Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Po prihlaseni do int. bankovnictvi se PC restartuje

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
olhor
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 09 dub 2006 11:13

Po prihlaseni do int. bankovnictvi se PC restartuje

#1 Příspěvek od olhor »

Dobry den,
mam problem ze kdyz jsem v internetovem bankovnictvi gemoney nebo se mi to same stavapri platbe kartou CS. Se mi zrestartuje PC. Koukal jsem do Event logu a je tam pouze chyba 100 Performance, coz jak jsem se docetl zaznamenava pouze navysovani casu pri bootovani od prvni instalace, coz nic neznamena pri startu se delaji aktualizace..... Vzhledem k povaze stranek, bych si byl rad jisty ze nejde o vir, dekuji.


Logfile of random's system information tool 1.09 (written by random/random)
Run by Olhor at 2012-07-06 11:43:38
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 100 GB (82%) free of 122 GB
Total RAM: 3584 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:43:42, on 6.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
D:\Olhor\Downloads\RSIT.exe
C:\Program Files\trend micro\Olhor.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\AdobeCollabSync.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\virtualni masina\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe

--
End of file - 7531 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Olhor\AppData\Roaming\Mozilla\Firefox\Profiles\f368w8kn.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

"web2pdfextension@web2pdf.adobedotcom"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33]
"Description"=
"Path"=C:\Windows\system32\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Olhor\AppData\Roaming\Mozilla\Firefox\Profiles\f368w8kn.default\extensions\
LogMeInClient@logmein.com
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-07-05 329480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-04-04 340384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-07-05 59144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-04-04 340384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-04-04 340384]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2012-03-07 3117344]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2012-04-04 36760]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2012-04-04 815512]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"Adobe Acrobat Synchronizer"=C:\Program Files\Adobe\Acrobat 10.0\Acrobat\AdobeCollabSync.exe [2012-04-04 1261472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Olhor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
C:\PROGRA~1\MICROS~3\Office14\ONENOTEM.EXE [2011-09-02 227712]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"VIDC.VMnc"=vmnc.dll
"vidc.MPG4"=MPG4c32.dll
"vidc.MP42"=MPG4c32.dll
"vidc.MP43"=MPG4c32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-07-06 11:40:49 ----D---- C:\rsit
2012-07-06 11:40:49 ----D---- C:\Program Files\trend micro
2012-07-05 19:57:32 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-07-05 19:57:32 ----A---- C:\Windows\system32\javaws.exe
2012-07-05 19:57:32 ----A---- C:\Windows\system32\javaw.exe
2012-07-05 19:57:32 ----A---- C:\Windows\system32\java.exe
2012-07-05 19:57:21 ----D---- C:\Program Files\Java
2012-07-05 19:56:24 ----D---- C:\ProgramData\McAfee
2012-07-01 20:50:46 ----A---- C:\Windows\system32\wups2.dll
2012-07-01 20:50:46 ----A---- C:\Windows\system32\wucltux.dll
2012-07-01 20:50:46 ----A---- C:\Windows\system32\wuaueng.dll
2012-07-01 20:50:46 ----A---- C:\Windows\system32\wuauclt.exe
2012-07-01 20:50:41 ----A---- C:\Windows\system32\wups.dll
2012-07-01 20:50:41 ----A---- C:\Windows\system32\wudriver.dll
2012-07-01 20:50:41 ----A---- C:\Windows\system32\wuapi.dll
2012-07-01 20:50:39 ----A---- C:\Windows\system32\wuwebv.dll
2012-07-01 20:50:39 ----A---- C:\Windows\system32\wuapp.exe
2012-06-19 20:48:27 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-19 20:48:26 ----A---- C:\Windows\system32\ieui.dll
2012-06-19 20:48:26 ----A---- C:\Windows\system32\iertutil.dll
2012-06-19 20:48:25 ----A---- C:\Windows\system32\wininet.dll
2012-06-19 20:48:25 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-19 20:48:25 ----A---- C:\Windows\system32\jscript.dll
2012-06-19 20:48:25 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-19 20:48:24 ----A---- C:\Windows\system32\url.dll
2012-06-19 20:48:24 ----A---- C:\Windows\system32\jscript9.dll
2012-06-19 20:48:22 ----A---- C:\Windows\system32\urlmon.dll
2012-06-19 20:48:20 ----A---- C:\Windows\system32\mshtml.dll
2012-06-19 20:48:19 ----A---- C:\Windows\system32\ieframe.dll
2012-06-19 17:57:09 ----D---- C:\Users\Olhor\AppData\Roaming\e-academy Inc
2012-06-19 16:39:52 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2012-06-19 16:20:03 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-19 16:20:00 ----A---- C:\Windows\system32\msi.dll
2012-06-19 16:19:59 ----A---- C:\Windows\system32\profsvc.dll
2012-06-19 16:19:57 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-19 16:19:57 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-19 16:19:57 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-19 16:19:37 ----A---- C:\Windows\system32\win32k.sys
2012-06-19 16:19:20 ----A---- C:\Windows\system32\crypt32.dll
2012-06-19 16:19:19 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-19 16:19:19 ----A---- C:\Windows\system32\cryptnet.dll

======List of files/folders modified in the last 1 month======

2012-07-06 11:43:42 ----D---- C:\Windows\Temp
2012-07-06 11:40:49 ----RD---- C:\Program Files
2012-07-06 11:28:37 ----D---- C:\Windows\system32\config
2012-07-06 11:23:13 ----D---- C:\Windows\system32\Tasks
2012-07-06 11:14:14 ----D---- C:\Windows\System32
2012-07-06 11:14:14 ----D---- C:\Windows\inf
2012-07-06 11:14:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-07-06 11:12:39 ----D---- C:\PerfLogs
2012-07-06 11:10:02 ----D---- C:\ProgramData\VMware
2012-07-05 21:53:46 ----D---- C:\Users\Olhor\AppData\Roaming\vlc
2012-07-05 21:39:11 ----D---- C:\Program Files\OpenVPN
2012-07-05 19:57:45 ----SHD---- C:\Windows\Installer
2012-07-05 19:57:22 ----A---- C:\Windows\system32\deployJava1.dll
2012-07-05 19:56:47 ----SHD---- C:\System Volume Information
2012-07-05 19:56:24 ----HD---- C:\ProgramData
2012-07-01 21:21:36 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-07-01 20:51:05 ----D---- C:\Windows\winsxs
2012-07-01 20:51:05 ----D---- C:\Windows\system32\cs-CZ
2012-07-01 20:50:52 ----D---- C:\Windows\system32\catroot
2012-07-01 20:50:51 ----D---- C:\Windows\system32\catroot2
2012-06-21 12:10:22 ----D---- C:\Windows\rescache
2012-06-21 11:52:13 ----D---- C:\Windows\Microsoft.NET
2012-06-21 11:52:12 ----RSD---- C:\Windows\assembly
2012-06-19 23:27:42 ----D---- C:\Windows\system32\migration
2012-06-19 23:27:42 ----D---- C:\Windows\system32\drivers
2012-06-19 23:27:42 ----D---- C:\Program Files\Internet Explorer
2012-06-19 20:53:22 ----D---- C:\ProgramData\Microsoft Help
2012-06-19 20:51:01 ----A---- C:\Windows\system32\MRT.exe
2012-06-19 17:57:10 ----SD---- C:\Users\Olhor\AppData\Roaming\Microsoft
2012-06-19 16:46:07 ----D---- C:\Windows\system32\DriverStore
2012-06-19 16:40:32 ----D---- C:\Users\Olhor\AppData\Roaming\Adobe
2012-06-19 16:39:52 ----D---- C:\ProgramData\Adobe
2012-06-19 16:39:10 ----D---- C:\Program Files\Common Files\Adobe
2012-06-19 16:37:20 ----RSD---- C:\Windows\Fonts
2012-06-19 16:37:07 ----D---- C:\Program Files\Adobe
2012-06-19 16:15:44 ----D---- C:\Windows\Tasks
2012-06-19 16:15:44 ----D---- C:\Windows\system32\wfp
2012-06-19 16:15:43 ----D---- C:\Windows\system32\wbem
2012-06-19 16:15:43 ----D---- C:\Windows
2012-06-19 16:14:48 ----RSD---- C:\Windows\Media
2012-06-19 16:14:48 ----D---- C:\Windows\system32\drivers\etc
2012-06-19 16:14:42 ----D---- C:\Windows\system32\CodeIntegrity
2012-06-19 16:14:07 ----D---- C:\Windows\AppCompat
2012-06-19 16:14:02 ----D---- C:\Program Files\YTD
2012-06-19 16:13:38 ----D---- C:\Windows\registration
2012-06-19 16:13:22 ----SD---- C:\ProgramData\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2012-03-14 50624]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmci;VMware VMCI Bus Driver; C:\Windows\system32\DRIVERS\vmci.sys [2011-08-08 98928]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2012-03-14 169080]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2012-03-14 120152]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2012-03-14 33656]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2012-03-14 148504]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2011-08-29 32496]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2012-01-18 36464]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2012-01-18 25712]
R2 VMparport;VMware VMparport; \??\C:\Windows\system32\Drivers\VMparport.sys [2012-01-18 23792]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\Drivers\vmx86.sys [2012-01-18 55664]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 AVerA706;AVerMedia A706 BDA Service; C:\Windows\system32\DRIVERS\AVerA706.sys [2009-06-10 1169920]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2009-07-14 429056]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
R3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2011-12-15 26624]
R3 vmkbd;VMware kbd; \??\C:\Windows\system32\drivers\VMkbd.sys [2012-01-18 25584]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2012-01-18 16624]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 AVerRemote;AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [2009-10-31 348160]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [2009-12-07 397312]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2012-03-07 913144]
R2 VMAuthdService;VMware Authorization Service; D:\virtualni masina\vmware-authd.exe [2012-01-18 79872]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\system32\vmnetdhcp.exe [2012-01-18 354416]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-08-29 665200]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\system32\vmnat.exe [2012-01-18 433264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-04 129976]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2011-12-15 14848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-11-30 1343400]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15699
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#2 Příspěvek od JaRon »

ahoj,
otazka znie:
Robi to Firefox aj MSIE :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

olhor
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 09 dub 2006 11:13

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#3 Příspěvek od olhor »

JaRon píše:ahoj,
otazka znie:
Robi to Firefox aj MSIE :???:

Zas takova lama nejsem :D Samozrejme oboje.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15699
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#4 Příspěvek od JaRon »

vies, ja musim overit vsetky varianty :)
1. odskusaj to pri vypnutom ESS
2. odskusaj Chrome - potom ho kludne odinstaluj
3. preventivne vloz logy z TDSSKiller + MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

olhor
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 09 dub 2006 11:13

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#5 Příspěvek od olhor »

TDSS log

18:36:32.0167 4016 TDSS rootkit removing tool 2.7.44.0 Jul 2 2012 20:01:08
18:36:32.0383 4016 ============================================================
18:36:32.0383 4016 Current date / time: 2012/07/08 18:36:32.0383
18:36:32.0383 4016 SystemInfo:
18:36:32.0383 4016
18:36:32.0384 4016 OS Version: 6.1.7601 ServicePack: 1.0
18:36:32.0384 4016 Product type: Workstation
18:36:32.0384 4016 ComputerName: OLHOR-PC
18:36:32.0385 4016 UserName: Olhor
18:36:32.0385 4016 Windows directory: C:\Windows
18:36:32.0385 4016 System windows directory: C:\Windows
18:36:32.0385 4016 Processor architecture: Intel x86
18:36:32.0385 4016 Number of processors: 1
18:36:32.0385 4016 Page size: 0x1000
18:36:32.0385 4016 Boot type: Normal boot
18:36:32.0385 4016 ============================================================
18:36:32.0788 4016 Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 (119.24 Gb), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:36:32.0788 4016 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:36:33.0189 4016 ============================================================
18:36:33.0189 4016 \Device\Harddisk0\DR0:
18:36:33.0190 4016 MBR partitions:
18:36:33.0190 4016 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xEE7B000
18:36:33.0190 4016 \Device\Harddisk1\DR1:
18:36:33.0190 4016 MBR partitions:
18:36:33.0190 4016 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x9644211
18:36:33.0190 4016 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x964428F, BlocksNum 0x30D3CAF1
18:36:33.0190 4016 ============================================================
18:36:33.0191 4016 C: <-> \Device\Harddisk0\DR0\Partition0
18:36:33.0194 4016 D: <-> \Device\Harddisk1\DR1\Partition1
18:36:33.0220 4016 E: <-> \Device\Harddisk1\DR1\Partition0
18:36:33.0221 4016 ============================================================
18:36:33.0221 4016 Initialize success
18:36:33.0221 4016 ============================================================
18:36:37.0989 2468 ============================================================
18:36:37.0989 2468 Scan started
18:36:37.0989 2468 Mode: Manual;
18:36:37.0989 2468 ============================================================
18:36:38.0338 2468 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\DRIVERS\1394ohci.sys
18:36:38.0341 2468 1394ohci - ok
18:36:38.0370 2468 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
18:36:38.0375 2468 ACPI - ok
18:36:38.0394 2468 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
18:36:38.0395 2468 AcpiPmi - ok
18:36:38.0420 2468 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:36:38.0421 2468 AdobeARMservice - ok
18:36:38.0456 2468 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\drivers\adp94xx.sys
18:36:38.0465 2468 adp94xx - ok
18:36:38.0493 2468 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\drivers\adpahci.sys
18:36:38.0500 2468 adpahci - ok
18:36:38.0524 2468 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\drivers\adpu320.sys
18:36:38.0528 2468 adpu320 - ok
18:36:38.0561 2468 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll
18:36:38.0563 2468 AeLookupSvc - ok
18:36:38.0652 2468 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
18:36:38.0656 2468 AFD - ok
18:36:38.0681 2468 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
18:36:38.0686 2468 agp440 - ok
18:36:38.0705 2468 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\drivers\djsvs.sys
18:36:38.0708 2468 aic78xx - ok
18:36:38.0915 2468 ALCXWDM (7997b6f02cbda0e31fa18cc85871b938) C:\Windows\system32\drivers\RTKVAC.SYS
18:36:38.0973 2468 ALCXWDM - ok
18:36:39.0021 2468 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe
18:36:39.0024 2468 ALG - ok
18:36:39.0044 2468 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
18:36:39.0046 2468 aliide - ok
18:36:39.0072 2468 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
18:36:39.0075 2468 amdagp - ok
18:36:39.0092 2468 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
18:36:39.0093 2468 amdide - ok
18:36:39.0113 2468 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
18:36:39.0114 2468 AmdK8 - ok
18:36:39.0133 2468 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\drivers\amdppm.sys
18:36:39.0138 2468 AmdPPM - ok
18:36:39.0158 2468 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
18:36:39.0161 2468 amdsata - ok
18:36:39.0185 2468 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\drivers\amdsbs.sys
18:36:39.0195 2468 amdsbs - ok
18:36:39.0213 2468 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
18:36:39.0214 2468 amdxata - ok
18:36:39.0237 2468 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
18:36:39.0239 2468 AppID - ok
18:36:39.0258 2468 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll
18:36:39.0260 2468 AppIDSvc - ok
18:36:39.0279 2468 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll
18:36:39.0280 2468 Appinfo - ok
18:36:39.0307 2468 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll
18:36:39.0311 2468 AppMgmt - ok
18:36:39.0331 2468 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\drivers\arc.sys
18:36:39.0336 2468 arc - ok
18:36:39.0399 2468 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\drivers\arcsas.sys
18:36:39.0402 2468 arcsas - ok
18:36:39.0424 2468 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
18:36:39.0425 2468 AsyncMac - ok
18:36:39.0442 2468 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
18:36:39.0443 2468 atapi - ok
18:36:39.0627 2468 atikmdag (712d8a95e45b070114c5309ada7358ff) C:\Windows\system32\DRIVERS\atikmdag.sys
18:36:39.0708 2468 atikmdag - ok
18:36:39.0778 2468 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
18:36:39.0787 2468 AudioEndpointBuilder - ok
18:36:39.0806 2468 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
18:36:39.0811 2468 Audiosrv - ok
18:36:39.0875 2468 AVerA706 (48afe225a6a9bf9d2b57de932aa0d3d7) C:\Windows\system32\DRIVERS\AVerA706.sys
18:36:39.0896 2468 AVerA706 - ok
18:36:39.0931 2468 AVerRemote (95d7f9544b6c989d1aebbbe4664bcd70) C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
18:36:39.0937 2468 AVerRemote - ok
18:36:39.0966 2468 AVerScheduleService (0db0ab8415bff81037981af1d3bbbe97) C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
18:36:39.0971 2468 AVerScheduleService - ok
18:36:40.0021 2468 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll
18:36:40.0024 2468 AxInstSV - ok
18:36:40.0072 2468 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\drivers\bxvbdx.sys
18:36:40.0087 2468 b06bdrv - ok
18:36:40.0114 2468 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
18:36:40.0121 2468 b57nd60x - ok
18:36:40.0151 2468 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll
18:36:40.0155 2468 BDESVC - ok
18:36:40.0193 2468 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
18:36:40.0195 2468 Beep - ok
18:36:40.0236 2468 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll
18:36:40.0244 2468 BFE - ok
18:36:40.0291 2468 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\System32\qmgr.dll
18:36:40.0306 2468 BITS - ok
18:36:40.0324 2468 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
18:36:40.0326 2468 blbdrive - ok
18:36:40.0346 2468 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
18:36:40.0349 2468 bowser - ok
18:36:40.0366 2468 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\BrFiltLo.sys
18:36:40.0371 2468 BrFiltLo - ok
18:36:40.0394 2468 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\BrFiltUp.sys
18:36:40.0395 2468 BrFiltUp - ok
18:36:40.0415 2468 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll
18:36:40.0427 2468 Browser - ok
18:36:40.0506 2468 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
18:36:40.0512 2468 Brserid - ok
18:36:40.0528 2468 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
18:36:40.0531 2468 BrSerWdm - ok
18:36:40.0549 2468 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
18:36:40.0552 2468 BrUsbMdm - ok
18:36:40.0575 2468 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
18:36:40.0576 2468 BrUsbSer - ok
18:36:40.0601 2468 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\drivers\bthmodem.sys
18:36:40.0606 2468 BTHMODEM - ok
18:36:40.0631 2468 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll
18:36:40.0636 2468 bthserv - ok
18:36:40.0656 2468 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
18:36:40.0659 2468 cdfs - ok
18:36:40.0690 2468 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
18:36:40.0692 2468 cdrom - ok
18:36:40.0724 2468 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
18:36:40.0727 2468 CertPropSvc - ok
18:36:40.0746 2468 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
18:36:40.0747 2468 circlass - ok
18:36:40.0777 2468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
18:36:40.0781 2468 CLFS - ok
18:36:40.0811 2468 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:36:40.0815 2468 clr_optimization_v2.0.50727_32 - ok
18:36:40.0858 2468 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:36:40.0861 2468 clr_optimization_v4.0.30319_32 - ok
18:36:40.0879 2468 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\drivers\CmBatt.sys
18:36:40.0881 2468 CmBatt - ok
18:36:40.0898 2468 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
18:36:40.0902 2468 cmdide - ok
18:36:40.0933 2468 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
18:36:40.0954 2468 CNG - ok
18:36:40.0973 2468 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\drivers\compbatt.sys
18:36:40.0975 2468 Compbatt - ok
18:36:40.0993 2468 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\DRIVERS\CompositeBus.sys
18:36:40.0994 2468 CompositeBus - ok
18:36:41.0011 2468 COMSysApp - ok
18:36:41.0031 2468 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\drivers\crcdisk.sys
18:36:41.0036 2468 crcdisk - ok
18:36:41.0077 2468 CryptSvc (06e771aa596b8761107ab57e99f128d7) C:\Windows\system32\cryptsvc.dll
18:36:41.0080 2468 CryptSvc - ok
18:36:41.0112 2468 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
18:36:41.0120 2468 CSC - ok
18:36:41.0159 2468 CscService (15f93b37f6801943360d9eb42485d5d3) C:\Windows\System32\cscsvc.dll
18:36:41.0170 2468 CscService - ok
18:36:41.0223 2468 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
18:36:41.0232 2468 DcomLaunch - ok
18:36:41.0258 2468 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll
18:36:41.0264 2468 defragsvc - ok
18:36:41.0289 2468 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
18:36:41.0291 2468 DfsC - ok
18:36:41.0330 2468 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll
18:36:41.0337 2468 Dhcp - ok
18:36:41.0381 2468 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
18:36:41.0382 2468 discache - ok
18:36:41.0404 2468 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\drivers\disk.sys
18:36:41.0405 2468 Disk - ok
18:36:41.0430 2468 dmvsc (2a958ef85db1b61ffca65044fa4bce9e) C:\Windows\system32\drivers\dmvsc.sys
18:36:41.0436 2468 dmvsc - ok
18:36:41.0470 2468 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll
18:36:41.0474 2468 Dnscache - ok
18:36:41.0498 2468 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll
18:36:41.0505 2468 dot3svc - ok
18:36:41.0528 2468 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll
18:36:41.0530 2468 DPS - ok
18:36:41.0556 2468 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
18:36:41.0558 2468 drmkaud - ok
18:36:41.0606 2468 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
18:36:41.0613 2468 DXGKrnl - ok
18:36:41.0636 2468 eamonm (8a45015e85a4dce0086b9973f0fd9a20) C:\Windows\system32\DRIVERS\eamonm.sys
18:36:41.0639 2468 eamonm - ok
18:36:41.0664 2468 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll
18:36:41.0669 2468 EapHost - ok
18:36:41.0824 2468 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\drivers\evbdx.sys
18:36:41.0882 2468 ebdrv - ok
18:36:41.0930 2468 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe
18:36:41.0935 2468 EFS - ok
18:36:41.0967 2468 ehdrv (5412ed24fffca64e2f0168399b86c952) C:\Windows\system32\DRIVERS\ehdrv.sys
18:36:41.0971 2468 ehdrv - ok
18:36:42.0021 2468 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe
18:36:42.0030 2468 ehRecvr - ok
18:36:42.0046 2468 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe
18:36:42.0049 2468 ehSched - ok
18:36:42.0125 2468 ekrn (ad4faade819e0da9933bea7c01d2c763) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
18:36:42.0134 2468 ekrn - ok
18:36:42.0195 2468 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\drivers\elxstor.sys
18:36:42.0205 2468 elxstor - ok
18:36:42.0246 2468 epfw (774babcb1144513dc86992003740b774) C:\Windows\system32\DRIVERS\epfw.sys
18:36:42.0248 2468 epfw - ok
18:36:42.0270 2468 EpfwLWF (2c22cc39309ee06ae870c183bf2a769d) C:\Windows\system32\DRIVERS\EpfwLWF.sys
18:36:42.0271 2468 EpfwLWF - ok
18:36:42.0289 2468 epfwwfp (2b4e5f01a4e786b422f4d617b51fa7d9) C:\Windows\system32\DRIVERS\epfwwfp.sys
18:36:42.0291 2468 epfwwfp - ok
18:36:42.0309 2468 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
18:36:42.0310 2468 ErrDev - ok
18:36:42.0360 2468 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll
18:36:42.0366 2468 EventSystem - ok
18:36:42.0389 2468 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
18:36:42.0393 2468 exfat - ok
18:36:42.0415 2468 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
18:36:42.0421 2468 fastfat - ok
18:36:42.0472 2468 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe
18:36:42.0484 2468 Fax - ok
18:36:42.0507 2468 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
18:36:42.0508 2468 fdc - ok
18:36:42.0527 2468 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll
18:36:42.0528 2468 fdPHost - ok
18:36:42.0547 2468 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll
18:36:42.0548 2468 FDResPub - ok
18:36:42.0574 2468 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
18:36:42.0575 2468 FileInfo - ok
18:36:42.0596 2468 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
18:36:42.0597 2468 Filetrace - ok
18:36:42.0614 2468 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
18:36:42.0618 2468 flpydisk - ok
18:36:42.0642 2468 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
18:36:42.0646 2468 FltMgr - ok
18:36:42.0693 2468 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll
18:36:42.0708 2468 FontCache - ok
18:36:42.0736 2468 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:36:42.0738 2468 FontCache3.0.0.0 - ok
18:36:42.0763 2468 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
18:36:42.0765 2468 FsDepends - ok
18:36:42.0784 2468 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys
18:36:42.0785 2468 Fs_Rec - ok
18:36:42.0817 2468 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
18:36:42.0822 2468 fvevol - ok
18:36:42.0849 2468 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\drivers\gagp30kx.sys
18:36:42.0855 2468 gagp30kx - ok
18:36:42.0936 2468 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll
18:36:42.0947 2468 gpsvc - ok
18:36:42.0965 2468 hcmon (88a6f2571405b3a4abc4ed2f52136317) C:\Windows\system32\drivers\hcmon.sys
18:36:42.0969 2468 hcmon - ok
18:36:42.0987 2468 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
18:36:42.0989 2468 hcw85cir - ok
18:36:43.0010 2468 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
18:36:43.0013 2468 HDAudBus - ok
18:36:43.0031 2468 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\drivers\HidBatt.sys
18:36:43.0035 2468 HidBatt - ok
18:36:43.0055 2468 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\drivers\hidbth.sys
18:36:43.0058 2468 HidBth - ok
18:36:43.0077 2468 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
18:36:43.0079 2468 HidIr - ok
18:36:43.0100 2468 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll
18:36:43.0105 2468 hidserv - ok
18:36:43.0124 2468 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
18:36:43.0125 2468 HidUsb - ok
18:36:43.0146 2468 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll
18:36:43.0149 2468 hkmsvc - ok
18:36:43.0176 2468 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll
18:36:43.0186 2468 HomeGroupListener - ok
18:36:43.0213 2468 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll
18:36:43.0220 2468 HomeGroupProvider - ok
18:36:43.0243 2468 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
18:36:43.0246 2468 HpSAMD - ok
18:36:43.0295 2468 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
18:36:43.0377 2468 HTTP - ok
18:36:43.0401 2468 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
18:36:43.0402 2468 hwpolicy - ok
18:36:43.0423 2468 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
18:36:43.0426 2468 i8042prt - ok
18:36:43.0465 2468 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
18:36:43.0474 2468 iaStorV - ok
18:36:43.0533 2468 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:36:43.0556 2468 idsvc - ok
18:36:43.0577 2468 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\drivers\iirsp.sys
18:36:43.0579 2468 iirsp - ok
18:36:43.0640 2468 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll
18:36:43.0654 2468 IKEEXT - ok
18:36:43.0679 2468 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
18:36:43.0681 2468 intelide - ok
18:36:43.0702 2468 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\drivers\intelppm.sys
18:36:43.0705 2468 intelppm - ok
18:36:43.0732 2468 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll
18:36:43.0738 2468 IPBusEnum - ok
18:36:43.0759 2468 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:36:43.0761 2468 IpFilterDriver - ok
18:36:43.0900 2468 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll
18:36:43.0909 2468 iphlpsvc - ok
18:36:43.0937 2468 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
18:36:43.0940 2468 IPMIDRV - ok
18:36:43.0959 2468 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
18:36:43.0963 2468 IPNAT - ok
18:36:43.0981 2468 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
18:36:43.0982 2468 IRENUM - ok
18:36:44.0009 2468 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
18:36:44.0011 2468 isapnp - ok
18:36:44.0039 2468 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
18:36:44.0048 2468 iScsiPrt - ok
18:36:44.0073 2468 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
18:36:44.0074 2468 kbdclass - ok
18:36:44.0087 2468 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
18:36:44.0090 2468 kbdhid - ok
18:36:44.0095 2468 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
18:36:44.0097 2468 KeyIso - ok
18:36:44.0110 2468 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
18:36:44.0111 2468 KSecDD - ok
18:36:44.0125 2468 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
18:36:44.0127 2468 KSecPkg - ok
18:36:44.0162 2468 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll
18:36:44.0171 2468 KtmRm - ok
18:36:44.0198 2468 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\system32\srvsvc.dll
18:36:44.0209 2468 LanmanServer - ok
18:36:44.0520 2468 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll
18:36:44.0526 2468 LanmanWorkstation - ok
18:36:44.0553 2468 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
18:36:44.0555 2468 lltdio - ok
18:36:44.0586 2468 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll
18:36:44.0593 2468 lltdsvc - ok
18:36:44.0617 2468 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll
18:36:44.0620 2468 lmhosts - ok
18:36:44.0709 2468 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\drivers\lsi_fc.sys
18:36:44.0712 2468 LSI_FC - ok
18:36:44.0743 2468 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\drivers\lsi_sas.sys
18:36:44.0746 2468 LSI_SAS - ok
18:36:44.0774 2468 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\drivers\lsi_sas2.sys
18:36:44.0777 2468 LSI_SAS2 - ok
18:36:44.0797 2468 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\drivers\lsi_scsi.sys
18:36:44.0799 2468 LSI_SCSI - ok
18:36:44.0825 2468 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
18:36:44.0836 2468 luafv - ok
18:36:44.0861 2468 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll
18:36:44.0867 2468 Mcx2Svc - ok
18:36:44.0894 2468 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\drivers\megasas.sys
18:36:44.0896 2468 megasas - ok
18:36:44.0923 2468 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\drivers\MegaSR.sys
18:36:44.0928 2468 MegaSR - ok
18:36:44.0951 2468 Microsoft SharePoint Workspace Audit Service - ok
18:36:44.0976 2468 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
18:36:44.0979 2468 MMCSS - ok
18:36:44.0996 2468 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
18:36:44.0998 2468 Modem - ok
18:36:45.0024 2468 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
18:36:45.0025 2468 monitor - ok
18:36:45.0043 2468 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
18:36:45.0044 2468 mouclass - ok
18:36:45.0062 2468 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
18:36:45.0064 2468 mouhid - ok
18:36:45.0096 2468 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
18:36:45.0098 2468 mountmgr - ok
18:36:45.0121 2468 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:36:45.0125 2468 MozillaMaintenance - ok
18:36:45.0153 2468 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
18:36:45.0157 2468 mpio - ok
18:36:45.0258 2468 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
18:36:45.0260 2468 mpsdrv - ok
18:36:45.0305 2468 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll
18:36:45.0315 2468 MpsSvc - ok
18:36:45.0338 2468 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
18:36:45.0341 2468 MRxDAV - ok
18:36:45.0371 2468 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
18:36:45.0375 2468 mrxsmb - ok
18:36:45.0409 2468 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:36:45.0414 2468 mrxsmb10 - ok
18:36:45.0437 2468 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:36:45.0440 2468 mrxsmb20 - ok
18:36:45.0457 2468 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
18:36:45.0458 2468 msahci - ok
18:36:45.0480 2468 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
18:36:45.0483 2468 msdsm - ok
18:36:45.0506 2468 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe
18:36:45.0515 2468 MSDTC - ok
18:36:45.0552 2468 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
18:36:45.0554 2468 Msfs - ok
18:36:45.0570 2468 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
18:36:45.0571 2468 mshidkmdf - ok
18:36:45.0590 2468 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
18:36:45.0591 2468 msisadrv - ok
18:36:45.0626 2468 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll
18:36:45.0631 2468 MSiSCSI - ok
18:36:45.0647 2468 msiserver - ok
18:36:45.0894 2468 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
18:36:45.0895 2468 MSKSSRV - ok
18:36:45.0913 2468 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
18:36:45.0914 2468 MSPCLOCK - ok
18:36:45.0929 2468 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
18:36:45.0930 2468 MSPQM - ok
18:36:45.0964 2468 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
18:36:45.0970 2468 MsRPC - ok
18:36:45.0994 2468 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
18:36:45.0995 2468 mssmbios - ok
18:36:46.0014 2468 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
18:36:46.0018 2468 MSTEE - ok
18:36:46.0035 2468 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\drivers\MTConfig.sys
18:36:46.0037 2468 MTConfig - ok
18:36:46.0137 2468 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
18:36:46.0138 2468 Mup - ok
18:36:46.0176 2468 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll
18:36:46.0185 2468 napagent - ok
18:36:46.0222 2468 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
18:36:46.0228 2468 NativeWifiP - ok
18:36:46.0278 2468 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
18:36:46.0291 2468 NDIS - ok
18:36:46.0311 2468 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
18:36:46.0320 2468 NdisCap - ok
18:36:46.0340 2468 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
18:36:46.0341 2468 NdisTapi - ok
18:36:46.0362 2468 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
18:36:46.0367 2468 Ndisuio - ok
18:36:46.0403 2468 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
18:36:46.0406 2468 NdisWan - ok
18:36:46.0426 2468 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
18:36:46.0428 2468 NDProxy - ok
18:36:46.0456 2468 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
18:36:46.0458 2468 NetBIOS - ok
18:36:46.0486 2468 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
18:36:46.0489 2468 NetBT - ok
18:36:46.0514 2468 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
18:36:46.0518 2468 Netlogon - ok
18:36:46.0614 2468 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll
18:36:46.0623 2468 Netman - ok
18:36:46.0667 2468 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll
18:36:46.0676 2468 netprofm - ok
18:36:46.0714 2468 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:36:46.0719 2468 NetTcpPortSharing - ok
18:36:46.0740 2468 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\drivers\nfrd960.sys
18:36:46.0742 2468 nfrd960 - ok
18:36:46.0774 2468 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll
18:36:46.0780 2468 NlaSvc - ok
18:36:46.0802 2468 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
18:36:46.0804 2468 Npfs - ok
18:36:46.0831 2468 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll
18:36:46.0838 2468 nsi - ok
18:36:46.0858 2468 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
18:36:46.0859 2468 nsiproxy - ok
18:36:46.0937 2468 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
18:36:46.0957 2468 Ntfs - ok
18:36:46.0991 2468 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
18:36:46.0992 2468 Null - ok
18:36:47.0026 2468 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
18:36:47.0034 2468 NVENETFD - ok
18:36:47.0056 2468 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
18:36:47.0069 2468 nvraid - ok
18:36:47.0090 2468 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
18:36:47.0094 2468 nvstor - ok
18:36:47.0117 2468 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
18:36:47.0119 2468 nv_agp - ok
18:36:47.0140 2468 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
18:36:47.0142 2468 ohci1394 - ok
18:36:47.0173 2468 OpenVPNService (ec322186d8fce3d632f3f597d67747dd) C:\Program Files\OpenVPN\bin\openvpnserv.exe
18:36:47.0175 2468 OpenVPNService - ok
18:36:47.0205 2468 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:36:47.0209 2468 ose - ok
18:36:47.0477 2468 osppsvc (358a9cca612c68eb2f07ddad4ce1d8d7) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:36:47.0554 2468 osppsvc - ok
18:36:47.0626 2468 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
18:36:47.0635 2468 p2pimsvc - ok
18:36:47.0669 2468 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll
18:36:47.0737 2468 p2psvc - ok
18:36:47.0761 2468 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
18:36:47.0763 2468 Parport - ok
18:36:47.0783 2468 partmgr (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys
18:36:47.0785 2468 partmgr - ok
18:36:47.0802 2468 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
18:36:47.0803 2468 Parvdm - ok
18:36:47.0826 2468 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll
18:36:47.0831 2468 PcaSvc - ok
18:36:47.0857 2468 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
18:36:47.0860 2468 pci - ok
18:36:47.0877 2468 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
18:36:47.0878 2468 pciide - ok
18:36:47.0903 2468 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\drivers\pcmcia.sys
18:36:47.0908 2468 pcmcia - ok
18:36:47.0926 2468 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
18:36:47.0927 2468 pcw - ok
18:36:47.0966 2468 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
18:36:47.0979 2468 PEAUTH - ok
18:36:48.0035 2468 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll
18:36:48.0121 2468 PeerDistSvc - ok
18:36:48.0235 2468 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll
18:36:48.0263 2468 pla - ok
18:36:48.0323 2468 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll
18:36:48.0331 2468 PlugPlay - ok
18:36:48.0355 2468 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll
18:36:48.0358 2468 PNRPAutoReg - ok
18:36:48.0391 2468 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
18:36:48.0396 2468 PNRPsvc - ok
18:36:48.0427 2468 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll
18:36:48.0433 2468 PolicyAgent - ok
18:36:48.0461 2468 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll
18:36:48.0469 2468 Power - ok
18:36:48.0509 2468 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
18:36:48.0512 2468 PptpMiniport - ok
18:36:48.0530 2468 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\drivers\processr.sys
18:36:48.0535 2468 Processor - ok
18:36:48.0558 2468 ProfSvc (cadefac453040e370a1bdff3973be00d) C:\Windows\system32\profsvc.dll
18:36:48.0564 2468 ProfSvc - ok
18:36:48.0581 2468 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
18:36:48.0585 2468 ProtectedStorage - ok
18:36:48.0611 2468 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
18:36:48.0613 2468 Psched - ok
18:36:48.0688 2468 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\drivers\ql2300.sys
18:36:48.0711 2468 ql2300 - ok
18:36:48.0787 2468 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\drivers\ql40xx.sys
18:36:48.0791 2468 ql40xx - ok
18:36:48.0870 2468 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll
18:36:48.0877 2468 QWAVE - ok
18:36:48.0895 2468 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
18:36:48.0896 2468 QWAVEdrv - ok
18:36:48.0913 2468 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
18:36:48.0914 2468 RasAcd - ok
18:36:48.0935 2468 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
18:36:48.0937 2468 RasAgileVpn - ok
18:36:48.0961 2468 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll
18:36:48.0968 2468 RasAuto - ok
18:36:48.0993 2468 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
18:36:48.0995 2468 Rasl2tp - ok
18:36:49.0029 2468 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll
18:36:49.0040 2468 RasMan - ok
18:36:49.0060 2468 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
18:36:49.0063 2468 RasPppoe - ok
18:36:49.0091 2468 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
18:36:49.0094 2468 RasSstp - ok
18:36:49.0125 2468 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
18:36:49.0130 2468 rdbss - ok
18:36:49.0148 2468 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
18:36:49.0151 2468 rdpbus - ok
18:36:49.0168 2468 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
18:36:49.0169 2468 RDPCDD - ok
18:36:49.0204 2468 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
18:36:49.0208 2468 RDPDR - ok
18:36:49.0226 2468 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
18:36:49.0227 2468 RDPENCDD - ok
18:36:49.0257 2468 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
18:36:49.0258 2468 RDPREFMP - ok
18:36:49.0289 2468 RDPWD (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys
18:36:49.0295 2468 RDPWD - ok
18:36:49.0323 2468 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
18:36:49.0326 2468 rdyboost - ok
18:36:49.0347 2468 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll
18:36:49.0353 2468 RemoteAccess - ok
18:36:49.0373 2468 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll
18:36:49.0378 2468 RemoteRegistry - ok
18:36:49.0404 2468 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll
18:36:49.0408 2468 RpcEptMapper - ok
18:36:49.0447 2468 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe
18:36:49.0452 2468 RpcLocator - ok
18:36:49.0484 2468 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
18:36:49.0490 2468 RpcSs - ok
18:36:49.0516 2468 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
18:36:49.0520 2468 rspndr - ok
18:36:49.0556 2468 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
18:36:49.0559 2468 RTL8167 - ok
18:36:49.0576 2468 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
18:36:49.0578 2468 s3cap - ok
18:36:49.0596 2468 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
18:36:49.0600 2468 SamSs - ok
18:36:49.0621 2468 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
18:36:49.0624 2468 sbp2port - ok
18:36:49.0732 2468 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll
18:36:49.0743 2468 SCardSvr - ok
18:36:49.0763 2468 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
18:36:49.0765 2468 scfilter - ok
18:36:49.0820 2468 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll
18:36:49.0836 2468 Schedule - ok
18:36:49.0861 2468 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
18:36:49.0863 2468 SCPolicySvc - ok
18:36:49.0892 2468 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll
18:36:49.0898 2468 SDRSVC - ok
18:36:49.0916 2468 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
18:36:49.0918 2468 secdrv - ok
18:36:49.0937 2468 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll
18:36:49.0940 2468 seclogon - ok
18:36:49.0959 2468 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll
18:36:49.0963 2468 SENS - ok
18:36:49.0989 2468 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll
18:36:49.0994 2468 SensrSvc - ok
18:36:50.0012 2468 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
18:36:50.0014 2468 Serenum - ok
18:36:50.0034 2468 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
18:36:50.0036 2468 Serial - ok
18:36:50.0059 2468 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\drivers\sermouse.sys
18:36:50.0061 2468 sermouse - ok
18:36:50.0185 2468 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll
18:36:50.0194 2468 SessionEnv - ok
18:36:50.0214 2468 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
18:36:50.0218 2468 sffdisk - ok
18:36:50.0239 2468 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
18:36:50.0241 2468 sffp_mmc - ok
18:36:50.0258 2468 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
18:36:50.0260 2468 sffp_sd - ok
18:36:50.0277 2468 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\drivers\sfloppy.sys
18:36:50.0278 2468 sfloppy - ok
18:36:50.0314 2468 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll
18:36:50.0327 2468 SharedAccess - ok
18:36:50.0363 2468 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll
18:36:50.0373 2468 ShellHWDetection - ok
18:36:50.0393 2468 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
18:36:50.0395 2468 sisagp - ok
18:36:50.0414 2468 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\drivers\SiSRaid2.sys
18:36:50.0418 2468 SiSRaid2 - ok
18:36:50.0445 2468 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\drivers\sisraid4.sys
18:36:50.0446 2468 SiSRaid4 - ok
18:36:50.0470 2468 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
18:36:50.0473 2468 Smb - ok
18:36:50.0510 2468 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe
18:36:50.0513 2468 SNMPTRAP - ok
18:36:50.0531 2468 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
18:36:50.0532 2468 spldr - ok
18:36:50.0672 2468 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe
18:36:50.0678 2468 Spooler - ok
18:36:50.0827 2468 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe
18:36:50.0884 2468 sppsvc - ok
18:36:50.0939 2468 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll
18:36:50.0980 2468 sppuinotify - ok
18:36:51.0011 2468 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
18:36:51.0018 2468 srv - ok
18:36:51.0046 2468 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
18:36:51.0053 2468 srv2 - ok
18:36:51.0073 2468 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
18:36:51.0076 2468 srvnet - ok
18:36:51.0107 2468 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll
18:36:51.0111 2468 SSDPSRV - ok
18:36:51.0129 2468 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll
18:36:51.0137 2468 SstpSvc - ok
18:36:51.0154 2468 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\drivers\stexstor.sys
18:36:51.0156 2468 stexstor - ok
18:36:51.0192 2468 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll
18:36:51.0204 2468 StiSvc - ok
18:36:51.0223 2468 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
18:36:51.0224 2468 storflt - ok
18:36:51.0241 2468 StorSvc (0bf669f0a910beda4a32258d363af2a5) C:\Windows\system32\storsvc.dll
18:36:51.0245 2468 StorSvc - ok
18:36:51.0263 2468 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
18:36:51.0267 2468 storvsc - ok
18:36:51.0284 2468 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
18:36:51.0285 2468 swenum - ok
18:36:51.0376 2468 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll
18:36:51.0384 2468 swprv - ok
18:36:51.0437 2468 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll
18:36:51.0460 2468 SysMain - ok
18:36:51.0487 2468 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll
18:36:51.0491 2468 TabletInputService - ok
18:36:51.0521 2468 tap0901 (8cf6e2ae1707d82e904ecca68cef8b87) C:\Windows\system32\DRIVERS\tap0901.sys
18:36:51.0522 2468 tap0901 - ok
18:36:51.0550 2468 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll
18:36:51.0559 2468 TapiSrv - ok
18:36:51.0578 2468 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll
18:36:51.0584 2468 TBS - ok
18:36:51.0706 2468 Tcpip (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys
18:36:51.0728 2468 Tcpip - ok
18:36:51.0758 2468 TCPIP6 (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys
18:36:51.0770 2468 TCPIP6 - ok
18:36:51.0795 2468 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
18:36:51.0796 2468 tcpipreg - ok
18:36:51.0823 2468 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
18:36:51.0825 2468 TDPIPE - ok
18:36:51.0844 2468 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys
18:36:51.0846 2468 TDTCP - ok
18:36:51.0867 2468 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
18:36:51.0869 2468 tdx - ok
18:36:51.0888 2468 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\DRIVERS\termdd.sys
18:36:51.0890 2468 TermDD - ok
18:36:51.0926 2468 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll
18:36:51.0944 2468 TermService - ok
18:36:51.0961 2468 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll
18:36:52.0070 2468 Themes - ok
18:36:52.0088 2468 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
18:36:52.0091 2468 THREADORDER - ok
18:36:52.0111 2468 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll
18:36:52.0117 2468 TrkWks - ok
18:36:52.0140 2468 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe
18:36:52.0143 2468 TrustedInstaller - ok
18:36:52.0168 2468 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
18:36:52.0169 2468 tssecsrv - ok
18:36:52.0189 2468 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
18:36:52.0190 2468 TsUsbFlt - ok
18:36:52.0209 2468 TsUsbGD (01246f0baad7b68ec0f472aa41e33282) C:\Windows\system32\drivers\TsUsbGD.sys
18:36:52.0211 2468 TsUsbGD - ok
18:36:52.0231 2468 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
18:36:52.0236 2468 tunnel - ok
18:36:52.0251 2468 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\drivers\uagp35.sys
18:36:52.0253 2468 uagp35 - ok
18:36:52.0276 2468 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
18:36:52.0283 2468 udfs - ok
18:36:52.0316 2468 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe
18:36:52.0320 2468 UI0Detect - ok
18:36:52.0339 2468 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
18:36:52.0341 2468 uliagpkx - ok
18:36:52.0361 2468 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\DRIVERS\umbus.sys
18:36:52.0361 2468 umbus - ok
18:36:52.0378 2468 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\drivers\umpass.sys
18:36:52.0380 2468 UmPass - ok
18:36:52.0404 2468 UmRdpService (409994a8eaceee4e328749c0353527a0) C:\Windows\System32\umrdp.dll
18:36:52.0531 2468 UmRdpService - ok
18:36:52.0559 2468 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll
18:36:52.0566 2468 upnphost - ok
18:36:52.0586 2468 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\drivers\usbccgp.sys
18:36:52.0589 2468 usbccgp - ok
18:36:52.0609 2468 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
18:36:52.0611 2468 usbcir - ok
18:36:52.0629 2468 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
18:36:52.0631 2468 usbehci - ok
18:36:52.0658 2468 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
18:36:52.0665 2468 usbhub - ok
18:36:52.0681 2468 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
18:36:52.0685 2468 usbohci - ok
18:36:52.0701 2468 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\drivers\usbprint.sys
18:36:52.0704 2468 usbprint - ok
18:36:52.0724 2468 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:36:52.0726 2468 USBSTOR - ok
18:36:52.0744 2468 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
18:36:52.0746 2468 usbuhci - ok
18:36:52.0767 2468 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll
18:36:52.0771 2468 UxSms - ok
18:36:52.0789 2468 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
18:36:52.0791 2468 VaultSvc - ok
18:36:52.0810 2468 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
18:36:52.0811 2468 vdrvroot - ok
18:36:52.0847 2468 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe
18:36:52.0959 2468 vds - ok
18:36:52.0978 2468 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
18:36:52.0980 2468 vga - ok
18:36:53.0000 2468 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
18:36:53.0001 2468 VgaSave - ok
18:36:53.0025 2468 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
18:36:53.0028 2468 vhdmp - ok
18:36:53.0050 2468 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
18:36:53.0052 2468 viaagp - ok
18:36:53.0071 2468 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\drivers\viac7.sys
18:36:53.0074 2468 ViaC7 - ok
18:36:53.0091 2468 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
18:36:53.0093 2468 viaide - ok
18:36:53.0213 2468 VMAuthdService (3accf0c817a2bb34efbfb72b57b00252) D:\virtualni masina\vmware-authd.exe
18:36:53.0216 2468 VMAuthdService - ok
18:36:53.0239 2468 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
18:36:53.0244 2468 vmbus - ok
18:36:53.0260 2468 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
18:36:53.0262 2468 VMBusHID - ok
18:36:53.0286 2468 vmci (15759158f7531853616b2b43af962fcb) C:\Windows\system32\DRIVERS\vmci.sys
18:36:53.0288 2468 vmci - ok
18:36:53.0307 2468 vmkbd (e5fa574436b840d071dbfe74300741ce) C:\Windows\system32\drivers\VMkbd.sys
18:36:53.0308 2468 vmkbd - ok
18:36:53.0326 2468 VMnetAdapter (1afa4af55cbea579a4bbe4f90967f720) C:\Windows\system32\DRIVERS\vmnetadapter.sys
18:36:53.0327 2468 VMnetAdapter - ok
18:36:53.0346 2468 VMnetBridge (392964a7bf46986fbd44b24a3bec2088) C:\Windows\system32\DRIVERS\vmnetbridge.sys
18:36:53.0349 2468 VMnetBridge - ok
18:36:53.0387 2468 VMnetDHCP (6f5fe74a4713290e6309b45904403798) C:\Windows\system32\vmnetdhcp.exe
18:36:53.0395 2468 VMnetDHCP - ok
18:36:53.0411 2468 VMnetuserif (c88e5f414c567ff10343df18f8c3e3f0) C:\Windows\system32\drivers\vmnetuserif.sys
18:36:53.0412 2468 VMnetuserif - ok
18:36:53.0430 2468 VMparport (cda57c86108ac6e11273f8cbd2ae83fc) C:\Windows\system32\Drivers\VMparport.sys
18:36:53.0432 2468 VMparport - ok
18:36:53.0577 2468 VMUSBArbService (af76c6d3f5053459e18e4c519fb496c8) C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
18:36:53.0587 2468 VMUSBArbService - ok
18:36:53.0628 2468 VMware NAT Service (5cc206036b6648cd3990d77e5117e1d9) C:\Windows\system32\vmnat.exe
18:36:53.0642 2468 VMware NAT Service - ok
18:36:53.0668 2468 vmx86 (847909a1fc0c8eb46ff975747d673a7f) C:\Windows\system32\Drivers\vmx86.sys
18:36:53.0669 2468 vmx86 - ok
18:36:53.0694 2468 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
18:36:53.0695 2468 volmgr - ok
18:36:53.0724 2468 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
18:36:53.0729 2468 volmgrx - ok
18:36:53.0756 2468 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
18:36:53.0761 2468 volsnap - ok
18:36:53.0789 2468 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\drivers\vsmraid.sys
18:36:53.0793 2468 vsmraid - ok
18:36:53.0853 2468 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe
18:36:53.0939 2468 VSS - ok
18:36:53.0956 2468 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
18:36:53.0958 2468 vwifibus - ok
18:36:53.0987 2468 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll
18:36:53.0995 2468 W32Time - ok
18:36:54.0021 2468 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\drivers\wacompen.sys
18:36:54.0023 2468 WacomPen - ok
18:36:54.0048 2468 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
18:36:54.0053 2468 WANARP - ok
18:36:54.0069 2468 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
18:36:54.0070 2468 Wanarpv6 - ok
18:36:54.0139 2468 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe
18:36:54.0174 2468 WatAdminSvc - ok
18:36:54.0236 2468 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe
18:36:54.0319 2468 wbengine - ok
18:36:54.0342 2468 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll
18:36:54.0350 2468 WbioSrvc - ok
18:36:54.0377 2468 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll
18:36:54.0389 2468 wcncsvc - ok
18:36:54.0407 2468 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll
18:36:54.0411 2468 WcsPlugInService - ok
18:36:54.0435 2468 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\drivers\wd.sys
18:36:54.0437 2468 Wd - ok
18:36:54.0476 2468 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
18:36:54.0486 2468 Wdf01000 - ok
18:36:54.0506 2468 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
18:36:54.0510 2468 WdiServiceHost - ok
18:36:54.0526 2468 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
18:36:54.0529 2468 WdiSystemHost - ok
18:36:54.0555 2468 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll
18:36:54.0563 2468 WebClient - ok
18:36:54.0653 2468 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll
18:36:54.0661 2468 Wecsvc - ok
18:36:54.0688 2468 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll
18:36:54.0692 2468 wercplsupport - ok
18:36:54.0719 2468 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll
18:36:54.0724 2468 WerSvc - ok
18:36:54.0741 2468 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
18:36:54.0743 2468 WfpLwf - ok
18:36:54.0761 2468 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
18:36:54.0763 2468 WIMMount - ok
18:36:54.0818 2468 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll
18:36:54.0828 2468 WinDefend - ok
18:36:54.0849 2468 WinHttpAutoProxySvc - ok
18:36:54.0879 2468 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll
18:36:54.0884 2468 Winmgmt - ok
18:36:54.0955 2468 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll
18:36:55.0033 2468 WinRM - ok
18:36:55.0097 2468 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll
18:36:55.0114 2468 Wlansvc - ok
18:36:55.0136 2468 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
18:36:55.0138 2468 WmiAcpi - ok
18:36:55.0173 2468 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe
18:36:55.0176 2468 wmiApSrv - ok
18:36:55.0241 2468 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe
18:36:55.0252 2468 WMPNetworkSvc - ok
18:36:55.0271 2468 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll
18:36:55.0275 2468 WPCSvc - ok
18:36:55.0295 2468 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll
18:36:55.0303 2468 WPDBusEnum - ok
18:36:55.0323 2468 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
18:36:55.0325 2468 ws2ifsl - ok
18:36:55.0344 2468 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\System32\wscsvc.dll
18:36:55.0351 2468 wscsvc - ok
18:36:55.0367 2468 WSearch - ok
18:36:55.0550 2468 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
18:36:55.0589 2468 wuauserv - ok
18:36:55.0645 2468 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
18:36:55.0649 2468 WudfPf - ok
18:36:55.0677 2468 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
18:36:55.0683 2468 WUDFRd - ok
18:36:55.0707 2468 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll
18:36:55.0713 2468 wudfsvc - ok
18:36:55.0752 2468 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll
18:36:55.0760 2468 WwanSvc - ok
18:36:55.0828 2468 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
18:36:55.0994 2468 \Device\Harddisk0\DR0 - ok
18:36:56.0011 2468 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
18:36:56.0165 2468 \Device\Harddisk1\DR1 - ok
18:36:56.0176 2468 Boot (0x1200) (1027c53222aa742ba2f5a023d331f0dd) \Device\Harddisk0\DR0\Partition0
18:36:56.0178 2468 \Device\Harddisk0\DR0\Partition0 - ok
18:36:56.0195 2468 Boot (0x1200) (4bf2debb0d9168607fb66a19a256b880) \Device\Harddisk1\DR1\Partition0
18:36:56.0199 2468 \Device\Harddisk1\DR1\Partition0 - ok
18:36:56.0217 2468 Boot (0x1200) (8f9786cf1e62702e722d0b11cdd98cc4) \Device\Harddisk1\DR1\Partition1
18:36:56.0219 2468 \Device\Harddisk1\DR1\Partition1 - ok
18:36:56.0225 2468 ============================================================
18:36:56.0225 2468 Scan finished
18:36:56.0225 2468 ============================================================
18:36:56.0251 3332 Detected object count: 0
18:36:56.0251 3332 Actual detected object count: 0

olhor
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 09 dub 2006 11:13

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#6 Příspěvek od olhor »

Malware bites log
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.61.0.1400
www.malwarebytes.org

Verze databáze: v2012.07.08.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Olhor :: OLHOR-PC [administrátor]

Ochrana: Povolena

8.7.2012 18:45:34
mbam-log-2012-07-08 (18-45-34).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 197892
Uplynulý čas: 3 minut, 51 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

olhor
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 09 dub 2006 11:13

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#7 Příspěvek od olhor »

ESS jsem zastavil ale tim to neni, na notebooku ho mam taky a jde to
Chrome jsem taky zkusil ale neumi me autentifikovat.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15699
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Po prihlaseni do int. bankovnictvi se PC restartuje

#8 Příspěvek od JaRon »

nuz na AV problem to nevypada, najprv skusime velke cistenie - moze/nemusi pomoct :)
citat:
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
• Stahnete a spustte
• Pro potvrzeni volby mackejte A, Enter
• Po pouziti utilitu smazte
• Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

OTC http://oldtimer.geekstogo.com/OTC.exe
• Stahnete a spustte
• Kliknete na CleanUp a potvrdte YES
• Program uklidi a restartuje PC

TFC http://oldtimer.geekstogo.com/TFC.exe
• Stahnete a spustte
• Kliknete na Start a potvrdte OK
• Program uklidi a restartuje pc
• Po pouziti utilitu smazte

Stahnete Ccleaner (viz muj podpis)
Panel čistič
• Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
• dejte Hledej problémy
• nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
• postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
• Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

+ vloz obsah adresara minidump - ak sa v nom nachadzaju subory
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět