Stránka 1 z 1

Prosím o kontrolu, vir PWS:Win32Sinowal.gen!Y

Napsal: 24 led 2013 18:31
od matej04
Dobrý den, asi 2 týdny mám problém s virem PWS:Win32Sinowal.gen!Y, antivir najde a vloží do karantény po zapnutí internetového prohlížeče se opět objeví a antivir jej opět nalezne. Několikrát jsem dělal úplnou kontrolu. I po použití jiných antiviru. Používám Microsoft Security Essentials. Vždy nalezne :

Kategorie: Program zcizující hesla

Popis: Tento program je nebezpečný. Zachycuje uživatelská hesla.

Doporučená akce: Ihned tento software odeberte.

Položky:
file:C:\Windows\temp\wqgrlsodlv\plugin.dll
-----------------------------------------------------------------------------------------------------------------------

Logfile of random's system information tool 1.09 (written by random/random)
Run by Asus at 2013-01-24 18:16:23
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 21 GB (9%) free of 238 GB
Total RAM: 4095 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:16:36, on 24.1.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Asus.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=109980 ... 5d39d352a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {EFAE8C33-9E35-406B-8E13-EAB9A1C6FB69} (NB_Activate Control) - http://sip.asus.com/Windows7_Activation ... tivate.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FastBootAgent - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10038 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"taskhost.exe"
taskeng.exe {5CAE9B00-43ED-4D77-ABB4-7BE9862FCE4B}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe"
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
Atouch64.exe
"C:\Program Files\Windows Sidebar\sidebar.exe"
ATKOSD.exe
KBFiltr.exe
WDC.exe
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
"C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe" -scan -congrats
"taskhost.exe"
"C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/Plus/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/19/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="4432.0.673785247\211803805" /prefetch:3
"C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4432.1.488168878\1741922119" --supports-dual-gpus=false --skip-gpu-full-info-collection --gpu-vendor-id=0x10de --gpu-device-id=0x0873 --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.15.11.8619 --ignored=" --type=renderer " /prefetch:12
"C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4432.2.671452323\1595787799" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Users\Asus\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/Plus/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/19/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="4432.4.963169601\1194958011" /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Asus\Downloads\RSITx64.exe"
"C:\Program Files\Microsoft Security Client\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 3FDFBFB3-0EB8-8A64-7C90-CA682A324376 -Reinvoke
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2882463467-1515623756-1338748403-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2882463467-1515623756-1338748403-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2882463467-1515623756-1338748403-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2882463467-1515623756-1338748403-1000UA.job
C:\Windows\tasks\SpeedyPC Pro Startup.job
C:\Windows\tasks\SpeedyPC Pro.job
C:\Windows\tasks\SpeedyPC Registration3.job
C:\Windows\tasks\SpeedyPC Update Version3 Startup Task.job
C:\Windows\tasks\SpeedyPC Update Version3.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-04-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-04-15 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-04-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2011-04-21 1535808]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2011-04-21 1000768]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-06-11 16328736]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-28 7982112]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 617856]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-04-09 320000]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2012-09-12 1289704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1840720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\Asus\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FPVProTrialInfo]
C:\Program Files (x86)\FastPictureViewer\FPVTrialInfo.exe [2011-11-07 328936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Asus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-18 116648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.2\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-07-13 17418928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\T-Mobile Communication Centre]
C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe [2008-07-23 1496312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~2\MCAFEE~1\30E3C3~1.285\SSSCHE~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Asus^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~2\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2005-03-16 113664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [2009-04-02 98304]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [2009-07-07 8493624]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [2009-04-20 159744]
"SSBkgdUpdate"=C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\AsScrProlog.exe [2010-04-23 72248]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-04-23 3054136]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-01-24 18:16:24 ----D---- C:\Program Files\trend micro
2013-01-24 18:16:23 ----D---- C:\rsit
2013-01-24 17:51:02 ----A---- C:\autoexec.bat
2013-01-24 17:50:40 ----A---- C:\Windows\system32\drivers\EsgScanner.sys
2013-01-24 17:50:30 ----D---- C:\sh4ldr
2013-01-24 17:50:30 ----D---- C:\Program Files\Enigma Software Group
2013-01-24 17:44:51 ----D---- C:\Windows\83B952C7F8F34CA3B4C533C85B24E478.TMP
2013-01-24 17:38:51 ----D---- C:\Users\Asus\AppData\Roaming\SpeedyPC Software
2013-01-24 17:38:51 ----D---- C:\Users\Asus\AppData\Roaming\DriverCure
2013-01-24 17:38:24 ----D---- C:\ProgramData\SpeedyPC Software
2013-01-24 17:38:24 ----D---- C:\Program Files (x86)\SpeedyPC Software
2013-01-24 12:50:43 ----SHD---- C:\$RECYCLE.BIN
2013-01-24 12:47:31 ----D---- C:\Windows\temp
2013-01-24 12:47:29 ----A---- C:\ComboFix.txt
2013-01-24 12:34:16 ----A---- C:\Windows\zip.exe
2013-01-24 12:34:16 ----A---- C:\Windows\SWSC.exe
2013-01-24 12:34:16 ----A---- C:\Windows\SWREG.exe
2013-01-24 12:34:16 ----A---- C:\Windows\sed.exe
2013-01-24 12:34:16 ----A---- C:\Windows\PEV.exe
2013-01-24 12:34:16 ----A---- C:\Windows\NIRCMD.exe
2013-01-24 12:34:16 ----A---- C:\Windows\MBR.exe
2013-01-24 12:34:16 ----A---- C:\Windows\grep.exe
2013-01-24 12:33:01 ----D---- C:\Qoobox
2013-01-24 12:32:42 ----D---- C:\Windows\erdnt
2013-01-23 20:02:59 ----A---- C:\Windows\ntbtlog.txt
2013-01-20 21:34:29 ----D---- C:\Program Files (x86)\BatchPhoto
2013-01-20 20:42:19 ----D---- C:\ProgramData\AVS4YOU
2013-01-20 20:42:17 ----D---- C:\Users\Asus\AppData\Roaming\AVS4YOU
2013-01-20 20:40:51 ----A---- C:\Windows\SYSWOW64\msxml3a.dll
2013-01-20 20:40:50 ----D---- C:\Program Files (x86)\AVS4YOU
2013-01-20 16:51:55 ----D---- C:\ProgramData\ReaConverter
2013-01-20 16:43:51 ----D---- C:\Users\Asus\AppData\Roaming\RCP 6
2013-01-20 16:43:30 ----D---- C:\Program Files (x86)\ReaConverter 6.8 Standard
2013-01-18 20:27:06 ----D---- C:\Program Files\CCleaner
2013-01-17 18:47:18 ----D---- C:\ProgramData\f3bcf942-cbaf-41ec-a77e-ec1219d67cad
2013-01-16 20:50:31 ----D---- C:\Program Files (x86)\ESET
2013-01-15 14:48:08 ----A---- C:\Windows\system32\mshtml.dll
2013-01-15 14:48:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-01-10 08:24:40 ----D---- C:\Program Files (x86)\Corel
2013-01-09 15:09:46 ----A---- C:\Windows\system32\win32spl.dll
2013-01-09 15:09:45 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-09 15:09:19 ----A---- C:\Windows\system32\msxml6.dll
2013-01-09 15:09:17 ----A---- C:\Windows\system32\msxml3.dll
2013-01-09 15:09:16 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-09 15:09:15 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-09 15:09:13 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-09 15:09:13 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 15:09:11 ----A---- C:\Windows\system32\usp10.dll
2013-01-09 15:09:10 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-09 15:09:00 ----A---- C:\Windows\system32\Wpc.dll
2013-01-09 15:08:59 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-09 15:08:59 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-09 15:08:59 ----A---- C:\Windows\system32\gameux.dll
2013-01-09 15:07:57 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-09 15:07:56 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-09 15:07:55 ----A---- C:\Windows\system32\kernel32.dll
2013-01-09 15:07:54 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-09 15:07:54 ----A---- C:\Windows\system32\wow64win.dll
2013-01-09 15:07:54 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-09 15:07:54 ----A---- C:\Windows\system32\wow64.dll
2013-01-09 15:07:54 ----A---- C:\Windows\system32\winsrv.dll
2013-01-09 15:07:54 ----A---- C:\Windows\system32\conhost.exe
2013-01-09 15:07:53 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 15:07:53 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-09 15:07:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-09 15:07:53 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-09 15:07:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 15:07:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 15:07:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 15:07:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 15:07:51 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 15:07:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 15:07:50 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 15:07:50 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 15:07:50 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 15:07:50 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 15:07:49 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 15:07:48 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 15:07:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 15:07:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 15:07:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 15:07:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 15:07:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 15:07:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 15:07:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 15:07:45 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 15:07:45 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 15:07:45 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-09 15:07:45 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-09 15:07:43 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-09 15:06:56 ----A---- C:\Windows\system32\taskhost.exe
2013-01-09 15:06:55 ----A---- C:\Windows\system32\win32k.sys
2013-01-06 19:16:45 ----D---- C:\Users\Asus\AppData\Roaming\Adobe Mini Bridge CS5
2013-01-06 19:16:44 ----D---- C:\Users\Asus\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-01-01 19:32:27 ----D---- C:\Users\Asus\AppData\Roaming\Telefónica Móviles
2013-01-01 19:31:41 ----A---- C:\Windows\system32\drivers\ewusbdev.sys
2013-01-01 19:31:20 ----D---- C:\Program Files (x86)\O2

