Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

blue screen

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
berousek
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 08 bře 2012 18:33

blue screen

#1 Příspěvek od berousek »

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:05:14, on 27.3.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\windows\system32\taskeng.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
C:\windows\system32\conime.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Opera\opera.exe
C:\Users\kotulka\Desktop\RSIT.exe
C:\Program Files\trend micro\kotulka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE9ENUS/110
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 7307 bytes

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll [2010-08-14 423792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL [2010-06-13 80248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-02-03 1185120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-03-25 59272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-02-03 1185120]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll [2010-08-14 423792]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-11-07 177456]
"PTHOSTTR"=C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2007-01-10 145184]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-04-18 178712]
"HP Software Update"=c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-04-15 70912]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files\PDF Complete\pdfsty.exe [2007-05-08 331552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2008-04-21 197904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DVD Check.lnk]
C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2008-04-21 197904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2007-06-08 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\windows\System32\Notepad.exe %1
.js - open - C:\windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-03-27 19:04:06 ----D---- C:\Program Files\trend micro
2012-03-27 19:03:07 ----D---- C:\rsit
2012-03-27 18:31:01 ----D---- C:\Program Files\Common Files\Microsoft
2012-03-27 18:29:25 ----D---- C:\Common7
2012-03-27 18:28:09 ----D---- C:\Program Files\Windows Kits
2012-03-27 18:03:40 ----D---- C:\ProgramData\Package Cache
2012-03-27 17:51:02 ----D---- C:\Program Files\Symantec
2012-03-27 17:51:02 ----D---- C:\Program Files\Common Files\Symantec Shared
2012-03-27 17:51:02 ----A---- C:\windows\system32\drivers\SYMEVENT.SYS
2012-03-27 17:50:07 ----D---- C:\windows\system32\drivers\NIS
2012-03-27 17:50:03 ----D---- C:\Program Files\Norton Internet Security
2012-03-27 17:50:02 ----D---- C:\ProgramData\Norton
2012-03-27 17:46:51 ----D---- C:\ProgramData\NortonInstaller
2012-03-27 17:46:51 ----D---- C:\Program Files\NortonInstaller
2012-03-27 15:03:14 ----HD---- C:\windows\msdownld.tmp
2012-03-27 15:02:54 ----A---- C:\windows\system32\wininet.dll
2012-03-27 15:02:54 ----A---- C:\windows\system32\urlmon.dll
2012-03-27 15:02:54 ----A---- C:\windows\system32\msrating.dll
2012-03-27 15:02:54 ----A---- C:\windows\system32\msls31.dll
2012-03-27 15:02:54 ----A---- C:\windows\system32\jsproxy.dll
2012-03-27 15:02:54 ----A---- C:\windows\system32\iertutil.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\SetIEInstalledDate.exe
2012-03-27 15:02:53 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2012-03-27 15:02:53 ----A---- C:\windows\system32\mshtmler.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\ieui.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\iesysprep.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\ieframe.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\ieapfltr.dat
2012-03-27 15:02:53 ----A---- C:\windows\system32\dxtrans.dll
2012-03-27 15:02:53 ----A---- C:\windows\system32\dxtmsft.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\wextract.exe
2012-03-27 15:02:52 ----A---- C:\windows\system32\webcheck.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\vbscript.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\url.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\mshtmled.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\msfeeds.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\licmgr10.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\inseng.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\iexpress.exe
2012-03-27 15:02:52 ----A---- C:\windows\system32\iesetup.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\iernonce.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\iedkcs32.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\ieapfltr.dll
2012-03-27 15:02:52 ----A---- C:\windows\system32\ie4uinit.exe
2012-03-27 15:02:52 ----A---- C:\windows\system32\icardie.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\pngfilt.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\occache.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\mshtml.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\mshta.exe
2012-03-27 15:02:51 ----A---- C:\windows\system32\jscript9.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\jscript.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\imgutil.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\ieUnatt.exe
2012-03-27 15:02:51 ----A---- C:\windows\system32\iepeers.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\ieakui.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\ieaksie.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\advpack.dll
2012-03-27 15:02:51 ----A---- C:\windows\system32\admparse.dll
2012-03-27 15:02:50 ----A---- C:\windows\system32\msfeedssync.exe
2012-03-27 15:02:50 ----A---- C:\windows\system32\msfeedsbs.dll
2012-03-27 15:02:50 ----A---- C:\windows\system32\ieakeng.dll
2012-03-27 15:02:50 ----A---- C:\windows\system32\IEAdvpack.dll
2012-03-27 15:01:28 ----A---- C:\windows\system32\mfmp4src.dll
2012-03-27 15:01:28 ----A---- C:\windows\system32\MFHEAACdec.dll
2012-03-27 15:01:28 ----A---- C:\windows\system32\MFH264Dec.dll
2012-03-27 15:01:27 ----A---- C:\windows\system32\mfreadwrite.dll
2012-03-27 15:01:26 ----A---- C:\windows\system32\mfps.dll
2012-03-27 15:01:26 ----A---- C:\windows\system32\mfplat.dll
2012-03-27 15:01:26 ----A---- C:\windows\system32\mf.dll
2012-03-27 15:01:25 ----A---- C:\windows\system32\stobject.dll
2012-03-27 15:01:25 ----A---- C:\windows\system32\shdocvw.dll
2012-03-27 15:01:23 ----A---- C:\windows\system32\XpsGdiConverter.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\XpsRasterService.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\FntCache.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\DWrite.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\d3d10warp.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\d3d10level9.dll
2012-03-27 15:01:22 ----A---- C:\windows\system32\d2d1.dll
2012-03-27 15:01:21 ----A---- C:\windows\system32\dxgi.dll
2012-03-27 15:01:21 ----A---- C:\windows\system32\d3d10core.dll
2012-03-27 15:01:21 ----A---- C:\windows\system32\d3d10_1core.dll
2012-03-27 15:01:21 ----A---- C:\windows\system32\d3d10_1.dll
2012-03-27 15:01:21 ----A---- C:\windows\system32\d3d10.dll
2012-03-27 15:01:20 ----A---- C:\windows\system32\xpsservices.dll
2012-03-27 15:01:20 ----A---- C:\windows\system32\printfilterpipelinesvc.exe
2012-03-27 15:01:20 ----A---- C:\windows\system32\printfilterpipelineprxy.dll
2012-03-27 15:01:20 ----A---- C:\windows\system32\OpcServices.dll
2012-03-27 15:01:20 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2012-03-27 15:01:20 ----A---- C:\windows\system32\cdd.dll
2012-03-27 15:01:19 ----A---- C:\windows\system32\XpsPrint.dll
2012-03-27 14:55:57 ----A---- C:\windows\system32\WMPhoto.dll
2012-03-27 14:55:57 ----A---- C:\windows\system32\dxdiagn.dll
2012-03-27 14:55:57 ----A---- C:\windows\system32\dxdiag.exe
2012-03-27 14:55:57 ----A---- C:\windows\system32\d3d11.dll
2012-03-27 14:55:56 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2012-03-27 14:55:56 ----A---- C:\windows\system32\WindowsCodecs.dll
2012-03-27 14:55:56 ----A---- C:\windows\system32\PhotoMetadataHandler.dll
2012-03-27 14:22:37 ----A---- C:\windows\system32\pncrt.dll
2012-03-27 14:20:55 ----D---- C:\Program Files\FreeTime
2012-03-27 11:45:31 ----D---- C:\windows\system32\eu-ES
2012-03-27 11:45:31 ----D---- C:\windows\system32\ca-ES
2012-03-27 11:45:29 ----D---- C:\windows\system32\vi-VN
2012-03-27 11:39:28 ----D---- C:\windows\system32\SPReview
2012-03-27 09:49:55 ----D---- C:\56ad27a04f6795b1a933d34ecb52a2
2012-03-27 09:42:34 ----ASH---- C:\hiberfil.sys
2012-03-26 21:48:59 ----SHD---- C:\$RECYCLE.BIN
2012-03-26 17:40:36 ----A---- C:\windows\system32\scavenge.dll
2012-03-26 17:40:07 ----A---- C:\windows\system32\compcln.exe
2012-03-26 17:29:59 ----A---- C:\windows\system32\SearchProtocolHost.exe
2012-03-26 17:29:59 ----A---- C:\windows\system32\SearchFilterHost.exe
2012-03-26 17:29:58 ----A---- C:\windows\system32\SearchIndexer.exe
2012-03-26 17:29:58 ----A---- C:\windows\system32\sdohlp.dll
2012-03-26 17:29:58 ----A---- C:\windows\system32\rtffilt.dll
2012-03-26 17:29:58 ----A---- C:\windows\system32\rsaenh.dll
2012-03-26 17:29:57 ----A---- C:\windows\system32\samlib.dll
2012-03-26 17:29:57 ----A---- C:\windows\system32\drivers\rmcast.sys
2012-03-26 17:29:56 ----A---- C:\windows\system32\rpchttp.dll
2012-03-26 17:29:56 ----A---- C:\windows\system32\rpcss.dll
2012-03-26 17:29:56 ----A---- C:\windows\system32\riched20.dll
2012-03-26 17:29:56 ----A---- C:\windows\system32\drivers\RNDISMP.sys
2012-03-26 17:29:55 ----A---- C:\windows\system32\scrrun.dll
2012-03-26 17:29:54 ----A---- C:\windows\system32\SCardSvr.dll
2012-03-26 17:29:54 ----A---- C:\windows\system32\scansetting.dll
2012-03-26 17:29:54 ----A---- C:\windows\system32\samsrv.dll
2012-03-26 17:29:53 ----A---- C:\windows\system32\scrobj.dll
2012-03-26 17:29:53 ----A---- C:\windows\system32\scksp.dll
2012-03-26 17:29:53 ----A---- C:\windows\system32\scecli.dll
2012-03-26 17:29:52 ----A---- C:\windows\system32\scesrv.dll
2012-03-26 17:29:51 ----A---- C:\windows\system32\pdh.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\perfdisk.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\PerfCenterCPL.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\pcaui.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\p2psvc.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\P2PGraph.dll
2012-03-26 17:29:50 ----A---- C:\windows\system32\drivers\pciidex.sys
2012-03-26 17:29:50 ----A---- C:\windows\system32\drivers\pciide.sys
2012-03-26 17:29:50 ----A---- C:\windows\system32\drivers\pci.sys
2012-03-26 17:29:50 ----A---- C:\windows\system32\drivers\pacer.sys
2012-03-26 17:29:49 ----A---- C:\windows\system32\PortableDeviceApi.dll
2012-03-26 17:29:49 ----A---- C:\windows\system32\PNPXAssoc.dll
2012-03-26 17:29:49 ----A---- C:\windows\system32\PnPutil.exe
2012-03-26 17:29:49 ----A---- C:\windows\system32\PnPUnattend.exe
2012-03-26 17:29:49 ----A---- C:\windows\system32\pnpui.dll
2012-03-26 17:29:49 ----A---- C:\windows\system32\pnpsetup.dll
2012-03-26 17:29:49 ----A---- C:\windows\system32\pnidui.dll
2012-03-26 17:29:49 ----A---- C:\windows\system32\drivers\portcls.sys
2012-03-26 17:29:49 ----A---- C:\windows\system32\drivers\partmgr.sys
2012-03-26 17:29:48 ----A---- C:\windows\system32\powercpl.dll
2012-03-26 17:29:48 ----A---- C:\windows\system32\PortableDeviceTypes.dll
2012-03-26 17:29:48 ----A---- C:\windows\system32\PortableDeviceClassExtension.dll
2012-03-26 17:29:48 ----A---- C:\windows\system32\photowiz.dll
2012-03-26 17:29:47 ----A---- C:\windows\system32\pidgenx.dll
2012-03-26 17:29:47 ----A---- C:\windows\system32\PhotoScreensaver.scr
2012-03-26 17:29:46 ----A---- C:\windows\system32\PkgMgr.exe
2012-03-26 17:29:46 ----A---- C:\windows\system32\nslookup.exe
2012-03-26 17:29:46 ----A---- C:\windows\system32\drivers\npfs.sys
2012-03-26 17:29:45 ----A---- C:\windows\system32\drivers\ntfs.sys
2012-03-26 17:29:43 ----A---- C:\windows\system32\NlsLexicons0009.dll
2012-03-26 17:29:42 ----A---- C:\windows\system32\offfilt.dll
2012-03-26 17:29:42 ----A---- C:\windows\system32\NlsLexicons0007.dll
2012-03-26 17:29:42 ----A---- C:\windows\system32\nlhtml.dll
2012-03-26 17:29:41 ----A---- C:\windows\system32\osk.exe
2012-03-26 17:29:41 ----A---- C:\windows\system32\onex.dll
2012-03-26 17:29:41 ----A---- C:\windows\system32\odbccp32.dll
2012-03-26 17:29:41 ----A---- C:\windows\system32\odbcconf.dll
2012-03-26 17:29:40 ----A---- C:\windows\system32\oobefldr.dll
2012-03-26 17:29:40 ----A---- C:\windows\system32\olepro32.dll
2012-03-26 17:29:40 ----A---- C:\windows\system32\oleprn.dll
2012-03-26 17:29:39 ----A---- C:\windows\system32\ocsetup.exe
2012-03-26 17:29:39 ----A---- C:\windows\system32\ntprint.dll
2012-03-26 17:29:39 ----A---- C:\windows\system32\ntmarta.dll
2012-03-26 17:29:39 ----A---- C:\windows\system32\drivers\nwifi.sys
2012-03-26 17:29:38 ----A---- C:\windows\system32\rasdlg.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rastapi.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasmontr.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasmans.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\raschap.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasgcw.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasdial.exe
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasdiag.dll
2012-03-26 17:29:37 ----A---- C:\windows\system32\rasapi32.dll
2012-03-26 17:29:36 ----A---- C:\windows\system32\rasppp.dll
2012-03-26 17:29:36 ----A---- C:\windows\system32\rasplap.dll
2012-03-26 17:29:36 ----A---- C:\windows\system32\Query.dll
2012-03-26 17:29:36 ----A---- C:\windows\system32\drivers\rassstp.sys
2012-03-26 17:29:36 ----A---- C:\windows\system32\drivers\raspppoe.sys
2012-03-26 17:29:35 ----A---- C:\windows\system32\RacEngn.dll
2012-03-26 17:29:35 ----A---- C:\windows\system32\qmgr.dll
2012-03-26 17:29:35 ----A---- C:\windows\system32\qedit.dll
2012-03-26 17:29:34 ----A---- C:\windows\system32\RelMon.dll
2012-03-26 17:29:34 ----A---- C:\windows\system32\rekeywiz.exe
2012-03-26 17:29:34 ----A---- C:\windows\system32\regsvc.dll
2012-03-26 17:29:32 ----A---- C:\windows\system32\reg.exe
2012-03-26 17:29:32 ----A---- C:\windows\system32\rdpencom.dll
2012-03-26 17:29:32 ----A---- C:\windows\system32\drivers\rdbss.sys
2012-03-26 17:29:31 ----A---- C:\windows\system32\regapi.dll
2012-03-26 17:29:31 ----A---- C:\windows\system32\rdpwsx.dll
2012-03-26 17:29:31 ----A---- C:\windows\system32\PresentationNative_v0300.dll
2012-03-26 17:29:31 ----A---- C:\windows\system32\drivers\rdpwd.sys
2012-03-26 17:29:30 ----A---- C:\windows\system32\prnntfy.dll
2012-03-26 17:29:30 ----A---- C:\windows\system32\printui.dll
2012-03-26 17:29:29 ----A---- C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2012-03-26 17:29:29 ----A---- C:\windows\system32\powrprof.dll
2012-03-26 17:29:27 ----A---- C:\windows\system32\qdvd.dll
2012-03-26 17:29:27 ----A---- C:\windows\system32\QAGENTRT.DLL
2012-03-26 17:29:27 ----A---- C:\windows\system32\puiapi.dll
2012-03-26 17:29:26 ----A---- C:\windows\system32\propsys.dll
2012-03-26 17:29:26 ----A---- C:\windows\system32\propdefs.dll
2012-03-26 17:29:26 ----A---- C:\windows\system32\profsvc.dll
2012-03-26 17:29:25 ----A---- C:\windows\system32\psisdecd.dll
2012-03-26 17:29:25 ----A---- C:\windows\system32\PSHED.DLL
2012-03-26 17:29:24 ----A---- C:\windows\system32\sendmail.dll
2012-03-26 17:29:21 ----A---- C:\windows\system32\services.exe
2012-03-26 17:29:20 ----A---- C:\windows\system32\sethc.exe
2012-03-26 17:29:19 ----A---- C:\windows\system32\setupapi.dll
2012-03-26 17:29:17 ----A---- C:\windows\system32\eapphost.dll
2012-03-26 17:29:17 ----A---- C:\windows\system32\eappgnui.dll
2012-03-26 17:29:17 ----A---- C:\windows\system32\drivers\ecache.sys
2012-03-26 17:29:16 ----A---- C:\windows\system32\EhStorAPI.dll
2012-03-26 17:29:16 ----A---- C:\windows\system32\eappcfg.dll
2012-03-26 17:29:16 ----A---- C:\windows\system32\eapp3hst.dll
2012-03-26 17:29:15 ----A---- C:\windows\system32\dsprop.dll
2012-03-26 17:29:15 ----A---- C:\windows\system32\dsound.dll
2012-03-26 17:29:15 ----A---- C:\windows\system32\drivers\Dumpata.sys
2012-03-26 17:29:14 ----A---- C:\windows\system32\ExplorerFrame.dll
2012-03-26 17:29:14 ----A---- C:\windows\system32\evr.dll
2012-03-26 17:29:14 ----A---- C:\windows\system32\eudcedit.exe
2012-03-26 17:29:14 ----A---- C:\windows\system32\dwm.exe
2012-03-26 17:29:14 ----A---- C:\windows\system32\drivers\exfat.sys
2012-03-26 17:29:14 ----A---- C:\windows\system32\drivers\dxg.sys
2012-03-26 17:29:13 ----A---- C:\windows\explorer.exe
2012-03-26 17:29:12 ----A---- C:\windows\system32\f3ahvoas.dll
2012-03-26 17:29:12 ----A---- C:\windows\system32\esent.dll
2012-03-26 17:29:11 ----A---- C:\windows\system32\emdmgmt.dll
2012-03-26 17:29:11 ----A---- C:\windows\system32\EhStorPwdMgr.dll
2012-03-26 17:29:11 ----A---- C:\windows\system32\EhStorAuthn.dll
2012-03-26 17:29:10 ----A---- C:\windows\system32\es.dll
2012-03-26 17:29:10 ----A---- C:\windows\system32\EhStorShell.dll
2012-03-26 17:29:10 ----A---- C:\windows\system32\dimsroam.dll
2012-03-26 17:29:10 ----A---- C:\windows\system32\diagperf.dll
2012-03-26 17:29:09 ----A---- C:\windows\system32\drivers\Diskdump.sys
2012-03-26 17:29:09 ----A---- C:\windows\system32\drivers\disk.sys
2012-03-26 17:29:09 ----A---- C:\windows\system32\diskraid.exe
2012-03-26 17:29:09 ----A---- C:\windows\system32\diskpart.exe
2012-03-26 17:29:09 ----A---- C:\windows\system32\dhcpcsvc6.dll
2012-03-26 17:29:08 ----A---- C:\windows\system32\dfsr.exe
2012-03-26 17:29:08 ----A---- C:\windows\system32\devmgr.dll
2012-03-26 17:29:07 ----A---- C:\windows\system32\dhcpcsvc.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\drvstore.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\drvinst.exe
2012-03-26 17:29:06 ----A---- C:\windows\system32\drmv2clt.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\drmmgrtn.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\dpapimig.exe
2012-03-26 17:29:06 ----A---- C:\windows\system32\dot3svc.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\dot3msm.dll
2012-03-26 17:29:06 ----A---- C:\windows\system32\dot3cfg.dll
2012-03-26 17:29:05 ----A---- C:\windows\system32\hbaapi.dll
2012-03-26 17:29:05 ----A---- C:\windows\system32\dmusic.dll
2012-03-26 17:29:05 ----A---- C:\windows\system32\dmsynth.dll
2012-03-26 17:29:04 ----A---- C:\windows\system32\gpresult.exe
2012-03-26 17:29:04 ----A---- C:\windows\system32\drivers\hdaudbus.sys
2012-03-26 17:29:03 ----A---- C:\windows\system32\iasads.dll
2012-03-26 17:29:03 ----A---- C:\windows\system32\gpupdate.exe
2012-03-26 17:29:03 ----A---- C:\windows\system32\gpsvc.dll
2012-03-26 17:29:02 ----A---- C:\windows\system32\iasnap.dll
2012-03-26 17:29:02 ----A---- C:\windows\system32\IasMigReader.exe
2012-03-26 17:29:02 ----A---- C:\windows\system32\IasMigPlugin.dll
2012-03-26 17:29:02 ----A---- C:\windows\system32\iashlpr.dll
2012-03-26 17:29:02 ----A---- C:\windows\system32\iasdatastore.dll
2012-03-26 17:29:02 ----A---- C:\windows\system32\iasacct.dll
2012-03-26 17:29:01 ----A---- C:\windows\system32\hidserv.dll
2012-03-26 17:29:01 ----A---- C:\windows\system32\hdwwiz.exe
2012-03-26 17:29:01 ----A---- C:\windows\system32\fontext.dll
2012-03-26 17:29:01 ----A---- C:\windows\system32\drivers\hidusb.sys
2012-03-26 17:29:01 ----A---- C:\windows\system32\drivers\hidclass.sys
2012-03-26 17:29:01 ----A---- C:\windows\system32\drivers\fltMgr.sys
2012-03-26 17:29:00 ----A---- C:\windows\system32\findstr.exe
2012-03-26 17:29:00 ----A---- C:\windows\system32\feclient.dll
2012-03-26 17:29:00 ----A---- C:\windows\system32\fdWSD.dll
2012-03-26 17:29:00 ----A---- C:\windows\system32\fdWCN.dll
2012-03-26 17:29:00 ----A---- C:\windows\system32\fdSSDP.dll
2012-03-26 17:29:00 ----A---- C:\windows\system32\fc.exe
2012-03-26 17:29:00 ----A---- C:\windows\system32\Faultrep.dll
2012-03-26 17:29:00 ----A---- C:\windows\system32\drivers\fastfat.sys
2012-03-26 17:28:59 ----A---- C:\windows\system32\gpapi.dll
2012-03-26 17:28:59 ----A---- C:\windows\system32\gdi32.dll
2012-03-26 17:28:59 ----A---- C:\windows\system32\fdProxy.dll
2012-03-26 17:28:59 ----A---- C:\windows\system32\fdeploy.dll
2012-03-26 17:28:59 ----A---- C:\windows\system32\fdBthProxy.dll
2012-03-26 17:28:59 ----A---- C:\windows\system32\fdBth.dll
2012-03-26 17:28:58 ----A---- C:\windows\system32\gpedit.dll
2012-03-26 17:28:57 ----A---- C:\windows\system32\fundisc.dll
2012-03-26 17:28:57 ----A---- C:\windows\system32\FunctionDiscoveryFolder.dll
2012-03-26 17:28:57 ----A---- C:\windows\system32\ftp.exe
2012-03-26 17:28:56 ----A---- C:\windows\system32\FwRemoteSvr.dll
2012-03-26 17:28:56 ----A---- C:\windows\system32\FWPUCLNT.DLL
2012-03-26 17:28:56 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2012-03-26 17:28:56 ----A---- C:\windows\system32\audiosrv.dll
2012-03-26 17:28:55 ----A---- C:\windows\system32\drivers\ataport.sys
2012-03-26 17:28:55 ----A---- C:\windows\system32\autochk.exe
2012-03-26 17:28:55 ----A---- C:\windows\system32\authz.dll
2012-03-26 17:28:55 ----A---- C:\windows\system32\authui.dll
2012-03-26 17:28:55 ----A---- C:\windows\system32\AudioSes.dll
2012-03-26 17:28:55 ----A---- C:\windows\system32\audiodg.exe
2012-03-26 17:28:54 ----A---- C:\windows\system32\autoplay.dll
2012-03-26 17:28:54 ----A---- C:\windows\system32\autofmt.exe
2012-03-26 17:28:54 ----A---- C:\windows\system32\autoconv.exe
2012-03-26 17:28:52 ----A---- C:\windows\system32\drivers\atapi.sys
2012-03-26 17:28:52 ----A---- C:\windows\system32\brcpl.dll
2012-03-26 17:28:51 ----A---- C:\windows\system32\drivers\bridge.sys
2012-03-26 17:28:51 ----A---- C:\windows\system32\bthci.dll
2012-03-26 17:28:51 ----A---- C:\windows\system32\browseui.dll
2012-03-26 17:28:51 ----A---- C:\windows\system32\basecsp.dll
2012-03-26 17:28:50 ----A---- C:\windows\system32\drivers\acpi.sys
2012-03-26 17:28:50 ----A---- C:\windows\system32\blackbox.dll
2012-03-26 17:28:50 ----A---- C:\windows\system32\bitsigd.dll
2012-03-26 17:28:50 ----A---- C:\windows\system32\BFE.DLL
2012-03-26 17:28:50 ----A---- C:\windows\system32\bcrypt.dll
2012-03-26 17:28:50 ----A---- C:\windows\system32\azroles.dll
2012-03-26 17:28:49 ----A---- C:\windows\system32\accessibilitycpl.dll
2012-03-26 17:28:47 ----A---- C:\windows\system32\apphelp.dll
2012-03-26 17:28:47 ----A---- C:\windows\system32\apds.dll
2012-03-26 17:28:46 ----A---- C:\windows\system32\adsmsext.dll
2012-03-26 17:28:46 ----A---- C:\windows\system32\adsldpc.dll
2012-03-26 17:28:45 ----A---- C:\windows\system32\conime.exe
2012-03-26 17:28:45 ----A---- C:\windows\system32\comuid.dll
2012-03-26 17:28:45 ----A---- C:\windows\system32\comsvcs.dll
2012-03-26 17:28:45 ----A---- C:\windows\system32\advapi32.dll
2012-03-26 17:28:45 ----A---- C:\windows\system32\adtschema.dll
2012-03-26 17:28:44 ----A---- C:\windows\system32\drivers\crashdmp.sys
2012-03-26 17:28:44 ----A---- C:\windows\system32\crypt32.dll
2012-03-26 17:28:44 ----A---- C:\windows\system32\credui.dll
2012-03-26 17:28:44 ----A---- C:\windows\system32\connect.dll
2012-03-26 17:28:43 ----A---- C:\windows\system32\comdlg32.dll
2012-03-26 17:28:43 ----A---- C:\windows\system32\cmdial32.dll
2012-03-26 17:28:41 ----A---- C:\windows\system32\dbgeng.dll
2012-03-26 17:28:41 ----A---- C:\windows\system32\davclnt.dll
2012-03-26 17:28:41 ----A---- C:\windows\system32\cmmon32.exe
2012-03-26 17:28:40 ----A---- C:\windows\system32\DevicePairingWizard.exe
2012-03-26 17:28:40 ----A---- C:\windows\system32\DevicePairingProxy.dll
2012-03-26 17:28:40 ----A---- C:\windows\system32\DevicePairing.dll
2012-03-26 17:28:40 ----A---- C:\windows\system32\DeviceEject.exe
2012-03-26 17:28:40 ----A---- C:\windows\system32\dataclen.dll
2012-03-26 17:28:40 ----A---- C:\windows\system32\d3d9.dll
2012-03-26 17:28:39 ----A---- C:\windows\system32\cscdll.dll
2012-03-26 17:28:39 ----A---- C:\windows\system32\cscapi.dll
2012-03-26 17:28:39 ----A---- C:\windows\system32\cryptui.dll
2012-03-26 17:28:39 ----A---- C:\windows\system32\cryptsvc.dll
2012-03-26 17:28:38 ----A---- C:\windows\system32\drivers\cdrom.sys
2012-03-26 17:28:38 ----A---- C:\windows\system32\csrstub.exe
2012-03-26 17:28:38 ----A---- C:\windows\system32\cscript.exe
2012-03-26 17:28:37 ----A---- C:\windows\system32\certmgr.dll
2012-03-26 17:28:37 ----A---- C:\windows\system32\CertEnrollUI.dll
2012-03-26 17:28:37 ----A---- C:\windows\system32\CertEnroll.dll
2012-03-26 17:28:37 ----A---- C:\windows\system32\certcli.dll
2012-03-26 17:28:36 ----A---- C:\windows\system32\cbsra.exe
2012-03-26 17:28:36 ----A---- C:\windows\system32\bthudtask.exe
2012-03-26 17:28:36 ----A---- C:\windows\system32\bthserv.dll
2012-03-26 17:28:35 ----A---- C:\windows\system32\CHxReadingStringIME.dll
2012-03-26 17:28:35 ----A---- C:\windows\system32\chsbrkr.dll
2012-03-26 17:28:35 ----A---- C:\windows\system32\drivers\Classpnp.sys
2012-03-26 17:28:35 ----A---- C:\windows\system32\cipher.exe
2012-03-26 17:28:35 ----A---- C:\windows\system32\ci.dll
2012-03-26 17:28:34 ----A---- C:\windows\system32\chtbrkr.dll
2012-03-26 17:28:34 ----A---- C:\windows\system32\clfs.sys
2012-03-26 17:28:34 ----A---- C:\windows\system32\certreq.exe
2012-03-26 17:28:34 ----A---- C:\windows\system32\certprop.dll
2012-03-26 17:28:33 ----A---- C:\windows\system32\msftedit.dll
2012-03-26 17:28:33 ----A---- C:\windows\system32\certutil.exe
2012-03-26 17:28:32 ----A---- C:\windows\system32\msihnd.dll
2012-03-26 17:28:32 ----A---- C:\windows\system32\msiexec.exe
2012-03-26 17:28:32 ----A---- C:\windows\system32\msexch40.dll
2012-03-26 17:28:32 ----A---- C:\windows\system32\msexcl40.dll
2012-03-26 17:28:32 ----A---- C:\windows\system32\msdtctm.dll
2012-03-26 17:28:31 ----A---- C:\windows\system32\msi.dll
2012-03-26 17:28:30 ----A---- C:\windows\system32\msdtcprx.dll
2012-03-26 17:28:29 ----A---- C:\windows\system32\msctfui.dll
2012-03-26 17:28:29 ----A---- C:\windows\system32\msctfp.dll
2012-03-26 17:28:29 ----A---- C:\windows\system32\MsCtfMonitor.dll
2012-03-26 17:28:29 ----A---- C:\windows\system32\msctf.dll
2012-03-26 17:28:28 ----A---- C:\windows\system32\msimsg.dll
2012-03-26 17:28:27 ----A---- C:\windows\system32\MPSSVC.dll
2012-03-26 17:28:26 ----A---- C:\windows\system32\mprapi.dll
2012-03-26 17:28:26 ----A---- C:\windows\system32\mpr.dll
2012-03-26 17:28:25 ----A---- C:\windows\system32\modemui.dll
2012-03-26 17:28:25 ----A---- C:\windows\system32\MMDevAPI.dll
2012-03-26 17:28:23 ----A---- C:\windows\system32\mscms.dll
2012-03-26 17:28:23 ----A---- C:\windows\system32\mscandui.dll
2012-03-26 17:28:22 ----A---- C:\windows\system32\mscories.dll
2012-03-26 17:28:22 ----A---- C:\windows\system32\mscorier.dll
2012-03-26 17:28:21 ----A---- C:\windows\system32\drivers\mrxdav.sys
2012-03-26 17:28:20 ----A---- C:\windows\system32\netcenter.dll
2012-03-26 17:28:20 ----A---- C:\windows\system32\netapi32.dll
2012-03-26 17:28:20 ----A---- C:\windows\system32\ncryptui.dll
2012-03-26 17:28:20 ----A---- C:\windows\system32\ncrypt.dll
2012-03-26 17:28:20 ----A---- C:\windows\system32\drivers\netbt.sys
2012-03-26 17:28:19 ----A---- C:\windows\system32\netplwiz.dll
2012-03-26 17:28:19 ----A---- C:\windows\system32\netlogon.dll
2012-03-26 17:28:19 ----A---- C:\windows\system32\drivers\netio.sys
2012-03-26 17:28:19 ----A---- C:\windows\system32\drivers\ndiswan.sys
2012-03-26 17:28:19 ----A---- C:\windows\system32\drivers\ndis.sys
2012-03-26 17:28:18 ----A---- C:\windows\system32\mtxclu.dll
2012-03-26 17:28:18 ----A---- C:\windows\system32\drivers\mup.sys
2012-03-26 17:28:16 ----A---- C:\windows\system32\NcdProp.dll
2012-03-26 17:28:16 ----A---- C:\windows\system32\NaturalLanguage6.dll
2012-03-26 17:28:15 ----A---- C:\windows\system32\netshell.dll
2012-03-26 17:28:14 ----A---- C:\windows\system32\newdev.exe
2012-03-26 17:28:14 ----A---- C:\windows\system32\newdev.dll
2012-03-26 17:28:14 ----A---- C:\windows\system32\networkexplorer.dll
2012-03-26 17:28:13 ----A---- C:\windows\system32\networkmap.dll
2012-03-26 17:28:13 ----A---- C:\windows\system32\networkitemfactory.dll
2012-03-26 17:28:13 ----A---- C:\windows\system32\msnetobj.dll
2012-03-26 17:28:13 ----A---- C:\windows\system32\msltus40.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msscntrs.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msscb.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msrepl40.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msrd3x40.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msrd2x40.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\mspbde40.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\msinfo32.exe
2012-03-26 17:28:12 ----A---- C:\windows\system32\msimtf.dll
2012-03-26 17:28:12 ----A---- C:\windows\system32\drivers\msrpc.sys
2012-03-26 17:28:11 ----A---- C:\windows\system32\msjtes40.dll
2012-03-26 17:28:11 ----A---- C:\windows\system32\msjter40.dll
2012-03-26 17:28:11 ----A---- C:\windows\system32\msjint40.dll
2012-03-26 17:28:11 ----A---- C:\windows\system32\msjetoledb40.dll
2012-03-26 17:28:11 ----A---- C:\windows\system32\drivers\msiscsi.sys
2012-03-26 17:28:10 ----A---- C:\windows\system32\msvcp60.dll
2012-03-26 17:28:10 ----A---- C:\windows\system32\msutb.dll
2012-03-26 17:28:10 ----A---- C:\windows\system32\msjet40.dll
2012-03-26 17:28:10 ----A---- C:\windows\system32\msisip.dll
2012-03-26 17:28:09 ----A---- C:\windows\system32\msxbde40.dll
2012-03-26 17:28:09 ----A---- C:\windows\system32\mswstr10.dll
2012-03-26 17:28:09 ----A---- C:\windows\system32\mswsock.dll
2012-03-26 17:28:09 ----A---- C:\windows\system32\mswdat10.dll
2012-03-26 17:28:08 ----A---- C:\windows\system32\MSVidCtl.dll
2012-03-26 17:28:08 ----A---- C:\windows\system32\msvcrt.dll
2012-03-26 17:28:08 ----A---- C:\windows\system32\mssphtb.dll
2012-03-26 17:28:08 ----A---- C:\windows\system32\mssph.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\mstlsapi.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\mssvp.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\msstrc.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\mssrch.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\mssprxy.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\mssitlb.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\msshsq.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\msshooks.dll
2012-03-26 17:28:07 ----A---- C:\windows\system32\msscp.dll
2012-03-26 17:28:06 ----A---- C:\windows\system32\mstext40.dll
2012-03-26 17:28:05 ----A---- C:\windows\system32\InkEd.dll
2012-03-26 17:28:04 ----A---- C:\windows\system32\infocardapi.dll
2012-03-26 17:28:04 ----A---- C:\windows\system32\inetppui.dll
2012-03-26 17:28:04 ----A---- C:\windows\system32\inetpp.dll
2012-03-26 17:28:03 ----A---- C:\windows\system32\imm32.dll
2012-03-26 17:28:02 ----A---- C:\windows\system32\iscsilog.dll
2012-03-26 17:28:02 ----A---- C:\windows\system32\ipsmsnap.dll
2012-03-26 17:28:02 ----A---- C:\windows\system32\IPSECSVC.DLL
2012-03-26 17:28:01 ----A---- C:\windows\system32\input.dll
2012-03-26 17:28:00 ----A---- C:\windows\system32\ipsecsnp.dll
2012-03-26 17:28:00 ----A---- C:\windows\system32\IPHLPAPI.DLL
2012-03-26 17:28:00 ----A---- C:\windows\system32\ipconfig.exe
2012-03-26 17:27:58 ----A---- C:\windows\system32\ifmon.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\icardres.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\icardagt.exe
2012-03-26 17:27:58 ----A---- C:\windows\system32\iassvcs.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\iassdo.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\iassam.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\iasrecst.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\iasrad.dll
2012-03-26 17:27:58 ----A---- C:\windows\system32\iaspolcy.dll
2012-03-26 17:27:57 ----A---- C:\windows\system32\IMJP10K.DLL
2012-03-26 17:27:56 ----A---- C:\windows\system32\imapi.dll
2012-03-26 17:27:55 ----A---- C:\windows\system32\imapi2fs.dll
2012-03-26 17:27:55 ----A---- C:\windows\system32\imapi2.dll
2012-03-26 17:27:55 ----A---- C:\windows\system32\IKEEXT.DLL
2012-03-26 17:27:49 ----A---- C:\windows\system32\milcore.dll
2012-03-26 17:27:48 ----A---- C:\windows\system32\mmcndmgr.dll
2012-03-26 17:27:48 ----A---- C:\windows\system32\mmcico.dll
2012-03-26 17:27:48 ----A---- C:\windows\system32\mmci.dll
2012-03-26 17:27:48 ----A---- C:\windows\system32\mimefilt.dll
2012-03-26 17:27:48 ----A---- C:\windows\system32\midimap.dll
2012-03-26 17:27:47 ----A---- C:\windows\system32\mmc.exe
2012-03-26 17:27:45 ----A---- C:\windows\system32\korwbrkr.dll
2012-03-26 17:27:45 ----A---- C:\windows\system32\drivers\ks.sys
2012-03-26 17:27:44 ----A---- C:\windows\system32\l2nacp.dll
2012-03-26 17:27:44 ----A---- C:\windows\system32\kdusb.dll
2012-03-26 17:27:44 ----A---- C:\windows\system32\kdcom.dll
2012-03-26 17:27:44 ----A---- C:\windows\system32\kd1394.dll
2012-03-26 17:27:44 ----A---- C:\windows\system32\drivers\kbdhid.sys
2012-03-26 17:27:43 ----A---- C:\windows\system32\mcupdate_GenuineIntel.dll
2012-03-26 17:27:43 ----A---- C:\windows\system32\mblctr.exe
2012-03-26 17:27:42 ----A---- C:\windows\system32\MediaMetadataHandler.dll
2012-03-26 17:27:42 ----A---- C:\windows\system32\logman.exe
2012-03-26 17:27:42 ----A---- C:\windows\system32\logagent.exe
2012-03-26 17:27:40 ----A---- C:\windows\system32\shsetup.dll
2012-03-26 17:27:40 ----A---- C:\windows\system32\Magnify.exe
2012-03-26 17:27:39 ----A---- C:\windows\system32\wercon.exe
2012-03-26 17:27:39 ----A---- C:\windows\system32\wer.dll
2012-03-26 17:27:39 ----A---- C:\windows\system32\WebClnt.dll
2012-03-26 17:27:39 ----A---- C:\windows\system32\wdscore.dll
2012-03-26 17:27:38 ----A---- C:\windows\system32\wdc.dll
2012-03-26 17:27:36 ----A---- C:\windows\system32\WindowsAnytimeUpgradeCPL.dll
2012-03-26 17:27:35 ----A---- C:\windows\system32\wevtutil.exe
2012-03-26 17:27:35 ----A---- C:\windows\system32\wevtsvc.dll
2012-03-26 17:27:34 ----A---- C:\windows\system32\whealogr.dll
2012-03-26 17:27:34 ----A---- C:\windows\system32\wevtapi.dll
2012-03-26 17:27:34 ----A---- C:\windows\system32\wersvc.dll
2012-03-26 17:27:34 ----A---- C:\windows\system32\WerFaultSecure.exe
2012-03-26 17:27:34 ----A---- C:\windows\system32\WerFault.exe
2012-03-26 17:27:33 ----A---- C:\windows\system32\win32spl.dll
2012-03-26 17:27:33 ----A---- C:\windows\system32\wiaservc.dll
2012-03-26 17:27:33 ----A---- C:\windows\system32\wiaaut.dll
2012-03-26 17:27:32 ----A---- C:\windows\system32\version.dll
2012-03-26 17:27:32 ----A---- C:\windows\system32\vdsutil.dll
2012-03-26 17:27:32 ----A---- C:\windows\system32\vdsdyn.dll
2012-03-26 17:27:32 ----A---- C:\windows\system32\vds.exe
2012-03-26 17:27:32 ----A---- C:\windows\system32\vdmdbg.dll
2012-03-26 17:27:30 ----A---- C:\windows\system32\uxsms.dll
2012-03-26 17:27:30 ----A---- C:\windows\system32\Utilman.exe
2012-03-26 17:27:30 ----A---- C:\windows\system32\user32.dll
2012-03-26 17:27:30 ----A---- C:\windows\system32\drivers\usbport.sys
2012-03-26 17:27:29 ----A---- C:\windows\system32\userenv.dll
2012-03-26 17:27:29 ----A---- C:\windows\system32\usercpl.dll
2012-03-26 17:27:28 ----A---- C:\windows\system32\wcnwiz2.dll
2012-03-26 17:27:28 ----A---- C:\windows\system32\wcnwiz.dll
2012-03-26 17:27:28 ----A---- C:\windows\system32\WcnNetsh.dll
2012-03-26 17:27:28 ----A---- C:\windows\system32\wcncsvc.dll
2012-03-26 17:27:28 ----A---- C:\windows\system32\drivers\watchdog.sys
2012-03-26 17:27:27 ----A---- C:\windows\system32\VSSVC.exe
2012-03-26 17:27:27 ----A---- C:\windows\system32\drivers\volmgrx.sys
2012-03-26 17:27:26 ----A---- C:\windows\system32\wscapi.dll
2012-03-26 17:27:26 ----A---- C:\windows\system32\w32time.dll
2012-03-26 17:27:26 ----A---- C:\windows\system32\vssapi.dll
2012-03-26 17:27:26 ----A---- C:\windows\system32\drivers\volsnap.sys
2012-03-26 17:27:25 ----A---- C:\windows\system32\WSDMon.dll
2012-03-26 17:27:25 ----A---- C:\windows\system32\wsdchngr.dll
2012-03-26 17:27:25 ----A---- C:\windows\system32\wscript.exe
2012-03-26 17:27:25 ----A---- C:\windows\system32\wscntfy.dll
2012-03-26 17:27:25 ----A---- C:\windows\system32\wscisvif.dll
2012-03-26 17:27:25 ----A---- C:\windows\system32\WscEapPr.dll
2012-03-26 17:27:24 ----A---- C:\windows\system32\wscsvc.dll
2012-03-26 17:27:24 ----A---- C:\windows\system32\wow32.dll
2012-03-26 17:27:24 ----A---- C:\windows\system32\WMVXENCD.DLL
2012-03-26 17:27:24 ----A---- C:\windows\system32\WMVSDECD.DLL
2012-03-26 17:27:24 ----A---- C:\windows\system32\WMVENCOD.DLL
2012-03-26 17:27:23 ----A---- C:\windows\system32\wpccpl.dll
2012-03-26 17:27:23 ----A---- C:\windows\system32\wpcao.dll
2012-03-26 17:27:22 ----A---- C:\windows\system32\wusa.exe
2012-03-26 17:27:22 ----A---- C:\windows\system32\wpcsvc.dll
2012-03-26 17:27:21 ----A---- C:\windows\system32\xmlfilter.dll
2012-03-26 17:27:20 ----A---- C:\windows\system32\wshext.dll
2012-03-26 17:27:20 ----A---- C:\windows\system32\wshbth.dll
2012-03-26 17:27:20 ----A---- C:\windows\system32\wsepno.dll
2012-03-26 17:27:19 ----A---- C:\windows\system32\wsnmp32.dll
2012-03-26 17:27:19 ----A---- C:\windows\system32\wlanpref.dll
2012-03-26 17:27:18 ----A---- C:\windows\system32\wlgpclnt.dll
2012-03-26 17:27:18 ----A---- C:\windows\system32\Wldap32.dll
2012-03-26 17:27:18 ----A---- C:\windows\system32\wlanui.dll
2012-03-26 17:27:18 ----A---- C:\windows\system32\wlangpui.dll
2012-03-26 17:27:18 ----A---- C:\windows\system32\wisptis.exe
2012-03-26 17:27:17 ----A---- C:\windows\system32\WinSCard.dll
2012-03-26 17:27:17 ----A---- C:\windows\system32\WinSAT.exe
2012-03-26 17:27:17 ----A---- C:\windows\system32\winrnr.dll
2012-03-26 17:27:17 ----A---- C:\windows\system32\winresume.exe
2012-03-26 17:27:16 ----A---- C:\windows\system32\winmm.dll
2012-03-26 17:27:16 ----A---- C:\windows\system32\winlogon.exe
2012-03-26 17:27:16 ----A---- C:\windows\system32\winload.exe
2012-03-26 17:27:14 ----A---- C:\windows\system32\wmpeffects.dll
2012-03-26 17:27:14 ----A---- C:\windows\system32\WMNetMgr.dll
2012-03-26 17:27:11 ----A---- C:\windows\system32\wmdrmsdk.dll
2012-03-26 17:27:09 ----A---- C:\windows\system32\Storprop.dll
2012-03-26 17:27:09 ----A---- C:\windows\system32\drivers\stream.sys
2012-03-26 17:27:09 ----A---- C:\windows\system32\drivers\Storport.sys
2012-03-26 17:27:08 ----A---- C:\windows\system32\sud.dll
2012-03-26 17:27:07 ----A---- C:\windows\system32\srchadmin.dll
2012-03-26 17:27:07 ----A---- C:\windows\system32\srcore.dll
2012-03-26 17:27:00 ----A---- C:\windows\system32\sysmain.dll
2012-03-26 17:27:00 ----A---- C:\windows\system32\sysclass.dll
2012-03-26 17:27:00 ----A---- C:\windows\system32\swprv.dll
2012-03-26 17:26:59 ----A---- C:\windows\system32\SyncCenter.dll
2012-03-26 17:26:58 ----A---- C:\windows\system32\smss.exe
2012-03-26 17:26:58 ----A---- C:\windows\system32\SMBHelperClass.dll
2012-03-26 17:26:58 ----A---- C:\windows\system32\SmartcardCredentialProvider.dll
2012-03-26 17:26:58 ----A---- C:\windows\system32\slwmi.dll
2012-03-26 17:26:58 ----A---- C:\windows\system32\drivers\smb.sys
2012-03-26 17:26:57 ----A---- C:\windows\system32\SmiEngine.dll
2012-03-26 17:26:57 ----A---- C:\windows\system32\slcc.dll
2012-03-26 17:26:56 ----A---- C:\windows\system32\SLsvc.exe
2012-03-26 17:26:56 ----A---- C:\windows\system32\SLC.dll
2012-03-26 17:26:56 ----A---- C:\windows\system32\shwebsvc.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\spoolss.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\spinstall.exe
2012-03-26 17:26:55 ----A---- C:\windows\system32\slwga.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\SLUINotify.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\SLUI.exe
2012-03-26 17:26:55 ----A---- C:\windows\system32\slmgr.vbs
2012-03-26 17:26:55 ----A---- C:\windows\system32\SLLUA.exe
2012-03-26 17:26:55 ----A---- C:\windows\system32\SLCommDlg.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\slcinst.dll
2012-03-26 17:26:55 ----A---- C:\windows\system32\SLCExt.dll
2012-03-26 17:26:54 ----A---- C:\windows\system32\spp.dll
2012-03-26 17:26:54 ----A---- C:\windows\system32\spcmsg.dll
2012-03-26 17:26:53 ----A---- C:\windows\system32\sqlsrv32.dll
2012-03-26 17:26:53 ----A---- C:\windows\system32\spwizui.dll
2012-03-26 17:26:53 ----A---- C:\windows\system32\spwinsat.dll
2012-03-26 17:26:53 ----A---- C:\windows\system32\sperror.dll
2012-03-26 17:26:52 ----A---- C:\windows\system32\spreview.exe
2012-03-26 17:26:52 ----A---- C:\windows\system32\drivers\spsys.sys
2012-03-26 17:26:51 ----A---- C:\windows\system32\softkbd.dll
2012-03-26 17:26:51 ----A---- C:\windows\system32\SndVol.exe
2012-03-26 17:26:50 ----A---- C:\windows\system32\TsWpfWrp.exe
2012-03-26 17:26:50 ----A---- C:\windows\system32\TSTheme.exe
2012-03-26 17:26:50 ----A---- C:\windows\system32\drivers\udfs.sys
2012-03-26 17:26:48 ----A---- C:\windows\system32\zipfldr.dll
2012-03-26 17:26:48 ----A---- C:\windows\system32\untfs.dll
2012-03-26 17:26:48 ----A---- C:\windows\system32\drivers\USBCAMD.sys
2012-03-26 17:26:48 ----A---- C:\windows\system32\drivers\usb8023.sys
2012-03-26 17:26:47 ----A---- C:\windows\system32\drivers\usbhub.sys
2012-03-26 17:26:47 ----A---- C:\windows\system32\drivers\usbehci.sys
2012-03-26 17:26:47 ----A---- C:\windows\system32\drivers\USBCAMD2.sys
2012-03-26 17:26:46 ----A---- C:\windows\system32\uDWM.dll
2012-03-26 17:26:45 ----A---- C:\windows\system32\ulib.dll
2012-03-26 17:26:44 ----A---- C:\windows\system32\umpnpmgr.dll
2012-03-26 17:26:44 ----A---- C:\windows\system32\systemcpl.dll
