Stránka 4 z 6

Re: Prosím o log

Napsal: 14 úno 2012 18:33
od stell
Ok,pozorne citaj co pisem
1:Preklikas sa sem,
C:\Qoobox\Quarantine\Registry_backups\service_Cscservice.reg.dat
Pravy klik>.prejmenovat>>Zmazes bodku a koncovku .dat
takze bude to vyzerat takto
C:\Qoobox\Quarantine\Registry_backups\service_Cscservice.reg
Ikonka sa zmeni na register, Pravy klik na ikonku, a kliknes na prikaz SLOUCIT>.potvrdit.


2:Premunuj ikonku Combofixu na uninstall
a spust, combofix sa odinstaluje,
Restart,,,

Stiahnes novu verziu combofixu na plochu a spustis, log vloz sem
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosím o log

Napsal: 14 úno 2012 19:07
od blai
Já jsem se tam proklikal, ale příkaz sloučit po kliknutí pravým tlačítkem tam bohužel není. :?:

Re: Prosím o log

Napsal: 14 úno 2012 19:08
od stell
Tak 2x klikni nan a suhlas,,

Re: Prosím o log

Napsal: 14 úno 2012 19:31
od blai
Combofix všechno projel, dvakrát se restartoval, ale log nejde dohledat.

Re: Prosím o log

Napsal: 14 úno 2012 19:36
od stell
:) stlac klaves winlogon+R a vloz tento prikaz
c:\combofix.txt
Malo by sa otvorit log, ak nie, tak spust combofix v nudzovom rezime, ak restartne tak znova trba do nudzoveho rezimu a pockat kym ti da log,
Pravdepodobne ti tam po restarte Firewall sarapati.

Re: Prosím o log

Napsal: 14 úno 2012 20:02
od blai
Tak po modré smrti a dvou restartech to mám :-)


ComboFix 12-02-13.01 - Krotil 14.02.2012 19:47:48.9.2 - x86 MINIMAL
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3327.2669 [GMT 1:00]
Spuštěný z: c:\users\Krotil\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB1865$
c:\windows\$NtUninstallKB1865$\2195031452\@
c:\windows\$NtUninstallKB1865$\2195031452\cfg.ini
c:\windows\$NtUninstallKB1865$\2195031452\Desktop.ini
c:\windows\$NtUninstallKB1865$\2195031452\L\xadqgnnk
c:\windows\$NtUninstallKB1865$\2195031452\twl.dll
c:\windows\$NtUninstallKB1865$\2195031452\U\00000001.@
c:\windows\$NtUninstallKB1865$\2195031452\U\00000002.@
c:\windows\$NtUninstallKB1865$\2195031452\U\00000004.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000000.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000004.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000032.@
c:\windows\$NtUninstallKB1865$\2195031452\version
c:\windows\$NtUninstallKB1865$\485870815
.
---- Předchozí spuštění -------
.
c:\windows\$NtUninstallKB1865$\163420878
c:\windows\$NtUninstallKB1865$\2195031452\@
c:\windows\$NtUninstallKB1865$\2195031452\cfg.ini
c:\windows\$NtUninstallKB1865$\2195031452\Desktop.ini
c:\windows\$NtUninstallKB1865$\2195031452\L\xadqgnnk
c:\windows\$NtUninstallKB1865$\2195031452\twl.dll
c:\windows\$NtUninstallKB1865$\2195031452\U\00000001.@
c:\windows\$NtUninstallKB1865$\2195031452\U\00000002.@
c:\windows\$NtUninstallKB1865$\2195031452\U\00000004.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000000.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000004.@
c:\windows\$NtUninstallKB1865$\2195031452\U\80000032.@
c:\windows\$NtUninstallKB1865$\2195031452\version
.
Nakažená kopie c:\windows\system32\drivers\csc.sys byla nalezena a vyléčena.
Obnovena kopie z - The cat found it :)
-- Předchozí spuštění --
.
Nakažená kopie c:\windows\system32\drivers\csc.sys byla nalezena a vyléčena.
Obnovena kopie z - The cat found it :)
c:\windows\system32\drivers\cdrom.sys chyběl.
Obnovena kopie z - c:\windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys
.
--------
.
c:\windows\system32\drivers\Serial.sys chyběl.
Obnovena kopie z - c:\windows\System32\DriverStore\FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\serial.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-14 do 2012-02-14 )))))))))))))))))))))))))))))))
.
.
2012-02-14 18:54 . 2012-02-14 18:54 -------- d-----w- c:\users\Krotil\AppData\Local\temp
2012-02-14 18:54 . 2012-02-14 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-14 18:53 . 2009-07-13 23:45 83456 ----a-w- c:\windows\system32\drivers\Serial.sys
2012-02-14 18:48 . 2012-02-14 18:48 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{235F9C96-D4AD-4BDD-8D0C-318E0349B00E}\offreg.dll
2012-02-14 18:46 . 2009-07-13 23:15 387584 ----a-w- c:\windows\system32\drivers\csc.sys
2012-02-14 18:24 . 2010-11-20 08:38 108544 ----a-w- c:\windows\system32\drivers\cdrom.sys
2012-02-14 15:19 . 2012-02-14 16:30 -------- d-----w- C:\TDSSKiller_Quarantine
2012-02-14 12:29 . 2012-01-17 03:39 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{235F9C96-D4AD-4BDD-8D0C-318E0349B00E}\mpengine.dll
2012-02-13 16:11 . 2012-02-14 16:32 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-12 21:43 . 2012-02-12 21:43 -------- d-----w- c:\program files\CCleaner
2012-02-12 13:26 . 2012-02-12 13:26 -------- d-----w- c:\programdata\Kaspersky Lab
2012-02-11 20:11 . 2012-02-12 14:32 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2012-02-11 17:57 . 2012-02-13 11:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-02-11 17:57 . 2012-02-11 18:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2012-02-09 18:00 . 2012-02-12 15:08 -------- d-----w- c:\program files\trend micro
2012-02-09 18:00 . 2012-02-11 18:34 -------- d-----w- C:\rsit
2012-02-05 15:55 . 2012-02-14 18:26 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-01-25 17:56 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-25 17:56 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-25 17:56 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-25 17:56 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-25 17:56 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-25 17:56 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-25 17:56 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-25 17:56 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-25 17:56 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-25 17:56 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-19 13:08 . 2012-01-19 13:08 -------- d-----w- c:\program files\TeamViewer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-14 12:32 . 2010-10-22 16:59 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-02-13 16:10 . 2011-07-02 11:23 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2012-02-13 16:04 . 2011-07-02 11:22 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-02-12 18:10 . 2011-01-15 08:22 484176 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-02-08 09:08 . 2011-06-02 10:42 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2012-02-08 09:08 . 2010-10-22 16:59 484176 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-01-29 04:10 . 2010-10-25 12:45 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-12-15 13:43 . 2011-11-22 16:34 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25 . 2011-12-15 11:12 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-19 14:01 . 2012-01-11 11:55 67072 ----a-w- c:\windows\system32\packager.dll
2011-11-17 05:38 . 2012-01-11 11:56 1288472 ----a-w- c:\windows\system32\ntdll.dll
2011-11-17 05:34 . 2012-01-25 17:56 224768 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-08-16 2736128]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-06 39408]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-02-10 1713152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NBAgent"="c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-28 1406248]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
c:\users\Krotil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
_uninst_53949120.lnk - c:\users\Krotil\AppData\Local\temp\_uninst_53949120.bat [N/A]
_uninst_55685608.lnk - c:\users\Krotil\AppData\Local\temp\_uninst_55685608.bat [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Image Transfer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Image Transfer.lnk
backup=c:\windows\pss\Image Transfer.lnk.CommonStartup
backupExtension=.CommonStartup
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CFcatchme;CFcatchme;c:\users\Krotil\AppData\Local\Temp\CFcatchme.sys [x]
R3 PROCEXP151;PROCEXP151;c:\windows\system32\Drivers\PROCEXP151.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-27 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-24 172032]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2011-07-22 690472]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-11-17 232448]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-01-11 1119232]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
compaq_rba
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-08-16 11:43 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 10.0.18.234 88.86.107.86
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-39372139.sys
SafeBoot-85319466.sys
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\.avgldx86]
"ImagePath"="\?"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2012-02-14 20:00:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-02-14 19:00
ComboFix2.txt 2012-02-12 22:16
.
Před spuštěním: Volných bajtů: 696 504 619 008
Po spuštění: Volných bajtů: 696 369 074 176
.
- - End Of File - - E1DFD263855833FACF9081C98B399B2A

Re: Prosím o log

Napsal: 14 úno 2012 20:12
od stell
ok
Odinstaluj tento smejd, len na to je dobre ze postavi nazad infikovane kluce.
c:\program files\Spybot - Search & Destroy
Odinstaluj aj AVG, potom ak PC bude ok Dame tam nieco ine, Win7 nepotrebuje Firewall.

Stiahni na plochu OTl
http://oldtimer.geekstogo.com/OTL.exe
spust, dole do okna skopiruj tento script, a klikni na Gombik OPRAVIT, log vloz sem.

Kód: Vybrat vše

:processes
explorer.exe
:Files
echo,Y|cacls "%WinDir%\system32\drivers\etc\hosts" /G everyone:f /c
ipconfig /flushdns /c
:Commands
[resethosts]
[emptytemp]
[clearallrestorepoints]
[start explorer]
[Reboot]

Re: Prosím o log

Napsal: 14 úno 2012 20:28
od blai
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
< echo,Y|cacls "%WinDir%\system32\drivers\etc\hosts" /G everyone:f /c >
Opravdu to chcete (A/N)?
C:\Users\Krotil\Downloads\cmd.bat deleted successfully.
C:\Users\Krotil\Downloads\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Konfigurace protokolu IP syst‚mu Windows
MezipamŘś pýekl d nˇ DNS byla ŁspŘçnŘ vypr zdnŘna.
C:\Users\Krotil\Downloads\cmd.bat deleted successfully.
C:\Users\Krotil\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Krotil
->Temp folder emptied: 66560 bytes
->Temporary Internet Files folder emptied: 3352340 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 720 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 4880 bytes

Total Files Cleaned = 3,00 mb



OTL by OldTimer - Version 3.2.31.0 log created on 02142012_202438

Files\Folders moved on Reboot...
File\Folder C:\Users\Krotil\AppData\Local\Temp\~DF0B94E6E6EEC03EBA.TMP not found!
File\Folder C:\Users\Krotil\AppData\Local\Temp\~DF1564DF1EFDCA2969.TMP not found!
File\Folder C:\Users\Krotil\AppData\Local\Temp\~DFC0AEE5197AD2DD48.TMP not found!
File\Folder C:\Users\Krotil\AppData\Local\Temp\~DFD1F52C9CA2D2B265.TMP not found!
C:\Users\Krotil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROEFHMBI\viewtopic[1].htm moved successfully.
C:\Users\Krotil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PKJO5W7R\plusone_gadget[1].htm moved successfully.
C:\Users\Krotil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OV3ACMVX\afr[1].htm moved successfully.

Registry entries deleted on Reboot...

Re: Prosím o log

Napsal: 14 úno 2012 20:29
od stell
Ok, daj novy log s TDSSKILLER>spust, ked dokonci sken, hore klikni na REPORT, log vloz sem.

Re: Prosím o log

Napsal: 14 úno 2012 20:32
od blai
20:31:26.0155 2920 TDSS rootkit removing tool 2.7.12.0 Feb 11 2012 16:58:52
20:31:26.0264 2920 ============================================================
20:31:26.0264 2920 Current date / time: 2012/02/14 20:31:26.0264
20:31:26.0264 2920 SystemInfo:
20:31:26.0264 2920
20:31:26.0264 2920 OS Version: 6.1.7601 ServicePack: 1.0
20:31:26.0264 2920 Product type: Workstation
20:31:26.0264 2920 ComputerName: KROTIL-PC
20:31:26.0264 2920 UserName: Krotil
20:31:26.0264 2920 Windows directory: C:\Windows
20:31:26.0264 2920 System windows directory: C:\Windows
20:31:26.0264 2920 Processor architecture: Intel x86
20:31:26.0264 2920 Number of processors: 2
20:31:26.0264 2920 Page size: 0x1000
20:31:26.0264 2920 Boot type: Normal boot
20:31:26.0264 2920 ============================================================
20:31:28.0120 2920 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
20:31:28.0120 2920 \Device\Harddisk0\DR0:
20:31:28.0120 2920 MBR used
20:31:28.0120 2920 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:31:28.0120 2920 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
20:31:28.0136 2920 Initialize success
20:31:28.0136 2920 ============================================================
20:31:29.0774 2740 ============================================================
20:31:29.0774 2740 Scan started
20:31:29.0774 2740 Mode: Manual;
20:31:29.0774 2740 ============================================================
20:31:30.0647 2740 .avgldx86 - ok
20:31:30.0772 2740 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
20:31:30.0772 2740 1394ohci - ok
20:31:30.0819 2740 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
20:31:30.0819 2740 ACPI - ok
20:31:30.0850 2740 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
20:31:30.0850 2740 AcpiPmi - ok
20:31:31.0022 2740 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
20:31:31.0037 2740 adp94xx - ok
20:31:31.0053 2740 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
20:31:31.0053 2740 adpahci - ok
20:31:31.0084 2740 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
20:31:31.0084 2740 adpu320 - ok
20:31:31.0147 2740 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
20:31:31.0147 2740 AFD - ok
20:31:31.0193 2740 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
20:31:31.0193 2740 agp440 - ok
20:31:31.0209 2740 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
20:31:31.0209 2740 aic78xx - ok
20:31:31.0240 2740 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
20:31:31.0256 2740 aliide - ok
20:31:31.0287 2740 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
20:31:31.0287 2740 amdagp - ok
20:31:31.0318 2740 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
20:31:31.0318 2740 amdide - ok
20:31:31.0318 2740 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
20:31:31.0318 2740 AmdK8 - ok
20:31:31.0349 2740 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\Windows\system32\DRIVERS\AmdLLD.sys
20:31:31.0349 2740 AmdLLD - ok
20:31:31.0381 2740 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
20:31:31.0381 2740 AmdPPM - ok
20:31:31.0396 2740 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
20:31:31.0396 2740 amdsata - ok
20:31:31.0412 2740 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
20:31:31.0412 2740 amdsbs - ok
20:31:31.0427 2740 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
20:31:31.0427 2740 amdxata - ok
20:31:31.0459 2740 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
20:31:31.0459 2740 AppID - ok
20:31:31.0521 2740 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
20:31:31.0521 2740 arc - ok
20:31:31.0537 2740 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
20:31:31.0537 2740 arcsas - ok
20:31:31.0583 2740 AsIO (9d8cb58b9a9e177ddd599791a58a654d) C:\Windows\system32\drivers\AsIO.sys
20:31:31.0583 2740 AsIO - ok
20:31:31.0599 2740 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
20:31:31.0599 2740 AsyncMac - ok
20:31:31.0615 2740 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
20:31:31.0615 2740 atapi - ok
20:31:31.0677 2740 AtiHdmiService (430449d04b05348879244c9090d405b4) C:\Windows\system32\drivers\AtiHdmi.sys
20:31:31.0677 2740 AtiHdmiService - ok
20:31:31.0755 2740 atikmdag (712d8a95e45b070114c5309ada7358ff) C:\Windows\system32\DRIVERS\atikmdag.sys
20:31:31.0833 2740 atikmdag - ok
20:31:31.0849 2740 AtiPcie (aca01c43d065e546c6dc88ea669ceca6) C:\Windows\system32\DRIVERS\AtiPcie.sys
20:31:31.0849 2740 AtiPcie - ok
20:31:31.0895 2740 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
20:31:31.0895 2740 b06bdrv - ok
20:31:31.0927 2740 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
20:31:31.0942 2740 b57nd60x - ok
20:31:31.0958 2740 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
20:31:31.0958 2740 Beep - ok
20:31:32.0083 2740 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
20:31:32.0083 2740 blbdrive - ok
20:31:32.0129 2740 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
20:31:32.0129 2740 bowser - ok
20:31:32.0129 2740 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:31:32.0129 2740 BrFiltLo - ok
20:31:32.0145 2740 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:31:32.0145 2740 BrFiltUp - ok
20:31:32.0176 2740 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
20:31:32.0176 2740 BridgeMP - ok
20:31:32.0207 2740 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
20:31:32.0207 2740 Brserid - ok
20:31:32.0207 2740 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
20:31:32.0207 2740 BrSerWdm - ok
20:31:32.0239 2740 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:31:32.0239 2740 BrUsbMdm - ok
20:31:32.0239 2740 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
20:31:32.0239 2740 BrUsbSer - ok
20:31:32.0254 2740 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
20:31:32.0254 2740 BTHMODEM - ok
20:31:32.0363 2740 catchme - ok
20:31:32.0379 2740 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
20:31:32.0379 2740 cdfs - ok
20:31:32.0426 2740 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
20:31:32.0426 2740 cdrom - ok
20:31:32.0488 2740 CFcatchme - ok
20:31:32.0504 2740 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
20:31:32.0504 2740 circlass - ok
20:31:32.0535 2740 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
20:31:32.0535 2740 CLFS - ok
20:31:32.0551 2740 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
20:31:32.0551 2740 CmBatt - ok
20:31:32.0597 2740 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
20:31:32.0597 2740 cmdide - ok
20:31:32.0629 2740 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
20:31:32.0629 2740 CNG - ok
20:31:32.0644 2740 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
20:31:32.0644 2740 Compbatt - ok
20:31:32.0660 2740 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
20:31:32.0660 2740 CompositeBus - ok
20:31:32.0675 2740 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
20:31:32.0675 2740 crcdisk - ok
20:31:32.0738 2740 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
20:31:32.0738 2740 CSC - ok
20:31:32.0800 2740 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
20:31:32.0800 2740 DfsC - ok
20:31:32.0816 2740 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
20:31:32.0816 2740 discache - ok
20:31:32.0831 2740 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
20:31:32.0831 2740 Disk - ok
20:31:32.0863 2740 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
20:31:32.0863 2740 drmkaud - ok
20:31:32.0925 2740 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
20:31:32.0925 2740 DXGKrnl - ok
20:31:32.0987 2740 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
20:31:33.0034 2740 ebdrv - ok
20:31:33.0065 2740 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
20:31:33.0081 2740 elxstor - ok
20:31:33.0097 2740 ENTECH - ok
20:31:33.0128 2740 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
20:31:33.0128 2740 ErrDev - ok
20:31:33.0159 2740 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
20:31:33.0159 2740 exfat - ok
20:31:33.0175 2740 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
20:31:33.0175 2740 fastfat - ok
20:31:33.0190 2740 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
20:31:33.0206 2740 fdc - ok
20:31:33.0206 2740 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
20:31:33.0206 2740 FileInfo - ok
20:31:33.0221 2740 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
20:31:33.0221 2740 Filetrace - ok
20:31:33.0237 2740 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
20:31:33.0237 2740 flpydisk - ok
20:31:33.0253 2740 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
20:31:33.0253 2740 FltMgr - ok
20:31:33.0268 2740 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
20:31:33.0268 2740 FsDepends - ok
20:31:33.0315 2740 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
20:31:33.0315 2740 fssfltr - ok
20:31:33.0331 2740 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
20:31:33.0331 2740 Fs_Rec - ok
20:31:33.0377 2740 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
20:31:33.0377 2740 fvevol - ok
20:31:33.0393 2740 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
20:31:33.0393 2740 gagp30kx - ok
20:31:33.0409 2740 GMSIPCI - ok
20:31:33.0424 2740 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
20:31:33.0424 2740 hcw85cir - ok
20:31:33.0471 2740 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
20:31:33.0471 2740 HdAudAddService - ok
20:31:33.0487 2740 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:31:33.0487 2740 HDAudBus - ok
20:31:33.0502 2740 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
20:31:33.0502 2740 HidBatt - ok
20:31:33.0518 2740 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
20:31:33.0518 2740 HidBth - ok
20:31:33.0533 2740 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
20:31:33.0533 2740 HidIr - ok
20:31:33.0580 2740 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
20:31:33.0580 2740 HidUsb - ok
20:31:33.0611 2740 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
20:31:33.0611 2740 HpSAMD - ok
20:31:33.0643 2740 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
20:31:33.0643 2740 HTTP - ok
20:31:33.0674 2740 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
20:31:33.0674 2740 hwpolicy - ok
20:31:33.0705 2740 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
20:31:33.0705 2740 i8042prt - ok
20:31:33.0736 2740 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
20:31:33.0736 2740 iaStorV - ok
20:31:33.0767 2740 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
20:31:33.0767 2740 iirsp - ok
20:31:33.0830 2740 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
20:31:33.0830 2740 intelide - ok
20:31:33.0861 2740 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
20:31:33.0861 2740 intelppm - ok
20:31:33.0877 2740 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:31:33.0892 2740 IpFilterDriver - ok
20:31:33.0955 2740 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
20:31:33.0955 2740 IPMIDRV - ok
20:31:33.0986 2740 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
20:31:33.0986 2740 IPNAT - ok
20:31:34.0001 2740 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
20:31:34.0001 2740 IRENUM - ok
20:31:34.0033 2740 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
20:31:34.0033 2740 isapnp - ok
20:31:34.0064 2740 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
20:31:34.0064 2740 iScsiPrt - ok
20:31:34.0095 2740 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
20:31:34.0095 2740 kbdclass - ok
20:31:34.0126 2740 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
20:31:34.0126 2740 kbdhid - ok
20:31:34.0157 2740 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
20:31:34.0157 2740 KSecDD - ok
20:31:34.0204 2740 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
20:31:34.0204 2740 KSecPkg - ok
20:31:34.0251 2740 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
20:31:34.0251 2740 lltdio - ok
20:31:34.0267 2740 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
20:31:34.0267 2740 LSI_FC - ok
20:31:34.0282 2740 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
20:31:34.0282 2740 LSI_SAS - ok
20:31:34.0298 2740 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:31:34.0298 2740 LSI_SAS2 - ok
20:31:34.0313 2740 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:31:34.0313 2740 LSI_SCSI - ok
20:31:34.0313 2740 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
20:31:34.0313 2740 luafv - ok
20:31:34.0329 2740 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
20:31:34.0329 2740 megasas - ok
20:31:34.0360 2740 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
20:31:34.0360 2740 MegaSR - ok
20:31:34.0391 2740 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
20:31:34.0391 2740 Modem - ok
20:31:34.0407 2740 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
20:31:34.0423 2740 monitor - ok
20:31:34.0423 2740 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
20:31:34.0423 2740 mouclass - ok
20:31:34.0438 2740 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
20:31:34.0438 2740 mouhid - ok
20:31:34.0485 2740 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
20:31:34.0485 2740 mountmgr - ok
20:31:34.0516 2740 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
20:31:34.0516 2740 mpio - ok
20:31:34.0532 2740 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
20:31:34.0532 2740 mpsdrv - ok
20:31:34.0563 2740 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
20:31:34.0563 2740 MRxDAV - ok
20:31:34.0594 2740 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:31:34.0610 2740 mrxsmb - ok
20:31:34.0625 2740 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:31:34.0641 2740 mrxsmb10 - ok
20:31:34.0657 2740 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:31:34.0657 2740 mrxsmb20 - ok
20:31:34.0657 2740 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
20:31:34.0657 2740 msahci - ok
20:31:34.0688 2740 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
20:31:34.0688 2740 msdsm - ok
20:31:34.0719 2740 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
20:31:34.0719 2740 Msfs - ok
20:31:34.0735 2740 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
20:31:34.0735 2740 mshidkmdf - ok
20:31:34.0766 2740 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
20:31:34.0766 2740 msisadrv - ok
20:31:34.0797 2740 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
20:31:34.0797 2740 MSKSSRV - ok
20:31:34.0828 2740 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
20:31:34.0828 2740 MSPCLOCK - ok
20:31:34.0859 2740 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
20:31:34.0859 2740 MSPQM - ok
20:31:34.0875 2740 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
20:31:34.0875 2740 MsRPC - ok
20:31:34.0891 2740 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
20:31:34.0891 2740 mssmbios - ok
20:31:34.0906 2740 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
20:31:34.0906 2740 MSTEE - ok
20:31:34.0922 2740 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
20:31:34.0922 2740 MTConfig - ok
20:31:34.0969 2740 MTsensor (cbe71c122434805cb73ffb6619f60598) C:\Windows\system32\DRIVERS\ASACPI.sys
20:31:34.0969 2740 MTsensor - ok
20:31:34.0984 2740 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
20:31:34.0984 2740 Mup - ok
20:31:35.0015 2740 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
20:31:35.0015 2740 NativeWifiP - ok
20:31:35.0093 2740 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
20:31:35.0093 2740 NDIS - ok
20:31:35.0109 2740 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
20:31:35.0109 2740 NdisCap - ok
20:31:35.0125 2740 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
20:31:35.0125 2740 NdisTapi - ok
20:31:35.0171 2740 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
20:31:35.0171 2740 Ndisuio - ok
20:31:35.0203 2740 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
20:31:35.0203 2740 NdisWan - ok
20:31:35.0234 2740 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
20:31:35.0234 2740 NDProxy - ok
20:31:35.0249 2740 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
20:31:35.0249 2740 NetBIOS - ok
20:31:35.0281 2740 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
20:31:35.0281 2740 NetBT - ok
20:31:35.0312 2740 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
20:31:35.0312 2740 nfrd960 - ok
20:31:35.0343 2740 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
20:31:35.0343 2740 Npfs - ok
20:31:35.0359 2740 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
20:31:35.0359 2740 nsiproxy - ok
20:31:35.0405 2740 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
20:31:35.0421 2740 Ntfs - ok
20:31:35.0421 2740 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
20:31:35.0421 2740 Null - ok
20:31:35.0624 2740 nvlddmkm (847b1755f7757f825305a1ffe6dac3e9) C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:31:35.0671 2740 nvlddmkm - ok
20:31:35.0702 2740 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
20:31:35.0702 2740 nvraid - ok
20:31:35.0749 2740 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
20:31:35.0749 2740 nvstor - ok
20:31:35.0764 2740 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
20:31:35.0780 2740 nv_agp - ok
20:31:35.0811 2740 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
20:31:35.0811 2740 ohci1394 - ok
20:31:35.0842 2740 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
20:31:35.0842 2740 Parport - ok
20:31:35.0858 2740 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
20:31:35.0858 2740 partmgr - ok
20:31:35.0873 2740 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
20:31:35.0889 2740 Parvdm - ok
20:31:35.0920 2740 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
20:31:35.0920 2740 pci - ok
20:31:35.0951 2740 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
20:31:35.0951 2740 pciide - ok
20:31:35.0967 2740 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
20:31:35.0967 2740 pcmcia - ok
20:31:35.0998 2740 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
20:31:35.0998 2740 pcw - ok
20:31:36.0014 2740 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
20:31:36.0029 2740 PEAUTH - ok
20:31:36.0061 2740 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
20:31:36.0076 2740 PptpMiniport - ok
20:31:36.0076 2740 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
20:31:36.0076 2740 Processor - ok
20:31:36.0092 2740 PROCEXP151 - ok
20:31:36.0123 2740 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
20:31:36.0123 2740 Psched - ok
20:31:36.0232 2740 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
20:31:36.0248 2740 ql2300 - ok
20:31:36.0263 2740 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
20:31:36.0279 2740 ql40xx - ok
20:31:36.0295 2740 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
20:31:36.0295 2740 QWAVEdrv - ok
20:31:36.0310 2740 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
20:31:36.0310 2740 RasAcd - ok
20:31:36.0326 2740 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:31:36.0326 2740 RasAgileVpn - ok
20:31:36.0341 2740 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:31:36.0341 2740 Rasl2tp - ok
20:31:36.0373 2740 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
20:31:36.0373 2740 RasPppoe - ok
20:31:36.0388 2740 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
20:31:36.0388 2740 RasSstp - ok
20:31:36.0419 2740 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
20:31:36.0419 2740 rdbss - ok
20:31:36.0435 2740 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
20:31:36.0435 2740 rdpbus - ok
20:31:36.0466 2740 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:31:36.0466 2740 RDPCDD - ok
20:31:36.0482 2740 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
20:31:36.0482 2740 RDPDR - ok
20:31:36.0497 2740 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
20:31:36.0497 2740 RDPENCDD - ok
20:31:36.0497 2740 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
20:31:36.0497 2740 RDPREFMP - ok
20:31:36.0544 2740 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
20:31:36.0544 2740 RDPWD - ok
20:31:36.0591 2740 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
20:31:36.0591 2740 rdyboost - ok
20:31:36.0622 2740 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
20:31:36.0622 2740 rspndr - ok
20:31:36.0653 2740 RTL8167 (be70718d14bfc8b6925c3a25a9c1be45) C:\Windows\system32\DRIVERS\Rt86win7.sys
20:31:36.0653 2740 RTL8167 - ok
20:31:36.0700 2740 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
20:31:36.0700 2740 s3cap - ok
20:31:36.0747 2740 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
20:31:36.0747 2740 sbp2port - ok
20:31:36.0778 2740 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
20:31:36.0778 2740 scfilter - ok
20:31:36.0809 2740 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
20:31:36.0809 2740 secdrv - ok
20:31:36.0825 2740 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
20:31:36.0825 2740 Serenum - ok
20:31:36.0856 2740 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
20:31:36.0856 2740 Serial - ok
20:31:36.0887 2740 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
20:31:36.0903 2740 sermouse - ok
20:31:36.0934 2740 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
20:31:36.0934 2740 sffdisk - ok
20:31:36.0950 2740 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
20:31:36.0950 2740 sffp_mmc - ok
20:31:36.0965 2740 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
20:31:36.0965 2740 sffp_sd - ok
20:31:36.0981 2740 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
20:31:36.0981 2740 sfloppy - ok
20:31:37.0028 2740 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
20:31:37.0028 2740 sisagp - ok
20:31:37.0043 2740 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:31:37.0043 2740 SiSRaid2 - ok
20:31:37.0059 2740 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
20:31:37.0059 2740 SiSRaid4 - ok
20:31:37.0090 2740 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
20:31:37.0090 2740 Smb - ok
20:31:37.0121 2740 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
20:31:37.0121 2740 spldr - ok
20:31:37.0168 2740 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
20:31:37.0168 2740 srv - ok
20:31:37.0184 2740 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
20:31:37.0184 2740 srv2 - ok
20:31:37.0215 2740 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
20:31:37.0215 2740 srvnet - ok
20:31:37.0246 2740 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
20:31:37.0246 2740 stexstor - ok
20:31:37.0277 2740 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
20:31:37.0277 2740 storflt - ok
20:31:37.0309 2740 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
20:31:37.0309 2740 storvsc - ok
20:31:37.0340 2740 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
20:31:37.0340 2740 swenum - ok
20:31:37.0402 2740 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
20:31:37.0418 2740 Tcpip - ok
20:31:37.0480 2740 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
20:31:37.0480 2740 TCPIP6 - ok
20:31:37.0527 2740 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
20:31:37.0527 2740 tcpipreg - ok
20:31:37.0543 2740 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
20:31:37.0543 2740 TDPIPE - ok
20:31:37.0558 2740 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
20:31:37.0558 2740 TDTCP - ok
20:31:37.0605 2740 tdx (ae9e96679923df875047fd1d35813acd) C:\Windows\system32\DRIVERS\tdx.sys
20:31:37.0605 2740 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tdx.sys. Real md5: ae9e96679923df875047fd1d35813acd, Fake md5: b459575348c20e8121d6039da063c704
20:31:37.0605 2740 tdx ( Virus.Win32.ZAccess.c ) - infected
20:31:37.0605 2740 tdx - detected Virus.Win32.ZAccess.c (0)
20:31:37.0636 2740 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
20:31:37.0636 2740 TermDD - ok
20:31:37.0683 2740 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:31:37.0683 2740 tssecsrv - ok
20:31:37.0714 2740 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
20:31:37.0714 2740 TsUsbFlt - ok
20:31:37.0730 2740 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
20:31:37.0730 2740 tunnel - ok
20:31:37.0761 2740 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
20:31:37.0761 2740 uagp35 - ok
20:31:37.0792 2740 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
20:31:37.0792 2740 udfs - ok
20:31:37.0808 2740 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
20:31:37.0808 2740 uliagpkx - ok
20:31:37.0823 2740 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
20:31:37.0823 2740 umbus - ok
20:31:37.0839 2740 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
20:31:37.0839 2740 UmPass - ok
20:31:37.0886 2740 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\drivers\usbccgp.sys
20:31:37.0886 2740 usbccgp - ok
20:31:37.0917 2740 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
20:31:37.0917 2740 usbcir - ok
20:31:37.0933 2740 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
20:31:37.0933 2740 usbehci - ok
20:31:37.0964 2740 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
20:31:37.0964 2740 usbhub - ok
20:31:38.0011 2740 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
20:31:38.0011 2740 usbohci - ok
20:31:38.0011 2740 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
20:31:38.0026 2740 usbprint - ok
20:31:38.0026 2740 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:31:38.0026 2740 USBSTOR - ok
20:31:38.0057 2740 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
20:31:38.0057 2740 usbuhci - ok
20:31:38.0073 2740 VClone (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys
20:31:38.0073 2740 VClone - ok
20:31:38.0089 2740 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
20:31:38.0089 2740 vdrvroot - ok
20:31:38.0135 2740 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
20:31:38.0135 2740 vga - ok
20:31:38.0167 2740 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
20:31:38.0167 2740 VgaSave - ok
20:31:38.0198 2740 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
20:31:38.0198 2740 vhdmp - ok
20:31:38.0229 2740 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
20:31:38.0229 2740 viaagp - ok
20:31:38.0245 2740 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
20:31:38.0245 2740 ViaC7 - ok
20:31:38.0307 2740 VIAHdAudAddService (b9ecf6756858c8fed4fe68e966bf2f5f) C:\Windows\system32\drivers\viahduaa.sys
20:31:38.0323 2740 VIAHdAudAddService - ok
20:31:38.0354 2740 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
20:31:38.0354 2740 viaide - ok
20:31:38.0369 2740 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
20:31:38.0369 2740 vmbus - ok
20:31:38.0416 2740 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
20:31:38.0416 2740 VMBusHID - ok
20:31:38.0432 2740 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
20:31:38.0432 2740 volmgr - ok
20:31:38.0463 2740 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
20:31:38.0463 2740 volmgrx - ok
20:31:38.0479 2740 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
20:31:38.0494 2740 volsnap - ok
20:31:38.0510 2740 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
20:31:38.0510 2740 vsmraid - ok
20:31:38.0525 2740 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
20:31:38.0525 2740 vwifibus - ok
20:31:38.0557 2740 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
20:31:38.0557 2740 WacomPen - ok
20:31:38.0588 2740 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
20:31:38.0603 2740 WANARP - ok
20:31:38.0603 2740 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
20:31:38.0603 2740 Wanarpv6 - ok
20:31:38.0635 2740 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
20:31:38.0635 2740 Wd - ok
20:31:38.0650 2740 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
20:31:38.0650 2740 Wdf01000 - ok
20:31:38.0697 2740 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
20:31:38.0697 2740 WfpLwf - ok
20:31:38.0713 2740 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
20:31:38.0713 2740 WIMMount - ok
20:31:38.0791 2740 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
20:31:38.0791 2740 WmiAcpi - ok
20:31:38.0822 2740 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
20:31:38.0822 2740 ws2ifsl - ok
20:31:38.0869 2740 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
20:31:38.0869 2740 WudfPf - ok
20:31:38.0900 2740 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:31:38.0900 2740 WUDFRd - ok
20:31:38.0947 2740 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:31:38.0978 2740 \Device\Harddisk0\DR0 - ok
20:31:38.0993 2740 Boot (0x1200) (82c556daee1c0f4232f6d9bbf7b7a014) \Device\Harddisk0\DR0\Partition0
20:31:38.0993 2740 \Device\Harddisk0\DR0\Partition0 - ok
20:31:39.0009 2740 Boot (0x1200) (3ad50ed3e92f690093c2cfc289e16a66) \Device\Harddisk0\DR0\Partition1
20:31:39.0009 2740 \Device\Harddisk0\DR0\Partition1 - ok
20:31:39.0009 2740 ============================================================
20:31:39.0009 2740 Scan finished
20:31:39.0009 2740 ============================================================
20:31:39.0009 3572 Detected object count: 1
20:31:39.0009 3572 Actual detected object count: 1
20:31:50.0834 3572 C:\Windows\system32\DRIVERS\tdx.sys - copied to quarantine
20:31:50.0943 3572 Backup copy found, using it..
20:31:50.0959 3572 C:\Windows\system32\DRIVERS\tdx.sys - will be cured on reboot

Re: Prosím o log

Napsal: 14 úno 2012 20:35
od stell
Ok, este nasiel infikovany driver, Restartuj pc,

Spustiť Poznámkový blok cez Štart - Programy - Príslušenstvo a skopírujte do neho celý tento text:

Kód: Vybrat vše

@ECHO OFF
ECHO script created by: stell
%windir%\SYSTEM32\WBEM\wmic.exe diskdrive get name,size,model>>log.txt
%windir%\SYSTEM32\WBEM\wmic.exe partition get name, bootable,size,type >>log.txt
del %0
Zvoľte možnosť Súbor,uložiť súbor ako, pomenujte súbor napríklad disk.bat a zvoľte Uložiť ako typ Všetky súbory.
Uložte súbor na plochu a spustíte ho - po chvíli sa vedľa neho vytvorí textový súbor log.txt,, vloz sem

Re: Prosím o log

Napsal: 14 úno 2012 20:42
od blai
Model Name Size
WDC WD10EARS-00Y5B1 ATA Device \\.\PHYSICALDRIVE0 1000202273280
Bootable Name Size Type
TRUE Disk #0, Partition #0 104857600 Installable File System
FALSE Disk #0, Partition #1 1000097185792 Installable File System

Re: Prosím o log

Napsal: 14 úno 2012 20:44
od stell
Ok, skryty rootkit oddiel nemas, :James008:

1:Stiahnuť aswMBR.exe na plochu.
2:Dvakrát kliknite na aswMBR.exe a spusťte
3:Kliknite na tlačidlo "Scan" pre spustenie skenovania
4:V prípade infekcie Kliknite na tlačidlo "Fix"
5:Uložte asw.log na plochu.a vloz sem
http://public.avast.com/%7Egmerek/aswMBR.exe
http://public.avast.com/%7Egmerek/aswMBR.htm

Re: Prosím o log

Napsal: 14 úno 2012 21:03
od blai
Mám dva logy.
První je bez fixu a druhý je po fixu :

aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-02-14 20:49:09
-----------------------------
20:49:09.015 OS Version: Windows 6.1.7601 Service Pack 1
20:49:09.015 Number of processors: 2 586 0x602
20:49:09.015 ComputerName: KROTIL-PC UserName: Krotil
20:49:10.185 Initialize success
20:51:12.073 AVAST engine defs: 12021401
20:51:23.788 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:51:23.788 Disk 0 Vendor: WDC_WD10EARS-00Y5B1 80.00A80 Size: 953869MB BusType: 3
20:51:23.804 Disk 0 MBR read successfully
20:51:23.819 Disk 0 MBR scan
20:51:23.819 Disk 0 Windows 7 default MBR code
20:51:23.819 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:51:23.819 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
20:51:23.835 Disk 0 scanning sectors +1953521664
20:51:23.882 Disk 0 scanning C:\Windows\system32\drivers
20:51:27.298 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Sirefef-JQ [Trj]
20:51:35.847 Disk 0 trace - called modules:
20:51:35.863 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x9f203fc0]<<
20:51:35.863 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863251e8]
20:51:35.863 3 CLASSPNP.SYS[8bf9f59e] -> nt!IofCallDriver -> [0x86cbf908]
20:51:35.878 \Driver\00001290[0x87d9f9e0] -> IRP_MJ_CREATE -> 0x9f203fc0
20:51:37.891 AVAST engine scan C:\Windows
20:51:41.900 AVAST engine scan C:\Windows\system32
20:53:52.269 AVAST engine scan C:\Windows\system32\drivers
20:53:55.826 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Sirefef-JQ [Trj]
20:54:06.824 AVAST engine scan C:\Users\Krotil
20:56:48.877 Disk 0 MBR has been saved successfully to "C:\Users\Krotil\Desktop\MBR.dat"
20:56:48.877 The log file has been saved successfully to "C:\Users\Krotil\Desktop\aswMBR.txt"


-----------------------------------------------------------


aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-02-14 20:49:09
-----------------------------
20:49:09.015 OS Version: Windows 6.1.7601 Service Pack 1
20:49:09.015 Number of processors: 2 586 0x602
20:49:09.015 ComputerName: KROTIL-PC UserName: Krotil
20:49:10.185 Initialize success
20:51:12.073 AVAST engine defs: 12021401
20:51:23.788 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:51:23.788 Disk 0 Vendor: WDC_WD10EARS-00Y5B1 80.00A80 Size: 953869MB BusType: 3
20:51:23.804 Disk 0 MBR read successfully
20:51:23.819 Disk 0 MBR scan
20:51:23.819 Disk 0 Windows 7 default MBR code
20:51:23.819 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:51:23.819 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
20:51:23.835 Disk 0 scanning sectors +1953521664
20:51:23.882 Disk 0 scanning C:\Windows\system32\drivers
20:51:27.298 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Sirefef-JQ [Trj]
20:51:35.847 Disk 0 trace - called modules:
20:51:35.863 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x9f203fc0]<<
20:51:35.863 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863251e8]
20:51:35.863 3 CLASSPNP.SYS[8bf9f59e] -> nt!IofCallDriver -> [0x86cbf908]
20:51:35.878 \Driver\00001290[0x87d9f9e0] -> IRP_MJ_CREATE -> 0x9f203fc0
20:51:37.891 AVAST engine scan C:\Windows
20:51:41.900 AVAST engine scan C:\Windows\system32
20:53:52.269 AVAST engine scan C:\Windows\system32\drivers
20:53:55.826 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Sirefef-JQ [Trj]
20:54:06.824 AVAST engine scan C:\Users\Krotil
20:56:48.877 Disk 0 MBR has been saved successfully to "C:\Users\Krotil\Desktop\MBR.dat"
20:56:48.877 The log file has been saved successfully to "C:\Users\Krotil\Desktop\aswMBR.txt"
20:57:36.186 Verifying
20:57:46.232 Disk 0 Windows 601 MBR fixed successfully
20:57:55.552 Verifying
20:58:05.583 Disk 0 Windows 601 MBR fixed successfully
20:58:34.271 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\cdrom.sys.vir **INFECTED** Win32:Sirefef-JQ [Trj]
20:58:34.318 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\cdrom.sys.vir_ **INFECTED** Win32:Sirefef-JQ [Trj]
20:58:34.396 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\csc.sys.vir **INFECTED** Win32:Smadow [Rtk]
20:58:34.443 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\csc.sys.vir_ **INFECTED** Win32:Smadow [Rtk]
20:58:34.505 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\dfsc.sys.vir_ **INFECTED** Win32:Sirefef-JQ [Trj]
20:58:34.645 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\netbt.sys.vir_ **INFECTED** Win32:Sirefef-JQ [Trj]
20:58:34.708 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\serial.sys.vir **INFECTED** Win32:Sirefef-JQ [Trj]
20:58:34.755 File: C:\Users\Krotil\Desktop\Qoobox\Quarantine\C\Windows\system32\Drivers\serial.sys.vir_ **INFECTED** Win32:Sirefef-JQ [Trj]
21:01:51.284 Disk 0 MBR has been saved successfully to "C:\Users\Krotil\Desktop\MBR.dat"
21:01:51.299 The log file has been saved successfully to "C:\Users\Krotil\Desktop\aswMBR2.txt"

Re: Prosím o log

Napsal: 14 úno 2012 21:07
od stell
Pri tejto akcii je nutné mať ComboFix na ploche.

Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:

Kód: Vybrat vše

KILLALL::
RESTORE::
C:\Windows\system32\drivers\afd.sys
ClearJavaCache::
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :
Obrázek

Po skonceni skenu vlož log