======List of files/folders modified in the last 1 month======

2013-01-24 18:16:24 ----RD---- C:\Program Files
2013-01-24 17:50:47 ----SHD---- C:\Windows\Installer
2013-01-24 17:50:41 ----D---- C:\Windows\system32\drivers
2013-01-24 17:50:39 ----D---- C:\Windows\system32\Tasks
2013-01-24 17:50:35 ----SD---- C:\Users\Asus\AppData\Roaming\Microsoft
2013-01-24 17:50:11 ----SHD---- C:\System Volume Information
2013-01-24 17:44:51 ----D---- C:\Windows
2013-01-24 17:38:59 ----D---- C:\Windows\Tasks
2013-01-24 17:38:28 ----D---- C:\Program Files (x86)\Common Files
2013-01-24 17:38:24 ----RD---- C:\Program Files (x86)
2013-01-24 17:38:24 ----D---- C:\ProgramData
2013-01-24 17:36:24 ----D---- C:\Windows\system32\config
2013-01-24 13:53:06 ----D---- C:\Windows\System32
2013-01-24 13:53:06 ----D---- C:\Windows\inf
2013-01-24 13:53:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-24 12:44:13 ----A---- C:\Windows\system.ini
2013-01-24 12:44:08 ----D---- C:\Windows\system32\drivers\etc
2013-01-24 12:43:18 ----D---- C:\Windows\SysWOW64
2013-01-24 12:40:55 ----D---- C:\Windows\SYSWOW64\drivers
2013-01-24 12:40:55 ----D---- C:\Windows\AppPatch
2013-01-24 12:31:48 ----D---- C:\Users\Asus\AppData\Roaming\ICQ
2013-01-22 14:48:08 ----D---- C:\Windows\Prefetch
2013-01-20 22:20:21 ----D---- C:\Program Files (x86)\Google
2013-01-20 22:04:46 ----D---- C:\Users\Asus\AppData\Roaming\Skype
2013-01-20 20:41:24 ----D---- C:\Windows\winsxs
2013-01-19 12:45:38 ----D---- C:\Windows\system32\catroot2
2013-01-18 23:09:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-01-18 22:44:05 ----D---- C:\Users\Asus\AppData\Roaming\Mozilla
2013-01-18 20:29:25 ----D---- C:\Users\Asus\AppData\Roaming\DAEMON Tools Lite
2013-01-18 20:29:19 ----D---- C:\Windows\ModemLogs
2013-01-18 20:29:13 ----D---- C:\Windows\Logs
2013-01-18 20:29:12 ----D---- C:\Windows\Minidump
2013-01-18 20:29:12 ----D---- C:\Windows\debug
2013-01-18 20:19:32 ----D---- C:\Windows\pss
2013-01-15 14:43:06 ----D---- C:\Windows\system32\catroot
2013-01-13 17:44:43 ----D---- C:\Windows\system32\sysprep
2013-01-10 18:08:57 ----D---- C:\Windows\rescache
2013-01-10 17:45:27 ----D---- C:\Windows\Microsoft.NET
2013-01-10 17:45:26 ----RSD---- C:\Windows\assembly
2013-01-10 08:35:19 ----D---- C:\ProgramData\CorelDRAW Graphics Suite X5
2013-01-10 08:33:16 ----D---- C:\ProgramData\Microsoft Help
2013-01-10 08:31:13 ----D---- C:\ProgramData\Corel
2013-01-10 08:13:22 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-01-10 08:13:21 ----D---- C:\Windows\system32\cs-CZ
2013-01-09 22:43:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-01-09 22:33:39 ----A---- C:\Windows\system32\MRT.exe
2013-01-09 19:11:57 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-01-06 20:43:46 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2013-01-01 19:31:40 ----D---- C:\Windows\system32\DriverStore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2010-04-23 35384]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-08-30 228768]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-07-30 241696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-13 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-09 140800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-28 1966624]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2009-05-26 40448]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2012-06-22 22704]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-14 100920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 FastBootAgent;FastBootAgent; C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-09-12 22072]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-06-11 382496]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-07-04 66872]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2012-10-10 1021888]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2011-09-14 72704]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 251400]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-12 1431888]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-06-07 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Prosím o kontrolu, vir PWS:Win32Sinowal.gen!Y

Napsal: 24 led 2013 18:38
od Rudy
Zdravím!
Stáhněte, rozbalte a spusťte TDSSKiller: http://support.kaspersky.com/downloads/ ... killer.zip . Nechte pracovat po skončení akce sem dejte log.

