Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus, nejaky malware, strata admin. prav

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Virus, nejaky malware, strata admin. prav

#1 Příspěvek od h4pple »

Zdravim, dneska som stahoval a spolu s obsahom sa mi stiahol aj virus, po restartovani ntb mi nechce spustat aplikacie, chcel som sem hodit log z RSIT ale nejde to pretoze mi to vypisuje ze "System windows nemoze ziskat pristup k zadanemu zariadeniu, suboru alebo zadanej ceste.Mozno nemate prislusne povolenia na pristup k danej polozke" ...akoby som stratil admin prava...a pri tom som to spustal ako administrator...vsetky procesy ktore startuju zvycajne s windowsom sa nedali spustit...vypisalo nieco v tom zmysle ze sa neda pristupit k suboru lebo obsahuje virus alebo skodlivy soft. Prosim pomoc, je to dost surne...kedze mi skoro nic nejde spustit na nom, dakujem :)

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#2 Příspěvek od h4pple »

tak PChunter mi to nechce spustit...."System windows nemoze ziskat pristup k zadanemu zariadeniu, suboru alebo zadanej ceste.Mozno nemate prislusne povolenia na pristup k danej polozke" toto mi pise...mam pokracovat v tom druhom postupe?

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#3 Příspěvek od h4pple »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014
Ran by h4pple99 (administrator) on H4PPLE on 06-02-2014 20:21:59
Running from H:\
Windows 8.1 (X64) OS Language: 041B
Internet Explorer Version 11
Boot Mode: Safe Mode (minimal)

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\cmd.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2013-08-12] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2013-08-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [ShadowPlay] - C:\WINDOWS\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Smart Update] - C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update.exe [1706576 2012-08-02] (Lenovo)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-02-03] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-30] (AVAST Software)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-03] (Samsung)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-03] (Samsung)
HKU\S-1-5-21-3547628435-3712409865-1790832751-1002\...\Run: [uTorrent] - C:\Users\h4pple99\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-01-28] (BitTorrent Inc.)
AppInit_DLLs: C:\windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-12-19] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-12-19] (NVIDIA Corporation)
Startup: C:\Users\h4pple99\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
SearchScopes: HKLM - DefaultScope {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM - {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - DefaultScope {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKCU - DefaultScope {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL =
SearchScopes: HKCU - {8DBF706B-58B0-444B-BDE3-20A901A30AFD} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://start.icq.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Nitro PDF Plug-In) - C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( )
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Dokumenty Google) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-16]
CHR Extension: (Disk Google) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-16]
CHR Extension: (YouTube) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-16]
CHR Extension: (Hľadať v Google) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-16]
CHR Extension: (AdBlock) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-08-16]
CHR Extension: (Skype Click to Call) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-12-14]
CHR Extension: (Glossy Blue) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\nheaocaplknjkpcnbadlgfpdfjaabiml [2013-08-16]
CHR Extension: (Peňaženka Google) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\h4pple99\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-16]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

==================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-30] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
S4 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [953720 2012-08-26] (Broadcom Corporation.)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S4 Lenovo Smart Update Service; C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update Service.exe [66640 2012-07-18] (Lenovo)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] ()
S4 NitroDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [216072 2012-07-16] (Nitro PDF Software)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software)
S2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2014-02-06] (AVAST Software)
S1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-11-30] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-30] ()
S1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1038072 2014-02-06] (AVAST Software)
S1 aswSP; C:\windows\system32\drivers\aswSP.sys [421704 2014-02-06] (AVAST Software)
S3 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [80184 2014-02-06] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-02-06] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-12-25] ()
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-12-13] (Disc Soft Ltd)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
R0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-12-13] (Microsoft Corporation)
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-12-25] ()
R0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
S3 pwdrvio; C:\windows\system32\pwdrvio.sys [19032 2013-07-01] ()
S3 pwdspio; C:\windows\system32\pwdspio.sys [12384 2013-07-01] ()
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8222736 2012-06-15] (Realtek Semiconductor Corp.)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-12-13] (Microsoft Corporation)
R0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-06 20:21 - 2014-02-06 20:21 - 00000000 ____D () C:\FRST
2014-02-06 17:34 - 2014-02-06 17:34 - 00000000 ____D () C:\Users\h4pple99\Desktop\PCHunter_free
2014-02-06 17:32 - 2014-02-06 17:33 - 06705279 _____ () C:\Users\h4pple99\Desktop\PCHunter_free.zip
2014-02-06 17:19 - 2014-02-06 17:19 - 00935175 _____ () C:\Users\h4pple99\Desktop\RSITx64.exe
2014-02-06 14:57 - 2014-02-06 14:57 - 00002033 _____ () C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-02-06 14:56 - 2013-08-21 05:31 - 00188232 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadmdm.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00169288 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadbus.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00158024 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadserd.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00021320 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadmdfl.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00017736 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadwhnt.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00017736 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadwh.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00017224 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadcmnt.sys
2014-02-06 14:56 - 2013-08-21 05:31 - 00017224 _____ (MCCI Corporation) C:\WINDOWS\system32\Drivers\ssadcm.sys
2014-02-06 14:53 - 2014-02-06 14:53 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-02-06 13:03 - 2014-02-06 13:18 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassins Creed IV Black Flag Freedom Cry [MULTI][PCDVD][DLC][RELOADED][WwW.GamesTorrents.CoM]
2014-02-06 12:58 - 2014-02-06 15:23 - 00000000 ____D () C:\Users\h4pple99\Documents\Assassin's Creed Liberation HD
2014-02-06 12:56 - 2014-02-06 12:56 - 00001186 _____ () C:\Users\Public\Desktop\Assassins Creed Liberation HD.lnk
2014-02-06 12:50 - 2014-02-06 15:23 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed Liberation HD
2014-02-06 12:40 - 2014-02-06 12:40 - 00080184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-02-06 12:37 - 2014-02-06 12:48 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassin's Creed Liberation HD
2014-02-06 12:26 - 2014-02-06 12:26 - 00016397 _____ () C:\Users\h4pple99\Desktop\Assassin's_Creed.Liberation_HD_+_1_DLC.(Ubisoft_Entertainment).(2014).Repack.torrent
2014-02-06 11:55 - 2014-02-06 12:15 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassins Creed Liberation HD [MULTI8][PCDVD][Incl Bonus DLC][P2P][WwW.GamesTorrents.CoM]
2014-02-04 16:40 - 2014-02-04 16:40 - 00014553 _____ () C:\Users\h4pple99\Desktop\[CzT]Ostrov_The_Island.torrent
2014-02-04 16:27 - 2014-02-04 16:27 - 00011838 _____ () C:\Users\h4pple99\Desktop\[CzT]Hra_The_Game_1997_.torrent
2014-02-02 11:51 - 2014-02-02 11:51 - 00024042 _____ () C:\Users\h4pple99\Desktop\[DC-Tracker.cz]Jak-jsem-poznal-vaši-matku-6-série-CZ.torrent
2014-02-02 11:32 - 2014-02-02 11:32 - 00015416 _____ () C:\Users\h4pple99\Desktop\[CzT]Na_srot_21_Over_2013_CZ_.torrent
2014-02-02 11:29 - 2014-02-02 11:29 - 00015545 _____ () C:\Users\h4pple99\Desktop\[CzT]Na_srot_21_Over_2013_.torrent
2014-02-01 21:01 - 2014-02-01 21:01 - 00011438 _____ () C:\Users\h4pple99\Desktop\Rozvrh LS.xlsx
2014-02-01 10:46 - 2014-02-01 11:00 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\TeamViewer
2014-02-01 10:45 - 2014-02-01 10:45 - 05854872 _____ (TeamViewer GmbH) C:\Users\h4pple99\Desktop\TeamViewer_Setup_sk.exe
2014-01-30 17:59 - 2014-01-30 18:00 - 36958420 _____ () C:\Users\h4pple99\Desktop\MOV04970.AVI
2014-01-28 19:33 - 2014-02-06 16:42 - 00004092 _____ () C:\WINDOWS\PFRO.log
2014-01-27 20:24 - 2014-01-27 20:24 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-01-27 20:24 - 2014-01-27 20:24 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-01-27 20:13 - 2014-01-27 20:13 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-01-27 20:13 - 2014-01-27 20:13 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-01-27 20:13 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 15230352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2014-01-27 20:13 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433221.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433221.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2014-01-27 20:13 - 2013-12-19 21:33 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2014-01-27 20:13 - 2013-12-19 21:33 - 00023754 _____ () C:\WINDOWS\system32\nvinfo.pb
2014-01-27 20:07 - 2014-01-27 20:07 - 00000000 ____D () C:\NVIDIA
2014-01-17 19:59 - 2014-01-17 20:06 - 166469358 _____ () C:\Users\h4pple99\Desktop\FI-XIV-MWM150.rar
2014-01-13 17:48 - 2014-01-13 17:48 - 00604047 _____ () C:\Users\h4pple99\Desktop\48648916.mp4
2014-01-11 22:38 - 2014-01-11 22:38 - 00000000 ____D () C:\Users\h4pple99\Desktop\FI-XIV-MWM130
2014-01-11 21:47 - 2014-01-11 21:53 - 141899819 _____ () C:\Users\h4pple99\Desktop\FI-XIV-MWM130.rar
2014-01-08 11:09 - 2014-01-08 11:09 - 00011589 _____ () C:\Users\h4pple99\Desktop\HumkyDumky.rar
2014-01-08 10:38 - 2014-01-08 10:48 - 00012024 _____ () C:\Users\h4pple99\Desktop\Humky-Dumky.rar
2014-01-08 10:32 - 2014-01-08 10:33 - 00000000 ____D () C:\Users\h4pple99\Desktop\Mozno to bude
2014-01-07 23:46 - 2014-01-07 23:46 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf

==================== One Month Modified Files and Folders =======

2014-02-06 20:21 - 2014-02-06 20:21 - 00000000 ____D () C:\FRST
2014-02-06 19:59 - 2013-12-13 22:54 - 00047512 _____ () C:\WINDOWS\system32\perfh01B.dat
2014-02-06 19:59 - 2013-12-13 22:54 - 00011800 _____ () C:\WINDOWS\system32\perfc01B.dat
2014-02-06 19:59 - 2013-11-14 08:28 - 00907186 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-06 18:49 - 2013-12-29 00:07 - 01338971 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-06 18:49 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-06 18:49 - 2013-08-15 16:33 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\uTorrent
2014-02-06 18:47 - 2013-09-01 14:11 - 00005028 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for h4pple-h4pple99 h4pple
2014-02-06 18:46 - 2013-08-16 00:35 - 00002226 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-06 18:46 - 2013-08-16 00:35 - 00000950 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-06 18:11 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-06 18:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-06 17:51 - 2013-08-16 00:35 - 00000954 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-06 17:34 - 2014-02-06 17:34 - 00000000 ____D () C:\Users\h4pple99\Desktop\PCHunter_free
2014-02-06 17:33 - 2014-02-06 17:32 - 06705279 _____ () C:\Users\h4pple99\Desktop\PCHunter_free.zip
2014-02-06 17:19 - 2014-02-06 17:19 - 00935175 _____ () C:\Users\h4pple99\Desktop\RSITx64.exe
2014-02-06 16:42 - 2014-01-28 19:33 - 00004092 _____ () C:\WINDOWS\PFRO.log
2014-02-06 16:25 - 2013-08-15 17:02 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\Skype
2014-02-06 16:17 - 2013-12-20 13:26 - 00000000 ____D () C:\Users\h4pple99\AppData\Local\Deployment
2014-02-06 15:23 - 2014-02-06 12:58 - 00000000 ____D () C:\Users\h4pple99\Documents\Assassin's Creed Liberation HD
2014-02-06 15:23 - 2014-02-06 12:50 - 00000000 ____D () C:\Program Files (x86)\Assassins Creed Liberation HD
2014-02-06 14:59 - 2013-12-14 08:27 - 00000000 ____D () C:\WINDOWS\LastGood
2014-02-06 14:57 - 2014-02-06 14:57 - 00002033 _____ () C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-02-06 14:53 - 2014-02-06 14:53 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-02-06 14:51 - 2013-09-26 14:08 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\Samsung
2014-02-06 13:41 - 2013-08-16 00:07 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3547628435-3712409865-1790832751-1002
2014-02-06 13:18 - 2014-02-06 13:03 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassins Creed IV Black Flag Freedom Cry [MULTI][PCDVD][DLC][RELOADED][WwW.GamesTorrents.CoM]
2014-02-06 12:57 - 2013-09-14 08:20 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-06 12:56 - 2014-02-06 12:56 - 00001186 _____ () C:\Users\Public\Desktop\Assassins Creed Liberation HD.lnk
2014-02-06 12:48 - 2014-02-06 12:37 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassin's Creed Liberation HD
2014-02-06 12:41 - 2013-10-04 14:09 - 00001993 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-02-06 12:40 - 2014-02-06 12:40 - 00080184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-02-06 12:40 - 2013-08-15 16:14 - 01038072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-02-06 12:40 - 2013-08-15 16:14 - 00421704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-02-06 12:40 - 2013-08-15 16:14 - 00334136 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-02-06 12:40 - 2013-08-15 16:14 - 00207904 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-02-06 12:40 - 2013-08-15 16:14 - 00078648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-02-06 12:40 - 2013-08-15 16:14 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-02-06 12:40 - 2013-08-15 16:14 - 00003924 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-02-06 12:26 - 2014-02-06 12:26 - 00016397 _____ () C:\Users\h4pple99\Desktop\Assassin's_Creed.Liberation_HD_+_1_DLC.(Ubisoft_Entertainment).(2014).Repack.torrent
2014-02-06 12:15 - 2014-02-06 11:55 - 00000000 ____D () C:\Users\h4pple99\Downloads\Assassins Creed Liberation HD [MULTI8][PCDVD][Incl Bonus DLC][P2P][WwW.GamesTorrents.CoM]
2014-02-06 11:21 - 2013-09-25 17:46 - 00000000 ____D () C:\Users\h4pple99\Documents\FIFA 14
2014-02-06 11:02 - 2013-09-10 18:40 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-02-06 09:43 - 2013-08-16 00:00 - 00000000 ____D () C:\Users\h4pple99\AppData\Local\Packages
2014-02-05 23:07 - 2013-08-26 10:42 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\vlc
2014-02-04 16:40 - 2014-02-04 16:40 - 00014553 _____ () C:\Users\h4pple99\Desktop\[CzT]Ostrov_The_Island.torrent
2014-02-04 16:27 - 2014-02-04 16:27 - 00011838 _____ () C:\Users\h4pple99\Desktop\[CzT]Hra_The_Game_1997_.torrent
2014-02-02 18:30 - 2013-09-10 20:52 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-02 11:51 - 2014-02-02 11:51 - 00024042 _____ () C:\Users\h4pple99\Desktop\[DC-Tracker.cz]Jak-jsem-poznal-vaši-matku-6-série-CZ.torrent
2014-02-02 11:32 - 2014-02-02 11:32 - 00015416 _____ () C:\Users\h4pple99\Desktop\[CzT]Na_srot_21_Over_2013_CZ_.torrent
2014-02-02 11:29 - 2014-02-02 11:29 - 00015545 _____ () C:\Users\h4pple99\Desktop\[CzT]Na_srot_21_Over_2013_.torrent
2014-02-01 21:01 - 2014-02-01 21:01 - 00011438 _____ () C:\Users\h4pple99\Desktop\Rozvrh LS.xlsx
2014-02-01 12:16 - 2013-08-15 18:09 - 00000000 ____D () C:\Users\h4pple99\Desktop\Torrents
2014-02-01 11:00 - 2014-02-01 10:46 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\TeamViewer
2014-02-01 10:45 - 2014-02-01 10:45 - 05854872 _____ (TeamViewer GmbH) C:\Users\h4pple99\Desktop\TeamViewer_Setup_sk.exe
2014-01-30 18:00 - 2014-01-30 17:59 - 36958420 _____ () C:\Users\h4pple99\Desktop\MOV04970.AVI
2014-01-29 11:08 - 2013-09-10 18:40 - 00000000 ____D () C:\ProgramData\Origin
2014-01-29 00:42 - 2013-12-13 21:57 - 00000000 ____D () C:\Users\h4pple99
2014-01-27 20:24 - 2014-01-27 20:24 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-01-27 20:24 - 2014-01-27 20:24 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-01-27 20:23 - 2013-12-13 21:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-01-27 20:13 - 2014-01-27 20:13 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-01-27 20:13 - 2014-01-27 20:13 - 00000000 _____ () C:\WINDOWS\setupact.log
2014-01-27 20:07 - 2014-01-27 20:07 - 00000000 ____D () C:\NVIDIA
2014-01-21 15:09 - 2013-09-15 18:10 - 00000000 ____D () C:\Users\h4pple99\Documents\Dokumenty
2014-01-18 15:14 - 2013-08-16 12:04 - 00000000 ____D () C:\Users\h4pple99\AppData\Roaming\DAEMON Tools Lite
2014-01-17 20:06 - 2014-01-17 19:59 - 166469358 _____ () C:\Users\h4pple99\Desktop\FI-XIV-MWM150.rar
2014-01-14 15:12 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-01-13 17:48 - 2014-01-13 17:48 - 00604047 _____ () C:\Users\h4pple99\Desktop\48648916.mp4
2014-01-11 22:38 - 2014-01-11 22:38 - 00000000 ____D () C:\Users\h4pple99\Desktop\FI-XIV-MWM130
2014-01-11 21:53 - 2014-01-11 21:47 - 141899819 _____ () C:\Users\h4pple99\Desktop\FI-XIV-MWM130.rar
2014-01-08 11:09 - 2014-01-08 11:09 - 00011589 _____ () C:\Users\h4pple99\Desktop\HumkyDumky.rar
2014-01-08 10:48 - 2014-01-08 10:38 - 00012024 _____ () C:\Users\h4pple99\Desktop\Humky-Dumky.rar
2014-01-08 10:33 - 2014-01-08 10:32 - 00000000 ____D () C:\Users\h4pple99\Desktop\Mozno to bude
2014-01-07 23:46 - 2014-01-07 23:46 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-30 09:54

==================== End Of Log ============================

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#4 Příspěvek od h4pple »

a) idem vyskusat spustit ten PChunter aj ked neviem ako presne mam na to ist...ak a mi podari tak sem hodim log potom

b) neviem ako mam cez cmd spustit obnovu, nikdy som to nerobil

EDIT: podarilo sa mi spustit PChunter vlozil som textak do raru.
Přílohy
pchunterreport.rar
PCHunterReport
(75.99 KiB) Staženo 33 x

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#5 Příspěvek od h4pple »

poprosil by som na tu novu verziu nejaky odkaz lebo nerad by som stiahol nieco zle :)

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#6 Příspěvek od h4pple »

spustil som ho normalne vo win najprv mi to odmietlo ze nema pristup, potom som spustil vyzeralo ze ho to spustilo ale combofix vyhodil okno s niecim takymto: "ComboFix is not meant to run in Compatibility mode. The program shall now exit." Mam to skusit spustit v nudzovom rezime ako PChunter?

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#7 Příspěvek od h4pple »

no takze, spustil som ho v nudzovom rezime a vypisalo mi ze: "this operating system is not supported! ComboFix only runs on: winxp 32/64, vista, 7, 8 ...windows 2000 is no longer supported." a pri tom ja mam osmicku windows, teda 8.1 aby som bol presnejsi...nechapem v com je problem.

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#8 Příspěvek od h4pple »

tu je log....


RogueKiller V8.8.6 [Feb 7 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operačný systém : Windows 8.1 (6.3.9600 ) 64 bits version
Spustené v : Núdzový režim
Užívateľ : h4pple99 [Práva Správcu]
Režim : Kontrola -- Dátum : 02/07/2014 19:44:31
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 2 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NÁJDENÉ
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NÁJDENÉ

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spustenie položky : 0 ¤¤¤

¤¤¤ webové prehliadače : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač : [NENAHRATÉ 0x0] ¤¤¤

¤¤¤ Vonkajšie Hives: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] cf455faf6b0a8e6f039f1a1c85940606
[BSP] 62bd435f1bfbc0fb8ba6e585765f7d3c : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097151 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončené : << RKreport[0]_S_02072014_194431.txt >>
RKreport[0]_S_02072014_193958.txt;RKreport[0]_S_02072014_194246.txt

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#9 Příspěvek od h4pple »

vytvoril som novy ucet ako spravcu(admina) prihlasil som sa...a hned uvodna privitacia obrazovka win 8 ze sa instaluju aplikacie a bla bla, potom ma to hodilo normalne na plochu a to iste, sami error pri programoch co sa psustaju pri starte, to iste presne ako pod mojim doterajsim kontom...dokonca ani program na touchpad nefunguje, som ho mal nastaveny ze sa vypne ked je pripojena mys a stale je zapnuty (touchpad), ako keby nechcelo spustit ziaden program...sradna ze chrome mi ide...ale uz adblocker v nom nejde.

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#10 Příspěvek od h4pple »

no, postupoval som podla pokynov, lenze po Scane mi neukazalo nic, ziadne okno kde by som mal volbu skip....ale log som nasiel na disku tak ho postnem.
EDIT: este chcem doplnit, neviem ci to ma nejaku vypovednu hodnotu ale chcem poznamenat este ze, pri spusteni programu mi naslo virus, teda avast mi ho nasiel a presunul do truhly, neviem ci som to uz spominal na zaciatku, vtedy este PC fungoval spravne, az po tom restarte prestal...a jedine co mi spusti pri starte je AVAST



20:49:20.0869 1692 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:49:20.0869 1692 UEFI system
20:49:20.0869 1692 ============================================================
20:49:20.0869 1692 Current date / time: 2014/02/07 20:49:20.0869
20:49:20.0869 1692 SystemInfo:
20:49:20.0869 1692
20:49:20.0869 1692 OS Version: 6.3.9600 ServicePack: 0.0
20:49:20.0869 1692 Product type: Workstation
20:49:20.0869 1692 ComputerName: H4PPLE
20:49:20.0869 1692 UserName: h4pple99
20:49:20.0869 1692 Windows directory: C:\WINDOWS
20:49:20.0869 1692 System windows directory: C:\WINDOWS
20:49:20.0869 1692 Running under WOW64
20:49:20.0869 1692 Processor architecture: Intel x64
20:49:20.0869 1692 Number of processors: 4
20:49:20.0869 1692 Page size: 0x1000
20:49:20.0869 1692 Boot type: Safe boot
20:49:20.0869 1692 ============================================================
20:49:21.0260 1692 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:49:21.0260 1692 ============================================================
20:49:21.0260 1692 \Device\Harddisk0\DR0:
20:49:21.0260 1692 GPT partitions:
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {DC04DB59-9565-43D6-ABFF-99D8069996A0}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {F3432D10-7572-4711-AB28-F1865977A690}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {802DD72C-CDB2-45BB-BAAD-A49964FEF93C}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {62C784EC-A322-4FE1-9677-6F94E6F74F41}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {31F05320-F0C0-4912-95BB-33B32AFFB7B6}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x6E7AD000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {3143DE1F-FEAB-4138-8F57-56543CE911ED}, Name: , StartLBA 0x6EC57800, BlocksNum 0xAF000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {75A15C95-5FB6-4640-B4B5-C26C89975994}, Name: Basic data partition, StartLBA 0x6ED06800, BlocksNum 0x3200000
20:49:21.0260 1692 \Device\Harddisk0\DR0\Partition8: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {FB4C769A-FA0A-4727-8DB9-8E8A2353740F}, Name: Basic data partition, StartLBA 0x71F06800, BlocksNum 0x2800000
20:49:21.0260 1692 MBR partitions:
20:49:21.0260 1692 ============================================================
20:49:21.0291 1692 C: <-> \Device\Harddisk0\DR0\Partition5
20:49:21.0338 1692 D: <-> \Device\Harddisk0\DR0\Partition7
20:49:21.0338 1692 ============================================================
20:49:21.0338 1692 Initialize success
20:49:21.0338 1692 ============================================================
20:49:31.0057 1712 ============================================================
20:49:31.0057 1712 Scan started
20:49:31.0057 1712 Mode: Manual; SigCheck; TDLFS;
20:49:31.0057 1712 ============================================================
20:49:31.0448 1712 ================ Scan system memory ========================
20:49:31.0448 1712 System memory - ok
20:49:31.0448 1712 ================ Scan services =============================
20:49:31.0619 1712 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
20:49:31.0651 1712 1394ohci - ok
20:49:31.0666 1712 [ AD508A1A46EC21B740AB31C28EFDFDB1 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
20:49:31.0666 1712 3ware - ok
20:49:31.0713 1712 [ 3D30878A269D934100FA5F972E53AF39 ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
20:49:31.0729 1712 ACPI - ok
20:49:31.0744 1712 [ AC8279D229398BCF05C3154ADCA86813 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
20:49:31.0744 1712 acpiex - ok
20:49:31.0776 1712 [ A8970D9BF23CD309E0403978A1B58F3F ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
20:49:31.0776 1712 acpipagr - ok
20:49:31.0791 1712 [ 111A89C99C5B4F1A7BCE5F643DD86F65 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
20:49:31.0791 1712 AcpiPmi - ok
20:49:31.0807 1712 [ 5758387D68A20AE7D3245011B07E36E7 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
20:49:31.0807 1712 acpitime - ok
20:49:31.0854 1712 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
20:49:31.0854 1712 ACPIVPC - ok
20:49:31.0948 1712 [ B362181ED3771DC03B4141927C80F801 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:49:31.0948 1712 AdobeARMservice - ok
20:49:31.0979 1712 [ 7C1FDF1B48298CBA7CE4BDD4978951AD ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS
20:49:32.0010 1712 ADP80XX - ok
20:49:32.0041 1712 [ B19CA8E441D35AA2B1EE51C10B27DA1B ] AeLookupSvc C:\WINDOWS\System32\aelupsvc.dll
20:49:32.0057 1712 AeLookupSvc - ok
20:49:32.0073 1712 [ 239268BAB58EAE9A3FF4E08334C00451 ] AFD C:\WINDOWS\system32\drivers\afd.sys
20:49:32.0088 1712 AFD - ok
20:49:32.0104 1712 [ 7DFAEBA9AD62D20102B576D5CAC45EC8 ] agp440 C:\WINDOWS\system32\drivers\agp440.sys
20:49:32.0119 1712 agp440 - ok
20:49:32.0119 1712 [ 8E8E34B7BA059050EED827410D0697A2 ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
20:49:32.0135 1712 ahcache - ok
20:49:32.0151 1712 [ A91D8E1E433EFB32551BCE69037E1CE7 ] ALG C:\WINDOWS\System32\alg.exe
20:49:32.0166 1712 ALG - ok
20:49:32.0198 1712 [ 7589DE749DB6F71A68489DCE04158729 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
20:49:32.0198 1712 AmdK8 - ok
20:49:32.0213 1712 [ B46D2D89AFF8A9490FA8C98C7A5616E3 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
20:49:32.0229 1712 AmdPPM - ok
20:49:32.0244 1712 [ D2BF2F94A47D332814910FD47C6BBCD2 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
20:49:32.0244 1712 amdsata - ok
20:49:32.0276 1712 [ A8E04943C7BBA7219AA50400272C3C6E ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
20:49:32.0276 1712 amdsbs - ok
20:49:32.0291 1712 [ CEA5F4F27CFC08E3A44D576811B35F50 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
20:49:32.0291 1712 amdxata - ok
20:49:32.0307 1712 [ 04951A9A937CBE28A2D3FEEA360B6D1F ] AppID C:\WINDOWS\system32\drivers\appid.sys
20:49:32.0323 1712 AppID - ok
20:49:32.0354 1712 [ C0DC3F58214A227980AEB091CFD2F973 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
20:49:32.0354 1712 AppIDSvc - ok
20:49:32.0385 1712 [ 7E790DE2487CEDB349D1750B9E47F090 ] Appinfo C:\WINDOWS\System32\appinfo.dll
20:49:32.0385 1712 Appinfo - ok
20:49:32.0416 1712 [ 4B964AE0DF433A3BFA7BD24713BC2E9B ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
20:49:32.0416 1712 AppReadiness - ok
20:49:32.0463 1712 [ 0B726D9ED75C787D6FFAF1E3873BCC70 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
20:49:32.0479 1712 AppXSvc - ok
20:49:32.0510 1712 [ 65045784366F7EC5FB4E71BCF923187B ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
20:49:32.0510 1712 arcsas - ok
20:49:32.0541 1712 [ D07E6D1765AEDD75E67987921BBA43AD ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
20:49:32.0557 1712 aswKbd - ok
20:49:32.0573 1712 [ 0ACC3F49015E628590CA4372322EB46B ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
20:49:32.0573 1712 aswMonFlt - ok
20:49:32.0588 1712 [ 679712B7A353EE665B9301592164A172 ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
20:49:32.0604 1712 aswRdr - ok
20:49:32.0604 1712 [ C04F7B373881009D7994D9BF55D24AB4 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
20:49:32.0620 1712 aswRvrt - ok
20:49:32.0635 1712 [ 43599E630DFC30AD4E6A2B4B269EB1C0 ] aswSnx C:\windows\system32\drivers\aswSnx.sys
20:49:32.0651 1712 aswSnx - ok
20:49:32.0666 1712 [ F22DE5F5BA8ADA0A861441B624B51EB5 ] aswSP C:\windows\system32\drivers\aswSP.sys
20:49:32.0682 1712 aswSP - ok
20:49:32.0698 1712 [ FD3EA14ADF6216BDF4030DB2EFD43D96 ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys
20:49:32.0698 1712 aswStm - ok
20:49:32.0729 1712 [ 90399625F341AB76BA4B85A5E860EB1F ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
20:49:32.0729 1712 aswVmm - ok
20:49:32.0745 1712 [ 74B14192CF79A72F7536B27CB8814FBD ] atapi C:\WINDOWS\system32\drivers\atapi.sys
20:49:32.0745 1712 atapi - ok
20:49:32.0776 1712 [ FC0E8778C000291CAF60EB88C011E931 ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys
20:49:32.0791 1712 atksgt - ok
20:49:32.0823 1712 [ 4903CBC14742B5AB4DCF7A92F7DEC483 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
20:49:32.0823 1712 AudioEndpointBuilder - ok
20:49:32.0854 1712 [ 86DD7884124D363A63CCE7A11FDEBBED ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
20:49:32.0854 1712 Audiosrv - ok
20:49:32.0932 1712 [ 4D41D30E2FAB3307967C7A0B045DC874 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:49:32.0948 1712 avast! Antivirus - ok
20:49:32.0979 1712 [ 96E8CAF20FC4B6C31CAD7816A801EB78 ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
20:49:32.0979 1712 AxInstSV - ok
20:49:33.0010 1712 [ A4A73F631FE2AA2826FBE4A399B04DEF ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
20:49:33.0026 1712 b06bdrv - ok
20:49:33.0041 1712 [ 8CC7F7E4AFCBA605921B137ED7992C68 ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
20:49:33.0057 1712 BasicDisplay - ok
20:49:33.0073 1712 [ 2748E116F8621A4DB0D39FCDD7318C01 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
20:49:33.0073 1712 BasicRender - ok
20:49:33.0120 1712 [ 70433F7A216BD0B5EC7DA1202EE53E65 ] bcbtums C:\WINDOWS\system32\drivers\bcbtums.sys
20:49:33.0120 1712 bcbtums - ok
20:49:33.0260 1712 [ 9A4EF701A4FC835F7DDD8956D930010F ] BCM43XX C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys
20:49:33.0370 1712 BCM43XX - ok
20:49:33.0416 1712 [ 18B186BCC56EC611DE519CBA7D4F65B0 ] BcmBtRSupport C:\WINDOWS\system32\BtwRSupportService.exe
20:49:33.0448 1712 BcmBtRSupport - ok
20:49:33.0479 1712 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21 ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys
20:49:33.0479 1712 bcmfn2 - ok
20:49:33.0557 1712 [ BBE61A40665B83488901E41082A6097D ] BDESVC C:\WINDOWS\System32\bdesvc.dll
20:49:33.0557 1712 BDESVC - ok
20:49:33.0620 1712 [ EC19013E4CF87609534165DF897274D6 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:49:33.0620 1712 Beep - ok
20:49:33.0651 1712 [ 6468B696C65775D51A06615830E0E79D ] BFE C:\WINDOWS\System32\bfe.dll
20:49:33.0666 1712 BFE - ok
20:49:33.0713 1712 [ 15225081966C785A9192782401643FD4 ] BITS C:\WINDOWS\System32\qmgr.dll
20:49:33.0729 1712 BITS - ok
20:49:33.0745 1712 [ 6B4FFFDDC618FCF64473CAA86E305697 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
20:49:33.0745 1712 bowser - ok
20:49:33.0760 1712 [ 748141CC03DF40C38F17D3F96BB15C80 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
20:49:33.0776 1712 BrokerInfrastructure - ok
20:49:33.0807 1712 [ D528D6A92D187777691993DD757AF19A ] Browser C:\WINDOWS\System32\browser.dll
20:49:33.0823 1712 Browser - ok
20:49:33.0823 1712 [ A8F23D453A424FF4DE04989C4727ECC7 ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
20:49:33.0838 1712 BthAvrcpTg - ok
20:49:33.0854 1712 [ 131F1C8573E7BFB41C54FBF5309CCD94 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys
20:49:33.0854 1712 BthEnum - ok
20:49:33.0870 1712 [ 746B9F94214915AECDE4B7FEA5FF9664 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
20:49:33.0885 1712 BthHFEnum - ok
20:49:33.0901 1712 [ 71FE2A48E4C93DDB9798C024880B6C07 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
20:49:33.0901 1712 bthhfhid - ok
20:49:33.0916 1712 [ FCD8BD17B7193CFFF18C332D1A381D7F ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
20:49:33.0932 1712 BthLEEnum - ok
20:49:33.0948 1712 [ 07E33226AD218A2A162662A05CAFB52F ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
20:49:33.0948 1712 BTHMODEM - ok
20:49:33.0979 1712 [ 3AFE71D80EDF5D4DE0C5731352905669 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
20:49:33.0979 1712 BthPan - ok
20:49:34.0010 1712 [ 10EDF9E0838BA4578FFFFF274632D454 ] BTHPORT C:\WINDOWS\System32\Drivers\BTHport.sys
20:49:34.0026 1712 BTHPORT - ok
20:49:34.0041 1712 [ E5E48FEED73D463175EAB1542495191C ] bthserv C:\WINDOWS\system32\bthserv.dll
20:49:34.0057 1712 bthserv - ok
20:49:34.0073 1712 [ 0E7FA34B975764C33B5DBC6F8C401627 ] BTHUSB C:\WINDOWS\System32\Drivers\BTHUSB.sys
20:49:34.0088 1712 BTHUSB - ok
20:49:34.0135 1712 [ 20C8EB70C0B179DF06A01CA503F4A824 ] btwampfl C:\WINDOWS\system32\DRIVERS\btwampfl.sys
20:49:34.0135 1712 btwampfl - ok
20:49:34.0213 1712 [ B0AAB7F9638D1315760F5C48A24CFEAB ] btwdins C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
20:49:34.0213 1712 btwdins - ok
20:49:34.0245 1712 [ 2FA6510E33F7DEFEC03658B74101A9B9 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
20:49:34.0245 1712 cdfs - ok
20:49:34.0260 1712 [ C6796EA22B513E3457514D92DCDB1A3D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
20:49:34.0276 1712 cdrom - ok
20:49:34.0291 1712 [ AB285CE3431FF3D2ACE669245874C1C7 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
20:49:34.0307 1712 CertPropSvc - ok
20:49:34.0323 1712 [ BE9936EDD3267FAAFF94A7835867F00B ] circlass C:\WINDOWS\System32\drivers\circlass.sys
20:49:34.0338 1712 circlass - ok
20:49:34.0370 1712 [ 7F006813C2AFE622C13D7AF94F56CD07 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
20:49:34.0385 1712 CLFS - ok
20:49:34.0401 1712 [ EF6EF85DADC3184A10D8F2F7159973CB ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
20:49:34.0416 1712 CmBatt - ok
20:49:34.0432 1712 [ 825BE21E6395E00698D8A23955A87972 ] CNG C:\WINDOWS\system32\Drivers\cng.sys
20:49:34.0448 1712 CNG - ok
20:49:34.0495 1712 [ 1F925AA990A6A446E8BA926B2D0A5201 ] CnxtHdAudService C:\WINDOWS\system32\drivers\CHDRT64.sys
20:49:34.0510 1712 CnxtHdAudService - ok
20:49:34.0526 1712 [ 03AAED827C36F35D70900558B8274905 ] CompositeBus C:\WINDOWS\System32\drivers\CompositeBus.sys
20:49:34.0541 1712 CompositeBus - ok
20:49:34.0541 1712 COMSysApp - ok
20:49:34.0541 1712 [ A1FF7DFBFBE164CF92603C651D304DD2 ] condrv C:\WINDOWS\system32\drivers\condrv.sys
20:49:34.0557 1712 condrv - ok
20:49:34.0635 1712 [ 034643AFE2973A175E782AE530A0683C ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
20:49:34.0651 1712 cphs - ok
20:49:34.0745 1712 [ 0EFE4B5884A8032617826A4D76F80969 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
20:49:34.0760 1712 CryptSvc - ok
20:49:34.0807 1712 [ 48AED45DF009081AF3F5144F7D624674 ] CxAudMsg C:\WINDOWS\system32\CxAudMsg64.exe
20:49:34.0807 1712 CxAudMsg - ok
20:49:34.0885 1712 [ 315BA4BC19316D72B2E037534E048B93 ] dam C:\WINDOWS\system32\drivers\dam.sys
20:49:34.0901 1712 dam - ok
20:49:34.0948 1712 [ 3FD5AE42EC87C6F532A931F96BE731DD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:49:34.0948 1712 DcomLaunch - ok
20:49:34.0963 1712 [ F4CCAADC2C78F57E4F16B24C9201CE22 ] defragsvc C:\WINDOWS\System32\defragsvc.dll
20:49:34.0979 1712 defragsvc - ok
20:49:35.0026 1712 [ 0BC71D4D3B5883903C37BF4E13B0F0C5 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
20:49:35.0041 1712 DeviceAssociationService - ok
20:49:35.0073 1712 [ 752A457320A946E03C3AA86C3ACD735E ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
20:49:35.0088 1712 DeviceInstall - ok
20:49:35.0151 1712 [ 5DB26D7E0216D0BF364A81D3829AD7B9 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
20:49:35.0151 1712 Dfsc - ok
20:49:35.0198 1712 [ 8B107F55FD61654A6C9F1B819AEC5FC4 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
20:49:35.0198 1712 Dhcp - ok
20:49:35.0213 1712 [ 4D40C9B33F738797CF50E77CB7C53E85 ] disk C:\WINDOWS\system32\drivers\disk.sys
20:49:35.0229 1712 disk - ok
20:49:35.0229 1712 [ EB70A894708D1BC176AFD690FF06085F ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
20:49:35.0229 1712 dmvsc - ok
20:49:35.0276 1712 [ 5BAF7714E68F93515A937A3FA8587EF9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:49:35.0276 1712 Dnscache - ok
20:49:35.0307 1712 [ 50288EA079BB520C2B8C8A154202D518 ] dot3svc C:\WINDOWS\System32\dot3svc.dll
20:49:35.0307 1712 dot3svc - ok
20:49:35.0338 1712 [ 281BEE07BA97E3E98D12A822D923D0D8 ] DPS C:\WINDOWS\system32\dps.dll
20:49:35.0354 1712 DPS - ok
20:49:35.0370 1712 [ DDC11A202207C0400CBE07315B8FDE5E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:49:35.0370 1712 drmkaud - ok
20:49:35.0401 1712 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
20:49:35.0417 1712 DsmSvc - ok
20:49:35.0448 1712 [ 6A0E850DDCB136AA3D2FB7234382DF12 ] dtsoftbus01 C:\WINDOWS\System32\drivers\dtsoftbus01.sys
20:49:35.0448 1712 dtsoftbus01 - ok
20:49:35.0510 1712 [ A3D1CB64DF885ACE126543E6D7067348 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
20:49:35.0542 1712 DXGKrnl - ok
20:49:35.0588 1712 [ 6073537F250B45E1CB2A02E97F0FE1B2 ] Eaphost C:\WINDOWS\System32\eapsvc.dll
20:49:35.0588 1712 Eaphost - ok
20:49:35.0667 1712 [ 114BCFDF367FF37C3F1B0A96AF542E4D ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
20:49:35.0729 1712 ebdrv - ok
20:49:35.0776 1712 [ F6F209DDB94959BA104FC8FC87C53759 ] EFS C:\WINDOWS\System32\lsass.exe
20:49:35.0776 1712 EFS - ok
20:49:35.0792 1712 [ 43531A5993380CC5113242C29D265FD9 ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
20:49:35.0792 1712 EhStorClass - ok
20:49:35.0823 1712 [ 6F8E738A9505A388B1157FDDE7B3101B ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
20:49:35.0838 1712 EhStorTcgDrv - ok
20:49:35.0854 1712 [ DFFFAE1442BA4076E18EED5E406FA0D3 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
20:49:35.0854 1712 ErrDev - ok
20:49:35.0901 1712 [ 14D498FB39BB60D1A36160F22BB4CA8E ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
20:49:35.0901 1712 ETD - ok
20:49:35.0948 1712 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3 ] EventSystem C:\WINDOWS\system32\es.dll
20:49:35.0963 1712 EventSystem - ok
20:49:35.0963 1712 [ 7729D294A555C7AEB281ED8E4D0E01E4 ] exfat C:\WINDOWS\system32\drivers\exfat.sys
20:49:35.0979 1712 exfat - ok
20:49:35.0979 1712 [ 7C4E0D5900B2A1D11EDD626D6DDB937B ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
20:49:35.0995 1712 fastfat - ok
20:49:36.0026 1712 [ 2BC8532ABF2B3756B78FA1DA54147DDE ] Fax C:\WINDOWS\system32\fxssvc.exe
20:49:36.0042 1712 Fax - ok
20:49:36.0073 1712 [ 5D8402613E778B3BD45E687A8372710B ] fdc C:\WINDOWS\System32\drivers\fdc.sys
20:49:36.0073 1712 fdc - ok
20:49:36.0104 1712 [ DC1A78BCCCB7EE53D6FD3BD615A8E222 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
20:49:36.0120 1712 fdPHost - ok
20:49:36.0120 1712 [ E5AD448F2DC84B1CF387FA7F2A3D1936 ] FDResPub C:\WINDOWS\system32\fdrespub.dll
20:49:36.0135 1712 FDResPub - ok
20:49:36.0167 1712 [ 0046E0BD031213D37123876B0D0FA61C ] fhsvc C:\WINDOWS\system32\fhsvc.dll
20:49:36.0167 1712 fhsvc - ok
20:49:36.0213 1712 [ 957A7A8F5ACCAF23DD9DFF6DAA393CE5 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
20:49:36.0276 1712 FileInfo - ok
20:49:36.0292 1712 [ A1A66C4FDAFD6B0289523232AFB7D8AF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
20:49:36.0307 1712 Filetrace - ok
20:49:36.0323 1712 [ BE743083CF7063C486A4398E3AEFE59A ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
20:49:36.0338 1712 flpydisk - ok
20:49:36.0354 1712 [ 60D5067FCE6D9433D35E04C01D8538B3 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:49:36.0370 1712 FltMgr - ok
20:49:36.0432 1712 [ 183CA7699474FDE235853967D1DA4D9B ] FontCache C:\WINDOWS\system32\FntCache.dll
20:49:36.0448 1712 FontCache - ok
20:49:36.0604 1712 [ 1C52387BF5A127F5F3BFB31288F30D93 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:49:36.0604 1712 FontCache3.0.0.0 - ok
20:49:36.0620 1712 [ 35005534E600E993A90B036E4E599F2B ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
20:49:36.0635 1712 FsDepends - ok
20:49:36.0651 1712 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:49:36.0651 1712 Fs_Rec - ok
20:49:36.0698 1712 [ 83E1F0983B02A6F8EC764D18E24ECF10 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
20:49:36.0713 1712 fvevol - ok
20:49:36.0729 1712 [ 9591D0B9351ED489EAFD9D1CE52A8015 ] FxPPM C:\WINDOWS\System32\drivers\fxppm.sys
20:49:36.0745 1712 FxPPM - ok
20:49:36.0760 1712 [ FC3EF65EE20D39F8749C2218DBA681CA ] gagp30kx C:\WINDOWS\system32\drivers\gagp30kx.sys
20:49:36.0760 1712 gagp30kx - ok
20:49:36.0792 1712 [ 0BF5CAD281E25F1418E5B8875DC5ADD1 ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
20:49:36.0807 1712 gencounter - ok
20:49:36.0838 1712 [ FDA72810CA2F8409D9B31E833C448E34 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
20:49:36.0854 1712 GPIOClx0101 - ok
20:49:36.0917 1712 [ 0BDE0FCF597E9B65600121EF54FF8340 ] gpsvc C:\WINDOWS\System32\gpsvc.dll
20:49:36.0932 1712 gpsvc - ok
20:49:37.0026 1712 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:49:37.0026 1712 gupdate - ok
20:49:37.0026 1712 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:49:37.0026 1712 gupdatem - ok
20:49:37.0057 1712 [ 56F69F7C25FB67C970997D7066DBC593 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys
20:49:37.0057 1712 HdAudAddService - ok
20:49:37.0088 1712 [ 03909BDBFF0DCACCABF2B2D4ADEE44DC ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
20:49:37.0088 1712 HDAudBus - ok
20:49:37.0104 1712 [ 10A70BC1871CD955D85CD88372724906 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
20:49:37.0120 1712 HidBatt - ok
20:49:37.0135 1712 [ 1EA1B4FABB8CC348E73CA90DBA22E104 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
20:49:37.0135 1712 HidBth - ok
20:49:37.0151 1712 [ C241A8BAFBBFC90176EA0F5240EACC17 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
20:49:37.0167 1712 hidi2c - ok
20:49:37.0182 1712 [ 9BDDEE26255421017E161CCB9D5EDA95 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
20:49:37.0182 1712 HidIr - ok
20:49:37.0213 1712 [ 449A20A674AA3FAA7F0DD4E33EE2DC20 ] hidserv C:\WINDOWS\system32\hidserv.dll
20:49:37.0213 1712 hidserv - ok
20:49:37.0229 1712 [ F31397220D9687E11EB448649AA6E038 ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
20:49:37.0229 1712 HidUsb - ok
20:49:37.0276 1712 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5 ] hkmsvc C:\WINDOWS\system32\kmsvc.dll
20:49:37.0276 1712 hkmsvc - ok
20:49:37.0292 1712 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
20:49:37.0307 1712 HomeGroupListener - ok
20:49:37.0338 1712 [ BE5F89BAFBD4272D5A0C0A37B97865ED ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
20:49:37.0354 1712 HomeGroupProvider - ok
20:49:37.0370 1712 [ A6AACEA4C785789BDA5912AD1FEDA80D ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
20:49:37.0385 1712 HpSAMD - ok
20:49:37.0417 1712 [ 3502776E366C913D49C0DA928AE3E6CB ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
20:49:37.0432 1712 HTTP - ok
20:49:37.0448 1712 [ 90656C0B3864804B090434EFC582404F ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
20:49:37.0463 1712 hwpolicy - ok
20:49:37.0479 1712 [ 6D6F9E3BF0484967E52F7E846BFF1CA1 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
20:49:37.0479 1712 hyperkbd - ok
20:49:37.0495 1712 [ 907C870F8C31F8DDD6F090857B46AB25 ] HyperVideo C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
20:49:37.0495 1712 HyperVideo - ok
20:49:37.0510 1712 [ 84CFC5EFA97D0C965EDE1D56F116A541 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
20:49:37.0526 1712 i8042prt - ok
20:49:37.0542 1712 [ 5D90E32E36CE5D4C535D17CE08AEAF05 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
20:49:37.0542 1712 iaLPSSi_GPIO - ok
20:49:37.0573 1712 [ DD05E7E80F52ADE9AEB292819920F32C ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
20:49:37.0573 1712 iaLPSSi_I2C - ok
20:49:37.0635 1712 [ 6C024B3AE192D72B216166802AF345DD ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
20:49:37.0635 1712 iaStorA - ok
20:49:37.0682 1712 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys
20:49:37.0698 1712 iaStorAV - ok
20:49:37.0713 1712 [ A2200C3033FA4EF249FC096A7A7D02A2 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
20:49:37.0729 1712 iaStorV - ok
20:49:37.0729 1712 IEEtwCollectorService - ok
20:49:37.0823 1712 [ 7A5A61997B5404C8EDDFCC62378164DC ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
20:49:37.0870 1712 igfx - ok
20:49:37.0917 1712 [ B82255670D270B75D2D2F0F8747D1443 ] IKEEXT C:\WINDOWS\System32\ikeext.dll
20:49:37.0932 1712 IKEEXT - ok
20:49:37.0964 1712 [ 4011430BC9DA46ADFAE9915EFEC312FB ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
20:49:37.0964 1712 intaud_WaveExtensible - ok
20:49:38.0010 1712 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
20:49:38.0026 1712 IntcDAud - ok
20:49:38.0135 1712 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
20:49:38.0151 1712 Intel(R) Capability Licensing Service Interface - ok
20:49:38.0167 1712 [ 4E448FCFFD00E8D657CD9E48D3E47157 ] intelide C:\WINDOWS\system32\drivers\intelide.sys
20:49:38.0182 1712 intelide - ok
20:49:38.0229 1712 [ 139CFCDCD36B1B1782FD8C0014AC9B0E ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
20:49:38.0229 1712 intelpep - ok
20:49:38.0245 1712 [ 47E74A8E53C7C24DCE38311E1451C1D9 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
20:49:38.0245 1712 intelppm - ok
20:49:38.0276 1712 [ 9DB76D7F9E4E53EFE5DD8C53DE837514 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:49:38.0292 1712 IpFilterDriver - ok
20:49:38.0339 1712 [ DFC4050D58565ADBEE793A8D4AEBDAE6 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
20:49:38.0354 1712 iphlpsvc - ok
20:49:38.0370 1712 [ 9949A3C7590B8C536C05312205079A82 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
20:49:38.0385 1712 IPMIDRV - ok
20:49:38.0401 1712 [ E23D32BAF152FBE35F18C6A2AB8EF271 ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
20:49:38.0401 1712 IPNAT - ok
20:49:38.0432 1712 [ AE44C526AB5F8A487D941CEB57B10C97 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
20:49:38.0432 1712 IRENUM - ok
20:49:38.0448 1712 [ 8AFEEA3955AA43616A60F133B1D25F21 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
20:49:38.0464 1712 isapnp - ok
20:49:38.0510 1712 [ 034D4BD9DC67C64F3A4C8A049B5173BF ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
20:49:38.0510 1712 iScsiPrt - ok
20:49:38.0557 1712 [ EE03564B7FAFE2E44EDA33D52E83B4A3 ] iwdbus C:\WINDOWS\System32\drivers\iwdbus.sys
20:49:38.0573 1712 iwdbus - ok
20:49:38.0620 1712 [ 78ABBE558F57144047F10A0F50FE4B2F ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
20:49:38.0620 1712 jhi_service - ok
20:49:38.0651 1712 [ 8BE92376799B6B44D543E8D07CDCF885 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
20:49:38.0651 1712 kbdclass - ok
20:49:38.0667 1712 [ FB6E47E569D4872ABEB506BE03A45FBA ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
20:49:38.0682 1712 kbdhid - ok
20:49:38.0682 1712 [ 813871C7D402A05F2E3A7075F9584A05 ] kdnic C:\WINDOWS\system32\DRIVERS\kdnic.sys
20:49:38.0698 1712 kdnic - ok
20:49:38.0714 1712 [ F6F209DDB94959BA104FC8FC87C53759 ] KeyIso C:\WINDOWS\system32\lsass.exe
20:49:38.0714 1712 KeyIso - ok
20:49:38.0729 1712 [ ADDECBCC777665BD113BED437E602AB0 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
20:49:38.0729 1712 KSecDD - ok
20:49:38.0760 1712 [ 7296EA420134EAC390798B3232D066A4 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
20:49:38.0760 1712 KSecPkg - ok
20:49:38.0776 1712 [ 11AFB527AA370B1DAFD5C36F35F6D45F ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
20:49:38.0776 1712 ksthunk - ok
20:49:38.0823 1712 [ 32B1A8351160F307A8C66BCB0F94A9C2 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
20:49:38.0823 1712 KtmRm - ok
20:49:38.0854 1712 [ 50AECF8C21AB2A6428A6E1E10549D8E5 ] L1C C:\WINDOWS\system32\DRIVERS\L1C63x64.sys
20:49:38.0870 1712 L1C - ok
20:49:38.0901 1712 [ 27B58E16CF895AC1F1A97C04814C2239 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
20:49:38.0917 1712 LanmanServer - ok
20:49:38.0964 1712 [ D0D9C2ECA4D03A8F06DCD91236B90C98 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
20:49:38.0979 1712 LanmanWorkstation - ok
20:49:39.0042 1712 [ 93138543A4D836E97543BA2B857BDBFF ] Lenovo Smart Update Service C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update Service.exe
20:49:39.0042 1712 Lenovo Smart Update Service - ok
20:49:39.0135 1712 [ EE289BD147FDFF95EF1B9BD65D3B974A ] lfsvc C:\WINDOWS\System32\GeofenceMonitorService.dll
20:49:39.0135 1712 lfsvc - ok
20:49:39.0167 1712 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\WINDOWS\system32\DRIVERS\LhdX64.sys
20:49:39.0167 1712 LHDmgr - ok
20:49:39.0198 1712 [ 156AB2E56DC3CA0B582E3362E07CDED7 ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys
20:49:39.0214 1712 lirsgt - ok
20:49:39.0229 1712 [ C09010B3680860131631F53E8FE7BAD8 ] lltdio C:\WINDOWS\system32\DRIVERS\lltdio.sys
20:49:39.0229 1712 lltdio - ok
20:49:39.0276 1712 [ 00E070FC0C673311AFD4B068D1242780 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
20:49:39.0276 1712 lltdsvc - ok
20:49:39.0323 1712 [ D113FAD71A5E67AA94B32A0F8828D265 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
20:49:39.0323 1712 lmhosts - ok
20:49:39.0354 1712 [ 2C24DC448DBE8DB9BE1441B824C57E79 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
20:49:39.0354 1712 LMS - ok
20:49:39.0432 1712 [ 2808470E5E91D8838243D9045588C303 ] LSCWinService C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
20:49:39.0432 1712 LSCWinService - ok
20:49:39.0479 1712 [ C755AE4635457AA2A11F79C0DF857ABC ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
20:49:39.0479 1712 LSI_SAS - ok
20:49:39.0495 1712 [ ADAC09CBE7A2040B7F68B5E5C9A75141 ] LSI_SAS2 C:\WINDOWS\system32\drivers\lsi_sas2.sys
20:49:39.0495 1712 LSI_SAS2 - ok
20:49:39.0495 1712 [ 04D1274BB9BBCCF12BD12374002AA191 ] LSI_SAS3 C:\WINDOWS\system32\drivers\lsi_sas3.sys
20:49:39.0510 1712 LSI_SAS3 - ok
20:49:39.0526 1712 [ 327469EEF3833D0C584B7E88A76AEC0C ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
20:49:39.0526 1712 LSI_SSS - ok
20:49:39.0557 1712 [ B6B69FF200F68888A7FAFDF204D00C91 ] LSM C:\WINDOWS\System32\lsm.dll
20:49:39.0573 1712 LSM - ok
20:49:39.0589 1712 [ 5EF604B0698F4FA962778285E8C5F1F2 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
20:49:39.0604 1712 luafv - ok
20:49:39.0620 1712 [ EB5C03A070F30D64A6DF80E53B22F53F ] megasas C:\WINDOWS\system32\drivers\megasas.sys
20:49:39.0620 1712 megasas - ok
20:49:39.0651 1712 [ F6F13533196DE7A582D422B0241E4363 ] megasr C:\WINDOWS\system32\drivers\megasr.sys
20:49:39.0667 1712 megasr - ok
20:49:39.0714 1712 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
20:49:39.0714 1712 MEIx64 - ok
20:49:39.0760 1712 [ FD788C2D96EA91469A3C1D13E80D7473 ] MMCSS C:\WINDOWS\system32\mmcss.dll
20:49:39.0760 1712 MMCSS - ok
20:49:39.0807 1712 [ 8B38C44F69259987C95135C9627E2378 ] Modem C:\WINDOWS\system32\drivers\modem.sys
20:49:39.0807 1712 Modem - ok
20:49:39.0823 1712 [ 601589000CC90F0DF8DA2CC254A3CCC9 ] monitor C:\WINDOWS\System32\drivers\monitor.sys
20:49:39.0839 1712 monitor - ok
20:49:39.0839 1712 [ CEAC6D40FE887CE8406C2393CF97DE06 ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys
20:49:39.0854 1712 mouclass - ok
20:49:39.0870 1712 [ 02D98BF804084E9A0D69D1C69B02CCA9 ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys
20:49:39.0870 1712 mouhid - ok
20:49:39.0885 1712 [ 515549560D481138E6E21AF7C6998E56 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys
20:49:39.0901 1712 mountmgr - ok
20:49:39.0901 1712 [ F170510BE94CF45E3C6274578F6204B2 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys
20:49:39.0917 1712 mpsdrv - ok
20:49:39.0964 1712 [ D186C5844393252147BE934F3871DB7A ] MpsSvc C:\WINDOWS\system32\mpssvc.dll
20:49:39.0979 1712 MpsSvc - ok
20:49:40.0010 1712 [ 59DCEC7499095DE5AED741358037AE2D ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys
20:49:40.0010 1712 MRxDAV - ok
20:49:40.0042 1712 [ 6129EDB793A4255B1E2FB41773AC9D9A ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:49:40.0042 1712 mrxsmb - ok
20:49:40.0057 1712 [ 295771B092D4F7FCF2B62F80CCD14320 ] mrxsmb10 C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
20:49:40.0057 1712 mrxsmb10 - ok
20:49:40.0073 1712 [ AAF56E4E84D35411B4E446C445732DFE ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
20:49:40.0073 1712 mrxsmb20 - ok
20:49:40.0104 1712 [ 4E888019078AC363076A5433E89AA4F8 ] MsBridge C:\WINDOWS\system32\DRIVERS\bridge.sys
20:49:40.0104 1712 MsBridge - ok
20:49:40.0151 1712 [ A082C17D14D0790E27D064EA4B138AE1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
20:49:40.0167 1712 MSDTC - ok
20:49:40.0182 1712 [ D13329FBF8345B28AB30F44CC247DC08 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:49:40.0198 1712 Msfs - ok
20:49:40.0198 1712 [ C6B474E46F9E543B875981ED3FFE6ADD ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys
20:49:40.0214 1712 msgpiowin32 - ok
20:49:40.0229 1712 [ 65C92EB9D08DB5C69F28C7FFD4E84E31 ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys
20:49:40.0229 1712 mshidkmdf - ok
20:49:40.0260 1712 [ 52299F086AC2DAFD100DD5DC4A8614BA ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys
20:49:40.0260 1712 mshidumdf - ok
20:49:40.0276 1712 [ 36D92AF3343C3A3E57FEF11C449AEA4C ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys
20:49:40.0276 1712 msisadrv - ok
20:49:40.0323 1712 [ 810F8A0A0680662BB0CE44D0E2CEF90C ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll
20:49:40.0339 1712 MSiSCSI - ok
20:49:40.0339 1712 msiserver - ok
20:49:40.0354 1712 [ A9BBBD2BAE6142253B9195E949AC2E8D ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:49:40.0354 1712 MSKSSRV - ok
20:49:40.0370 1712 [ 375E44168F2DFB91A68B8A3F619C5A7C ] MsLldp C:\WINDOWS\system32\DRIVERS\mslldp.sys
20:49:40.0385 1712 MsLldp - ok
20:49:40.0401 1712 [ 7B2128EB875DCBC006E6A913211006D6 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:49:40.0417 1712 MSPCLOCK - ok
20:49:40.0417 1712 [ 1E88171579B218115C7A772F8DE04BD8 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:49:40.0432 1712 MSPQM - ok
20:49:40.0464 1712 [ BBE2A455053E63BECBF42C2F9B21FAE0 ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys
20:49:40.0479 1712 MsRPC - ok
20:49:40.0495 1712 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys
20:49:40.0495 1712 mssmbios - ok
20:49:40.0510 1712 [ 115019AE01E0EB9C048530D2928AB4A2 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
20:49:40.0526 1712 MSTEE - ok
20:49:40.0526 1712 [ 96D604A35070360F0DD4A7A8AF410B5E ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
20:49:40.0542 1712 MTConfig - ok
20:49:40.0557 1712 [ 619CA29326B82372621DB2C0964D8365 ] Mup C:\WINDOWS\system32\Drivers\mup.sys
20:49:40.0557 1712 Mup - ok
20:49:40.0573 1712 [ B8C35C94DCB2DFEAF03BB42131F2F77F ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
20:49:40.0589 1712 mvumis - ok
20:49:40.0636 1712 [ 41A45D2A75494EABF2806EA051E00376 ] napagent C:\WINDOWS\system32\qagentRT.dll
20:49:40.0651 1712 napagent - ok
20:49:40.0682 1712 [ CF8B989D89D6807B887690F2CF24EFD9 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
20:49:40.0698 1712 NativeWifiP - ok
20:49:40.0745 1712 [ 71E3C0100AA19D11373CCEB2F51A6008 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
20:49:40.0745 1712 NcaSvc - ok
20:49:40.0761 1712 [ 51DF09CAB2CAC64FEE3E371D9028ED01 ] NcbService C:\WINDOWS\System32\ncbservice.dll
20:49:40.0761 1712 NcbService - ok
20:49:40.0792 1712 [ 2586C4C167499210DCBF3ECFD8CCE210 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
20:49:40.0792 1712 NcdAutoSetup - ok
20:49:40.0823 1712 [ AD9086052A5E5153AF43FE74138A4B27 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
20:49:40.0854 1712 NDIS - ok
20:49:40.0886 1712 [ C6BB12BC35D1637CA17AE16D3A4725EB ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
20:49:40.0886 1712 NdisCap - ok
20:49:40.0901 1712 [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37 ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
20:49:40.0901 1712 NdisImPlatform - ok
20:49:41.0073 1712 [ 9423421E735BD5394351E0C47C76BB92 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:49:41.0089 1712 NdisTapi - ok
20:49:41.0104 1712 [ B832B35055BA2B7B4181861FF94D8E59 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:49:41.0104 1712 Ndisuio - ok
20:49:41.0120 1712 [ 1F58E48EF75F34C35D8E93A0DC535CFE ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
20:49:41.0136 1712 NdisVirtualBus - ok
20:49:41.0151 1712 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:49:41.0167 1712 NdisWan - ok
20:49:41.0167 1712 [ DEC29080202D4F9F17F55E18BCFCC41A ] NdisWanLegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:49:41.0182 1712 NdisWanLegacy - ok
20:49:41.0182 1712 [ A5BD69A8812FA79D1A487691DD3FB244 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:49:41.0198 1712 NDProxy - ok
20:49:41.0214 1712 [ 5A072F0B90C29C5233D78BE33EF5ED78 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
20:49:41.0214 1712 Ndu - ok
20:49:41.0229 1712 [ A83D67D347A684F10B7D3019C8A6380C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:49:41.0245 1712 NetBIOS - ok
20:49:41.0261 1712 [ 0217532E19A748F0E5D569307363D5FD ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:49:41.0261 1712 NetBT - ok
20:49:41.0276 1712 [ F6F209DDB94959BA104FC8FC87C53759 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:49:41.0276 1712 Netlogon - ok
20:49:41.0323 1712 [ B7AD851A21FEBA3BA214972627614207 ] Netman C:\WINDOWS\System32\netman.dll
20:49:41.0339 1712 Netman - ok
20:49:41.0386 1712 [ F0F0A372C2EF6358399C4936F91B6131 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
20:49:41.0401 1712 netprofm - ok
20:49:41.0448 1712 [ 1092B3190E69E0C5ECBCE90F171DE047 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:49:41.0464 1712 NetTcpPortSharing - ok
20:49:41.0479 1712 [ 70414DB660BFBB7BD58FCE8EA4364E1B ] netvsc C:\WINDOWS\system32\DRIVERS\netvsc63.sys
20:49:41.0479 1712 netvsc - ok
20:49:41.0557 1712 [ 8CE7F624D791733E8CECFA443B2DF513 ] NitroDriverReadSpool2 C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe
20:49:41.0573 1712 NitroDriverReadSpool2 - ok
20:49:41.0589 1712 [ 3A280F3B3C7A46E29C404ACD46ECBF5E ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
20:49:41.0604 1712 NlaSvc - ok
20:49:41.0682 1712 [ AAAE3B793B248A3DF86C65928484AB9A ] nlsX86cc C:\windows\SysWOW64\NLSSRV32.EXE
20:49:41.0682 1712 nlsX86cc - ok
20:49:41.0761 1712 [ 8F44A2F57C9F1A19AC9C6288C10FB351 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:49:41.0776 1712 Npfs - ok
20:49:41.0807 1712 [ CBDB4F0871C88DF930FC0E8588CA67FC ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
20:49:41.0823 1712 npsvctrig - ok
20:49:41.0854 1712 [ 6E2271ED0C3E95B8E29F3752B91B9E84 ] nsi C:\WINDOWS\system32\nsisvc.dll
20:49:41.0870 1712 nsi - ok
20:49:41.0870 1712 [ E490B459978CB87779E84C761D22B827 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
20:49:41.0886 1712 nsiproxy - ok
20:49:41.0917 1712 [ 4412D565C0278C401575E11072C7DCE3 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:49:41.0964 1712 Ntfs - ok
20:49:41.0964 1712 [ EF1B290FC9F0E47CC0B537292BEE5904 ] Null C:\WINDOWS\system32\drivers\Null.sys
20:49:41.0979 1712 Null - ok
20:49:42.0167 1712 [ 0218E1CE8F7B5D404980192B9112D03A ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
20:49:42.0307 1712 nvlddmkm - ok
20:49:42.0432 1712 [ 1C7C6D7481CABD4EF38A81F5B68F02E8 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
20:49:42.0448 1712 NvNetworkService - ok
20:49:42.0479 1712 [ 2E334C10BFAB37BDF2A66F6E0D36C061 ] nvpciflt C:\WINDOWS\system32\DRIVERS\nvpciflt.sys
20:49:42.0479 1712 nvpciflt - ok
20:49:42.0526 1712 [ BC6B5942AFF25EBAF62DE43C3807EDF8 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
20:49:42.0542 1712 nvraid - ok
20:49:42.0542 1712 [ 1F43ABFFAC3D6CA356851D517392966E ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
20:49:42.0557 1712 nvstor - ok
20:49:42.0823 1712 [ 7A03646D5330A790A9D47D9F9C38758D ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
20:49:42.0995 1712 NvStreamSvc - ok
20:49:43.0057 1712 [ B7973C405247C5A44BA46B12A4B7AEEA ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
20:49:43.0073 1712 nvsvc - ok
20:49:43.0089 1712 [ 09216A70CC364D0974F606F6F2109210 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
20:49:43.0089 1712 nvvad_WaveExtensible - ok
20:49:43.0120 1712 [ 6934A936A7369DFE37B7DBA93F5E5E49 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
20:49:43.0136 1712 nv_agp - ok
20:49:43.0167 1712 [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:49:43.0182 1712 ose - ok
20:49:43.0214 1712 [ 3B510F20806B94E389784ED09DBD2111 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
20:49:43.0229 1712 p2pimsvc - ok
20:49:43.0276 1712 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B ] p2psvc C:\WINDOWS\system32\p2psvc.dll
20:49:43.0276 1712 p2psvc - ok
20:49:43.0308 1712 [ 764B1121867B2D9B31C491668AC72B2B ] Parport C:\WINDOWS\System32\drivers\parport.sys
20:49:43.0308 1712 Parport - ok
20:49:43.0323 1712 [ EF0C1749C9A8CEE9A457473D433CC00F ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
20:49:43.0323 1712 partmgr - ok
20:49:43.0354 1712 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
20:49:43.0370 1712 PcaSvc - ok
20:49:43.0370 1712 [ C0D3F3BC1C84B4BA746D9847314C1164 ] pci C:\WINDOWS\system32\drivers\pci.sys
20:49:43.0386 1712 pci - ok
20:49:43.0401 1712 [ 346E38FCC6859A727DD28AFAD1F0AFF4 ] pciide C:\WINDOWS\system32\drivers\pciide.sys
20:49:43.0417 1712 pciide - ok
20:49:43.0433 1712 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397 ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
20:49:43.0448 1712 pcmcia - ok
20:49:43.0464 1712 [ BF28771D1436C88BE1D297D3098B0F7D ] pcw C:\WINDOWS\system32\drivers\pcw.sys
20:49:43.0464 1712 pcw - ok
20:49:43.0511 1712 [ B9D968D8E2B0F9C6301CEB39CFC9B9E4 ] pdc C:\WINDOWS\system32\drivers\pdc.sys
20:49:43.0526 1712 pdc - ok
20:49:43.0573 1712 [ BA50CC0BD19004AAB88BE37338B6FA0D ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
20:49:43.0589 1712 PEAUTH - ok
20:49:43.0667 1712 [ 8E3C640FFF5A963F570233AE99C0FFF3 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
20:49:43.0667 1712 PerfHost - ok
20:49:43.0792 1712 [ 928061178CD9856CA6B67FFFCE6BA766 ] pla C:\WINDOWS\system32\pla.dll
20:49:43.0808 1712 pla - ok
20:49:43.0839 1712 [ 752A457320A946E03C3AA86C3ACD735E ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
20:49:43.0854 1712 PlugPlay - ok
20:49:43.0870 1712 [ 045EB4F260606A03BE340D09DEAF3BA4 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
20:49:43.0870 1712 PNRPAutoReg - ok
20:49:43.0901 1712 [ 3B510F20806B94E389784ED09DBD2111 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
20:49:43.0917 1712 PNRPsvc - ok
20:49:43.0948 1712 [ C16097D77A232A288D65F299E2E01105 ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
20:49:43.0964 1712 PolicyAgent - ok
20:49:43.0979 1712 [ 00E08B30E7F7C13ECE2CDF4F46A77311 ] Power C:\WINDOWS\system32\umpo.dll
20:49:43.0995 1712 Power - ok
20:49:44.0104 1712 [ B7DB57A000D46D4DE75BC0C563E58072 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
20:49:44.0136 1712 PrintNotify - ok
20:49:44.0229 1712 [ ECD373F9571C745894367CC2635EA44F ] Processor C:\WINDOWS\System32\drivers\processr.sys
20:49:44.0245 1712 Processor - ok
20:49:44.0261 1712 [ 8513A1E7AE4B9DC82C4B4F432C648A58 ] ProfSvc C:\WINDOWS\system32\profsvc.dll
20:49:44.0261 1712 ProfSvc - ok
20:49:44.0308 1712 [ 8528BB05E4D4E25945F78B00B2555FB7 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
20:49:44.0323 1712 Psched - ok
20:49:44.0339 1712 [ 6DAD398D60B9F6BAF0D3C53184C3CA4D ] pwdrvio C:\windows\system32\pwdrvio.sys
20:49:44.0354 1712 pwdrvio - ok
20:49:44.0386 1712 [ FE194DD23B549C1C397EB1102EC84EDC ] pwdspio C:\windows\system32\pwdspio.sys
20:49:44.0386 1712 pwdspio - ok
20:49:44.0464 1712 [ AF90BB44C99D6820BE52C9BBAA523283 ] QWAVE C:\WINDOWS\system32\qwave.dll
20:49:44.0479 1712 QWAVE - ok
20:49:44.0511 1712 [ 3FB466684609A4329858CF2EBD62E0FD ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
20:49:44.0526 1712 QWAVEdrv - ok
20:49:44.0542 1712 [ 2C56F0EE27E4EF70CA4B4983D3638905 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:49:44.0558 1712 RasAcd - ok
20:49:44.0573 1712 [ 5F061AC45266841A2860C1858ED863B8 ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:49:44.0589 1712 RasAuto - ok
20:49:44.0604 1712 [ BF3B17016764F20F9D28CF1A8DC210C0 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:49:44.0620 1712 RasMan - ok
20:49:44.0636 1712 [ 5247F308C4103CDC4FE12AE1D235800A ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:49:44.0636 1712 RasPppoe - ok
20:49:44.0667 1712 [ B939A2A0F9D6C6C186721E268EB6FA93 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:49:44.0683 1712 rdbss - ok
20:49:44.0683 1712 [ 6B21EBF892CD8CACB71669B35AB5DE32 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
20:49:44.0698 1712 rdpbus - ok
20:49:44.0714 1712 [ 680C1DAE268B6FB67FA21B389A8B79EF ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
20:49:44.0729 1712 RDPDR - ok
20:49:44.0745 1712 [ 858776908AF838E3790F3261B799CDA6 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
20:49:44.0745 1712 RdpVideoMiniport - ok
20:49:44.0761 1712 [ 847C6A08912C3515807049C93E526D65 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
20:49:44.0761 1712 rdyboost - ok
20:49:44.0792 1712 [ 036746D54347FD2D0385668E2A4064E4 ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys
20:49:44.0823 1712 ReFS - ok
20:49:44.0854 1712 [ BFFB40FBE6D2C3469F8D06EE5E4934AB ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:49:44.0870 1712 RemoteAccess - ok
20:49:44.0901 1712 [ 4DCCABE03D06955ED61BABBD8EF9F30F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:49:44.0917 1712 RemoteRegistry - ok
20:49:44.0948 1712 [ 02307C86CB24769306B0DFA0C751952E ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys
20:49:44.0948 1712 RFCOMM - ok
20:49:44.0964 1712 [ D894CBD7DA753C881EE8D5E33B583225 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
20:49:44.0964 1712 RpcEptMapper - ok
20:49:45.0011 1712 [ 5CAE8F47B31D5CFC322B5B898C19E0FE ] RpcLocator C:\WINDOWS\system32\locator.exe
20:49:45.0011 1712 RpcLocator - ok
20:49:45.0089 1712 [ 675C575444AAFD56B4E8A99EF8A570CD ] rpcnet C:\Windows\SysWOW64\rpcnet.exe
20:49:45.0104 1712 rpcnet - ok
20:49:45.0198 1712 [ 3FD5AE42EC87C6F532A931F96BE731DD ] RpcSs C:\WINDOWS\system32\rpcss.dll
20:49:45.0198 1712 RpcSs - ok
20:49:45.0261 1712 [ 2D05A5508F4685412F2B89E8C2189ABC ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
20:49:45.0261 1712 rspndr - ok
20:49:45.0292 1712 [ 8EB6DCEB7473C232D8BC9A886E3183AC ] RSUSBVSTOR C:\WINDOWS\System32\Drivers\RtsUVStor.sys
20:49:45.0308 1712 RSUSBVSTOR - ok
20:49:45.0448 1712 [ 5B51809556BCAB9EAE08C0665D9A658C ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
20:49:45.0542 1712 rtsuvc - ok
20:49:45.0573 1712 [ 1A063730F221B2746FF00457AE17E4F0 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
20:49:45.0573 1712 s3cap - ok
20:49:45.0620 1712 [ F6F209DDB94959BA104FC8FC87C53759 ] SamSs C:\WINDOWS\system32\lsass.exe
20:49:45.0636 1712 SamSs - ok
20:49:45.0667 1712 [ C624A1B32211C3166EDB3F4AB02A30B7 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
20:49:45.0683 1712 sbp2port - ok
20:49:45.0698 1712 [ 47C497FA4DDEA908633CAA60CEBE6805 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
20:49:45.0714 1712 SCardSvr - ok
20:49:45.0714 1712 [ E76C4E98302AE39CC6FA5D20FC8B5438 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
20:49:45.0729 1712 ScDeviceEnum - ok
20:49:45.0745 1712 [ ABD0237B15DBD2B4695F4B7D734A58F7 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
20:49:45.0761 1712 scfilter - ok
20:49:45.0776 1712 [ 888A30EAB651502352C18745367FD179 ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:49:45.0808 1712 Schedule - ok
20:49:45.0839 1712 [ AB285CE3431FF3D2ACE669245874C1C7 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
20:49:45.0854 1712 SCPolicySvc - ok
20:49:45.0870 1712 [ 2F9A3380B8C0380E5608E29C7AA66899 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
20:49:45.0886 1712 sdbus - ok
20:49:45.0901 1712 [ 4EAF4DCF9DBD9A56952A58F56D61C005 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
20:49:45.0901 1712 sdstor - ok
20:49:45.0917 1712 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
20:49:45.0917 1712 secdrv - ok
20:49:45.0933 1712 [ C49009F897BA4F2F4F31043663AA1485 ] seclogon C:\WINDOWS\system32\seclogon.dll
20:49:45.0948 1712 seclogon - ok
20:49:45.0980 1712 [ A88882E64BDC1D8E8D6E727B71CCCC53 ] SENS C:\WINDOWS\System32\sens.dll
20:49:45.0995 1712 SENS - ok
20:49:46.0011 1712 [ E66A7C8CE7ED22DED6DF1CA479FB4790 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
20:49:46.0026 1712 SensrSvc - ok
20:49:46.0042 1712 [ DB2FF24CE0BDD15FE75870AFE312BA89 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
20:49:46.0042 1712 SerCx - ok
20:49:46.0089 1712 [ 0044B31F93946D5D41982314381FE431 ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
20:49:46.0089 1712 SerCx2 - ok
20:49:46.0120 1712 [ 3CD600C089C1251BEEB4CD4CD5164F9E ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
20:49:46.0120 1712 Serenum - ok
20:49:46.0136 1712 [ D864381BC9C725FAB01D94C060660166 ] Serial C:\WINDOWS\System32\drivers\serial.sys
20:49:46.0151 1712 Serial - ok
20:49:46.0167 1712 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
20:49:46.0183 1712 sermouse - ok
20:49:46.0198 1712 [ 441E6FF1F34D7A942946DB42A15FB519 ] SessionEnv C:\WINDOWS\system32\sessenv.dll
20:49:46.0214 1712 SessionEnv - ok
20:49:46.0230 1712 [ 472B7A5AC181C050888DB454663DD764 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
20:49:46.0245 1712 sfloppy - ok
20:49:46.0276 1712 [ F4414F57DF2CECB8FC969AA43A6B0D50 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:49:46.0292 1712 SharedAccess - ok
20:49:46.0308 1712 [ 0D190D8B4B20446BE6299AC734DFADF1 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:49:46.0339 1712 ShellHWDetection - ok
20:49:46.0370 1712 [ 2F518D13DD6F3053837FE606F1A2EA1F ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
20:49:46.0386 1712 SiSRaid2 - ok
20:49:46.0386 1712 [ 1AC9A200A9C49C4508F04AAFFCA34A3F ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
20:49:46.0386 1712 SiSRaid4 - ok
20:49:46.0495 1712 [ 9F712B26EE3B0242DE997A42FD302E2C ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
20:49:46.0542 1712 Skype C2C Service - ok
20:49:46.0636 1712 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:49:46.0636 1712 SkypeUpdate - ok
20:49:46.0667 1712 [ 587ACA15210D1B01FBF272E07A08F91A ] smphost C:\WINDOWS\System32\smphost.dll
20:49:46.0683 1712 smphost - ok
20:49:46.0714 1712 [ 49EEB92DE930B8566EF615D600781DB4 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
20:49:46.0730 1712 SNMPTRAP - ok
20:49:46.0776 1712 [ F6EBE514D13ECE7EDC23440039CDF9AB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
20:49:46.0792 1712 spaceport - ok
20:49:46.0808 1712 [ F337BE11071818FC3F5DC2940B6BDE34 ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
20:49:46.0808 1712 SpbCx - ok
20:49:46.0839 1712 [ FE0CB40F36D3FCDD3A1B312EF72C38D5 ] Spooler C:\WINDOWS\System32\spoolsv.exe
20:49:46.0855 1712 Spooler - ok
20:49:46.0948 1712 [ E6DEC72A2A23FAA53EB9FEC3C7E29D66 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
20:49:47.0058 1712 sppsvc - ok
20:49:47.0105 1712 [ 2B78788A1485F9B99A578A299DF42C02 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:49:47.0120 1712 srv - ok
20:49:47.0136 1712 [ C1AE59C0B0817236EC083A91C396005A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
20:49:47.0151 1712 srv2 - ok
20:49:47.0167 1712 [ 77195C32175FC63D6054EBA5A066D727 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
20:49:47.0183 1712 srvnet - ok
20:49:47.0214 1712 [ 52D6F40B50ECFC051979FEC68E74F0F8 ] ssadbus C:\WINDOWS\System32\drivers\ssadbus.sys
20:49:47.0214 1712 ssadbus - ok
20:49:47.0245 1712 [ D6CFD3B2EABCF9327DE39C62BABFA1E3 ] ssadmdfl C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys
20:49:47.0261 1712 ssadmdfl - ok
20:49:47.0292 1712 [ 5EB01E6148742C3EC2185AC92F6D16FD ] ssadmdm C:\WINDOWS\system32\DRIVERS\ssadmdm.sys
20:49:47.0292 1712 ssadmdm - ok
20:49:47.0323 1712 [ FF20F67DD5644BD1D2E7FCD95AF7F03B ] ssadserd C:\WINDOWS\system32\DRIVERS\ssadserd.sys
20:49:47.0323 1712 ssadserd - ok
20:49:47.0370 1712 [ BB9ED3EDD8E85008215A7250D325A72E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:49:47.0386 1712 SSDPSRV - ok
20:49:47.0417 1712 [ 3911418AFDE10EA6823B7799E4815524 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
20:49:47.0433 1712 SstpSvc - ok
20:49:47.0480 1712 [ A87A39F9B42D82F5D60D36BB1D3CC9D3 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
20:49:47.0495 1712 Steam Client Service - ok
20:49:47.0495 1712 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
20:49:47.0511 1712 stexstor - ok
20:49:47.0542 1712 [ D638904FE86A5FE542A1BA13A9D68E5C ] stisvc C:\WINDOWS\System32\wiaservc.dll
20:49:47.0558 1712 stisvc - ok
20:49:47.0589 1712 [ 0ED2E318ABB68C1A35A8B8038BDB4C90 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
20:49:47.0605 1712 storahci - ok
20:49:47.0620 1712 [ 7A08CEE1535F5A448215634C5EA74E50 ] storflt C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
20:49:47.0636 1712 storflt - ok
20:49:47.0667 1712 [ 6B06E2D11E604BE2B1A406C4CB3B90DE ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
20:49:47.0667 1712 stornvme - ok
20:49:47.0698 1712 [ 3118058E3D07021A55324A943C6D722B ] StorSvc C:\WINDOWS\system32\storsvc.dll
20:49:47.0698 1712 StorSvc - ok
20:49:47.0714 1712 [ 548759755BC73DAD663250239D7E0B9F ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
20:49:47.0730 1712 storvsc - ok
20:49:47.0730 1712 [ D8E1AE075AB3E8AD56F69C44AA978596 ] svsvc C:\WINDOWS\system32\svsvc.dll
20:49:47.0745 1712 svsvc - ok
20:49:47.0761 1712 [ 84E0F5D41C138C5CC975137A2A98F6D3 ] swenum C:\WINDOWS\System32\drivers\swenum.sys
20:49:47.0776 1712 swenum - ok
20:49:47.0808 1712 [ A5DC2E63F5E5D3C0B843307374998479 ] swprv C:\WINDOWS\System32\swprv.dll
20:49:47.0823 1712 swprv - ok
20:49:47.0870 1712 [ E45DA7CBBA34510C8B9473AD7D4FFD0B ] SysMain C:\WINDOWS\system32\sysmain.dll
20:49:47.0886 1712 SysMain - ok
20:49:47.0901 1712 [ 373382005ACB27CB16ED16722FBE946A ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
20:49:47.0917 1712 SystemEventsBroker - ok
20:49:47.0948 1712 [ BA6DD39266A5E15515C8C14DA2DA3E5C ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
20:49:47.0948 1712 TabletInputService - ok
20:49:47.0980 1712 [ F0B9D3ED88E56D3CD713DFF21E42AAF0 ] tap0901 C:\WINDOWS\system32\DRIVERS\tap0901.sys
20:49:47.0980 1712 tap0901 - ok
20:49:48.0011 1712 [ B517410F157693043DACA21B19B258A6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:49:48.0026 1712 TapiSrv - ok
20:49:48.0073 1712 [ 6617F44D2432C529B2249A0498B6B40A ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
20:49:48.0120 1712 Tcpip - ok
20:49:48.0151 1712 [ 6617F44D2432C529B2249A0498B6B40A ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:49:48.0198 1712 TCPIP6 - ok
20:49:48.0230 1712 [ 33A7D83EEB15431773A6E186CFAABA21 ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
20:49:48.0245 1712 tcpipreg - ok
20:49:48.0292 1712 [ FFF28F9F6823EB1756C60F1649560BBF ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
20:49:48.0308 1712 tdx - ok
20:49:48.0323 1712 [ 232D185D2337F141311D0CF1983E1431 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
20:49:48.0323 1712 terminpt - ok
20:49:48.0370 1712 [ 2C77831737491F4D684D315B95C62883 ] TermService C:\WINDOWS\System32\termsrv.dll
20:49:48.0386 1712 TermService - ok
20:49:48.0417 1712 [ 05FBE1F7C13E87AF7A414CDF288B1F62 ] Themes C:\WINDOWS\system32\themeservice.dll
20:49:48.0433 1712 Themes - ok
20:49:48.0464 1712 [ FD788C2D96EA91469A3C1D13E80D7473 ] THREADORDER C:\WINDOWS\system32\mmcss.dll
20:49:48.0480 1712 THREADORDER - ok
20:49:48.0495 1712 [ 347A3E49CE18402305B8119A6EC7CFEB ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
20:49:48.0511 1712 TimeBroker - ok
20:49:48.0527 1712 [ 82F909359600D3603FE852DB7F135626 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
20:49:48.0527 1712 TPM - ok
20:49:48.0573 1712 [ C97E14BB6A196B0554D6EB67D8818175 ] TrkWks C:\WINDOWS\System32\trkwks.dll
20:49:48.0589 1712 TrkWks - ok
20:49:48.0652 1712 [ DA56FFA46030E6FEB215E3D5DAA65B11 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
20:49:48.0652 1712 TrustedInstaller - ok
20:49:48.0667 1712 [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
20:49:48.0683 1712 TsUsbFlt - ok
20:49:48.0698 1712 [ E0088068DCE2EE82897027DDB8E05254 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
20:49:48.0698 1712 TsUsbGD - ok
20:49:48.0730 1712 [ C8E0E78B5D284C2FF59BDFFDAF997242 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
20:49:48.0730 1712 tunnel - ok
20:49:48.0745 1712 [ F6EEAD052943B5A3104C1405BB856C54 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
20:49:48.0761 1712 uagp35 - ok
20:49:48.0777 1712 [ FE6067B1FD4E63650C667B33D080565B ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
20:49:48.0777 1712 UASPStor - ok
20:49:48.0808 1712 [ 5D1B430EA11064C56E7C8F84B90DEB6A ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
20:49:48.0808 1712 UCX01000 - ok
20:49:48.0839 1712 [ 1EC649F112896FAE33250F0B97AC5D0B ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
20:49:48.0855 1712 udfs - ok
20:49:48.0870 1712 [ 9578691F297E1B1F519970FE6D47CB21 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
20:49:48.0870 1712 UEFI - ok
20:49:48.0917 1712 [ 320878AFECDBBD61BBE98624A6CAAC08 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
20:49:48.0933 1712 UI0Detect - ok
20:49:48.0964 1712 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
20:49:48.0980 1712 uliagpkx - ok
20:49:48.0995 1712 [ DA34C39A18E60E7C3FA0630566408034 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
20:49:49.0011 1712 umbus - ok
20:49:49.0027 1712 [ AE8294875E5446E359B1E8035D40C05E ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
20:49:49.0027 1712 UmPass - ok
20:49:49.0073 1712 [ E3DDF7D43E05784FAA5E042605EEE528 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
20:49:49.0073 1712 UmRdpService - ok
20:49:49.0167 1712 [ E1A119AD21F5AFE22EB516C549306D3D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
20:49:49.0183 1712 UNS - ok
20:49:49.0198 1712 [ 4A2FFDAC45F317E17DF642C7160EB633 ] upnphost C:\WINDOWS\System32\upnphost.dll
20:49:49.0214 1712 upnphost - ok
20:49:49.0261 1712 [ 433ECDE01A52691FA7ACA51C10C09B70 ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
20:49:49.0277 1712 usbccgp - ok
20:49:49.0292 1712 [ B3D6457D841A0CAEF4C52D88621715F2 ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
20:49:49.0308 1712 usbcir - ok
20:49:49.0308 1712 [ 5477D6E27C7D266EF8C152B9A25ADE5E ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
20:49:49.0323 1712 usbehci - ok
20:49:49.0339 1712 [ DF56C2C04EFA328D7A66B69007130266 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
20:49:49.0355 1712 usbhub - ok
20:49:49.0386 1712 [ C0E33820326199CE3CFD3B9F27F81D99 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
20:49:49.0402 1712 USBHUB3 - ok
20:49:49.0417 1712 [ 3019097FB6C985EF24C058090FF3BDBD ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
20:49:49.0417 1712 usbohci - ok
20:49:49.0433 1712 [ 4D655E3B684BE9B0F7FFD8A2935C348C ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
20:49:49.0433 1712 usbprint - ok
20:49:49.0448 1712 [ B1230E9813B5C7E762DF27756AA23917 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
20:49:49.0464 1712 USBSTOR - ok
20:49:49.0480 1712 [ BA4FA655E0FC577DB7436FC963932CE4 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
20:49:49.0480 1712 usbuhci - ok
20:49:49.0511 1712 [ 3B44CB989757428208CCFCC028C13110 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
20:49:49.0527 1712 USBXHCI - ok
20:49:49.0542 1712 [ 3CAAB947B1F247A570DE15983BEDEBCF ] usb_rndisx C:\WINDOWS\system32\DRIVERS\usb8023x.sys
20:49:49.0542 1712 usb_rndisx - ok
20:49:49.0558 1712 [ F6F209DDB94959BA104FC8FC87C53759 ] VaultSvc C:\WINDOWS\system32\lsass.exe
20:49:49.0573 1712 VaultSvc - ok
20:49:49.0573 1712 [ FEB26E3B8345A7E8D62F945C4AE86562 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
20:49:49.0589 1712 vdrvroot - ok
20:49:49.0636 1712 [ CFBAD6B48EDFAA0828A52646B7C4C08D ] vds C:\WINDOWS\System32\vds.exe
20:49:49.0652 1712 vds - ok
20:49:49.0698 1712 [ A026EDEAA5EECAE0B08E2748B616D4BD ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
20:49:49.0698 1712 VerifierExt - ok
20:49:49.0714 1712 [ 041D3EF364E624DBB2703A64A5AADF89 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
20:49:49.0745 1712 vhdmp - ok
20:49:49.0761 1712 [ 06D38968028E9AB19DE9B618C7B6D199 ] viaide C:\WINDOWS\system32\drivers\viaide.sys
20:49:49.0761 1712 viaide - ok
20:49:49.0792 1712 [ C6305BDFC4F7CE51F72BB072C03D4ACE ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
20:49:49.0792 1712 vmbus - ok
20:49:49.0808 1712 [ DA40BEA0A863CE768C940CA9723BF81F ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
20:49:49.0823 1712 VMBusHID - ok
20:49:49.0855 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
20:49:49.0870 1712 vmicguestinterface - ok
20:49:49.0886 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll
20:49:49.0886 1712 vmicheartbeat - ok
20:49:49.0902 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
20:49:49.0902 1712 vmickvpexchange - ok
20:49:49.0917 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicrdv C:\WINDOWS\System32\ICSvc.dll
20:49:49.0917 1712 vmicrdv - ok
20:49:49.0933 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll
20:49:49.0948 1712 vmicshutdown - ok
20:49:49.0948 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmictimesync C:\WINDOWS\System32\ICSvc.dll
20:49:49.0964 1712 vmictimesync - ok
20:49:49.0964 1712 [ 9067880BBB1C18703DBFF27D731D7ECA ] vmicvss C:\WINDOWS\System32\ICSvc.dll
20:49:49.0980 1712 vmicvss - ok
20:49:49.0995 1712 [ 55D7D963DE85162F1C49721E502F9744 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
20:49:50.0011 1712 volmgr - ok
20:49:50.0027 1712 [ CCB9E901F7254BF96D28EB1B0E5329B7 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
20:49:50.0027 1712 volmgrx - ok
20:49:50.0042 1712 [ 9F9CE33B50611A1C61A46B8911E0B30B ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
20:49:50.0058 1712 volsnap - ok
20:49:50.0073 1712 [ 01355C98B5C3ED1EC446743CDA848FCE ] vpci C:\WINDOWS\System32\drivers\vpci.sys
20:49:50.0073 1712 vpci - ok
20:49:50.0105 1712 [ 4539F45F9F4C9757A86A56C949421E07 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
20:49:50.0105 1712 vsmraid - ok
20:49:50.0136 1712 [ D51D7EF1EA5ED2BB01E9D07E6E0533BC ] VSS C:\WINDOWS\system32\vssvc.exe
20:49:50.0167 1712 VSS - ok
20:49:50.0183 1712 [ 0849B7260F26FE05EA56DED0672E2F4B ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
20:49:50.0198 1712 VSTXRAID - ok
20:49:50.0214 1712 [ BE970C369E43B509C1EDA2B8FA7CECB0 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
20:49:50.0230 1712 vwifibus - ok
20:49:50.0230 1712 [ 6B26AD573CCDD5209DF4397438B76354 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys
20:49:50.0245 1712 vwififlt - ok
20:49:50.0261 1712 [ 0B48E0DFB44EE475F4FD8A8EE599AF30 ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys
20:49:50.0261 1712 vwifimp - ok
20:49:50.0308 1712 [ 7599E582CA3A6AAA95A18FFE1172D339 ] W32Time C:\WINDOWS\system32\w32time.dll
20:49:50.0323 1712 W32Time - ok
20:49:50.0355 1712 [ 0910AB9ED404C1434E2D0376C2AD5D8B ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
20:49:50.0370 1712 WacomPen - ok
20:49:50.0402 1712 [ 92BF4B3EBD6F163B94B7A20C65E7B698 ] wbengine C:\WINDOWS\system32\wbengine.exe
20:49:50.0417 1712 wbengine - ok
20:49:50.0464 1712 [ 58F28103889817C93E5B5AFABC87E709 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
20:49:50.0480 1712 WbioSrvc - ok
20:49:50.0495 1712 [ 772365894F14652D376B2E5030179DC9 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
20:49:50.0511 1712 Wcmsvc - ok
20:49:50.0527 1712 [ D2726823DF7E19F213F4805A9D6D145F ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
20:49:50.0542 1712 wcncsvc - ok
20:49:50.0558 1712 [ 846C02A8B48CBD921A3D6AB521AA0DC4 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
20:49:50.0558 1712 WcsPlugInService - ok
20:49:50.0573 1712 [ 694B28DE12AD47031FFB4B052662131A ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
20:49:50.0589 1712 WdBoot - ok
20:49:50.0605 1712 [ CB6C63FF8342B467E2EF76E98D5B934D ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
20:49:50.0620 1712 Wdf01000 - ok
20:49:50.0652 1712 [ 0B99529A3BECC3528D865DDECB62503B ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
20:49:50.0652 1712 WdFilter - ok
20:49:50.0667 1712 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
20:49:50.0683 1712 WdiServiceHost - ok
20:49:50.0698 1712 [ 40C67D1A4891120874767F6E6604D6C5 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
20:49:50.0698 1712 WdiSystemHost - ok
20:49:50.0730 1712 [ 282E7D46310338FF4A6B7680440EB0DA ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
20:49:50.0730 1712 WdNisDrv - ok
20:49:50.0777 1712 WdNisSvc - ok
20:49:50.0792 1712 [ 6588A957873326361AB1CAC4E76F8394 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:49:50.0808 1712 WebClient - ok
20:49:50.0823 1712 [ 3274312F263882B51B964329FAF49734 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
20:49:50.0823 1712 Wecsvc - ok
20:49:50.0855 1712 [ 7CDD84E0023A0C5C230B06A7965EC65E ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
20:49:50.0855 1712 WEPHOSTSVC - ok
20:49:50.0870 1712 [ AA1315B87D9B2E39584165318A59F15D ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
20:49:50.0886 1712 wercplsupport - ok
20:49:50.0902 1712 [ 22B4C24AB921BFF7827FFBCA1F4E1BB3 ] WerSvc C:\WINDOWS\System32\WerSvc.dll
20:49:50.0917 1712 WerSvc - ok
20:49:50.0933 1712 [ 2E3E82D7B1076B90F4E228A8EF17B261 ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
20:49:50.0933 1712 WFPLWFS - ok
20:49:50.0964 1712 [ E06AFE2F94BA7CFA2FE4FD2A449E60E2 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
20:49:50.0964 1712 WiaRpc - ok
20:49:51.0011 1712 [ 867BCC69ED9C31C501465EB0E8BA9DFA ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
20:49:51.0011 1712 WIMMount - ok
20:49:51.0011 1712 WinDefend - ok
20:49:51.0058 1712 [ DD079EC8F44DCA3A176B345C6ADEFB66 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
20:49:51.0073 1712 WinHttpAutoProxySvc - ok
20:49:51.0136 1712 [ 9DB490F3E823C5C3C070644B96CB9D59 ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:49:51.0136 1712 Winmgmt - ok
20:49:51.0214 1712 [ 690C3FC5C9DBD6B9AEDF8341EC720E41 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
20:49:51.0245 1712 WinRM - ok
20:49:51.0292 1712 [ 9378B4E7E4E3EAE2F05823CFFF2C6EF4 ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
20:49:51.0308 1712 WlanSvc - ok
20:49:51.0370 1712 [ C2838466CCC44FAEF2C3D4C1E5971ECB ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
20:49:51.0386 1712 wlidsvc - ok
20:49:51.0417 1712 [ 2834D9D3B4F554A39C72F00EA3F0E128 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
20:49:51.0433 1712 WmiAcpi - ok
20:49:51.0464 1712 [ 7AFAC828F52D62F304A911EC32F42EEE ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
20:49:51.0480 1712 wmiApSrv - ok
20:49:51.0511 1712 WMPNetworkSvc - ok
20:49:51.0574 1712 [ E178371E493BF17EB90FE71ABA8BE643 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
20:49:51.0589 1712 workfolderssvc - ok
20:49:51.0620 1712 [ E746BCDBA2E02CF6B8D6B26FB167FBE0 ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
20:49:51.0620 1712 wpcfltr - ok
20:49:51.0636 1712 [ 4E6A0F60DA7EF050D3D26417CD4D24E9 ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll
20:49:51.0636 1712 WPCSvc - ok
20:49:51.0652 1712 [ D27491CFCE452C154CECFA155AD0EBC8 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
20:49:51.0667 1712 WPDBusEnum - ok
20:49:51.0683 1712 [ 9F2904B55F6CECCD1A8D986B5CE2609A ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
20:49:51.0683 1712 WpdUpFltr - ok
20:49:51.0699 1712 [ AE072B0339D0A18E455DC21666CAD572 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
20:49:51.0714 1712 ws2ifsl - ok
20:49:51.0730 1712 [ 5CFA46C4ACB2FD70572017052378DAE5 ] wscsvc C:\WINDOWS\System32\wscsvc.dll
20:49:51.0730 1712 wscsvc - ok
20:49:51.0745 1712 WSearch - ok
20:49:51.0808 1712 [ 3671C668670626DAB0D47B44F65F0489 ] WSService C:\WINDOWS\System32\WSService.dll
20:49:51.0886 1712 WSService - ok
20:49:51.0902 1712 [ 72B4E9DF6456C43C42A1419B09486045 ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
20:49:51.0917 1712 wsvd - ok
20:49:51.0980 1712 [ 86D0BF4F792053A50D6EE43DFA5837A5 ] wuauserv C:\WINDOWS\system32\wuaueng.dll
20:49:52.0011 1712 wuauserv - ok
20:49:52.0058 1712 [ 2FEAE33E9B2B56104596E1BA444405A9 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
20:49:52.0058 1712 WudfPf - ok
20:49:52.0074 1712 [ 19240C13F526125554B5370566F21A0A ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
20:49:52.0074 1712 WUDFRd - ok
20:49:52.0089 1712 [ 19240C13F526125554B5370566F21A0A ] WUDFSensorLP C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
20:49:52.0089 1712 WUDFSensorLP - ok
20:49:52.0105 1712 [ BB73CBC65AABC4EA0A5C6A1474A0A743 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
20:49:52.0120 1712 wudfsvc - ok
20:49:52.0120 1712 [ 19240C13F526125554B5370566F21A0A ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
20:49:52.0136 1712 WUDFWpdFs - ok
20:49:52.0183 1712 [ 2FA9794CA36147756F3FDFD6CA29B46F ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
20:49:52.0199 1712 WwanSvc - ok
20:49:52.0230 1712 [ 18D476A18E4DCC9B5823EBF6DAD96C58 ] xusb22 C:\WINDOWS\System32\drivers\xusb22.sys
20:49:52.0230 1712 xusb22 - ok
20:49:52.0245 1712 ================ Scan global ===============================
20:49:52.0292 1712 [ C89780A6F58D113C28A96D85D1261DC5 ] C:\WINDOWS\system32\basesrv.dll
20:49:52.0324 1712 [ 599F1244C60E3D6C28A8DA7FBA7A2C13 ] C:\WINDOWS\system32\winsrv.dll
20:49:52.0339 1712 [ 9C1833ABD62876856836C5AE55C7CE86 ] C:\WINDOWS\system32\sxssrv.dll
20:49:52.0386 1712 [ B4B610BBCB002EC478C6FD80CF915697 ] C:\WINDOWS\system32\services.exe
20:49:52.0402 1712 [Global] - ok
20:49:52.0402 1712 ================ Scan MBR ==================================
20:49:52.0402 1712 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
20:49:52.0480 1712 \Device\Harddisk0\DR0 - ok
20:49:52.0480 1712 ================ Scan VBR ==================================
20:49:52.0511 1712 [ 9B77FB09307F05060E651E793C4FCD6A ] \Device\Harddisk0\DR0\Partition1
20:49:52.0511 1712 \Device\Harddisk0\DR0\Partition1 - ok
20:49:52.0527 1712 [ E39913353736776A48609CE9AD6FF7E2 ] \Device\Harddisk0\DR0\Partition2
20:49:52.0527 1712 \Device\Harddisk0\DR0\Partition2 - ok
20:49:52.0542 1712 [ 108E2D0C907544B39A8BF6B6CDCF9D7D ] \Device\Harddisk0\DR0\Partition3
20:49:52.0542 1712 \Device\Harddisk0\DR0\Partition3 - ok
20:49:52.0558 1712 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition4
20:49:52.0558 1712 \Device\Harddisk0\DR0\Partition4 - ok
20:49:52.0636 1712 [ 42710B902894B32D1C9A9C44B0ECAF8F ] \Device\Harddisk0\DR0\Partition5
20:49:52.0636 1712 \Device\Harddisk0\DR0\Partition5 - ok
20:49:52.0667 1712 [ BA0DFBA163425753A5D7C8F389F5C204 ] \Device\Harddisk0\DR0\Partition6
20:49:52.0667 1712 \Device\Harddisk0\DR0\Partition6 - ok
20:49:52.0683 1712 [ B4C0208A58CDC748FAF650D6439A3A2E ] \Device\Harddisk0\DR0\Partition7
20:49:52.0683 1712 \Device\Harddisk0\DR0\Partition7 - ok
20:49:52.0683 1712 [ F4434E1267D228386BA55BEAD97D476F ] \Device\Harddisk0\DR0\Partition8
20:49:52.0699 1712 \Device\Harddisk0\DR0\Partition8 - ok
20:49:52.0699 1712 ============================================================
20:49:52.0699 1712 Scan finished
20:49:52.0699 1712 ============================================================
20:49:52.0699 1704 Detected object count: 0
20:49:52.0699 1704 Actual detected object count: 0
20:52:14.0565 1688 Deinitialize success

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#11 Příspěvek od h4pple »

spravil som screen posielam ho v raru :)
Přílohy
screen.rar
(42.03 KiB) Staženo 44 x

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#12 Příspěvek od h4pple »

urobil som obnovu systemu a vyzera ze to ide v pohode, aspon tak sa tvari :)
EDIT: este dodam ze na ploche sa mi objavil priecinok s nazvom RK_Quarantine a v nom subor PhysicalDrive0_User.dat

h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

Re: Virus, nejaky malware, strata admin. prav

#13 Příspěvek od h4pple »

hej hej, myslel som ze to nieje dolezite, nabuduce popisem presnejsie, teda dufam ze nabuduce uz nebude :D tak diky, snad to uz pojde bez problemov :)

Zamčeno