2012-03-26 17:26:34 ----A---- C:\windows\system32\tquery.dll
2012-03-26 17:26:34 ----A---- C:\windows\system32\tcpipcfg.dll
2012-03-26 17:26:33 ----A---- C:\windows\system32\tcpmon.dll
2012-03-26 17:26:33 ----A---- C:\windows\system32\tapisrv.dll
2012-03-26 17:26:31 ----A---- C:\windows\system32\thawbrkr.dll
2012-03-26 17:26:31 ----A---- C:\windows\system32\termsrv.dll
2012-03-26 17:26:30 ----A---- C:\windows\system32\themeui.dll
2012-03-26 17:26:30 ----A---- C:\windows\system32\themecpl.dll
2012-03-26 17:26:29 ----A---- C:\windows\system32\drivers\termdd.sys
2012-03-26 17:26:29 ----A---- C:\windows\system32\drivers\tdx.sys
2012-03-26 08:59:08 ----A---- C:\windows\system32\srvsvc.dll
2012-03-26 08:59:00 ----A---- C:\windows\system32\netevent.dll
2012-03-26 08:41:55 ----A---- C:\windows\system32\winhttp.dll
2012-03-26 08:41:13 ----A---- C:\windows\system32\drivers\http.sys
2012-03-26 08:41:12 ----A---- C:\windows\system32\httpapi.dll
2012-03-26 08:41:09 ----A---- C:\windows\system32\nshhttp.dll
2012-03-25 19:01:15 ----D---- C:\Users\kotulka\AppData\Roaming\AIMP3
2012-03-25 19:00:47 ----D---- C:\Program Files\AIMP3
2012-03-25 18:52:30 ----D---- C:\ProgramData\Sun
2012-03-25 18:51:06 ----A---- C:\windows\system32\npdeployJava1.dll
2012-03-25 18:51:05 ----A---- C:\windows\system32\javaws.exe
2012-03-25 18:51:05 ----A---- C:\windows\system32\javaw.exe
2012-03-25 18:51:05 ----A---- C:\windows\system32\java.exe
2012-03-25 18:51:05 ----A---- C:\windows\system32\deployJava1.dll
2012-03-25 12:50:35 ----D---- C:\windows\Minidump
2012-03-25 11:59:07 ----A---- C:\windows\system32\PresentationHostProxy.dll
2012-03-25 11:59:07 ----A---- C:\windows\system32\PresentationHost.exe
2012-03-25 11:59:06 ----A---- C:\windows\system32\netfxperf.dll
2012-03-25 11:59:06 ----A---- C:\windows\system32\mscoree.dll
2012-03-25 11:59:05 ----A---- C:\windows\system32\dfshim.dll
2012-03-25 10:42:31 ----ASH---- C:\pagefile.sys
2012-03-25 10:42:19 ----SHD---- C:\System Volume Information
2012-03-25 10:22:04 ----D---- C:\windows\system32\WindowsPowerShell
2012-03-25 10:18:13 ----A---- C:\windows\system32\winrsmgr.dll
2012-03-25 10:17:29 ----A---- C:\windows\system32\wsmprovhost.exe
2012-03-25 10:17:29 ----A---- C:\windows\system32\winrshost.exe
2012-03-25 10:17:29 ----A---- C:\windows\system32\winrs.exe
2012-03-25 10:17:23 ----A---- C:\windows\system32\wsmplpxy.dll
2012-03-25 10:17:22 ----A---- C:\windows\system32\winrssrv.dll
2012-03-25 10:17:13 ----A---- C:\windows\system32\wecapi.dll
2012-03-25 10:17:12 ----A---- C:\windows\system32\wevtfwd.dll
2012-03-25 10:17:12 ----A---- C:\windows\system32\wecutil.exe
2012-03-25 10:17:12 ----A---- C:\windows\system32\wecsvc.dll
2012-03-25 10:17:11 ----A---- C:\windows\system32\WsmRes.dll
2012-03-25 10:17:07 ----A---- C:\windows\system32\pwrshplugin.dll
2012-03-25 10:16:41 ----A---- C:\windows\system32\winrm.vbs
2012-03-25 10:16:28 ----A---- C:\windows\system32\WsmAuto.dll
2012-03-25 10:16:27 ----A---- C:\windows\system32\WsmWmiPl.dll
2012-03-25 10:16:26 ----A---- C:\windows\system32\winrscmd.dll
2012-03-25 10:16:25 ----A---- C:\windows\system32\WSManMigrationPlugin.dll
2012-03-25 10:16:24 ----A---- C:\windows\system32\WSManHTTPConfig.exe
2012-03-25 10:16:23 ----A---- C:\windows\system32\WsmSvc.dll
2012-03-25 10:01:27 ----A---- C:\windows\system32\ntkrnlpa.exe
2012-03-25 10:01:24 ----A---- C:\windows\system32\ntoskrnl.exe
2012-03-25 10:01:22 ----A---- C:\windows\system32\ntdll.dll
2012-03-25 10:00:30 ----A---- C:\windows\system32\netiohlp.dll
2012-03-25 10:00:22 ----A---- C:\windows\system32\NETSTAT.EXE
2012-03-25 10:00:22 ----A---- C:\windows\system32\ARP.EXE
2012-03-25 10:00:21 ----A---- C:\windows\system32\TCPSVCS.EXE
2012-03-25 10:00:21 ----A---- C:\windows\system32\finger.exe
2012-03-25 10:00:20 ----A---- C:\windows\system32\MRINFO.EXE
2012-03-25 10:00:20 ----A---- C:\windows\system32\HOSTNAME.EXE
2012-03-25 10:00:19 ----A---- C:\windows\system32\ROUTE.EXE
2012-03-25 09:59:28 ----A---- C:\windows\system32\atmfd.dll
2012-03-25 09:59:27 ----A---- C:\windows\system32\fontsub.dll
2012-03-25 09:59:25 ----A---- C:\windows\system32\atmlib.dll
2012-03-25 09:59:24 ----A---- C:\windows\system32\lpk.dll
2012-03-25 09:59:23 ----A---- C:\windows\system32\dciman32.dll
2012-03-25 09:53:21 ----A---- C:\windows\system32\wmp.dll
2012-03-25 09:53:05 ----D---- C:\windows\system32\EventProviders
2012-03-25 09:52:56 ----A---- C:\windows\system32\wmploc.DLL
2012-03-25 09:45:08 ----D---- C:\windows\Prefetch
2012-03-25 09:42:29 ----A---- C:\windows\system32\wlansvc.dll
2012-03-25 09:42:29 ----A---- C:\windows\system32\wlanhlp.dll
2012-03-25 09:42:28 ----A---- C:\windows\system32\wlanmsm.dll
2012-03-25 09:42:27 ----A---- C:\windows\system32\L2SecHC.dll
2012-03-25 09:42:26 ----A---- C:\windows\system32\wlansec.dll
2012-03-25 09:42:26 ----A---- C:\windows\system32\wlanapi.dll
2012-03-25 09:42:10 ----A---- C:\windows\system32\odbc32.dll
2012-03-25 09:40:41 ----A---- C:\windows\system32\msv1_0.dll
2012-03-25 09:38:57 ----A---- C:\windows\system32\msxml6.dll
2012-03-25 09:38:42 ----A---- C:\windows\system32\WMVCORE.DLL
2012-03-25 09:38:39 ----A---- C:\windows\system32\rrinstaller.exe
2012-03-25 09:38:39 ----A---- C:\windows\system32\mfpmp.exe
2012-03-25 09:38:38 ----A---- C:\windows\system32\mferror.dll
2012-03-25 09:38:31 ----A---- C:\windows\system32\dnsrslvr.dll
2012-03-25 09:38:31 ----A---- C:\windows\system32\dnscacheugc.exe
2012-03-25 09:38:31 ----A---- C:\windows\system32\dnsapi.dll
2012-03-25 09:38:17 ----A---- C:\windows\system32\usp10.dll
2012-03-25 09:38:10 ----A---- C:\windows\system32\drivers\srv.sys
2012-03-25 09:37:55 ----A---- C:\windows\system32\drivers\bowser.sys
2012-03-25 09:37:46 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2012-03-25 09:37:45 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2012-03-25 09:37:45 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2012-03-25 09:37:41 ----A---- C:\windows\system32\asycfilt.dll
2012-03-25 09:36:42 ----A---- C:\windows\system32\drivers\dfsc.sys
2012-03-25 09:36:33 ----A---- C:\windows\system32\mfc42.dll
2012-03-25 09:36:32 ----A---- C:\windows\system32\mfc42u.dll
2012-03-25 09:36:16 ----A---- C:\windows\system32\iccvid.dll
2012-03-25 09:13:09 ----A---- C:\windows\system32\ole32.dll
2012-03-25 09:13:04 ----A---- C:\windows\system32\atl.dll
2012-03-25 09:13:01 ----A---- C:\windows\system32\win32k.sys
2012-03-25 09:12:56 ----A---- C:\windows\system32\drivers\afd.sys
2012-03-25 09:12:54 ----A---- C:\windows\system32\spoolsv.exe
2012-03-25 09:12:50 ----A---- C:\windows\system32\wkssvc.dll
2012-03-25 09:12:41 ----A---- C:\windows\system32\t2embed.dll
2012-03-25 09:12:32 ----A---- C:\windows\system32\wmpmde.dll
2012-03-25 09:12:14 ----A---- C:\windows\system32\shsvcs.dll
2012-03-25 09:11:53 ----A---- C:\windows\system32\sdclt.exe
2012-03-25 09:11:44 ----A---- C:\windows\system32\drivers\srvnet.sys
2012-03-25 09:11:44 ----A---- C:\windows\system32\drivers\srv2.sys
2012-03-25 09:11:35 ----A---- C:\windows\system32\MP4SDECD.DLL
2012-03-25 09:11:33 ----A---- C:\windows\system32\rtutils.dll
2012-03-25 09:11:03 ----A---- C:\windows\system32\localspl.dll
2012-03-25 09:10:59 ----A---- C:\windows\system32\oleaut32.dll
2012-03-25 09:10:55 ----A---- C:\windows\system32\mfc40.dll
2012-03-25 09:10:54 ----A---- C:\windows\system32\mfc40u.dll
2012-03-25 09:10:49 ----A---- C:\windows\system32\msxml3.dll
2012-03-25 09:10:34 ----A---- C:\windows\system32\gameux.dll
2012-03-25 09:10:33 ----A---- C:\windows\system32\Apphlpdm.dll
2012-03-25 09:10:29 ----A---- C:\windows\system32\GameUXLegacyGDFs.dll
2012-03-25 09:10:20 ----A---- C:\windows\system32\lsasrv.dll
2012-03-25 09:10:18 ----A---- C:\windows\system32\wdigest.dll
2012-03-25 09:10:18 ----A---- C:\windows\system32\kerberos.dll
2012-03-25 09:10:15 ----A---- C:\windows\system32\drivers\ksecdd.sys
2012-03-25 09:10:14 ----A---- C:\windows\system32\secur32.dll
2012-03-25 09:10:14 ----A---- C:\windows\system32\lsass.exe
2012-03-25 09:10:10 ----A---- C:\windows\system32\schedsvc.dll
2012-03-25 09:10:08 ----A---- C:\windows\system32\taskschd.dll
2012-03-25 09:10:07 ----A---- C:\windows\system32\wmicmiplugin.dll
2012-03-25 09:10:07 ----A---- C:\windows\system32\taskeng.exe
2012-03-25 09:10:06 ----A---- C:\windows\system32\taskcomp.dll
2012-03-25 09:10:02 ----A---- C:\windows\system32\inetcomm.dll
2012-03-25 09:09:34 ----A---- C:\windows\system32\EncDec.dll
2012-03-25 09:09:33 ----A---- C:\windows\system32\sbeio.dll
2012-03-25 09:09:33 ----A---- C:\windows\system32\sbe.dll
2012-03-25 09:09:24 ----A---- C:\windows\system32\iphlpsvc.dll
2012-03-25 09:09:23 ----A---- C:\windows\system32\drivers\tunnel.sys
2012-03-25 09:09:08 ----A---- C:\windows\system32\shell32.dll
2012-03-25 09:09:04 ----A---- C:\windows\system32\shlwapi.dll
2012-03-25 09:07:49 ----A---- C:\windows\system32\RMActivate_isv.exe
2012-03-25 09:07:49 ----A---- C:\windows\system32\RMActivate.exe
2012-03-25 09:07:29 ----A---- C:\windows\system32\secproc_isv.dll
2012-03-25 09:07:22 ----A---- C:\windows\system32\secproc.dll
2012-03-25 09:07:22 ----A---- C:\windows\system32\RMActivate_ssp.exe
2012-03-25 09:07:21 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2012-03-25 09:07:18 ----A---- C:\windows\system32\secproc_ssp.dll
2012-03-25 09:07:18 ----A---- C:\windows\system32\msdrm.dll
2012-03-25 09:07:17 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2012-03-25 09:07:13 ----A---- C:\windows\system32\consent.exe
2012-03-25 09:05:23 ----D---- C:\ProgramData\WindowsSearch
2012-03-25 09:04:36 ----A---- C:\windows\system32\tzres.dll
2012-03-25 09:03:24 ----A---- C:\windows\system32\wmpdxm.dll
2012-03-25 09:03:00 ----A---- C:\windows\system32\kernel32.dll
2012-03-25 08:53:07 ----A---- C:\windows\system32\mstscax.dll
2012-03-25 08:53:05 ----A---- C:\windows\system32\mstsc.exe
2012-03-25 08:53:04 ----A---- C:\windows\system32\tsgqec.dll
2012-03-25 08:53:04 ----A---- C:\windows\system32\tscupgrd.exe
2012-03-25 08:53:04 ----A---- C:\windows\system32\aaclient.dll
2012-03-25 08:52:53 ----A---- C:\windows\system32\winsrv.dll
2012-03-25 08:52:52 ----A---- C:\windows\system32\csrsrv.dll
2012-03-25 08:52:44 ----A---- C:\windows\system32\msasn1.dll
2012-03-25 08:52:30 ----A---- C:\windows\system32\drivers\tcpip.sys
2012-03-25 08:52:27 ----A---- C:\windows\system32\drivers\tcpipreg.sys
2012-03-25 08:52:19 ----A---- C:\windows\system32\rpcrt4.dll
2012-03-25 08:52:09 ----A---- C:\windows\system32\quartz.dll
2012-03-25 08:52:08 ----A---- C:\windows\system32\tsbyuv.dll
2012-03-25 08:52:07 ----A---- C:\windows\system32\msvidc32.dll
2012-03-25 08:52:07 ----A---- C:\windows\system32\msrle32.dll
2012-03-25 08:52:06 ----A---- C:\windows\system32\msyuv.dll
2012-03-25 08:52:05 ----A---- C:\windows\system32\iyuv_32.dll
2012-03-25 08:52:03 ----A---- C:\windows\system32\avifil32.dll
2012-03-25 08:52:02 ----A---- C:\windows\system32\mciavi32.dll
2012-03-25 08:52:01 ----A---- C:\windows\system32\msvfw32.dll
2012-03-25 08:51:55 ----A---- C:\windows\system32\WMSPDMOD.DLL
2012-03-25 08:51:51 ----A---- C:\windows\system32\rastls.dll
2012-03-25 08:51:38 ----A---- C:\windows\system32\WSDApi.dll
2012-03-25 08:51:19 ----A---- C:\windows\system32\comctl32.dll
2012-03-25 08:47:50 ----A---- C:\windows\system32\schannel.dll
2012-03-25 08:45:25 ----D---- C:\windows\pss
2012-03-25 08:30:18 ----A---- C:\windows\system32\browserchoice.exe
2012-03-25 08:12:04 ----A---- C:\windows\system32\unregmp2.exe
2012-03-25 08:11:53 ----A---- C:\windows\system32\spwmp.dll
2012-03-25 08:11:52 ----A---- C:\windows\system32\dxmasf.dll
2012-03-25 08:02:43 ----N---- C:\windows\system32\MpSigStub.exe
2012-03-25 07:54:20 ----D---- C:\Users\kotulka\AppData\Roaming\Skype
2012-03-25 07:53:44 ----D---- C:\Program Files\Common Files\Skype
2012-03-25 07:53:35 ----RD---- C:\Program Files\Skype
2012-03-25 07:53:24 ----D---- C:\ProgramData\Skype
2012-03-25 07:51:43 ----A---- C:\windows\myClean.bat
2012-03-25 07:44:37 ----A---- C:\windows\system32\wintrust.dll
2012-03-25 07:41:13 ----A---- C:\windows\system32\cabview.dll
2012-03-25 07:32:50 ----D---- C:\Program Files\The KMPlayer
2012-03-25 07:28:22 ----D---- C:\Users\kotulka\AppData\Roaming\WinRAR
2012-03-25 07:28:06 ----D---- C:\Program Files\WinRAR
2012-03-25 07:25:45 ----D---- C:\Program Files\CCleaner
2012-03-25 07:23:52 ----D---- C:\ProgramData\AVAST Software
2012-03-25 07:23:52 ----D---- C:\Program Files\AVAST Software
2012-03-25 07:21:06 ----D---- C:\Users\kotulka\AppData\Roaming\Adobe
2012-03-25 07:18:43 ----A---- C:\windows\system32\agremove.exe
2012-03-25 07:16:04 ----D---- C:\Program Files\Google
2012-03-25 07:07:31 ----D---- C:\Users\kotulka\AppData\Roaming\Opera
2012-03-25 02:18:38 ----A---- C:\windows\WININIT.INI
2012-03-25 01:31:52 ----D---- C:\Users\kotulka\AppData\Roaming\Ashampoo
2012-03-25 01:25:27 ----D---- C:\Program Files\Opera
2012-03-25 01:22:06 ----D---- C:\ProgramData\ashampoo
2012-03-25 01:21:27 ----D---- C:\Program Files\Ashampoo
2012-03-25 01:11:47 ----D---- C:\Users\kotulka\AppData\Roaming\Identities
2012-03-25 01:10:57 ----D---- C:\Users\kotulka\AppData\Roaming\Macromedia
2012-03-25 01:10:37 ----D---- C:\Users\kotulka\AppData\Roaming\Hewlett-Packard
2012-03-25 01:05:10 ----SD---- C:\Users\kotulka\AppData\Roaming\Microsoft
2012-03-25 00:59:54 ----A---- C:\windows\system32\wups2.dll
2012-03-25 00:59:54 ----A---- C:\windows\system32\wuauclt.exe
2012-03-25 00:59:53 ----A---- C:\windows\system32\wucltux.dll
2012-03-25 00:59:53 ----A---- C:\windows\system32\wuaueng.dll
2012-03-25 00:57:52 ----A---- C:\windows\system32\wups.dll
2012-03-25 00:57:52 ----A---- C:\windows\system32\wudriver.dll
2012-03-25 00:57:52 ----A---- C:\windows\system32\wuapi.dll
2012-03-25 00:57:30 ----A---- C:\windows\system32\wuwebv.dll
2012-03-25 00:57:30 ----A---- C:\windows\system32\wuapp.exe
2012-03-25 00:55:23 ----D---- C:\windows\SoftwareDistribution

