Stránka 1 z 1

Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 26 črc 2013 08:10
od Pakl
Přátelé rádci, AVAST Free přece jen zpomaloval můj komp, instaloval jsem Aviru, zdá se lepší. Nicméně při skenování na skryté objekty vypíše hlášky, že "hiden files was found", aniž by dále řekla, co s tím. Jiné problémy nemám, komp běží stále stejně. Je to snad jen planý poplach? Tu je můj RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Pavel at 2013-07-26 09:00:03
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 42 GB (41%) free of 103 GB
Total RAM: 5120 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:00:18, on 26.7.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
C:\Program Files (x86)\JetToolBar\JetTB.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Utility\HotkeyP\HotkeyP.exe
C:\Program Files (x86)\SugarSync\SugarSync.exe
C:\Users\Pavel\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Users\Pavel\AppData\Roaming\Wuala\Wuala.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Pavel\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
E:\Stahy\RSIT.exe
C:\Program Files (x86)\trend micro\Pavel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, enhanced for Bing and MSN
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: LastPass Browser Helper Object - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [TrueCrypt] "C:\Program Files\TrueCrypt\TrueCrypt.exe" /q preferences /a logon
O4 - HKCU\..\Run: [HotkeyP] C:\Utility\HotkeyP\HotkeyP.exe 0
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSync.exe" -startInTray -usedelay=true
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Pavel\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Policies\Explorer\Run: [JetToolBar] C:\Program Files (x86)\JetToolBar\JetTB.exe
O4 - Startup: Dropbox.lnk = Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Privatefirewall 7.0.lnk = C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: LastPass - file://C:\Users\Pavel\AppData\Roaming\LastPass\context.html?cmd=lastpass
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Pavel\AppData\Roaming\LastPass\context.html?cmd=fillforms
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Přidat do stávajícího PDF - res://C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Spustit klienta k monitoru &1 - C:\Windows\web\AOpenClient.htm
O8 - Extra context menu item: Spustit klienta k monitoru &2 - C:\Windows\web\AOpenClient.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O21 - SSODL: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ABBYY FineReader 10 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.10.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Privacyware network service (PFNet) - Privacyware/PWI, Inc. - C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\pfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SearchAnonymizer - Unknown owner - C:\Users\Pavel\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16521 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2874635146-696550908-3422958121-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2874635146-696550908-3422958121-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-22 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-05-22 587104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95D9ECF5-2A4D-4550-BE49-70D42F71296E}]
LastPass Browser Helper Object - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll [2012-05-08 7889952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-22 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - LastPass Toolbar - C:\Users\Pavel\AppData\Roaming\LastPass\LPBar.dll [2012-05-08 7889952]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-07-19 345144]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2011-12-05 393216]
"Google Update"=C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-19 116648]
"TrueCrypt"=C:\Program Files\TrueCrypt\TrueCrypt.exe [2012-09-22 1516496]
"HotkeyP"=C:\Utility\HotkeyP\HotkeyP.exe [2011-09-23 147456]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"SugarSync"=C:\Program Files (x86)\SugarSync\SugarSync.exe [2013-06-26 12419424]
"SansaDispatch"=C:\Users\Pavel\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2013-07-24 613888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"JetToolBar"=C:\Program Files (x86)\JetToolBar\JetTB.exe [2004-05-03 569404]

C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
Privatefirewall 7.0.lnk - C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll [2012-10-30 159040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Virtual Storage Mount Notification - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll [2012-10-30 159040]
Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll [2012-04-09 158224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PFNet]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.tscc"=tsccvid.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-07-26 09:00:05 ----D---- C:\Program Files (x86)\trend micro
2013-07-26 09:00:03 ----D---- C:\rsit
2013-07-24 13:59:37 ----D---- C:\Users\Pavel\AppData\Roaming\SanDisk
2013-07-19 08:57:36 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-19 08:57:33 ----A---- C:\Windows\SysWOW64\qedit.dll
2013-07-19 08:55:55 ----A---- C:\Windows\SysWOW64\DWrite.dll
2013-07-19 08:46:51 ----D---- C:\Users\Pavel\AppData\Roaming\Mozilla

======List of files/folders modified in the last 1 month======

2013-07-26 09:00:18 ----D---- C:\Windows\Temp
2013-07-26 09:00:18 ----D---- C:\Windows\Prefetch
2013-07-26 09:00:05 ----RD---- C:\Program Files (x86)
2013-07-26 08:59:44 ----SHD---- C:\System Volume Information
2013-07-26 08:58:48 ----D---- C:\Users\Pavel\AppData\Roaming\DisplayFusion
2013-07-26 08:52:53 ----D---- C:\Users\Pavel\AppData\Roaming\Dropbox
2013-07-26 08:52:51 ----D---- C:\Users\Pavel\AppData\Roaming\Skype
2013-07-26 08:37:01 ----D---- C:\Program Files (x86)\DOSBox-0.74
2013-07-26 08:34:56 ----D---- C:\Program Files (x86)\Hesla JB
2013-07-26 08:28:15 ----D---- C:\Program Files (x86)\BibleWorks 8
2013-07-25 08:51:17 ----D---- C:\Users\Pavel\AppData\Roaming\KeePass
2013-07-24 16:20:45 ----D---- C:\Windows\System32
2013-07-24 14:26:41 ----D---- C:\Users\Pavel\AppData\Roaming\MyPhoneExplorer
2013-07-24 12:15:11 ----D---- C:\Users\Pavel\AppData\Roaming\uTorrent
2013-07-24 10:36:27 ----D---- C:\Program Files (x86)\Torrent Master
2013-07-21 14:25:32 ----D---- C:\Utility
2013-07-20 16:03:05 ----D---- C:\ProgramData\firebird
2013-07-19 11:17:10 ----D---- C:\Windows\Microsoft.NET
2013-07-19 11:16:25 ----RSD---- C:\Windows\assembly
2013-07-19 10:38:22 ----D---- C:\Windows\debug
2013-07-19 10:25:35 ----D---- C:\Windows\winsxs
2013-07-19 10:25:30 ----D---- C:\Windows\inf
2013-07-19 10:23:53 ----SHD---- C:\Config.Msi
2013-07-19 10:22:47 ----D---- C:\Windows\SysWOW64
2013-07-19 10:22:47 ----D---- C:\Program Files (x86)\Windows Defender
2013-07-19 09:16:09 ----SHD---- C:\Windows\Installer
2013-07-19 08:40:31 ----D---- C:\Windows
2013-07-19 08:40:31 ----D---- C:\Program Files (x86)\SugarSync

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys []
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys []
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys []
R0 tib_mounter;Acronis TIB Mounter; C:\Windows\system32\DRIVERS\tib_mounter.sys []
R0 vididr;Acronis Virtual Disk; C:\Windows\system32\DRIVERS\vididr.sys []
R0 vidsflt;Acronis Disk Storage Filter; C:\Windows\system32\DRIVERS\vidsflt.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys []
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys []
R1 cbfs3;cbfs3; \??\C:\Windows\system32\drivers\cbfs3.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 pwipf6;Privacyware Filter Driver; C:\Windows\system32\DRIVERS\pwipf6.sys []
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys []
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys []
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys []
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys []
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NVNET;NVIDIA nForce Ethernet Driver; C:\Windows\system32\DRIVERS\nvmf6264.sys []
R3 SSCBFS3;SugarSync CallBack File System driver v3; C:\Windows\system32\DRIVERS\sscbfs3.sys []
R3 V0530Dev;Creative Camera VF0530 Driver; C:\Windows\system32\DRIVERS\V0530Vid.sys []
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys []
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 grmnusb;grmnusb; C:\Windows\system32\drivers\grmnusb.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys []
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys []
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-11-25 814344]
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2012-09-24 1127840]
R2 afcdpsrv;Acronis Nonstop Backup Service; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-12-22 3692536]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 361984]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-07-19 108088]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-07-19 84024]
R2 Canon Driver Information Assist Service;Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe [2011-04-22 5873840]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe [2010-09-17 98304]
R2 Garmin Core Update Service;Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-03-27 185688]
R2 PFNet;Privacyware network service; C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\pfsvc.exe [2013-01-14 374600]
R2 SearchAnonymizer;SearchAnonymizer; C:\Users\Pavel\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2011-04-01 40960]
R2 Správce výběru OS;Aktivátor Správce výběru OS Acronis; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-07-07 2156952]
R2 syncagentsrv;Acronis Sync Agent Service; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-09-14 7024712]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe [2010-09-17 3735552]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-29 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-06-03 162408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-15 256904]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-02-15 654848]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-29 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 50899608]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 27 črc 2013 08:58
od vyosek
Zdravim :)

:arrow: V tomto smeru miva vetsinou Avira falesne poplachy, ale proverime...

:arrow: Vypnete pocas skenu gmerem Aviru, at nejsou v kolizi

:arrow: Stahnete aswMBR http://public.avast.com/%7Egmerek/aswMBR.exe a ulozte jej na plochu.
  • Utilitu spustte a prikazte ji, at skenuje - klik na Scan
  • Kliknutim na Save log ulozte log aswMBR na plochu
  • Obsah logu aswMBR mi sem vlozte
:arrow: Dale poprosim o gmer dle navodu kolegy
Naughty píše: :arrow: stáhni gmer http://www2.gmer.net/gmer.zip

-rozbal
- odskrkni volbu IAT/EAT
- zbytek nech nastaveno jak je
- klik na Scan, po dokonceni kontroly vloz obsah logu.

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 27 črc 2013 18:35
od Pakl
Tu je aswMBR, jeden řádek tam byl červeně, ten začínající cestou: \Driver\nvstor64[0xfffffa8004ca89e0....

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-07-27 19:03:47
-----------------------------
19:03:47.393 OS Version: Windows x64 6.1.7601 Service Pack 1
19:03:47.393 Number of processors: 2 586 0x4B02
19:03:47.395 ComputerName: PAVEL-STŮL UserName: Pavel
19:03:50.170 Initialize success
19:06:15.663 AVAST engine defs: 13072700
19:06:45.189 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000067
19:06:45.193 Disk 0 Vendor: WDC_WD50 05.0 Size: 476938MB BusType: 3
19:06:45.196 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000068
19:06:45.200 Disk 1 Vendor: WDC_WD16 05.0 Size: 152626MB BusType: 3
19:06:45.212 Disk 0 MBR read successfully
19:06:45.216 Disk 0 MBR scan
19:06:45.225 Disk 0 unknown MBR code
19:06:45.229 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 102649 MB offset 63
19:06:45.238 Disk 0 Partition - 00 05 Extended 374287 MB offset 210226590
19:06:45.265 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 353806 MB offset 210226655
19:06:45.275 Disk 0 Partition - 00 05 Extended 20481 MB offset 934822350
19:06:45.328 Disk 0 scanning C:\Windows\system32\drivers
19:06:56.109 Service scanning
19:07:25.267 Modules scanning
19:07:25.282 Disk 0 trace - called modules:
19:07:25.295 ntoskrnl.exe fltsrv.sys tdrpman.sys CLASSPNP.SYS disk.sys vidsflt.sys ACPI.sys >>UNKNOWN [0xfffffa8004bdb2c0]<<sptd.sys storport.sys hal.dll nvstor64.sys
19:07:25.303 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800521c060]
19:07:25.312 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa800521a3f0]
19:07:25.319 5 vidsflt.sys[fffff88000f2e5cd] -> nt!IofCallDriver -> [0xfffffa800507ac90]
19:07:25.329 7 ACPI.sys[fffff8800100b7a1] -> nt!IofCallDriver -> \Device\00000067[0xfffffa8004cb0060]
19:07:25.337 \Driver\nvstor64[0xfffffa8004ca89e0] -> IRP_MJ_CREATE -> 0xfffffa8004bdb2c0
19:07:26.107 AVAST engine scan C:\Windows
19:07:27.933 AVAST engine scan C:\Windows\system32
19:12:23.096 AVAST engine scan C:\Windows\system32\drivers
19:12:41.962 AVAST engine scan C:\Users\Pavel
19:17:06.841 AVAST engine scan C:\ProgramData
19:17:39.989 Scan finished successfully
19:18:18.399 Disk 0 MBR has been saved successfully to "C:\Users\Pavel\Desktop\MBR.dat"
19:18:18.409 The log file has been saved successfully to "C:\Users\Pavel\Desktop\aswMBR.txt"
_____________________________________________________

... a tu je gmer:

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-27 19:33:57
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000067 WDC_WD50 rev.05.0 465,76GB
Running: gmer.exe; Driver: C:\Users\Pavel\AppData\Local\Temp\pwloiuow.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800037b6000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff800037b602f 18 bytes [00, 00, 00, 00, 00, 00, 00, ...]
PAGE C:\Windows\system32\drivers\ataport.SYS!DllUnload fffff88000c1c4a0 12 bytes {MOV RAX, 0xfffffa80042b02a0; JMP RAX}
.text C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload fffff88004a4ed64 12 bytes {MOV RAX, 0xfffffa80055f32a0; JMP RAX}

---- User code sections - GMER 2.1 ----

.text C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe[3308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe[3308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
? C:\Windows\System32\perfnet.dll [4244] entry point in ".data" section 000000006ff85d98
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
? C:\Windows\system32\mssprxy.dll [4708] entry point in ".rdata" section 000000006f7471e6
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x62f228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x62f268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x62f1a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x62f128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x62f328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x62f368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x62f2e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x62f2a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x62f068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x62f0a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x62f028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x62f1e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x62f168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x62f0e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4744] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0xd48628; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0xd48668; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0xd485a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0xd48528; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0xd48728; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0xd48768; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0xd486e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0xd486a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0xd48468; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0xd484a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0xd48428; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0xd485e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0xd48568; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0xd484e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0xb5a228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0xb5a268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0xb5a1a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0xb5a128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0xb5a328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0xb5a368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0xb5a2e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0xb5a2a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0xb5a068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0xb5a0a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0xb5a028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0xb5a1e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0xb5a168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0xb5a0e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0xa9a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0xa9a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0xa99a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0xa9928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0xa9b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0xa9b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0xa9ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0xa9aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0xa9868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0xa98a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0xa9828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0xa99e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0xa9968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0xa98e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x4b6e28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x4b6e68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x4b6da8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x4b6d28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x4b6f28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x4b6f68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x4b6ee8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x4b6ea8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x4b6c68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x4b6ca8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x4b6c28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x4b6de8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x4b6d68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x4b6ce8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x587628; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x587668; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x5875a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x587528; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x587728; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x587768; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x5876e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x5876a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x587468; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x5874a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x587428; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x5875e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x587568; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x5874e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x2bba28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x2bba68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x2bb9a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x2bb928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x2bbb28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x2bbb68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x2bbae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x2bbaa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x2bb868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x2bb8a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x2bb828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x2bb9e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x2bb968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x2bb8e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter + 1 0000000076d59b81 11 bytes {MOV EAX, 0xffffffffde97690c; INC BYTE [RDI]; ADD [RAX], AL; JMP RAX}
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefd3d75f0 5 bytes JMP 000007fffd2700d8
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefdbc1180 5 bytes JMP 000007fffd2701b8
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefdbc1320 7 bytes JMP 000007fffd270148
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefdbc4450 6 bytes JMP 000007fffd270110
.text C:\Program Files\Microsoft Office\Office14\WINWORD.EXE[6892] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefdbc6720 10 bytes JMP 000007fffd270180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x639a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x639a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x6399a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x639928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x639b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x639b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x639ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x639aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x639868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x6398a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x639828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x6399e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x639968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x6398e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0x41ba28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0x41ba68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0x41b9a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0x41b928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0x41bb28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0x41bb68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0x41bae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0x41baa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0x41b868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0x41b8a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0x41b828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0x41b9e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0x41b968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0x41b8e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007715f991 7 bytes {MOV EDX, 0xe2ce28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007715fbd5 7 bytes {MOV EDX, 0xe2ce68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007715fc05 7 bytes {MOV EDX, 0xe2cda8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007715fc1d 7 bytes {MOV EDX, 0xe2cd28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007715fc35 7 bytes {MOV EDX, 0xe2cf28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007715fc65 7 bytes {MOV EDX, 0xe2cf68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007715fce5 7 bytes {MOV EDX, 0xe2cee8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007715fcfd 7 bytes {MOV EDX, 0xe2cea8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007715fd49 7 bytes {MOV EDX, 0xe2cc68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007715fe41 7 bytes {MOV EDX, 0xe2cca8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077160099 7 bytes {MOV EDX, 0xe2cc28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000771610a5 7 bytes {MOV EDX, 0xe2cde8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007716111d 7 bytes {MOV EDX, 0xe2cd68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077161321 7 bytes {MOV EDX, 0xe2cce8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3044] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2596] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2596] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\Users\Pavel\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe[6864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\Users\Pavel\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe[6864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2
.text C:\totalcmd\TOTALCMD.EXE[4916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ba1465 2 bytes [BA, 75]
.text C:\totalcmd\TOTALCMD.EXE[4916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ba14bb 2 bytes [BA, 75]
.text ... * 2

---- Devices - GMER 2.1 ----

Device \Driver\atapi \Device\Ide\IdePort0 fffffa80042bc2c0
Device \Driver\atapi \Device\Ide\IdePort1 fffffa80042bc2c0
Device \FileSystem\Ntfs \Ntfs fffffa8004bdf2c0
Device \Driver\nvstor64 \Device\00000068 fffffa8004bdb2c0
Device \Driver\usbuhci \Device\USBFDO-3 fffffa80053ef2c0
Device \Driver\usbehci \Device\USBPDO-1 fffffa80056182c0
Device \Driver\nvstor64 \Device\RaidPort0 fffffa8004bdb2c0
Device \Driver\cdrom \Device\CdRom0 fffffa800540d2c0
Device \Driver\nvstor64 \Device\RaidPort1 fffffa8004bdb2c0
Device \Driver\nvstor64 \Device\00000069 fffffa8004bdb2c0
Device \Driver\usbehci \Device\USBFDO-4 fffffa80056182c0
Device \Driver\usbuhci \Device\USBPDO-2 fffffa80053ef2c0
Device \Driver\usbohci \Device\USBFDO-0 fffffa80055f52c0
Device \Driver\NetBT \Device\NetBT_Tcpip_{BDBC399F-0EC9-447C-9783-916C7CA8ADCF} fffffa800542d2c0
Device \Driver\usbuhci \Device\USBPDO-3 fffffa80053ef2c0
Device \Driver\usbehci \Device\USBFDO-1 fffffa80056182c0
Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa800542d2c0
Device \Driver\nvstor64 \Device\00000067 fffffa8004bdb2c0
Device \Driver\usbehci \Device\USBPDO-4 fffffa80056182c0
Device \Driver\usbuhci \Device\USBFDO-2 fffffa80053ef2c0
Device \Driver\atapi \Device\ScsiPort0 fffffa80042bc2c0
Device \Driver\usbohci \Device\USBPDO-0 fffffa80055f52c0
Device \Driver\atapi \Device\ScsiPort1 fffffa80042bc2c0
Device \Driver\nvstor64 \Device\ScsiPort2 fffffa8004bdb2c0
Device \Driver\nvstor64 \Device\ScsiPort3 fffffa8004bdb2c0

---- Trace I/O - GMER 2.1 ----

Trace ntoskrnl.exe fltsrv.sys tdrpman.sys CLASSPNP.SYS disk.sys vidsflt.sys ACPI.sys >>UNKNOWN [0xfffffa8004bdb2c0]<< sptd.sys storport.sys hal.dll nvstor64.sys fffffa8004bdb2c0
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800521c060] fffffa800521c060
Trace 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa800521a3f0] fffffa800521a3f0
Trace 5 vidsflt.sys[fffff88000f2e5cd] -> nt!IofCallDriver -> [0xfffffa800507ac90] fffffa800507ac90
Trace 7 ACPI.sys[fffff8800100b7a1] -> nt!IofCallDriver -> \Device\00000067[0xfffffa8004cb0060] fffffa8004cb0060
Trace \Driver\nvstor64[0xfffffa8004ca89e0] -> IRP_MJ_CREATE -> 0xfffffa8004bdb2c0 fffffa8004bdb2c0

---- Threads - GMER 2.1 ----

Thread C:\Windows\system32\svchost.exe [1128:3724] 000007fef4f00ea8
Thread C:\Windows\system32\svchost.exe [1128:3268] 000007fef4ef9db0
Thread C:\Windows\system32\svchost.exe [1128:1328] 000007fef4f01c94
Thread C:\Windows\system32\svchost.exe [1128:6344] 000007fef4efaa10
Thread C:\Windows\System32\spoolsv.exe [1584:2160] 000007fef95f10c8
Thread C:\Windows\System32\spoolsv.exe [1584:2168] 000007fef95b6144
Thread C:\Windows\System32\spoolsv.exe [1584:2172] 000007fef99e5fd0
Thread C:\Windows\System32\spoolsv.exe [1584:2176] 000007fef9593438
Thread C:\Windows\System32\spoolsv.exe [1584:2180] 000007fef99e63ec
Thread C:\Windows\System32\spoolsv.exe [1584:2188] 000007fef9895e5c
Thread C:\Windows\System32\spoolsv.exe [1584:2260] 000007fef9848760
Thread C:\Windows\system32\svchost.exe [1656:2064] 000007fef9c135c0
Thread C:\Windows\system32\svchost.exe [1656:2980] 000007fef9c15600
Thread C:\Windows\system32\svchost.exe [1656:4588] 000007fefade2940
Thread C:\Windows\system32\svchost.exe [1656:4596] 000007feef892888
Thread C:\Windows\system32\svchost.exe [1656:7068] 000007feef892a40
Thread C:\Windows\system32\svchost.exe [2052:4756] 000007feebe18470
Thread C:\Windows\system32\svchost.exe [2052:4760] 000007feebe22418
Thread C:\Windows\system32\svchost.exe [2608:5048] 000007fef54644e0

---- Registry - GMER 2.1 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0x02 0xE1 0x35 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0x02 0xE1 0x35 ...

---- Disk sectors - GMER 2.1 ----

Disk \Device\Harddisk0\DR0 unknown MBR code

---- EOF - GMER 2.1 ----


A MOC DÍK!

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 27 črc 2013 20:45
od vyosek
:arrow: Stahnete SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte z uvedene stranky verzi dle sveho operacniho systemu (32(x86)bit ci 64(x64)bit)
  • Ulozte na plochu a spustte
  • Zvolte moznost Uninstall a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete Defogger http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Ulozte na plochu a spustte
  • Kliknete na Disable a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Udelejte znovu aswMBR a i gmer

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 10:27
od Pakl
Vše jsem provedl, vše šlo odkliknout.
Tady jsou oba logy:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-07-28 10:50:41
-----------------------------
10:50:41.632 OS Version: Windows x64 6.1.7601 Service Pack 1
10:50:41.633 Number of processors: 2 586 0x4B02
10:50:41.634 ComputerName: PAVEL-STŮL UserName: Pavel
10:50:42.647 Initialize success
10:51:20.022 AVAST engine defs: 13072700
10:51:31.648 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000066
10:51:31.653 Disk 0 Vendor: WDC_WD50 05.0 Size: 476938MB BusType: 3
10:51:31.657 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000067
10:51:31.660 Disk 1 Vendor: WDC_WD16 05.0 Size: 152626MB BusType: 3
10:51:31.759 Disk 0 MBR read successfully
10:51:31.764 Disk 0 MBR scan
10:51:31.772 Disk 0 unknown MBR code
10:51:31.777 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 102649 MB offset 63
10:51:31.786 Disk 0 Partition - 00 05 Extended 374287 MB offset 210226590
10:51:31.805 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 353806 MB offset 210226655
10:51:31.814 Disk 0 Partition - 00 05 Extended 20481 MB offset 934822350
10:51:31.867 Disk 0 scanning C:\Windows\system32\drivers
10:51:42.640 Service scanning
10:52:10.905 Modules scanning
10:52:10.942 Disk 0 trace - called modules:
10:52:10.976 ntoskrnl.exe fltsrv.sys tdrpman.sys CLASSPNP.SYS disk.sys vidsflt.sys ACPI.sys storport.sys hal.dll nvstor64.sys
10:52:10.984 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800522b670]
10:52:10.993 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> [0xfffffa8005228c70]
10:52:11.000 5 vidsflt.sys[fffff88000fb65cd] -> nt!IofCallDriver -> [0xfffffa8004e29860]
10:52:11.008 7 ACPI.sys[fffff88000f347a1] -> nt!IofCallDriver -> \Device\00000066[0xfffffa8004e2d9c0]
10:52:11.830 AVAST engine scan C:\Windows
10:52:13.763 AVAST engine scan C:\Windows\system32
10:56:43.051 AVAST engine scan C:\Windows\system32\drivers
10:56:56.328 AVAST engine scan C:\Users\Pavel
11:01:30.350 AVAST engine scan C:\ProgramData
11:02:11.086 Scan finished successfully
11:11:15.620 Disk 0 MBR has been saved successfully to "C:\Users\Pavel\Desktop\MBR.dat"
11:11:15.628 The log file has been saved successfully to "C:\Users\Pavel\Desktop\aswMBR.txt"
__________________________________________________________________

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-28 11:25:07
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000066 WDC_WD50 rev.05.0 465,76GB
Running: gmer.exe; Driver: C:\Users\Pavel\AppData\Local\Temp\pwloiuow.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800037b2000 45 bytes [00, 00, 16, 02, 4E, 74, 66, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff800037b202f 10 bytes [00, 01, 00, 06, 00, 00, 00, ...]
.text C:\Windows\System32\win32k.sys!XLATEOBJ_iXlate + 657 fffff960000bb441 13 bytes {MOV RAX, 0xfffff88004654a20; JMP RAX}
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000103e00 7 bytes [00, A3, F3, FF, 01, AF, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000103e08 3 bytes [C0, 06, 02]
.text ... * 106
.text C:\Windows\System32\win32k.sys!EngGetProcessHandle + 424 fffff960001c2a98 15 bytes {MOV RAX, 0xfffff88004654f70; JMP RAX}

---- User code sections - GMER 2.1 ----

.text C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe[3540] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe[3540] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\PFGUI.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 000000006fef11a8 2 bytes [EF, 6F]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 000000006fef13a8 2 bytes [EF, 6F]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 000000006fef1422 2 bytes [EF, 6F]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[4820] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 000000006fef1498 2 bytes [EF, 6F]
.text C:\Users\Pavel\AppData\Roaming\Wuala\Wuala.exe[4988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Users\Pavel\AppData\Roaming\Wuala\Wuala.exe[4988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0xba9a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0xba9a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0xba99a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0xba9928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0xba9b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0xba9b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0xba9ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0xba9aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0xba9868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0xba98a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0xba9828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0xba99e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0xba9968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0xba98e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0x743a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0x743a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0x7439a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0x743928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0x743b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0x743b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0x743ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0x743aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0x743868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0x7438a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0x743828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0x7439e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0x743968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0x7438e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1460] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0x78a228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0x78a268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0x78a1a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0x78a128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0x78a328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0x78a368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0x78a2e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0x78a2a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0x78a068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0x78a0a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0x78a028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0x78a1e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0x78a168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0x78a0e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0x579228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0x579268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0x5791a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0x579128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0x579328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0x579368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0x5792e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0x5792a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0x579068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0x5790a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0x579028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0x5791e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0x579168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0x5790e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0xbd3a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0xbd3a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0xbd39a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0xbd3928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0xbd3b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0xbd3b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0xbd3ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0xbd3aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0xbd3868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0xbd38a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0xbd3828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0xbd39e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0xbd3968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0xbd38e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0x1bc228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0x1bc268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0x1bc1a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0x1bc128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0x1bc328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0x1bc368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0x1bc2e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0x1bc2a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0x1bc068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0x1bc0a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0x1bc028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0x1bc1e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0x1bc168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0x1bc0e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0x2d0a28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0x2d0a68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0x2d09a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0x2d0928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0x2d0b28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0x2d0b68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0x2d0ae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0x2d0aa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0x2d0868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0x2d08a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0x2d0828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0x2d09e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0x2d0968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0x2d08e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 00000000778cf991 7 bytes {MOV EDX, 0xc8aa28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 00000000778cfbd5 7 bytes {MOV EDX, 0xc8aa68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000778cfc05 7 bytes {MOV EDX, 0xc8a9a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000778cfc1d 7 bytes {MOV EDX, 0xc8a928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000778cfc35 7 bytes {MOV EDX, 0xc8ab28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 00000000778cfc65 7 bytes {MOV EDX, 0xc8ab68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000778cfce5 7 bytes {MOV EDX, 0xc8aae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000778cfcfd 7 bytes {MOV EDX, 0xc8aaa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 00000000778cfd49 7 bytes {MOV EDX, 0xc8a868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000778cfe41 7 bytes {MOV EDX, 0xc8a8a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000778d0099 7 bytes {MOV EDX, 0xc8a828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000778d10a5 7 bytes {MOV EDX, 0xc8a9e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 00000000778d111d 7 bytes {MOV EDX, 0xc8a968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 00000000778d1321 7 bytes {MOV EDX, 0xc8a8e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075651465 2 bytes [65, 75]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2428] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756514bb 2 bytes [65, 75]
.text ... * 2

---- Threads - GMER 2.1 ----

Thread C:\Windows\system32\svchost.exe [1360:1568] 000007fef0858470
Thread C:\Windows\system32\svchost.exe [1360:940] 000007fef0862418
Thread C:\Windows\system32\taskhost.exe [3304:3560] 000007fef4481010
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4236:5200] 000007fefbeb2a7c

---- Registry - GMER 2.1 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0x02 0xE1 0x35 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0x02 0xE1 0x35 ...

---- Disk sectors - GMER 2.1 ----

Disk \Device\Harddisk0\DR0 unknown MBR code

---- EOF - GMER 2.1 ----

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 12:40
od vyosek
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V okne Additional Option zakliknete vsechny moznosti
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 12:55
od Pakl
Provedeno:

13:52:18.0972 5020 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:52:20.0976 5020 ============================================================
13:52:20.0976 5020 Current date / time: 2013/07/28 13:52:20.0976
13:52:20.0976 5020 SystemInfo:
13:52:20.0976 5020
13:52:20.0976 5020 OS Version: 6.1.7601 ServicePack: 1.0
13:52:20.0976 5020 Product type: Workstation
13:52:20.0976 5020 ComputerName: PAVEL-STŮL
13:52:20.0976 5020 UserName: Pavel
13:52:20.0976 5020 Windows directory: C:\Windows
13:52:20.0976 5020 System windows directory: C:\Windows
13:52:20.0976 5020 Running under WOW64
13:52:20.0976 5020 Processor architecture: Intel x64
13:52:20.0976 5020 Number of processors: 2
13:52:20.0976 5020 Page size: 0x1000
13:52:20.0976 5020 Boot type: Normal boot
13:52:20.0977 5020 ============================================================
13:52:22.0740 5020 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:52:22.0753 5020 Drive \Device\Harddisk1\DR1 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:52:22.0759 5020 ============================================================
13:52:22.0759 5020 \Device\Harddisk0\DR0:
13:52:22.0759 5020 MBR partitions:
13:52:22.0759 5020 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC87CD5F
13:52:22.0770 5020 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC87CDDF, BlocksNum 0x2B3073EF
13:52:22.0789 5020 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x37B8420D, BlocksNum 0x2800A34
13:52:22.0789 5020 \Device\Harddisk1\DR1:
13:52:22.0790 5020 MBR partitions:
13:52:22.0790 5020 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82
13:52:22.0790 5020 ============================================================
13:52:22.0819 5020 C: <-> \Device\Harddisk0\DR0\Partition1
13:52:22.0872 5020 D: <-> \Device\Harddisk0\DR0\Partition2
13:52:22.0896 5020 E: <-> \Device\Harddisk0\DR0\Partition3
13:52:22.0905 5020 F: <-> \Device\Harddisk1\DR1\Partition1
13:52:22.0905 5020 ============================================================
13:52:22.0906 5020 Initialize success
13:52:22.0906 5020 ============================================================
13:52:50.0607 5592 ============================================================
13:52:50.0607 5592 Scan started
13:52:50.0607 5592 Mode: Manual; SigCheck; TDLFS;
13:52:50.0607 5592 ============================================================
13:52:51.0524 5592 ================ Scan system memory ========================
13:52:51.0524 5592 System memory - ok
13:52:51.0525 5592 ================ Scan services =============================
13:52:51.0573 5592 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
13:52:51.0645 5592 !SASCORE ( UnsignedFile.Multi.Generic ) - warning
13:52:51.0645 5592 !SASCORE - detected UnsignedFile.Multi.Generic (1)
13:52:51.0750 5592 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
13:52:51.0791 5592 1394ohci - ok
13:52:51.0849 5592 [ 7633C00714BB85B830CAD68F441D1CBB ] ABBYY.Licensing.FineReader.Professional.10.0 C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
13:52:51.0933 5592 ABBYY.Licensing.FineReader.Professional.10.0 - ok
13:52:51.0963 5592 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
13:52:51.0985 5592 ACPI - ok
13:52:52.0039 5592 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
13:52:52.0143 5592 AcpiPmi - ok
13:52:52.0222 5592 [ F578ABFF32E9E3B9518CD59C3A931A3E ] AcrSch2Svc C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
13:52:52.0269 5592 AcrSch2Svc - ok
13:52:52.0369 5592 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:52:52.0390 5592 AdobeFlashPlayerUpdateSvc - ok
13:52:52.0419 5592 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
13:52:52.0466 5592 adp94xx - ok
13:52:52.0499 5592 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
13:52:52.0534 5592 adpahci - ok
13:52:52.0552 5592 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
13:52:52.0586 5592 adpu320 - ok
13:52:52.0615 5592 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:52:52.0666 5592 AeLookupSvc - ok
13:52:52.0712 5592 [ ABCF9C80EAACE03021BB7F450EB8993F ] afcdp C:\Windows\system32\DRIVERS\afcdp.sys
13:52:52.0760 5592 afcdp - ok
13:52:52.0849 5592 [ 37D739F9CD9D3E99F5E824C91E62200D ] afcdpsrv C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
13:52:52.0954 5592 afcdpsrv - ok
13:52:52.0983 5592 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
13:52:53.0027 5592 AFD - ok
13:52:53.0056 5592 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:52:53.0079 5592 agp440 - ok
13:52:53.0100 5592 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
13:52:53.0129 5592 ALG - ok
13:52:53.0148 5592 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
13:52:53.0168 5592 aliide - ok
13:52:53.0201 5592 [ 4EAAAAB8759644D572522FBCDD196A13 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
13:52:53.0265 5592 AMD External Events Utility - ok
13:52:53.0342 5592 AMD FUEL Service - ok
13:52:53.0351 5592 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
13:52:53.0376 5592 amdide - ok
13:52:53.0418 5592 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
13:52:53.0437 5592 amdiox64 - ok
13:52:53.0481 5592 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
13:52:53.0596 5592 AmdK8 - ok
13:52:53.0799 5592 [ 22A14DF59FB8D0BE918C597988AF4296 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:52:54.0122 5592 amdkmdag - ok
13:52:54.0156 5592 [ EE22D3ED6D55A855E709F811CCCA97ED ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
13:52:54.0204 5592 amdkmdap - ok
13:52:54.0230 5592 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
13:52:54.0314 5592 AmdPPM - ok
13:52:54.0344 5592 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
13:52:54.0368 5592 amdsata - ok
13:52:54.0388 5592 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
13:52:54.0416 5592 amdsbs - ok
13:52:54.0429 5592 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
13:52:54.0449 5592 amdxata - ok
13:52:54.0508 5592 [ 2E2B1A491CB78C7D8C8A265C004B1F79 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
13:52:54.0520 5592 AntiVirSchedulerService - ok
13:52:54.0550 5592 [ AAE3238C2A0B2CF17851B3D06C8EA8C0 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
13:52:54.0563 5592 AntiVirService - ok
13:52:54.0587 5592 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
13:52:54.0642 5592 AppID - ok
13:52:54.0663 5592 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:52:54.0723 5592 AppIDSvc - ok
13:52:54.0755 5592 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
13:52:54.0805 5592 Appinfo - ok
13:52:54.0828 5592 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
13:52:54.0859 5592 AppMgmt - ok
13:52:54.0893 5592 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
13:52:54.0920 5592 arc - ok
13:52:54.0940 5592 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
13:52:54.0965 5592 arcsas - ok
13:52:55.0044 5592 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:52:55.0073 5592 aspnet_state - ok
13:52:55.0096 5592 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:52:55.0146 5592 AsyncMac - ok
13:52:55.0164 5592 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
13:52:55.0184 5592 atapi - ok
13:52:55.0216 5592 [ 437F55435623D4D54D36197F5AD8B435 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
13:52:55.0260 5592 AtiHDAudioService - ok
13:52:55.0450 5592 [ 22A14DF59FB8D0BE918C597988AF4296 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:52:55.0633 5592 atikmdag - ok
13:52:55.0667 5592 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:52:55.0720 5592 AudioEndpointBuilder - ok
13:52:55.0742 5592 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
13:52:55.0794 5592 AudioSrv - ok
13:52:55.0824 5592 [ 09E6069EF94B345061B4BD3CEBD974C8 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
13:52:55.0848 5592 avgntflt - ok
13:52:55.0873 5592 [ 488486DAD09A5B6C6DBB8B990A8B2307 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
13:52:55.0890 5592 avipbb - ok
13:52:55.0918 5592 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
13:52:55.0933 5592 avkmgr - ok
13:52:55.0962 5592 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:52:55.0995 5592 AxInstSV - ok
13:52:56.0021 5592 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
13:52:56.0062 5592 b06bdrv - ok
13:52:56.0094 5592 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
13:52:56.0129 5592 b57nd60a - ok
13:52:56.0157 5592 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
13:52:56.0174 5592 BDESVC - ok
13:52:56.0183 5592 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
13:52:56.0230 5592 Beep - ok
13:52:56.0267 5592 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
13:52:56.0321 5592 BFE - ok
13:52:56.0347 5592 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
13:52:56.0419 5592 BITS - ok
13:52:56.0442 5592 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
13:52:56.0466 5592 blbdrive - ok
13:52:56.0516 5592 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:52:56.0561 5592 bowser - ok
13:52:56.0594 5592 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:52:57.0211 5592 BrFiltLo - ok
13:52:57.0240 5592 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:52:57.0276 5592 BrFiltUp - ok
13:52:57.0373 5592 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
13:52:57.0394 5592 Browser - ok
13:52:57.0425 5592 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
13:52:57.0459 5592 Brserid - ok
13:52:57.0477 5592 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
13:52:57.0507 5592 BrSerWdm - ok
13:52:57.0523 5592 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
13:52:57.0549 5592 BrUsbMdm - ok
13:52:57.0562 5592 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
13:52:57.0584 5592 BrUsbSer - ok
13:52:57.0604 5592 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:52:57.0641 5592 BTHMODEM - ok
13:52:57.0668 5592 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
13:52:57.0727 5592 bthserv - ok
13:52:57.0858 5592 [ 9D8A415DF6E7BEF4FC34BF0A4C5C69AC ] Canon Driver Information Assist Service C:\Program Files\Canon\DIAS\CnxDIAS.exe
13:52:58.0036 5592 Canon Driver Information Assist Service - ok
13:52:58.0083 5592 [ 555FA105C22B1616094EDAD1CBFB0551 ] cbfs3 C:\Windows\system32\drivers\cbfs3.sys
13:52:58.0118 5592 cbfs3 - ok
13:52:58.0137 5592 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:52:58.0202 5592 cdfs - ok
13:52:58.0254 5592 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:52:58.0297 5592 cdrom - ok
13:52:58.0325 5592 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
13:52:58.0394 5592 CertPropSvc - ok
13:52:58.0414 5592 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
13:52:58.0455 5592 circlass - ok
13:52:58.0488 5592 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
13:52:58.0514 5592 CLFS - ok
13:52:58.0575 5592 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:52:58.0628 5592 clr_optimization_v2.0.50727_32 - ok
13:52:58.0660 5592 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:52:58.0685 5592 clr_optimization_v2.0.50727_64 - ok
13:52:58.0816 5592 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:52:58.0842 5592 clr_optimization_v4.0.30319_32 - ok
13:52:58.0860 5592 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:52:58.0876 5592 clr_optimization_v4.0.30319_64 - ok
13:52:58.0894 5592 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:52:58.0920 5592 CmBatt - ok
13:52:58.0938 5592 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:52:58.0959 5592 cmdide - ok
13:52:58.0995 5592 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
13:52:59.0040 5592 CNG - ok
13:52:59.0055 5592 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:52:59.0077 5592 Compbatt - ok
13:52:59.0094 5592 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
13:52:59.0123 5592 CompositeBus - ok
13:52:59.0131 5592 COMSysApp - ok
13:52:59.0152 5592 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
13:52:59.0178 5592 crcdisk - ok
13:52:59.0208 5592 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:52:59.0227 5592 CryptSvc - ok
13:52:59.0254 5592 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
13:52:59.0297 5592 CSC - ok
13:52:59.0323 5592 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
13:52:59.0359 5592 CscService - ok
13:52:59.0386 5592 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:52:59.0442 5592 DcomLaunch - ok
13:52:59.0467 5592 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
13:52:59.0532 5592 defragsvc - ok
13:52:59.0552 5592 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:52:59.0608 5592 DfsC - ok
13:52:59.0641 5592 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
13:52:59.0664 5592 dg_ssudbus - ok
13:52:59.0683 5592 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
13:52:59.0710 5592 Dhcp - ok
13:52:59.0741 5592 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
13:52:59.0800 5592 discache - ok
13:52:59.0808 5592 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
13:52:59.0825 5592 Disk - ok
13:52:59.0842 5592 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:52:59.0861 5592 Dnscache - ok
13:52:59.0886 5592 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:52:59.0956 5592 dot3svc - ok
13:52:59.0984 5592 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
13:53:00.0031 5592 DPS - ok
13:53:00.0050 5592 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:53:00.0080 5592 drmkaud - ok
13:53:00.0121 5592 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:53:00.0184 5592 DXGKrnl - ok
13:53:00.0219 5592 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
13:53:00.0273 5592 EapHost - ok
13:53:00.0384 5592 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
13:53:00.0516 5592 ebdrv - ok
13:53:00.0541 5592 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
13:53:00.0560 5592 EFS - ok
13:53:00.0590 5592 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
13:53:00.0652 5592 elxstor - ok
13:53:00.0667 5592 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:53:00.0691 5592 ErrDev - ok
13:53:00.0724 5592 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
13:53:00.0777 5592 EventSystem - ok
13:53:00.0796 5592 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
13:53:00.0866 5592 exfat - ok
13:53:00.0884 5592 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:53:00.0990 5592 fastfat - ok
13:53:01.0024 5592 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
13:53:01.0070 5592 Fax - ok
13:53:01.0084 5592 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:53:01.0105 5592 fdc - ok
13:53:01.0114 5592 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
13:53:01.0164 5592 fdPHost - ok
13:53:01.0194 5592 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
13:53:01.0247 5592 FDResPub - ok
13:53:01.0262 5592 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:53:01.0286 5592 FileInfo - ok
13:53:01.0302 5592 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:53:01.0355 5592 Filetrace - ok
13:53:01.0419 5592 [ 1A18EBD87AA9FBF6EFE8CFADA08D0275 ] FirebirdGuardianDefaultInstance C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
13:53:01.0438 5592 FirebirdGuardianDefaultInstance ( UnsignedFile.Multi.Generic ) - warning
13:53:01.0439 5592 FirebirdGuardianDefaultInstance - detected UnsignedFile.Multi.Generic (1)
13:53:01.0503 5592 [ 53C740150C082AAF3C7D21C1D6A9FF98 ] FirebirdServerDefaultInstance C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
13:53:01.0607 5592 FirebirdServerDefaultInstance ( UnsignedFile.Multi.Generic ) - warning
13:53:01.0608 5592 FirebirdServerDefaultInstance - detected UnsignedFile.Multi.Generic (1)
13:53:01.0674 5592 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:53:01.0784 5592 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
13:53:01.0784 5592 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
13:53:01.0808 5592 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:53:01.0830 5592 flpydisk - ok
13:53:01.0856 5592 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:53:01.0887 5592 FltMgr - ok
13:53:01.0931 5592 [ F0CC1A9106F9FB0F704F6ED95622B43E ] fltsrv C:\Windows\system32\DRIVERS\fltsrv.sys
13:53:01.0957 5592 fltsrv - ok
13:53:02.0008 5592 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
13:53:02.0067 5592 FontCache - ok
13:53:02.0108 5592 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:53:02.0205 5592 FontCache3.0.0.0 - ok
13:53:02.0226 5592 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:53:02.0281 5592 FsDepends - ok
13:53:02.0308 5592 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:53:02.0330 5592 Fs_Rec - ok
13:53:02.0366 5592 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:53:02.0413 5592 fvevol - ok
13:53:02.0426 5592 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
13:53:02.0450 5592 gagp30kx - ok
13:53:02.0493 5592 [ 2973B4EB7BE10A0D491B2037DCAAE88F ] Garmin Core Update Service C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
13:53:02.0509 5592 Garmin Core Update Service - ok
13:53:02.0544 5592 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
13:53:02.0600 5592 gpsvc - ok
13:53:02.0641 5592 [ B9893A68032A6D9ADDB5B98287C630F7 ] grmnusb C:\Windows\system32\drivers\grmnusb.sys
13:53:02.0658 5592 grmnusb - ok
13:53:02.0692 5592 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:53:02.0709 5592 gupdate - ok
13:53:02.0715 5592 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:53:02.0729 5592 gupdatem - ok
13:53:02.0743 5592 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
13:53:02.0768 5592 hcw85cir - ok
13:53:02.0795 5592 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:53:02.0833 5592 HdAudAddService - ok
13:53:02.0847 5592 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:53:02.0869 5592 HDAudBus - ok
13:53:02.0885 5592 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
13:53:02.0906 5592 HidBatt - ok
13:53:02.0921 5592 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
13:53:02.0949 5592 HidBth - ok
13:53:02.0959 5592 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
13:53:02.0985 5592 HidIr - ok
13:53:03.0013 5592 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
13:53:03.0060 5592 hidserv - ok
13:53:03.0074 5592 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:53:03.0095 5592 HidUsb - ok
13:53:03.0114 5592 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:53:03.0166 5592 hkmsvc - ok
13:53:03.0195 5592 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:53:03.0237 5592 HomeGroupListener - ok
13:53:03.0266 5592 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:53:03.0288 5592 HomeGroupProvider - ok
13:53:03.0309 5592 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
13:53:03.0334 5592 HpSAMD - ok
13:53:03.0368 5592 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:53:03.0441 5592 HTTP - ok
13:53:03.0466 5592 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:53:03.0487 5592 hwpolicy - ok
13:53:03.0507 5592 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
13:53:03.0538 5592 i8042prt - ok
13:53:03.0563 5592 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
13:53:03.0598 5592 iaStorV - ok
13:53:03.0634 5592 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:53:03.0691 5592 idsvc - ok
13:53:03.0711 5592 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
13:53:03.0734 5592 iirsp - ok
13:53:03.0764 5592 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
13:53:03.0822 5592 IKEEXT - ok
13:53:03.0898 5592 [ 04A5D3B6C99B7BD5928BF85C54464CF8 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
13:53:04.0017 5592 IntcAzAudAddService - ok
13:53:04.0038 5592 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
13:53:04.0061 5592 intelide - ok
13:53:04.0093 5592 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:53:04.0118 5592 intelppm - ok
13:53:04.0139 5592 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:53:04.0197 5592 IPBusEnum - ok
13:53:04.0217 5592 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:53:04.0271 5592 IpFilterDriver - ok
13:53:04.0305 5592 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:53:04.0344 5592 iphlpsvc - ok
13:53:04.0365 5592 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
13:53:04.0391 5592 IPMIDRV - ok
13:53:04.0407 5592 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:53:04.0465 5592 IPNAT - ok
13:53:04.0479 5592 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:53:04.0507 5592 IRENUM - ok
13:53:04.0534 5592 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:53:04.0556 5592 isapnp - ok
13:53:04.0586 5592 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
13:53:04.0620 5592 iScsiPrt - ok
13:53:04.0634 5592 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:53:04.0657 5592 kbdclass - ok
13:53:04.0682 5592 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:53:04.0705 5592 kbdhid - ok
13:53:04.0717 5592 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
13:53:04.0734 5592 KeyIso - ok
13:53:04.0761 5592 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:53:04.0786 5592 KSecDD - ok
13:53:04.0807 5592 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:53:04.0834 5592 KSecPkg - ok
13:53:04.0852 5592 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:53:04.0902 5592 ksthunk - ok
13:53:04.0941 5592 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
13:53:05.0012 5592 KtmRm - ok
13:53:05.0038 5592 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:53:05.0087 5592 LanmanServer - ok
13:53:05.0102 5592 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:53:05.0165 5592 LanmanWorkstation - ok
13:53:05.0191 5592 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:53:05.0243 5592 lltdio - ok
13:53:05.0274 5592 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:53:05.0334 5592 lltdsvc - ok
13:53:05.0353 5592 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:53:05.0404 5592 lmhosts - ok
13:53:05.0425 5592 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
13:53:05.0452 5592 LSI_FC - ok
13:53:05.0470 5592 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
13:53:05.0496 5592 LSI_SAS - ok
13:53:05.0519 5592 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:53:05.0567 5592 LSI_SAS2 - ok
13:53:05.0607 5592 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:53:05.0634 5592 LSI_SCSI - ok
13:53:05.0649 5592 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
13:53:05.0705 5592 luafv - ok
13:53:05.0724 5592 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
13:53:05.0747 5592 megasas - ok
13:53:05.0767 5592 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
13:53:05.0798 5592 MegaSR - ok
13:53:05.0833 5592 Microsoft SharePoint Workspace Audit Service - ok
13:53:05.0846 5592 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
13:53:05.0893 5592 MMCSS - ok
13:53:05.0911 5592 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
13:53:05.0961 5592 Modem - ok
13:53:05.0975 5592 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:53:05.0996 5592 monitor - ok
13:53:06.0015 5592 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:53:06.0037 5592 mouclass - ok
13:53:06.0051 5592 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:53:06.0073 5592 mouhid - ok
13:53:06.0096 5592 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:53:06.0119 5592 mountmgr - ok
13:53:06.0136 5592 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
13:53:06.0169 5592 mpio - ok
13:53:06.0193 5592 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:53:06.0245 5592 mpsdrv - ok
13:53:06.0274 5592 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
13:53:06.0333 5592 MpsSvc - ok
13:53:06.0364 5592 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:53:06.0400 5592 MRxDAV - ok
13:53:06.0423 5592 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:53:06.0460 5592 mrxsmb - ok
13:53:06.0508 5592 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:53:06.0539 5592 mrxsmb10 - ok
13:53:06.0551 5592 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:53:06.0576 5592 mrxsmb20 - ok
13:53:06.0588 5592 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
13:53:06.0611 5592 msahci - ok
13:53:06.0646 5592 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:53:06.0673 5592 msdsm - ok
13:53:06.0694 5592 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
13:53:06.0728 5592 MSDTC - ok
13:53:06.0754 5592 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:53:06.0804 5592 Msfs - ok
13:53:06.0814 5592 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:53:06.0864 5592 mshidkmdf - ok
13:53:06.0873 5592 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:53:06.0894 5592 msisadrv - ok
13:53:06.0922 5592 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:53:06.0977 5592 MSiSCSI - ok
13:53:06.0984 5592 msiserver - ok
13:53:07.0005 5592 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:53:07.0053 5592 MSKSSRV - ok
13:53:07.0069 5592 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:53:07.0118 5592 MSPCLOCK - ok
13:53:07.0131 5592 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:53:07.0179 5592 MSPQM - ok
13:53:07.0204 5592 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:53:07.0259 5592 MsRPC - ok
13:53:07.0281 5592 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
13:53:07.0298 5592 mssmbios - ok
13:53:07.0312 5592 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:53:07.0361 5592 MSTEE - ok
13:53:07.0377 5592 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
13:53:07.0397 5592 MTConfig - ok
13:53:07.0405 5592 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
13:53:07.0428 5592 Mup - ok
13:53:07.0454 5592 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
13:53:07.0524 5592 napagent - ok
13:53:07.0549 5592 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:53:07.0586 5592 NativeWifiP - ok
13:53:07.0621 5592 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:53:07.0656 5592 NDIS - ok
13:53:07.0673 5592 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:53:07.0724 5592 NdisCap - ok
13:53:07.0742 5592 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:53:07.0792 5592 NdisTapi - ok
13:53:07.0823 5592 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:53:07.0875 5592 Ndisuio - ok
13:53:07.0900 5592 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:53:07.0954 5592 NdisWan - ok
13:53:07.0977 5592 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:53:08.0027 5592 NDProxy - ok
13:53:08.0039 5592 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:53:08.0090 5592 NetBIOS - ok
13:53:08.0128 5592 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:53:08.0184 5592 NetBT - ok
13:53:08.0192 5592 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
13:53:08.0211 5592 Netlogon - ok
13:53:08.0234 5592 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
13:53:08.0287 5592 Netman - ok
13:53:08.0314 5592 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:53:08.0361 5592 NetMsmqActivator - ok
13:53:08.0395 5592 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:53:08.0410 5592 NetPipeActivator - ok
13:53:08.0425 5592 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
13:53:08.0482 5592 netprofm - ok
13:53:08.0493 5592 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:53:08.0509 5592 NetTcpActivator - ok
13:53:08.0517 5592 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:53:08.0532 5592 NetTcpPortSharing - ok
13:53:08.0558 5592 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
13:53:08.0581 5592 nfrd960 - ok
13:53:08.0612 5592 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:53:08.0634 5592 NlaSvc - ok
13:53:08.0657 5592 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:53:08.0709 5592 Npfs - ok
13:53:08.0738 5592 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
13:53:08.0784 5592 nsi - ok
13:53:08.0809 5592 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:53:08.0858 5592 nsiproxy - ok
13:53:08.0916 5592 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:53:08.0990 5592 Ntfs - ok
13:53:09.0014 5592 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
13:53:09.0061 5592 Null - ok
13:53:09.0085 5592 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
13:53:09.0118 5592 NVENETFD - ok
13:53:09.0152 5592 [ 0AD267A4674805B61A5D7B911D2A978A ] NVNET C:\Windows\system32\DRIVERS\nvmf6264.sys
13:53:09.0181 5592 NVNET - ok
13:53:09.0206 5592 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:53:09.0233 5592 nvraid - ok
13:53:09.0264 5592 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:53:09.0289 5592 nvstor - ok
13:53:09.0312 5592 [ 71B6ECD3C56FBF12FB1968DA3953B703 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys
13:53:09.0330 5592 nvstor64 - ok
13:53:09.0350 5592 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:53:09.0377 5592 nv_agp - ok
13:53:09.0401 5592 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:53:09.0430 5592 ohci1394 - ok
13:53:09.0474 5592 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:53:09.0502 5592 ose64 - ok
13:53:09.0610 5592 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:53:09.0756 5592 osppsvc - ok
13:53:09.0797 5592 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:53:09.0820 5592 p2pimsvc - ok
13:53:09.0842 5592 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
13:53:09.0884 5592 p2psvc - ok
13:53:09.0909 5592 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
13:53:09.0934 5592 Parport - ok
13:53:09.0955 5592 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:53:09.0979 5592 partmgr - ok
13:53:09.0996 5592 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:53:10.0021 5592 PcaSvc - ok
13:53:10.0029 5592 pccsmcfd - ok
13:53:10.0049 5592 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
13:53:10.0068 5592 pci - ok
13:53:10.0083 5592 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
13:53:10.0103 5592 pciide - ok
13:53:10.0125 5592 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:53:10.0155 5592 pcmcia - ok
13:53:10.0176 5592 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
13:53:10.0198 5592 pcw - ok
13:53:10.0225 5592 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:53:10.0297 5592 PEAUTH - ok
13:53:10.0329 5592 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
13:53:10.0379 5592 PeerDistSvc - ok
13:53:10.0440 5592 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:53:10.0468 5592 PerfHost - ok
13:53:10.0594 5592 [ 7A805CE3682BE4B811B17205B640DD1F ] PFNet C:\Program Files (x86)\Privacyware\Privatefirewall 7.0\pfsvc.exe
13:53:10.0616 5592 PFNet - ok
13:53:10.0669 5592 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
13:53:10.0758 5592 pla - ok
13:53:10.0795 5592 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:53:10.0820 5592 PlugPlay - ok
13:53:10.0840 5592 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:53:10.0865 5592 PNRPAutoReg - ok
13:53:10.0889 5592 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:53:10.0911 5592 PNRPsvc - ok
13:53:10.0932 5592 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:53:10.0986 5592 PolicyAgent - ok
13:53:11.0012 5592 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
13:53:11.0065 5592 Power - ok
13:53:11.0088 5592 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:53:11.0141 5592 PptpMiniport - ok
13:53:11.0169 5592 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:53:11.0195 5592 Processor - ok
13:53:11.0227 5592 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
13:53:11.0258 5592 ProfSvc - ok
13:53:11.0275 5592 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:53:11.0292 5592 ProtectedStorage - ok
13:53:11.0320 5592 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:53:11.0364 5592 Psched - ok
13:53:11.0419 5592 [ F61AAE2E133C3DCE8BA1705E301D4224 ] pwipf6 C:\Windows\system32\DRIVERS\pwipf6.sys
13:53:11.0445 5592 pwipf6 - ok
13:53:11.0488 5592 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
13:53:11.0565 5592 ql2300 - ok
13:53:11.0583 5592 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
13:53:11.0610 5592 ql40xx - ok
13:53:11.0632 5592 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
13:53:11.0671 5592 QWAVE - ok
13:53:11.0686 5592 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:53:11.0714 5592 QWAVEdrv - ok
13:53:11.0732 5592 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:53:11.0783 5592 RasAcd - ok
13:53:11.0802 5592 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:53:11.0854 5592 RasAgileVpn - ok
13:53:11.0868 5592 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
13:53:11.0924 5592 RasAuto - ok
13:53:11.0955 5592 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:53:12.0008 5592 Rasl2tp - ok
13:53:12.0040 5592 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
13:53:12.0109 5592 RasMan - ok
13:53:12.0119 5592 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:53:12.0174 5592 RasPppoe - ok
13:53:12.0183 5592 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:53:12.0238 5592 RasSstp - ok
13:53:12.0256 5592 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:53:12.0316 5592 rdbss - ok
13:53:12.0334 5592 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
13:53:12.0358 5592 rdpbus - ok
13:53:12.0371 5592 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:53:12.0421 5592 RDPCDD - ok
13:53:12.0456 5592 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
13:53:12.0485 5592 RDPDR - ok
13:53:12.0506 5592 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:53:12.0557 5592 RDPENCDD - ok
13:53:12.0571 5592 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
13:53:12.0631 5592 RDPREFMP - ok
13:53:12.0690 5592 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:53:12.0711 5592 RdpVideoMiniport - ok
13:53:12.0743 5592 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:53:12.0771 5592 RDPWD - ok
13:53:12.0804 5592 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:53:12.0833 5592 rdyboost - ok
13:53:12.0874 5592 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:53:12.0932 5592 RemoteAccess - ok
13:53:12.0946 5592 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:53:13.0007 5592 RemoteRegistry - ok
13:53:13.0026 5592 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:53:13.0074 5592 RpcEptMapper - ok
13:53:13.0096 5592 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
13:53:13.0120 5592 RpcLocator - ok
13:53:13.0161 5592 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
13:53:13.0214 5592 RpcSs - ok
13:53:13.0249 5592 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:53:13.0304 5592 rspndr - ok
13:53:13.0327 5592 RTHDMIAzAudService - ok
13:53:13.0353 5592 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
13:53:13.0374 5592 s3cap - ok
13:53:13.0392 5592 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
13:53:13.0410 5592 SamSs - ok
13:53:13.0439 5592 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
13:53:13.0457 5592 SASDIFSV - ok
13:53:13.0486 5592 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
13:53:13.0504 5592 SASKUTIL - ok
13:53:13.0527 5592 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:53:13.0556 5592 sbp2port - ok
13:53:13.0577 5592 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:53:13.0640 5592 SCardSvr - ok
13:53:13.0658 5592 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:53:13.0712 5592 scfilter - ok
13:53:13.0750 5592 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
13:53:13.0816 5592 Schedule - ok
13:53:13.0842 5592 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
13:53:13.0885 5592 SCPolicySvc - ok
13:53:13.0902 5592 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:53:13.0943 5592 SDRSVC - ok
13:53:13.0985 5592 [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Pavel\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
13:53:13.0997 5592 SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
13:53:13.0997 5592 SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
13:53:14.0026 5592 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:53:14.0093 5592 secdrv - ok
13:53:14.0117 5592 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
13:53:14.0171 5592 seclogon - ok
13:53:14.0188 5592 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
13:53:14.0243 5592 SENS - ok
13:53:14.0256 5592 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:53:14.0281 5592 SensrSvc - ok
13:53:14.0299 5592 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
13:53:14.0316 5592 Serenum - ok
13:53:14.0330 5592 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
13:53:14.0348 5592 Serial - ok
13:53:14.0376 5592 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
13:53:14.0393 5592 sermouse - ok
13:53:14.0438 5592 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
13:53:14.0497 5592 SessionEnv - ok
13:53:14.0528 5592 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:53:14.0545 5592 sffdisk - ok
13:53:14.0560 5592 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:53:14.0577 5592 sffp_mmc - ok
13:53:14.0592 5592 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:53:14.0612 5592 sffp_sd - ok
13:53:14.0634 5592 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
13:53:14.0651 5592 sfloppy - ok
13:53:14.0702 5592 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:53:14.0777 5592 SharedAccess - ok
13:53:14.0822 5592 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:53:14.0873 5592 ShellHWDetection - ok
13:53:14.0893 5592 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:53:14.0909 5592 SiSRaid2 - ok
13:53:14.0928 5592 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
13:53:14.0953 5592 SiSRaid4 - ok
13:53:15.0006 5592 [ 4E8A4BB5B11D828FF986F6228B1CD3DF ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
13:53:15.0097 5592 SkypeUpdate - ok
13:53:15.0114 5592 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:53:15.0167 5592 Smb - ok
13:53:15.0217 5592 [ FDB6E127DF739D4911319F0C8D339CAF ] snapman C:\Windows\system32\DRIVERS\snapman.sys
13:53:15.0246 5592 snapman - ok
13:53:15.0269 5592 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:53:15.0294 5592 SNMPTRAP - ok
13:53:15.0312 5592 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
13:53:15.0335 5592 spldr - ok
13:53:15.0376 5592 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
13:53:15.0405 5592 Spooler - ok
13:53:15.0486 5592 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
13:53:15.0660 5592 sppsvc - ok
13:53:15.0680 5592 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
13:53:15.0735 5592 sppuinotify - ok
13:53:15.0813 5592 [ 51B3F28772E44F0B87DF19B42C90BA8A ] Správce výběru OS C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
13:53:15.0900 5592 Správce výběru OS - ok
13:53:15.0910 5592 sptd - ok
13:53:15.0945 5592 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
13:53:15.0985 5592 srv - ok
13:53:16.0008 5592 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:53:16.0042 5592 srv2 - ok
13:53:16.0058 5592 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:53:16.0085 5592 srvnet - ok
13:53:16.0119 5592 [ 2BD486E7A2EB225E9E8E3DD1C016461B ] SSCBFS3 C:\Windows\system32\DRIVERS\sscbfs3.sys
13:53:16.0148 5592 SSCBFS3 - ok
13:53:16.0170 5592 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:53:16.0221 5592 SSDPSRV - ok
13:53:16.0237 5592 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:53:16.0291 5592 SstpSvc - ok
13:53:16.0325 5592 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
13:53:16.0352 5592 ssudmdm - ok
13:53:16.0381 5592 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
13:53:16.0404 5592 stexstor - ok
13:53:16.0442 5592 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
13:53:16.0477 5592 stisvc - ok
13:53:16.0523 5592 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
13:53:16.0545 5592 storflt - ok
13:53:16.0563 5592 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll
13:53:16.0586 5592 StorSvc - ok
13:53:16.0604 5592 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
13:53:16.0626 5592 storvsc - ok
13:53:16.0646 5592 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
13:53:16.0666 5592 swenum - ok
13:53:16.0686 5592 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
13:53:16.0763 5592 swprv - ok
13:53:16.0955 5592 [ 4BF999638D299447F02477237D171CA5 ] syncagentsrv C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
13:53:17.0157 5592 syncagentsrv - ok
13:53:17.0228 5592 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
13:53:17.0293 5592 SysMain - ok
13:53:17.0322 5592 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:53:17.0357 5592 TabletInputService - ok
13:53:17.0381 5592 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:53:17.0447 5592 TapiSrv - ok
13:53:17.0464 5592 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
13:53:17.0511 5592 TBS - ok
13:53:17.0560 5592 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:53:17.0645 5592 Tcpip - ok
13:53:17.0683 5592 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
13:53:17.0733 5592 TCPIP6 - ok
13:53:17.0765 5592 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:53:17.0787 5592 tcpipreg - ok
13:53:17.0818 5592 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:53:17.0840 5592 TDPIPE - ok
13:53:17.0904 5592 [ 843DAFC2CD4ED5D57FA40FD2000C6296 ] tdrpman C:\Windows\system32\DRIVERS\tdrpman.sys
13:53:17.0965 5592 tdrpman - ok
13:53:17.0989 5592 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:53:18.0010 5592 TDTCP - ok
13:53:18.0041 5592 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:53:18.0093 5592 tdx - ok
13:53:18.0115 5592 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
13:53:18.0138 5592 TermDD - ok
13:53:18.0167 5592 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
13:53:18.0239 5592 TermService - ok
13:53:18.0264 5592 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
13:53:18.0295 5592 Themes - ok
13:53:18.0324 5592 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
13:53:18.0371 5592 THREADORDER - ok
13:53:18.0427 5592 [ 31C9790525705B292F3B30F6676873CD ] tib_mounter C:\Windows\system32\DRIVERS\tib_mounter.sys
13:53:18.0478 5592 tib_mounter - ok
13:53:18.0500 5592 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
13:53:18.0549 5592 TrkWks - ok
13:53:18.0599 5592 [ 370A6907DDF79532A39319492B1FA38A ] truecrypt C:\Windows\system32\drivers\truecrypt.sys
13:53:18.0630 5592 truecrypt - ok
13:53:18.0661 5592 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:53:18.0707 5592 TrustedInstaller - ok
13:53:18.0736 5592 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:53:18.0785 5592 tssecsrv - ok
13:53:18.0805 5592 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
13:53:18.0829 5592 TsUsbFlt - ok
13:53:18.0860 5592 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:53:18.0924 5592 tunnel - ok
13:53:18.0947 5592 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
13:53:18.0971 5592 uagp35 - ok
13:53:18.0993 5592 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:53:19.0050 5592 udfs - ok
13:53:19.0081 5592 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:53:19.0120 5592 UI0Detect - ok
13:53:19.0143 5592 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:53:19.0166 5592 uliagpkx - ok
13:53:19.0185 5592 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
13:53:19.0211 5592 umbus - ok
13:53:19.0232 5592 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
13:53:19.0252 5592 UmPass - ok
13:53:19.0280 5592 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
13:53:19.0311 5592 UmRdpService - ok
13:53:19.0351 5592 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
13:53:19.0421 5592 upnphost - ok
13:53:19.0446 5592 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
13:53:19.0473 5592 usbaudio - ok
13:53:19.0502 5592 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:53:19.0528 5592 usbccgp - ok
13:53:19.0555 5592 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:53:19.0589 5592 usbcir - ok
13:53:19.0618 5592 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:53:19.0640 5592 usbehci - ok
13:53:19.0661 5592 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:53:19.0681 5592 usbhub - ok
13:53:19.0707 5592 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:53:19.0726 5592 usbohci - ok
13:53:19.0743 5592 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:53:19.0770 5592 usbprint - ok
13:53:19.0806 5592 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:53:19.0823 5592 USBSTOR - ok
13:53:19.0833 5592 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:53:19.0861 5592 usbuhci - ok
13:53:19.0883 5592 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
13:53:19.0914 5592 usbvideo - ok
13:53:19.0931 5592 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
13:53:19.0978 5592 UxSms - ok
13:53:20.0009 5592 [ 81838071C71E93EB38194514C6580F82 ] V0530Dev C:\Windows\system32\DRIVERS\V0530Vid.sys
13:53:20.0050 5592 V0530Dev - ok
13:53:20.0067 5592 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
13:53:20.0085 5592 VaultSvc - ok
13:53:20.0103 5592 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
13:53:20.0125 5592 vdrvroot - ok
13:53:20.0149 5592 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
13:53:20.0218 5592 vds - ok
13:53:20.0244 5592 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:53:20.0269 5592 vga - ok
13:53:20.0291 5592 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
13:53:20.0339 5592 VgaSave - ok
13:53:20.0358 5592 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
13:53:20.0390 5592 vhdmp - ok
13:53:20.0419 5592 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
13:53:20.0439 5592 viaide - ok
13:53:20.0499 5592 [ 927CBC96C4635F235301411E530FB56E ] vididr C:\Windows\system32\DRIVERS\vididr.sys
13:53:20.0524 5592 vididr - ok
13:53:20.0560 5592 [ 88B4E5C396003BCF479CA4D9BE851D57 ] vidsflt C:\Windows\system32\DRIVERS\vidsflt.sys
13:53:20.0582 5592 vidsflt - ok
13:53:20.0606 5592 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
13:53:20.0635 5592 vmbus - ok
13:53:20.0658 5592 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
13:53:20.0678 5592 VMBusHID - ok
13:53:20.0699 5592 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:53:20.0723 5592 volmgr - ok
13:53:20.0749 5592 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:53:20.0784 5592 volmgrx - ok
13:53:20.0806 5592 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:53:20.0837 5592 volsnap - ok
13:53:20.0865 5592 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
13:53:20.0891 5592 vsmraid - ok
13:53:20.0939 5592 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
13:53:21.0061 5592 VSS - ok
13:53:21.0082 5592 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
13:53:21.0110 5592 vwifibus - ok
13:53:21.0148 5592 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
13:53:21.0217 5592 W32Time - ok
13:53:21.0243 5592 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
13:53:21.0265 5592 WacomPen - ok
13:53:21.0282 5592 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
13:53:21.0334 5592 WANARP - ok
13:53:21.0344 5592 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:53:21.0390 5592 Wanarpv6 - ok
13:53:21.0454 5592 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
13:53:21.0553 5592 WatAdminSvc - ok
13:53:21.0602 5592 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
13:53:21.0662 5592 wbengine - ok
13:53:21.0681 5592 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
13:53:21.0717 5592 WbioSrvc - ok
13:53:21.0745 5592 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:53:21.0784 5592 wcncsvc - ok
13:53:21.0800 5592 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:53:21.0826 5592 WcsPlugInService - ok
13:53:21.0850 5592 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
13:53:21.0872 5592 Wd - ok
13:53:21.0907 5592 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:53:21.0967 5592 Wdf01000 - ok
13:53:21.0986 5592 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:53:22.0011 5592 WdiServiceHost - ok
13:53:22.0021 5592 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:53:22.0050 5592 WdiSystemHost - ok
13:53:22.0079 5592 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
13:53:22.0137 5592 WebClient - ok
13:53:22.0162 5592 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:53:22.0230 5592 Wecsvc - ok
13:53:22.0242 5592 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:53:22.0297 5592 wercplsupport - ok
13:53:22.0316 5592 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
13:53:22.0387 5592 WerSvc - ok
13:53:22.0402 5592 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
13:53:22.0452 5592 WfpLwf - ok
13:53:22.0472 5592 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
13:53:22.0498 5592 WIMMount - ok
13:53:22.0535 5592 WinDefend - ok
13:53:22.0560 5592 WinHttpAutoProxySvc - ok
13:53:22.0636 5592 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:53:22.0687 5592 Winmgmt - ok
13:53:22.0746 5592 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
13:53:22.0860 5592 WinRM - ok
13:53:22.0902 5592 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
13:53:22.0930 5592 WinUsb - ok
13:53:22.0972 5592 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
13:53:23.0032 5592 Wlansvc - ok
13:53:23.0061 5592 [ 680A7846370000D20D7E74917D5B7936 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
13:53:23.0080 5592 WmBEnum - ok
13:53:23.0105 5592 [ 14C35BA8189C6F65D839163AA285E954 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
13:53:23.0127 5592 WmFilter - ok
13:53:23.0163 5592 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:53:23.0185 5592 WmiAcpi - ok
13:53:23.0227 5592 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:53:23.0263 5592 wmiApSrv - ok
13:53:23.0286 5592 WMPNetworkSvc - ok
13:53:23.0311 5592 [ 8488DD91A3EE54A8E29F02AD7BB8201E ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
13:53:23.0329 5592 WmVirHid - ok
13:53:23.0350 5592 [ 14802B3A30AA849C97CB968CCC813BF3 ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
13:53:23.0370 5592 WmXlCore - ok
13:53:23.0388 5592 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:53:23.0414 5592 WPCSvc - ok
13:53:23.0439 5592 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:53:23.0470 5592 WPDBusEnum - ok
13:53:23.0499 5592 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:53:23.0550 5592 ws2ifsl - ok
13:53:23.0565 5592 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
13:53:23.0592 5592 wscsvc - ok
13:53:23.0603 5592 WSearch - ok
13:53:23.0689 5592 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
13:53:23.0774 5592 wuauserv - ok
13:53:23.0808 5592 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:53:23.0831 5592 WudfPf - ok
13:53:23.0852 5592 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:53:23.0878 5592 WUDFRd - ok
13:53:23.0907 5592 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:53:23.0925 5592 wudfsvc - ok
13:53:23.0953 5592 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
13:53:23.0983 5592 WwanSvc - ok
13:53:24.0005 5592 ================ Scan global ===============================
13:53:24.0046 5592 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
13:53:24.0075 5592 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
13:53:24.0087 5592 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
13:53:24.0111 5592 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
13:53:24.0133 5592 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
13:53:24.0139 5592 [Global] - ok
13:53:24.0141 5592 ================ Scan MBR ==================================
13:53:24.0150 5592 [ F2634EFAB9E22A7870007C2453CEFE38 ] \Device\Harddisk0\DR0
13:53:24.0435 5592 \Device\Harddisk0\DR0 - ok
13:53:24.0440 5592 [ D1AD4C53EADD115593E05FA56D6B9DEA ] \Device\Harddisk1\DR1
13:53:24.0721 5592 \Device\Harddisk1\DR1 - ok
13:53:24.0722 5592 ================ Scan VBR ==================================
13:53:24.0793 5592 [ F78E32E6BF30480BF78AD5D3CCC844D9 ] \Device\Harddisk0\DR0\Partition1
13:53:24.0795 5592 \Device\Harddisk0\DR0\Partition1 - ok
13:53:24.0800 5592 [ 6BCE7D69EC597A477D96A78101847AE0 ] \Device\Harddisk0\DR0\Partition2
13:53:24.0802 5592 \Device\Harddisk0\DR0\Partition2 - ok
13:53:24.0833 5592 [ 292FE5C5C7EF24CF3F102B0839D5C398 ] \Device\Harddisk0\DR0\Partition3
13:53:24.0835 5592 \Device\Harddisk0\DR0\Partition3 - ok
13:53:24.0840 5592 [ 2359426677412649FEE681CD7058BA21 ] \Device\Harddisk1\DR1\Partition1
13:53:24.0841 5592 \Device\Harddisk1\DR1\Partition1 - ok
13:53:24.0845 5592 ============================================================
13:53:24.0845 5592 Scan finished
13:53:24.0845 5592 ============================================================
13:53:24.0867 6396 Detected object count: 5
13:53:24.0867 6396 Actual detected object count: 5
13:53:57.0070 6396 !SASCORE ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:57.0070 6396 !SASCORE ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:53:57.0076 6396 FirebirdGuardianDefaultInstance ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:57.0076 6396 FirebirdGuardianDefaultInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:53:57.0078 6396 FirebirdServerDefaultInstance ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:57.0078 6396 FirebirdServerDefaultInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:53:57.0081 6396 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:57.0081 6396 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:53:57.0084 6396 SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
13:53:57.0084 6396 SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:54:10.0120 5124 Deinitialize success

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 12:56
od vyosek
Vse vypada OK = falesny poplach Aviry

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 13:16
od Pakl
To jsem rád - a vám dík za pomoc.

Re: Avira hlásí "hidden objects" jinak se zdá být vše OK

Napsal: 28 črc 2013 13:33
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock: