Stránka 3 z 6
Re: Prosím o log
Napsal: 13 úno 2012 17:46
od Rudy
CF neustále maže nové a nové věci, které jsou podle všeho něčím napadeny. Smazal toho daleko víc, než bylo ve skriptu. Zkuste ještě sken AVPTool, ale v nouz. režimu. Pokud nenajdeme konkrétní škodnou, bude to na reinstal systému.
Re: Prosím o log
Napsal: 13 úno 2012 18:27
od blai
V nouzáku to AVPtool taky našel, ale dal jsem delete a podruhé ne.Navíc se systém sám restartoval a v klasickém režimu už žádný virus nebyl.
Mám tu také log :
http://leteckaposta.cz/977457861
Re: Prosím o log
Napsal: 13 úno 2012 18:47
od Rudy
Potřebuji log, který vypadá nějak takto:
Status: Absent (events: 1)
11.2.2012 21:57:49 Not found malware HackTool.Win32.BruteForce.it C:\Program Files\GamePark\GameparkUpdate.exe Medium
Status: Deleted (events: 2)
12.2.2012 1:20:13 Deleted malware HackTool.Win32.BruteForce.it E:\Programy\GameParkSetup11024.exe Medium
12.2.2012 1:20:13 Deleted malware HackTool.Win32.BruteForce.it E:\Programy\GameParkSetup11024.exe//data0001 Medium
Děkuji.
Re: Prosím o log
Napsal: 14 úno 2012 14:09
od blai
Mám jednu dobrou a jednu špatnou zprávu.Jde zase internet.Nechal jsem to projet přes noc AVP toolem, ale zaseklo se to na 6 % přes celou noc, ale dokázal odstranit nějakej sajrajt.Log bohužel nemám, protože jsem musel zase restartovat.Mám to ještě oskenovat "GMER"?
Re: Prosím o log
Napsal: 14 úno 2012 14:44
od stell
Zdravim
Zaskok za kolegu, pokial pride Rudy, spust TDSSKILLER.
Stiahnite si ho prosím TDSSKILLER na plochu
http://support.kaspersky.com/downloads/ ... killer.exe
Spustenie aplikácie: 2x-klik na >TDSSKiller.exe
Spustenie kontroly: Start Scan
Report.txt vloz sem
Re: Prosím o log
Napsal: 14 úno 2012 16:25
od blai
Mohu se zeptat kde hledat log?
Nemůžu ho najít.Hledal jsem na C:\TDSSKiller\_log.txt
Horší je, že se při práci s těmito programy počítač kousne a je potřeba ho restartovat.
Díky
Re: Prosím o log
Napsal: 14 úno 2012 16:43
od stell
Tak hladaj lepsie, otvor disk C:\ a hladaj zlozku TDSSKILLER, ak si spustil tak zlozka tam musi byt, otvorisa report log je tam, ak [pocitac kousol, tak restart do nudzoveho rezimu a spust to tam.
Re: Prosím o log
Napsal: 14 úno 2012 17:00
od blai
16:02:43.0569 5460 TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
16:02:43.0647 5460 ============================================================
16:02:43.0647 5460 Current date / time: 2012/02/14 16:02:43.0647
16:02:43.0647 5460 SystemInfo:
16:02:43.0647 5460
16:02:43.0647 5460 OS Version: 6.1.7601 ServicePack: 1.0
16:02:43.0647 5460 Product type: Workstation
16:02:43.0662 5460 ComputerName: KROTIL-PC
16:02:43.0662 5460 UserName: Krotil
16:02:43.0662 5460 Windows directory: C:\Windows
16:02:43.0662 5460 System windows directory: C:\Windows
16:02:43.0662 5460 Processor architecture: Intel x86
16:02:43.0662 5460 Number of processors: 2
16:02:43.0662 5460 Page size: 0x1000
16:02:43.0662 5460 Boot type: Normal boot
16:02:43.0662 5460 ============================================================
16:02:45.0472 5460 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:02:45.0472 5460 \Device\Harddisk0\DR0:
16:02:45.0472 5460 MBR used
16:02:45.0472 5460 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
16:02:45.0472 5460 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
16:02:45.0503 5460 Initialize success
16:02:45.0503 5460 ============================================================
16:02:47.0531 5444 ============================================================
16:02:47.0531 5444 Scan started
16:02:47.0531 5444 Mode: Manual;
16:02:47.0531 5444 ============================================================
16:02:48.0139 5444 .avgldx86 - ok
16:02:48.0295 5444 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
16:02:48.0295 5444 1394ohci - ok
16:02:48.0358 5444 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
16:02:48.0358 5444 ACPI - ok
16:02:48.0389 5444 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
16:02:48.0389 5444 AcpiPmi - ok
16:02:48.0483 5444 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
16:02:48.0498 5444 adp94xx - ok
16:02:48.0545 5444 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
16:02:48.0561 5444 adpahci - ok
16:02:48.0592 5444 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
16:02:48.0592 5444 adpu320 - ok
16:02:48.0701 5444 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
16:02:48.0717 5444 AFD - ok
16:02:48.0748 5444 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
16:02:48.0748 5444 agp440 - ok
16:02:48.0779 5444 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
16:02:48.0779 5444 aic78xx - ok
16:02:48.0826 5444 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
16:02:48.0826 5444 aliide - ok
16:02:48.0873 5444 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
16:02:48.0873 5444 amdagp - ok
16:02:48.0888 5444 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
16:02:48.0888 5444 amdide - ok
16:02:48.0919 5444 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
16:02:48.0919 5444 AmdK8 - ok
16:02:48.0966 5444 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\Windows\system32\DRIVERS\AmdLLD.sys
16:02:48.0966 5444 AmdLLD - ok
16:02:48.0982 5444 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
16:02:48.0982 5444 AmdPPM - ok
16:02:49.0013 5444 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
16:02:49.0013 5444 amdsata - ok
16:02:49.0029 5444 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
16:02:49.0029 5444 amdsbs - ok
16:02:49.0044 5444 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
16:02:49.0044 5444 amdxata - ok
16:02:49.0075 5444 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
16:02:49.0075 5444 AppID - ok
16:02:49.0107 5444 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
16:02:49.0107 5444 arc - ok
16:02:49.0122 5444 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
16:02:49.0122 5444 arcsas - ok
16:02:49.0153 5444 AsIO (9d8cb58b9a9e177ddd599791a58a654d) C:\Windows\system32\drivers\AsIO.sys
16:02:49.0153 5444 AsIO - ok
16:02:49.0169 5444 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
16:02:49.0169 5444 AsyncMac - ok
16:02:49.0185 5444 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
16:02:49.0185 5444 atapi - ok
16:02:49.0247 5444 AtiHdmiService (430449d04b05348879244c9090d405b4) C:\Windows\system32\drivers\AtiHdmi.sys
16:02:49.0247 5444 AtiHdmiService - ok
16:02:49.0372 5444 atikmdag (712d8a95e45b070114c5309ada7358ff) C:\Windows\system32\DRIVERS\atikmdag.sys
16:02:49.0450 5444 atikmdag - ok
16:02:49.0465 5444 AtiPcie (aca01c43d065e546c6dc88ea669ceca6) C:\Windows\system32\DRIVERS\AtiPcie.sys
16:02:49.0465 5444 AtiPcie - ok
16:02:49.0481 5444 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
16:02:49.0497 5444 b06bdrv - ok
16:02:49.0512 5444 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
16:02:49.0512 5444 b57nd60x - ok
16:02:49.0543 5444 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
16:02:49.0543 5444 Beep - ok
16:02:49.0653 5444 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
16:02:49.0653 5444 blbdrive - ok
16:02:49.0684 5444 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
16:02:49.0699 5444 bowser - ok
16:02:49.0699 5444 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:02:49.0715 5444 BrFiltLo - ok
16:02:49.0731 5444 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:02:49.0731 5444 BrFiltUp - ok
16:02:49.0777 5444 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
16:02:49.0777 5444 BridgeMP - ok
16:02:49.0809 5444 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
16:02:49.0824 5444 Brserid - ok
16:02:49.0824 5444 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
16:02:49.0824 5444 BrSerWdm - ok
16:02:49.0840 5444 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
16:02:49.0840 5444 BrUsbMdm - ok
16:02:49.0855 5444 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
16:02:49.0855 5444 BrUsbSer - ok
16:02:49.0871 5444 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
16:02:49.0871 5444 BTHMODEM - ok
16:02:50.0011 5444 catchme - ok
16:02:50.0043 5444 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
16:02:50.0043 5444 cdfs - ok
16:02:50.0089 5444 cdrom - ok
16:02:50.0136 5444 CFcatchme - ok
16:02:50.0152 5444 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
16:02:50.0152 5444 circlass - ok
16:02:50.0199 5444 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
16:02:50.0199 5444 CLFS - ok
16:02:50.0230 5444 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
16:02:50.0245 5444 CmBatt - ok
16:02:50.0292 5444 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
16:02:50.0292 5444 cmdide - ok
16:02:50.0339 5444 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
16:02:50.0339 5444 CNG - ok
16:02:50.0370 5444 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
16:02:50.0370 5444 Compbatt - ok
16:02:50.0433 5444 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
16:02:50.0433 5444 CompositeBus - ok
16:02:50.0448 5444 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
16:02:50.0464 5444 crcdisk - ok
16:02:50.0526 5444 CSC (e924f4b4f86bf63b498bc0f46105f8cc) C:\Windows\system32\drivers\csc.sys
16:02:50.0526 5444 Suspicious file (Forged): C:\Windows\system32\drivers\csc.sys. Real md5: e924f4b4f86bf63b498bc0f46105f8cc, Fake md5: 3c2177a897b4ca2788c6fb0c3fd81d4b
16:02:50.0526 5444 CSC ( Virus.Win32.ZAccess.c ) - infected
16:02:50.0526 5444 CSC - detected Virus.Win32.ZAccess.c (0)
16:02:50.0573 5444 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
16:02:50.0573 5444 DfsC - ok
16:02:50.0589 5444 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
16:02:50.0589 5444 discache - ok
16:02:50.0620 5444 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
16:02:50.0620 5444 Disk - ok
16:02:50.0635 5444 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
16:02:50.0635 5444 drmkaud - ok
16:02:50.0682 5444 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
16:02:50.0698 5444 DXGKrnl - ok
16:02:50.0760 5444 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
16:02:50.0807 5444 ebdrv - ok
16:02:50.0838 5444 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
16:02:50.0838 5444 elxstor - ok
16:02:50.0869 5444 ENTECH - ok
16:02:50.0916 5444 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
16:02:50.0916 5444 ErrDev - ok
16:02:50.0947 5444 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
16:02:50.0947 5444 exfat - ok
16:02:50.0963 5444 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
16:02:50.0963 5444 fastfat - ok
16:02:50.0963 5444 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
16:02:50.0979 5444 fdc - ok
16:02:50.0994 5444 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
16:02:50.0994 5444 FileInfo - ok
16:02:50.0994 5444 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
16:02:50.0994 5444 Filetrace - ok
16:02:51.0010 5444 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
16:02:51.0010 5444 flpydisk - ok
16:02:51.0025 5444 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
16:02:51.0041 5444 FltMgr - ok
16:02:51.0057 5444 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
16:02:51.0057 5444 FsDepends - ok
16:02:51.0088 5444 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
16:02:51.0088 5444 fssfltr - ok
16:02:51.0119 5444 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
16:02:51.0119 5444 Fs_Rec - ok
16:02:51.0150 5444 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
16:02:51.0166 5444 fvevol - ok
16:02:51.0166 5444 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
16:02:51.0166 5444 gagp30kx - ok
16:02:51.0197 5444 GMSIPCI - ok
16:02:51.0228 5444 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
16:02:51.0228 5444 hcw85cir - ok
16:02:51.0275 5444 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
16:02:51.0275 5444 HdAudAddService - ok
16:02:51.0306 5444 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:02:51.0306 5444 HDAudBus - ok
16:02:51.0322 5444 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
16:02:51.0322 5444 HidBatt - ok
16:02:51.0337 5444 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
16:02:51.0337 5444 HidBth - ok
16:02:51.0353 5444 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
16:02:51.0369 5444 HidIr - ok
16:02:51.0415 5444 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
16:02:51.0415 5444 HidUsb - ok
16:02:51.0462 5444 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
16:02:51.0462 5444 HpSAMD - ok
16:02:51.0509 5444 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
16:02:51.0509 5444 HTTP - ok
16:02:51.0540 5444 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
16:02:51.0540 5444 hwpolicy - ok
16:02:51.0571 5444 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
16:02:51.0571 5444 i8042prt - ok
16:02:51.0618 5444 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
16:02:51.0618 5444 iaStorV - ok
16:02:51.0649 5444 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
16:02:51.0649 5444 iirsp - ok
16:02:51.0681 5444 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
16:02:51.0681 5444 intelide - ok
16:02:51.0727 5444 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
16:02:51.0727 5444 intelppm - ok
16:02:51.0759 5444 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:02:51.0759 5444 IpFilterDriver - ok
16:02:51.0837 5444 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
16:02:51.0852 5444 IPMIDRV - ok
16:02:51.0868 5444 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
16:02:51.0868 5444 IPNAT - ok
16:02:51.0883 5444 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
16:02:51.0883 5444 IRENUM - ok
16:02:51.0899 5444 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
16:02:51.0899 5444 isapnp - ok
16:02:51.0915 5444 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
16:02:51.0961 5444 iScsiPrt - ok
16:02:52.0117 5444 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
16:02:52.0117 5444 kbdclass - ok
16:02:52.0149 5444 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
16:02:52.0149 5444 kbdhid - ok
16:02:52.0195 5444 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
16:02:52.0195 5444 KSecDD - ok
16:02:52.0242 5444 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
16:02:52.0242 5444 KSecPkg - ok
16:02:52.0320 5444 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
16:02:52.0320 5444 lltdio - ok
16:02:52.0336 5444 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
16:02:52.0336 5444 LSI_FC - ok
16:02:52.0351 5444 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
16:02:52.0367 5444 LSI_SAS - ok
16:02:52.0367 5444 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:02:52.0367 5444 LSI_SAS2 - ok
16:02:52.0383 5444 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:02:52.0383 5444 LSI_SCSI - ok
16:02:52.0398 5444 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
16:02:52.0398 5444 luafv - ok
16:02:52.0429 5444 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
16:02:52.0429 5444 megasas - ok
16:02:52.0445 5444 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
16:02:52.0445 5444 MegaSR - ok
16:02:52.0476 5444 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
16:02:52.0476 5444 Modem - ok
16:02:52.0507 5444 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
16:02:52.0507 5444 monitor - ok
16:02:52.0523 5444 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
16:02:52.0523 5444 mouclass - ok
16:02:52.0570 5444 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
16:02:52.0570 5444 mouhid - ok
16:02:52.0601 5444 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
16:02:52.0601 5444 mountmgr - ok
16:02:52.0648 5444 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
16:02:52.0648 5444 mpio - ok
16:02:52.0663 5444 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
16:02:52.0663 5444 mpsdrv - ok
16:02:52.0710 5444 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
16:02:52.0710 5444 MRxDAV - ok
16:02:52.0741 5444 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:02:52.0757 5444 mrxsmb - ok
16:02:52.0788 5444 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:02:52.0804 5444 mrxsmb10 - ok
16:02:52.0819 5444 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:02:52.0819 5444 mrxsmb20 - ok
16:02:52.0851 5444 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
16:02:52.0851 5444 msahci - ok
16:02:52.0882 5444 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
16:02:52.0882 5444 msdsm - ok
16:02:52.0913 5444 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
16:02:52.0913 5444 Msfs - ok
16:02:52.0929 5444 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
16:02:52.0929 5444 mshidkmdf - ok
16:02:52.0960 5444 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
16:02:52.0960 5444 msisadrv - ok
16:02:53.0007 5444 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
16:02:53.0007 5444 MSKSSRV - ok
16:02:53.0022 5444 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
16:02:53.0038 5444 MSPCLOCK - ok
16:02:53.0069 5444 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
16:02:53.0069 5444 MSPQM - ok
16:02:53.0100 5444 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
16:02:53.0100 5444 MsRPC - ok
16:02:53.0116 5444 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
16:02:53.0116 5444 mssmbios - ok
16:02:53.0131 5444 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
16:02:53.0131 5444 MSTEE - ok
16:02:53.0147 5444 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
16:02:53.0147 5444 MTConfig - ok
16:02:53.0194 5444 MTsensor (cbe71c122434805cb73ffb6619f60598) C:\Windows\system32\DRIVERS\ASACPI.sys
16:02:53.0194 5444 MTsensor - ok
16:02:53.0209 5444 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
16:02:53.0209 5444 Mup - ok
16:02:53.0241 5444 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
16:02:53.0241 5444 NativeWifiP - ok
16:02:53.0319 5444 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
16:02:53.0334 5444 NDIS - ok
16:02:53.0365 5444 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
16:02:53.0365 5444 NdisCap - ok
16:02:53.0381 5444 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
16:02:53.0381 5444 NdisTapi - ok
16:02:53.0443 5444 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
16:02:53.0459 5444 Ndisuio - ok
16:02:53.0490 5444 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
16:02:53.0490 5444 NdisWan - ok
16:02:53.0537 5444 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
16:02:53.0553 5444 NDProxy - ok
16:02:53.0568 5444 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
16:02:53.0568 5444 NetBIOS - ok
16:02:53.0615 5444 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
16:02:53.0615 5444 NetBT - ok
16:02:53.0677 5444 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
16:02:53.0677 5444 nfrd960 - ok
16:02:53.0724 5444 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
16:02:53.0724 5444 Npfs - ok
16:02:53.0740 5444 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
16:02:53.0740 5444 nsiproxy - ok
16:02:53.0818 5444 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
16:02:53.0849 5444 Ntfs - ok
16:02:53.0865 5444 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
16:02:53.0865 5444 Null - ok
16:02:54.0083 5444 nvlddmkm (847b1755f7757f825305a1ffe6dac3e9) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:02:54.0130 5444 nvlddmkm - ok
16:02:54.0161 5444 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
16:02:54.0161 5444 nvraid - ok
16:02:54.0208 5444 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
16:02:54.0208 5444 nvstor - ok
16:02:54.0239 5444 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
16:02:54.0239 5444 nv_agp - ok
16:02:54.0286 5444 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
16:02:54.0286 5444 ohci1394 - ok
16:02:54.0348 5444 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
16:02:54.0364 5444 Parport - ok
16:02:54.0395 5444 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
16:02:54.0395 5444 partmgr - ok
16:02:54.0411 5444 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
16:02:54.0411 5444 Parvdm - ok
16:02:54.0457 5444 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
16:02:54.0457 5444 pci - ok
16:02:54.0489 5444 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
16:02:54.0489 5444 pciide - ok
16:02:54.0520 5444 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
16:02:54.0520 5444 pcmcia - ok
16:02:54.0535 5444 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
16:02:54.0535 5444 pcw - ok
16:02:54.0567 5444 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
16:02:54.0567 5444 PEAUTH - ok
16:02:54.0629 5444 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
16:02:54.0629 5444 PptpMiniport - ok
16:02:54.0645 5444 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
16:02:54.0645 5444 Processor - ok
16:02:54.0660 5444 PROCEXP151 - ok
16:02:54.0707 5444 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
16:02:54.0707 5444 Psched - ok
16:02:54.0816 5444 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
16:02:54.0863 5444 ql2300 - ok
16:02:54.0879 5444 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
16:02:54.0879 5444 ql40xx - ok
16:02:54.0910 5444 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
16:02:54.0910 5444 QWAVEdrv - ok
16:02:54.0941 5444 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
16:02:54.0941 5444 RasAcd - ok
16:02:54.0957 5444 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
16:02:54.0957 5444 RasAgileVpn - ok
16:02:54.0988 5444 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:02:54.0988 5444 Rasl2tp - ok
16:02:55.0019 5444 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
16:02:55.0019 5444 RasPppoe - ok
16:02:55.0035 5444 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
16:02:55.0035 5444 RasSstp - ok
16:02:55.0066 5444 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
16:02:55.0066 5444 rdbss - ok
16:02:55.0097 5444 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
16:02:55.0097 5444 rdpbus - ok
16:02:55.0128 5444 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:02:55.0128 5444 RDPCDD - ok
16:02:55.0159 5444 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
16:02:55.0159 5444 RDPDR - ok
16:02:55.0175 5444 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
16:02:55.0175 5444 RDPENCDD - ok
16:02:55.0191 5444 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
16:02:55.0191 5444 RDPREFMP - ok
16:02:55.0237 5444 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
16:02:55.0237 5444 RDPWD - ok
16:02:55.0284 5444 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
16:02:55.0284 5444 rdyboost - ok
16:02:55.0331 5444 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
16:02:55.0331 5444 rspndr - ok
16:02:55.0378 5444 RTL8167 (be70718d14bfc8b6925c3a25a9c1be45) C:\Windows\system32\DRIVERS\Rt86win7.sys
16:02:55.0378 5444 RTL8167 - ok
16:02:55.0425 5444 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
16:02:55.0425 5444 s3cap - ok
16:02:55.0487 5444 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
16:02:55.0487 5444 sbp2port - ok
16:02:55.0534 5444 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
16:02:55.0549 5444 scfilter - ok
16:02:55.0565 5444 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:02:55.0581 5444 secdrv - ok
16:02:55.0596 5444 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
16:02:55.0596 5444 Serenum - ok
16:02:55.0643 5444 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
16:02:55.0643 5444 Serial - ok
16:02:55.0690 5444 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
16:02:55.0705 5444 sermouse - ok
16:02:55.0768 5444 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
16:02:55.0768 5444 sffdisk - ok
16:02:55.0783 5444 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
16:02:55.0783 5444 sffp_mmc - ok
16:02:55.0815 5444 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
16:02:55.0815 5444 sffp_sd - ok
16:02:55.0830 5444 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
16:02:55.0830 5444 sfloppy - ok
16:02:55.0893 5444 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
16:02:55.0893 5444 sisagp - ok
16:02:55.0908 5444 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:02:55.0908 5444 SiSRaid2 - ok
16:02:55.0939 5444 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
16:02:55.0939 5444 SiSRaid4 - ok
16:02:55.0986 5444 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
16:02:55.0986 5444 Smb - ok
16:02:56.0017 5444 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
16:02:56.0017 5444 spldr - ok
16:02:56.0064 5444 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
16:02:56.0080 5444 srv - ok
16:02:56.0111 5444 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
16:02:56.0111 5444 srv2 - ok
16:02:56.0142 5444 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
16:02:56.0142 5444 srvnet - ok
16:02:56.0189 5444 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
16:02:56.0189 5444 stexstor - ok
16:02:56.0220 5444 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
16:02:56.0220 5444 storflt - ok
16:02:56.0267 5444 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
16:02:56.0267 5444 storvsc - ok
16:02:56.0283 5444 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
16:02:56.0283 5444 swenum - ok
16:02:56.0376 5444 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
16:02:56.0392 5444 Tcpip - ok
16:02:56.0470 5444 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
16:02:56.0485 5444 TCPIP6 - ok
16:02:56.0532 5444 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
16:02:56.0532 5444 tcpipreg - ok
16:02:56.0563 5444 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
16:02:56.0563 5444 TDPIPE - ok
16:02:56.0579 5444 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
16:02:56.0579 5444 TDTCP - ok
16:02:56.0610 5444 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
16:02:56.0610 5444 tdx - ok
16:02:56.0657 5444 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
16:02:56.0657 5444 TermDD - ok
16:02:56.0719 5444 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:02:56.0719 5444 tssecsrv - ok
16:02:56.0766 5444 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
16:02:56.0766 5444 TsUsbFlt - ok
16:02:56.0813 5444 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
16:02:56.0813 5444 tunnel - ok
16:02:56.0844 5444 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
16:02:56.0844 5444 uagp35 - ok
16:02:56.0907 5444 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
16:02:56.0907 5444 udfs - ok
16:02:56.0938 5444 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
16:02:56.0938 5444 uliagpkx - ok
16:02:56.0969 5444 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
16:02:56.0969 5444 umbus - ok
16:02:57.0000 5444 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
16:02:57.0000 5444 UmPass - ok
16:02:57.0031 5444 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\drivers\usbccgp.sys
16:02:57.0047 5444 usbccgp - ok
16:02:57.0078 5444 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
16:02:57.0078 5444 usbcir - ok
16:02:57.0094 5444 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
16:02:57.0094 5444 usbehci - ok
16:02:57.0265 5444 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
16:02:57.0281 5444 usbhub - ok
16:02:57.0297 5444 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
16:02:57.0297 5444 usbohci - ok
16:02:57.0312 5444 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
16:02:57.0328 5444 usbprint - ok
16:02:57.0343 5444 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:02:57.0343 5444 USBSTOR - ok
16:02:57.0390 5444 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
16:02:57.0390 5444 usbuhci - ok
16:02:57.0406 5444 VClone (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys
16:02:57.0421 5444 VClone - ok
16:02:57.0421 5444 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
16:02:57.0421 5444 vdrvroot - ok
16:02:57.0453 5444 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
16:02:57.0468 5444 vga - ok
16:02:57.0484 5444 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
16:02:57.0484 5444 VgaSave - ok
16:02:57.0515 5444 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
16:02:57.0531 5444 vhdmp - ok
16:02:57.0655 5444 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
16:02:57.0655 5444 viaagp - ok
16:02:57.0687 5444 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
16:02:57.0687 5444 ViaC7 - ok
16:02:57.0733 5444 VIAHdAudAddService (b9ecf6756858c8fed4fe68e966bf2f5f) C:\Windows\system32\drivers\viahduaa.sys
16:02:57.0749 5444 VIAHdAudAddService - ok
16:02:57.0765 5444 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
16:02:57.0780 5444 viaide - ok
16:02:57.0827 5444 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
16:02:57.0827 5444 vmbus - ok
16:02:57.0874 5444 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
16:02:57.0874 5444 VMBusHID - ok
16:02:57.0889 5444 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
16:02:57.0889 5444 volmgr - ok
16:02:57.0921 5444 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
16:02:57.0921 5444 volmgrx - ok
16:02:57.0936 5444 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
16:02:57.0952 5444 volsnap - ok
16:02:57.0983 5444 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
16:02:57.0983 5444 vsmraid - ok
16:02:58.0014 5444 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
16:02:58.0014 5444 vwifibus - ok
16:02:58.0030 5444 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
16:02:58.0045 5444 WacomPen - ok
16:02:58.0092 5444 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
16:02:58.0092 5444 WANARP - ok
16:02:58.0092 5444 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
16:02:58.0092 5444 Wanarpv6 - ok
16:02:58.0123 5444 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
16:02:58.0123 5444 Wd - ok
16:02:58.0155 5444 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
16:02:58.0155 5444 Wdf01000 - ok
16:02:58.0201 5444 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
16:02:58.0201 5444 WfpLwf - ok
16:02:58.0217 5444 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
16:02:58.0217 5444 WIMMount - ok
16:02:58.0279 5444 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
16:02:58.0279 5444 WmiAcpi - ok
16:02:58.0311 5444 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
16:02:58.0311 5444 ws2ifsl - ok
16:02:58.0357 5444 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
16:02:58.0357 5444 WudfPf - ok
16:02:58.0389 5444 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:02:58.0404 5444 WUDFRd - ok
16:02:58.0482 5444 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:02:58.0513 5444 \Device\Harddisk0\DR0 - ok
16:02:58.0529 5444 Boot (0x1200) (82c556daee1c0f4232f6d9bbf7b7a014) \Device\Harddisk0\DR0\Partition0
16:02:58.0529 5444 \Device\Harddisk0\DR0\Partition0 - ok
16:02:58.0545 5444 Boot (0x1200) (3ad50ed3e92f690093c2cfc289e16a66) \Device\Harddisk0\DR0\Partition1
16:02:58.0545 5444 \Device\Harddisk0\DR0\Partition1 - ok
16:02:58.0545 5444 ============================================================
16:02:58.0545 5444 Scan finished
16:02:58.0545 5444 ============================================================
16:02:58.0576 5432 Detected object count: 1
16:02:58.0576 5432 Actual detected object count: 1
Re: Prosím o log
Napsal: 14 úno 2012 17:01
od blai
16:16:21.0850 1952 TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
16:16:21.0990 1952 ============================================================
16:16:21.0990 1952 Current date / time: 2012/02/14 16:16:21.0990
16:16:21.0990 1952 SystemInfo:
16:16:21.0990 1952
16:16:21.0990 1952 OS Version: 6.1.7601 ServicePack: 1.0
16:16:21.0990 1952 Product type: Workstation
16:16:21.0990 1952 ComputerName: KROTIL-PC
16:16:21.0990 1952 UserName: Krotil
16:16:21.0990 1952 Windows directory: C:\Windows
16:16:21.0990 1952 System windows directory: C:\Windows
16:16:21.0990 1952 Processor architecture: Intel x86
16:16:21.0990 1952 Number of processors: 2
16:16:21.0990 1952 Page size: 0x1000
16:16:21.0990 1952 Boot type: Normal boot
16:16:21.0990 1952 ============================================================
16:16:27.0809 1952 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:16:27.0809 1952 \Device\Harddisk0\DR0:
16:16:27.0825 1952 MBR used
16:16:27.0825 1952 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
16:16:27.0825 1952 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
16:16:27.0872 1952 Initialize success
16:16:27.0872 1952 ============================================================
16:16:29.0478 4020 ============================================================
16:16:29.0478 4020 Scan started
16:16:29.0478 4020 Mode: Manual;
16:16:29.0478 4020 ============================================================
16:16:30.0695 4020 .avgldx86 - ok
16:16:30.0789 4020 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
16:16:30.0789 4020 1394ohci - ok
16:16:30.0836 4020 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
16:16:30.0836 4020 ACPI - ok
16:16:30.0867 4020 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
16:16:30.0867 4020 AcpiPmi - ok
16:16:31.0038 4020 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
16:16:31.0038 4020 adp94xx - ok
16:16:31.0054 4020 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
16:16:31.0070 4020 adpahci - ok
16:16:31.0085 4020 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
16:16:31.0085 4020 adpu320 - ok
16:16:31.0179 4020 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
16:16:31.0179 4020 AFD - ok
16:16:31.0226 4020 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
16:16:31.0226 4020 agp440 - ok
16:16:31.0241 4020 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
16:16:31.0241 4020 aic78xx - ok
16:16:31.0288 4020 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
16:16:31.0288 4020 aliide - ok
16:16:31.0319 4020 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
16:16:31.0319 4020 amdagp - ok
16:16:31.0350 4020 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
16:16:31.0350 4020 amdide - ok
16:16:31.0382 4020 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
16:16:31.0382 4020 AmdK8 - ok
16:16:31.0428 4020 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\Windows\system32\DRIVERS\AmdLLD.sys
16:16:31.0428 4020 AmdLLD - ok
16:16:31.0444 4020 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
16:16:31.0444 4020 AmdPPM - ok
16:16:31.0475 4020 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
16:16:31.0475 4020 amdsata - ok
16:16:31.0506 4020 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
16:16:31.0506 4020 amdsbs - ok
16:16:31.0522 4020 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
16:16:31.0522 4020 amdxata - ok
16:16:31.0553 4020 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
16:16:31.0553 4020 AppID - ok
16:16:31.0616 4020 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
16:16:31.0616 4020 arc - ok
16:16:31.0631 4020 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
16:16:31.0631 4020 arcsas - ok
16:16:31.0662 4020 AsIO (9d8cb58b9a9e177ddd599791a58a654d) C:\Windows\system32\drivers\AsIO.sys
16:16:31.0662 4020 AsIO - ok
16:16:31.0678 4020 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
16:16:31.0678 4020 AsyncMac - ok
16:16:31.0694 4020 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
16:16:31.0709 4020 atapi - ok
16:16:31.0756 4020 AtiHdmiService (430449d04b05348879244c9090d405b4) C:\Windows\system32\drivers\AtiHdmi.sys
16:16:31.0772 4020 AtiHdmiService - ok
16:16:31.0850 4020 atikmdag (712d8a95e45b070114c5309ada7358ff) C:\Windows\system32\DRIVERS\atikmdag.sys
16:16:31.0912 4020 atikmdag - ok
16:16:31.0928 4020 AtiPcie (aca01c43d065e546c6dc88ea669ceca6) C:\Windows\system32\DRIVERS\AtiPcie.sys
16:16:31.0928 4020 AtiPcie - ok
16:16:31.0974 4020 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
16:16:31.0990 4020 b06bdrv - ok
16:16:32.0006 4020 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
16:16:32.0006 4020 b57nd60x - ok
16:16:32.0037 4020 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
16:16:32.0037 4020 Beep - ok
16:16:32.0162 4020 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
16:16:32.0162 4020 blbdrive - ok
16:16:32.0193 4020 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
16:16:32.0193 4020 bowser - ok
16:16:32.0208 4020 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:16:32.0208 4020 BrFiltLo - ok
16:16:32.0208 4020 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:16:32.0208 4020 BrFiltUp - ok
16:16:32.0271 4020 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
16:16:32.0271 4020 BridgeMP - ok
16:16:32.0286 4020 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
16:16:32.0286 4020 Brserid - ok
16:16:32.0302 4020 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
16:16:32.0302 4020 BrSerWdm - ok
16:16:32.0318 4020 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
16:16:32.0318 4020 BrUsbMdm - ok
16:16:32.0318 4020 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
16:16:32.0333 4020 BrUsbSer - ok
16:16:32.0333 4020 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
16:16:32.0333 4020 BTHMODEM - ok
16:16:32.0474 4020 catchme - ok
16:16:32.0489 4020 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
16:16:32.0489 4020 cdfs - ok
16:16:32.0505 4020 cdrom - ok
16:16:32.0536 4020 CFcatchme - ok
16:16:32.0552 4020 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
16:16:32.0552 4020 circlass - ok
16:16:32.0583 4020 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
16:16:32.0598 4020 CLFS - ok
16:16:32.0614 4020 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
16:16:32.0614 4020 CmBatt - ok
16:16:32.0645 4020 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
16:16:32.0661 4020 cmdide - ok
16:16:32.0692 4020 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
16:16:32.0692 4020 CNG - ok
16:16:32.0739 4020 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
16:16:32.0739 4020 Compbatt - ok
16:16:32.0754 4020 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
16:16:32.0754 4020 CompositeBus - ok
16:16:32.0770 4020 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
16:16:32.0770 4020 crcdisk - ok
16:16:32.0848 4020 CSC (e924f4b4f86bf63b498bc0f46105f8cc) C:\Windows\system32\drivers\csc.sys
16:16:32.0848 4020 Suspicious file (Forged): C:\Windows\system32\drivers\csc.sys. Real md5: e924f4b4f86bf63b498bc0f46105f8cc, Fake md5: 3c2177a897b4ca2788c6fb0c3fd81d4b
16:16:32.0848 4020 CSC ( Virus.Win32.ZAccess.c ) - infected
16:16:32.0848 4020 CSC - detected Virus.Win32.ZAccess.c (0)
16:16:33.0020 4020 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
16:16:33.0020 4020 DfsC - ok
16:16:33.0129 4020 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
16:16:33.0129 4020 discache - ok
16:16:33.0191 4020 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
16:16:33.0191 4020 Disk - ok
16:16:33.0410 4020 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
16:16:33.0425 4020 drmkaud - ok
16:16:33.0472 4020 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
16:16:33.0472 4020 DXGKrnl - ok
16:16:33.0893 4020 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
16:16:33.0940 4020 ebdrv - ok
16:16:34.0065 4020 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
16:16:34.0158 4020 elxstor - ok
16:16:34.0190 4020 ENTECH - ok
16:16:34.0236 4020 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
16:16:34.0236 4020 ErrDev - ok
16:16:34.0252 4020 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
16:16:34.0268 4020 exfat - ok
16:16:34.0268 4020 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
16:16:34.0268 4020 fastfat - ok
16:16:34.0283 4020 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
16:16:34.0299 4020 fdc - ok
16:16:34.0299 4020 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
16:16:34.0299 4020 FileInfo - ok
16:16:34.0314 4020 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
16:16:34.0314 4020 Filetrace - ok
16:16:34.0330 4020 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
16:16:34.0330 4020 flpydisk - ok
16:16:34.0346 4020 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
16:16:34.0346 4020 FltMgr - ok
16:16:34.0377 4020 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
16:16:34.0377 4020 FsDepends - ok
16:16:34.0455 4020 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
16:16:34.0470 4020 fssfltr - ok
16:16:34.0517 4020 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
16:16:34.0517 4020 Fs_Rec - ok
16:16:34.0580 4020 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
16:16:34.0580 4020 fvevol - ok
16:16:34.0595 4020 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
16:16:34.0595 4020 gagp30kx - ok
16:16:34.0626 4020 GMSIPCI - ok
16:16:34.0626 4020 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
16:16:34.0642 4020 hcw85cir - ok
16:16:34.0704 4020 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
16:16:34.0720 4020 HdAudAddService - ok
16:16:34.0876 4020 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:16:34.0876 4020 HDAudBus - ok
16:16:34.0938 4020 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
16:16:34.0938 4020 HidBatt - ok
16:16:34.0970 4020 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
16:16:34.0970 4020 HidBth - ok
16:16:34.0985 4020 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
16:16:34.0985 4020 HidIr - ok
16:16:35.0032 4020 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
16:16:35.0032 4020 HidUsb - ok
16:16:35.0079 4020 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
16:16:35.0079 4020 HpSAMD - ok
16:16:35.0094 4020 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
16:16:35.0110 4020 HTTP - ok
16:16:35.0141 4020 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
16:16:35.0141 4020 hwpolicy - ok
16:16:35.0157 4020 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
16:16:35.0172 4020 i8042prt - ok
16:16:35.0204 4020 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
16:16:35.0204 4020 iaStorV - ok
16:16:35.0219 4020 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
16:16:35.0219 4020 iirsp - ok
16:16:35.0250 4020 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
16:16:35.0250 4020 intelide - ok
16:16:35.0297 4020 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
16:16:35.0297 4020 intelppm - ok
16:16:35.0328 4020 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:16:35.0328 4020 IpFilterDriver - ok
16:16:35.0406 4020 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
16:16:35.0406 4020 IPMIDRV - ok
16:16:35.0422 4020 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
16:16:35.0422 4020 IPNAT - ok
16:16:35.0422 4020 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
16:16:35.0422 4020 IRENUM - ok
16:16:35.0453 4020 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
16:16:35.0453 4020 isapnp - ok
16:16:35.0484 4020 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
16:16:35.0484 4020 iScsiPrt - ok
16:16:35.0562 4020 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
16:16:35.0562 4020 kbdclass - ok
16:16:35.0578 4020 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
16:16:35.0578 4020 kbdhid - ok
16:16:35.0609 4020 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
16:16:35.0609 4020 KSecDD - ok
16:16:35.0656 4020 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
16:16:35.0656 4020 KSecPkg - ok
16:16:35.0703 4020 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
16:16:35.0703 4020 lltdio - ok
16:16:35.0734 4020 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
16:16:35.0734 4020 LSI_FC - ok
16:16:35.0734 4020 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
16:16:35.0750 4020 LSI_SAS - ok
16:16:35.0750 4020 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:16:35.0765 4020 LSI_SAS2 - ok
16:16:35.0765 4020 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:16:35.0765 4020 LSI_SCSI - ok
16:16:35.0781 4020 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
16:16:35.0781 4020 luafv - ok
16:16:35.0796 4020 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
16:16:35.0796 4020 megasas - ok
16:16:35.0812 4020 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
16:16:35.0812 4020 MegaSR - ok
16:16:35.0843 4020 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
16:16:35.0843 4020 Modem - ok
16:16:35.0859 4020 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
16:16:35.0859 4020 monitor - ok
16:16:35.0874 4020 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
16:16:35.0874 4020 mouclass - ok
16:16:35.0890 4020 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
16:16:35.0890 4020 mouhid - ok
16:16:35.0937 4020 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
16:16:35.0937 4020 mountmgr - ok
16:16:35.0968 4020 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
16:16:35.0968 4020 mpio - ok
16:16:35.0984 4020 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
16:16:35.0984 4020 mpsdrv - ok
16:16:36.0015 4020 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
16:16:36.0015 4020 MRxDAV - ok
16:16:36.0046 4020 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:16:36.0062 4020 mrxsmb - ok
16:16:36.0077 4020 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:16:36.0093 4020 mrxsmb10 - ok
16:16:36.0108 4020 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:16:36.0108 4020 mrxsmb20 - ok
16:16:36.0124 4020 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
16:16:36.0124 4020 msahci - ok
16:16:36.0155 4020 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
16:16:36.0155 4020 msdsm - ok
16:16:36.0171 4020 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
16:16:36.0171 4020 Msfs - ok
16:16:36.0186 4020 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
16:16:36.0186 4020 mshidkmdf - ok
16:16:36.0218 4020 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
16:16:36.0218 4020 msisadrv - ok
16:16:36.0264 4020 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
16:16:36.0264 4020 MSKSSRV - ok
16:16:36.0264 4020 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
16:16:36.0264 4020 MSPCLOCK - ok
16:16:36.0280 4020 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
16:16:36.0280 4020 MSPQM - ok
16:16:36.0296 4020 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
16:16:36.0296 4020 MsRPC - ok
16:16:36.0311 4020 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
16:16:36.0311 4020 mssmbios - ok
16:16:36.0342 4020 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
16:16:36.0342 4020 MSTEE - ok
16:16:36.0358 4020 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
16:16:36.0358 4020 MTConfig - ok
16:16:36.0389 4020 MTsensor (cbe71c122434805cb73ffb6619f60598) C:\Windows\system32\DRIVERS\ASACPI.sys
16:16:36.0389 4020 MTsensor - ok
16:16:36.0420 4020 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
16:16:36.0420 4020 Mup - ok
16:16:36.0436 4020 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
16:16:36.0436 4020 NativeWifiP - ok
16:16:36.0514 4020 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
16:16:36.0514 4020 NDIS - ok
16:16:36.0530 4020 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
16:16:36.0530 4020 NdisCap - ok
16:16:36.0545 4020 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
16:16:36.0545 4020 NdisTapi - ok
16:16:36.0592 4020 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
16:16:36.0592 4020 Ndisuio - ok
16:16:36.0623 4020 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
16:16:36.0639 4020 NdisWan - ok
16:16:36.0654 4020 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
16:16:36.0654 4020 NDProxy - ok
16:16:36.0670 4020 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
16:16:36.0670 4020 NetBIOS - ok
16:16:36.0701 4020 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
16:16:36.0701 4020 NetBT - ok
16:16:36.0748 4020 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
16:16:36.0748 4020 nfrd960 - ok
16:16:36.0795 4020 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
16:16:36.0795 4020 Npfs - ok
16:16:36.0795 4020 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
16:16:36.0810 4020 nsiproxy - ok
16:16:36.0857 4020 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
16:16:36.0857 4020 Ntfs - ok
16:16:36.0873 4020 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
16:16:36.0873 4020 Null - ok
16:16:37.0060 4020 nvlddmkm (847b1755f7757f825305a1ffe6dac3e9) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:16:37.0107 4020 nvlddmkm - ok
16:16:37.0138 4020 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
16:16:37.0138 4020 nvraid - ok
16:16:37.0169 4020 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
16:16:37.0169 4020 nvstor - ok
16:16:37.0200 4020 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
16:16:37.0200 4020 nv_agp - ok
16:16:37.0232 4020 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
16:16:37.0232 4020 ohci1394 - ok
16:16:37.0278 4020 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
16:16:37.0278 4020 Parport - ok
16:16:37.0310 4020 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
16:16:37.0310 4020 partmgr - ok
16:16:37.0325 4020 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
16:16:37.0325 4020 Parvdm - ok
16:16:37.0356 4020 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
16:16:37.0356 4020 pci - ok
16:16:37.0388 4020 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
16:16:37.0388 4020 pciide - ok
16:16:37.0403 4020 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
16:16:37.0419 4020 pcmcia - ok
16:16:37.0434 4020 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
16:16:37.0434 4020 pcw - ok
16:16:37.0466 4020 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
16:16:37.0466 4020 PEAUTH - ok
16:16:37.0512 4020 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
16:16:37.0512 4020 PptpMiniport - ok
16:16:37.0528 4020 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
16:16:37.0528 4020 Processor - ok
16:16:37.0559 4020 PROCEXP151 - ok
16:16:37.0590 4020 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
16:16:37.0590 4020 Psched - ok
16:16:37.0700 4020 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
16:16:37.0700 4020 ql2300 - ok
16:16:37.0731 4020 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
16:16:37.0731 4020 ql40xx - ok
16:16:37.0762 4020 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
16:16:37.0762 4020 QWAVEdrv - ok
16:16:37.0778 4020 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
16:16:37.0778 4020 RasAcd - ok
16:16:37.0793 4020 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
16:16:37.0793 4020 RasAgileVpn - ok
16:16:37.0809 4020 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:16:37.0809 4020 Rasl2tp - ok
16:16:37.0856 4020 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
16:16:37.0856 4020 RasPppoe - ok
16:16:37.0856 4020 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
16:16:37.0856 4020 RasSstp - ok
16:16:37.0887 4020 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
16:16:37.0887 4020 rdbss - ok
16:16:37.0902 4020 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
16:16:37.0918 4020 rdpbus - ok
16:16:37.0949 4020 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:16:37.0949 4020 RDPCDD - ok
16:16:37.0965 4020 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
16:16:37.0965 4020 RDPDR - ok
16:16:37.0965 4020 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
16:16:37.0965 4020 RDPENCDD - ok
16:16:37.0980 4020 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
16:16:37.0980 4020 RDPREFMP - ok
16:16:38.0027 4020 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
16:16:38.0027 4020 RDPWD - ok
16:16:38.0090 4020 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
16:16:38.0090 4020 rdyboost - ok
16:16:38.0121 4020 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
16:16:38.0121 4020 rspndr - ok
16:16:38.0152 4020 RTL8167 (be70718d14bfc8b6925c3a25a9c1be45) C:\Windows\system32\DRIVERS\Rt86win7.sys
16:16:38.0152 4020 RTL8167 - ok
16:16:38.0183 4020 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
16:16:38.0183 4020 s3cap - ok
16:16:38.0230 4020 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
16:16:38.0230 4020 sbp2port - ok
16:16:38.0277 4020 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
16:16:38.0277 4020 scfilter - ok
16:16:38.0292 4020 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:16:38.0292 4020 secdrv - ok
16:16:38.0308 4020 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
16:16:38.0308 4020 Serenum - ok
16:16:38.0339 4020 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
16:16:38.0339 4020 Serial - ok
16:16:38.0386 4020 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
16:16:38.0386 4020 sermouse - ok
16:16:38.0417 4020 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
16:16:38.0417 4020 sffdisk - ok
16:16:38.0433 4020 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
16:16:38.0433 4020 sffp_mmc - ok
16:16:38.0448 4020 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
16:16:38.0448 4020 sffp_sd - ok
16:16:38.0464 4020 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
16:16:38.0464 4020 sfloppy - ok
16:16:38.0511 4020 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
16:16:38.0511 4020 sisagp - ok
16:16:38.0542 4020 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:16:38.0542 4020 SiSRaid2 - ok
16:16:38.0558 4020 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
16:16:38.0558 4020 SiSRaid4 - ok
16:16:38.0589 4020 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
16:16:38.0589 4020 Smb - ok
16:16:38.0604 4020 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
16:16:38.0604 4020 spldr - ok
16:16:38.0651 4020 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
16:16:38.0651 4020 srv - ok
16:16:38.0667 4020 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
16:16:38.0667 4020 srv2 - ok
16:16:38.0698 4020 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
16:16:38.0698 4020 srvnet - ok
16:16:38.0729 4020 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
16:16:38.0729 4020 stexstor - ok
16:16:38.0760 4020 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
16:16:38.0760 4020 storflt - ok
16:16:38.0792 4020 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
16:16:38.0792 4020 storvsc - ok
16:16:38.0823 4020 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
16:16:38.0823 4020 swenum - ok
16:16:38.0901 4020 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
16:16:38.0916 4020 Tcpip - ok
16:16:38.0948 4020 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
16:16:38.0963 4020 TCPIP6 - ok
16:16:38.0994 4020 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
16:16:38.0994 4020 tcpipreg - ok
16:16:39.0010 4020 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
16:16:39.0026 4020 TDPIPE - ok
16:16:39.0026 4020 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
16:16:39.0041 4020 TDTCP - ok
16:16:39.0072 4020 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
16:16:39.0072 4020 tdx - ok
16:16:39.0104 4020 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
16:16:39.0104 4020 TermDD - ok
16:16:39.0150 4020 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:16:39.0150 4020 tssecsrv - ok
16:16:39.0182 4020 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
16:16:39.0182 4020 TsUsbFlt - ok
16:16:39.0213 4020 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
16:16:39.0213 4020 tunnel - ok
16:16:39.0228 4020 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
16:16:39.0228 4020 uagp35 - ok
16:16:39.0260 4020 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
16:16:39.0260 4020 udfs - ok
16:16:39.0291 4020 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
16:16:39.0291 4020 uliagpkx - ok
16:16:39.0338 4020 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
16:16:39.0338 4020 umbus - ok
16:16:39.0353 4020 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
16:16:39.0353 4020 UmPass - ok
16:16:39.0384 4020 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\drivers\usbccgp.sys
16:16:39.0384 4020 usbccgp - ok
16:16:39.0416 4020 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
16:16:39.0416 4020 usbcir - ok
16:16:39.0447 4020 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
16:16:39.0447 4020 usbehci - ok
16:16:39.0478 4020 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
16:16:39.0494 4020 usbhub - ok
16:16:39.0525 4020 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
16:16:39.0525 4020 usbohci - ok
16:16:39.0540 4020 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
16:16:39.0540 4020 usbprint - ok
16:16:39.0556 4020 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:16:39.0556 4020 USBSTOR - ok
16:16:39.0572 4020 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
16:16:39.0572 4020 usbuhci - ok
16:16:39.0603 4020 VClone (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys
16:16:39.0603 4020 VClone - ok
16:16:39.0618 4020 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
16:16:39.0618 4020 vdrvroot - ok
16:16:39.0696 4020 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
16:16:39.0696 4020 vga - ok
16:16:39.0728 4020 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
16:16:39.0728 4020 VgaSave - ok
16:16:39.0759 4020 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
16:16:39.0759 4020 vhdmp - ok
16:16:39.0868 4020 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
16:16:39.0868 4020 viaagp - ok
16:16:39.0884 4020 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
16:16:39.0884 4020 ViaC7 - ok
16:16:39.0930 4020 VIAHdAudAddService (b9ecf6756858c8fed4fe68e966bf2f5f) C:\Windows\system32\drivers\viahduaa.sys
16:16:39.0946 4020 VIAHdAudAddService - ok
16:16:39.0962 4020 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
16:16:39.0962 4020 viaide - ok
16:16:39.0993 4020 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
16:16:39.0993 4020 vmbus - ok
16:16:40.0024 4020 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
16:16:40.0024 4020 VMBusHID - ok
16:16:40.0055 4020 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
16:16:40.0055 4020 volmgr - ok
16:16:40.0071 4020 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
16:16:40.0071 4020 volmgrx - ok
16:16:40.0086 4020 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
16:16:40.0086 4020 volsnap - ok
16:16:40.0133 4020 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
16:16:40.0133 4020 vsmraid - ok
16:16:40.0164 4020 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
16:16:40.0164 4020 vwifibus - ok
16:16:40.0180 4020 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
16:16:40.0180 4020 WacomPen - ok
16:16:40.0227 4020 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
16:16:40.0227 4020 WANARP - ok
16:16:40.0227 4020 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
16:16:40.0227 4020 Wanarpv6 - ok
16:16:40.0258 4020 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
16:16:40.0258 4020 Wd - ok
16:16:40.0289 4020 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
16:16:40.0289 4020 Wdf01000 - ok
16:16:40.0352 4020 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
16:16:40.0352 4020 WfpLwf - ok
16:16:40.0367 4020 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
16:16:40.0367 4020 WIMMount - ok
16:16:40.0445 4020 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
16:16:40.0445 4020 WmiAcpi - ok
16:16:40.0461 4020 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
16:16:40.0461 4020 ws2ifsl - ok
16:16:40.0508 4020 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
16:16:40.0508 4020 WudfPf - ok
16:16:40.0554 4020 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:16:40.0554 4020 WUDFRd - ok
16:16:40.0601 4020 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:16:40.0648 4020 \Device\Harddisk0\DR0 - ok
16:16:40.0648 4020 Boot (0x1200) (82c556daee1c0f4232f6d9bbf7b7a014) \Device\Harddisk0\DR0\Partition0
16:16:40.0648 4020 \Device\Harddisk0\DR0\Partition0 - ok
16:16:40.0664 4020 Boot (0x1200) (3ad50ed3e92f690093c2cfc289e16a66) \Device\Harddisk0\DR0\Partition1
16:16:40.0664 4020 \Device\Harddisk0\DR0\Partition1 - ok
16:16:40.0664 4020 ============================================================
16:16:40.0664 4020 Scan finished
16:16:40.0664 4020 ============================================================
16:16:40.0679 4084 Detected object count: 1
16:16:40.0679 4084 Actual detected object count: 1
16:19:53.0870 4084 C:\Windows\system32\drivers\csc.sys - copied to quarantine
16:19:53.0932 4084 Backup copy found, using it..
16:19:53.0932 4084 C:\Windows\system32\drivers\csc.sys - will be cured on reboot
16:19:55.0508 4084 CSC ( Virus.Win32.ZAccess.c ) - User select action: Cure
16:20:06.0194 3944 Deinitialize success
Re: Prosím o log
Napsal: 14 úno 2012 17:02
od blai
16:26:33.0840 3972 TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
16:26:33.0980 3972 ============================================================
16:26:33.0980 3972 Current date / time: 2012/02/14 16:26:33.0980
16:26:33.0980 3972 SystemInfo:
16:26:33.0980 3972
16:26:33.0980 3972 OS Version: 6.1.7601 ServicePack: 1.0
16:26:33.0980 3972 Product type: Workstation
16:26:33.0980 3972 ComputerName: KROTIL-PC
16:26:33.0980 3972 UserName: Krotil
16:26:33.0980 3972 Windows directory: C:\Windows
16:26:33.0980 3972 System windows directory: C:\Windows
16:26:33.0980 3972 Processor architecture: Intel x86
16:26:33.0980 3972 Number of processors: 2
16:26:33.0980 3972 Page size: 0x1000
16:26:33.0980 3972 Boot type: Normal boot
16:26:33.0980 3972 ============================================================
16:26:36.0336 3972 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:26:36.0336 3972 Drive \Device\Harddisk1\DR1 - Size: 0x77AFFC00 (1.87 Gb), SectorSize: 0x200, Cylinders: 0xF4, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
16:26:36.0336 3972 \Device\Harddisk0\DR0:
16:26:36.0336 3972 MBR used
16:26:36.0336 3972 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
16:26:36.0336 3972 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
16:26:36.0336 3972 \Device\Harddisk1\DR1:
16:26:36.0336 3972 MBR used
16:26:36.0336 3972 \Device\Harddisk1\DR1\Partition0: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x3BB7FE
16:26:36.0367 3972 Initialize success
16:26:36.0367 3972 ============================================================
16:26:47.0817 1464 Deinitialize success
Re: Prosím o log
Napsal: 14 úno 2012 17:12
od stell
ok, mas tam Rootkit ZAccess.c
C:\Windows\system32\drivers\csc.sys
Spust este raz v nudzovom rezime TDSSKILLER, klikni na Change parameters, zafajkni services and drivers, a boot sectors,,
a klikni OK,, start scan, po scane TU nastavis CURE,
C:\Windows\system32\drivers\csc.sys, a klikni na ok, log vloz sem
Re: Prosím o log
Napsal: 14 úno 2012 17:34
od stell
Aha, ty si uz tu strcil log,
16:19:55.0508 4084 CSC ( Virus.Win32.ZAccess.c ) - User select action: Cure
16:20:06.0194 3944 Deinitialize success
Dobre, najdi na C:\Qoobox, zazipsuj a nahraj to sem
http://leteckaposta.cz/
Link vloz sem.
Re: Prosím o log
Napsal: 14 úno 2012 17:46
od blai
Re: Prosím o log
Napsal: 14 úno 2012 18:03
od stell
Ok, stiahni na plochu system look
http://jpshortstuff.247fixes.com/SystemLook.exe
Spust, do okna skopiruj tento scrip>.a klik look, log vloz sem
Re: Prosím o log
Napsal: 14 úno 2012 18:27
od blai
SystemLook 30.07.11 by jpshortstuff
Log created at 18:25 on 14/02/2012 by Krotil
Administrator - Elevation successful
========== filefind ==========
Searching for "*cscsvc.dll*"
C:\Windows\System32\cscsvc.dll --a---- 546304 bytes [11:24 02/07/2011] [22:23 11/02/2012] B7A8C3DCD4EF924230254203B824D7C1
C:\Windows\System32\cs-CZ\cscsvc.dll.mui --a---- 22528 bytes [08:43 14/07/2009] [08:43 14/07/2009] BD2B8FE8E65ADECBE6455017691B2588
C:\Windows\winsxs\x86_microsoft-windows-o..s-service.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_1503d3044a61d760\cscsvc.dll.mui --a---- 22528 bytes [08:43 14/07/2009] [08:43 14/07/2009] BD2B8FE8E65ADECBE6455017691B2588
C:\Windows\winsxs\x86_microsoft-windows-offlinefiles-service_31bf3856ad364e35_6.1.7600.16385_none_09a9e82dc2b3d9eb\cscsvc.dll --a---- 544256 bytes [23:15 13/07/2009] [01:15 14/07/2009] 56FB5F222EA30D3D3FC459879772CB73
C:\Windows\winsxs\x86_microsoft-windows-offlinefiles-service_31bf3856ad364e35_6.1.7601.17514_none_0bdafbf5bfa25d85\cscsvc.dll --a---- 546304 bytes [11:24 02/07/2011] [22:23 11/02/2012] B7A8C3DCD4EF924230254203B824D7C1
-= EOF =-