======List of files/folders modified in the last 1 month======

2012-03-27 19:04:06 ----RD---- C:\Program Files
2012-03-27 19:03:59 ----D---- C:\windows\Temp
2012-03-27 18:52:46 ----D---- C:\windows\winsxs
2012-03-27 18:50:34 ----D---- C:\windows\rescache
2012-03-27 18:42:40 ----SHD---- C:\windows\Installer
2012-03-27 18:38:16 ----RSD---- C:\windows\assembly
2012-03-27 18:37:32 ----D---- C:\windows\System32
2012-03-27 18:37:32 ----A---- C:\windows\system32\PerfStringBackup.INI
2012-03-27 18:37:20 ----D---- C:\windows\inf
2012-03-27 18:34:17 ----D---- C:\Windows
2012-03-27 18:31:01 ----D---- C:\Program Files\Common Files
2012-03-27 18:03:40 ----HD---- C:\ProgramData
2012-03-27 17:52:37 ----D---- C:\windows\system32\Tasks
2012-03-27 17:51:02 ----D---- C:\windows\system32\drivers
2012-03-27 17:40:29 ----D---- C:\windows\system32\catroot
2012-03-27 17:40:27 ----D---- C:\windows\system32\catroot2
2012-03-27 17:38:34 ----D---- C:\windows\Panther
2012-03-27 17:35:08 ----AD---- C:\windows\system32\lv-LV
2012-03-27 17:35:01 ----RD---- C:\windows\Offline Web Pages
2012-03-27 17:35:01 ----D---- C:\windows\system32\wbem
2012-03-27 17:35:01 ----D---- C:\windows\system32\migration
2012-03-27 17:35:01 ----D---- C:\windows\system32\en-US
2012-03-27 17:35:01 ----D---- C:\windows\PolicyDefinitions
2012-03-27 17:35:01 ----D---- C:\Program Files\Internet Explorer
2012-03-27 17:35:00 ----SD---- C:\windows\Downloaded Program Files
2012-03-27 17:34:58 ----D---- C:\windows\system32\drivers\sl-SI
2012-03-27 17:34:58 ----D---- C:\windows\system32\drivers\sk-SK
2012-03-27 17:34:58 ----D---- C:\windows\system32\drivers\ro-RO
2012-03-27 17:34:58 ----D---- C:\windows\system32\drivers\cs-CZ
2012-03-27 17:34:58 ----AD---- C:\windows\system32\sl-SI
2012-03-27 17:34:58 ----AD---- C:\windows\system32\sk-SK
2012-03-27 17:34:58 ----AD---- C:\windows\system32\ro-RO
2012-03-27 17:34:58 ----AD---- C:\windows\system32\cs-CZ
2012-03-27 17:32:42 ----D---- C:\windows\Microsoft.NET
2012-03-27 14:24:27 ----AD---- C:\windows\system32\lt-LT
2012-03-27 13:53:13 ----D---- C:\windows\AppPatch
2012-03-27 12:13:51 ----SHD---- C:\boot
2012-03-27 11:46:40 ----D---- C:\Program Files\Windows Calendar
2012-03-27 11:46:40 ----D---- C:\Program Files\Movie Maker
2012-03-27 11:46:39 ----D---- C:\Program Files\Windows Sidebar
2012-03-27 11:46:39 ----D---- C:\Program Files\Windows Media Player
2012-03-27 11:46:39 ----D---- C:\Program Files\Windows Mail
2012-03-27 11:46:39 ----D---- C:\Program Files\Windows Collaboration
2012-03-27 11:46:38 ----D---- C:\Program Files\Windows Photo Gallery
2012-03-27 11:46:34 ----D---- C:\Program Files\Common Files\System
2012-03-27 11:46:32 ----D---- C:\windows\servicing
2012-03-27 11:46:32 ----D---- C:\Program Files\Windows Defender
2012-03-27 11:46:29 ----D---- C:\windows\system32\XPSViewer
2012-03-27 11:46:29 ----D---- C:\windows\IME
2012-03-27 11:46:27 ----D---- C:\windows\system32\da-DK
2012-03-27 11:46:27 ----AD---- C:\windows\system32\hr-HR
2012-03-27 11:46:27 ----AD---- C:\windows\system32\et-EE
2012-03-27 11:46:26 ----D---- C:\windows\system32\ko-KR
2012-03-27 11:46:25 ----D---- C:\windows\system32\it-IT
2012-03-27 11:46:25 ----D---- C:\windows\system32\el-GR
2012-03-27 11:46:25 ----D---- C:\windows\system32\de-DE
2012-03-27 11:46:24 ----D---- C:\windows\system32\oobe
2012-03-27 11:46:23 ----D---- C:\windows\system32\sv-SE
2012-03-27 11:46:23 ----D---- C:\windows\system32\setup
2012-03-27 11:46:23 ----D---- C:\windows\system32\ru-RU
2012-03-27 11:46:23 ----D---- C:\windows\system32\he-IL
2012-03-27 11:46:23 ----D---- C:\windows\system32\fr-FR
2012-03-27 11:46:23 ----D---- C:\windows\system32\fi-FI
2012-03-27 11:46:23 ----D---- C:\windows\system32\cs
2012-03-27 11:46:23 ----D---- C:\windows\system32\AdvancedInstallers
2012-03-27 11:46:20 ----D---- C:\windows\system32\SLUI
2012-03-27 11:46:20 ----D---- C:\windows\system32\pt-PT
2012-03-27 11:46:20 ----D---- C:\windows\system32\hu-HU
2012-03-27 11:46:18 ----D---- C:\windows\system32\zh-CN
2012-03-27 11:46:18 ----D---- C:\windows\system32\sr-Latn-CS
2012-03-27 11:46:18 ----D---- C:\windows\system32\manifeststore
2012-03-27 11:46:18 ----D---- C:\windows\system32\es-ES
2012-03-27 11:46:18 ----D---- C:\windows\system32\en
2012-03-27 11:46:17 ----D---- C:\windows\system32\zh-TW
2012-03-27 11:46:17 ----D---- C:\windows\system32\uk-UA
2012-03-27 11:46:17 ----D---- C:\windows\system32\pl-PL
2012-03-27 11:46:17 ----D---- C:\windows\system32\ja-JP
2012-03-27 11:46:17 ----AD---- C:\windows\system32\bg-BG
2012-03-27 11:46:15 ----D---- C:\windows\system32\th-TH
2012-03-27 11:46:15 ----D---- C:\windows\system32\drivers\en-US
2012-03-27 11:46:14 ----D---- C:\windows\system32\tr-TR
2012-03-27 11:46:13 ----D---- C:\windows\system32\nl-NL
2012-03-27 11:46:13 ----D---- C:\windows\system32\nb-NO
2012-03-27 11:46:08 ----D---- C:\windows\system32\ar-SA
2012-03-27 11:46:07 ----D---- C:\windows\system32\pt-BR
2012-03-27 11:46:07 ----D---- C:\windows\system32\migwiz
2012-03-27 11:45:40 ----RSD---- C:\windows\Fonts
2012-03-27 11:45:29 ----D---- C:\windows\system32\Boot
2012-03-27 11:28:19 ----A---- C:\windows\fonts\GlobalUserInterface.CompositeFont
2012-03-27 10:11:02 ----D---- C:\windows\system32\LogFiles
2012-03-26 14:42:37 ----D---- C:\windows\system32\WDI
2012-03-26 13:46:22 ----D---- C:\windows\Logs
2012-03-25 18:52:27 ----D---- C:\Program Files\Common Files\Java
2012-03-25 18:49:53 ----D---- C:\Program Files\Java
2012-03-25 17:00:07 ----D---- C:\windows\Debug
2012-03-25 12:03:20 ----D---- C:\Program Files\Microsoft.NET
2012-03-25 09:49:23 ----D---- C:\windows\Registration
2012-03-25 08:39:50 ----D---- C:\ProgramData\McAfee
2012-03-25 07:46:20 ----D---- C:\ProgramData\SiteAdvisor
2012-03-25 07:25:12 ----D---- C:\Program Files\Common Files\microsoft shared
2012-03-25 07:17:03 ----D---- C:\windows\Tasks
2012-03-25 02:18:34 ----D---- C:\Program Files\Common Files\Roxio Shared
2012-03-25 02:16:23 ----D---- C:\ProgramData\Roxio
2012-03-25 02:00:07 ----SD---- C:\ProgramData\Microsoft
2012-03-25 01:17:58 ----D---- C:\windows\system32\NDF
2012-03-25 01:11:35 ----D---- C:\windows\system
2012-03-25 01:10:18 ----D---- C:\ProgramData\Hewlett-Packard
2012-03-25 01:09:50 ----HD---- C:\System.sav
2012-03-25 01:09:50 ----D---- C:\SwSetup
2012-03-25 01:05:10 ----RD---- C:\Users
2012-03-25 00:55:30 ----D---- C:\windows\system32\restore
2012-03-04 16:23:04 ----A---- C:\windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\windows\system32\drivers\iastor.sys [2008-04-15 312344]
R0 SymDS;Symantec Data Store; C:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS [2010-06-13 339504]
R0 SymEFA;Symantec Extended File Attributes; C:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS [2010-07-29 666672]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [2010-08-09 692272]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVix86.sys [2010-06-27 344112]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS [2010-07-29 50096]
R1 SymIRON;Symantec Iron Driver; C:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS [2010-06-27 134704]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS [2010-07-13 331312]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\windows\system32\DRIVERS\bcmwl6.sys [2008-03-21 1207288]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e6032.sys [2007-05-24 223616]
R3 HBtnKey;HBtnKey; C:\windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-19 16768]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120326.019\NAVENG.SYS [2012-03-27 86136]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120326.019\NAVEX15.SYS [2012-03-27 1576312]
R3 SRTSP;Symantec Real Time Storage Protection; C:\windows\system32\drivers\NIS\1201000.025\SRTSP.SYS [2010-07-29 489008]
R3 SymEvent;SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT.SYS [2012-03-27 126512]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2007-06-08 30008]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2008-01-21 45624]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;Andrea ADI Filters Service; C:\windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-04-15 94208]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-04-18 354840]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-18 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [2010-07-23 126904]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 540448]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-01-21 21504]
R3 WPFFontCache_v0400;@c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-25 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2007-06-08 172131]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-25 136176]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2008-04-16 165192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-27 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetMsmqActivator;@c:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

berousek
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 08 bře 2012 18:33

Re: blue screen

#2 Příspěvek od berousek »

Zdravím,mal som už 3 krat blue screen:Driver irql not less or equal.-Tak som stiahol debugging tool a oskenoval kde je chyba a vyšlo najavo že by to mohol byt nejaky :IASTOR
Tak neviem čo teraz s tym

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: blue screen

#3 Příspěvek od motji »

Hezký večer :) ,
můžete minidump zararovat a vložit zde jako přílohu?

:arrow: Stáhněte TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
- a uložte ho na plochu.
- 2x klikněte na ikonu programu a spusťte
- dejte volbu Spustit kontrolu - pak potvrdte start sken
- pokud program najde infikovaný soubor, ukáže se Vám předvolená akce Cure, v tom případě potvrdte tlačítko Continue
- pokud bude chtít program restartovat počítač, klikněte na tlačítko Reboot Now
- pokud si restart nevyžádá, klikněte na tlačítko Report. Měl vy na Vás vyskočit log, obsah logu zkopírujte do svého topicu.
- pokud se log nezobrazí, je uložený ve Vašem kořenovém adresáři.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

berousek
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 08 bře 2012 18:33

Re: blue screen

#4 Příspěvek od berousek »

zdravím.dakujem za pomoc ale odkedy som aktualizoval ovladače intel matrix storage manager tak mi to nevyhazuje.Keby sa to nahodou ešte opakovalo tak sa budem riadit Vašimi pokynmi :thumbsup:
Naposledy upravil(a) berousek dne 29 bře 2012 15:55, celkem upraveno 1 x.

berousek
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 08 bře 2012 18:33

Re: blue screen

#5 Příspěvek od berousek »

pro jistotu vam pošlu ten log

16:11:30.0052 2644 TDSS rootkit removing tool 2.7.23.0 Mar 26 2012 13:40:18
16:11:30.0188 2644 ============================================================
16:11:30.0188 2644 Current date / time: 2012/03/29 16:11:30.0188
16:11:30.0188 2644 SystemInfo:
16:11:30.0188 2644
16:11:30.0188 2644 OS Version: 6.0.6002 ServicePack: 2.0
16:11:30.0188 2644 Product type: Workstation
16:11:30.0188 2644 ComputerName: KOTULKA-PC
16:11:30.0189 2644 UserName: kotulka
16:11:30.0189 2644 Windows directory: C:\windows
16:11:30.0189 2644 System windows directory: C:\windows
16:11:30.0189 2644 Processor architecture: Intel x86
16:11:30.0189 2644 Number of processors: 1
16:11:30.0189 2644 Page size: 0x1000
16:11:30.0189 2644 Boot type: Normal boot
16:11:30.0189 2644 ============================================================
16:11:30.0762 2644 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:11:30.0765 2644 \Device\Harddisk0\DR0:
16:11:30.0765 2644 MBR used
16:11:30.0765 2644 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xCD93B71
16:11:30.0765 2644 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xCD93BB0, BlocksNum 0x1201000
16:11:30.0829 2644 Initialize success
16:11:30.0829 2644 ============================================================
16:11:40.0136 2936 ============================================================
16:11:40.0136 2936 Scan started
16:11:40.0136 2936 Mode: Manual;
16:11:40.0136 2936 ============================================================
16:11:40.0906 2936 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\windows\system32\drivers\acpi.sys
16:11:40.0917 2936 ACPI - ok
16:11:41.0010 2936 ADIHdAudAddService (fb9ece3f7b8a03e474e611031ad4cd23) C:\windows\system32\drivers\ADIHdAud.sys
16:11:41.0017 2936 ADIHdAudAddService - ok
16:11:41.0110 2936 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\windows\system32\drivers\adp94xx.sys
16:11:41.0118 2936 adp94xx - ok
16:11:41.0179 2936 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\windows\system32\drivers\adpahci.sys
16:11:41.0185 2936 adpahci - ok
16:11:41.0237 2936 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\windows\system32\drivers\adpu160m.sys
16:11:41.0243 2936 adpu160m - ok
16:11:41.0267 2936 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\windows\system32\drivers\adpu320.sys
16:11:41.0271 2936 adpu320 - ok
16:11:41.0343 2936 AEADIFilters (12d23758621b00b8d3134095ec3325fd) C:\windows\system32\AEADISRV.EXE
16:11:41.0348 2936 AEADIFilters - ok
16:11:41.0433 2936 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\windows\System32\aelupsvc.dll
16:11:41.0434 2936 AeLookupSvc - ok
16:11:41.0532 2936 AFD (3911b972b55fea0478476b2e777b29fa) C:\windows\system32\drivers\afd.sys
16:11:41.0538 2936 AFD - ok
16:11:41.0620 2936 AgereModemAudio (8ed60797908fd394eee0d6949f493224) C:\Windows\system32\agrsmsvc.exe
16:11:41.0622 2936 AgereModemAudio - ok
16:11:41.0738 2936 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\windows\system32\DRIVERS\AGRSM.sys
16:11:42.0027 2936 AgereSoftModem - ok
16:11:42.0285 2936 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\windows\system32\drivers\agp440.sys
16:11:42.0301 2936 agp440 - ok
16:11:42.0394 2936 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\windows\system32\drivers\djsvs.sys
16:11:42.0413 2936 aic78xx - ok
16:11:42.0499 2936 ALG (a1545b731579895d8cc44fc0481c1192) C:\windows\System32\alg.exe
16:11:42.0502 2936 ALG - ok
16:11:42.0586 2936 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\windows\system32\drivers\aliide.sys
16:11:42.0587 2936 aliide - ok
16:11:42.0856 2936 amdagp (c47344bc706e5f0b9dce369516661578) C:\windows\system32\drivers\amdagp.sys
16:11:42.0858 2936 amdagp - ok
16:11:42.0895 2936 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\windows\system32\drivers\amdide.sys
16:11:42.0899 2936 amdide - ok
16:11:42.0960 2936 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\windows\system32\drivers\amdk7.sys
16:11:42.0962 2936 AmdK7 - ok
16:11:43.0026 2936 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\windows\system32\DRIVERS\amdk8.sys
16:11:43.0028 2936 AmdK8 - ok
16:11:43.0280 2936 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\windows\System32\appinfo.dll
16:11:43.0285 2936 Appinfo - ok
16:11:43.0374 2936 arc (5d2888182fb46632511acee92fdad522) C:\windows\system32\drivers\arc.sys
16:11:43.0391 2936 arc - ok
16:11:43.0456 2936 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\windows\system32\drivers\arcsas.sys
16:11:43.0458 2936 arcsas - ok
16:11:43.0717 2936 aspnet_state (776acefa0ca9df0faa51a5fb2f435705) C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
16:11:43.0731 2936 aspnet_state - ok
16:11:43.0855 2936 AsyncMac (53b202abee6455406254444303e87be1) C:\windows\system32\DRIVERS\asyncmac.sys
16:11:43.0857 2936 AsyncMac - ok
16:11:43.0931 2936 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\windows\system32\drivers\atapi.sys
16:11:43.0934 2936 atapi - ok
16:11:44.0029 2936 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\windows\System32\Audiosrv.dll
16:11:44.0036 2936 AudioEndpointBuilder - ok
16:11:44.0073 2936 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\windows\System32\Audiosrv.dll
16:11:44.0077 2936 Audiosrv - ok
16:11:44.0181 2936 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\windows\system32\DRIVERS\b57nd60x.sys
16:11:44.0186 2936 b57nd60x - ok
16:11:44.0399 2936 BCM43XX (3f5e7621cdf6867d3d8417d13a098277) C:\windows\system32\DRIVERS\bcmwl6.sys
16:11:44.0453 2936 BCM43XX - ok
16:11:44.0516 2936 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\windows\system32\drivers\Beep.sys
16:11:44.0520 2936 Beep - ok
16:11:44.0622 2936 BFE (c789af0f724fda5852fb9a7d3a432381) C:\windows\System32\bfe.dll
16:11:44.0629 2936 BFE - ok
16:11:44.0903 2936 BHDrvx86 (eb7f1f1dfa95c25d762c22d3cf13d4e0) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120317.002\BHDrvx86.sys
16:11:44.0938 2936 BHDrvx86 - ok
16:11:45.0083 2936 BITS (93952506c6d67330367f7e7934b6a02f) C:\windows\System32\qmgr.dll
16:11:45.0103 2936 BITS - ok
16:11:45.0193 2936 blbdrive (d4df28447741fd3d953526e33a617397) C:\windows\system32\drivers\blbdrive.sys
16:11:45.0196 2936 blbdrive - ok
16:11:45.0257 2936 bowser (35f376253f687bde63976ccb3f2108ca) C:\windows\system32\DRIVERS\bowser.sys
16:11:45.0259 2936 bowser - ok
16:11:45.0339 2936 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\drivers\brfiltlo.sys
16:11:45.0341 2936 BrFiltLo - ok
16:11:45.0400 2936 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\drivers\brfiltup.sys
16:11:45.0401 2936 BrFiltUp - ok
16:11:45.0474 2936 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\windows\System32\browser.dll
16:11:45.0478 2936 Browser - ok
16:11:45.0569 2936 Brserid (b304e75cff293029eddf094246747113) C:\windows\system32\drivers\brserid.sys
16:11:45.0573 2936 Brserid - ok
16:11:45.0627 2936 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\system32\drivers\brserwdm.sys
16:11:45.0629 2936 BrSerWdm - ok
16:11:45.0705 2936 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\system32\drivers\brusbmdm.sys
16:11:45.0706 2936 BrUsbMdm - ok
16:11:45.0775 2936 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\system32\drivers\brusbser.sys
16:11:45.0777 2936 BrUsbSer - ok
16:11:45.0857 2936 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\windows\system32\drivers\bthmodem.sys
16:11:45.0860 2936 BTHMODEM - ok
16:11:45.0998 2936 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\windows\system32\DRIVERS\cdfs.sys
16:11:46.0000 2936 cdfs - ok
16:11:46.0067 2936 cdrom (6b4bffb9becd728097024276430db314) C:\windows\system32\DRIVERS\cdrom.sys
16:11:46.0072 2936 cdrom - ok
16:11:46.0130 2936 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\windows\System32\certprop.dll
16:11:46.0132 2936 CertPropSvc - ok
16:11:46.0214 2936 circlass (e5d4133f37219dbcfe102bc61072589d) C:\windows\system32\drivers\circlass.sys
16:11:46.0216 2936 circlass - ok
16:11:46.0290 2936 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\windows\system32\CLFS.sys
16:11:46.0306 2936 CLFS - ok
16:11:46.0390 2936 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:11:46.0396 2936 clr_optimization_v2.0.50727_32 - ok
16:11:46.0505 2936 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:11:46.0509 2936 clr_optimization_v4.0.30319_32 - ok
16:11:46.0615 2936 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\windows\system32\DRIVERS\CmBatt.sys
16:11:46.0617 2936 CmBatt - ok
16:11:46.0664 2936 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\windows\system32\drivers\cmdide.sys
16:11:46.0666 2936 cmdide - ok
16:11:46.0787 2936 Com4Qlb (d8774ace03b46c9b01a49818055f9ad4) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
16:11:46.0790 2936 Com4Qlb - ok
16:11:46.0905 2936 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\windows\system32\DRIVERS\compbatt.sys
16:11:46.0907 2936 Compbatt - ok
16:11:46.0952 2936 COMSysApp - ok
16:11:46.0986 2936 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\windows\system32\drivers\crcdisk.sys
16:11:46.0987 2936 crcdisk - ok
16:11:47.0054 2936 Crusoe (1f07becdca750766a96cda811ba86410) C:\windows\system32\drivers\crusoe.sys
16:11:47.0056 2936 Crusoe - ok
16:11:47.0149 2936 CryptSvc (fb27772beaf8e1d28ccd825c09da939b) C:\windows\system32\cryptsvc.dll
16:11:47.0153 2936 CryptSvc - ok
16:11:47.0217 2936 DAMDrv (5d5984255a4bfaa4262fb750df7cd537) C:\windows\system32\DRIVERS\DAMDrv.sys
16:11:47.0219 2936 DAMDrv - ok
16:11:47.0345 2936 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\windows\system32\rpcss.dll
16:11:47.0369 2936 DcomLaunch - ok
16:11:47.0446 2936 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\windows\system32\Drivers\dfsc.sys
16:11:47.0450 2936 DfsC - ok
16:11:47.0639 2936 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\windows\system32\DFSR.exe
16:11:47.0707 2936 DFSR - ok
16:11:47.0784 2936 Dhcp (9028559c132146fb75eb7acf384b086a) C:\windows\System32\dhcpcsvc.dll
16:11:47.0787 2936 Dhcp - ok
16:11:47.0854 2936 disk (5d4aefc3386920236a548271f8f1af6a) C:\windows\system32\drivers\disk.sys
16:11:47.0857 2936 disk - ok
16:11:47.0966 2936 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\windows\System32\dnsrslvr.dll
16:11:47.0969 2936 Dnscache - ok
16:11:48.0043 2936 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\windows\System32\dot3svc.dll
16:11:48.0049 2936 dot3svc - ok
16:11:48.0109 2936 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\windows\system32\dps.dll
16:11:48.0113 2936 DPS - ok
16:11:48.0199 2936 drmkaud (97fef831ab90bee128c9af390e243f80) C:\windows\system32\drivers\drmkaud.sys
16:11:48.0201 2936 drmkaud - ok
16:11:48.0366 2936 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\windows\System32\drivers\dxgkrnl.sys
16:11:48.0405 2936 DXGKrnl - ok
16:11:48.0523 2936 e1express (9636e42b3114b66ce6edfb34b9d8e81b) C:\windows\system32\DRIVERS\e1e6032.sys
16:11:48.0529 2936 e1express - ok
16:11:48.0591 2936 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\windows\system32\DRIVERS\E1G60I32.sys
16:11:48.0595 2936 E1G60 - ok
16:11:48.0734 2936 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\windows\System32\eapsvc.dll
16:11:48.0737 2936 EapHost - ok
16:11:48.0819 2936 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\windows\system32\drivers\ecache.sys
16:11:48.0825 2936 Ecache - ok
16:11:48.0941 2936 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
16:11:48.0950 2936 eeCtrl - ok
16:11:49.0098 2936 elxstor (23b62471681a124889978f6295b3f4c6) C:\windows\system32\drivers\elxstor.sys
16:11:49.0108 2936 elxstor - ok
16:11:49.0219 2936 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\windows\system32\emdmgmt.dll
16:11:49.0263 2936 EMDMgmt - ok
16:11:49.0413 2936 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
16:11:49.0416 2936 EraserUtilRebootDrv - ok
16:11:49.0563 2936 ErrDev (3db974f3935483555d7148663f726c61) C:\windows\system32\drivers\errdev.sys
16:11:49.0565 2936 ErrDev - ok
16:11:49.0666 2936 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\windows\system32\es.dll
16:11:49.0672 2936 EventSystem - ok
16:11:49.0761 2936 exfat (22b408651f9123527bcee54b4f6c5cae) C:\windows\system32\drivers\exfat.sys
16:11:49.0765 2936 exfat - ok
16:11:49.0820 2936 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\windows\system32\drivers\fastfat.sys
16:11:49.0824 2936 fastfat - ok
16:11:49.0914 2936 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\windows\system32\DRIVERS\fdc.sys
16:11:49.0916 2936 fdc - ok
16:11:49.0979 2936 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\windows\system32\fdPHost.dll
16:11:49.0983 2936 fdPHost - ok
16:11:50.0022 2936 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\windows\system32\fdrespub.dll
16:11:50.0024 2936 FDResPub - ok
16:11:50.0105 2936 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\windows\system32\drivers\fileinfo.sys
16:11:50.0108 2936 FileInfo - ok
16:11:50.0172 2936 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\windows\system32\drivers\filetrace.sys
16:11:50.0174 2936 Filetrace - ok
16:11:50.0291 2936 FLCDLOCK (224138e0ccdf7ce3281298473f6fd1d2) C:\Windows\system32\flcdlock.exe
16:11:50.0296 2936 FLCDLOCK - ok
16:11:50.0372 2936 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\windows\system32\DRIVERS\flpydisk.sys
16:11:50.0375 2936 flpydisk - ok
16:11:50.0470 2936 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\windows\system32\drivers\fltmgr.sys
16:11:50.0475 2936 FltMgr - ok
16:11:50.0575 2936 FontCache (8ce364388c8eca59b14b539179276d44) C:\windows\system32\FntCache.dll
16:11:50.0609 2936 FontCache - ok
16:11:50.0701 2936 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:11:50.0713 2936 FontCache3.0.0.0 - ok
16:11:50.0811 2936 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\windows\system32\drivers\Fs_Rec.sys
16:11:50.0813 2936 Fs_Rec - ok
16:11:50.0843 2936 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\windows\system32\drivers\gagp30kx.sys
16:11:50.0846 2936 gagp30kx - ok
16:11:50.0923 2936 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\windows\System32\gpsvc.dll
16:11:50.0945 2936 gpsvc - ok
16:11:51.0057 2936 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
16:11:51.0070 2936 gupdate - ok
16:11:51.0084 2936 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
16:11:51.0086 2936 gupdatem - ok
16:11:51.0218 2936 HBtnKey (de15777902a5d9121857d155873a1d1b) C:\windows\system32\DRIVERS\cpqbttn.sys
16:11:51.0219 2936 HBtnKey - ok
16:11:51.0301 2936 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\windows\system32\drivers\HdAudio.sys
16:11:51.0309 2936 HdAudAddService - ok
16:11:51.0408 2936 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\windows\system32\DRIVERS\HDAudBus.sys
16:11:51.0428 2936 HDAudBus - ok
16:11:51.0475 2936 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\windows\system32\drivers\hidbth.sys
16:11:51.0477 2936 HidBth - ok
16:11:51.0501 2936 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\windows\system32\drivers\hidir.sys
16:11:51.0503 2936 HidIr - ok
16:11:51.0591 2936 hidserv (84067081f3318162797385e11a8f0582) C:\windows\system32\hidserv.dll
16:11:51.0594 2936 hidserv - ok
16:11:51.0664 2936 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\windows\system32\DRIVERS\hidusb.sys
16:11:51.0666 2936 HidUsb - ok
16:11:51.0722 2936 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\windows\system32\kmsvc.dll
16:11:51.0730 2936 hkmsvc - ok
16:11:51.0844 2936 HP Health Check Service (d13e6bfd7e9189d26a42e94cb2447044) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
16:11:51.0847 2936 HP Health Check Service - ok
16:11:51.0984 2936 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\windows\system32\drivers\hpcisss.sys
16:11:51.0987 2936 HpCISSs - ok
16:11:52.0071 2936 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\windows\system32\DRIVERS\HpqKbFiltr.sys
16:11:52.0073 2936 HpqKbFiltr - ok
16:11:52.0179 2936 hpqwmiex (1665c7121a026df10c903db9bc5e9d43) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
16:11:52.0183 2936 hpqwmiex - ok
16:11:52.0301 2936 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\windows\system32\drivers\HTTP.sys
16:11:52.0311 2936 HTTP - ok
16:11:52.0381 2936 i2omp (c6b032d69650985468160fc9937cf5b4) C:\windows\system32\drivers\i2omp.sys
16:11:52.0384 2936 i2omp - ok
16:11:52.0451 2936 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\windows\system32\DRIVERS\i8042prt.sys
16:11:52.0453 2936 i8042prt - ok
16:11:52.0554 2936 IAANTMON (3ad7614c487c948add435662265750fb) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
16:11:52.0568 2936 IAANTMON - ok
16:11:52.0722 2936 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\windows\system32\drivers\iastor.sys
16:11:52.0726 2936 iaStor - ok
16:11:52.0785 2936 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\windows\system32\drivers\iastorv.sys
16:11:52.0791 2936 iaStorV - ok
16:11:52.0879 2936 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
16:11:52.0883 2936 IDriverT - ok
16:11:53.0003 2936 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:11:53.0040 2936 idsvc - ok
16:11:53.0226 2936 IDSVix86 (b6662611e8fa3a71473c4a9bd0d23755) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120328.002\IDSvix86.sys
16:11:53.0234 2936 IDSVix86 - ok
16:11:53.0400 2936 igfx (9378d57e2b96c0a185d844770ad49948) C:\windows\system32\DRIVERS\igdkmd32.sys
16:11:53.0477 2936 igfx - ok
16:11:53.0551 2936 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\windows\system32\drivers\iirsp.sys
16:11:53.0553 2936 iirsp - ok
16:11:53.0640 2936 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\windows\System32\ikeext.dll
16:11:53.0656 2936 IKEEXT - ok
16:11:53.0718 2936 intelide (83aa759f3189e6370c30de5dc5590718) C:\windows\system32\drivers\intelide.sys
16:11:53.0720 2936 intelide - ok
16:11:53.0759 2936 intelppm (224191001e78c89dfa78924c3ea595ff) C:\windows\system32\DRIVERS\intelppm.sys
16:11:53.0762 2936 intelppm - ok
16:11:53.0833 2936 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\windows\system32\ipbusenum.dll
16:11:53.0837 2936 IPBusEnum - ok
16:11:53.0893 2936 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\windows\system32\DRIVERS\ipfltdrv.sys
16:11:53.0895 2936 IpFilterDriver - ok
16:11:53.0965 2936 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\windows\System32\iphlpsvc.dll
16:11:53.0977 2936 iphlpsvc - ok
16:11:54.0012 2936 IpInIp - ok
16:11:54.0068 2936 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\windows\system32\drivers\ipmidrv.sys
16:11:54.0071 2936 IPMIDRV - ok
16:11:54.0101 2936 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\windows\system32\DRIVERS\ipnat.sys
16:11:54.0104 2936 IPNAT - ok
16:11:54.0149 2936 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\windows\system32\drivers\irenum.sys
16:11:54.0161 2936 IRENUM - ok
16:11:54.0225 2936 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\windows\system32\drivers\isapnp.sys
16:11:54.0227 2936 isapnp - ok
16:11:54.0285 2936 iScsiPrt (232fa340531d940aac623b121a595034) C:\windows\system32\DRIVERS\msiscsi.sys
16:11:54.0290 2936 iScsiPrt - ok
16:11:54.0340 2936 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\windows\system32\drivers\iteatapi.sys
16:11:54.0352 2936 iteatapi - ok
16:11:54.0426 2936 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\windows\system32\drivers\iteraid.sys
16:11:54.0428 2936 iteraid - ok
16:11:54.0521 2936 IviRegMgr (213822072085b5bbad9af30ab577d817) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
16:11:54.0543 2936 IviRegMgr - ok
16:11:54.0676 2936 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\windows\system32\DRIVERS\kbdclass.sys
16:11:54.0678 2936 kbdclass - ok
16:11:54.0753 2936 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\windows\system32\DRIVERS\kbdhid.sys
16:11:54.0755 2936 kbdhid - ok
16:11:54.0830 2936 KeyIso (a3e186b4b935905b829219502557314e) C:\windows\system32\lsass.exe
16:11:54.0831 2936 KeyIso - ok
16:11:54.0896 2936 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\windows\system32\Drivers\ksecdd.sys
16:11:54.0922 2936 KSecDD - ok
16:11:55.0032 2936 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\windows\system32\msdtckrm.dll
16:11:55.0055 2936 KtmRm - ok
16:11:55.0114 2936 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\windows\system32\srvsvc.dll
16:11:55.0118 2936 LanmanServer - ok
16:11:55.0170 2936 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\windows\System32\wkssvc.dll
16:11:55.0177 2936 LanmanWorkstation - ok
16:11:55.0261 2936 LightScribeService (c215e09622118383b236dd56c2065183) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
16:11:55.0266 2936 LightScribeService - ok
16:11:55.0383 2936 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\windows\system32\DRIVERS\lltdio.sys
16:11:55.0386 2936 lltdio - ok
16:11:55.0437 2936 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\windows\System32\lltdsvc.dll
16:11:55.0444 2936 lltdsvc - ok
16:11:55.0484 2936 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\windows\System32\lmhsvc.dll
16:11:55.0503 2936 lmhosts - ok
16:11:55.0576 2936 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\windows\system32\drivers\lsi_fc.sys
16:11:55.0579 2936 LSI_FC - ok
16:11:55.0604 2936 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\windows\system32\drivers\lsi_sas.sys
16:11:55.0610 2936 LSI_SAS - ok
16:11:55.0674 2936 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\windows\system32\drivers\lsi_scsi.sys
16:11:55.0677 2936 LSI_SCSI - ok
16:11:55.0749 2936 luafv (8f5c7426567798e62a3b3614965d62cc) C:\windows\system32\drivers\luafv.sys
16:11:55.0753 2936 luafv - ok
16:11:55.0823 2936 megasas (0001ce609d66632fa17b84705f658879) C:\windows\system32\drivers\megasas.sys
16:11:55.0826 2936 megasas - ok
16:11:55.0897 2936 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\windows\system32\drivers\megasr.sys
16:11:55.0924 2936 MegaSR - ok
16:11:56.0061 2936 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
16:11:56.0064 2936 Microsoft Office Groove Audit Service - ok
16:11:56.0146 2936 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\windows\system32\mmcss.dll
16:11:56.0148 2936 MMCSS - ok
16:11:56.0240 2936 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\windows\system32\drivers\modem.sys
16:11:56.0243 2936 Modem - ok
16:11:56.0298 2936 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\windows\system32\DRIVERS\monitor.sys
16:11:56.0301 2936 monitor - ok
16:11:56.0343 2936 mouclass (5bf6a1326a335c5298477754a506d263) C:\windows\system32\DRIVERS\mouclass.sys
16:11:56.0345 2936 mouclass - ok
16:11:56.0398 2936 mouhid (93b8d4869e12cfbe663915502900876f) C:\windows\system32\DRIVERS\mouhid.sys
16:11:56.0400 2936 mouhid - ok
16:11:56.0450 2936 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\windows\system32\drivers\mountmgr.sys
16:11:56.0453 2936 MountMgr - ok
16:11:56.0509 2936 mpio (511d011289755dd9f9a7579fb0b064e6) C:\windows\system32\drivers\mpio.sys
16:11:56.0513 2936 mpio - ok
16:11:56.0566 2936 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\windows\system32\drivers\mpsdrv.sys
16:11:56.0569 2936 mpsdrv - ok
16:11:56.0646 2936 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\windows\system32\mpssvc.dll
16:11:56.0658 2936 MpsSvc - ok
16:11:56.0731 2936 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\windows\system32\drivers\mraid35x.sys
16:11:56.0734 2936 Mraid35x - ok
16:11:56.0827 2936 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\windows\system32\drivers\mrxdav.sys
16:11:56.0831 2936 MRxDAV - ok
16:11:56.0903 2936 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\windows\system32\DRIVERS\mrxsmb.sys
16:11:56.0906 2936 mrxsmb - ok
16:11:56.0966 2936 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\windows\system32\DRIVERS\mrxsmb10.sys
16:11:56.0972 2936 mrxsmb10 - ok
16:11:57.0049 2936 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\windows\system32\DRIVERS\mrxsmb20.sys
16:11:57.0053 2936 mrxsmb20 - ok
16:11:57.0119 2936 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\windows\system32\drivers\msahci.sys
16:11:57.0121 2936 msahci - ok
16:11:57.0191 2936 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\windows\system32\drivers\msdsm.sys
16:11:57.0194 2936 msdsm - ok
16:11:57.0286 2936 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\windows\System32\msdtc.exe
16:11:57.0297 2936 MSDTC - ok
16:11:57.0409 2936 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\windows\system32\drivers\Msfs.sys
16:11:57.0412 2936 Msfs - ok
16:11:57.0476 2936 msisadrv (0f400e306f385c56317357d6dea56f62) C:\windows\system32\drivers\msisadrv.sys
16:11:57.0481 2936 msisadrv - ok
16:11:57.0529 2936 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\windows\system32\iscsiexe.dll
16:11:57.0540 2936 MSiSCSI - ok
16:11:57.0594 2936 msiserver - ok
16:11:57.0667 2936 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\windows\system32\drivers\MSKSSRV.sys
16:11:57.0676 2936 MSKSSRV - ok
16:11:57.0744 2936 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\windows\system32\drivers\MSPCLOCK.sys
16:11:57.0746 2936 MSPCLOCK - ok
16:11:57.0829 2936 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\windows\system32\drivers\MSPQM.sys
16:11:57.0830 2936 MSPQM - ok
16:11:57.0897 2936 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\windows\system32\drivers\MsRPC.sys
16:11:57.0903 2936 MsRPC - ok
16:11:57.0998 2936 mssmbios (e384487cb84be41d09711c30ca79646c) C:\windows\system32\DRIVERS\mssmbios.sys
16:11:58.0001 2936 mssmbios - ok
16:11:58.0065 2936 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\windows\system32\drivers\MSTEE.sys
16:11:58.0067 2936 MSTEE - ok
16:11:58.0145 2936 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\windows\system32\Drivers\mup.sys
16:11:58.0149 2936 Mup - ok
16:11:58.0234 2936 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\windows\system32\qagentRT.dll
16:11:58.0245 2936 napagent - ok
16:11:58.0324 2936 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\windows\system32\DRIVERS\nwifi.sys
16:11:58.0334 2936 NativeWifiP - ok
16:11:58.0516 2936 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120328.036\NAVENG.SYS
16:11:58.0519 2936 NAVENG - ok
16:11:58.0749 2936 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120328.036\NAVEX15.SYS
16:11:58.0803 2936 NAVEX15 - ok
16:11:58.0946 2936 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\windows\system32\drivers\ndis.sys
16:11:58.0969 2936 NDIS - ok
16:11:59.0038 2936 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\windows\system32\DRIVERS\ndistapi.sys
16:11:59.0040 2936 NdisTapi - ok
16:11:59.0081 2936 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\windows\system32\DRIVERS\ndisuio.sys
16:11:59.0083 2936 Ndisuio - ok
16:11:59.0134 2936 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\windows\system32\DRIVERS\ndiswan.sys
16:11:59.0137 2936 NdisWan - ok
16:11:59.0220 2936 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\windows\system32\drivers\NDProxy.sys
16:11:59.0222 2936 NDProxy - ok
16:11:59.0286 2936 Net Driver HPZ12 (a081cb6fb9a12668f233eb5414be3a0e) C:\windows\system32\HPZinw12.dll
16:11:59.0288 2936 Net Driver HPZ12 - ok
16:11:59.0353 2936 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\windows\system32\DRIVERS\netbios.sys
16:11:59.0355 2936 NetBIOS - ok
16:11:59.0419 2936 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\windows\system32\DRIVERS\netbt.sys
16:11:59.0429 2936 netbt - ok
16:11:59.0508 2936 Netlogon (a3e186b4b935905b829219502557314e) C:\windows\system32\lsass.exe
16:11:59.0510 2936 Netlogon - ok
16:11:59.0588 2936 Netman (c8052711daecc48b982434c5116ca401) C:\windows\System32\netman.dll
16:11:59.0595 2936 Netman - ok
16:11:59.0705 2936 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
16:11:59.0709 2936 NetMsmqActivator - ok
16:11:59.0743 2936 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
16:11:59.0745 2936 NetPipeActivator - ok
16:11:59.0855 2936 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\windows\System32\netprofm.dll
16:11:59.0861 2936 netprofm - ok
16:11:59.0960 2936 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
16:11:59.0962 2936 NetTcpActivator - ok
16:11:59.0977 2936 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
16:11:59.0979 2936 NetTcpPortSharing - ok
16:12:00.0104 2936 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\windows\system32\drivers\nfrd960.sys
16:12:00.0106 2936 nfrd960 - ok
16:12:00.0218 2936 NIS (e78a365cc3e0fbfc018a33dce01909f8) C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe
16:12:00.0222 2936 NIS - ok
16:12:00.0319 2936 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\windows\System32\nlasvc.dll
16:12:00.0324 2936 NlaSvc - ok
16:12:00.0409 2936 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\windows\system32\drivers\Npfs.sys
16:12:00.0411 2936 Npfs - ok
16:12:00.0463 2936 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\windows\system32\nsisvc.dll
16:12:00.0466 2936 nsi - ok
16:12:00.0535 2936 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\windows\system32\drivers\nsiproxy.sys
16:12:00.0538 2936 nsiproxy - ok
16:12:00.0660 2936 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\windows\system32\drivers\Ntfs.sys
16:12:00.0696 2936 Ntfs - ok
16:12:00.0754 2936 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\windows\system32\drivers\ntrigdigi.sys
16:12:00.0759 2936 ntrigdigi - ok
16:12:00.0819 2936 Null (c5dbbcda07d780bda9b685df333bb41e) C:\windows\system32\drivers\Null.sys
16:12:00.0822 2936 Null - ok
16:12:00.0877 2936 nvraid (2edf9e7751554b42cbb60116de727101) C:\windows\system32\drivers\nvraid.sys
16:12:00.0881 2936 nvraid - ok
16:12:00.0946 2936 nvstor (abed0c09758d1d97db0042dbb2688177) C:\windows\system32\drivers\nvstor.sys
16:12:00.0948 2936 nvstor - ok
16:12:01.0043 2936 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\windows\system32\drivers\nv_agp.sys
16:12:01.0046 2936 nv_agp - ok
16:12:01.0108 2936 NwlnkFlt - ok
16:12:01.0151 2936 NwlnkFwd - ok
16:12:01.0275 2936 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
16:12:01.0298 2936 odserv - ok
16:12:01.0415 2936 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\windows\system32\DRIVERS\ohci1394.sys
16:12:01.0417 2936 ohci1394 - ok
16:12:01.0521 2936 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:12:01.0524 2936 ose - ok
16:12:01.0627 2936 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\windows\system32\p2psvc.dll
16:12:01.0650 2936 p2pimsvc - ok
16:12:01.0708 2936 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\windows\system32\p2psvc.dll
16:12:01.0716 2936 p2psvc - ok
16:12:01.0809 2936 Parport (8a79fdf04a73428597e2caf9d0d67850) C:\windows\system32\DRIVERS\parport.sys
16:12:01.0812 2936 Parport - ok
16:12:01.0893 2936 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\windows\system32\drivers\partmgr.sys
16:12:01.0895 2936 partmgr - ok
16:12:02.0001 2936 Parvdm (6c580025c81caf3ae9e3617c22cad00e) C:\windows\system32\DRIVERS\parvdm.sys
16:12:02.0003 2936 Parvdm - ok
16:12:02.0074 2936 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\windows\System32\pcasvc.dll
16:12:02.0078 2936 PcaSvc - ok
16:12:02.0145 2936 pci (941dc1d19e7e8620f40bbc206981efdb) C:\windows\system32\drivers\pci.sys
16:12:02.0149 2936 pci - ok
16:12:02.0262 2936 pciide (1636d43f10416aeb483bc6001097b26c) C:\windows\system32\DRIVERS\pciide.sys
16:12:02.0264 2936 pciide - ok
16:12:02.0353 2936 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\windows\system32\DRIVERS\pcmcia.sys
16:12:02.0358 2936 pcmcia - ok
16:12:02.0432 2936 pdfcDispatcher - ok
16:12:02.0585 2936 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\windows\system32\drivers\peauth.sys
16:12:02.0617 2936 PEAUTH - ok
16:12:02.0761 2936 pla (b1689df169143f57053f795390c99db3) C:\windows\system32\pla.dll
16:12:02.0818 2936 pla - ok
16:12:02.0884 2936 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\windows\system32\umpnpmgr.dll
16:12:02.0890 2936 PlugPlay - ok
16:12:02.0952 2936 Pml Driver HPZ12 (65bc271f337637731d3c71455ae1f476) C:\windows\system32\HPZipm12.dll
16:12:02.0957 2936 Pml Driver HPZ12 - ok
16:12:03.0036 2936 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\windows\system32\p2psvc.dll
16:12:03.0052 2936 PNRPAutoReg - ok
16:12:03.0113 2936 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\windows\system32\p2psvc.dll
16:12:03.0121 2936 PNRPsvc - ok
16:12:03.0192 2936 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\windows\System32\ipsecsvc.dll
16:12:03.0199 2936 PolicyAgent - ok
16:12:03.0284 2936 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\windows\system32\DRIVERS\raspptp.sys
16:12:03.0287 2936 PptpMiniport - ok
16:12:03.0364 2936 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\windows\system32\drivers\processr.sys
16:12:03.0366 2936 Processor - ok
16:12:03.0425 2936 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\windows\system32\profsvc.dll
16:12:03.0433 2936 ProfSvc - ok
16:12:03.0488 2936 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\windows\system32\lsass.exe
16:12:03.0490 2936 ProtectedStorage - ok
16:12:03.0576 2936 PSched (99514faa8df93d34b5589187db3aa0ba) C:\windows\system32\DRIVERS\pacer.sys
16:12:03.0579 2936 PSched - ok
16:12:03.0694 2936 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\windows\system32\drivers\ql2300.sys
16:12:03.0729 2936 ql2300 - ok
16:12:03.0814 2936 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\windows\system32\drivers\ql40xx.sys
16:12:03.0818 2936 ql40xx - ok
16:12:03.0880 2936 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\windows\system32\qwave.dll
16:12:03.0888 2936 QWAVE - ok
16:12:03.0978 2936 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\windows\system32\drivers\qwavedrv.sys
16:12:03.0980 2936 QWAVEdrv - ok
16:12:04.0013 2936 RasAcd (147d7f9c556d259924351feb0de606c3) C:\windows\system32\DRIVERS\rasacd.sys
16:12:04.0015 2936 RasAcd - ok
16:12:04.0089 2936 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\windows\System32\rasauto.dll
16:12:04.0095 2936 RasAuto - ok
16:12:04.0168 2936 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\windows\system32\DRIVERS\rasl2tp.sys
16:12:04.0174 2936 Rasl2tp - ok
16:12:04.0222 2936 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\windows\System32\rasmans.dll
16:12:04.0231 2936 RasMan - ok
16:12:04.0290 2936 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\windows\system32\DRIVERS\raspppoe.sys
16:12:04.0292 2936 RasPppoe - ok
16:12:04.0336 2936 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\windows\system32\DRIVERS\rassstp.sys
16:12:04.0339 2936 RasSstp - ok
16:12:04.0442 2936 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\windows\system32\DRIVERS\rdbss.sys
16:12:04.0448 2936 rdbss - ok
16:12:04.0526 2936 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\windows\system32\DRIVERS\RDPCDD.sys
16:12:04.0528 2936 RDPCDD - ok
16:12:04.0618 2936 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\windows\system32\drivers\rdpdr.sys
16:12:04.0623 2936 rdpdr - ok
16:12:04.0669 2936 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\windows\system32\drivers\rdpencdd.sys
16:12:04.0671 2936 RDPENCDD - ok
16:12:04.0740 2936 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\windows\system32\drivers\RDPWD.sys
16:12:04.0745 2936 RDPWD - ok
16:12:04.0843 2936 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\windows\System32\mprdim.dll
16:12:04.0849 2936 RemoteAccess - ok
16:12:04.0916 2936 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\windows\system32\regsvc.dll
16:12:04.0923 2936 RemoteRegistry - ok
16:12:05.0011 2936 Revoflt (b9bb8e2093c1615ad6ea55ad96214354) C:\windows\system32\DRIVERS\revoflt.sys
16:12:05.0018 2936 Revoflt - ok
16:12:05.0090 2936 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\windows\system32\locator.exe
16:12:05.0093 2936 RpcLocator - ok
16:12:05.0161 2936 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\windows\system32\rpcss.dll
16:12:05.0168 2936 RpcSs - ok
16:12:05.0250 2936 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\windows\system32\DRIVERS\rspndr.sys
16:12:05.0254 2936 rspndr - ok
16:12:05.0328 2936 SamSs (a3e186b4b935905b829219502557314e) C:\windows\system32\lsass.exe
16:12:05.0330 2936 SamSs - ok
16:12:05.0404 2936 sbp2port (3ce8f073a557e172b330109436984e30) C:\windows\system32\drivers\sbp2port.sys
16:12:05.0407 2936 sbp2port - ok
16:12:05.0493 2936 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\windows\System32\SCardSvr.dll
16:12:05.0497 2936 SCardSvr - ok
16:12:05.0556 2936 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\windows\system32\schedsvc.dll
16:12:05.0579 2936 Schedule - ok
16:12:05.0620 2936 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\windows\System32\certprop.dll
16:12:05.0623 2936 SCPolicySvc - ok
16:12:05.0673 2936 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\windows\System32\SDRSVC.dll
16:12:05.0678 2936 SDRSVC - ok
16:12:05.0741 2936 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
16:12:05.0743 2936 secdrv - ok
16:12:05.0818 2936 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\windows\system32\seclogon.dll
16:12:05.0823 2936 seclogon - ok
16:12:05.0854 2936 SENS (a9bbab5759771e523f55563d6cbe140f) C:\windows\System32\sens.dll
16:12:05.0860 2936 SENS - ok
16:12:05.0954 2936 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\windows\system32\drivers\serenum.sys
16:12:05.0956 2936 Serenum - ok
16:12:05.0980 2936 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\windows\system32\drivers\serial.sys
16:12:05.0985 2936 Serial - ok
16:12:06.0059 2936 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\windows\system32\drivers\sermouse.sys
16:12:06.0061 2936 sermouse - ok
16:12:06.0147 2936 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\windows\system32\sessenv.dll
16:12:06.0151 2936 SessionEnv - ok
16:12:06.0214 2936 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\windows\system32\drivers\sffdisk.sys
16:12:06.0215 2936 sffdisk - ok
16:12:06.0243 2936 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\windows\system32\drivers\sffp_mmc.sys
16:12:06.0245 2936 sffp_mmc - ok
16:12:06.0270 2936 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\windows\system32\drivers\sffp_sd.sys
16:12:06.0273 2936 sffp_sd - ok
16:12:06.0297 2936 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\windows\system32\drivers\sfloppy.sys
16:12:06.0299 2936 sfloppy - ok
16:12:06.0396 2936 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\windows\System32\ipnathlp.dll
16:12:06.0406 2936 SharedAccess - ok
16:12:06.0461 2936 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\windows\System32\shsvcs.dll
16:12:06.0471 2936 ShellHWDetection - ok
16:12:06.0562 2936 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\windows\system32\drivers\sisagp.sys
16:12:06.0564 2936 sisagp - ok
16:12:06.0609 2936 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\windows\system32\drivers\sisraid2.sys
16:12:06.0610 2936 SiSRaid2 - ok
16:12:06.0647 2936 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\windows\system32\drivers\sisraid4.sys
16:12:06.0648 2936 SiSRaid4 - ok
16:12:06.0733 2936 SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files\Skype\Updater\Updater.exe
16:12:06.0737 2936 SkypeUpdate - ok
16:12:06.0927 2936 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\windows\system32\SLsvc.exe
16:12:07.0038 2936 slsvc - ok
16:12:07.0098 2936 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\windows\system32\SLUINotify.dll
16:12:07.0109 2936 SLUINotify - ok
16:12:07.0160 2936 Smb (7b75299a4d201d6a6533603d6914ab04) C:\windows\system32\DRIVERS\smb.sys
16:12:07.0163 2936 Smb - ok
16:12:07.0290 2936 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\windows\System32\snmptrap.exe
16:12:07.0295 2936 SNMPTRAP - ok
16:12:07.0378 2936 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\windows\system32\drivers\spldr.sys
16:12:07.0380 2936 spldr - ok
16:12:07.0468 2936 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\windows\System32\spoolsv.exe
16:12:07.0471 2936 Spooler - ok
16:12:07.0585 2936 SRTSP (83726cf02eced69138948083e06b6eac) C:\windows\System32\Drivers\NIS\1207000.00D\SRTSP.SYS
16:12:07.0612 2936 SRTSP - ok
16:12:07.0699 2936 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\windows\system32\drivers\NIS\1207000.00D\SRTSPX.SYS
16:12:07.0701 2936 SRTSPX - ok
16:12:07.0765 2936 srv (41987f9fc0e61adf54f581e15029ad91) C:\windows\system32\DRIVERS\srv.sys
16:12:07.0773 2936 srv - ok
16:12:07.0823 2936 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\windows\system32\DRIVERS\srv2.sys
16:12:07.0827 2936 srv2 - ok
16:12:07.0911 2936 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\windows\system32\DRIVERS\srvnet.sys
16:12:07.0917 2936 srvnet - ok
16:12:07.0979 2936 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\windows\System32\ssdpsrv.dll
16:12:07.0985 2936 SSDPSRV - ok
16:12:08.0056 2936 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\windows\system32\sstpsvc.dll
16:12:08.0061 2936 SstpSvc - ok
16:12:08.0118 2936 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\windows\System32\wiaservc.dll
16:12:08.0136 2936 stisvc - ok
16:12:08.0214 2936 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\windows\system32\DRIVERS\swenum.sys
16:12:08.0216 2936 swenum - ok
16:12:08.0267 2936 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\windows\System32\swprv.dll
16:12:08.0278 2936 swprv - ok
16:12:08.0359 2936 Symc8xx (192aa3ac01df071b541094f251deed10) C:\windows\system32\drivers\symc8xx.sys
16:12:08.0361 2936 Symc8xx - ok
16:12:08.0469 2936 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\windows\system32\drivers\NIS\1207000.00D\SYMDS.SYS
16:12:08.0481 2936 SymDS - ok
16:12:08.0575 2936 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\windows\system32\drivers\NIS\1207000.00D\SYMEFA.SYS
16:12:08.0596 2936 SymEFA - ok
16:12:08.0688 2936 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\windows\system32\Drivers\SYMEVENT.SYS
16:12:08.0693 2936 SymEvent - ok
16:12:08.0773 2936 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\windows\system32\drivers\NIS\1207000.00D\Ironx86.SYS
16:12:08.0780 2936 SymIRON - ok
16:12:08.0908 2936 SYMTDIv (d42a7229e333af725f1445f785e4658d) C:\windows\System32\Drivers\NIS\1207000.00D\SYMTDIV.SYS
16:12:08.0928 2936 SYMTDIv - ok
16:12:08.0981 2936 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\windows\system32\drivers\sym_hi.sys
16:12:08.0983 2936 Sym_hi - ok
16:12:09.0012 2936 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\windows\system32\drivers\sym_u3.sys
16:12:09.0013 2936 Sym_u3 - ok
16:12:09.0077 2936 SynTP (f5d926807bd9bc0af68f9376144de425) C:\windows\system32\DRIVERS\SynTP.sys
16:12:09.0083 2936 SynTP - ok
16:12:09.0166 2936 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\windows\system32\sysmain.dll
16:12:09.0196 2936 SysMain - ok
16:12:09.0285 2936 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\windows\System32\TabSvc.dll
16:12:09.0289 2936 TabletInputService - ok
16:12:09.0359 2936 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\windows\System32\tapisrv.dll
16:12:09.0372 2936 TapiSrv - ok
16:12:09.0446 2936 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\windows\System32\tbssvc.dll
16:12:09.0450 2936 TBS - ok
16:12:09.0548 2936 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\windows\system32\drivers\tcpip.sys
16:12:09.0567 2936 Tcpip - ok
16:12:09.0653 2936 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\windows\system32\DRIVERS\tcpip.sys
16:12:09.0662 2936 Tcpip6 - ok
16:12:09.0744 2936 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\windows\system32\drivers\tcpipreg.sys
16:12:09.0746 2936 tcpipreg - ok
16:12:09.0814 2936 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\windows\system32\drivers\tdpipe.sys
16:12:09.0816 2936 TDPIPE - ok
16:12:09.0884 2936 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\windows\system32\drivers\tdtcp.sys
16:12:09.0886 2936 TDTCP - ok
16:12:09.0951 2936 tdx (76b06eb8a01fc8624d699e7045303e54) C:\windows\system32\DRIVERS\tdx.sys
16:12:09.0955 2936 tdx - ok
16:12:10.0049 2936 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\windows\system32\DRIVERS\termdd.sys
16:12:10.0051 2936 TermDD - ok
16:12:10.0119 2936 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\windows\System32\termsrv.dll
16:12:10.0131 2936 TermService - ok
16:12:10.0175 2936 Themes (c7230fbee14437716701c15be02c27b8) C:\windows\system32\shsvcs.dll
16:12:10.0179 2936 Themes - ok
16:12:10.0236 2936 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\windows\system32\mmcss.dll
16:12:10.0238 2936 THREADORDER - ok
16:12:10.0319 2936 TPM (cb258c2f726f1be73c507022be33ebb3) C:\windows\system32\drivers\tpm.sys
16:12:10.0321 2936 TPM - ok
16:12:10.0385 2936 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\windows\System32\trkwks.dll
16:12:10.0389 2936 TrkWks - ok
16:12:10.0453 2936 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\windows\servicing\TrustedInstaller.exe
16:12:10.0454 2936 TrustedInstaller - ok
16:12:10.0553 2936 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\windows\system32\DRIVERS\tssecsrv.sys
16:12:10.0571 2936 tssecsrv - ok
16:12:10.0620 2936 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\windows\system32\DRIVERS\tunmp.sys
16:12:10.0622 2936 tunmp - ok
16:12:10.0668 2936 tunnel (300db877ac094feab0be7688c3454a9c) C:\windows\system32\DRIVERS\tunnel.sys
16:12:10.0671 2936 tunnel - ok
16:12:10.0735 2936 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\windows\system32\drivers\uagp35.sys
16:12:10.0737 2936 uagp35 - ok
16:12:10.0830 2936 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\windows\system32\DRIVERS\udfs.sys
16:12:10.0836 2936 udfs - ok
16:12:10.0924 2936 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\windows\system32\UI0Detect.exe
16:12:10.0928 2936 UI0Detect - ok
16:12:11.0005 2936 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\windows\system32\drivers\uliagpkx.sys
16:12:11.0007 2936 uliagpkx - ok
16:12:11.0069 2936 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\windows\system32\drivers\uliahci.sys
16:12:11.0075 2936 uliahci - ok
16:12:11.0122 2936 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\windows\system32\drivers\ulsata.sys
16:12:11.0125 2936 UlSata - ok
16:12:11.0179 2936 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\windows\system32\drivers\ulsata2.sys
16:12:11.0183 2936 ulsata2 - ok
16:12:11.0238 2936 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\windows\system32\DRIVERS\umbus.sys
16:12:11.0240 2936 umbus - ok
16:12:11.0287 2936 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\windows\System32\upnphost.dll
16:12:11.0307 2936 upnphost - ok
16:12:11.0396 2936 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\windows\system32\DRIVERS\usbccgp.sys
16:12:11.0399 2936 usbccgp - ok
16:12:11.0454 2936 usbcir (e9476e6c486e76bc4898074768fb7131) C:\windows\system32\drivers\usbcir.sys
16:12:11.0457 2936 usbcir - ok
16:12:11.0558 2936 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\windows\system32\DRIVERS\usbehci.sys
16:12:11.0561 2936 usbehci - ok
16:12:11.0624 2936 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\windows\system32\DRIVERS\usbhub.sys
16:12:11.0629 2936 usbhub - ok
16:12:11.0717 2936 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\windows\system32\DRIVERS\usbohci.sys
16:12:11.0718 2936 usbohci - ok
16:12:11.0762 2936 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\windows\system32\drivers\usbprint.sys
16:12:11.0764 2936 usbprint - ok
16:12:11.0840 2936 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\windows\system32\DRIVERS\USBSTOR.SYS
16:12:11.0842 2936 USBSTOR - ok
16:12:11.0897 2936 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\windows\system32\DRIVERS\usbuhci.sys
16:12:11.0899 2936 usbuhci - ok
16:12:11.0954 2936 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\windows\System32\uxsms.dll
16:12:11.0958 2936 UxSms - ok
16:12:12.0006 2936 vds (cd88d1b7776dc17a119049742ec07eb4) C:\windows\System32\vds.exe
16:12:12.0029 2936 vds - ok
16:12:12.0167 2936 vga (87b06e1f30b749a114f74622d013f8d4) C:\windows\system32\DRIVERS\vgapnp.sys
16:12:12.0171 2936 vga - ok
16:12:12.0210 2936 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\windows\System32\drivers\vga.sys
16:12:12.0212 2936 VgaSave - ok
16:12:12.0285 2936 viaagp (5d7159def58a800d5781ba3a879627bc) C:\windows\system32\drivers\viaagp.sys
16:12:12.0289 2936 viaagp - ok
16:12:12.0318 2936 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\windows\system32\drivers\viac7.sys
16:12:12.0322 2936 ViaC7 - ok
16:12:12.0362 2936 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\windows\system32\drivers\viaide.sys
16:12:12.0364 2936 viaide - ok
16:12:12.0424 2936 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\windows\system32\drivers\volmgr.sys
16:12:12.0427 2936 volmgr - ok
16:12:12.0499 2936 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\windows\system32\drivers\volmgrx.sys
16:12:12.0507 2936 volmgrx - ok
16:12:12.0598 2936 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\windows\system32\drivers\volsnap.sys
16:12:12.0604 2936 volsnap - ok
16:12:12.0664 2936 vsmraid (587253e09325e6bf226b299774b728a9) C:\windows\system32\drivers\vsmraid.sys
16:12:12.0665 2936 vsmraid - ok
16:12:12.0766 2936 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\windows\system32\vssvc.exe
16:12:12.0800 2936 VSS - ok
16:12:12.0862 2936 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\windows\system32\w32time.dll
16:12:12.0876 2936 W32Time - ok
16:12:12.0985 2936 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\windows\system32\drivers\wacompen.sys
16:12:12.0986 2936 WacomPen - ok
16:12:13.0032 2936 Wanarp (55201897378cca7af8b5efd874374a26) C:\windows\system32\DRIVERS\wanarp.sys
16:12:13.0035 2936 Wanarp - ok
16:12:13.0064 2936 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\windows\system32\DRIVERS\wanarp.sys
16:12:13.0065 2936 Wanarpv6 - ok
16:12:13.0161 2936 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\windows\System32\wcncsvc.dll
16:12:13.0185 2936 wcncsvc - ok
16:12:13.0252 2936 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\windows\System32\WcsPlugInService.dll
16:12:13.0259 2936 WcsPlugInService - ok
16:12:13.0332 2936 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\windows\system32\drivers\wd.sys
16:12:13.0334 2936 Wd - ok
16:12:13.0399 2936 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\windows\system32\drivers\Wdf01000.sys
16:12:13.0412 2936 Wdf01000 - ok
16:12:13.0470 2936 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\windows\system32\wdi.dll
16:12:13.0475 2936 WdiServiceHost - ok
16:12:13.0503 2936 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\windows\system32\wdi.dll
16:12:13.0507 2936 WdiSystemHost - ok
16:12:13.0587 2936 WebClient (04c37d8107320312fbae09926103d5e2) C:\windows\System32\webclnt.dll
16:12:13.0594 2936 WebClient - ok
16:12:13.0651 2936 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\windows\system32\wecsvc.dll
16:12:13.0662 2936 Wecsvc - ok
16:12:13.0745 2936 wercplsupport (670ff720071ed741206d69bd995ea453) C:\windows\System32\wercplsupport.dll
16:12:13.0750 2936 wercplsupport - ok
16:12:13.0847 2936 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\windows\System32\WerSvc.dll
16:12:13.0852 2936 WerSvc - ok
16:12:13.0959 2936 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
16:12:13.0980 2936 WinDefend - ok
16:12:14.0014 2936 WinHttpAutoProxySvc - ok
16:12:14.0119 2936 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\windows\system32\wbem\WMIsvc.dll
16:12:14.0124 2936 Winmgmt - ok
16:12:14.0226 2936 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\windows\system32\WsmSvc.dll
16:12:14.0244 2936 WinRM - ok
16:12:14.0330 2936 Wlansvc (c008405e4feeb069e30da1d823910234) C:\windows\System32\wlansvc.dll
16:12:14.0348 2936 Wlansvc - ok
16:12:14.0407 2936 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\windows\system32\DRIVERS\wmiacpi.sys
16:12:14.0411 2936 WmiAcpi - ok
16:12:14.0521 2936 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\windows\system32\wbem\WmiApSrv.exe
16:12:14.0525 2936 wmiApSrv - ok
16:12:14.0630 2936 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
16:12:14.0662 2936 WMPNetworkSvc - ok
16:12:14.0746 2936 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\windows\System32\wpcsvc.dll
16:12:14.0758 2936 WPCSvc - ok
16:12:14.0804 2936 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\windows\system32\wpdbusenum.dll
16:12:14.0809 2936 WPDBusEnum - ok
16:12:15.0002 2936 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
16:12:15.0025 2936 WPFFontCache_v0400 - ok
16:12:15.0130 2936 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\windows\system32\drivers\ws2ifsl.sys
16:12:15.0132 2936 ws2ifsl - ok
16:12:15.0182 2936 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\windows\System32\wscsvc.dll
16:12:15.0187 2936 wscsvc - ok
16:12:15.0220 2936 WSearch - ok
16:12:15.0340 2936 wuauserv (6298277b73c77fa99106b271a7525163) C:\windows\system32\wuaueng.dll
16:12:15.0412 2936 wuauserv - ok
16:12:15.0478 2936 wudfsvc (575a4190d989f64732119e4114045a4f) C:\windows\System32\WUDFSvc.dll
16:12:15.0483 2936 wudfsvc - ok
16:12:15.0540 2936 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
16:12:15.0547 2936 \Device\Harddisk0\DR0 - ok
16:12:15.0565 2936 Boot (0x1200) (d58400361a92142051a4bb0eb72c1501) \Device\Harddisk0\DR0\Partition0
16:12:15.0567 2936 \Device\Harddisk0\DR0\Partition0 - ok
16:12:15.0603 2936 Boot (0x1200) (46353d3c7e515f32e33f0400c7151bbf) \Device\Harddisk0\DR0\Partition1
16:12:15.0604 2936 \Device\Harddisk0\DR0\Partition1 - ok
16:12:15.0609 2936 ============================================================
16:12:15.0609 2936 Scan finished
16:12:15.0609 2936 ============================================================
16:12:15.0639 1020 Detected object count: 0
16:12:15.0639 1020 Actual detected object count: 0

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: blue screen

#6 Příspěvek od motji »

Log je ok. Pokud s počítačem nejsou problémy, je to vše :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

berousek
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 08 bře 2012 18:33

Re: blue screen

#7 Příspěvek od berousek »

dekuji. :thumbsup:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: blue screen

#8 Příspěvek od motji »

Není zač :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět