Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#16 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
FCopy::
c:\windows\ServicePackFiles\i386\atapi.sys | c:\windows\system32\drivers\atapi.sys

RegLock::
[HKEY_USERS\S-1-5-21-746137067-616249376-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#17 Příspěvek od Petulda »

ComboFix 13-09-16.01 - Administrator 16.09.2013 23:32:09.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.510.119 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: E:\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
--------------- FCopy ---------------
.
c:\windows\ServicePackFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-16 do 2013-09-16 )))))))))))))))))))))))))))))))
.
.
2013-09-15 18:15 . 2013-09-15 18:15 -------- d-----w- c:\program files\trend micro
2013-09-15 16:33 . 2013-09-15 17:29 -------- d-----w- C:\AdwCleaner
2013-09-15 15:24 . 2013-09-15 15:24 388096 ----a-r- c:\documents and settings\Administrator\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-09-15 15:24 . 2013-09-15 15:24 -------- d-----w- c:\program files\hij
2013-09-15 11:19 . 2013-09-15 11:19 -------- d---a-w- c:\windows\VDLL.DLL
2013-09-15 11:19 . 2013-09-15 11:19 -------- d---a-w- c:\windows\system32\runouce.exe
2013-09-15 11:19 . 2013-09-15 11:19 -------- d---a-w- c:\windows\RUNDL132.EXE
2013-09-15 11:19 . 2013-09-15 11:19 -------- d---a-w- c:\windows\logo_1.exe
2013-09-15 08:57 . 2013-09-15 08:57 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2013-09-15 08:57 . 2013-09-15 08:57 572928 ----a-w- c:\windows\system32\msvcp90.dll
2013-09-15 08:57 . 2013-09-15 08:57 655872 ----a-w- c:\windows\system32\msvcr90.dll
2013-09-15 08:57 . 2013-09-15 08:57 34048 ----a-w- c:\windows\system32\eEmpty.exe
2013-09-15 08:57 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2013-09-15 08:57 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2013-09-15 08:57 . 2013-09-15 08:57 -------- d-----w- c:\program files\Common Files\MicroWorld
2013-09-15 08:57 . 2013-09-15 08:57 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MicroWorld
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-15 02:15 . 2013-03-08 19:59 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-15 02:15 . 2011-11-18 15:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 01:56 . 2004-08-17 12:49 386560 ----a-w- c:\windows\system32\themeui.dll
2013-08-08 06:09 . 2005-03-02 17:08 1877760 ----a-w- c:\windows\system32\win32k.sys
2013-08-08 06:05 . 2004-08-17 12:49 920064 ----a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2004-08-17 12:49 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2004-08-17 12:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2004-08-17 12:49 18944 ----a-w- c:\windows\system32\corpol.dll
2013-08-08 00:02 . 2004-08-17 12:44 385024 ----a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2005-04-28 18:32 1289216 ----a-w- c:\windows\system32\ole32.dll
2013-08-02 23:48 . 2006-10-18 20:47 1543680 ------w- c:\windows\system32\wmvdecod.dll
2013-07-10 10:37 . 2004-08-17 12:49 406016 ----a-w- c:\windows\system32\usp10.dll
2013-07-04 07:34 . 2005-03-02 17:08 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 07:33 . 2005-03-02 17:08 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-03-20 12:37 . 2008-02-22 15:52 5689344 ----a-w- c:\program files\mplayerc.exe
2009-08-31 15:55 . 2013-07-03 09:12 118000 ----a-w- c:\program files\mozilla firefox\components\qippipe.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\DllCache\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-03-23 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-03-23 13881448]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"Intel AppUp(R) center"="c:\program files\Intel\IntelAppStore\bin\ismagent.exe" [2013-05-17 156000]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-17 44544]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Nikon Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Nikon Monitor.lnk
backup=c:\windows\pss\Nikon Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Philips GoGear VIBE Device Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Philips GoGear VIBE Device Manager.lnk
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-10-27 18:17 207424 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-10-23 13:18 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-03-12 21:43 81920 ----a-w- c:\program files\D-Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intel AppUp(R) center Systray]
2013-05-17 21:57 927968 ----a-w- c:\program files\Intel\IntelAppStore\bin\AppUp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-02-17 06:15 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-02-17 06:15 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
2003-08-19 09:43 57344 ----a-w- c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 07:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-03-23 22:42 13881448 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-03-23 22:42 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-08-11 13:43 1519616 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 08:08 16380416 ------r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"MDM"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Intel\\IntelAppStore\\bin\\ismagent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 d346bus;d346bus;c:\windows\system32\drivers\d346bus.sys [8.3.2008 16:18 156800]
R0 d346prt;d346prt;c:\windows\system32\drivers\d346prt.sys [8.3.2008 16:18 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22.2.2008 18:41 685816]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [21.12.2012 22:10 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7.4.2008 18:26 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7.4.2008 18:26 21256]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [14.8.2013 11:10 3291008]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [3.6.2013 16:21 162408]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-06 07:54 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-08 02:15]
.
2013-09-16 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-12-21 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\zz48cv4d.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: !HIDDEN! 2011-11-20 10:17; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-16 23:49
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3064)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Celkový čas: 2013-09-16 23:56:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-16 21:56
ComboFix2.txt 2013-09-16 20:09
.
Před spuštěním: 4 249 161 728
Po spuštění: 4 368 203 776
.
- - End Of File - - 357413B85D88BFC696EEB1EC570C0846
413FC2A0C716421B3158746D63736515

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#18 Příspěvek od Rudy »

Spusťte ještě tuto utilitu: http://www.stahuj.centrum.cz/utility_a_ ... dsskiller/ . Rozbalte na plochu, spusťte a nechte pracovat. Na konci akce se objeví log, který se, zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#19 Příspěvek od Petulda »

