Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

setup.exe - Vista

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

setup.exe - Vista

#1 Příspěvek od Leba »

Zdravím,
dostal se mi do ruk NTB s Vistou.
Problém je že při zapnutí nenaběhne klasicky plocha ale IE který je přesměrovaný na IP 193.107.17.79 a blokne jakoukoliv manipulaci s PC tak že jde vidět v AN jen zaplatit 50 doláčů :)
Spouštěcí soubor jsem našel ve složce TEMP nějaký setup.exe ale nejde smazat.
Vista naběhne ale zůstane černé pozadí kde není nic ani nabídka start ani ikony ( není spuštěný explorer.exe ) při ručním spuštění nereaguje.

Tady je LOG

Logfile of random's system information tool 1.09 (written by random/random)
Run by Robo at 2012-05-23 22:40:38
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 203 GB (69%) free of 292 GB
Total RAM: 3061 MB (61% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\At1.job
C:\Windows\tasks\At10.job
C:\Windows\tasks\At11.job
C:\Windows\tasks\At12.job
C:\Windows\tasks\At13.job
C:\Windows\tasks\At14.job
C:\Windows\tasks\At15.job
C:\Windows\tasks\At16.job
C:\Windows\tasks\At17.job
C:\Windows\tasks\At18.job
C:\Windows\tasks\At19.job
C:\Windows\tasks\At2.job
C:\Windows\tasks\At20.job
C:\Windows\tasks\At21.job
C:\Windows\tasks\At22.job
C:\Windows\tasks\At23.job
C:\Windows\tasks\At24.job
C:\Windows\tasks\At25.job
C:\Windows\tasks\At26.job
C:\Windows\tasks\At27.job
C:\Windows\tasks\At28.job
C:\Windows\tasks\At29.job
C:\Windows\tasks\At3.job
C:\Windows\tasks\At30.job
C:\Windows\tasks\At31.job
C:\Windows\tasks\At32.job
C:\Windows\tasks\At33.job
C:\Windows\tasks\At34.job
C:\Windows\tasks\At35.job
C:\Windows\tasks\At36.job
C:\Windows\tasks\At37.job
C:\Windows\tasks\At38.job
C:\Windows\tasks\At39.job
C:\Windows\tasks\At4.job
C:\Windows\tasks\At40.job
C:\Windows\tasks\At41.job
C:\Windows\tasks\At42.job
C:\Windows\tasks\At43.job
C:\Windows\tasks\At44.job
C:\Windows\tasks\At45.job
C:\Windows\tasks\At46.job
C:\Windows\tasks\At47.job
C:\Windows\tasks\At48.job
C:\Windows\tasks\At5.job
C:\Windows\tasks\At6.job
C:\Windows\tasks\At7.job
C:\Windows\tasks\At8.job
C:\Windows\tasks\At9.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{6A1516EB-7EB1-4127-88A8-F8934616180F}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-03-19 192112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-09-21 3853984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll [2012-01-14 1003576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-04-09 1519272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-04-09 1519272]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-03-19 192112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2008-05-04 167936]
"OEM02Mon.exe"=C:\Windows\OEM02Mon.exe [2008-03-04 36864]
"SigmatelSysTrayApp"=C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [2007-11-12 405504]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-03-06 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-03-06 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-03-06 133656]
"Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2008-07-03 3563520]
"DELL Webcam Manager"=C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe [2007-07-27 118784]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-03-21 174872]
"Logitech Hardware Abstraction Layer"=C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE [2007-01-11 101136]
""= []
"PCMService"=C:\Program Files\Dell\MediaDirect\PCMService.exe [2007-12-21 184320]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-01-11 101136]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-08 305440]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2012-04-09 1557160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"*Restore"=C:\Windows\System32\rstrui.exe [2008-11-14 318464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-04-05 39408]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-11 86960]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe
SetPoint.lnk - C:\Program Files\SetPoint\SetPoint.exe

C:\Users\Robo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-03-06 200704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jmcheng]
C:\Windows\system32\config\system [2012-05-23 32768000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoViewContextMenu"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"VIDC.DIVX"=divx.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-05-23 22:40:38 ----D---- C:\rsit
2012-05-23 22:40:38 ----D---- C:\Program Files\trend micro
2012-05-23 22:32:51 ----SD---- C:\ComboFix
2012-05-23 20:05:37 ----D---- C:\Program Files\CCleaner
2012-05-23 16:18:39 ----A---- C:\Windows\zip.exe
2012-05-23 16:18:39 ----A---- C:\Windows\SWSC.exe
2012-05-23 16:18:39 ----A---- C:\Windows\SWREG.exe
2012-05-23 16:18:39 ----A---- C:\Windows\sed.exe
2012-05-23 16:18:39 ----A---- C:\Windows\PEV.exe
2012-05-23 16:18:39 ----A---- C:\Windows\NIRCMD.exe
2012-05-23 16:18:39 ----A---- C:\Windows\MBR.exe
2012-05-23 16:18:39 ----A---- C:\Windows\grep.exe
2012-05-23 16:18:36 ----D---- C:\Windows\ERDNT
2012-05-23 16:18:33 ----D---- C:\Qoobox
2012-05-23 16:18:10 ----SD---- C:\32788R22FWJFW
2012-05-23 16:09:25 ----ASH---- C:\hiberfil.sys
2012-05-11 17:26:36 ----A---- C:\ProgramData\LY4uMees.exe
2012-04-28 14:12:59 ----ASH---- C:\Windows\system32\dds_trash_log.cmd

======List of files/folders modified in the last 1 month======

2012-05-23 22:40:38 ----RD---- C:\Program Files
2012-05-23 22:40:15 ----D---- C:\Windows
2012-05-23 22:38:01 ----SHD---- C:\System Volume Information
2012-05-23 22:34:09 ----D---- C:\Windows\System32
2012-05-23 22:32:49 ----D---- C:\Windows\system32\drivers
2012-05-23 22:32:35 ----D---- C:\Windows\inf
2012-05-23 22:32:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-05-23 22:27:47 ----D---- C:\Windows\Temp
2012-05-23 20:10:15 ----D---- C:\Users\Robo\AppData\Roaming\Media Player Classic
2012-05-23 20:10:03 ----D---- C:\Windows\Debug
2012-05-23 19:42:13 ----D---- C:\Windows\Logs
2012-05-23 19:32:50 ----SHD---- C:\$Recycle.Bin
2012-05-23 16:15:31 ----D---- C:\Windows\Prefetch
2012-05-23 16:05:37 ----SD---- C:\ProgramData\Microsoft
2012-05-23 16:04:35 ----SD---- C:\Users\Robo\AppData\Roaming\Microsoft
2012-05-11 18:00:28 ----HD---- C:\ProgramData
2012-05-11 17:53:40 ----D---- C:\Windows\system32\catroot2
2012-05-11 17:26:42 ----D---- C:\Windows\Tasks
2012-05-11 17:26:42 ----D---- C:\Windows\system32\Tasks
2012-05-11 17:22:29 ----A---- C:\Windows\system32\mrt.exe
2012-05-09 18:50:14 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-04-28 14:17:05 ----D---- C:\Windows\system32\drivers\etc
2012-04-28 13:10:22 ----SHD---- C:\Windows\Installer
2012-04-28 13:10:22 ----D---- C:\Program Files\Ask.com

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2007-09-06 304920]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2007-11-14 43840]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2008-06-23 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-09-06 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-09-06 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-09-06 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2008-06-23 8704]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-05-04 164400]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2008-07-03 18424]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; C:\Windows\system32\DRIVERS\bcmwl6.sys [2008-07-03 1207288]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-11-14 19456]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-11-14 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 78128]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 80176]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 16560]
R3 catchme;catchme; \??\C:\Users\Robo\AppData\Local\Temp\catchme.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2008-06-23 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2008-06-23 208384]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-03-06 2016256]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\Windows\system32\drivers\IntcHdmi.sys [2008-03-06 111616]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2007-01-11 32272]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2007-01-11 32528]
R3 OEM02Dev;Creative Camera OEM002 Driver; C:\Windows\system32\DRIVERS\OEM02Dev.sys [2008-03-04 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver; C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2008-03-04 7424]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-11-12 330240]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-06-23 661504]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 278528]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-11-14 220160]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Windows\system32\aestsrv.exe [2007-11-12 73728]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 enecbpth;Uscbs108; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-03-21 355096]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 STacSV;SigmaTel Audio Service; C:\Windows\system32\STacSV.exe [2007-11-12 102400]
S2 AMService;AMService; C:\Windows\TEMP\bidnfs\setup.exe [2012-05-02 45568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2008-07-03 24064]
S2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2008-06-23 386560]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 257696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-10-04 182768]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-08 545568]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Mate tam, krom jineho, peknou mrchu v podobe ZeroAccessu - tohle nebude lehke na leceni :boxed:

:arrow: S tim ComboFixem jste tam nacvicoval co, vy s nim umite zachazet :???:

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

Re: setup.exe - Vista

#3 Příspěvek od Leba »

tak s toho nemám radost :(
ComboFix jsem zkoušel amatérsky na samém začátku :(

Log



RogueKiller V7.4.5 [05/18/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: Robo [Práva správce]
Mód: Kontrola -- Datum: 05/23/2012 23:37:32

¤¤¤ Škodlivé procesy: 1 ¤¤¤
[SUSP PATH] setup.exe -- C:\Windows\TEMP\bidnfs\setup.exe -> KILLED [TermProc]

¤¤¤ Záznamy Registrů: 105 ¤¤¤
[SUSP PATH] HKUS\.DEFAULT[...]\Run : AMService (C:\Windows\TEMP\jffcsw\setup.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-18[...]\Run : AMService (C:\Windows\TEMP\jffcsw\setup.exe) -> FOUND
[SUSP PATH] HKLM\[...]\Winlogon : Shell (C:\Windows\Temp\xldlgf\setup.exe) -> FOUND
[SUSP PATH] At17.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At16.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At15.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At14.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At13.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At12.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At11.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At10.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At1.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At26.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At25.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At24.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At23.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At22.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At21.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At20.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At2.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At19.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At18.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At35.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At34.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At33.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At32.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At31.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At30.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At3.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At29.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At28.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At27.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At44.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At43.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At42.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At41.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At40.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At4.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At39.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At38.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At37.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At36.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At9.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At8.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At7.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At6.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At5.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At48.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At47.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At46.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At45.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At1.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At10.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At11.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At12.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At13.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At14.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At15.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At16.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At17.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At18.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At19.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At2.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At20.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At21.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At22.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At23.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At24.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At25.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At26.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At27.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At28.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At29.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At3.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At30.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At31.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At32.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At33.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At34.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At35.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At36.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At37.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At38.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At39.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At4.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At40.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At41.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At42.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At43.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At44.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At45.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At46.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At47.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At48.job @ : C:\ProgramData\LY4uMees.exe_ -> FOUND
[SUSP PATH] At5.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At6.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At7.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At8.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[SUSP PATH] At9.job @ : C:\ProgramData\LY4uMees.exe -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (10.0.0.1:3128) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HIDDEN VAL] HKLM\[...]\Run : @ () -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤
[FAKED] dfsc.sys : c:\windows\system32\drivers\dfsc.sys --> CANNOT FIX

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200BEVT-75ZCT2 +++++
--- User ---
[MBR] 0cef50ba4431309551b5dfd5ae7ac3c7
[BSP] e4f1a3792e18a93ded96ab613143948a : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 101 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 208896 | Size: 10240 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 21180416 | Size: 292341 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 619896832 | Size: 2560 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: -Pretec 08GB USB Device +++++
--- User ---
[MBR] 3d6e07461c2b5f5c67fc65f109020212
[BSP] 11300e7ea6df89770ae73797c3436570 : MBR Code unknown
Partition table:
0 - [XXXXXX] UNKNOWN (0x20) [VISIBLE] Offset (sectors): 234840425 | Size: 994568 Mo
1 - [XXXXXX] UNKNOWN (0x69) [VISIBLE] Offset (sectors): 1376390655 | Size: 798350 Mo
2 - [XXXXXX] UNKNOWN (0x74) [VISIBLE] Offset (sectors): 1802725748 | Size: 877581 Mo
3 - [XXXXXX] UNKNOWN (0x73) [VISIBLE] Offset (sectors): 2885681152 | Size: 26 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#4 Příspěvek od vyosek »

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Host a Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Proxy a Zprava - otevre se log, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

Re: setup.exe - Vista

#5 Příspěvek od Leba »

Pochopil jsem, na CF nešáhnu bez vyzvání...

Log bodu 1

RogueKiller V7.4.5 [05/18/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: Robo [Práva správce]
Mód: Odebrat -- Datum: 05/24/2012 00:01:45

¤¤¤ Škodlivé procesy: 1 ¤¤¤
[SUSP PATH] setup.exe -- C:\Windows\TEMP\bidnfs\setup.exe -> KILLED [TermProc]

¤¤¤ Záznamy Registrů: 59 ¤¤¤
[SUSP PATH] HKUS\.DEFAULT[...]\Run : AMService (C:\Windows\TEMP\jffcsw\setup.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Winlogon : Shell (C:\Windows\Temp\xldlgf\setup.exe) -> REPLACED (Explorer.exe)
[SUSP PATH] At17.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At16.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At15.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At14.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At13.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At12.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At11.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At10.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At1.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At26.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At25.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At24.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At23.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At22.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At21.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At20.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At2.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At19.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At18.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At35.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At34.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At33.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At32.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At31.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At30.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At3.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At29.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At28.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At27.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At44.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At43.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At42.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At41.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At40.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At4.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At39.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At38.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At37.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At36.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At9.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At8.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At7.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At6.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At5.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At48.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At47.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At46.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At45.job @ : C:\ProgramData\LY4uMees.exe_ -> DELETED
[SUSP PATH] At1.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At10.job @ : C:\ProgramData\LY4uMees.exe -> DELETED
[SUSP PATH] At13.job @ : C:\ProgramData\LY4uMees.exe -> ERROR
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (10.0.0.1:3128) -> NOT REMOVED, USE PROXYFIX
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HIDDEN VAL] HKLM\[...]\Run : @ () -> DELETED

¤¤¤ Zvláštní soubory / Složky: ¤¤¤
[FAKED] dfsc.sys : c:\windows\system32\drivers\dfsc.sys --> CANNOT FIX

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200BEVT-75ZCT2 +++++
--- User ---
[MBR] 0cef50ba4431309551b5dfd5ae7ac3c7
[BSP] e4f1a3792e18a93ded96ab613143948a : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 101 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 208896 | Size: 10240 Mo
2 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 21180416 | Size: 292341 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 619896832 | Size: 2560 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt


Log bodu 2


RogueKiller V7.4.5 [05/18/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: Robo [Práva správce]
Mód: Oprava HOSTS -- Datum: 05/24/2012 00:02:32

¤¤¤ Škodlivé procesy: 1 ¤¤¤
[SUSP PATH] setup.exe -- C:\Windows\TEMP\bidnfs\setup.exe -> KILLED [TermProc]

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤


¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost

Dokončeno : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt


Log bodu 3


RogueKiller V7.4.5 [05/18/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: Robo [Práva správce]
Mód: Oprava Proxy -- Datum: 05/24/2012 00:07:49

¤¤¤ Škodlivé procesy: 1 ¤¤¤
[SUSP PATH] setup.exe -- C:\Windows\TEMP\bidnfs\setup.exe -> KILLED [TermProc]

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Záznamy Registrů: 1 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (10.0.0.1:3128) -> DELETED

Dokončeno : << RKreport[5].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt


Log bodu 4


00:12:02.0965 0320 TDSS rootkit removing tool 2.7.37.0 May 23 2012 08:15:30
00:12:02.0996 0320 ============================================================
00:12:02.0996 0320 Current date / time: 2012/05/24 00:12:02.0996
00:12:02.0996 0320 SystemInfo:
00:12:02.0996 0320
00:12:02.0996 0320 OS Version: 6.0.6001 ServicePack: 1.0
00:12:02.0996 0320 Product type: Workstation
00:12:02.0996 0320 ComputerName: ROBO-PC
00:12:02.0996 0320 UserName: Robo
00:12:02.0996 0320 Windows directory: C:\Windows
00:12:02.0996 0320 System windows directory: C:\Windows
00:12:02.0996 0320 Processor architecture: Intel x86
00:12:02.0996 0320 Number of processors: 2
00:12:02.0996 0320 Page size: 0x1000
00:12:02.0996 0320 Boot type: Normal boot
00:12:02.0996 0320 ============================================================
00:12:03.0355 0320 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:12:03.0355 0320 Drive \Device\Harddisk1\DR4 - Size: 0x1E1509000 (7.52 Gb), SectorSize: 0x200, Cylinders: 0x3D5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
00:12:03.0355 0320 ============================================================
00:12:03.0355 0320 \Device\Harddisk0\DR0:
00:12:03.0355 0320 MBR partitions:
00:12:03.0355 0320 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x33000, BlocksNum 0x1400000
00:12:03.0355 0320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1433000, BlocksNum 0x23AFAFF8
00:12:03.0386 0320 \Device\Harddisk1\DR4:
00:12:03.0386 0320 MBR partitions:
00:12:03.0386 0320 ============================================================
00:12:03.0448 0320 C: <-> \Device\Harddisk0\DR0\Partition1
00:12:03.0479 0320 D: <-> \Device\Harddisk0\DR0\Partition0
00:12:03.0479 0320 ============================================================
00:12:03.0479 0320 Initialize success
00:12:03.0479 0320 ============================================================
00:12:33.0775 2540 ============================================================
00:12:33.0775 2540 Scan started
00:12:33.0775 2540 Mode: Manual; SigCheck; TDLFS;
00:12:33.0775 2540 ============================================================
00:12:34.0227 2540 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
00:12:34.0321 2540 ACPI - ok
00:12:34.0461 2540 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:12:34.0477 2540 AdobeFlashPlayerUpdateSvc - ok
00:12:34.0570 2540 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
00:12:34.0633 2540 adp94xx - ok
00:12:34.0695 2540 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
00:12:34.0695 2540 adpahci - ok
00:12:34.0726 2540 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
00:12:34.0742 2540 adpu160m - ok
00:12:34.0789 2540 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
00:12:34.0804 2540 adpu320 - ok
00:12:34.0835 2540 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
00:12:34.0867 2540 AeLookupSvc - ok
00:12:34.0913 2540 AESTFilters (ef1142512bec12f1c2c87735da1755be) C:\Windows\system32\aestsrv.exe
00:12:34.0929 2540 AESTFilters - ok
00:12:35.0023 2540 AFD (48eb99503533c27ac6135648e5474457) C:\Windows\system32\drivers\afd.sys
00:12:35.0038 2540 AFD - ok
00:12:35.0085 2540 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
00:12:35.0101 2540 agp440 - ok
00:12:35.0132 2540 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
00:12:35.0147 2540 aic78xx - ok
00:12:35.0163 2540 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
00:12:35.0194 2540 ALG - ok
00:12:35.0225 2540 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
00:12:35.0241 2540 aliide - ok
00:12:35.0257 2540 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
00:12:35.0257 2540 amdagp - ok
00:12:35.0272 2540 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
00:12:35.0288 2540 amdide - ok
00:12:35.0319 2540 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
00:12:35.0366 2540 AmdK7 - ok
00:12:35.0413 2540 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
00:12:35.0444 2540 AmdK8 - ok
00:12:35.0537 2540 AMService - ok
00:12:35.0615 2540 ApfiltrService (a80230bd04f0b8bf05185b369bb1cbb8) C:\Windows\system32\DRIVERS\Apfiltr.sys
00:12:35.0647 2540 ApfiltrService - ok
00:12:35.0709 2540 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
00:12:35.0725 2540 Appinfo - ok
00:12:35.0834 2540 Apple Mobile Device (4b5ae15e5c73eb4dc8dbec2788230d41) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
00:12:35.0849 2540 Apple Mobile Device - ok
00:12:35.0912 2540 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
00:12:35.0927 2540 arc - ok
00:12:36.0005 2540 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
00:12:36.0021 2540 arcsas - ok
00:12:36.0068 2540 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
00:12:36.0115 2540 AsyncMac - ok
00:12:36.0130 2540 atapi (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
00:12:36.0130 2540 atapi - ok
00:12:36.0208 2540 AudioEndpointBuilder (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
00:12:36.0224 2540 AudioEndpointBuilder - ok
00:12:36.0271 2540 Audiosrv (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
00:12:36.0302 2540 Audiosrv - ok
00:12:36.0349 2540 BCM42RLY (7bd70aeed0d975285a1b20bd012ebf4e) C:\Windows\system32\drivers\BCM42RLY.sys
00:12:36.0364 2540 BCM42RLY - ok
00:12:36.0473 2540 BCM43XX (fa6707a346cd122407f3b0bad1c47639) C:\Windows\system32\DRIVERS\bcmwl6.sys
00:12:36.0567 2540 BCM43XX - ok
00:12:36.0692 2540 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
00:12:36.0707 2540 Beep - ok
00:12:36.0863 2540 BITS (02ed7b4dbc2a3232a389106da7515c3d) C:\Windows\System32\qmgr.dll
00:12:37.0051 2540 BITS - ok
00:12:37.0066 2540 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
00:12:37.0113 2540 blbdrive - ok
00:12:37.0238 2540 Bonjour Service (3f56903e124e820aeece6d471583c6c1) C:\Program Files\Bonjour\mDNSResponder.exe
00:12:37.0238 2540 Bonjour Service - ok
00:12:37.0300 2540 bowser (8153396d5551276227fa146900f734e6) C:\Windows\system32\DRIVERS\bowser.sys
00:12:37.0347 2540 bowser - ok
00:12:37.0378 2540 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
00:12:37.0409 2540 BrFiltLo - ok
00:12:37.0456 2540 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
00:12:37.0472 2540 BrFiltUp - ok
00:12:37.0519 2540 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
00:12:37.0550 2540 Browser - ok
00:12:37.0612 2540 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
00:12:37.0643 2540 Brserid - ok
00:12:37.0675 2540 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
00:12:37.0721 2540 BrSerWdm - ok
00:12:37.0768 2540 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
00:12:37.0799 2540 BrUsbMdm - ok
00:12:37.0815 2540 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
00:12:37.0909 2540 BrUsbSer - ok
00:12:37.0955 2540 BthEnum (e5145a9dec2a863de262d40eff7d793a) C:\Windows\system32\DRIVERS\BthEnum.sys
00:12:37.0955 2540 BthEnum - ok
00:12:38.0002 2540 BTHMODEM (5ffa6988ff9597986ff2ada736cc90c0) C:\Windows\system32\DRIVERS\bthmodem.sys
00:12:38.0033 2540 BTHMODEM - ok
00:12:38.0065 2540 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
00:12:38.0096 2540 BthPan - ok
00:12:38.0127 2540 BTHPORT (9f299c5274672900591e7c616d725f56) C:\Windows\system32\Drivers\BTHport.sys
00:12:38.0158 2540 BTHPORT - ok
00:12:38.0205 2540 BthServ (58ee7f5e68310bc8d4e7cebd8358c12e) C:\Windows\System32\bthserv.dll
00:12:38.0236 2540 BthServ - ok
00:12:38.0252 2540 BTHUSB (31c9453df130b4b89eafcdc97319ccc2) C:\Windows\system32\Drivers\BTHUSB.sys
00:12:38.0252 2540 BTHUSB - ok
00:12:38.0314 2540 btwaudio (4a28e7bd365377d0512b7ef8c7596d2c) C:\Windows\system32\drivers\btwaudio.sys
00:12:38.0330 2540 btwaudio - ok
00:12:38.0392 2540 btwavdt (5ffde57253d665067b0886612817eb11) C:\Windows\system32\drivers\btwavdt.sys
00:12:38.0392 2540 btwavdt - ok
00:12:38.0408 2540 btwrchid (ab07dc8b05c31a4f95fc73019be9db15) C:\Windows\system32\DRIVERS\btwrchid.sys
00:12:38.0423 2540 btwrchid - ok
00:12:38.0533 2540 catchme - ok
00:12:38.0579 2540 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
00:12:38.0626 2540 cdfs - ok
00:12:38.0689 2540 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
00:12:38.0735 2540 cdrom - ok
00:12:38.0782 2540 CertPropSvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
00:12:38.0829 2540 CertPropSvc - ok
00:12:38.0860 2540 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
00:12:38.0891 2540 circlass - ok
00:12:38.0923 2540 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
00:12:38.0938 2540 CLFS - ok
00:12:39.0016 2540 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:12:39.0032 2540 clr_optimization_v2.0.50727_32 - ok
00:12:39.0157 2540 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:12:39.0157 2540 clr_optimization_v4.0.30319_32 - ok
00:12:39.0188 2540 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
00:12:39.0219 2540 CmBatt - ok
00:12:39.0250 2540 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
00:12:39.0266 2540 cmdide - ok
00:12:39.0297 2540 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
00:12:39.0313 2540 Compbatt - ok
00:12:39.0313 2540 COMSysApp - ok
00:12:39.0328 2540 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
00:12:39.0328 2540 crcdisk - ok
00:12:39.0359 2540 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
00:12:39.0406 2540 Crusoe - ok
00:12:39.0484 2540 CryptSvc (6de363f9f99334514c46aec02d3e3678) C:\Windows\system32\cryptsvc.dll
00:12:39.0515 2540 CryptSvc - ok
00:12:39.0609 2540 DcomLaunch (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
00:12:39.0640 2540 DcomLaunch - ok
00:12:39.0703 2540 DfsC (cbda4adeec40ff219a141729e4774d05) C:\Windows\system32\Drivers\dfsc.sys
00:12:39.0703 2540 Suspicious file (Forged): C:\Windows\system32\Drivers\dfsc.sys. Real md5: cbda4adeec40ff219a141729e4774d05, Fake md5: a3e9fa213f443ac77c7746119d13feec
00:12:39.0703 2540 DfsC ( Virus.Win32.ZAccess.c ) - infected
00:12:39.0703 2540 DfsC - detected Virus.Win32.ZAccess.c (0)
00:12:39.0921 2540 DFSR (fa3463f25f9cc9c3bcf1e7912feff099) C:\Windows\system32\DFSR.exe
00:12:40.0030 2540 DFSR - ok
00:12:40.0171 2540 Dhcp (43a988a9c10333476cb5fb667cbd629d) C:\Windows\System32\dhcpcsvc.dll
00:12:40.0202 2540 Dhcp - ok
00:12:40.0249 2540 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
00:12:40.0264 2540 disk - ok
00:12:40.0327 2540 Dnscache (4805d9a6d281c7a7defd9094dec6af7d) C:\Windows\System32\dnsrslvr.dll
00:12:40.0358 2540 Dnscache - ok
00:12:40.0389 2540 dot3svc (5af620a08c614e24206b79e8153cf1a8) C:\Windows\System32\dot3svc.dll
00:12:40.0420 2540 dot3svc - ok
00:12:40.0483 2540 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
00:12:40.0514 2540 DPS - ok
00:12:40.0561 2540 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
00:12:40.0592 2540 drmkaud - ok
00:12:40.0670 2540 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
00:12:40.0779 2540 DXGKrnl - ok
00:12:40.0841 2540 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
00:12:40.0857 2540 e1express - ok
00:12:40.0888 2540 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
00:12:40.0951 2540 E1G60 - ok
00:12:40.0982 2540 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
00:12:40.0997 2540 EapHost - ok
00:12:41.0029 2540 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
00:12:41.0044 2540 Ecache - ok
00:12:41.0122 2540 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
00:12:41.0153 2540 ehRecvr - ok
00:12:41.0169 2540 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
00:12:41.0185 2540 ehSched - ok
00:12:41.0216 2540 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
00:12:41.0231 2540 ehstart - ok
00:12:41.0309 2540 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
00:12:41.0372 2540 elxstor - ok
00:12:41.0481 2540 EMDMgmt (70b1a86df0c8ead17d2bc332edae2c7c) C:\Windows\system32\emdmgmt.dll
00:12:41.0575 2540 EMDMgmt - ok
00:12:41.0637 2540 enecbpth (11028c6a84a967070cb1286550f2058f) C:\Windows\system32\sysmgmthp.dll
00:12:41.0637 2540 enecbpth ( Backdoor.Multi.ZAccess.gen ) - infected
00:12:41.0637 2540 enecbpth - detected Backdoor.Multi.ZAccess.gen (0)
00:12:41.0668 2540 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
00:12:41.0715 2540 ErrDev - ok
00:12:41.0824 2540 EventSystem (3cb3343d720168b575133a0a20dc2465) C:\Windows\system32\es.dll
00:12:41.0840 2540 EventSystem - ok
00:12:41.0902 2540 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
00:12:41.0933 2540 exfat - ok
00:12:41.0980 2540 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
00:12:41.0996 2540 fastfat - ok
00:12:42.0027 2540 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
00:12:42.0058 2540 fdc - ok
00:12:42.0089 2540 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
00:12:42.0136 2540 fdPHost - ok
00:12:42.0183 2540 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
00:12:42.0261 2540 FDResPub - ok
00:12:42.0292 2540 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
00:12:42.0292 2540 FileInfo - ok
00:12:42.0323 2540 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
00:12:42.0355 2540 Filetrace - ok
00:12:42.0370 2540 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
00:12:42.0401 2540 flpydisk - ok
00:12:42.0433 2540 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
00:12:42.0433 2540 FltMgr - ok
00:12:42.0511 2540 FontCache3.0.0.0 (c9be08664611ddaf98e2331e9288b00b) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
00:12:42.0526 2540 FontCache3.0.0.0 - ok
00:12:42.0542 2540 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
00:12:42.0557 2540 Fs_Rec - ok
00:12:42.0589 2540 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
00:12:42.0604 2540 gagp30kx - ok
00:12:42.0667 2540 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:12:42.0667 2540 GEARAspiWDM - ok
00:12:42.0729 2540 gpsvc (d9f1113d9401185245573350712f92fc) C:\Windows\System32\gpsvc.dll
00:12:42.0760 2540 gpsvc - ok
00:12:42.0932 2540 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
00:12:42.0963 2540 gupdate - ok
00:12:42.0994 2540 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
00:12:42.0994 2540 gupdatem - ok
00:12:43.0088 2540 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
00:12:43.0103 2540 gusvc - ok
00:12:43.0135 2540 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
00:12:43.0166 2540 HDAudBus - ok
00:12:43.0228 2540 HidBth (204c3b1846e9cbaaef88b8e1f86782f8) C:\Windows\system32\DRIVERS\hidbth.sys
00:12:43.0244 2540 HidBth - ok
00:12:43.0275 2540 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
00:12:43.0322 2540 HidIr - ok
00:12:43.0369 2540 hidserv (53d5a2f9ce6ae47d7507727df1da79f8) C:\Windows\System32\hidserv.dll
00:12:43.0415 2540 hidserv - ok
00:12:43.0431 2540 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
00:12:43.0462 2540 HidUsb - ok
00:12:43.0509 2540 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
00:12:43.0540 2540 hkmsvc - ok
00:12:43.0571 2540 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
00:12:43.0571 2540 HpCISSs - ok
00:12:43.0712 2540 HSF_DPV (99f85640054ba65190b860d878a7c9ae) C:\Windows\system32\DRIVERS\HSX_DPV.sys
00:12:43.0837 2540 HSF_DPV - ok
00:12:43.0915 2540 HSXHWAZL (cfbc2b81972e298f0e19ee68fa9e73da) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
00:12:43.0930 2540 HSXHWAZL - ok
00:12:44.0024 2540 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
00:12:44.0055 2540 HTTP - ok
00:12:44.0086 2540 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
00:12:44.0102 2540 i2omp - ok
00:12:44.0164 2540 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
00:12:44.0195 2540 i8042prt - ok
00:12:44.0336 2540 IAANTMON (ae38a12f79a4980ddb88f36514f8a1da) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
00:12:44.0367 2540 IAANTMON - ok
00:12:44.0461 2540 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\Windows\system32\drivers\iastor.sys
00:12:44.0461 2540 iaStor - ok
00:12:44.0507 2540 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
00:12:44.0507 2540 iaStorV - ok
00:12:44.0601 2540 ICQ Service (a4e43a7ab1202356bebeb6b798f15488) C:\Program Files\ICQ6Toolbar\ICQ Service.exe
00:12:44.0617 2540 ICQ Service - ok
00:12:44.0741 2540 idsvc (7b630acaed64fef0c3e1cf255cb56686) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:12:44.0819 2540 idsvc - ok
00:12:45.0085 2540 igfx (c134e69ce901422d1f2d7ea8d69098fe) C:\Windows\system32\DRIVERS\igdkmd32.sys
00:12:45.0225 2540 igfx - ok
00:12:45.0334 2540 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
00:12:45.0334 2540 iirsp - ok
00:12:45.0412 2540 IKEEXT (a3bc480a2bf8aa8e4dabd2d5dce0afac) C:\Windows\System32\ikeext.dll
00:12:45.0459 2540 IKEEXT - ok
00:12:45.0506 2540 IntcHdmiAddService (98d303ccb3415e9202e82043b37d66dc) C:\Windows\system32\drivers\IntcHdmi.sys
00:12:45.0537 2540 IntcHdmiAddService - ok
00:12:45.0599 2540 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\DRIVERS\intelide.sys
00:12:45.0599 2540 intelide - ok
00:12:45.0631 2540 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
00:12:45.0662 2540 intelppm - ok
00:12:45.0693 2540 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
00:12:45.0724 2540 IPBusEnum - ok
00:12:45.0755 2540 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:12:45.0787 2540 IpFilterDriver - ok
00:12:45.0911 2540 iphlpsvc (6a35d233693edc29a12742049bc5e37f) C:\Windows\System32\iphlpsvc.dll
00:12:45.0943 2540 iphlpsvc - ok
00:12:45.0974 2540 IpInIp - ok
00:12:46.0036 2540 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
00:12:46.0083 2540 IPMIDRV - ok
00:12:46.0114 2540 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
00:12:46.0177 2540 IPNAT - ok
00:12:46.0286 2540 iPod Service (dc434081fbfd27c719473cb0cce8deca) C:\Program Files\iPod\bin\iPodService.exe
00:12:46.0333 2540 iPod Service - ok
00:12:46.0379 2540 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
00:12:46.0395 2540 IRENUM - ok
00:12:46.0442 2540 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
00:12:46.0442 2540 isapnp - ok
00:12:46.0504 2540 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
00:12:46.0520 2540 iScsiPrt - ok
00:12:46.0551 2540 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
00:12:46.0551 2540 iteatapi - ok
00:12:46.0582 2540 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
00:12:46.0582 2540 iteraid - ok
00:12:46.0629 2540 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
00:12:46.0645 2540 kbdclass - ok
00:12:46.0660 2540 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
00:12:46.0676 2540 kbdhid - ok
00:12:46.0707 2540 KeyIso (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:12:46.0723 2540 KeyIso - ok
00:12:46.0785 2540 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
00:12:46.0847 2540 KSecDD - ok
00:12:46.0957 2540 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
00:12:47.0003 2540 KtmRm - ok
00:12:47.0081 2540 LanmanServer (1925e63c91cf1610ae41bfd539062079) C:\Windows\System32\srvsvc.dll
00:12:47.0097 2540 LanmanServer - ok
00:12:47.0175 2540 LanmanWorkstation (2ae2e1628c5d3f1c0a46a67c9fa1df15) C:\Windows\System32\wkssvc.dll
00:12:47.0206 2540 LanmanWorkstation - ok
00:12:47.0269 2540 LHidFilt (597d79382c154cedb638a65012925a23) C:\Windows\system32\DRIVERS\LHidFilt.Sys
00:12:47.0269 2540 LHidFilt - ok
00:12:47.0315 2540 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
00:12:47.0347 2540 lltdio - ok
00:12:47.0393 2540 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
00:12:47.0440 2540 lltdsvc - ok
00:12:47.0471 2540 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
00:12:47.0518 2540 lmhosts - ok
00:12:47.0565 2540 LMouFilt (9ead053d28182bd6acb19d5f58202194) C:\Windows\system32\DRIVERS\LMouFilt.Sys
00:12:47.0565 2540 LMouFilt - ok
00:12:47.0612 2540 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
00:12:47.0612 2540 LSI_FC - ok
00:12:47.0643 2540 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
00:12:47.0659 2540 LSI_SAS - ok
00:12:47.0705 2540 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
00:12:47.0721 2540 LSI_SCSI - ok
00:12:47.0768 2540 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
00:12:47.0799 2540 luafv - ok
00:12:47.0830 2540 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
00:12:47.0861 2540 Mcx2Svc - ok
00:12:47.0908 2540 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
00:12:47.0908 2540 mdmxsdk - ok
00:12:47.0955 2540 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
00:12:47.0955 2540 megasas - ok
00:12:48.0017 2540 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
00:12:48.0064 2540 MegaSR - ok
00:12:48.0205 2540 Microsoft Office Groove Audit Service (fafe367d032ed82e9332b4c741a20216) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
00:12:48.0220 2540 Microsoft Office Groove Audit Service - ok
00:12:48.0236 2540 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
00:12:48.0267 2540 MMCSS - ok
00:12:48.0298 2540 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
00:12:48.0329 2540 Modem - ok
00:12:48.0376 2540 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
00:12:48.0407 2540 monitor - ok
00:12:48.0423 2540 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
00:12:48.0439 2540 mouclass - ok
00:12:48.0485 2540 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
00:12:48.0517 2540 mouhid - ok
00:12:48.0532 2540 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
00:12:48.0548 2540 MountMgr - ok
00:12:48.0579 2540 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
00:12:48.0579 2540 mpio - ok
00:12:48.0595 2540 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
00:12:48.0610 2540 mpsdrv - ok
00:12:48.0673 2540 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
00:12:48.0673 2540 Mraid35x - ok
00:12:48.0688 2540 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
00:12:48.0704 2540 MRxDAV - ok
00:12:48.0766 2540 mrxsmb (5734a0f2be7e495f7d3ed6efd4b9f5a1) C:\Windows\system32\DRIVERS\mrxsmb.sys
00:12:48.0782 2540 mrxsmb - ok
00:12:48.0875 2540 mrxsmb10 (6b5fa5adfacac9dbbe0991f4566d7d55) C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:12:48.0907 2540 mrxsmb10 - ok
00:12:48.0953 2540 mrxsmb20 (5c80d8159181c7abf1b14ba703b01e0b) C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:12:48.0969 2540 mrxsmb20 - ok
00:12:49.0000 2540 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
00:12:49.0016 2540 msahci - ok
00:12:49.0063 2540 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
00:12:49.0078 2540 msdsm - ok
00:12:49.0125 2540 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
00:12:49.0156 2540 MSDTC - ok
00:12:49.0203 2540 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
00:12:49.0234 2540 Msfs - ok
00:12:49.0265 2540 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
00:12:49.0265 2540 msisadrv - ok
00:12:49.0312 2540 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
00:12:49.0359 2540 MSiSCSI - ok
00:12:49.0359 2540 msiserver - ok
00:12:49.0406 2540 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
00:12:49.0421 2540 MSKSSRV - ok
00:12:49.0437 2540 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
00:12:49.0453 2540 MSPCLOCK - ok
00:12:49.0499 2540 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
00:12:49.0515 2540 MSPQM - ok
00:12:49.0546 2540 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
00:12:49.0546 2540 MsRPC - ok
00:12:49.0577 2540 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
00:12:49.0593 2540 mssmbios - ok
00:12:49.0609 2540 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
00:12:49.0640 2540 MSTEE - ok
00:12:49.0702 2540 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
00:12:49.0702 2540 Mup - ok
00:12:49.0749 2540 napagent (c43b25863fbd65b6d2a142af3ae320ca) C:\Windows\system32\qagentRT.dll
00:12:49.0780 2540 napagent - ok
00:12:49.0843 2540 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
00:12:49.0858 2540 NativeWifiP - ok
00:12:49.0936 2540 NDIS (c8560010a542b5dca94c62468dc20784) C:\Windows\system32\drivers\ndis.sys
00:12:49.0967 2540 NDIS - ok
00:12:50.0014 2540 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
00:12:50.0045 2540 NdisTapi - ok
00:12:50.0077 2540 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
00:12:50.0108 2540 Ndisuio - ok
00:12:50.0155 2540 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
00:12:50.0186 2540 NdisWan - ok
00:12:50.0201 2540 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
00:12:50.0248 2540 NDProxy - ok
00:12:50.0279 2540 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
00:12:50.0311 2540 NetBIOS - ok
00:12:50.0342 2540 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
00:12:50.0389 2540 netbt - ok
00:12:50.0420 2540 Netlogon (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:12:50.0435 2540 Netlogon - ok
00:12:50.0482 2540 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
00:12:50.0529 2540 Netman - ok
00:12:50.0591 2540 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
00:12:50.0638 2540 netprofm - ok
00:12:50.0701 2540 NetTcpPortSharing (0ad5876ef4e9eb77c8f93eb5b2fff386) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:12:50.0716 2540 NetTcpPortSharing - ok
00:12:50.0763 2540 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
00:12:50.0779 2540 nfrd960 - ok
00:12:50.0810 2540 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
00:12:50.0888 2540 NlaSvc - ok
00:12:50.0919 2540 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
00:12:50.0950 2540 Npfs - ok
00:12:50.0997 2540 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
00:12:51.0028 2540 nsi - ok
00:12:51.0059 2540 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
00:12:51.0091 2540 nsiproxy - ok
00:12:51.0184 2540 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
00:12:51.0247 2540 Ntfs - ok
00:12:51.0262 2540 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
00:12:51.0325 2540 ntrigdigi - ok
00:12:51.0356 2540 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
00:12:51.0371 2540 Null - ok
00:12:51.0403 2540 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
00:12:51.0418 2540 nvraid - ok
00:12:51.0449 2540 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
00:12:51.0465 2540 nvstor - ok
00:12:51.0543 2540 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
00:12:51.0543 2540 nv_agp - ok
00:12:51.0543 2540 NwlnkFlt - ok
00:12:51.0559 2540 NwlnkFwd - ok
00:12:51.0715 2540 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
00:12:51.0730 2540 odserv - ok
00:12:51.0793 2540 OEM02Dev (19cac780b858822055f46c58a111723c) C:\Windows\system32\DRIVERS\OEM02Dev.sys
00:12:51.0839 2540 OEM02Dev - ok
00:12:51.0886 2540 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\Windows\system32\DRIVERS\OEM02Vfx.sys
00:12:51.0886 2540 OEM02Vfx - ok
00:12:51.0917 2540 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
00:12:51.0949 2540 ohci1394 - ok
00:12:51.0980 2540 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:12:51.0995 2540 ose - ok
00:12:52.0089 2540 p2pimsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:12:52.0151 2540 p2pimsvc - ok
00:12:52.0183 2540 p2psvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:12:52.0245 2540 p2psvc - ok
00:12:52.0292 2540 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
00:12:52.0354 2540 Parport - ok
00:12:52.0385 2540 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
00:12:52.0385 2540 partmgr - ok
00:12:52.0401 2540 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
00:12:52.0463 2540 Parvdm - ok
00:12:52.0495 2540 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
00:12:52.0510 2540 PcaSvc - ok
00:12:52.0541 2540 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
00:12:52.0557 2540 pci - ok
00:12:52.0588 2540 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
00:12:52.0604 2540 pciide - ok
00:12:52.0666 2540 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
00:12:52.0666 2540 pcmcia - ok
00:12:52.0775 2540 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
00:12:52.0931 2540 PEAUTH - ok
00:12:53.0150 2540 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
00:12:53.0368 2540 pla - ok
00:12:53.0571 2540 PlugPlay (78f975cb6d18265be6f492edb2d7bc7b) C:\Windows\system32\umpnpmgr.dll
00:12:53.0602 2540 PlugPlay - ok
00:12:53.0680 2540 PNRPAutoReg (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:12:53.0696 2540 PNRPAutoReg - ok
00:12:53.0727 2540 PNRPsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:12:53.0789 2540 PNRPsvc - ok
00:12:53.0899 2540 PolicyAgent (47b8f37aa18b74d8c2e1bc1a7a2c8f8a) C:\Windows\System32\ipsecsvc.dll
00:12:53.0977 2540 PolicyAgent - ok
00:12:54.0055 2540 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
00:12:54.0117 2540 PptpMiniport - ok
00:12:54.0148 2540 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
00:12:54.0179 2540 Processor - ok
00:12:54.0226 2540 ProfSvc (b627e4fc8585e8843c5905d4d3587a90) C:\Windows\system32\profsvc.dll
00:12:54.0273 2540 ProfSvc - ok
00:12:54.0289 2540 ProtectedStorage (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:12:54.0304 2540 ProtectedStorage - ok
00:12:54.0335 2540 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
00:12:54.0351 2540 PSched - ok
00:12:54.0445 2540 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys
00:12:54.0460 2540 PxHelp20 - ok
00:12:54.0601 2540 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
00:12:54.0710 2540 ql2300 - ok
00:12:54.0803 2540 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
00:12:54.0819 2540 ql40xx - ok
00:12:54.0928 2540 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
00:12:54.0944 2540 QWAVE - ok
00:12:54.0959 2540 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
00:12:54.0975 2540 QWAVEdrv - ok
00:12:55.0209 2540 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
00:12:55.0443 2540 R300 - ok
00:12:55.0630 2540 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
00:12:55.0646 2540 RasAcd - ok
00:12:55.0693 2540 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
00:12:55.0708 2540 RasAuto - ok
00:12:55.0739 2540 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
00:12:55.0771 2540 Rasl2tp - ok
00:12:55.0802 2540 RasMan (6e7c284fc5c4ec07ad164d93810385a6) C:\Windows\System32\rasmans.dll
00:12:55.0817 2540 RasMan - ok
00:12:55.0849 2540 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
00:12:55.0864 2540 RasPppoe - ok
00:12:55.0880 2540 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
00:12:55.0911 2540 RasSstp - ok
00:12:55.0927 2540 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
00:12:55.0958 2540 rdbss - ok
00:12:55.0989 2540 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
00:12:56.0005 2540 RDPCDD - ok
00:12:56.0051 2540 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
00:12:56.0083 2540 rdpdr - ok
00:12:56.0083 2540 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
00:12:56.0114 2540 RDPENCDD - ok
00:12:56.0192 2540 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
00:12:56.0223 2540 RDPWD - ok
00:12:56.0285 2540 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
00:12:56.0317 2540 RemoteAccess - ok
00:12:56.0332 2540 RemoteRegistry (cc4e32400f3c7253400cf8f3f3a0b676) C:\Windows\system32\regsvc.dll
00:12:56.0379 2540 RemoteRegistry - ok
00:12:56.0441 2540 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys
00:12:56.0457 2540 RFCOMM - ok
00:12:56.0519 2540 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
00:12:56.0535 2540 rimmptsk - ok
00:12:56.0551 2540 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
00:12:56.0551 2540 rimsptsk - ok
00:12:56.0582 2540 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
00:12:56.0582 2540 rismxdp - ok
00:12:56.0613 2540 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
00:12:56.0629 2540 RpcLocator - ok
00:12:56.0707 2540 RpcSs (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
00:12:56.0738 2540 RpcSs - ok
00:12:56.0800 2540 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
00:12:56.0847 2540 rspndr - ok
00:12:56.0894 2540 SamSs (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:12:56.0894 2540 SamSs - ok
00:12:56.0941 2540 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
00:12:56.0956 2540 sbp2port - ok
00:12:57.0003 2540 SCardSvr (11387e32642269c7e62e8b52c060b3c6) C:\Windows\System32\SCardSvr.dll
00:12:57.0019 2540 SCardSvr - ok
00:12:57.0128 2540 Schedule (7b587b8a6d4a99f79d2902d0385f29bd) C:\Windows\system32\schedsvc.dll
00:12:57.0190 2540 Schedule - ok
00:12:57.0221 2540 SCPolicySvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
00:12:57.0253 2540 SCPolicySvc - ok
00:12:57.0284 2540 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
00:12:57.0315 2540 sdbus - ok
00:12:57.0362 2540 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
00:12:57.0393 2540 SDRSVC - ok
00:12:57.0393 2540 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
00:12:57.0455 2540 secdrv - ok
00:12:57.0471 2540 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
00:12:57.0518 2540 seclogon - ok
00:12:57.0549 2540 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
00:12:57.0565 2540 SENS - ok
00:12:57.0596 2540 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
00:12:57.0658 2540 Serenum - ok
00:12:57.0705 2540 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
00:12:57.0752 2540 Serial - ok
00:12:57.0767 2540 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
00:12:57.0799 2540 sermouse - ok
00:12:57.0861 2540 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
00:12:57.0892 2540 SessionEnv - ok
00:12:57.0939 2540 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
00:12:57.0955 2540 sffdisk - ok
00:12:57.0970 2540 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
00:12:58.0001 2540 sffp_mmc - ok
00:12:58.0017 2540 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\DRIVERS\sffp_sd.sys
00:12:58.0033 2540 sffp_sd - ok
00:12:58.0079 2540 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
00:12:58.0142 2540 sfloppy - ok
00:12:58.0189 2540 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
00:12:58.0235 2540 SharedAccess - ok
00:12:58.0298 2540 ShellHWDetection (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\System32\shsvcs.dll
00:12:58.0313 2540 ShellHWDetection - ok
00:12:58.0345 2540 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
00:12:58.0345 2540 sisagp - ok
00:12:58.0376 2540 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
00:12:58.0391 2540 SiSRaid2 - ok
00:12:58.0423 2540 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
00:12:58.0438 2540 SiSRaid4 - ok
00:12:58.0657 2540 slsvc (0ba91e1358ad25236863039bb2609a2e) C:\Windows\system32\SLsvc.exe
00:12:58.0969 2540 slsvc - ok
00:12:59.0109 2540 SLUINotify (7c6dc44ca0bfa6291629ab764200d1d4) C:\Windows\system32\SLUINotify.dll
00:12:59.0156 2540 SLUINotify - ok
00:12:59.0281 2540 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
00:12:59.0296 2540 Smb - ok
00:12:59.0343 2540 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
00:12:59.0359 2540 SNMPTRAP - ok
00:12:59.0359 2540 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
00:12:59.0374 2540 spldr - ok
00:12:59.0452 2540 Spooler (3665f79026a3f91fbca63f2c65a09b19) C:\Windows\System32\spoolsv.exe
00:12:59.0452 2540 Spooler - ok
00:12:59.0530 2540 srv (2252aef839b1093d16761189f45af885) C:\Windows\system32\DRIVERS\srv.sys
00:12:59.0546 2540 srv - ok
00:12:59.0593 2540 srv2 (b7ff59408034119476b00a81bb53d5d1) C:\Windows\system32\DRIVERS\srv2.sys
00:12:59.0624 2540 srv2 - ok
00:12:59.0686 2540 srvnet (2accc9b12af02030f531e6cca6f8b76e) C:\Windows\system32\DRIVERS\srvnet.sys
00:12:59.0702 2540 srvnet - ok
00:12:59.0733 2540 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
00:12:59.0764 2540 SSDPSRV - ok
00:12:59.0827 2540 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
00:12:59.0842 2540 SstpSvc - ok
00:12:59.0873 2540 STacSV (7e6dd4b34acd36af6c711d2bde91b040) C:\Windows\system32\STacSV.exe
00:12:59.0920 2540 STacSV - ok
00:12:59.0983 2540 STHDA (6a2a5e809c2c0178326d92b19ee4aad3) C:\Windows\system32\drivers\stwrt.sys
00:13:00.0061 2540 STHDA - ok
00:13:00.0139 2540 stisvc (7dd08a597bc56051f320da0baf69e389) C:\Windows\System32\wiaservc.dll
00:13:00.0185 2540 stisvc - ok
00:13:00.0279 2540 stllssvr (1d0063597c3666404fcf97698abeb019) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
00:13:00.0295 2540 stllssvr - ok
00:13:00.0310 2540 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
00:13:00.0326 2540 swenum - ok
00:13:00.0373 2540 swprv (b36c7cdb86f7f7a8e884479219766950) C:\Windows\System32\swprv.dll
00:13:00.0404 2540 swprv - ok
00:13:00.0435 2540 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
00:13:00.0435 2540 Symc8xx - ok
00:13:00.0466 2540 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
00:13:00.0466 2540 Sym_hi - ok
00:13:00.0497 2540 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
00:13:00.0513 2540 Sym_u3 - ok
00:13:00.0575 2540 SysMain (8710a92d0024b03b5fb9540df1f71f1d) C:\Windows\system32\sysmain.dll
00:13:00.0622 2540 SysMain - ok
00:13:00.0638 2540 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
00:13:00.0653 2540 TabletInputService - ok
00:13:00.0716 2540 TapiSrv (680916bb09ee0f3a6aca7c274b0d633f) C:\Windows\System32\tapisrv.dll
00:13:00.0747 2540 TapiSrv - ok
00:13:00.0763 2540 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
00:13:00.0794 2540 TBS - ok
00:13:00.0919 2540 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys
00:13:01.0012 2540 Tcpip - ok
00:13:01.0043 2540 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys
00:13:01.0168 2540 Tcpip6 - ok
00:13:01.0246 2540 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
00:13:01.0309 2540 tcpipreg - ok
00:13:01.0340 2540 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
00:13:01.0387 2540 TDPIPE - ok
00:13:01.0402 2540 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
00:13:01.0433 2540 TDTCP - ok
00:13:01.0465 2540 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
00:13:01.0496 2540 tdx - ok
00:13:01.0527 2540 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
00:13:01.0543 2540 TermDD - ok
00:13:01.0589 2540 TermService (d605031e225aaccbceb5b76a4f1603a6) C:\Windows\System32\termsrv.dll
00:13:01.0652 2540 TermService - ok
00:13:01.0730 2540 Themes (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\system32\shsvcs.dll
00:13:01.0745 2540 Themes - ok
00:13:01.0777 2540 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
00:13:01.0792 2540 THREADORDER - ok
00:13:01.0839 2540 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
00:13:01.0886 2540 TrkWks - ok
00:13:01.0948 2540 TrustedInstaller (16613a1bad034d4ecf957af18b7c2ff5) C:\Windows\servicing\TrustedInstaller.exe
00:13:01.0995 2540 TrustedInstaller - ok
00:13:02.0026 2540 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
00:13:02.0042 2540 tssecsrv - ok
00:13:02.0089 2540 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
00:13:02.0104 2540 tunmp - ok
00:13:02.0167 2540 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys
00:13:02.0167 2540 tunnel - ok
00:13:02.0198 2540 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
00:13:02.0198 2540 uagp35 - ok
00:13:02.0245 2540 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
00:13:02.0276 2540 udfs - ok
00:13:02.0323 2540 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
00:13:02.0369 2540 UI0Detect - ok
00:13:02.0401 2540 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
00:13:02.0416 2540 uliagpkx - ok
00:13:02.0463 2540 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
00:13:02.0479 2540 uliahci - ok
00:13:02.0510 2540 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
00:13:02.0510 2540 UlSata - ok
00:13:02.0541 2540 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
00:13:02.0557 2540 ulsata2 - ok
00:13:02.0603 2540 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
00:13:02.0635 2540 umbus - ok
00:13:02.0650 2540 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
00:13:02.0681 2540 upnphost - ok
00:13:02.0744 2540 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\Windows\system32\Drivers\usbaapl.sys
00:13:02.0759 2540 USBAAPL - ok
00:13:02.0806 2540 usbccgp (a7cd5b4adea26765cab06bdab7b07b13) C:\Windows\system32\DRIVERS\usbccgp.sys
00:13:02.0837 2540 usbccgp - ok
00:13:02.0853 2540 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
00:13:02.0915 2540 usbcir - ok
00:13:02.0931 2540 usbehci (686d4188ae36254c3008b71fedacadf3) C:\Windows\system32\DRIVERS\usbehci.sys
00:13:02.0962 2540 usbehci - ok
00:13:03.0009 2540 usbhub (4e42f665a658f08d153f7fffe7c83806) C:\Windows\system32\DRIVERS\usbhub.sys
00:13:03.0009 2540 usbhub - ok
00:13:03.0056 2540 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
00:13:03.0103 2540 usbohci - ok
00:13:03.0118 2540 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
00:13:03.0165 2540 usbprint - ok
00:13:03.0227 2540 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:13:03.0243 2540 USBSTOR - ok
00:13:03.0274 2540 usbuhci (40f95a3d6d50d82f947f1d167c2ec39d) C:\Windows\system32\DRIVERS\usbuhci.sys
00:13:03.0305 2540 usbuhci - ok
00:13:03.0337 2540 UxSms (032a0acc3909ae7215d524e29d536797) C:\Windows\System32\uxsms.dll
00:13:03.0368 2540 UxSms - ok
00:13:03.0430 2540 vds (b13bc395b9d6116628f5af47e0802ac4) C:\Windows\System32\vds.exe
00:13:03.0461 2540 vds - ok
00:13:03.0493 2540 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
00:13:03.0539 2540 vga - ok
00:13:03.0555 2540 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
00:13:03.0586 2540 VgaSave - ok
00:13:03.0617 2540 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
00:13:03.0633 2540 viaagp - ok
00:13:03.0664 2540 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
00:13:03.0695 2540 ViaC7 - ok
00:13:03.0711 2540 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
00:13:03.0711 2540 viaide - ok
00:13:03.0742 2540 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
00:13:03.0742 2540 volmgr - ok
00:13:03.0773 2540 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
00:13:03.0789 2540 volmgrx - ok
00:13:03.0836 2540 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
00:13:03.0836 2540 volsnap - ok
00:13:03.0883 2540 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
00:13:03.0898 2540 vsmraid - ok
00:13:04.0007 2540 VSS (d5fb73d19c46ade183f968e13f186b23) C:\Windows\system32\vssvc.exe
00:13:04.0101 2540 VSS - ok
00:13:04.0148 2540 W32Time (1cf9206966a8458cda9a8b20df8ab7d3) C:\Windows\system32\w32time.dll
00:13:04.0179 2540 W32Time - ok
00:13:04.0257 2540 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
00:13:04.0288 2540 WacomPen - ok
00:13:04.0335 2540 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:13:04.0366 2540 Wanarp - ok
00:13:04.0397 2540 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:13:04.0413 2540 Wanarpv6 - ok
00:13:04.0491 2540 wcncsvc (f3a5c2e1a6533192b070d06ecf6be796) C:\Windows\System32\wcncsvc.dll
00:13:04.0507 2540 wcncsvc - ok
00:13:04.0538 2540 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
00:13:04.0569 2540 WcsPlugInService - ok
00:13:04.0585 2540 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
00:13:04.0600 2540 Wd - ok
00:13:04.0663 2540 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
00:13:04.0694 2540 Wdf01000 - ok
00:13:04.0725 2540 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
00:13:04.0756 2540 WdiServiceHost - ok
00:13:04.0787 2540 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
00:13:04.0819 2540 WdiSystemHost - ok
00:13:04.0865 2540 WebClient (cf9a5f41789b642db967021de06a2713) C:\Windows\System32\webclnt.dll
00:13:04.0881 2540 WebClient - ok
00:13:04.0959 2540 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
00:13:04.0975 2540 Wecsvc - ok
00:13:05.0006 2540 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
00:13:05.0053 2540 wercplsupport - ok
00:13:05.0099 2540 WerSvc (fd1965aaa112c6818a30ab02742d0461) C:\Windows\System32\WerSvc.dll
00:13:05.0131 2540 WerSvc - ok
00:13:05.0209 2540 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
00:13:05.0255 2540 winachsf - ok
00:13:05.0365 2540 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
00:13:05.0380 2540 WinDefend - ok
00:13:05.0396 2540 WinHttpAutoProxySvc - ok
00:13:05.0489 2540 Winmgmt (00b79a7c984678f24cf052e5beb3a2f5) C:\Windows\system32\wbem\WMIsvc.dll
00:13:05.0536 2540 Winmgmt - ok
00:13:05.0661 2540 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
00:13:05.0770 2540 WinRM - ok
00:13:05.0879 2540 Wlansvc (275f4346e569df56cfb95243bd6f6ff0) C:\Windows\System32\wlansvc.dll
00:13:05.0926 2540 Wlansvc - ok
00:13:05.0957 2540 wltrysvc - ok
00:13:05.0989 2540 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
00:13:06.0020 2540 WmiAcpi - ok
00:13:06.0082 2540 wmiApSrv (aba4cf9f856d9a3a25f4ddd7690a6e9d) C:\Windows\system32\wbem\WmiApSrv.exe
00:13:06.0129 2540 wmiApSrv - ok
00:13:06.0269 2540 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
00:13:06.0347 2540 WMPNetworkSvc - ok
00:13:06.0410 2540 WPCSvc (5d94cd167751294962ba238d82dd1bb8) C:\Windows\System32\wpcsvc.dll
00:13:06.0457 2540 WPCSvc - ok
00:13:06.0488 2540 WPDBusEnum (396d406292b0cd26e3504ffe82784702) C:\Windows\system32\wpdbusenum.dll
00:13:06.0519 2540 WPDBusEnum - ok
00:13:06.0722 2540 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
00:13:06.0800 2540 WPFFontCache_v0400 - ok
00:13:06.0893 2540 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
00:13:06.0940 2540 ws2ifsl - ok
00:13:06.0971 2540 wscsvc (683dd16b590372f2c9661d277f35e49c) C:\Windows\system32\wscsvc.dll
00:13:07.0003 2540 wscsvc - ok
00:13:07.0003 2540 WSearch - ok
00:13:07.0174 2540 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll
00:13:07.0330 2540 wuauserv - ok
00:13:07.0471 2540 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
00:13:07.0517 2540 WUDFRd - ok
00:13:07.0642 2540 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
00:13:07.0689 2540 wudfsvc - ok
00:13:07.0736 2540 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
00:13:07.0751 2540 XAudio - ok
00:13:07.0783 2540 XAudioService (cd5f291a1161f15896d1a4d63daff5df) C:\Windows\system32\DRIVERS\xaudio.exe
00:13:07.0845 2540 XAudioService - ok
00:13:07.0923 2540 yukonwlh (a4822191c7cea271903c2a4fb6d9809d) C:\Windows\system32\DRIVERS\yk60x86.sys
00:13:07.0954 2540 yukonwlh - ok
00:13:08.0001 2540 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
00:13:08.0453 2540 \Device\Harddisk0\DR0 - ok
00:13:08.0453 2540 MBR (0x1B8) (d4b3987bee0a0394b385becdce0f7f13) \Device\Harddisk1\DR4
00:14:15.0736 2540 \Device\Harddisk1\DR4 - ok
00:14:15.0799 2540 Boot (0x1200) (7d9dfdcdda59e7ed5a422c65a73e16cc) \Device\Harddisk0\DR0\Partition0
00:14:15.0799 2540 \Device\Harddisk0\DR0\Partition0 - ok
00:14:15.0830 2540 Boot (0x1200) (0f827282df3ccceca6e6afd0e2c60d95) \Device\Harddisk0\DR0\Partition1
00:14:15.0830 2540 \Device\Harddisk0\DR0\Partition1 - ok
00:14:15.0845 2540 ============================================================
00:14:15.0845 2540 Scan finished
00:14:15.0845 2540 ============================================================
00:14:15.0861 3588 Detected object count: 2
00:14:15.0861 3588 Actual detected object count: 2
00:15:19.0930 3588 DfsC ( Virus.Win32.ZAccess.c ) - skipped by user
00:15:19.0930 3588 DfsC ( Virus.Win32.ZAccess.c ) - User select action: Skip
00:15:19.0946 3588 enecbpth ( Backdoor.Multi.ZAccess.gen ) - skipped by user
00:15:19.0946 3588 enecbpth ( Backdoor.Multi.ZAccess.gen ) - User select action: Skip
Naposledy upravil(a) Leba dne 23 kvě 2012 23:17, celkem upraveno 1 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#6 Příspěvek od vyosek »

Super, hura do TDSSKilleru
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#7 Příspěvek od vyosek »

Priste prosim needitujte, ja si toho nemusim vsimnou, nota bene kdyz jsme oba online...

Spustte znovu TDSSKiller a nechte na nalezech predvolene moznosti co budou = nic nemente..probehne zrejme restart a pak bude nasledovat log, ten sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

Re: setup.exe - Vista

#8 Příspěvek od Leba »

Log zde

00:27:16.0041 2792 TDSS rootkit removing tool 2.7.37.0 May 23 2012 08:15:30
00:27:16.0057 2792 ============================================================
00:27:16.0057 2792 Current date / time: 2012/05/24 00:27:16.0057
00:27:16.0057 2792 SystemInfo:
00:27:16.0057 2792
00:27:16.0057 2792 OS Version: 6.0.6001 ServicePack: 1.0
00:27:16.0057 2792 Product type: Workstation
00:27:16.0057 2792 ComputerName: ROBO-PC
00:27:16.0057 2792 UserName: Robo
00:27:16.0057 2792 Windows directory: C:\Windows
00:27:16.0057 2792 System windows directory: C:\Windows
00:27:16.0057 2792 Processor architecture: Intel x86
00:27:16.0057 2792 Number of processors: 2
00:27:16.0057 2792 Page size: 0x1000
00:27:16.0057 2792 Boot type: Normal boot
00:27:16.0057 2792 ============================================================
00:27:16.0493 2792 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:27:16.0509 2792 Drive \Device\Harddisk1\DR1 - Size: 0x1E1509000 (7.52 Gb), SectorSize: 0x200, Cylinders: 0x3D5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
00:27:16.0509 2792 ============================================================
00:27:16.0509 2792 \Device\Harddisk0\DR0:
00:27:16.0509 2792 MBR partitions:
00:27:16.0509 2792 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x33000, BlocksNum 0x1400000
00:27:16.0509 2792 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1433000, BlocksNum 0x23AFAFF8
00:27:16.0540 2792 \Device\Harddisk1\DR1:
00:27:16.0540 2792 MBR partitions:
00:27:16.0540 2792 ============================================================
00:27:16.0587 2792 C: <-> \Device\Harddisk0\DR0\Partition1
00:27:16.0681 2792 D: <-> \Device\Harddisk0\DR0\Partition0
00:27:16.0681 2792 ============================================================
00:27:16.0681 2792 Initialize success
00:27:16.0681 2792 ============================================================
00:27:23.0919 2308 ============================================================
00:27:23.0919 2308 Scan started
00:27:23.0919 2308 Mode: Manual; SigCheck; TDLFS;
00:27:23.0919 2308 ============================================================
00:27:24.0793 2308 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
00:27:24.0917 2308 ACPI - ok
00:27:25.0011 2308 Scan interrupted by user!
00:27:25.0011 2308 Scan interrupted by user!
00:27:25.0011 2308 Scan interrupted by user!
00:27:25.0011 2308 ============================================================
00:27:25.0011 2308 Scan finished
00:27:25.0011 2308 ============================================================
00:27:25.0011 3824 Detected object count: 0
00:27:25.0011 3824 Actual detected object count: 0
00:27:28.0989 3492 ============================================================
00:27:28.0989 3492 Scan started
00:27:28.0989 3492 Mode: Manual; SigCheck; TDLFS;
00:27:28.0989 3492 ============================================================
00:27:29.0129 3492 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
00:27:29.0161 3492 ACPI - ok
00:27:29.0317 3492 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:27:29.0332 3492 AdobeFlashPlayerUpdateSvc - ok
00:27:29.0395 3492 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
00:27:29.0410 3492 adp94xx - ok
00:27:29.0457 3492 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
00:27:29.0473 3492 adpahci - ok
00:27:29.0504 3492 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
00:27:29.0504 3492 adpu160m - ok
00:27:29.0535 3492 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
00:27:29.0551 3492 adpu320 - ok
00:27:29.0582 3492 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
00:27:29.0629 3492 AeLookupSvc - ok
00:27:29.0675 3492 AESTFilters (ef1142512bec12f1c2c87735da1755be) C:\Windows\system32\aestsrv.exe
00:27:29.0707 3492 AESTFilters - ok
00:27:29.0941 3492 AFD (48eb99503533c27ac6135648e5474457) C:\Windows\system32\drivers\afd.sys
00:27:30.0003 3492 AFD - ok
00:27:30.0065 3492 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
00:27:30.0065 3492 agp440 - ok
00:27:30.0112 3492 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
00:27:30.0128 3492 aic78xx - ok
00:27:30.0175 3492 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
00:27:30.0268 3492 ALG - ok
00:27:30.0315 3492 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
00:27:30.0331 3492 aliide - ok
00:27:30.0362 3492 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
00:27:30.0377 3492 amdagp - ok
00:27:30.0409 3492 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
00:27:30.0424 3492 amdide - ok
00:27:30.0455 3492 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
00:27:30.0518 3492 AmdK7 - ok
00:27:30.0549 3492 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
00:27:30.0643 3492 AmdK8 - ok
00:27:30.0736 3492 AMService - ok
00:27:30.0799 3492 ApfiltrService (a80230bd04f0b8bf05185b369bb1cbb8) C:\Windows\system32\DRIVERS\Apfiltr.sys
00:27:30.0830 3492 ApfiltrService - ok
00:27:30.0861 3492 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
00:27:30.0923 3492 Appinfo - ok
00:27:31.0064 3492 Apple Mobile Device (4b5ae15e5c73eb4dc8dbec2788230d41) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
00:27:31.0064 3492 Apple Mobile Device - ok
00:27:31.0142 3492 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
00:27:31.0157 3492 arc - ok
00:27:31.0220 3492 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
00:27:31.0220 3492 arcsas - ok
00:27:31.0267 3492 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
00:27:31.0329 3492 AsyncMac - ok
00:27:31.0345 3492 atapi (0d83c87a801a3dfcd1bf73893fe7518c) C:\Windows\system32\drivers\atapi.sys
00:27:31.0360 3492 atapi - ok
00:27:31.0423 3492 AudioEndpointBuilder (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
00:27:31.0454 3492 AudioEndpointBuilder - ok
00:27:31.0454 3492 Audiosrv (42076e29aafa0830a2c5d4e310f58dd1) C:\Windows\System32\Audiosrv.dll
00:27:31.0485 3492 Audiosrv - ok
00:27:31.0532 3492 BCM42RLY (7bd70aeed0d975285a1b20bd012ebf4e) C:\Windows\system32\drivers\BCM42RLY.sys
00:27:31.0532 3492 BCM42RLY - ok
00:27:31.0641 3492 BCM43XX (fa6707a346cd122407f3b0bad1c47639) C:\Windows\system32\DRIVERS\bcmwl6.sys
00:27:31.0719 3492 BCM43XX - ok
00:27:31.0781 3492 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
00:27:31.0859 3492 Beep - ok
00:27:31.0969 3492 BITS (02ed7b4dbc2a3232a389106da7515c3d) C:\Windows\System32\qmgr.dll
00:27:32.0015 3492 BITS - ok
00:27:32.0047 3492 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
00:27:32.0093 3492 blbdrive - ok
00:27:32.0187 3492 Bonjour Service (3f56903e124e820aeece6d471583c6c1) C:\Program Files\Bonjour\mDNSResponder.exe
00:27:32.0203 3492 Bonjour Service - ok
00:27:32.0343 3492 bowser (8153396d5551276227fa146900f734e6) C:\Windows\system32\DRIVERS\bowser.sys
00:27:32.0437 3492 bowser - ok
00:27:32.0468 3492 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
00:27:32.0515 3492 BrFiltLo - ok
00:27:32.0530 3492 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
00:27:32.0608 3492 BrFiltUp - ok
00:27:32.0655 3492 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
00:27:32.0686 3492 Browser - ok
00:27:32.0733 3492 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
00:27:32.0811 3492 Brserid - ok
00:27:32.0842 3492 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
00:27:32.0905 3492 BrSerWdm - ok
00:27:32.0920 3492 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
00:27:32.0998 3492 BrUsbMdm - ok
00:27:33.0014 3492 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
00:27:33.0107 3492 BrUsbSer - ok
00:27:33.0154 3492 BthEnum (e5145a9dec2a863de262d40eff7d793a) C:\Windows\system32\DRIVERS\BthEnum.sys
00:27:33.0170 3492 BthEnum - ok
00:27:33.0248 3492 BTHMODEM (5ffa6988ff9597986ff2ada736cc90c0) C:\Windows\system32\DRIVERS\bthmodem.sys
00:27:33.0310 3492 BTHMODEM - ok
00:27:33.0341 3492 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
00:27:33.0373 3492 BthPan - ok
00:27:33.0404 3492 BTHPORT (9f299c5274672900591e7c616d725f56) C:\Windows\system32\Drivers\BTHport.sys
00:27:33.0435 3492 BTHPORT - ok
00:27:33.0482 3492 BthServ (58ee7f5e68310bc8d4e7cebd8358c12e) C:\Windows\System32\bthserv.dll
00:27:33.0529 3492 BthServ - ok
00:27:33.0560 3492 BTHUSB (31c9453df130b4b89eafcdc97319ccc2) C:\Windows\system32\Drivers\BTHUSB.sys
00:27:33.0591 3492 BTHUSB - ok
00:27:33.0638 3492 btwaudio (4a28e7bd365377d0512b7ef8c7596d2c) C:\Windows\system32\drivers\btwaudio.sys
00:27:33.0653 3492 btwaudio - ok
00:27:33.0700 3492 btwavdt (5ffde57253d665067b0886612817eb11) C:\Windows\system32\drivers\btwavdt.sys
00:27:33.0716 3492 btwavdt - ok
00:27:33.0731 3492 btwrchid (ab07dc8b05c31a4f95fc73019be9db15) C:\Windows\system32\DRIVERS\btwrchid.sys
00:27:33.0747 3492 btwrchid - ok
00:27:33.0841 3492 catchme - ok
00:27:33.0903 3492 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
00:27:33.0950 3492 cdfs - ok
00:27:33.0997 3492 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
00:27:34.0043 3492 cdrom - ok
00:27:34.0075 3492 CertPropSvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
00:27:34.0137 3492 CertPropSvc - ok
00:27:34.0168 3492 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
00:27:34.0199 3492 circlass - ok
00:27:34.0231 3492 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
00:27:34.0246 3492 CLFS - ok
00:27:34.0340 3492 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:27:34.0355 3492 clr_optimization_v2.0.50727_32 - ok
00:27:34.0480 3492 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:27:34.0480 3492 clr_optimization_v4.0.30319_32 - ok
00:27:34.0511 3492 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
00:27:34.0543 3492 CmBatt - ok
00:27:34.0574 3492 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
00:27:34.0574 3492 cmdide - ok
00:27:34.0589 3492 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
00:27:34.0605 3492 Compbatt - ok
00:27:34.0605 3492 COMSysApp - ok
00:27:34.0621 3492 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
00:27:34.0621 3492 crcdisk - ok
00:27:34.0683 3492 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
00:27:34.0745 3492 Crusoe - ok
00:27:34.0792 3492 CryptSvc (6de363f9f99334514c46aec02d3e3678) C:\Windows\system32\cryptsvc.dll
00:27:34.0855 3492 CryptSvc - ok
00:27:34.0933 3492 DcomLaunch (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
00:27:35.0042 3492 DcomLaunch - ok
00:27:35.0120 3492 DfsC (a3e9fa213f443ac77c7746119d13feec) C:\Windows\system32\Drivers\dfsc.sys
00:27:35.0182 3492 DfsC - ok
00:27:35.0728 3492 DFSR (fa3463f25f9cc9c3bcf1e7912feff099) C:\Windows\system32\DFSR.exe
00:27:35.0884 3492 DFSR - ok
00:27:36.0040 3492 Dhcp (43a988a9c10333476cb5fb667cbd629d) C:\Windows\System32\dhcpcsvc.dll
00:27:36.0071 3492 Dhcp - ok
00:27:36.0134 3492 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
00:27:36.0149 3492 disk - ok
00:27:36.0196 3492 Dnscache (4805d9a6d281c7a7defd9094dec6af7d) C:\Windows\System32\dnsrslvr.dll
00:27:36.0274 3492 Dnscache - ok
00:27:36.0305 3492 dot3svc (5af620a08c614e24206b79e8153cf1a8) C:\Windows\System32\dot3svc.dll
00:27:36.0352 3492 dot3svc - ok
00:27:36.0383 3492 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
00:27:36.0430 3492 DPS - ok
00:27:36.0461 3492 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
00:27:36.0477 3492 drmkaud - ok
00:27:36.0602 3492 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
00:27:36.0664 3492 DXGKrnl - ok
00:27:36.0711 3492 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
00:27:36.0805 3492 e1express - ok
00:27:36.0851 3492 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
00:27:36.0914 3492 E1G60 - ok
00:27:36.0961 3492 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
00:27:36.0976 3492 EapHost - ok
00:27:37.0023 3492 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
00:27:37.0023 3492 Ecache - ok
00:27:37.0085 3492 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
00:27:37.0148 3492 ehRecvr - ok
00:27:37.0163 3492 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
00:27:37.0195 3492 ehSched - ok
00:27:37.0210 3492 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
00:27:37.0226 3492 ehstart - ok
00:27:37.0273 3492 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
00:27:37.0288 3492 elxstor - ok
00:27:37.0366 3492 EMDMgmt (70b1a86df0c8ead17d2bc332edae2c7c) C:\Windows\system32\emdmgmt.dll
00:27:37.0475 3492 EMDMgmt - ok
00:27:37.0491 3492 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
00:27:37.0522 3492 ErrDev - ok
00:27:37.0585 3492 EventSystem (3cb3343d720168b575133a0a20dc2465) C:\Windows\system32\es.dll
00:27:37.0631 3492 EventSystem - ok
00:27:37.0694 3492 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
00:27:37.0741 3492 exfat - ok
00:27:37.0803 3492 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
00:27:37.0819 3492 fastfat - ok
00:27:37.0850 3492 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
00:27:37.0897 3492 fdc - ok
00:27:37.0928 3492 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
00:27:37.0990 3492 fdPHost - ok
00:27:38.0021 3492 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
00:27:38.0084 3492 FDResPub - ok
00:27:38.0287 3492 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
00:27:38.0287 3492 FileInfo - ok
00:27:38.0474 3492 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
00:27:38.0521 3492 Filetrace - ok
00:27:38.0630 3492 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
00:27:38.0817 3492 flpydisk - ok
00:27:38.0864 3492 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
00:27:38.0879 3492 FltMgr - ok
00:27:39.0051 3492 FontCache3.0.0.0 (c9be08664611ddaf98e2331e9288b00b) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
00:27:39.0051 3492 FontCache3.0.0.0 - ok
00:27:39.0129 3492 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
00:27:39.0176 3492 Fs_Rec - ok
00:27:39.0191 3492 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
00:27:39.0207 3492 gagp30kx - ok
00:27:39.0285 3492 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:27:39.0301 3492 GEARAspiWDM - ok
00:27:39.0410 3492 gpsvc (d9f1113d9401185245573350712f92fc) C:\Windows\System32\gpsvc.dll
00:27:39.0535 3492 gpsvc - ok
00:27:40.0315 3492 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
00:27:41.0422 3492 gupdate - ok
00:27:41.0843 3492 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
00:27:41.0859 3492 gupdatem - ok
00:27:42.0062 3492 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
00:27:42.0124 3492 gusvc - ok
00:27:42.0171 3492 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
00:27:42.0249 3492 HDAudBus - ok
00:27:42.0374 3492 HidBth (204c3b1846e9cbaaef88b8e1f86782f8) C:\Windows\system32\DRIVERS\hidbth.sys
00:27:42.0452 3492 HidBth - ok
00:27:42.0483 3492 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
00:27:42.0577 3492 HidIr - ok
00:27:42.0623 3492 hidserv (53d5a2f9ce6ae47d7507727df1da79f8) C:\Windows\System32\hidserv.dll
00:27:42.0686 3492 hidserv - ok
00:27:42.0764 3492 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
00:27:42.0873 3492 HidUsb - ok
00:27:42.0889 3492 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
00:27:42.0967 3492 hkmsvc - ok
00:27:43.0107 3492 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
00:27:43.0123 3492 HpCISSs - ok
00:27:43.0294 3492 HSF_DPV (99f85640054ba65190b860d878a7c9ae) C:\Windows\system32\DRIVERS\HSX_DPV.sys
00:27:43.0388 3492 HSF_DPV - ok
00:27:43.0466 3492 HSXHWAZL (cfbc2b81972e298f0e19ee68fa9e73da) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
00:27:43.0481 3492 HSXHWAZL - ok
00:27:43.0778 3492 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
00:27:43.0871 3492 HTTP - ok
00:27:43.0918 3492 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
00:27:43.0918 3492 i2omp - ok
00:27:43.0996 3492 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
00:27:44.0012 3492 i8042prt - ok
00:27:44.0168 3492 IAANTMON (ae38a12f79a4980ddb88f36514f8a1da) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
00:27:44.0199 3492 IAANTMON - ok
00:27:44.0293 3492 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\Windows\system32\drivers\iastor.sys
00:27:44.0308 3492 iaStor - ok
00:27:44.0386 3492 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
00:27:44.0464 3492 iaStorV - ok
00:27:44.0558 3492 ICQ Service (a4e43a7ab1202356bebeb6b798f15488) C:\Program Files\ICQ6Toolbar\ICQ Service.exe
00:27:44.0573 3492 ICQ Service - ok
00:27:44.0714 3492 idsvc (7b630acaed64fef0c3e1cf255cb56686) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:27:44.0776 3492 idsvc - ok
00:27:45.0416 3492 igfx (c134e69ce901422d1f2d7ea8d69098fe) C:\Windows\system32\DRIVERS\igdkmd32.sys
00:27:45.0587 3492 igfx - ok
00:27:45.0743 3492 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
00:27:45.0759 3492 iirsp - ok
00:27:45.0837 3492 IKEEXT (a3bc480a2bf8aa8e4dabd2d5dce0afac) C:\Windows\System32\ikeext.dll
00:27:45.0899 3492 IKEEXT - ok
00:27:45.0962 3492 IntcHdmiAddService (98d303ccb3415e9202e82043b37d66dc) C:\Windows\system32\drivers\IntcHdmi.sys
00:27:46.0024 3492 IntcHdmiAddService - ok
00:27:46.0055 3492 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\DRIVERS\intelide.sys
00:27:46.0055 3492 intelide - ok
00:27:46.0087 3492 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
00:27:46.0133 3492 intelppm - ok
00:27:46.0180 3492 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
00:27:46.0211 3492 IPBusEnum - ok
00:27:46.0227 3492 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:27:46.0274 3492 IpFilterDriver - ok
00:27:46.0367 3492 iphlpsvc (6a35d233693edc29a12742049bc5e37f) C:\Windows\System32\iphlpsvc.dll
00:27:46.0461 3492 iphlpsvc - ok
00:27:46.0461 3492 IpInIp - ok
00:27:46.0523 3492 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
00:27:46.0570 3492 IPMIDRV - ok
00:27:46.0586 3492 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
00:27:46.0664 3492 IPNAT - ok
00:27:46.0851 3492 iPod Service (dc434081fbfd27c719473cb0cce8deca) C:\Program Files\iPod\bin\iPodService.exe
00:27:46.0929 3492 iPod Service - ok
00:27:46.0960 3492 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
00:27:47.0023 3492 IRENUM - ok
00:27:47.0054 3492 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
00:27:47.0069 3492 isapnp - ok
00:27:47.0132 3492 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
00:27:47.0147 3492 iScsiPrt - ok
00:27:47.0179 3492 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
00:27:47.0194 3492 iteatapi - ok
00:27:47.0241 3492 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
00:27:47.0241 3492 iteraid - ok
00:27:47.0257 3492 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
00:27:47.0272 3492 kbdclass - ok
00:27:47.0335 3492 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
00:27:47.0381 3492 kbdhid - ok
00:27:47.0413 3492 KeyIso (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:27:47.0491 3492 KeyIso - ok
00:27:47.0537 3492 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
00:27:47.0569 3492 KSecDD - ok
00:27:47.0631 3492 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
00:27:47.0693 3492 KtmRm - ok
00:27:47.0756 3492 LanmanServer (1925e63c91cf1610ae41bfd539062079) C:\Windows\System32\srvsvc.dll
00:27:47.0834 3492 LanmanServer - ok
00:27:47.0912 3492 LanmanWorkstation (2ae2e1628c5d3f1c0a46a67c9fa1df15) C:\Windows\System32\wkssvc.dll
00:27:47.0990 3492 LanmanWorkstation - ok
00:27:48.0037 3492 LHidFilt (597d79382c154cedb638a65012925a23) C:\Windows\system32\DRIVERS\LHidFilt.Sys
00:27:48.0037 3492 LHidFilt - ok
00:27:48.0083 3492 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
00:27:48.0115 3492 lltdio - ok
00:27:48.0161 3492 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
00:27:48.0224 3492 lltdsvc - ok
00:27:48.0317 3492 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
00:27:48.0364 3492 lmhosts - ok
00:27:48.0411 3492 LMouFilt (9ead053d28182bd6acb19d5f58202194) C:\Windows\system32\DRIVERS\LMouFilt.Sys
00:27:48.0411 3492 LMouFilt - ok
00:27:48.0442 3492 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
00:27:48.0458 3492 LSI_FC - ok
00:27:48.0520 3492 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
00:27:48.0536 3492 LSI_SAS - ok
00:27:48.0598 3492 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
00:27:48.0598 3492 LSI_SCSI - ok
00:27:48.0645 3492 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
00:27:48.0676 3492 luafv - ok
00:27:48.0723 3492 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
00:27:48.0754 3492 Mcx2Svc - ok
00:27:48.0785 3492 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
00:27:48.0832 3492 mdmxsdk - ok
00:27:48.0879 3492 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
00:27:48.0879 3492 megasas - ok
00:27:48.0941 3492 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
00:27:49.0004 3492 MegaSR - ok
00:27:49.0238 3492 Microsoft Office Groove Audit Service (fafe367d032ed82e9332b4c741a20216) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
00:27:49.0253 3492 Microsoft Office Groove Audit Service - ok
00:27:49.0300 3492 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
00:27:49.0331 3492 MMCSS - ok
00:27:49.0378 3492 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
00:27:49.0425 3492 Modem - ok
00:27:49.0472 3492 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
00:27:49.0503 3492 monitor - ok
00:27:49.0534 3492 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
00:27:49.0534 3492 mouclass - ok
00:27:49.0597 3492 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
00:27:49.0643 3492 mouhid - ok
00:27:49.0675 3492 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
00:27:49.0690 3492 MountMgr - ok
00:27:49.0721 3492 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
00:27:49.0737 3492 mpio - ok
00:27:49.0768 3492 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
00:27:49.0799 3492 mpsdrv - ok
00:27:49.0815 3492 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
00:27:49.0815 3492 Mraid35x - ok
00:27:49.0831 3492 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
00:27:49.0846 3492 MRxDAV - ok
00:27:49.0909 3492 mrxsmb (5734a0f2be7e495f7d3ed6efd4b9f5a1) C:\Windows\system32\DRIVERS\mrxsmb.sys
00:27:49.0971 3492 mrxsmb - ok
00:27:50.0018 3492 mrxsmb10 (6b5fa5adfacac9dbbe0991f4566d7d55) C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:27:50.0065 3492 mrxsmb10 - ok
00:27:50.0111 3492 mrxsmb20 (5c80d8159181c7abf1b14ba703b01e0b) C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:27:50.0143 3492 mrxsmb20 - ok
00:27:50.0174 3492 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
00:27:50.0174 3492 msahci - ok
00:27:50.0205 3492 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
00:27:50.0205 3492 msdsm - ok
00:27:50.0252 3492 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
00:27:50.0299 3492 MSDTC - ok
00:27:50.0330 3492 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
00:27:50.0392 3492 Msfs - ok
00:27:50.0423 3492 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
00:27:50.0423 3492 msisadrv - ok
00:27:50.0470 3492 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
00:27:50.0517 3492 MSiSCSI - ok
00:27:50.0517 3492 msiserver - ok
00:27:50.0564 3492 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
00:27:50.0611 3492 MSKSSRV - ok
00:27:50.0642 3492 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
00:27:50.0657 3492 MSPCLOCK - ok
00:27:50.0673 3492 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
00:27:50.0704 3492 MSPQM - ok
00:27:50.0751 3492 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
00:27:50.0767 3492 MsRPC - ok
00:27:50.0798 3492 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
00:27:50.0798 3492 mssmbios - ok
00:27:50.0829 3492 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
00:27:50.0845 3492 MSTEE - ok
00:27:50.0876 3492 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
00:27:50.0891 3492 Mup - ok
00:27:50.0938 3492 napagent (c43b25863fbd65b6d2a142af3ae320ca) C:\Windows\system32\qagentRT.dll
00:27:50.0969 3492 napagent - ok
00:27:51.0016 3492 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
00:27:51.0047 3492 NativeWifiP - ok
00:27:51.0110 3492 NDIS (c8560010a542b5dca94c62468dc20784) C:\Windows\system32\drivers\ndis.sys
00:27:51.0141 3492 NDIS - ok
00:27:51.0235 3492 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
00:27:51.0266 3492 NdisTapi - ok
00:27:51.0281 3492 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
00:27:51.0375 3492 Ndisuio - ok
00:27:51.0406 3492 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
00:27:51.0469 3492 NdisWan - ok
00:27:51.0484 3492 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
00:27:51.0562 3492 NDProxy - ok
00:27:51.0593 3492 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
00:27:51.0625 3492 NetBIOS - ok
00:27:51.0859 3492 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
00:27:51.0921 3492 netbt - ok
00:27:51.0983 3492 Netlogon (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:27:51.0999 3492 Netlogon - ok
00:27:52.0077 3492 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
00:27:52.0171 3492 Netman - ok
00:27:52.0202 3492 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
00:27:52.0280 3492 netprofm - ok
00:27:52.0327 3492 NetTcpPortSharing (0ad5876ef4e9eb77c8f93eb5b2fff386) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:27:52.0342 3492 NetTcpPortSharing - ok
00:27:52.0389 3492 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
00:27:52.0405 3492 nfrd960 - ok
00:27:52.0451 3492 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
00:27:52.0514 3492 NlaSvc - ok
00:27:52.0545 3492 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
00:27:52.0561 3492 Npfs - ok
00:27:52.0576 3492 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
00:27:52.0623 3492 nsi - ok
00:27:52.0639 3492 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
00:27:52.0685 3492 nsiproxy - ok
00:27:52.0779 3492 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
00:27:52.0935 3492 Ntfs - ok
00:27:52.0966 3492 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
00:27:53.0044 3492 ntrigdigi - ok
00:27:53.0044 3492 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
00:27:53.0107 3492 Null - ok
00:27:53.0169 3492 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
00:27:53.0169 3492 nvraid - ok
00:27:53.0216 3492 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
00:27:53.0216 3492 nvstor - ok
00:27:53.0247 3492 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
00:27:53.0263 3492 nv_agp - ok
00:27:53.0263 3492 NwlnkFlt - ok
00:27:53.0278 3492 NwlnkFwd - ok
00:27:53.0450 3492 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
00:27:53.0512 3492 odserv - ok
00:27:53.0559 3492 OEM02Dev (19cac780b858822055f46c58a111723c) C:\Windows\system32\DRIVERS\OEM02Dev.sys
00:27:53.0653 3492 OEM02Dev - ok
00:27:53.0684 3492 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\Windows\system32\DRIVERS\OEM02Vfx.sys
00:27:53.0699 3492 OEM02Vfx - ok
00:27:53.0731 3492 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
00:27:53.0762 3492 ohci1394 - ok
00:27:53.0809 3492 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:27:53.0855 3492 ose - ok
00:27:53.0980 3492 p2pimsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:27:54.0105 3492 p2pimsvc - ok
00:27:54.0121 3492 p2psvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:27:54.0152 3492 p2psvc - ok
00:27:54.0199 3492 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
00:27:54.0308 3492 Parport - ok
00:27:54.0355 3492 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
00:27:54.0370 3492 partmgr - ok
00:27:54.0401 3492 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
00:27:54.0464 3492 Parvdm - ok
00:27:54.0495 3492 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
00:27:54.0557 3492 PcaSvc - ok
00:27:54.0589 3492 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
00:27:54.0620 3492 pci - ok
00:27:54.0651 3492 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
00:27:54.0651 3492 pciide - ok
00:27:54.0682 3492 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
00:27:54.0713 3492 pcmcia - ok
00:27:54.0823 3492 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
00:27:54.0979 3492 PEAUTH - ok
00:27:55.0228 3492 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
00:27:55.0369 3492 pla - ok
00:27:55.0587 3492 PlugPlay (78f975cb6d18265be6f492edb2d7bc7b) C:\Windows\system32\umpnpmgr.dll
00:27:55.0681 3492 PlugPlay - ok
00:27:55.0759 3492 PNRPAutoReg (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:27:55.0774 3492 PNRPAutoReg - ok
00:27:55.0790 3492 PNRPsvc (5de1a3972fd3112c75eb17bdcf454169) C:\Windows\system32\p2psvc.dll
00:27:55.0805 3492 PNRPsvc - ok
00:27:55.0868 3492 PolicyAgent (47b8f37aa18b74d8c2e1bc1a7a2c8f8a) C:\Windows\System32\ipsecsvc.dll
00:27:55.0977 3492 PolicyAgent - ok
00:27:56.0071 3492 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
00:27:56.0133 3492 PptpMiniport - ok
00:27:56.0164 3492 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
00:27:56.0227 3492 Processor - ok
00:27:56.0320 3492 ProfSvc (b627e4fc8585e8843c5905d4d3587a90) C:\Windows\system32\profsvc.dll
00:27:56.0383 3492 ProfSvc - ok
00:27:56.0445 3492 ProtectedStorage (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:27:56.0461 3492 ProtectedStorage - ok
00:27:56.0476 3492 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
00:27:56.0523 3492 PSched - ok
00:27:56.0617 3492 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys
00:27:56.0632 3492 PxHelp20 - ok
00:27:56.0773 3492 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
00:27:56.0913 3492 ql2300 - ok
00:27:56.0960 3492 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
00:27:56.0975 3492 ql40xx - ok
00:27:57.0022 3492 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
00:27:57.0053 3492 QWAVE - ok
00:27:57.0053 3492 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
00:27:57.0069 3492 QWAVEdrv - ok
00:27:57.0272 3492 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
00:27:57.0459 3492 R300 - ok
00:27:57.0646 3492 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
00:27:57.0677 3492 RasAcd - ok
00:27:57.0709 3492 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
00:27:57.0755 3492 RasAuto - ok
00:27:57.0771 3492 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
00:27:57.0802 3492 Rasl2tp - ok
00:27:57.0865 3492 RasMan (6e7c284fc5c4ec07ad164d93810385a6) C:\Windows\System32\rasmans.dll
00:27:57.0943 3492 RasMan - ok
00:27:57.0974 3492 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
00:27:58.0036 3492 RasPppoe - ok
00:27:58.0067 3492 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
00:27:58.0083 3492 RasSstp - ok
00:27:58.0114 3492 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
00:27:58.0177 3492 rdbss - ok
00:27:58.0192 3492 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
00:27:58.0239 3492 RDPCDD - ok
00:27:58.0504 3492 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
00:27:58.0551 3492 rdpdr - ok
00:27:58.0567 3492 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
00:27:58.0613 3492 RDPENCDD - ok
00:27:58.0676 3492 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
00:27:58.0723 3492 RDPWD - ok
00:27:58.0754 3492 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
00:27:58.0816 3492 RemoteAccess - ok
00:27:58.0847 3492 RemoteRegistry (cc4e32400f3c7253400cf8f3f3a0b676) C:\Windows\system32\regsvc.dll
00:27:58.0863 3492 RemoteRegistry - ok
00:27:58.0910 3492 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys
00:27:58.0925 3492 RFCOMM - ok
00:27:58.0972 3492 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
00:27:59.0003 3492 rimmptsk - ok
00:27:59.0035 3492 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
00:27:59.0050 3492 rimsptsk - ok
00:27:59.0050 3492 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
00:27:59.0081 3492 rismxdp - ok
00:27:59.0113 3492 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
00:27:59.0144 3492 RpcLocator - ok
00:27:59.0237 3492 RpcSs (301ae00e12408650baddc04dbc832830) C:\Windows\system32\rpcss.dll
00:27:59.0269 3492 RpcSs - ok
00:27:59.0331 3492 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
00:27:59.0393 3492 rspndr - ok
00:27:59.0440 3492 SamSs (a911ecac81f94adeafbe8e3f7873edb0) C:\Windows\system32\lsass.exe
00:27:59.0471 3492 SamSs - ok
00:27:59.0612 3492 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
00:27:59.0627 3492 sbp2port - ok
00:27:59.0674 3492 SCardSvr (11387e32642269c7e62e8b52c060b3c6) C:\Windows\System32\SCardSvr.dll
00:27:59.0721 3492 SCardSvr - ok
00:27:59.0861 3492 Schedule (7b587b8a6d4a99f79d2902d0385f29bd) C:\Windows\system32\schedsvc.dll
00:27:59.0971 3492 Schedule - ok
00:28:00.0002 3492 SCPolicySvc (87c2d0377b23e2d8a41093c2f5fb1a5b) C:\Windows\System32\certprop.dll
00:28:00.0033 3492 SCPolicySvc - ok
00:28:00.0189 3492 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
00:28:00.0251 3492 sdbus - ok
00:28:00.0283 3492 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
00:28:00.0329 3492 SDRSVC - ok
00:28:00.0329 3492 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
00:28:00.0392 3492 secdrv - ok
00:28:00.0407 3492 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
00:28:00.0454 3492 seclogon - ok
00:28:00.0470 3492 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
00:28:00.0517 3492 SENS - ok
00:28:00.0563 3492 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
00:28:00.0626 3492 Serenum - ok
00:28:00.0657 3492 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
00:28:00.0704 3492 Serial - ok
00:28:00.0719 3492 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
00:28:00.0751 3492 sermouse - ok
00:28:00.0797 3492 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
00:28:00.0829 3492 SessionEnv - ok
00:28:00.0844 3492 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
00:28:00.0891 3492 sffdisk - ok
00:28:00.0938 3492 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
00:28:00.0953 3492 sffp_mmc - ok
00:28:00.0969 3492 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\DRIVERS\sffp_sd.sys
00:28:01.0016 3492 sffp_sd - ok
00:28:01.0031 3492 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
00:28:01.0094 3492 sfloppy - ok
00:28:01.0141 3492 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
00:28:01.0187 3492 SharedAccess - ok
00:28:01.0265 3492 ShellHWDetection (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\System32\shsvcs.dll
00:28:01.0312 3492 ShellHWDetection - ok
00:28:01.0343 3492 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
00:28:01.0359 3492 sisagp - ok
00:28:01.0375 3492 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
00:28:01.0375 3492 SiSRaid2 - ok
00:28:01.0406 3492 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
00:28:01.0421 3492 SiSRaid4 - ok
00:28:01.0749 3492 slsvc (0ba91e1358ad25236863039bb2609a2e) C:\Windows\system32\SLsvc.exe
00:28:01.0967 3492 slsvc - ok
00:28:02.0186 3492 SLUINotify (7c6dc44ca0bfa6291629ab764200d1d4) C:\Windows\system32\SLUINotify.dll
00:28:02.0217 3492 SLUINotify - ok
00:28:02.0311 3492 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
00:28:02.0357 3492 Smb - ok
00:28:02.0373 3492 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
00:28:02.0404 3492 SNMPTRAP - ok
00:28:02.0404 3492 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
00:28:02.0420 3492 spldr - ok
00:28:02.0482 3492 Spooler (3665f79026a3f91fbca63f2c65a09b19) C:\Windows\System32\spoolsv.exe
00:28:02.0545 3492 Spooler - ok
00:28:02.0623 3492 srv (2252aef839b1093d16761189f45af885) C:\Windows\system32\DRIVERS\srv.sys
00:28:02.0701 3492 srv - ok
00:28:02.0747 3492 srv2 (b7ff59408034119476b00a81bb53d5d1) C:\Windows\system32\DRIVERS\srv2.sys
00:28:02.0825 3492 srv2 - ok
00:28:02.0903 3492 srvnet (2accc9b12af02030f531e6cca6f8b76e) C:\Windows\system32\DRIVERS\srvnet.sys
00:28:02.0981 3492 srvnet - ok
00:28:03.0059 3492 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
00:28:03.0122 3492 SSDPSRV - ok
00:28:03.0169 3492 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
00:28:03.0247 3492 SstpSvc - ok
00:28:03.0278 3492 STacSV (7e6dd4b34acd36af6c711d2bde91b040) C:\Windows\system32\STacSV.exe
00:28:03.0309 3492 STacSV - ok
00:28:03.0356 3492 STHDA (6a2a5e809c2c0178326d92b19ee4aad3) C:\Windows\system32\drivers\stwrt.sys
00:28:03.0434 3492 STHDA - ok
00:28:03.0496 3492 stisvc (7dd08a597bc56051f320da0baf69e389) C:\Windows\System32\wiaservc.dll
00:28:03.0543 3492 stisvc - ok
00:28:03.0668 3492 stllssvr (1d0063597c3666404fcf97698abeb019) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
00:28:03.0668 3492 stllssvr - ok
00:28:03.0699 3492 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
00:28:03.0715 3492 swenum - ok
00:28:03.0808 3492 swprv (b36c7cdb86f7f7a8e884479219766950) C:\Windows\System32\swprv.dll
00:28:03.0871 3492 swprv - ok
00:28:03.0902 3492 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
00:28:03.0917 3492 Symc8xx - ok
00:28:03.0949 3492 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
00:28:03.0964 3492 Sym_hi - ok
00:28:03.0995 3492 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
00:28:03.0995 3492 Sym_u3 - ok
00:28:04.0042 3492 SysMain (8710a92d0024b03b5fb9540df1f71f1d) C:\Windows\system32\sysmain.dll
00:28:04.0105 3492 SysMain - ok
00:28:04.0136 3492 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
00:28:04.0151 3492 TabletInputService - ok
00:28:04.0183 3492 TapiSrv (680916bb09ee0f3a6aca7c274b0d633f) C:\Windows\System32\tapisrv.dll
00:28:04.0214 3492 TapiSrv - ok
00:28:04.0229 3492 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
00:28:04.0261 3492 TBS - ok
00:28:04.0385 3492 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys
00:28:04.0448 3492 Tcpip - ok
00:28:04.0463 3492 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys
00:28:04.0495 3492 Tcpip6 - ok
00:28:04.0541 3492 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
00:28:04.0557 3492 tcpipreg - ok
00:28:04.0588 3492 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
00:28:04.0619 3492 TDPIPE - ok
00:28:04.0635 3492 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
00:28:04.0682 3492 TDTCP - ok
00:28:04.0713 3492 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
00:28:04.0744 3492 tdx - ok
00:28:04.0760 3492 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
00:28:04.0760 3492 TermDD - ok
00:28:04.0822 3492 TermService (d605031e225aaccbceb5b76a4f1603a6) C:\Windows\System32\termsrv.dll
00:28:04.0900 3492 TermService - ok
00:28:04.0963 3492 Themes (1e3fdb80e40a3ce645f229dfbdfb7694) C:\Windows\system32\shsvcs.dll
00:28:04.0994 3492 Themes - ok
00:28:05.0056 3492 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
00:28:05.0087 3492 THREADORDER - ok
00:28:05.0119 3492 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
00:28:05.0197 3492 TrkWks - ok
00:28:05.0228 3492 TrustedInstaller (16613a1bad034d4ecf957af18b7c2ff5) C:\Windows\servicing\TrustedInstaller.exe
00:28:05.0259 3492 TrustedInstaller - ok
00:28:05.0290 3492 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
00:28:05.0321 3492 tssecsrv - ok
00:28:05.0353 3492 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
00:28:05.0384 3492 tunmp - ok
00:28:05.0415 3492 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys
00:28:05.0446 3492 tunnel - ok
00:28:05.0477 3492 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
00:28:05.0493 3492 uagp35 - ok
00:28:05.0524 3492 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
00:28:05.0555 3492 udfs - ok
00:28:05.0587 3492 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
00:28:05.0618 3492 UI0Detect - ok
00:28:05.0633 3492 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
00:28:05.0633 3492 uliagpkx - ok
00:28:05.0665 3492 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
00:28:05.0680 3492 uliahci - ok
00:28:05.0711 3492 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
00:28:05.0727 3492 UlSata - ok
00:28:05.0743 3492 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
00:28:05.0758 3492 ulsata2 - ok
00:28:05.0789 3492 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
00:28:05.0852 3492 umbus - ok
00:28:05.0899 3492 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
00:28:05.0945 3492 upnphost - ok
00:28:05.0992 3492 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\Windows\system32\Drivers\usbaapl.sys
00:28:06.0023 3492 USBAAPL - ok
00:28:06.0070 3492 usbccgp (a7cd5b4adea26765cab06bdab7b07b13) C:\Windows\system32\DRIVERS\usbccgp.sys
00:28:06.0117 3492 usbccgp - ok
00:28:06.0148 3492 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
00:28:06.0211 3492 usbcir - ok
00:28:06.0211 3492 usbehci (686d4188ae36254c3008b71fedacadf3) C:\Windows\system32\DRIVERS\usbehci.sys
00:28:06.0257 3492 usbehci - ok
00:28:06.0304 3492 usbhub (4e42f665a658f08d153f7fffe7c83806) C:\Windows\system32\DRIVERS\usbhub.sys
00:28:06.0320 3492 usbhub - ok
00:28:06.0351 3492 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
00:28:06.0429 3492 usbohci - ok
00:28:06.0445 3492 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
00:28:06.0507 3492 usbprint - ok
00:28:06.0523 3492 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:28:06.0569 3492 USBSTOR - ok
00:28:06.0601 3492 usbuhci (40f95a3d6d50d82f947f1d167c2ec39d) C:\Windows\system32\DRIVERS\usbuhci.sys
00:28:06.0632 3492 usbuhci - ok
00:28:06.0694 3492 UxSms (032a0acc3909ae7215d524e29d536797) C:\Windows\System32\uxsms.dll
00:28:06.0741 3492 UxSms - ok
00:28:06.0835 3492 vds (b13bc395b9d6116628f5af47e0802ac4) C:\Windows\System32\vds.exe
00:28:06.0913 3492 vds - ok
00:28:06.0959 3492 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
00:28:06.0991 3492 vga - ok
00:28:07.0022 3492 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
00:28:07.0069 3492 VgaSave - ok
00:28:07.0100 3492 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
00:28:07.0100 3492 viaagp - ok
00:28:07.0131 3492 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
00:28:07.0162 3492 ViaC7 - ok
00:28:07.0178 3492 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
00:28:07.0193 3492 viaide - ok
00:28:07.0225 3492 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
00:28:07.0225 3492 volmgr - ok
00:28:07.0303 3492 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
00:28:07.0318 3492 volmgrx - ok
00:28:07.0349 3492 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
00:28:07.0396 3492 volsnap - ok
00:28:07.0427 3492 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
00:28:07.0459 3492 vsmraid - ok
00:28:07.0568 3492 VSS (d5fb73d19c46ade183f968e13f186b23) C:\Windows\system32\vssvc.exe
00:28:07.0677 3492 VSS - ok
00:28:07.0708 3492 W32Time (1cf9206966a8458cda9a8b20df8ab7d3) C:\Windows\system32\w32time.dll
00:28:07.0786 3492 W32Time - ok
00:28:07.0880 3492 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
00:28:07.0911 3492 WacomPen - ok
00:28:07.0927 3492 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:28:07.0973 3492 Wanarp - ok
00:28:08.0020 3492 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
00:28:08.0036 3492 Wanarpv6 - ok
00:28:08.0098 3492 wcncsvc (f3a5c2e1a6533192b070d06ecf6be796) C:\Windows\System32\wcncsvc.dll
00:28:08.0129 3492 wcncsvc - ok
00:28:08.0129 3492 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
00:28:08.0161 3492 WcsPlugInService - ok
00:28:08.0176 3492 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
00:28:08.0192 3492 Wd - ok
00:28:08.0254 3492 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
00:28:08.0270 3492 Wdf01000 - ok
00:28:08.0285 3492 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
00:28:08.0332 3492 WdiServiceHost - ok
00:28:08.0332 3492 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
00:28:08.0348 3492 WdiSystemHost - ok
00:28:08.0379 3492 WebClient (cf9a5f41789b642db967021de06a2713) C:\Windows\System32\webclnt.dll
00:28:08.0410 3492 WebClient - ok
00:28:08.0457 3492 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
00:28:08.0504 3492 Wecsvc - ok
00:28:08.0535 3492 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
00:28:08.0566 3492 wercplsupport - ok
00:28:08.0613 3492 WerSvc (fd1965aaa112c6818a30ab02742d0461) C:\Windows\System32\WerSvc.dll
00:28:08.0660 3492 WerSvc - ok
00:28:08.0738 3492 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
00:28:08.0769 3492 winachsf - ok
00:28:08.0925 3492 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
00:28:08.0956 3492 WinDefend - ok
00:28:08.0956 3492 WinHttpAutoProxySvc - ok
00:28:09.0081 3492 Winmgmt (00b79a7c984678f24cf052e5beb3a2f5) C:\Windows\system32\wbem\WMIsvc.dll
00:28:09.0143 3492 Winmgmt - ok
00:28:09.0362 3492 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
00:28:09.0455 3492 WinRM - ok
00:28:09.0549 3492 Wlansvc (275f4346e569df56cfb95243bd6f6ff0) C:\Windows\System32\wlansvc.dll
00:28:09.0611 3492 Wlansvc - ok
00:28:09.0611 3492 wltrysvc - ok
00:28:09.0674 3492 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
00:28:09.0689 3492 WmiAcpi - ok
00:28:09.0752 3492 wmiApSrv (aba4cf9f856d9a3a25f4ddd7690a6e9d) C:\Windows\system32\wbem\WmiApSrv.exe
00:28:09.0799 3492 wmiApSrv - ok
00:28:09.0939 3492 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
00:28:10.0079 3492 WMPNetworkSvc - ok
00:28:10.0126 3492 WPCSvc (5d94cd167751294962ba238d82dd1bb8) C:\Windows\System32\wpcsvc.dll
00:28:10.0173 3492 WPCSvc - ok
00:28:10.0204 3492 WPDBusEnum (396d406292b0cd26e3504ffe82784702) C:\Windows\system32\wpdbusenum.dll
00:28:10.0220 3492 WPDBusEnum - ok
00:28:10.0407 3492 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
00:28:10.0454 3492 WPFFontCache_v0400 - ok
00:28:10.0579 3492 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
00:28:10.0594 3492 ws2ifsl - ok
00:28:10.0625 3492 wscsvc (683dd16b590372f2c9661d277f35e49c) C:\Windows\system32\wscsvc.dll
00:28:10.0641 3492 wscsvc - ok
00:28:10.0657 3492 WSearch - ok
00:28:10.0813 3492 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll
00:28:10.0922 3492 wuauserv - ok
00:28:11.0047 3492 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
00:28:11.0078 3492 WUDFRd - ok
00:28:11.0109 3492 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
00:28:11.0140 3492 wudfsvc - ok
00:28:11.0156 3492 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
00:28:11.0156 3492 XAudio - ok
00:28:11.0203 3492 XAudioService (cd5f291a1161f15896d1a4d63daff5df) C:\Windows\system32\DRIVERS\xaudio.exe
00:28:11.0218 3492 XAudioService - ok
00:28:11.0265 3492 yukonwlh (a4822191c7cea271903c2a4fb6d9809d) C:\Windows\system32\DRIVERS\yk60x86.sys
00:28:11.0327 3492 yukonwlh - ok
00:28:11.0374 3492 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
00:28:12.0217 3492 \Device\Harddisk0\DR0 - ok
00:28:12.0232 3492 MBR (0x1B8) (d4b3987bee0a0394b385becdce0f7f13) \Device\Harddisk1\DR1
00:29:19.0671 3492 \Device\Harddisk1\DR1 - ok
00:29:19.0702 3492 Boot (0x1200) (7d9dfdcdda59e7ed5a422c65a73e16cc) \Device\Harddisk0\DR0\Partition0
00:29:19.0702 3492 \Device\Harddisk0\DR0\Partition0 - ok
00:29:19.0905 3492 Boot (0x1200) (0f827282df3ccceca6e6afd0e2c60d95) \Device\Harddisk0\DR0\Partition1
00:29:19.0905 3492 \Device\Harddisk0\DR0\Partition1 - ok
00:29:19.0905 3492 ============================================================
00:29:19.0905 3492 Scan finished
00:29:19.0905 3492 ============================================================
00:29:19.0921 3556 Detected object count: 0
00:29:19.0921 3556 Actual detected object count: 0

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#9 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix


:offtopic: Pokracovani rano :o :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

Re: setup.exe - Vista

#10 Příspěvek od Leba »

Trošku se to protáhlo :( dělal log
Ráno se zase lognu

Log

ComboFix 12-05-23.05 - Robo 24.05.2012 0:38.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.3061.1944 [GMT 2:00]
Spuštěný z: c:\users\Robo\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\filmy\[12.1.09] Yes..Man.Ts.Xvid-PreVail\_desktop.ini
c:\filmy\[12.1.09] Yes..Man.Ts.Xvid-PreVail\Sample\_desktop.ini
c:\filmy\Bolt\_desktop.ini
c:\filmy\Forbidden Kingdom[2008]R5 DvDrip[Eng]-FXG\_desktop.ini
c:\filmy\Horton Hears a Who! [2008]DvDrip AC3[Eng]-FXG\_desktop.ini
c:\filmy\KungFuPanda\_desktop.ini
c:\filmy\mapy VKU\_desktop.ini
c:\filmy\OpenSeason2\_desktop.ini
c:\programdata\LY4uMees.exe
c:\windows\iun6002.exe
c:\windows\system32\dds_trash_log.cmd
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AMService
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-23 do 2012-05-23 )))))))))))))))))))))))))))))))
.
.
2012-05-23 22:45 . 2012-05-23 23:00 -------- d-----w- c:\users\Robo\AppData\Local\temp
2012-05-23 22:45 . 2012-05-23 22:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-23 22:21 . 2012-05-23 22:21 -------- d-----w- C:\TDSSKiller_Quarantine
2012-05-23 20:40 . 2012-05-23 20:40 -------- d-----w- C:\rsit
2012-05-23 20:40 . 2012-05-23 20:40 -------- d-----w- c:\program files\trend micro
2012-05-23 18:05 . 2012-05-23 18:05 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-23 22:22 . 2011-06-18 12:02 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-05-11 16:49 . 2011-06-18 12:01 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-05-09 16:50 . 2012-04-11 17:21 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 16:50 . 2011-10-08 22:04 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 17:41 . 2012-04-11 17:41 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F60F67B-37A7-4631-8887-7C1BEE459942}\offreg.dll
2012-03-14 02:15 . 2012-04-10 20:41 6582328 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F60F67B-37A7-4631-8887-7C1BEE459942}\mpengine.dll
2010-04-25 12:48 . 2010-04-25 12:50 961080 ----a-w- c:\program files\SaveAsPDFandXPS.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-04-09 15:43 1519272 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-05 39408]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-07-03 3563520]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 101136]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 101136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-04-09 1557160]
.
c:\users\Robo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-13 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2008-11-13 679936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jmcheng]
2012-04-28 12:23 10752 ----a-w- c:\windows\System32\config\systemprofile\AppData\Local\jmcheng.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 257696]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-11-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 16:50]
.
2012-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 19:17]
.
2012-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 19:17]
.
2012-05-23 c:\windows\Tasks\User_Feed_Synchronization-{6A1516EB-7EB1-4127-88A8-F8934616180F}.job
- c:\windows\system32\msfeedssync.exe [2011-06-18 04:32]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 62.240.178.250 10.0.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-77050330.sys
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-24 01:01
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\users\Robo\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f3,b8,6c,cd,0e,75,d9,4a,9d,2b,4b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f3,b8,6c,cd,0e,75,d9,4a,9d,2b,4b,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1856)
c:\windows\system32\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2012-05-24 01:03:30 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-05-23 23:03
.
Před spuštěním: Volných bajtů: 214 053 646 336
Po spuštění: Volných bajtů: 213 524 013 056
.
- - End Of File - - AB181CF9FBD6C0FABCA537661D71252F

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#11 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\program files\Ask.com
    c:\program files\ICQ6Toolbar
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "ISUSPM Startup"=-
    "ISUSScheduler"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "QuickTime Task"=-
    "iTunesHelper"=-
    "SunJavaUpdateSched"=-
    "ApnUpdater"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jmcheng]
    
    Collect::
    c:\windows\System32\config\systemprofile\AppData\Local\jmcheng.dll
    C:\ProgramData\LY4uMees.exe
    
    Driver::
    ICQ Service
    
    File::
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\User_Feed_Synchronization-{6A1516EB-7EB1-4127-88A8-F8934616180F}.job
    C:\Windows\tasks\Adobe Flash Player Updater.job
    
    DDS::
    uStart Page = hxxp://www.yahoo.com/
    
    Rootkit::
    c:\users\Robo\AppData\Local\Temp\catchme.dll
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    AtJob::
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Leba
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 08 zář 2006 14:53
Kontaktovat uživatele:

Re: setup.exe - Vista

#12 Příspěvek od Leba »

ComboFix 12-05-23.05 - Robo 24.05.2012 14:31:30.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.3061.2014 [GMT 2:00]
Spuštěný z: c:\users\Robo\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Robo\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\User_Feed_Synchronization-{6A1516EB-7EB1-4127-88A8-F8934616180F}.job"
.
file zipped: c:\windows\System32\config\systemprofile\AppData\Local\jmcheng.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Robo\pdf
c:\users\Robo\pdf\AdbeRdr910_cs_CZ.exe
c:\windows\System32\config\systemprofile\AppData\Local\jmcheng.dll
c:\windows\system32\wbem\Performance\WmiApRpl_new.ini
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\User_Feed_Synchronization-{6A1516EB-7EB1-4127-88A8-F8934616180F}.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-24 do 2012-05-24 )))))))))))))))))))))))))))))))
.
.
2012-05-24 12:38 . 2012-05-24 12:42 -------- d-----w- c:\users\Robo\AppData\Local\temp
2012-05-24 12:38 . 2012-05-24 12:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-23 22:21 . 2012-05-23 22:21 -------- d-----w- C:\TDSSKiller_Quarantine
2012-05-23 20:40 . 2012-05-23 20:40 -------- d-----w- C:\rsit
2012-05-23 20:40 . 2012-05-23 20:40 -------- d-----w- c:\program files\trend micro
2012-05-23 18:05 . 2012-05-23 18:05 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-23 22:22 . 2011-06-18 12:02 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-05-11 16:49 . 2011-06-18 12:01 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-05-09 16:50 . 2012-04-11 17:21 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 16:50 . 2011-10-08 22:04 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 17:41 . 2012-04-11 17:41 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F60F67B-37A7-4631-8887-7C1BEE459942}\offreg.dll
2012-03-14 02:15 . 2012-04-10 20:41 6582328 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F60F67B-37A7-4631-8887-7C1BEE459942}\mpengine.dll
2010-04-25 12:48 . 2010-04-25 12:50 961080 ----a-w- c:\program files\SaveAsPDFandXPS.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-07-03 3563520]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 101136]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 101136]
.
c:\users\Robo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-13 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2008-11-13 679936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 257696]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-11-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 62.240.178.250 10.0.0.1
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2928)
c:\windows\system32\btncopy.dll
c:\program files\Microsoft Office\Office12\1051\GrooveIntlResource.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\System32\bcmwltry.exe
c:\windows\system32\conime.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\system32\WUDFHost.exe
.
**************************************************************************
.
Celkový čas: 2012-05-24 14:45:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-05-24 12:45
ComboFix2.txt 2012-05-23 23:03
.
Před spuštěním: Volných bajtů: 213 469 868 032
Po spuštění: Volných bajtů: 213 352 697 856
.
- - End Of File - - EF0DA21AF761904073B828681882BF4A
Nahr nˇ probŘhlo ŁspŘçnŘ

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: setup.exe - Vista

#13 Příspěvek od vyosek »

Jak se chova nas pacient :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět