Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Win32:Hupigon-ONX, Patched-HO

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Win32:Hupigon-ONX, Patched-HO

#1 Příspěvek od liborolomouc »

Dobrý den,
Avast Internet Security mi hlásí Win32:Hupigon-ONX.trj v c:hiberfil.sys a Win32:Patched-HO.trj v D:pagefilesys. Antivir to sám opravit nedokáže. Mám W7 i antivir aktualizovaný. Poradíte prosím jak infekce odstranit? Rovnou dávám log z RSIT (jestli jsou tam nějaký zbytečný řádky, příště je nedám):
Dík, Libor

Logfile of random's system information tool 1.09 (written by random/random)
Run by Libor at 2012-10-14 14:05:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 30 GB (60%) free of 50 GB
Total RAM: 2047 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:06:18, on 14.10.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Downloads\RSIT.exe
C:\Program Files\trend micro\Libor.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000. ... 13D3289CEC}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6590 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Libor\AppData\Roaming\Mozilla\Firefox\Profiles\j73xd8cn.default

prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "keyword.URL" - "http://search.sweetim.com/search.asp?sr ... 0.10005&q="

"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/wpi,version=1.4]
"Description"=
"Path"=C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Libor\AppData\Roaming\Mozilla\Firefox\Profiles\j73xd8cn.default\searchplugins\
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-01 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-01 157672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"=C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2009-06-14 307200]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"SoundMan"=C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-08-21 4282728]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-04-14 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-01-24 2289664]

C:\Users\Libor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-10-14 14:05:53 ----D---- C:\rsit
2012-10-14 14:05:53 ----D---- C:\Program Files\trend micro
2012-10-10 18:08:04 ----A---- C:\Windows\system32\wintrust.dll
2012-10-10 18:07:56 ----A---- C:\Windows\system32\tzres.dll
2012-10-10 18:07:33 ----A---- C:\Windows\system32\KernelBase.dll
2012-10-10 18:07:33 ----A---- C:\Windows\system32\kernel32.dll
2012-10-10 18:07:32 ----A---- C:\Windows\system32\winsrv.dll
2012-10-10 18:07:32 ----A---- C:\Windows\system32\conhost.exe
2012-10-10 18:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-10-10 18:07:30 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-10-10 18:07:29 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-10-10 18:07:28 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-10-10 18:07:28 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-10-10 18:07:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-10-10 18:07:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-10-10 18:07:23 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-10-10 18:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-10 18:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-10-10 18:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-10 18:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-10-10 18:07:22 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-10-10 18:07:00 ----A---- C:\Windows\system32\crypt32.dll
2012-10-10 18:06:59 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-10 18:06:59 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-10 18:06:27 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-10-10 18:06:26 ----A---- C:\Windows\system32\kerberos.dll
2012-10-10 18:06:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-10 18:06:14 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-09-28 21:50:37 ----A---- C:\Windows\system32\OxpsConverter.exe
2012-09-21 22:00:53 ----A---- C:\Windows\system32\mshtmled.dll
2012-09-21 22:00:52 ----A---- C:\Windows\system32\vbscript.dll
2012-09-21 22:00:52 ----A---- C:\Windows\system32\jsproxy.dll
2012-09-21 22:00:51 ----A---- C:\Windows\system32\msfeeds.dll
2012-09-21 22:00:51 ----A---- C:\Windows\system32\ieUnatt.exe
2012-09-21 22:00:51 ----A---- C:\Windows\system32\ieui.dll
2012-09-21 22:00:50 ----A---- C:\Windows\system32\wininet.dll
2012-09-21 22:00:50 ----A---- C:\Windows\system32\jscript.dll
2012-09-21 22:00:49 ----A---- C:\Windows\system32\jscript9.dll
2012-09-21 22:00:48 ----A---- C:\Windows\system32\url.dll
2012-09-21 22:00:47 ----A---- C:\Windows\system32\iertutil.dll
2012-09-21 22:00:46 ----A---- C:\Windows\system32\urlmon.dll
2012-09-21 22:00:43 ----A---- C:\Windows\system32\ieframe.dll
2012-09-21 22:00:42 ----A---- C:\Windows\system32\mshtml.dll
2012-09-18 22:36:30 ----D---- C:\Program Files\CDA Converter Plus

======List of files/folders modified in the last 1 month======

2012-10-14 14:06:02 ----D---- C:\Windows\Temp
2012-10-14 14:05:53 ----RD---- C:\Program Files
2012-10-14 14:01:59 ----D---- C:\Windows
2012-10-14 14:01:08 ----D---- C:\Windows\system32\config
2012-10-14 13:58:42 ----D---- C:\Windows\inf
2012-10-14 13:58:41 ----D---- C:\Windows\debug
2012-10-14 13:52:41 ----D---- C:\Windows\system32\Tasks
2012-10-14 13:52:38 ----D---- C:\Program Files\CCleaner
2012-10-14 12:28:47 ----D---- C:\Windows\Prefetch
2012-10-14 12:28:23 ----D---- C:\Windows\system32\drivers
2012-10-13 21:27:01 ----D---- C:\Windows\rescache
2012-10-13 17:54:18 ----D---- C:\Users\Libor\AppData\Roaming\Skype
2012-10-10 18:28:40 ----D---- C:\Windows\winsxs
2012-10-10 18:26:44 ----D---- C:\Windows\system32\cs-CZ
2012-10-10 18:26:44 ----D---- C:\Windows\System32
2012-10-10 18:06:12 ----D---- C:\Windows\system32\catroot2
2012-10-10 18:06:12 ----D---- C:\Windows\system32\catroot
2012-10-09 18:21:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-10-05 23:19:11 ----D---- C:\Users\Libor\AppData\Roaming\vlc
2012-09-28 00:32:12 ----A---- C:\Windows\system32\MRT.exe
2012-09-25 18:26:02 ----SHD---- C:\Windows\Installer
2012-09-25 17:59:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-09-23 13:28:20 ----D---- C:\Users\Libor\AppData\Roaming\dvdcss
2012-09-21 22:02:25 ----D---- C:\Windows\system32\migration
2012-09-21 22:02:25 ----D---- C:\Program Files\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-03-07 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-08-21 202928]
R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-08-21 113776]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-08-21 18544]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-08-21 44784]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-14 43008]
S2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 cpuz132;cpuz132; \??\C:\Users\Libor\AppData\Local\Temp\cpuz132\cpuz132_x32.sys []
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RkHit;RkHit; \??\C:\Windows\system32\drivers\RKHit.sys []
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-08-21 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe [2012-08-21 133912]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-01-24 73728]
R2 MsDepSvc;Web Deployment Agent Service; C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-13 135664]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-10-10 194104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-13 135664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-09 1343400]

-----------------EOF-----------------

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#2 Příspěvek od liborolomouc »

Ahoj a dík za ochotu,
připojuju report z Combofixu a jdu na to livecd a to co píšeš.

ComboFix 12-10-14.03 - Libor 14.10.2012 16:58:05.1.1 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2047.1271 [GMT 2:00]
SpuÜtýnř z: c:\users\Libor\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvo°en novř Bod ObnovenÝ
.
.
((((((((((((((((((((((((((((((((((((((( OstatnÝ vřmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((((((((((((((((( OvladaŔe/Slu×by )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Service_RkHit
.
.
((((((((((((((((((((((((( Soubory vytvo°enÚ od 2012-09-14 do 2012-10-14 )))))))))))))))))))))))))))))))
.
.
2012-10-14 15:06 . 2012-10-14 15:09 -------- d-----w- c:\users\Libor\AppData\Local\temp
2012-10-14 12:42 . 2012-10-14 12:42 96224 ----a-w- c:\program files\Mozilla Firefox\updated\webapprt-stub.exe
2012-10-14 12:40 . 2012-10-14 12:40 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8285E64F-654A-4FA5-98CA-35F930D38530}\offreg.dll
2012-10-14 12:05 . 2012-10-14 12:06 -------- d-----w- C:\rsit
2012-10-14 12:05 . 2012-10-14 12:06 -------- d-----w- c:\program files\trend micro
2012-10-13 07:44 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8285E64F-654A-4FA5-98CA-35F930D38530}\mpengine.dll
2012-10-10 16:08 . 2012-08-24 16:57 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 16:06 . 2012-06-02 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 16:06 . 2012-06-02 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 16:06 . 2012-08-31 17:18 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-10-10 16:06 . 2012-08-10 23:56 542208 ----a-w- c:\windows\system32\kerberos.dll
2012-10-10 16:06 . 2012-08-30 17:12 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-10 16:06 . 2012-08-30 17:12 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-09-28 19:50 . 2012-08-21 20:12 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-18 20:36 . 2012-09-19 04:04 -------- d-----w- c:\program files\CDA Converter Plus
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M vřpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-09 16:21 . 2012-09-01 18:47 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 16:21 . 2012-02-29 19:21 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-01 18:38 . 2012-09-01 18:38 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-01 18:38 . 2012-06-18 21:43 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-01 18:38 . 2010-04-19 18:55 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-22 17:16 . 2012-09-12 16:00 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 17:16 . 2012-09-12 16:00 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 17:16 . 2012-09-12 16:00 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 17:16 . 2012-09-12 16:00 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 09:13 . 2011-03-07 15:44 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2010-06-16 19:44 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2010-06-16 19:44 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-05-06 19:48 202928 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-08-21 09:13 . 2012-05-06 19:48 18544 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-08-21 09:13 . 2012-02-25 07:29 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2010-06-16 19:44 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2012-05-06 19:48 113776 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-08-21 09:13 . 2010-06-16 19:44 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2010-07-01 15:00 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2010-06-16 19:44 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-02 16:57 . 2012-09-12 16:00 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-07-18 17:47 . 2012-08-16 04:09 2345984 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 20:51 . 2011-11-13 12:06 3511776 ----a-w- c:\program files\ccsetup312.exe
2011-09-30 17:30 . 2011-09-30 17:37 13886544 ----a-w- c:\program files\Firefox Setup 7.0.1.exe
2011-03-31 14:25 . 2011-04-09 12:16 1033520 ----a-w- c:\program files\IE9-Windows7-x86-csy.exe
2009-12-07 06:25 . 2009-12-07 17:14 3211616 ----a-w- c:\program files\tcmd750a.exe
2012-09-07 21:19 . 2012-09-07 21:19 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( SpouÜtýcÝ body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznßmka* prßzdnÚ zßznamy a legitimnÝ vřchozÝ ˙daje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-14 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2009-06-14 307200]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-08-21 4282728]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-15 384512]
.
c:\users\Libor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-15 384512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-06-27 17:03 152872 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 11:32 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R2 gupdate;Slu×ba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Slu×ba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Slu×ba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [x]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [x]
S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 11:30 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresß°e 'NaplßnovanÚ ˙lohy'
.
2012-10-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 16:21]
.
2012-10-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-04-14 16:59]
.
2012-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 21:10]
.
2012-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 21:10]
.
.
------- Dopl˛kovř sken -------
.
uStart Page = hxxp://www.google.cz/
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10005&barid={7C74F617-F466-11E1-98B1-0013D3289CEC}
IE: ????3?? - c:\users\Libor\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Libor\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
Trusted Zone: csob.cz\ib24
Trusted Zone: kuaiche.com\software
TCP: DhcpNameServer = 178.17.80.66 178.17.80.67
FF - ProfilePath - c:\users\Libor\AppData\Roaming\Mozilla\Firefox\Profiles\j73xd8cn.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&crg=3.1010000.10005&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATN╔ POLOÄKY ODSTRAN╠N╔ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
.
--------------------- ZAMKNUT╔ KL═╚E V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2925927421-2149105454-134573018-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uŰ_fĆ3*N}Ć]
@="c:\\Users\\Libor\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2925927421-2149105454-134573018-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uŰ_fĆ3*N}ĆhQŔÉ■öąc]
@="c:\\Users\\Libor\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ JinÚ spuÜtenÚ procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\SOUNDMAN.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkovř Ŕas: 2012-10-14 17:13:12 - poŔÝtaŔ byl restartovßn
ComboFix-quarantined-files.txt 2012-10-14 15:13
.
P°ed spuÜtýnÝm: Volnřch bajt¨: 31á426á424á832
Po spuÜtýnÝ: Volnřch bajt¨: 31á336á091á648
.
- - End Of File - - E5C49113247BA7F29A25E8EB4A1DB094

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#3 Příspěvek od liborolomouc »

No, chvíli to trvalo, ale:
- NOD jsem tvým návodem smazal (netušil jsem, že tam jeho zbytek zůstal)
- pomocí livecd smazány ty 2 soubory (mazal jsem Deletem, ne Shift+Del a dělal jsem to ve zkušebním režimu bez instalace Ubuntu namísto/vedle stávajících W7)
- nerozuměl jsem tomu "luftl" v BTW, ale jestli to není podstatný, tak se nezdržuj vysvětlováním

Zatím zdar, Libor

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#4 Příspěvek od liborolomouc »

AV zase hlásí tutéž havěť, ale tentokrát v jiném umístění:
c:\.Trash-999\files\ je ten Hupigon
d:\.Trash-999\files\ je ten Patch
Jsou to adresáře, které tam dřív nebyly.....

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#5 Příspěvek od liborolomouc »

Udělal jsem co píšeš, dávám logy z USBFix i z TDSSKiller. AV aktualizován program, jádro i vir.databáze, spouštím teď.

Log z USBFix:
############################## | UsbFix 7.059 | [Research]

User: Libor (Administrator) # LAP [ ]
Updated 16/09/2011 by El Desaparecido
Started at 18:17:21 | 15/10/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com

CPU: AMD Athlon(tm) 64 Processor 3000+
Microsoft Windows 7 Home Premium (6.1.7601 32-Bit) # Service Pack 1
Internet Explorer 9.0.8112.16421

Windows Firewall: Enabled
RAM -> 2047 Mb
C:\ (%systemdrive%) -> Fixed drive # 49 Gb (29 Mb free - 60%) [] # NTFS
D:\ -> Fixed drive # 249 Gb (193 Mb free - 78%) [FUN] # NTFS
E:\ -> CD-ROM
F:\ -> Removable drive # 8 Gb (8 Mb free - 100%) [] # FAT32
G:\ -> Removable drive # 984 Mb (387 Mb free - 39%) [] # FAT

################## | Files # Infected Folders |

Found ! C:\ESETUninstaller.exe
Found ! C:\Windows\system32\secushr.dat
Found ! D:\RECYCLER\S-1-5-21-789336058-1708537768-839522115-1003
Found ! D:\RECYCLER\S-1-5-21-789336058-1708537768-839522115-1004

################## | Registry |

Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

################## | Mountpoints2 |


################## | Vaccin |

(!) This computer is not vaccinated!

################## | E.O.F |



Log z TDSSKiller:

18:26:34.0106 1664 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
18:26:36.0122 1664 ============================================================
18:26:36.0122 1664 Current date / time: 2012/10/15 18:26:36.0122
18:26:36.0122 1664 SystemInfo:
18:26:36.0122 1664
18:26:36.0122 1664 OS Version: 6.1.7601 ServicePack: 1.0
18:26:36.0122 1664 Product type: Workstation
18:26:36.0122 1664 ComputerName: LAP
18:26:36.0512 1664 UserName: Libor
18:26:36.0512 1664 Windows directory: C:\Windows
18:26:36.0512 1664 System windows directory: C:\Windows
18:26:36.0512 1664 Processor architecture: Intel x86
18:26:36.0512 1664 Number of processors: 1
18:26:36.0512 1664 Page size: 0x1000
18:26:36.0512 1664 Boot type: Normal boot
18:26:36.0512 1664 ============================================================
18:26:37.0184 1664 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:26:37.0309 1664 ============================================================
18:26:37.0309 1664 \Device\Harddisk0\DR0:
18:26:37.0309 1664 MBR partitions:
18:26:37.0309 1664 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x61A7927
18:26:37.0325 1664 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x61A79A5, BlocksNum 0x1F120E81
18:26:37.0325 1664 ============================================================
18:26:37.0356 1664 D: <-> \Device\Harddisk0\DR0\Partition2
18:26:37.0403 1664 C: <-> \Device\Harddisk0\DR0\Partition1
18:26:37.0403 1664 ============================================================
18:26:37.0403 1664 Initialize success
18:26:37.0403 1664 ============================================================
18:27:22.0043 3464 ============================================================
18:27:22.0043 3464 Scan started
18:27:22.0043 3464 Mode: Manual;
18:27:22.0043 3464 ============================================================
18:27:22.0387 3464 ================ Scan system memory ========================
18:27:22.0387 3464 System memory - ok
18:27:22.0387 3464 ================ Scan services =============================
18:27:22.0543 3464 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:27:22.0559 3464 1394ohci - ok
18:27:22.0622 3464 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:27:22.0637 3464 ACPI - ok
18:27:22.0668 3464 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:27:22.0684 3464 AcpiPmi - ok
18:27:22.0809 3464 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:27:22.0809 3464 AdobeARMservice - ok
18:27:22.0887 3464 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:27:22.0903 3464 AdobeFlashPlayerUpdateSvc - ok
18:27:22.0965 3464 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:27:22.0965 3464 adp94xx - ok
18:27:23.0012 3464 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:27:23.0012 3464 adpahci - ok
18:27:23.0043 3464 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:27:23.0059 3464 adpu320 - ok
18:27:23.0106 3464 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:27:23.0106 3464 AeLookupSvc - ok
18:27:23.0153 3464 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
18:27:23.0184 3464 AFD - ok
18:27:23.0215 3464 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
18:27:23.0215 3464 agp440 - ok
18:27:23.0262 3464 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
18:27:23.0262 3464 aic78xx - ok
18:27:23.0418 3464 [ 7997B6F02CBDA0E31FA18CC85871B938 ] ALCXWDM C:\Windows\system32\drivers\RTKVAC.SYS
18:27:23.0543 3464 ALCXWDM - ok
18:27:23.0606 3464 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
18:27:23.0606 3464 ALG - ok
18:27:23.0653 3464 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
18:27:23.0653 3464 aliide - ok
18:27:23.0684 3464 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:27:23.0684 3464 amdagp - ok
18:27:23.0700 3464 Scan interrupted by user!
18:27:23.0700 3464 ================ Scan global ===============================
18:27:23.0700 3464 Scan interrupted by user!
18:27:23.0700 3464 ================ Scan MBR ==================================
18:27:23.0700 3464 Scan interrupted by user!
18:27:23.0700 3464 ================ Scan VBR ==================================
18:27:23.0700 3464 Scan interrupted by user!
18:27:23.0700 3464 ============================================================
18:27:23.0700 3464 Scan finished
18:27:23.0700 3464 ============================================================
18:27:23.0731 1408 Detected object count: 0
18:27:23.0731 1408 Actual detected object count: 0
18:28:38.0393 3316 ============================================================
18:28:38.0393 3316 Scan started
18:28:38.0393 3316 Mode: Manual; SigCheck; TDLFS;
18:28:38.0393 3316 ============================================================
18:28:39.0206 3316 ================ Scan system memory ========================
18:28:39.0206 3316 System memory - ok
18:28:39.0221 3316 ================ Scan services =============================
18:28:39.0377 3316 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:28:39.0534 3316 1394ohci - ok
18:28:39.0581 3316 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:28:39.0612 3316 ACPI - ok
18:28:39.0659 3316 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:28:39.0706 3316 AcpiPmi - ok
18:28:39.0799 3316 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:28:39.0831 3316 AdobeARMservice - ok
18:28:39.0893 3316 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:28:39.0924 3316 AdobeFlashPlayerUpdateSvc - ok
18:28:39.0971 3316 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:28:40.0018 3316 adp94xx - ok
18:28:40.0065 3316 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:28:40.0096 3316 adpahci - ok
18:28:40.0127 3316 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:28:40.0159 3316 adpu320 - ok
18:28:40.0206 3316 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:28:40.0252 3316 AeLookupSvc - ok
18:28:40.0299 3316 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
18:28:40.0362 3316 AFD - ok
18:28:40.0409 3316 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
18:28:40.0424 3316 agp440 - ok
18:28:40.0471 3316 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
18:28:40.0502 3316 aic78xx - ok
18:28:40.0659 3316 [ 7997B6F02CBDA0E31FA18CC85871B938 ] ALCXWDM C:\Windows\system32\drivers\RTKVAC.SYS
18:28:40.0831 3316 ALCXWDM - ok
18:28:40.0862 3316 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
18:28:40.0893 3316 ALG - ok
18:28:40.0924 3316 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
18:28:40.0940 3316 aliide - ok
18:28:40.0956 3316 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:28:40.0987 3316 amdagp - ok
18:28:41.0002 3316 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
18:28:41.0018 3316 amdide - ok
18:28:41.0065 3316 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:28:41.0096 3316 AmdK8 - ok
18:28:41.0127 3316 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:28:41.0159 3316 AmdPPM - ok
18:28:41.0190 3316 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:28:41.0206 3316 amdsata - ok
18:28:41.0237 3316 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:28:41.0268 3316 amdsbs - ok
18:28:41.0315 3316 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:28:41.0346 3316 amdxata - ok
18:28:41.0393 3316 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
18:28:41.0471 3316 AppID - ok
18:28:41.0502 3316 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:28:41.0581 3316 AppIDSvc - ok
18:28:41.0627 3316 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
18:28:41.0706 3316 Appinfo - ok
18:28:41.0768 3316 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
18:28:41.0799 3316 arc - ok
18:28:41.0831 3316 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:28:41.0862 3316 arcsas - ok
18:28:41.0940 3316 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
18:28:41.0956 3316 aswFsBlk - ok
18:28:42.0018 3316 [ 09678587C5C70F91720631EF048B4744 ] aswFW C:\Windows\system32\drivers\aswFW.sys
18:28:42.0049 3316 aswFW - ok
18:28:42.0127 3316 [ 31E0D16EB06D09A248AFF20C76F9091B ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
18:28:42.0159 3316 aswKbd - ok
18:28:42.0206 3316 [ F76E51561562AC4105DBBE53FC99BC10 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
18:28:42.0237 3316 aswMonFlt - ok
18:28:42.0299 3316 [ 7B948E3657BEA62E437BC46CA6EF6012 ] aswNdis C:\Windows\system32\DRIVERS\aswNdis.sys
18:28:42.0315 3316 aswNdis - ok
18:28:42.0377 3316 [ C6E5E1E0FB3827B2359F4D394ECAA070 ] aswNdis2 C:\Windows\system32\drivers\aswNdis2.sys
18:28:42.0424 3316 aswNdis2 - ok
18:28:42.0487 3316 [ 924819669AFD0EDF5C067193D371FAB0 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
18:28:42.0518 3316 aswRdr - ok
18:28:42.0596 3316 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
18:28:42.0643 3316 aswSnx - ok
18:28:42.0690 3316 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\Windows\system32\drivers\aswSP.sys
18:28:42.0737 3316 aswSP - ok
18:28:42.0784 3316 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
18:28:42.0815 3316 aswTdi - ok
18:28:42.0862 3316 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:28:42.0924 3316 AsyncMac - ok
18:28:42.0971 3316 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
18:28:43.0002 3316 atapi - ok
18:28:43.0174 3316 [ 712D8A95E45B070114C5309ADA7358FF ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:28:43.0377 3316 atikmdag - ok
18:28:43.0424 3316 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:28:43.0518 3316 AudioEndpointBuilder - ok
18:28:43.0549 3316 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:28:43.0627 3316 Audiosrv - ok
18:28:43.0706 3316 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
18:28:43.0721 3316 avast! Antivirus - ok
18:28:43.0768 3316 [ DD4C61CB3CDBC8B0A7D2107C6944DC71 ] avast! Firewall C:\Program Files\Alwil Software\Avast5\afwServ.exe
18:28:43.0799 3316 avast! Firewall - ok
18:28:43.0846 3316 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:28:43.0893 3316 AxInstSV - ok
18:28:43.0956 3316 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
18:28:44.0002 3316 b06bdrv - ok
18:28:44.0034 3316 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
18:28:44.0081 3316 b57nd60x - ok
18:28:44.0143 3316 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
18:28:44.0190 3316 BDESVC - ok
18:28:44.0221 3316 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
18:28:44.0284 3316 Beep - ok
18:28:44.0346 3316 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
18:28:44.0440 3316 BFE - ok
18:28:44.0502 3316 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\system32\qmgr.dll
18:28:44.0596 3316 BITS - ok
18:28:44.0627 3316 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:28:44.0674 3316 blbdrive - ok
18:28:44.0706 3316 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:28:44.0768 3316 bowser - ok
18:28:44.0799 3316 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:28:44.0846 3316 BrFiltLo - ok
18:28:44.0877 3316 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:28:44.0924 3316 BrFiltUp - ok
18:28:44.0971 3316 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
18:28:45.0034 3316 BridgeMP - ok
18:28:45.0065 3316 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
18:28:45.0112 3316 Browser - ok
18:28:45.0159 3316 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:28:45.0206 3316 Brserid - ok
18:28:45.0252 3316 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:28:45.0299 3316 BrSerWdm - ok
18:28:45.0315 3316 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:28:45.0377 3316 BrUsbMdm - ok
18:28:45.0409 3316 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:28:45.0456 3316 BrUsbSer - ok
18:28:45.0471 3316 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:28:45.0534 3316 BTHMODEM - ok
18:28:45.0596 3316 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
18:28:45.0674 3316 bthserv - ok
18:28:45.0737 3316 catchme - ok
18:28:45.0784 3316 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:28:45.0862 3316 cdfs - ok
18:28:45.0909 3316 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:28:45.0956 3316 cdrom - ok
18:28:46.0002 3316 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
18:28:46.0081 3316 CertPropSvc - ok
18:28:46.0112 3316 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:28:46.0143 3316 circlass - ok
18:28:46.0190 3316 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
18:28:46.0221 3316 CLFS - ok
18:28:46.0315 3316 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:28:46.0346 3316 clr_optimization_v2.0.50727_32 - ok
18:28:46.0409 3316 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:28:46.0440 3316 clr_optimization_v4.0.30319_32 - ok
18:28:46.0471 3316 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:28:46.0518 3316 CmBatt - ok
18:28:46.0549 3316 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:28:46.0581 3316 cmdide - ok
18:28:46.0627 3316 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
18:28:46.0690 3316 CNG - ok
18:28:46.0721 3316 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:28:46.0752 3316 Compbatt - ok
18:28:46.0799 3316 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:28:46.0846 3316 CompositeBus - ok
18:28:46.0877 3316 COMSysApp - ok
18:28:46.0909 3316 cpuz132 - ok
18:28:46.0940 3316 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:28:46.0971 3316 crcdisk - ok
18:28:47.0018 3316 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:28:47.0081 3316 CryptSvc - ok
18:28:47.0143 3316 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
18:28:47.0237 3316 DcomLaunch - ok
18:28:47.0284 3316 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
18:28:47.0362 3316 defragsvc - ok
18:28:47.0424 3316 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:28:47.0471 3316 DfsC - ok
18:28:47.0534 3316 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:28:47.0627 3316 Dhcp - ok
18:28:47.0659 3316 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
18:28:47.0737 3316 discache - ok
18:28:47.0768 3316 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:28:47.0799 3316 Disk - ok
18:28:47.0846 3316 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:28:47.0893 3316 Dnscache - ok
18:28:47.0940 3316 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
18:28:48.0002 3316 dot3svc - ok
18:28:48.0049 3316 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
18:28:48.0127 3316 DPS - ok
18:28:48.0174 3316 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:28:48.0221 3316 drmkaud - ok
18:28:48.0268 3316 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:28:48.0331 3316 DXGKrnl - ok
18:28:48.0377 3316 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
18:28:48.0456 3316 EapHost - ok
18:28:48.0581 3316 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
18:28:48.0737 3316 ebdrv - ok
18:28:48.0768 3316 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
18:28:48.0815 3316 EFS - ok
18:28:48.0877 3316 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:28:48.0924 3316 ehRecvr - ok
18:28:48.0956 3316 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
18:28:49.0002 3316 ehSched - ok
18:28:49.0065 3316 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:28:49.0112 3316 elxstor - ok
18:28:49.0159 3316 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:28:49.0190 3316 ErrDev - ok
18:28:49.0268 3316 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
18:28:49.0362 3316 EventSystem - ok
18:28:49.0377 3316 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
18:28:49.0471 3316 exfat - ok
18:28:49.0502 3316 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:28:49.0581 3316 fastfat - ok
18:28:49.0659 3316 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
18:28:49.0721 3316 Fax - ok
18:28:49.0752 3316 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:28:49.0784 3316 fdc - ok
18:28:49.0815 3316 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
18:28:49.0909 3316 fdPHost - ok
18:28:49.0940 3316 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
18:28:50.0018 3316 FDResPub - ok
18:28:50.0065 3316 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:28:50.0096 3316 FileInfo - ok
18:28:50.0112 3316 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:28:50.0190 3316 Filetrace - ok
18:28:50.0221 3316 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:28:50.0252 3316 flpydisk - ok
18:28:50.0299 3316 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:28:50.0331 3316 FltMgr - ok
18:28:50.0393 3316 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
18:28:50.0456 3316 FontCache - ok
18:28:50.0518 3316 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:28:50.0549 3316 FontCache3.0.0.0 - ok
18:28:50.0565 3316 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:28:50.0596 3316 FsDepends - ok
18:28:50.0643 3316 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:28:50.0659 3316 Fs_Rec - ok
18:28:50.0721 3316 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:28:50.0768 3316 fvevol - ok
18:28:50.0815 3316 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:28:50.0846 3316 gagp30kx - ok
18:28:50.0893 3316 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\Windows\system32\giveio.sys
18:28:50.0940 3316 giveio ( UnsignedFile.Multi.Generic ) - warning
18:28:50.0940 3316 giveio - detected UnsignedFile.Multi.Generic (1)
18:28:50.0987 3316 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
18:28:51.0081 3316 gpsvc - ok
18:28:51.0159 3316 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
18:28:51.0190 3316 gupdate - ok
18:28:51.0252 3316 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
18:28:51.0268 3316 gupdatem - ok
18:28:51.0346 3316 [ 408DDD80EEDE47175F6844817B90213E ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
18:28:51.0377 3316 gusvc - ok
18:28:51.0424 3316 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:28:51.0456 3316 hcw85cir - ok
18:28:51.0487 3316 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:28:51.0534 3316 HDAudBus - ok
18:28:51.0565 3316 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:28:51.0596 3316 HidBatt - ok
18:28:51.0627 3316 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:28:51.0674 3316 HidBth - ok
18:28:51.0706 3316 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:28:51.0768 3316 HidIr - ok
18:28:51.0799 3316 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
18:28:51.0877 3316 hidserv - ok
18:28:51.0956 3316 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
18:28:52.0018 3316 HidUsb - ok
18:28:52.0049 3316 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:28:52.0127 3316 hkmsvc - ok
18:28:52.0159 3316 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:28:52.0206 3316 HomeGroupListener - ok
18:28:52.0268 3316 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:28:52.0331 3316 HomeGroupProvider - ok
18:28:52.0377 3316 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:28:52.0409 3316 HpSAMD - ok
18:28:52.0471 3316 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:28:52.0549 3316 HTTP - ok
18:28:52.0581 3316 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:28:52.0612 3316 hwpolicy - ok
18:28:52.0659 3316 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:28:52.0706 3316 i8042prt - ok
18:28:52.0768 3316 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:28:52.0799 3316 iaStorV - ok
18:28:52.0862 3316 [ B1A28FA1AFDE10B95FF9354B15701D70 ] ICQ Service C:\Program Files\ICQ6Toolbar\ICQ Service.exe
18:28:52.0909 3316 ICQ Service - ok
18:28:52.0971 3316 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:28:53.0034 3316 idsvc - ok
18:28:53.0081 3316 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:28:53.0096 3316 iirsp - ok
18:28:53.0159 3316 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
18:28:53.0268 3316 IKEEXT - ok
18:28:53.0315 3316 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
18:28:53.0346 3316 intelide - ok
18:28:53.0393 3316 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:28:53.0440 3316 intelppm - ok
18:28:53.0471 3316 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:28:53.0565 3316 IPBusEnum - ok
18:28:53.0581 3316 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:28:53.0659 3316 IpFilterDriver - ok
18:28:53.0721 3316 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:28:53.0815 3316 iphlpsvc - ok
18:28:53.0862 3316 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:28:53.0909 3316 IPMIDRV - ok
18:28:53.0940 3316 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:28:54.0018 3316 IPNAT - ok
18:28:54.0049 3316 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:28:54.0096 3316 IRENUM - ok
18:28:54.0127 3316 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:28:54.0159 3316 isapnp - ok
18:28:54.0190 3316 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:28:54.0252 3316 iScsiPrt - ok
18:28:54.0284 3316 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:28:54.0315 3316 kbdclass - ok
18:28:54.0346 3316 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:28:54.0377 3316 kbdhid - ok
18:28:54.0409 3316 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
18:28:54.0440 3316 KeyIso - ok
18:28:54.0471 3316 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:28:54.0502 3316 KSecDD - ok
18:28:54.0534 3316 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:28:54.0565 3316 KSecPkg - ok
18:28:54.0612 3316 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
18:28:54.0706 3316 KtmRm - ok
18:28:54.0752 3316 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll
18:28:54.0846 3316 LanmanServer - ok
18:28:54.0877 3316 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:28:54.0956 3316 LanmanWorkstation - ok
18:28:55.0018 3316 [ D57D1BE0129C1B45653B0FA920BC4B38 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
18:28:55.0049 3316 LightScribeService ( UnsignedFile.Multi.Generic ) - warning
18:28:55.0049 3316 LightScribeService - detected UnsignedFile.Multi.Generic (1)
18:28:55.0096 3316 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:28:55.0159 3316 lltdio - ok
18:28:55.0206 3316 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:28:55.0284 3316 lltdsvc - ok
18:28:55.0315 3316 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
18:28:55.0377 3316 lmhosts - ok
18:28:55.0424 3316 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:28:55.0456 3316 LSI_FC - ok
18:28:55.0502 3316 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:28:55.0534 3316 LSI_SAS - ok
18:28:55.0565 3316 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:28:55.0596 3316 LSI_SAS2 - ok
18:28:55.0612 3316 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:28:55.0643 3316 LSI_SCSI - ok
18:28:55.0674 3316 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
18:28:55.0752 3316 luafv - ok
18:28:55.0799 3316 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:28:55.0846 3316 Mcx2Svc - ok
18:28:55.0877 3316 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:28:55.0909 3316 megasas - ok
18:28:55.0956 3316 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:28:56.0002 3316 MegaSR - ok
18:28:56.0034 3316 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
18:28:56.0127 3316 MMCSS - ok
18:28:56.0159 3316 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
18:28:56.0221 3316 Modem - ok
18:28:56.0268 3316 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:28:56.0315 3316 monitor - ok
18:28:56.0346 3316 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
18:28:56.0377 3316 mouclass - ok
18:28:56.0424 3316 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:28:56.0456 3316 mouhid - ok
18:28:56.0502 3316 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:28:56.0534 3316 mountmgr - ok
18:28:56.0612 3316 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:28:56.0627 3316 MozillaMaintenance - ok
18:28:56.0674 3316 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
18:28:56.0706 3316 mpio - ok
18:28:56.0752 3316 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:28:56.0831 3316 mpsdrv - ok
18:28:56.0877 3316 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:28:56.0971 3316 MpsSvc - ok
18:28:57.0002 3316 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:28:57.0049 3316 MRxDAV - ok
18:28:57.0096 3316 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:28:57.0143 3316 mrxsmb - ok
18:28:57.0174 3316 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:28:57.0206 3316 mrxsmb10 - ok
18:28:57.0252 3316 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:28:57.0284 3316 mrxsmb20 - ok
18:28:57.0331 3316 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
18:28:57.0362 3316 msahci - ok
18:28:57.0456 3316 [ AAAC4B494DE45836121A40AEC980B631 ] MsDepSvc C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe
18:28:57.0487 3316 MsDepSvc - ok
18:28:57.0518 3316 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:28:57.0549 3316 msdsm - ok
18:28:57.0581 3316 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
18:28:57.0643 3316 MSDTC - ok
18:28:57.0706 3316 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:28:57.0768 3316 Msfs - ok
18:28:57.0815 3316 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:28:57.0877 3316 mshidkmdf - ok
18:28:57.0924 3316 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:28:57.0940 3316 msisadrv - ok
18:28:57.0987 3316 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:28:58.0065 3316 MSiSCSI - ok
18:28:58.0096 3316 msiserver - ok
18:28:58.0143 3316 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:28:58.0221 3316 MSKSSRV - ok
18:28:58.0252 3316 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:28:58.0331 3316 MSPCLOCK - ok
18:28:58.0346 3316 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:28:58.0424 3316 MSPQM - ok
18:28:58.0471 3316 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:28:58.0502 3316 MsRPC - ok
18:28:58.0549 3316 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:28:58.0581 3316 mssmbios - ok
18:28:58.0612 3316 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:28:58.0690 3316 MSTEE - ok
18:28:58.0721 3316 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:28:58.0768 3316 MTConfig - ok
18:28:58.0815 3316 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
18:28:58.0831 3316 MTsensor - ok
18:28:58.0862 3316 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
18:28:58.0909 3316 Mup - ok
18:28:58.0956 3316 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
18:28:59.0034 3316 napagent - ok
18:28:59.0096 3316 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:28:59.0159 3316 NativeWifiP - ok
18:28:59.0252 3316 [ 5E8EDD6A52E897C19EC6E149FE6C7A8E ] NBService C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
18:28:59.0299 3316 NBService - ok
18:28:59.0362 3316 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:28:59.0424 3316 NDIS - ok
18:28:59.0471 3316 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:28:59.0549 3316 NdisCap - ok
18:28:59.0581 3316 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:28:59.0643 3316 NdisTapi - ok
18:28:59.0706 3316 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:28:59.0768 3316 Ndisuio - ok
18:28:59.0799 3316 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:28:59.0862 3316 NdisWan - ok
18:28:59.0909 3316 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:28:59.0971 3316 NDProxy - ok
18:29:00.0018 3316 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:29:00.0096 3316 NetBIOS - ok
18:29:00.0127 3316 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:29:00.0206 3316 NetBT - ok
18:29:00.0221 3316 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
18:29:00.0268 3316 Netlogon - ok
18:29:00.0331 3316 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
18:29:00.0409 3316 Netman - ok
18:29:00.0456 3316 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
18:29:00.0549 3316 netprofm - ok
18:29:00.0581 3316 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:29:00.0612 3316 NetTcpPortSharing - ok
18:29:00.0659 3316 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:29:00.0690 3316 nfrd960 - ok
18:29:00.0737 3316 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:29:00.0831 3316 NlaSvc - ok
18:29:00.0909 3316 [ A328A46D87BB92CE4D8A4528E9D84787 ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
18:29:00.0940 3316 NMIndexingService - ok
18:29:00.0971 3316 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:29:01.0034 3316 Npfs - ok
18:29:01.0065 3316 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
18:29:01.0159 3316 nsi - ok
18:29:01.0190 3316 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:29:01.0252 3316 nsiproxy - ok
18:29:01.0331 3316 [ 0D87503986BB3DFED58E343FE39DDE13 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:29:01.0424 3316 Ntfs - ok
18:29:01.0456 3316 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
18:29:01.0534 3316 Null - ok
18:29:01.0581 3316 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:29:01.0612 3316 nvraid - ok
18:29:01.0659 3316 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:29:01.0690 3316 nvstor - ok
18:29:01.0721 3316 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:29:01.0752 3316 nv_agp - ok
18:29:01.0799 3316 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:29:01.0831 3316 ohci1394 - ok
18:29:01.0877 3316 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:29:01.0924 3316 p2pimsvc - ok
18:29:01.0956 3316 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
18:29:02.0002 3316 p2psvc - ok
18:29:02.0081 3316 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:29:02.0112 3316 Parport - ok
18:29:02.0143 3316 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:29:02.0174 3316 partmgr - ok
18:29:02.0221 3316 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:29:02.0252 3316 Parvdm - ok
18:29:02.0299 3316 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:29:02.0362 3316 PcaSvc - ok
18:29:02.0409 3316 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
18:29:02.0440 3316 pci - ok
18:29:02.0471 3316 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
18:29:02.0502 3316 pciide - ok
18:29:02.0534 3316 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:29:02.0581 3316 pcmcia - ok
18:29:02.0612 3316 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
18:29:02.0643 3316 pcw - ok
18:29:02.0674 3316 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:29:02.0784 3316 PEAUTH - ok
18:29:02.0893 3316 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
18:29:03.0034 3316 pla - ok
18:29:03.0081 3316 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:29:03.0159 3316 PlugPlay - ok
18:29:03.0206 3316 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:29:03.0237 3316 PNRPAutoReg - ok
18:29:03.0284 3316 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:29:03.0331 3316 PNRPsvc - ok
18:29:03.0377 3316 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:29:03.0471 3316 PolicyAgent - ok
18:29:03.0518 3316 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
18:29:03.0581 3316 Power - ok
18:29:03.0627 3316 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:29:03.0706 3316 PptpMiniport - ok
18:29:03.0737 3316 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:29:03.0784 3316 Processor - ok
18:29:03.0831 3316 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
18:29:03.0893 3316 ProfSvc - ok
18:29:03.0924 3316 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:29:03.0956 3316 ProtectedStorage - ok
18:29:04.0002 3316 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:29:04.0081 3316 Psched - ok
18:29:04.0143 3316 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:29:04.0237 3316 ql2300 - ok
18:29:04.0268 3316 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:29:04.0299 3316 ql40xx - ok
18:29:04.0346 3316 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
18:29:04.0409 3316 QWAVE - ok
18:29:04.0440 3316 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:29:04.0487 3316 QWAVEdrv - ok
18:29:04.0518 3316 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:29:04.0581 3316 RasAcd - ok
18:29:04.0643 3316 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:29:04.0690 3316 RasAgileVpn - ok
18:29:04.0737 3316 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
18:29:04.0799 3316 RasAuto - ok
18:29:04.0846 3316 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:29:04.0893 3316 Rasl2tp - ok
18:29:04.0924 3316 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
18:29:04.0987 3316 RasMan - ok
18:29:05.0002 3316 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:29:05.0049 3316 RasPppoe - ok
18:29:05.0081 3316 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:29:05.0127 3316 RasSstp - ok
18:29:05.0174 3316 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:29:05.0206 3316 rdbss - ok
18:29:05.0237 3316 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:29:05.0268 3316 rdpbus - ok
18:29:05.0299 3316 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:29:05.0331 3316 RDPCDD - ok
18:29:05.0377 3316 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:29:05.0424 3316 RDPENCDD - ok
18:29:05.0456 3316 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:29:05.0487 3316 RDPREFMP - ok
18:29:05.0534 3316 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:29:05.0549 3316 RDPWD - ok
18:29:05.0596 3316 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:29:05.0612 3316 rdyboost - ok
18:29:05.0659 3316 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
18:29:05.0690 3316 RemoteAccess - ok
18:29:05.0721 3316 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:29:05.0784 3316 RemoteRegistry - ok
18:29:05.0815 3316 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:29:05.0877 3316 RpcEptMapper - ok
18:29:05.0909 3316 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
18:29:05.0940 3316 RpcLocator - ok
18:29:05.0971 3316 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
18:29:06.0018 3316 RpcSs - ok
18:29:06.0049 3316 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:29:06.0096 3316 rspndr - ok
18:29:06.0143 3316 [ 4E20765744BFBC16F6D6E5BD5598786B ] RTL8023xp C:\Windows\system32\DRIVERS\Rtnicxp.sys
18:29:06.0174 3316 RTL8023xp - ok
18:29:06.0190 3316 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
18:29:06.0206 3316 SamSs - ok
18:29:06.0252 3316 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:29:06.0268 3316 sbp2port - ok
18:29:06.0299 3316 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:29:06.0346 3316 SCardSvr - ok
18:29:06.0377 3316 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:29:06.0409 3316 scfilter - ok
18:29:06.0456 3316 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
18:29:06.0534 3316 Schedule - ok
18:29:06.0549 3316 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:29:06.0596 3316 SCPolicySvc - ok
18:29:06.0612 3316 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:29:06.0659 3316 SDRSVC - ok
18:29:06.0690 3316 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:29:06.0721 3316 secdrv - ok
18:29:06.0752 3316 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
18:29:06.0799 3316 seclogon - ok
18:29:06.0831 3316 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
18:29:06.0877 3316 SENS - ok
18:29:06.0909 3316 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:29:06.0940 3316 SensrSvc - ok
18:29:06.0987 3316 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:29:07.0002 3316 Serenum - ok
18:29:07.0034 3316 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:29:07.0065 3316 Serial - ok
18:29:07.0096 3316 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:29:07.0127 3316 sermouse - ok
18:29:07.0190 3316 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
18:29:07.0237 3316 SessionEnv - ok
18:29:07.0268 3316 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:29:07.0299 3316 sffdisk - ok
18:29:07.0315 3316 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:29:07.0346 3316 sffp_mmc - ok
18:29:07.0362 3316 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:29:07.0393 3316 sffp_sd - ok
18:29:07.0409 3316 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:29:07.0440 3316 sfloppy - ok
18:29:07.0487 3316 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:29:07.0534 3316 SharedAccess - ok
18:29:07.0565 3316 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:29:07.0627 3316 ShellHWDetection - ok
18:29:07.0659 3316 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:29:07.0690 3316 sisagp - ok
18:29:07.0721 3316 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:29:07.0752 3316 SiSRaid2 - ok
18:29:07.0768 3316 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:29:07.0784 3316 SiSRaid4 - ok
18:29:07.0846 3316 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:29:07.0862 3316 SkypeUpdate - ok
18:29:07.0893 3316 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:29:07.0924 3316 Smb - ok
18:29:08.0002 3316 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:29:08.0018 3316 SNMPTRAP - ok
18:29:08.0049 3316 [ 5D6401DB90EC81B71F8E2C5C8F0FEF23 ] speedfan C:\Windows\system32\speedfan.sys
18:29:08.0081 3316 speedfan ( UnsignedFile.Multi.Generic ) - warning
18:29:08.0081 3316 speedfan - detected UnsignedFile.Multi.Generic (1)
18:29:08.0096 3316 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
18:29:08.0112 3316 spldr - ok
18:29:08.0159 3316 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
18:29:08.0190 3316 Spooler - ok
18:29:08.0284 3316 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
18:29:08.0409 3316 sppsvc - ok
18:29:08.0456 3316 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:29:08.0549 3316 sppuinotify - ok
18:29:08.0596 3316 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:29:08.0627 3316 srv - ok
18:29:08.0674 3316 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:29:08.0721 3316 srv2 - ok
18:29:08.0768 3316 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:29:08.0799 3316 srvnet - ok
18:29:08.0846 3316 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:29:08.0924 3316 SSDPSRV - ok
18:29:08.0956 3316 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:29:09.0034 3316 SstpSvc - ok
18:29:09.0081 3316 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:29:09.0112 3316 stexstor - ok
18:29:09.0174 3316 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
18:29:09.0252 3316 StiSvc - ok
18:29:09.0284 3316 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
18:29:09.0315 3316 swenum - ok
18:29:09.0362 3316 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
18:29:09.0456 3316 swprv - ok
18:29:09.0518 3316 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
18:29:09.0612 3316 SysMain - ok
18:29:09.0659 3316 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:29:09.0721 3316 TabletInputService - ok
18:29:09.0768 3316 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
18:29:09.0846 3316 TapiSrv - ok
18:29:09.0877 3316 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
18:29:09.0956 3316 TBS - ok
18:29:10.0034 3316 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:29:10.0143 3316 Tcpip - ok
18:29:10.0206 3316 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:29:10.0284 3316 TCPIP6 - ok
18:29:10.0331 3316 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:29:10.0393 3316 tcpipreg - ok
18:29:10.0440 3316 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:29:10.0471 3316 TDPIPE - ok
18:29:10.0502 3316 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:29:10.0534 3316 TDTCP - ok
18:29:10.0565 3316 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:29:10.0612 3316 tdx - ok
18:29:10.0643 3316 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:29:10.0659 3316 TermDD - ok
18:29:10.0690 3316 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
18:29:10.0752 3316 TermService - ok
18:29:10.0768 3316 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
18:29:10.0815 3316 Themes - ok
18:29:10.0831 3316 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
18:29:10.0877 3316 THREADORDER - ok
18:29:10.0924 3316 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
18:29:10.0987 3316 TrkWks - ok
18:29:11.0034 3316 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:29:11.0081 3316 TrustedInstaller - ok
18:29:11.0127 3316 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:29:11.0159 3316 tssecsrv - ok
18:29:11.0206 3316 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:29:11.0237 3316 TsUsbFlt - ok
18:29:11.0284 3316 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:29:11.0315 3316 tunnel - ok
18:29:11.0346 3316 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:29:11.0362 3316 uagp35 - ok
18:29:11.0393 3316 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:29:11.0440 3316 udfs - ok
18:29:11.0487 3316 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:29:11.0518 3316 UI0Detect - ok
18:29:11.0549 3316 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:29:11.0565 3316 uliagpkx - ok
18:29:11.0596 3316 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
18:29:11.0612 3316 umbus - ok
18:29:11.0643 3316 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:29:11.0674 3316 UmPass - ok
18:29:11.0706 3316 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
18:29:11.0768 3316 upnphost - ok
18:29:11.0799 3316 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
18:29:11.0815 3316 usbccgp - ok
18:29:11.0846 3316 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:29:11.0877 3316 usbcir - ok
18:29:11.0893 3316 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:29:11.0924 3316 usbehci - ok
18:29:11.0956 3316 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:29:11.0987 3316 usbhub - ok
18:29:12.0018 3316 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
18:29:12.0049 3316 usbohci - ok
18:29:12.0081 3316 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:29:12.0096 3316 usbprint - ok
18:29:12.0143 3316 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:29:12.0174 3316 USBSTOR - ok
18:29:12.0206 3316 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:29:12.0237 3316 usbuhci - ok
18:29:12.0268 3316 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
18:29:12.0377 3316 UxSms - ok
18:29:12.0409 3316 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
18:29:12.0440 3316 VaultSvc - ok
18:29:12.0471 3316 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:29:12.0502 3316 vdrvroot - ok
18:29:12.0565 3316 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
18:29:12.0643 3316 vds - ok
18:29:12.0690 3316 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:29:12.0737 3316 vga - ok
18:29:12.0752 3316 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
18:29:12.0831 3316 VgaSave - ok
18:29:12.0862 3316 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:29:12.0893 3316 vhdmp - ok
18:29:12.0924 3316 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:29:12.0940 3316 viaagp - ok
18:29:12.0971 3316 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
18:29:13.0002 3316 ViaC7 - ok
18:29:13.0018 3316 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
18:29:13.0034 3316 viaide - ok
18:29:13.0065 3316 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:29:13.0081 3316 volmgr - ok
18:29:13.0112 3316 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:29:13.0143 3316 volmgrx - ok
18:29:13.0159 3316 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:29:13.0190 3316 volsnap - ok
18:29:13.0221 3316 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:29:13.0237 3316 vsmraid - ok
18:29:13.0299 3316 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
18:29:13.0377 3316 VSS - ok
18:29:13.0393 3316 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
18:29:13.0424 3316 vwifibus - ok
18:29:13.0471 3316 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
18:29:13.0518 3316 W32Time - ok
18:29:13.0565 3316 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:29:13.0596 3316 WacomPen - ok
18:29:13.0627 3316 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:29:13.0659 3316 WANARP - ok
18:29:13.0690 3316 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:29:13.0721 3316 Wanarpv6 - ok
18:29:13.0784 3316 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:29:13.0862 3316 WatAdminSvc - ok
18:29:13.0909 3316 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
18:29:13.0971 3316 wbengine - ok
18:29:14.0002 3316 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:29:14.0049 3316 WbioSrvc - ok
18:29:14.0081 3316 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:29:14.0127 3316 wcncsvc - ok
18:29:14.0174 3316 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:29:14.0206 3316 WcsPlugInService - ok
18:29:14.0221 3316 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:29:14.0252 3316 Wd - ok
18:29:14.0284 3316 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:29:14.0315 3316 Wdf01000 - ok
18:29:14.0331 3316 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:29:14.0362 3316 WdiServiceHost - ok
18:29:14.0377 3316 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:29:14.0409 3316 WdiSystemHost - ok
18:29:14.0440 3316 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
18:29:14.0471 3316 WebClient - ok
18:29:14.0502 3316 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:29:14.0549 3316 Wecsvc - ok
18:29:14.0565 3316 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:29:14.0612 3316 wercplsupport - ok
18:29:14.0643 3316 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
18:29:14.0706 3316 WerSvc - ok
18:29:14.0737 3316 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:29:14.0784 3316 WfpLwf - ok
18:29:14.0799 3316 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:29:14.0815 3316 WIMMount - ok
18:29:14.0893 3316 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:29:14.0940 3316 WinDefend - ok
18:29:14.0971 3316 WinHttpAutoProxySvc - ok
18:29:15.0018 3316 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:29:15.0081 3316 Winmgmt - ok
18:29:15.0159 3316 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
18:29:15.0284 3316 WinRM - ok
18:29:15.0362 3316 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:29:15.0393 3316 WinUsb - ok
18:29:15.0456 3316 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:29:15.0549 3316 Wlansvc - ok
18:29:15.0581 3316 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:29:15.0612 3316 WmiAcpi - ok
18:29:15.0659 3316 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:29:15.0706 3316 wmiApSrv - ok
18:29:15.0799 3316 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:29:15.0893 3316 WMPNetworkSvc - ok
18:29:15.0924 3316 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:29:15.0971 3316 WPCSvc - ok
18:29:16.0018 3316 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:29:16.0065 3316 WPDBusEnum - ok
18:29:16.0096 3316 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:29:16.0174 3316 ws2ifsl - ok
18:29:16.0221 3316 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll
18:29:16.0284 3316 wscsvc - ok
18:29:16.0299 3316 WSearch - ok
18:29:16.0409 3316 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
18:29:16.0534 3316 wuauserv - ok
18:29:16.0565 3316 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:29:16.0643 3316 WudfPf - ok
18:29:16.0706 3316 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:29:16.0784 3316 WUDFRd - ok
18:29:16.0831 3316 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:29:16.0909 3316 wudfsvc - ok
18:29:16.0940 3316 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
18:29:17.0002 3316 WwanSvc - ok
18:29:17.0049 3316 ================ Scan global ===============================
18:29:17.0096 3316 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
18:29:17.0127 3316 [ 48CB4FDBCAAEAC7BCE2F5941545FF071 ] C:\Windows\system32\winsrv.dll
18:29:17.0159 3316 [ 48CB4FDBCAAEAC7BCE2F5941545FF071 ] C:\Windows\system32\winsrv.dll
18:29:17.0206 3316 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
18:29:17.0252 3316 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
18:29:17.0268 3316 [Global] - ok
18:29:17.0268 3316 ================ Scan MBR ==================================
18:29:17.0284 3316 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
18:29:17.0612 3316 \Device\Harddisk0\DR0 - ok
18:29:17.0612 3316 ================ Scan VBR ==================================
18:29:17.0627 3316 [ 43E78F6C491F275633C4919A44F3F550 ] \Device\Harddisk0\DR0\Partition1
18:29:17.0627 3316 \Device\Harddisk0\DR0\Partition1 - ok
18:29:17.0659 3316 [ 4EBB76BDEF3A38B4DA9CBF59EF4CF01F ] \Device\Harddisk0\DR0\Partition2
18:29:17.0659 3316 \Device\Harddisk0\DR0\Partition2 - ok
18:29:17.0674 3316 ============================================================
18:29:17.0674 3316 Scan finished
18:29:17.0674 3316 ============================================================
18:29:17.0706 1984 Detected object count: 3
18:29:17.0706 1984 Actual detected object count: 3
18:29:42.0268 1984 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
18:29:42.0268 1984 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:29:42.0284 1984 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
18:29:42.0284 1984 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:29:42.0284 1984 speedfan ( UnsignedFile.Multi.Generic ) - skipped by user
18:29:42.0284 1984 speedfan ( UnsignedFile.Multi.Generic ) - User select action: Skip

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#6 Příspěvek od liborolomouc »

Ano, přes regedit se dá Editor registrů spustit.

AV hlásí znovu oba viry na stejném umístění jako naposledy:
c:\.Trash-999\files\ je ten Hupigon
d:\.Trash-999\files\ je ten Patch

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#7 Příspěvek od liborolomouc »

Udělám co píšeš.
Napadlo mě, jestli má cenu nechat AV dát ty 2 soubory např. do truhly, nebo smazat?

Jinak ti hrozně dík za pomoc, toto je dááleko za mými schopnostmi. Na revanš: jak podpořit forum jsem zjistil a taky udělám, ale na foru jsi to řešil ty, čili ....?

liborolomouc
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 14 říj 2012 13:44

Re: Win32:Hupigon-ONX, Patched-HO

#8 Příspěvek od liborolomouc »

Tak ještě jednou aspoň VELKEJ DÍK a ahoj, Libor

Zamčeno