19:18:38.0843 0x0570 TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29
19:18:39.0187 0x0570 ============================================================
19:18:39.0187 0x0570 Current date / time: 2013/09/17 19:18:39.0187
19:18:39.0187 0x0570 SystemInfo:
19:18:39.0187 0x0570
19:18:39.0187 0x0570 OS Version: 5.1.2600 ServicePack: 3.0
19:18:39.0187 0x0570 Product type: Workstation
19:18:39.0187 0x0570 ComputerName: LEPSI
19:18:39.0187 0x0570 UserName: Administrator
19:18:39.0187 0x0570 Windows directory: C:\WINDOWS
19:18:39.0187 0x0570 System windows directory: C:\WINDOWS
19:18:39.0187 0x0570 Processor architecture: Intel x86
19:18:39.0187 0x0570 Number of processors: 2
19:18:39.0187 0x0570 Page size: 0x1000
19:18:39.0187 0x0570 Boot type: Normal boot
19:18:39.0187 0x0570 ============================================================
19:18:39.0187 0x0570 BG loaded
19:18:53.0687 0x0570 Drive \Device\Harddisk0\DR0 - Size: 0xDF98DDE00 (55.90 Gb), SectorSize: 0x200, Cylinders: 0x1C81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x000000A4
19:18:53.0718 0x0570 Drive \Device\Harddisk1\DR2 - Size: 0x3C7200000 (15.11 Gb), SectorSize: 0x200, Cylinders: 0x7B4, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:18:53.0718 0x0570 ============================================================
19:18:53.0718 0x0570 \Device\Harddisk0\DR0:
19:18:53.0750 0x0570 MBR partitions:
19:18:53.0750 0x0570 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x6FC7C41
19:18:53.0750 0x0570 \Device\Harddisk1\DR2:
19:18:53.0750 0x0570 MBR partitions:
19:18:53.0750 0x0570 \Device\Harddisk1\DR2\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x1E36636
19:18:53.0750 0x0570 ============================================================
19:18:54.0000 0x0570 C: <-> \Device\Harddisk0\DR0\Partition1
19:18:54.0000 0x0570 ============================================================
19:18:54.0000 0x0570 Initialize success
19:18:54.0000 0x0570 ============================================================
20:02:17.0093 0x0840 ============================================================
20:02:17.0093 0x0840 Scan started
20:02:17.0093 0x0840 Mode: Manual;
20:02:17.0093 0x0840 ============================================================
20:02:17.0484 0x0840 ================ Scan system memory ========================
20:02:17.0484 0x0840 System memory - ok
20:02:17.0484 0x0840 ================ Scan services =============================
20:02:17.0859 0x0840 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
20:02:17.0859 0x0840 Aavmker4 - ok
20:02:17.0859 0x0840 Abiosdsk - ok
20:02:18.0015 0x0840 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
20:02:18.0031 0x0840 ACDaemon - ok
20:02:18.0062 0x0840 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:02:18.0078 0x0840 ACPI - ok
20:02:18.0109 0x0840 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:02:18.0109 0x0840 ACPIEC - ok
20:02:18.0203 0x0840 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:02:18.0218 0x0840 AdobeFlashPlayerUpdateSvc - ok
20:02:18.0250 0x0840 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:02:18.0250 0x0840 aec - ok
20:02:18.0296 0x0840 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:02:18.0296 0x0840 AFD - ok
20:02:18.0328 0x0840 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:02:18.0328 0x0840 Alerter - ok
20:02:18.0343 0x0840 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
20:02:18.0343 0x0840 ALG - ok
20:02:18.0359 0x0840 AliIde - ok
20:02:18.0390 0x0840 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:02:18.0406 0x0840 AppMgmt - ok
20:02:18.0500 0x0840 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:02:18.0546 0x0840 aspnet_state - ok
20:02:18.0578 0x0840 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:02:18.0578 0x0840 aswFsBlk - ok
20:02:18.0609 0x0840 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
20:02:18.0625 0x0840 aswMon2 - ok
20:02:18.0640 0x0840 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
20:02:18.0640 0x0840 aswRdr - ok
20:02:18.0687 0x0840 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
20:02:18.0718 0x0840 aswSnx - ok
20:02:18.0750 0x0840 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
20:02:18.0765 0x0840 aswSP - ok
20:02:18.0781 0x0840 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
20:02:18.0781 0x0840 aswTdi - ok
20:02:18.0812 0x0840 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:02:18.0812 0x0840 AsyncMac - ok
20:02:18.0843 0x0840 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:02:18.0843 0x0840 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: 9F3A2F5AA6875C72BF062C712CFA2674
20:02:18.0843 0x0840 atapi ( LockedFile.Multi.Generic ) - warning
20:02:18.0843 0x0840 atapi - detected LockedFile.Multi.Generic (1)
20:02:18.0843 0x0840 Atdisk - ok
20:02:18.0875 0x0840 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:02:18.0890 0x0840 Atmarpc - ok
20:02:18.0968 0x0840 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:02:18.0984 0x0840 AudioSrv - ok
20:02:19.0046 0x0840 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:02:19.0062 0x0840 audstub - ok
20:02:19.0296 0x0840 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
20:02:19.0312 0x0840 avast! Antivirus - ok
20:02:19.0359 0x0840 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:02:19.0390 0x0840 Beep - ok
20:02:19.0453 0x0840 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
20:02:19.0515 0x0840 BITS - ok
20:02:19.0546 0x0840 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
20:02:19.0546 0x0840 Browser - ok
20:02:19.0562 0x0840 catchme - ok
20:02:19.0640 0x0840 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:02:19.0687 0x0840 Cdaudio - ok
20:02:19.0734 0x0840 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:02:19.0781 0x0840 Cdfs - ok
20:02:19.0843 0x0840 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:02:19.0875 0x0840 Cdrom - ok
20:02:19.0875 0x0840 Changer - ok
20:02:19.0937 0x0840 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:02:19.0953 0x0840 CiSvc - ok
20:02:19.0984 0x0840 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:02:20.0015 0x0840 ClipSrv - ok
20:02:20.0406 0x0840 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:02:20.0578 0x0840 clr_optimization_v2.0.50727_32 - ok
20:02:20.0593 0x0840 CmdIde - ok
20:02:20.0593 0x0840 COMSysApp - ok
20:02:20.0640 0x0840 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:02:20.0656 0x0840 CryptSvc - ok
20:02:20.0703 0x0840 [ 99159E3EF20A4792AEFE4115E8AD0957 ] d346bus C:\WINDOWS\system32\DRIVERS\d346bus.sys
20:02:20.0718 0x0840 d346bus - ok
20:02:20.0734 0x0840 [ FB228CD598B7686E98FBF7BFB55666EB ] d346prt C:\WINDOWS\system32\Drivers\d346prt.sys
20:02:20.0750 0x0840 d346prt - ok
20:02:21.0125 0x0840 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:02:21.0312 0x0840 DcomLaunch - ok
20:02:21.0359 0x0840 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:02:21.0359 0x0840 Dhcp - ok
20:02:21.0390 0x0840 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:02:21.0421 0x0840 Disk - ok
20:02:21.0421 0x0840 dmadmin - ok
20:02:22.0078 0x0840 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:02:22.0390 0x0840 dmboot - ok
20:02:22.0484 0x0840 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:02:22.0515 0x0840 dmio - ok
20:02:22.0546 0x0840 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:02:22.0546 0x0840 dmload - ok
20:02:22.0593 0x0840 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:02:22.0609 0x0840 dmserver - ok
20:02:22.0625 0x0840 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:02:22.0640 0x0840 DMusic - ok
20:02:22.0671 0x0840 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:02:22.0703 0x0840 Dnscache - ok
20:02:22.0734 0x0840 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:02:22.0796 0x0840 Dot3svc - ok
20:02:22.0812 0x0840 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:02:22.0812 0x0840 drmkaud - ok
20:02:22.0875 0x0840 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:02:22.0875 0x0840 EapHost - ok
20:02:22.0906 0x0840 [ FD9FC82F134B1C91004FFC76A5AE494B ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys
20:02:22.0906 0x0840 ENTECH - ok
20:02:22.0953 0x0840 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:02:22.0953 0x0840 ERSvc - ok
20:02:22.0984 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
20:02:23.0000 0x0840 Eventlog - ok
20:02:23.0031 0x0840 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
20:02:23.0046 0x0840 EventSystem - ok
20:02:23.0078 0x0840 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:02:23.0093 0x0840 Fastfat - ok
20:02:23.0125 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:02:23.0140 0x0840 FastUserSwitchingCompatibility - ok
20:02:23.0156 0x0840 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:02:23.0156 0x0840 Fdc - ok
20:02:23.0187 0x0840 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:02:23.0187 0x0840 Fips - ok
20:02:23.0203 0x0840 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:02:23.0218 0x0840 Flpydisk - ok
20:02:23.0234 0x0840 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:02:23.0234 0x0840 FltMgr - ok
20:02:23.0312 0x0840 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:02:23.0328 0x0840 FontCache3.0.0.0 - ok
20:02:23.0359 0x0840 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:02:23.0359 0x0840 Fs_Rec - ok
20:02:23.0375 0x0840 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:02:23.0375 0x0840 Ftdisk - ok
20:02:23.0406 0x0840 [ 54789F9BA0D59072CDD4E7C200E122C4 ] gdrv C:\WINDOWS\gdrv.sys
20:02:25.0875 0x0840 gdrv - ok
20:02:25.0953 0x0840 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:02:25.0984 0x0840 Gpc - ok
20:02:26.0109 0x0840 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
20:02:26.0156 0x0840 gupdate - ok
20:02:26.0171 0x0840 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
20:02:26.0171 0x0840 gupdatem - ok
20:02:26.0234 0x0840 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:02:26.0265 0x0840 gusvc - ok
20:02:26.0312 0x0840 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:02:26.0312 0x0840 HDAudBus - ok
20:02:26.0453 0x0840 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:02:26.0484 0x0840 helpsvc - ok
20:02:26.0500 0x0840 [ 00E25EE90166B3E1BE6E74AEBF858306 ] HidServ C:\WINDOWS\System32\hidserv.dll
20:02:26.0515 0x0840 HidServ - ok
20:02:26.0531 0x0840 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:02:26.0531 0x0840 HidUsb - ok
20:02:26.0578 0x0840 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:02:26.0593 0x0840 hkmsvc - ok
20:02:26.0625 0x0840 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:02:26.0625 0x0840 HTTP - ok
20:02:26.0640 0x0840 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:02:26.0656 0x0840 HTTPFilter - ok
20:02:26.0687 0x0840 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:02:26.0687 0x0840 i8042prt - ok
20:02:26.0750 0x0840 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:02:26.0750 0x0840 IDriverT - ok
20:02:26.0906 0x0840 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:02:26.0984 0x0840 idsvc - ok
20:02:27.0000 0x0840 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:02:27.0000 0x0840 Imapi - ok
20:02:27.0031 0x0840 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:02:27.0046 0x0840 ImapiService - ok
20:02:27.0234 0x0840 [ C4006AF18682FCA0D8A011A0A21070F8 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:02:27.0390 0x0840 IntcAzAudAddService - ok
20:02:27.0406 0x0840 IntelIde - ok
20:02:27.0421 0x0840 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:02:27.0421 0x0840 intelppm - ok
20:02:27.0437 0x0840 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:02:27.0437 0x0840 Ip6Fw - ok
20:02:27.0484 0x0840 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:02:27.0484 0x0840 IpFilterDriver - ok
20:02:27.0500 0x0840 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:02:27.0500 0x0840 IpInIp - ok
20:02:27.0531 0x0840 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:02:27.0531 0x0840 IpNat - ok
20:02:27.0562 0x0840 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:02:27.0562 0x0840 IPSec - ok
20:02:27.0593 0x0840 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:02:27.0593 0x0840 IRENUM - ok
20:02:27.0609 0x0840 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:02:27.0609 0x0840 isapnp - ok
20:02:27.0625 0x0840 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:02:27.0625 0x0840 Kbdclass - ok
20:02:27.0640 0x0840 [ 86C8F23616C6C6E5B2776901C17B945B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:02:27.0656 0x0840 kbdhid - ok
20:02:27.0671 0x0840 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:02:27.0687 0x0840 kmixer - ok
20:02:27.0703 0x0840 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:02:27.0718 0x0840 KSecDD - ok
20:02:27.0750 0x0840 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:02:27.0750 0x0840 lanmanserver - ok
20:02:27.0781 0x0840 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:02:27.0796 0x0840 lanmanworkstation - ok
20:02:27.0796 0x0840 lbrtfdc - ok
20:02:27.0828 0x0840 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:02:27.0843 0x0840 LmHosts - ok
20:02:27.0890 0x0840 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
20:02:27.0906 0x0840 MDM - ok
20:02:27.0921 0x0840 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:02:27.0921 0x0840 Messenger - ok
20:02:27.0953 0x0840 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:02:27.0953 0x0840 mnmdd - ok
20:02:27.0984 0x0840 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:02:27.0984 0x0840 mnmsrvc - ok
20:02:28.0015 0x0840 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:02:28.0015 0x0840 Modem - ok
20:02:28.0031 0x0840 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:02:28.0031 0x0840 Mouclass - ok
20:02:28.0046 0x0840 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:02:28.0046 0x0840 mouhid - ok
20:02:28.0093 0x0840 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:02:28.0093 0x0840 MountMgr - ok
20:02:28.0140 0x0840 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:02:28.0140 0x0840 MozillaMaintenance - ok
20:02:28.0171 0x0840 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:02:28.0171 0x0840 MRxDAV - ok
20:02:28.0218 0x0840 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:02:28.0250 0x0840 MRxSmb - ok
20:02:28.0281 0x0840 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:02:28.0281 0x0840 MSDTC - ok
20:02:28.0296 0x0840 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:02:28.0296 0x0840 Msfs - ok
20:02:28.0312 0x0840 MSIServer - ok
20:02:28.0328 0x0840 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:02:28.0328 0x0840 MSKSSRV - ok
20:02:28.0343 0x0840 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:02:28.0343 0x0840 MSPCLOCK - ok
20:02:28.0375 0x0840 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:02:28.0375 0x0840 MSPQM - ok
20:02:28.0406 0x0840 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:02:28.0406 0x0840 mssmbios - ok
20:02:28.0437 0x0840 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:02:28.0437 0x0840 Mup - ok
20:02:28.0500 0x0840 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
20:02:28.0546 0x0840 napagent - ok
20:02:28.0578 0x0840 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:02:28.0578 0x0840 NDIS - ok
20:02:28.0625 0x0840 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:02:28.0625 0x0840 NdisTapi - ok
20:02:28.0656 0x0840 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:02:28.0656 0x0840 Ndisuio - ok
20:02:28.0671 0x0840 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:02:28.0687 0x0840 NdisWan - ok
20:02:28.0718 0x0840 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:02:28.0718 0x0840 NDProxy - ok
20:02:28.0812 0x0840 [ 6D4028D458EAAA1782099750790DC8C9 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
20:02:28.0859 0x0840 Nero BackItUp Scheduler 3 - ok
20:02:28.0890 0x0840 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:02:28.0890 0x0840 NetBIOS - ok
20:02:28.0906 0x0840 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:02:28.0921 0x0840 NetBT - ok
20:02:28.0937 0x0840 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
20:02:28.0953 0x0840 NetDDE - ok
20:02:28.0953 0x0840 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:02:28.0968 0x0840 NetDDEdsdm - ok
20:02:28.0984 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:02:29.0000 0x0840 Netlogon - ok
20:02:29.0015 0x0840 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
20:02:29.0031 0x0840 Netman - ok
20:02:29.0093 0x0840 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:02:29.0093 0x0840 NetTcpPortSharing - ok
20:02:29.0140 0x0840 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
20:02:29.0156 0x0840 Nla - ok
20:02:29.0250 0x0840 [ FF4D73B16EA3A32D34CEB3A7BC3C3773 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
20:02:29.0265 0x0840 NMIndexingService - ok
20:02:29.0296 0x0840 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:02:29.0296 0x0840 Npfs - ok
20:02:29.0343 0x0840 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:02:29.0359 0x0840 Ntfs - ok
20:02:29.0390 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:02:29.0390 0x0840 NtLmSsp - ok
20:02:29.0437 0x0840 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:02:29.0484 0x0840 NtmsSvc - ok
20:02:29.0531 0x0840 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
20:02:29.0531 0x0840 Null - ok
20:02:29.0984 0x0840 [ 231E377E60A96B53C169C5E04AC0A67A ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:02:30.0328 0x0840 nv - ok
20:02:30.0390 0x0840 [ E10AACC565E0A8B76AC4FB912343D38E ] NVHDA C:\WINDOWS\system32\drivers\nvhda32.sys
20:02:30.0390 0x0840 NVHDA - ok
20:02:30.0437 0x0840 [ A1D291A173A68C332678DDF3FC38D85B ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
20:02:30.0437 0x0840 NVSvc - ok
20:02:30.0468 0x0840 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:02:30.0468 0x0840 NwlnkFlt - ok
20:02:30.0468 0x0840 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:02:30.0468 0x0840 NwlnkFwd - ok
20:02:30.0500 0x0840 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:02:30.0500 0x0840 ose - ok
20:02:30.0531 0x0840 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
20:02:30.0531 0x0840 Parport - ok
20:02:30.0562 0x0840 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:02:30.0562 0x0840 PartMgr - ok
20:02:30.0593 0x0840 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:02:30.0609 0x0840 ParVdm - ok
20:02:30.0625 0x0840 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:02:30.0625 0x0840 PCI - ok
20:02:30.0640 0x0840 PCIDump - ok
20:02:30.0656 0x0840 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:02:30.0671 0x0840 PCIIde - ok
20:02:30.0703 0x0840 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:02:30.0703 0x0840 Pcmcia - ok
20:02:30.0703 0x0840 PDCOMP - ok
20:02:30.0718 0x0840 PDFRAME - ok
20:02:30.0718 0x0840 PDRELI - ok
20:02:30.0734 0x0840 PDRFRAME - ok
20:02:30.0765 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
20:02:30.0781 0x0840 PlugPlay - ok
20:02:30.0796 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:02:30.0796 0x0840 PolicyAgent - ok
20:02:30.0812 0x0840 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:02:30.0812 0x0840 PptpMiniport - ok
20:02:30.0828 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:02:30.0828 0x0840 ProtectedStorage - ok
20:02:30.0843 0x0840 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:02:30.0843 0x0840 PSched - ok
20:02:30.0875 0x0840 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:02:30.0875 0x0840 Ptilink - ok
20:02:30.0890 0x0840 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:02:30.0890 0x0840 RasAcd - ok
20:02:30.0906 0x0840 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:02:30.0921 0x0840 RasAuto - ok
20:02:30.0937 0x0840 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:02:30.0937 0x0840 Rasl2tp - ok
20:02:30.0968 0x0840 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:02:30.0968 0x0840 RasMan - ok
20:02:31.0000 0x0840 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:02:31.0000 0x0840 RasPppoe - ok
20:02:31.0031 0x0840 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:02:31.0031 0x0840 Raspti - ok
20:02:31.0046 0x0840 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:02:31.0062 0x0840 Rdbss - ok
20:02:31.0078 0x0840 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:02:31.0078 0x0840 RDPCDD - ok
20:02:31.0109 0x0840 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:02:31.0109 0x0840 rdpdr - ok
20:02:31.0156 0x0840 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:02:31.0156 0x0840 RDPWD - ok
20:02:31.0187 0x0840 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:02:31.0187 0x0840 RDSessMgr - ok
20:02:31.0218 0x0840 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:02:31.0218 0x0840 redbook - ok
20:02:31.0250 0x0840 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:02:31.0250 0x0840 RemoteAccess - ok
20:02:31.0281 0x0840 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:02:31.0296 0x0840 RemoteRegistry - ok
20:02:31.0312 0x0840 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
20:02:31.0328 0x0840 RpcLocator - ok
20:02:31.0375 0x0840 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\System32\rpcss.dll
20:02:31.0390 0x0840 RpcSs - ok
20:02:31.0453 0x0840 [ 99F13D7E9AAEC74A5B7D10AB780D9D6F ] RSVP C:\WINDOWS\system32\rsvp.exe
20:02:31.0468 0x0840 RSVP - ok
20:02:31.0500 0x0840 [ BADABE0940C01619E8510B90FB314929 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:02:31.0500 0x0840 RTLE8023xp - ok
20:02:31.0515 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
20:02:31.0531 0x0840 SamSs - ok
20:02:31.0562 0x0840 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:02:31.0562 0x0840 SCardSvr - ok
20:02:31.0609 0x0840 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:02:31.0609 0x0840 Schedule - ok
20:02:31.0656 0x0840 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:02:31.0656 0x0840 Secdrv - ok
20:02:31.0671 0x0840 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:02:31.0687 0x0840 seclogon - ok
20:02:31.0703 0x0840 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
20:02:31.0703 0x0840 SENS - ok
20:02:31.0718 0x0840 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:02:31.0734 0x0840 serenum - ok
20:02:31.0750 0x0840 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:02:31.0750 0x0840 Serial - ok
20:02:31.0765 0x0840 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:02:31.0781 0x0840 Sfloppy - ok
20:02:31.0812 0x0840 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:02:31.0828 0x0840 SharedAccess - ok
20:02:31.0843 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:02:31.0859 0x0840 ShellHWDetection - ok
20:02:31.0859 0x0840 Simbad - ok
20:02:32.0312 0x0840 [ D0776778A9FC5E37F2E9EB21FC8A9709 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
20:02:32.0671 0x0840 Skype C2C Service - ok
20:02:32.0796 0x0840 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
20:02:32.0796 0x0840 SkypeUpdate - ok
20:02:32.0812 0x0840 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:02:32.0812 0x0840 splitter - ok
20:02:32.0843 0x0840 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:02:32.0843 0x0840 Spooler - ok
20:02:32.0906 0x0840 [ D390675B8CE45E5FB359338E5E649329 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
20:02:32.0906 0x0840 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: D390675B8CE45E5FB359338E5E649329
20:02:32.0906 0x0840 sptd ( LockedFile.Multi.Generic ) - warning
20:02:32.0906 0x0840 sptd - detected LockedFile.Multi.Generic (1)
20:02:32.0921 0x0840 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:02:32.0921 0x0840 sr - ok
20:02:32.0953 0x0840 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
20:02:32.0968 0x0840 srservice - ok
20:02:33.0015 0x0840 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:02:33.0031 0x0840 Srv - ok
20:02:33.0078 0x0840 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:02:33.0078 0x0840 SSDPSRV - ok
20:02:33.0109 0x0840 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:02:33.0140 0x0840 stisvc - ok
20:02:33.0156 0x0840 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:02:33.0171 0x0840 swenum - ok
20:02:33.0187 0x0840 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:02:33.0187 0x0840 swmidi - ok
20:02:33.0203 0x0840 SwPrv - ok
20:02:33.0218 0x0840 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:02:33.0218 0x0840 sysaudio - ok
20:02:33.0265 0x0840 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:02:33.0265 0x0840 SysmonLog - ok
20:02:33.0296 0x0840 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:02:33.0312 0x0840 TapiSrv - ok
20:02:33.0343 0x0840 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:02:33.0375 0x0840 Tcpip - ok
20:02:33.0406 0x0840 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:02:33.0406 0x0840 TDPIPE - ok
20:02:33.0421 0x0840 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:02:33.0421 0x0840 TDTCP - ok
20:02:33.0437 0x0840 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:02:33.0437 0x0840 TermDD - ok
20:02:33.0515 0x0840 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
20:02:33.0546 0x0840 TermService - ok
20:02:33.0578 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
20:02:33.0593 0x0840 Themes - ok
20:02:33.0640 0x0840 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
20:02:33.0640 0x0840 TlntSvr - ok
20:02:33.0656 0x0840 TosIde - ok
20:02:33.0687 0x0840 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:02:33.0703 0x0840 TrkWks - ok
20:02:33.0765 0x0840 [ F2AEE22231046CAD8D2F94D2C0F9BEFB ] trufos C:\WINDOWS\system32\drivers\trufos.sys
20:02:33.0953 0x0840 trufos - ok
20:02:34.0015 0x0840 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:02:34.0078 0x0840 Udfs - ok
20:02:34.0156 0x0840 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:02:34.0312 0x0840 Update - ok
20:02:34.0421 0x0840 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
20:02:34.0437 0x0840 upnphost - ok
20:02:34.0453 0x0840 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
20:02:34.0468 0x0840 UPS - ok
20:02:34.0500 0x0840 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:02:34.0515 0x0840 usbccgp - ok
20:02:34.0531 0x0840 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:02:34.0546 0x0840 usbehci - ok
20:02:34.0593 0x0840 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:02:34.0609 0x0840 usbhub - ok
20:02:34.0671 0x0840 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:02:34.0687 0x0840 usbscan - ok
20:02:34.0703 0x0840 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:02:34.0703 0x0840 USBSTOR - ok
20:02:34.0734 0x0840 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:02:34.0734 0x0840 usbuhci - ok
20:02:34.0765 0x0840 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:02:34.0765 0x0840 VgaSave - ok
20:02:34.0781 0x0840 ViaIde - ok
20:02:34.0796 0x0840 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:02:34.0796 0x0840 VolSnap - ok
20:02:34.0843 0x0840 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
20:02:34.0859 0x0840 VSS - ok
20:02:34.0890 0x0840 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
20:02:34.0890 0x0840 W32Time - ok
20:02:34.0921 0x0840 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:02:34.0921 0x0840 Wanarp - ok
20:02:34.0937 0x0840 WDICA - ok
20:02:34.0968 0x0840 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:02:34.0968 0x0840 wdmaud - ok
20:02:35.0000 0x0840 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:02:35.0000 0x0840 WebClient - ok
20:02:35.0078 0x0840 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:02:35.0093 0x0840 winmgmt - ok
20:02:35.0125 0x0840 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
20:02:35.0140 0x0840 WmdmPmSN - ok
20:02:35.0171 0x0840 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi C:\WINDOWS\System32\advapi32.dll
20:02:35.0203 0x0840 Wmi - ok
20:02:35.0250 0x0840 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:02:35.0250 0x0840 WmiApSrv - ok
20:02:35.0343 0x0840 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
20:02:35.0375 0x0840 WMPNetworkSvc - ok
20:02:35.0390 0x0840 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
20:02:35.0406 0x0840 WpdUsb - ok
20:02:35.0437 0x0840 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:02:35.0437 0x0840 WS2IFSL - ok
20:02:35.0484 0x0840 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:02:35.0484 0x0840 wscsvc - ok
20:02:35.0515 0x0840 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:02:35.0531 0x0840 wuauserv - ok
20:02:35.0562 0x0840 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:02:35.0562 0x0840 WudfPf - ok
20:02:35.0593 0x0840 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:02:35.0593 0x0840 WudfRd - ok
20:02:35.0625 0x0840 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
20:02:35.0656 0x0840 WudfSvc - ok
20:02:35.0703 0x0840 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:02:35.0734 0x0840 WZCSVC - ok
20:02:35.0750 0x0840 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:02:35.0765 0x0840 xmlprov - ok
20:02:35.0765 0x0840 ================ Scan global ===============================
20:02:35.0796 0x0840 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
20:02:35.0828 0x0840 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:02:35.0875 0x0840 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:02:35.0906 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
20:02:35.0906 0x0840 [Global] - ok
20:02:35.0906 0x0840 ================ Scan MBR ==================================
20:02:35.0921 0x0840 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:02:36.0109 0x0840 \Device\Harddisk0\DR0 - ok
20:02:36.0109 0x0840 ================ Scan VBR ==================================
20:02:36.0109 0x0840 [ F30B56B5AEEDC1ACCE4617F40D113564 ] \Device\Harddisk0\DR0\Partition1
20:02:36.0125 0x0840 \Device\Harddisk0\DR0\Partition1 - ok
20:02:36.0125 0x0840 ============================================================
20:02:36.0125 0x0840 Scan finished
20:02:36.0125 0x0840 ============================================================
20:02:36.0140 0x0a7c Detected object count: 2
20:02:36.0140 0x0a7c Actual detected object count: 2
20:02:40.0484 0x0a7c atapi ( LockedFile.Multi.Generic ) - skipped by user
20:02:40.0484 0x0a7c atapi ( LockedFile.Multi.Generic ) - User select action: Skip
20:02:40.0484 0x0a7c sptd ( LockedFile.Multi.Generic ) - skipped by user
20:02:40.0484 0x0a7c sptd ( LockedFile.Multi.Generic ) - User select action: Skip
20:03:18.0015 0x0df0 ============================================================
20:03:18.0015 0x0df0 Scan started
20:03:18.0015 0x0df0 Mode: Manual;
20:03:18.0015 0x0df0 ============================================================
20:03:18.0437 0x0df0 ================ Scan system memory ========================
20:03:18.0437 0x0df0 System memory - ok
20:03:18.0437 0x0df0 ================ Scan services =============================
20:03:18.0812 0x0df0 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
20:03:18.0812 0x0df0 Aavmker4 - ok
20:03:18.0812 0x0df0 Abiosdsk - ok
20:03:18.0953 0x0df0 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
20:03:18.0953 0x0df0 ACDaemon - ok
20:03:18.0984 0x0df0 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:03:18.0984 0x0df0 ACPI - ok
20:03:19.0031 0x0df0 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:03:19.0031 0x0df0 ACPIEC - ok
20:03:19.0093 0x0df0 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:03:19.0093 0x0df0 AdobeFlashPlayerUpdateSvc - ok
20:03:19.0125 0x0df0 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:03:19.0125 0x0df0 aec - ok
20:03:19.0156 0x0df0 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:03:19.0156 0x0df0 AFD - ok
20:03:19.0203 0x0df0 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:03:19.0203 0x0df0 Alerter - ok
20:03:19.0218 0x0df0 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
20:03:19.0218 0x0df0 ALG - ok
20:03:19.0218 0x0df0 AliIde - ok
20:03:19.0265 0x0df0 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:03:19.0265 0x0df0 AppMgmt - ok
20:03:19.0375 0x0df0 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:03:19.0375 0x0df0 aspnet_state - ok
20:03:19.0406 0x0df0 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:03:19.0406 0x0df0 aswFsBlk - ok
20:03:19.0453 0x0df0 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
20:03:19.0453 0x0df0 aswMon2 - ok
20:03:19.0468 0x0df0 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
20:03:19.0468 0x0df0 aswRdr - ok
20:03:19.0515 0x0df0 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
20:03:19.0531 0x0df0 aswSnx - ok
20:03:19.0562 0x0df0 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
20:03:19.0562 0x0df0 aswSP - ok
20:03:19.0593 0x0df0 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
20:03:19.0593 0x0df0 aswTdi - ok
20:03:19.0609 0x0df0 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:03:19.0609 0x0df0 AsyncMac - ok
20:03:19.0640 0x0df0 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:03:19.0656 0x0df0 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: 9F3A2F5AA6875C72BF062C712CFA2674
20:03:19.0656 0x0df0 atapi ( LockedFile.Multi.Generic ) - warning
20:03:19.0656 0x0df0 atapi - detected LockedFile.Multi.Generic (1)
20:03:19.0656 0x0df0 Atdisk - ok
20:03:19.0671 0x0df0 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:03:19.0671 0x0df0 Atmarpc - ok
20:03:19.0703 0x0df0 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:03:19.0703 0x0df0 AudioSrv - ok
20:03:19.0718 0x0df0 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:03:19.0734 0x0df0 audstub - ok
20:03:19.0828 0x0df0 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
20:03:19.0843 0x0df0 avast! Antivirus - ok
20:03:19.0875 0x0df0 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:03:19.0875 0x0df0 Beep - ok
20:03:19.0921 0x0df0 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
20:03:19.0937 0x0df0 BITS - ok
20:03:19.0968 0x0df0 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
20:03:19.0968 0x0df0 Browser - ok
20:03:19.0968 0x0df0 catchme - ok
20:03:20.0000 0x0df0 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:03:20.0000 0x0df0 Cdaudio - ok
20:03:20.0031 0x0df0 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:03:20.0046 0x0df0 Cdfs - ok
20:03:20.0062 0x0df0 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:03:20.0062 0x0df0 Cdrom - ok
20:03:20.0062 0x0df0 Changer - ok
20:03:20.0093 0x0df0 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:03:20.0093 0x0df0 CiSvc - ok
20:03:20.0109 0x0df0 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:03:20.0109 0x0df0 ClipSrv - ok
20:03:20.0156 0x0df0 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:03:20.0156 0x0df0 clr_optimization_v2.0.50727_32 - ok
20:03:20.0156 0x0df0 CmdIde - ok
20:03:20.0171 0x0df0 COMSysApp - ok
20:03:20.0187 0x0df0 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:03:20.0187 0x0df0 CryptSvc - ok
20:03:20.0234 0x0df0 [ 99159E3EF20A4792AEFE4115E8AD0957 ] d346bus C:\WINDOWS\system32\DRIVERS\d346bus.sys
20:03:20.0234 0x0df0 d346bus - ok
20:03:20.0250 0x0df0 [ FB228CD598B7686E98FBF7BFB55666EB ] d346prt C:\WINDOWS\system32\Drivers\d346prt.sys
20:03:20.0250 0x0df0 d346prt - ok
20:03:20.0296 0x0df0 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:03:20.0312 0x0df0 DcomLaunch - ok
20:03:20.0328 0x0df0 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:03:20.0343 0x0df0 Dhcp - ok
20:03:20.0359 0x0df0 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:03:20.0359 0x0df0 Disk - ok
20:03:20.0375 0x0df0 dmadmin - ok
20:03:20.0421 0x0df0 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:03:20.0421 0x0df0 dmboot - ok
20:03:20.0437 0x0df0 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:03:20.0453 0x0df0 dmio - ok
20:03:20.0484 0x0df0 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:03:20.0484 0x0df0 dmload - ok
20:03:20.0515 0x0df0 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:03:20.0515 0x0df0 dmserver - ok
20:03:20.0531 0x0df0 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:03:20.0531 0x0df0 DMusic - ok
20:03:20.0562 0x0df0 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:03:20.0562 0x0df0 Dnscache - ok
20:03:20.0593 0x0df0 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:03:20.0609 0x0df0 Dot3svc - ok
20:03:20.0625 0x0df0 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:03:20.0625 0x0df0 drmkaud - ok
20:03:20.0640 0x0df0 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:03:20.0640 0x0df0 EapHost - ok
20:03:20.0671 0x0df0 [ FD9FC82F134B1C91004FFC76A5AE494B ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys
20:03:20.0671 0x0df0 ENTECH - ok
20:03:20.0703 0x0df0 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:03:20.0703 0x0df0 ERSvc - ok
20:03:20.0734 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
20:03:20.0734 0x0df0 Eventlog - ok
20:03:20.0781 0x0df0 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
20:03:20.0781 0x0df0 EventSystem - ok
20:03:20.0812 0x0df0 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:03:20.0828 0x0df0 Fastfat - ok
20:03:20.0859 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:03:20.0859 0x0df0 FastUserSwitchingCompatibility - ok
20:03:20.0921 0x0df0 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:03:20.0921 0x0df0 Fdc - ok
20:03:21.0015 0x0df0 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:03:21.0015 0x0df0 Fips - ok
20:03:21.0062 0x0df0 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:03:21.0062 0x0df0 Flpydisk - ok
20:03:21.0093 0x0df0 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:03:21.0093 0x0df0 FltMgr - ok
20:03:21.0203 0x0df0 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:03:21.0203 0x0df0 FontCache3.0.0.0 - ok
20:03:21.0281 0x0df0 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:03:21.0281 0x0df0 Fs_Rec - ok
20:03:21.0328 0x0df0 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:03:21.0328 0x0df0 Ftdisk - ok
20:03:21.0359 0x0df0 [ 54789F9BA0D59072CDD4E7C200E122C4 ] gdrv C:\WINDOWS\gdrv.sys
20:03:21.0359 0x0df0 gdrv - ok
20:03:21.0390 0x0df0 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:03:21.0390 0x0df0 Gpc - ok
20:03:21.0484 0x0df0 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
20:03:21.0484 0x0df0 gupdate - ok
20:03:21.0484 0x0df0 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
20:03:21.0484 0x0df0 gupdatem - ok
20:03:21.0515 0x0df0 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:03:21.0515 0x0df0 gusvc - ok
20:03:21.0546 0x0df0 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:03:21.0546 0x0df0 HDAudBus - ok
20:03:21.0625 0x0df0 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:03:21.0625 0x0df0 helpsvc - ok
20:03:21.0640 0x0df0 [ 00E25EE90166B3E1BE6E74AEBF858306 ] HidServ C:\WINDOWS\System32\hidserv.dll
20:03:21.0640 0x0df0 HidServ - ok
20:03:21.0656 0x0df0 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:03:21.0656 0x0df0 HidUsb - ok
20:03:21.0687 0x0df0 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:03:21.0687 0x0df0 hkmsvc - ok
20:03:21.0718 0x0df0 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:03:21.0718 0x0df0 HTTP - ok
20:03:21.0750 0x0df0 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:03:21.0765 0x0df0 HTTPFilter - ok
20:03:21.0796 0x0df0 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:03:21.0796 0x0df0 i8042prt - ok
20:03:21.0859 0x0df0 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:03:21.0859 0x0df0 IDriverT - ok
20:03:22.0015 0x0df0 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:03:22.0015 0x0df0 idsvc - ok
20:03:22.0046 0x0df0 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:03:22.0046 0x0df0 Imapi - ok
20:03:22.0078 0x0df0 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:03:22.0078 0x0df0 ImapiService - ok
20:03:22.0265 0x0df0 [ C4006AF18682FCA0D8A011A0A21070F8 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:03:22.0312 0x0df0 IntcAzAudAddService - ok
20:03:22.0328 0x0df0 IntelIde - ok
20:03:22.0359 0x0df0 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:03:22.0359 0x0df0 intelppm - ok
20:03:22.0375 0x0df0 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:03:22.0375 0x0df0 Ip6Fw - ok
20:03:22.0406 0x0df0 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:03:22.0421 0x0df0 IpFilterDriver - ok
20:03:22.0437 0x0df0 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:03:22.0437 0x0df0 IpInIp - ok
20:03:22.0453 0x0df0 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:03:22.0453 0x0df0 IpNat - ok
20:03:22.0484 0x0df0 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:03:22.0500 0x0df0 IPSec - ok
20:03:22.0500 0x0df0 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:03:22.0500 0x0df0 IRENUM - ok
20:03:22.0531 0x0df0 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:03:22.0531 0x0df0 isapnp - ok
20:03:22.0546 0x0df0 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:03:22.0546 0x0df0 Kbdclass - ok
20:03:22.0562 0x0df0 [ 86C8F23616C6C6E5B2776901C17B945B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:03:22.0562 0x0df0 kbdhid - ok
20:03:22.0593 0x0df0 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:03:22.0593 0x0df0 kmixer - ok
20:03:22.0625 0x0df0 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:03:22.0625 0x0df0 KSecDD - ok
20:03:22.0656 0x0df0 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:03:22.0671 0x0df0 lanmanserver - ok
20:03:22.0703 0x0df0 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:03:22.0718 0x0df0 lanmanworkstation - ok
20:03:22.0718 0x0df0 lbrtfdc - ok
20:03:22.0750 0x0df0 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:03:22.0750 0x0df0 LmHosts - ok
20:03:22.0812 0x0df0 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
20:03:22.0812 0x0df0 MDM - ok
20:03:22.0843 0x0df0 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:03:22.0843 0x0df0 Messenger - ok
20:03:22.0875 0x0df0 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:03:22.0875 0x0df0 mnmdd - ok
20:03:22.0906 0x0df0 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:03:22.0906 0x0df0 mnmsrvc - ok
20:03:22.0921 0x0df0 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:03:22.0921 0x0df0 Modem - ok
20:03:22.0937 0x0df0 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:03:22.0953 0x0df0 Mouclass - ok
20:03:22.0968 0x0df0 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:03:22.0968 0x0df0 mouhid - ok
20:03:22.0984 0x0df0 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:03:22.0984 0x0df0 MountMgr - ok
20:03:23.0046 0x0df0 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:03:23.0046 0x0df0 MozillaMaintenance - ok
20:03:23.0062 0x0df0 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:03:23.0062 0x0df0 MRxDAV - ok
20:03:23.0125 0x0df0 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:03:23.0125 0x0df0 MRxSmb - ok
20:03:23.0156 0x0df0 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:03:23.0156 0x0df0 MSDTC - ok
20:03:23.0171 0x0df0 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:03:23.0171 0x0df0 Msfs - ok
20:03:23.0187 0x0df0 MSIServer - ok
20:03:23.0203 0x0df0 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:03:23.0203 0x0df0 MSKSSRV - ok
20:03:23.0218 0x0df0 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:03:23.0218 0x0df0 MSPCLOCK - ok
20:03:23.0234 0x0df0 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:03:23.0234 0x0df0 MSPQM - ok
20:03:23.0265 0x0df0 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:03:23.0265 0x0df0 mssmbios - ok
20:03:23.0281 0x0df0 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:03:23.0281 0x0df0 Mup - ok
20:03:23.0328 0x0df0 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
20:03:23.0328 0x0df0 napagent - ok
20:03:23.0359 0x0df0 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:03:23.0359 0x0df0 NDIS - ok
20:03:23.0390 0x0df0 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:03:23.0406 0x0df0 NdisTapi - ok
20:03:23.0437 0x0df0 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:03:23.0437 0x0df0 Ndisuio - ok
20:03:23.0453 0x0df0 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:03:23.0453 0x0df0 NdisWan - ok
20:03:23.0468 0x0df0 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:03:23.0468 0x0df0 NDProxy - ok
20:03:23.0578 0x0df0 [ 6D4028D458EAAA1782099750790DC8C9 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
20:03:23.0593 0x0df0 Nero BackItUp Scheduler 3 - ok
20:03:23.0625 0x0df0 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:03:23.0625 0x0df0 NetBIOS - ok
20:03:23.0640 0x0df0 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:03:23.0656 0x0df0 NetBT - ok
20:03:23.0671 0x0df0 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
20:03:23.0687 0x0df0 NetDDE - ok
20:03:23.0687 0x0df0 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:03:23.0687 0x0df0 NetDDEdsdm - ok
20:03:23.0718 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:03:23.0718 0x0df0 Netlogon - ok
20:03:23.0750 0x0df0 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
20:03:23.0750 0x0df0 Netman - ok
20:03:23.0812 0x0df0 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:03:23.0812 0x0df0 NetTcpPortSharing - ok
20:03:23.0859 0x0df0 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
20:03:23.0875 0x0df0 Nla - ok
20:03:23.0937 0x0df0 [ FF4D73B16EA3A32D34CEB3A7BC3C3773 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
20:03:23.0953 0x0df0 NMIndexingService - ok
20:03:23.0984 0x0df0 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:03:23.0984 0x0df0 Npfs - ok
20:03:24.0031 0x0df0 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:03:24.0031 0x0df0 Ntfs - ok
20:03:24.0062 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:03:24.0062 0x0df0 NtLmSsp - ok
20:03:24.0109 0x0df0 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:03:24.0109 0x0df0 NtmsSvc - ok
20:03:24.0140 0x0df0 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
20:03:24.0140 0x0df0 Null - ok
20:03:24.0546 0x0df0 [ 231E377E60A96B53C169C5E04AC0A67A ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:03:24.0640 0x0df0 nv - ok
20:03:24.0671 0x0df0 [ E10AACC565E0A8B76AC4FB912343D38E ] NVHDA C:\WINDOWS\system32\drivers\nvhda32.sys
20:03:24.0671 0x0df0 NVHDA - ok
20:03:24.0718 0x0df0 [ A1D291A173A68C332678DDF3FC38D85B ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
20:03:24.0718 0x0df0 NVSvc - ok
20:03:24.0750 0x0df0 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:03:24.0750 0x0df0 NwlnkFlt - ok
20:03:24.0765 0x0df0 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:03:24.0765 0x0df0 NwlnkFwd - ok
20:03:24.0796 0x0df0 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:03:24.0796 0x0df0 ose - ok
20:03:24.0828 0x0df0 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
20:03:24.0828 0x0df0 Parport - ok
20:03:24.0843 0x0df0 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:03:24.0843 0x0df0 PartMgr - ok
20:03:24.0875 0x0df0 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:03:24.0875 0x0df0 ParVdm - ok
20:03:24.0906 0x0df0 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:03:24.0906 0x0df0 PCI - ok
20:03:24.0906 0x0df0 PCIDump - ok
20:03:24.0953 0x0df0 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:03:24.0953 0x0df0 PCIIde - ok
20:03:24.0984 0x0df0 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:03:24.0984 0x0df0 Pcmcia - ok
20:03:24.0984 0x0df0 PDCOMP - ok
20:03:25.0000 0x0df0 PDFRAME - ok
20:03:25.0000 0x0df0 PDRELI - ok
20:03:25.0015 0x0df0 PDRFRAME - ok
20:03:25.0046 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
20:03:25.0046 0x0df0 PlugPlay - ok
20:03:25.0062 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:03:25.0062 0x0df0 PolicyAgent - ok
20:03:25.0093 0x0df0 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:03:25.0093 0x0df0 PptpMiniport - ok
20:03:25.0093 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:03:25.0093 0x0df0 ProtectedStorage - ok
20:03:25.0125 0x0df0 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:03:25.0125 0x0df0 PSched - ok
20:03:25.0156 0x0df0 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:03:25.0156 0x0df0 Ptilink - ok
20:03:25.0156 0x0df0 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:03:25.0156 0x0df0 RasAcd - ok
20:03:25.0187 0x0df0 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:03:25.0187 0x0df0 RasAuto - ok
20:03:25.0203 0x0df0 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:03:25.0203 0x0df0 Rasl2tp - ok
20:03:25.0234 0x0df0 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:03:25.0250 0x0df0 RasMan - ok
20:03:25.0265 0x0df0 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:03:25.0265 0x0df0 RasPppoe - ok
20:03:25.0312 0x0df0 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:03:25.0312 0x0df0 Raspti - ok
20:03:25.0328 0x0df0 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:03:25.0328 0x0df0 Rdbss - ok
20:03:25.0343 0x0df0 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:03:25.0359 0x0df0 RDPCDD - ok
20:03:25.0390 0x0df0 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:03:25.0390 0x0df0 rdpdr - ok
20:03:25.0421 0x0df0 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:03:25.0421 0x0df0 RDPWD - ok
20:03:25.0453 0x0df0 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:03:25.0468 0x0df0 RDSessMgr - ok
20:03:25.0484 0x0df0 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:03:25.0484 0x0df0 redbook - ok
20:03:25.0515 0x0df0 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:03:25.0515 0x0df0 RemoteAccess - ok
20:03:25.0546 0x0df0 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:03:25.0546 0x0df0 RemoteRegistry - ok
20:03:25.0578 0x0df0 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
20:03:25.0578 0x0df0 RpcLocator - ok
20:03:25.0609 0x0df0 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\System32\rpcss.dll
20:03:25.0625 0x0df0 RpcSs - ok
20:03:25.0656 0x0df0 [ 99F13D7E9AAEC74A5B7D10AB780D9D6F ] RSVP C:\WINDOWS\system32\rsvp.exe
20:03:25.0656 0x0df0 RSVP - ok
20:03:25.0703 0x0df0 [ BADABE0940C01619E8510B90FB314929 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:03:25.0703 0x0df0 RTLE8023xp - ok
20:03:25.0718 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
20:03:25.0718 0x0df0 SamSs - ok
20:03:25.0750 0x0df0 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:03:25.0750 0x0df0 SCardSvr - ok
20:03:25.0781 0x0df0 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:03:25.0796 0x0df0 Schedule - ok
20:03:25.0828 0x0df0 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:03:25.0828 0x0df0 Secdrv - ok
20:03:25.0859 0x0df0 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:03:25.0875 0x0df0 seclogon - ok
20:03:25.0890 0x0df0 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
20:03:25.0890 0x0df0 SENS - ok
20:03:25.0906 0x0df0 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:03:25.0906 0x0df0 serenum - ok
20:03:25.0937 0x0df0 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:03:25.0937 0x0df0 Serial - ok
20:03:25.0953 0x0df0 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:03:25.0953 0x0df0 Sfloppy - ok
20:03:26.0000 0x0df0 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:03:26.0000 0x0df0 SharedAccess - ok
20:03:26.0031 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:03:26.0031 0x0df0 ShellHWDetection - ok
20:03:26.0031 0x0df0 Simbad - ok
20:03:26.0484 0x0df0 [ D0776778A9FC5E37F2E9EB21FC8A9709 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
20:03:26.0515 0x0df0 Skype C2C Service - ok
20:03:26.0609 0x0df0 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
20:03:26.0609 0x0df0 SkypeUpdate - ok
20:03:26.0625 0x0df0 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:03:26.0625 0x0df0 splitter - ok
20:03:26.0656 0x0df0 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:03:26.0656 0x0df0 Spooler - ok
20:03:26.0718 0x0df0 [ D390675B8CE45E5FB359338E5E649329 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
20:03:26.0718 0x0df0 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: D390675B8CE45E5FB359338E5E649329
20:03:26.0718 0x0df0 sptd ( LockedFile.Multi.Generic ) - warning
20:03:26.0718 0x0df0 sptd - detected LockedFile.Multi.Generic (1)
20:03:26.0734 0x0df0 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:03:26.0734 0x0df0 sr - ok
20:03:26.0781 0x0df0 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
20:03:26.0781 0x0df0 srservice - ok
20:03:26.0828 0x0df0 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:03:26.0843 0x0df0 Srv - ok
20:03:26.0859 0x0df0 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:03:26.0859 0x0df0 SSDPSRV - ok
20:03:26.0890 0x0df0 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:03:26.0906 0x0df0 stisvc - ok
20:03:26.0937 0x0df0 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:03:26.0937 0x0df0 swenum - ok
20:03:26.0953 0x0df0 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:03:26.0953 0x0df0 swmidi - ok
20:03:26.0968 0x0df0 SwPrv - ok
20:03:27.0000 0x0df0 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:03:27.0000 0x0df0 sysaudio - ok
20:03:27.0031 0x0df0 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:03:27.0031 0x0df0 SysmonLog - ok
20:03:27.0062 0x0df0 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:03:27.0062 0x0df0 TapiSrv - ok
20:03:27.0125 0x0df0 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:03:27.0125 0x0df0 Tcpip - ok
20:03:27.0156 0x0df0 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:03:27.0156 0x0df0 TDPIPE - ok
20:03:27.0171 0x0df0 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:03:27.0171 0x0df0 TDTCP - ok
20:03:27.0187 0x0df0 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:03:27.0187 0x0df0 TermDD - ok
20:03:27.0218 0x0df0 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
20:03:27.0234 0x0df0 TermService - ok
20:03:27.0265 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
20:03:27.0265 0x0df0 Themes - ok
20:03:27.0312 0x0df0 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
20:03:27.0312 0x0df0 TlntSvr - ok
20:03:27.0328 0x0df0 TosIde - ok
20:03:27.0343 0x0df0 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:03:27.0343 0x0df0 TrkWks - ok
20:03:27.0390 0x0df0 [ F2AEE22231046CAD8D2F94D2C0F9BEFB ] trufos C:\WINDOWS\system32\drivers\trufos.sys
20:03:27.0406 0x0df0 trufos - ok
20:03:27.0421 0x0df0 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:03:27.0437 0x0df0 Udfs - ok
20:03:27.0468 0x0df0 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:03:27.0468 0x0df0 Update - ok
20:03:27.0500 0x0df0 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
20:03:27.0515 0x0df0 upnphost - ok
20:03:27.0531 0x0df0 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
20:03:27.0531 0x0df0 UPS - ok
20:03:27.0562 0x0df0 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:03:27.0562 0x0df0 usbccgp - ok
20:03:27.0578 0x0df0 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:03:27.0578 0x0df0 usbehci - ok
20:03:27.0593 0x0df0 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:03:27.0593 0x0df0 usbhub - ok
20:03:27.0609 0x0df0 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:03:27.0609 0x0df0 usbscan - ok
20:03:27.0640 0x0df0 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:03:27.0640 0x0df0 USBSTOR - ok
20:03:27.0656 0x0df0 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:03:27.0656 0x0df0 usbuhci - ok
20:03:27.0671 0x0df0 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:03:27.0671 0x0df0 VgaSave - ok
20:03:27.0671 0x0df0 ViaIde - ok
20:03:27.0703 0x0df0 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:03:27.0703 0x0df0 VolSnap - ok
20:03:27.0734 0x0df0 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
20:03:27.0734 0x0df0 VSS - ok
20:03:27.0765 0x0df0 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
20:03:27.0781 0x0df0 W32Time - ok
20:03:27.0796 0x0df0 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:03:27.0796 0x0df0 Wanarp - ok
20:03:27.0812 0x0df0 WDICA - ok
20:03:27.0843 0x0df0 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:03:27.0843 0x0df0 wdmaud - ok
20:03:27.0875 0x0df0 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:03:27.0875 0x0df0 WebClient - ok
20:03:27.0953 0x0df0 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:03:27.0953 0x0df0 winmgmt - ok
20:03:27.0984 0x0df0 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
20:03:28.0000 0x0df0 WmdmPmSN - ok
20:03:28.0046 0x0df0 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi C:\WINDOWS\System32\advapi32.dll
20:03:28.0062 0x0df0 Wmi - ok
20:03:28.0093 0x0df0 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:03:28.0093 0x0df0 WmiApSrv - ok
20:03:28.0187 0x0df0 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
20:03:28.0187 0x0df0 WMPNetworkSvc - ok
20:03:28.0218 0x0df0 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
20:03:28.0218 0x0df0 WpdUsb - ok
20:03:28.0250 0x0df0 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:03:28.0250 0x0df0 WS2IFSL - ok
20:03:28.0296 0x0df0 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:03:28.0296 0x0df0 wscsvc - ok
20:03:28.0328 0x0df0 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:03:28.0328 0x0df0 wuauserv - ok
20:03:28.0343 0x0df0 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:03:28.0359 0x0df0 WudfPf - ok
20:03:28.0390 0x0df0 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:03:28.0390 0x0df0 WudfRd - ok
20:03:28.0421 0x0df0 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
20:03:28.0421 0x0df0 WudfSvc - ok
20:03:28.0468 0x0df0 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:03:28.0484 0x0df0 WZCSVC - ok
20:03:28.0500 0x0df0 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:03:28.0515 0x0df0 xmlprov - ok
20:03:28.0515 0x0df0 ================ Scan global ===============================
20:03:28.0546 0x0df0 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
20:03:28.0578 0x0df0 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:03:28.0593 0x0df0 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:03:28.0625 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
20:03:28.0640 0x0df0 [Global] - ok
20:03:28.0640 0x0df0 ================ Scan MBR ==================================
20:03:28.0656 0x0df0 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:03:28.0843 0x0df0 \Device\Harddisk0\DR0 - ok
20:03:28.0843 0x0df0 ================ Scan VBR ==================================
20:03:28.0843 0x0df0 [ F30B56B5AEEDC1ACCE4617F40D113564 ] \Device\Harddisk0\DR0\Partition1
20:03:28.0859 0x0df0 \Device\Harddisk0\DR0\Partition1 - ok
20:03:28.0859 0x0df0 ============================================================
20:03:28.0859 0x0df0 Scan finished
20:03:28.0859 0x0df0 ============================================================
20:03:28.0875 0x0cc0 Detected object count: 2
20:03:28.0875 0x0cc0 Actual detected object count: 2
20:03:50.0468 0x0cc0 atapi ( LockedFile.Multi.Generic ) - skipped by user
20:03:50.0468 0x0cc0 atapi ( LockedFile.Multi.Generic ) - User select action: Skip
20:03:50.0468 0x0cc0 sptd ( LockedFile.Multi.Generic ) - skipped by user
20:03:50.0468 0x0cc0 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#20 Příspěvek od Petulda »

19:18:38.0843 0x0570 TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29
19:18:39.0187 0x0570 ============================================================
19:18:39.0187 0x0570 Current date / time: 2013/09/17 19:18:39.0187
19:18:39.0187 0x0570 SystemInfo:
19:18:39.0187 0x0570
19:18:39.0187 0x0570 OS Version: 5.1.2600 ServicePack: 3.0
19:18:39.0187 0x0570 Product type: Workstation
19:18:39.0187 0x0570 ComputerName: LEPSI
19:18:39.0187 0x0570 UserName: Administrator
19:18:39.0187 0x0570 Windows directory: C:\WINDOWS
19:18:39.0187 0x0570 System windows directory: C:\WINDOWS
19:18:39.0187 0x0570 Processor architecture: Intel x86
19:18:39.0187 0x0570 Number of processors: 2
19:18:39.0187 0x0570 Page size: 0x1000
19:18:39.0187 0x0570 Boot type: Normal boot
19:18:39.0187 0x0570 ============================================================
19:18:39.0187 0x0570 BG loaded
19:18:53.0687 0x0570 Drive \Device\Harddisk0\DR0 - Size: 0xDF98DDE00 (55.90 Gb), SectorSize: 0x200, Cylinders: 0x1C81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x000000A4
19:18:53.0718 0x0570 Drive \Device\Harddisk1\DR2 - Size: 0x3C7200000 (15.11 Gb), SectorSize: 0x200, Cylinders: 0x7B4, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:18:53.0718 0x0570 ============================================================
19:18:53.0718 0x0570 \Device\Harddisk0\DR0:
19:18:53.0750 0x0570 MBR partitions:
19:18:53.0750 0x0570 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x6FC7C41
19:18:53.0750 0x0570 \Device\Harddisk1\DR2:
19:18:53.0750 0x0570 MBR partitions:
19:18:53.0750 0x0570 \Device\Harddisk1\DR2\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x1E36636
19:18:53.0750 0x0570 ============================================================
19:18:54.0000 0x0570 C: <-> \Device\Harddisk0\DR0\Partition1
19:18:54.0000 0x0570 ============================================================
19:18:54.0000 0x0570 Initialize success
19:18:54.0000 0x0570 ============================================================
20:02:17.0093 0x0840 ============================================================
20:02:17.0093 0x0840 Scan started
20:02:17.0093 0x0840 Mode: Manual;
20:02:17.0093 0x0840 ============================================================
20:02:17.0484 0x0840 ================ Scan system memory ========================
20:02:17.0484 0x0840 System memory - ok
20:02:17.0484 0x0840 ================ Scan services =============================
20:02:17.0859 0x0840 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
20:02:17.0859 0x0840 Aavmker4 - ok
20:02:17.0859 0x0840 Abiosdsk - ok
20:02:18.0015 0x0840 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
20:02:18.0031 0x0840 ACDaemon - ok
20:02:18.0062 0x0840 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:02:18.0078 0x0840 ACPI - ok
20:02:18.0109 0x0840 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:02:18.0109 0x0840 ACPIEC - ok
20:02:18.0203 0x0840 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:02:18.0218 0x0840 AdobeFlashPlayerUpdateSvc - ok
20:02:18.0250 0x0840 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:02:18.0250 0x0840 aec - ok
20:02:18.0296 0x0840 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:02:18.0296 0x0840 AFD - ok
20:02:18.0328 0x0840 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:02:18.0328 0x0840 Alerter - ok
20:02:18.0343 0x0840 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
20:02:18.0343 0x0840 ALG - ok
20:02:18.0359 0x0840 AliIde - ok
20:02:18.0390 0x0840 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:02:18.0406 0x0840 AppMgmt - ok
20:02:18.0500 0x0840 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:02:18.0546 0x0840 aspnet_state - ok
20:02:18.0578 0x0840 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:02:18.0578 0x0840 aswFsBlk - ok
20:02:18.0609 0x0840 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
20:02:18.0625 0x0840 aswMon2 - ok
20:02:18.0640 0x0840 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
20:02:18.0640 0x0840 aswRdr - ok
20:02:18.0687 0x0840 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
20:02:18.0718 0x0840 aswSnx - ok
20:02:18.0750 0x0840 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
20:02:18.0765 0x0840 aswSP - ok
20:02:18.0781 0x0840 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
20:02:18.0781 0x0840 aswTdi - ok
20:02:18.0812 0x0840 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:02:18.0812 0x0840 AsyncMac - ok
20:02:18.0843 0x0840 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:02:18.0843 0x0840 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: 9F3A2F5AA6875C72BF062C712CFA2674
20:02:18.0843 0x0840 atapi ( LockedFile.Multi.Generic ) - warning
20:02:18.0843 0x0840 atapi - detected LockedFile.Multi.Generic (1)
20:02:18.0843 0x0840 Atdisk - ok
20:02:18.0875 0x0840 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:02:18.0890 0x0840 Atmarpc - ok
20:02:18.0968 0x0840 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:02:18.0984 0x0840 AudioSrv - ok
20:02:19.0046 0x0840 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:02:19.0062 0x0840 audstub - ok
20:02:19.0296 0x0840 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
20:02:19.0312 0x0840 avast! Antivirus - ok
20:02:19.0359 0x0840 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:02:19.0390 0x0840 Beep - ok
20:02:19.0453 0x0840 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
20:02:19.0515 0x0840 BITS - ok
20:02:19.0546 0x0840 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
20:02:19.0546 0x0840 Browser - ok
20:02:19.0562 0x0840 catchme - ok
20:02:19.0640 0x0840 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:02:19.0687 0x0840 Cdaudio - ok
20:02:19.0734 0x0840 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:02:19.0781 0x0840 Cdfs - ok
20:02:19.0843 0x0840 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:02:19.0875 0x0840 Cdrom - ok
20:02:19.0875 0x0840 Changer - ok
20:02:19.0937 0x0840 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:02:19.0953 0x0840 CiSvc - ok
20:02:19.0984 0x0840 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:02:20.0015 0x0840 ClipSrv - ok
20:02:20.0406 0x0840 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:02:20.0578 0x0840 clr_optimization_v2.0.50727_32 - ok
20:02:20.0593 0x0840 CmdIde - ok
20:02:20.0593 0x0840 COMSysApp - ok
20:02:20.0640 0x0840 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:02:20.0656 0x0840 CryptSvc - ok
20:02:20.0703 0x0840 [ 99159E3EF20A4792AEFE4115E8AD0957 ] d346bus C:\WINDOWS\system32\DRIVERS\d346bus.sys
20:02:20.0718 0x0840 d346bus - ok
20:02:20.0734 0x0840 [ FB228CD598B7686E98FBF7BFB55666EB ] d346prt C:\WINDOWS\system32\Drivers\d346prt.sys
20:02:20.0750 0x0840 d346prt - ok
20:02:21.0125 0x0840 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:02:21.0312 0x0840 DcomLaunch - ok
20:02:21.0359 0x0840 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:02:21.0359 0x0840 Dhcp - ok
20:02:21.0390 0x0840 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:02:21.0421 0x0840 Disk - ok
20:02:21.0421 0x0840 dmadmin - ok
20:02:22.0078 0x0840 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:02:22.0390 0x0840 dmboot - ok
20:02:22.0484 0x0840 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:02:22.0515 0x0840 dmio - ok
20:02:22.0546 0x0840 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:02:22.0546 0x0840 dmload - ok
20:02:22.0593 0x0840 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:02:22.0609 0x0840 dmserver - ok
20:02:22.0625 0x0840 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:02:22.0640 0x0840 DMusic - ok
20:02:22.0671 0x0840 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:02:22.0703 0x0840 Dnscache - ok
20:02:22.0734 0x0840 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:02:22.0796 0x0840 Dot3svc - ok
20:02:22.0812 0x0840 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:02:22.0812 0x0840 drmkaud - ok
20:02:22.0875 0x0840 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:02:22.0875 0x0840 EapHost - ok
20:02:22.0906 0x0840 [ FD9FC82F134B1C91004FFC76A5AE494B ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys
20:02:22.0906 0x0840 ENTECH - ok
20:02:22.0953 0x0840 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:02:22.0953 0x0840 ERSvc - ok
20:02:22.0984 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
20:02:23.0000 0x0840 Eventlog - ok
20:02:23.0031 0x0840 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
20:02:23.0046 0x0840 EventSystem - ok
20:02:23.0078 0x0840 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:02:23.0093 0x0840 Fastfat - ok
20:02:23.0125 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:02:23.0140 0x0840 FastUserSwitchingCompatibility - ok
20:02:23.0156 0x0840 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:02:23.0156 0x0840 Fdc - ok
20:02:23.0187 0x0840 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:02:23.0187 0x0840 Fips - ok
20:02:23.0203 0x0840 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:02:23.0218 0x0840 Flpydisk - ok
20:02:23.0234 0x0840 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:02:23.0234 0x0840 FltMgr - ok
20:02:23.0312 0x0840 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:02:23.0328 0x0840 FontCache3.0.0.0 - ok
20:02:23.0359 0x0840 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:02:23.0359 0x0840 Fs_Rec - ok
20:02:23.0375 0x0840 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:02:23.0375 0x0840 Ftdisk - ok
20:02:23.0406 0x0840 [ 54789F9BA0D59072CDD4E7C200E122C4 ] gdrv C:\WINDOWS\gdrv.sys
20:02:25.0875 0x0840 gdrv - ok
20:02:25.0953 0x0840 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:02:25.0984 0x0840 Gpc - ok
20:02:26.0109 0x0840 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
20:02:26.0156 0x0840 gupdate - ok
20:02:26.0171 0x0840 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
20:02:26.0171 0x0840 gupdatem - ok
20:02:26.0234 0x0840 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:02:26.0265 0x0840 gusvc - ok
20:02:26.0312 0x0840 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:02:26.0312 0x0840 HDAudBus - ok
20:02:26.0453 0x0840 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:02:26.0484 0x0840 helpsvc - ok
20:02:26.0500 0x0840 [ 00E25EE90166B3E1BE6E74AEBF858306 ] HidServ C:\WINDOWS\System32\hidserv.dll
20:02:26.0515 0x0840 HidServ - ok
20:02:26.0531 0x0840 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:02:26.0531 0x0840 HidUsb - ok
20:02:26.0578 0x0840 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:02:26.0593 0x0840 hkmsvc - ok
20:02:26.0625 0x0840 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:02:26.0625 0x0840 HTTP - ok
20:02:26.0640 0x0840 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:02:26.0656 0x0840 HTTPFilter - ok
20:02:26.0687 0x0840 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:02:26.0687 0x0840 i8042prt - ok
20:02:26.0750 0x0840 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:02:26.0750 0x0840 IDriverT - ok
20:02:26.0906 0x0840 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:02:26.0984 0x0840 idsvc - ok
20:02:27.0000 0x0840 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:02:27.0000 0x0840 Imapi - ok
20:02:27.0031 0x0840 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:02:27.0046 0x0840 ImapiService - ok
20:02:27.0234 0x0840 [ C4006AF18682FCA0D8A011A0A21070F8 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:02:27.0390 0x0840 IntcAzAudAddService - ok
20:02:27.0406 0x0840 IntelIde - ok
20:02:27.0421 0x0840 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:02:27.0421 0x0840 intelppm - ok
20:02:27.0437 0x0840 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:02:27.0437 0x0840 Ip6Fw - ok
20:02:27.0484 0x0840 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:02:27.0484 0x0840 IpFilterDriver - ok
20:02:27.0500 0x0840 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:02:27.0500 0x0840 IpInIp - ok
20:02:27.0531 0x0840 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:02:27.0531 0x0840 IpNat - ok
20:02:27.0562 0x0840 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:02:27.0562 0x0840 IPSec - ok
20:02:27.0593 0x0840 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:02:27.0593 0x0840 IRENUM - ok
20:02:27.0609 0x0840 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:02:27.0609 0x0840 isapnp - ok
20:02:27.0625 0x0840 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:02:27.0625 0x0840 Kbdclass - ok
20:02:27.0640 0x0840 [ 86C8F23616C6C6E5B2776901C17B945B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:02:27.0656 0x0840 kbdhid - ok
20:02:27.0671 0x0840 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:02:27.0687 0x0840 kmixer - ok
20:02:27.0703 0x0840 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:02:27.0718 0x0840 KSecDD - ok
20:02:27.0750 0x0840 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:02:27.0750 0x0840 lanmanserver - ok
20:02:27.0781 0x0840 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:02:27.0796 0x0840 lanmanworkstation - ok
20:02:27.0796 0x0840 lbrtfdc - ok
20:02:27.0828 0x0840 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:02:27.0843 0x0840 LmHosts - ok
20:02:27.0890 0x0840 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
20:02:27.0906 0x0840 MDM - ok
20:02:27.0921 0x0840 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:02:27.0921 0x0840 Messenger - ok
20:02:27.0953 0x0840 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:02:27.0953 0x0840 mnmdd - ok
20:02:27.0984 0x0840 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:02:27.0984 0x0840 mnmsrvc - ok
20:02:28.0015 0x0840 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:02:28.0015 0x0840 Modem - ok
20:02:28.0031 0x0840 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:02:28.0031 0x0840 Mouclass - ok
20:02:28.0046 0x0840 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:02:28.0046 0x0840 mouhid - ok
20:02:28.0093 0x0840 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:02:28.0093 0x0840 MountMgr - ok
20:02:28.0140 0x0840 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:02:28.0140 0x0840 MozillaMaintenance - ok
20:02:28.0171 0x0840 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:02:28.0171 0x0840 MRxDAV - ok
20:02:28.0218 0x0840 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:02:28.0250 0x0840 MRxSmb - ok
20:02:28.0281 0x0840 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:02:28.0281 0x0840 MSDTC - ok
20:02:28.0296 0x0840 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:02:28.0296 0x0840 Msfs - ok
20:02:28.0312 0x0840 MSIServer - ok
20:02:28.0328 0x0840 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:02:28.0328 0x0840 MSKSSRV - ok
20:02:28.0343 0x0840 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:02:28.0343 0x0840 MSPCLOCK - ok
20:02:28.0375 0x0840 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:02:28.0375 0x0840 MSPQM - ok
20:02:28.0406 0x0840 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:02:28.0406 0x0840 mssmbios - ok
20:02:28.0437 0x0840 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:02:28.0437 0x0840 Mup - ok
20:02:28.0500 0x0840 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
20:02:28.0546 0x0840 napagent - ok
20:02:28.0578 0x0840 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:02:28.0578 0x0840 NDIS - ok
20:02:28.0625 0x0840 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:02:28.0625 0x0840 NdisTapi - ok
20:02:28.0656 0x0840 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:02:28.0656 0x0840 Ndisuio - ok
20:02:28.0671 0x0840 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:02:28.0687 0x0840 NdisWan - ok
20:02:28.0718 0x0840 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:02:28.0718 0x0840 NDProxy - ok
20:02:28.0812 0x0840 [ 6D4028D458EAAA1782099750790DC8C9 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
20:02:28.0859 0x0840 Nero BackItUp Scheduler 3 - ok
20:02:28.0890 0x0840 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:02:28.0890 0x0840 NetBIOS - ok
20:02:28.0906 0x0840 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:02:28.0921 0x0840 NetBT - ok
20:02:28.0937 0x0840 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
20:02:28.0953 0x0840 NetDDE - ok
20:02:28.0953 0x0840 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:02:28.0968 0x0840 NetDDEdsdm - ok
20:02:28.0984 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:02:29.0000 0x0840 Netlogon - ok
20:02:29.0015 0x0840 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
20:02:29.0031 0x0840 Netman - ok
20:02:29.0093 0x0840 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:02:29.0093 0x0840 NetTcpPortSharing - ok
20:02:29.0140 0x0840 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
20:02:29.0156 0x0840 Nla - ok
20:02:29.0250 0x0840 [ FF4D73B16EA3A32D34CEB3A7BC3C3773 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
20:02:29.0265 0x0840 NMIndexingService - ok
20:02:29.0296 0x0840 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:02:29.0296 0x0840 Npfs - ok
20:02:29.0343 0x0840 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:02:29.0359 0x0840 Ntfs - ok
20:02:29.0390 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:02:29.0390 0x0840 NtLmSsp - ok
20:02:29.0437 0x0840 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:02:29.0484 0x0840 NtmsSvc - ok
20:02:29.0531 0x0840 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
20:02:29.0531 0x0840 Null - ok
20:02:29.0984 0x0840 [ 231E377E60A96B53C169C5E04AC0A67A ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:02:30.0328 0x0840 nv - ok
20:02:30.0390 0x0840 [ E10AACC565E0A8B76AC4FB912343D38E ] NVHDA C:\WINDOWS\system32\drivers\nvhda32.sys
20:02:30.0390 0x0840 NVHDA - ok
20:02:30.0437 0x0840 [ A1D291A173A68C332678DDF3FC38D85B ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
20:02:30.0437 0x0840 NVSvc - ok
20:02:30.0468 0x0840 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:02:30.0468 0x0840 NwlnkFlt - ok
20:02:30.0468 0x0840 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:02:30.0468 0x0840 NwlnkFwd - ok
20:02:30.0500 0x0840 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:02:30.0500 0x0840 ose - ok
20:02:30.0531 0x0840 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
20:02:30.0531 0x0840 Parport - ok
20:02:30.0562 0x0840 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:02:30.0562 0x0840 PartMgr - ok
20:02:30.0593 0x0840 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:02:30.0609 0x0840 ParVdm - ok
20:02:30.0625 0x0840 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:02:30.0625 0x0840 PCI - ok
20:02:30.0640 0x0840 PCIDump - ok
20:02:30.0656 0x0840 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:02:30.0671 0x0840 PCIIde - ok
20:02:30.0703 0x0840 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:02:30.0703 0x0840 Pcmcia - ok
20:02:30.0703 0x0840 PDCOMP - ok
20:02:30.0718 0x0840 PDFRAME - ok
20:02:30.0718 0x0840 PDRELI - ok
20:02:30.0734 0x0840 PDRFRAME - ok
20:02:30.0765 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
20:02:30.0781 0x0840 PlugPlay - ok
20:02:30.0796 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:02:30.0796 0x0840 PolicyAgent - ok
20:02:30.0812 0x0840 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:02:30.0812 0x0840 PptpMiniport - ok
20:02:30.0828 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:02:30.0828 0x0840 ProtectedStorage - ok
20:02:30.0843 0x0840 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:02:30.0843 0x0840 PSched - ok
20:02:30.0875 0x0840 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:02:30.0875 0x0840 Ptilink - ok
20:02:30.0890 0x0840 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:02:30.0890 0x0840 RasAcd - ok
20:02:30.0906 0x0840 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:02:30.0921 0x0840 RasAuto - ok
20:02:30.0937 0x0840 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:02:30.0937 0x0840 Rasl2tp - ok
20:02:30.0968 0x0840 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:02:30.0968 0x0840 RasMan - ok
20:02:31.0000 0x0840 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:02:31.0000 0x0840 RasPppoe - ok
20:02:31.0031 0x0840 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:02:31.0031 0x0840 Raspti - ok
20:02:31.0046 0x0840 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:02:31.0062 0x0840 Rdbss - ok
20:02:31.0078 0x0840 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:02:31.0078 0x0840 RDPCDD - ok
20:02:31.0109 0x0840 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:02:31.0109 0x0840 rdpdr - ok
20:02:31.0156 0x0840 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:02:31.0156 0x0840 RDPWD - ok
20:02:31.0187 0x0840 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:02:31.0187 0x0840 RDSessMgr - ok
20:02:31.0218 0x0840 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:02:31.0218 0x0840 redbook - ok
20:02:31.0250 0x0840 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:02:31.0250 0x0840 RemoteAccess - ok
20:02:31.0281 0x0840 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:02:31.0296 0x0840 RemoteRegistry - ok
20:02:31.0312 0x0840 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
20:02:31.0328 0x0840 RpcLocator - ok
20:02:31.0375 0x0840 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\System32\rpcss.dll
20:02:31.0390 0x0840 RpcSs - ok
20:02:31.0453 0x0840 [ 99F13D7E9AAEC74A5B7D10AB780D9D6F ] RSVP C:\WINDOWS\system32\rsvp.exe
20:02:31.0468 0x0840 RSVP - ok
20:02:31.0500 0x0840 [ BADABE0940C01619E8510B90FB314929 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:02:31.0500 0x0840 RTLE8023xp - ok
20:02:31.0515 0x0840 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
20:02:31.0531 0x0840 SamSs - ok
20:02:31.0562 0x0840 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:02:31.0562 0x0840 SCardSvr - ok
20:02:31.0609 0x0840 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:02:31.0609 0x0840 Schedule - ok
20:02:31.0656 0x0840 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:02:31.0656 0x0840 Secdrv - ok
20:02:31.0671 0x0840 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:02:31.0687 0x0840 seclogon - ok
20:02:31.0703 0x0840 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
20:02:31.0703 0x0840 SENS - ok
20:02:31.0718 0x0840 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:02:31.0734 0x0840 serenum - ok
20:02:31.0750 0x0840 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:02:31.0750 0x0840 Serial - ok
20:02:31.0765 0x0840 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:02:31.0781 0x0840 Sfloppy - ok
20:02:31.0812 0x0840 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:02:31.0828 0x0840 SharedAccess - ok
20:02:31.0843 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:02:31.0859 0x0840 ShellHWDetection - ok
20:02:31.0859 0x0840 Simbad - ok
20:02:32.0312 0x0840 [ D0776778A9FC5E37F2E9EB21FC8A9709 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
20:02:32.0671 0x0840 Skype C2C Service - ok
20:02:32.0796 0x0840 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
20:02:32.0796 0x0840 SkypeUpdate - ok
20:02:32.0812 0x0840 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:02:32.0812 0x0840 splitter - ok
20:02:32.0843 0x0840 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:02:32.0843 0x0840 Spooler - ok
20:02:32.0906 0x0840 [ D390675B8CE45E5FB359338E5E649329 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
20:02:32.0906 0x0840 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: D390675B8CE45E5FB359338E5E649329
20:02:32.0906 0x0840 sptd ( LockedFile.Multi.Generic ) - warning
20:02:32.0906 0x0840 sptd - detected LockedFile.Multi.Generic (1)
20:02:32.0921 0x0840 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:02:32.0921 0x0840 sr - ok
20:02:32.0953 0x0840 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
20:02:32.0968 0x0840 srservice - ok
20:02:33.0015 0x0840 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:02:33.0031 0x0840 Srv - ok
20:02:33.0078 0x0840 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:02:33.0078 0x0840 SSDPSRV - ok
20:02:33.0109 0x0840 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:02:33.0140 0x0840 stisvc - ok
20:02:33.0156 0x0840 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:02:33.0171 0x0840 swenum - ok
20:02:33.0187 0x0840 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:02:33.0187 0x0840 swmidi - ok
20:02:33.0203 0x0840 SwPrv - ok
20:02:33.0218 0x0840 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:02:33.0218 0x0840 sysaudio - ok
20:02:33.0265 0x0840 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:02:33.0265 0x0840 SysmonLog - ok
20:02:33.0296 0x0840 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:02:33.0312 0x0840 TapiSrv - ok
20:02:33.0343 0x0840 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:02:33.0375 0x0840 Tcpip - ok
20:02:33.0406 0x0840 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:02:33.0406 0x0840 TDPIPE - ok
20:02:33.0421 0x0840 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:02:33.0421 0x0840 TDTCP - ok
20:02:33.0437 0x0840 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:02:33.0437 0x0840 TermDD - ok
20:02:33.0515 0x0840 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
20:02:33.0546 0x0840 TermService - ok
20:02:33.0578 0x0840 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
20:02:33.0593 0x0840 Themes - ok
20:02:33.0640 0x0840 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
20:02:33.0640 0x0840 TlntSvr - ok
20:02:33.0656 0x0840 TosIde - ok
20:02:33.0687 0x0840 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:02:33.0703 0x0840 TrkWks - ok
20:02:33.0765 0x0840 [ F2AEE22231046CAD8D2F94D2C0F9BEFB ] trufos C:\WINDOWS\system32\drivers\trufos.sys
20:02:33.0953 0x0840 trufos - ok
20:02:34.0015 0x0840 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:02:34.0078 0x0840 Udfs - ok
20:02:34.0156 0x0840 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:02:34.0312 0x0840 Update - ok
20:02:34.0421 0x0840 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
20:02:34.0437 0x0840 upnphost - ok
20:02:34.0453 0x0840 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
20:02:34.0468 0x0840 UPS - ok
20:02:34.0500 0x0840 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:02:34.0515 0x0840 usbccgp - ok
20:02:34.0531 0x0840 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:02:34.0546 0x0840 usbehci - ok
20:02:34.0593 0x0840 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:02:34.0609 0x0840 usbhub - ok
20:02:34.0671 0x0840 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:02:34.0687 0x0840 usbscan - ok
20:02:34.0703 0x0840 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:02:34.0703 0x0840 USBSTOR - ok
20:02:34.0734 0x0840 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:02:34.0734 0x0840 usbuhci - ok
20:02:34.0765 0x0840 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:02:34.0765 0x0840 VgaSave - ok
20:02:34.0781 0x0840 ViaIde - ok
20:02:34.0796 0x0840 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:02:34.0796 0x0840 VolSnap - ok
20:02:34.0843 0x0840 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
20:02:34.0859 0x0840 VSS - ok
20:02:34.0890 0x0840 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
20:02:34.0890 0x0840 W32Time - ok
20:02:34.0921 0x0840 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:02:34.0921 0x0840 Wanarp - ok
20:02:34.0937 0x0840 WDICA - ok
20:02:34.0968 0x0840 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:02:34.0968 0x0840 wdmaud - ok
20:02:35.0000 0x0840 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:02:35.0000 0x0840 WebClient - ok
20:02:35.0078 0x0840 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:02:35.0093 0x0840 winmgmt - ok
20:02:35.0125 0x0840 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
20:02:35.0140 0x0840 WmdmPmSN - ok
20:02:35.0171 0x0840 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi C:\WINDOWS\System32\advapi32.dll
20:02:35.0203 0x0840 Wmi - ok
20:02:35.0250 0x0840 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:02:35.0250 0x0840 WmiApSrv - ok
20:02:35.0343 0x0840 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
20:02:35.0375 0x0840 WMPNetworkSvc - ok
20:02:35.0390 0x0840 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
20:02:35.0406 0x0840 WpdUsb - ok
20:02:35.0437 0x0840 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:02:35.0437 0x0840 WS2IFSL - ok
20:02:35.0484 0x0840 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:02:35.0484 0x0840 wscsvc - ok
20:02:35.0515 0x0840 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:02:35.0531 0x0840 wuauserv - ok
20:02:35.0562 0x0840 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:02:35.0562 0x0840 WudfPf - ok
20:02:35.0593 0x0840 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:02:35.0593 0x0840 WudfRd - ok
20:02:35.0625 0x0840 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
20:02:35.0656 0x0840 WudfSvc - ok
20:02:35.0703 0x0840 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:02:35.0734 0x0840 WZCSVC - ok
20:02:35.0750 0x0840 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:02:35.0765 0x0840 xmlprov - ok
20:02:35.0765 0x0840 ================ Scan global ===============================
20:02:35.0796 0x0840 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
20:02:35.0828 0x0840 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:02:35.0875 0x0840 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:02:35.0906 0x0840 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
20:02:35.0906 0x0840 [Global] - ok
20:02:35.0906 0x0840 ================ Scan MBR ==================================
20:02:35.0921 0x0840 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:02:36.0109 0x0840 \Device\Harddisk0\DR0 - ok
20:02:36.0109 0x0840 ================ Scan VBR ==================================
20:02:36.0109 0x0840 [ F30B56B5AEEDC1ACCE4617F40D113564 ] \Device\Harddisk0\DR0\Partition1
20:02:36.0125 0x0840 \Device\Harddisk0\DR0\Partition1 - ok
20:02:36.0125 0x0840 ============================================================
20:02:36.0125 0x0840 Scan finished
20:02:36.0125 0x0840 ============================================================
20:02:36.0140 0x0a7c Detected object count: 2
20:02:36.0140 0x0a7c Actual detected object count: 2
20:02:40.0484 0x0a7c atapi ( LockedFile.Multi.Generic ) - skipped by user
20:02:40.0484 0x0a7c atapi ( LockedFile.Multi.Generic ) - User select action: Skip
20:02:40.0484 0x0a7c sptd ( LockedFile.Multi.Generic ) - skipped by user
20:02:40.0484 0x0a7c sptd ( LockedFile.Multi.Generic ) - User select action: Skip
20:03:18.0015 0x0df0 ============================================================
20:03:18.0015 0x0df0 Scan started
20:03:18.0015 0x0df0 Mode: Manual;
20:03:18.0015 0x0df0 ============================================================
20:03:18.0437 0x0df0 ================ Scan system memory ========================
20:03:18.0437 0x0df0 System memory - ok
20:03:18.0437 0x0df0 ================ Scan services =============================
20:03:18.0812 0x0df0 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
20:03:18.0812 0x0df0 Aavmker4 - ok
20:03:18.0812 0x0df0 Abiosdsk - ok
20:03:18.0953 0x0df0 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
20:03:18.0953 0x0df0 ACDaemon - ok
20:03:18.0984 0x0df0 [ 4FE34F1F3126B61FCC6B2043AA8112C9 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:03:18.0984 0x0df0 ACPI - ok
20:03:19.0031 0x0df0 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:03:19.0031 0x0df0 ACPIEC - ok
20:03:19.0093 0x0df0 [ 3109B16A0939BA11696EEB04F345D099 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:03:19.0093 0x0df0 AdobeFlashPlayerUpdateSvc - ok
20:03:19.0125 0x0df0 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:03:19.0125 0x0df0 aec - ok
20:03:19.0156 0x0df0 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:03:19.0156 0x0df0 AFD - ok
20:03:19.0203 0x0df0 [ E0A6FA244B8624D78FE5FF6F56A33BAE ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:03:19.0203 0x0df0 Alerter - ok
20:03:19.0218 0x0df0 [ 88842DE939A827577BF24243699AC80A ] ALG C:\WINDOWS\System32\alg.exe
20:03:19.0218 0x0df0 ALG - ok
20:03:19.0218 0x0df0 AliIde - ok
20:03:19.0265 0x0df0 [ 6B8E7A90E576D4FE308F97C69060A171 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:03:19.0265 0x0df0 AppMgmt - ok
20:03:19.0375 0x0df0 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:03:19.0375 0x0df0 aspnet_state - ok
20:03:19.0406 0x0df0 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:03:19.0406 0x0df0 aswFsBlk - ok
20:03:19.0453 0x0df0 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
20:03:19.0453 0x0df0 aswMon2 - ok
20:03:19.0468 0x0df0 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
20:03:19.0468 0x0df0 aswRdr - ok
20:03:19.0515 0x0df0 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
20:03:19.0531 0x0df0 aswSnx - ok
20:03:19.0562 0x0df0 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
20:03:19.0562 0x0df0 aswSP - ok
20:03:19.0593 0x0df0 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
20:03:19.0593 0x0df0 aswTdi - ok
20:03:19.0609 0x0df0 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:03:19.0609 0x0df0 AsyncMac - ok
20:03:19.0640 0x0df0 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:03:19.0656 0x0df0 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: 9F3A2F5AA6875C72BF062C712CFA2674
20:03:19.0656 0x0df0 atapi ( LockedFile.Multi.Generic ) - warning
20:03:19.0656 0x0df0 atapi - detected LockedFile.Multi.Generic (1)
20:03:19.0656 0x0df0 Atdisk - ok
20:03:19.0671 0x0df0 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:03:19.0671 0x0df0 Atmarpc - ok
20:03:19.0703 0x0df0 [ DE31B88962A8645DBA5A37B993E7B0F1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:03:19.0703 0x0df0 AudioSrv - ok
20:03:19.0718 0x0df0 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:03:19.0734 0x0df0 audstub - ok
20:03:19.0828 0x0df0 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
20:03:19.0843 0x0df0 avast! Antivirus - ok
20:03:19.0875 0x0df0 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:03:19.0875 0x0df0 Beep - ok
20:03:19.0921 0x0df0 [ 19395D092FD85DDC2D9C7729CF5A2AC8 ] BITS C:\WINDOWS\system32\qmgr.dll
20:03:19.0937 0x0df0 BITS - ok
20:03:19.0968 0x0df0 [ 89E739BBA5F636297EA5B5F811189E06 ] Browser C:\WINDOWS\System32\browser.dll
20:03:19.0968 0x0df0 Browser - ok
20:03:19.0968 0x0df0 catchme - ok
20:03:20.0000 0x0df0 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:03:20.0000 0x0df0 Cdaudio - ok
20:03:20.0031 0x0df0 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:03:20.0046 0x0df0 Cdfs - ok
20:03:20.0062 0x0df0 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:03:20.0062 0x0df0 Cdrom - ok
20:03:20.0062 0x0df0 Changer - ok
20:03:20.0093 0x0df0 [ E390DC1D7C461D7D56EC53402F329928 ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:03:20.0093 0x0df0 CiSvc - ok
20:03:20.0109 0x0df0 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:03:20.0109 0x0df0 ClipSrv - ok
20:03:20.0156 0x0df0 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:03:20.0156 0x0df0 clr_optimization_v2.0.50727_32 - ok
20:03:20.0156 0x0df0 CmdIde - ok
20:03:20.0171 0x0df0 COMSysApp - ok
20:03:20.0187 0x0df0 [ F3AB0933CBD166D271992F411C27CCAF ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:03:20.0187 0x0df0 CryptSvc - ok
20:03:20.0234 0x0df0 [ 99159E3EF20A4792AEFE4115E8AD0957 ] d346bus C:\WINDOWS\system32\DRIVERS\d346bus.sys
20:03:20.0234 0x0df0 d346bus - ok
20:03:20.0250 0x0df0 [ FB228CD598B7686E98FBF7BFB55666EB ] d346prt C:\WINDOWS\system32\Drivers\d346prt.sys
20:03:20.0250 0x0df0 d346prt - ok
20:03:20.0296 0x0df0 [ BE27674D1CBC3214AEC84B4336A38BBF ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:03:20.0312 0x0df0 DcomLaunch - ok
20:03:20.0328 0x0df0 [ 8C9A53E285AC5E6704844D0459EC85BE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:03:20.0343 0x0df0 Dhcp - ok
20:03:20.0359 0x0df0 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:03:20.0359 0x0df0 Disk - ok
20:03:20.0375 0x0df0 dmadmin - ok
20:03:20.0421 0x0df0 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:03:20.0421 0x0df0 dmboot - ok
20:03:20.0437 0x0df0 [ FFF1720AF51171F32F1EAD5CF71F2810 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:03:20.0453 0x0df0 dmio - ok
20:03:20.0484 0x0df0 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:03:20.0484 0x0df0 dmload - ok
20:03:20.0515 0x0df0 [ 2BFEFE9E865655A76982F050450B9591 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:03:20.0515 0x0df0 dmserver - ok
20:03:20.0531 0x0df0 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:03:20.0531 0x0df0 DMusic - ok
20:03:20.0562 0x0df0 [ DFAA406BF19F4EE806A6F8D4342137F7 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:03:20.0562 0x0df0 Dnscache - ok
20:03:20.0593 0x0df0 [ 4A3E2BD20157A0946751229E92EB8621 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:03:20.0609 0x0df0 Dot3svc - ok
20:03:20.0625 0x0df0 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:03:20.0625 0x0df0 drmkaud - ok
20:03:20.0640 0x0df0 [ 0887D9C2BE8D940778CAD1E3B85F2A41 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:03:20.0640 0x0df0 EapHost - ok
20:03:20.0671 0x0df0 [ FD9FC82F134B1C91004FFC76A5AE494B ] ENTECH C:\WINDOWS\system32\DRIVERS\ENTECH.sys
20:03:20.0671 0x0df0 ENTECH - ok
20:03:20.0703 0x0df0 [ A2A4912798F2BE706ABADD3D30800D16 ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:03:20.0703 0x0df0 ERSvc - ok
20:03:20.0734 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] Eventlog C:\WINDOWS\system32\services.exe
20:03:20.0734 0x0df0 Eventlog - ok
20:03:20.0781 0x0df0 [ A371F11EF07653591C8DE26AFB13CE7F ] EventSystem C:\WINDOWS\system32\es.dll
20:03:20.0781 0x0df0 EventSystem - ok
20:03:20.0812 0x0df0 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:03:20.0828 0x0df0 Fastfat - ok
20:03:20.0859 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:03:20.0859 0x0df0 FastUserSwitchingCompatibility - ok
20:03:20.0921 0x0df0 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:03:20.0921 0x0df0 Fdc - ok
20:03:21.0015 0x0df0 [ AC366695A0796560AA37215AD5762AAF ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:03:21.0015 0x0df0 Fips - ok
20:03:21.0062 0x0df0 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:03:21.0062 0x0df0 Flpydisk - ok
20:03:21.0093 0x0df0 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:03:21.0093 0x0df0 FltMgr - ok
20:03:21.0203 0x0df0 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:03:21.0203 0x0df0 FontCache3.0.0.0 - ok
20:03:21.0281 0x0df0 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:03:21.0281 0x0df0 Fs_Rec - ok
20:03:21.0328 0x0df0 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:03:21.0328 0x0df0 Ftdisk - ok
20:03:21.0359 0x0df0 [ 54789F9BA0D59072CDD4E7C200E122C4 ] gdrv C:\WINDOWS\gdrv.sys
20:03:21.0359 0x0df0 gdrv - ok
20:03:21.0390 0x0df0 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:03:21.0390 0x0df0 Gpc - ok
20:03:21.0484 0x0df0 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
20:03:21.0484 0x0df0 gupdate - ok
20:03:21.0484 0x0df0 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
20:03:21.0484 0x0df0 gupdatem - ok
20:03:21.0515 0x0df0 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:03:21.0515 0x0df0 gusvc - ok
20:03:21.0546 0x0df0 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:03:21.0546 0x0df0 HDAudBus - ok
20:03:21.0625 0x0df0 [ FCFE31FB75F8A6295B6B0AF87A626282 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:03:21.0625 0x0df0 helpsvc - ok
20:03:21.0640 0x0df0 [ 00E25EE90166B3E1BE6E74AEBF858306 ] HidServ C:\WINDOWS\System32\hidserv.dll
20:03:21.0640 0x0df0 HidServ - ok
20:03:21.0656 0x0df0 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:03:21.0656 0x0df0 HidUsb - ok
20:03:21.0687 0x0df0 [ 7A6B320928F86BC851530D63C82965D9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:03:21.0687 0x0df0 hkmsvc - ok
20:03:21.0718 0x0df0 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:03:21.0718 0x0df0 HTTP - ok
20:03:21.0750 0x0df0 [ 58FE2F2DA3BC5573F4A35B3760D3125F ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:03:21.0765 0x0df0 HTTPFilter - ok
20:03:21.0796 0x0df0 [ C528E27945367191E7BAE364930B6932 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:03:21.0796 0x0df0 i8042prt - ok
20:03:21.0859 0x0df0 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:03:21.0859 0x0df0 IDriverT - ok
20:03:22.0015 0x0df0 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:03:22.0015 0x0df0 idsvc - ok
20:03:22.0046 0x0df0 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:03:22.0046 0x0df0 Imapi - ok
20:03:22.0078 0x0df0 [ F7B93AAFAD33B2320954C17E26C8D361 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:03:22.0078 0x0df0 ImapiService - ok
20:03:22.0265 0x0df0 [ C4006AF18682FCA0D8A011A0A21070F8 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
20:03:22.0312 0x0df0 IntcAzAudAddService - ok
20:03:22.0328 0x0df0 IntelIde - ok
20:03:22.0359 0x0df0 [ 27B290D632AF2CF3CF40BFDDB7370985 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:03:22.0359 0x0df0 intelppm - ok
20:03:22.0375 0x0df0 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:03:22.0375 0x0df0 Ip6Fw - ok
20:03:22.0406 0x0df0 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:03:22.0421 0x0df0 IpFilterDriver - ok
20:03:22.0437 0x0df0 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:03:22.0437 0x0df0 IpInIp - ok
20:03:22.0453 0x0df0 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:03:22.0453 0x0df0 IpNat - ok
20:03:22.0484 0x0df0 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:03:22.0500 0x0df0 IPSec - ok
20:03:22.0500 0x0df0 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:03:22.0500 0x0df0 IRENUM - ok
20:03:22.0531 0x0df0 [ CC9F8A2D60AED1A51A3AC34C59B987AE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:03:22.0531 0x0df0 isapnp - ok
20:03:22.0546 0x0df0 [ 1B6162FE7F66B1A71A4B70F941C4AA9B ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:03:22.0546 0x0df0 Kbdclass - ok
20:03:22.0562 0x0df0 [ 86C8F23616C6C6E5B2776901C17B945B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:03:22.0562 0x0df0 kbdhid - ok
20:03:22.0593 0x0df0 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:03:22.0593 0x0df0 kmixer - ok
20:03:22.0625 0x0df0 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:03:22.0625 0x0df0 KSecDD - ok
20:03:22.0656 0x0df0 [ 3428E8F86F8ADD36B42FB23542C7B3E4 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:03:22.0671 0x0df0 lanmanserver - ok
20:03:22.0703 0x0df0 [ 936C1D110232D23B621CB0196E4F80F0 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:03:22.0718 0x0df0 lanmanworkstation - ok
20:03:22.0718 0x0df0 lbrtfdc - ok
20:03:22.0750 0x0df0 [ 0AB159F536E3E8F7F07113702A07CCA5 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:03:22.0750 0x0df0 LmHosts - ok
20:03:22.0812 0x0df0 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
20:03:22.0812 0x0df0 MDM - ok
20:03:22.0843 0x0df0 [ 221CD1C815B8A6B79389C3F5D1018DE8 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:03:22.0843 0x0df0 Messenger - ok
20:03:22.0875 0x0df0 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:03:22.0875 0x0df0 mnmdd - ok
20:03:22.0906 0x0df0 [ 9A57D046F88F4B69751B11FD40088A61 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:03:22.0906 0x0df0 mnmsrvc - ok
20:03:22.0921 0x0df0 [ 44032B0C6D9954D3FD26438330B99EE7 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:03:22.0921 0x0df0 Modem - ok
20:03:22.0937 0x0df0 [ 4CB582831DBDE63CE43B45D771218374 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:03:22.0953 0x0df0 Mouclass - ok
20:03:22.0968 0x0df0 [ BB269EBA740737AB749B214D568B6812 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:03:22.0968 0x0df0 mouhid - ok
20:03:22.0984 0x0df0 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:03:22.0984 0x0df0 MountMgr - ok
20:03:23.0046 0x0df0 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:03:23.0046 0x0df0 MozillaMaintenance - ok
20:03:23.0062 0x0df0 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:03:23.0062 0x0df0 MRxDAV - ok
20:03:23.0125 0x0df0 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:03:23.0125 0x0df0 MRxSmb - ok
20:03:23.0156 0x0df0 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:03:23.0156 0x0df0 MSDTC - ok
20:03:23.0171 0x0df0 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:03:23.0171 0x0df0 Msfs - ok
20:03:23.0187 0x0df0 MSIServer - ok
20:03:23.0203 0x0df0 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:03:23.0203 0x0df0 MSKSSRV - ok
20:03:23.0218 0x0df0 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:03:23.0218 0x0df0 MSPCLOCK - ok
20:03:23.0234 0x0df0 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:03:23.0234 0x0df0 MSPQM - ok
20:03:23.0265 0x0df0 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:03:23.0265 0x0df0 mssmbios - ok
20:03:23.0281 0x0df0 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:03:23.0281 0x0df0 Mup - ok
20:03:23.0328 0x0df0 [ 6EA362E9DB03D44F6B996F4D8BE237E9 ] napagent C:\WINDOWS\System32\qagentrt.dll
20:03:23.0328 0x0df0 napagent - ok
20:03:23.0359 0x0df0 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:03:23.0359 0x0df0 NDIS - ok
20:03:23.0390 0x0df0 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:03:23.0406 0x0df0 NdisTapi - ok
20:03:23.0437 0x0df0 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:03:23.0437 0x0df0 Ndisuio - ok
20:03:23.0453 0x0df0 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:03:23.0453 0x0df0 NdisWan - ok
20:03:23.0468 0x0df0 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:03:23.0468 0x0df0 NDProxy - ok
20:03:23.0578 0x0df0 [ 6D4028D458EAAA1782099750790DC8C9 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
20:03:23.0593 0x0df0 Nero BackItUp Scheduler 3 - ok
20:03:23.0625 0x0df0 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:03:23.0625 0x0df0 NetBIOS - ok
20:03:23.0640 0x0df0 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:03:23.0656 0x0df0 NetBT - ok
20:03:23.0671 0x0df0 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDE C:\WINDOWS\system32\netdde.exe
20:03:23.0687 0x0df0 NetDDE - ok
20:03:23.0687 0x0df0 [ 933DE774986EC85E48210C44AB431DE6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:03:23.0687 0x0df0 NetDDEdsdm - ok
20:03:23.0718 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:03:23.0718 0x0df0 Netlogon - ok
20:03:23.0750 0x0df0 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40 ] Netman C:\WINDOWS\System32\netman.dll
20:03:23.0750 0x0df0 Netman - ok
20:03:23.0812 0x0df0 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:03:23.0812 0x0df0 NetTcpPortSharing - ok
20:03:23.0859 0x0df0 [ 39EE7C3BFBC64BA87CC8CF67386E814C ] Nla C:\WINDOWS\System32\mswsock.dll
20:03:23.0875 0x0df0 Nla - ok
20:03:23.0937 0x0df0 [ FF4D73B16EA3A32D34CEB3A7BC3C3773 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
20:03:23.0953 0x0df0 NMIndexingService - ok
20:03:23.0984 0x0df0 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:03:23.0984 0x0df0 Npfs - ok
20:03:24.0031 0x0df0 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:03:24.0031 0x0df0 Ntfs - ok
20:03:24.0062 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:03:24.0062 0x0df0 NtLmSsp - ok
20:03:24.0109 0x0df0 [ 023DD70573D644F3D9C8B1258A7BFD08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:03:24.0109 0x0df0 NtmsSvc - ok