Re: Prosím o kontrolu, vir PWS:Win32Sinowal.gen!Y

Napsal: 24 led 2013 18:57
od matej04
Tady je log z TDSSkilleru. :) Díky.

18:54:48.0446 1164 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
18:54:48.0605 1164 ============================================================
18:54:48.0605 1164 Current date / time: 2013/01/24 18:54:48.0605
18:54:48.0605 1164 SystemInfo:
18:54:48.0605 1164
18:54:48.0605 1164 OS Version: 6.1.7601 ServicePack: 1.0
18:54:48.0605 1164 Product type: Workstation
18:54:48.0606 1164 ComputerName: ASUS-PC
18:54:48.0606 1164 UserName: Asus
18:54:48.0606 1164 Windows directory: C:\Windows
18:54:48.0606 1164 System windows directory: C:\Windows
18:54:48.0606 1164 Running under WOW64
18:54:48.0606 1164 Processor architecture: Intel x64
18:54:48.0606 1164 Number of processors: 2
18:54:48.0606 1164 Page size: 0x1000
18:54:48.0606 1164 Boot type: Normal boot
18:54:48.0606 1164 ============================================================
18:54:50.0198 1164 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:54:50.0203 1164 ============================================================
18:54:50.0203 1164 \Device\Harddisk0\DR0:
18:54:50.0203 1164 MBR partitions:
18:54:50.0203 1164 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C3000
18:54:50.0221 1164 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D1C4000, BlocksNum 0x1D1C1800
18:54:50.0221 1164 ============================================================
18:54:50.0272 1164 C: <-> \Device\Harddisk0\DR0\Partition1
18:54:50.0360 1164 D: <-> \Device\Harddisk0\DR0\Partition2
18:54:50.0360 1164 ============================================================
18:54:50.0360 1164 Initialize success
18:54:50.0360 1164 ============================================================
18:54:53.0047 2736 ============================================================
18:54:53.0047 2736 Scan started
18:54:53.0047 2736 Mode: Manual;
18:54:53.0047 2736 ============================================================
18:54:53.0839 2736 ================ Scan system memory ========================
18:54:53.0839 2736 System memory - ok
18:54:53.0840 2736 ================ Scan services =============================
18:54:54.0303 2736 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:54:54.0306 2736 1394ohci - ok
18:54:54.0344 2736 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:54:54.0347 2736 ACPI - ok
18:54:54.0383 2736 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:54:54.0384 2736 AcpiPmi - ok
18:54:54.0494 2736 [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
18:54:54.0496 2736 Adobe LM Service - ok
18:54:54.0719 2736 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
18:54:54.0722 2736 AdobeFlashPlayerUpdateSvc - ok
18:54:54.0787 2736 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:54:54.0793 2736 adp94xx - ok
18:54:54.0842 2736 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:54:54.0847 2736 adpahci - ok
18:54:54.0872 2736 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:54:54.0874 2736 adpu320 - ok
18:54:54.0956 2736 [ C0BF554D2277F7A4C735D475ADE2E3B2 ] ADSMService C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
18:54:54.0959 2736 ADSMService - ok
18:54:54.0985 2736 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:54:54.0987 2736 AeLookupSvc - ok
18:54:55.0036 2736 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
18:54:55.0040 2736 AFD - ok
18:54:55.0087 2736 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:54:55.0088 2736 agp440 - ok
18:54:55.0121 2736 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
18:54:55.0122 2736 ALG - ok
18:54:55.0157 2736 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
18:54:55.0157 2736 aliide - ok
18:54:55.0175 2736 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
18:54:55.0176 2736 amdide - ok
18:54:55.0233 2736 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:54:55.0233 2736 AmdK8 - ok
18:54:55.0251 2736 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:54:55.0252 2736 AmdPPM - ok
18:54:55.0298 2736 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:54:55.0300 2736 amdsata - ok
18:54:55.0318 2736 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:54:55.0319 2736 amdsbs - ok
18:54:55.0337 2736 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:54:55.0337 2736 amdxata - ok
18:54:55.0403 2736 [ 391887990CDAA83DE5C56C3FDE966DA1 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
18:54:55.0404 2736 AmUStor - ok
18:54:55.0448 2736 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
18:54:55.0449 2736 AppID - ok
18:54:55.0480 2736 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:54:55.0482 2736 AppIDSvc - ok
18:54:55.0516 2736 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
18:54:55.0518 2736 Appinfo - ok
18:54:55.0578 2736 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
18:54:55.0580 2736 arc - ok
18:54:55.0597 2736 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:54:55.0599 2736 arcsas - ok
18:54:55.0660 2736 [ 88FBC8BEBFD38566235EAA5E4DBC4E05 ] AsDsm C:\Windows\system32\drivers\AsDsm.sys
18:54:55.0661 2736 AsDsm - ok
18:54:55.0726 2736 [ EB1807795CD3EEAA3288B4A30DE254E8 ] ASLDRService C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
18:54:55.0728 2736 ASLDRService - ok
18:54:55.0789 2736 [ 2DB34EDD17D3A8DA7105A19C95A3DD68 ] ASMMAP64 C:\Program Files\ATKGFNEX\ASMMAP64.sys
18:54:55.0790 2736 ASMMAP64 - ok
18:54:55.0922 2736 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
18:54:55.0924 2736 aspnet_state - ok
18:54:55.0963 2736 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:54:55.0964 2736 AsyncMac - ok
18:54:56.0010 2736 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
18:54:56.0011 2736 atapi - ok
18:54:56.0069 2736 [ 0ACC06FCF46F64ED4F11E57EE461C1F4 ] athr C:\Windows\system32\DRIVERS\athrx.sys
18:54:56.0085 2736 athr - ok
18:54:56.0126 2736 [ 7C157574A181B19B9DCF5F339E25337E ] ATKGFNEXSrv C:\Program Files\ATKGFNEX\GFNEXSrv.exe
18:54:56.0127 2736 ATKGFNEXSrv - ok
18:54:56.0173 2736 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:54:56.0178 2736 AudioEndpointBuilder - ok
18:54:56.0205 2736 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
18:54:56.0210 2736 AudioSrv - ok
18:54:56.0304 2736 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:54:56.0306 2736 AxInstSV - ok
18:54:56.0365 2736 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
18:54:56.0369 2736 b06bdrv - ok
18:54:56.0422 2736 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
18:54:56.0425 2736 b57nd60a - ok
18:54:56.0465 2736 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
18:54:56.0467 2736 BDESVC - ok
18:54:56.0486 2736 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
18:54:56.0487 2736 Beep - ok
18:54:56.0556 2736 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
18:54:56.0563 2736 BFE - ok
18:54:56.0615 2736 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
18:54:56.0626 2736 BITS - ok
18:54:56.0659 2736 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:54:56.0660 2736 blbdrive - ok
18:54:56.0694 2736 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:54:56.0695 2736 bowser - ok
18:54:56.0734 2736 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:54:56.0735 2736 BrFiltLo - ok
18:54:56.0754 2736 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:54:56.0755 2736 BrFiltUp - ok
18:54:56.0773 2736 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
18:54:56.0775 2736 BridgeMP - ok
18:54:56.0801 2736 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
18:54:56.0803 2736 Browser - ok
18:54:56.0827 2736 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:54:56.0830 2736 Brserid - ok
18:54:56.0848 2736 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:54:56.0849 2736 BrSerWdm - ok
18:54:56.0900 2736 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:54:56.0903 2736 BrUsbMdm - ok
18:54:56.0922 2736 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:54:56.0923 2736 BrUsbSer - ok
18:54:56.0951 2736 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:54:56.0952 2736 BTHMODEM - ok
18:54:56.0988 2736 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
18:54:56.0989 2736 bthserv - ok
18:54:57.0018 2736 catchme - ok
18:54:57.0035 2736 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:54:57.0037 2736 cdfs - ok
18:54:57.0087 2736 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
18:54:57.0088 2736 cdrom - ok
18:54:57.0127 2736 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
18:54:57.0128 2736 CertPropSvc - ok
18:54:57.0168 2736 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:54:57.0168 2736 circlass - ok
18:54:57.0207 2736 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
18:54:57.0211 2736 CLFS - ok
18:54:57.0272 2736 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:54:57.0275 2736 clr_optimization_v2.0.50727_32 - ok
18:54:57.0321 2736 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:54:57.0323 2736 clr_optimization_v2.0.50727_64 - ok
18:54:57.0422 2736 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:54:57.0425 2736 clr_optimization_v4.0.30319_32 - ok
18:54:57.0441 2736 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:54:57.0444 2736 clr_optimization_v4.0.30319_64 - ok
18:54:57.0481 2736 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:54:57.0482 2736 CmBatt - ok
18:54:57.0498 2736 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:54:57.0500 2736 cmdide - ok
18:54:57.0536 2736 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
18:54:57.0540 2736 CNG - ok
18:54:57.0563 2736 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:54:57.0564 2736 Compbatt - ok
18:54:57.0616 2736 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:54:57.0617 2736 CompositeBus - ok
18:54:57.0636 2736 COMSysApp - ok
18:54:57.0655 2736 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:54:57.0656 2736 crcdisk - ok
18:54:57.0708 2736 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:54:57.0711 2736 CryptSvc - ok
18:54:57.0765 2736 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:54:57.0775 2736 DcomLaunch - ok
18:54:57.0831 2736 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
18:54:57.0834 2736 defragsvc - ok
18:54:57.0881 2736 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:54:57.0883 2736 DfsC - ok
18:54:57.0936 2736 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
18:54:57.0941 2736 Dhcp - ok
18:54:57.0973 2736 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
18:54:57.0975 2736 discache - ok
18:54:58.0007 2736 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:54:58.0008 2736 Disk - ok
18:54:58.0039 2736 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:54:58.0042 2736 Dnscache - ok
18:54:58.0078 2736 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
18:54:58.0081 2736 dot3svc - ok
18:54:58.0111 2736 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
18:54:58.0114 2736 DPS - ok
18:54:58.0154 2736 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:54:58.0155 2736 drmkaud - ok
18:54:58.0209 2736 [ FB9BEF3401EE5ECC2603311B9C64F44A ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
18:54:58.0211 2736 dtsoftbus01 - ok
18:54:58.0273 2736 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:54:58.0283 2736 DXGKrnl - ok
18:54:58.0359 2736 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
18:54:58.0363 2736 EapHost - ok
18:54:58.0475 2736 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
18:54:58.0496 2736 ebdrv - ok
18:54:58.0550 2736 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
18:54:58.0553 2736 EFS - ok
18:54:58.0620 2736 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:54:58.0628 2736 ehRecvr - ok
18:54:58.0655 2736 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
18:54:58.0657 2736 ehSched - ok
18:54:58.0748 2736 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:54:58.0754 2736 elxstor - ok
18:54:58.0782 2736 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:54:58.0784 2736 ErrDev - ok
18:54:58.0846 2736 [ 3B32CAA07D672F8A2E0DF5CB3A873F45 ] EsgScanner C:\Windows\system32\DRIVERS\EsgScanner.sys
18:54:58.0847 2736 EsgScanner - ok
18:54:58.0887 2736 [ 1299D1EA00B7A4BF69C5869DCA31E0F6 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
18:54:58.0889 2736 ETD - ok
18:54:58.0924 2736 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
18:54:58.0928 2736 EventSystem - ok
18:54:58.0980 2736 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
18:54:58.0982 2736 exfat - ok
18:54:59.0453 2736 [ 8C89F06DBC239492E0AAAA0B0D8645EA ] FastBootAgent C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe
18:54:59.0457 2736 FastBootAgent - ok
18:54:59.0483 2736 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:54:59.0486 2736 fastfat - ok
18:54:59.0552 2736 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
18:54:59.0561 2736 Fax - ok
18:54:59.0602 2736 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:54:59.0604 2736 fdc - ok
18:54:59.0649 2736 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
18:54:59.0652 2736 fdPHost - ok
18:54:59.0670 2736 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
18:54:59.0673 2736 FDResPub - ok
18:54:59.0689 2736 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:54:59.0691 2736 FileInfo - ok
18:54:59.0717 2736 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:54:59.0718 2736 Filetrace - ok
18:54:59.0811 2736 [ 5CEE6CD43AE5844C49300EA0B1E557EE ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
18:54:59.0825 2736 FLEXnet Licensing Service 64 - ok
18:54:59.0859 2736 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:54:59.0859 2736 flpydisk - ok
18:54:59.0907 2736 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:54:59.0909 2736 FltMgr - ok
18:54:59.0961 2736 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
18:54:59.0970 2736 FontCache - ok
18:55:00.0020 2736 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:55:00.0020 2736 FontCache3.0.0.0 - ok
18:55:00.0054 2736 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:55:00.0055 2736 FsDepends - ok
18:55:00.0083 2736 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:55:00.0084 2736 Fs_Rec - ok
18:55:00.0139 2736 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:55:00.0141 2736 fvevol - ok
18:55:00.0173 2736 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:55:00.0174 2736 gagp30kx - ok
18:55:00.0224 2736 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
18:55:00.0231 2736 gpsvc - ok
18:55:00.0263 2736 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
18:55:00.0264 2736 hamachi - ok
18:55:00.0292 2736 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:55:00.0293 2736 hcw85cir - ok
18:55:00.0338 2736 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:55:00.0341 2736 HdAudAddService - ok
18:55:00.0365 2736 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:55:00.0367 2736 HDAudBus - ok
18:55:00.0385 2736 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:55:00.0385 2736 HidBatt - ok
18:55:00.0408 2736 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:55:00.0410 2736 HidBth - ok
18:55:00.0425 2736 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:55:00.0426 2736 HidIr - ok
18:55:00.0460 2736 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
18:55:00.0462 2736 hidserv - ok
18:55:00.0517 2736 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:55:00.0518 2736 HidUsb - ok
18:55:00.0564 2736 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:55:00.0569 2736 hkmsvc - ok
18:55:00.0607 2736 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:55:00.0612 2736 HomeGroupListener - ok
18:55:00.0647 2736 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:55:00.0654 2736 HomeGroupProvider - ok
18:55:00.0687 2736 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:55:00.0689 2736 HpSAMD - ok
18:55:00.0750 2736 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:55:00.0757 2736 HTTP - ok
18:55:00.0809 2736 [ 84D3088475BD9BC56ED76D6E0F740A63 ] Huawei C:\Windows\system32\DRIVERS\ewdcsc.sys
18:55:00.0810 2736 Huawei - ok
18:55:00.0861 2736 [ 8F9B0FC4EC3A8194BD4CBC5ED3E7ABEB ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys
18:55:00.0862 2736 hwdatacard - ok
18:55:00.0916 2736 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:55:00.0918 2736 hwpolicy - ok
18:55:00.0952 2736 [ B45B3647BA32749B94FA689175EC8C26 ] hwusbdev C:\Windows\system32\DRIVERS\ewusbdev.sys
18:55:00.0953 2736 hwusbdev - ok
18:55:01.0017 2736 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:55:01.0019 2736 i8042prt - ok
18:55:01.0071 2736 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:55:01.0075 2736 iaStorV - ok
18:55:01.0154 2736 [ 7A95A3AD931B97FEC5067E40636CE37F ] ICQ Service C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
18:55:01.0157 2736 ICQ Service - ok
18:55:01.0238 2736 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
18:55:01.0240 2736 IDriverT - ok
18:55:01.0301 2736 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:55:01.0312 2736 idsvc - ok
18:55:01.0349 2736 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:55:01.0350 2736 iirsp - ok
18:55:01.0408 2736 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
18:55:01.0415 2736 IKEEXT - ok
18:55:01.0538 2736 [ 0C3CF4B3BAE28E121A1689E3538F8712 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
18:55:01.0559 2736 IntcAzAudAddService - ok
18:55:01.0601 2736 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
18:55:01.0602 2736 intelide - ok
18:55:01.0642 2736 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:55:01.0643 2736 intelppm - ok
18:55:01.0683 2736 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:55:01.0687 2736 IPBusEnum - ok
18:55:01.0715 2736 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:55:01.0717 2736 IpFilterDriver - ok
18:55:01.0766 2736 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:55:01.0775 2736 iphlpsvc - ok
18:55:01.0819 2736 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:55:01.0820 2736 IPMIDRV - ok
18:55:01.0852 2736 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:55:01.0854 2736 IPNAT - ok
18:55:01.0886 2736 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:55:01.0888 2736 IRENUM - ok
18:55:01.0908 2736 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:55:01.0910 2736 isapnp - ok
18:55:01.0940 2736 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:55:01.0943 2736 iScsiPrt - ok
18:55:01.0973 2736 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
18:55:01.0974 2736 kbdclass - ok
18:55:02.0017 2736 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
18:55:02.0019 2736 kbdhid - ok
18:55:02.0051 2736 [ E63EF8C3271D014F14E2469CE75FECB4 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys
18:55:02.0053 2736 kbfiltr - ok
18:55:02.0072 2736 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
18:55:02.0076 2736 KeyIso - ok
18:55:02.0113 2736 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:55:02.0114 2736 KSecDD - ok
18:55:02.0130 2736 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:55:02.0131 2736 KSecPkg - ok
18:55:02.0161 2736 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
18:55:02.0162 2736 ksthunk - ok
18:55:02.0200 2736 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
18:55:02.0205 2736 KtmRm - ok
18:55:02.0248 2736 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
18:55:02.0254 2736 LanmanServer - ok
18:55:02.0295 2736 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:55:02.0300 2736 LanmanWorkstation - ok
18:55:02.0335 2736 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:55:02.0336 2736 lltdio - ok
18:55:02.0376 2736 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:55:02.0380 2736 lltdsvc - ok
18:55:02.0400 2736 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:55:02.0403 2736 lmhosts - ok
18:55:02.0458 2736 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:55:02.0459 2736 LSI_FC - ok
18:55:02.0476 2736 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:55:02.0477 2736 LSI_SAS - ok
18:55:02.0492 2736 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:55:02.0493 2736 LSI_SAS2 - ok
18:55:02.0513 2736 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:55:02.0514 2736 LSI_SCSI - ok
18:55:02.0544 2736 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
18:55:02.0546 2736 luafv - ok
18:55:02.0585 2736 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:55:02.0588 2736 Mcx2Svc - ok
18:55:02.0607 2736 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:55:02.0608 2736 megasas - ok
18:55:02.0653 2736 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:55:02.0655 2736 MegaSR - ok
18:55:02.0729 2736 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
18:55:02.0732 2736 Microsoft Office Groove Audit Service - ok
18:55:02.0767 2736 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
18:55:02.0772 2736 MMCSS - ok
18:55:02.0812 2736 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
18:55:02.0813 2736 Modem - ok
18:55:02.0840 2736 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:55:02.0841 2736 monitor - ok
18:55:02.0873 2736 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:55:02.0887 2736 mouclass - ok
18:55:02.0920 2736 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:55:02.0921 2736 mouhid - ok
18:55:02.0951 2736 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:55:02.0953 2736 mountmgr - ok
18:55:03.0013 2736 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
18:55:03.0015 2736 MpFilter - ok
18:55:03.0035 2736 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
18:55:03.0037 2736 mpio - ok
18:55:03.0067 2736 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:55:03.0068 2736 mpsdrv - ok
18:55:03.0110 2736 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:55:03.0118 2736 MpsSvc - ok
18:55:03.0159 2736 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:55:03.0161 2736 MRxDAV - ok
18:55:03.0193 2736 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:55:03.0195 2736 mrxsmb - ok
18:55:03.0244 2736 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:55:03.0247 2736 mrxsmb10 - ok
18:55:03.0263 2736 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:55:03.0266 2736 mrxsmb20 - ok
18:55:03.0305 2736 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
18:55:03.0306 2736 msahci - ok
18:55:03.0338 2736 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:55:03.0340 2736 msdsm - ok
18:55:03.0363 2736 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
18:55:03.0366 2736 MSDTC - ok
18:55:03.0423 2736 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:55:03.0424 2736 Msfs - ok
18:55:03.0444 2736 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:55:03.0445 2736 mshidkmdf - ok
18:55:03.0471 2736 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:55:03.0472 2736 msisadrv - ok
18:55:03.0516 2736 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:55:03.0519 2736 MSiSCSI - ok
18:55:03.0526 2736 msiserver - ok
18:55:03.0566 2736 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:55:03.0566 2736 MSKSSRV - ok
18:55:03.0625 2736 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
18:55:03.0626 2736 MsMpSvc - ok
18:55:03.0646 2736 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:55:03.0646 2736 MSPCLOCK - ok
18:55:03.0653 2736 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:55:03.0654 2736 MSPQM - ok
18:55:03.0698 2736 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:55:03.0701 2736 MsRPC - ok
18:55:03.0739 2736 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:55:03.0740 2736 mssmbios - ok
18:55:03.0765 2736 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:55:03.0765 2736 MSTEE - ok
18:55:03.0784 2736 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:55:03.0785 2736 MTConfig - ok
18:55:03.0822 2736 [ 032D35C996F21D19A205A7C8F0B76F3C ] MTsensor C:\Windows\system32\DRIVERS\ATK64AMD.sys
18:55:03.0822 2736 MTsensor - ok
18:55:03.0853 2736 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
18:55:03.0854 2736 Mup - ok
18:55:03.0891 2736 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
18:55:03.0898 2736 napagent - ok
18:55:03.0952 2736 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:55:03.0955 2736 NativeWifiP - ok
18:55:04.0016 2736 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:55:04.0022 2736 NDIS - ok
18:55:04.0049 2736 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:55:04.0050 2736 NdisCap - ok
18:55:04.0099 2736 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:55:04.0099 2736 NdisTapi - ok
18:55:04.0137 2736 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:55:04.0138 2736 Ndisuio - ok
18:55:04.0175 2736 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:55:04.0176 2736 NdisWan - ok
18:55:04.0212 2736 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:55:04.0212 2736 NDProxy - ok
18:55:04.0251 2736 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:55:04.0251 2736 NetBIOS - ok
18:55:04.0288 2736 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:55:04.0291 2736 NetBT - ok
18:55:04.0305 2736 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
18:55:04.0308 2736 Netlogon - ok
18:55:04.0350 2736 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
18:55:04.0355 2736 Netman - ok
18:55:04.0521 2736 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:55:04.0523 2736 NetMsmqActivator - ok
18:55:04.0542 2736 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:55:04.0545 2736 NetPipeActivator - ok
18:55:04.0584 2736 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
18:55:04.0591 2736 netprofm - ok
18:55:04.0598 2736 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:55:04.0601 2736 NetTcpActivator - ok
18:55:04.0609 2736 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:55:04.0611 2736 NetTcpPortSharing - ok
18:55:04.0650 2736 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:55:04.0651 2736 nfrd960 - ok
18:55:04.0693 2736 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
18:55:04.0694 2736 NisDrv - ok
18:55:04.0727 2736 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
18:55:04.0730 2736 NisSrv - ok
18:55:04.0755 2736 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:55:04.0760 2736 NlaSvc - ok
18:55:04.0782 2736 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:55:04.0783 2736 Npfs - ok
18:55:04.0808 2736 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
18:55:04.0811 2736 nsi - ok
18:55:04.0828 2736 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:55:04.0829 2736 nsiproxy - ok
18:55:04.0907 2736 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:55:04.0919 2736 Ntfs - ok
18:55:04.0979 2736 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
18:55:04.0980 2736 Null - ok
18:55:05.0231 2736 [ 5AE348E8710F743199E7225B5DD90868 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
18:55:05.0306 2736 nvlddmkm - ok
18:55:05.0365 2736 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:55:05.0366 2736 nvraid - ok
18:55:05.0394 2736 [ E58D81FB8616D0CB55C1E36AA0B213C9 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
18:55:05.0395 2736 nvsmu - ok
18:55:05.0419 2736 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:55:05.0421 2736 nvstor - ok
18:55:05.0449 2736 [ 1978DD2EE567287D040B5A9468ECEB72 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys
18:55:05.0451 2736 nvstor64 - ok
18:55:05.0516 2736 [ EC61934CDA39114DA769E29B1DC092BE ] nvsvc C:\Windows\system32\nvvsvc.exe
18:55:05.0523 2736 nvsvc - ok
18:55:05.0560 2736 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:55:05.0561 2736 nv_agp - ok
18:55:05.0642 2736 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:55:05.0647 2736 odserv - ok
18:55:05.0679 2736 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:55:05.0680 2736 ohci1394 - ok
18:55:05.0744 2736 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:55:05.0745 2736 ose - ok
18:55:05.0798 2736 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:55:05.0804 2736 p2pimsvc - ok
18:55:05.0826 2736 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
18:55:05.0832 2736 p2psvc - ok
18:55:05.0870 2736 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:55:05.0871 2736 Parport - ok
18:55:05.0900 2736 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:55:05.0901 2736 partmgr - ok
18:55:05.0939 2736 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:55:05.0943 2736 PcaSvc - ok
18:55:05.0986 2736 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
18:55:05.0988 2736 pci - ok
18:55:06.0009 2736 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
18:55:06.0010 2736 pciide - ok
18:55:06.0049 2736 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:55:06.0051 2736 pcmcia - ok
18:55:06.0071 2736 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
18:55:06.0073 2736 pcw - ok
18:55:06.0098 2736 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:55:06.0103 2736 PEAUTH - ok
18:55:06.0254 2736 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
18:55:06.0259 2736 PerfHost - ok
18:55:06.0338 2736 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
18:55:06.0357 2736 pla - ok
18:55:06.0393 2736 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:55:06.0400 2736 PlugPlay - ok
18:55:06.0427 2736 PnkBstrA - ok
18:55:06.0451 2736 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:55:06.0454 2736 PNRPAutoReg - ok
18:55:06.0478 2736 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:55:06.0483 2736 PNRPsvc - ok
18:55:06.0521 2736 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:55:06.0526 2736 PolicyAgent - ok
18:55:06.0564 2736 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
18:55:06.0569 2736 Power - ok
18:55:06.0613 2736 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:55:06.0614 2736 PptpMiniport - ok
18:55:06.0646 2736 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:55:06.0647 2736 Processor - ok
18:55:06.0677 2736 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
18:55:06.0681 2736 ProfSvc - ok
18:55:06.0693 2736 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:55:06.0696 2736 ProtectedStorage - ok
18:55:06.0740 2736 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:55:06.0742 2736 Psched - ok
18:55:06.0816 2736 [ 543A4EF0923BF70D126625B034EF25AF ] PSI_SVC_2 c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
18:55:06.0819 2736 PSI_SVC_2 - ok
18:55:06.0882 2736 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:55:06.0898 2736 ql2300 - ok
18:55:06.0951 2736 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:55:06.0953 2736 ql40xx - ok
18:55:06.0989 2736 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
18:55:06.0996 2736 QWAVE - ok
18:55:07.0013 2736 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:55:07.0015 2736 QWAVEdrv - ok
18:55:07.0033 2736 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:55:07.0034 2736 RasAcd - ok
18:55:07.0071 2736 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:55:07.0072 2736 RasAgileVpn - ok
18:55:07.0107 2736 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
18:55:07.0111 2736 RasAuto - ok
18:55:07.0146 2736 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:55:07.0148 2736 Rasl2tp - ok
18:55:07.0207 2736 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
18:55:07.0216 2736 RasMan - ok
18:55:07.0260 2736 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:55:07.0262 2736 RasPppoe - ok
18:55:07.0275 2736 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:55:07.0277 2736 RasSstp - ok
18:55:07.0325 2736 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:55:07.0330 2736 rdbss - ok
18:55:07.0356 2736 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:55:07.0358 2736 rdpbus - ok
18:55:07.0375 2736 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:55:07.0376 2736 RDPCDD - ok
18:55:07.0407 2736 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:55:07.0409 2736 RDPENCDD - ok
18:55:07.0423 2736 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:55:07.0423 2736 RDPREFMP - ok
18:55:07.0452 2736 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:55:07.0455 2736 RDPWD - ok
18:55:07.0499 2736 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:55:07.0502 2736 rdyboost - ok
18:55:07.0526 2736 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:55:07.0529 2736 RemoteAccess - ok
18:55:07.0563 2736 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:55:07.0568 2736 RemoteRegistry - ok
18:55:07.0597 2736 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:55:07.0601 2736 RpcEptMapper - ok
18:55:07.0626 2736 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
18:55:07.0629 2736 RpcLocator - ok
18:55:07.0674 2736 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
18:55:07.0681 2736 RpcSs - ok
18:55:07.0718 2736 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:55:07.0720 2736 rspndr - ok
18:55:07.0749 2736 [ B49DC435AE3695BAC5623DD94B05732D ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
18:55:07.0751 2736 RTL8167 - ok
18:55:07.0771 2736 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
18:55:07.0774 2736 SamSs - ok
18:55:07.0809 2736 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:55:07.0810 2736 sbp2port - ok
18:55:07.0855 2736 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:55:07.0860 2736 SCardSvr - ok
18:55:07.0905 2736 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:55:07.0906 2736 scfilter - ok
18:55:07.0968 2736 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
18:55:07.0984 2736 Schedule - ok
18:55:08.0026 2736 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:55:08.0028 2736 SCPolicySvc - ok
18:55:08.0059 2736 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:55:08.0064 2736 SDRSVC - ok
18:55:08.0102 2736 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:55:08.0102 2736 secdrv - ok
18:55:08.0145 2736 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
18:55:08.0149 2736 seclogon - ok
18:55:08.0183 2736 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
18:55:08.0187 2736 SENS - ok
18:55:08.0219 2736 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:55:08.0223 2736 SensrSvc - ok
18:55:08.0249 2736 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:55:08.0250 2736 Serenum - ok
18:55:08.0309 2736 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:55:08.0311 2736 Serial - ok
18:55:08.0354 2736 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:55:08.0356 2736 sermouse - ok
18:55:08.0426 2736 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
18:55:08.0433 2736 SessionEnv - ok
18:55:08.0474 2736 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:55:08.0475 2736 sffdisk - ok
18:55:08.0490 2736 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:55:08.0492 2736 sffp_mmc - ok
18:55:08.0504 2736 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:55:08.0506 2736 sffp_sd - ok
18:55:08.0545 2736 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:55:08.0546 2736 sfloppy - ok
18:55:08.0598 2736 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:55:08.0603 2736 SharedAccess - ok
18:55:08.0645 2736 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:55:08.0655 2736 ShellHWDetection - ok
18:55:08.0683 2736 [ 1BC348CF6BAA90EC8E533EF6E6A69933 ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSG664.sys
18:55:08.0684 2736 SiSGbeLH - ok
18:55:08.0715 2736 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:55:08.0716 2736 SiSRaid2 - ok
18:55:08.0737 2736 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:55:08.0738 2736 SiSRaid4 - ok
18:55:08.0797 2736 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
18:55:08.0800 2736 SkypeUpdate - ok
18:55:08.0824 2736 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:55:08.0826 2736 Smb - ok
18:55:08.0875 2736 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:55:08.0882 2736 SNMPTRAP - ok
18:55:08.0956 2736 [ 1D8474722CDFFBB8FCA5FA12C50A05A2 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
18:55:08.0974 2736 SNP2UVC - ok
18:55:09.0019 2736 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
18:55:09.0020 2736 spldr - ok
18:55:09.0066 2736 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
18:55:09.0078 2736 Spooler - ok
18:55:09.0184 2736 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
18:55:09.0211 2736 sppsvc - ok
18:55:09.0234 2736 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:55:09.0239 2736 sppuinotify - ok
18:55:09.0355 2736 [ 8978ED1D492B1A430857A43CDD130AED ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
18:55:09.0365 2736 SpyHunter 4 Service - ok
18:55:09.0409 2736 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
18:55:09.0412 2736 srv - ok
18:55:09.0428 2736 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:55:09.0431 2736 srv2 - ok
18:55:09.0445 2736 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:55:09.0446 2736 srvnet - ok
18:55:09.0484 2736 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:55:09.0489 2736 SSDPSRV - ok
18:55:09.0510 2736 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:55:09.0515 2736 SstpSvc - ok
18:55:09.0538 2736 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:55:09.0540 2736 stexstor - ok
18:55:09.0600 2736 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
18:55:09.0609 2736 stisvc - ok
18:55:09.0643 2736 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
18:55:09.0644 2736 swenum - ok
18:55:09.0743 2736 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:55:09.0748 2736 SwitchBoard - ok
18:55:09.0792 2736 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
18:55:09.0803 2736 swprv - ok
18:55:09.0866 2736 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
18:55:09.0882 2736 SysMain - ok
18:55:09.0917 2736 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:55:09.0921 2736 TabletInputService - ok
18:55:09.0968 2736 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
18:55:09.0978 2736 TapiSrv - ok
18:55:09.0996 2736 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
18:55:10.0000 2736 TBS - ok
18:55:10.0090 2736 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:55:10.0110 2736 Tcpip - ok
18:55:10.0190 2736 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:55:10.0206 2736 TCPIP6 - ok
18:55:10.0248 2736 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:55:10.0249 2736 tcpipreg - ok
18:55:10.0286 2736 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:55:10.0287 2736 TDPIPE - ok
18:55:10.0323 2736 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:55:10.0324 2736 TDTCP - ok
18:55:10.0360 2736 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:55:10.0361 2736 tdx - ok
18:55:10.0377 2736 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:55:10.0378 2736 TermDD - ok
18:55:10.0418 2736 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
18:55:10.0427 2736 TermService - ok
18:55:10.0456 2736 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
18:55:10.0461 2736 Themes - ok
18:55:10.0488 2736 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
18:55:10.0493 2736 THREADORDER - ok
18:55:10.0506 2736 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
18:55:10.0512 2736 TrkWks - ok
18:55:10.0575 2736 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:55:10.0578 2736 TrustedInstaller - ok
18:55:10.0615 2736 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:55:10.0616 2736 tssecsrv - ok
18:55:10.0669 2736 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:55:10.0670 2736 TsUsbFlt - ok
18:55:10.0715 2736 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:55:10.0717 2736 tunnel - ok
18:55:10.0750 2736 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:55:10.0751 2736 uagp35 - ok
18:55:10.0795 2736 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:55:10.0799 2736 udfs - ok
18:55:10.0837 2736 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:55:10.0844 2736 UI0Detect - ok
18:55:10.0864 2736 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:55:10.0865 2736 uliagpkx - ok
18:55:10.0915 2736 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
18:55:10.0916 2736 umbus - ok
18:55:10.0940 2736 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:55:10.0941 2736 UmPass - ok
18:55:10.0975 2736 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
18:55:10.0982 2736 upnphost - ok
18:55:11.0024 2736 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:55:11.0026 2736 usbccgp - ok
18:55:11.0059 2736 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:55:11.0060 2736 usbcir - ok
18:55:11.0100 2736 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:55:11.0101 2736 usbehci - ok
18:55:11.0151 2736 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:55:11.0154 2736 usbhub - ok
18:55:11.0165 2736 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
18:55:11.0166 2736 usbohci - ok
18:55:11.0215 2736 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:55:11.0216 2736 usbprint - ok
18:55:11.0264 2736 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
18:55:11.0265 2736 usbscan - ok
18:55:11.0297 2736 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:55:11.0298 2736 USBSTOR - ok
18:55:11.0313 2736 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
18:55:11.0314 2736 usbuhci - ok
18:55:11.0358 2736 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
18:55:11.0360 2736 usbvideo - ok
18:55:11.0394 2736 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
18:55:11.0398 2736 UxSms - ok
18:55:11.0415 2736 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
18:55:11.0418 2736 VaultSvc - ok
18:55:11.0454 2736 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:55:11.0455 2736 vdrvroot - ok
18:55:11.0498 2736 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
18:55:11.0506 2736 vds - ok
18:55:11.0539 2736 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:55:11.0539 2736 vga - ok
18:55:11.0558 2736 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
18:55:11.0559 2736 VgaSave - ok
18:55:11.0597 2736 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:55:11.0600 2736 vhdmp - ok
18:55:11.0617 2736 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
18:55:11.0618 2736 viaide - ok
18:55:11.0633 2736 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:55:11.0634 2736 volmgr - ok
18:55:11.0669 2736 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:55:11.0672 2736 volmgrx - ok
18:55:11.0699 2736 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:55:11.0701 2736 volsnap - ok
18:55:11.0745 2736 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:55:11.0747 2736 vsmraid - ok
18:55:11.0821 2736 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
18:55:11.0845 2736 VSS - ok
18:55:11.0865 2736 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
18:55:11.0866 2736 vwifibus - ok
18:55:11.0879 2736 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
18:55:11.0880 2736 vwififlt - ok
18:55:11.0911 2736 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
18:55:11.0911 2736 vwifimp - ok
18:55:11.0946 2736 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
18:55:11.0952 2736 W32Time - ok
18:55:11.0993 2736 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:55:11.0994 2736 WacomPen - ok
18:55:12.0040 2736 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:55:12.0042 2736 WANARP - ok
18:55:12.0048 2736 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:55:12.0050 2736 Wanarpv6 - ok
18:55:12.0116 2736 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:55:12.0125 2736 WatAdminSvc - ok
18:55:12.0196 2736 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
18:55:12.0216 2736 wbengine - ok
18:55:12.0261 2736 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:55:12.0267 2736 WbioSrvc - ok
18:55:12.0310 2736 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:55:12.0316 2736 wcncsvc - ok
18:55:12.0336 2736 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:55:12.0341 2736 WcsPlugInService - ok
18:55:12.0365 2736 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:55:12.0366 2736 Wd - ok
18:55:12.0410 2736 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:55:12.0415 2736 Wdf01000 - ok
18:55:12.0443 2736 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:55:12.0448 2736 WdiServiceHost - ok
18:55:12.0454 2736 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:55:12.0460 2736 WdiSystemHost - ok
18:55:12.0502 2736 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
18:55:12.0508 2736 WebClient - ok
18:55:12.0535 2736 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:55:12.0541 2736 Wecsvc - ok
18:55:12.0559 2736 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:55:12.0564 2736 wercplsupport - ok
18:55:12.0593 2736 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
18:55:12.0598 2736 WerSvc - ok
18:55:12.0648 2736 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:55:12.0648 2736 WfpLwf - ok
18:55:12.0664 2736 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:55:12.0665 2736 WIMMount - ok
18:55:12.0694 2736 WinDefend - ok
18:55:12.0712 2736 WinHttpAutoProxySvc - ok
18:55:12.0783 2736 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:55:12.0787 2736 Winmgmt - ok
18:55:12.0873 2736 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
18:55:12.0891 2736 WinRM - ok
18:55:12.0955 2736 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:55:12.0956 2736 WinUsb - ok
18:55:13.0004 2736 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
18:55:13.0014 2736 Wlansvc - ok
18:55:13.0046 2736 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:55:13.0047 2736 WmiAcpi - ok
18:55:13.0079 2736 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:55:13.0081 2736 wmiApSrv - ok
18:55:13.0115 2736 WMPNetworkSvc - ok
18:55:13.0139 2736 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:55:13.0144 2736 WPCSvc - ok
18:55:13.0181 2736 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:55:13.0187 2736 WPDBusEnum - ok
18:55:13.0221 2736 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:55:13.0222 2736 ws2ifsl - ok
18:55:13.0241 2736 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
18:55:13.0247 2736 wscsvc - ok
18:55:13.0253 2736 WSearch - ok
18:55:13.0329 2736 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
18:55:13.0350 2736 wuauserv - ok
18:55:13.0386 2736 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:55:13.0387 2736 WudfPf - ok
18:55:13.0418 2736 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:55:13.0420 2736 WUDFRd - ok
18:55:13.0449 2736 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:55:13.0455 2736 wudfsvc - ok
18:55:13.0497 2736 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
18:55:13.0503 2736 WwanSvc - ok
18:55:13.0543 2736 ================ Scan global ===============================
18:55:13.0565 2736 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
18:55:13.0600 2736 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
18:55:13.0622 2736 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
18:55:13.0654 2736 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
18:55:13.0682 2736 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
18:55:13.0688 2736 [Global] - ok
18:55:13.0689 2736 ================ Scan MBR ==================================
18:55:13.0708 2736 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
18:55:14.0441 2736 \Device\Harddisk0\DR0 - ok
18:55:14.0442 2736 ================ Scan VBR ==================================
18:55:14.0448 2736 [ 5232617D485BB20D6257CCEC3C07CC66 ] \Device\Harddisk0\DR0\Partition1
18:55:14.0452 2736 \Device\Harddisk0\DR0\Partition1 - ok
18:55:14.0480 2736 [ 2DC38C74CC1A786F31F30BE32600C555 ] \Device\Harddisk0\DR0\Partition2
18:55:14.0483 2736 \Device\Harddisk0\DR0\Partition2 - ok
18:55:14.0484 2736 ============================================================
18:55:14.0484 2736 Scan finished
18:55:14.0484 2736 ============================================================
18:55:14.0497 4968 Detected object count: 0
18:55:14.0497 4968 Actual detected object count: 0

Re: Prosím o kontrolu, vir PWS:Win32Sinowal.gen!Y

Napsal: 24 led 2013 19:56
od Rudy
Nenašel nic. Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware