UKASH logi proszę o pomoc

Wszystko co dotyczy bezpieczeństwa systemów oraz walki z malware, w szczególności analiza logów
obojętne

Użytkownik
Posty: 2
Rejestracja: 05 wrz 2012, 17:55

UKASH logi proszę o pomoc

Post05 wrz 2012, 18:09


Awatar użytkownika
kominekl

Ekspert
Posty: 5855
Rejestracja: 27 lis 2011, 14:25
Kontaktowanie:

UKASH logi proszę o pomoc

Post05 wrz 2012, 20:26

"AOL Toolbar" = Pasek narzędzi AOL 5.0
"incredibar" = Incredibar Toolbar on IE
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"{FB697452-8CA4-46B4-98B1-165C922A2EF3}" = Update Manager for SweetPacks 1.0


Odinstaluj to oprogramowanie, oraz inne zbędne ci.

Combofix.


Wejdź w START -> URUCHom -> i wklej tam -> "C:\Users\Ania\Desktop\ComboFix.exe" /uninstall .

Logi.


Uruchom OTL -> w oknie Własne opcje skanowania/skrypt wklej:

:OTL

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ania\AppData\Local\Temp\catchme.sys -- (catchme)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Dostępne tylko dla zarejestrowanych użytkowników
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&loc=IB_DS&a=6R8sMfRxTz&i=26
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = Dostępne tylko dla zarejestrowanych użytkowników{searchTerms}&invocationType=tb50winampie7
IE - HKU\S-1-5-21-2768689247-1661368180-885769354-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ania\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ania\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
CHR - Extension: Web Assistant = C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Skype Click to Call = C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Web Assistant = C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Skype Click to Call = C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll (Symantec Corporation)
O4 - HKU\S-1-5-21-2768689247-1661368180-885769354-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-2768689247-1661368180-885769354-1000..\Run: [TsUsbRedirectionGroupPolicyExtension] C:\Users\Ania\AppData\Local\Microsoft\Windows\2351\TsUsbRedirectionGroupPolicyExtension.exe ()
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} Dostępne tylko dla zarejestrowanych użytkowników (Bitdefender QuickScan Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} Dostępne tylko dla zarejestrowanych użytkowników (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Dostępne tylko dla zarejestrowanych użytkowników (Java Plug-in 10.6.2)

:Files
C:\Program Files\Google\Update
C:\Users\Ania\AppData\Local\Google\Update
$RECYCLE.BIN /alldrives
C:\Windows\temp
C:\ComboFix
C:\Qoobox
C:\Users\Ania\AppData\Local\Temp
C:\Windows\erdnt
C:\Users\Ania\AppData\Roaming\hellomoto
C:\Windows\tasks\*.*
C:\Users\Ania\Desktop\ComboFix(15526).exe
C:\Users\Ania\Desktop\ComboFix - Shortcut.lnk
C:\Users\Ania\AppData\Roaming\EurekaLog
C:\Users\Ania\AppData\Local\Microsoft\Windows\2351
C:\Program Files\SweetIM

:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

:Commands
[emptyflash]
[clearallrestorepoints]
[emptytemp]


Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podaj log z ADWCleaner (z opcji Delete) -> Dostępne tylko dla zarejestrowanych użytkowników + log z TDSSKiller -> http://www.hotfix.pl/instrukcja-obslugi ... r-a341.htm + nowe logi z OTL + log z Autoruns -> http://www.hotfix.pl/optymalizacja-auto ... s-a128.htm.
Kiedy komputery staną się twoim jedynym życiem, jedynym totemem odstraszającym klątwę nudy, wtedy prędzej czy później granica między tymi dwoma wymiarami zniknie i postacie z Błękitnej Pustki zaczną pojawiać się w Realu. Czasem są twoimi przyjaciółmi. A czasem nie.

obojętne

Użytkownik
Posty: 2
Rejestracja: 05 wrz 2012, 17:55

UKASH logi proszę o pomoc

Post05 wrz 2012, 21:55

TDSSKiller

21:47:12.0559 4704 TDSS rootkit removing tool 2.7.22.0 Mar 21 2012 17:40:00
21:47:14.0563 4704 ============================================================
21:47:14.0563 4704 Current date / time: 2012/09/05 21:47:14.0563
21:47:14.0563 4704 SystemInfo:
21:47:14.0563 4704
21:47:14.0563 4704 OS Version: 6.0.6002 ServicePack: 2.0
21:47:14.0563 4704 Product type: Workstation
21:47:14.0563 4704 ComputerName: ANIA-PC
21:47:14.0564 4704 UserName: Ania
21:47:14.0564 4704 Windows directory: C:\Windows
21:47:14.0564 4704 System windows directory: C:\Windows
21:47:14.0564 4704 Processor architecture: Intel x86
21:47:14.0564 4704 Number of processors: 2
21:47:14.0564 4704 Page size: 0x1000
21:47:14.0564 4704 Boot type: Normal boot
21:47:14.0564 4704 ============================================================
21:47:16.0103 4704 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
21:47:16.0104 4704 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
21:47:16.0109 4704 Drive \Device\Harddisk2\DR2 - Size: 0x1E2A00000 (7.54 Gb), SectorSize: 0x200, Cylinders: 0x3D8, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:47:16.0111 4704 \Device\Harddisk0\DR0:
21:47:16.0112 4704 MBR used
21:47:16.0112 4704 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1C1A27C1
21:47:16.0112 4704 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1C1A2800, BlocksNum 0x1021800
21:47:16.0112 4704 \Device\Harddisk1\DR1:
21:47:16.0112 4704 MBR used
21:47:16.0112 4704 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D1C4542
21:47:16.0112 4704 \Device\Harddisk2\DR2:
21:47:16.0114 4704 MBR used
21:47:16.0114 4704 \Device\Harddisk2\DR2\Partition0: MBR, Type 0xC, StartLBA 0x17B8, BlocksNum 0xF13848
21:47:16.0591 4704 Initialize success
21:47:16.0591 4704 ============================================================
21:47:18.0594 4584 ============================================================
21:47:18.0594 4584 Scan started
21:47:18.0594 4584 Mode: Manual;
21:47:18.0594 4584 ============================================================
21:47:20.0311 4584 Accelerometer (3b10711ad8656c097e0d16a41b29c54c) C:\Windows\system32\DRIVERS\Accelerometer.sys
21:47:20.0322 4584 Accelerometer - ok
21:47:20.0455 4584 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
21:47:20.0461 4584 ACPI - ok
21:47:20.0619 4584 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys
21:47:20.0621 4584 adfs - ok
21:47:20.0709 4584 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
21:47:20.0732 4584 adp94xx - ok
21:47:20.0871 4584 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
21:47:20.0892 4584 adpahci - ok
21:47:20.0939 4584 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
21:47:20.0952 4584 adpu160m - ok
21:47:20.0967 4584 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
21:47:20.0982 4584 adpu320 - ok
21:47:21.0027 4584 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
21:47:21.0029 4584 AeLookupSvc - ok
21:47:21.0174 4584 AESTFilters (ef1142512bec12f1c2c87735da1755be) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\aestsrv.exe
21:47:21.0177 4584 AESTFilters - ok
21:47:21.0322 4584 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
21:47:21.0332 4584 AFD - ok
21:47:21.0474 4584 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
21:47:21.0497 4584 agp440 - ok
21:47:21.0648 4584 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
21:47:21.0696 4584 aic78xx - ok
21:47:21.0756 4584 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
21:47:21.0761 4584 ALG - ok
21:47:21.0888 4584 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
21:47:21.0909 4584 aliide - ok
21:47:22.0047 4584 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
21:47:22.0067 4584 amdagp - ok
21:47:22.0111 4584 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
21:47:22.0126 4584 amdide - ok
21:47:22.0256 4584 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
21:47:22.0273 4584 AmdK7 - ok
21:47:22.0299 4584 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
21:47:22.0313 4584 AmdK8 - ok
21:47:22.0506 4584 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
21:47:22.0510 4584 Appinfo - ok
21:47:22.0739 4584 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
21:47:22.0786 4584 arc - ok
21:47:22.0862 4584 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
21:47:22.0875 4584 arcsas - ok
21:47:23.0003 4584 aspnet_state (776acefa0ca9df0faa51a5fb2f435705) C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
21:47:23.0090 4584 aspnet_state - ok
21:47:23.0215 4584 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
21:47:23.0234 4584 AsyncMac - ok
21:47:23.0375 4584 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
21:47:23.0376 4584 atapi - ok
21:47:23.0575 4584 athr (600efe56f37adbd65a0fb076b50d1b8d) C:\Windows\system32\DRIVERS\athr.sys
21:47:23.0633 4584 athr - ok
21:47:23.0820 4584 athur (50edc3bc29ffe35a3604e0cf041fdf24) C:\Windows\system32\DRIVERS\athur.sys
21:47:23.0860 4584 athur - ok
21:47:23.0991 4584 Ati External Event Utility (2580ac48801134b6eedd6ee6aea96c95) C:\Windows\system32\Ati2evxx.exe
21:47:24.0008 4584 Ati External Event Utility - ok
21:47:24.0283 4584 atikmdag (5e4232783f05ebae72d22a91907a76f4) C:\Windows\system32\DRIVERS\atikmdag.sys
21:47:24.0520 4584 atikmdag - ok
21:47:24.0675 4584 AtiPcie (5a1465ad2e7c1bc39cda12a355329096) C:\Windows\system32\DRIVERS\AtiPcie.sys
21:47:24.0686 4584 AtiPcie - ok
21:47:24.0802 4584 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
21:47:24.0811 4584 AudioEndpointBuilder - ok
21:47:24.0828 4584 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
21:47:24.0831 4584 Audiosrv - ok
21:47:24.0937 4584 Autodesk Content Service (1992c2a1867d95aa3a0802539358d162) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
21:47:24.0938 4584 Autodesk Content Service - ok
21:47:25.0053 4584 Autodesk Licensing Service (ead65493edba0ebea2192d46b938298e) C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
21:47:25.0056 4584 Autodesk Licensing Service - ok
21:47:25.0221 4584 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
21:47:25.0262 4584 BCM43XV - ok
21:47:25.0398 4584 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
21:47:25.0403 4584 Beep - ok
21:47:25.0561 4584 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
21:47:25.0579 4584 BFE - ok
21:47:25.0736 4584 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\system32\qmgr.dll
21:47:25.0776 4584 BITS - ok
21:47:25.0906 4584 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
21:47:25.0948 4584 blbdrive - ok
21:47:26.0000 4584 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
21:47:26.0005 4584 bowser - ok
21:47:26.0149 4584 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
21:47:26.0204 4584 BrFiltLo - ok
21:47:26.0263 4584 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
21:47:26.0279 4584 BrFiltUp - ok
21:47:26.0364 4584 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
21:47:26.0368 4584 Browser - ok
21:47:26.0462 4584 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
21:47:26.0476 4584 Brserid - ok
21:47:26.0578 4584 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
21:47:26.0590 4584 BrSerWdm - ok
21:47:26.0648 4584 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
21:47:26.0677 4584 BrUsbMdm - ok
21:47:26.0788 4584 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
21:47:26.0823 4584 BrUsbSer - ok
21:47:26.0984 4584 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys
21:47:26.0996 4584 BthEnum - ok
21:47:27.0064 4584 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
21:47:27.0085 4584 BTHMODEM - ok
21:47:27.0318 4584 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
21:47:27.0331 4584 BthPan - ok
21:47:27.0583 4584 BTHPORT (611ff3f2f095c8d4a6d4cfd9dcc09793) C:\Windows\system32\Drivers\BTHport.sys
21:47:27.0615 4584 BTHPORT - ok
21:47:27.0733 4584 BthServ (a4c8377fa4a994e07075107dbe2e3dce) C:\Windows\System32\bthserv.dll
21:47:27.0748 4584 BthServ - ok
21:47:27.0851 4584 BTHUSB (d330803eab2a15caec7f011f1d4cb30e) C:\Windows\system32\Drivers\BTHUSB.sys
21:47:27.0874 4584 BTHUSB - ok
21:47:27.0990 4584 ccEvtMgr (5a6fd8778a42fd0bdc6f6ed9a181669b) c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
21:47:27.0994 4584 ccEvtMgr - ok
21:47:28.0032 4584 ccSetMgr (5a6fd8778a42fd0bdc6f6ed9a181669b) c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
21:47:28.0036 4584 ccSetMgr - ok
21:47:28.0191 4584 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
21:47:28.0192 4584 cdfs - ok
21:47:28.0349 4584 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
21:47:28.0428 4584 cdrom - ok
21:47:28.0663 4584 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
21:47:28.0665 4584 CertPropSvc - ok
21:47:28.0859 4584 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
21:47:28.0878 4584 circlass - ok
21:47:28.0958 4584 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
21:47:28.0966 4584 CLFS - ok
21:47:29.0034 4584 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:47:29.0120 4584 clr_optimization_v2.0.50727_32 - ok
21:47:29.0168 4584 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:47:29.0173 4584 clr_optimization_v4.0.30319_32 - ok
21:47:29.0278 4584 CLTNetCnService (5a6fd8778a42fd0bdc6f6ed9a181669b) c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
21:47:29.0282 4584 CLTNetCnService - ok
21:47:29.0541 4584 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
21:47:29.0563 4584 CmBatt - ok
21:47:29.0764 4584 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
21:47:29.0792 4584 cmdide - ok
21:47:30.0043 4584 COH_Mon (6186b6b953bdc884f0f379b84b3e3a98) C:\Windows\system32\Drivers\COH_Mon.sys
21:47:30.0092 4584 COH_Mon - ok
21:47:30.0245 4584 Com4QLBEx (7795f8cebc284a426b53f541e538695f) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
21:47:30.0464 4584 Com4QLBEx - ok
21:47:30.0683 4584 comHost (75a69ca9998577f8b2be8695040e5df4) c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
21:47:30.0713 4584 comHost - ok
21:47:30.0875 4584 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
21:47:30.0891 4584 Compbatt - ok
21:47:30.0997 4584 COMSysApp - ok
21:47:31.0088 4584 CO_Mon (73f5d6835bfa66019c03e316d99649da) C:\Windows\system32\drivers\CO_Mon.sys
21:47:31.0100 4584 CO_Mon - ok
21:47:31.0338 4584 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
21:47:31.0389 4584 crcdisk - ok
21:47:31.0584 4584 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
21:47:31.0604 4584 Crusoe - ok
21:47:31.0804 4584 CryptSvc (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll
21:47:31.0814 4584 CryptSvc - ok
21:47:32.0023 4584 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
21:47:32.0057 4584 DcomLaunch - ok
21:47:32.0200 4584 DCService.exe (cc8b5c964b777f4ec3e89f13b4b5ff0f) C:\ProgramData\DatacardService\DCService.exe
21:47:32.0208 4584 DCService.exe - ok
21:47:32.0361 4584 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
21:47:32.0373 4584 DfsC - ok
21:47:32.0675 4584 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
21:47:32.0893 4584 DFSR - ok
21:47:33.0127 4584 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
21:47:33.0137 4584 Dhcp - ok
21:47:33.0307 4584 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
21:47:33.0321 4584 disk - ok
21:47:33.0514 4584 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
21:47:33.0521 4584 Dnscache - ok
21:47:33.0631 4584 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
21:47:33.0641 4584 dot3svc - ok
21:47:34.0034 4584 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
21:47:34.0101 4584 Dot4 - ok
21:47:34.0511 4584 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
21:47:34.0547 4584 Dot4Print - ok
21:47:34.0929 4584 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
21:47:34.0987 4584 dot4usb - ok
21:47:35.0253 4584 DpHost (db162274197796ac5b3d54da7eca1909) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
21:47:35.0342 4584 DpHost - ok
21:47:35.0705 4584 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
21:47:35.0717 4584 DPS - ok
21:47:35.0954 4584 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
21:47:35.0996 4584 drmkaud - ok
21:47:36.0207 4584 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
21:47:36.0221 4584 DXGKrnl - ok
21:47:36.0422 4584 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
21:47:36.0447 4584 E1G60 - ok
21:47:36.0579 4584 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
21:47:36.0584 4584 EapHost - ok
21:47:36.0690 4584 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
21:47:36.0705 4584 Ecache - ok
21:47:36.0868 4584 eeCtrl (fce87ba643d5e9a8b6e0378508d1b22d) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:47:36.0880 4584 eeCtrl - ok
21:47:37.0028 4584 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
21:47:37.0040 4584 ehRecvr - ok
21:47:37.0142 4584 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
21:47:37.0148 4584 ehSched - ok
21:47:37.0165 4584 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
21:47:37.0167 4584 ehstart - ok
21:47:37.0384 4584 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
21:47:37.0482 4584 elxstor - ok
21:47:37.0631 4584 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
21:47:37.0676 4584 EMDMgmt - ok
21:47:37.0896 4584 enecir (4cd6b056c5fd9e97c06fe74c81479517) C:\Windows\system32\DRIVERS\enecir.sys
21:47:37.0925 4584 enecir - ok
21:47:38.0056 4584 EraserUtilRebootDrv (115dc729465a8c386615207f28875255) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:47:38.0061 4584 EraserUtilRebootDrv - ok
21:47:38.0253 4584 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
21:47:38.0313 4584 ErrDev - ok
21:47:38.0559 4584 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
21:47:38.0577 4584 EventSystem - ok
21:47:38.0706 4584 ewusbnet (1a7ae4575f4d56e9aa990a0b9f6bb2bb) C:\Windows\system32\DRIVERS\ewusbnet.sys
21:47:38.0753 4584 ewusbnet - ok
21:47:38.0936 4584 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
21:47:38.0965 4584 exfat - ok
21:47:39.0105 4584 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
21:47:39.0113 4584 fastfat - ok
21:47:39.0422 4584 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
21:47:39.0441 4584 fdc - ok
21:47:39.0510 4584 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
21:47:39.0513 4584 fdPHost - ok
21:47:39.0557 4584 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
21:47:39.0559 4584 FDResPub - ok
21:47:39.0638 4584 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
21:47:39.0650 4584 FileInfo - ok
21:47:39.0790 4584 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
21:47:39.0800 4584 Filetrace - ok
21:47:39.0918 4584 FLEXnet Licensing Service (73081cf28f0ae20a52ca4f67cee6e6b0) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
21:47:39.0962 4584 FLEXnet Licensing Service - ok
21:47:40.0076 4584 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
21:47:40.0086 4584 flpydisk - ok
21:47:40.0141 4584 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
21:47:40.0147 4584 FltMgr - ok
21:47:40.0232 4584 FontCache (452feaab2a8dbb42ed751754cb2594f5) C:\Windows\system32\FntCache.dll
21:47:40.0266 4584 FontCache - ok
21:47:40.0354 4584 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:47:40.0370 4584 FontCache3.0.0.0 - ok
21:47:40.0513 4584 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
21:47:40.0525 4584 Fs_Rec - ok
21:47:40.0676 4584 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
21:47:40.0700 4584 gagp30kx - ok
21:47:40.0917 4584 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
21:47:40.0934 4584 gpsvc - ok
21:47:41.0043 4584 gupdate - ok
21:47:41.0065 4584 gupdatem - ok
21:47:41.0154 4584 gusvc (5d4bc124faae6730ac002cdb67bf1a1c) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
21:47:41.0170 4584 gusvc - ok
21:47:41.0382 4584 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
21:47:41.0422 4584 HdAudAddService - ok
21:47:41.0689 4584 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:47:41.0716 4584 HDAudBus - ok
21:47:41.0904 4584 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
21:47:41.0931 4584 HidBth - ok
21:47:42.0089 4584 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
21:47:42.0100 4584 HidIr - ok
21:47:42.0223 4584 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\System32\hidserv.dll
21:47:42.0225 4584 hidserv - ok
21:47:42.0300 4584 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
21:47:42.0312 4584 HidUsb - ok
21:47:42.0576 4584 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
21:47:42.0589 4584 hkmsvc - ok
21:47:42.0680 4584 HP Health Check Service (d13e6bfd7e9189d26a42e94cb2447044) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
21:47:42.0682 4584 HP Health Check Service - ok
21:47:42.0937 4584 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
21:47:42.0980 4584 HpCISSs - ok
21:47:43.0104 4584 hpdskflt (24f3f496c18efc234777723a67a85f81) C:\Windows\system32\DRIVERS\hpdskflt.sys
21:47:43.0246 4584 hpdskflt - ok
21:47:43.0523 4584 hpqcxs08 (fcb563b0a23643e5f80b6ff1e60f610f) C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
21:47:43.0530 4584 hpqcxs08 - ok
21:47:43.0687 4584 hpqddsvc (25e443e27165c652723a92d9bdfd4649) C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
21:47:43.0701 4584 hpqddsvc - ok
21:47:43.0882 4584 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
21:47:43.0910 4584 HpqKbFiltr - ok
21:47:44.0087 4584 hpqwmiex (d50fdad1e57aa60f1973cfc77d905f0e) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
21:47:44.0113 4584 hpqwmiex - ok
21:47:44.0224 4584 hpsrv (6d0ac28c5bd8d8495f83f5929a45e559) C:\Windows\system32\Hpservice.exe
21:47:44.0225 4584 hpsrv - ok
21:47:44.0440 4584 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
21:47:44.0537 4584 HSFHWAZL - ok
21:47:44.0974 4584 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
21:47:45.0122 4584 HSF_DPV - ok
21:47:45.0324 4584 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
21:47:45.0347 4584 HTTP - ok
21:47:45.0488 4584 huawei_enumerator (bb3c8e4b88842f3a1b9c5d603210c277) C:\Windows\system32\DRIVERS\ew_jubusenum.sys
21:47:45.0507 4584 huawei_enumerator - ok
21:47:45.0729 4584 hwdatacard (0b3957226ec94b1ecb7b9348bb535a23) C:\Windows\system32\DRIVERS\ewusbmdm.sys
21:47:45.0748 4584 hwdatacard - ok
21:47:45.0893 4584 hwusbdev - ok
21:47:46.0072 4584 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
21:47:46.0139 4584 i2omp - ok
21:47:46.0487 4584 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
21:47:46.0672 4584 i8042prt - ok
21:47:46.0917 4584 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
21:47:46.0948 4584 iaStorV - ok
21:47:47.0044 4584 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
21:47:47.0088 4584 IDriverT - ok
21:47:47.0278 4584 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:47:47.0352 4584 idsvc - ok
21:47:47.0524 4584 IDSvix86 (f85dc24dafa76237722fe38b3196c61a) C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20120629.001\IDSvix86.sys
21:47:47.0534 4584 IDSvix86 - ok
21:47:47.0735 4584 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
21:47:47.0851 4584 iirsp - ok
21:47:48.0296 4584 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
21:47:48.0311 4584 IKEEXT - ok
21:47:48.0701 4584 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
21:47:48.0714 4584 intelide - ok
21:47:49.0045 4584 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
21:47:49.0086 4584 intelppm - ok
21:47:49.0236 4584 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
21:47:49.0258 4584 IPBusEnum - ok
21:47:49.0442 4584 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:47:49.0455 4584 IpFilterDriver - ok
21:47:49.0860 4584 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
21:47:49.0906 4584 iphlpsvc - ok
21:47:49.0991 4584 IpInIp - ok
21:47:50.0212 4584 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
21:47:50.0250 4584 IPMIDRV - ok
21:47:50.0523 4584 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
21:47:50.0547 4584 IPNAT - ok
21:47:50.0710 4584 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
21:47:50.0721 4584 IRENUM - ok
21:47:50.0769 4584 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
21:47:50.0788 4584 isapnp - ok
21:47:50.0982 4584 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
21:47:50.0989 4584 iScsiPrt - ok
21:47:51.0237 4584 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
21:47:51.0902 4584 iteatapi - ok
21:47:52.0182 4584 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
21:47:52.0417 4584 iteraid - ok
21:47:52.0697 4584 JMCR (5ee25c846a119a75d66a485cf8e77e78) C:\Windows\system32\DRIVERS\jmcr.sys
21:47:52.0728 4584 JMCR - ok
21:47:52.0840 4584 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
21:47:52.0857 4584 kbdclass - ok
21:47:52.0948 4584 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
21:47:52.0963 4584 kbdhid - ok
21:47:53.0118 4584 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
21:47:53.0119 4584 KeyIso - ok
21:47:53.0622 4584 KSecDD (4a1445efa932a3baf5bdb02d7131ee20) C:\Windows\system32\Drivers\ksecdd.sys
21:47:53.0734 4584 KSecDD - ok
21:47:53.0863 4584 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
21:47:53.0874 4584 KtmRm - ok
21:47:53.0999 4584 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\System32\srvsvc.dll
21:47:54.0009 4584 LanmanServer - ok
21:47:54.0114 4584 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
21:47:54.0121 4584 LanmanWorkstation - ok
21:47:54.0222 4584 LiveUpdate Notice (5a6fd8778a42fd0bdc6f6ed9a181669b) c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
21:47:54.0224 4584 LiveUpdate Notice - ok
21:47:54.0555 4584 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
21:47:55.0425 4584 lltdio - ok
21:47:55.0549 4584 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
21:47:55.0697 4584 lltdsvc - ok
21:47:55.0856 4584 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
21:47:55.0859 4584 lmhosts - ok
21:47:56.0028 4584 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
21:47:56.0054 4584 LSI_FC - ok
21:47:56.0340 4584 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
21:47:56.0465 4584 LSI_SAS - ok
21:47:56.0721 4584 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
21:47:56.0746 4584 LSI_SCSI - ok
21:47:57.0001 4584 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
21:47:57.0014 4584 luafv - ok
21:47:57.0130 4584 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
21:47:57.0142 4584 Mcx2Svc - ok
21:47:57.0211 4584 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
21:47:57.0256 4584 megasas - ok
21:47:57.0443 4584 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
21:47:57.0481 4584 MegaSR - ok
21:47:57.0686 4584 mi-raysat_3dsMax2009_32 (aa0c4a2c33ce075df2c272d678734991) C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
21:47:57.0688 4584 mi-raysat_3dsMax2009_32 - ok
21:47:57.0799 4584 Microsoft Office Groove Audit Service (7c4c76b39d5525c4a465e0be32528e19) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
21:47:57.0823 4584 Microsoft Office Groove Audit Service - ok
21:47:58.0223 4584 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
21:47:58.0245 4584 MMCSS - ok
21:47:58.0563 4584 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
21:47:58.0590 4584 Modem - ok
21:47:58.0803 4584 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
21:47:58.0805 4584 monitor - ok
21:47:58.0883 4584 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
21:47:58.0909 4584 mouclass - ok
21:47:59.0116 4584 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
21:47:59.0128 4584 mouhid - ok
21:47:59.0407 4584 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
21:47:59.0443 4584 MountMgr - ok
21:47:59.0611 4584 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
21:47:59.0635 4584 mpio - ok
21:47:59.0689 4584 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
21:47:59.0690 4584 mpsdrv - ok
21:47:59.0741 4584 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
21:47:59.0756 4584 MpsSvc - ok
21:47:59.0888 4584 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
21:47:59.0918 4584 Mraid35x - ok
21:47:59.0964 4584 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
21:47:59.0966 4584 MRxDAV - ok
21:48:00.0086 4584 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:48:00.0092 4584 mrxsmb - ok
21:48:00.0136 4584 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:48:00.0139 4584 mrxsmb10 - ok
21:48:00.0305 4584 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:48:00.0307 4584 mrxsmb20 - ok
21:48:00.0602 4584 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
21:48:00.0605 4584 msahci - ok
21:48:00.0650 4584 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
21:48:00.0665 4584 msdsm - ok
21:48:00.0896 4584 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
21:48:00.0936 4584 MSDTC - ok
21:48:01.0045 4584 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
21:48:01.0048 4584 Msfs - ok
21:48:01.0395 4584 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
21:48:01.0421 4584 msisadrv - ok
21:48:01.0641 4584 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
21:48:01.0680 4584 MSiSCSI - ok
21:48:01.0808 4584 msiserver - ok
21:48:01.0966 4584 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
21:48:02.0013 4584 MSKSSRV - ok
21:48:02.0196 4584 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
21:48:02.0212 4584 MSPCLOCK - ok
21:48:02.0508 4584 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
21:48:02.0510 4584 MSPQM - ok
21:48:02.0649 4584 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
21:48:02.0679 4584 MsRPC - ok
21:48:02.0925 4584 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
21:48:02.0930 4584 mssmbios - ok
21:48:03.0135 4584 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
21:48:03.0150 4584 MSTEE - ok
21:48:03.0295 4584 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
21:48:03.0319 4584 Mup - ok
21:48:03.0416 4584 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
21:48:03.0428 4584 napagent - ok
21:48:03.0577 4584 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
21:48:03.0583 4584 NativeWifiP - ok
21:48:03.0711 4584 NAVENG (f11033730b38260b6892e837c457fb4b) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120704.017\NAVENG.SYS
21:48:03.0714 4584 NAVENG - ok
21:48:03.0791 4584 NAVEX15 (4e4e7c0259d3bb97de24a636c0e06aba) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120704.017\NAVEX15.SYS
21:48:03.0808 4584 NAVEX15 - ok
21:48:03.0990 4584 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
21:48:04.0002 4584 NDIS - ok
21:48:04.0129 4584 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
21:48:04.0140 4584 NdisTapi - ok
21:48:04.0219 4584 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
21:48:04.0221 4584 Ndisuio - ok
21:48:04.0290 4584 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
21:48:04.0452 4584 NdisWan - ok
21:48:04.0616 4584 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
21:48:04.0629 4584 NDProxy - ok
21:48:04.0754 4584 Net Driver HPZ12 (69c503c004f49aee8b8e3067cc047ba7) C:\Windows\system32\HPZinw12.dll
21:48:04.0757 4584 Net Driver HPZ12 - ok
21:48:04.0939 4584 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
21:48:04.0941 4584 NetBIOS - ok
21:48:05.0067 4584 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
21:48:05.0072 4584 netbt - ok
21:48:05.0129 4584 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
21:48:05.0131 4584 Netlogon - ok
21:48:05.0353 4584 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
21:48:05.0367 4584 Netman - ok
21:48:05.0511 4584 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:05.0536 4584 NetMsmqActivator - ok
21:48:05.0552 4584 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:05.0556 4584 NetPipeActivator - ok
21:48:05.0903 4584 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
21:48:05.0958 4584 netprofm - ok
21:48:06.0117 4584 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:06.0125 4584 NetTcpActivator - ok
21:48:06.0140 4584 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:06.0143 4584 NetTcpPortSharing - ok
21:48:06.0318 4584 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
21:48:06.0336 4584 nfrd960 - ok
21:48:06.0525 4584 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
21:48:06.0532 4584 NlaSvc - ok
21:48:06.0641 4584 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
21:48:06.0645 4584 Npfs - ok
21:48:06.0693 4584 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
21:48:06.0698 4584 nsi - ok
21:48:06.0795 4584 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
21:48:06.0797 4584 nsiproxy - ok
21:48:06.0937 4584 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
21:48:06.0976 4584 Ntfs - ok
21:48:07.0217 4584 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
21:48:07.0237 4584 ntrigdigi - ok
21:48:07.0407 4584 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
21:48:07.0410 4584 Null - ok
21:48:07.0642 4584 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
21:48:07.0705 4584 NVENETFD - ok
21:48:07.0876 4584 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
21:48:07.0901 4584 nvraid - ok
21:48:07.0986 4584 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
21:48:08.0020 4584 nvstor - ok
21:48:08.0406 4584 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
21:48:08.0435 4584 nv_agp - ok
21:48:08.0655 4584 NwlnkFlt - ok
21:48:08.0683 4584 NwlnkFwd - ok
21:48:08.0820 4584 odserv (1f0e05dff4f5a833168e49be1256f002) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:48:08.0915 4584 odserv - ok
21:48:09.0088 4584 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
21:48:09.0089 4584 ohci1394 - ok
21:48:09.0196 4584 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:48:09.0315 4584 ose - ok
21:48:09.0465 4584 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
21:48:09.0481 4584 p2pimsvc - ok
21:48:09.0499 4584 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
21:48:09.0505 4584 p2psvc - ok
21:48:09.0622 4584 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
21:48:09.0624 4584 Parport - ok
21:48:09.0673 4584 partmgr (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys
21:48:09.0699 4584 partmgr - ok
21:48:09.0805 4584 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
21:48:09.0819 4584 Parvdm - ok
21:48:09.0912 4584 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
21:48:09.0916 4584 PcaSvc - ok
21:48:10.0043 4584 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
21:48:10.0049 4584 pci - ok
21:48:10.0239 4584 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
21:48:10.0267 4584 pciide - ok
21:48:10.0435 4584 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
21:48:10.0453 4584 pcmcia - ok
21:48:10.0511 4584 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
21:48:10.0518 4584 PEAUTH - ok
21:48:10.0652 4584 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
21:48:10.0698 4584 pla - ok
21:48:10.0812 4584 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
21:48:10.0823 4584 PlugPlay - ok
21:48:10.0940 4584 Pml Driver HPZ12 (12b4549d515cb26bb8d375038017ca65) C:\Windows\system32\HPZipm12.dll
21:48:10.0944 4584 Pml Driver HPZ12 - ok
21:48:11.0389 4584 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
21:48:11.0415 4584 PNRPAutoReg - ok
21:48:11.0512 4584 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
21:48:11.0536 4584 PNRPsvc - ok
21:48:11.0739 4584 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
21:48:11.0752 4584 PolicyAgent - ok
21:48:11.0918 4584 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
21:48:11.0940 4584 PptpMiniport - ok
21:48:12.0058 4584 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
21:48:12.0061 4584 Processor - ok
21:48:12.0284 4584 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
21:48:12.0296 4584 ProfSvc - ok
21:48:12.0405 4584 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
21:48:12.0409 4584 ProtectedStorage - ok
21:48:12.0489 4584 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
21:48:12.0493 4584 PSched - ok
21:48:12.0661 4584 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
21:48:12.0725 4584 ql2300 - ok
21:48:12.0892 4584 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
21:48:12.0913 4584 ql40xx - ok
21:48:13.0085 4584 QPCapSvc (026d1fa4033b82f18b99e44351d7e82e) C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
21:48:13.0094 4584 QPCapSvc - ok
21:48:13.0179 4584 QPSched (7697bca450eae30a6cdb98898239e8b7) C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
21:48:13.0191 4584 QPSched - ok
21:48:13.0430 4584 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
21:48:13.0445 4584 QWAVE - ok
21:48:13.0568 4584 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
21:48:13.0572 4584 QWAVEdrv - ok
21:48:13.0624 4584 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
21:48:13.0626 4584 RasAcd - ok
21:48:13.0715 4584 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
21:48:13.0720 4584 RasAuto - ok
21:48:13.0839 4584 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:48:13.0858 4584 Rasl2tp - ok
21:48:13.0924 4584 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
21:48:13.0937 4584 RasMan - ok
21:48:14.0058 4584 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
21:48:14.0084 4584 RasPppoe - ok
21:48:14.0126 4584 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
21:48:14.0139 4584 RasSstp - ok
21:48:14.0265 4584 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
21:48:14.0271 4584 rdbss - ok
21:48:14.0394 4584 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:48:14.0396 4584 RDPCDD - ok
21:48:14.0527 4584 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
21:48:14.0560 4584 rdpdr - ok
21:48:14.0603 4584 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
21:48:14.0605 4584 RDPENCDD - ok
21:48:14.0721 4584 RDPWD (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys
21:48:14.0748 4584 RDPWD - ok
21:48:14.0834 4584 Recovery Service for Windows (b9570481a1babcc4a9e941c553596077) C:\Windows\SMINST\BLService.exe
21:48:14.0849 4584 Recovery Service for Windows - ok
21:48:14.0944 4584 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
21:48:14.0950 4584 RemoteAccess - ok
21:48:15.0018 4584 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
21:48:15.0032 4584 RemoteRegistry - ok
21:48:15.0132 4584 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys
21:48:15.0176 4584 RFCOMM - ok
21:48:15.0313 4584 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
21:48:15.0321 4584 RpcLocator - ok
21:48:15.0460 4584 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
21:48:15.0479 4584 RpcSs - ok
21:48:15.0587 4584 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
21:48:15.0593 4584 rspndr - ok
21:48:15.0723 4584 RTL8169 (abbe0f54ba3a378262c9cb86cf7d91f8) C:\Windows\system32\DRIVERS\Rtlh86.sys
21:48:15.0765 4584 RTL8169 - ok
21:48:15.0872 4584 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
21:48:15.0879 4584 SamSs - ok
21:48:15.0993 4584 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
21:48:16.0042 4584 sbp2port - ok
21:48:16.0136 4584 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
21:48:16.0151 4584 SCardSvr - ok
21:48:16.0259 4584 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
21:48:16.0275 4584 Schedule - ok
21:48:16.0349 4584 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
21:48:16.0350 4584 SCPolicySvc - ok
21:48:16.0539 4584 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
21:48:16.0574 4584 sdbus - ok
21:48:16.0654 4584 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
21:48:16.0736 4584 SDRSVC - ok
21:48:16.0896 4584 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
21:48:16.0899 4584 secdrv - ok
21:48:16.0963 4584 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
21:48:16.0973 4584 seclogon - ok
21:48:17.0036 4584 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\system32\sens.dll
21:48:17.0046 4584 SENS - ok
21:48:17.0132 4584 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
21:48:17.0151 4584 Serenum - ok
21:48:17.0240 4584 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
21:48:17.0261 4584 Serial - ok
21:48:17.0348 4584 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
21:48:17.0454 4584 sermouse - ok
21:48:17.0562 4584 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
21:48:17.0569 4584 SessionEnv - ok
21:48:17.0657 4584 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
21:48:17.0676 4584 sffdisk - ok
21:48:17.0761 4584 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
21:48:17.0780 4584 sffp_mmc - ok
21:48:17.0883 4584 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
21:48:17.0908 4584 sffp_sd - ok
21:48:18.0017 4584 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
21:48:18.0032 4584 sfloppy - ok
21:48:18.0104 4584 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
21:48:18.0112 4584 SharedAccess - ok
21:48:18.0197 4584 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
21:48:18.0208 4584 ShellHWDetection - ok
21:48:18.0320 4584 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
21:48:18.0342 4584 sisagp - ok
21:48:18.0445 4584 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
21:48:18.0468 4584 SiSRaid2 - ok
21:48:18.0508 4584 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
21:48:18.0534 4584 SiSRaid4 - ok
21:48:18.0676 4584 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
21:48:18.0785 4584 slsvc - ok
21:48:18.0896 4584 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
21:48:18.0900 4584 SLUINotify - ok
21:48:18.0965 4584 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
21:48:18.0969 4584 Smb - ok
21:48:19.0053 4584 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
21:48:19.0056 4584 SNMPTRAP - ok
21:48:19.0160 4584 SPBBCDrv (72c6d9494cfb97cc799b12dfd01920f3) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
21:48:19.0175 4584 SPBBCDrv - ok
21:48:19.0325 4584 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
21:48:19.0364 4584 spldr - ok
21:48:19.0465 4584 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
21:48:19.0477 4584 Spooler - ok
21:48:19.0651 4584 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
21:48:19.0655 4584 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
21:48:19.0673 4584 sptd ( LockedFile.Multi.Generic ) - warning
21:48:19.0673 4584 sptd - detected LockedFile.Multi.Generic (1)
21:48:19.0877 4584 SRTSP (e0e54a571d4323567e95e11fe76a5ff3) C:\Windows\system32\Drivers\SRTSP.SYS
21:48:19.0897 4584 SRTSP - ok
21:48:20.0023 4584 SRTSPL (4e44f0e22df824d318988caa6f321c30) C:\Windows\system32\Drivers\SRTSPL.SYS
21:48:20.0056 4584 SRTSPL - ok
21:48:20.0107 4584 SRTSPX (d3bb40427cf3d02e56bba97feda0a3aa) C:\Windows\system32\Drivers\SRTSPX.SYS
21:48:20.0164 4584 SRTSPX - ok
21:48:20.0239 4584 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
21:48:20.0246 4584 srv - ok
21:48:20.0398 4584 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
21:48:20.0401 4584 srv2 - ok
21:48:20.0445 4584 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
21:48:20.0451 4584 srvnet - ok
21:48:20.0508 4584 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
21:48:20.0525 4584 SSDPSRV - ok
21:48:20.0659 4584 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
21:48:20.0676 4584 SstpSvc - ok
21:48:20.0833 4584 ST330 (c9fa6a70c051fc59d22c2e4cd211ad9b) C:\Windows\system32\drivers\st330.sys
21:48:20.0874 4584 ST330 - ok
21:48:21.0005 4584 STacSV (e6f7d35741a6239ce7b54d7665eab523) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_9a642328\STacSV.exe
21:48:21.0015 4584 STacSV - ok
21:48:21.0150 4584 STBUS (0017202eb0224f82706f04ed35ab23c2) C:\Windows\system32\drivers\stbus.sys
21:48:21.0185 4584 STBUS - ok
21:48:21.0258 4584 STHDA (5e71b3635d5f96d23eee1da92b85c850) C:\Windows\system32\DRIVERS\stwrt.sys
21:48:21.0289 4584 STHDA - ok
21:48:21.0422 4584 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
21:48:21.0436 4584 stisvc - ok
21:48:21.0567 4584 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
21:48:21.0579 4584 swenum - ok
21:48:21.0645 4584 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
21:48:21.0656 4584 swprv - ok
21:48:21.0746 4584 Symantec Core LC (438fafe708c93b2236fc26b6f2bd5fd0) C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
21:48:21.0787 4584 Symantec Core LC - ok
21:48:22.0188 4584 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
21:48:22.0232 4584 Symc8xx - ok
21:48:22.0383 4584 SYMDNS (fbc9c3b9805849e4cd78aa920e8cd26d) C:\Windows\System32\Drivers\SYMDNS.SYS
21:48:22.0385 4584 SYMDNS - ok
21:48:22.0503 4584 SymEvent (e03ee3ef1037099554d17bed99545a5e) C:\Windows\system32\Drivers\SYMEVENT.SYS
21:48:22.0517 4584 SymEvent - ok
21:48:22.0621 4584 SYMFW (4c1638572e422554944619b2ee51c9a9) C:\Windows\System32\Drivers\SYMFW.SYS
21:48:22.0626 4584 SYMFW - ok
21:48:22.0676 4584 SymIM (9bcbef50804a8c25a16781cb53231bfa) C:\Windows\system32\DRIVERS\SymIMv.sys
21:48:22.0680 4584 SymIM - ok
21:48:22.0775 4584 SYMNDISV (ffff1f125e0d6b2047816720627e867c) C:\Windows\System32\Drivers\SYMNDISV.SYS
21:48:22.0778 4584 SYMNDISV - ok
21:48:22.0929 4584 SYMREDRV (fc89356b6aa9dee10a284c18215c5b60) C:\Windows\System32\Drivers\SYMREDRV.SYS
21:48:22.0932 4584 SYMREDRV - ok
21:48:23.0097 4584 SYMTDI (9d32181eb6586758071e9ff012fb9ab0) C:\Windows\System32\Drivers\SYMTDI.SYS
21:48:23.0104 4584 SYMTDI - ok
21:48:23.0186 4584 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
21:48:23.0273 4584 Sym_hi - ok
21:48:23.0537 4584 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
21:48:23.0581 4584 Sym_u3 - ok
21:48:23.0779 4584 SynTP (bf7aa84d5af0faa0978c840e63b17dbf) C:\Windows\system32\DRIVERS\SynTP.sys
21:48:23.0810 4584 SynTP - ok
21:48:23.0938 4584 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
21:48:23.0953 4584 SysMain - ok
21:48:24.0063 4584 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
21:48:24.0068 4584 TabletInputService - ok
21:48:24.0127 4584 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
21:48:24.0136 4584 TapiSrv - ok
21:48:24.0304 4584 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
21:48:24.0309 4584 TBS - ok
21:48:24.0514 4584 Tcpip (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys
21:48:24.0571 4584 Tcpip - ok
21:48:24.0714 4584 Tcpip6 (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys
21:48:24.0727 4584 Tcpip6 - ok
21:48:24.0849 4584 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
21:48:24.0850 4584 tcpipreg - ok
21:48:24.0926 4584 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
21:48:24.0949 4584 TDPIPE - ok
21:48:25.0055 4584 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
21:48:25.0077 4584 TDTCP - ok
21:48:25.0118 4584 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
21:48:25.0123 4584 tdx - ok
21:48:25.0227 4584 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
21:48:25.0254 4584 TermDD - ok
21:48:25.0472 4584 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
21:48:25.0492 4584 TermService - ok
21:48:25.0585 4584 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
21:48:25.0589 4584 Themes - ok
21:48:25.0644 4584 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
21:48:25.0646 4584 THREADORDER - ok
21:48:25.0722 4584 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
21:48:25.0733 4584 TrkWks - ok
21:48:25.0822 4584 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
21:48:25.0826 4584 TrustedInstaller - ok
21:48:25.0945 4584 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:48:25.0966 4584 tssecsrv - ok
21:48:26.0078 4584 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
21:48:26.0117 4584 tunmp - ok
21:48:26.0208 4584 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
21:48:26.0215 4584 tunnel - ok
21:48:26.0352 4584 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
21:48:26.0390 4584 uagp35 - ok
21:48:26.0539 4584 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
21:48:26.0562 4584 udfs - ok
21:48:26.0626 4584 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
21:48:26.0629 4584 UI0Detect - ok
21:48:26.0719 4584 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
21:48:26.0733 4584 uliagpkx - ok
21:48:26.0781 4584 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
21:48:26.0798 4584 uliahci - ok
21:48:26.0829 4584 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
21:48:26.0842 4584 UlSata - ok
21:48:26.0867 4584 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
21:48:26.0881 4584 ulsata2 - ok
21:48:26.0963 4584 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
21:48:26.0981 4584 umbus - ok
21:48:27.0035 4584 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
21:48:27.0047 4584 upnphost - ok
21:48:27.0158 4584 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
21:48:27.0183 4584 usbccgp - ok
21:48:27.0340 4584 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
21:48:27.0357 4584 usbcir - ok
21:48:27.0500 4584 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
21:48:27.0575 4584 usbehci - ok
21:48:27.0703 4584 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
21:48:27.0722 4584 usbhub - ok
21:48:27.0768 4584 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
21:48:27.0781 4584 usbohci - ok
21:48:27.0908 4584 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
21:48:27.0929 4584 usbprint - ok
21:48:28.0073 4584 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
21:48:28.0094 4584 usbscan - ok
21:48:28.0136 4584 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:48:28.0171 4584 USBSTOR - ok
21:48:28.0318 4584 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
21:48:28.0347 4584 usbuhci - ok
21:48:28.0411 4584 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
21:48:28.0445 4584 usbvideo - ok
21:48:28.0497 4584 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
21:48:28.0504 4584 UxSms - ok
21:48:28.0624 4584 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
21:48:28.0639 4584 vds - ok
21:48:28.0745 4584 vfs101x (4d45a93a7dd638ca2db0a86fbfbf42d1) C:\Windows\system32\drivers\vfs101x.sys
21:48:28.0758 4584 vfs101x - ok
21:48:28.0858 4584 vfsFPService (14c9b01b3c2efa722fbc75286682994e) C:\Windows\system32\vfsFPService.exe
21:48:28.0865 4584 vfsFPService - ok
21:48:28.0950 4584 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
21:48:28.0961 4584 vga - ok
21:48:29.0002 4584 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
21:48:29.0004 4584 VgaSave - ok
21:48:29.0029 4584 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
21:48:29.0052 4584 viaagp - ok
21:48:29.0075 4584 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
21:48:29.0086 4584 ViaC7 - ok
21:48:29.0189 4584 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
21:48:29.0201 4584 viaide - ok
21:48:29.0238 4584 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
21:48:29.0256 4584 volmgr - ok
21:48:29.0316 4584 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
21:48:29.0429 4584 volmgrx - ok
21:48:29.0557 4584 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
21:48:29.0587 4584 volsnap - ok
21:48:29.0700 4584 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
21:48:29.0728 4584 vsmraid - ok
21:48:29.0845 4584 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
21:48:29.0898 4584 VSS - ok
21:48:30.0023 4584 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
21:48:30.0040 4584 W32Time - ok
21:48:30.0170 4584 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
21:48:30.0193 4584 WacomPen - ok
21:48:30.0242 4584 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
21:48:30.0254 4584 Wanarp - ok
21:48:30.0265 4584 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
21:48:30.0268 4584 Wanarpv6 - ok
21:48:30.0395 4584 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
21:48:30.0409 4584 wcncsvc - ok
21:48:30.0476 4584 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
21:48:30.0488 4584 WcsPlugInService - ok
21:48:30.0585 4584 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
21:48:30.0612 4584 Wd - ok
21:48:30.0750 4584 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
21:48:30.0766 4584 Wdf01000 - ok
21:48:30.0869 4584 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
21:48:30.0884 4584 WdiServiceHost - ok
21:48:30.0899 4584 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
21:48:30.0914 4584 WdiSystemHost - ok
21:48:30.0986 4584 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
21:48:30.0998 4584 WebClient - ok
21:48:31.0086 4584 Wecsvc (905214925a88311fce52f66153de7610) C:\Windows\system32\wecsvc.dll
21:48:31.0096 4584 Wecsvc - ok
21:48:31.0151 4584 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
21:48:31.0158 4584 wercplsupport - ok
21:48:31.0200 4584 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
21:48:31.0207 4584 WerSvc - ok
21:48:31.0333 4584 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
21:48:31.0372 4584 winachsf - ok
21:48:31.0439 4584 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
21:48:31.0476 4584 WinDefend - ok
21:48:31.0492 4584 WinHttpAutoProxySvc - ok
21:48:31.0713 4584 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
21:48:31.0719 4584 Winmgmt - ok
21:48:31.0831 4584 WinRM (01874d4689c212460fbabf0ecd7cb7f7) C:\Windows\system32\WsmSvc.dll
21:48:31.0849 4584 WinRM - ok
21:48:31.0964 4584 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
21:48:31.0983 4584 Wlansvc - ok
21:48:32.0123 4584 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
21:48:32.0125 4584 WmiAcpi - ok
21:48:32.0198 4584 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
21:48:32.0205 4584 wmiApSrv - ok
21:48:32.0314 4584 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
21:48:32.0325 4584 WMPNetworkSvc - ok
21:48:32.0520 4584 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
21:48:32.0541 4584 WPCSvc - ok
21:48:32.0599 4584 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
21:48:32.0605 4584 WPDBusEnum - ok
21:48:32.0700 4584 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
21:48:32.0780 4584 WpdUsb - ok
21:48:32.0969 4584 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:48:32.0986 4584 WPFFontCache_v0400 - ok
21:48:33.0106 4584 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
21:48:33.0109 4584 ws2ifsl - ok
21:48:33.0147 4584 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\system32\wscsvc.dll
21:48:33.0151 4584 wscsvc - ok
21:48:33.0240 4584 WSearch - ok
21:48:33.0335 4584 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
21:48:33.0378 4584 wuauserv - ok
21:48:33.0534 4584 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:48:33.0538 4584 WUDFRd - ok
21:48:33.0593 4584 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
21:48:33.0601 4584 wudfsvc - ok
21:48:33.0739 4584 {22D78859-9CE9-4B77-BF18-AC83E81A9263} (4d840c6af3c020ed3a35efba9025cf4a) C:\Program Files\HP\QuickPlay\000.fcl
21:48:33.0740 4584 {22D78859-9CE9-4B77-BF18-AC83E81A9263} - ok
21:48:33.0789 4584 MBR (0x1B8) (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0
21:48:33.0835 4584 \Device\Harddisk0\DR0 - ok
21:48:33.0842 4584 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
21:48:33.0846 4584 \Device\Harddisk1\DR1 - ok
21:48:33.0854 4584 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
21:48:37.0290 4584 \Device\Harddisk2\DR2 - ok
21:48:37.0296 4584 Boot (0x1200) (3d7f53761a9a2b80b699f9f67b3ecdc9) \Device\Harddisk0\DR0\Partition0
21:48:37.0298 4584 \Device\Harddisk0\DR0\Partition0 - ok
21:48:37.0303 4584 Boot (0x1200) (0da94abe36784568b80fa007a9c6fbfb) \Device\Harddisk0\DR0\Partition1
21:48:37.0305 4584 \Device\Harddisk0\DR0\Partition1 - ok
21:48:37.0312 4584 Boot (0x1200) (b8e9ead212e37afad27b6101eec8e16c) \Device\Harddisk1\DR1\Partition0
21:48:37.0313 4584 \Device\Harddisk1\DR1\Partition0 - ok
21:48:37.0320 4584 Boot (0x1200) (913ef10d697e4e73a055a491c828ba6e) \Device\Harddisk2\DR2\Partition0
21:48:37.0321 4584 \Device\Harddisk2\DR2\Partition0 - ok
21:48:37.0322 4584 ============================================================
21:48:37.0322 4584 Scan finished
21:48:37.0322 4584 ============================================================
21:48:37.0338 4576 Detected object count: 1
21:48:37.0338 4576 Actual detected object count: 1
21:49:34.0814 4576 sptd ( LockedFile.Multi.Generic ) - skipped by user
21:49:34.0815 4576 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

-- 05 wrz 2012, 21:55 --

adw

# AdwCleaner v2.000 - Logfile created 09/05/2012 at 21:36:38
# Updated 30/08/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Ania - ANIA-PC
# Boot Mode : Normal
# Running from : C:\Users\Ania\Downloads\adwcleaner (1).exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : Web Assistant Updater

***** [Files / Folders] *****

File Deleted : C:\user.js
Folder Deleted : C:\Program Files\Web Assistant
Folder Deleted : C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd

***** [Registry] *****

Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B}
Key Deleted : HKCU\Software\SweetIm
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C01315C7-B4E2-4864-B43D-5FAFC414D179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C1545464-C77C-4130-A572-1C619E2895FE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED0E67AD-926C-4008-87E5-03CF72AA2A7E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF7FEC6D-451B-4452-9D26-7E10C6B5DB6E}
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.IncredibarESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\I
Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\IncredibarApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CFE8AAFD-A0F3-4329-84E9-6B679EC93EC2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C36554-31F0-49DD-8857-ED6A64DF45BE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Deleted : HKLM\Software\SweetIm
Key Deleted : HKLM\Software\Web Assistant
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Google Chrome v19.0.1084.52

File : C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.16] : homepage = "hxxp://mystart.incredibar.com/mb143?a=6R8sMfRxTz&i=26",
Deleted [l.20] : urls_to_restore_on_startup = [ "hxxp://mystart.incredibar.com/mb143?a=6R8sMfRxTz&i=26" ]
Deleted [l.1382] : homepage = "hxxp://mystart.incredibar.com/mb143?a=6R8sMfRxTz&i=26",
Deleted [l.1775] : urls_to_restore_on_startup = [ "hxxp://mystart.incredibar.com/mb143?a=6R8sMfRxTz&i=26" ]

-\\ Opera v11.10.2092.0

File : C:\Users\Ania\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [6090 octets] - [05/09/2012 21:34:49]
AdwCleaner[S1].txt - [6592 octets] - [05/09/2012 21:36:38]

########## EOF - C:\AdwCleaner[S1].txt - [6652 octets] ##########

Awatar użytkownika
kominekl

Ekspert
Posty: 5855
Rejestracja: 27 lis 2011, 14:25
Kontaktowanie:

UKASH logi proszę o pomoc

Post06 wrz 2012, 19:36

Podawanie logów.


Wszelkie logi podawaj na -> Dostępne tylko dla zarejestrowanych użytkowników, a w temacie podawaj tylko log do logu.

ADWCleaner.


Dobrze wyszło. Czekamy na wykonanie reszty instrukcji.
Kiedy komputery staną się twoim jedynym życiem, jedynym totemem odstraszającym klątwę nudy, wtedy prędzej czy później granica między tymi dwoma wymiarami zniknie i postacie z Błękitnej Pustki zaczną pojawiać się w Realu. Czasem są twoimi przyjaciółmi. A czasem nie.



  • Reklama

Wróć do „Bezpieczeństwo”



Kto jest online

Użytkownicy przeglądający to forum: Bing [Bot] i 3 gości