20:03:24.0140 0x0df0 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
20:03:24.0140 0x0df0 Null - ok
20:03:24.0546 0x0df0 [ 231E377E60A96B53C169C5E04AC0A67A ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:03:24.0640 0x0df0 nv - ok
20:03:24.0671 0x0df0 [ E10AACC565E0A8B76AC4FB912343D38E ] NVHDA C:\WINDOWS\system32\drivers\nvhda32.sys
20:03:24.0671 0x0df0 NVHDA - ok
20:03:24.0718 0x0df0 [ A1D291A173A68C332678DDF3FC38D85B ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
20:03:24.0718 0x0df0 NVSvc - ok
20:03:24.0750 0x0df0 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:03:24.0750 0x0df0 NwlnkFlt - ok
20:03:24.0765 0x0df0 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:03:24.0765 0x0df0 NwlnkFwd - ok
20:03:24.0796 0x0df0 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:03:24.0796 0x0df0 ose - ok
20:03:24.0828 0x0df0 [ 46F8DB73B4A53E543F8E371DC7C75BAE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
20:03:24.0828 0x0df0 Parport - ok
20:03:24.0843 0x0df0 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:03:24.0843 0x0df0 PartMgr - ok
20:03:24.0875 0x0df0 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:03:24.0875 0x0df0 ParVdm - ok
20:03:24.0906 0x0df0 [ 6CE351D149CB4BEFC702951E471E1730 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:03:24.0906 0x0df0 PCI - ok
20:03:24.0906 0x0df0 PCIDump - ok
20:03:24.0953 0x0df0 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:03:24.0953 0x0df0 PCIIde - ok
20:03:24.0984 0x0df0 [ 4FC31E6C19A5CE5198B1ABFF94CAE758 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:03:24.0984 0x0df0 Pcmcia - ok
20:03:24.0984 0x0df0 PDCOMP - ok
20:03:25.0000 0x0df0 PDFRAME - ok
20:03:25.0000 0x0df0 PDRELI - ok
20:03:25.0015 0x0df0 PDRFRAME - ok
20:03:25.0046 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] PlugPlay C:\WINDOWS\system32\services.exe
20:03:25.0046 0x0df0 PlugPlay - ok
20:03:25.0062 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:03:25.0062 0x0df0 PolicyAgent - ok
20:03:25.0093 0x0df0 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:03:25.0093 0x0df0 PptpMiniport - ok
20:03:25.0093 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:03:25.0093 0x0df0 ProtectedStorage - ok
20:03:25.0125 0x0df0 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:03:25.0125 0x0df0 PSched - ok
20:03:25.0156 0x0df0 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:03:25.0156 0x0df0 Ptilink - ok
20:03:25.0156 0x0df0 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:03:25.0156 0x0df0 RasAcd - ok
20:03:25.0187 0x0df0 [ 2B5E44EA009F2F374B980E1E9A70635D ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:03:25.0187 0x0df0 RasAuto - ok
20:03:25.0203 0x0df0 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:03:25.0203 0x0df0 Rasl2tp - ok
20:03:25.0234 0x0df0 [ D57554C664B64604BD1EE13EA2C07E77 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:03:25.0250 0x0df0 RasMan - ok
20:03:25.0265 0x0df0 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:03:25.0265 0x0df0 RasPppoe - ok
20:03:25.0312 0x0df0 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:03:25.0312 0x0df0 Raspti - ok
20:03:25.0328 0x0df0 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:03:25.0328 0x0df0 Rdbss - ok
20:03:25.0343 0x0df0 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:03:25.0359 0x0df0 RDPCDD - ok
20:03:25.0390 0x0df0 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:03:25.0390 0x0df0 rdpdr - ok
20:03:25.0421 0x0df0 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:03:25.0421 0x0df0 RDPWD - ok
20:03:25.0453 0x0df0 [ C0D9D9711CB74EE9BC66353D8CBDAB0E ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:03:25.0468 0x0df0 RDSessMgr - ok
20:03:25.0484 0x0df0 [ 611BFD220305BE3A85AE876EA47D4AA5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:03:25.0484 0x0df0 redbook - ok
20:03:25.0515 0x0df0 [ 127C26B5371651043450E52542099ABA ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:03:25.0515 0x0df0 RemoteAccess - ok
20:03:25.0546 0x0df0 [ 8F31505484A190D5B22274708799F4EC ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:03:25.0546 0x0df0 RemoteRegistry - ok
20:03:25.0578 0x0df0 [ 718B3BDC0BC3C2F7D065A53D26202AF9 ] RpcLocator C:\WINDOWS\system32\locator.exe
20:03:25.0578 0x0df0 RpcLocator - ok
20:03:25.0609 0x0df0 [ BE27674D1CBC3214AEC84B4336A38BBF ] RpcSs C:\WINDOWS\System32\rpcss.dll
20:03:25.0625 0x0df0 RpcSs - ok
20:03:25.0656 0x0df0 [ 99F13D7E9AAEC74A5B7D10AB780D9D6F ] RSVP C:\WINDOWS\system32\rsvp.exe
20:03:25.0656 0x0df0 RSVP - ok
20:03:25.0703 0x0df0 [ BADABE0940C01619E8510B90FB314929 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
20:03:25.0703 0x0df0 RTLE8023xp - ok
20:03:25.0718 0x0df0 [ ED0A176354487CEED65B80A7148AB739 ] SamSs C:\WINDOWS\system32\lsass.exe
20:03:25.0718 0x0df0 SamSs - ok
20:03:25.0750 0x0df0 [ 410046E401EB11E1E6749E9DEEA41D4A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:03:25.0750 0x0df0 SCardSvr - ok
20:03:25.0781 0x0df0 [ 3FF232A7731621B8902D81D42418C93C ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:03:25.0796 0x0df0 Schedule - ok
20:03:25.0828 0x0df0 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:03:25.0828 0x0df0 Secdrv - ok
20:03:25.0859 0x0df0 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:03:25.0875 0x0df0 seclogon - ok
20:03:25.0890 0x0df0 [ A530B75C10C23C9AB28FDB6CE719E21F ] SENS C:\WINDOWS\system32\sens.dll
20:03:25.0890 0x0df0 SENS - ok
20:03:25.0906 0x0df0 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:03:25.0906 0x0df0 serenum - ok
20:03:25.0937 0x0df0 [ B842729337C9B921615C40D3C1A1AF96 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:03:25.0937 0x0df0 Serial - ok
20:03:25.0953 0x0df0 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:03:25.0953 0x0df0 Sfloppy - ok
20:03:26.0000 0x0df0 [ F58FACA9621D2DB01BD0927D9A0A208E ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:03:26.0000 0x0df0 SharedAccess - ok
20:03:26.0031 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:03:26.0031 0x0df0 ShellHWDetection - ok
20:03:26.0031 0x0df0 Simbad - ok
20:03:26.0484 0x0df0 [ D0776778A9FC5E37F2E9EB21FC8A9709 ] Skype C2C Service C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
20:03:26.0515 0x0df0 Skype C2C Service - ok
20:03:26.0609 0x0df0 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
20:03:26.0609 0x0df0 SkypeUpdate - ok
20:03:26.0625 0x0df0 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:03:26.0625 0x0df0 splitter - ok
20:03:26.0656 0x0df0 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:03:26.0656 0x0df0 Spooler - ok
20:03:26.0718 0x0df0 [ D390675B8CE45E5FB359338E5E649329 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
20:03:26.0718 0x0df0 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: D390675B8CE45E5FB359338E5E649329
20:03:26.0718 0x0df0 sptd ( LockedFile.Multi.Generic ) - warning
20:03:26.0718 0x0df0 sptd - detected LockedFile.Multi.Generic (1)
20:03:26.0734 0x0df0 [ 94610C8653635E4459316A0050D55CE7 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:03:26.0734 0x0df0 sr - ok
20:03:26.0781 0x0df0 [ 35B91147124F64AC8081A2EDB9EA4DEE ] srservice C:\WINDOWS\system32\srsvc.dll
20:03:26.0781 0x0df0 srservice - ok
20:03:26.0828 0x0df0 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:03:26.0843 0x0df0 Srv - ok
20:03:26.0859 0x0df0 [ BECD5271DC4E3B7C3D035F790FCBC1E5 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:03:26.0859 0x0df0 SSDPSRV - ok
20:03:26.0890 0x0df0 [ C1CDD9275F6A115BB0AE1D55D8D27BA6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:03:26.0906 0x0df0 stisvc - ok
20:03:26.0937 0x0df0 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:03:26.0937 0x0df0 swenum - ok
20:03:26.0953 0x0df0 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:03:26.0953 0x0df0 swmidi - ok
20:03:26.0968 0x0df0 SwPrv - ok
20:03:27.0000 0x0df0 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:03:27.0000 0x0df0 sysaudio - ok
20:03:27.0031 0x0df0 [ CE06F01B88ACE199A1BF460CAC29C110 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:03:27.0031 0x0df0 SysmonLog - ok
20:03:27.0062 0x0df0 [ C2546CD7A398476F9DF5614B2AE160E8 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:03:27.0062 0x0df0 TapiSrv - ok
20:03:27.0125 0x0df0 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:03:27.0125 0x0df0 Tcpip - ok
20:03:27.0156 0x0df0 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:03:27.0156 0x0df0 TDPIPE - ok
20:03:27.0171 0x0df0 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:03:27.0171 0x0df0 TDTCP - ok
20:03:27.0187 0x0df0 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:03:27.0187 0x0df0 TermDD - ok
20:03:27.0218 0x0df0 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E ] TermService C:\WINDOWS\System32\termsrv.dll
20:03:27.0234 0x0df0 TermService - ok
20:03:27.0265 0x0df0 [ EE9A2B9EA968A792A053C9D1A86BF870 ] Themes C:\WINDOWS\System32\shsvcs.dll
20:03:27.0265 0x0df0 Themes - ok
20:03:27.0312 0x0df0 [ CD0CC7B167D78043A41C98D4921EFB54 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
20:03:27.0312 0x0df0 TlntSvr - ok
20:03:27.0328 0x0df0 TosIde - ok
20:03:27.0343 0x0df0 [ 38853304CCB938D30E0C4CDE8D2C2A8A ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:03:27.0343 0x0df0 TrkWks - ok
20:03:27.0390 0x0df0 [ F2AEE22231046CAD8D2F94D2C0F9BEFB ] trufos C:\WINDOWS\system32\drivers\trufos.sys
20:03:27.0406 0x0df0 trufos - ok
20:03:27.0421 0x0df0 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:03:27.0437 0x0df0 Udfs - ok
20:03:27.0468 0x0df0 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:03:27.0468 0x0df0 Update - ok
20:03:27.0500 0x0df0 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E ] upnphost C:\WINDOWS\System32\upnphost.dll
20:03:27.0515 0x0df0 upnphost - ok
20:03:27.0531 0x0df0 [ 20A0F6A11959E92908717D09E87D670D ] UPS C:\WINDOWS\System32\ups.exe
20:03:27.0531 0x0df0 UPS - ok
20:03:27.0562 0x0df0 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:03:27.0562 0x0df0 usbccgp - ok
20:03:27.0578 0x0df0 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:03:27.0578 0x0df0 usbehci - ok
20:03:27.0593 0x0df0 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:03:27.0593 0x0df0 usbhub - ok
20:03:27.0609 0x0df0 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:03:27.0609 0x0df0 usbscan - ok
20:03:27.0640 0x0df0 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:03:27.0640 0x0df0 USBSTOR - ok
20:03:27.0656 0x0df0 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:03:27.0656 0x0df0 usbuhci - ok
20:03:27.0671 0x0df0 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:03:27.0671 0x0df0 VgaSave - ok
20:03:27.0671 0x0df0 ViaIde - ok
20:03:27.0703 0x0df0 [ 28A4B296B47782173C346E376CB374D1 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:03:27.0703 0x0df0 VolSnap - ok
20:03:27.0734 0x0df0 [ D6BA1A63D9E00933F1CD2A885573AFB2 ] VSS C:\WINDOWS\System32\vssvc.exe
20:03:27.0734 0x0df0 VSS - ok
20:03:27.0765 0x0df0 [ FA4E1CDBA256787F2149F4AAD07BC91F ] W32Time C:\WINDOWS\system32\w32time.dll
20:03:27.0781 0x0df0 W32Time - ok
20:03:27.0796 0x0df0 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:03:27.0796 0x0df0 Wanarp - ok
20:03:27.0812 0x0df0 WDICA - ok
20:03:27.0843 0x0df0 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:03:27.0843 0x0df0 wdmaud - ok
20:03:27.0875 0x0df0 [ 47AE51048A82DFA1CD6B51D369F7E169 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:03:27.0875 0x0df0 WebClient - ok
20:03:27.0953 0x0df0 [ E488332126E3B1182D2B8A0C35408EC6 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:03:27.0953 0x0df0 winmgmt - ok
20:03:27.0984 0x0df0 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
20:03:28.0000 0x0df0 WmdmPmSN - ok
20:03:28.0046 0x0df0 [ 0171CFF34BBA8C5977F18C48D8AEF8C6 ] Wmi C:\WINDOWS\System32\advapi32.dll
20:03:28.0062 0x0df0 Wmi - ok
20:03:28.0093 0x0df0 [ 23F6F03272F7E5679F1F050AED5ACEE6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:03:28.0093 0x0df0 WmiApSrv - ok
20:03:28.0187 0x0df0 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
20:03:28.0187 0x0df0 WMPNetworkSvc - ok
20:03:28.0218 0x0df0 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
20:03:28.0218 0x0df0 WpdUsb - ok
20:03:28.0250 0x0df0 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:03:28.0250 0x0df0 WS2IFSL - ok
20:03:28.0296 0x0df0 [ 4C86D5FAF78194995AF9CC1075F65DD3 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:03:28.0296 0x0df0 wscsvc - ok
20:03:28.0328 0x0df0 [ C1364564800EE9784192145324A23308 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:03:28.0328 0x0df0 wuauserv - ok
20:03:28.0343 0x0df0 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:03:28.0359 0x0df0 WudfPf - ok
20:03:28.0390 0x0df0 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:03:28.0390 0x0df0 WudfRd - ok
20:03:28.0421 0x0df0 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
20:03:28.0421 0x0df0 WudfSvc - ok
20:03:28.0468 0x0df0 [ A27D4BA7264C0BF52F32D10405BEA1D4 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:03:28.0484 0x0df0 WZCSVC - ok
20:03:28.0500 0x0df0 [ EAA4BB9EDB3FB10CF8979FE65E63658F ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:03:28.0515 0x0df0 xmlprov - ok
20:03:28.0515 0x0df0 ================ Scan global ===============================
20:03:28.0546 0x0df0 [ F36278E42C8C5DF03CE17DAC8231C91C ] C:\WINDOWS\system32\basesrv.dll
20:03:28.0578 0x0df0 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:03:28.0593 0x0df0 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6 ] C:\WINDOWS\system32\winsrv.dll
20:03:28.0625 0x0df0 [ 9EF697AF07BB8DD82C3B02CA953A95B7 ] C:\WINDOWS\system32\services.exe
20:03:28.0640 0x0df0 [Global] - ok
20:03:28.0640 0x0df0 ================ Scan MBR ==================================
20:03:28.0656 0x0df0 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:03:28.0843 0x0df0 \Device\Harddisk0\DR0 - ok
20:03:28.0843 0x0df0 ================ Scan VBR ==================================
20:03:28.0843 0x0df0 [ F30B56B5AEEDC1ACCE4617F40D113564 ] \Device\Harddisk0\DR0\Partition1
20:03:28.0859 0x0df0 \Device\Harddisk0\DR0\Partition1 - ok
20:03:28.0859 0x0df0 ============================================================
20:03:28.0859 0x0df0 Scan finished
20:03:28.0859 0x0df0 ============================================================
20:03:28.0875 0x0cc0 Detected object count: 2
20:03:28.0875 0x0cc0 Actual detected object count: 2
20:03:50.0468 0x0cc0 atapi ( LockedFile.Multi.Generic ) - skipped by user
20:03:50.0468 0x0cc0 atapi ( LockedFile.Multi.Generic ) - User select action: Skip
20:03:50.0468 0x0cc0 sptd ( LockedFile.Multi.Generic ) - skipped by user
20:03:50.0468 0x0cc0 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#21 Příspěvek od Rudy »

Máte nainstalovaný DaemonTools?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#22 Příspěvek od Petulda »

ne ne.. ale můžu, jestli je potřeba, každopádně PC už zrychlil a nerestartuje se :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#23 Příspěvek od Rudy »

To by bylo OK. Neinstalujte nic. A nějaký jiný emulátor opt. mechanik také ne?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#24 Příspěvek od Petulda »

Akorát Nero Scout :D

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#25 Příspěvek od Rudy »

Ach tak, to bude ono. Pokud je tedy všecho v pořádku, je to vše.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Petulda
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 97
Registrován: 09 led 2007 20:39

Re: Kontrola logu

#26 Příspěvek od Petulda »

Super, děkuji vám moc za vaší obětavou práci ;)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#27 Příspěvek od Rudy »

Nemáte zač! :) CF odinstalujte pomocí T-Cleaneru: http://vyosek.ic.cz/pro_usery/T-Cleaner.exe .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno