Run DLL

1

Run DLL

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Pojavio mi se problem da mi iskače neki prozorčić sa nejasnom porukom, ne određuje mi šta ne valja a iskače stalno.

Šta da radim?

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 28 Jun 2015 22:02

PA ne znam šta bih dodao, odjednom je počelo da iskače, možda je povezano sa pokretanjem mozile jer kratko nakon pokretanja se to pojavi, skoro sam imao neki problem sa dodacima ali sam to obrisao, moguće je da zbog toga se ovo dešava.



Dopuna: 28 Jun 2015 22:30

sad videh da mu se u program fajl pojavile ove tri fascikle koje ne znam odakle, verovatno sam nešto instalirao pored nekog kreka. nisam uspeo da ih deinstaliram


Dopuna: 28 Jun 2015 22:38

Ovo su sadržaji tih fascikla








Dopuna: 28 Jun 2015 22:41

a sad vidim da mi i malware izbaci poruku kad se pojavi taj prozorčić


Dopuna: 28 Jun 2015 22:51

ponovio sam sve pošto sam nešto uspeo da izibrišem


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-06-2015
Ran by wolf (administrator) on WOLF-PC on 28-06-2015 22:46:17
Running from C:\Users\wolf\Desktop
Loaded Profiles: wolf (Available Profiles: wolf & Administrator)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: engleski (SAD)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
( ) C:\Windows\System32\lmabcoms.exe
( ) C:\Windows\System32\lxbkcoms.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
(Nalpeiron Ltd.) C:\Windows\System32\NLSSRV32.EXE
(Ralink Technology, Corp.) C:\Program Files\Tenda\Common\RaRegistry.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
() C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Nokia) C:\Program Files\Nokia\PC Internet Access\NPCIA.exe
(Tenda Technology, Corp.) C:\Program Files\Tenda\Common\RaUI.exe
(Nokia.) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
() C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
() C:\Program Files\RealNetworks\RealDownloader\downloader2.exe
(ACD Systems) C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(BitTorrent Inc.) C:\Users\wolf\AppData\Roaming\uTorrent\uTorrent.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files\Nokia\PC Internet Access\NPCIA.exe [663552 2009-09-17] (Nokia)
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [3639568 2014-07-10] (Disc Soft Ltd)
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: J - J:\setup.exe
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {33d9778f-b687-11e4-be80-001d7da6a5fe} - J:\OriginInstaller.exe
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {44d1f4ec-b8e2-11e4-8d97-001d7da6a5fe} - I:\AutoRun.exe
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {44d1f500-b8e2-11e4-8d97-fb33faa4f8c7} - I:\AutoRun.exe
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {4a06256a-8d35-11e4-a9fd-f9c4027cb097} - H:\SETUP.EXE
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {4a06265d-8d35-11e4-a9fd-f9c4027cb097} - I:\OriginInstaller.exe
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\...\MountPoints2: {9a6b0f7a-1a5c-11e5-acbd-e288b12de2ba} - H:\NokiaPCIA_Autorun.exe
HKU\S-1-5-18\...\Run: [Advanced SystemCare 8] => "C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Tenda Wireless Utility.lnk [2015-01-06]
ShortcutTarget: Tenda Wireless Utility.lnk -> C:\Program Files\Tenda\Common\RaUI.exe (Tenda Technology, Corp.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.hotsearches.info/?pid=20176&r.....p;unqvl=90
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.hotsearches.info/?pid=20176&r.....p;unqvl=90
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
BHO: bestadblocker -> {08B2EB20-DA0D-42A4-8E43-EDB856C0FEAE} -> C:\Program Files\bestadblocker\0maq0ouNkI1Bdd.dll [2015-06-28] ()
BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-22] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-22] (Oracle Corporation)
BHO: No Name -> {F33A2581-69F5-47A2-8753-E791B9DE281F} -> No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F70AC9A2-BBC3-4989-9043-5885F882E46B}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Homepage: https://www.google.rs/
FF Keyword.URL: hxxp://websearch.hotsearches.info/?pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-27] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-22] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 9\npnitromozilla.dll [2013-12-17] (Nitro PDF)
FF Plugin: @real.com/nppl3260;version=17.0.15.10 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2015-02-07] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=17.0.15.10 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2015-02-07] (RealPlayer Cloud)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default\user.js [2015-02-07]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pogodakyu.xml [2014-11-26]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\vokabular.xml [2014-11-26]
FF Extension: Mozilla Firefox Hotfixer - C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default\Extensions\veggy@veggyAddon.com [2015-06-28]
FF HKLM\...\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-07]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASC_GhromePluginFor6.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Disc Soft Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe [887056 2014-07-10] (Disc Soft Ltd)
R2 ed78fbc6; c:\Program Files\ProcessProc\ProcessProc.dll [2630144 2015-06-28] () [File not signed]
R2 lmab_device; C:\Windows\system32\LMabcoms.exe [593920 2009-11-11] ( ) [File not signed]
R2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [537256 2008-02-19] ( )
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe [197128 2013-12-17] (Nitro PDF Software)
R2 RalinkRegistryWriter; C:\Program Files\Tenda\Common\RaRegistry.exe [375872 2011-03-31] (Ralink Technology, Corp.)
S3 RaMediaServer; C:\Program Files\Tenda\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
R2 RealPlayer Cloud Service; C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-07] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
R3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [575488 2008-09-23] (Nokia.) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [37376 2014-12-26] (Microsoft Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26080 2012-10-08] (Wondershare)
S3 asmthub3; C:\Windows\system32\drivers\asmthub3.sys [100328 2011-03-04] (ASMedia Technology Inc)
S3 asmtxhci; C:\Windows\system32\drivers\asmtxhci.sys [309224 2011-03-04] (ASMedia Technology Inc)
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [279712 2015-05-07] ()
S3 b06diag; C:\Windows\system32\drivers\bxdiagx.sys [76840 2010-12-16] (Broadcom Corporation)
S3 BFN7x86; C:\Windows\system32\drivers\Xeno7x86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.)
S3 BFNVis32; C:\Windows\system32\drivers\XenoVx86.sys [129640 2011-01-14] (Bigfoot Networks, Inc.)
S3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [36616 2015-02-08] (IVT Corporation.)
S3 BXOIS; C:\Windows\system32\drivers\bxois.sys [431144 2010-12-10] (Broadcom Corporation)
S3 cbaf; C:\Windows\System32\Drivers\cbaf.sys [11008 2007-11-03] (Intel Corp.)
S3 dfuuwb; C:\Windows\System32\Drivers\DfuUWB.sys [500736 2008-09-11] (Intel Corp.)
R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [24704 2014-12-26] (Disc Soft Ltd)
S3 ETD; C:\Windows\system32\drivers\ETD.sys [109448 2010-02-03] (ELAN Microelectronic Corp.)
S3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [33152 2011-03-07] (Etron Technology Inc)
S3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [52992 2011-03-07] (Etron Technology Inc)
S3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [61704 2011-03-18] (FTDI Ltd.)
S3 HWA; C:\Windows\System32\Drivers\HWA.sys [53376 2008-09-29] (Intel Corp.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-02-08] (REALiX(tm))
S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [269584 2011-01-13] (Intel(R) Corporation)
S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [61712 2011-01-13] (Intel(R) Corporation)
S3 ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [36552 2009-11-16] (Intel Corporation)
S3 ioatdma2; C:\Windows\System32\Drivers\qd26032.sys [37576 2009-11-16] (Intel Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2015-05-07] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [98520 2015-06-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
S3 mcdbus; C:\Windows\system32\drivers\mcdbus.sys [116736 2009-02-24] (MagicISO, Inc.) [File not signed]
S3 MEI; C:\Windows\system32\drivers\HECI.sys [40832 2009-06-23] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [5810 2004-08-13] ()
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1321568 2015-02-08] (Ralink Technology Corp.)
S3 nusb3hub; C:\Windows\system32\drivers\nusb3hub.sys [63872 2011-02-10] (Renesas Electronics Corporation)
S3 nusb3xhc; C:\Windows\system32\drivers\nusb3xhc.sys [141952 2011-02-10] (Renesas Electronics Corporation)
S3 nvamacpi; C:\Windows\system32\drivers\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
S3 TSSK; C:\Windows\System32\tssk.sys [67896 2015-05-08] (电脑管家)
S3 TTP7; C:\Windows\system32\drivers\ttp7up.sys [12928 2005-11-09] (TerraTec) [File not signed]
S3 uagp35; C:\Windows\system32\drivers\sisagpx.sys [58400 2009-08-01] (Silicon Integrated Systems Corporation)
S3 UsbFltr; C:\Windows\system32\drivers\copperhd.sys [11596 2005-11-02] (Razer (Asia-Pacific) Pte Ltd)
S3 uwbusb; C:\Windows\System32\Drivers\usbuwbmini.sys [9600 2008-09-15] (Intel Corp.)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34704 2007-05-11] (IVT Corporation.)
S3 cpuz137; \??\C:\Users\wolf\AppData\Local\Temp\cpuz137\cpuz137_x32.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwusb_cdcacm; system32\DRIVERS\ew_cdcacm.sys [X]
S3 hwusb_wwanecm; system32\DRIVERS\ew_wwanecm.sys [X]
S1 QMUdisk; \??\C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMUdisk.sys [X]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 22:41 - 2015-06-28 22:41 - 00000000 ___HD C:\Users\wolf\Desktop\[Originals]
2015-06-28 22:20 - 2015-06-28 22:20 - 00112624 _____ C:\Users\wolf\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-28 22:06 - 2015-06-28 22:07 - 00042783 _____ C:\Users\wolf\Desktop\Addition.txt
2015-06-28 22:05 - 2015-06-28 22:46 - 00020061 _____ C:\Users\wolf\Desktop\FRST.txt
2015-06-28 22:04 - 2015-06-28 22:46 - 00000000 ____D C:\FRST
2015-06-28 22:03 - 2015-06-28 22:03 - 01636352 _____ (Farbar) C:\Users\wolf\Desktop\FRST.exe
2015-06-28 19:39 - 2015-06-28 19:39 - 00000000 ____D C:\Program Files\ProcessProc
2015-06-28 19:37 - 2015-06-28 22:22 - 00000000 ____D C:\Program Files\bestadblocker
2015-06-28 19:36 - 2015-06-28 19:38 - 00000000 ____D C:\ProgramData\18386483835372826866
2015-06-28 19:36 - 2015-06-28 19:36 - 00000000 ____D C:\Program Files\CutThePriicea
2015-06-28 19:35 - 2015-06-28 19:35 - 00000484 _____ C:\Windows\Tasks\SmartHues.job
2015-06-28 19:35 - 2015-06-28 19:35 - 00000000 ____D C:\ProgramData\{f520581b-bf18-7f31-f520-0581bbf1606e}
2015-06-28 19:34 - 2015-06-28 19:34 - 00000000 ____D C:\Users\wolf\AppData\Roaming\systweak
2015-06-28 18:03 - 2015-06-28 18:09 - 00000000 ____D C:\Users\wolf\Downloads\suz
2015-06-27 21:47 - 2015-06-27 21:47 - 00435540 _____ C:\Windows\system32\RAIHVDump.dmp
2015-06-27 19:56 - 2015-06-27 19:59 - 32488166 _____ C:\Users\wolf\Desktop\donje kilote.mp4
2015-06-24 16:01 - 2015-06-24 16:01 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ccdcmb_01009.Wdf
2015-06-24 16:01 - 2015-06-24 16:01 - 00000000 ____D C:\ProgramData\PC Suite
2015-06-24 16:00 - 2015-06-24 16:00 - 00002026 _____ C:\Users\Public\Desktop\Nokia PC Internet Access.lnk
2015-06-24 16:00 - 2015-06-24 16:00 - 00000000 ____D C:\Users\wolf\AppData\Roaming\PC Suite
2015-06-24 16:00 - 2015-06-24 16:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nokia PC Internet Access
2015-06-24 16:00 - 2015-06-24 16:00 - 00000000 ____D C:\Program Files\PC Connectivity Solution
2015-06-24 16:00 - 2015-06-24 16:00 - 00000000 ____D C:\Program Files\Nokia
2015-06-24 16:00 - 2015-06-24 16:00 - 00000000 ____D C:\Program Files\DIFX
2015-06-24 16:00 - 2010-12-02 15:13 - 00075264 _____ (Nokia) C:\Windows\system32\nmwcdcls.dll
2015-06-24 16:00 - 2008-08-26 10:26 - 00018816 _____ (Nokia) C:\Windows\system32\Drivers\pccsmcfd.sys
2015-06-24 15:59 - 2015-06-24 15:59 - 00000000 ____D C:\ProgramData\Installations
2015-06-22 10:53 - 2015-06-22 10:53 - 00000000 ____D C:\Users\wolf\AppData\Local\GHISLER
2015-06-22 10:49 - 2015-06-22 10:50 - 00000000 ____D C:\totalcmd
2015-06-22 10:49 - 2015-06-22 10:49 - 00000000 ____D C:\Users\wolf\AppData\Roaming\GHISLER
2015-06-22 10:49 - 2015-06-22 10:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\UC.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\RAR.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\PKZIP.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\PKUNZIP.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\NOCLOSE.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\LHA.PIF
2015-06-22 10:49 - 2010-06-17 07:55 - 00000545 _____ C:\Windows\ARJ.PIF
2015-06-21 21:22 - 2015-06-21 21:22 - 00000000 ____D C:\Users\wolf\Documents\Adobe Scripts
2015-06-21 21:20 - 2015-06-21 21:20 - 00001141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
2015-06-21 21:20 - 2015-06-21 21:20 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-06-21 21:18 - 2015-06-21 21:18 - 00001103 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
2015-06-21 21:17 - 2015-06-21 21:17 - 00001196 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
2015-06-21 21:16 - 2015-06-21 21:16 - 00001469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
2015-06-21 21:16 - 2015-06-21 21:16 - 00001297 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
2015-06-21 21:15 - 2015-06-21 21:15 - 00000927 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-06-21 21:15 - 2015-06-21 21:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-06-21 21:15 - 2015-06-21 21:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-06-21 21:15 - 2015-06-21 21:15 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR
2015-06-19 11:03 - 2015-06-19 11:03 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\wolf\Downloads\flashplayer18au_ha_install.exe
2015-06-17 18:45 - 2015-06-17 18:45 - 00000000 _____ C:\ASPI.LOG
2015-06-17 18:19 - 2015-06-17 18:19 - 00000000 ____D C:\Users\wolf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ALCATech
2015-06-17 18:19 - 2015-06-17 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ALCATech
2015-06-17 18:19 - 2015-06-17 18:19 - 00000000 ____D C:\Program Files\ALCATech
2015-06-13 20:11 - 2015-06-13 20:11 - 00002074 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-10 10:39 - 2015-06-02 21:35 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 10:39 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 10:39 - 2015-05-25 19:00 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 10:39 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 10:39 - 2015-05-23 05:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 10:39 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 10:39 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 10:39 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 10:39 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 10:39 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 10:39 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 10:39 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 10:39 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 10:39 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 10:39 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 10:39 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 10:39 - 2015-05-23 05:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 10:39 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 10:39 - 2015-05-23 05:00 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 10:39 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 10:39 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 10:39 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 10:39 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 10:39 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 10:39 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 10:39 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 10:39 - 2015-05-23 04:38 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 10:39 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 10:39 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 10:39 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 10:39 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 10:39 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 10:39 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 10:38 - 2015-05-09 07:41 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 10:38 - 2015-05-09 07:41 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 10:38 - 2015-05-09 07:41 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 10:38 - 2015-05-09 07:40 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 10:38 - 2015-05-09 07:34 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 06:24 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 06:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 06:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 10:38 - 2015-05-09 06:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 10:38 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 10:38 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 10:38 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 10:38 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 10:38 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 10:38 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-07 22:26 - 2015-06-07 22:26 - 00000000 ____D C:\Users\Public\Documents\AKVIS
2015-06-07 22:26 - 2015-06-07 22:26 - 00000000 ____D C:\ProgramData\AKVIS
2015-06-07 22:22 - 2015-06-07 22:24 - 37568480 _____ (AKVIS ) C:\Users\wolf\Downloads\akvis-coloriage-setup.exe
2015-06-07 22:03 - 2015-06-07 22:03 - 09179017 _____ (Bertheussen IT ) C:\Users\wolf\Downloads\recolored.exe
2015-06-07 12:08 - 2015-05-25 20:12 - 03994560 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-06-07 12:08 - 2015-05-25 20:12 - 03939776 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-07 12:08 - 2015-05-25 20:12 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-07 12:08 - 2015-05-25 20:12 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-07 12:08 - 2015-05-25 20:09 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-07 12:08 - 2015-05-25 20:07 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-07 12:08 - 2015-05-25 20:06 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-07 12:08 - 2015-05-25 20:06 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-07 12:08 - 2015-05-25 20:06 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-07 12:08 - 2015-05-25 20:06 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-06-07 12:08 - 2015-05-25 20:06 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-07 12:08 - 2015-05-25 20:06 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-06-07 12:08 - 2015-05-25 20:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-07 12:08 - 2015-05-25 20:05 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-06-07 12:08 - 2015-05-25 20:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-07 12:08 - 2015-05-25 20:05 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-07 12:08 - 2015-05-25 20:05 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-06-07 12:08 - 2015-05-25 20:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-07 12:08 - 2015-05-25 20:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-07 12:08 - 2015-05-25 20:01 - 00853504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-07 12:08 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-07 12:08 - 2015-05-25 20:00 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-07 12:08 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-07 12:08 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-07 12:08 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-07 12:08 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-07 12:08 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-07 12:08 - 2015-05-25 20:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-07 12:08 - 2015-05-25 19:10 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-06-07 12:08 - 2015-05-25 18:53 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-07 12:08 - 2015-04-11 05:07 - 00054656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-07 12:08 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-06-07 12:08 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 02937344 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 02045952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-06-07 12:06 - 2015-05-09 05:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-06-07 12:06 - 2015-05-09 05:13 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-06-07 12:06 - 2015-05-09 05:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-06-07 12:06 - 2015-05-09 05:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-06-07 12:06 - 2015-05-09 05:13 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-06-03 10:07 - 2015-06-04 11:16 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-01 11:13 - 2015-06-01 11:13 - 00000000 ____D C:\Users\wolf\AppData\Local\GWX

