Stránka 1 z 2

Podivne chování

Napsal: 21 led 2013 14:29
od miromen
Nejsem si jisty zda jde o nakaženi ale pozoruji zpomaleny internet a jiste zaseky. Konkretně vypadky Wifi po připojeni ex.HDD, zadrhavani ukazatele při psani přispěvku do ruznych for. Taky nevim jestli to neni tim že jsem nedavno přešel z IE8 na IE9.
Takže bych rad poprosil o kontrolu....

Logfile of random's system information tool 1.09 (written by random/random)
Run by Miromen at 2013-01-21 14:23:12
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 14 GB (8%) free of 183 GB
Total RAM: 3956 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:23:12, on 21.1.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Miromen\Desktop\RSIT.exe
C:\Program Files\trend micro\Miromen.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: W2PBrowser Browser Helper - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-21-1604290871-1745575891-3147878822-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1604290871-1745575891-3147878822-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2044D22-CA22-4DAD-80D3-6D56F41F1E20}: NameServer = 62.129.50.20,85.135.32.100
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Samsung UPD Service - Unknown owner - C:\Windows\System32\SUPDSvc.exe (file missing)
O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SimpleSlideShowServer - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Intel(R) Turbo Boost Technology Monitor (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10544 bytes

======Scheduled tasks folder======

C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1604290871-1745575891-3147878822-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1604290871-1745575891-3147878822-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-06-04 425680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-05-07 453064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA609D72-8482-4076-8991-8CDAE5B93BCB}]
W2PBrowser Class - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-08-23 1236992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-12-13 4527888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-05-07 157640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2012-12-04 773728]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{340BE65B-7621-4B0B-B0F9-DBCCD8D70887}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"vidc.mjpg"=pvmjpg30.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-01-21 14:21:00 ----D---- C:\rsit
2013-01-21 14:20:34 ----SHD---- C:\$RECYCLE.BIN
2013-01-21 13:50:59 ----D---- C:\Windows\temp
2013-01-21 13:50:58 ----A---- C:\ComboFix.txt
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\wininet.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\wextract.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\webcheck.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\vbscript.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\urlmon.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\url.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\pngfilt.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\occache.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\msrating.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\msls31.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\mshtmler.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\mshtml.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\mshta.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\jscript9.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\jscript.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\inseng.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\imgutil.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iexpress.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieui.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iesetup.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iertutil.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iernonce.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iepeers.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieframe.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieapfltr.dat
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieakui.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieaksie.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ieakeng.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\IEAdvpack.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\ie4uinit.exe
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\icardie.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2013-01-19 19:01:17 ----A---- C:\Windows\SysWOW64\admparse.dll
2013-01-18 17:04:37 ----D---- C:\Program Files (x86)\SpeedFan
2013-01-18 16:52:42 ----A---- C:\Windows\Language_trs.ini
2013-01-13 11:08:51 ----D---- C:\Program Files (x86)\MyFree Codec
2013-01-12 16:41:41 ----D---- C:\Download
2013-01-12 16:40:10 ----D---- C:\AllShare
2013-01-12 13:51:12 ----A---- C:\Windows\SysWOW64\drivers\PCASp50a64.sys
2013-01-12 13:51:12 ----A---- C:\Windows\SysWOW64\drivers\PCASp50.sys
2013-01-12 13:51:12 ----A---- C:\Windows\SysWOW64\ASIW32N50.dll
2013-01-12 13:51:12 ----A---- C:\Windows\SysWOW64\ASINDIS5.sys
2013-01-12 13:51:07 ----D---- C:\Program Files (x86)\ASUS
2013-01-12 12:36:59 ----RA---- C:\Windows\SysWOW64\drivers\PcaSp60.sys
2013-01-12 00:19:48 ----D---- C:\ProgramData\Codemasters
2013-01-12 00:18:15 ----A---- C:\Windows\SysWOW64\XAudio2_7.dll
2013-01-12 00:18:15 ----A---- C:\Windows\SysWOW64\XAPOFX1_5.dll
2013-01-12 00:18:14 ----A---- C:\Windows\SysWOW64\xactengine3_7.dll
2013-01-12 00:18:13 ----A---- C:\Windows\SysWOW64\d3dcsx_43.dll
2013-01-12 00:18:12 ----A---- C:\Windows\SysWOW64\d3dx11_43.dll
2013-01-12 00:18:09 ----A---- C:\Windows\SysWOW64\D3DX9_43.dll
2013-01-12 00:18:08 ----A---- C:\Windows\SysWOW64\xinput1_3.dll
2013-01-12 00:02:42 ----D---- C:\Program Files (x86)\F1 2012
2013-01-11 15:34:45 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-01-09 09:04:52 ----A---- C:\Windows\SysWOW64\win32spl.dll
2013-01-09 09:04:45 ----A---- C:\Windows\SysWOW64\msxml6.dll
2013-01-09 09:04:44 ----A---- C:\Windows\SysWOW64\msxml3.dll
2013-01-09 09:04:43 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2013-01-09 09:04:41 ----A---- C:\Windows\SysWOW64\usp10.dll
2013-01-09 09:04:37 ----A---- C:\Windows\SysWOW64\gameux.dll
2013-01-09 09:04:36 ----A---- C:\Windows\SysWOW64\Wpc.dll
2013-01-09 09:04:20 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2013-01-09 09:04:20 ----A---- C:\Windows\SysWOW64\kernel32.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 09:04:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 09:04:19 ----A---- C:\Windows\SysWOW64\wow32.dll
2013-01-09 09:04:19 ----A---- C:\Windows\SysWOW64\user.exe
2013-01-09 09:04:19 ----A---- C:\Windows\SysWOW64\setup16.exe
2013-01-09 09:04:19 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2013-01-09 09:04:19 ----A---- C:\Windows\SysWOW64\instnm.exe
2013-01-08 00:09:31 ----D---- C:\Windows\SysWOW64\directx
2013-01-08 00:09:06 ----D---- C:\Program Files (x86)\MSI Afterburner
2013-01-06 23:08:57 ----D---- C:\Program Files (x86)\AGEIA Technologies
2013-01-06 23:08:18 ----D---- C:\ProgramData\NVIDIA
2013-01-06 23:07:31 ----A---- C:\Windows\SysWOW64\OpenCL.dll
2013-01-06 23:07:18 ----D---- C:\ProgramData\NVIDIA Corporation
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvwgf2um.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvopencl.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvoglv32.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvd3dum.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvcuvid.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvcuvenc.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvcuda.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvcompiler.dll
2013-01-06 23:05:37 ----A---- C:\Windows\SysWOW64\nvapi.dll
2013-01-03 14:07:29 ----D---- C:\ProgramData\Futuremark
2013-01-03 14:01:44 ----D---- C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-01-03 14:01:35 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-01-03 14:01:17 ----A---- C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-01-03 14:01:16 ----A---- C:\Windows\SysWOW64\d3dx10_43.dll
2012-12-23 03:18:44 ----A---- C:\Windows\cmm.dat

======List of files/folders modified in the last 1 month======

2013-01-21 14:17:17 ----RD---- C:\Program Files
2013-01-21 13:51:00 ----D---- C:\Qoobox
2013-01-21 13:50:59 ----D---- C:\Windows
2013-01-21 13:48:35 ----A---- C:\Windows\system.ini
2013-01-21 13:46:14 ----D---- C:\Windows\SysWOW64
2013-01-21 13:44:21 ----D---- C:\Windows\SysWOW64\drivers
2013-01-21 13:44:21 ----D---- C:\Windows\AppPatch
2013-01-21 13:44:21 ----D---- C:\Program Files (x86)\Common Files
2013-01-21 13:40:04 ----D---- C:\Windows\Prefetch
2013-01-21 13:29:56 ----D---- C:\Windows\System32
2013-01-21 13:29:56 ----D---- C:\Windows\inf
2013-01-21 12:19:55 ----D---- C:\Users\Miromen\AppData\Roaming\Skype
2013-01-21 08:01:40 ----A---- C:\Windows\SysWOW64\log.txt
2013-01-20 21:04:13 ----RD---- C:\Program Files (x86)
2013-01-20 09:50:25 ----D---- C:\Program Files (x86)\The KMPlayer
2013-01-20 09:50:12 ----D---- C:\Users\Miromen\AppData\Roaming\uTorrent
2013-01-20 09:20:05 ----SHD---- C:\System Volume Information
2013-01-20 09:18:57 ----D---- C:\Users\Miromen\AppData\Roaming\Winamp
2013-01-20 09:18:57 ----D---- C:\Users\Miromen\AppData\Roaming\DAEMON Tools Pro
2013-01-20 09:18:55 ----D---- C:\Windows\Panther
2013-01-20 09:18:55 ----D---- C:\Windows\Logs
2013-01-20 09:18:55 ----D---- C:\Windows\debug
2013-01-20 08:34:59 ----SHD---- C:\Windows\Installer
2013-01-20 00:16:55 ----D---- C:\Windows\rescache
2013-01-19 19:19:35 ----D---- C:\Windows\winsxs
2013-01-19 19:03:38 ----D---- C:\Windows\SysWOW64\cs-CZ
2013-01-19 19:03:38 ----D---- C:\Program Files (x86)\Internet Explorer
2013-01-19 19:03:37 ----D---- C:\Windows\SysWOW64\migration
2013-01-19 19:03:37 ----D---- C:\Windows\SysWOW64\en-US
2013-01-19 19:03:36 ----D---- C:\Windows\PolicyDefinitions
2013-01-18 16:53:23 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2013-01-18 16:53:21 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-01-14 10:54:49 ----D---- C:\Windows\Tasks
2013-01-14 10:54:38 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-01-13 12:26:32 ----D---- C:\Windows\Microsoft.NET
2013-01-13 09:10:46 ----D---- C:\video_output
2013-01-13 09:03:33 ----D---- C:\ProgramData
2013-01-13 08:53:33 ----D---- C:\Program Files (x86)\uTorrent
2013-01-13 08:41:07 ----D---- C:\Users\Miromen\AppData\Roaming\CyberLink
2013-01-12 18:00:58 ----D---- C:\Users\Miromen\AppData\Roaming\Samsung
2013-01-12 18:00:01 ----D---- C:\Program Files (x86)\Samsung
2013-01-12 16:34:14 ----D---- C:\AllShare Play
2013-01-12 12:00:26 ----SD---- C:\Users\Miromen\AppData\Roaming\Microsoft
2013-01-09 18:18:08 ----RSD---- C:\Windows\assembly
2013-01-06 23:08:57 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-01-06 23:08:38 ----RD---- C:\Users
2013-01-05 08:52:18 ----D---- C:\Users\Miromen\AppData\Roaming\Vso
2013-01-03 14:43:32 ----D---- C:\Users\Miromen\AppData\Roaming\NVIDIA

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R1 SABI;SAMSUNG Kernel Driver For Windows 7; \??\C:\Windows\system32\Drivers\SABI.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys []
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys []
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys []
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys []
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys []
R3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys []
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys []
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys []
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys []
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys []
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys []
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys []
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys []
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys []
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys []
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys []
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S2 ASInsHelp;ASInsHelp; \??\C:\Windows\SysWow64\drivers\AsInsHelp64.sys []
S3 aaxif5iq;aaxif5iq; C:\Windows\SysWOW64\drivers\aaxif5iq.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys []
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys []
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys []
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys []
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys []
S3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver; C:\Windows\system32\DRIVERS\PcaSp60.sys [2010-09-07 38912]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys []
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys []
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-07-21 951584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-02-03 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-12-29 1260472]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-07-07 247152]
R2 SamsungAllShareV2.0;Samsung AllShare PC; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-02-03 2320920]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-10 116648]
S2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-04-28 704872]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe [2010-06-03 246520]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-10 116648]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Samsung UPD Service;Samsung UPD Service; C:\Windows\System32\SUPDSvc.exe []
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []

-----------------EOF-----------------

Re: Podivne chování

Napsal: 21 led 2013 16:35
od miromen
Ja se omlouvam a tve připominky beru na vědoni. Neměl jsem tušeni co muže CF zpusobit a je to pro mě nova informace.
Je tedy ještě nějaka možnost o napraveni me chyby a pokus o nějakou kontrolu ?
Log z CF mam jestli by to tedy pomohlo...

Re: Podivne chování

Napsal: 21 led 2013 17:16
od miromen
Diky
Nejsem si uplně jisty za byl HDD při spuštěnem CB zapojen ale s největši pravděpodobnosti ano. Pořad mi vrta hlavou proč se po jeho zasunuti někdy deaktivuje Wifi a někdy ne takže proto jsi nejsem uplně jisty zda v danou chvili zapojen byl.
Jinak mě asi opět zdrbeš protože jsem ze zoufalstvi odinstaloval aktualizaci IE9 a zda se že problem na forech přestal. Ale ještě to nemam na 100% odzkoušene a navic je(byl) tento problem docela podivny.

Combo Fix...

ComboFix 13-01-21.01 - Miromen 21.01.2013 13:40:03.5.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3956.2555 [GMT 1:00]
Spuštěný z: c:\users\Miromen\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-21 do 2013-01-21 )))))))))))))))))))))))))))))))
.
.
2013-01-21 12:46 . 2013-01-21 12:46 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-01-21 12:46 . 2013-01-21 12:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-20 18:01 . 2013-01-20 18:01 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85DF9CE0-F647-4A7A-9865-70C6AE0FC7ED}\offreg.dll
2013-01-20 09:03 . 2013-01-20 09:03 -------- d-----w- c:\users\Miromen\AppData\Local\ElevatedDiagnostics
2013-01-18 16:04 . 2013-01-20 20:03 -------- d-----w- c:\program files (x86)\SpeedFan
2013-01-18 07:20 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85DF9CE0-F647-4A7A-9865-70C6AE0FC7ED}\mpengine.dll
2013-01-13 10:08 . 2013-01-13 10:08 -------- d-----w- c:\program files (x86)\MyFree Codec
2013-01-12 15:41 . 2013-01-12 15:41 -------- d-----w- C:\Download
2013-01-12 15:40 . 2013-01-12 15:40 -------- d-----w- C:\AllShare
2013-01-12 12:51 . 2006-11-28 20:46 52800 ----a-w- c:\windows\SysWow64\drivers\PCASp50.sys
2013-01-12 12:51 . 2006-11-28 20:46 41280 ----a-w- c:\windows\SysWow64\drivers\PCASp50a64.sys
2013-01-12 12:51 . 2003-04-21 20:46 61440 ----a-w- c:\windows\SysWow64\ASIW32N50.dll
2013-01-12 12:51 . 2002-09-10 18:35 16302 ----a-w- c:\windows\SysWow64\ASINDIS5.sys
2013-01-12 12:51 . 2001-04-16 04:48 15577 ----a-w- c:\windows\SysWow64\ASINDIS3.vxd
2013-01-12 12:51 . 2013-01-18 15:53 -------- d-----w- c:\program files (x86)\ASUS
2013-01-12 11:37 . 2010-09-07 06:27 38912 ----a-r- c:\windows\system32\drivers\PcaSp60.sys
2013-01-12 11:36 . 2010-09-07 06:27 38912 ----a-r- c:\windows\SysWow64\drivers\PcaSp60.sys
2013-01-11 23:19 . 2013-01-11 23:19 -------- d-----w- c:\users\Miromen\AppData\Local\FLT
2013-01-11 23:19 . 2013-01-11 23:19 -------- d-----w- c:\programdata\Codemasters
2013-01-11 23:18 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2013-01-11 23:18 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2013-01-11 23:18 . 2010-06-02 03:55 239960 ----a-w- c:\windows\SysWow64\xactengine3_7.dll
2013-01-11 23:18 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2013-01-11 23:18 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-01-11 23:18 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-01-11 23:18 . 2007-04-04 17:53 81768 ----a-w- c:\windows\SysWow64\xinput1_3.dll
2013-01-11 23:02 . 2013-01-11 23:16 -------- d-----w- c:\program files (x86)\F1 2012
2013-01-11 08:56 . 2013-01-20 20:04 -------- d-----w- c:\program files\CPUID
2013-01-07 23:09 . 2013-01-11 23:59 -------- d-----w- c:\program files (x86)\MSI Afterburner
2013-01-06 22:08 . 2013-01-06 22:08 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-01-06 22:08 . 2013-01-12 16:46 -------- d-----w- c:\users\UpdatusUser
2013-01-06 22:08 . 2013-01-06 22:08 -------- d-----w- c:\programdata\NVIDIA
2013-01-06 22:08 . 2012-12-29 08:40 6382008 ----a-w- c:\windows\system32\nvcpl.dll
2013-01-06 22:08 . 2012-12-29 08:40 3455416 ----a-w- c:\windows\system32\nvsvc64.dll
2013-01-06 22:08 . 2012-12-29 08:40 884152 ----a-w- c:\windows\system32\nvvsvc.exe
2013-01-06 22:08 . 2012-12-29 08:40 63928 ----a-w- c:\windows\system32\nvshext.dll
2013-01-06 22:08 . 2012-12-29 08:40 2558392 ----a-w- c:\windows\system32\nvsvcr.dll
2013-01-06 22:08 . 2012-12-29 08:40 118712 ----a-w- c:\windows\system32\nvmctray.dll
2013-01-06 22:07 . 2012-12-29 10:34 61368 ----a-w- c:\windows\system32\OpenCL.dll
2013-01-06 22:07 . 2012-12-29 10:34 53176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-01-06 22:07 . 2013-01-06 22:07 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-01-03 13:07 . 2013-01-03 13:07 -------- d-----w- c:\programdata\Futuremark
2013-01-03 13:01 . 2013-01-03 13:01 -------- d-----w- c:\windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-01-03 13:01 . 2013-01-03 13:01 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-01-03 13:01 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-01-03 13:01 . 2010-05-26 10:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-14 09:54 . 2012-03-29 07:36 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-14 09:54 . 2012-03-29 07:36 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-09 09:48 . 2012-04-11 09:22 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-16 17:11 . 2012-12-21 19:29 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-21 19:29 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 19:29 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-21 19:29 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-11-30 04:45 . 2013-01-09 08:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-11-09 05:45 . 2012-12-12 02:18 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-09 04:42 . 2012-12-12 02:18 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-02 05:59 . 2012-12-12 02:17 478208 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 05:11 . 2012-12-12 02:17 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2012-10-31 19:09 . 2012-10-31 19:09 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2012-10-31 19:09 . 2012-10-31 19:09 82816 ----a-w- c:\users\Miromen\AppData\Roaming\pcouffin.sys
2012-10-25 14:33 . 2012-11-20 00:30 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2012-10-25 14:33 . 2012-11-20 00:30 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2012-10-25 14:32 . 2012-11-20 00:30 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2012-10-25 14:28 . 2012-11-20 00:30 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2012-10-25 14:27 . 2012-11-20 00:30 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2012-10-25 14:27 . 2012-11-20 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2012-10-25 14:27 . 2012-11-20 00:30 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2012-10-25 14:27 . 2012-11-20 00:30 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2012-10-25 14:27 . 2012-11-20 00:30 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2012-10-25 13:59 . 2012-11-20 00:30 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2012-10-25 13:59 . 2012-11-20 00:30 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2012-10-25 13:58 . 2012-11-20 00:30 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2012-10-25 13:55 . 2012-11-20 00:30 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2012-10-25 13:45 . 2012-11-20 00:30 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-10-25 13:36 . 2012-11-20 00:30 1885696 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2012-10-25 13:35 . 2012-11-20 00:30 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2012-10-25 13:23 . 2012-11-20 00:30 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2012-10-25 13:23 . 2012-11-20 00:30 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2012-10-25 13:23 . 2012-11-20 00:30 1504768 ----a-w- c:\windows\SysWow64\d3d11.dll
2012-10-25 13:22 . 2012-11-20 00:30 1643008 ----a-w- c:\windows\system32\DWrite.dll
2012-10-25 13:21 . 2012-11-20 00:30 1175552 ----a-w- c:\windows\system32\FntCache.dll
2012-10-25 13:14 . 2012-11-20 00:30 2434560 ----a-w- c:\windows\system32\d3d10warp.dll
2012-10-25 13:12 . 2012-11-20 00:30 363008 ----a-w- c:\windows\system32\dxgi.dll
2012-10-25 13:08 . 2012-11-20 00:30 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2012-10-25 13:08 . 2012-11-20 00:30 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2012-10-25 13:07 . 2012-11-20 00:30 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2012-10-25 13:02 . 2012-11-20 00:30 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2012-10-25 13:01 . 2012-11-20 00:30 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-10-25 13:01 . 2012-11-20 00:30 1887232 ----a-w- c:\windows\system32\d3d11.dll
2012-10-25 13:01 . 2012-11-20 00:30 296960 ----a-w- c:\windows\system32\d3d10core.dll
2012-10-25 13:00 . 2012-11-20 00:30 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2012-10-25 12:56 . 2012-11-20 00:30 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2012-10-25 12:50 . 2012-11-20 00:30 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2012-10-25 12:47 . 2012-11-20 00:30 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-10-25 12:47 . 2012-11-20 00:30 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2012-10-25 12:47 . 2012-11-20 00:30 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2012-10-25 12:43 . 2012-11-20 00:30 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2012-10-25 12:42 . 2012-11-20 00:30 1238528 ----a-w- c:\windows\system32\d3d10.dll
2012-10-25 12:38 . 2012-11-20 00:30 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-10-25 12:32 . 2012-11-20 00:30 3928064 ----a-w- c:\windows\system32\d2d1.dll
2012-10-25 12:15 . 2012-11-20 00:30 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2012-10-25 11:54 . 2012-11-20 00:30 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2012-10-25 11:48 . 2012-11-20 00:30 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2012-10-25 11:30 . 2012-11-20 00:30 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-10-25 10:40 . 2012-11-20 00:30 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2012-10-25 10:23 . 2012-11-20 00:30 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-21 1132320]
SRS Premium Sound.lnk - c:\windows\Installer\{340BE65B-7621-4B0B-B0F9-DBCCD8D70887}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-8-31 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2012-06-11 12800]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2012-06-11 171008]
R3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver;c:\windows\system32\DRIVERS\PcaSp60.sys [2010-09-07 38912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe [2010-08-09 166704]
R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-22 1255736]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 13824]
S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-04-16 13832]
S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-02-03 2320920]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-07-13 344616]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 39464]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2012-04-25 258896]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2012-10-31 82816]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-07-08 401696]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604290871-1745575891-3147878822-1000Core.job
- c:\users\Miromen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-08 18:01]
.
2012-05-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604290871-1745575891-3147878822-1000UA.job
- c:\users\Miromen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-08 18:01]
.
2013-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-10 11:12]
.
2013-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-10 11:12]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-08-04 11106408]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mStart Page = hxxp://samsung.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: Interfaces\{A707A0BB-6629-4D6B-AE33-CD968F76E9AC}\D49425F4D454E4: DhcpNameServer = 62.129.50.20 85.135.32.100
TCP: Interfaces\{A707A0BB-6629-4D6B-AE33-CD968F76E9AC}\D69627F6D656E6: DhcpNameServer = 62.129.50.20 85.135.32.100
TCP: Interfaces\{F2044D22-CA22-4DAD-80D3-6D56F41F1E20}: NameServer = 62.129.50.20,85.135.32.100
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-01-21 13:50:58
ComboFix-quarantined-files.txt 2013-01-21 12:50
ComboFix2.txt 2013-01-06 09:29
ComboFix3.txt 2012-11-15 09:41
.
Před spuštěním: Volných bajtů: 14 050 693 120
Po spuštění: Volných bajtů: 14 475 706 368
.
- - End Of File - - D7867EF521C43D229B8D7C84DAAB8946

Re: Podivne chování

Napsal: 21 led 2013 17:17
od miromen
GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-21 17:16:55
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB
Running: gmer.exe; Driver: C:\Users\Miromen\AppData\Local\Temp\awdiifog.sys


---- Kernel code sections - GMER 2.0 ----

.text C:\Windows\system32\drivers\USBPORT.SYS!DllUnload fffff88000c28d64 12 bytes {MOV RAX, 0xfffffa8006a002a0; JMP RAX}

---- User code sections - GMER 2.0 ----

.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[3760] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[3336] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076838a29 5 bytes JMP 000000016ae138a4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 000000007685cbf3 5 bytes JMP 000000016af4ff58
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007685cfca 5 bytes JMP 000000016ad47f51
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 000000007687cb0c 5 bytes JMP 000000016af4fef5
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 000000007687ce64 5 bytes JMP 000000016af4ffbe
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 000000007688fbd1 5 bytes JMP 000000016af4fe8a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 000000007688fc9d 5 bytes JMP 000000016af4fe1f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!MessageBoxExA 000000007688fcd6 5 bytes JMP 000000016af4fdbd
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\USER32.dll!MessageBoxExW 000000007688fcfa 5 bytes JMP 000000016af4fd5b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000074e993ec 5 bytes JMP 000000016af50ab2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW 000000007185388e 5 bytes JMP 000000016af514fa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet 00000000718f7922 5 bytes JMP 000000016af5159b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[3380] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000074d72694 5 bytes JMP 000000016af50cab
? C:\Windows\system32\mssprxy.dll [3380] entry point in ".rdata" section 0000000074a871e6
? C:\Windows\System32\NLSData0000.dll [3380] entry point in ".rdata" section 0000000060e1c541
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076838a29 5 bytes JMP 000000016ae138a4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076846285 5 bytes JMP 000000016ad83ca7
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076847603 5 bytes JMP 000000016add7de1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 000000007685cbf3 5 bytes JMP 000000016af4ff58
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007685cfca 5 bytes JMP 000000016ad47f51
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 000000007685f52b 5 bytes JMP 000000016ae3d937
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 000000007687cb0c 5 bytes JMP 000000016af4fef5
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 000000007687ce64 5 bytes JMP 000000016af4ffbe
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 000000007688fbd1 5 bytes JMP 000000016af4fe8a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 000000007688fc9d 5 bytes JMP 000000016af4fe1f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!MessageBoxExA 000000007688fcd6 5 bytes JMP 000000016af4fdbd
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\USER32.dll!MessageBoxExW 000000007688fcfa 5 bytes JMP 000000016af4fd5b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000074ec6143 5 bytes JMP 000000016af502ae
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074f09d0b 5 bytes JMP 000000016ae13432
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000074e33e59 5 bytes JMP 000000016ae2d8cb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000074e33eae 5 bytes JMP 000000016ae2e3d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000074e34731 5 bytes JMP 000000016af50eab
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000074e35dee 5 bytes JMP 000000016af50ef6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000074e993ec 5 bytes JMP 000000016af50ab2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW 000000007185388e 5 bytes JMP 000000016af514fa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet 00000000718f7922 5 bytes JMP 000000016af5159b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4680] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000074d72694 5 bytes JMP 000000016af50cab
? C:\Windows\system32\mssprxy.dll [4680] entry point in ".rdata" section 0000000074a871e6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076838a29 5 bytes JMP 000000016ae138a4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076846285 5 bytes JMP 000000016ad83ca7
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076847603 5 bytes JMP 000000016add7de1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 000000007685cbf3 5 bytes JMP 000000016af4ff58
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007685cfca 5 bytes JMP 000000016ad47f51
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 000000007685f52b 5 bytes JMP 000000016ae3d937
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 000000007687cb0c 5 bytes JMP 000000016af4fef5
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 000000007687ce64 5 bytes JMP 000000016af4ffbe
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 000000007688fbd1 5 bytes JMP 000000016af4fe8a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 000000007688fc9d 5 bytes JMP 000000016af4fe1f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!MessageBoxExA 000000007688fcd6 5 bytes JMP 000000016af4fdbd
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\USER32.dll!MessageBoxExW 000000007688fcfa 5 bytes JMP 000000016af4fd5b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000074ec6143 5 bytes JMP 000000016af502ae
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074f09d0b 5 bytes JMP 000000016ae13432
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000074e33e59 5 bytes JMP 000000016ae2d8cb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000074e33eae 5 bytes JMP 000000016ae2e3d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000074e34731 5 bytes JMP 000000016af50eab
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000074e35dee 5 bytes JMP 000000016af50ef6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000074e993ec 5 bytes JMP 000000016af50ab2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheetW 000000007185388e 5 bytes JMP 000000016af514fa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll!PropertySheet 00000000718f7922 5 bytes JMP 000000016af5159b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[4608] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000074d72694 5 bytes JMP 000000016af50cab
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074bb1401 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074bb1419 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074bb1431 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074bb144a 2 bytes [BB, 74]
.text ... * 9
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074bb14dd 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074bb14f5 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074bb150d 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074bb1525 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074bb153d 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074bb1555 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074bb156d 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074bb1585 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074bb159d 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074bb15b5 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074bb15cd 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074bb16b2 2 bytes [BB, 74]
.text C:\Users\Miromen\Desktop\gmer.exe[4132] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074bb16bd 2 bytes [BB, 74]

---- Devices - GMER 2.0 ----

Device \Driver\aa8186o3 \Device\Scsi\aa8186o31
Device \Driver\aa8186o3 \Device\Scsi\aa8186o31Port1Path0Target0Lun0
Device \FileSystem\Ntfs \Ntfs
Device \Driver\usbehci \Device\USBPDO-1 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\cdrom \Device\CdRom0 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\cdrom \Device\CdRom1 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\USBSTOR \Device\000000c0 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\usbehci \Device\USBFDO-0 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{A707A0BB-6629-4D6B-AE33-CD968F76E9AC} ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{2CC791F8-BE83-4642-A510-388285BAC7B4} ws\system32\DRIVERS\kbdclass.sys
Device \Driver\USBSTOR \Device\000000bf ws\system32\DRIVERS\kbdclass.sys
Device \Driver\usbehci \Device\USBFDO-1 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export ws\system32\DRIVERS\kbdclass.sys
Device \Driver\usbehci \Device\USBPDO-0
Device \Driver\aa8186o3 \Device\ScsiPort1
Device \Driver\NetBT \Device\NetBT_Tcpip_{F2044D22-CA22-4DAD-80D3-6D56F41F1E20}
Device \Driver\NetBT \Device\NetBT_Tcpip_{40F13BF3-DF8B-4F95-A74A-5486F7241429}

---- Modules - GMER 2.0 ----

Module \SystemRoot\System32\Drivers\aa8186o3.SYS fffff8800302e000-fffff8800307f000 (331776 bytes)

---- Threads - GMER 2.0 ----

Thread C:\Windows\System32\svchost.exe [1496:2700] 000007fef6b49688
Thread C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [4308:4392] 00000000735827e1
---- Processes - GMER 2.0 ----

Library ? (*** suspicious ***) @ C:\Windows\System32\svchost.exe [1496] 000007fefc7b0000
Library ? (*** suspicious ***) @ C:\Program Files\Windows Media Player\wmpnetwk.exe [3936] 000007feeeff0000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [4308] 00000000752b0000

---- Registry - GMER 2.0 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4cedde071692
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4cedde071692@18e2c27e19db 0x41 0xDD 0xEF 0x46 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4cedde071692@38ece44733b5 0xF9 0xD8 0x62 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 6586
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xBB 0xDD 0x05 0x1C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD2 0x05 0x14 0xAD ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC8 0xF1 0xB1 0xE7 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xEC 0xD6 0x88 0x1D ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4cedde071692 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4cedde071692@18e2c27e19db 0x41 0xDD 0xEF 0x46 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4cedde071692@38ece44733b5 0xF9 0xD8 0x62 0x54 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xBB 0xDD 0x05 0x1C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD2 0x05 0x14 0xAD ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC8 0xF1 0xB1 0xE7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xEC 0xD6 0x88 0x1D ...

---- Disk sectors - GMER 2.0 ----

Disk \Device\Harddisk0\DR0 unknown MBR code

---- EOF - GMER 2.0 ----

Re: Podivne chování

Napsal: 21 led 2013 18:22
od miromen
Tak na nějakych strankach se na IE8 vyskytuji chyby a taky vyskakuji hlašky o zastaralosti. Z toho duvodu jsem šel do IE9 ktera jak jsem se dočetl opravdu odstraňuje některe obtiže a je tedy vhodne ji nainstalovat.....

Zatim odinstalovan Daemon a aktualizovan SPTD.

Otestovano a zda se byt v pořadku...
system32\DRIVERS\kbdclass.sys

https://www.virustotal.com/file/450c5ba ... /analysis/

Re: Podivne chování

Napsal: 21 led 2013 18:28
od miromen
MbrScan

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows 7 Service Pack 1 (64 bit)
PROCESSOR      : Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
BOOT           : Normal Boot
DATE           : 2013/01/21 (ISO 8601) at 18:26:40
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __WDC WD50 00BEVT-35A0R (01.0)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : NO
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

DISK           : Device\Harddisk1\DR1 __ADATA NH13 (AX00)
BUS_TYPE       : (0x07)  USB
USE_PIO        : NO
MAX_TRANSFER   : 64 Kb
ALIGNMENT_MASK : byte aligned
________________________________________________________________________________

Device\Harddisk0\DR0	465.8 Go  [Fixed] ==> Mebratix.B MBR Code

MBR_MD5   : CCD749E26FA83B646C7CFF899473A2B1
MBR_SHA1  : 016071775E7EDABD95877E6614493F4B0F44DCC8

Device\Harddisk0\Partition1	100.0 Mo  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	179.0 Go  	0x07 NTFS / HPFS
Device\Harddisk0\Partition3	19.02 Go  	0x27 RE Hidden partition 
Device\Harddisk0\Partition4	267.6 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

Device\Harddisk1\DR1	698.6 Go  [Fixed] ==> XP MBR Code ....

MBR_MD5   : 7D05209E09D1C32EDA201B767B3A153D
MBR_SHA1  : 8290043E4C5FA8FF5C624FF822EAFE38AAC73B53

Device\Harddisk1\Partition1	698.6 Go  	0x07 NTFS / HPFS __ BOOTABLE __
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\Windows\system32\hal.dll => Invisible on the disk
ADDRESS : 0x03607000
SIZE    : 292.0 Ko

DRIVER  : C:\Windows\system32\kdcom.dll => Invisible on the disk
ADDRESS : 0x00BB0000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\mcupdate_GenuineIntel.dll => Invisible on the disk
ADDRESS : 0x00C8B000
SIZE    : 316.0 Ko

DRIVER  : C:\Windows\system32\CLFS.SYS => Invisible on the disk
ADDRESS : 0x00CEE000
SIZE    : 376.0 Ko

DRIVER  : C:\Windows\system32\CI.dll => Invisible on the disk
ADDRESS : 0x00EAD000
SIZE    : 768.0 Ko

DRIVER  : C:\Windows\system32\drivers\Wdf01000.sys => Invisible on the disk
ADDRESS : 0x010AB000
SIZE    : 776.0 Ko

DRIVER  : C:\Windows\system32\drivers\WDFLDR.SYS => Invisible on the disk
ADDRESS : 0x0116D000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\system32\drivers\ACPI.sys => Invisible on the disk
ADDRESS : 0x013A6000
SIZE    : 348.0 Ko

DRIVER  : C:\Windows\system32\drivers\WMILIB.SYS => Invisible on the disk
ADDRESS : 0x01200000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\msisadrv.sys => Invisible on the disk
ADDRESS : 0x01209000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\vdrvroot.sys => Invisible on the disk
ADDRESS : 0x01213000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\drivers\pci.sys => Invisible on the disk
ADDRESS : 0x0117D000
SIZE    : 204.0 Ko

DRIVER  : C:\Windows\System32\drivers\partmgr.sys => Invisible on the disk
ADDRESS : 0x011B0000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\compbatt.sys => Invisible on the disk
ADDRESS : 0x01220000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\BATTC.SYS => Invisible on the disk
ADDRESS : 0x011C5000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\drivers\volmgr.sys => Invisible on the disk
ADDRESS : 0x011D1000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\System32\drivers\volmgrx.sys => Invisible on the disk
ADDRESS : 0x01000000
SIZE    : 368.0 Ko

DRIVER  : C:\Windows\System32\drivers\mountmgr.sys => Invisible on the disk
ADDRESS : 0x0105C000
SIZE    : 104.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\iaStor.sys => Invisible on the disk
ADDRESS : 0x014D4000
SIZE    : 2.04 Mo

DRIVER  : C:\Windows\system32\drivers\atapi.sys => Invisible on the disk
ADDRESS : 0x016DE000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\ataport.SYS => Invisible on the disk
ADDRESS : 0x016E7000
SIZE    : 168.0 Ko

DRIVER  : C:\Windows\system32\drivers\msahci.sys => Invisible on the disk
ADDRESS : 0x01711000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\system32\drivers\PCIIDEX.SYS => Invisible on the disk
ADDRESS : 0x0171C000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\system32\drivers\amdxata.sys => Invisible on the disk
ADDRESS : 0x0172C000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\system32\drivers\fltmgr.sys => Invisible on the disk
ADDRESS : 0x01737000
SIZE    : 304.0 Ko

DRIVER  : C:\Windows\system32\drivers\fileinfo.sys => Invisible on the disk
ADDRESS : 0x01783000
SIZE    : 80.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Ntfs.sys => Invisible on the disk
ADDRESS : 0x01858000
SIZE    : 1.64 Mo

DRIVER  : C:\Windows\System32\Drivers\msrpc.sys => Invisible on the disk
ADDRESS : 0x01797000
SIZE    : 376.0 Ko

DRIVER  : C:\Windows\System32\Drivers\ksecdd.sys => Invisible on the disk
ADDRESS : 0x01800000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\System32\Drivers\cng.sys => Invisible on the disk
ADDRESS : 0x01400000
SIZE    : 456.0 Ko

DRIVER  : C:\Windows\System32\drivers\pcw.sys => Invisible on the disk
ADDRESS : 0x0181B000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Fs_Rec.sys => Invisible on the disk
ADDRESS : 0x0182C000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\ndis.sys => Invisible on the disk
ADDRESS : 0x01A7F000
SIZE    : 968.0 Ko

DRIVER  : C:\Windows\system32\drivers\NETIO.SYS => Invisible on the disk
ADDRESS : 0x01B71000
SIZE    : 384.0 Ko

DRIVER  : C:\Windows\System32\Drivers\ksecpkg.sys => Invisible on the disk
ADDRESS : 0x01BD1000
SIZE    : 172.0 Ko

DRIVER  : C:\Windows\System32\drivers\tcpip.sys => Invisible on the disk
ADDRESS : 0x01C38000
SIZE    : 2.00 Mo

DRIVER  : C:\Windows\System32\drivers\fwpkclnt.sys => Invisible on the disk
ADDRESS : 0x01E39000
SIZE    : 296.0 Ko

DRIVER  : C:\Windows\system32\drivers\volsnap.sys => Invisible on the disk
ADDRESS : 0x01E83000
SIZE    : 304.0 Ko

DRIVER  : C:\Windows\System32\Drivers\spldr.sys => Invisible on the disk
ADDRESS : 0x01ECF000
SIZE    : 32.0 Ko

DRIVER  : C:\Windows\System32\drivers\rdyboost.sys => Invisible on the disk
ADDRESS : 0x01ED7000
SIZE    : 232.0 Ko

DRIVER  : C:\Windows\System32\Drivers\mup.sys => Invisible on the disk
ADDRESS : 0x01F11000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\System32\drivers\hwpolicy.sys => Invisible on the disk
ADDRESS : 0x01F23000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\fvevol.sys => Invisible on the disk
ADDRESS : 0x01F2C000
SIZE    : 232.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\disk.sys => Invisible on the disk
ADDRESS : 0x01F66000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\CLASSPNP.SYS => Invisible on the disk
ADDRESS : 0x01F7C000
SIZE    : 192.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\cdrom.sys => Invisible on the disk
ADDRESS : 0x04910000
SIZE    : 168.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Null.SYS => Invisible on the disk
ADDRESS : 0x0493A000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Beep.SYS => Invisible on the disk
ADDRESS : 0x04943000
SIZE    : 28.0 Ko

DRIVER  : C:\Windows\System32\drivers\vga.sys => Invisible on the disk
ADDRESS : 0x0494A000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\System32\drivers\VIDEOPRT.SYS => Invisible on the disk
ADDRESS : 0x04958000
SIZE    : 148.0 Ko

DRIVER  : C:\Windows\System32\drivers\watchdog.sys => Invisible on the disk
ADDRESS : 0x0497D000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\RDPCDD.sys => Invisible on the disk
ADDRESS : 0x0498D000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\rdpencdd.sys => Invisible on the disk
ADDRESS : 0x04996000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\rdprefmp.sys => Invisible on the disk
ADDRESS : 0x0499F000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Msfs.SYS => Invisible on the disk
ADDRESS : 0x049A8000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Npfs.SYS => Invisible on the disk
ADDRESS : 0x049B3000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\tdx.sys => Invisible on the disk
ADDRESS : 0x049C4000
SIZE    : 136.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\TDI.SYS => Invisible on the disk
ADDRESS : 0x049E6000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\drivers\afd.sys => Invisible on the disk
ADDRESS : 0x04600000
SIZE    : 548.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\netbt.sys => Invisible on the disk
ADDRESS : 0x04689000
SIZE    : 276.0 Ko

DRIVER  : C:\Windows\system32\drivers\ws2ifsl.sys => Invisible on the disk
ADDRESS : 0x046CE000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\wfplwf.sys => Invisible on the disk
ADDRESS : 0x046D9000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\pacer.sys => Invisible on the disk
ADDRESS : 0x01FBA000
SIZE    : 152.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\vwififlt.sys => Invisible on the disk
ADDRESS : 0x01FE0000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\netbios.sys => Invisible on the disk
ADDRESS : 0x046E2000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\wanarp.sys => Invisible on the disk
ADDRESS : 0x01C00000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\system32\drivers\termdd.sys => Invisible on the disk
ADDRESS : 0x01C1B000
SIZE    : 80.0 Ko

DRIVER  : C:\Windows\system32\Drivers\SABI.sys => Invisible on the disk
ADDRESS : 0x049F3000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rdbss.sys => Invisible on the disk
ADDRESS : 0x01A00000
SIZE    : 324.0 Ko

DRIVER  : C:\Windows\system32\drivers\nsiproxy.sys => Invisible on the disk
ADDRESS : 0x01A51000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\drivers\mssmbios.sys => Invisible on the disk
ADDRESS : 0x01A5D000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\System32\drivers\discache.sys => Invisible on the disk
ADDRESS : 0x01A68000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dfsc.sys => Invisible on the disk
ADDRESS : 0x01836000
SIZE    : 120.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\blbdrive.sys => Invisible on the disk
ADDRESS : 0x01472000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\tunnel.sys => Invisible on the disk
ADDRESS : 0x01483000
SIZE    : 152.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\nvlddmkm.sys => Invisible on the disk
ADDRESS : 0x05CA6000
SIZE    : 10.62 Mo

DRIVER  : C:\Windows\System32\drivers\dxgkrnl.sys => Invisible on the disk
ADDRESS : 0x040A3000
SIZE    : 976.0 Ko

DRIVER  : C:\Windows\System32\drivers\dxgmms1.sys => Invisible on the disk
ADDRESS : 0x04197000
SIZE    : 280.0 Ko

DRIVER  : C:\Windows\system32\drivers\HDAudBus.sys => Invisible on the disk
ADDRESS : 0x04000000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\HECIx64.sys => Invisible on the disk
ADDRESS : 0x04024000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\drivers\usbehci.sys => Invisible on the disk
ADDRESS : 0x04035000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\drivers\USBPORT.SYS => Invisible on the disk
ADDRESS : 0x04046000
SIZE    : 344.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\bcmwl664.sys => Invisible on the disk
ADDRESS : 0x04E83000
SIZE    : 4.54 Mo

DRIVER  : C:\Windows\system32\DRIVERS\vwifibus.sys => Invisible on the disk
ADDRESS : 0x0530D000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\yk62x64.sys => Invisible on the disk
ADDRESS : 0x0531A000
SIZE    : 404.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\nusb3xhc.sys => Invisible on the disk
ADDRESS : 0x0537F000
SIZE    : 192.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\USBD.SYS => Invisible on the disk
ADDRESS : 0x053AF000
SIZE    : 8.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\CmBatt.sys => Invisible on the disk
ADDRESS : 0x053B1000
SIZE    : 20.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\i8042prt.sys => Invisible on the disk
ADDRESS : 0x053B6000
SIZE    : 120.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\kbdclass.sys => Invisible on the disk
ADDRESS : 0x053D4000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ETD.sys => Invisible on the disk
ADDRESS : 0x04E00000
SIZE    : 264.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mouclass.sys => Invisible on the disk
ADDRESS : 0x04E42000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\Impcd.sys => Invisible on the disk
ADDRESS : 0x04E51000
SIZE    : 156.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\intelppm.sys => Invisible on the disk
ADDRESS : 0x053E3000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\drivers\CompositeBus.sys => Invisible on the disk
ADDRESS : 0x041DD000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\serscan.sys => Invisible on the disk
ADDRESS : 0x04E78000
SIZE    : 32.0 Ko

DRIVER  : C:\Windows\system32\drivers\ksthunk.sys => Invisible on the disk
ADDRESS : 0x053F9000
SIZE    : 24.0 Ko

DRIVER  : C:\Windows\system32\drivers\ks.sys => Invisible on the disk
ADDRESS : 0x06744000
SIZE    : 268.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\AgileVpn.sys => Invisible on the disk
ADDRESS : 0x06787000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rasl2tp.sys => Invisible on the disk
ADDRESS : 0x0679D000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ndistapi.sys => Invisible on the disk
ADDRESS : 0x041ED000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ndiswan.sys => Invisible on the disk
ADDRESS : 0x067C1000
SIZE    : 188.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\raspppoe.sys => Invisible on the disk
ADDRESS : 0x05C00000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\raspptp.sys => Invisible on the disk
ADDRESS : 0x05C1B000
SIZE    : 132.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rassstp.sys => Invisible on the disk
ADDRESS : 0x05C3C000
SIZE    : 104.0 Ko

DRIVER  : C:\Windows\System32\Drivers\pcouffin.sys => Invisible on the disk
ADDRESS : 0x05C56000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\drivers\swenum.sys => Invisible on the disk
ADDRESS : 0x04E80000
SIZE    : 8.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\MarvinBus64.sys => Invisible on the disk
ADDRESS : 0x00F6D000
SIZE    : 272.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\umbus.sys => Invisible on the disk
ADDRESS : 0x05C6B000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\usbhub.sys => Invisible on the disk
ADDRESS : 0x00E00000
SIZE    : 360.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\nusb3hub.sys => Invisible on the disk
ADDRESS : 0x05C7D000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\System32\Drivers\NDProxy.SYS => Invisible on the disk
ADDRESS : 0x014A9000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\drivers\nvhda64v.sys => Invisible on the disk
ADDRESS : 0x01076000
SIZE    : 200.0 Ko

DRIVER  : C:\Windows\system32\drivers\portcls.sys => Invisible on the disk
ADDRESS : 0x00E5A000
SIZE    : 244.0 Ko

DRIVER  : C:\Windows\system32\drivers\drmk.sys => Invisible on the disk
ADDRESS : 0x00FB1000
SIZE    : 136.0 Ko

DRIVER  : C:\Windows\system32\drivers\RTKVHD64.sys => Invisible on the disk
ADDRESS : 0x0564B000
SIZE    : 2.33 Mo

DRIVER  : C:\Windows\system32\DRIVERS\USBSTOR.SYS => Invisible on the disk
ADDRESS : 0x0589F000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\System32\win32k.sys => Invisible on the disk
ADDRESS : 0x00070000
SIZE    : 3.09 Mo

DRIVER  : C:\Windows\System32\drivers\Dxapi.sys => Invisible on the disk
ADDRESS : 0x058BA000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\usbccgp.sys => Invisible on the disk
ADDRESS : 0x058C6000
SIZE    : 116.0 Ko

DRIVER  : C:\Windows\System32\Drivers\usbvideo.sys => Invisible on the disk
ADDRESS : 0x058E3000
SIZE    : 184.0 Ko

DRIVER  : C:\Windows\System32\Drivers\crashdmp.sys => Invisible on the disk
ADDRESS : 0x05911000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\hidusb.sys => Invisible on the disk
ADDRESS : 0x05932000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\HIDCLASS.SYS => Invisible on the disk
ADDRESS : 0x05940000
SIZE    : 100.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\HIDPARSE.SYS => Invisible on the disk
ADDRESS : 0x05959000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\kbdhid.sys => Invisible on the disk
ADDRESS : 0x05962000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\drivers\btwampfl.sys => Invisible on the disk
ADDRESS : 0x02443000
SIZE    : 2.54 Mo

DRIVER  : C:\Windows\System32\Drivers\BTHUSB.sys => Invisible on the disk
ADDRESS : 0x026CC000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\System32\Drivers\bthport.sys => Invisible on the disk
ADDRESS : 0x026E4000
SIZE    : 560.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mouhid.sys => Invisible on the disk
ADDRESS : 0x02770000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rfcomm.sys => Invisible on the disk
ADDRESS : 0x0277D000
SIZE    : 176.0 Ko

DRIVER  : C:\Windows\system32\drivers\BthEnum.sys => Invisible on the disk
ADDRESS : 0x027A9000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\bthpan.sys => Invisible on the disk
ADDRESS : 0x027B9000
SIZE    : 128.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\btwavdt.sys => Invisible on the disk
ADDRESS : 0x05970000
SIZE    : 500.0 Ko

DRIVER  : C:\Windows\system32\drivers\btwaudio.sys => Invisible on the disk
ADDRESS : 0x00D4C000
SIZE    : 540.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\btwl2cap.sys => Invisible on the disk
ADDRESS : 0x027D9000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\btwrchid.sys => Invisible on the disk
ADDRESS : 0x027E7000
SIZE    : 16.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\monitor.sys => Invisible on the disk
ADDRESS : 0x027EB000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\System32\TSDDD.dll => Invisible on the disk
ADDRESS : 0x00580000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\System32\cdd.dll => Invisible on the disk
ADDRESS : 0x007C0000
SIZE    : 156.0 Ko

DRIVER  : C:\Windows\system32\drivers\luafv.sys => Invisible on the disk
ADDRESS : 0x02400000
SIZE    : 140.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\lltdio.sys => Invisible on the disk
ADDRESS : 0x02423000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\nwifi.sys => Invisible on the disk
ADDRESS : 0x00C00000
SIZE    : 332.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ndisuio.sys => Invisible on the disk
ADDRESS : 0x059ED000
SIZE    : 76.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rspndr.sys => Invisible on the disk
ADDRESS : 0x05600000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\TurboB.sys => Invisible on the disk
ADDRESS : 0x02438000
SIZE    : 28.0 Ko

DRIVER  : C:\Windows\system32\drivers\HTTP.sys => Invisible on the disk
ADDRESS : 0x06CB4000
SIZE    : 804.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\bowser.sys => Invisible on the disk
ADDRESS : 0x06D7D000
SIZE    : 120.0 Ko

DRIVER  : C:\Windows\System32\drivers\mpsdrv.sys => Invisible on the disk
ADDRESS : 0x06D9B000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb.sys => Invisible on the disk
ADDRESS : 0x06DB3000
SIZE    : 180.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb10.sys => Invisible on the disk
ADDRESS : 0x06C00000
SIZE    : 312.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb20.sys => Invisible on the disk
ADDRESS : 0x06C4E000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\vwifimp.sys => Invisible on the disk
ADDRESS : 0x06C72000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\peauth.sys => Invisible on the disk
ADDRESS : 0x074ED000
SIZE    : 664.0 Ko

DRIVER  : C:\Windows\System32\Drivers\secdrv.SYS => Invisible on the disk
ADDRESS : 0x07593000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srvnet.sys => Invisible on the disk
ADDRESS : 0x0759E000
SIZE    : 196.0 Ko

DRIVER  : C:\Windows\System32\drivers\tcpipreg.sys => Invisible on the disk
ADDRESS : 0x075CF000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srv2.sys => Invisible on the disk
ADDRESS : 0x07400000
SIZE    : 420.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srv.sys => Invisible on the disk
ADDRESS : 0x07AA3000
SIZE    : 608.0 Ko

DRIVER  : C:\Windows\System32\smss.exe => Invisible on the disk
ADDRESS : 0x47730000
SIZE    : 128.0 Ko

Device\Harddisk0\DR0 => Mebratix.B MBR Code found in sector 3
SystemStartOptions :  NOEXECUTE=OPTIN  NUMPROC=4

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D8 8E C0 8E D0 BC 00 7C 8B F4 BF 00 06   3À.Ø.À.м.|.ô¿..
0x00000010   B9 00 01 FC F3 A5 EA 1B 00 60 00 0E 1F 06 E8 95   ¹..üó¥ê..`....è.
0x00000020   00 07 80 3E 97 01 01 74 75 80 3E 97 01 02 74 00   ...>...tu.>...t.
0x00000030   C6 06 94 01 00 E8 04 01 BE BE 01 B3 04 F6 04 80   Æ....è..¾¾.³.ö..
0x00000040   75 0F 83 C6 10 FE CB 75 F4 CD 18 BE 5D 01 E8 FC   u..Æ.þËuôÍ.¾].èü
0x00000050   00 BB 00 7C 06 53 50 55 8B EC C7 46 02 00 00 5D   .».|.SPU.ìÇF...]
0x00000060   50 55 8B EC C7 46 02 00 00 5D FF 74 0A FF 74 08   PU.ìÇF...].t..t.
0x00000070   06 53 50 55 8B EC C7 46 02 01 00 5D 50 55 8B EC   .SPU.ìÇF...]PU.ì
0x00000080   C7 46 02 10 00 5D 16 1F 8B F4 B4 42 CD 13 83 C4   ÇF...]...ô´BÍ..Ä
0x00000090   10 EB 00 CB C6 06 95 01 00 E8 A0 00 EB 00 BB 00   .ë.ËÆ....è..ë.».
0x000000A0   7C 06 53 B8 01 02 B5 00 B1 05 B6 00 B2 80 CD 13   |.S¸..µ.±.¶.².Í.
0x000000B0   C6 06 94 01 01 CB B8 00 F0 8E C0 33 C0 8B F0 BB   Æ....˸.ð.À3À.ð»
0x000000C0   FF FF 26 81 3C 53 77 74 08 83 C6 01 4B 75 F3 EB   ..&.<Swt..Æ.Kuóë
0x000000D0   1A 26 81 7C 02 53 6D 74 02 EB EE 26 81 7C 04 69   .&.|.Smt.ëî&.|.i
0x000000E0   40 74 02 EB E4 83 C6 06 E8 01 00 C3 1E 57 26 8B   @t.ëä.Æ.è..Ã.W&.
0x000000F0   14 26 8A 44 03 EE 26 8B 44 07 8E D8 26 8B 44 05   .&.D.î&.D..Ø&.D.
0x00000100   8B F8 C7 05 43 58 C7 45 02 5C 00 26 8A 44 02 EE   .øÇ.CXÇE.\.&.D.î
0x00000110   B1 02 8A 65 05 80 FC FF 74 13 80 FC 80 76 0E C7   ±..e..ü.t..ü.v.Ç
0x00000120   45 02 5D 00 80 EC 80 88 65 05 EE B1 01 26 8B 14   E.]..ì..e.î±.&..
0x00000130   26 8A 44 04 EE 5F 1F 88 0E 97 01 C3 BB 00 06 B8   &.D.î_.....û..¸
0x00000140   01 03 B5 00 B1 01 B6 00 B2 80 CD 13 C3 AC 3C 00   ..µ.±.¶.².Í.ì<.
0x00000150   74 0A B4 0E B7 00 B3 07 CD 10 EB F1 C3 4D 69 73   t.´.·.³.Í.ëñÃMis
0x00000160   73 69 6E 67 20 6F 70 65 72 61 74 69 6E 67 20 73   sing operating s
0x00000170   79 73 74 65 6D 00 00 00 00 00 00 00 00 00 00 00   ystem...........
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   46 44 53 54 00 00 3E 02 00 27 00 00 BC 0A 8D 7E   FDST..>..'..¼..~
0x000001A0   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x000001B0   65 6D 00 00 00 63 7B 9A 15 EA EC E5 00 00 80 20   em...c{..êìå... 
0x000001C0   21 00 07 DF 13 0C 00 08 00 00 00 20 03 00 00 DF   !..ß....... ...ß
0x000001D0   14 0C 07 FE FF FF 00 28 03 00 00 00 60 16 00 FE   ...þ...(....`..þ
0x000001E0   FF FF 0F FE FF FF 00 28 63 16 00 68 74 21 00 FE   ...þ...(c..ht!.þ
0x000001F0   FF FF 27 FE FF FF 00 90 D7 37 00 C0 60 02 55 AA   ..'þ....×7.À`.Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed8            MOV DS, AX   
0x0004    8ec0            MOV ES, AX   
0x0006    8ed0            MOV SS, AX   
0x0008    bc 007c         MOV SP, 0x7c00   
0x000B    8bf4            MOV SI, SP   
0x000D    bf 0006         MOV DI, 0x600   
0x0010    b9 0001         MOV CX, 0x100   
0x0013    fc              CLD   
0x0014    f3 a5           REP MOVSW   
0x0016    ea 1b00 6000    JMP FAR 0x60:0x1b   
0x001B    0e              PUSH CS   
0x001C    1f              POP DS   
0x001D    06              PUSH ES   
0x001E    e8 9500         CALL 0xb6   
0x0021    07              POP ES   
0x0022    803e 9701 01    CMP BYTE [0x197], 0x1   
0x0027    74 75           JZ 0x9e   
0x0029    803e 9701 02    CMP BYTE [0x197], 0x2   
0x002E    74 00           JZ 0x30   
0x0030    c606 9401 00    MOV BYTE [0x194], 0x0   
0x0035    e8 0401         CALL 0x13c   
0x0038    be be01         MOV SI, 0x1be   
0x003B    b3 04           MOV BL, 0x4   
0x003D    f604 80         TEST BYTE [SI], 0x80   
0x0040    75 0f           JNZ 0x51   
0x0042    83c6 10         ADD SI, 0x10   
0x0045    fecb            DEC BL   
0x0047    75 f4           JNZ 0x3d   
0x0049    cd 18           INT 0x18   
0x004B    be 5d01         MOV SI, 0x15d   
0x004E    e8 fc00         CALL 0x14d   
0x0051    bb 007c         MOV BX, 0x7c00   
0x0054    06              PUSH ES   
0x0055    53              PUSH BX   
0x0056    50              PUSH AX   
0x0057    55              PUSH BP   
0x0058    8bec            MOV BP, SP   
0x005A    c746 02 0000    MOV WORD [BP+0x2], 0x0   
0x005F    5d              POP BP   
0x0060    50              PUSH AX   
0x0061    55              PUSH BP   
0x0062    8bec            MOV BP, SP   
0x0064    c746 02 0000    MOV WORD [BP+0x2], 0x0   
0x0069    5d              POP BP   
0x006A    ff74 0a         PUSH WORD [SI+0xa]   
0x006D    ff74 08         PUSH WORD [SI+0x8]   
0x0070    06              PUSH ES   
0x0071    53              PUSH BX   
0x0072    50              PUSH AX   
0x0073    55              PUSH BP   
0x0074    8bec            MOV BP, SP   
0x0076    c746 02 0100    MOV WORD [BP+0x2], 0x1   
0x007B    5d              POP BP   
0x007C    50              PUSH AX   
0x007D    55              PUSH BP   
0x007E    8bec            MOV BP, SP   
0x0080    c746 02 1000    MOV WORD [BP+0x2], 0x10   
0x0085    5d              POP BP   
0x0086    16              PUSH SS   
0x0087    1f              POP DS   
0x0088    8bf4            MOV SI, SP   
0x008A    b4 42           MOV AH, 0x42   
0x008C    cd 13           INT 0x13   
0x008E    83c4 10         ADD SP, 0x10   
0x0091    eb 00           JMP 0x93   
0x0093    cb              RETF   
0x0094    c606 9501 00    MOV BYTE [0x195], 0x0   
0x0099    e8 a000         CALL 0x13c   
0x009C    eb 00           JMP 0x9e   
0x009E    bb 007c         MOV BX, 0x7c00   
0x00A1    06              PUSH ES   
0x00A2    53              PUSH BX   
0x00A3    b8 0102         MOV AX, 0x201   
0x00A6    b5 00           MOV CH, 0x0   
0x00A8    b1 05           MOV CL, 0x5   
0x00AA    b6 00           MOV DH, 0x0   
0x00AC    b2 80           MOV DL, 0x80   
0x00AE    cd 13           INT 0x13   
0x00B0    c606 9401 01    MOV BYTE [0x194], 0x1   
0x00B5    cb              RETF   
0x00B6    b8 00f0         MOV AX, 0xf000   
0x00B9    8ec0            MOV ES, AX   
0x00BB    33c0            XOR AX, AX   
0x00BD    8bf0            MOV SI, AX   
0x00BF    bb ffff         MOV BX, 0xffff   
0x00C2    26 813c 5377    CMP WORD ES:[SI], 0x7753   
0x00C7    74 08           JZ 0xd1   
0x00C9    83c6 01         ADD SI, 0x1   
0x00CC    4b              DEC BX   
0x00CD    75 f3           JNZ 0xc2   
0x00CF    eb 1a           JMP 0xeb   
0x00D1    26 817c 02 536d CMP WORD ES:[SI+0x2], 0x6d53   
0x00D7    74 02           JZ 0xdb   
0x00D9    eb ee           JMP 0xc9   
0x00DB    26 817c 04 6940 CMP WORD ES:[SI+0x4], 0x4069   
0x00E1    74 02           JZ 0xe5   
0x00E3    eb e4           JMP 0xc9   
0x00E5    83c6 06         ADD SI, 0x6   
0x00E8    e8 0100         CALL 0xec   
0x00EB    c3              RET   
0x00EC    1e              PUSH DS   
0x00ED    57              PUSH DI   
0x00EE    26 8b14         MOV DX, ES:[SI]   
0x00F1    26 8a44 03      MOV AL, ES:[SI+0x3]   
0x00F5    ee              OUT DX, AL   
0x00F6    26 8b44 07      MOV AX, ES:[SI+0x7]   
0x00FA    8ed8            MOV DS, AX   
0x00FC    26 8b44 05      MOV AX, ES:[SI+0x5]   
0x0100    8bf8            MOV DI, AX   
0x0102    c705 4358       MOV WORD [DI], 0x5843   
0x0106    c745 02 5c00    MOV WORD [DI+0x2], 0x5c   
0x010B    26 8a44 02      MOV AL, ES:[SI+0x2]   
0x010F    ee              OUT DX, AL   
0x0110    b1 02           MOV CL, 0x2   
0x0112    8a65 05         MOV AH, [DI+0x5]   
0x0115    80fc ff         CMP AH, 0xff   
0x0118    74 13           JZ 0x12d   
0x011A    80fc 80         CMP AH, 0x80   
0x011D    76 0e           JBE 0x12d   
0x011F    c745 02 5d00    MOV WORD [DI+0x2], 0x5d   
0x0124    80ec 80         SUB AH, 0x80   
0x0127    8865 05         MOV [DI+0x5], AH   
0x012A    ee              OUT DX, AL   
0x012B    b1 01           MOV CL, 0x1   
0x012D    26 8b14         MOV DX, ES:[SI]   
0x0130    26 8a44 04      MOV AL, ES:[SI+0x4]   
0x0134    ee              OUT DX, AL   
0x0135    5f              POP DI   
0x0136    1f              POP DS   
0x0137    880e 9701       MOV [0x197], CL   
0x013B    c3              RET   
0x013C    bb 0006         MOV BX, 0x600   
0x013F    b8 0103         MOV AX, 0x301   
0x0142    b5 00           MOV CH, 0x0   
0x0144    b1 01           MOV CL, 0x1   
0x0146    b6 00           MOV DH, 0x0   
0x0148    b2 80           MOV DL, 0x80   
0x014A    cd 13           INT 0x13   
0x014C    c3              RET   
0x014D    ac              LODSB   
0x014E    3c 00           CMP AL, 0x0   
0x0150    74 0a           JZ 0x15c   
0x0152    b4 0e           MOV AH, 0xe   
0x0154    b7 00           MOV BH, 0x0   
0x0156    b3 07           MOV BL, 0x7   
0x0158    cd 10           INT 0x10   
0x015A    eb f1           JMP 0x14d   
0x015C    c3              RET   
0x015D    4d              DEC BP   
0x015E    6973 73 696e    IMUL SI, [BP+DI+0x73], 0x6e69   
0x0163    67 206f 70      AND [EDI+0x70], CH   
0x0167    65              DB 0x65   
0x0167    65 72 61        JB 0x1cb   
0x016A    74 69           JZ 0x1d5   
0x016C    6e              OUTSB   
0x016D    67 2073 79      AND [EBX+0x79], DH   
0x0171    73 74           JAE 0x1e7   
0x0173    65 6d           INS WORD GS:[DI], DX   
0x0175    0000            ADD [BX+SI], AL   
0x0177    0000            ADD [BX+SI], AL   
0x0179    0000            ADD [BX+SI], AL   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0046 44         ADD [BP+0x44], AL   
0x0192    53              PUSH BX   
0x0193    54              PUSH SP   
0x0194    0000            ADD [BX+SI], AL   
0x0196    3e 0200         ADD AL, DS:[BX+SI]   
0x0199    27              DAA   
0x019A    0000            ADD [BX+SI], AL   
0x019C    bc 0a8d         MOV SP, 0x8d0a   
0x019F    7e 67           JLE 0x208   
0x01A1    206f 70         AND [BX+0x70], CH   
0x01A4    65              DB 0x65   
0x01A4    65 72 61        JB 0x208   
0x01A7    74 69           JZ 0x212   
0x01A9    6e              OUTSB   
0x01AA    67 2073 79      AND [EBX+0x79], DH   
0x01AE    73 74           JAE 0x224   
0x01B0    65 6d           INS WORD GS:[DI], DX   
0x01B2    0000            ADD [BX+SI], AL   
0x01B4    0063 7b         ADD [BP+DI+0x7b], AH   
0x01B7    9a 15ea ece5    CALL FAR 0xe5ec:0xea15   
0x01BC    0000            ADD [BX+SI], AL   
0x01BE    8020 21         AND BYTE [BX+SI], 0x21   
0x01C1    0007            ADD [BX], AL   
0x01C3    df13            FIST WORD [BP+DI]   
0x01C5    0c 00           OR AL, 0x0   
0x01C7    0800            OR [BX+SI], AL   
0x01C9    0000            ADD [BX+SI], AL   
0x01CB    2003            AND [BP+DI], AL   
0x01CD    0000            ADD [BX+SI], AL   
0x01CF    df14            FIST WORD [SI]   
0x01D1    0c 07           OR AL, 0x7   
0x01D3    fe              DB 0xfe   
0x01D4    ff              DB 0xff   
0x01D5    ff00            INC WORD [BX+SI]   
0x01D7    2803            SUB [BP+DI], AL   
0x01D9    0000            ADD [BX+SI], AL   
0x01DB    0060 16         ADD [BX+SI+0x16], AH   
0x01DE    00fe            ADD DH, BH   
0x01E0    ff              DB 0xff   
0x01E1    ff0f            DEC WORD [BX]   
0x01E3    fe              DB 0xfe   
0x01E4    ff              DB 0xff   
0x01E5    ff00            INC WORD [BX+SI]   
0x01E7    2863 16         SUB [BP+DI+0x16], AH   
0x01EA    0068 74         ADD [BX+SI+0x74], CH   
0x01ED    2100            AND [BX+SI], AX   
0x01EF    fe              DB 0xfe   
0x01F0    ff              DB 0xff   
0x01F1    ff27            JMP [BX]   
0x01F3    fe              DB 0xfe   
0x01F4    ff              DB 0xff   
0x01F5    ff00            INC WORD [BX+SI]   
0x01F7    90              NOP   
0x01F8    d7              XLATB   
0x01F9    37              AAA   
0x01FA    00c0            ADD AL, AL   
0x01FC    60              PUSHA   
0x01FD    0255 aa         ADD DL, [DI-0x56]   


_______MBR   \Device\Harddisk1\DR1  

0x00000000   33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C   3À.м.|ûP.P.ü¾.|
0x00000010   BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04   ¿..PW¹å.ó¤Ë½¾.±.
0x00000020   38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5   8n.|.u..Å.âôÍ..õ
0x00000030   83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B   .Æ.It.8,tö.µ.´..
0x00000040   F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88   ð¬<.tü»..´.Í.ëò.
0x00000050   4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B   N.èF.s*þF..~..t.
0x00000060   80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83   .~..t..¶.uÒ.F...
0x00000070   46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB   F...V..è!.s..¶.ë
0x00000080   BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0   ¼.>þ}Uªt..~..tÈ.
0x00000090   B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56   ·.ë©.ü.W.õË¿...V
0x000000A0   00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC   .´.Í.r#.Á$?..Þ.ü
0x000000B0   43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56   C÷ã.Ñ.Ö±.ÒîB÷â9V
0x000000C0   0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C   .w#r.9F.s.¸..».|
0x000000D0   8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A   .N..V.Í.sQOtN2ä.
0x000000E0   56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD   V.Í.ëä.V.`»ªU´AÍ
0x000000F0   13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60   .r6.ûUªu0öÁ.t+a`
0x00000100   6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A   j.j..v..v.j.h.|j
0x00000110   01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B   .j.´B.ôÍ.aas.Ot.
0x00000120   32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61   2ä.V.Í.ëÖaùÃInva
0x00000130   6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61   lid partition ta
0x00000140   62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E   ble.Error loadin
0x00000150   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x00000160   65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61   em.Missing opera
0x00000170   74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00   ting system.....
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 2C 44 63 7B 20 A2 26 00 00 80 01   .....,Dc{ ¢&....
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 C2 52 54 57 00 00   ...þ..?...ÂRTW..
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed0            MOV SS, AX   
0x0004    bc 007c         MOV SP, 0x7c00   
0x0007    fb              STI   
0x0008    50              PUSH AX   
0x0009    07              POP ES   
0x000A    50              PUSH AX   
0x000B    1f              POP DS   
0x000C    fc              CLD   
0x000D    be 1b7c         MOV SI, 0x7c1b   
0x0010    bf 1b06         MOV DI, 0x61b   
0x0013    50              PUSH AX   
0x0014    57              PUSH DI   
0x0015    b9 e501         MOV CX, 0x1e5   
0x0018    f3 a4           REP MOVSB   
0x001A    cb              RETF   
0x001B    bd be07         MOV BP, 0x7be   
0x001E    b1 04           MOV CL, 0x4   
0x0020    386e 00         CMP [BP+0x0], CH   
0x0023    7c 09           JL 0x2e   
0x0025    75 13           JNZ 0x3a   
0x0027    83c5 10         ADD BP, 0x10   
0x002A    e2 f4           LOOP 0x20   
0x002C    cd 18           INT 0x18   
0x002E    8bf5            MOV SI, BP   
0x0030    83c6 10         ADD SI, 0x10   
0x0033    49              DEC CX   
0x0034    74 19           JZ 0x4f   
0x0036    382c            CMP [SI], CH   
0x0038    74 f6           JZ 0x30   
0x003A    a0 b507         MOV AL, [0x7b5]   
0x003D    b4 07           MOV AH, 0x7   
0x003F    8bf0            MOV SI, AX   
0x0041    ac              LODSB   
0x0042    3c 00           CMP AL, 0x0   
0x0044    74 fc           JZ 0x42   
0x0046    bb 0700         MOV BX, 0x7   
0x0049    b4 0e           MOV AH, 0xe   
0x004B    cd 10           INT 0x10   
0x004D    eb f2           JMP 0x41   
0x004F    884e 10         MOV [BP+0x10], CL   
0x0052    e8 4600         CALL 0x9b   
0x0055    73 2a           JAE 0x81   
0x0057    fe46 10         INC BYTE [BP+0x10]   
0x005A    807e 04 0b      CMP BYTE [BP+0x4], 0xb   
0x005E    74 0b           JZ 0x6b   
0x0060    807e 04 0c      CMP BYTE [BP+0x4], 0xc   
0x0064    74 05           JZ 0x6b   
0x0066    a0 b607         MOV AL, [0x7b6]   
0x0069    75 d2           JNZ 0x3d   
0x006B    8046 02 06      ADD BYTE [BP+0x2], 0x6   
0x006F    8346 08 06      ADD WORD [BP+0x8], 0x6   
0x0073    8356 0a 00      ADC WORD [BP+0xa], 0x0   
0x0077    e8 2100         CALL 0x9b   
0x007A    73 05           JAE 0x81   
0x007C    a0 b607         MOV AL, [0x7b6]   
0x007F    eb bc           JMP 0x3d   
0x0081    813e fe7d 55aa  CMP WORD [0x7dfe], 0xaa55   
0x0087    74 0b           JZ 0x94   
0x0089    807e 10 00      CMP BYTE [BP+0x10], 0x0   
0x008D    74 c8           JZ 0x57   
0x008F    a0 b707         MOV AL, [0x7b7]   
0x0092    eb a9           JMP 0x3d   
0x0094    8bfc            MOV DI, SP   
0x0096    1e              PUSH DS   
0x0097    57              PUSH DI   
0x0098    8bf5            MOV SI, BP   
0x009A    cb              RETF   
0x009B    bf 0500         MOV DI, 0x5   
0x009E    8a56 00         MOV DL, [BP+0x0]   
0x00A1    b4 08           MOV AH, 0x8   
0x00A3    cd 13           INT 0x13   
0x00A5    72 23           JB 0xca   
0x00A7    8ac1            MOV AL, CL   
0x00A9    24 3f           AND AL, 0x3f   
0x00AB    98              CBW   
0x00AC    8ade            MOV BL, DH   
0x00AE    8afc            MOV BH, AH   
0x00B0    43              INC BX   
0x00B1    f7e3            MUL BX   
0x00B3    8bd1            MOV DX, CX   
0x00B5    86d6            XCHG DH, DL   
0x00B7    b1 06           MOV CL, 0x6   
0x00B9    d2ee            SHR DH, CL   
0x00BB    42              INC DX   
0x00BC    f7e2            MUL DX   
0x00BE    3956 0a         CMP [BP+0xa], DX   
0x00C1    77 23           JA 0xe6   
0x00C3    72 05           JB 0xca   
0x00C5    3946 08         CMP [BP+0x8], AX   
0x00C8    73 1c           JAE 0xe6   
0x00CA    b8 0102         MOV AX, 0x201   
0x00CD    bb 007c         MOV BX, 0x7c00   
0x00D0    8b4e 02         MOV CX, [BP+0x2]   
0x00D3    8b56 00         MOV DX, [BP+0x0]   
0x00D6    cd 13           INT 0x13   
0x00D8    73 51           JAE 0x12b   
0x00DA    4f              DEC DI   
0x00DB    74 4e           JZ 0x12b   
0x00DD    32e4            XOR AH, AH   
0x00DF    8a56 00         MOV DL, [BP+0x0]   
0x00E2    cd 13           INT 0x13   
0x00E4    eb e4           JMP 0xca   
0x00E6    8a56 00         MOV DL, [BP+0x0]   
0x00E9    60              PUSHA   
0x00EA    bb aa55         MOV BX, 0x55aa   
0x00ED    b4 41           MOV AH, 0x41   
0x00EF    cd 13           INT 0x13   
0x00F1    72 36           JB 0x129   
0x00F3    81fb 55aa       CMP BX, 0xaa55   
0x00F7    75 30           JNZ 0x129   
0x00F9    f6c1 01         TEST CL, 0x1   
0x00FC    74 2b           JZ 0x129   
0x00FE    61              POPA   
0x00FF    60              PUSHA   
0x0100    6a 00           PUSH 0x0   
0x0102    6a 00           PUSH 0x0   
0x0104    ff76 0a         PUSH WORD [BP+0xa]   
0x0107    ff76 08         PUSH WORD [BP+0x8]   
0x010A    6a 00           PUSH 0x0   
0x010C    68 007c         PUSH 0x7c00   
0x010F    6a 01           PUSH 0x1   
0x0111    6a 10           PUSH 0x10   
0x0113    b4 42           MOV AH, 0x42   
0x0115    8bf4            MOV SI, SP   
0x0117    cd 13           INT 0x13   
0x0119    61              POPA   
0x011A    61              POPA   
0x011B    73 0e           JAE 0x12b   
0x011D    4f              DEC DI   
0x011E    74 0b           JZ 0x12b   
0x0120    32e4            XOR AH, AH   
0x0122    8a56 00         MOV DL, [BP+0x0]   
0x0125    cd 13           INT 0x13   
0x0127    eb d6           JMP 0xff   
0x0129    61              POPA   
0x012A    f9              STC   
0x012B    c3              RET   
0x012C    49              DEC CX   
0x012D    6e              OUTSB   
0x012E    76 61           JBE 0x191   
0x0130    6c              INSB   
0x0131    6964 20 7061    IMUL SP, [SI+0x20], 0x6170   
0x0136    72 74           JB 0x1ac   
0x0138    6974 69 6f6e    IMUL SI, [SI+0x69], 0x6e6f   
0x013D    2074 61         AND [SI+0x61], DH   
0x0140    626c 65         BOUND BP, [SI+0x65]   
0x0143    0045 72         ADD [DI+0x72], AL   
0x0146    72 6f           JB 0x1b7   
0x0148    72 20           JB 0x16a   
0x014A    6c              INSB   
0x014B    6f              OUTSW   
0x014C    61              POPA   
0x014D    64 696e 67 206f IMUL BP, FS:[BP+0x67], 0x6f20   
0x0153    70 65           JO 0x1ba   
0x0155    72 61           JB 0x1b8   
0x0157    74 69           JZ 0x1c2   
0x0159    6e              OUTSB   
0x015A    67 2073 79      AND [EBX+0x79], DH   
0x015E    73 74           JAE 0x1d4   
0x0160    65 6d           INS WORD GS:[DI], DX   
0x0162    004d 69         ADD [DI+0x69], CL   
0x0165    73 73           JAE 0x1da   
0x0167    696e 67 206f    IMUL BP, [BP+0x67], 0x6f20   
0x016C    70 65           JO 0x1d3   
0x016E    72 61           JB 0x1d1   
0x0170    74 69           JZ 0x1db   
0x0172    6e              OUTSB   
0x0173    67 2073 79      AND [EBX+0x79], DH   
0x0177    73 74           JAE 0x1ed   
0x0179    65 6d           INS WORD GS:[DI], DX   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0000            ADD [BX+SI], AL   
0x0191    0000            ADD [BX+SI], AL   
0x0193    0000            ADD [BX+SI], AL   
0x0195    0000            ADD [BX+SI], AL   
0x0197    0000            ADD [BX+SI], AL   
0x0199    0000            ADD [BX+SI], AL   
0x019B    0000            ADD [BX+SI], AL   
0x019D    0000            ADD [BX+SI], AL   
0x019F    0000            ADD [BX+SI], AL   
0x01A1    0000            ADD [BX+SI], AL   
0x01A3    0000            ADD [BX+SI], AL   
0x01A5    0000            ADD [BX+SI], AL   
0x01A7    0000            ADD [BX+SI], AL   
0x01A9    0000            ADD [BX+SI], AL   
0x01AB    0000            ADD [BX+SI], AL   
0x01AD    0000            ADD [BX+SI], AL   
0x01AF    0000            ADD [BX+SI], AL   
0x01B1    0000            ADD [BX+SI], AL   
0x01B3    0000            ADD [BX+SI], AL   
0x01B5    2c 44           SUB AL, 0x44   
0x01B7    637b 20         ARPL [BP+DI+0x20], DI   
0x01BA    a2 2600         MOV [0x26], AL   
0x01BD    0080 0101       ADD [BX+SI+0x101], AL   
0x01C1    0007            ADD [BX], AL   
0x01C3    fe              DB 0xfe   
0x01C4    ff              DB 0xff   
0x01C5    ff              DB 0xff   
0x01C6    3f              AAS   
0x01C7    0000            ADD [BX+SI], AL   
0x01C9    00c2            ADD DL, AL   
0x01CB    52              PUSH DX   
0x01CC    54              PUSH SP   
0x01CD    57              PUSH DI   
0x01CE    0000            ADD [BX+SI], AL   
0x01D0    0000            ADD [BX+SI], AL   
0x01D2    0000            ADD [BX+SI], AL   
0x01D4    0000            ADD [BX+SI], AL   
0x01D6    0000            ADD [BX+SI], AL   
0x01D8    0000            ADD [BX+SI], AL   
0x01DA    0000            ADD [BX+SI], AL   
0x01DC    0000            ADD [BX+SI], AL   
0x01DE    0000            ADD [BX+SI], AL   
0x01E0    0000            ADD [BX+SI], AL   
0x01E2    0000            ADD [BX+SI], AL   
0x01E4    0000            ADD [BX+SI], AL   
0x01E6    0000            ADD [BX+SI], AL   
0x01E8    0000            ADD [BX+SI], AL   
0x01EA    0000            ADD [BX+SI], AL   
0x01EC    0000            ADD [BX+SI], AL   
0x01EE    0000            ADD [BX+SI], AL   
0x01F0    0000            ADD [BX+SI], AL   
0x01F2    0000            ADD [BX+SI], AL   
0x01F4    0000            ADD [BX+SI], AL   
0x01F6    0000            ADD [BX+SI], AL   
0x01F8    0000            ADD [BX+SI], AL   
0x01FA    0000            ADD [BX+SI], AL   
0x01FC    0000            ADD [BX+SI], AL   
0x01FE    55              PUSH BP   
0x01FF    aa              STOSB   


Re: Podivne chování

Napsal: 21 led 2013 18:41
od miromen
Dump_Hdd1_DR1.mbr v pořadku

Dump_Hdd0_DR0.mbr - 1 pochybeni
https://www.virustotal.com/file/920c6b1 ... 358789662/

Re: Podivne chování

Napsal: 21 led 2013 19:18
od miromen
Dump_Hdd0_DR0_Sector3.bin - opět 1 pochybeni
https://www.virustotal.com/file/9695d12 ... 358791824/

Re: Podivne chování

Napsal: 21 led 2013 19:25
od miromen
Tdsskiller jsem dělal podle navodu ale žadne okno na mě nevyskočilo. Nicmeně log se uložil.

1.čast tdsskiller logu.....

19:11:28.0838 1136 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
19:11:28.0947 1136 ============================================================
19:11:28.0947 1136 Current date / time: 2013/01/21 19:11:28.0947
19:11:28.0947 1136 SystemInfo:
19:11:28.0947 1136
19:11:28.0947 1136 OS Version: 6.1.7601 ServicePack: 1.0
19:11:28.0947 1136 Product type: Workstation
19:11:28.0947 1136 ComputerName: MIROMEN-PC
19:11:28.0947 1136 UserName: Miromen
19:11:28.0947 1136 Windows directory: C:\Windows
19:11:28.0947 1136 System windows directory: C:\Windows
19:11:28.0947 1136 Running under WOW64
19:11:28.0947 1136 Processor architecture: Intel x64
19:11:28.0947 1136 Number of processors: 4
19:11:28.0947 1136 Page size: 0x1000
19:11:28.0947 1136 Boot type: Normal boot
19:11:28.0947 1136 ============================================================
19:11:29.0384 1136 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:11:29.0399 1136 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:11:29.0399 1136 ============================================================
19:11:29.0399 1136 \Device\Harddisk0\DR0:
19:11:29.0399 1136 MBR partitions:
19:11:29.0399 1136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
19:11:29.0399 1136 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x16600000
19:11:29.0415 1136 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x16633000, BlocksNum 0x21746000
19:11:29.0415 1136 \Device\Harddisk1\DR1:
19:11:29.0415 1136 MBR partitions:
19:11:29.0415 1136 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x575452C2
19:11:29.0415 1136 ============================================================
19:11:29.0462 1136 C: <-> \Device\Harddisk0\DR0\Partition2
19:11:29.0508 1136 D: <-> \Device\Harddisk0\DR0\Partition3
19:11:29.0805 1136 I: <-> \Device\Harddisk1\DR1\Partition1
19:11:29.0805 1136 ============================================================
19:11:29.0805 1136 Initialize success
19:11:29.0805 1136 ============================================================
19:12:14.0358 1052 ============================================================
19:12:14.0358 1052 Scan started
19:12:14.0358 1052 Mode: Manual; SigCheck; TDLFS;
19:12:14.0358 1052 ============================================================
19:12:14.0686 1052 ================ Scan system memory ========================
19:12:14.0686 1052 System memory - ok
19:12:14.0686 1052 ================ Scan services =============================
19:12:14.0982 1052 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
19:12:15.0045 1052 1394ohci - ok
19:12:15.0092 1052 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
19:12:15.0107 1052 ACPI - ok
19:12:15.0170 1052 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
19:12:15.0201 1052 AcpiPmi - ok
19:12:15.0326 1052 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:12:15.0326 1052 AdobeARMservice - ok
19:12:15.0372 1052 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
19:12:15.0404 1052 adp94xx - ok
19:12:15.0482 1052 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
19:12:15.0497 1052 adpahci - ok
19:12:15.0513 1052 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
19:12:15.0528 1052 adpu320 - ok
19:12:15.0560 1052 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:12:15.0622 1052 AeLookupSvc - ok
19:12:15.0731 1052 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
19:12:15.0747 1052 AFD - ok
19:12:15.0825 1052 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:12:15.0825 1052 agp440 - ok
19:12:15.0856 1052 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
19:12:15.0887 1052 ALG - ok
19:12:15.0918 1052 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
19:12:15.0934 1052 aliide - ok
19:12:15.0981 1052 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
19:12:15.0981 1052 amdide - ok
19:12:16.0028 1052 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
19:12:16.0028 1052 AmdK8 - ok
19:12:16.0043 1052 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
19:12:16.0074 1052 AmdPPM - ok
19:12:16.0106 1052 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
19:12:16.0121 1052 amdsata - ok
19:12:16.0168 1052 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
19:12:16.0168 1052 amdsbs - ok
19:12:16.0215 1052 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
19:12:16.0215 1052 amdxata - ok
19:12:16.0293 1052 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
19:12:16.0355 1052 AppID - ok
19:12:16.0386 1052 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
19:12:16.0418 1052 AppIDSvc - ok
19:12:16.0464 1052 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
19:12:16.0511 1052 Appinfo - ok
19:12:16.0574 1052 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
19:12:16.0589 1052 arc - ok
19:12:16.0605 1052 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
19:12:16.0605 1052 arcsas - ok
19:12:16.0698 1052 ASInsHelp - ok
19:12:16.0730 1052 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:12:16.0776 1052 AsyncMac - ok
19:12:16.0870 1052 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
19:12:16.0886 1052 atapi - ok
19:12:16.0964 1052 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:12:17.0088 1052 AudioEndpointBuilder - ok
19:12:17.0120 1052 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
19:12:17.0151 1052 AudioSrv - ok
19:12:17.0213 1052 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
19:12:17.0244 1052 AxInstSV - ok
19:12:17.0307 1052 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
19:12:17.0354 1052 b06bdrv - ok
19:12:17.0432 1052 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
19:12:17.0447 1052 b57nd60a - ok
19:12:17.0603 1052 [ 43AD3D3E7674833FCA9A7C4E7180AD54 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
19:12:17.0697 1052 BCM43XX - ok
19:12:17.0712 1052 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
19:12:17.0744 1052 BDESVC - ok
19:12:17.0790 1052 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
19:12:17.0853 1052 Beep - ok
19:12:17.0915 1052 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
19:12:17.0962 1052 BFE - ok
19:12:18.0040 1052 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
19:12:18.0118 1052 BITS - ok
19:12:18.0165 1052 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
19:12:18.0212 1052 blbdrive - ok
19:12:18.0258 1052 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:12:18.0290 1052 bowser - ok
19:12:18.0321 1052 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:12:18.0368 1052 BrFiltLo - ok
19:12:18.0414 1052 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:12:18.0446 1052 BrFiltUp - ok
19:12:18.0461 1052 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
19:12:18.0508 1052 BridgeMP - ok
19:12:18.0539 1052 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
19:12:18.0555 1052 Browser - ok
19:12:18.0570 1052 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
19:12:18.0617 1052 Brserid - ok
19:12:18.0633 1052 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
19:12:18.0648 1052 BrSerWdm - ok
19:12:18.0664 1052 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
19:12:18.0695 1052 BrUsbMdm - ok
19:12:18.0711 1052 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
19:12:18.0726 1052 BrUsbSer - ok
19:12:18.0789 1052 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
19:12:18.0836 1052 BthEnum - ok
19:12:18.0867 1052 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
19:12:18.0898 1052 BTHMODEM - ok
19:12:18.0945 1052 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
19:12:18.0976 1052 BthPan - ok
19:12:19.0023 1052 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
19:12:19.0085 1052 BTHPORT - ok
19:12:19.0116 1052 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
19:12:19.0179 1052 bthserv - ok
19:12:19.0210 1052 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
19:12:19.0241 1052 BTHUSB - ok
19:12:19.0272 1052 [ 7A2CE8C1BF4DAA1F2766E21E9CA11078 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys
19:12:19.0304 1052 btwampfl - ok
19:12:19.0335 1052 [ A75BF6802A967F5AACECC3C67FEBDF55 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
19:12:19.0350 1052 btwaudio - ok
19:12:19.0382 1052 [ D895DC213EDBDA5FCC53AAD1F1E0E63B ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
19:12:19.0397 1052 btwavdt - ok
19:12:19.0506 1052 [ 6A667ADAD3C2151131E6A478850762BE ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
19:12:19.0553 1052 btwdins - ok
19:12:19.0584 1052 [ 07096D2BC22CCB6CEA5A532DF0BE8A75 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
19:12:19.0584 1052 btwl2cap - ok
19:12:19.0616 1052 [ 6D7AA2BDE0135599C5F230D69DB3B420 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
19:12:19.0616 1052 btwrchid - ok
19:12:19.0678 1052 catchme - ok
19:12:19.0709 1052 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:12:19.0772 1052 cdfs - ok
19:12:19.0818 1052 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:12:19.0850 1052 cdrom - ok
19:12:19.0896 1052 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
19:12:19.0959 1052 CertPropSvc - ok
19:12:20.0006 1052 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
19:12:20.0052 1052 circlass - ok
19:12:20.0084 1052 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
19:12:20.0099 1052 CLFS - ok
19:12:20.0193 1052 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:12:20.0224 1052 clr_optimization_v2.0.50727_32 - ok
19:12:20.0271 1052 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:12:20.0286 1052 clr_optimization_v2.0.50727_64 - ok
19:12:20.0380 1052 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:12:20.0396 1052 clr_optimization_v4.0.30319_32 - ok
19:12:20.0442 1052 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:12:20.0458 1052 clr_optimization_v4.0.30319_64 - ok
19:12:20.0489 1052 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
19:12:20.0520 1052 CmBatt - ok
19:12:20.0552 1052 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:12:20.0552 1052 cmdide - ok
19:12:20.0614 1052 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
19:12:20.0645 1052 CNG - ok
19:12:20.0708 1052 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
19:12:20.0723 1052 Compbatt - ok
19:12:20.0770 1052 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
19:12:20.0786 1052 CompositeBus - ok
19:12:20.0801 1052 COMSysApp - ok
19:12:20.0832 1052 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
19:12:20.0848 1052 crcdisk - ok
19:12:20.0895 1052 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:12:20.0942 1052 CryptSvc - ok
19:12:20.0988 1052 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:12:21.0082 1052 DcomLaunch - ok
19:12:21.0113 1052 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
19:12:21.0207 1052 defragsvc - ok
19:12:21.0222 1052 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:12:21.0254 1052 DfsC - ok
19:12:21.0332 1052 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
19:12:21.0347 1052 dg_ssudbus - ok
19:12:21.0410 1052 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
19:12:21.0425 1052 Dhcp - ok
19:12:21.0456 1052 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
19:12:21.0488 1052 discache - ok
19:12:21.0519 1052 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
19:12:21.0519 1052 Disk - ok
19:12:21.0566 1052 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:12:21.0566 1052 Dnscache - ok
19:12:21.0612 1052 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
19:12:21.0675 1052 dot3svc - ok
19:12:21.0706 1052 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
19:12:21.0768 1052 DPS - ok
19:12:21.0831 1052 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:12:21.0862 1052 drmkaud - ok
19:12:21.0909 1052 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:12:21.0956 1052 DXGKrnl - ok
19:12:21.0987 1052 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
19:12:22.0034 1052 EapHost - ok
19:12:22.0143 1052 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
19:12:22.0268 1052 ebdrv - ok
19:12:22.0299 1052 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
19:12:22.0314 1052 EFS - ok
19:12:22.0392 1052 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:12:22.0424 1052 ehRecvr - ok
19:12:22.0439 1052 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
19:12:22.0455 1052 ehSched - ok
19:12:22.0533 1052 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
19:12:22.0564 1052 elxstor - ok
19:12:22.0580 1052 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:12:22.0611 1052 ErrDev - ok
19:12:22.0673 1052 [ 0C8324462B9791A1ECE2A329A7378A55 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
19:12:22.0689 1052 ETD - ok
19:12:22.0736 1052 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
19:12:22.0814 1052 EventSystem - ok
19:12:22.0845 1052 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
19:12:22.0892 1052 exfat - ok
19:12:22.0923 1052 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:12:23.0001 1052 fastfat - ok
19:12:23.0063 1052 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
19:12:23.0094 1052 Fax - ok
19:12:23.0126 1052 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
19:12:23.0157 1052 fdc - ok
19:12:23.0188 1052 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
19:12:23.0282 1052 fdPHost - ok
19:12:23.0313 1052 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
19:12:23.0375 1052 FDResPub - ok
19:12:23.0422 1052 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:12:23.0438 1052 FileInfo - ok
19:12:23.0453 1052 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:12:23.0516 1052 Filetrace - ok
19:12:23.0547 1052 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
19:12:23.0578 1052 flpydisk - ok
19:12:23.0625 1052 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:12:23.0656 1052 FltMgr - ok
19:12:23.0703 1052 [ 5B92E2B067F64DC53698EB84966B3F0D ] FontCache C:\Windows\system32\FntCache.dll
19:12:23.0750 1052 FontCache - ok
19:12:23.0812 1052 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:12:23.0828 1052 FontCache3.0.0.0 - ok
19:12:23.0843 1052 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:12:23.0874 1052 FsDepends - ok
19:12:23.0906 1052 [ 2BF3B36B96D015AF666B6AA63AE2E38F ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
19:12:23.0921 1052 fssfltr - ok
19:12:24.0030 1052 [ 45B52394F9624237F33A8A3D73C0B221 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
19:12:24.0077 1052 fsssvc - ok
19:12:24.0108 1052 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:12:24.0124 1052 Fs_Rec - ok
19:12:24.0171 1052 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:12:24.0202 1052 fvevol - ok
19:12:24.0218 1052 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
19:12:24.0233 1052 gagp30kx - ok
19:12:24.0296 1052 [ 521A469CAF61F00E1DE081CC2099C1D6 ] GameConsoleService C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
19:12:24.0311 1052 GameConsoleService - ok
19:12:24.0358 1052 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
19:12:24.0467 1052 gpsvc - ok
19:12:24.0561 1052 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:12:24.0576 1052 gupdate - ok
19:12:24.0576 1052 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:12:24.0592 1052 gupdatem - ok
19:12:24.0639 1052 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:12:24.0670 1052 hcw85cir - ok
19:12:24.0717 1052 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:12:24.0764 1052 HdAudAddService - ok
19:12:24.0795 1052 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
19:12:24.0826 1052 HDAudBus - ok
19:12:24.0857 1052 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
19:12:24.0873 1052 HECIx64 - ok
19:12:24.0904 1052 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
19:12:24.0951 1052 HidBatt - ok
19:12:24.0966 1052 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
19:12:25.0013 1052 HidBth - ok
19:12:25.0044 1052 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
19:12:25.0091 1052 HidIr - ok
19:12:25.0122 1052 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
19:12:25.0169 1052 hidserv - ok
19:12:25.0216 1052 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:12:25.0232 1052 HidUsb - ok
19:12:25.0294 1052 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:12:25.0356 1052 hkmsvc - ok
19:12:25.0388 1052 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:12:25.0419 1052 HomeGroupListener - ok
19:12:25.0450 1052 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:12:25.0481 1052 HomeGroupProvider - ok
19:12:25.0528 1052 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:12:25.0528 1052 HpSAMD - ok
19:12:25.0590 1052 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:12:25.0637 1052 HTTP - ok
19:12:25.0668 1052 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:12:25.0684 1052 hwpolicy - ok
19:12:25.0715 1052 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:12:25.0746 1052 i8042prt - ok
19:12:25.0778 1052 [ A5F72BB0D024E7E463344105BE613AE4 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
19:12:25.0793 1052 iaStor - ok
19:12:25.0840 1052 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:12:25.0887 1052 iaStorV - ok
19:12:25.0949 1052 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:12:25.0980 1052 idsvc - ok
19:12:26.0168 1052 [ A87261EF1546325B559374F5689CF5BC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
19:12:26.0355 1052 igfx - ok
19:12:26.0386 1052 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
19:12:26.0402 1052 iirsp - ok
19:12:26.0448 1052 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
19:12:26.0542 1052 IKEEXT - ok
19:12:26.0589 1052 [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys
19:12:26.0620 1052 Impcd - ok
19:12:26.0714 1052 [ 5F35FE198EE7818221414776F8413AB0 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
19:12:26.0792 1052 IntcAzAudAddService - ok
19:12:26.0807 1052 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
19:12:26.0823 1052 intelide - ok
19:12:26.0838 1052 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:12:26.0885 1052 intelppm - ok
19:12:26.0916 1052 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:12:26.0963 1052 IPBusEnum - ok
19:12:26.0994 1052 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:12:27.0072 1052 IpFilterDriver - ok
19:12:27.0135 1052 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:12:27.0182 1052 iphlpsvc - ok
19:12:27.0228 1052 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:12:27.0260 1052 IPMIDRV - ok
19:12:27.0291 1052 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:12:27.0353 1052 IPNAT - ok
19:12:27.0384 1052 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:12:27.0400 1052 IRENUM - ok
19:12:27.0447 1052 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:12:27.0462 1052 isapnp - ok
19:12:27.0509 1052 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:12:27.0525 1052 iScsiPrt - ok
19:12:27.0572 1052 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:12:27.0572 1052 kbdclass - ok
19:12:27.0618 1052 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
19:12:27.0650 1052 kbdhid - ok
19:12:27.0665 1052 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
19:12:27.0696 1052 KeyIso - ok
19:12:27.0712 1052 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:12:27.0728 1052 KSecDD - ok
19:12:27.0774 1052 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:12:27.0790 1052 KSecPkg - ok
19:12:27.0837 1052 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
19:12:27.0868 1052 ksthunk - ok
19:12:27.0915 1052 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
19:12:27.0977 1052 KtmRm - ok
19:12:28.0040 1052 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
19:12:28.0118 1052 LanmanServer - ok
19:12:28.0149 1052 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:12:28.0196 1052 LanmanWorkstation - ok
19:12:28.0211 1052 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:12:28.0258 1052 lltdio - ok
19:12:28.0289 1052 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:12:28.0352 1052 lltdsvc - ok
19:12:28.0367 1052 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:12:28.0430 1052 lmhosts - ok
19:12:28.0523 1052 [ 85C7497997BA8B7C1728B12199616747 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:12:28.0539 1052 LMS - ok
19:12:28.0586 1052 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
19:12:28.0617 1052 LSI_FC - ok
19:12:28.0617 1052 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
19:12:28.0632 1052 LSI_SAS - ok
19:12:28.0648 1052 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:12:28.0664 1052 LSI_SAS2 - ok
19:12:28.0679 1052 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:12:28.0679 1052 LSI_SCSI - ok
19:12:28.0710 1052 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
19:12:28.0773 1052 luafv - ok
19:12:28.0820 1052 [ 024DA28053D57E9E32BEE52600576BBB ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus64.sys
19:12:28.0866 1052 MarvinBus - ok
19:12:28.0913 1052 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:12:28.0929 1052 Mcx2Svc - ok
19:12:28.0944 1052 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
19:12:28.0960 1052 megasas - ok
19:12:29.0007 1052 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
19:12:29.0022 1052 MegaSR - ok
19:12:29.0054 1052 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
19:12:29.0100 1052 MMCSS - ok
19:12:29.0116 1052 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
19:12:29.0163 1052 Modem - ok
19:12:29.0178 1052 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:12:29.0210 1052 monitor - ok
19:12:29.0241 1052 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:12:29.0241 1052 mouclass - ok
19:12:29.0256 1052 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:12:29.0288 1052 mouhid - ok
19:12:29.0334 1052 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:12:29.0350 1052 mountmgr - ok
19:12:29.0381 1052 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
19:12:29.0397 1052 mpio - ok
19:12:29.0412 1052 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:12:29.0459 1052 mpsdrv - ok
19:12:29.0506 1052 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:12:29.0600 1052 MpsSvc - ok
19:12:29.0631 1052 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:12:29.0678 1052 MRxDAV - ok
19:12:29.0724 1052 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:12:29.0740 1052 mrxsmb - ok
19:12:29.0771 1052 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:12:29.0802 1052 mrxsmb10 - ok
19:12:29.0818 1052 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:12:29.0834 1052 mrxsmb20 - ok
19:12:29.0865 1052 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
19:12:29.0880 1052 msahci - ok
19:12:29.0896 1052 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:12:29.0912 1052 msdsm - ok
19:12:29.0927 1052 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
19:12:29.0974 1052 MSDTC - ok
19:12:30.0021 1052 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:12:30.0083 1052 Msfs - ok
19:12:30.0114 1052 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:12:30.0161 1052 mshidkmdf - ok
19:12:30.0192 1052 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:12:30.0208 1052 msisadrv - ok
19:12:30.0239 1052 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:12:30.0317 1052 MSiSCSI - ok
19:12:30.0317 1052 msiserver - ok
19:12:30.0348 1052 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:12:30.0426 1052 MSKSSRV - ok
19:12:30.0442 1052 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:12:30.0489 1052 MSPCLOCK - ok
19:12:30.0504 1052 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:12:30.0551 1052 MSPQM - ok
19:12:30.0598 1052 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:12:30.0614 1052 MsRPC - ok
19:12:30.0660 1052 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
19:12:30.0660 1052 mssmbios - ok
19:12:30.0692 1052 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:12:30.0770 1052 MSTEE - ok
19:12:30.0785 1052 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
19:12:30.0801 1052 MTConfig - ok
19:12:30.0816 1052 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
19:12:30.0832 1052 Mup - ok
19:12:30.0863 1052 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
19:12:30.0910 1052 napagent - ok
19:12:30.0957 1052 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:12:30.0988 1052 NativeWifiP - ok
19:12:31.0050 1052 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:12:31.0097 1052 NDIS - ok
19:12:31.0128 1052 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:12:31.0160 1052 NdisCap - ok
19:12:31.0175 1052 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:12:31.0238 1052 NdisTapi - ok
19:12:31.0284 1052 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:12:31.0347 1052 Ndisuio - ok
19:12:31.0378 1052 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:12:31.0456 1052 NdisWan - ok
19:12:31.0487 1052 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:12:31.0581 1052 NDProxy - ok
19:12:31.0612 1052 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:12:31.0690 1052 NetBIOS - ok
19:12:31.0721 1052 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:12:31.0768 1052 NetBT - ok
19:12:31.0799 1052 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
19:12:31.0799 1052 Netlogon - ok
19:12:31.0846 1052 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
19:12:31.0908 1052 Netman - ok
19:12:31.0940 1052 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
19:12:32.0002 1052 netprofm - ok
19:12:32.0033 1052 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:12:32.0049 1052 NetTcpPortSharing - ok
19:12:32.0064 1052 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
19:12:32.0080 1052 nfrd960 - ok
19:12:32.0142 1052 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:12:32.0174 1052 NlaSvc - ok
19:12:32.0205 1052 [ 4903177FC90E77ABEB19021451E9475E ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
19:12:32.0267 1052 nmwcd - ok
19:12:32.0298 1052 [ E6844A4C97E5409BBE24BB4ED000320D ] nmwcdc C:\Windows\system32\drivers\ccdcmbox64.sys
19:12:32.0361 1052 nmwcdc - ok
19:12:32.0408 1052 [ F59F8CF59F7905622686637177E2A828 ] nmwcdnsucx64 C:\Windows\system32\drivers\nmwcdnsucx64.sys
19:12:32.0454 1052 nmwcdnsucx64 - ok
19:12:32.0501 1052 [ A0E7F80157AF77B1CEAA8ADD3A3E7D85 ] nmwcdnsux64 C:\Windows\system32\drivers\nmwcdnsux64.sys
19:12:32.0564 1052 nmwcdnsux64 - ok
19:12:32.0579 1052 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:12:32.0626 1052 Npfs - ok
19:12:32.0673 1052 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
19:12:32.0720 1052 nsi - ok
19:12:32.0735 1052 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:12:32.0782 1052 nsiproxy - ok
19:12:32.0844 1052 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:12:32.0922 1052 Ntfs - ok
19:12:32.0954 1052 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
19:12:33.0000 1052 Null - ok
19:12:33.0047 1052 [ 285ACEC1B13A15BA520AAE06BACB9CFF ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
19:12:33.0063 1052 nusb3hub - ok
19:12:33.0094 1052 [ F6D625FF7B56BB6EA063F0D3A5BBC996 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
19:12:33.0110 1052 nusb3xhc - ok
19:12:33.0156 1052 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
19:12:33.0172 1052 NVHDA - ok
19:12:33.0406 1052 [ 26AA3C7E6E1DB7107BF93503F6F57E88 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:12:33.0562 1052 nvlddmkm - ok
19:12:33.0609 1052 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:12:33.0609 1052 nvraid - ok
19:12:33.0656 1052 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:12:33.0671 1052 nvstor - ok
19:12:33.0749 1052 [ A83AC04D672567CAF8BE7A4D73C0B850 ] nvsvc C:\Windows\system32\nvvsvc.exe
19:12:33.0796 1052 nvsvc - ok
19:12:33.0858 1052 [ FB660F80BDC4F13D594996976AFAECD9 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
19:12:33.0905 1052 nvUpdatusService - ok
19:12:33.0936 1052 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:12:33.0952 1052 nv_agp - ok
19:12:33.0983 1052 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:12:34.0014 1052 ohci1394 - ok
19:12:34.0092 1052 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:12:34.0108 1052 ose - ok
19:12:34.0139 1052 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:12:34.0170 1052 p2pimsvc - ok
19:12:34.0202 1052 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
19:12:34.0248 1052 p2psvc - ok
19:12:34.0280 1052 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
19:12:34.0311 1052 Parport - ok
19:12:34.0342 1052 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:12:34.0358 1052 partmgr - ok
19:12:34.0420 1052 [ 5EACB8A19CAD7057806FBBF9550165E1 ] PcaSp60 C:\Windows\system32\DRIVERS\PcaSp60.sys
19:12:34.0451 1052 PcaSp60 - ok
19:12:34.0482 1052 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:12:34.0514 1052 PcaSvc - ok
19:12:34.0545 1052 [ 3FDE033DFB0D07F8B7D5C9A3044AA121 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
19:12:34.0560 1052 pccsmcfd - ok
19:12:34.0592 1052 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
19:12:34.0623 1052 pci - ok
19:12:34.0654 1052 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
19:12:34.0685 1052 pciide - ok
19:12:34.0716 1052 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
19:12:34.0732 1052 pcmcia - ok
19:12:34.0794 1052 [ AF7CE12C4F3DC8CB2B07685C916BBCFE ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
19:12:34.0810 1052 pcouffin - ok
19:12:34.0810 1052 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
19:12:34.0826 1052 pcw - ok
19:12:34.0841 1052 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:12:34.0888 1052 PEAUTH - ok
19:12:34.0982 1052 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
19:12:35.0028 1052 PerfHost - ok
19:12:35.0091 1052 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
19:12:35.0200 1052 pla - ok
19:12:35.0247 1052 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:12:35.0262 1052 PlugPlay - ok
19:12:35.0278 1052 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:12:35.0294 1052 PNRPAutoReg - ok
19:12:35.0309 1052 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:12:35.0325 1052 PNRPsvc - ok
19:12:35.0372 1052 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:12:35.0434 1052 PolicyAgent - ok
19:12:35.0465 1052 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
19:12:35.0543 1052 Power - ok
19:12:35.0574 1052 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:12:35.0621 1052 PptpMiniport - ok
19:12:35.0652 1052 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
19:12:35.0684 1052 Processor - ok
19:12:35.0730 1052 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
19:12:35.0762 1052 ProfSvc - ok
19:12:35.0777 1052 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:12:35.0793 1052 ProtectedStorage - ok
19:12:35.0840 1052 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:12:35.0886 1052 Psched - ok
19:12:35.0918 1052 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
19:12:35.0980 1052 ql2300 - ok
19:12:36.0011 1052 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
19:12:36.0027 1052 ql40xx - ok
19:12:36.0042 1052 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
19:12:36.0058 1052 QWAVE - ok
19:12:36.0089 1052 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:12:36.0105 1052 QWAVEdrv - ok
19:12:36.0105 1052 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:12:36.0152 1052 RasAcd - ok
19:12:36.0183 1052 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:12:36.0214 1052 RasAgileVpn - ok
19:12:36.0245 1052 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
19:12:36.0323 1052 RasAuto - ok
19:12:36.0354 1052 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:12:36.0417 1052 Rasl2tp - ok
19:12:36.0464 1052 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
19:12:36.0557 1052 RasMan - ok
19:12:36.0588 1052 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:12:36.0651 1052 RasPppoe - ok
19:12:36.0682 1052 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:12:36.0729 1052 RasSstp - ok
19:12:36.0760 1052 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:12:36.0838 1052 rdbss - ok
19:12:36.0854 1052 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
19:12:36.0869 1052 rdpbus - ok
19:12:36.0900 1052 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:12:36.0932 1052 RDPCDD - ok
19:12:36.0947 1052 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:12:37.0025 1052 RDPENCDD - ok
19:12:37.0056 1052 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:12:37.0103 1052 RDPREFMP - ok
19:12:37.0181 1052 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
19:12:37.0212 1052 RdpVideoMiniport - ok
19:12:37.0244 1052 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:12:37.0275 1052 RDPWD - ok
19:12:37.0306 1052 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:12:37.0337 1052 rdyboost - ok
19:12:37.0353 1052 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:12:37.0415 1052 RemoteAccess - ok
19:12:37.0431 1052 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:12:37.0493 1052 RemoteRegistry - ok
19:12:37.0556 1052 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
19:12:37.0602 1052 RFCOMM - ok
19:12:37.0665 1052 [ 7CCAEBCAB6FC1ED0206C07E083E79207 ] RichVideo C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
19:12:37.0680 1052 RichVideo - ok
19:12:37.0712 1052 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:12:37.0743 1052 RpcEptMapper - ok
19:12:37.0774 1052 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
19:12:37.0805 1052 RpcLocator - ok
19:12:37.0836 1052 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
19:12:37.0883 1052 RpcSs - ok
19:12:37.0914 1052 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:12:37.0961 1052 rspndr - ok
19:12:38.0008 1052 [ BAEFEE35D27A5440D35092CE10267BEC ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
19:12:38.0024 1052 RTL8167 - ok
19:12:38.0039 1052 [ 62DB6CC4B0818F1B5F3441241B098F12 ] SABI C:\Windows\system32\Drivers\SABI.sys
19:12:38.0070 1052 SABI - ok
19:12:38.0086 1052 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
19:12:38.0102 1052 SamSs - ok
19:12:38.0133 1052 [ D641337B75B9A9D5AE10687AA1097755 ] Samsung UPD Service C:\Windows\System32\SUPDSvc.exe
19:12:38.0148 1052 Samsung UPD Service - ok
19:12:38.0226 1052 [ 328100AF2EFD951EAB657384EC361B6F ] SamsungAllShareV2.0 C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
19:12:38.0226 1052 SamsungAllShareV2.0 - ok
19:12:38.0273 1052 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:12:38.0289 1052 sbp2port - ok
19:12:38.0320 1052 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:12:38.0351 1052 SCardSvr - ok
19:12:38.0382 1052 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:12:38.0445 1052 scfilter - ok
19:12:38.0507 1052 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
19:12:38.0585 1052 Schedule - ok
19:12:38.0616 1052 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:12:38.0663 1052 SCPolicySvc - ok
19:12:38.0710 1052 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:12:38.0741 1052 SDRSVC - ok
19:12:38.0772 1052 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:12:38.0882 1052 secdrv - ok
19:12:38.0928 1052 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
19:12:38.0975 1052 seclogon - ok
19:12:39.0006 1052 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
19:12:39.0038 1052 SENS - ok
19:12:39.0053 1052 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:12:39.0084 1052 SensrSvc - ok
19:12:39.0131 1052 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
19:12:39.0162 1052 Serenum - ok
19:12:39.0194 1052 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
19:12:39.0225 1052 Serial - ok
19:12:39.0287 1052 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
19:12:39.0318 1052 sermouse - ok
19:12:39.0412 1052 [ 9BDE8F1F5D060E912FCF9FB58B71CBC1 ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
19:12:39.0443 1052 ServiceLayer - ok
19:12:39.0490 1052 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
19:12:39.0552 1052 SessionEnv - ok
19:12:39.0584 1052 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:12:39.0599 1052 sffdisk - ok
19:12:39.0615 1052 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:12:39.0615 1052 sffp_mmc - ok
19:12:39.0630 1052 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:12:39.0646 1052 sffp_sd - ok
19:12:39.0677 1052 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
19:12:39.0708 1052 sfloppy - ok
19:12:39.0755 1052 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:12:39.0802 1052 SharedAccess - ok
19:12:39.0849 1052 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:12:39.0911 1052 ShellHWDetection - ok
19:12:39.0958 1052 [ 1980FE1F5A32067DAD1D8776B63C2669 ] SimpleSlideShowServer C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
19:12:39.0974 1052 SimpleSlideShowServer - ok
19:12:40.0005 1052 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:12:40.0020 1052 SiSRaid2 - ok
19:12:40.0052 1052 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
19:12:40.0067 1052 SiSRaid4 - ok
19:12:40.0239 1052 [ 183F04C6742902F33039913A96F5B574 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
19:12:40.0301 1052 Skype C2C Service - ok
19:12:40.0395 1052 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:12:40.0410 1052 SkypeUpdate - ok
19:12:40.0442 1052 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:12:40.0488 1052 Smb - ok
19:12:40.0535 1052 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:12:40.0566 1052 SNMPTRAP - ok
19:12:40.0598 1052 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
19:12:40.0613 1052 spldr - ok
19:12:40.0676 1052 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
19:12:40.0691 1052 Spooler - ok
19:12:40.0800 1052 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
19:12:40.0863 1052 sppsvc - ok
19:12:40.0894 1052 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:12:40.0925 1052 sppuinotify - ok
19:12:41.0003 1052 [ D6AB7C13FCDD2E4CAC35244D2C172D9A ] sptd C:\Windows\System32\Drivers\sptd.sys
19:12:41.0034 1052 sptd - ok
19:12:41.0112 1052 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
19:12:41.0190 1052 srv - ok
19:12:41.0253 1052 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:12:41.0315 1052 srv2 - ok
19:12:41.0362 1052 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:12:41.0378 1052 srvnet - ok
19:12:41.0424 1052 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:12:41.0471 1052 SSDPSRV - ok
19:12:41.0487 1052 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:12:41.0534 1052 SstpSvc - ok
19:12:41.0580 1052 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
19:12:41.0596 1052 ssudmdm - ok
19:12:41.0612 1052 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
19:12:41.0627 1052 stexstor - ok
19:12:41.0674 1052 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
19:12:41.0705 1052 StillCam - ok
19:12:41.0768 1052 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
19:12:41.0877 1052 stisvc - ok
19:12:41.0924 1052 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
19:12:41.0939 1052 swenum - ok
19:12:41.0986 1052 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
19:12:42.0017 1052 swprv - ok
19:12:42.0080 1052 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
19:12:42.0158 1052 SysMain - ok
19:12:42.0189 1052 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:12:42.0236 1052 TabletInputService - ok
19:12:42.0251 1052 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
19:12:42.0329 1052 TapiSrv - ok
19:12:42.0360 1052 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
19:12:42.0407 1052 TBS - ok
19:12:42.0454 1052 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:12:42.0516 1052 Tcpip - ok
19:12:42.0548 1052 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:12:42.0594 1052 TCPIP6 - ok
19:12:42.0626 1052 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:12:42.0626 1052 tcpipreg - ok
19:12:42.0657 1052 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:12:42.0672 1052 TDPIPE - ok
19:12:42.0704 1052 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:12:42.0719 1052 TDTCP - ok
19:12:42.0782 1052 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:12:42.0844 1052 tdx - ok
19:12:42.0875 1052 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
19:12:42.0875 1052 TermDD - ok
19:12:42.0922 1052 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
19:12:42.0984 1052 TermService - ok
19:12:43.0016 1052 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
19:12:43.0047 1052 Themes - ok
19:12:43.0078 1052 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
19:12:43.0125 1052 THREADORDER - ok
19:12:43.0140 1052 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
19:12:43.0172 1052 TrkWks - ok
19:12:43.0234 1052 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:12:43.0312 1052 TrustedInstaller - ok
19:12:43.0343 1052 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:12:43.0390 1052 tssecsrv - ok
19:12:43.0452 1052 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:12:43.0484 1052 TsUsbFlt - ok
19:12:43.0530 1052 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:12:43.0608 1052 tunnel - ok
19:12:43.0655 1052 [ B355581A9DA34C92E2DBAFA410D2F829 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys
19:12:43.0655 1052 TurboB - ok
19:12:43.0733 1052 [ 6564E84B1522C12EA1C3A181ED03276F ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe
19:12:43.0749 1052 TurboBoost - ok
19:12:43.0780 1052 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
19:12:43.0811 1052 uagp35 - ok
19:12:43.0858 1052 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:12:43.0936 1052 udfs - ok
19:12:43.0983 1052 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:12:43.0983 1052 UI0Detect - ok
19:12:44.0030 1052 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:12:44.0045 1052 uliagpkx - ok
19:12:44.0076 1052 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:12:44.0092 1052 umbus - ok
19:12:44.0108 1052 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
19:12:44.0139 1052 UmPass - ok
19:12:44.0264 1052 [ 4735B3050C0D6F9DC571451298C54FA0 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:12:44.0357 1052 UNS - ok
19:12:44.0388 1052 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
19:12:44.0420 1052 upnphost - ok
19:12:44.0466 1052 [ 907F50B8695DAA65A9445D27AD306E65 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
19:12:44.0482 1052 upperdev - ok
19:12:44.0529 1052 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:12:44.0544 1052 usbccgp - ok
19:12:44.0576 1052 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:12:44.0591 1052 usbcir - ok
19:12:44.0622 1052 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
19:12:44.0638 1052 usbehci - ok
19:12:44.0669 1052 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:12:44.0685 1052 usbhub - ok
19:12:44.0716 1052 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:12:44.0732 1052 usbohci - ok
19:12:44.0763 1052 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:12:44.0810 1052 usbprint - ok
19:12:44.0841 1052 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
19:12:44.0888 1052 usbscan - ok
19:12:44.0950 1052 [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser C:\Windows\system32\drivers\usbser.sys
19:12:44.0981 1052 usbser - ok
19:12:45.0012 1052 [ 3F7498527B48657091C355F683BEB0DD ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
19:12:45.0075 1052 UsbserFilt - ok
19:12:45.0090 1052 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:12:45.0106 1052 USBSTOR - ok
19:12:45.0122 1052 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:12:45.0153 1052 usbuhci - ok
19:12:45.0215 1052 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
19:12:45.0246 1052 usbvideo - ok
19:12:45.0278 1052 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
19:12:45.0309 1052 usb_rndisx - ok
19:12:45.0340 1052 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
19:12:45.0402 1052 UxSms - ok
19:12:45.0418 1052 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
19:12:45.0418 1052 VaultSvc - ok
19:12:45.0465 1052 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:12:45.0480 1052 vdrvroot - ok
19:12:45.0527 1052 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
19:12:45.0590 1052 vds - ok
19:12:45.0636 1052 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:12:45.0652 1052 vga - ok
19:12:45.0668 1052 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
19:12:45.0714 1052 VgaSave - ok
19:12:45.0746 1052 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:12:45.0761 1052 vhdmp - ok
19:12:45.0792 1052 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
19:12:45.0808 1052 viaide - ok
19:12:45.0839 1052 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:12:45.0870 1052 volmgr - ok
19:12:45.0902 1052 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:12:45.0917 1052 volmgrx - ok
19:12:45.0933 1052 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:12:45.0948 1052 volsnap - ok
19:12:45.0980 1052 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
19:12:45.0980 1052 vsmraid - ok
19:12:46.0058 1052 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
19:12:46.0167 1052 VSS - ok
19:12:46.0183 1052 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:12:46.0198 1052 vwifibus - ok
19:12:46.0229 1052 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:12:46.0261 1052 vwififlt - ok
19:12:46.0307 1052 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
19:12:46.0323 1052 vwifimp - ok
19:12:46.0354 1052 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
19:12:46.0401 1052 W32Time - ok
19:12:46.0417 1052 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
19:12:46.0448 1052 WacomPen - ok
19:12:46.0510 1052 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:12:46.0541 1052 WANARP - ok
19:12:46.0541 1052 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:12:46.0573 1052 Wanarpv6 - ok
19:12:46.0651 1052 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
19:12:46.0713 1052 WatAdminSvc - ok
19:12:46.0760 1052 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
19:12:46.0869 1052 wbengine - ok
19:12:46.0900 1052 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:12:46.0947 1052 WbioSrvc - ok
19:12:46.0994 1052 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:12:47.0041 1052 wcncsvc - ok
19:12:47.0056 1052 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:12:47.0072 1052 WcsPlugInService - ok
19:12:47.0103 1052 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
19:12:47.0119 1052 Wd - ok
19:12:47.0165 1052 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:12:47.0181 1052 Wdf01000 - ok
19:12:47.0197 1052 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:12:47.0228 1052 WdiServiceHost - ok
19:12:47.0243 1052 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:12:47.0259 1052 WdiSystemHost - ok
19:12:47.0290 1052 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
19:12:47.0321 1052 WebClient - ok
19:12:47.0353 1052 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:12:47.0446 1052 Wecsvc - ok
19:12:47.0462 1052 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:12:47.0509 1052 wercplsupport - ok
19:12:47.0540 1052 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
19:12:47.0587 1052 WerSvc - ok
19:12:47.0618 1052 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:12:47.0696 1052 WfpLwf - ok
19:12:47.0711 1052 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:12:47.0711 1052 WIMMount - ok
19:12:47.0743 1052 WinDefend - ok
19:12:47.0758 1052 WinHttpAutoProxySvc - ok
19:12:47.0821 1052 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:12:47.0867 1052 Winmgmt - ok
19:12:47.0961 1052 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
19:12:48.0070 1052 WinRM - ok
19:12:48.0133 1052 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
19:12:48.0148 1052 WinUsb - ok
19:12:48.0195 1052 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
19:12:48.0257 1052 Wlansvc - ok
19:12:48.0491 1052 [ 98F138897EF4246381D197CB81846D62 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:12:48.0632 1052 wlidsvc - ok
19:12:48.0663 1052 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:12:48.0694 1052 WmiAcpi - ok
19:12:48.0725 1052 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:12:48.0741 1052 wmiApSrv - ok
19:12:48.0772 1052 WMPNetworkSvc - ok
19:12:48.0803 1052 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:12:48.0819 1052 WPCSvc - ok
19:12:48.0866 1052 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:12:48.0897 1052 WPDBusEnum - ok
19:12:48.0913 1052 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:12:48.0991 1052 ws2ifsl - ok
19:12:49.0006 1052 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
19:12:49.0053 1052 wscsvc - ok
19:12:49.0053 1052 WSearch - ok
19:12:49.0131 1052 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
19:12:49.0240 1052 wuauserv - ok
19:12:49.0256 1052 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:12:49.0303 1052 WudfPf - ok
19:12:49.0334 1052 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:12:49.0365 1052 WUDFRd - ok
19:12:49.0396 1052 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:12:49.0412 1052 wudfsvc - ok
19:12:49.0443 1052 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
19:12:49.0474 1052 WwanSvc - ok
19:12:49.0521 1052 [ 4647FDA6E21B18824D6073801177F4F7 ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys
19:12:49.0552 1052 yukonw7 - ok

Re: Podivne chování

Napsal: 21 led 2013 19:26
od miromen
2.čast tdsskiller logu....

19:12:49.0568 1052 ================ Scan global ===============================
19:12:49.0583 1052 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
19:12:49.0615 1052 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
19:12:49.0630 1052 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
19:12:49.0646 1052 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
19:12:49.0677 1052 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
19:12:49.0693 1052 [Global] - ok
19:12:49.0693 1052 ================ Scan MBR ==================================
19:12:49.0708 1052 [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
19:12:50.0207 1052 \Device\Harddisk0\DR0 - ok
19:12:50.0207 1052 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
19:12:50.0769 1052 \Device\Harddisk1\DR1 - ok
19:12:50.0769 1052 ================ Scan VBR ==================================
19:12:50.0769 1052 [ 8470E90E03DE6F5EA1F052795BD47D56 ] \Device\Harddisk0\DR0\Partition1
19:12:50.0769 1052 \Device\Harddisk0\DR0\Partition1 - ok
19:12:50.0816 1052 [ 1EEE6A02F0696528029D45882113C867 ] \Device\Harddisk0\DR0\Partition2
19:12:50.0816 1052 \Device\Harddisk0\DR0\Partition2 - ok
19:12:50.0847 1052 [ 30843A274BE9011AFBCC1965BCC08FDC ] \Device\Harddisk0\DR0\Partition3
19:12:50.0847 1052 \Device\Harddisk0\DR0\Partition3 - ok
19:12:50.0847 1052 [ DC7E43CB30EC98BF322D35CFADF05FF9 ] \Device\Harddisk1\DR1\Partition1
19:12:50.0847 1052 \Device\Harddisk1\DR1\Partition1 - ok
19:12:50.0847 1052 ============================================================
19:12:50.0847 1052 Scan finished
19:12:50.0847 1052 ============================================================
19:12:50.0863 3480 Detected object count: 0
19:12:50.0863 3480 Actual detected object count: 0
19:14:10.0235 0880 ============================================================
19:14:10.0235 0880 Scan started
19:14:10.0235 0880 Mode: Manual; SigCheck; TDLFS;
19:14:10.0235 0880 ============================================================
19:14:10.0579 0880 ================ Scan system memory ========================
19:14:10.0579 0880 System memory - ok
19:14:10.0579 0880 ================ Scan services =============================
19:14:10.0781 0880 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
19:14:10.0813 0880 1394ohci - ok
19:14:10.0859 0880 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
19:14:10.0859 0880 ACPI - ok
19:14:10.0891 0880 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
19:14:10.0906 0880 AcpiPmi - ok
19:14:10.0984 0880 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:14:11.0000 0880 AdobeARMservice - ok
19:14:11.0062 0880 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
19:14:11.0093 0880 adp94xx - ok
19:14:11.0109 0880 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
19:14:11.0125 0880 adpahci - ok
19:14:11.0140 0880 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
19:14:11.0156 0880 adpu320 - ok
19:14:11.0187 0880 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:14:11.0218 0880 AeLookupSvc - ok
19:14:11.0249 0880 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
19:14:11.0281 0880 AFD - ok
19:14:11.0312 0880 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:14:11.0327 0880 agp440 - ok
19:14:11.0343 0880 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
19:14:11.0374 0880 ALG - ok
19:14:11.0374 0880 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
19:14:11.0390 0880 aliide - ok
19:14:11.0421 0880 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
19:14:11.0437 0880 amdide - ok
19:14:11.0437 0880 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
19:14:11.0452 0880 AmdK8 - ok
19:14:11.0468 0880 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
19:14:11.0468 0880 AmdPPM - ok
19:14:11.0499 0880 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
19:14:11.0530 0880 amdsata - ok
19:14:11.0546 0880 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
19:14:11.0561 0880 amdsbs - ok
19:14:11.0577 0880 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
19:14:11.0577 0880 amdxata - ok
19:14:11.0624 0880 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
19:14:11.0671 0880 AppID - ok
19:14:11.0686 0880 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
19:14:11.0733 0880 AppIDSvc - ok
19:14:11.0749 0880 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
19:14:11.0780 0880 Appinfo - ok
19:14:11.0811 0880 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
19:14:11.0827 0880 arc - ok
19:14:11.0827 0880 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
19:14:11.0842 0880 arcsas - ok
19:14:11.0920 0880 ASInsHelp - ok
19:14:11.0936 0880 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:14:11.0998 0880 AsyncMac - ok
19:14:12.0029 0880 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
19:14:12.0029 0880 atapi - ok
19:14:12.0076 0880 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:14:12.0123 0880 AudioEndpointBuilder - ok
19:14:12.0154 0880 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
19:14:12.0185 0880 AudioSrv - ok
19:14:12.0217 0880 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
19:14:12.0232 0880 AxInstSV - ok
19:14:12.0263 0880 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
19:14:12.0279 0880 b06bdrv - ok
19:14:12.0310 0880 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
19:14:12.0326 0880 b57nd60a - ok
19:14:12.0466 0880 [ 43AD3D3E7674833FCA9A7C4E7180AD54 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
19:14:12.0529 0880 BCM43XX - ok
19:14:12.0575 0880 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
19:14:12.0575 0880 BDESVC - ok
19:14:12.0591 0880 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
19:14:12.0638 0880 Beep - ok
19:14:12.0685 0880 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
19:14:12.0747 0880 BFE - ok
19:14:12.0809 0880 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
19:14:12.0856 0880 BITS - ok
19:14:12.0872 0880 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
19:14:12.0887 0880 blbdrive - ok
19:14:12.0919 0880 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:14:12.0934 0880 bowser - ok
19:14:12.0950 0880 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:14:12.0965 0880 BrFiltLo - ok
19:14:12.0965 0880 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:14:12.0981 0880 BrFiltUp - ok
19:14:12.0997 0880 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
19:14:13.0043 0880 BridgeMP - ok
19:14:13.0075 0880 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
19:14:13.0090 0880 Browser - ok
19:14:13.0106 0880 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
19:14:13.0121 0880 Brserid - ok
19:14:13.0137 0880 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
19:14:13.0137 0880 BrSerWdm - ok
19:14:13.0153 0880 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
19:14:13.0168 0880 BrUsbMdm - ok
19:14:13.0184 0880 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
19:14:13.0199 0880 BrUsbSer - ok
19:14:13.0215 0880 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
19:14:13.0231 0880 BthEnum - ok
19:14:13.0246 0880 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
19:14:13.0262 0880 BTHMODEM - ok
19:14:13.0277 0880 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
19:14:13.0293 0880 BthPan - ok
19:14:13.0309 0880 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
19:14:13.0324 0880 BTHPORT - ok
19:14:13.0355 0880 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
19:14:13.0387 0880 bthserv - ok
19:14:13.0387 0880 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
19:14:13.0402 0880 BTHUSB - ok
19:14:13.0433 0880 [ 7A2CE8C1BF4DAA1F2766E21E9CA11078 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys
19:14:13.0449 0880 btwampfl - ok
19:14:13.0465 0880 [ A75BF6802A967F5AACECC3C67FEBDF55 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
19:14:13.0465 0880 btwaudio - ok
19:14:13.0480 0880 [ D895DC213EDBDA5FCC53AAD1F1E0E63B ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
19:14:13.0496 0880 btwavdt - ok
19:14:13.0574 0880 [ 6A667ADAD3C2151131E6A478850762BE ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
19:14:13.0605 0880 btwdins - ok
19:14:13.0636 0880 [ 07096D2BC22CCB6CEA5A532DF0BE8A75 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
19:14:13.0652 0880 btwl2cap - ok
19:14:13.0667 0880 [ 6D7AA2BDE0135599C5F230D69DB3B420 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
19:14:13.0683 0880 btwrchid - ok
19:14:13.0683 0880 catchme - ok
19:14:13.0699 0880 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:14:13.0745 0880 cdfs - ok
19:14:13.0777 0880 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:14:13.0792 0880 cdrom - ok
19:14:13.0823 0880 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
19:14:13.0855 0880 CertPropSvc - ok
19:14:13.0870 0880 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
19:14:13.0886 0880 circlass - ok
19:14:13.0917 0880 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
19:14:13.0917 0880 CLFS - ok
19:14:13.0995 0880 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:14:14.0011 0880 clr_optimization_v2.0.50727_32 - ok
19:14:14.0073 0880 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:14:14.0089 0880 clr_optimization_v2.0.50727_64 - ok
19:14:14.0167 0880 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:14:14.0182 0880 clr_optimization_v4.0.30319_32 - ok
19:14:14.0229 0880 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:14:14.0245 0880 clr_optimization_v4.0.30319_64 - ok
19:14:14.0276 0880 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
19:14:14.0291 0880 CmBatt - ok
19:14:14.0323 0880 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:14:14.0338 0880 cmdide - ok
19:14:14.0385 0880 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
19:14:14.0416 0880 CNG - ok
19:14:14.0432 0880 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
19:14:14.0432 0880 Compbatt - ok
19:14:14.0479 0880 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
19:14:14.0494 0880 CompositeBus - ok
19:14:14.0510 0880 COMSysApp - ok
19:14:14.0510 0880 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
19:14:14.0525 0880 crcdisk - ok
19:14:14.0572 0880 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:14:14.0588 0880 CryptSvc - ok
19:14:14.0635 0880 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:14:14.0697 0880 DcomLaunch - ok
19:14:14.0713 0880 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
19:14:14.0759 0880 defragsvc - ok
19:14:14.0775 0880 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:14:14.0806 0880 DfsC - ok
19:14:14.0837 0880 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
19:14:14.0837 0880 dg_ssudbus - ok
19:14:14.0884 0880 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
19:14:14.0900 0880 Dhcp - ok
19:14:14.0915 0880 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
19:14:14.0947 0880 discache - ok
19:14:14.0962 0880 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
19:14:14.0962 0880 Disk - ok
19:14:15.0009 0880 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:14:15.0009 0880 Dnscache - ok
19:14:15.0056 0880 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
19:14:15.0103 0880 dot3svc - ok
19:14:15.0134 0880 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
19:14:15.0181 0880 DPS - ok
19:14:15.0212 0880 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:14:15.0227 0880 drmkaud - ok
19:14:15.0274 0880 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:14:15.0321 0880 DXGKrnl - ok
19:14:15.0337 0880 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
19:14:15.0368 0880 EapHost - ok
19:14:15.0461 0880 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
19:14:15.0508 0880 ebdrv - ok
19:14:15.0539 0880 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
19:14:15.0571 0880 EFS - ok
19:14:15.0633 0880 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:14:15.0664 0880 ehRecvr - ok
19:14:15.0680 0880 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
19:14:15.0695 0880 ehSched - ok
19:14:15.0727 0880 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
19:14:15.0758 0880 elxstor - ok
19:14:15.0773 0880 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:14:15.0773 0880 ErrDev - ok
19:14:15.0820 0880 [ 0C8324462B9791A1ECE2A329A7378A55 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
19:14:15.0820 0880 ETD - ok
19:14:15.0867 0880 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
19:14:15.0898 0880 EventSystem - ok
19:14:15.0929 0880 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
19:14:15.0961 0880 exfat - ok
19:14:15.0976 0880 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:14:16.0023 0880 fastfat - ok
19:14:16.0054 0880 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
19:14:16.0085 0880 Fax - ok
19:14:16.0101 0880 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
19:14:16.0117 0880 fdc - ok
19:14:16.0132 0880 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
19:14:16.0179 0880 fdPHost - ok
19:14:16.0195 0880 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
19:14:16.0226 0880 FDResPub - ok
19:14:16.0257 0880 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:14:16.0273 0880 FileInfo - ok
19:14:16.0273 0880 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:14:16.0304 0880 Filetrace - ok
19:14:16.0335 0880 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
19:14:16.0335 0880 flpydisk - ok
19:14:16.0382 0880 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:14:16.0397 0880 FltMgr - ok
19:14:16.0429 0880 [ 5B92E2B067F64DC53698EB84966B3F0D ] FontCache C:\Windows\system32\FntCache.dll
19:14:16.0460 0880 FontCache - ok
19:14:16.0507 0880 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:14:16.0522 0880 FontCache3.0.0.0 - ok
19:14:16.0553 0880 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:14:16.0569 0880 FsDepends - ok
19:14:16.0600 0880 [ 2BF3B36B96D015AF666B6AA63AE2E38F ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
19:14:16.0600 0880 fssfltr - ok
19:14:16.0694 0880 [ 45B52394F9624237F33A8A3D73C0B221 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
19:14:16.0725 0880 fsssvc - ok
19:14:16.0756 0880 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:14:16.0772 0880 Fs_Rec - ok
19:14:16.0819 0880 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:14:16.0850 0880 fvevol - ok
19:14:16.0865 0880 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
19:14:16.0881 0880 gagp30kx - ok
19:14:16.0928 0880 [ 521A469CAF61F00E1DE081CC2099C1D6 ] GameConsoleService C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
19:14:16.0943 0880 GameConsoleService - ok
19:14:16.0990 0880 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
19:14:17.0037 0880 gpsvc - ok
19:14:17.0115 0880 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:14:17.0131 0880 gupdate - ok
19:14:17.0146 0880 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:14:17.0162 0880 gupdatem - ok
19:14:17.0193 0880 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:14:17.0209 0880 hcw85cir - ok
19:14:17.0240 0880 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:14:17.0271 0880 HdAudAddService - ok
19:14:17.0287 0880 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
19:14:17.0318 0880 HDAudBus - ok
19:14:17.0333 0880 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
19:14:17.0349 0880 HECIx64 - ok
19:14:17.0380 0880 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
19:14:17.0396 0880 HidBatt - ok
19:14:17.0427 0880 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
19:14:17.0443 0880 HidBth - ok
19:14:17.0458 0880 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
19:14:17.0474 0880 HidIr - ok
19:14:17.0489 0880 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
19:14:17.0552 0880 hidserv - ok
19:14:17.0583 0880 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:14:17.0599 0880 HidUsb - ok
19:14:17.0614 0880 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:14:17.0677 0880 hkmsvc - ok
19:14:17.0708 0880 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:14:17.0723 0880 HomeGroupListener - ok
19:14:17.0755 0880 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:14:17.0770 0880 HomeGroupProvider - ok
19:14:17.0801 0880 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:14:17.0833 0880 HpSAMD - ok
19:14:17.0879 0880 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:14:17.0926 0880 HTTP - ok
19:14:17.0942 0880 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:14:17.0957 0880 hwpolicy - ok
19:14:17.0973 0880 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:14:17.0989 0880 i8042prt - ok
19:14:18.0020 0880 [ A5F72BB0D024E7E463344105BE613AE4 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
19:14:18.0035 0880 iaStor - ok
19:14:18.0082 0880 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:14:18.0113 0880 iaStorV - ok
19:14:18.0176 0880 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:14:18.0207 0880 idsvc - ok
19:14:18.0363 0880 [ A87261EF1546325B559374F5689CF5BC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
19:14:18.0441 0880 igfx - ok
19:14:18.0457 0880 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
19:14:18.0457 0880 iirsp - ok
19:14:18.0519 0880 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
19:14:18.0566 0880 IKEEXT - ok
19:14:18.0597 0880 [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys
19:14:18.0613 0880 Impcd - ok
19:14:18.0691 0880 [ 5F35FE198EE7818221414776F8413AB0 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
19:14:18.0737 0880 IntcAzAudAddService - ok
19:14:18.0753 0880 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
19:14:18.0769 0880 intelide - ok
19:14:18.0784 0880 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:14:18.0800 0880 intelppm - ok
19:14:18.0815 0880 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:14:18.0862 0880 IPBusEnum - ok
19:14:18.0893 0880 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:14:18.0925 0880 IpFilterDriver - ok
19:14:18.0971 0880 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:14:18.0987 0880 iphlpsvc - ok
19:14:19.0018 0880 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:14:19.0049 0880 IPMIDRV - ok
19:14:19.0065 0880 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:14:19.0127 0880 IPNAT - ok
19:14:19.0143 0880 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:14:19.0159 0880 IRENUM - ok
19:14:19.0190 0880 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:14:19.0205 0880 isapnp - ok
19:14:19.0252 0880 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:14:19.0283 0880 iScsiPrt - ok
19:14:19.0299 0880 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:14:19.0315 0880 kbdclass - ok
19:14:19.0361 0880 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
19:14:19.0361 0880 kbdhid - ok
19:14:19.0377 0880 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
19:14:19.0393 0880 KeyIso - ok
19:14:19.0424 0880 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:14:19.0439 0880 KSecDD - ok
19:14:19.0486 0880 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:14:19.0502 0880 KSecPkg - ok
19:14:19.0517 0880 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
19:14:19.0549 0880 ksthunk - ok
19:14:19.0580 0880 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
19:14:19.0611 0880 KtmRm - ok
19:14:19.0658 0880 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
19:14:19.0689 0880 LanmanServer - ok
19:14:19.0736 0880 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:14:19.0767 0880 LanmanWorkstation - ok
19:14:19.0783 0880 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:14:19.0814 0880 lltdio - ok
19:14:19.0845 0880 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:14:19.0892 0880 lltdsvc - ok
19:14:19.0907 0880 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:14:19.0939 0880 lmhosts - ok
19:14:20.0001 0880 [ 85C7497997BA8B7C1728B12199616747 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:14:20.0001 0880 LMS - ok
19:14:20.0032 0880 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
19:14:20.0048 0880 LSI_FC - ok
19:14:20.0048 0880 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
19:14:20.0063 0880 LSI_SAS - ok
19:14:20.0079 0880 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:14:20.0079 0880 LSI_SAS2 - ok
19:14:20.0095 0880 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:14:20.0110 0880 LSI_SCSI - ok
19:14:20.0110 0880 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
19:14:20.0157 0880 luafv - ok
19:14:20.0188 0880 [ 024DA28053D57E9E32BEE52600576BBB ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus64.sys
19:14:20.0204 0880 MarvinBus - ok
19:14:20.0235 0880 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:14:20.0235 0880 Mcx2Svc - ok
19:14:20.0251 0880 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
19:14:20.0266 0880 megasas - ok
19:14:20.0282 0880 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
19:14:20.0297 0880 MegaSR - ok
19:14:20.0313 0880 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
19:14:20.0344 0880 MMCSS - ok
19:14:20.0360 0880 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
19:14:20.0407 0880 Modem - ok
19:14:20.0422 0880 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:14:20.0422 0880 monitor - ok
19:14:20.0438 0880 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:14:20.0438 0880 mouclass - ok
19:14:20.0453 0880 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:14:20.0453 0880 mouhid - ok
19:14:20.0500 0880 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:14:20.0500 0880 mountmgr - ok
19:14:20.0531 0880 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
19:14:20.0547 0880 mpio - ok
19:14:20.0578 0880 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:14:20.0609 0880 mpsdrv - ok
19:14:20.0656 0880 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:14:20.0703 0880 MpsSvc - ok
19:14:20.0734 0880 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:14:20.0750 0880 MRxDAV - ok
19:14:20.0781 0880 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:14:20.0797 0880 mrxsmb - ok
19:14:20.0812 0880 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:14:20.0828 0880 mrxsmb10 - ok
19:14:20.0875 0880 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:14:20.0875 0880 mrxsmb20 - ok
19:14:20.0906 0880 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
19:14:20.0921 0880 msahci - ok
19:14:20.0937 0880 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:14:20.0953 0880 msdsm - ok
19:14:20.0953 0880 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
19:14:20.0968 0880 MSDTC - ok
19:14:20.0984 0880 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:14:21.0031 0880 Msfs - ok
19:14:21.0046 0880 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:14:21.0077 0880 mshidkmdf - ok
19:14:21.0109 0880 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:14:21.0140 0880 msisadrv - ok
19:14:21.0171 0880 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:14:21.0202 0880 MSiSCSI - ok
19:14:21.0202 0880 msiserver - ok
19:14:21.0218 0880 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:14:21.0249 0880 MSKSSRV - ok
19:14:21.0265 0880 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:14:21.0296 0880 MSPCLOCK - ok
19:14:21.0311 0880 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:14:21.0343 0880 MSPQM - ok
19:14:21.0389 0880 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:14:21.0405 0880 MsRPC - ok
19:14:21.0436 0880 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
19:14:21.0452 0880 mssmbios - ok
19:14:21.0467 0880 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:14:21.0530 0880 MSTEE - ok
19:14:21.0530 0880 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
19:14:21.0545 0880 MTConfig - ok
19:14:21.0561 0880 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
19:14:21.0577 0880 Mup - ok
19:14:21.0608 0880 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
19:14:21.0670 0880 napagent - ok
19:14:21.0701 0880 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:14:21.0717 0880 NativeWifiP - ok
19:14:21.0764 0880 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:14:21.0811 0880 NDIS - ok
19:14:21.0826 0880 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:14:21.0857 0880 NdisCap - ok
19:14:21.0873 0880 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:14:21.0920 0880 NdisTapi - ok
19:14:21.0951 0880 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:14:21.0982 0880 Ndisuio - ok
19:14:22.0013 0880 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:14:22.0060 0880 NdisWan - ok
19:14:22.0091 0880 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:14:22.0138 0880 NDProxy - ok
19:14:22.0169 0880 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:14:22.0201 0880 NetBIOS - ok
19:14:22.0247 0880 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:14:22.0294 0880 NetBT - ok
19:14:22.0294 0880 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
19:14:22.0310 0880 Netlogon - ok
19:14:22.0341 0880 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
19:14:22.0388 0880 Netman - ok
19:14:22.0403 0880 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
19:14:22.0450 0880 netprofm - ok
19:14:22.0481 0880 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:14:22.0481 0880 NetTcpPortSharing - ok
19:14:22.0497 0880 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
19:14:22.0513 0880 nfrd960 - ok
19:14:22.0559 0880 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:14:22.0575 0880 NlaSvc - ok
19:14:22.0606 0880 [ 4903177FC90E77ABEB19021451E9475E ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
19:14:22.0622 0880 nmwcd - ok
19:14:22.0637 0880 [ E6844A4C97E5409BBE24BB4ED000320D ] nmwcdc C:\Windows\system32\drivers\ccdcmbox64.sys
19:14:22.0653 0880 nmwcdc - ok
19:14:22.0700 0880 [ F59F8CF59F7905622686637177E2A828 ] nmwcdnsucx64 C:\Windows\system32\drivers\nmwcdnsucx64.sys
19:14:22.0747 0880 nmwcdnsucx64 - ok
19:14:22.0793 0880 [ A0E7F80157AF77B1CEAA8ADD3A3E7D85 ] nmwcdnsux64 C:\Windows\system32\drivers\nmwcdnsux64.sys
19:14:22.0825 0880 nmwcdnsux64 - ok
19:14:22.0840 0880 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:14:22.0887 0880 Npfs - ok
19:14:22.0903 0880 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
19:14:22.0934 0880 nsi - ok
19:14:22.0949 0880 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:14:22.0996 0880 nsiproxy - ok
19:14:23.0043 0880 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:14:23.0090 0880 Ntfs - ok
19:14:23.0105 0880 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
19:14:23.0137 0880 Null - ok
19:14:23.0168 0880 [ 285ACEC1B13A15BA520AAE06BACB9CFF ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
19:14:23.0183 0880 nusb3hub - ok
19:14:23.0199 0880 [ F6D625FF7B56BB6EA063F0D3A5BBC996 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
19:14:23.0215 0880 nusb3xhc - ok
19:14:23.0246 0880 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
19:14:23.0261 0880 NVHDA - ok
19:14:23.0465 0880 [ 26AA3C7E6E1DB7107BF93503F6F57E88 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:14:23.0668 0880 nvlddmkm - ok
19:14:23.0762 0880 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:14:23.0777 0880 nvraid - ok
19:14:23.0808 0880 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:14:23.0824 0880 nvstor - ok
19:14:23.0855 0880 [ A83AC04D672567CAF8BE7A4D73C0B850 ] nvsvc C:\Windows\system32\nvvsvc.exe
19:14:23.0886 0880 nvsvc - ok
19:14:23.0949 0880 [ FB660F80BDC4F13D594996976AFAECD9 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
19:14:23.0980 0880 nvUpdatusService - ok
19:14:24.0011 0880 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:14:24.0027 0880 nv_agp - ok
19:14:24.0058 0880 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:14:24.0074 0880 ohci1394 - ok
19:14:24.0120 0880 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:14:24.0120 0880 ose - ok
19:14:24.0152 0880 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:14:24.0167 0880 p2pimsvc - ok
19:14:24.0198 0880 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
19:14:24.0198 0880 p2psvc - ok
19:14:24.0230 0880 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
19:14:24.0245 0880 Parport - ok
19:14:24.0276 0880 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:14:24.0276 0880 partmgr - ok
19:14:24.0308 0880 [ 5EACB8A19CAD7057806FBBF9550165E1 ] PcaSp60 C:\Windows\system32\DRIVERS\PcaSp60.sys
19:14:24.0323 0880 PcaSp60 - ok
19:14:24.0370 0880 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:14:24.0401 0880 PcaSvc - ok
19:14:24.0417 0880 [ 3FDE033DFB0D07F8B7D5C9A3044AA121 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
19:14:24.0432 0880 pccsmcfd - ok
19:14:24.0464 0880 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
19:14:24.0479 0880 pci - ok
19:14:24.0510 0880 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
19:14:24.0526 0880 pciide - ok
19:14:24.0557 0880 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
19:14:24.0573 0880 pcmcia - ok
19:14:24.0604 0880 [ AF7CE12C4F3DC8CB2B07685C916BBCFE ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
19:14:24.0620 0880 pcouffin - ok
19:14:24.0620 0880 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
19:14:24.0635 0880 pcw - ok
19:14:24.0651 0880 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:14:24.0698 0880 PEAUTH - ok
19:14:24.0791 0880 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
19:14:24.0822 0880 PerfHost - ok
19:14:24.0869 0880 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
19:14:24.0932 0880 pla - ok
19:14:24.0978 0880 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:14:24.0994 0880 PlugPlay - ok
19:14:25.0025 0880 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:14:25.0041 0880 PNRPAutoReg - ok
19:14:25.0056 0880 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:14:25.0072 0880 PNRPsvc - ok
19:14:25.0103 0880 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:14:25.0150 0880 PolicyAgent - ok
19:14:25.0181 0880 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
19:14:25.0212 0880 Power - ok
19:14:25.0212 0880 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:14:25.0244 0880 PptpMiniport - ok
19:14:25.0290 0880 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
19:14:25.0290 0880 Processor - ok
19:14:25.0337 0880 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
19:14:25.0353 0880 ProfSvc - ok
19:14:25.0368 0880 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:14:25.0384 0880 ProtectedStorage - ok
19:14:25.0415 0880 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:14:25.0446 0880 Psched - ok
19:14:25.0509 0880 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
19:14:25.0556 0880 ql2300 - ok
19:14:25.0571 0880 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
19:14:25.0587 0880 ql40xx - ok
19:14:25.0618 0880 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
19:14:25.0634 0880 QWAVE - ok
19:14:25.0649 0880 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:14:25.0665 0880 QWAVEdrv - ok
19:14:25.0680 0880 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:14:25.0712 0880 RasAcd - ok
19:14:25.0743 0880 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:14:25.0790 0880 RasAgileVpn - ok
19:14:25.0821 0880 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
19:14:25.0852 0880 RasAuto - ok
19:14:25.0883 0880 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:14:25.0914 0880 Rasl2tp - ok
19:14:25.0961 0880 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
19:14:26.0008 0880 RasMan - ok
19:14:26.0039 0880 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:14:26.0102 0880 RasPppoe - ok
19:14:26.0102 0880 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:14:26.0148 0880 RasSstp - ok
19:14:26.0180 0880 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:14:26.0226 0880 rdbss - ok
19:14:26.0242 0880 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
19:14:26.0242 0880 rdpbus - ok
19:14:26.0258 0880 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:14:26.0289 0880 RDPCDD - ok
19:14:26.0304 0880 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:14:26.0336 0880 RDPENCDD - ok
19:14:26.0351 0880 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:14:26.0382 0880 RDPREFMP - ok
19:14:26.0414 0880 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
19:14:26.0429 0880 RdpVideoMiniport - ok
19:14:26.0476 0880 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:14:26.0492 0880 RDPWD - ok
19:14:26.0538 0880 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:14:26.0554 0880 rdyboost - ok
19:14:26.0585 0880 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:14:26.0616 0880 RemoteAccess - ok
19:14:26.0648 0880 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:14:26.0679 0880 RemoteRegistry - ok
19:14:26.0710 0880 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
19:14:26.0726 0880 RFCOMM - ok
19:14:26.0788 0880 [ 7CCAEBCAB6FC1ED0206C07E083E79207 ] RichVideo C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
19:14:26.0804 0880 RichVideo - ok
19:14:26.0835 0880 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:14:26.0882 0880 RpcEptMapper - ok
19:14:26.0897 0880 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
19:14:26.0913 0880 RpcLocator - ok
19:14:26.0944 0880 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
19:14:26.0991 0880 RpcSs - ok
19:14:27.0006 0880 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:14:27.0038 0880 rspndr - ok
19:14:27.0053 0880 [ BAEFEE35D27A5440D35092CE10267BEC ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
19:14:27.0069 0880 RTL8167 - ok
19:14:27.0084 0880 [ 62DB6CC4B0818F1B5F3441241B098F12 ] SABI C:\Windows\system32\Drivers\SABI.sys
19:14:27.0100 0880 SABI - ok
19:14:27.0116 0880 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
19:14:27.0131 0880 SamSs - ok
19:14:27.0147 0880 [ D641337B75B9A9D5AE10687AA1097755 ] Samsung UPD Service C:\Windows\System32\SUPDSvc.exe
19:14:27.0162 0880 Samsung UPD Service - ok
19:14:27.0225 0880 [ 328100AF2EFD951EAB657384EC361B6F ] SamsungAllShareV2.0 C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
19:14:27.0225 0880 SamsungAllShareV2.0 - ok
19:14:27.0272 0880 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:14:27.0287 0880 sbp2port - ok
19:14:27.0318 0880 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:14:27.0350 0880 SCardSvr - ok
19:14:27.0396 0880 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:14:27.0428 0880 scfilter - ok
19:14:27.0490 0880 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
19:14:27.0568 0880 Schedule - ok
19:14:27.0615 0880 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:14:27.0646 0880 SCPolicySvc - ok
19:14:27.0677 0880 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:14:27.0693 0880 SDRSVC - ok
19:14:27.0724 0880 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:14:27.0755 0880 secdrv - ok
19:14:27.0818 0880 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
19:14:27.0864 0880 seclogon - ok
19:14:27.0880 0880 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
19:14:27.0927 0880 SENS - ok
19:14:27.0942 0880 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:14:27.0942 0880 SensrSvc - ok
19:14:27.0958 0880 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
19:14:27.0974 0880 Serenum - ok
19:14:27.0989 0880 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
19:14:28.0005 0880 Serial - ok
19:14:28.0036 0880 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
19:14:28.0052 0880 sermouse - ok
19:14:28.0114 0880 [ 9BDE8F1F5D060E912FCF9FB58B71CBC1 ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
19:14:28.0145 0880 ServiceLayer - ok
19:14:28.0176 0880 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
19:14:28.0223 0880 SessionEnv - ok
19:14:28.0254 0880 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:14:28.0270 0880 sffdisk - ok
19:14:28.0286 0880 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:14:28.0301 0880 sffp_mmc - ok
19:14:28.0301 0880 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:14:28.0317 0880 sffp_sd - ok
19:14:28.0332 0880 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
19:14:28.0348 0880 sfloppy - ok
19:14:28.0379 0880 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:14:28.0426 0880 SharedAccess - ok
19:14:28.0457 0880 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:14:28.0488 0880 ShellHWDetection - ok
19:14:28.0520 0880 [ 1980FE1F5A32067DAD1D8776B63C2669 ] SimpleSlideShowServer C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
19:14:28.0520 0880 SimpleSlideShowServer - ok
19:14:28.0535 0880 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:14:28.0551 0880 SiSRaid2 - ok
19:14:28.0582 0880 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
19:14:28.0598 0880 SiSRaid4 - ok
19:14:28.0754 0880 [ 183F04C6742902F33039913A96F5B574 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
19:14:28.0816 0880 Skype C2C Service - ok
19:14:28.0878 0880 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:14:28.0894 0880 SkypeUpdate - ok
19:14:28.0910 0880 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:14:28.0972 0880 Smb - ok
19:14:29.0003 0880 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:14:29.0019 0880 SNMPTRAP - ok
19:14:29.0050 0880 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
19:14:29.0050 0880 spldr - ok
19:14:29.0097 0880 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
19:14:29.0128 0880 Spooler - ok
19:14:29.0237 0880 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
19:14:29.0331 0880 sppsvc - ok
19:14:29.0378 0880 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:14:29.0409 0880 sppuinotify - ok
19:14:29.0440 0880 [ D6AB7C13FCDD2E4CAC35244D2C172D9A ] sptd C:\Windows\System32\Drivers\sptd.sys
19:14:29.0456 0880 sptd - ok
19:14:29.0502 0880 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
19:14:29.0534 0880 srv - ok
19:14:29.0565 0880 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:14:29.0580 0880 srv2 - ok
19:14:29.0627 0880 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:14:29.0643 0880 srvnet - ok
19:14:29.0674 0880 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:14:29.0721 0880 SSDPSRV - ok
19:14:29.0736 0880 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:14:29.0768 0880 SstpSvc - ok
19:14:29.0814 0880 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
19:14:29.0830 0880 ssudmdm - ok
19:14:29.0861 0880 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
19:14:29.0877 0880 stexstor - ok
19:14:29.0892 0880 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
19:14:29.0908 0880 StillCam - ok
19:14:29.0939 0880 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
19:14:29.0986 0880 stisvc - ok
19:14:30.0033 0880 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
19:14:30.0033 0880 swenum - ok
19:14:30.0064 0880 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
19:14:30.0111 0880 swprv - ok
19:14:30.0173 0880 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
19:14:30.0236 0880 SysMain - ok
19:14:30.0267 0880 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:14:30.0298 0880 TabletInputService - ok
19:14:30.0345 0880 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
19:14:30.0392 0880 TapiSrv - ok
19:14:30.0423 0880 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
19:14:30.0501 0880 TBS - ok
19:14:30.0579 0880 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:14:30.0610 0880 Tcpip - ok
19:14:30.0657 0880 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:14:30.0704 0880 TCPIP6 - ok
19:14:30.0735 0880 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:14:30.0735 0880 tcpipreg - ok
19:14:30.0766 0880 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:14:30.0782 0880 TDPIPE - ok
19:14:30.0813 0880 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:14:30.0813 0880 TDTCP - ok
19:14:30.0844 0880 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:14:30.0906 0880 tdx - ok
19:14:30.0938 0880 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
19:14:30.0938 0880 TermDD - ok
19:14:30.0984 0880 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
19:14:31.0031 0880 TermService - ok
19:14:31.0078 0880 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
19:14:31.0094 0880 Themes - ok
19:14:31.0109 0880 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
19:14:31.0140 0880 THREADORDER - ok
19:14:31.0156 0880 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
19:14:31.0187 0880 TrkWks - ok
19:14:31.0250 0880 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:14:31.0312 0880 TrustedInstaller - ok
19:14:31.0359 0880 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:14:31.0421 0880 tssecsrv - ok
19:14:31.0452 0880 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:14:31.0468 0880 TsUsbFlt - ok
19:14:31.0499 0880 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:14:31.0562 0880 tunnel - ok
19:14:31.0608 0880 [ B355581A9DA34C92E2DBAFA410D2F829 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys
19:14:31.0624 0880 TurboB - ok
19:14:31.0718 0880 [ 6564E84B1522C12EA1C3A181ED03276F ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe
19:14:31.0733 0880 TurboBoost - ok
19:14:31.0764 0880 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
19:14:31.0780 0880 uagp35 - ok
19:14:31.0827 0880 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:14:31.0874 0880 udfs - ok
19:14:31.0920 0880 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:14:31.0936 0880 UI0Detect - ok
19:14:31.0967 0880 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:14:31.0983 0880 uliagpkx - ok
19:14:32.0030 0880 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:14:32.0045 0880 umbus - ok
19:14:32.0076 0880 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
19:14:32.0076 0880 UmPass - ok
19:14:32.0201 0880 [ 4735B3050C0D6F9DC571451298C54FA0 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:14:32.0248 0880 UNS - ok
19:14:32.0279 0880 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
19:14:32.0326 0880 upnphost - ok
19:14:32.0357 0880 [ 907F50B8695DAA65A9445D27AD306E65 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
19:14:32.0388 0880 upperdev - ok
19:14:32.0420 0880 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:14:32.0451 0880 usbccgp - ok
19:14:32.0482 0880 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:14:32.0513 0880 usbcir - ok
19:14:32.0560 0880 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
19:14:32.0560 0880 usbehci - ok
19:14:32.0576 0880 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:14:32.0591 0880 usbhub - ok
19:14:32.0638 0880 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:14:32.0638 0880 usbohci - ok
19:14:32.0669 0880 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
19:14:32.0685 0880 usbprint - ok
19:14:32.0716 0880 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
19:14:32.0732 0880 usbscan - ok
19:14:32.0778 0880 [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser C:\Windows\system32\drivers\usbser.sys
19:14:32.0794 0880 usbser - ok
19:14:32.0841 0880 [ 3F7498527B48657091C355F683BEB0DD ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
19:14:32.0872 0880 UsbserFilt - ok
19:14:32.0919 0880 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:14:32.0934 0880 USBSTOR - ok
19:14:32.0966 0880 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:14:32.0981 0880 usbuhci - ok
19:14:33.0028 0880 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
19:14:33.0044 0880 usbvideo - ok
19:14:33.0090 0880 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
19:14:33.0106 0880 usb_rndisx - ok
19:14:33.0153 0880 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
19:14:33.0215 0880 UxSms - ok
19:14:33.0231 0880 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
19:14:33.0246 0880 VaultSvc - ok
19:14:33.0293 0880 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:14:33.0309 0880 vdrvroot - ok
19:14:33.0371 0880 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
19:14:33.0418 0880 vds - ok
19:14:33.0465 0880 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:14:33.0480 0880 vga - ok
19:14:33.0527 0880 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
19:14:33.0574 0880 VgaSave - ok
19:14:33.0699 0880 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:14:33.0714 0880 vhdmp - ok
19:14:33.0761 0880 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
19:14:33.0777 0880 viaide - ok
19:14:33.0839 0880 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:14:33.0855 0880 volmgr - ok
19:14:33.0902 0880 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:14:33.0917 0880 volmgrx - ok
19:14:33.0980 0880 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:14:33.0995 0880 volsnap - ok
19:14:34.0042 0880 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
19:14:34.0058 0880 vsmraid - ok
19:14:34.0151 0880 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
19:14:34.0214 0880 VSS - ok
19:14:34.0245 0880 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:14:34.0260 0880 vwifibus - ok
19:14:34.0292 0880 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:14:34.0307 0880 vwififlt - ok
19:14:34.0323 0880 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
19:14:34.0338 0880 vwifimp - ok
19:14:34.0385 0880 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
19:14:34.0416 0880 W32Time - ok
19:14:34.0448 0880 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
19:14:34.0448 0880 WacomPen - ok
19:14:34.0494 0880 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:14:34.0557 0880 WANARP - ok
19:14:34.0557 0880 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:14:34.0588 0880 Wanarpv6 - ok
19:14:34.0650 0880 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
19:14:34.0697 0880 WatAdminSvc - ok
19:14:34.0791 0880 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
19:14:34.0838 0880 wbengine - ok
19:14:34.0869 0880 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:14:34.0916 0880 WbioSrvc - ok
19:14:34.0978 0880 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:14:35.0025 0880 wcncsvc - ok
19:14:35.0040 0880 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:14:35.0056 0880 WcsPlugInService - ok
19:14:35.0072 0880 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
19:14:35.0087 0880 Wd - ok
19:14:35.0134 0880 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:14:35.0165 0880 Wdf01000 - ok
19:14:35.0196 0880 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:14:35.0212 0880 WdiServiceHost - ok
19:14:35.0212 0880 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:14:35.0228 0880 WdiSystemHost - ok
19:14:35.0259 0880 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
19:14:35.0306 0880 WebClient - ok
19:14:35.0352 0880 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:14:35.0399 0880 Wecsvc - ok
19:14:35.0430 0880 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:14:35.0493 0880 wercplsupport - ok
19:14:35.0524 0880 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
19:14:35.0555 0880 WerSvc - ok
19:14:35.0586 0880 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:14:35.0633 0880 WfpLwf - ok
19:14:35.0664 0880 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:14:35.0664 0880 WIMMount - ok
19:14:35.0696 0880 WinDefend - ok
19:14:35.0711 0880 WinHttpAutoProxySvc - ok
19:14:35.0774 0880 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:14:35.0852 0880 Winmgmt - ok
19:14:35.0945 0880 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
19:14:36.0008 0880 WinRM - ok
19:14:36.0101 0880 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
19:14:36.0117 0880 WinUsb - ok
19:14:36.0179 0880 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
19:14:36.0226 0880 Wlansvc - ok
19:14:36.0382 0880 [ 98F138897EF4246381D197CB81846D62 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:14:36.0429 0880 wlidsvc - ok
19:14:36.0460 0880 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
19:14:36.0476 0880 WmiAcpi - ok
19:14:36.0507 0880 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:14:36.0538 0880 wmiApSrv - ok
19:14:36.0569 0880 WMPNetworkSvc - ok
19:14:36.0616 0880 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:14:36.0647 0880 WPCSvc - ok
19:14:36.0710 0880 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:14:36.0725 0880 WPDBusEnum - ok
19:14:36.0756 0880 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:14:36.0788 0880 ws2ifsl - ok
19:14:36.0819 0880 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
19:14:36.0834 0880 wscsvc - ok
19:14:36.0834 0880 WSearch - ok
19:14:36.0912 0880 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
19:14:36.0944 0880 wuauserv - ok
19:14:36.0990 0880 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:14:36.0990 0880 WudfPf - ok
19:14:37.0022 0880 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:14:37.0022 0880 WUDFRd - ok
19:14:37.0053 0880 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:14:37.0084 0880 wudfsvc - ok
19:14:37.0115 0880 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
19:14:37.0131 0880 WwanSvc - ok
19:14:37.0178 0880 [ 4647FDA6E21B18824D6073801177F4F7 ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys
19:14:37.0193 0880 yukonw7 - ok
19:14:37.0193 0880 ================ Scan global ===============================
19:14:37.0224 0880 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
19:14:37.0302 0880 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
19:14:37.0302 0880 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
19:14:37.0412 0880 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
19:14:37.0474 0880 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
19:14:37.0474 0880 [Global] - ok
19:14:37.0474 0880 ================ Scan MBR ==================================
19:14:37.0521 0880 [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
19:14:38.0051 0880 \Device\Harddisk0\DR0 - ok
19:14:38.0051 0880 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
19:14:38.0847 0880 \Device\Harddisk1\DR1 - ok
19:14:38.0847 0880 ================ Scan VBR ==================================
19:14:38.0862 0880 [ 8470E90E03DE6F5EA1F052795BD47D56 ] \Device\Harddisk0\DR0\Partition1
19:14:38.0862 0880 \Device\Harddisk0\DR0\Partition1 - ok
19:14:38.0862 0880 [ 1EEE6A02F0696528029D45882113C867 ] \Device\Harddisk0\DR0\Partition2
19:14:38.0878 0880 \Device\Harddisk0\DR0\Partition2 - ok
19:14:38.0894 0880 [ 30843A274BE9011AFBCC1965BCC08FDC ] \Device\Harddisk0\DR0\Partition3
19:14:38.0894 0880 \Device\Harddisk0\DR0\Partition3 - ok
19:14:38.0894 0880 [ DC7E43CB30EC98BF322D35CFADF05FF9 ] \Device\Harddisk1\DR1\Partition1
19:14:38.0909 0880 \Device\Harddisk1\DR1\Partition1 - ok
19:14:38.0909 0880 ============================================================
19:14:38.0909 0880 Scan finished
19:14:38.0909 0880 ============================================================
19:14:38.0909 3176 Detected object count: 0
19:14:38.0909 3176 Actual detected object count: 0

Re: Podivne chování

Napsal: 21 led 2013 19:27
od miromen
Zde ještě log z UsbFix..

############################## | UsbFix V 7.096 | [Deletion]

User: Miromen (Administrator) # MIROMEN-PC
Updated 15/08/2012 by El Desaparecido
Started at 18:54:36 | 21/01/2013

Website: http://eldesaparecido.com
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com

PC: SAMSUNG ELECTRONICS CO., LTD. (RF510/RF410/RF710 ) (x64-based PC) # Notebook
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [Total : 3956 | Free : 2364]
BIOS: Phoenix SecureCore(tm) NB Version 02GB.M025.20101027.hkk
BOOT: Normal boot

OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | Updated]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 179 Gb (20 Mb free - 11%) [] # NTFS
D:\ -> Fixed drive # 268 Gb (16 Mb free - 6%) [] # NTFS
E:\ -> CD-ROM
I:\ -> Fixed drive # 699 Gb (62 Mb free - 9%) [] # NTFS

################## | Active Processes |

C:\Windows\system32\csrss.exe (500)
C:\Windows\system32\wininit.exe (568)
C:\Windows\system32\csrss.exe (588)
C:\Windows\system32\services.exe (632)
C:\Windows\system32\lsass.exe (648)
C:\Windows\system32\lsm.exe (656)
C:\Windows\system32\svchost.exe (776)
C:\Windows\system32\winlogon.exe (820)
C:\Windows\system32\nvvsvc.exe (868)
C:\Windows\system32\svchost.exe (908)
C:\Windows\System32\svchost.exe (1008)
C:\Windows\System32\svchost.exe (296)
C:\Windows\system32\svchost.exe (364)
C:\Windows\system32\svchost.exe (492)
C:\Windows\system32\svchost.exe (1036)
C:\Windows\system32\svchost.exe (1148)
C:\Windows\system32\WLANExt.exe (1280)
C:\Windows\system32\conhost.exe (1296)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1308)
C:\Windows\system32\nvvsvc.exe (1316)
C:\Windows\System32\spoolsv.exe (1396)
C:\Windows\system32\svchost.exe (1444)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1608)
C:\Windows\system32\taskhost.exe (1808)
C:\Windows\system32\Dwm.exe (1864)
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (1960)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (2016)
C:\Windows\Explorer.EXE (368)
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (1576)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (1904)
C:\Windows\system32\svchost.exe (2112)
C:\Program Files\Intel\TurboBoost\TurboBoost.exe (2156)
C:\Windows\System32\svchost.exe (2288)
C:\Windows\system32\svchost.exe (2732)
C:\Windows\system32\svchost.exe (2904)
C:\Windows\system32\svchost.exe (3044)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (1748)
C:\Program Files\Elantech\ETDCtrl.exe (1728)
C:\Program Files\Windows Sidebar\sidebar.exe (2400)
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe (2504)
C:\Program Files\Elantech\ETDCtrlHelper.exe (3232)
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (3248)
C:\Windows\system32\SearchIndexer.exe (3292)
C:\Program Files\Windows Media Player\wmpnetwk.exe (3372)
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (3452)
C:\Windows\system32\taskeng.exe (3716)
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (3752)
C:\Windows\system32\wbem\wmiprvse.exe (3880)
C:\Windows\SysWOW64\RunDll32.exe (3976)
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (4008)
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (3096)
C:\Windows\System32\svchost.exe (3412)
C:\Windows\system32\DllHost.exe (4504)
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (4556)
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (4592)
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (4124)
C:\Program Files (x86)\Internet Explorer\iexplore.exe (2692)
C:\Program Files (x86)\Internet Explorer\iexplore.exe (4336)
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (4000)
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (5036)
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (4948)
C:\Program Files (x86)\Internet Explorer\iexplore.exe (4868)
C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (4256)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (4932)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (5060)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (4688)
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (5176)
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (5352)
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (5476)
C:\Windows\system32\SearchProtocolHost.exe (4524)
C:\Windows\system32\SearchFilterHost.exe (1936)
C:\Windows\System32\svchost.exe (4700)
C:\UsbFix\Go.exe (5464)
C:\Windows\system32\wbem\wmiprvse.exe (2852)

################## | Stopped processes |

Stopped! C:\Windows\system32\nvvsvc.exe (868)
Stopped! C:\Windows\system32\WLANExt.exe (1280)
Stopped! C:\Windows\system32\conhost.exe (1296)
Stopped! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1308)
Stopped! C:\Windows\system32\nvvsvc.exe (1316)
Stopped! C:\Windows\System32\spoolsv.exe (1396)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1608)
Stopped! C:\Windows\system32\taskhost.exe (1808)
Stopped! C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (1960)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (2016)
Stopped! C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (1576)
Stopped! C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (1904)
Stopped! C:\Program Files\Intel\TurboBoost\TurboBoost.exe (2156)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (1748)
Stopped! C:\Program Files\Elantech\ETDCtrl.exe (1728)
Stopped! C:\Program Files\Windows Sidebar\sidebar.exe (2400)
Stopped! C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe (2504)
Stopped! C:\Program Files\Elantech\ETDCtrlHelper.exe (3232)
Stopped! C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (3248)
Stopped! C:\Windows\system32\SearchIndexer.exe (3292)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (3372)
Stopped! C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (3452)
Stopped! C:\Windows\system32\taskeng.exe (3716)
Stopped! C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (3752)
Stopped! C:\Windows\SysWOW64\RunDll32.exe (3976)
Stopped! C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (4008)
Stopped! C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (3096)
Stopped! C:\Windows\system32\DllHost.exe (4504)
Stopped! C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (4556)
Stopped! C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (4592)
Stopped! C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (4124)
Stopped! C:\Program Files (x86)\Internet Explorer\iexplore.exe (2692)
Stopped! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4336)
Stopped! C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (4000)
Stopped! C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (5036)
Stopped! C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (4948)
Stopped! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4868)
Stopped! C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (4256)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (4932)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (5060)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (4688)
Stopped! C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (5176)
Stopped! C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (5352)
Stopped! C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (5476)

################## | Files # Infected Folders |

Deleted ! C:\Users\Miromen\AppData\Roaming\Temp
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-1604290871-1745575891-3147878822-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1604290871-1745575891-3147878822-1000
Deleted ! I:\$RECYCLE.BIN\S-1-5-21-1604290871-1745575891-3147878822-1000

(!) Temporary files deleted.

################## | Registry |

Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

################## | Mountpoints2 |


################## | Listing |

[21/01/2013 - 18:57:35 | SHD ] C:\$RECYCLE.BIN
[16/05/2012 - 06:54:02 | D ] C:\23621707248e39c179cd8b33
[12/01/2013 - 16:40:10 | D ] C:\AllShare
[12/01/2013 - 16:34:14 | D ] C:\AllShare Play
[21/01/2013 - 13:50:58 | N | 23711] C:\ComboFix.txt
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[12/01/2013 - 16:41:41 | D ] C:\Download
[26/10/2012 - 12:58:49 | N | 14] C:\end
[21/01/2013 - 18:02:21 | ASH | 4148592640] C:\hiberfil.sys
[31/08/2010 - 03:43:23 | D ] C:\Intel
[22/03/2012 - 18:17:49 | RD ] C:\MSOCache
[22/03/2012 - 18:43:40 | D ] C:\NVIDIA
[21/01/2013 - 18:02:25 | ASH | 4148592640] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[21/01/2013 - 14:17:17 | D ] C:\Program Files
[20/01/2013 - 21:04:13 | D ] C:\Program Files (x86)
[13/01/2013 - 09:03:33 | D ] C:\ProgramData
[21/01/2013 - 13:51:00 | D ] C:\Qoobox
[21/03/2012 - 21:56:10 | D ] C:\Recovery
[31/08/2010 - 03:45:22 | N | 2162] C:\RHDSetup.log
[21/01/2013 - 14:21:01 | D ] C:\rsit
[21/03/2012 - 22:03:44 | N | 196] C:\setup.log
[21/01/2013 - 18:01:04 | SHD ] C:\System Volume Information
[07/10/2012 - 07:10:50 | D ] C:\Temp
[10/09/2012 - 14:11:35 | D ] C:\Upload
[21/01/2013 - 18:57:35 | D ] C:\UsbFix
[21/01/2013 - 18:54:58 | A | 10285] C:\UsbFix.txt
[06/01/2013 - 23:08:38 | D ] C:\Users
[13/01/2013 - 09:10:46 | D ] C:\video_output
[21/01/2013 - 17:45:19 | D ] C:\Windows
[21/01/2013 - 18:57:35 | D ] D:\$RECYCLE.BIN
[27/12/2012 - 00:19:03 | D ] D:\$WINDOWS.~BT
[25/04/2011 - 23:56:42 | D ] D:\1920x1080
[22/04/2012 - 16:58:03 | D ] D:\Auto
[08/08/2012 - 13:11:54 | D ] D:\Camera
[24/10/2012 - 14:05:38 | D ] D:\Digital Video Essentials PAL (Test for Home Theater)
[24/10/2012 - 16:17:04 | D ] D:\Digital.Video.Essentials.HD-DVD.1080p.VC-1.DTrueHD.5.1
[27/08/2012 - 08:12:47 | D ] D:\Filmy
[26/07/2012 - 12:41:13 | D ] D:\Fota
[08/07/2011 - 21:58:59 | D ] D:\Hudba
[29/03/2011 - 14:12:28 | D ] D:\internet
[16/12/2011 - 08:16:43 | D ] D:\Jana telefon
[29/03/2011 - 13:28:46 | D ] D:\KARAOKE
[11/07/2012 - 20:48:00 | D ] D:\KARINKA
[08/01/2013 - 01:07:25 | D ] D:\msdownld.tmp
[25/04/2011 - 23:56:42 | D ] D:\Nokia
[25/04/2011 - 23:56:42 | D ] D:\Nová složka (6)
[29/03/2011 - 13:28:01 | D ] D:\Office 2010 (New) Professional Plus 32bit and 64bit with Volume Edition Activator_timesurfer
[25/03/2012 - 15:11:41 | D ] D:\Program Files
[13/01/2013 - 08:49:45 | D ] D:\Prometheus 3D
[17/11/2012 - 08:07:50 | D ] D:\SE ARC
[29/03/2011 - 14:14:58 | D ] D:\Smeti
[11/02/2011 - 15:55:53 | SHD ] D:\System Volume Information
[29/03/2011 - 13:21:44 | D ] D:\Tecar Forum
[24/09/2012 - 17:13:45 | N | 16101358601] D:\The.Dark.Knight.2008.1080p.BluRay.DTS.x264-ESiR PEPETOY.mkv
[06/10/2012 - 15:41:57 | D ] D:\Torrent
[29/03/2011 - 13:20:04 | D ] D:\video_output
[03/08/2012 - 12:23:06 | N | 441214] D:\VirtualDJ Local Database v6.xml
[21/01/2013 - 18:57:35 | SHD ] I:\$RECYCLE.BIN
[02/07/2011 - 15:03:38 | N | 5281136] I:\021_Excision_Downlink_-_Existence_VIP_-_Original_Mix-csm.mp3
[29/08/2012 - 02:25:20 | D ] I:\100MSDCF
[29/08/2012 - 02:27:13 | D ] I:\102MSDCF
[29/08/2012 - 01:26:12 | D ] I:\2005 - Radium
[29/08/2012 - 01:26:29 | D ] I:\2006 Have It All
[10/10/2011 - 03:09:18 | N | 14404807775] I:\3.10.to.Yuma.2007.BluRay.1080p.DTS.x264.dxva-EuReKA.AC3.CZ-iNKViZiT0R.mkv
[16/12/2012 - 23:58:14 | D ] I:\3D
[24/11/2012 - 00:28:40 | D ] I:\4K video
[24/11/2012 - 00:29:02 | D ] I:\7680×4320 Wallpapers
[24/09/2011 - 07:16:36 | N | 14234445903] I:\ACDC.Live.At.River.Plate.2011.1080p.BluRay.DTS.x264-HDMaNiAcS.mkv
[29/08/2012 - 01:26:35 | D ] I:\Alphaville - First Harvest 1984 - 92
[29/08/2012 - 01:27:05 | D ] I:\Antimatter - Alternative Matter [3 CD Deluxe Edition] (2010) EAC-FLAC
[28/11/2012 - 09:21:58 | N | 11161057612] I:\Anything.For.Her.2008.FRENCH.1080p.BluRay.DTS-HDMA.x264-SYNERGY.mkv
[07/10/2012 - 08:43:50 | D ] I:\Apocalyptica - Plays Metallica By Four Cellos [DTS 5.1]
[29/08/2012 - 01:27:24 | D ] I:\Awolnation - 2012 - Sail (Remixez)
[29/08/2012 - 01:27:31 | D ] I:\Awolnation - Megalithic Symphony 320kbps mp3
[29/08/2012 - 01:27:37 | D ] I:\BASS
[02/12/2011 - 22:30:51 | N | 746989568] I:\Benga.v.zaloze.2010.DVDRip.XviD.CZ.MY.avi
[29/08/2012 - 01:29:29 | D ] I:\best of classical music
[26/05/2012 - 12:12:51 | N | 1457575661] I:\Blind Guardian – Nightfall In Middle-Earth, 1998.flac
[01/04/2012 - 16:52:06 | N | 35796324] I:\Boemerang (HIGH QUALITY) - YouTube_0.mp4
[24/09/2012 - 08:09:27 | D ] I:\Cinema Paradiso [1988] Ita 1080p
[11/11/2012 - 17:27:48 | D ] I:\Clouding
[24/10/2012 - 18:07:19 | D ] I:\Digital.Video.Essentials.HD-DVD.1080p.VC-1.DTrueHD.5.1
[29/08/2012 - 01:29:37 | D ] I:\DORO PESCH
[24/11/2012 - 20:38:13 | D ] I:\End of Watch
[29/08/2012 - 01:29:47 | D ] I:\Epica - Requiem For The Indifferent (2012) DutchReleaseTeam
[29/08/2012 - 01:29:47 | D ] I:\Filmy
[29/08/2012 - 02:23:38 | D ] I:\FLAC
[27/09/2012 - 19:45:28 | D ] I:\Gang Story (2011)
[23/09/2012 - 23:38:06 | N | 8524427533] I:\Gladiátor.[2000].1080p.HDTV.Dts.En.Cz..mkv
[20/01/2013 - 09:49:58 | N | 6228086174] I:\Hamilton.2012.720p.BluRay.CZ.mkv
[12/12/2011 - 20:18:54 | N | 8746953140] I:\Hanna.2011.1080p.BluRay.X264-AMIABLE.CZ-GOGO.mkv
[18/11/2012 - 14:16:20 | D ] I:\HD
[29/01/2012 - 22:14:34 | N | 10629779230] I:\Headhunters.mkv
[29/01/2012 - 14:58:34 | N | 46820] I:\Headhunters.srt
[11/12/2012 - 12:47:30 | N | 17655970092] I:\House.of.Flying.Daggers.2004.BDRemux.1080p.dts.Chi.Rus.mkv
[29/08/2012 - 02:30:52 | D ] I:\Iron.Sky.2012.720p.BluRay.x264-HAiDEAF [PublicHD]
[29/08/2012 - 08:00:35 | D ] I:\Jerusalema.2008.720p.BluRay.x264-AVCHD
[18/01/2012 - 15:08:15 | N | 8529495329] I:\Killer.Elite.2011.1080p.BluRay.X264-AMIABLE.rumux.CZ.sub-FWG.mkv
[16/12/2012 - 20:37:54 | D ] I:\Lawless
[20/01/2013 - 00:17:26 | N | 4467505974] I:\Looper.2012.720p.BRRiP.XViD.DTS-LEGi0N.mkv
[23/10/2012 - 23:45:34 | D ] I:\Lucky Louie
[31/08/2012 - 12:28:52 | N | 13448614753] I:\Mama Mia.mkv
[23/09/2012 - 16:40:14 | N | 33426] I:\Mama Mia.sub
[30/09/2012 - 07:54:43 | D ] I:\Manowar
[30/09/2012 - 08:25:16 | N | 11223214646] I:\Men.in.Black.III.2012.FRENCH.1080p.BluRay.x264-AUTOPSiEHD.mkv
[23/09/2011 - 09:22:04 | N | 13496891700] I:\Metallica - Francais Pour Une Nuit (2009) [Full Blu Ray 1080i DTS][WwW.ZoNaTorrent.CoM].mkv
[08/12/2012 - 11:02:28 | D ] I:\Modern Talking & Blue System - Das Nummer 1 Album! (2010) FLAC+CUE
[29/09/2012 - 20:31:38 | N | 5083499076] I:\Muži v černém 3 - Men in Black 3 (2012) [720p] CZ 5.1 640Kbps, ENG DTS, title multi..mkv
[08/11/2012 - 11:50:13 | N | 1014786048] I:\Méďa.cz.avi
[11/11/2012 - 09:19:07 | N | 1505116160] I:\Můj otec je šílenec.avi
[11/12/2012 - 12:16:41 | N | 687950006] I:\Ohen,led-a-dynamit---Komedie,1990,xvid,CZ...avi
[28/09/2012 - 17:55:37 | N | 1386073308] I:\Okresni prebor POSLEDNI ZAPAS PEPIKA HNATKA DVDRip.XviD.AC3.CZ[lightfenix].avi
[16/09/2012 - 19:26:13 | D ] I:\Ondskan
[29/08/2012 - 08:00:42 | D ] I:\Planningtorock - W
[09/12/2012 - 20:16:43 | D ] I:\Poulet.Aux.Prunes.2011.BRRip.AC3.HORiZON-ArtSubs
[06/10/2012 - 07:52:18 | N | 11209244488] I:\Prometheus (2012) [1080p].mkv
[29/08/2012 - 08:01:32 | D ] I:\Richard Hickox LSO - Carl Orff - Carmina Burana (2008.Chandos.SACD) 24-88
[18/09/2011 - 15:27:11 | N | 11735610659] I:\sem-wtbs.1080p.mkv
[20/11/2012 - 09:51:04 | D ] I:\Star Trek Voyager
[29/08/2012 - 08:04:22 | D ] I:\STREAM
[29/08/2012 - 07:47:32 | SHD ] I:\System Volume Information
[29/08/2012 - 07:53:12 | D ] I:\Teräsbetoni - Metallitotuus
[29/04/2012 - 05:50:22 | N | 9350665089] I:\The Devils Double 2011 BluRay 1080p DTS x264-CHD.mkv
[29/08/2012 - 07:53:21 | D ] I:\The Greatest Hits [Sanctuary]
[29/08/2012 - 07:53:45 | D ] I:\The Knife In Collaboration With Mt. Sims And Planningtorock - Tomorrow, In A Year (2010)
[29/08/2012 - 07:54:25 | D ] I:\Top 1000 Pop Hits of the 80s (4.32gb)
[28/09/2011 - 09:47:28 | N | 19957708051] I:\Transformers.mkv
[28/09/2011 - 09:55:57 | N | 119864] I:\Transformers.srt
[29/08/2012 - 07:56:38 | D ] I:\ULTRA BASS
[09/05/2000 - 02:01:49 | D ] I:\user_font
[01/09/2012 - 23:59:05 | D ] I:\Videoclips
[20/09/2011 - 21:20:41 | N | 6698201902] I:\Yanni Live! The Concert Event (2006).mkv
[29/08/2012 - 08:07:27 | D ] I:\Yello - Touch Yello (2009) [FLAC]
[29/08/2012 - 08:37:31 | D ] I:\Zaloha D
[09/12/2012 - 08:06:50 | N | 779194368] I:\Zapisnik jednej lasky.avi
[17/03/2012 - 21:40:48 | N | 732870656] I:\Zena v cernem - The Woman in Black 2012.avi
[24/12/2012 - 12:44:56 | D ] I:\Zlaté vánoční koledy
[19/09/2011 - 18:39:57 | N | 4687701551] I:\[HD 1080p ENG DTS] Flight 666 Film PART1 [HDitaly].mkv
[19/09/2011 - 18:40:02 | N | 4679170267] I:\[HD 1080p ENG DTS] Flight 666 Film PART2 [HDitaly].mkv
[29/04/2012 - 04:17:48 | N | 950002564] I:\Ďáblův-dvojník---The-Devil's-Double-(2011)-CZ-BRRip-XviD.avi

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_MIROMEN-PC.zip
http://eldesaparecido.com/upload.php
Thank you for your contribution.

################## | E.O.F |

Re: Podivne chování

Napsal: 21 led 2013 19:50
od miromen
Takže na mě vyskočilo okno s vykřičnikem kde je napsano MBR maybe abnormal. :roll:
Jinak vypalovani neni problem. :)
A hrozně velke diky za ochotu. :thumbsup:

Re: Podivne chování

Napsal: 22 led 2013 18:27
od miromen
Taky tě vitam....
No tak zde jsem v koncich nebo přesněji řečeno zde konči me schopnosti. Ač mam hlavu jak 100kg hřib tak tvuj postup se mi nepodařilo dokončit. Skončil jsem prakticky hned na začatku kdy jsem nabootoval CD knk DVD a v prostředi Reatogo-X-PE se mi nepodařilo spustit OTLpe. Proč nebo jakto to se mě neptej prostě to nešlo. :(

Re: Podivne chování

Napsal: 22 led 2013 18:33
od miromen
A nevadi že už jsem na W7 ?

Re: Podivne chování

Napsal: 22 led 2013 18:37
od miromen
Ok