intelppm - ok
11:46:23.0790 1060 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:46:23.0884 1060 IpFilterDriver - ok
11:46:23.0989 1060 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
11:46:24.0056 1060 IPMIDRV - ok
11:46:24.0164 1060 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:46:24.0249 1060 IPNAT - ok
11:46:24.0358 1060 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:46:24.0395 1060 IRENUM - ok
11:46:24.0511 1060 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
11:46:24.0556 1060 isapnp - ok
11:46:24.0685 1060 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
11:46:24.0797 1060 iScsiPrt - ok
11:46:24.0933 1060 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
11:46:24.0945 1060 kbdclass - ok
11:46:25.0055 1060 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
11:46:25.0105 1060 kbdhid - ok
11:46:25.0238 1060 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
11:46:25.0309 1060 KSecDD - ok
11:46:25.0435 1060 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
11:46:25.0467 1060 KSecPkg - ok
11:46:25.0615 1060 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:46:25.0677 1060 ksthunk - ok
11:46:25.0865 1060 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:46:25.0975 1060 lltdio - ok
11:46:26.0123 1060 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:46:26.0181 1060 LSI_FC - ok
11:46:26.0299 1060 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:46:26.0344 1060 LSI_SAS - ok
11:46:26.0482 1060 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:46:26.0526 1060 LSI_SAS2 - ok
11:46:26.0650 1060 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:46:26.0701 1060 LSI_SCSI - ok
11:46:26.0824 1060 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:46:26.0896 1060 luafv - ok
11:46:27.0097 1060 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
11:46:27.0180 1060 MarvinBus - ok
11:46:27.0284 1060 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:46:27.0344 1060 megasas - ok
11:46:27.0463 1060 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:46:27.0567 1060 MegaSR - ok
11:46:27.0679 1060 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:46:27.0770 1060 Modem - ok
11:46:27.0895 1060 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:46:27.0943 1060 monitor - ok
11:46:28.0073 1060 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:46:28.0084 1060 mouclass - ok
11:46:28.0193 1060 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:46:28.0243 1060 mouhid - ok
11:46:28.0356 1060 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
11:46:28.0414 1060 mountmgr - ok
11:46:28.0526 1060 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
11:46:28.0570 1060 mpio - ok
11:46:28.0664 1060 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:46:28.0761 1060 mpsdrv - ok
11:46:28.0932 1060 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
11:46:29.0043 1060 MRxDAV - ok
11:46:29.0174 1060 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:46:29.0283 1060 mrxsmb - ok
11:46:29.0429 1060 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:46:29.0518 1060 mrxsmb10 - ok
11:46:29.0662 1060 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:46:29.0728 1060 mrxsmb20 - ok
11:46:29.0839 1060 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
11:46:29.0864 1060 msahci - ok
11:46:29.0970 1060 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
11:46:30.0032 1060 msdsm - ok
11:46:30.0145 1060 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:46:30.0200 1060 Msfs - ok
11:46:30.0291 1060 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:46:30.0378 1060 mshidkmdf - ok
11:46:30.0486 1060 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
11:46:30.0511 1060 msisadrv - ok
11:46:30.0704 1060 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:46:30.0776 1060 MSKSSRV - ok
11:46:30.0913 1060 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:46:30.0996 1060 MSPCLOCK - ok
11:46:31.0161 1060 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:46:31.0244 1060 MSPQM - ok
11:46:31.0487 1060 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
11:46:31.0556 1060 MsRPC - ok
11:46:31.0753 1060 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
11:46:31.0763 1060 mssmbios - ok
11:46:32.0230 1060 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:46:32.0342 1060 MSTEE - ok
11:46:32.0556 1060 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:46:32.0652 1060 MTConfig - ok
11:46:32.0988 1060 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
11:46:33.0090 1060 MTsensor - ok
11:46:33.0279 1060 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:46:33.0305 1060 Mup - ok
11:46:33.0513 1060 mv91cons (6af2640b5d7202fa0d96467318d4592e) C:\Windows\system32\DRIVERS\mv91cons.sys
11:46:33.0521 1060 mv91cons - ok
11:46:33.0732 1060 mv91xx (8db5861a8db19abaf430fcd001ef5e93) C:\Windows\system32\DRIVERS\mv91xx.sys
11:46:33.0742 1060 mv91xx - ok
11:46:33.0965 1060 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:46:34.0077 1060 NativeWifiP - ok
11:46:34.0396 1060 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
11:46:34.0458 1060 NDIS - ok
11:46:34.0555 1060 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:46:34.0645 1060 NdisCap - ok
11:46:34.0801 1060 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:46:34.0906 1060 NdisTapi - ok
11:46:35.0075 1060 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
11:46:35.0155 1060 Ndisuio - ok
11:46:35.0279 1060 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
11:46:35.0408 1060 NdisWan - ok
11:46:35.0532 1060 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
11:46:35.0635 1060 NDProxy - ok
11:46:35.0725 1060 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:46:35.0809 1060 NetBIOS - ok
11:46:35.0911 1060 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
11:46:36.0009 1060 NetBT - ok
11:46:36.0195 1060 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:46:36.0236 1060 nfrd960 - ok
11:46:36.0366 1060 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:46:36.0455 1060 Npfs - ok
11:46:36.0604 1060 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:46:36.0696 1060 nsiproxy - ok
11:46:36.0957 1060 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
11:46:37.0099 1060 Ntfs - ok
11:46:37.0223 1060 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:46:37.0288 1060 Null - ok
11:46:37.0469 1060 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
11:46:37.0580 1060 nvraid - ok
11:46:37.0733 1060 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
11:46:37.0832 1060 nvstor - ok
11:46:37.0950 1060 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
11:46:38.0003 1060 nv_agp - ok
11:46:38.0169 1060 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
11:46:38.0238 1060 ohci1394 - ok
11:46:38.0639 1060 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:46:38.0668 1060 Parport - ok
11:46:38.0791 1060 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
11:46:38.0825 1060 partmgr - ok
11:46:38.0986 1060 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
11:46:39.0028 1060 pci - ok
11:46:39.0155 1060 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
11:46:39.0179 1060 pciide - ok
11:46:39.0312 1060 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:46:39.0377 1060 pcmcia - ok
11:46:39.0464 1060 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:46:39.0490 1060 pcw - ok
11:46:39.0640 1060 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:46:39.0744 1060 PEAUTH - ok
11:46:39.0909 1060 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
11:46:39.0991 1060 PptpMiniport - ok
11:46:40.0122 1060 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:46:40.0181 1060 Processor - ok
11:46:40.0342 1060 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
11:46:40.0408 1060 Psched - ok
11:46:40.0644 1060 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:46:40.0749 1060 ql2300 - ok
11:46:40.0874 1060 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:46:40.0909 1060 ql40xx - ok
11:46:41.0089 1060 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:46:41.0180 1060 QWAVEdrv - ok
11:46:41.0347 1060 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:46:41.0405 1060 RasAcd - ok
11:46:41.0606 1060 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:46:41.0715 1060 RasAgileVpn - ok
11:46:41.0893 1060 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:46:41.0975 1060 Rasl2tp - ok
11:46:42.0045 1060 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:46:42.0119 1060 RasPppoe - ok
11:46:42.0253 1060 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:46:42.0333 1060 RasSstp - ok
11:46:42.0452 1060 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
11:46:42.0561 1060 rdbss - ok
11:46:42.0660 1060 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:46:42.0720 1060 rdpbus - ok
11:46:42.0848 1060 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:46:42.0911 1060 RDPCDD - ok
11:46:43.0099 1060 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
11:46:43.0227 1060 RDPDR - ok
11:46:43.0371 1060 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:46:43.0426 1060 RDPENCDD - ok
11:46:43.0530 1060 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:46:43.0571 1060 RDPREFMP - ok
11:46:43.0676 1060 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
11:46:43.0781 1060 RDPWD - ok
11:46:43.0882 1060 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
11:46:43.0942 1060 rdyboost - ok
11:46:44.0075 1060 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
11:46:44.0141 1060 RimUsb - ok
11:46:44.0286 1060 RsFx0103 (cd553b8633466a6d1c115812f2619f1f) C:\Windows\system32\DRIVERS\RsFx0103.sys
11:46:44.0374 1060 RsFx0103 - ok
11:46:44.0532 1060 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:46:44.0623 1060 rspndr - ok
11:46:44.0780 1060 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
11:46:44.0855 1060 RTL8167 - ok
11:46:45.0050 1060 RTL8187 (333224d4d25f9bcca488e08345083e1c) C:\Windows\system32\DRIVERS\rtl8187.sys
11:46:45.0156 1060 RTL8187 - ok
11:46:45.0272 1060 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
11:46:45.0357 1060 s3cap - ok
11:46:45.0458 1060 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
11:46:45.0490 1060 sbp2port - ok
11:46:45.0651 1060 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
11:46:45.0676 1060 SCDEmu - ok
11:46:45.0815 1060 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
11:46:45.0901 1060 scfilter - ok
11:46:46.0061 1060 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:46:46.0134 1060 secdrv - ok
11:46:46.0277 1060 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:46:46.0321 1060 Serenum - ok
11:46:46.0458 1060 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:46:46.0533 1060 Serial - ok
11:46:46.0749 1060 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:46:46.0818 1060 sermouse - ok
11:46:46.0948 1060 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
11:46:47.0044 1060 sffdisk - ok
11:46:47.0138 1060 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
11:46:47.0204 1060 sffp_mmc - ok
11:46:47.0287 1060 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
11:46:47.0325 1060 sffp_sd - ok
11:46:47.0420 1060 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:46:47.0509 1060 sfloppy - ok
11:46:47.0630 1060 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:46:47.0718 1060 SiSRaid2 - ok
11:46:47.0853 1060 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:46:47.0893 1060 SiSRaid4 - ok
11:46:48.0012 1060 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:46:48.0106 1060 Smb - ok
11:46:48.0217 1060 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:46:48.0242 1060 spldr - ok
11:46:48.0444 1060 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
11:46:48.0540 1060 srv - ok
11:46:48.0705 1060 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
11:46:48.0809 1060 srv2 - ok
11:46:48.0933 1060 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
11:46:48.0994 1060 srvnet - ok
11:46:49.0143 1060 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:46:49.0176 1060 stexstor - ok
11:46:49.0271 1060 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
11:46:49.0281 1060 storflt - ok
11:46:49.0319 1060 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
11:46:49.0345 1060 storvsc - ok
11:46:49.0385 1060 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
11:46:49.0410 1060 swenum - ok
11:46:50.0002 1060 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
11:46:50.0090 1060 Tcpip - ok
11:46:50.0290 1060 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
11:46:50.0324 1060 TCPIP6 - ok
11:46:50.0420 1060 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
11:46:50.0453 1060 tcpipreg - ok
11:46:50.0556 1060 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:46:50.0646 1060 TDPIPE - ok
11:46:50.0740 1060 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:46:50.0813 1060 TDTCP - ok
11:46:50.0928 1060 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
11:46:51.0104 1060 tdx - ok
11:46:51.0167 1060 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
11:46:51.0179 1060 TermDD - ok
11:46:51.0304 1060 truecrypt (8de922cd4fea6f83b10805df965b9a08) C:\Windows\system32\drivers\truecrypt.sys
11:46:51.0316 1060 truecrypt - ok
11:46:51.0393 1060 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:46:51.0465 1060 tssecsrv - ok
11:46:51.0552 1060 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
11:46:51.0608 1060 tunnel - ok
11:46:51.0616 1060 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:46:51.0643 1060 uagp35 - ok
11:46:51.0666 1060 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
11:46:51.0714 1060 udfs - ok
11:46:51.0729 1060 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
11:46:51.0756 1060 uliagpkx - ok
11:46:51.0772 1060 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
11:46:51.0809 1060 umbus - ok
11:46:51.0817 1060 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:46:51.0845 1060 UmPass - ok
11:46:51.0876 1060 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
11:46:51.0928 1060 usbccgp - ok
11:46:51.0944 1060 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
11:46:51.0962 1060 usbcir - ok
11:46:51.0992 1060 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
11:46:52.0026 1060 usbehci - ok
11:46:52.0068 1060 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
11:46:52.0109 1060 usbhub - ok
11:46:52.0148 1060 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
11:46:52.0190 1060 usbohci - ok
11:46:52.0214 1060 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:46:52.0251 1060 usbprint - ok
11:46:52.0279 1060 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:46:52.0303 1060 USBSTOR - ok
11:46:52.0340 1060 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
11:46:52.0369 1060 usbuhci - ok
11:46:52.0395 1060 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
11:46:52.0436 1060 vdrvroot - ok
11:46:52.0447 1060 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:46:52.0464 1060 vga - ok
11:46:52.0477 1060 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:46:52.0538 1060 VgaSave - ok
11:46:52.0549 1060 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
11:46:52.0582 1060 vhdmp - ok
11:46:52.0590 1060 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
11:46:52.0616 1060 viaide - ok
11:46:52.0684 1060 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
11:46:52.0789 1060 vmbus - ok
11:46:52.0815 1060 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
11:46:52.0853 1060 VMBusHID - ok
11:46:52.0899 1060 vmci (69f38919ff1510560d67f9a0b2375b01) C:\Windows\system32\drivers\vmci.sys
11:46:52.0923 1060 vmci - ok
11:46:52.0948 1060 VMnetAdapter (3c37a81c995aee1802c9d8dd9ea0e835) C:\Windows\system32\DRIVERS\vmnetadapter.sys
11:46:52.0972 1060 VMnetAdapter - ok
11:46:53.0000 1060 VMnetBridge (d3b25ed3a6796fe3078475d8cfcd6024) C:\Windows\system32\DRIVERS\vmnetbridge.sys
11:46:53.0023 1060 VMnetBridge - ok
11:46:53.0075 1060 VMnetuserif (ea48bef5bc53d6cb5fec8f9be088b337) C:\Windows\system32\drivers\vmnetuserif.sys
11:46:53.0084 1060 VMnetuserif - ok
11:46:53.0155 1060 vmx86 (1286147733e31fe4e40237eb289cd7a8) C:\Windows\system32\drivers\vmx86.sys
11:46:53.0164 1060 vmx86 - ok
11:46:53.0226 1060 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
11:46:53.0267 1060 volmgr - ok
11:46:53.0298 1060 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
11:46:53.0318 1060 volmgrx - ok
11:46:53.0344 1060 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
11:46:53.0410 1060 volsnap - ok
11:46:53.0444 1060 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\Windows\system32\DRIVERS\vpchbus.sys
11:46:53.0545 1060 vpcbus - ok
11:46:53.0586 1060 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:46:53.0613 1060 vpcnfltr - ok
11:46:53.0685 1060 vpcusb (31924e31bc315773e6d149b157db46d5) C:\Windows\system32\DRIVERS\vpcusb.sys
11:46:53.0769 1060 vpcusb - ok
11:46:53.0823 1060 vpcvmm (c5b651e52540e6f46da66574c74b4898) C:\Windows\system32\drivers\vpcvmm.sys
11:46:53.0837 1060 vpcvmm - ok
11:46:53.0892 1060 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:46:53.0922 1060 vsmraid - ok
11:46:53.0947 1060 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:46:53.0979 1060 vwifibus - ok
11:46:54.0005 1060 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
11:46:54.0040 1060 vwififlt - ok
11:46:54.0074 1060 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:46:54.0173 1060 WacomPen - ok
11:46:54.0280 1060 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:46:54.0352 1060 WANARP - ok
11:46:54.0357 1060 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
11:46:54.0394 1060 Wanarpv6 - ok
11:46:54.0435 1060 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:46:54.0449 1060 Wd - ok
11:46:54.0479 1060 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:46:54.0506 1060 Wdf01000 - ok
11:46:54.0565 1060 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:46:54.0632 1060 WfpLwf - ok
11:46:54.0653 1060 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:46:54.0687 1060 WIMMount - ok
11:46:54.0764 1060 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
11:46:54.0807 1060 WmiAcpi - ok
11:46:54.0838 1060 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:46:54.0894 1060 ws2ifsl - ok
11:46:54.0944 1060 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
11:46:54.0987 1060 WSDPrintDevice - ok
11:46:55.0024 1060 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
11:46:55.0098 1060 WudfPf - ok
11:46:55.0169 1060 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:46:55.0229 1060 WUDFRd - ok
11:46:55.0307 1060 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys
11:46:55.0327 1060 yukonw7 - ok
11:46:55.0387 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk5\DR5
11:46:55.0496 1060 \Device\Harddisk5\DR5 - ok
11:46:55.0500 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk6\DR6
11:46:55.0612 1060 \Device\Harddisk6\DR6 - ok
11:46:55.0623 1060 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
11:46:55.0838 1060 \Device\Harddisk0\DR0 - ok
11:46:55.0842 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
11:46:55.0906 1060 \Device\Harddisk1\DR1 - ok
11:46:55.0924 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
11:46:56.0393 1060 \Device\Harddisk2\DR2 - ok
11:46:56.0397 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk4\DR4
11:46:56.0447 1060 \Device\Harddisk4\DR4 - ok
11:46:56.0514 1060 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk3\DR3
11:46:56.0649 1060 \Device\Harddisk3\DR3 - ok
11:46:56.0696 1060 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk7\DR7
11:46:56.0838 1060 \Device\Harddisk7\DR7 - ok
11:46:56.0842 1060 Boot (0x1200) (263664c25b8a666b6301c9fcb2732a2d) \Device\Harddisk5\DR5\Partition0
11:46:56.0842 1060 \Device\Harddisk5\DR5\Partition0 - ok
11:46:56.0852 1060 Boot (0x1200) (1d6e1a18e1961252959e4ad4b0447b30) \Device\Harddisk6\DR6\Partition0
11:46:56.0853 1060 \Device\Harddisk6\DR6\Partition0 - ok
11:46:56.0857 1060 Boot (0x1200) (960107f34bd15344ba47bfa2a1a564c6) \Device\Harddisk0\DR0\Partition0
11:46:56.0857 1060 \Device\Harddisk0\DR0\Partition0 - ok
11:46:56.0874 1060 Boot (0x1200) (60664df79229a136dd76a7007b408d6b) \Device\Harddisk0\DR0\Partition1
11:46:56.0875 1060 \Device\Harddisk0\DR0\Partition1 - ok
11:46:56.0878 1060 Boot (0x1200) (c964dda21943ac7dcd7c2751b48b460b) \Device\Harddisk1\DR1\Partition0
11:46:56.0879 1060 \Device\Harddisk1\DR1\Partition0 - ok
11:46:56.0893 1060 Boot (0x1200) (1918f1dc6ba9c7f102168c3438f5e6c6) \Device\Harddisk2\DR2\Partition0
11:46:56.0894 1060 \Device\Harddisk2\DR2\Partition0 - ok
11:46:56.0906 1060 Boot (0x1200) (bfa2c1fe89c8947cce6440aa587f8896) \Device\Harddisk2\DR2\Partition1
11:46:56.0907 1060 \Device\Harddisk2\DR2\Partition1 - ok
11:46:56.0923 1060 Boot (0x1200) (4d0b58bb1dc13718a5d396f3fdc4779c) \Device\Harddisk2\DR2\Partition2
11:46:56.0923 1060 \Device\Harddisk2\DR2\Partition2 - ok
11:46:56.0927 1060 Boot (0x1200) (24e8464cbbf1ed284104b6c4285c9887) \Device\Harddisk4\DR4\Partition0
11:46:56.0928 1060 \Device\Harddisk4\DR4\Partition0 - ok
11:46:56.0932 1060 Boot (0x1200) (872deff883661f1ae33a696ba2eacc1d) \Device\Harddisk3\DR3\Partition0
11:46:56.0933 1060 \Device\Harddisk3\DR3\Partition0 - ok
11:46:56.0937 1060 Boot (0x1200) (d69883444eeed4b4e8867bc85e6b9a4e) \Device\Harddisk3\DR3\Partition1
11:46:56.0938 1060 \Device\Harddisk3\DR3\Partition1 - ok
11:46:56.0942 1060 Boot (0x1200) (25ff27d159e9969e1e7185601b29aff5) \Device\Harddisk7\DR7\Partition0
11:46:56.0944 1060 \Device\Harddisk7\DR7\Partition0 - ok
11:46:56.0944 1060 ============================================================
11:46:56.0944 1060 Scan finished
11:46:56.0944 1060 ============================================================
11:46:56.0960 1120 Detected object count: 0
11:46:56.0960 1120 Actual detected object count: 0
11:48:04.0523 3168 Deinitialize success
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Asi to je hloupa otazka, ale nevite jak vypnu eset nod 32? Pouzivam jen windows firewall, mam jej vypnout take?
Dekuji.
Dekuji.
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Odpovim si sam v detailnim navodu je odkaz na stranku kde je navod jak vypnout anitviry a firewally.
http://www.bleepingcomputer.com/forums/topic114351.html
http://www.bleepingcomputer.com/forums/topic114351.html
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
Log:
ComboFix 12-01-07.03 - Jakub 08.01.2012 12:19:17.1.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4095.2359 [GMT 1:00]
Spuštěný z: c:\users\Jakub\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\mazuki.dll
c:\users\Jakub\AppData\Roaming\Microsoft\Windows\Recent\How To Solve Sudoku Puzzles - Sudoku - How To Solve Sudoku Puzzles - Sudoku Video Tutorials - Sudoku Solving Techniques'These Sudoku Video Tutorials are the.url
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\java.exe
S:\Autorun.inf
S:\Setup.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-08 do 2012-01-08 )))))))))))))))))))))))))))))))
.
.
2012-01-08 11:27 . 2012-01-08 11:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-08 11:27 . 2012-01-08 11:27 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-01-08 10:45 . 2012-01-08 10:45 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\offreg.dll
2012-01-08 09:00 . 2012-01-08 09:09 -------- d-----w- c:\program files\trend micro
2012-01-08 09:00 . 2012-01-08 09:24 -------- d-----w- C:\rsit
2012-01-06 18:09 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\mpengine.dll
2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\program files\Microsoft Games
2011-12-26 22:04 . 2011-12-26 22:21 -------- d-----w- c:\users\Jakub\AppData\Roaming\Mumble
2011-12-26 22:04 . 2011-12-26 22:04 -------- d-----w- c:\users\Jakub\AppData\Local\Mumble
2011-12-26 22:03 . 2011-12-26 22:03 -------- d-----w- c:\program files (x86)\Mumble
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\users\Jakub\Calibre knihovna
2011-12-26 10:25 . 2011-12-26 12:04 -------- d-----w- c:\users\Jakub\AppData\Roaming\calibre
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\program files (x86)\Calibre2
2011-12-18 13:06 . 2011-12-18 18:42 -------- d-----w- c:\users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 12:37 . 2011-12-18 12:37 -------- d-----w- c:\programdata\Apple Computer
2011-12-18 12:35 . 2011-12-18 12:35 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-12-18 12:34 . 2011-12-18 12:34 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-12-18 10:34 . 2011-12-18 10:34 -------- d-----w- c:\users\Jakub\AppData\Local\Apple Computer
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\users\Jakub\AppData\Local\Apple
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\programdata\Apple
2011-12-16 09:53 . 2011-12-16 09:53 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2011-12-16 09:53 . 2011-12-16 09:53 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2011-12-14 11:11 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 11:11 . 2011-11-05 05:26 1197568 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 11:11 . 2011-11-05 04:35 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-12-12 20:27 . 2011-12-12 20:27 -------- d-----w- c:\program files (x86)\Edgard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 13:29 . 2010-03-07 06:46 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-28 17:58 . 2011-10-28 17:58 230864 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-05-13 26192168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"="c:\windows\system32\DeltaIITray.exe" [2009-07-27 236040]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"MRUTray"="c:\program files (x86)\Marvell\raid\tray\MarvellTray.exe" [2010-04-12 731176]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SC2RAR - Shortcut.lnk - c:\sc2raru10\SC2RAR\SC2RAR.exe [2010-12-15 76800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener;c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
R3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
R3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08);c:\program files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
R3 MSSQL$SQL08;SQL Server (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
R3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
R3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent;c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent;k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleServiceORCL11;OracleServiceORCL11;k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL11 [x]
R3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service;c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL [x]
R3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service;k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL11 [x]
R3 ReportServer$SQL08;SQL Server Reporting Services (SQL08);c:\program files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
R3 SQLAgent$SQL08;SQL Server Agent (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
R4 OracleJobSchedulerORCL;OracleJobSchedulerORCL;c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL [x]
R4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11;k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL11 [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 Marvell RAID;Marvell RAID Event Agent;c:\program files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
S2 MRUWebService;MRU Web Service;c:\program files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
S2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener;k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
S2 OracleServiceORCL;OracleServiceORCL;c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMwareHostd;VMware Host Agent;c:\program files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
S2 VMwareServerWebAccess;VMware Server Web Access;c:\program files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\DRIVERS\MAudioDelta.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [x]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 86165092
*Deregistered* - 86165092
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 18:55]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 18:55]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\VMware\VMware Server\vsocklib.dll
Trusted Zone: cohenw7
TCP: DhcpNameServer = 192.168.10.1
Handler: qcom - {B8DBD265-42C3-43e6-B439-E968C71984C6} - c:\common~1\QUESTS~1\CODEXP~1\qcom.dll
DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574}
DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF}
FF - ProfilePath - c:\users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Digital Music Notebook: {0493D792-5C92-440b-81A8-AD6CDFC75212} - c:\program files (x86)\Yamaha Corporation\Digital Music Notebook\Common\Bootstrapper\XpCom
.
.
------- Asociace souborů -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1ClrAgent]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:c:\app\Jakub\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2ClrAgent]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:k:\oracle\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1TNSListener]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2TNSListener]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-01-08 12:30:11
ComboFix-quarantined-files.txt 2012-01-08 11:30
.
Před spuštěním: 32 319 549 440 bytes free
Po spuštění: 102 770 868 224 bytes free
.
- - End Of File - - 33B83CC52DDF9527C6C1DE72F778294F
ComboFix 12-01-07.03 - Jakub 08.01.2012 12:19:17.1.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1033.18.4095.2359 [GMT 1:00]
Spuštěný z: c:\users\Jakub\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\mazuki.dll
c:\users\Jakub\AppData\Roaming\Microsoft\Windows\Recent\How To Solve Sudoku Puzzles - Sudoku - How To Solve Sudoku Puzzles - Sudoku Video Tutorials - Sudoku Solving Techniques'These Sudoku Video Tutorials are the.url
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\java.exe
S:\Autorun.inf
S:\Setup.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-08 do 2012-01-08 )))))))))))))))))))))))))))))))
.
.
2012-01-08 11:27 . 2012-01-08 11:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-08 11:27 . 2012-01-08 11:27 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-01-08 10:45 . 2012-01-08 10:45 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\offreg.dll
2012-01-08 09:00 . 2012-01-08 09:09 -------- d-----w- c:\program files\trend micro
2012-01-08 09:00 . 2012-01-08 09:24 -------- d-----w- C:\rsit
2012-01-06 18:09 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43EFDCBF-89C4-4C00-A220-4D629C0AEA78}\mpengine.dll
2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\program files\Microsoft Games
2011-12-26 22:04 . 2011-12-26 22:21 -------- d-----w- c:\users\Jakub\AppData\Roaming\Mumble
2011-12-26 22:04 . 2011-12-26 22:04 -------- d-----w- c:\users\Jakub\AppData\Local\Mumble
2011-12-26 22:03 . 2011-12-26 22:03 -------- d-----w- c:\program files (x86)\Mumble
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\users\Jakub\Calibre knihovna
2011-12-26 10:25 . 2011-12-26 12:04 -------- d-----w- c:\users\Jakub\AppData\Roaming\calibre
2011-12-26 10:25 . 2011-12-26 10:25 -------- d-----w- c:\program files (x86)\Calibre2
2011-12-18 13:06 . 2011-12-18 18:42 -------- d-----w- c:\users\Jakub\AppData\Roaming\Apple Computer
2011-12-18 12:37 . 2011-12-18 12:37 -------- d-----w- c:\programdata\Apple Computer
2011-12-18 12:35 . 2011-12-18 12:35 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-12-18 12:34 . 2011-12-18 12:34 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-12-18 10:34 . 2011-12-18 10:34 -------- d-----w- c:\users\Jakub\AppData\Local\Apple Computer
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\users\Jakub\AppData\Local\Apple
2011-12-18 10:31 . 2011-12-18 10:31 -------- d-----w- c:\programdata\Apple
2011-12-16 09:53 . 2011-12-16 09:53 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2011-12-16 09:53 . 2011-12-16 09:53 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2011-12-14 11:11 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 11:11 . 2011-11-05 05:26 1197568 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 11:11 . 2011-11-05 04:35 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-12-12 20:27 . 2011-12-12 20:27 -------- d-----w- c:\program files (x86)\Edgard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 13:29 . 2010-03-07 06:46 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-28 17:58 . 2011-10-28 17:58 230864 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-05-13 26192168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"M-Audio Taskbar Icon"="c:\windows\system32\DeltaIITray.exe" [2009-07-27 236040]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"MRUTray"="c:\program files (x86)\Marvell\raid\tray\MarvellTray.exe" [2010-04-12 731176]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SC2RAR - Shortcut.lnk - c:\sc2raru10\SC2RAR\SC2RAR.exe [2010-12-15 76800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OracleOraDb11g_home1TNSListener;OracleOraDb11g_home1TNSListener;c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
R3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [2008-07-10 214040]
R3 MSOLAP$SQL08;SQL Server Analysis Services (SQL08);c:\program files\Microsoft SQL Server\MSAS10.SQL08\OLAP\bin\msmdsrv.exe [2009-03-30 43735400]
R3 MSSQL$SQL08;SQL Server (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\sqlservr.exe [2011-02-05 57917288]
R3 MSSQLFDLauncher$SQL08;SQL Full-text Filter Daemon Launcher (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
R3 OracleOraDb11g_home1ClrAgent;OracleOraDb11g_home1ClrAgent;c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleOraDb11g_home2ClrAgent;OracleOraDb11g_home2ClrAgent;k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [2010-03-12 83968]
R3 OracleServiceORCL11;OracleServiceORCL11;k:\oracle\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL11 [x]
R3 OracleVssWriterORCL;Oracle ORCL VSS Writer Service;c:\app\jakub\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL [x]
R3 OracleVssWriterORCL11;Oracle ORCL11 VSS Writer Service;k:\oracle\product\11.2.0\dbhome_1\bin\OraVSSW.exe ORCL11 [x]
R3 ReportServer$SQL08;SQL Server Reporting Services (SQL08);c:\program files\Microsoft SQL Server\MSRS10.SQL08\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2009-03-30 2075480]
R3 SQLAgent$SQL08;SQL Server Agent (SQL08);c:\program files\Microsoft SQL Server\MSSQL10.SQL08\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-07-30 24645]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 61976]
R4 OracleJobSchedulerORCL;OracleJobSchedulerORCL;c:\app\jakub\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL [x]
R4 OracleJobSchedulerORCL11;OracleJobSchedulerORCL11;k:\oracle\product\11.2.0\dbhome_1\Bin\extjob.exe ORCL11 [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 Marvell RAID;Marvell RAID Event Agent;c:\program files (x86)\Marvell\raid\svc\mvraidsvc.exe [2010-04-12 235560]
S2 MRUWebService;MRU Web Service;c:\program files (x86)\Marvell\raid\Apache2\bin\httpd.exe [2008-06-12 24635]
S2 OracleOraDb11g_home2TNSListener;OracleOraDb11g_home2TNSListener;k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR [x]
S2 OracleServiceORCL;OracleServiceORCL;c:\app\jakub\product\11.2.0\dbhome_1\bin\ORACLE.EXE ORCL [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMwareHostd;VMware Host Agent;c:\program files (x86)\VMware\VMware Server\vmware-hostd.exe [2009-10-20 322096]
S2 VMwareServerWebAccess;VMware Server Web Access;c:\program files (x86)\VMware\VMware Server\tomcat\bin\Tomcat6.exe [2009-10-20 57344]
S3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\DRIVERS\MAudioDelta.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [x]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 86165092
*Deregistered* - 86165092
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 18:55]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job
- c:\users\Jakub\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-04 18:55]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\VMware\VMware Server\vsocklib.dll
Trusted Zone: cohenw7
TCP: DhcpNameServer = 192.168.10.1
Handler: qcom - {B8DBD265-42C3-43e6-B439-E968C71984C6} - c:\common~1\QUESTS~1\CODEXP~1\qcom.dll
DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574}
DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF}
FF - ProfilePath - c:\users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\1uba89x8.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Digital Music Notebook: {0493D792-5C92-440b-81A8-AD6CDFC75212} - c:\program files (x86)\Yamaha Corporation\Digital Music Notebook\Common\Bootstrapper\XpCom
.
.
------- Asociace souborů -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1ClrAgent]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:c:\app\Jakub\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2ClrAgent]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS=\"EXTPROC_DLLS=ONLY:k:\oracle\product\11.2.0\dbhome_1\bin\oraclr11.dll\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home1TNSListener]
"ImagePath"="c:\app\Jakub\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\OracleOraDb11g_home2TNSListener]
"ImagePath"="k:\oracle\product\11.2.0\dbhome_1\BIN\TNSLSNR "
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-01-08 12:30:11
ComboFix-quarantined-files.txt 2012-01-08 11:30
.
Před spuštěním: 32 319 549 440 bytes free
Po spuštění: 102 770 868 224 bytes free
.
- - End Of File - - 33B83CC52DDF9527C6C1DE72F778294F
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun

- Stahne a ulozte na plochu UsbFix http://www.viry.cz/forum/viewtopic.php?f=24&t=102308
- Spustte a kliknete na Deletion
- Po dokonceni sem vlozte log, pokud na Vas nevyskoci, najdete jej zde C:\UsbFix.txt
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun
############################## | UsbFix 7.059 | [Deletion]
User: Jakub (Administrator) # COHENW7 [System manufacturer P5K Premium]
Updated 16/09/2011 by El Desaparecido
Started at 13:52:16 | 08/01/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com
CPU: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
CPU 2: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Microsoft Windows 7 Professional (6.1.7600 64-Bit) #
Internet Explorer 8.0.7600.16385
Windows Firewall: Disabled /!\
RAM -> 4095 Mb
C:\ (%systemdrive%) -> Fixed drive # 195 Gb (96 Mb free - 49%) [W7] # NTFS
H:\ -> Fixed drive # 977 Gb (3 Mb free - 0%) [Storage1] # NTFS
I:\ -> Fixed drive # 932 Gb (347 Mb free - 37%) [TB2] # NTFS
J:\ -> Fixed drive # 195 Gb (62 Mb free - 32%) [] # NTFS
K:\ -> Fixed drive # 886 Gb (401 Mb free - 45%) [Storage2] # NTFS
L:\ -> Fixed drive # 932 Gb (1 Mb free - 0%) [TB1] # NTFS
M:\ -> Fixed drive # 488 Gb (254 Mb free - 52%) [Store1] # NTFS
N:\ -> Fixed drive # 443 Gb (82 Mb free - 19%) [Store2] # NTFS
O:\ -> Fixed drive # 1863 Gb (458 Mb free - 25%) [STORAGE_3] # NTFS
P:\ -> Fixed drive # 541 Gb (6 Mb free - 1%) [TEMPSTORAGE] # NTFS
Q:\ -> Fixed drive # 1863 Gb (126 Mb free - 7%) [STORAGE_2] # NTFS
R:\ -> CD-ROM
S:\ -> Fixed drive # 466 Gb (16 Mb free - 4%) [FreeAgent Drive] # NTFS
V:\ -> CD-ROM
W:\ -> Removable drive # 4 Gb (533 Mb free - 14%) [CORSAIR] # FAT32
################## | Files # Infected Folders |
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! I:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! J:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! L:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! M:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! M:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! M:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! N:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! O:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! P:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! Q:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-3287831667-1201800720-717243645-3958
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-345947992-755240569-1322415880-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-4001789067-1826171093-4117508642-1001
Deleted ! S:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! S:\Recycler\S-1-5-21-220523388-630328440-1177238915-1003
Deleted ! S:\Recycler\S-1-5-21-3287831667-1201800720-717243645-12347
Deleted ! S:\Recycler\S-1-5-21-3287831667-1201800720-717243645-3958
Not deleted ! R:\autorun.inf
Not deleted ! R:\autorun.exe
Not deleted ! V:\autorun.inf
Deleted ! O:\_reinstall\ati\autorun.exe
Deleted ! S:\appz\_reinstall\ati\autorun.exe
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[08/01/2012 - 14:09:17 | SHD ] C:\$RECYCLE.BIN
[18/06/2011 - 10:09:53 | N | 1024] C:\.rnd
[15/10/2011 - 14:12:55 | D ] C:\a
[19/06/2010 - 10:09:57 | D ] C:\app
[24/09/2011 - 10:55:21 | D ] C:\ATI
[20/07/2011 - 07:00:11 | N | 2529086] C:\benthicsqallsetup2134.dat
[13/06/2011 - 13:16:21 | D ] C:\CodeSite
[08/01/2012 - 12:30:11 | N | 13585] C:\ComboFix.txt
[13/06/2011 - 13:14:35 | D ] C:\Common Files
[12/06/2010 - 10:53:10 | D ] C:\Default Split Group
[19/06/2010 - 07:53:22 | D ] C:\DevSuiteHome_1
[22/10/2010 - 22:38:52 | D ] C:\dir_for_oracle
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[07/11/2010 - 15:43:23 | D ] C:\Download
[13/12/2011 - 20:15:49 | N | 612285] C:\Footmen (11).SC2Replay
[08/01/2012 - 11:41:21 | ASH | 3220525056] C:\hiberfil.sys
[14/06/2010 - 06:32:04 | RD ] C:\MSOCache
[10/10/2010 - 13:57:53 | N | 4141] C:\net..txr
[08/01/2012 - 11:41:23 | ASH | 268435456] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[30/04/2010 - 23:00:04 | N | 2777] C:\posouvac_titulku.sql
[08/01/2012 - 10:00:48 | D ] C:\Program Files
[26/12/2011 - 23:03:51 | D ] C:\Program Files (x86)
[08/01/2012 - 12:26:19 | D ] C:\ProgramData
[08/01/2012 - 12:30:13 | D ] C:\Qoobox
[27/02/2010 - 16:07:28 | D ] C:\Recovery
[08/01/2012 - 11:05:15 | N | 1404] C:\RKreport[1].txt
[08/01/2012 - 10:24:22 | D ] C:\rsit
[17/11/2011 - 10:37:14 | D ] C:\Sc2gears
[15/12/2010 - 16:17:24 | D ] C:\SC2RARu10
[03/12/2011 - 23:55:53 | D ] C:\SC2Replay Archive
[28/12/2010 - 21:03:57 | D ] C:\sc2replay_my
[10/10/2010 - 13:40:28 | D ] C:\server
[08/01/2012 - 12:17:10 | SHD ] C:\System Volume Information
[08/01/2012 - 10:57:32 | N | 1894] C:\TDSSKiller.2.6.25.0_08.01.2012_10.56.52_log.txt
[08/01/2012 - 11:00:18 | N | 85860] C:\TDSSKiller.2.6.25.0_08.01.2012_10.57.36_log.txt
[08/01/2012 - 11:40:06 | N | 86782] C:\TDSSKiller.2.6.25.0_08.01.2012_11.37.41_log.txt
[08/01/2012 - 11:48:04 | N | 84682] C:\TDSSKiller.2.6.25.0_08.01.2012_11.45.54_log.txt
[08/01/2012 - 13:50:59 | D ] C:\TEMP
[07/11/2010 - 15:43:23 | D ] C:\tmpDownload
[28/05/2011 - 16:36:24 | D ] C:\totalcmd
[08/01/2012 - 10:32:33 | N | 74806] C:\treeinfo.wc
[08/01/2012 - 14:09:17 | D ] C:\UsbFix
[08/01/2012 - 13:52:27 | A | 6848] C:\UsbFix.txt
[19/06/2010 - 06:48:21 | D ] C:\Users
[18/06/2011 - 10:09:34 | D ] C:\Virtual Machines
[08/01/2012 - 12:27:22 | D ] C:\Windows
[27/02/2011 - 18:56:30 | D ] C:\winscp432
[07/11/2010 - 13:52:34 | D ] C:\YouTubeGet
[29/05/2011 - 12:32:38 | D ] C:\_CERT_MY
[29/05/2011 - 13:22:57 | D ] C:\_oracle_instalation_files
[08/01/2012 - 14:09:17 | D ] H:\$RECYCLE.BIN
[30/03/2011 - 23:59:46 | N | 13928726] H:\Business Process Management.pdf
[11/01/2009 - 05:12:48 | N | 3256915968] H:\en_sql_server_2008_developer_x86_x64_ia64_dvd_x14-88839.iso
[01/05/2011 - 13:50:30 | D ] H:\ex3
[28/04/2011 - 21:52:00 | D ] H:\extract
[28/04/2011 - 21:56:23 | D ] H:\extract2
[08/07/2011 - 17:37:53 | D ] H:\MS SQL for Oracle DBA
[18/06/2010 - 06:00:21 | SHD ] H:\System Volume Information
[31/12/2011 - 13:18:00 | N | 20760] H:\treeinfo.wc
[10/06/2011 - 11:06:31 | D ] H:\virtual_machines_microsoft
[08/01/2012 - 14:09:17 | D ] I:\$RECYCLE.BIN
[01/07/2008 - 12:32:48 | N | 3187837] I:\04KGFQ00.TIF
[10/02/2008 - 12:10:43 | N | 9111793] I:\2005-AdagioForStrings.mp3
[21/06/2008 - 22:32:10 | N | 12509707] I:\20050921050118_ML-2550_GDI_Common.exe
[02/06/2011 - 17:34:21 | D ] I:\AMADEUS
[02/06/2011 - 17:34:23 | D ] I:\ANGLICTINA
[07/06/2011 - 14:49:11 | D ] I:\audio_cz
[28/11/2006 - 20:14:24 | N | 2243] I:\beethoven.m3u
[26/11/2011 - 10:37:09 | N | 1832] I:\dance.m3u
[14/10/2010 - 19:05:38 | N | 3968] I:\dance_choice.m3u
[05/06/2011 - 11:44:32 | D ] I:\filip
[05/06/2011 - 08:07:42 | D ] I:\Jdownload_mp3
[06/06/2011 - 07:40:14 | D ] I:\mp3_from_youtube
[04/01/2012 - 09:49:08 | D ] I:\MP3_SORTED
[19/05/2004 - 22:58:05 | N | 2994789] I:\MyHouseOnCNN.mp3
[02/06/2011 - 17:35:51 | D ] I:\MY_STUFF
[12/09/2009 - 06:54:54 | N | 4919424] I:\Neneh_Cherry___Youssou_N_Dour_-_7_Seconds.mp3
[02/12/2009 - 22:33:24 | N | 2040343] I:\P1050081.JPG
[03/12/2009 - 00:06:34 | N | 1407000] I:\P1050082.JPG
[03/12/2009 - 00:06:40 | N | 1466288] I:\P1050083.JPG
[03/12/2009 - 00:06:46 | N | 1449594] I:\P1050084.JPG
[03/12/2009 - 00:06:58 | N | 1458948] I:\P1050085.JPG
[03/12/2009 - 00:07:10 | N | 1753575] I:\P1050086.JPG
[02/06/2011 - 17:35:52 | D ] I:\panasonic-DVD-REC
[02/06/2011 - 17:35:52 | D ] I:\RED_ROSE
[06/09/2011 - 20:34:16 | N | 829] I:\roadrunner.m3u
[02/06/2011 - 17:36:00 | D ] I:\SMAH VOICE
[30/05/2011 - 10:23:17 | SHD ] I:\System Volume Information
[02/06/2011 - 17:36:03 | D ] I:\tempschema
[18/10/2009 - 10:08:39 | N | 3386515] I:\Unforgettable.mp3
[09/06/2008 - 15:21:14 | N | 28538368] I:\V0609001.MP3
[02/06/2011 - 17:36:04 | D ] I:\Yamaha
[02/06/2011 - 17:36:21 | D ] I:\Yann Tiersen
[05/12/2004 - 10:01:00 | N | 1010360] I:\Yann Tiersen_-_Amelie_(6songs).pdf
[01/01/2012 - 00:29:21 | D ] I:\_audio_books
[29/10/2011 - 13:01:25 | D ] I:\_matej
[29/05/2011 - 20:09:18 | D ] I:\_MP3_090102
[29/05/2011 - 20:15:21 | D ] I:\_MP3_090320
[29/05/2011 - 20:16:21 | D ] I:\_MP3_20070630
[29/05/2011 - 20:18:18 | D ] I:\_MP3_20080401
[03/07/2011 - 11:01:25 | D ] I:\_mp3_20100214
[09/06/2011 - 13:10:06 | D ] I:\_MP3_DOWNLOADED
[29/05/2011 - 20:32:30 | D ] I:\_music
[29/05/2011 - 20:33:59 | D ] I:\_TORR_270808
[29/05/2011 - 20:41:13 | D ] I:\_TORR_DOWNLOAD
[29/05/2011 - 20:43:38 | D ] I:\_TORR_MP3
[31/12/2011 - 21:26:57 | D ] I:\__MIDI
[08/01/2012 - 14:09:17 | D ] J:\$RECYCLE.BIN
[06/05/2009 - 20:42:11 | N | 1024] J:\.rnd
[21/02/2010 - 00:05:10 | D ] J:\alfred
[17/07/2010 - 22:37:21 | N | 540106] J:\AnalysisLog.sr0
[15/06/2010 - 22:20:25 | D ] J:\AppDev
[19/03/2011 - 14:31:30 | D ] J:\audiograbber
[22/04/2009 - 13:59:37 | N | 0] J:\AUTOEXEC.BAT
[28/02/2010 - 00:40:41 | D ] J:\Boot
[22/04/2009 - 13:51:44 | N | 211] J:\Boot.BAK
[28/02/2010 - 00:40:41 | N | 355] J:\boot.ini
[14/07/2009 - 02:38:58 | RASH | 383562] J:\bootmgr
[28/02/2010 - 00:40:42 | N | 8192] J:\BOOTSECT.BAK
[25/04/2009 - 18:42:25 | N | 666251264] J:\BROODWAR.iso
[27/09/2009 - 10:21:28 | N | 720896] J:\bwchart.exe
[12/06/2010 - 11:10:37 | D ] J:\bwchart104b
[24/04/2009 - 18:18:25 | D ] J:\CodeSite
[22/04/2009 - 13:59:37 | N | 0] J:\CONFIG.SYS
[16/01/2010 - 20:58:19 | N | 2670] J:\crebas.sql
[30/04/2010 - 18:17:23 | D ] J:\dir_for_oracle
[20/06/2009 - 15:55:24 | D ] J:\Documents and Settings
[20/02/2010 - 12:21:54 | D ] J:\Downloads
[28/07/2010 - 17:37:54 | N | 117912] J:\EMebRemover.exe
[02/10/2009 - 13:47:21 | D ] J:\FOTOS
[07/11/2007 - 08:00:40 | N | 1110] J:\globdata.ini
[02/05/2009 - 22:33:47 | D ] J:\GTK
[09/05/2009 - 09:04:24 | D ] J:\Inetpub
[22/04/2009 - 16:00:28 | D ] J:\Intel
[22/04/2009 - 13:59:37 | N | 0] J:\IO.SYS
[30/05/2009 - 10:43:59 | D ] J:\Isos
[13/05/2009 - 19:22:46 | D ] J:\Loader 0.4.936_2
[01/09/2009 - 18:43:07 | N | 4250009600] J:\LexDATA.iso
[31/05/2009 - 10:40:17 | N | 75222] J:\log.txt
[28/07/2010 - 17:56:35 | N | 77312] J:\mbr.exe
[28/07/2010 - 18:03:05 | N | 195] J:\mbr.log
[01/02/2010 - 12:36:40 | N | 40] J:\moduleName.txt
[22/04/2009 - 13:59:37 | N | 0] J:\MSDOS.SYS
[24/04/2009 - 19:20:42 | RD ] J:\MSOCache
[05/07/2009 - 00:45:25 | D ] J:\Native Store
[31/07/2010 - 11:31:48 | N | 13189] J:\netstat.txt
[14/04/2008 - 13:00:00 | N | 47564] J:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250048] J:\ntldr
[24/04/2009 - 18:41:26 | D ] J:\oracle
[28/12/2010 - 17:42:39 | N | 2145386496] J:\pagefile.sys
[22/04/2009 - 20:21:29 | D ] J:\praced
[07/08/2010 - 11:51:30 | D ] J:\Program Files
[22/04/2009 - 18:18:55 | D ] J:\RaidTool
[22/04/2009 - 19:20:55 | D ] J:\RECYCLER
[09/02/2010 - 15:19:54 | D ] J:\replays
[28/12/2010 - 17:47:58 | D ] J:\sc2rar
[28/01/2010 - 21:03:03 | D ] J:\Skillb
[13/08/2009 - 18:37:01 | N | 726784000] J:\STARCRAFT.iso
[16/10/2008 - 11:23:56 | N | 665944064] J:\starcraft_broodwar.iso
[22/04/2009 - 14:03:01 | SHD ] J:\System Volume Information
[28/12/2010 - 21:56:36 | D ] J:\TEMP
[26/04/2009 - 08:38:00 | D ] J:\totalcmd
[28/12/2010 - 17:44:28 | D ] J:\WINDOWS
[16/05/2010 - 08:42:15 | N | 740865888] J:\WVOL_EN.bin
[16/05/2010 - 08:42:15 | N | 75] J:\WVOL_EN.cue
[24/04/2010 - 13:01:35 | D ] J:\X-CUESplitter 1.2
[03/07/2010 - 12:22:31 | D ] J:\_maps
[03/07/2010 - 12:22:54 | N | 8130108] J:\_maps.rar
[20/06/2010 - 10:52:11 | D ] J:\_OLDCOHEN
[08/01/2012 - 14:09:17 | D ] K:\$RECYCLE.BIN
[01/12/2006 - 22:37:14 | N | 904704] K:\msdia80.dll
[14/06/2011 - 11:34:27 | D ] K:\oracle
[28/07/2010 - 20:58:19 | | 7603322880] K:\SC2-L100-D1.iso
[02/07/2011 - 22:22:17 | D ] K:\sc2Vids
[17/08/2010 - 19:47:18 | | 6967820288] K:\starcraft2_bonus.iso
[20/06/2010 - 08:29:21 | SHD ] K:\System Volume Information
[26/12/2011 - 09:53:26 | D ] K:\videos_music
[18/06/2011 - 16:17:28 | D ] K:\Virtual Machines
[08/01/2012 - 14:09:17 | D ] L:\$RECYCLE.BIN
[12/06/2010 - 10:53:10 | N | 15040448] L:\Gavrylyuk-wedding.mp3
[24/08/2010 - 06:51:38 | N | 17979250] L:\MRU_User_Guide-00F.pdf
[29/05/2011 - 06:56:35 | SHD ] L:\System Volume Information
[03/11/2011 - 19:39:58 | D ] L:\ORA
[03/01/2012 - 23:01:54 | D ] L:\ORA_J
[05/01/2012 - 12:08:50 | D ] L:\ORA_K
[06/01/2012 - 19:27:44 | D ] L:\ORA_n
[08/01/2012 - 14:09:17 | D ] M:\$RECYCLE.BIN
[26/01/2009 - 06:59:09 | N | 33292037] M:\(Rockport) Letterhead & Logo Design 4.pdf
[21/05/2011 - 18:10:19 | D ] M:\Boot
[14/07/2009 - 02:38:58 | RASH | 383562] M:\bootmgr
[09/03/2011 - 04:58:45 | N | 8192] M:\BOOTSECT.BAK
[10/04/2010 - 20:37:55 | N | 4851357] M:\D52601GC10_sg1.pdf
[10/04/2010 - 20:38:09 | N | 5123527] M:\D52601GC10_sg2.pdf
[26/04/2009 - 09:26:43 | D ] M:\mp3_backup
[09/12/2011 - 18:04:05 | N | 8339] M:\nirvana_app.mid
[09/12/2011 - 18:03:49 | N | 100558] M:\nirvana_app.not
[09/12/2011 - 17:54:35 | N | 26811] M:\nirvana_smeels.mid
[19/05/2010 - 13:22:24 | N | 78575616] M:\pcsp64.dmp
[09/07/2009 - 18:05:37 | D ] M:\RECYCLER
[09/12/2011 - 14:40:00 | N | 30167] M:\Sepultura - Kaiowas p 2hands.mid
[23/04/2009 - 05:41:17 | SHD ] M:\System Volume Information
[06/06/2011 - 14:15:20 | N | 21579] M:\treeinfo.wc
[31/03/2008 - 16:58:59 | N | 4583] M:\Windows.XP.PRO.SP3.5503-YAB.NFO.txt
[30/12/2010 - 18:54:16 | D ] M:\_boogie
[09/08/2010 - 11:29:16 | D ] M:\_MSSQL_2008
[01/02/2010 - 12:38:38 | D ] M:\_VIRTUALBOX
[15/06/2010 - 07:21:58 | D ] M:\__ACTUAL
[25/04/2011 - 07:38:36 | D ] M:\__NOTY_NEW
[15/09/2010 - 17:02:45 | D ] M:\___NOTY
[08/01/2012 - 14:09:17 | D ] N:\$RECYCLE.BIN
[11/07/2010 - 19:02:24 | N | 1396] N:\heslo.php
[11/07/2010 - 19:02:01 | N | 1351] N:\heslo.php.bak
[11/07/2010 - 19:04:02 | N | 1339] N:\index.html
[11/07/2010 - 19:02:33 | N | 1346] N:\index.html.bak
[05/01/2012 - 17:19:53 | D ] N:\java
[15/11/2009 - 21:58:12 | D ] N:\nlog
[17/06/2010 - 21:11:27 | D ] N:\nlog_finished
[25/04/2011 - 07:40:39 | D ] N:\nlog_ora_oldcohen
[08/01/2012 - 13:19:31 | D ] N:\nlog_ora_downloading
[08/01/2012 - 13:05:00 | D ] N:\nlog_ora_finished
[08/01/2012 - 00:25:30 | D ] N:\nlog_ora2
[08/01/2012 - 00:25:44 | D ] N:\nlog_ora2_finished
[11/09/2011 - 09:20:29 | D ] N:\nlog_ora2_to_down
[19/06/2010 - 11:02:04 | D ] N:\PLSQL Developer 7.1.5.1398
[24/04/2009 - 17:43:28 | D ] N:\RECYCLER
[23/04/2009 - 05:41:17 | SHD ] N:\System Volume Information
[05/01/2012 - 16:43:04 | N | 16140] N:\treeinfo.wc
[11/10/2010 - 13:52:56 | N | 877725] N:\Uživatelská příručka Kindle 3.pdf
[11/06/2010 - 21:43:11 | N | 31232] N:\Záměna - výpočet.xls
[08/01/2012 - 14:09:17 | D ] O:\$RECYCLE.BIN
[26/10/2011 - 20:30:04 | D ] O:\java
[07/01/2011 - 13:35:10 | N | 14850937459] O:\k_back_c.zip
[08/01/2012 - 12:34:25 | D ] O:\ORA
[16/12/2011 - 22:06:16 | D ] O:\ORA Sort
[08/01/2012 - 10:28:15 | D ] O:\ORA_cz
[02/09/2011 - 10:29:40 | D ] O:\ORA_filip
[18/12/2011 - 11:18:18 | D ] O:\ORA_HDD
[20/11/2011 - 00:08:54 | D ] O:\ORA_prace
[27/11/2011 - 11:21:48 | D ] O:\ORA_S_dwh
[22/08/2011 - 10:45:04 | D ] O:\ORA_xtrack
[26/11/2011 - 19:27:08 | D ] O:\Sc2_Videos
[19/08/2011 - 17:29:33 | SHD ] O:\System Volume Information
[12/12/2011 - 21:24:51 | D ] O:\_reinstall
[28/09/2011 - 15:55:46 | D ] O:\_Seagate
[08/01/2012 - 14:09:17 | D ] P:\$RECYCLE.BIN
[21/03/2010 - 17:09:12 | N | 14850332] P:\American Football Training Like Pros.pdf
[19/09/2009 - 15:26:17 | D ] P:\RECYCLER
[19/09/2009 - 13:10:53 | SHD ] P:\System Volume Information
[24/11/2009 - 07:27:52 | D ] P:\temp
[03/07/2011 - 21:26:48 | N | 2316] P:\treeinfo.wc
[22/12/2010 - 16:39:02 | D ] P:\_to_delete
[08/01/2012 - 14:09:17 | D ] Q:\$RECYCLE.BIN
[05/06/2011 - 07:55:28 | D ] Q:\backups
[06/07/2011 - 16:42:29 | D ] Q:\english
[29/05/2011 - 07:38:14 | D ] Q:\fotos
[29/05/2011 - 16:13:59 | D ] Q:\ICKO
[22/05/2011 - 09:37:08 | D ] Q:\noty
[22/05/2011 - 08:11:34 | SHD ] Q:\System Volume Information
[18/10/2011 - 19:20:45 | N | 1501021] Q:\treeinfo.wc
[29/05/2011 - 07:07:17 | D ] Q:\wallz and pics
[29/05/2011 - 07:05:47 | D ] Q:\worx
[29/05/2011 - 07:07:31 | D ] Q:\worx_audio
[22/05/2011 - 09:31:47 | D ] Q:\__unsorted_prace
[11/06/2011 - 11:47:13 | D ] Q:\_____actual
[27/09/2006 - 10:49:15 | R | 824320] R:\autorun.exe
[09/08/2006 - 11:41:11 | R | 44] R:\autorun.inf
[09/08/2006 - 11:40:13 | D ] R:\data
[19/09/2006 - 09:55:39 | D ] R:\dema
[28/08/2006 - 09:41:32 | R | 3262] R:\fcecae.ico
[25/09/2006 - 13:06:36 | D ] R:\info
[28/09/2006 - 14:29:19 | R | 161948668] R:\setup.exe
[12/10/2011 - 14:34:16 | D ] S:\$AVG
[08/01/2012 - 14:09:17 | D ] S:\$RECYCLE.BIN
[12/10/2010 - 07:37:31 | D ] S:\apache_plus_otha
[08/11/2011 - 10:21:41 | D ] S:\appz
[21/09/2011 - 11:14:26 | D ] S:\BlackGuard
[20/01/2011 - 11:36:10 | N | 51221] S:\Bohemian_Rhapsody.mid
[22/06/2011 - 16:38:03 | D ] S:\Cisco_VPN
[04/08/2010 - 07:35:24 | N | 6392216] S:\data_modeling.pdf
[19/01/2011 - 17:47:23 | N | 4725201] S:\db11g-interactivequickref-187977.zip
[20/05/2011 - 15:07:46 | D ] S:\downz_th3scene
[07/02/2008 - 23:46:34 | N | 6501609] S:\Fotbal.wmv
[25/09/2009 - 21:18:08 | N | 38622] S:\FreeAgentGoNext.ico
[02/12/2011 - 17:43:45 | D ] S:\Grand theft auto 2
[20/01/2011 - 11:34:26 | N | 66722] S:\hammer.mid
[04/11/2009 - 16:41:00 | D ] S:\helps
[12/10/2010 - 07:32:12 | D ] S:\jdwon
[08/11/2011 - 12:28:57 | D ] S:\MP3
[28/04/2011 - 15:19:30 | D ] S:\MS SQL for Oracle DBA
[14/10/2011 - 20:05:38 | D ] S:\My Ear
[27/05/2011 - 16:48:16 | D ] S:\new books
[25/11/2011 - 17:13:28 | N | 3335345] S:\Oliver Onions - Don't lose control(360p_H.264-AAC).mp3
[15/11/2011 - 12:21:00 | D ] S:\Paul Wardingham - Assimilate Regenerate - 2011 by dyslexicpanda
[02/11/2011 - 17:20:40 | D ] S:\Piano For Stress
[28/10/2011 - 13:31:12 | N | 402592] S:\pokoj_01.sh3d
[28/11/2011 - 10:51:35 | N | 402929] S:\pokoj_02.sh3d
[19/01/2011 - 18:45:49 | N | 23094] S:\Radiohead - Creep.mid
[08/01/2012 - 14:09:16 | D ] S:\RECYCLER
[17/01/2011 - 18:04:14 | N | 86779] S:\river1.JPG
[17/01/2011 - 18:04:21 | N | 74793] S:\river2.JPG
[17/01/2011 - 18:04:26 | N | 68698] S:\river3.JPG
[24/03/2011 - 13:48:45 | N | 4052587] S:\Sc2gears-4.4.1.zip
[20/01/2011 - 11:35:16 | N | 72525] S:\scorch.asp.htm
[29/06/2011 - 08:02:31 | D ] S:\Seagate
[20/01/2011 - 11:34:33 | N | 45435] S:\show.mid
[08/09/2011 - 16:33:47 | SHD ] S:\System Volume Information
[20/05/2011 - 12:49:03 | N | 23829321] S:\th3scene.com-Toon.Track.Midi.Collection.rar
[08/01/2012 - 13:36:35 | N | 889393] S:\treeinfo.wc
[20/01/2011 - 11:36:00 | N | 41219] S:\Under_Pressure.mid
[20/01/2011 - 11:38:58 | N | 21551] S:\whowants.mid
[12/10/2011 - 19:38:13 | D ] S:\_audio_cz
[14/11/2011 - 22:04:23 | D ] S:\_boogie
[28/11/2011 - 10:52:44 | D ] S:\_DUM
[22/11/2011 - 20:52:59 | D ] S:\_eco
[08/02/2011 - 17:41:17 | D ] S:\_flashka
[28/03/2011 - 14:24:01 | D ] S:\_flashka_car
[29/08/2010 - 20:44:09 | D ] S:\_juliandyke.com
[06/09/2010 - 10:41:46 | D ] S:\_oracle
[12/10/2010 - 06:57:00 | D ] S:\_oracle_docu
[29/10/2011 - 10:52:24 | D ] S:\_PRACE
[05/05/2011 - 10:38:32 | D ] S:\_prace_down
[06/01/2011 - 22:22:40 | D ] S:\_PRACE_MP3
[14/10/2011 - 20:09:52 | D ] S:\__SC2_vids_you
[14/07/2009 - 10:29:38 | R | 122] V:\autorun.inf
[14/07/2009 - 10:29:38 | RD ] V:\boot
[14/07/2009 - 10:29:38 | R | 383562] V:\bootmgr
[14/07/2009 - 10:29:38 | R | 667712] V:\bootmgr.efi
[14/07/2009 - 10:29:38 | RD ] V:\efi
[14/07/2009 - 10:29:38 | R | 106760] V:\setup.exe
[14/07/2009 - 10:29:38 | RD ] V:\sources
[14/07/2009 - 10:29:38 | RD ] V:\support
[14/07/2009 - 10:29:38 | RD ] V:\upgrade
[01/01/2007 - 00:00:00 | N | 4439148] W:\Audio_001.wav
[01/01/2007 - 00:00:00 | N | 15164268] W:\Audio_002.wav
[01/01/2007 - 00:00:00 | N | 32162172] W:\Audio_003.wav
[01/01/2007 - 00:00:00 | N | 38724252] W:\Audio_004.wav
[01/01/2007 - 00:00:00 | N | 1948380] W:\Audio_005.wav
[01/01/2007 - 00:00:00 | N | 88835964] W:\Audio_006.wav
[01/01/2007 - 00:00:00 | N | 49569324] W:\Audio_007.wav
[01/01/2007 - 00:00:00 | N | 11459868] W:\Audio_008.wav
[01/01/2007 - 00:00:00 | N | 4544988] W:\Audio_009.wav
[01/01/2007 - 00:00:00 | N | 1334508] W:\Audio_010.wav
[01/01/2007 - 00:00:00 | N | 32606700] W:\Audio_011.wav
[01/01/2007 - 00:00:00 | N | 19355532] W:\Audio_012.wav
[01/01/2007 - 00:00:00 | N | 47558364] W:\Audio_013.wav
[01/01/2007 - 00:00:00 | N | 10281516] W:\Audio_014.wav
[01/01/2007 - 00:00:00 | N | 81102588] W:\Audio_015.wav
[14/11/2009 - 19:28:38 | D ] W:\USER FILES
[04/05/2008 - 01:26:58 | N | 11002] W:\Nocturne in C Minor.mid
[09/07/2007 - 14:23:46 | N | 7479296] W:\Amber.mp3
[09/07/2007 - 14:49:10 | N | 5318656] W:\Finding Beauty.mp3
[01/01/2007 - 00:00:00 | N | 4940124] W:\Audio_016.wav
[01/01/2007 - 00:00:00 | N | 7070] W:\Nocturne in C MinorA.MID
[21/11/2009 - 08:12:50 | D ] W:\Original
[01/01/2007 - 00:00:00 | N | 42329868] W:\Audio_017.wav
[01/01/2007 - 00:00:00 | N | 1214556] W:\Audio_018.wav
[01/01/2007 - 00:00:00 | N | 32726652] W:\Audio_019.wav
[01/01/2007 - 00:00:00 | N | 9328956] W:\Audio_020.wav
[01/01/2007 - 00:00:00 | N | 140090748] W:\Audio_021.wav
[01/01/2007 - 00:00:00 | N | 43345932] W:\Audio_022.wav
[01/01/2007 - 00:00:00 | N | 1426236] W:\Audio_023.wav
[01/01/2007 - 00:00:00 | N | 9597084] W:\Audio_024.wav
[01/01/2007 - 00:00:00 | N | 21980364] W:\Audio_025.wav
[01/01/2007 - 00:00:00 | N | 27879180] W:\Audio_026.wav
[01/01/2007 - 00:00:00 | N | 38187996] W:\Audio_027.wav
[01/01/2007 - 00:00:00 | N | 1334508] W:\Audio_028.wav
[01/01/2007 - 00:00:00 | N | 22961148] W:\Audio_029.wav
[01/01/2007 - 00:00:00 | N | 22657740] W:\Audio_030.wav
[01/01/2007 - 00:00:00 | N | 17753820] W:\Audio_031.wav
[01/01/2007 - 00:00:00 | N | 41179740] W:\Audio_032.wav
[01/01/2007 - 00:00:00 | N | 27025404] W:\Audio_033.wav
[01/01/2007 - 00:00:00 | N | 31371900] W:\Audio_034.wav
[01/01/2007 - 00:00:00 | N | 32691372] W:\Audio_035.wav
[29/11/2009 - 22:24:58 | D ] W:\_cvp final
[29/11/2009 - 22:25:02 | D ] W:\old
[29/11/2009 - 22:25:04 | D ] W:\_cvp choice mp3
[29/11/2009 - 22:25:04 | D ] W:\_cvp usable
[01/01/2007 - 00:00:00 | N | 58029468] W:\Audio_036.wav
[01/01/2007 - 00:00:00 | D ] W:\NewFolder
[01/01/2007 - 00:00:00 | N | 34525932] W:\Audio_037.wav
[01/01/2007 - 00:00:00 | N | 20900796] W:\Audio_038.wav
[01/01/2007 - 00:00:00 | N | 3719436] W:\Audio_039.wav
[01/01/2007 - 00:00:00 | N | 44397276] W:\Audio_040.wav
[01/01/2007 - 00:00:00 | N | 26192796] W:\Audio_041.wav
[01/01/2007 - 00:00:00 | N | 21218316] W:\Audio_042.wav
[06/12/2009 - 20:14:02 | D ] W:\20091206
[09/12/2009 - 21:39:40 | D ] W:\DPks
[01/01/2007 - 00:00:00 | N | 2670511] W:\CVP-407.bup
[01/01/2007 - 00:00:00 | N | 325500] W:\Audio_043.wav
[01/01/2007 - 00:00:00 | N | 52815084] W:\Audio_044.wav
[01/01/2007 - 00:00:00 | N | 27180636] W:\Audio_045.wav
[01/01/2007 - 00:00:00 | N | 8715084] W:\Audio_046.wav
[01/01/2007 - 00:00:00 | N | 9237228] W:\Audio_047.wav
[01/01/2007 - 00:00:00 | N | 20011740] W:\Audio_048.wav
[26/01/2010 - 11:29:32 | D ] W:\_kaiwav
[26/01/2010 - 22:13:04 | D ] W:\oscar peterson
[05/02/2010 - 22:05:06 | D ] W:\midi
[01/01/2007 - 00:00:00 | N | 28140252] W:\Audio_049.wav
[01/01/2007 - 00:00:00 | N | 2075388] W:\Audio_050.wav
[01/01/2007 - 00:00:00 | N | 28994028] W:\Audio_051.wav
[01/01/2007 - 00:00:00 | D ] W:\AAA
[01/01/2007 - 00:00:00 | D ] W:\KAIOWAS
[13/02/2010 - 21:54:52 | D ] W:\grieg
[01/01/2007 - 00:00:00 | N | 27942684] W:\Audio_052.wav
[01/01/2007 - 00:00:00 | N | 42033516] W:\Audio_053.wav
[01/01/2007 - 00:00:00 | N | 37256604] W:\Audio_054.wav
[01/01/2007 - 00:00:00 | N | 37771692] W:\Audio_055.wav
[01/01/2007 - 00:00:00 | N | 49675164] W:\Audio_056.wav
[01/01/2007 - 00:00:00 | N | 39606252] W:\Audio_057.wav
[28/02/2006 - 13:14:08 | N | 3102] W:\Victor's Piano Solo.mid
[01/01/2007 - 00:00:00 | D ] W:\ADAMS
[01/01/2007 - 00:00:00 | D ] W:\BACH O
[01/01/2007 - 00:00:00 | D ] W:\BACH P
[01/01/2007 - 00:00:00 | D ] W:\CHI
[01/01/2007 - 00:00:00 | D ] W:\COMPETINE D'UN
[01/01/2007 - 00:00:00 | D ] W:\JASCO
[01/01/2007 - 00:00:00 | D ] W:\LA DISPUTE
[01/01/2007 - 00:00:00 | D ] W:\LA1
[01/01/2007 - 00:00:00 | D ] W:\LAUARA
[01/01/2007 - 00:00:00 | D ] W:\MOONLIH
[01/01/2007 - 00:00:00 | D ] W:\MY STUFF
[01/01/2007 - 00:00:00 | D ] W:\MY_VARIATIONS
[01/01/2007 - 00:00:00 | D ] W:\OVER THE RAINBOD
[01/01/2007 - 00:00:00 | D ] W:\RANDE
[01/01/2007 - 00:00:00 | D ] W:\SUR LE FIL
[01/01/2007 - 00:00:00 | N | 12815] W:\adams1.MID
[01/01/2007 - 00:00:00 | N | 34725] W:\BACH1.MID
[01/01/2007 - 00:00:00 | N | 14351] W:\BACHP1.MID
[01/01/2007 - 00:00:00 | N | 14942] W:\BACHP2.MID
[01/01/2007 - 00:00:00 | N | 12815] W:\BACHP3.MID
[01/01/2007 - 00:00:00 | N | 14314] W:\BACHP4.MID
[01/01/2007 - 00:00:00 | N | 7282] W:\COP1.MID
[01/01/2007 - 00:00:00 | N | 5403] W:\LA2.MID
[01/01/2007 - 00:00:00 | N | 10864] W:\T1.MID
[01/01/2007 - 00:00:00 | N | 34864620] W:\Audio_058.wav
[07/03/2010 - 11:55:06 | D ] W:\burgmuller
[01/01/2007 - 00:00:00 | N | 1101660] W:\Audio_059.wav
[01/01/2007 - 00:00:00 | N | 7755468] W:\Audio_060.wav
[01/01/2007 - 00:00:00 | N | 8566908] W:\Audio_061.wav
[01/01/2007 - 00:00:00 | N | 30440508] W:\Audio_062.wav
[01/01/2007 - 00:00:00 | N | 49378812] W:\Audio_063.wav
[21/03/2010 - 07:46:04 | D ] W:\_CERT_MY
[01/01/2007 - 00:00:00 | N | 47868828] W:\Audio_064.wav
[24/03/2010 - 07:00:16 | D ] W:\Fazil Say
[01/01/2007 - 00:00:00 | D ] W:\AAA ORAN
[01/01/2007 - 00:00:00 | N | 41080956] W:\Audio_065.wav
[18/04/2010 - 11:59:30 | N | 1270] W:\Alla turca jazz.mid
[28/02/2006 - 13:14:08 | N | 3102] W:\]
[01/01/2007 - 00:00:00 | N | 50303148] W:\Audio_066.wav
[01/01/2007 - 00:00:00 | D ] W:\GLASGOW
[24/04/2010 - 09:23:22 | N | 23266] W:\what_i_say_piano_2h_2.mid
[01/01/2007 - 00:00:00 | N | 27088908] W:\Audio_067.wav
[30/04/2010 - 23:14:54 | N | 7759] W:\lovstory.mid
[25/06/2010 - 20:55:10 | N | 1817] W:\GHOST.mid
[01/01/2007 - 00:00:00 | N | 38597244] W:\Audio_068.wav
[01/01/2007 - 00:00:00 | N | 22763580] W:\Audio_073.wav
[01/07/2010 - 20:38:12 | N | 5249567] W:\Audio_068.mp3
[27/05/2010 - 08:33:36 | N | 245540160] W:\VTS_01_1 T80 2_0ch 192Kbps DELAY 0ms.mp3
[02/07/2010 - 13:02:34 | D ] W:\_GENRATOR
[01/01/2007 - 00:00:00 | N | 20936076] W:\Audio_069.wav
[01/01/2007 - 00:00:00 | N | 35676060] W:\Audio_070.wav
[01/01/2007 - 00:00:00 | D ] W:\A NEW SONG
[01/01/2007 - 00:00:00 | N | 3080192] W:\Audio_074.wav
[07/08/2010 - 13:49:04 | D ] W:\_dum
[16/08/2010 - 18:48:08 | D ] W:\Report Project2
[22/09/2010 - 22:43:20 | D ] W:\_noty
[23/09/2010 - 17:26:26 | D ] W:\muse_midi
[01/01/2007 - 00:00:00 | N | 47558364] W:\Audio_071.wav
[02/10/2010 - 09:54:20 | D ] W:\queen
[01/01/2007 - 00:00:00 | N | 37027840] W:\Audio_072.wav
[06/11/2010 - 21:00:14 | D ] W:\a_midi
[12/11/2010 - 15:02:10 | D ] W:\_gogol
[29/12/2010 - 18:02:44 | D ] W:\_boogie
[01/01/2007 - 00:00:00 | N | 131072] W:\Audio_075.wav
[01/01/2007 - 00:00:00 | N | 3014656] W:\Audio_076.wav
[01/01/2007 - 00:00:00 | N | 24943884] W:\Audio_077.wav
[01/01/2007 - 00:00:00 | N | 4721] W:\NewSonGMY.MID
[03/01/2011 - 07:10:56 | D ] W:\_mp3
[25/02/2011 - 00:37:48 | D ] W:\Sinfonie Nr. 3 c-moll, Orgel-Sinfonie, op. 78
[01/01/2007 - 00:00:00 | N | 19333120] W:\Audio_078.wav
[09/12/2011 - 17:57:02 | D ] W:\_new
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
H:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
I:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
J:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
K:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
L:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
M:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
N:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
O:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
P:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
Q:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
S:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
W:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_COHENW7.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.
################## | E.O.F |
User: Jakub (Administrator) # COHENW7 [System manufacturer P5K Premium]
Updated 16/09/2011 by El Desaparecido
Started at 13:52:16 | 08/01/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com
CPU: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
CPU 2: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Microsoft Windows 7 Professional (6.1.7600 64-Bit) #
Internet Explorer 8.0.7600.16385
Windows Firewall: Disabled /!\
RAM -> 4095 Mb
C:\ (%systemdrive%) -> Fixed drive # 195 Gb (96 Mb free - 49%) [W7] # NTFS
H:\ -> Fixed drive # 977 Gb (3 Mb free - 0%) [Storage1] # NTFS
I:\ -> Fixed drive # 932 Gb (347 Mb free - 37%) [TB2] # NTFS
J:\ -> Fixed drive # 195 Gb (62 Mb free - 32%) [] # NTFS
K:\ -> Fixed drive # 886 Gb (401 Mb free - 45%) [Storage2] # NTFS
L:\ -> Fixed drive # 932 Gb (1 Mb free - 0%) [TB1] # NTFS
M:\ -> Fixed drive # 488 Gb (254 Mb free - 52%) [Store1] # NTFS
N:\ -> Fixed drive # 443 Gb (82 Mb free - 19%) [Store2] # NTFS
O:\ -> Fixed drive # 1863 Gb (458 Mb free - 25%) [STORAGE_3] # NTFS
P:\ -> Fixed drive # 541 Gb (6 Mb free - 1%) [TEMPSTORAGE] # NTFS
Q:\ -> Fixed drive # 1863 Gb (126 Mb free - 7%) [STORAGE_2] # NTFS
R:\ -> CD-ROM
S:\ -> Fixed drive # 466 Gb (16 Mb free - 4%) [FreeAgent Drive] # NTFS
V:\ -> CD-ROM
W:\ -> Removable drive # 4 Gb (533 Mb free - 14%) [CORSAIR] # FAT32
################## | Files # Infected Folders |
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! H:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! I:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! J:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! J:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! L:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! M:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! M:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! M:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! N:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! N:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! O:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-500
Deleted ! P:\$RECYCLE.BIN\S-1-5-21-3201754487-793416718-2818019736-1001
Deleted ! P:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! Q:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-2794234989-373363643-3910967931-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-3287831667-1201800720-717243645-3958
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-345947992-755240569-1322415880-1000
Deleted ! S:\$RECYCLE.BIN\S-1-5-21-4001789067-1826171093-4117508642-1001
Deleted ! S:\Recycler\S-1-5-21-1275210071-1659004503-682003330-500
Deleted ! S:\Recycler\S-1-5-21-220523388-630328440-1177238915-1003
Deleted ! S:\Recycler\S-1-5-21-3287831667-1201800720-717243645-12347
Deleted ! S:\Recycler\S-1-5-21-3287831667-1201800720-717243645-3958
Not deleted ! R:\autorun.inf
Not deleted ! R:\autorun.exe
Not deleted ! V:\autorun.inf
Deleted ! O:\_reinstall\ati\autorun.exe
Deleted ! S:\appz\_reinstall\ati\autorun.exe
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[08/01/2012 - 14:09:17 | SHD ] C:\$RECYCLE.BIN
[18/06/2011 - 10:09:53 | N | 1024] C:\.rnd
[15/10/2011 - 14:12:55 | D ] C:\a
[19/06/2010 - 10:09:57 | D ] C:\app
[24/09/2011 - 10:55:21 | D ] C:\ATI
[20/07/2011 - 07:00:11 | N | 2529086] C:\benthicsqallsetup2134.dat
[13/06/2011 - 13:16:21 | D ] C:\CodeSite
[08/01/2012 - 12:30:11 | N | 13585] C:\ComboFix.txt
[13/06/2011 - 13:14:35 | D ] C:\Common Files
[12/06/2010 - 10:53:10 | D ] C:\Default Split Group
[19/06/2010 - 07:53:22 | D ] C:\DevSuiteHome_1
[22/10/2010 - 22:38:52 | D ] C:\dir_for_oracle
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[07/11/2010 - 15:43:23 | D ] C:\Download
[13/12/2011 - 20:15:49 | N | 612285] C:\Footmen (11).SC2Replay
[08/01/2012 - 11:41:21 | ASH | 3220525056] C:\hiberfil.sys
[14/06/2010 - 06:32:04 | RD ] C:\MSOCache
[10/10/2010 - 13:57:53 | N | 4141] C:\net..txr
[08/01/2012 - 11:41:23 | ASH | 268435456] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[30/04/2010 - 23:00:04 | N | 2777] C:\posouvac_titulku.sql
[08/01/2012 - 10:00:48 | D ] C:\Program Files
[26/12/2011 - 23:03:51 | D ] C:\Program Files (x86)
[08/01/2012 - 12:26:19 | D ] C:\ProgramData
[08/01/2012 - 12:30:13 | D ] C:\Qoobox
[27/02/2010 - 16:07:28 | D ] C:\Recovery
[08/01/2012 - 11:05:15 | N | 1404] C:\RKreport[1].txt
[08/01/2012 - 10:24:22 | D ] C:\rsit
[17/11/2011 - 10:37:14 | D ] C:\Sc2gears
[15/12/2010 - 16:17:24 | D ] C:\SC2RARu10
[03/12/2011 - 23:55:53 | D ] C:\SC2Replay Archive
[28/12/2010 - 21:03:57 | D ] C:\sc2replay_my
[10/10/2010 - 13:40:28 | D ] C:\server
[08/01/2012 - 12:17:10 | SHD ] C:\System Volume Information
[08/01/2012 - 10:57:32 | N | 1894] C:\TDSSKiller.2.6.25.0_08.01.2012_10.56.52_log.txt
[08/01/2012 - 11:00:18 | N | 85860] C:\TDSSKiller.2.6.25.0_08.01.2012_10.57.36_log.txt
[08/01/2012 - 11:40:06 | N | 86782] C:\TDSSKiller.2.6.25.0_08.01.2012_11.37.41_log.txt
[08/01/2012 - 11:48:04 | N | 84682] C:\TDSSKiller.2.6.25.0_08.01.2012_11.45.54_log.txt
[08/01/2012 - 13:50:59 | D ] C:\TEMP
[07/11/2010 - 15:43:23 | D ] C:\tmpDownload
[28/05/2011 - 16:36:24 | D ] C:\totalcmd
[08/01/2012 - 10:32:33 | N | 74806] C:\treeinfo.wc
[08/01/2012 - 14:09:17 | D ] C:\UsbFix
[08/01/2012 - 13:52:27 | A | 6848] C:\UsbFix.txt
[19/06/2010 - 06:48:21 | D ] C:\Users
[18/06/2011 - 10:09:34 | D ] C:\Virtual Machines
[08/01/2012 - 12:27:22 | D ] C:\Windows
[27/02/2011 - 18:56:30 | D ] C:\winscp432
[07/11/2010 - 13:52:34 | D ] C:\YouTubeGet
[29/05/2011 - 12:32:38 | D ] C:\_CERT_MY
[29/05/2011 - 13:22:57 | D ] C:\_oracle_instalation_files
[08/01/2012 - 14:09:17 | D ] H:\$RECYCLE.BIN
[30/03/2011 - 23:59:46 | N | 13928726] H:\Business Process Management.pdf
[11/01/2009 - 05:12:48 | N | 3256915968] H:\en_sql_server_2008_developer_x86_x64_ia64_dvd_x14-88839.iso
[01/05/2011 - 13:50:30 | D ] H:\ex3
[28/04/2011 - 21:52:00 | D ] H:\extract
[28/04/2011 - 21:56:23 | D ] H:\extract2
[08/07/2011 - 17:37:53 | D ] H:\MS SQL for Oracle DBA
[18/06/2010 - 06:00:21 | SHD ] H:\System Volume Information
[31/12/2011 - 13:18:00 | N | 20760] H:\treeinfo.wc
[10/06/2011 - 11:06:31 | D ] H:\virtual_machines_microsoft
[08/01/2012 - 14:09:17 | D ] I:\$RECYCLE.BIN
[01/07/2008 - 12:32:48 | N | 3187837] I:\04KGFQ00.TIF
[10/02/2008 - 12:10:43 | N | 9111793] I:\2005-AdagioForStrings.mp3
[21/06/2008 - 22:32:10 | N | 12509707] I:\20050921050118_ML-2550_GDI_Common.exe
[02/06/2011 - 17:34:21 | D ] I:\AMADEUS
[02/06/2011 - 17:34:23 | D ] I:\ANGLICTINA
[07/06/2011 - 14:49:11 | D ] I:\audio_cz
[28/11/2006 - 20:14:24 | N | 2243] I:\beethoven.m3u
[26/11/2011 - 10:37:09 | N | 1832] I:\dance.m3u
[14/10/2010 - 19:05:38 | N | 3968] I:\dance_choice.m3u
[05/06/2011 - 11:44:32 | D ] I:\filip
[05/06/2011 - 08:07:42 | D ] I:\Jdownload_mp3
[06/06/2011 - 07:40:14 | D ] I:\mp3_from_youtube
[04/01/2012 - 09:49:08 | D ] I:\MP3_SORTED
[19/05/2004 - 22:58:05 | N | 2994789] I:\MyHouseOnCNN.mp3
[02/06/2011 - 17:35:51 | D ] I:\MY_STUFF
[12/09/2009 - 06:54:54 | N | 4919424] I:\Neneh_Cherry___Youssou_N_Dour_-_7_Seconds.mp3
[02/12/2009 - 22:33:24 | N | 2040343] I:\P1050081.JPG
[03/12/2009 - 00:06:34 | N | 1407000] I:\P1050082.JPG
[03/12/2009 - 00:06:40 | N | 1466288] I:\P1050083.JPG
[03/12/2009 - 00:06:46 | N | 1449594] I:\P1050084.JPG
[03/12/2009 - 00:06:58 | N | 1458948] I:\P1050085.JPG
[03/12/2009 - 00:07:10 | N | 1753575] I:\P1050086.JPG
[02/06/2011 - 17:35:52 | D ] I:\panasonic-DVD-REC
[02/06/2011 - 17:35:52 | D ] I:\RED_ROSE
[06/09/2011 - 20:34:16 | N | 829] I:\roadrunner.m3u
[02/06/2011 - 17:36:00 | D ] I:\SMAH VOICE
[30/05/2011 - 10:23:17 | SHD ] I:\System Volume Information
[02/06/2011 - 17:36:03 | D ] I:\tempschema
[18/10/2009 - 10:08:39 | N | 3386515] I:\Unforgettable.mp3
[09/06/2008 - 15:21:14 | N | 28538368] I:\V0609001.MP3
[02/06/2011 - 17:36:04 | D ] I:\Yamaha
[02/06/2011 - 17:36:21 | D ] I:\Yann Tiersen
[05/12/2004 - 10:01:00 | N | 1010360] I:\Yann Tiersen_-_Amelie_(6songs).pdf
[01/01/2012 - 00:29:21 | D ] I:\_audio_books
[29/10/2011 - 13:01:25 | D ] I:\_matej
[29/05/2011 - 20:09:18 | D ] I:\_MP3_090102
[29/05/2011 - 20:15:21 | D ] I:\_MP3_090320
[29/05/2011 - 20:16:21 | D ] I:\_MP3_20070630
[29/05/2011 - 20:18:18 | D ] I:\_MP3_20080401
[03/07/2011 - 11:01:25 | D ] I:\_mp3_20100214
[09/06/2011 - 13:10:06 | D ] I:\_MP3_DOWNLOADED
[29/05/2011 - 20:32:30 | D ] I:\_music
[29/05/2011 - 20:33:59 | D ] I:\_TORR_270808
[29/05/2011 - 20:41:13 | D ] I:\_TORR_DOWNLOAD
[29/05/2011 - 20:43:38 | D ] I:\_TORR_MP3
[31/12/2011 - 21:26:57 | D ] I:\__MIDI
[08/01/2012 - 14:09:17 | D ] J:\$RECYCLE.BIN
[06/05/2009 - 20:42:11 | N | 1024] J:\.rnd
[21/02/2010 - 00:05:10 | D ] J:\alfred
[17/07/2010 - 22:37:21 | N | 540106] J:\AnalysisLog.sr0
[15/06/2010 - 22:20:25 | D ] J:\AppDev
[19/03/2011 - 14:31:30 | D ] J:\audiograbber
[22/04/2009 - 13:59:37 | N | 0] J:\AUTOEXEC.BAT
[28/02/2010 - 00:40:41 | D ] J:\Boot
[22/04/2009 - 13:51:44 | N | 211] J:\Boot.BAK
[28/02/2010 - 00:40:41 | N | 355] J:\boot.ini
[14/07/2009 - 02:38:58 | RASH | 383562] J:\bootmgr
[28/02/2010 - 00:40:42 | N | 8192] J:\BOOTSECT.BAK
[25/04/2009 - 18:42:25 | N | 666251264] J:\BROODWAR.iso
[27/09/2009 - 10:21:28 | N | 720896] J:\bwchart.exe
[12/06/2010 - 11:10:37 | D ] J:\bwchart104b
[24/04/2009 - 18:18:25 | D ] J:\CodeSite
[22/04/2009 - 13:59:37 | N | 0] J:\CONFIG.SYS
[16/01/2010 - 20:58:19 | N | 2670] J:\crebas.sql
[30/04/2010 - 18:17:23 | D ] J:\dir_for_oracle
[20/06/2009 - 15:55:24 | D ] J:\Documents and Settings
[20/02/2010 - 12:21:54 | D ] J:\Downloads
[28/07/2010 - 17:37:54 | N | 117912] J:\EMebRemover.exe
[02/10/2009 - 13:47:21 | D ] J:\FOTOS
[07/11/2007 - 08:00:40 | N | 1110] J:\globdata.ini
[02/05/2009 - 22:33:47 | D ] J:\GTK
[09/05/2009 - 09:04:24 | D ] J:\Inetpub
[22/04/2009 - 16:00:28 | D ] J:\Intel
[22/04/2009 - 13:59:37 | N | 0] J:\IO.SYS
[30/05/2009 - 10:43:59 | D ] J:\Isos
[13/05/2009 - 19:22:46 | D ] J:\Loader 0.4.936_2
[01/09/2009 - 18:43:07 | N | 4250009600] J:\LexDATA.iso
[31/05/2009 - 10:40:17 | N | 75222] J:\log.txt
[28/07/2010 - 17:56:35 | N | 77312] J:\mbr.exe
[28/07/2010 - 18:03:05 | N | 195] J:\mbr.log
[01/02/2010 - 12:36:40 | N | 40] J:\moduleName.txt
[22/04/2009 - 13:59:37 | N | 0] J:\MSDOS.SYS
[24/04/2009 - 19:20:42 | RD ] J:\MSOCache
[05/07/2009 - 00:45:25 | D ] J:\Native Store
[31/07/2010 - 11:31:48 | N | 13189] J:\netstat.txt
[14/04/2008 - 13:00:00 | N | 47564] J:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 250048] J:\ntldr
[24/04/2009 - 18:41:26 | D ] J:\oracle
[28/12/2010 - 17:42:39 | N | 2145386496] J:\pagefile.sys
[22/04/2009 - 20:21:29 | D ] J:\praced
[07/08/2010 - 11:51:30 | D ] J:\Program Files
[22/04/2009 - 18:18:55 | D ] J:\RaidTool
[22/04/2009 - 19:20:55 | D ] J:\RECYCLER
[09/02/2010 - 15:19:54 | D ] J:\replays
[28/12/2010 - 17:47:58 | D ] J:\sc2rar
[28/01/2010 - 21:03:03 | D ] J:\Skillb
[13/08/2009 - 18:37:01 | N | 726784000] J:\STARCRAFT.iso
[16/10/2008 - 11:23:56 | N | 665944064] J:\starcraft_broodwar.iso
[22/04/2009 - 14:03:01 | SHD ] J:\System Volume Information
[28/12/2010 - 21:56:36 | D ] J:\TEMP
[26/04/2009 - 08:38:00 | D ] J:\totalcmd
[28/12/2010 - 17:44:28 | D ] J:\WINDOWS
[16/05/2010 - 08:42:15 | N | 740865888] J:\WVOL_EN.bin
[16/05/2010 - 08:42:15 | N | 75] J:\WVOL_EN.cue
[24/04/2010 - 13:01:35 | D ] J:\X-CUESplitter 1.2
[03/07/2010 - 12:22:31 | D ] J:\_maps
[03/07/2010 - 12:22:54 | N | 8130108] J:\_maps.rar
[20/06/2010 - 10:52:11 | D ] J:\_OLDCOHEN
[08/01/2012 - 14:09:17 | D ] K:\$RECYCLE.BIN
[01/12/2006 - 22:37:14 | N | 904704] K:\msdia80.dll
[14/06/2011 - 11:34:27 | D ] K:\oracle
[28/07/2010 - 20:58:19 | | 7603322880] K:\SC2-L100-D1.iso
[02/07/2011 - 22:22:17 | D ] K:\sc2Vids
[17/08/2010 - 19:47:18 | | 6967820288] K:\starcraft2_bonus.iso
[20/06/2010 - 08:29:21 | SHD ] K:\System Volume Information
[26/12/2011 - 09:53:26 | D ] K:\videos_music
[18/06/2011 - 16:17:28 | D ] K:\Virtual Machines
[08/01/2012 - 14:09:17 | D ] L:\$RECYCLE.BIN
[12/06/2010 - 10:53:10 | N | 15040448] L:\Gavrylyuk-wedding.mp3
[24/08/2010 - 06:51:38 | N | 17979250] L:\MRU_User_Guide-00F.pdf
[29/05/2011 - 06:56:35 | SHD ] L:\System Volume Information
[03/11/2011 - 19:39:58 | D ] L:\ORA
[03/01/2012 - 23:01:54 | D ] L:\ORA_J
[05/01/2012 - 12:08:50 | D ] L:\ORA_K
[06/01/2012 - 19:27:44 | D ] L:\ORA_n
[08/01/2012 - 14:09:17 | D ] M:\$RECYCLE.BIN
[26/01/2009 - 06:59:09 | N | 33292037] M:\(Rockport) Letterhead & Logo Design 4.pdf
[21/05/2011 - 18:10:19 | D ] M:\Boot
[14/07/2009 - 02:38:58 | RASH | 383562] M:\bootmgr
[09/03/2011 - 04:58:45 | N | 8192] M:\BOOTSECT.BAK
[10/04/2010 - 20:37:55 | N | 4851357] M:\D52601GC10_sg1.pdf
[10/04/2010 - 20:38:09 | N | 5123527] M:\D52601GC10_sg2.pdf
[26/04/2009 - 09:26:43 | D ] M:\mp3_backup
[09/12/2011 - 18:04:05 | N | 8339] M:\nirvana_app.mid
[09/12/2011 - 18:03:49 | N | 100558] M:\nirvana_app.not
[09/12/2011 - 17:54:35 | N | 26811] M:\nirvana_smeels.mid
[19/05/2010 - 13:22:24 | N | 78575616] M:\pcsp64.dmp
[09/07/2009 - 18:05:37 | D ] M:\RECYCLER
[09/12/2011 - 14:40:00 | N | 30167] M:\Sepultura - Kaiowas p 2hands.mid
[23/04/2009 - 05:41:17 | SHD ] M:\System Volume Information
[06/06/2011 - 14:15:20 | N | 21579] M:\treeinfo.wc
[31/03/2008 - 16:58:59 | N | 4583] M:\Windows.XP.PRO.SP3.5503-YAB.NFO.txt
[30/12/2010 - 18:54:16 | D ] M:\_boogie
[09/08/2010 - 11:29:16 | D ] M:\_MSSQL_2008
[01/02/2010 - 12:38:38 | D ] M:\_VIRTUALBOX
[15/06/2010 - 07:21:58 | D ] M:\__ACTUAL
[25/04/2011 - 07:38:36 | D ] M:\__NOTY_NEW
[15/09/2010 - 17:02:45 | D ] M:\___NOTY
[08/01/2012 - 14:09:17 | D ] N:\$RECYCLE.BIN
[11/07/2010 - 19:02:24 | N | 1396] N:\heslo.php
[11/07/2010 - 19:02:01 | N | 1351] N:\heslo.php.bak
[11/07/2010 - 19:04:02 | N | 1339] N:\index.html
[11/07/2010 - 19:02:33 | N | 1346] N:\index.html.bak
[05/01/2012 - 17:19:53 | D ] N:\java
[15/11/2009 - 21:58:12 | D ] N:\nlog
[17/06/2010 - 21:11:27 | D ] N:\nlog_finished
[25/04/2011 - 07:40:39 | D ] N:\nlog_ora_oldcohen
[08/01/2012 - 13:19:31 | D ] N:\nlog_ora_downloading
[08/01/2012 - 13:05:00 | D ] N:\nlog_ora_finished
[08/01/2012 - 00:25:30 | D ] N:\nlog_ora2
[08/01/2012 - 00:25:44 | D ] N:\nlog_ora2_finished
[11/09/2011 - 09:20:29 | D ] N:\nlog_ora2_to_down
[19/06/2010 - 11:02:04 | D ] N:\PLSQL Developer 7.1.5.1398
[24/04/2009 - 17:43:28 | D ] N:\RECYCLER
[23/04/2009 - 05:41:17 | SHD ] N:\System Volume Information
[05/01/2012 - 16:43:04 | N | 16140] N:\treeinfo.wc
[11/10/2010 - 13:52:56 | N | 877725] N:\Uživatelská příručka Kindle 3.pdf
[11/06/2010 - 21:43:11 | N | 31232] N:\Záměna - výpočet.xls
[08/01/2012 - 14:09:17 | D ] O:\$RECYCLE.BIN
[26/10/2011 - 20:30:04 | D ] O:\java
[07/01/2011 - 13:35:10 | N | 14850937459] O:\k_back_c.zip
[08/01/2012 - 12:34:25 | D ] O:\ORA
[16/12/2011 - 22:06:16 | D ] O:\ORA Sort
[08/01/2012 - 10:28:15 | D ] O:\ORA_cz
[02/09/2011 - 10:29:40 | D ] O:\ORA_filip
[18/12/2011 - 11:18:18 | D ] O:\ORA_HDD
[20/11/2011 - 00:08:54 | D ] O:\ORA_prace
[27/11/2011 - 11:21:48 | D ] O:\ORA_S_dwh
[22/08/2011 - 10:45:04 | D ] O:\ORA_xtrack
[26/11/2011 - 19:27:08 | D ] O:\Sc2_Videos
[19/08/2011 - 17:29:33 | SHD ] O:\System Volume Information
[12/12/2011 - 21:24:51 | D ] O:\_reinstall
[28/09/2011 - 15:55:46 | D ] O:\_Seagate
[08/01/2012 - 14:09:17 | D ] P:\$RECYCLE.BIN
[21/03/2010 - 17:09:12 | N | 14850332] P:\American Football Training Like Pros.pdf
[19/09/2009 - 15:26:17 | D ] P:\RECYCLER
[19/09/2009 - 13:10:53 | SHD ] P:\System Volume Information
[24/11/2009 - 07:27:52 | D ] P:\temp
[03/07/2011 - 21:26:48 | N | 2316] P:\treeinfo.wc
[22/12/2010 - 16:39:02 | D ] P:\_to_delete
[08/01/2012 - 14:09:17 | D ] Q:\$RECYCLE.BIN
[05/06/2011 - 07:55:28 | D ] Q:\backups
[06/07/2011 - 16:42:29 | D ] Q:\english
[29/05/2011 - 07:38:14 | D ] Q:\fotos
[29/05/2011 - 16:13:59 | D ] Q:\ICKO
[22/05/2011 - 09:37:08 | D ] Q:\noty
[22/05/2011 - 08:11:34 | SHD ] Q:\System Volume Information
[18/10/2011 - 19:20:45 | N | 1501021] Q:\treeinfo.wc
[29/05/2011 - 07:07:17 | D ] Q:\wallz and pics
[29/05/2011 - 07:05:47 | D ] Q:\worx
[29/05/2011 - 07:07:31 | D ] Q:\worx_audio
[22/05/2011 - 09:31:47 | D ] Q:\__unsorted_prace
[11/06/2011 - 11:47:13 | D ] Q:\_____actual
[27/09/2006 - 10:49:15 | R | 824320] R:\autorun.exe
[09/08/2006 - 11:41:11 | R | 44] R:\autorun.inf
[09/08/2006 - 11:40:13 | D ] R:\data
[19/09/2006 - 09:55:39 | D ] R:\dema
[28/08/2006 - 09:41:32 | R | 3262] R:\fcecae.ico
[25/09/2006 - 13:06:36 | D ] R:\info
[28/09/2006 - 14:29:19 | R | 161948668] R:\setup.exe
[12/10/2011 - 14:34:16 | D ] S:\$AVG
[08/01/2012 - 14:09:17 | D ] S:\$RECYCLE.BIN
[12/10/2010 - 07:37:31 | D ] S:\apache_plus_otha
[08/11/2011 - 10:21:41 | D ] S:\appz
[21/09/2011 - 11:14:26 | D ] S:\BlackGuard
[20/01/2011 - 11:36:10 | N | 51221] S:\Bohemian_Rhapsody.mid
[22/06/2011 - 16:38:03 | D ] S:\Cisco_VPN
[04/08/2010 - 07:35:24 | N | 6392216] S:\data_modeling.pdf
[19/01/2011 - 17:47:23 | N | 4725201] S:\db11g-interactivequickref-187977.zip
[20/05/2011 - 15:07:46 | D ] S:\downz_th3scene
[07/02/2008 - 23:46:34 | N | 6501609] S:\Fotbal.wmv
[25/09/2009 - 21:18:08 | N | 38622] S:\FreeAgentGoNext.ico
[02/12/2011 - 17:43:45 | D ] S:\Grand theft auto 2
[20/01/2011 - 11:34:26 | N | 66722] S:\hammer.mid
[04/11/2009 - 16:41:00 | D ] S:\helps
[12/10/2010 - 07:32:12 | D ] S:\jdwon
[08/11/2011 - 12:28:57 | D ] S:\MP3
[28/04/2011 - 15:19:30 | D ] S:\MS SQL for Oracle DBA
[14/10/2011 - 20:05:38 | D ] S:\My Ear
[27/05/2011 - 16:48:16 | D ] S:\new books
[25/11/2011 - 17:13:28 | N | 3335345] S:\Oliver Onions - Don't lose control(360p_H.264-AAC).mp3
[15/11/2011 - 12:21:00 | D ] S:\Paul Wardingham - Assimilate Regenerate - 2011 by dyslexicpanda
[02/11/2011 - 17:20:40 | D ] S:\Piano For Stress
[28/10/2011 - 13:31:12 | N | 402592] S:\pokoj_01.sh3d
[28/11/2011 - 10:51:35 | N | 402929] S:\pokoj_02.sh3d
[19/01/2011 - 18:45:49 | N | 23094] S:\Radiohead - Creep.mid
[08/01/2012 - 14:09:16 | D ] S:\RECYCLER
[17/01/2011 - 18:04:14 | N | 86779] S:\river1.JPG
[17/01/2011 - 18:04:21 | N | 74793] S:\river2.JPG
[17/01/2011 - 18:04:26 | N | 68698] S:\river3.JPG
[24/03/2011 - 13:48:45 | N | 4052587] S:\Sc2gears-4.4.1.zip
[20/01/2011 - 11:35:16 | N | 72525] S:\scorch.asp.htm
[29/06/2011 - 08:02:31 | D ] S:\Seagate
[20/01/2011 - 11:34:33 | N | 45435] S:\show.mid
[08/09/2011 - 16:33:47 | SHD ] S:\System Volume Information
[20/05/2011 - 12:49:03 | N | 23829321] S:\th3scene.com-Toon.Track.Midi.Collection.rar
[08/01/2012 - 13:36:35 | N | 889393] S:\treeinfo.wc
[20/01/2011 - 11:36:00 | N | 41219] S:\Under_Pressure.mid
[20/01/2011 - 11:38:58 | N | 21551] S:\whowants.mid
[12/10/2011 - 19:38:13 | D ] S:\_audio_cz
[14/11/2011 - 22:04:23 | D ] S:\_boogie
[28/11/2011 - 10:52:44 | D ] S:\_DUM
[22/11/2011 - 20:52:59 | D ] S:\_eco
[08/02/2011 - 17:41:17 | D ] S:\_flashka
[28/03/2011 - 14:24:01 | D ] S:\_flashka_car
[29/08/2010 - 20:44:09 | D ] S:\_juliandyke.com
[06/09/2010 - 10:41:46 | D ] S:\_oracle
[12/10/2010 - 06:57:00 | D ] S:\_oracle_docu
[29/10/2011 - 10:52:24 | D ] S:\_PRACE
[05/05/2011 - 10:38:32 | D ] S:\_prace_down
[06/01/2011 - 22:22:40 | D ] S:\_PRACE_MP3
[14/10/2011 - 20:09:52 | D ] S:\__SC2_vids_you
[14/07/2009 - 10:29:38 | R | 122] V:\autorun.inf
[14/07/2009 - 10:29:38 | RD ] V:\boot
[14/07/2009 - 10:29:38 | R | 383562] V:\bootmgr
[14/07/2009 - 10:29:38 | R | 667712] V:\bootmgr.efi
[14/07/2009 - 10:29:38 | RD ] V:\efi
[14/07/2009 - 10:29:38 | R | 106760] V:\setup.exe
[14/07/2009 - 10:29:38 | RD ] V:\sources
[14/07/2009 - 10:29:38 | RD ] V:\support
[14/07/2009 - 10:29:38 | RD ] V:\upgrade
[01/01/2007 - 00:00:00 | N | 4439148] W:\Audio_001.wav
[01/01/2007 - 00:00:00 | N | 15164268] W:\Audio_002.wav
[01/01/2007 - 00:00:00 | N | 32162172] W:\Audio_003.wav
[01/01/2007 - 00:00:00 | N | 38724252] W:\Audio_004.wav
[01/01/2007 - 00:00:00 | N | 1948380] W:\Audio_005.wav
[01/01/2007 - 00:00:00 | N | 88835964] W:\Audio_006.wav
[01/01/2007 - 00:00:00 | N | 49569324] W:\Audio_007.wav
[01/01/2007 - 00:00:00 | N | 11459868] W:\Audio_008.wav
[01/01/2007 - 00:00:00 | N | 4544988] W:\Audio_009.wav
[01/01/2007 - 00:00:00 | N | 1334508] W:\Audio_010.wav
[01/01/2007 - 00:00:00 | N | 32606700] W:\Audio_011.wav
[01/01/2007 - 00:00:00 | N | 19355532] W:\Audio_012.wav
[01/01/2007 - 00:00:00 | N | 47558364] W:\Audio_013.wav
[01/01/2007 - 00:00:00 | N | 10281516] W:\Audio_014.wav
[01/01/2007 - 00:00:00 | N | 81102588] W:\Audio_015.wav
[14/11/2009 - 19:28:38 | D ] W:\USER FILES
[04/05/2008 - 01:26:58 | N | 11002] W:\Nocturne in C Minor.mid
[09/07/2007 - 14:23:46 | N | 7479296] W:\Amber.mp3
[09/07/2007 - 14:49:10 | N | 5318656] W:\Finding Beauty.mp3
[01/01/2007 - 00:00:00 | N | 4940124] W:\Audio_016.wav
[01/01/2007 - 00:00:00 | N | 7070] W:\Nocturne in C MinorA.MID
[21/11/2009 - 08:12:50 | D ] W:\Original
[01/01/2007 - 00:00:00 | N | 42329868] W:\Audio_017.wav
[01/01/2007 - 00:00:00 | N | 1214556] W:\Audio_018.wav
[01/01/2007 - 00:00:00 | N | 32726652] W:\Audio_019.wav
[01/01/2007 - 00:00:00 | N | 9328956] W:\Audio_020.wav
[01/01/2007 - 00:00:00 | N | 140090748] W:\Audio_021.wav
[01/01/2007 - 00:00:00 | N | 43345932] W:\Audio_022.wav
[01/01/2007 - 00:00:00 | N | 1426236] W:\Audio_023.wav
[01/01/2007 - 00:00:00 | N | 9597084] W:\Audio_024.wav
[01/01/2007 - 00:00:00 | N | 21980364] W:\Audio_025.wav
[01/01/2007 - 00:00:00 | N | 27879180] W:\Audio_026.wav
[01/01/2007 - 00:00:00 | N | 38187996] W:\Audio_027.wav
[01/01/2007 - 00:00:00 | N | 1334508] W:\Audio_028.wav
[01/01/2007 - 00:00:00 | N | 22961148] W:\Audio_029.wav
[01/01/2007 - 00:00:00 | N | 22657740] W:\Audio_030.wav
[01/01/2007 - 00:00:00 | N | 17753820] W:\Audio_031.wav
[01/01/2007 - 00:00:00 | N | 41179740] W:\Audio_032.wav
[01/01/2007 - 00:00:00 | N | 27025404] W:\Audio_033.wav
[01/01/2007 - 00:00:00 | N | 31371900] W:\Audio_034.wav
[01/01/2007 - 00:00:00 | N | 32691372] W:\Audio_035.wav
[29/11/2009 - 22:24:58 | D ] W:\_cvp final
[29/11/2009 - 22:25:02 | D ] W:\old
[29/11/2009 - 22:25:04 | D ] W:\_cvp choice mp3
[29/11/2009 - 22:25:04 | D ] W:\_cvp usable
[01/01/2007 - 00:00:00 | N | 58029468] W:\Audio_036.wav
[01/01/2007 - 00:00:00 | D ] W:\NewFolder
[01/01/2007 - 00:00:00 | N | 34525932] W:\Audio_037.wav
[01/01/2007 - 00:00:00 | N | 20900796] W:\Audio_038.wav
[01/01/2007 - 00:00:00 | N | 3719436] W:\Audio_039.wav
[01/01/2007 - 00:00:00 | N | 44397276] W:\Audio_040.wav
[01/01/2007 - 00:00:00 | N | 26192796] W:\Audio_041.wav
[01/01/2007 - 00:00:00 | N | 21218316] W:\Audio_042.wav
[06/12/2009 - 20:14:02 | D ] W:\20091206
[09/12/2009 - 21:39:40 | D ] W:\DPks
[01/01/2007 - 00:00:00 | N | 2670511] W:\CVP-407.bup
[01/01/2007 - 00:00:00 | N | 325500] W:\Audio_043.wav
[01/01/2007 - 00:00:00 | N | 52815084] W:\Audio_044.wav
[01/01/2007 - 00:00:00 | N | 27180636] W:\Audio_045.wav
[01/01/2007 - 00:00:00 | N | 8715084] W:\Audio_046.wav
[01/01/2007 - 00:00:00 | N | 9237228] W:\Audio_047.wav
[01/01/2007 - 00:00:00 | N | 20011740] W:\Audio_048.wav
[26/01/2010 - 11:29:32 | D ] W:\_kaiwav
[26/01/2010 - 22:13:04 | D ] W:\oscar peterson
[05/02/2010 - 22:05:06 | D ] W:\midi
[01/01/2007 - 00:00:00 | N | 28140252] W:\Audio_049.wav
[01/01/2007 - 00:00:00 | N | 2075388] W:\Audio_050.wav
[01/01/2007 - 00:00:00 | N | 28994028] W:\Audio_051.wav
[01/01/2007 - 00:00:00 | D ] W:\AAA
[01/01/2007 - 00:00:00 | D ] W:\KAIOWAS
[13/02/2010 - 21:54:52 | D ] W:\grieg
[01/01/2007 - 00:00:00 | N | 27942684] W:\Audio_052.wav
[01/01/2007 - 00:00:00 | N | 42033516] W:\Audio_053.wav
[01/01/2007 - 00:00:00 | N | 37256604] W:\Audio_054.wav
[01/01/2007 - 00:00:00 | N | 37771692] W:\Audio_055.wav
[01/01/2007 - 00:00:00 | N | 49675164] W:\Audio_056.wav
[01/01/2007 - 00:00:00 | N | 39606252] W:\Audio_057.wav
[28/02/2006 - 13:14:08 | N | 3102] W:\Victor's Piano Solo.mid
[01/01/2007 - 00:00:00 | D ] W:\ADAMS
[01/01/2007 - 00:00:00 | D ] W:\BACH O
[01/01/2007 - 00:00:00 | D ] W:\BACH P
[01/01/2007 - 00:00:00 | D ] W:\CHI
[01/01/2007 - 00:00:00 | D ] W:\COMPETINE D'UN
[01/01/2007 - 00:00:00 | D ] W:\JASCO
[01/01/2007 - 00:00:00 | D ] W:\LA DISPUTE
[01/01/2007 - 00:00:00 | D ] W:\LA1
[01/01/2007 - 00:00:00 | D ] W:\LAUARA
[01/01/2007 - 00:00:00 | D ] W:\MOONLIH
[01/01/2007 - 00:00:00 | D ] W:\MY STUFF
[01/01/2007 - 00:00:00 | D ] W:\MY_VARIATIONS
[01/01/2007 - 00:00:00 | D ] W:\OVER THE RAINBOD
[01/01/2007 - 00:00:00 | D ] W:\RANDE
[01/01/2007 - 00:00:00 | D ] W:\SUR LE FIL
[01/01/2007 - 00:00:00 | N | 12815] W:\adams1.MID
[01/01/2007 - 00:00:00 | N | 34725] W:\BACH1.MID
[01/01/2007 - 00:00:00 | N | 14351] W:\BACHP1.MID
[01/01/2007 - 00:00:00 | N | 14942] W:\BACHP2.MID
[01/01/2007 - 00:00:00 | N | 12815] W:\BACHP3.MID
[01/01/2007 - 00:00:00 | N | 14314] W:\BACHP4.MID
[01/01/2007 - 00:00:00 | N | 7282] W:\COP1.MID
[01/01/2007 - 00:00:00 | N | 5403] W:\LA2.MID
[01/01/2007 - 00:00:00 | N | 10864] W:\T1.MID
[01/01/2007 - 00:00:00 | N | 34864620] W:\Audio_058.wav
[07/03/2010 - 11:55:06 | D ] W:\burgmuller
[01/01/2007 - 00:00:00 | N | 1101660] W:\Audio_059.wav
[01/01/2007 - 00:00:00 | N | 7755468] W:\Audio_060.wav
[01/01/2007 - 00:00:00 | N | 8566908] W:\Audio_061.wav
[01/01/2007 - 00:00:00 | N | 30440508] W:\Audio_062.wav
[01/01/2007 - 00:00:00 | N | 49378812] W:\Audio_063.wav
[21/03/2010 - 07:46:04 | D ] W:\_CERT_MY
[01/01/2007 - 00:00:00 | N | 47868828] W:\Audio_064.wav
[24/03/2010 - 07:00:16 | D ] W:\Fazil Say
[01/01/2007 - 00:00:00 | D ] W:\AAA ORAN
[01/01/2007 - 00:00:00 | N | 41080956] W:\Audio_065.wav
[18/04/2010 - 11:59:30 | N | 1270] W:\Alla turca jazz.mid
[28/02/2006 - 13:14:08 | N | 3102] W:\]
[01/01/2007 - 00:00:00 | N | 50303148] W:\Audio_066.wav
[01/01/2007 - 00:00:00 | D ] W:\GLASGOW
[24/04/2010 - 09:23:22 | N | 23266] W:\what_i_say_piano_2h_2.mid
[01/01/2007 - 00:00:00 | N | 27088908] W:\Audio_067.wav
[30/04/2010 - 23:14:54 | N | 7759] W:\lovstory.mid
[25/06/2010 - 20:55:10 | N | 1817] W:\GHOST.mid
[01/01/2007 - 00:00:00 | N | 38597244] W:\Audio_068.wav
[01/01/2007 - 00:00:00 | N | 22763580] W:\Audio_073.wav
[01/07/2010 - 20:38:12 | N | 5249567] W:\Audio_068.mp3
[27/05/2010 - 08:33:36 | N | 245540160] W:\VTS_01_1 T80 2_0ch 192Kbps DELAY 0ms.mp3
[02/07/2010 - 13:02:34 | D ] W:\_GENRATOR
[01/01/2007 - 00:00:00 | N | 20936076] W:\Audio_069.wav
[01/01/2007 - 00:00:00 | N | 35676060] W:\Audio_070.wav
[01/01/2007 - 00:00:00 | D ] W:\A NEW SONG
[01/01/2007 - 00:00:00 | N | 3080192] W:\Audio_074.wav
[07/08/2010 - 13:49:04 | D ] W:\_dum
[16/08/2010 - 18:48:08 | D ] W:\Report Project2
[22/09/2010 - 22:43:20 | D ] W:\_noty
[23/09/2010 - 17:26:26 | D ] W:\muse_midi
[01/01/2007 - 00:00:00 | N | 47558364] W:\Audio_071.wav
[02/10/2010 - 09:54:20 | D ] W:\queen
[01/01/2007 - 00:00:00 | N | 37027840] W:\Audio_072.wav
[06/11/2010 - 21:00:14 | D ] W:\a_midi
[12/11/2010 - 15:02:10 | D ] W:\_gogol
[29/12/2010 - 18:02:44 | D ] W:\_boogie
[01/01/2007 - 00:00:00 | N | 131072] W:\Audio_075.wav
[01/01/2007 - 00:00:00 | N | 3014656] W:\Audio_076.wav
[01/01/2007 - 00:00:00 | N | 24943884] W:\Audio_077.wav
[01/01/2007 - 00:00:00 | N | 4721] W:\NewSonGMY.MID
[03/01/2011 - 07:10:56 | D ] W:\_mp3
[25/02/2011 - 00:37:48 | D ] W:\Sinfonie Nr. 3 c-moll, Orgel-Sinfonie, op. 78
[01/01/2007 - 00:00:00 | N | 19333120] W:\Audio_078.wav
[09/12/2011 - 17:57:02 | D ] W:\_new
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
H:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
I:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
J:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
K:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
L:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
M:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
N:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
O:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
P:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
Q:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
S:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
W:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_COHENW7.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.
################## | E.O.F |
Re: Esetem hlaseny Agent.SDG.Gen Trojsky kun

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: RegLock:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] File:: c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000Core.job c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2794234989-373363643-3910967931-1000UA.job Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PWRISOVM.EXE"=- "QuickTime Task"=- Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