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-28 22:45 - 2015-01-19 23:13 - 00000000 ____D C:\Users\wolf\AppData\Roaming\uTorrent
2015-06-28 22:30 - 2014-12-26 22:03 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-28 21:03 - 2015-01-12 10:58 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-28 12:39 - 2015-05-22 20:47 - 01092019 ____N C:\Windows\WindowsUpdate.log
2015-06-28 10:32 - 2009-07-14 06:34 - 00023904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-28 10:32 - 2009-07-14 06:34 - 00023904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-28 10:24 - 2009-07-14 06:53 - 00032626 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-28 10:24 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-28 00:14 - 2014-12-26 11:49 - 00000000 ____D C:\Users\wolf\Desktop\Desktop fascikla
2015-06-27 21:14 - 2015-01-04 21:18 - 00000000 ____D C:\Users\wolf\Desktop\video isečci
2015-06-27 16:07 - 2010-11-20 23:01 - 00785794 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-27 14:10 - 2015-01-15 18:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-27 14:10 - 2015-01-15 18:39 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-27 11:33 - 2014-12-26 22:03 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-27 11:33 - 2014-12-26 22:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-27 10:50 - 2014-12-26 22:03 - 00000000 ____D C:\Users\wolf\AppData\Local\Adobe
2015-06-25 11:20 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-06-24 20:58 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\tracing
2015-06-24 19:58 - 2014-12-30 17:11 - 00000000 ____D C:\Users\wolf\AppData\Local\Microsoft Games
2015-06-24 15:30 - 2015-01-06 21:21 - 00000000 ____D C:\ProgramData\Ralink
2015-06-21 21:25 - 2014-12-26 21:07 - 00000000 ____D C:\Users\wolf\AppData\Roaming\Adobe
2015-06-21 21:20 - 2015-01-07 19:05 - 00000000 ____D C:\ProgramData\Adobe
2015-06-21 21:19 - 2015-01-07 19:05 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-06-21 21:19 - 2015-01-07 19:05 - 00000000 ____D C:\Program Files\Adobe
2015-06-21 18:28 - 2014-12-31 14:50 - 00000000 ____D C:\OutputFolder
2015-06-21 18:22 - 2014-12-31 12:32 - 00000000 ____D C:\Users\wolf\AppData\Roaming\avidemux
2015-06-21 14:31 - 2014-12-30 22:21 - 00000000 ____D C:\Users\wolf\AppData\Roaming\vlc
2015-06-19 17:02 - 2015-02-15 20:34 - 00000000 ____D C:\RLTMP
2015-06-18 08:41 - 2015-01-15 18:39 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2015-01-15 18:39 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-18 08:41 - 2015-01-12 10:57 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-13 20:11 - 2015-02-11 16:58 - 00000000 ____D C:\Program Files\Google
2015-06-11 10:35 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-06-11 09:40 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\sr-Latn-CS
2015-06-10 23:10 - 2014-12-26 22:10 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 23:05 - 2009-07-14 04:04 - 00000580 _____ C:\Windows\win.ini
2015-06-10 23:04 - 2014-12-26 21:36 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 22:57 - 2014-12-26 21:36 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 17:17 - 2014-12-26 20:23 - 00000000 ____D C:\ProgramData\TEMP
2015-06-07 22:24 - 2014-12-27 12:58 - 00000000 ____D C:\Users\wolf\AppData\Local\Downloaded Installations
2015-06-04 11:16 - 2014-12-26 19:34 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service

==================== Files in the root of some directories =======

2015-04-07 20:08 - 2015-04-07 20:08 - 0001017 _____ () C:\Users\wolf\AppData\Local\recently-used.xbel
2015-02-08 20:50 - 2015-02-08 20:50 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-23 10:29

==================== End of log ==========================
https://www.mycity.rs/must-login.png

Dopuna: 28 Jun 2015 22:59

Da zaključim, ovo se sve desilo kad sam pokušavao da nađem AKtivaciju za Office 2010 i aktiviram ga. to je ovo; KMS Activator for Microsoft Office 2010 Applications x86 x64 Multilingual-FIXISO~DiBYA






[edit by magna86: uklonjen prvi log]

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav, Smile

Citat:Da zaključim, ovo se sve desilo kad sam pokušavao da nađem AKtivaciju za Office 2010 i aktiviram ga. to je ovo; KMS Activator for Microsoft Office 2010 Applications x86 x64 Multilingual-FIXISO~DiBYA

Bar si iskren. Razz

Zamolio bih te da procitas pravilnik MyCity foruma jer mi ne podrzavamo pirateriju. Wink

Sto se tice logova ... da, uzasni su. Idemo redom ...


Iz start > control panel > programs and features pokusaj da deinstaliras sledece maliciozne programe:

- bestadblocker
- ConvertGuru
- Surfing Protection
- CutThePrice


...i sve ostalo sto ne koristis.
I da li ti je poznat 'Cool Clock' program? Ako ne, ukloni i njega.










1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

Start
CreateRestorePoint:
VerifySignature: C:\Windows\System32\tssk.sys
File: C:\Windows\system32\themeservice.dll
File: C:\Windows\System32\tssk.sys
Folder: C:\Users\wolf\AppData\Local\GWX
Folder: C:\ProgramData\TEMP
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt 
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: typo c:\resetlog.txt

CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.hotsearches.info/?pid=20176&r=201.....S&unqvl=90
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.hotsearches.info/?pid=20176&r=201.....S&unqvl=90
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
BHO: bestadblocker -> {08B2EB20-DA0D-42A4-8E43-EDB856C0FEAE} -> C:\Program Files\bestadblocker\0maq0ouNkI1Bdd.dll [2015-06-28] ()
BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL No File
BHO: No Name -> {F33A2581-69F5-47A2-8753-E791B9DE281F} -> No File
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Keyword.URL: hxxp://websearch.hotsearches.info/?pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASC_GhromePluginFor6.crx [Not Found]
R2 ed78fbc6; c:\Program Files\ProcessProc\ProcessProc.dll [2630144 2015-06-28] () [File not signed]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [X]

Hosts:
C:\Program Files\bestadblocker
C:\Program Files\IObit
c:\Program Files\ProcessProc
C:\Program Files\Google
2015-06-28 19:39 - 2015-06-28 19:39 - 00000000 ____D C:\Program Files\ProcessProc
2015-06-28 19:37 - 2015-06-28 22:22 - 00000000 ____D C:\Program Files\bestadblocker
2015-06-28 19:36 - 2015-06-28 19:38 - 00000000 ____D C:\ProgramData\18386483835372826866
2015-06-28 19:36 - 2015-06-28 19:36 - 00000000 ____D C:\Program Files\CutThePriicea
2015-06-28 19:35 - 2015-06-28 19:35 - 00000484 _____ C:\Windows\Tasks\SmartHues.job
2015-06-28 19:35 - 2015-06-28 19:35 - 00000000 ____D C:\ProgramData\{f520581b-bf18-7f31-f520-0581bbf1606e}
2015-06-28 19:34 - 2015-06-28 19:34 - 00000000 ____D C:\Users\wolf\AppData\Roaming\systweak
2015-06-28 18:03 - 2015-06-28 18:09 - 00000000 ____D C:\Users\wolf\Downloads\suz

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
AlternateDataStreams: C:\ProgramData\TEMP:5CB1E0D3

RemoveProxy:
CustomCLSID: HKU\S-1-5-21-3743286084-892125646-1870079314-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\Users\wolf\AppData\Local\Temp\15F0\temp\KMS Activator for Microsoft Office 2010 Applications x86  (the data entry has 41 more characters).
Task: {67120933-6112-4DCF-B895-65B202498218} - System32\Tasks\SmartHues => c:\programdata\{f520581b-bf18-7f31-f520-0581bbf1606e}\kms activator for microsoft office 2010 applications x86 x64 multilingual-fixiso~dibya.exe [2014-06-28] () <==== ATTENTION
Task: {A08F80F7-F59D-4A83-B050-82119709E46C} - System32\Tasks\Uninstaller_SkipUac_wolf => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {BB31A55E-AD51-439C-B0A8-F0A57EADA0B6} - System32\Tasks\Driver Booster SkipUAC (wolf) => C:\Program Files\IObit\Driver Booster\DriverBooster.exe
Task: C:\Windows\Tasks\SmartHues.job => c:\programdata\{f520581b-bf18-7f31-f520-0581bbf1606e}\kms activator for microsoft office 2010 applications x86 x64 multilingual-fixiso~dibya.exe <==== ATTENTION

EmptyTemp:
End


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Neke od gore navedenih programa sam uspeo da deinstaliram a neke ne, ostali su delovi, to sam slikao i nalepio slike gore.....vidim da su obrisani iz sistemskih fajlova..... ne znam da li je završio FIX, restartovao je ali posle toga nije nastavio. evo sadržaja loga...

Fix result of Farbar Recovery Scan Tool (x86) Version: 28-06-2015
Ran by wolf at 2015-06-28 23:29:33 Run:1
Running from C:\Users\wolf\Desktop
Loaded Profiles: wolf (Available Profiles: wolf & Administrator)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
VerifySignature: C:\Windows\System32\tssk.sys
File: C:\Windows\system32\themeservice.dll
File: C:\Windows\System32\tssk.sys
Folder: C:\Users\wolf\AppData\Local\GWX
Folder: C:\ProgramData\TEMP
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: typo c:\resetlog.txt

CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.hotsearches.info/?

pid=20176&r=201.....S&unqvl=90
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\Software\Microsoft\Internet Explorer\Main,Start Page =

http://websearch.hotsearches.info/?pid=20176&r=201.....S&unqvl=90
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL =

http://websearch.hotsearches.info/?l=1&q={searchTerms}

&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q=

{searchTerms}&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-

73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}

&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
SearchScopes: HKU\S-1-5-21-3743286084-892125646-1870079314-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL =

http://websearch.hotsearches.info/?l=1&q={searchTerms}

&pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90
BHO: bestadblocker -> {08B2EB20-DA0D-42A4-8E43-EDB856C0FEAE} -> C:\Program Files\bestadblocker\0maq0ouNkI1Bdd.dll

[2015-06-28] ()
BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\PROGRA~1\IObit

\SURFIN~1\BROWER~1\ASCPLU~1.DLL No File
BHO: No Name -> {F33A2581-69F5-47A2-8753-E791B9DE281F} -> No File
FF DefaultSearchEngine,S: WebSearch
FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?

pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF SelectedSearchEngine: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Keyword.URL: hxxp://websearch.hotsearches.info/?

pid=20176&r=2015/06/28&hid=10316168558987199969&lg=EN&cc=RS&unqvl=90&l=1&q=
CHR HKLM\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files\IObit\Surfing Protection

\BrowerProtect\ASC_GhromePluginFor6.crx [Not Found]
R2 ed78fbc6; c:\Program Files\ProcessProc\ProcessProc.dll [2630144 2015-06-28] () [File not signed]
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [X]

Hosts:
C:\Program Files\bestadblocker
C:\Program Files\IObit
c:\Program Files\ProcessProc
C:\Program Files\Google
2015-06-28 19:39 - 2015-06-28 19:39 - 00000000 ____D C:\Program Files\ProcessProc
2015-06-28 19:37 - 2015-06-28 22:22 - 00000000 ____D C:\Program Files\bestadblocker
2015-06-28 19:36 - 2015-06-28 19:38 - 00000000 ____D C:\ProgramData\18386483835372826866
2015-06-28 19:36 - 2015-06-28 19:36 - 00000000 ____D C:\Program Files\CutThePriicea
2015-06-28 19:35 - 2015-06-28 19:35 - 00000484 _____ C:\Windows\Tasks\SmartHues.job
2015-06-28 19:35 - 2015-06-28 19:35 - 00000000 ____D C:\ProgramData\{f520581b-bf18-7f31-f520-0581bbf1606e}
2015-06-28 19:34 - 2015-06-28 19:34 - 00000000 ____D C:\Users\wolf\AppData\Roaming\systweak
2015-06-28 18:03 - 2015-06-28 18:09 - 00000000 ____D C:\Users\wolf\Downloads\suz

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
AlternateDataStreams: C:\ProgramData\TEMP:5CB1E0D3

RemoveProxy:
CustomCLSID: HKU\S-1-5-21-3743286084-892125646-1870079314-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-

7D1476CD1EF5}\localserver32 -> C:\Users\wolf\AppData\Local\Temp\15F0\temp\KMS Activator for Microsoft Office 2010

Applications x86 (the data entry has 41 more characters).
Task: {67120933-6112-4DCF-B895-65B202498218} - System32\Tasks\SmartHues => c:\programdata\{f520581b-bf18-7f31-f520

-0581bbf1606e}\kms activator for microsoft office 2010 applications x86 x64 multilingual-fixiso~dibya.exe [2014-06

-28] () <==== ATTENTION
Task: {A08F80F7-F59D-4A83-B050-82119709E46C} - System32\Tasks\Uninstaller_SkipUac_wolf => C:\Program Files\IObit

\IObit Uninstaller\IObitUninstaler.exe
Task: {BB31A55E-AD51-439C-B0A8-F0A57EADA0B6} - System32\Tasks\Driver Booster SkipUAC (wolf) => C:\Program Files

\IObit\Driver Booster\DriverBooster.exe
Task: C:\Windows\Tasks\SmartHues.job => c:\programdata\{f520581b-bf18-7f31-f520-0581bbf1606e}\kms activator for

microsoft office 2010 applications x86 x64 multilingual-fixiso~dibya.exe <==== ATTENTION

EmptyTemp:
End
*****************

Restore point was successfully created.
"C:\Windows\System32\tssk.sys" => File is digitaly signed.

========================= File: C:\Windows\system32\themeservice.dll ========================

MD5: 59CFDA4EACB3788F8B17F87B49B0AC0E
Creation and modification date: 2009-07-14 01:39 - 2014-12-26 19:18
Size: 0037376
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: THEMESERVICE
Original Name: THEMESERVICE.DLL.MUI
Product Name: Microsoft® Windows® Operating System
Description: Windows Shell Theme Service Dll
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright$creamod: © Microsoft Corporation. All rights reserved.

====== End of File: ======


========================= File: C:\Windows\System32\tssk.sys ========================

MD5: 2E3CC606AE30D3FE4D2CC2DBE1A5AC5F
Creation and modification date: 2015-05-08 15:18 - 2015-05-08 15:17
Size: 0067896
Attributes: ----A
Company Name: 电脑管家
Internal Name: TSSK.sys
Original Name: TSSK
Product Name: 电脑管家
Description: 电脑管家-TSSK Driver
File Version: 10.8.16208.227
Product Version: 10,8,16208,227
Copyright$creamod: Copyright ? 2015 Tencent. All Rights Reserved.

====== End of File: ======


========================= Folder: C:\Users\wolf\AppData\Local\GWX ========================

2015-06-01 11:13 - 2015-06-07 09:50 - 0000071 _____ () C:\Users\wolf\AppData\Local\GWX\TelemetryStore.xml
2015-06-01 11:13 - 2015-06-01 11:13 - 0000000 _____ () C:\Users\wolf\AppData\Local\GWX\TelemetryStore.xml.lock

====== End of Folder: ======


========================= Folder: C:\ProgramData\TEMP ========================


====== End of Folder: ======


========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f =========

Operacija je uspeçno dovrçena.



========= End of Reg: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully.

========= netsh advfirewall reset =========

Ok.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Ok.


========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= netsh int ip reset c:\resetlog.txt =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= ipconfig /release =========


Windows IP Configuration

No operation can be performed on Wireless Network Connection 5 while it has its media disconnected.
No operation can be performed on Wireless Network Connection 4 while it has its media disconnected.
An error occurred while releasing interface Local Area Connection : Sistem ne mo�e da prona�e navedenu datoteku.


Wireless LAN adapter Wireless Network Connection 5:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :

Wireless LAN adapter Wireless Network Connection 4:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::b499:9696:772:41dc%17
Default Gateway . . . . . . . . . :

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::c1ad:ff98:7a8c:11c1%11
Default Gateway . . . . . . . . . :

========= End of CMD: =========


========= ipconfig /renew =========


Windows IP Configuration

No operation can be performed on Wireless Network Connection 5 while it has its media disconnected.
No operation can be performed on Wireless Network Connection 4 while it has its media disconnected.
An error occurred while renewing interface Local Area Connection : Sistem ne mo�e da prona�e navedenu datoteku.


Wireless LAN adapter Wireless Network Connection 5:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :

Wireless LAN adapter Wireless Network Connection 4:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::b499:9696:772:41dc%17
IPv4 Address. . . . . . . . . . . : 192.168.1.8
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::c1ad:ff98:7a8c:11c1%11
Default Gateway . . . . . . . . . :

========= End of CMD: =========


========= typo c:\resetlog.txt =========

'typo' is not recognized as an internal or external command,
operable program or batch file.

========= End of CMD: =========

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value

restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}" => key removed

successfully.
HKCR\CLSID\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE} => key not found.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope

=> value removed successfully.
"HKU\S-1-5-21-3743286084-892125646-1870079314-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-

BC4C-4172-9AC4-73315F71CFFE}" => key removed successfully.
HKCR\CLSID\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08B2EB20-DA0D-42A4-8E43-

EDB856C0FEAE}" => key removed successfully.
"HKCR\CLSID\{08B2EB20-DA0D-42A4-8E43-EDB856C0FEAE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-

E2E7EF20C814}" => key removed successfully.
HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-

8BDE245DC7E6}" => key removed successfully.
"HKCR\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F33A2581-69F5-47A2-8753-

E791B9DE281F}" => key removed successfully.
HKCR\CLSID\{F33A2581-69F5-47A2-8753-E791B9DE281F} => key not found.
Firefox DefaultSearchEngine,S removed successfully.
Firefox DefaultSearchUrl removed successfully.
Firefox SearchEngineOrder.1 removed successfully.
Firefox SearchEngineOrder.1,S removed successfully.
Firefox SelectedSearchEngine removed successfully.
Firefox SelectedSearchEngine,S removed successfully.
Firefox Keyword.URL removed successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd" => key removed successfully.
ed78fbc6 => Service removed successfully.
gupdate => Service removed successfully.
gupdatem => Service removed successfully.
LiveUpdateSvc => Service removed successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
C:\Program Files\bestadblocker => moved successfully.
"C:\Program Files\IObit" => File/Folder not found.
c:\Program Files\ProcessProc => moved successfully.
C:\Program Files\Google => moved successfully.
"C:\Program Files\ProcessProc" => File/Folder not found.
"C:\Program Files\bestadblocker" => File/Folder not found.
C:\ProgramData\18386483835372826866 => moved successfully.
C:\Program Files\CutThePriicea => moved successfully.
C:\Windows\Tasks\SmartHues.job => moved successfully.
C:\ProgramData\{f520581b-bf18-7f31-f520-0581bbf1606e} => moved successfully.
C:\Users\wolf\AppData\Roaming\systweak => moved successfully.
C:\Users\wolf\Downloads\suz => moved successfully.
C:\Windows => ":nlsPreferences" ADS removed successfully..
C:\ProgramData\TEMP => ":56E2E879" ADS removed successfully..
C:\ProgramData\TEMP => ":5CB1E0D3" ADS removed successfully..

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings =>

value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value

removed successfully.
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings

\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-3743286084-892125646-1870079314-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings

\Connections\\SavedLegacySettings => value removed successfully.


========= End of RemoveProxy: =========

"HKU\S-1-5-21-3743286084-892125646-1870079314-1000_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}" => key

removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{67120933-6112-4DCF-B895-65B202498218}"

=> key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67120933-6112-4DCF-B895-65B202498218}"

=> key removed successfully.
C:\Windows\System32\Tasks\SmartHues => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartHues" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A08F80F7-F59D-4A83-B050-82119709E46C}"

=> key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A08F80F7-F59D-4A83-B050-82119709E46C}"

=> key removed successfully.
C:\Windows\System32\Tasks\Uninstaller_SkipUac_wolf => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_wolf" => key removed

successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BB31A55E-AD51-439C-B0A8-F0A57EADA0B6}"

=> key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB31A55E-AD51-439C-B0A8-F0A57EADA0B6}"

=> key removed successfully.
C:\Windows\System32\Tasks\Driver Booster SkipUAC (wolf) => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (wolf)" => key

removed successfully.
C:\Windows\Tasks\SmartHues.job not found.
EmptyTemp: => 38.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 23:31:03 ====

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Sledeci korak. Postavi log pa se pisemo sutra.









Preuzmi smeenk-ov zoek () sa ovog linka i sačuvaj ga na Desktop.
Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


Klikni na More Options dugme i stikliraj polje ispred sledece opcije:
Auto Clean
Napomena: Stikliraj samo navedenu opciju, ostale opcije ne dirati ! !


Klikni na dugme i pričekaj da se skeniranje završi.
zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)

Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

posle prethodnog koraka je problem koji sam ima je nestao , evo loga drugog koraka;


Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by wolf on pon 29.06.2015 at 10:27:00,55.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\wolf\Desktop\zoek.exe [Scan all users] [Checkboxes used]

==== System Restore Info ======================

29.6.2015 10:28:51 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\Program Files\ABBYY FineReader 6.0 deleted successfully
C:\Program Files\Application Assistance deleted successfully
C:\Program Files\SUPERAntiSpyware deleted successfully
C:\Program Files\uTorrent deleted successfully
C:\Program Files\Common Files\IObit deleted successfully
C:\PROGRA~2\Connect Manager deleted successfully
C:\PROGRA~2\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\PROGRA~2\NVIDIA Corporation deleted successfully
C:\PROGRA~2\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted successfully
C:\PROGRA~2\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} deleted successfully
C:\Users\wolf\AppData\Roaming\Mariaglorum deleted successfully
C:\Users\wolf\AppData\Roaming\NVIDIA deleted successfully
C:\Users\wolf\AppData\Roaming\Publish Providers deleted successfully
C:\Users\wolf\AppData\Local\VS Revo Group deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Program Files\ABBYY FineReader 6.0 not found
C:\Program Files\Application Assistance not found
C:\Program Files\SUPERAntiSpyware not found
C:\Program Files\uTorrent not found
C:\PROGRA~2\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} not found
C:\PROGRA~2\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} not found
C:\Users\wolf\AppData\Roaming\AlawarEntertainment deleted
C:\Users\wolf\AppData\Roaming\ProductData deleted
C:\PROGRA~2\APN deleted
C:\PROGRA~2\ProductData deleted
C:\PROGRA~2\Package Cache deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Windows\system32\GroupPolicy\Machine deleted
C:\Windows\system32\GroupPolicy\User deleted
C:\Windows\system32\GroupPolicy\gpt.ini deleted
C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default\Extensions\zzoomit@zoom.com deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default
user_pref("browser.startup.homepage", "https://www.google.rs/");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{338950EA-82DB-44C1-930D-0C28E023C9F0}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [07.02.2015 23:04]

==== Firefox Extensions ======================

ProfilePath: C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default
- RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
- Mozilla Firefox Hotfixer - %ProfilePath%\extensions\veggy@veggyAddon.com

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\wolf\AppData\Roaming\Mozilla\Firefox\Profiles\x28ikosk.default
DC26A2A219E08DE10320E8B7D5433690 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
E42650C972D21F334EB0D3264941DCD7 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
52CE0DBFD9738AE528CF525A0367EBEB - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
252949179FE1C491B7D16A9AA376B29B - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealPlayer Video Downloader for HTML5 (32-bit)
2D9D8D860B7EB6AB150E04267C9CC633 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
780819305925EA7F9393A5640BC42F95 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
94A3088646C777CE99C3C1D7809C4BAC - C:\Program Files\Nitro\Pro 9\npnitromozilla.dll - Nitro PDF plugin for Firefox and Chrome
F0E80E561C3F715DB01ACCC97B72463A - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery
073A22FDCDAFD513DAD0D972BD2DF76E - C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll - Silverlight Plug-In
CA808688B28D12B368F9A511FC5E3697 - C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U45
B28862688B70415A3C0C5DCC8B242388 - C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.450.15
2820FF3A306D6AEB8BFBBB753BD83EBE - C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_194.dll - Shockwave Flash
6D23BB87BCF88731959BF79082D442E6 - C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrlui.dll - Microsoft® Silverlight
0C21CB9426AD831DB02FB66232B3A42F - C:\Program Files\Nitro\Pro 9\NPShellExtension.dll - Nitro Pro ShellExtension
6900B96FDD37E5C08FE0AEF0C542F103 - C:\Program Files\Nitro\Pro 9\npdf.dll - FileOpen WebPublisher3+ MSO Security exchange
7B31592F0D472146865BF096CCD34798 - C:\Program Files\Nitro\Pro 9\npnitroie.dll - Nitro PDF plugin for Internet Explorer


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\wolf\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{96AD2236-D99D-43F7-A3D3-44C4E939111C} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"

==== Deleting Registry Keys ======================

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACDSeeCommanderPro8 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter deleted successfully

==== Empty IE Cache ======================

C:\Users\wolf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\wolf\AppData\Local\Mozilla\Firefox\Profiles\x28ikosk.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=49 folders=26 15406819 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\wolf\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\wolf\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on pon 29.06.2015 at 10:50:13,57 ======================

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

To bi bilo to. Sistem i browseri su dezinfikovani, problem resen. Sada mozes da instaliras Google Chrome ako tako zelis. Odradimo jos dodatnu, brzu AntiRootKit proveru i da privedemo slucaj kraju.


Preuzmi TDSSKiller, sacuvaj alat na Desktop i dvoklikom pokreni TDSSKiller.exe
U "End user Licence Agreement" dijalogu klikni na Accept.
Takođe, u "KSN Statement" dijalogu klikni na Accept.


klikni na dugme Start Scan

Ukoliko sumnjive stavke Suspicious object budu detektovani, podrazumevana opcija (default action) jeste Skip, klikni na Continue.
Ukoliko maliciozni objekti Malicious objects budu detektovani, izaberi opciju Cure.

Okaci mi sadrzaj log-a sa sledece lokacije:
C:\TDSSKiller_verzija programa_DD.MM.GG_HH.MM.SS.txt
(DD-dan, MM-mesec, GG-godina, HH-sat, MM-minut, SS-sekunda; datum i vreme kada je log napravljen)

offline
  • Pridružio: 01 Mar 2008
  • Poruke: 245

Napisano: 29 Jun 2015 15:05

15:02:05.0402 0x06d8 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
15:02:14.0441 0x06d8 ============================================================
15:02:14.0441 0x06d8 Current date / time: 2015/06/29 15:02:14.0441
15:02:14.0441 0x06d8 SystemInfo:
15:02:14.0441 0x06d8
15:02:14.0441 0x06d8 OS Version: 6.1.7601 ServicePack: 1.0
15:02:14.0441 0x06d8 Product type: Workstation
15:02:14.0441 0x06d8 ComputerName: WOLF-PC
15:02:14.0441 0x06d8 UserName: wolf
15:02:14.0441 0x06d8 Windows directory: C:\Windows
15:02:14.0441 0x06d8 System windows directory: C:\Windows
15:02:14.0441 0x06d8 Processor architecture: Intel x86
15:02:14.0441 0x06d8 Number of processors: 3
15:02:14.0441 0x06d8 Page size: 0x1000
15:02:14.0441 0x06d8 Boot type: Normal boot
15:02:14.0441 0x06d8 ============================================================
15:02:17.0207 0x06d8 KLMD registered as C:\Windows\system32\drivers\44468500.sys
15:02:17.0855 0x06d8 System UUID: {0D2B90AA-DD70-9A4A-9A8A-ED701182E18A}
15:02:19.0079 0x06d8 Drive \Device\Harddisk0\DR0 - Size: 0x3A38A25E00 ( 232.88 Gb ), SectorSize: 0x200, Cylinders: 0x7E2D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
15:02:19.0079 0x06d8 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0CADE00 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
15:02:19.0079 0x06d8 ============================================================
15:02:19.0079 0x06d8 \Device\Harddisk0\DR0:
15:02:19.0079 0x06d8 MBR partitions:
15:02:19.0079 0x06d8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
15:02:19.0079 0x06d8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x140A3000
15:02:19.0102 0x06d8 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x140D5CDF, BlocksNum 0x90EA9E1
15:02:19.0102 0x06d8 \Device\Harddisk1\DR1:
15:02:19.0102 0x06d8 MBR partitions:
15:02:19.0102 0x06d8 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x3C6C9780
15:02:19.0118 0x06d8 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x3C6CD6BF, BlocksNum 0x38038302
15:02:19.0118 0x06d8 ============================================================
15:02:19.0204 0x06d8 C: <-> \Device\Harddisk0\DR0\Partition2
15:02:19.0243 0x06d8 D: <-> \Device\Harddisk0\DR0\Partition3
15:02:19.0258 0x06d8 E: <-> \Device\Harddisk1\DR1\Partition1
15:02:19.0282 0x06d8 F: <-> \Device\Harddisk1\DR1\Partition2
15:02:19.0282 0x06d8 ============================================================
15:02:19.0282 0x06d8 Initialize success
15:02:19.0282 0x06d8 ============================================================
15:02:28.0680 0x0e44 ============================================================
15:02:28.0680 0x0e44 Scan started
15:02:28.0680 0x0e44 Mode: Manual;
15:02:28.0680 0x0e44 ============================================================
15:02:28.0680 0x0e44 KSN ping started
15:02:42.0493 0x0e44 KSN ping finished: true
15:02:43.0907 0x0e44 ================ Scan system memory ========================
15:02:43.0907 0x0e44 System memory - ok
15:02:43.0907 0x0e44 ================ Scan services =============================
15:02:44.0086 0x0e44 [ 411C39EE2498232ACAF102668117109B, 0BB2C2F6F19FBB3CC26DEECA3D32276C530E98B90BE2B389223135691753140C ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
15:02:44.0094 0x0e44 1394ohci - ok
15:02:44.0172 0x0e44 [ 97E93A2D8C9D0F72F1C1A34D764A6C63, FCC43E27920BCBF41935224F4FFBB0B6C1FD50D9BD6EE3D7119D80CBE7A77CBE ] ACPI C:\Windows\system32\drivers\ACPI.sys
15:02:44.0188 0x0e44 ACPI - ok
15:02:44.0211 0x0e44 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
15:02:44.0211 0x0e44 AcpiPmi - ok
15:02:44.0336 0x0e44 [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
15:02:44.0344 0x0e44 AdobeARMservice - ok
15:02:44.0407 0x0e44 [ 6259A5B669AE018A5E53247259A101C3, 1CD2102FAF1DCEB6B8278D098A7C1A85ED6D6E5DCF7F70E0E9A5166B67C8D057 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:02:44.0422 0x0e44 AdobeFlashPlayerUpdateSvc - ok
15:02:44.0469 0x0e44 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
15:02:44.0500 0x0e44 adp94xx - ok
15:02:44.0540 0x0e44 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\drivers\adpahci.sys
15:02:44.0563 0x0e44 adpahci - ok
15:02:44.0586 0x0e44 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\drivers\adpu320.sys
15:02:44.0610 0x0e44 adpu320 - ok
15:02:44.0649 0x0e44 [ 12E6A172D72AFC626727B8635DD17E39, 33B3D109C39DF6EA86AFC3C89A93657906E981D3D22FF854401BC7326990CC08 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
15:02:44.0649 0x0e44 AeLookupSvc - ok
15:02:44.0696 0x0e44 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\Windows\system32\drivers\afd.sys
15:02:44.0727 0x0e44 AFD - ok
15:02:44.0750 0x0e44 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
15:02:44.0750 0x0e44 agp440 - ok
15:02:44.0790 0x0e44 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\drivers\djsvs.sys
15:02:44.0797 0x0e44 aic78xx - ok
15:02:44.0844 0x0e44 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
15:02:44.0844 0x0e44 ALG - ok
15:02:44.0883 0x0e44 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
15:02:44.0883 0x0e44 aliide - ok
15:02:44.0938 0x0e44 [ 64710E6C92C0D3893EDBDA84FBCD3188, 06FF1242CECA94260E66C00EAFEE6AC338DD500EB35A3F46F7473AEA546922DE ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
15:02:44.0954 0x0e44 AMD External Events Utility - ok
15:02:44.0969 0x0e44 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
15:02:44.0977 0x0e44 amdagp - ok
15:02:44.0993 0x0e44 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys
15:02:44.0993 0x0e44 amdide - ok
15:02:45.0016 0x0e44 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
15:02:45.0016 0x0e44 AmdK8 - ok
15:02:45.0758 0x0e44 [ 83240DBD6E44CC207B95D1EBB085E3A7, DD29B4F21D22D5DD7DC6F965EEADB40B958934301C74178AC3B0CB2AA59D3808 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
15:02:46.0461 0x0e44 amdkmdag - ok
15:02:46.0547 0x0e44 [ B6DB3BDF2CF56C60ED497104653B8A5C, 8C48866134828336EE287802B1AE6D419D97D15D71CAD12911255EF5CEFFB5A7 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
15:02:46.0563 0x0e44 amdkmdap - ok
15:02:46.0586 0x0e44 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
15:02:46.0586 0x0e44 AmdPPM - ok
15:02:46.0618 0x0e44 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys
15:02:46.0625 0x0e44 amdsata - ok
15:02:46.0665 0x0e44 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
15:02:46.0680 0x0e44 amdsbs - ok
15:02:46.0704 0x0e44 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
15:02:46.0711 0x0e44 amdxata - ok
15:02:46.0750 0x0e44 [ 548CCBD8B48FDF7E2435AD6017920A7F, E79257CA143AF8E08CFF85E68C5D9C010150788DBC0924D5B25C1562A11EEE6C ] Apowersoft_AudioDevice C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys
15:02:46.0750 0x0e44 Apowersoft_AudioDevice - ok
15:02:46.0790 0x0e44 [ DF1FD3855004E4731D16C207E5EEECB0, A02C2918BD7933661E8303CE60B07F8C89E0BC5AF541D68D61B1F1BB695D6150 ] AppID C:\Windows\system32\drivers\appid.sys
15:02:46.0797 0x0e44 AppID - ok
15:02:46.0821 0x0e44 [ 390F3C9F7ACDDE08A557E1DCAEBBEBB7, 27E0C02D27A9D582B4C926E2EB96A46FF8B6909030D81122415C136BE4216E71 ] AppIDSvc C:\Windows\System32\appidsvc.dll
15:02:46.0821 0x0e44 AppIDSvc - ok
15:02:46.0852 0x0e44 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll
15:02:46.0852 0x0e44 Appinfo - ok
15:02:46.0883 0x0e44 [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll
15:02:46.0891 0x0e44 AppMgmt - ok
15:02:46.0907 0x0e44 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\drivers\arc.sys
15:02:46.0915 0x0e44 arc - ok
15:02:46.0930 0x0e44 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\drivers\arcsas.sys
15:02:46.0930 0x0e44 arcsas - ok
15:02:46.0961 0x0e44 [ 6E5B37EFC8BB04B55C5E417C893D839B, 2B0175DAFBA61573DE4D360DE1E5B76243E97B51D01D165E7EC33B299BC3AF7D ] asmthub3 C:\Windows\system32\drivers\asmthub3.sys
15:02:46.0961 0x0e44 asmthub3 - ok
15:02:46.0985 0x0e44 [ 0DDB9502E990C770E383B7A758E2B7DF, D819C4A6E91078ACB115821287E67C68E257FC5E28C921532F8BA5B601B84773 ] asmtxhci C:\Windows\system32\drivers\asmtxhci.sys
15:02:47.0000 0x0e44 asmtxhci - ok
15:02:47.0079 0x0e44 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
15:02:47.0079 0x0e44 aspnet_state - ok
15:02:47.0118 0x0e44 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
15:02:47.0118 0x0e44 AsyncMac - ok
15:02:47.0157 0x0e44 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
15:02:47.0157 0x0e44 atapi - ok
15:02:47.0196 0x0e44 [ 04F1A13265313C0E0A4F9D8C2CDC0F76, 8EB81405CFFAD619CAD6FDD8F62AF66AA1741A4EA38D6C4DF9A3151E8C35AFF7 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
15:02:47.0204 0x0e44 AtiHDAudioService - ok
15:02:47.0258 0x0e44 [ F9C24D25D9FF29F894995A64812B4D85, 3430E4EE1F7D185E269AF220C96BCA55143BA7C3A28262240F4D30DD1810A38C ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
15:02:47.0258 0x0e44 atksgt - ok
15:02:47.0321 0x0e44 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:02:47.0344 0x0e44 AudioEndpointBuilder - ok
15:02:47.0383 0x0e44 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv C:\Windows\System32\Audiosrv.dll
15:02:47.0407 0x0e44 Audiosrv - ok
15:02:47.0446 0x0e44 [ 06C6E8F88E79E01C883043E25B99DB43, 4D928D707F46614B4AA30900D4C26F4ED44152D8C421911F871E38C45979CA06 ] AxInstSV C:\Windows\System32\AxInstSV.dll
15:02:47.0454 0x0e44 AxInstSV - ok
15:02:47.0508 0x0e44 [ 07EA834FAD4AB6CBFBF4C580EC95E0C2, A9A352B1E5415A63F9E25D799F314575E6FD4CDCAF9C3595338DAB7EBEB4498D ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys
15:02:47.0540 0x0e44 b06bdrv - ok
15:02:47.0563 0x0e44 [ 260965B13B51B112F365FC11DD3C429A, 8851E3E63235B345CA193EC96F135AED86C7866B9DA56F162D1C10742E28D31F ] b06diag C:\Windows\system32\drivers\bxdiagx.sys
15:02:47.0563 0x0e44 b06diag - ok
15:02:47.0586 0x0e44 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
15:02:47.0602 0x0e44 b57nd60x - ok
15:02:47.0625 0x0e44 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
15:02:47.0633 0x0e44 BDESVC - ok
15:02:47.0649 0x0e44 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
15:02:47.0649 0x0e44 Beep - ok
15:02:47.0704 0x0e44 [ CDF46BFB74EC0DAB0849037D91E0DCFC, F5C8EEE34C07F4256A5A8D8C771626691B9C0CAFB850FCA51F9EE7A394E88129 ] BFE C:\Windows\System32\bfe.dll
15:02:47.0727 0x0e44 BFE - ok
15:02:47.0758 0x0e44 [ 675BAB5FEAD17D2800B58C31F5113B66, F5D0332DF332A775695ABDD4A790524904C0B63A3254FD98D5EE9078AD332561 ] BFN7x86 C:\Windows\system32\drivers\Xeno7x86.sys
15:02:47.0758 0x0e44 BFN7x86 - ok
15:02:47.0774 0x0e44 [ E2D17A2FA5EDEF495222AA25F02F0E34, 01160BA21FFBB80256A57E84879FB86472E1DF77433F2CC64DBF979AC2A660BB ] BFNVis32 C:\Windows\system32\drivers\XenoVx86.sys
15:02:47.0782 0x0e44 BFNVis32 - ok
15:02:47.0829 0x0e44 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\System32\qmgr.dll
15:02:47.0860 0x0e44 BITS - ok
15:02:47.0883 0x0e44 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
15:02:47.0891 0x0e44 blbdrive - ok
15:02:47.0915 0x0e44 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:02:47.0922 0x0e44 bowser - ok
15:02:47.0946 0x0e44 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
15:02:47.0946 0x0e44 BrFiltLo - ok
15:02:47.0961 0x0e44 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
15:02:47.0969 0x0e44 BrFiltUp - ok
15:02:47.0993 0x0e44 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll
15:02:47.0993 0x0e44 Browser - ok
15:02:48.0040 0x0e44 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
15:02:48.0063 0x0e44 Brserid - ok
15:02:48.0086 0x0e44 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
15:02:48.0094 0x0e44 BrSerWdm - ok
15:02:48.0110 0x0e44 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
15:02:48.0110 0x0e44 BrUsbMdm - ok
15:02:48.0125 0x0e44 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
15:02:48.0125 0x0e44 BrUsbSer - ok
15:02:48.0165 0x0e44 [ 22EB06B1955FA33E2AEED3175585B90B, D9706E53A3F54455264B3B45A266B3D3B81420FD8B48F1820E0F7799492E0634 ] Btcsrusb C:\Windows\system32\Drivers\btcusb.sys
15:02:48.0172 0x0e44 Btcsrusb - ok
15:02:48.0211 0x0e44 [ 2865A5C8E98C70C605F417908CEBB3A4, B1C5AC228BD7072AF8668C009C6CDC13EE9FCB9481F57524300F37C40BF1E935 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
15:02:48.0219 0x0e44 BthEnum - ok
15:02:48.0243 0x0e44 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
15:02:48.0243 0x0e44 BTHMODEM - ok
15:02:48.0274 0x0e44 [ AD1872E5829E8A2C3B5B4B641C3EAB0E, 8C2DBCAC08DDB41E2B44E257C55FA2D0272959B308EFF9EAF5FF9AE1E4A0AA39 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
15:02:48.0282 0x0e44 BthPan - ok
15:02:48.0329 0x0e44 [ 1153DE2E4F5941E10C399CB5592F78A1, 2B88AF246D62F72FA9F5B921B0375AE59A0F263672472D5EC9FDB5CA5EF51C31 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
15:02:48.0344 0x0e44 BTHPORT - ok
15:02:48.0391 0x0e44 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
15:02:48.0399 0x0e44 bthserv - ok
15:02:48.0422 0x0e44 [ C81E9413A25A439F436B1D4B6A0CF9E9, A4C290163207AED22C70C7F90B28F6FC24892889643D60D915059405AC5A4A72 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
15:02:48.0430 0x0e44 BTHUSB - ok
15:02:48.0477 0x0e44 [ E28E93545A215E4F045C9FF795F13136, 7A1ADDB995D9ABB58D7DBB6A128D0D7C960AAE56120AD8B2F3A776D8588068E3 ] BXOIS C:\Windows\system32\drivers\bxois.sys
15:02:48.0516 0x0e44 BXOIS - ok
15:02:48.0540 0x0e44 [ 53D2CFA25D9DF05EDADBF2A9023A4DEA, 99D5A68DB5903F61999DC725436EEF234D4C639F0A3AE1D3C99CBC752EF72723 ] cbaf C:\Windows\System32\Drivers\cbaf.sys
15:02:48.0540 0x0e44 cbaf - ok
15:02:48.0563 0x0e44 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:02:48.0571 0x0e44 cdfs - ok
15:02:48.0602 0x0e44 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
15:02:48.0610 0x0e44 cdrom - ok
15:02:48.0633 0x0e44 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
15:02:48.0641 0x0e44 CertPropSvc - ok
15:02:48.0665 0x0e44 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\drivers\circlass.sys
15:02:48.0665 0x0e44 circlass - ok
15:02:48.0696 0x0e44 [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS C:\Windows\system32\CLFS.sys
15:02:48.0711 0x0e44 CLFS - ok
15:02:48.0766 0x0e44 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:02:48.0774 0x0e44 clr_optimization_v2.0.50727_32 - ok
15:02:48.0813 0x0e44 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:02:48.0821 0x0e44 clr_optimization_v4.0.30319_32 - ok
15:02:48.0844 0x0e44 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
15:02:48.0844 0x0e44 CmBatt - ok
15:02:48.0883 0x0e44 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
15:02:48.0883 0x0e44 cmdide - ok
15:02:48.0930 0x0e44 [ 8ADF8A3E63601BD185DE6BB459AF47F5, CCB06AFA9668CE934D899AA3FF505FF2EC0F5B640B388BD3172B9DC27940EAB6 ] CNG C:\Windows\system32\Drivers\cng.sys
15:02:48.0954 0x0e44 CNG - ok
15:02:48.0977 0x0e44 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\drivers\compbatt.sys
15:02:48.0977 0x0e44 Compbatt - ok
15:02:49.0000 0x0e44 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
15:02:49.0008 0x0e44 CompositeBus - ok
15:02:49.0016 0x0e44 COMSysApp - ok
15:02:49.0094 0x0e44 cpuz137 - ok
15:02:49.0118 0x0e44 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
15:02:49.0118 0x0e44 crcdisk - ok
15:02:49.0165 0x0e44 [ B97E16D36DB7B7DD22C97857506FA58A, 30D14F68904379B8B57B1EEB37B5986A831D3F767918ACD9E29D479F38B9F289 ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:02:49.0180 0x0e44 CryptSvc - ok
15:02:49.0204 0x0e44 [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC C:\Windows\system32\drivers\csc.sys
15:02:49.0227 0x0e44 CSC - ok
15:02:49.0274 0x0e44 [ 631E8D7C440C001FADB0FF2D5FB5ACFB, FD527722BD12C0F56610876E578D5AC2B8B561142C37E1FB1A3E4075FFCCA904 ] CscService C:\Windows\System32\cscsvc.dll
15:02:49.0297 0x0e44 CscService - ok
15:02:49.0336 0x0e44 [ FAFD0AE107BF665CB457608831814B0C, 1E28AB18DC4D46335267C37445AC73EE37BAF7F81202121FD61209F825E0DAF0 ] DcomLaunch C:\Windows\system32\rpcss.dll
15:02:49.0352 0x0e44 DcomLaunch - ok
15:02:49.0391 0x0e44 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
15:02:49.0415 0x0e44 defragsvc - ok
15:02:49.0422 0x0e44 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
15:02:49.0422 0x0e44 DfsC - ok
15:02:49.0461 0x0e44 [ 80AFE83D3B9CE2B31F2EBAA10C13F4BF, 7041AC34FF55722462ABA83E5ABA82B8797502C4F18F1E204C3C7A8A5BB62B53 ] dfuuwb C:\Windows\System32\Drivers\DfuUWB.sys
15:02:49.0485 0x0e44 dfuuwb - ok
15:02:49.0524 0x0e44 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
15:02:49.0540 0x0e44 Dhcp - ok
15:02:49.0633 0x0e44 [ 7AB2DE012C88870C9274E966EC88AB61, CE2098B152B9C039C29C0573C813BFBF13B2D2E6BEE83985374160884A817133 ] DiagTrack C:\Windows\system32\diagtrack.dll
15:02:49.0688 0x0e44 DiagTrack - ok
15:02:49.0782 0x0e44 [ F5DF96342ACC1CFB5C55DEA9BF812DFD, 75D012E74F4037AC14036A304603B5DBD2A4BBB0B3BCAD4DC254BCF1B42E22E7 ] Disc Soft Bus Service C:\Program Files\DAEMON Tools Ultra\DiscSoftBusService.exe
15:02:49.0844 0x0e44 Disc Soft Bus Service - ok
15:02:49.0868 0x0e44 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
15:02:49.0875 0x0e44 discache - ok
15:02:49.0899 0x0e44 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\drivers\disk.sys
15:02:49.0899 0x0e44 Disk - ok
15:02:49.0922 0x0e44 [ 2A958EF85DB1B61FFCA65044FA4BCE9E, C83511685EE1CE85A5ADF9B5BE96C375A521601F66024BDC3EE044C0B6E85D69 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
15:02:49.0930 0x0e44 dmvsc - ok
15:02:49.0946 0x0e44 [ C941FD3429EA406D14266F671EC5B4A7, 61A85515AD639A9D47F9A72FA825D80CF462F36C4F244A95A44ED137F082B8A8 ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:02:49.0954 0x0e44 Dnscache - ok
15:02:49.0977 0x0e44 [ DCAD2BDC526AE53BEED47BEAD703D144, 70071C81266E020CC4BD22785E610D5F431A08038535EB387B567BBB05632654 ] dot3svc C:\Windows\System32\dot3svc.dll
15:02:49.0993 0x0e44 dot3svc - ok
15:02:50.0024 0x0e44 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
15:02:50.0032 0x0e44 DPS - ok
15:02:50.0063 0x0e44 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
15:02:50.0063 0x0e44 drmkaud - ok
15:02:50.0086 0x0e44 [ 50778FE9ED67AEB01EA99877B1B4A4DF, 67B094D260A270F2444160BA3F83A1CCEFEBD33E5085DB5C1BD21E8B1F445493 ] dtscsibus C:\Windows\system32\DRIVERS\dtscsibus.sys
15:02:50.0086 0x0e44 dtscsibus - ok
15:02:50.0157 0x0e44 [ B1234153466969A433AD39B58E9A4820, B7F029FCCB07AEB2EF4AFCE8EB0428DAEEA926713A9C3433F77A74D4D881612A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:02:50.0204 0x0e44 DXGKrnl - ok
15:02:50.0219 0x0e44 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
15:02:50.0219 0x0e44 EapHost - ok
15:02:50.0360 0x0e44 [ 16CFF939DEE99B82AF86A52BC808AB16, 9533522C0AA283ACDB254CFC6A5A77897B1BC408B544FECEF5F02DF5A50415A4 ] ebdrv C:\Windows\system32\drivers\evbdx.sys
15:02:50.0469 0x0e44 ebdrv - ok
15:02:50.0493 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] EFS C:\Windows\System32\lsass.exe
15:02:50.0493 0x0e44 EFS - ok
15:02:50.0571 0x0e44 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
15:02:50.0602 0x0e44 ehRecvr - ok
15:02:50.0625 0x0e44 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
15:02:50.0633 0x0e44 ehSched - ok
15:02:50.0688 0x0e44 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\drivers\elxstor.sys
15:02:50.0711 0x0e44 elxstor - ok
15:02:50.0735 0x0e44 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
15:02:50.0735 0x0e44 ErrDev - ok
15:02:50.0758 0x0e44 [ 6AA41A73DF56CAC2004DDED5D530A578, B2B742A96A4BE98D7E6A660387A03A92AF696970B0D438621DCE1296D7AF6A75 ] ETD C:\Windows\system32\drivers\ETD.sys
15:02:50.0758 0x0e44 ETD - ok
15:02:50.0774 0x0e44 [ F252ECC4E4554CC455A917FF16FBD2B7, B861DB53760FB70A5EB75B24453F2B87167F05A781A90034860E836266AEFFBD ] EtronHub3 C:\Windows\System32\Drivers\EtronHub3.sys
15:02:50.0782 0x0e44 EtronHub3 - ok
15:02:50.0790 0x0e44 [ EBE0A6A662364E099BCF9AE6B678DB90, C01686D11138D31D556A22EA08297BE5948E0E5F88F98390987B3E045563DA8B ] EtronXHCI C:\Windows\System32\Drivers\EtronXHCI.sys
15:02:50.0797 0x0e44 EtronXHCI - ok
15:02:50.0836 0x0e44 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
15:02:50.0844 0x0e44 EventSystem - ok
15:02:50.0875 0x0e44 ew_usbenumfilter - ok
15:02:50.0891 0x0e44 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
15:02:50.0899 0x0e44 exfat - ok
15:02:50.0930 0x0e44 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:02:50.0946 0x0e44 fastfat - ok
15:02:50.0977 0x0e44 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
15:02:50.0993 0x0e44 Fax - ok
15:02:51.0024 0x0e44 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\drivers\fdc.sys
15:02:51.0032 0x0e44 fdc - ok
15:02:51.0055 0x0e44 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
15:02:51.0055 0x0e44 fdPHost - ok
15:02:51.0094 0x0e44 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
15:02:51.0102 0x0e44 FDResPub - ok
15:02:51.0118 0x0e44 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:02:51.0125 0x0e44 FileInfo - ok
15:02:51.0133 0x0e44 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:02:51.0141 0x0e44 Filetrace - ok
15:02:51.0157 0x0e44 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
15:02:51.0165 0x0e44 flpydisk - ok
15:02:51.0188 0x0e44 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:02:51.0196 0x0e44 FltMgr - ok
15:02:51.0274 0x0e44 [ 6EC244F102C7F129678E5F7309D1366D, C30DA201AC623DA440B0A0716534557C578218C2A591FA8893CCCBD96B4518F9 ] FontCache C:\Windows\system32\FntCache.dll
15:02:51.0329 0x0e44 FontCache - ok
15:02:51.0383 0x0e44 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
15:02:51.0383 0x0e44 FontCache3.0.0.0 - ok
15:02:51.0407 0x0e44 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
15:02:51.0415 0x0e44 FsDepends - ok
15:02:51.0438 0x0e44 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:02:51.0438 0x0e44 Fs_Rec - ok
15:02:51.0469 0x0e44 [ AAE37F0F2F613218DCE17B42A18C38DB, 3C235370054E1AB3EFD6E59825B38F63F6B861025ABFE05CAC940B56D17D25BC ] FTDIBUS C:\Windows\system32\drivers\ftdibus.sys
15:02:51.0469 0x0e44 FTDIBUS - ok
15:02:51.0500 0x0e44 [ 48BFD1BA45C9C9E7AB339E25ABFBA1D2, 950F5C1A6FD00E0AABD090753781729EFFF8157525D0DD127864C27E0F7F21FA ] FTSER2K C:\Windows\system32\drivers\ftser2k.sys
15:02:51.0500 0x0e44 FTSER2K - ok
15:02:51.0555 0x0e44 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
15:02:51.0571 0x0e44 fvevol - ok
15:02:51.0602 0x0e44 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
15:02:51.0602 0x0e44 gagp30kx - ok
15:02:51.0665 0x0e44 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
15:02:51.0696 0x0e44 gpsvc - ok
15:02:51.0719 0x0e44 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
15:02:51.0727 0x0e44 hcw85cir - ok
15:02:51.0766 0x0e44 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
15:02:51.0766 0x0e44 HDAudBus - ok
15:02:51.0790 0x0e44 [ 30D57EE84E1E169D41A6E873B549A096, 3473AF4A8B651E27ADC91BEC3AF379196ECB7525D768D7984D1FCF67A322116B ] HECI C:\Windows\system32\drivers\HECI.sys
15:02:51.0797 0x0e44 HECI - ok
15:02:51.0805 0x0e44 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
15:02:51.0805 0x0e44 HidBatt - ok
15:02:51.0844 0x0e44 [ 72B8842C548A9584329690867FCA8B0E, 003351B4AA893738ED0440601A51C9CCE72972F94188C9DB00097D511BCAAC3C ] HidBth C:\Windows\system32\drivers\hidbth.sys
15:02:51.0852 0x0e44 HidBth - ok
15:02:51.0883 0x0e44 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\drivers\hidir.sys
15:02:51.0883 0x0e44 HidIr - ok
15:02:51.0907 0x0e44 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll
15:02:51.0915 0x0e44 hidserv - ok
15:02:51.0946 0x0e44 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
15:02:51.0954 0x0e44 HidUsb - ok
15:02:51.0977 0x0e44 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
15:02:51.0985 0x0e44 hkmsvc - ok
15:02:52.0008 0x0e44 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:02:52.0016 0x0e44 HomeGroupListener - ok
15:02:52.0047 0x0e44 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:02:52.0055 0x0e44 HomeGroupProvider - ok
15:02:52.0079 0x0e44 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
15:02:52.0086 0x0e44 HpSAMD - ok
15:02:52.0133 0x0e44 [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:02:52.0165 0x0e44 HTTP - ok
15:02:52.0172 0x0e44 huawei_enumerator - ok
15:02:52.0204 0x0e44 [ 7F8590B4B3CEDC9C691F587BF847E0DB, 464CAF8D4DDFA95BCE41577E85C0803A42B00885372012EC5B2DA0B75C4F894F ] HWA C:\Windows\System32\Drivers\HWA.sys
15:02:52.0211 0x0e44 HWA - ok
15:02:52.0250 0x0e44 [ 6FFB351C9C9BB88E91785F4CD7396D31, 699DA017B48CD0531174ACFE1EB74F09D5B55FC62FF0C5D77EB21256BE692854 ] HWiNFO32 C:\Windows\system32\drivers\HWiNFO32.SYS
15:02:52.0250 0x0e44 HWiNFO32 - ok
15:02:52.0258 0x0e44 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
15:02:52.0258 0x0e44 hwpolicy - ok
15:02:52.0274 0x0e44 hwusb_cdcacm - ok
15:02:52.0274 0x0e44 hwusb_wwanecm - ok
15:02:52.0297 0x0e44 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
15:02:52.0297 0x0e44 i8042prt - ok
15:02:52.0321 0x0e44 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
15:02:52.0344 0x0e44 iaStorV - ok
15:02:52.0430 0x0e44 [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:02:52.0485 0x0e44 idsvc - ok
15:02:52.0508 0x0e44 IEEtwCollectorService - ok
15:02:52.0540 0x0e44 [ 45DAC45438C9BFDDF8F2E6734F3EC89A, B77ABFCCFE439AB4DF254E7140E75CDE3D0808DAFDA3AC58780450BF44720B89 ] IFCoEMP C:\Windows\system32\drivers\ifM60x32.sys
15:02:52.0555 0x0e44 IFCoEMP - ok
15:02:52.0586 0x0e44 [ B6F742A0DDE9E97DCC34B5AB73A771C5, 4CE998E15AABA3737FEBDC40FAE32C9205078A9AACF5BFF885CF972D9BFE9895 ] IFCoEVB C:\Windows\system32\drivers\ifP60X32.sys
15:02:52.0586 0x0e44 IFCoEVB - ok
15:02:52.0610 0x0e44 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\drivers\iirsp.sys
15:02:52.0618 0x0e44 iirsp - ok
15:02:52.0696 0x0e44 [ BCDC3A3706221E62D27DDA50EC251F36, 5CFAB7A8D494E54D9418CE681672A9870555DB67C8638E9DA63C98CA9B1E9031 ] IKEEXT C:\Windows\System32\ikeext.dll
15:02:52.0719 0x0e44 IKEEXT - ok
15:02:52.0750 0x0e44 [ E3C36AC5AE87EC970AE8EA2A93D59AE1, 8403A5243DF38EFC35A0200760EC081E42467744AF25A1F2168D5A8198AF6A5B ] Impcd C:\Windows\system32\drivers\Impcd.sys
15:02:52.0758 0x0e44 Impcd - ok
15:02:52.0915 0x0e44 [ B29B6E4992DB5536463536C288A1F835, 3BB14BC6B5324D8DB3E13E4FC432E52A8406FFC14FB9FF5A702AF9DC4266CB6E ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
15:02:53.0063 0x0e44 IntcAzAudAddService - ok
15:02:53.0094 0x0e44 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
15:02:53.0094 0x0e44 intelide - ok
15:02:53.0102 0x0e44 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\drivers\intelppm.sys
15:02:53.0102 0x0e44 intelppm - ok
15:02:53.0133 0x0e44 [ 10411032B74715E251293CA44FD4F467, 14E360825F130CC8F43491001EBFC4ADB177EBAC1AA74C85E52EE11134093396 ] ioatdma1 C:\Windows\System32\Drivers\qd16032.sys
15:02:53.0133 0x0e44 ioatdma1 - ok
15:02:53.0157 0x0e44 [ 99A13B19A5958F285536E8516FD33669, 5C1F4C69FB2F8E562D054F1772B72DF33CA96EFCDF3EBFDA183CEAB15EA326C1 ] ioatdma2 C:\Windows\System32\Drivers\qd26032.sys
15:02:53.0157 0x0e44 ioatdma2 - ok
15:02:53.0196 0x0e44 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
15:02:53.0196 0x0e44 IPBusEnum - ok
15:02:53.0227 0x0e44 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:02:53.0227 0x0e44 IpFilterDriver - ok
15:02:53.0274 0x0e44 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:02:53.0297 0x0e44 iphlpsvc - ok
15:02:53.0329 0x0e44 [ D38A50ED76F309C75591FDFA427E2997, 7B783A451B5C57E80F703BEF7FB3F40C0D91DE89266E92309ACE8711B0CF20B3 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
15:02:53.0336 0x0e44 IPMIDRV - ok
15:02:53.0344 0x0e44 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
15:02:53.0352 0x0e44 IPNAT - ok
15:02:53.0375 0x0e44 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:02:53.0375 0x0e44 IRENUM - ok
15:02:53.0391 0x0e44 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
15:02:53.0391 0x0e44 isapnp - ok
15:02:53.0422 0x0e44 [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
15:02:53.0446 0x0e44 iScsiPrt - ok
15:02:53.0477 0x0e44 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
15:02:53.0477 0x0e44 kbdclass - ok
15:02:53.0500 0x0e44 [ 056B425B6E108632DAF3FEF267CEF7A6, 936A343F85C39DB606384001D3B4694D58A3A891B3F5D1865412D88C933D0787 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
15:02:53.0500 0x0e44 kbdhid - ok
15:02:53.0516 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] KeyIso C:\Windows\system32\lsass.exe
15:02:53.0524 0x0e44 KeyIso - ok
15:02:53.0555 0x0e44 [ 17920ED7800719A18630003C80EC0F70, 0A6AFE14407E698D8D0DF3D1CFE92884BC4D74AC7059B27E733CF15D702C68DC ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:02:53.0563 0x0e44 KSecDD - ok
15:02:53.0579 0x0e44 [ 48D00D913540F177C67D11302FDDA0D3, EDE129E8EBD07FF2972F9406B4FF1FF44CB2F13AC16CB737786C7000D8B51DB7 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
15:02:53.0594 0x0e44 KSecPkg - ok
15:02:53.0641 0x0e44 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
15:02:53.0657 0x0e44 KtmRm - ok
15:02:53.0704 0x0e44 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\system32\srvsvc.dll
15:02:53.0704 0x0e44 LanmanServer - ok
15:02:53.0735 0x0e44 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:02:53.0743 0x0e44 LanmanWorkstation - ok
15:02:53.0790 0x0e44 [ 8CCF9ED46D52AF1375875F74A91FFACF, 43A38AE17D054C88176C7F1527CAA0D45AB0AC429C1C0440D9F2DECE0F90C058 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
15:02:53.0790 0x0e44 lirsgt - ok
15:02:53.0813 0x0e44 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
15:02:53.0821 0x0e44 lltdio - ok
15:02:53.0852 0x0e44 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:02:53.0868 0x0e44 lltdsvc - ok
15:02:53.0891 0x0e44 lmab_device - ok
15:02:53.0907 0x0e44 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
15:02:53.0907 0x0e44 lmhosts - ok
15:02:53.0938 0x0e44 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
15:02:53.0946 0x0e44 LSI_FC - ok
15:02:53.0961 0x0e44 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
15:02:53.0969 0x0e44 LSI_SAS - ok
15:02:53.0977 0x0e44 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
15:02:53.0985 0x0e44 LSI_SAS2 - ok
15:02:53.0993 0x0e44 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
15:02:54.0000 0x0e44 LSI_SCSI - ok
15:02:54.0024 0x0e44 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
15:02:54.0024 0x0e44 luafv - ok
15:02:54.0047 0x0e44 lxbk_device - ok
15:02:54.0094 0x0e44 [ B4CD87E78A01562E3DA67FE1C2779204, 536AC01C53A18E7B43F02F345FC3088C189A2D01F5E060714C0534FE7ECA2356 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
15:02:54.0094 0x0e44 MBAMProtector - ok
15:02:54.0235 0x0e44 [ 301E3FDFCF33640BB8763BA444BC5093, 362B069BB9A313A06B376CE27E6F7F8D569F6CA39A8ABC96D9DF231EE462C604 ] MBAMScheduler C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
15:02:54.0321 0x0e44 MBAMScheduler - ok
15:02:54.0407 0x0e44 [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
15:02:54.0454 0x0e44 MBAMService - ok
15:02:54.0493 0x0e44 [ 739164A8B8FB2F1B50A498F20AF7B21E, 8E7A387C3726A863BF251E638D072FA472B698EF6868E9A7A00EF1272F809C64 ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
15:02:54.0500 0x0e44 MBAMSwissArmy - ok
15:02:54.0524 0x0e44 [ 490F0F3ED8A970E2BAA38F719242B8F7, 03F902365372639424AB654AEBF6EB2B6B73363275435ADC2D086EAA7112AC3D ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
15:02:54.0532 0x0e44 MBAMWebAccessControl - ok
15:02:54.0563 0x0e44 [ 8FD868E32459ECE2A1BB0169F513D31E, F28E47FBEC8EC8424FFFB359668E0FEEA66A69E9D737D75472934FAC39770390 ] mcdbus C:\Windows\system32\drivers\mcdbus.sys
15:02:54.0571 0x0e44 mcdbus - ok
15:02:54.0602 0x0e44 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
15:02:54.0610 0x0e44 Mcx2Svc - ok
15:02:54.0633 0x0e44 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\drivers\megasas.sys
15:02:54.0633 0x0e44 megasas - ok
15:02:54.0657 0x0e44 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
15:02:54.0680 0x0e44 MegaSR - ok
15:02:54.0704 0x0e44 [ 30D57EE84E1E169D41A6E873B549A096, 3473AF4A8B651E27ADC91BEC3AF379196ECB7525D768D7984D1FCF67A322116B ] MEI C:\Windows\system32\drivers\HECI.sys
15:02:54.0704 0x0e44 MEI - ok
15:02:54.0758 0x0e44 Microsoft SharePoint Workspace Audit Service - ok
15:02:54.0774 0x0e44 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
15:02:54.0782 0x0e44 MMCSS - ok
15:02:54.0797 0x0e44 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
15:02:54.0805 0x0e44 Modem - ok
15:02:54.0829 0x0e44 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
15:02:54.0829 0x0e44 monitor - ok
15:02:54.0852 0x0e44 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\drivers\mouclass.sys
15:02:54.0860 0x0e44 mouclass - ok
15:02:54.0883 0x0e44 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\drivers\mouhid.sys
15:02:54.0883 0x0e44 mouhid - ok
15:02:54.0915 0x0e44 [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
15:02:54.0954 0x0e44 mountmgr - ok
15:02:55.0047 0x0e44 [ 9FC679D10A7377BB04ECC3D0E2E26B53, 24ACD4EC1618A052C29E4463138B28F62C8B78D442DB82F4925E64FC5849A096 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
15:02:55.0071 0x0e44 MozillaMaintenance - ok
15:02:55.0141 0x0e44 [ F112DA773EC3E9D3CDE9221ED300E033, 693C416B281DA3489C096812D0E4E0413C05798D36AF534624C3B29551CE68A4 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
15:02:55.0157 0x0e44 MpFilter - ok
15:02:55.0188 0x0e44 [ 295D096AEB9E3E62BE6DA40778275976, DF8EBB986D308800B44A4CC0475FD0A5DE01CD046629CFA84E8BA9626901EFA9 ] mpio C:\Windows\system32\drivers\mpio.sys
15:02:55.0196 0x0e44 mpio - ok
15:02:55.0290 0x0e44 [ BB7BB66A8DAF16950F83AE7BF498AF8F, A96FC3BE055C52B98E7ECDF68D69081620F829B04B5496C73D87F271E40EA638 ] MpKsl5080800e C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B1D8D5C4-B7D3-4F47-BC4B-993B22969241}\MpKsl5080800e.sys
15:02:55.0297 0x0e44 MpKsl5080800e - ok
15:02:55.0313 0x0e44 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
15:02:55.0321 0x0e44 mpsdrv - ok
15:02:55.0375 0x0e44 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll
15:02:55.0399 0x0e44 MpsSvc - ok
15:02:55.0438 0x0e44 [ 1C3EBF74425637371DD208B67381A949, 0E4E7C1DDCCC4435FA26889B0F9C13EDE863FC506C71E26A90479E180DE0ADC4 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
15:02:55.0438 0x0e44 MRxDAV - ok
15:02:55.0469 0x0e44 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
15:02:55.0477 0x0e44 mrxsmb - ok
15:02:55.0508 0x0e44 [ AC8EB88C4176892062CF7A8952943662, C91191751329A136D5CEEF2E07CADC1A1A6C46C224E78B874E467E401254B0DA ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:02:55.0516 0x0e44 mrxsmb10 - ok
15:02:55.0540 0x0e44 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:02:55.0540 0x0e44 mrxsmb20 - ok
15:02:55.0563 0x0e44 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys
15:02:55.0563 0x0e44 msahci - ok
15:02:55.0586 0x0e44 [ 60B7B332BB86C4F313C7D4CF8D3A830C, CA5924C10128E9E2A528C39D5278EA00F7DB1AD9D0648D36665B9FA6BB07A737 ] msdsm C:\Windows\system32\drivers\msdsm.sys
15:02:55.0594 0x0e44 msdsm - ok
15:02:55.0618 0x0e44 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
15:02:55.0625 0x0e44 MSDTC - ok
15:02:55.0657 0x0e44 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
15:02:55.0665 0x0e44 Msfs - ok
15:02:55.0680 0x0e44 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
15:02:55.0680 0x0e44 mshidkmdf - ok
15:02:55.0688 0x0e44 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
15:02:55.0696 0x0e44 msisadrv - ok
15:02:55.0727 0x0e44 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
15:02:55.0735 0x0e44 MSiSCSI - ok
15:02:55.0735 0x0e44 msiserver - ok
15:02:55.0766 0x0e44 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
15:02:55.0766 0x0e44 MSKSSRV - ok
15:02:55.0821 0x0e44 [ CC09BB7FDEFC5763CCB3CF7DAE2D76CF, F8F00900EDBA2F64BF136DD0B6C83CAF07C72F24F3D49C78B7EA24757FDBC6D0 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
15:02:55.0821 0x0e44 MsMpSvc - ok
15:02:55.0844 0x0e44 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
15:02:55.0844 0x0e44 MSPCLOCK - ok
15:02:55.0852 0x0e44 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
15:02:55.0860 0x0e44 MSPQM - ok
15:02:55.0875 0x0e44 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
15:02:55.0883 0x0e44 MsRPC - ok
15:02:55.0899 0x0e44 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
15:02:55.0899 0x0e44 mssmbios - ok
15:02:55.0922 0x0e44 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
15:02:55.0922 0x0e44 MSTEE - ok
15:02:55.0938 0x0e44 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
15:02:55.0946 0x0e44 MTConfig - ok
15:02:55.0954 0x0e44 [ D48659BB24C48345D926ECB45C1EBDF5, EDEDE58316827530C25F8085F62AD48EA6D44B0F8AC1917B940F53B02CF72EA6 ] MTsensor C:\Windows\system32\drivers\ASACPI.sys
15:02:55.0954 0x0e44 MTsensor - ok
15:02:55.0969 0x0e44 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
15:02:55.0977 0x0e44 Mup - ok
15:02:56.0008 0x0e44 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll
15:02:56.0016 0x0e44 napagent - ok
15:02:56.0055 0x0e44 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
15:02:56.0079 0x0e44 NativeWifiP - ok
15:02:56.0133 0x0e44 [ 15B74B6283CEBCCE3054C1001CA01B5E, 7AAABC641D1444437ED8762EF0F52E1E2EEA858AFB18B7CBDB05851D07AD2E1D ] NDIS C:\Windows\system32\drivers\ndis.sys
15:02:56.0165 0x0e44 NDIS - ok
15:02:56.0188 0x0e44 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
15:02:56.0188 0x0e44 NdisCap - ok
15:02:56.0219 0x0e44 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:02:56.0227 0x0e44 NdisTapi - ok
15:02:56.0258 0x0e44 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
15:02:56.0258 0x0e44 Ndisuio - ok
15:02:56.0282 0x0e44 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
15:02:56.0290 0x0e44 NdisWan - ok
15:02:56.0313 0x0e44 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
15:02:56.0313 0x0e44 NDProxy - ok
15:02:56.0329 0x0e44 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
15:02:56.0336 0x0e44 NetBIOS - ok
15:02:56.0360 0x0e44 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
15:02:56.0360 0x0e44 NetBT - ok
15:02:56.0383 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] Netlogon C:\Windows\system32\lsass.exe
15:02:56.0383 0x0e44 Netlogon - ok
15:02:56.0415 0x0e44 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
15:02:56.0430 0x0e44 Netman - ok
15:02:56.0469 0x0e44 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
15:02:56.0485 0x0e44 NetMsmqActivator - ok
15:02:56.0500 0x0e44 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
15:02:56.0508 0x0e44 NetPipeActivator - ok
15:02:56.0547 0x0e44 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
15:02:56.0563 0x0e44 netprofm - ok
15:02:56.0657 0x0e44 [ 7CCE4FF6D485D7DDF2D83F1DB148323B, 7B1140A9CDCBD158C7714CCC340B2B678197D84D0E9622F0DFDC81283D4C4125 ] netr28u C:\Windows\system32\DRIVERS\netr28u.sys
15:02:56.0719 0x0e44 netr28u - ok
15:02:56.0727 0x0e44 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
15:02:56.0735 0x0e44 NetTcpActivator - ok
15:02:56.0743 0x0e44 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
15:02:56.0743 0x0e44 NetTcpPortSharing - ok
15:02:56.0766 0x0e44 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
15:02:56.0774 0x0e44 nfrd960 - ok
15:02:56.0805 0x0e44 [ 780FF28BCD8470C5FDDEEF69982AA295, 1ED386E87E0AA733F23D554D2BF4EF4168DB9A419B7BA0BA8FBA20F118BE21DF ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
15:02:56.0805 0x0e44 NisDrv - ok
15:02:56.0844 0x0e44 [ 3FF257F54649D4F19E39263C5D581CD1, 1F201EEE770A452AA30C6270AAA456A77F9F3A102F473E12C22D3B8809932C1B ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
15:02:56.0860 0x0e44 NisSrv - ok
15:02:56.0915 0x0e44 [ 4313A9C8FB224FBB17A348BA7E6E4431, DCCB4FDFEC221AC14E0BF22C9B2C11F81B08F4CE4670B66308A541E3C3FB56B7 ] NitroDriverReadSpool9 C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
15:02:56.0930 0x0e44 NitroDriverReadSpool9 - ok
15:02:56.0977 0x0e44 [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc C:\Windows\System32\nlasvc.dll
15:02:56.0993 0x0e44 NlaSvc - ok
15:02:57.0024 0x0e44 [ 33E4FEAC832AA2DC8BE339C652C3657E, F05F4F44B19C22876F63C2174E292C675CB6A222D40E63F49896CE734C87FEE8 ] nlsX86cc C:\Windows\system32\NLSSRV32.EXE
15:02:57.0024 0x0e44 nlsX86cc - ok
15:02:57.0063 0x0e44 [ 712BC0C22BA00B2BA324C6B8DF668EE7, 037D760539D860D501EDD78BCC7469CBAC92DBC8DD49A472410DA897B2101A5A ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
15:02:57.0063 0x0e44 nmwcd - ok
15:02:57.0102 0x0e44 [ 7312987B6CCDE6F6CEE32C14BED1CA2E, ED109675B8AE4229104791D749F1B4834B82BD425B1AA4E2E75E96E203A3CD20 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
15:02:57.0102 0x0e44 nmwcdc - ok
15:02:57.0118 0x0e44 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
15:02:57.0118 0x0e44 Npfs - ok
15:02:57.0141 0x0e44 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
15:02:57.0149 0x0e44 nsi - ok
15:02:57.0165 0x0e44 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
15:02:57.0165 0x0e44 nsiproxy - ok
15:02:57.0274 0x0e44 [ 90EE3C4BD199287D2630C5232F459367, E517FCCCA5BE615C439F814823B5A06295635844E81B6B827E63A9A6308593FC ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
15:02:57.0329 0x0e44 Ntfs - ok
15:02:57.0352 0x0e44 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
15:02:57.0352 0x0e44 Null - ok
15:02:57.0375 0x0e44 [ BAD636EE7FF5BF539854BBA33868EFC2, 338B87D7826829196645923AEDFF3387397CDBFD49F336D11B7CCECF31B558A1 ] nusb3hub C:\Windows\system32\drivers\nusb3hub.sys
15:02:57.0375 0x0e44 nusb3hub - ok
15:02:57.0407 0x0e44 [ DFAFDC3051E04FFAFDDC4872394C1FC8, F58FB4A7143A8B2B4D0733CBE2030DA365E4A4472CCB236341D4F015333F5C76 ] nusb3xhc C:\Windows\system32\drivers\nusb3xhc.sys
15:02:57.0422 0x0e44 nusb3xhc - ok
15:02:57.0446 0x0e44 [ BC9795F928C1775286E207F55F4870CD, 7289B6D92A447DA77646F42374F86AD0D95BD4C32F702F41695A31FBBB984AF9 ] nvamacpi C:\Windows\system32\drivers\NVAMACPI.sys
15:02:57.0446 0x0e44 nvamacpi - ok
15:02:57.0500 0x0e44 [ 8196A84583185499F3E8C20FFDAF36D6, D456FC4ACBBAA9B1075622A59D858CCBB5465807ED5DB512D731007A0875BCC9 ] NVNET C:\Windows\system32\DRIVERS\nvmf6232.sys
15:02:57.0516 0x0e44 NVNET - ok
15:02:57.0555 0x0e44 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys
15:02:57.0563 0x0e44 nvraid - ok
15:02:57.0579 0x0e44 [ F13618F0CB1E95232F4C2401592A59E9, 119C8075536D4C3602754E680574B0E18C813E9FE5555B2B854F3A6E768C22D0 ] nvsmu C:\Windows\system32\drivers\nvsmu.sys
15:02:57.0579 0x0e44 nvsmu - ok
15:02:57.0602 0x0e44 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
15:02:57.0610 0x0e44 nvstor - ok
15:02:57.0633 0x0e44 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
15:02:57.0641 0x0e44 nv_agp - ok
15:02:57.0665 0x0e44 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
15:02:57.0665 0x0e44 ohci1394 - ok
15:02:57.0704 0x0e44 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:02:57.0711 0x0e44 ose - ok
15:02:57.0961 0x0e44 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
15:02:58.0110 0x0e44 osppsvc - ok
15:02:58.0165 0x0e44 [ 38BEA463EF49BC314C1167E5246E48A9, 51371E412515292E53876B59268140727E66A1F3F2CCC88DDDED7B2340525C51 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
15:02:58.0180 0x0e44 p2pimsvc - ok
15:02:58.0219 0x0e44 [ A664AFCAC636466AFBE7C16F9841A4BA, 362217991E4BF5B1683A7594E95FE8D813167462E68573251B78624D24E4AF34 ] p2psvc C:\Windows\system32\p2psvc.dll
15:02:58.0235 0x0e44 p2psvc - ok
15:02:58.0266 0x0e44 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
15:02:58.0274 0x0e44 Parport - ok
15:02:58.0305 0x0e44 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys
15:02:58.0305 0x0e44 partmgr - ok
15:02:58.0321 0x0e44 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
15:02:58.0321 0x0e44 Parvdm - ok
15:02:58.0352 0x0e44 [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc C:\Windows\System32\pcasvc.dll
15:02:58.0352 0x0e44 PcaSvc - ok
15:02:58.0399 0x0e44 [ FD2041E9BA03DB7764B2248F02475079, DECEED110524BF83B4097188BF24BF0DDE1CE838DF7748B0DC807ABE351EB20A ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
15:02:58.0399 0x0e44 pccsmcfd - ok
15:02:58.0422 0x0e44 [ 1A3A608A0FA58B6FFDB61901074CC7C5, 26931139CC849F402034250C279FD3A48CA462F6C1B4DF0B2885D9FDB3C160E0 ] pci C:\Windows\system32\drivers\pci.sys
15:02:58.0438 0x0e44 pci - ok
15:02:58.0461 0x0e44 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
15:02:58.0461 0x0e44 pciide - ok
15:02:58.0493 0x0e44 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
15:02:58.0516 0x0e44 pcmcia - ok
15:02:58.0532 0x0e44 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
15:02:58.0532 0x0e44 pcw - ok
15:02:58.0586 0x0e44 [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
15:02:58.0618 0x0e44 PEAUTH - ok
15:02:58.0665 0x0e44 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
15:02:58.0704 0x0e44 PeerDistSvc - ok
15:02:58.0790 0x0e44 [ BBD76805265483BE78F61D7E5DCBA5FA, 4B43463C6FD61B8736D00E34ABCBD0C17D617D45325D3F8E5BBF932BD7CD57B4 ] pla C:\Windows\system32\pla.dll
15:02:58.0883 0x0e44 pla - ok
15:02:58.0938 0x0e44 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
15:02:58.0946 0x0e44 PlugPlay - ok
15:02:58.0961 0x0e44 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
15:02:58.0969 0x0e44 PNRPAutoReg - ok
15:02:59.0000 0x0e44 [ 38BEA463EF49BC314C1167E5246E48A9, 51371E412515292E53876B59268140727E66A1F3F2CCC88DDDED7B2340525C51 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
15:02:59.0008 0x0e44 PNRPsvc - ok
15:02:59.0055 0x0e44 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
15:02:59.0079 0x0e44 PolicyAgent - ok
15:02:59.0118 0x0e44 [ AC42F771CC29727BD1663F211E9AC507, FA08F63C1A3279EC0FAF9B25E24A9C6CCB63BE415636A1B55A5275AF2BDB317D ] Power C:\Windows\system32\umpo.dll
15:02:59.0125 0x0e44 Power - ok
15:02:59.0157 0x0e44 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
15:02:59.0165 0x0e44 PptpMiniport - ok
15:02:59.0196 0x0e44 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\drivers\processr.sys
15:02:59.0196 0x0e44 Processor - ok
15:02:59.0243 0x0e44 [ EC1C7DD0512A6588ACF3AAF297E2297D, 1A3F92EFF3EA6D67DDA77C0DADDACB5AD79288EF77854C166174E8601E1788F8 ] ProfSvc C:\Windows\system32\profsvc.dll
15:02:59.0250 0x0e44 ProfSvc - ok
15:02:59.0266 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] ProtectedStorage C:\Windows\system32\lsass.exe
15:02:59.0266 0x0e44 ProtectedStorage - ok
15:02:59.0321 0x0e44 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
15:02:59.0321 0x0e44 Psched - ok
15:02:59.0422 0x0e44 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\drivers\ql2300.sys
15:02:59.0516 0x0e44 ql2300 - ok
15:02:59.0540 0x0e44 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
15:02:59.0547 0x0e44 ql40xx - ok
15:02:59.0571 0x0e44 QMUdisk - ok
15:02:59.0602 0x0e44 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
15:02:59.0618 0x0e44 QWAVE - ok
15:02:59.0633 0x0e44 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
15:02:59.0641 0x0e44 QWAVEdrv - ok
15:02:59.0711 0x0e44 [ F502A4B72524D21C5CA7183E61FB522E, 819B5DF8916776E7ACBFB0FDFBD0CDCFD173E750DF3A16D8462EDA13BB013DE0 ] RalinkRegistryWriter C:\Program Files\Tenda\Common\RaRegistry.exe
15:02:59.0735 0x0e44 RalinkRegistryWriter - ok
15:02:59.0805 0x0e44 [ CBC738221E5B80C4566E4AC0DC16CC8C, 13A2AFCE5D88E49EE509244A780ED30D85CE8F2CB8DA40C7E12B00C33D9743C0 ] RaMediaServer C:\Program Files\Tenda\Common\RaMediaServer.exe
15:02:59.0852 0x0e44 RaMediaServer - ok
15:02:59.0868 0x0e44 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
15:02:59.0875 0x0e44 RasAcd - ok
15:02:59.0915 0x0e44 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
15:02:59.0915 0x0e44 RasAgileVpn - ok
15:02:59.0946 0x0e44 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
15:02:59.0954 0x0e44 RasAuto - ok
15:02:59.0969 0x0e44 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
15:02:59.0969 0x0e44 Rasl2tp - ok
15:02:59.0993 0x0e44 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
15:03:00.0016 0x0e44 RasMan - ok
15:03:00.0032 0x0e44 [ C4AACCECA39AF598DCDB3D9304067569, 73F9ED969135567D62AC02F8310C24DE483558D00741F90F1BF6B7F26971E8E6 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
15:03:00.0032 0x0e44 RasPppoe - ok
15:03:00.0063 0x0e44 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
15:03:00.0063 0x0e44 RasSstp - ok
15:03:00.0086 0x0e44 [ 3DE21D7810540772789732E6DB84C17C, AECD58D7C7253FA07B70AAB86A5116E5B0F6B0002ACB67833CB1F2D45CECA65E ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
15:03:00.0110 0x0e44 rdbss - ok
15:03:00.0125 0x0e44 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
15:03:00.0125 0x0e44 rdpbus - ok
15:03:00.0141 0x0e44 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
15:03:00.0141 0x0e44 RDPCDD - ok
15:03:00.0180 0x0e44 [ 7F881C6D3781CAB9C0E15595BB8696BE, F61A3D82897A34D77930D3B7916206B3D3624044ED94E69CD1A314392A94C553 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
15:03:00.0188 0x0e44 RDPDR - ok
15:03:00.0211 0x0e44 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
15:03:00.0219 0x0e44 RDPENCDD - ok
15:03:00.0227 0x0e44 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
15:03:00.0227 0x0e44 RDPREFMP - ok
15:03:00.0290 0x0e44 [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
15:03:00.0297 0x0e44 RdpVideoMiniport - ok
15:03:00.0336 0x0e44 [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
15:03:00.0352 0x0e44 RDPWD - ok
15:03:00.0383 0x0e44 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
15:03:00.0391 0x0e44 rdyboost - ok
15:03:00.0446 0x0e44 [ 590DE2C0FF4E367050239BD1DDC912C1, B8D1D01C276C15EDA5B6BE5F1FD16315063D1C9BA6D22D51AED51FC93D417A17 ] RealNetworks Downloader Resolver Service C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
15:03:00.0446 0x0e44 RealNetworks Downloader Resolver Service - ok
15:03:00.0586 0x0e44 [ AC36A47C010100B7EDFB2A70114D3E89, 3051841EB4FC8A9CDA5B1B9168D459A639F7E588E859F51D6B865CD073CFCE13 ] RealPlayer Cloud Service C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
15:03:00.0657 0x0e44 RealPlayer Cloud Service - ok
15:03:00.0688 0x0e44 [ A650FA927A4D1D71C53E317A0DDD6B7E, F1D476213CE15E0060440CDBF36806649F172408EC0977A35AEE67F30C43B15A ] RealPlayerUpdateSvc C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
15:03:00.0688 0x0e44 RealPlayerUpdateSvc - ok
15:03:00.0719 0x0e44 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
15:03:00.0719 0x0e44 RemoteAccess - ok
15:03:00.0758 0x0e44 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
15:03:00.0758 0x0e44 RemoteRegistry - ok
15:03:00.0813 0x0e44 [ CB928D9E6DAF51879DD6BA8D02F01321, DFD263B67DDF98AE09AF6D6986CBC7BE3206BCE8403AAC51BCF9459E78233D12 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
15:03:00.0836 0x0e44 RFCOMM - ok
15:03:00.0860 0x0e44 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
15:03:00.0868 0x0e44 RpcEptMapper - ok
15:03:00.0891 0x0e44 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
15:03:00.0899 0x0e44 RpcLocator - ok
15:03:00.0938 0x0e44 [ FAFD0AE107BF665CB457608831814B0C, 1E28AB18DC4D46335267C37445AC73EE37BAF7F81202121FD61209F825E0DAF0 ] RpcSs C:\Windows\system32\rpcss.dll
15:03:00.0961 0x0e44 RpcSs - ok
15:03:00.0977 0x0e44 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
15:03:00.0985 0x0e44 rspndr - ok
15:03:01.0016 0x0e44 [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys
15:03:01.0016 0x0e44 s3cap - ok
15:03:01.0032 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] SamSs C:\Windows\system32\lsass.exe
15:03:01.0032 0x0e44 SamSs - ok
15:03:01.0063 0x0e44 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
15:03:01.0071 0x0e44 sbp2port - ok
15:03:01.0110 0x0e44 [ 4E9B73E60D128E2703EC6E7EA066BB32, E3436F24BAAEE29CBD22926C01EA2330CACEB3F1450AD078F87958845DB6649B ] SCardSvr C:\Windows\System32\SCardSvr.dll
15:03:01.0118 0x0e44 SCardSvr - ok
15:03:01.0141 0x0e44 [ 12784CF1B1E9C3540CC7C83324965277, BC72B292416DDFCD9B5137AEA416B4C24F035E345462801E917E69A8F1EFF1FA ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
15:03:01.0149 0x0e44 scfilter - ok
15:03:01.0204 0x0e44 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
15:03:01.0235 0x0e44 Schedule - ok
15:03:01.0266 0x0e44 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
15:03:01.0274 0x0e44 SCPolicySvc - ok
15:03:01.0305 0x0e44 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
15:03:01.0313 0x0e44 SDRSVC - ok
15:03:01.0360 0x0e44 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
15:03:01.0368 0x0e44 secdrv - ok
15:03:01.0407 0x0e44 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
15:03:01.0407 0x0e44 seclogon - ok
15:03:01.0430 0x0e44 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll
15:03:01.0430 0x0e44 SENS - ok
15:03:01.0454 0x0e44 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
15:03:01.0454 0x0e44 SensrSvc - ok
15:03:01.0485 0x0e44 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
15:03:01.0485 0x0e44 Serenum - ok
15:03:01.0500 0x0e44 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
15:03:01.0508 0x0e44 Serial - ok
15:03:01.0532 0x0e44 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\drivers\sermouse.sys
15:03:01.0532 0x0e44 sermouse - ok
15:03:01.0618 0x0e44 [ DD1328A18712A0B9C9A946EE55A2B1EC, 9DE6E92A6EC38DD477A2EF96D49026E8132E6C7C10D6C8FC6D67E20896906BE9 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
15:03:01.0649 0x0e44 ServiceLayer - ok
15:03:01.0688 0x0e44 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
15:03:01.0696 0x0e44 SessionEnv - ok
15:03:01.0711 0x0e44 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
15:03:01.0719 0x0e44 sffdisk - ok
15:03:01.0735 0x0e44 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
15:03:01.0743 0x0e44 sffp_mmc - ok
15:03:01.0758 0x0e44 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
15:03:01.0766 0x0e44 sffp_sd - ok
15:03:01.0774 0x0e44 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
15:03:01.0774 0x0e44 sfloppy - ok
15:03:01.0813 0x0e44 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
15:03:01.0836 0x0e44 SharedAccess - ok
15:03:01.0883 0x0e44 [ C99E91D09029514F07586307A75A95A6, 462B1D7C497DC7AE70FD8AEB28E33B6B3E5529868E77B4AC64046A57AF41D862 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:03:01.0899 0x0e44 ShellHWDetection - ok
15:03:01.0922 0x0e44 [ 546B935F005E9BB7FEC7B17D42547D0E, 175F93A740A28508FA2653DFA35337B11EA788705E821E66F8ED83333E502F22 ] sisagp C:\Windows\system32\drivers\SISAGPX.sys
15:03:01.0930 0x0e44 sisagp - ok
15:03:01.0954 0x0e44 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
15:03:01.0954 0x0e44 SiSRaid2 - ok
15:03:01.0985 0x0e44 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
15:03:01.0985 0x0e44 SiSRaid4 - ok
15:03:02.0024 0x0e44 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
15:03:02.0024 0x0e44 Smb - ok
15:03:02.0063 0x0e44 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
15:03:02.0063 0x0e44 SNMPTRAP - ok
15:03:02.0102 0x0e44 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
15:03:02.0102 0x0e44 spldr - ok
15:03:02.0149 0x0e44 [ CAE10A25F936C053E41CBE0FA06FF15D, E1641E2723FC92BC1E1F8023AC6174745E1F0E374F4506A0983556E2DD49CB08 ] Spooler C:\Windows\System32\spoolsv.exe
15:03:02.0165 0x0e44 Spooler - ok
15:03:02.0321 0x0e44 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
15:03:02.0477 0x0e44 sppsvc - ok
15:03:02.0508 0x0e44 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
15:03:02.0516 0x0e44 sppuinotify - ok
15:03:02.0540 0x0e44 [ B9526AFE58B0EB537A391DFA925A1E40, 87F27389BEBEA3C66FE899CF560DDED2CF1EC0D27C70EC3D7064A30D401F3B87 ] srv C:\Windows\system32\DRIVERS\srv.sys
15:03:02.0563 0x0e44 srv - ok
15:03:02.0586 0x0e44 [ DBAF2D20FD39EFA9AED654C9E99CE7F5, 3CFFFF65D351CD11BB7F3505495FA9883F7A0958D54BB62B10CCFE7BA500AC7C ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
15:03:02.0602 0x0e44 srv2 - ok
15:03:02.0618 0x0e44 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
15:03:02.0618 0x0e44 srvnet - ok
15:03:02.0641 0x0e44 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
15:03:02.0657 0x0e44 SSDPSRV - ok
15:03:02.0680 0x0e44 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
15:03:02.0688 0x0e44 SstpSvc - ok
15:03:02.0711 0x0e44 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\drivers\stexstor.sys
15:03:02.0711 0x0e44 stexstor - ok
15:03:02.0766 0x0e44 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
15:03:02.0782 0x0e44 StiSvc - ok
15:03:02.0790 0x0e44 [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys
15:03:02.0797 0x0e44 storflt - ok
15:03:02.0813 0x0e44 [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys
15:03:02.0813 0x0e44 storvsc - ok
15:03:02.0829 0x0e44 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
15:03:02.0829 0x0e44 swenum - ok
15:03:02.0946 0x0e44 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
15:03:02.0985 0x0e44 SwitchBoard - ok
15:03:03.0016 0x0e44 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
15:03:03.0040 0x0e44 swprv - ok
15:03:03.0063 0x0e44 [ 16E7642DA4BACCCD7696B326CAA84870, 1A0526A3A270D6201330ED289F4FE17CBBA69FE3CF0AE68236D5F39AF42E0057 ] Synth3dVsc C:\Windows\system32\drivers\Synth3dVsc.sys
15:03:03.0071 0x0e44 Synth3dVsc - ok
15:03:03.0110 0x0e44 [ 90EE01890C857BBB7DFAAD2D99F73D85, B1D4C785D64F9E2DE594145088A94E43FCBCB72F3D953904D3E0634728552D0E ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
15:03:03.0125 0x0e44 SynTP - ok
15:03:03.0188 0x0e44 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
15:03:03.0250 0x0e44 SysMain - ok
15:03:03.0274 0x0e44 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
15:03:03.0290 0x0e44 TabletInputService - ok
15:03:03.0329 0x0e44 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
15:03:03.0344 0x0e44 TapiSrv - ok
15:03:03.0375 0x0e44 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
15:03:03.0383 0x0e44 TBS - ok
15:03:03.0454 0x0e44 [ EA47AB18E289333AB94397D77CA6E3A1, 3DCC320487EA6045B046E332BA751FA43EB45A95F9F61D5A7B7184948DD59E90 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
15:03:03.0563 0x0e44 Tcpip - ok
15:03:03.0633 0x0e44 [ EA47AB18E289333AB94397D77CA6E3A1, 3DCC320487EA6045B046E332BA751FA43EB45A95F9F61D5A7B7184948DD59E90 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
15:03:03.0680 0x0e44 TCPIP6 - ok
15:03:03.0711 0x0e44 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
15:03:03.0719 0x0e44 tcpipreg - ok
15:03:03.0750 0x0e44 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
15:03:03.0750 0x0e44 TDPIPE - ok
15:03:03.0782 0x0e44 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
15:03:03.0782 0x0e44 TDTCP - ok
15:03:03.0813 0x0e44 [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx C:\Windows\system32\DRIVERS\tdx.sys
15:03:03.0813 0x0e44 tdx - ok
15:03:03.0836 0x0e44 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
15:03:03.0844 0x0e44 TermDD - ok
15:03:03.0868 0x0e44 [ E951866BAC5A23403F62A349EDBB6EEB, BE6FB3C09D1CF8952B4D041F45B4DEE53D78EE7D27A5135012BC92B2F7CFBEA3 ] terminpt C:\Windows\system32\drivers\terminpt.sys
15:03:03.0868 0x0e44 terminpt - ok
15:03:03.0930 0x0e44 [ DD01319264B6D19E379BDD079A27DA91, 81A9B57BF5002C500D9C7AAA41ACAE388895FAEC0B693E0BE84703A7C534F0B3 ] TermService C:\Windows\System32\termsrv.dll
15:03:03.0946 0x0e44 TermService - ok
15:03:03.0969 0x0e44 [ 59CFDA4EACB3788F8B17F87B49B0AC0E, 653CE0697A31BA79BE1094601BA3A94912B368E29212AF79288B010D45AD7658 ] Themes C:\Windows\system32\themeservice.dll
15:03:03.0977 0x0e44 Themes - ok
15:03:03.0993 0x0e44 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
15:03:03.0993 0x0e44 THREADORDER - ok
15:03:04.0008 0x0e44 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
15:03:04.0008 0x0e44 TrkWks - ok
15:03:04.0063 0x0e44 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:03:04.0079 0x0e44 TrustedInstaller - ok
15:03:04.0133 0x0e44 [ E10601CF12F9E619BC16A40E962954E9, 7B4697ECC6DDD0A86FEB626B48CAB59BC41B4DDAC7287C8B5F938671DF881D5D ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
15:03:04.0133 0x0e44 tssecsrv - ok
15:03:04.0157 0x0e44 [ 2E3CC606AE30D3FE4D2CC2DBE1A5AC5F, 50CDDB982CF1B14E70C810399D56B1D815FD8D94B89B924810096447F0A0AF4B ] TSSK C:\Windows\system32\tssk.sys
15:03:04.0165 0x0e44 TSSK - ok
15:03:04.0204 0x0e44 [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
15:03:04.0204 0x0e44 TsUsbFlt - ok
15:03:04.0227 0x0e44 [ 01246F0BAAD7B68EC0F472AA41E33282, 51F975AF029AD015576FFFA3E88F5DBB8B40C7CD30ECDEDE8AFABCB08C954199 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
15:03:04.0227 0x0e44 TsUsbGD - ok
15:03:04.0250 0x0e44 [ 045ACB987C650D8186C6B4A692223860, C1CDDF7DABAE531C53290C7C70F35DD65751B399D269711865AD65F9E4E43B0B ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys
15:03:04.0258 0x0e44 tsusbhub - ok
15:03:04.0274 0x0e44 [ F5B8DAD03E1BA3EB875E361385DA9F1F, 43ABC8060CC354F33BA2A2571389C76BEB9CDA0A4C4B540D9FA0FE63490C5E25 ] TTP7 C:\Windows\system32\drivers\ttp7up.sys
15:03:04.0274 0x0e44 TTP7 - ok
15:03:04.0297 0x0e44 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
15:03:04.0305 0x0e44 tunnel - ok
15:03:04.0329 0x0e44 [ 546B935F005E9BB7FEC7B17D42547D0E, 175F93A740A28508FA2653DFA35337B11EA788705E821E66F8ED83333E502F22 ] uagp35 C:\Windows\system32\drivers\sisagpx.sys
15:03:04.0329 0x0e44 uagp35 - ok
15:03:04.0352 0x0e44 [ E604DE37D14C79D9E44DBD585A31F095, 37BF25DD1DB1CA63203239362C0A11F1D03E4C7D90759877C20662A9C13AC754 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
15:03:04.0368 0x0e44 udfs - ok
15:03:04.0391 0x0e44 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
15:03:04.0399 0x0e44 UI0Detect - ok
15:03:04.0422 0x0e44 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
15:03:04.0430 0x0e44 uliagpkx - ok
15:03:04.0454 0x0e44 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
15:03:04.0454 0x0e44 umbus - ok
15:03:04.0469 0x0e44 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\drivers\umpass.sys
15:03:04.0469 0x0e44 UmPass - ok
15:03:04.0485 0x0e44 [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll
15:03:04.0493 0x0e44 UmRdpService - ok
15:03:04.0547 0x0e44 [ BB879DCFD22926EFBEB3298129898CBB, 2A24E6CD5D6E0CEA3082C0699A2371084CC1268B31BC714098EA0D0C11B3AFAC ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
15:03:04.0547 0x0e44 UnlockerDriver5 - ok
15:03:04.0586 0x0e44 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
15:03:04.0610 0x0e44 upnphost - ok
15:03:04.0657 0x0e44 [ 7062ED67A10F1C83B2AB951736E24F11, 97FE9044DA6F903F59652DFAA54033EE892B88D53F709F23B2FB8A8FBE995C1B ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
15:03:04.0657 0x0e44 upperdev - ok
15:03:04.0696 0x0e44 [ 5620619CE693AADF8767CDA00F940BEE, 3B20D7FBDDE8E0E1D36BC444CCFB825380E39F40A63325608A5D1FA385072906 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
15:03:04.0696 0x0e44 usbccgp - ok
15:03:04.0719 0x0e44 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
15:03:04.0727 0x0e44 usbcir - ok
15:03:04.0758 0x0e44 [ 3735F2A99C5EA762D869748333C83CE8, 11EA3D8611A24D3ECDD79BAF7673D94ED1606F6CB4130C72F2C4CB2DB515DA73 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
15:03:04.0758 0x0e44 usbehci - ok
15:03:04.0774 0x0e44 [ 08369F1FDD7C0D4287373D253D64D75E, D937015F3E76F7018C7C943017A0528A9DC48F754342BCD55BD0FBBE98EDF3C2 ] usbfilter C:\Windows\system32\drivers\usbfilter.sys
15:03:04.0782 0x0e44 usbfilter - ok
15:03:04.0805 0x0e44 [ CA349E24ECDE0E0005DAC5A2DC9931A2, 0934033615C2191AE6AAAE7E8FC79EDC33D96D7AD05DFA1A0ACA53FDEA5B7524 ] UsbFltr C:\Windows\system32\drivers\copperhd.sys
15:03:04.0805 0x0e44 UsbFltr - ok
15:03:04.0829 0x0e44 [ 7DE31B21FA92EE427C058C44CEB7859B, A2CB53B01F7277F192AEA23BD2F215CEAD53CC7C09211F98C01D7947948865E0 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
15:03:04.0852 0x0e44 usbhub - ok
15:03:04.0883 0x0e44 [ E83AF87457337D459F48139FAC8A1994, 734B47BFEB6C3E9FED86B91C9E65A048134F891A2BD3BC08A91BF56925461AFB ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
15:03:04.0883 0x0e44 usbohci - ok
15:03:04.0899 0x0e44 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
15:03:04.0899 0x0e44 usbprint - ok
15:03:04.0938 0x0e44 [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
15:03:04.0938 0x0e44 usbscan - ok
15:03:04.0985 0x0e44 [ 007C0C8D5B01D82ACEB70431D15083F6, 7EAF68CD3C38D3CD2CDFEE9ECE1DFB38E274F1F9E6F70B73BCE1336E87D5496C ] usbser C:\Windows\system32\drivers\usbser.sys
15:03:04.0985 0x0e44 usbser - ok
15:03:05.0000 0x0e44 [ B76D8039F5B595C4CA551B3D5DD15A98, 473CFD71AEDFBDE61F317C87221E0419C054FE9DFF085C6B76B6A53581FEDA36 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
15:03:05.0000 0x0e44 UsbserFilt - ok
15:03:05.0016 0x0e44 [ 6A3DB51D317307F3AC65CB127B9A2BEB, 22A0035EB206075FBE27161FEB563C3A8A1A1EE6AFAAAF4EA9283B4B6B9FB5B4 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:03:05.0016 0x0e44 USBSTOR - ok
15:03:05.0040 0x0e44 [ AD77F1AA7450939A5BE79EA76461CA59, 4B84CECAFAD257C19F78FE950A53A04C0DCAD63A884CE480E1C20053C19EBC2C ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
15:03:05.0040 0x0e44 usbuhci - ok
15:03:05.0055 0x0e44 [ 5F417923B13D093168A4503D3C2B9AF6, 43C3EBE82D4131FA1D64099FFD7723A21897AEBD104F45AD004C43800FB8BFBE ] uwbusb C:\Windows\System32\Drivers\usbuwbmini.sys
15:03:05.0063 0x0e44 uwbusb - ok
15:03:05.0079 0x0e44 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
15:03:05.0086 0x0e44 UxSms - ok
15:03:05.0094 0x0e44 [ 91D8B4FF9CD5725DD6507F49CC50BB03, 55555D0CCFE73F39E825EEDD13A1CB1995591D4148F450EF98780992990F1167 ] VaultSvc C:\Windows\system32\lsass.exe
15:03:05.0102 0x0e44 VaultSvc - ok
15:03:05.0196 0x0e44 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
15:03:05.0204 0x0e44 vdrvroot - ok
15:03:05.0282 0x0e44 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
15:03:05.0422 0x0e44 vds - ok
15:03:05.0446 0x0e44 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
15:03:05.0454 0x0e44 vga - ok
15:03:05.0469 0x0e44 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
15:03:05.0477 0x0e44 VgaSave - ok
15:03:05.0485 0x0e44 VGPU - ok
15:03:05.0508 0x0e44 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
15:03:05.0516 0x0e44 vhdmp - ok
15:03:05.0547 0x0e44 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
15:03:05.0547 0x0e44 viaagp - ok
15:03:05.0563 0x0e44 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
15:03:05.0563 0x0e44 ViaC7 - ok
15:03:05.0586 0x0e44 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
15:03:05.0594 0x0e44 viaide - ok
15:03:05.0633 0x0e44 [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys
15:03:05.0633 0x0e44 vmbus - ok
15:03:05.0657 0x0e44 [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
15:03:05.0665 0x0e44 VMBusHID - ok
15:03:05.0688 0x0e44 [ B3D128CA06C1C84A2918B239C535E399, 3C363CCDD4BE2AD4E5EB251B086A4A06285AA665AF28797771CCC7765853ED0F ] volmgr C:\Windows\system32\drivers\volmgr.sys
15:03:05.0688 0x0e44 volmgr - ok
15:03:05.0711 0x0e44 [ 92BF001FFCB6D705302267BBEEFE473A, 061957EF0C735858CDBE3B6639869C60DD2896D83C6C785D4F0FA4B44464DAB6 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
15:03:05.0735 0x0e44 volmgrx - ok
15:03:05.0766 0x0e44 [ 9356AA63B1F89A7B283983446D58899E, E6AB0155E4D8FEB60E98F124A9716C4D3EEA4E4BDB7CB93A0E11609D03A6FDA5 ] volsnap C:\Windows\system32\drivers\volsnap.sys
15:03:05.0782 0x0e44 volsnap - ok
15:03:05.0821 0x0e44 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
15:03:05.0836 0x0e44 vsmraid - ok
15:03:05.0922 0x0e44 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
15:03:05.0977 0x0e44 VSS - ok
15:03:06.0000 0x0e44 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
15:03:06.0000 0x0e44 vwifibus - ok
15:03:06.0016 0x0e44 [ 632F1B4B573B19CE0C80DF8432D1F65D, 522D93304B473696360AD8BE423E5A24541873AF5E362724644788C171AB27B0 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
15:03:06.0024 0x0e44 vwififlt - ok
15:03:06.0040 0x0e44 [ 30B788B9B23EB05D306D2A20B8425BFC, 18CF121EC66F2C269F7C5CF16292D3F067C764E338F830D036D08D1FAD861C49 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
15:03:06.0047 0x0e44 vwifimp - ok
15:03:06.0063 0x0e44 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
15:03:06.0079 0x0e44 W32Time - ok
15:03:06.0094 0x0e44 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
15:03:06.0094 0x0e44 WacomPen - ok
15:03:06.0125 0x0e44 [ 1FFE8CA5F775E1C4DA3629F215A322B5, 84B0D9E94A3B0B63F4DFFB414E9BBF1F3A53BB8B1EA6700D7E0B66975B43084D ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
15:03:06.0125 0x0e44 WANARP - ok
15:03:06.0133 0x0e44 [ 1FFE8CA5F775E1C4DA3629F215A322B5, 84B0D9E94A3B0B63F4DFFB414E9BBF1F3A53BB8B1EA6700D7E0B66975B43084D ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
15:03:06.0133 0x0e44 Wanarpv6 - ok
15:03:06.0219 0x0e44 [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
15:03:06.0274 0x0e44 WatAdminSvc - ok
15:03:06.0344 0x0e44 [ E7DA95E73F04EF2D7155171C50C7EA74, EF221E6D63DC5319FC8A2FEFABD912D300B2C98D3C899A6C33E4EC658C3B5C9B ] wbengine C:\Windows\system32\wbengine.exe
15:03:06.0407 0x0e44 wbengine - ok
15:03:06.0438 0x0e44 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
15:03:06.0446 0x0e44 WbioSrvc - ok
15:03:06.0477 0x0e44 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
15:03:06.0493 0x0e44 wcncsvc - ok
15:03:06.0508 0x0e44 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:03:06.0516 0x0e44 WcsPlugInService - ok
15:03:06.0532 0x0e44 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\drivers\wd.sys
15:03:06.0532 0x0e44 Wd - ok
15:03:06.0571 0x0e44 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
15:03:06.0602 0x0e44 Wdf01000 - ok
15:03:06.0641 0x0e44 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost C:\Windows\system32\wdi.dll
15:03:06.0649 0x0e44 WdiServiceHost - ok
15:03:06.0657 0x0e44 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost C:\Windows\system32\wdi.dll
15:03:06.0665 0x0e44 WdiSystemHost - ok
15:03:06.0696 0x0e44 [ 049FAF4EE26617B4CFCE3C4F45953C16, 0F5CA2303FD8A3A2B6D13BC12D9FA04FFBB515EBF10AFBEBF3C6157B151C026A ] WebClient C:\Windows\System32\webclnt.dll
15:03:06.0727 0x0e44 WebClient - ok
15:03:06.0750 0x0e44 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
15:03:06.0766 0x0e44 Wecsvc - ok
15:03:06.0790 0x0e44 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
15:03:06.0797 0x0e44 wercplsupport - ok
15:03:06.0821 0x0e44 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
15:03:06.0829 0x0e44 WerSvc - ok
15:03:06.0860 0x0e44 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
15:03:06.0860 0x0e44 WfpLwf - ok
15:03:06.0883 0x0e44 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
15:03:06.0883 0x0e44 WIMMount - ok
15:03:06.0954 0x0e44 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
15:03:07.0000 0x0e44 WinDefend - ok
15:03:07.0016 0x0e44 WinHttpAutoProxySvc - ok
15:03:07.0063 0x0e44 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
15:03:07.0079 0x0e44 Winmgmt - ok
15:03:07.0180 0x0e44 [ AD61501AB6BFAECBF94EBB28BDF4B45B, C54F11AFB02C38FB2462BEBA14A36AEC015C9EE72969FFC5311AA9AFC971E4CB ] WinRM C:\Windows\system32\WsmSvc.dll
15:03:07.0227 0x0e44 WinRM - ok
15:03:07.0313 0x0e44 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
15:03:07.0313 0x0e44 WinUsb - ok
15:03:07.0391 0x0e44 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
15:03:07.0454 0x0e44 Wlansvc - ok
15:03:07.0618 0x0e44 [ 5E7C103F8475C4289847D15E129C20F7, C6325D3557545FA1DA26B0B1EA9A1C95AED1FA84A93BE29A771DAD9ECB00768B ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
15:03:07.0680 0x0e44 wlidsvc - ok
15:03:07.0711 0x0e44 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
15:03:07.0711 0x0e44 WmiAcpi - ok
15:03:07.0750 0x0e44 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
15:03:07.0766 0x0e44 wmiApSrv - ok
15:03:07.0883 0x0e44 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
15:03:07.0946 0x0e44 WMPNetworkSvc - ok
15:03:07.0961 0x0e44 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
15:03:07.0969 0x0e44 WPCSvc - ok
15:03:07.0993 0x0e44 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
15:03:08.0000 0x0e44 WPDBusEnum - ok
15:03:08.0016 0x0e44 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
15:03:08.0024 0x0e44 ws2ifsl - ok
15:03:08.0040 0x0e44 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll
15:03:08.0040 0x0e44 wscsvc - ok
15:03:08.0047 0x0e44 WSearch - ok
15:03:08.0188 0x0e44 [ B5202CD63C502A16F6C94186089CF602, 0C4B3F92318D81B67820524D71618333539FEAD2877D8ABA5D7D82E66A9A6417 ] wuauserv C:\Windows\system32\wuaueng.dll
15:03:08.0243 0x0e44 wuauserv - ok
15:03:08.0274 0x0e44 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
15:03:08.0274 0x0e44 WudfPf - ok
15:03:08.0313 0x0e44 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
15:03:08.0329 0x0e44 WUDFRd - ok
15:03:08.0360 0x0e44 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
15:03:08.0368 0x0e44 wudfsvc - ok
15:03:08.0399 0x0e44 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\Windows\System32\wwansvc.dll
15:03:08.0415 0x0e44 WwanSvc - ok
15:03:08.0461 0x0e44 ================ Scan global ===============================
15:03:08.0485 0x0e44 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
15:03:08.0516 0x0e44 [ 33A704DE3BB90C86968767FC4D2A0D53, 372754FEDAE43FDBA2831B5CB40F2240E4CFBDA3244D8F972136CF88DB98F12E ] C:\Windows\system32\winsrv.dll
15:03:08.0540 0x0e44 [ 33A704DE3BB90C86968767FC4D2A0D53, 372754FEDAE43FDBA2831B5CB40F2240E4CFBDA3244D8F972136CF88DB98F12E ] C:\Windows\system32\winsrv.dll
15:03:08.0563 0x0e44 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
15:03:08.0602 0x0e44 [ 0780A42DBD7D9969F9BF4A19AA4285B5, 8EA41124A4E97732C5DAA616457FBA7111CB38986F3427FA776ED00BC1407171 ] C:\Windows\system32\services.exe
15:03:08.0618 0x0e44 [ Global ] - ok
15:03:08.0618 0x0e44 ================ Scan MBR ==================================
15:03:08.0641 0x0e44 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:03:09.0290 0x0e44 \Device\Harddisk0\DR0 - ok
15:03:09.0297 0x0e44 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
15:03:09.0344 0x0e44 \Device\Harddisk1\DR1 - ok
15:03:09.0344 0x0e44 ================ Scan VBR ==================================
15:03:09.0344 0x0e44 [ ADE39F73A062CE7CAD0E0B2DAC0F5B1B ] \Device\Harddisk0\DR0\Partition1
15:03:09.0344 0x0e44 \Device\Harddisk0\DR0\Partition1 - ok
15:03:09.0352 0x0e44 [ 46A0D4E7A37439988A6F168759BBA8FC ] \Device\Harddisk0\DR0\Partition2
15:03:09.0352 0x0e44 \Device\Harddisk0\DR0\Partition2 - ok
15:03:09.0360 0x0e44 [ 924D0416BF32C5605099AAB210236D12 ] \Device\Harddisk0\DR0\Partition3
15:03:09.0360 0x0e44 \Device\Harddisk0\DR0\Partition3 - ok
15:03:09.0360 0x0e44 [ 4D4AE54E9BBFF68AFDB005E6E3108F23 ] \Device\Harddisk1\DR1\Partition1
15:03:09.0407 0x0e44 \Device\Harddisk1\DR1\Partition1 - ok
15:03:09.0415 0x0e44 [ 492D6313F9EC8FD13E7A668696710092 ] \Device\Harddisk1\DR1\Partition2
15:03:09.0454 0x0e44 \Device\Harddisk1\DR1\Partition2 - ok
15:03:09.0454 0x0e44 ================ Scan generic autorun ======================
15:03:09.0547 0x0e44 [ 20DE1CDD37A5D3D4177B8D9FEF907D81, F6CE80984852595A677C92B8C555F9B0D398BAE36768E0D6FC7F8C7211D962D2 ] C:\Program Files\Microsoft Security Client\msseces.exe
15:03:09.0579 0x0e44 MSC - ok
15:03:09.0657 0x0e44 [ 393F021E2A9FA19AC94BA4482E32FC6C, 8DC7A061643099B8A1915ADB59D89912A117883D4194BCC05F653E19DFD321A9 ] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
15:03:09.0680 0x0e44 AdobeAAMUpdater-1.0 - ok
15:03:09.0711 0x0e44 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
15:03:09.0719 0x0e44 SwitchBoard - ok
15:03:09.0868 0x0e44 [ E1636F57581CAB5D995FD54D2991EF57, BB6B3D005054D386D596A4BA4D9D2F1284D7C845C1CD5EE63775B4569559E0EB ] C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
15:03:09.0961 0x0e44 AdobeCS5.5ServiceManager - ok
15:03:10.0063 0x0e44 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
15:03:10.0125 0x0e44 Sidebar - ok
15:03:10.0165 0x0e44 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
15:03:10.0172 0x0e44 mctadmin - ok
15:03:10.0243 0x0e44 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
15:03:10.0274 0x0e44 Sidebar - ok
15:03:10.0282 0x0e44 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
15:03:10.0290 0x0e44 mctadmin - ok
15:03:10.0368 0x0e44 [ 16F1D5CF6465FCA139FA289648B349EE, 3B500B4C73F3B6B49185545881128008A57691C233B88500E8BD11C65B2617EA ] C:\Program Files\Nokia\PC Internet Access\NPCIA.exe
15:03:10.0407 0x0e44 NokiaPCInternetAccess - ok
15:03:10.0594 0x0e44 [ 0337F93218B7D555B0C01AD666E9EA27, D0714327AB157E540D55CEFE446D5A1C45BC71A9777CB5E942B2969DE34C2B60 ] C:\Program Files\DAEMON Tools Ultra\DTAgent.exe
15:03:10.0758 0x0e44 DAEMON Tools Ultra Agent - ok
15:03:10.0766 0x0e44 Waiting for KSN requests completion. In queue: 90
15:03:11.0766 0x0e44 Waiting for KSN requests completion. In queue: 90
15:03:12.0766 0x0e44 Waiting for KSN requests completion. In queue: 90
15:03:13.0797 0x0e44 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.8.204.0 ), 0x61000 ( enabled : updated )
15:03:13.0805 0x0e44 Win FW state via NFP2: enabled
15:03:16.0625 0x0e44 ============================================================
15:03:16.0625 0x0e44 Scan finished
15:03:16.0625 0x0e44 ============================================================
15:03:16.0641 0x16b8 Detected object count: 0
15:03:16.0641 0x16b8 Actual detected object count: 0
15:03:39.0743 0x1738 Deinitialize success

Dopuna: 29 Jun 2015 15:06

nije bilo ničeg sumnjivog niti za brisanje

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Vidim po logovima. Nista, to bi bilo to.





Sledeća procedura će implementirati završno čišćenje.



Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.

Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;
Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.

Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Ukoliko neki alat ili izveštaj nije uklonjen, slobodno ih obriši ručno.


Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)
- Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
- DelFix briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.

Ko je trenutno na forumu
 

Ukupno su 883 korisnika na forumu :: 7 registrovanih, 0 sakrivenih i 876 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Fabius, goxin, Marko Marković, opt1, Romibrat, SR-3m, TBF1D