Skocz do zawartości


Zdjęcie

Logi - Złośliwy proces panmap.exe


  • Zamknięty Temat jest zamknięty
4 odpowiedzi w tym temacie

#1 Frixon

Frixon

    Początkujący

  • 43 postów

Napisano 06 01 2013 - 04:28

Cześć wszystkim.
Mam taki problem, bo wgrał mi się plik o nazwie panmap.exe.
Znajduje się on w C:\Users\Frixon\AppData\Local\Temp
Oczywiście go tam nie widać, jest superhiper ukryty i nie mogę nic z nim zrobić.
Ogólnie to antywirus (comodo) mi go nie wykrywa i nie mam jak tego cholerstwa się pozbyć.
Tworzy on 3 procesy (panmap,exe, AppLaunch.exe, CertPolEng.exe)
Chamski wirus, wykradł mi hasło do popularnego konta na YouTube, a nie zamierzam całą noc patrzeć czy kolejnych haseł mi gdzieś nie rozsyła.
W cmd.exe -> netstat pokazuje jakieś ip od tego procesu i jest WYSŁANO_SYN przy nim.
Ma ktoś może sposób? Polecenie do OTL czy coś?
Z góry dzięki.

LOGI Z OTL:

OTL logfile created on: 2013-01-06 03:33:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Frixon\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 2,06 Gb Available Physical Memory | 51,46% Memory free
8,00 Gb Paging File | 5,62 Gb Available in Paging File | 70,34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,78 Gb Total Space | 200,17 Gb Free Space | 85,99% Space Free | Partition Type: NTFS

Computer Name: FRIXON-KOMPUTER | User Name: Frixon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013-01-06 03:33:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Frixon\Downloads\OTL.exe
PRC - [2013-01-05 20:14:26 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Templates\CertPolEng.exe
PRC - [2013-01-05 17:13:04 | 001,084,416 | RHS- | M] (Advanced Micro Devices, Inc.) -- C:\Users\Frixon\AppData\Local\Temp\panmap.exe
PRC - [2012-12-05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009-06-10 22:22:41 | 000,055,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe


========== Modules (No Company Name) ==========

MOD - [2012-12-05 02:15:15 | 012,456,040 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
MOD - [2012-12-05 02:15:15 | 000,460,904 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
MOD - [2012-12-05 02:15:14 | 004,008,040 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
MOD - [2012-12-05 02:14:29 | 000,587,880 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libglesv2.dll
MOD - [2012-12-05 02:14:28 | 000,124,520 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libegl.dll
MOD - [2012-12-05 02:14:21 | 000,157,304 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avutil-51.dll
MOD - [2012-12-05 02:14:20 | 000,275,576 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avformat-54.dll
MOD - [2012-12-05 02:14:19 | 002,168,952 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll
MOD - [2009-07-14 18:55:04 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009-07-14 06:00:48 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\965b1fa2decab0efc0c837ab7252bba1\Microsoft.VisualBasic.ni.dll
MOD - [2009-07-14 05:55:55 | 006,618,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\7f457271e765b5d72f081942b829469c\System.Data.ni.dll
MOD - [2009-07-14 05:55:34 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll
MOD - [2009-07-14 05:55:32 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009-07-14 05:55:26 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009-07-14 05:55:05 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009-07-14 05:55:00 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009-06-10 22:23:17 | 002,933,248 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012-12-14 20:45:34 | 003,572,160 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV:64bit: - [2012-12-14 20:45:10 | 000,158,928 | ---- | M] (COMODO) [On_Demand | Stopped] -- C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)
SRV:64bit: - [2012-09-28 02:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012-12-14 20:45:42 | 000,023,328 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:64bit: - [2012-09-28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012-09-28 02:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012-05-14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011-09-29 10:30:34 | 000,646,248 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011-09-16 08:12:58 | 000,032,360 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan620.sys -- (RTVLANPT)
DRV:64bit: - [2011-06-15 14:11:20 | 000,058,472 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (TEAM)
DRV:64bit: - [2011-06-15 14:11:20 | 000,058,472 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV:64bit: - [2011-06-15 14:11:20 | 000,027,136 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2010-03-09 11:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = {searchTerms} - Bing
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = {searchTerms} - Bing

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = {searchTerms} - Bing
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: Google
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: Google
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - Extension: Dysk Google = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: Szukaj w Google = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Speed Dial = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi\2.5.3_0\
CHR - Extension: Test My Speed! = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcjjdphdponfcmmeebndmnfhmbpongj\1.0_0\
CHR - Extension: YoWindow Weather = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef\1.41_0\
CHR - Extension: Adres IP = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnjjlbngpejmmhgcaagljaomgnginml\7.0_0\
CHR - Extension: Auto HD For YouTube = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak\3.3.1_0\
CHR - Extension: Gmail = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4 - HKLM..\Run: [R577SO] C:\Program Files (x86)\GIGABYTE\R577SO\R577SO.exe (GIGABYTE Technology Co.,Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AQQ] C:\Program Files\WapSter\WapSter AQQ\AQQ.exe (AQQ Sp. z o.o.)
O4 - HKCU..\Run: [Certificate Policy Engine] C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Templates\CertPolEng.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23291486-4FE9-4507-B99B-6EF4BB28E303}: DhcpNameServer = 217.172.224.160 192.168.0.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013-01-06 03:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2013-01-06 03:05:28 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2013-01-06 03:04:28 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2013-01-06 03:04:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2013-01-06 03:04:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2013-01-05 21:50:05 | 000,324,419 | ---- | C] (http://magiclauncher.com) -- C:\Users\Frixon\Desktop\MagicLauncher.exe
[2013-01-05 21:40:22 | 000,000,000 | ---D | C] -- C:\Users\Frixon\.thumbnails
[2013-01-05 21:28:27 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\fontconfig
[2013-01-05 21:28:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\gegl-0.2
[2013-01-05 21:28:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\.gimp-2.8
[2013-01-05 21:27:02 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2
[2013-01-05 21:05:12 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Desktop\YouTube
[2013-01-05 21:02:35 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Publish Providers
[2013-01-05 20:54:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013-01-05 20:53:58 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2013-01-05 20:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2013-01-05 20:50:46 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Desktop\vegaspro
[2013-01-05 20:31:53 | 000,000,000 | ---D | C] -- C:\Users\Frixon\WapSter
[2013-01-05 20:30:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WapSter
[2013-01-05 20:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\WapSter
[2013-01-05 20:18:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2013-01-05 20:15:35 | 000,108,032 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Users\Frixon\AppData\Roaming\zz24PANEL.exe
[2013-01-05 20:15:29 | 000,108,032 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Users\Frixon\AppData\Roaming\zz24FTP.exe
[2013-01-05 20:14:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\dclogs
[2013-01-05 20:09:28 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Sony
[2013-01-05 20:09:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2013-01-05 20:08:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Sony
[2013-01-05 19:56:49 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Dxtory Software
[2013-01-05 19:56:48 | 003,673,600 | ---- | C] (Dxtory Software) -- C:\Windows\SysNative\DxtoryCodec64.dll
[2013-01-05 19:56:48 | 003,166,720 | ---- | C] (Dxtory Software) -- C:\Windows\SysWow64\DxtoryCodec.dll
[2013-01-05 19:56:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013-01-05 19:56:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dxtory Software
[2013-01-05 19:55:59 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Cool Record Edit Pro
[2013-01-05 19:55:52 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Documents\Free Sound Recorder
[2013-01-05 19:55:52 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Free Sound Recorder
[2013-01-05 19:55:45 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\NCTAudioFile2.dll
[2013-01-05 19:55:45 | 001,212,416 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioInformation2.dll
[2013-01-05 19:55:45 | 000,880,640 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioEditor2.dll
[2013-01-05 19:55:45 | 000,835,584 | ---- | C] (NCT) -- C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
[2013-01-05 19:55:45 | 000,602,112 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioTransform2.dll
[2013-01-05 19:55:45 | 000,479,232 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioVisualization2.dll
[2013-01-05 19:55:45 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioRecord2.dll
[2013-01-05 19:55:45 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioPlayer2.dll
[2013-01-05 19:55:45 | 000,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTTextToAudio2.dll
[2013-01-05 19:55:45 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\NCTWMAFile2.dll
[2013-01-05 19:55:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Sound Recorder
[2013-01-05 19:55:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Sound Recorder
[2013-01-05 19:36:18 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013-01-05 19:30:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013-01-05 19:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013-01-05 19:30:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
[2013-01-05 19:30:00 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013-01-05 19:29:58 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2013-01-05 19:29:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013-01-05 19:29:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2013-01-05 19:29:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013-01-05 19:29:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2013-01-05 19:11:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2013-01-05 19:09:52 | 000,000,000 | ---D | C] -- C:\AMD
[2013-01-05 18:59:09 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\.minecraft
[2013-01-05 18:58:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013-01-05 18:58:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013-01-05 18:57:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\WinRAR
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013-01-05 18:56:22 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013-01-05 18:28:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Audacity
[2013-01-05 18:27:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2013-01-05 18:24:25 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\ATI
[2013-01-05 18:24:25 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\ATI
[2013-01-05 18:18:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2013-01-05 18:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2013-01-05 18:13:10 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Documents\temp
[2013-01-05 18:10:45 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013-01-05 18:10:08 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013-01-05 18:10:07 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2013-01-05 18:09:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013-01-05 18:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIGABYTE
[2013-01-05 18:09:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013-01-05 18:09:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Google
[2013-01-05 18:08:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Deployment
[2013-01-05 18:08:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Apps
[2013-01-05 18:00:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Diagnostics
[2013-01-05 17:54:12 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2013-01-05 17:54:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2013-01-05 17:54:03 | 000,000,000 | ---D | C] -- C:\Intel
[2013-01-05 17:52:44 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2013-01-05 17:51:47 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2013-01-05 17:51:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2013-01-05 17:50:28 | 000,646,248 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2013-01-05 17:49:21 | 000,058,472 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtTeam60.sys
[2013-01-05 17:49:21 | 000,032,360 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtVlan620.sys
[2013-01-05 17:49:21 | 000,027,136 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\RtNdPt60.sys
[2013-01-05 17:49:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
[2013-01-05 17:49:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2013-01-05 17:49:20 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2013-01-05 17:46:14 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Desktop\STERY
[2013-01-05 16:41:21 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Searches
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013-01-05 16:37:59 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Identities
[2013-01-05 16:37:57 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Contacts
[2013-01-05 16:37:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\VirtualStore
[2013-01-05 16:37:47 | 000,000,000 | --SD | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Videos
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Saved Games
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Pictures
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Music
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Links
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Favorites
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Downloads
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Documents
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Desktop
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Ustawienia lokalne
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Temporary Internet Files
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Szablony
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\SendTo
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Recent
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\PrintHood
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\NetHood
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moje wideo
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moje obrazy
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Moje dokumenty
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moja muzyka
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Menu Start
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Historia
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Dane aplikacji
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Dane aplikacji
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Cookies
[2013-01-05 16:37:47 | 000,000,000 | -H-D | C] -- C:\Users\Frixon\AppData
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Temp
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Microsoft
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Media Center Programs
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji
[2013-01-05 16:31:16 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013-01-05 16:30:56 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2013-01-05 16:30:10 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013-01-05 16:30:00 | 000,000,000 | -HSD | C] -- C:\Boot
[2013-01-05 16:29:46 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM
[2012-12-14 20:45:42 | 000,023,328 | ---- | C] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys
[2012-12-14 20:45:32 | 000,042,856 | ---- | C] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll
[2012-12-14 20:45:30 | 000,453,808 | ---- | C] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2012-12-14 20:45:30 | 000,350,272 | ---- | C] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2012-12-14 20:45:20 | 000,321,744 | ---- | C] (COMODO) -- C:\Windows\SysNative\cmdvrt64.dll
[2012-12-14 20:45:14 | 000,260,304 | ---- | C] (COMODO) -- C:\Windows\SysWow64\cmdvrt32.dll

========== Files - Modified Within 30 Days ==========

[2013-01-06 03:33:38 | 000,123,920 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat
[2013-01-06 03:18:24 | 001,549,696 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-01-06 03:18:24 | 000,697,674 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2013-01-06 03:18:24 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-01-06 03:18:24 | 000,134,784 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2013-01-06 03:18:24 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-01-06 03:14:04 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-06 03:14:04 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-06 03:13:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-01-06 03:13:41 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2013-01-06 03:12:55 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-01-06 03:12:55 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-01-06 03:06:06 | 000,001,888 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013-01-05 21:50:12 | 000,324,419 | ---- | M] (http://magiclauncher.com) -- C:\Users\Frixon\Desktop\MagicLauncher.exe
[2013-01-05 21:40:38 | 000,002,987 | ---- | M] () -- C:\Users\Frixon\AppData\Local\recently-used.xbel
[2013-01-05 21:40:22 | 000,954,085 | ---- | M] () -- C:\Users\Frixon\Documents\zasady.xcf
[2013-01-05 21:02:23 | 000,002,564 | ---- | M] () -- C:\Users\Frixon\Documents\Register Vegas Pro.htm
[2013-01-05 20:54:00 | 000,001,908 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
[2013-01-05 20:30:55 | 000,000,703 | ---- | M] () -- C:\Users\Frixon\Desktop\AQQ.lnk
[2013-01-05 20:18:55 | 000,001,998 | ---- | M] () -- C:\Windows\unins000.dat
[2013-01-05 20:18:54 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe
[2013-01-05 19:56:48 | 000,001,182 | ---- | M] () -- C:\Users\Frixon\Desktop\Dxtory.lnk
[2013-01-05 19:55:45 | 000,001,129 | ---- | M] () -- C:\Users\Frixon\Desktop\Free Sound Recorder.lnk
[2013-01-05 19:30:56 | 000,001,007 | ---- | M] () -- C:\Users\Frixon\Desktop\SpeedFan.lnk
[2013-01-05 19:30:55 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2013-01-05 19:14:20 | 360,898,846 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013-01-05 18:27:28 | 000,001,007 | ---- | M] () -- C:\Users\Frixon\Desktop\Audacity.lnk
[2013-01-05 18:21:46 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2013-01-05 18:09:58 | 000,002,295 | ---- | M] () -- C:\Users\Frixon\Desktop\Google Chrome.lnk
[2013-01-05 16:37:33 | 000,171,136 | RHS- | M] () -- C:\W7LDR
[2013-01-05 16:34:30 | 000,067,908 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013-01-05 16:34:30 | 000,067,908 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013-01-05 16:32:52 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013-01-05 16:31:21 | 000,274,840 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-01-05 16:30:02 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012-12-14 20:45:42 | 000,023,328 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys
[2012-12-14 20:45:32 | 000,042,856 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll
[2012-12-14 20:45:30 | 000,453,808 | ---- | M] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2012-12-14 20:45:30 | 000,350,272 | ---- | M] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2012-12-14 20:45:20 | 000,321,744 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdvrt64.dll
[2012-12-14 20:45:14 | 000,260,304 | ---- | M] (COMODO) -- C:\Windows\SysWow64\cmdvrt32.dll

========== Files Created - No Company Name ==========

[2013-01-06 03:06:06 | 000,001,888 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013-01-06 03:06:00 | 000,123,920 | ---- | C] () -- C:\Windows\SysNative\drivers\sfi.dat
[2013-01-05 21:40:38 | 000,002,987 | ---- | C] () -- C:\Users\Frixon\AppData\Local\recently-used.xbel
[2013-01-05 21:40:21 | 000,954,085 | ---- | C] () -- C:\Users\Frixon\Documents\zasady.xcf
[2013-01-05 21:27:30 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2013-01-05 20:54:00 | 000,001,908 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
[2013-01-05 20:30:55 | 000,000,703 | ---- | C] () -- C:\Users\Frixon\Desktop\AQQ.lnk
[2013-01-05 20:18:55 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2013-01-05 20:18:55 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2013-01-05 20:18:55 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2013-01-05 20:18:55 | 000,001,998 | ---- | C] () -- C:\Windows\unins000.dat
[2013-01-05 20:10:28 | 000,002,564 | ---- | C] () -- C:\Users\Frixon\Documents\Register Vegas Pro.htm
[2013-01-05 19:56:54 | 000,000,184 | ---- | C] () -- C:\Users\Frixon\DxtoryLicenceFile.dxtorylic
[2013-01-05 19:56:48 | 000,001,182 | ---- | C] () -- C:\Users\Frixon\Desktop\Dxtory.lnk
[2013-01-05 19:55:45 | 000,113,486 | ---- | C] () -- C:\Windows\SysWow64\NCTWMAProfiles.prx
[2013-01-05 19:55:45 | 000,001,129 | ---- | C] () -- C:\Users\Frixon\Desktop\Free Sound Recorder.lnk
[2013-01-05 19:30:56 | 000,001,007 | ---- | C] () -- C:\Users\Frixon\Desktop\SpeedFan.lnk
[2013-01-05 19:30:55 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2013-01-05 18:27:28 | 000,001,019 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013-01-05 18:27:28 | 000,001,007 | ---- | C] () -- C:\Users\Frixon\Desktop\Audacity.lnk
[2013-01-05 18:21:46 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013-01-05 18:09:58 | 000,002,295 | ---- | C] () -- C:\Users\Frixon\Desktop\Google Chrome.lnk
[2013-01-05 18:09:08 | 000,001,048 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-05 18:09:07 | 000,001,044 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-05 17:52:41 | 360,898,846 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013-01-05 17:50:28 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2013-01-05 16:39:26 | 000,001,451 | ---- | C] () -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013-01-05 16:39:26 | 000,001,417 | ---- | C] () -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013-01-05 16:37:33 | 000,171,136 | RHS- | C] () -- C:\W7LDR
[2013-01-05 16:34:18 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013-01-05 16:34:10 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013-01-05 16:32:52 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013-01-05 16:30:56 | 3220,037,632 | -HS- | C] () -- C:\hiberfil.sys
[2013-01-05 16:30:02 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2013-01-05 16:30:00 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2012-09-28 02:29:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-09-28 02:29:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-05-02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009-07-14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013-01-05 21:52:30 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\.minecraft
[2013-01-05 22:28:37 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Audacity
[2013-01-05 19:55:59 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Cool Record Edit Pro
[2013-01-06 00:06:04 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\dclogs
[2013-01-05 20:33:11 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Free Sound Recorder
[2013-01-05 21:02:35 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Publish Providers
[2013-01-05 21:02:32 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Sony

========== Purity Check ==========



< End of report >


[uwaga=pawel315]
Temat przeniosłem do prawidłowego działu
[/uwaga]

Użytkownik pawel315 edytował ten post 06 01 2013 - 12:18

  • 0

#2 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 06 01 2013 - 12:26

Witaj.

Uruchom OTL w okienku Własne opcje skanowania/skrypt wklej:
:OTL
O4 - HKCU..\Run: [Certificate Policy Engine] C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Templates\CertPolEng.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1


:Files
C:\Windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
C:\Users\Frixon\AppData\Local\Temp\panmap.exe
C:\Users\Frixon\AppData\Roaming\zz24PANEL.exe
C:\Users\Frixon\AppData\Roaming\zz24FTP.exe
Kliknij Wykonaj skrypt daj log z usuwania.
Następnie:
  • Daj nowe logi z OTL'a
  • Dorzuć log z TDSS killer'a


  • 1

#3 Frixon

Frixon

    Początkujący

  • 43 postów

Napisano 06 01 2013 - 13:08

Wykonałem skrypt. Procesy zniknęły z taskmanagera.
Podaję logi z OTL oraz z TDSS.
OTL:

OTL logfile created on: 2013-01-06 12:02:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Frixon\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 3,03 Gb Available Physical Memory | 75,82% Memory free
8,00 Gb Paging File | 6,91 Gb Available in Paging File | 86,44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,78 Gb Total Space | 200,54 Gb Free Space | 86,15% Space Free | Partition Type: NTFS

Computer Name: FRIXON-KOMPUTER | User Name: Frixon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013-01-06 11:58:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Frixon\Downloads\OTL.exe
PRC - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - [2012-12-14 20:45:34 | 003,572,160 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV:64bit: - [2012-12-14 20:45:10 | 000,158,928 | ---- | M] (COMODO) [On_Demand | Stopped] -- C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)
SRV:64bit: - [2012-09-28 02:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012-12-14 20:45:42 | 000,023,328 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:64bit: - [2012-09-28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012-09-28 02:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012-05-14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011-09-29 10:30:34 | 000,646,248 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011-09-16 08:12:58 | 000,032,360 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtVlan620.sys -- (RTVLANPT)
DRV:64bit: - [2011-06-15 14:11:20 | 000,058,472 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (TEAM)
DRV:64bit: - [2011-06-15 14:11:20 | 000,058,472 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV:64bit: - [2011-06-15 14:11:20 | 000,027,136 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2010-03-09 11:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - Extension: Dysk Google = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: Szukaj w Google = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Speed Dial = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi\2.5.3_0\
CHR - Extension: Test My Speed! = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcjjdphdponfcmmeebndmnfhmbpongj\1.0_0\
CHR - Extension: YoWindow Weather = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef\1.41_0\
CHR - Extension: Adres IP = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnjjlbngpejmmhgcaagljaomgnginml\7.0_0\
CHR - Extension: Auto HD For YouTube = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak\3.3.1_0\
CHR - Extension: Gmail = C:\Users\Frixon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4 - HKLM..\Run: [R577SO] C:\Program Files (x86)\GIGABYTE\R577SO\R577SO.exe (GIGABYTE Technology Co.,Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AQQ] C:\Program Files\WapSter\WapSter AQQ\AQQ.exe (AQQ Sp. z o.o.)
O4 - HKCU..\Run: [Certificate Policy Engine] C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Templates\CertPolEng.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23291486-4FE9-4507-B99B-6EF4BB28E303}: DhcpNameServer = 217.172.224.160 192.168.0.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013-01-06 11:59:18 | 000,000,000 | ---D | C] -- C:\_OTL
[2013-01-06 03:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2013-01-06 03:05:28 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2013-01-06 03:04:28 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2013-01-06 03:04:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2013-01-06 03:04:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2013-01-05 21:50:05 | 000,324,419 | ---- | C] (http://magiclauncher.com) -- C:\Users\Frixon\Desktop\MagicLauncher.exe
[2013-01-05 21:40:22 | 000,000,000 | ---D | C] -- C:\Users\Frixon\.thumbnails
[2013-01-05 21:28:27 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\fontconfig
[2013-01-05 21:28:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\gegl-0.2
[2013-01-05 21:28:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\.gimp-2.8
[2013-01-05 21:27:02 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP 2
[2013-01-05 21:05:12 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Desktop\YouTube
[2013-01-05 21:02:35 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Publish Providers
[2013-01-05 20:54:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2013-01-05 20:53:58 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2013-01-05 20:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2013-01-05 20:31:53 | 000,000,000 | ---D | C] -- C:\Users\Frixon\WapSter
[2013-01-05 20:30:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WapSter
[2013-01-05 20:30:47 | 000,000,000 | ---D | C] -- C:\Program Files\WapSter
[2013-01-05 20:18:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2013-01-05 20:14:26 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\dclogs
[2013-01-05 20:09:28 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Sony
[2013-01-05 20:09:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2013-01-05 20:08:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Sony
[2013-01-05 19:56:49 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Dxtory Software
[2013-01-05 19:56:48 | 003,673,600 | ---- | C] (Dxtory Software) -- C:\Windows\SysNative\DxtoryCodec64.dll
[2013-01-05 19:56:48 | 003,166,720 | ---- | C] (Dxtory Software) -- C:\Windows\SysWow64\DxtoryCodec.dll
[2013-01-05 19:56:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013-01-05 19:56:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dxtory Software
[2013-01-05 19:55:59 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Cool Record Edit Pro
[2013-01-05 19:55:52 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Documents\Free Sound Recorder
[2013-01-05 19:55:52 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Free Sound Recorder
[2013-01-05 19:55:45 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\NCTAudioFile2.dll
[2013-01-05 19:55:45 | 001,212,416 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioInformation2.dll
[2013-01-05 19:55:45 | 000,880,640 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioEditor2.dll
[2013-01-05 19:55:45 | 000,835,584 | ---- | C] (NCT) -- C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
[2013-01-05 19:55:45 | 000,602,112 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioTransform2.dll
[2013-01-05 19:55:45 | 000,479,232 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioVisualization2.dll
[2013-01-05 19:55:45 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioRecord2.dll
[2013-01-05 19:55:45 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTAudioPlayer2.dll
[2013-01-05 19:55:45 | 000,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\SysWow64\NCTTextToAudio2.dll
[2013-01-05 19:55:45 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\NCTWMAFile2.dll
[2013-01-05 19:55:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Sound Recorder
[2013-01-05 19:55:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Sound Recorder
[2013-01-05 19:36:18 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013-01-05 19:30:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013-01-05 19:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013-01-05 19:30:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
[2013-01-05 19:30:00 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2013-01-05 19:29:58 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2013-01-05 19:29:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2013-01-05 19:29:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2013-01-05 19:29:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013-01-05 19:29:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2013-01-05 19:11:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2013-01-05 19:09:52 | 000,000,000 | ---D | C] -- C:\AMD
[2013-01-05 18:59:09 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\.minecraft
[2013-01-05 18:58:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013-01-05 18:58:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013-01-05 18:57:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\WinRAR
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013-01-05 18:56:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013-01-05 18:56:22 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013-01-05 18:28:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Audacity
[2013-01-05 18:27:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2013-01-05 18:24:25 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\ATI
[2013-01-05 18:24:25 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\ATI
[2013-01-05 18:18:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2013-01-05 18:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2013-01-05 18:13:10 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Documents\temp
[2013-01-05 18:10:45 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2013-01-05 18:10:08 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013-01-05 18:10:07 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2013-01-05 18:09:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013-01-05 18:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GIGABYTE
[2013-01-05 18:09:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013-01-05 18:09:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Google
[2013-01-05 18:08:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Deployment
[2013-01-05 18:08:56 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Apps
[2013-01-05 18:00:04 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Diagnostics
[2013-01-05 17:54:12 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2013-01-05 17:54:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2013-01-05 17:54:03 | 000,000,000 | ---D | C] -- C:\Intel
[2013-01-05 17:52:44 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2013-01-05 17:51:47 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2013-01-05 17:51:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2013-01-05 17:50:28 | 000,646,248 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2013-01-05 17:49:21 | 000,058,472 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtTeam60.sys
[2013-01-05 17:49:21 | 000,032,360 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtVlan620.sys
[2013-01-05 17:49:21 | 000,027,136 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\RtNdPt60.sys
[2013-01-05 17:49:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
[2013-01-05 17:49:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2013-01-05 17:49:20 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2013-01-05 17:46:14 | 000,000,000 | ---D | C] -- C:\Users\Frixon\Desktop\STERY
[2013-01-05 16:41:21 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Searches
[2013-01-05 16:38:07 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013-01-05 16:37:59 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Identities
[2013-01-05 16:37:57 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Contacts
[2013-01-05 16:37:55 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\VirtualStore
[2013-01-05 16:37:47 | 000,000,000 | --SD | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Videos
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Saved Games
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Pictures
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Music
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Links
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Favorites
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Downloads
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Documents
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\Desktop
[2013-01-05 16:37:47 | 000,000,000 | R--D | C] -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Ustawienia lokalne
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Temporary Internet Files
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Szablony
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\SendTo
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Recent
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\PrintHood
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\NetHood
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moje wideo
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moje obrazy
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Moje dokumenty
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Documents\Moja muzyka
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Menu Start
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Historia
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Dane aplikacji
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\AppData\Local\Dane aplikacji
[2013-01-05 16:37:47 | 000,000,000 | -HSD | C] -- C:\Users\Frixon\Cookies
[2013-01-05 16:37:47 | 000,000,000 | -H-D | C] -- C:\Users\Frixon\AppData
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Temp
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Local\Microsoft
[2013-01-05 16:37:47 | 000,000,000 | ---D | C] -- C:\Users\Frixon\AppData\Roaming\Media Center Programs
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Recovery
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2013-01-05 16:36:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji
[2013-01-05 16:31:16 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2013-01-05 16:30:56 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2013-01-05 16:30:10 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2013-01-05 16:30:00 | 000,000,000 | -HSD | C] -- C:\Boot
[2013-01-05 16:29:46 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\OEM
[2012-12-14 20:45:42 | 000,023,328 | ---- | C] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys
[2012-12-14 20:45:32 | 000,042,856 | ---- | C] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll
[2012-12-14 20:45:30 | 000,453,808 | ---- | C] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2012-12-14 20:45:30 | 000,350,272 | ---- | C] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2012-12-14 20:45:20 | 000,321,744 | ---- | C] (COMODO) -- C:\Windows\SysNative\cmdvrt64.dll
[2012-12-14 20:45:14 | 000,260,304 | ---- | C] (COMODO) -- C:\Windows\SysWow64\cmdvrt32.dll

========== Files - Modified Within 30 Days ==========

[2013-01-06 12:01:29 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-06 12:00:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-01-06 12:00:12 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2013-01-06 12:00:08 | 000,420,992 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat
[2013-01-06 11:59:27 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-01-06 11:59:27 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-01-06 03:18:24 | 001,549,696 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-01-06 03:18:24 | 000,697,674 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2013-01-06 03:18:24 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-01-06 03:18:24 | 000,134,784 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2013-01-06 03:18:24 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-01-06 03:14:04 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-06 03:06:06 | 000,001,888 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013-01-05 21:50:12 | 000,324,419 | ---- | M] (http://magiclauncher.com) -- C:\Users\Frixon\Desktop\MagicLauncher.exe
[2013-01-05 21:40:38 | 000,002,987 | ---- | M] () -- C:\Users\Frixon\AppData\Local\recently-used.xbel
[2013-01-05 21:40:22 | 000,954,085 | ---- | M] () -- C:\Users\Frixon\Documents\zasady.xcf
[2013-01-05 21:02:23 | 000,002,564 | ---- | M] () -- C:\Users\Frixon\Documents\Register Vegas Pro.htm
[2013-01-05 20:54:00 | 000,001,908 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
[2013-01-05 20:30:55 | 000,000,703 | ---- | M] () -- C:\Users\Frixon\Desktop\AQQ.lnk
[2013-01-05 20:18:55 | 000,001,998 | ---- | M] () -- C:\Windows\unins000.dat
[2013-01-05 20:18:54 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe
[2013-01-05 19:56:48 | 000,001,182 | ---- | M] () -- C:\Users\Frixon\Desktop\Dxtory.lnk
[2013-01-05 19:55:45 | 000,001,129 | ---- | M] () -- C:\Users\Frixon\Desktop\Free Sound Recorder.lnk
[2013-01-05 19:30:56 | 000,001,007 | ---- | M] () -- C:\Users\Frixon\Desktop\SpeedFan.lnk
[2013-01-05 19:30:55 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[2013-01-05 19:14:20 | 360,898,846 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013-01-05 18:27:28 | 000,001,007 | ---- | M] () -- C:\Users\Frixon\Desktop\Audacity.lnk
[2013-01-05 18:21:46 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2013-01-05 18:09:58 | 000,002,295 | ---- | M] () -- C:\Users\Frixon\Desktop\Google Chrome.lnk
[2013-01-05 16:37:33 | 000,171,136 | RHS- | M] () -- C:\W7LDR
[2013-01-05 16:34:30 | 000,067,908 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2013-01-05 16:34:30 | 000,067,908 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2013-01-05 16:32:52 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013-01-05 16:31:21 | 000,274,840 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-01-05 16:30:02 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012-12-14 20:45:42 | 000,023,328 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys
[2012-12-14 20:45:32 | 000,042,856 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll
[2012-12-14 20:45:30 | 000,453,808 | ---- | M] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2012-12-14 20:45:30 | 000,350,272 | ---- | M] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2012-12-14 20:45:20 | 000,321,744 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdvrt64.dll
[2012-12-14 20:45:14 | 000,260,304 | ---- | M] (COMODO) -- C:\Windows\SysWow64\cmdvrt32.dll

========== Files Created - No Company Name ==========

[2013-01-06 03:06:06 | 000,001,888 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013-01-06 03:06:00 | 000,420,992 | ---- | C] () -- C:\Windows\SysNative\drivers\sfi.dat
[2013-01-05 21:40:38 | 000,002,987 | ---- | C] () -- C:\Users\Frixon\AppData\Local\recently-used.xbel
[2013-01-05 21:40:21 | 000,954,085 | ---- | C] () -- C:\Users\Frixon\Documents\zasady.xcf
[2013-01-05 21:27:30 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2013-01-05 20:54:00 | 000,001,908 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Pro 9.0.lnk
[2013-01-05 20:30:55 | 000,000,703 | ---- | C] () -- C:\Users\Frixon\Desktop\AQQ.lnk
[2013-01-05 20:18:55 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2013-01-05 20:18:55 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2013-01-05 20:18:55 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2013-01-05 20:18:55 | 000,001,998 | ---- | C] () -- C:\Windows\unins000.dat
[2013-01-05 20:10:28 | 000,002,564 | ---- | C] () -- C:\Users\Frixon\Documents\Register Vegas Pro.htm
[2013-01-05 19:56:54 | 000,000,184 | ---- | C] () -- C:\Users\Frixon\DxtoryLicenceFile.dxtorylic
[2013-01-05 19:56:48 | 000,001,182 | ---- | C] () -- C:\Users\Frixon\Desktop\Dxtory.lnk
[2013-01-05 19:55:45 | 000,113,486 | ---- | C] () -- C:\Windows\SysWow64\NCTWMAProfiles.prx
[2013-01-05 19:55:45 | 000,001,129 | ---- | C] () -- C:\Users\Frixon\Desktop\Free Sound Recorder.lnk
[2013-01-05 19:30:56 | 000,001,007 | ---- | C] () -- C:\Users\Frixon\Desktop\SpeedFan.lnk
[2013-01-05 19:30:55 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
[2013-01-05 18:27:28 | 000,001,019 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013-01-05 18:27:28 | 000,001,007 | ---- | C] () -- C:\Users\Frixon\Desktop\Audacity.lnk
[2013-01-05 18:21:46 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013-01-05 18:09:58 | 000,002,295 | ---- | C] () -- C:\Users\Frixon\Desktop\Google Chrome.lnk
[2013-01-05 18:09:08 | 000,001,048 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-05 18:09:07 | 000,001,044 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-05 17:52:41 | 360,898,846 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013-01-05 17:50:28 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2013-01-05 16:39:26 | 000,001,451 | ---- | C] () -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013-01-05 16:39:26 | 000,001,417 | ---- | C] () -- C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013-01-05 16:37:33 | 000,171,136 | RHS- | C] () -- C:\W7LDR
[2013-01-05 16:34:18 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2013-01-05 16:34:10 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2013-01-05 16:32:52 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2013-01-05 16:30:56 | 3220,037,632 | -HS- | C] () -- C:\hiberfil.sys
[2013-01-05 16:30:02 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2013-01-05 16:30:00 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2012-09-28 02:29:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-09-28 02:29:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-05-02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009-07-14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013-01-05 21:52:30 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\.minecraft
[2013-01-05 22:28:37 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Audacity
[2013-01-05 19:55:59 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Cool Record Edit Pro
[2013-01-06 00:06:04 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\dclogs
[2013-01-05 20:33:11 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Free Sound Recorder
[2013-01-05 21:02:35 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Publish Providers
[2013-01-05 21:02:32 | 000,000,000 | ---D | M] -- C:\Users\Frixon\AppData\Roaming\Sony

========== Purity Check ==========



< End of report >


TDSS Killer:

12:02:55.0590 3300 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
12:02:56.0635 3300 ============================================================
12:02:56.0635 3300 Current date / time: 2013/01/06 12:02:56.0635
12:02:56.0635 3300 SystemInfo:
12:02:56.0635 3300
12:02:56.0635 3300 OS Version: 6.1.7600 ServicePack: 0.0
12:02:56.0635 3300 Product type: Workstation
12:02:56.0635 3300 ComputerName: FRIXON-KOMPUTER
12:02:56.0635 3300 UserName: Frixon
12:02:56.0635 3300 Windows directory: C:\Windows
12:02:56.0635 3300 System windows directory: C:\Windows
12:02:56.0635 3300 Running under WOW64
12:02:56.0635 3300 Processor architecture: Intel x64
12:02:56.0635 3300 Number of processors: 4
12:02:56.0635 3300 Page size: 0x1000
12:02:56.0635 3300 Boot type: Normal boot
12:02:56.0635 3300 ============================================================
12:02:57.0930 3300 Drive \Device\Harddisk0\DR0 - Size: 0x3A38A25E00 (232.88 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:02:57.0946 3300 ============================================================
12:02:57.0946 3300 \Device\Harddisk0\DR0:
12:02:57.0961 3300 MBR partitions:
12:02:57.0961 3300 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32FCD, BlocksNum 0x1D1915B4
12:02:57.0961 3300 ============================================================
12:02:57.0992 3300 C: <-> \Device\Harddisk0\DR0\Partition1
12:02:57.0992 3300 ============================================================
12:02:57.0992 3300 Initialize success
12:02:57.0992 3300 ============================================================
12:03:00.0488 3356 ============================================================
12:03:00.0488 3356 Scan started
12:03:00.0488 3356 Mode: Manual;
12:03:00.0488 3356 ============================================================
12:03:01.0471 3356 ================ Scan system memory ========================
12:03:01.0471 3356 System memory - ok
12:03:01.0471 3356 ================ Scan services =============================
12:03:01.0830 3356 [ 1B00662092F9F9568B995902F0CC40D5 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
12:03:01.0830 3356 1394ohci - ok
12:03:01.0861 3356 [ 6F11E88748CDEFD2F76AA215F97DDFE5 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
12:03:01.0861 3356 ACPI - ok
12:03:01.0877 3356 [ 63B05A0420CE4BF0E4AF6DCC7CADA254 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
12:03:01.0877 3356 AcpiPmi - ok
12:03:01.0908 3356 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
12:03:01.0924 3356 adp94xx - ok
12:03:01.0939 3356 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
12:03:01.0955 3356 adpahci - ok
12:03:01.0970 3356 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
12:03:01.0970 3356 adpu320 - ok
12:03:01.0986 3356 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:03:02.0002 3356 AeLookupSvc - ok
12:03:02.0033 3356 [ B9384E03479D2506BC924C16A3DB87BC ] AFD C:\Windows\system32\drivers\afd.sys
12:03:02.0033 3356 AFD - ok
12:03:02.0064 3356 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
12:03:02.0064 3356 agp440 - ok
12:03:02.0080 3356 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
12:03:02.0080 3356 ALG - ok
12:03:02.0080 3356 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
12:03:02.0095 3356 aliide - ok
12:03:02.0126 3356 [ 4C1E3649C89C7D542CD18ECC5210099D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:03:02.0126 3356 AMD External Events Utility - ok
12:03:02.0142 3356 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\DRIVERS\amdide.sys
12:03:02.0142 3356 amdide - ok
12:03:02.0142 3356 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
12:03:02.0158 3356 AmdK8 - ok
12:03:02.0407 3356 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
12:03:02.0594 3356 amdkmdag - ok
12:03:02.0704 3356 [ 20F3CD38B107C1BD747C0EA37D450165 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
12:03:02.0704 3356 amdkmdap - ok
12:03:02.0735 3356 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
12:03:02.0735 3356 AmdPPM - ok
12:03:02.0750 3356 [ 7A4B413614C055935567CF88A9734D38 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
12:03:02.0750 3356 amdsata - ok
12:03:02.0766 3356 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
12:03:02.0766 3356 amdsbs - ok
12:03:02.0782 3356 [ B4AD0CACBAB298671DD6F6EF7E20679D ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
12:03:02.0782 3356 amdxata - ok
12:03:02.0813 3356 [ 42FD751B27FA0E9C69BB39F39E409594 ] AppID C:\Windows\system32\drivers\appid.sys
12:03:02.0813 3356 AppID - ok
12:03:02.0828 3356 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
12:03:02.0828 3356 AppIDSvc - ok
12:03:02.0844 3356 [ D065BE66822847B7F127D1F90158376E ] Appinfo C:\Windows\System32\appinfo.dll
12:03:02.0844 3356 Appinfo - ok
12:03:02.0875 3356 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
12:03:02.0875 3356 AppMgmt - ok
12:03:02.0891 3356 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
12:03:02.0891 3356 arc - ok
12:03:02.0891 3356 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
12:03:02.0891 3356 arcsas - ok
12:03:02.0906 3356 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:03:02.0906 3356 AsyncMac - ok
12:03:02.0922 3356 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\DRIVERS\atapi.sys
12:03:02.0922 3356 atapi - ok
12:03:03.0016 3356 [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
12:03:03.0016 3356 AtiHDAudioService - ok
12:03:03.0031 3356 [ 7E2F5A758F63F80F8B03F889B4E6B19F ] AtiHdmiService C:\Windows\system32\drivers\AtiHdmi.sys
12:03:03.0047 3356 AtiHdmiService - ok
12:03:03.0094 3356 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:03:03.0109 3356 AudioEndpointBuilder - ok
12:03:03.0125 3356 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioSrv C:\Windows\System32\Audiosrv.dll
12:03:03.0140 3356 AudioSrv - ok
12:03:03.0172 3356 [ B20B5FA5CA050E9926E4D1DB81501B32 ] AxInstSV C:\Windows\System32\AxInstSV.dll
12:03:03.0172 3356 AxInstSV - ok
12:03:03.0203 3356 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
12:03:03.0218 3356 b06bdrv - ok
12:03:03.0250 3356 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
12:03:03.0250 3356 b57nd60a - ok
12:03:03.0281 3356 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
12:03:03.0281 3356 BDESVC - ok
12:03:03.0281 3356 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
12:03:03.0281 3356 Beep - ok
12:03:03.0328 3356 [ 4992C609A6315671463E30F6512BC022 ] BFE C:\Windows\System32\bfe.dll
12:03:03.0343 3356 BFE - ok
12:03:03.0374 3356 [ 7F0C323FE3DA28AA4AA1BDA3F575707F ] BITS C:\Windows\System32\qmgr.dll
12:03:03.0390 3356 BITS - ok
12:03:03.0406 3356 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
12:03:03.0406 3356 blbdrive - ok
12:03:03.0421 3356 [ 91CE0D3DC57DD377E690A2D324022B08 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:03:03.0421 3356 bowser - ok
12:03:03.0421 3356 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:03:03.0421 3356 BrFiltLo - ok
12:03:03.0437 3356 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:03:03.0437 3356 BrFiltUp - ok
12:03:03.0452 3356 [ 94FBC06F294D58D02361918418F996E3 ] Browser C:\Windows\System32\browser.dll
12:03:03.0452 3356 Browser - ok
12:03:03.0468 3356 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
12:03:03.0468 3356 Brserid - ok
12:03:03.0484 3356 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
12:03:03.0484 3356 BrSerWdm - ok
12:03:03.0484 3356 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
12:03:03.0484 3356 BrUsbMdm - ok
12:03:03.0484 3356 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
12:03:03.0484 3356 BrUsbSer - ok
12:03:03.0499 3356 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
12:03:03.0499 3356 BTHMODEM - ok
12:03:03.0515 3356 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
12:03:03.0515 3356 bthserv - ok
12:03:03.0546 3356 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:03:03.0546 3356 cdfs - ok
12:03:03.0562 3356 [ 83D2D75E1EFB81B3450C18131443F7DB ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
12:03:03.0562 3356 cdrom - ok
12:03:03.0577 3356 [ 312E2F82AF11E79906898AC3E3D58A1F ] CertPropSvc C:\Windows\System32\certprop.dll
12:03:03.0577 3356 CertPropSvc - ok
12:03:03.0593 3356 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
12:03:03.0593 3356 circlass - ok
12:03:03.0608 3356 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
12:03:03.0608 3356 CLFS - ok
12:03:03.0749 3356 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:03:03.0764 3356 clr_optimization_v2.0.50727_32 - ok
12:03:03.0858 3356 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:03:03.0858 3356 clr_optimization_v2.0.50727_64 - ok
12:03:03.0983 3356 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:03:03.0983 3356 clr_optimization_v4.0.30319_32 - ok
12:03:04.0045 3356 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:03:04.0061 3356 clr_optimization_v4.0.30319_64 - ok
12:03:04.0092 3356 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
12:03:04.0092 3356 CmBatt - ok
12:03:04.0279 3356 [ A8D8C1A401A2C50714A7C60F67E63657 ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
12:03:04.0373 3356 cmdAgent - ok
12:03:04.0420 3356 [ 304A483EAA36A902528A270B2355B81A ] cmderd C:\Windows\system32\DRIVERS\cmderd.sys
12:03:04.0420 3356 cmderd - ok
12:03:04.0466 3356 [ 548573D78FDD43DE2ADE2DDA7A5644AC ] cmdGuard C:\Windows\system32\DRIVERS\cmdguard.sys
12:03:04.0466 3356 cmdGuard - ok
12:03:04.0482 3356 [ C49E1215C76EFE38C8E5EA1F29B3D870 ] cmdHlp C:\Windows\system32\DRIVERS\cmdhlp.sys
12:03:04.0482 3356 cmdHlp - ok
12:03:04.0482 3356 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
12:03:04.0482 3356 cmdide - ok
12:03:04.0498 3356 [ 385513BBCE70F13AB634CBBB0CA2A55B ] cmdvirth C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
12:03:04.0498 3356 cmdvirth - ok
12:03:04.0544 3356 [ F95FD4CB7DA00BA2A63CE9F6B5C053E1 ] CNG C:\Windows\system32\Drivers\cng.sys
12:03:04.0544 3356 CNG - ok
12:03:04.0544 3356 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
12:03:04.0544 3356 Compbatt - ok
12:03:04.0576 3356 [ F26B3A86F6FA87CA360B879581AB4123 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
12:03:04.0576 3356 CompositeBus - ok
12:03:04.0591 3356 COMSysApp - ok
12:03:04.0591 3356 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
12:03:04.0591 3356 crcdisk - ok
12:03:04.0638 3356 [ 8C57411B66282C01533CB776F98AD384 ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:03:04.0638 3356 CryptSvc - ok
12:03:04.0654 3356 [ 4A6173C2279B498CD8F57CAE504564CB ] CSC C:\Windows\system32\drivers\csc.sys
12:03:04.0654 3356 CSC - ok
12:03:04.0685 3356 [ 873FBF927C06E5CEE04DEC617502F8FD ] CscService C:\Windows\System32\cscsvc.dll
12:03:04.0700 3356 CscService - ok
12:03:04.0732 3356 [ 7266972E86890E2B30C0C322E906B027 ] DcomLaunch C:\Windows\system32\rpcss.dll
12:03:04.0747 3356 DcomLaunch - ok
12:03:04.0794 3356 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
12:03:04.0794 3356 defragsvc - ok
12:03:04.0825 3356 [ 3F1DC527070ACB87E40AFE46EF6DA749 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
12:03:04.0825 3356 DfsC - ok
12:03:04.0841 3356 [ CE3B9562D997F69B330D181A8875960F ] Dhcp C:\Windows\system32\dhcpcore.dll
12:03:04.0856 3356 Dhcp - ok
12:03:04.0856 3356 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
12:03:04.0856 3356 discache - ok
12:03:04.0872 3356 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
12:03:04.0872 3356 Disk - ok
12:03:04.0919 3356 [ 676108C4E3AA6F6B34633748BD0BEBD9 ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:03:04.0919 3356 Dnscache - ok
12:03:04.0997 3356 [ 14452ACDB09B70964C8C21BF80A13ACB ] dot3svc C:\Windows\System32\dot3svc.dll
12:03:04.0997 3356 dot3svc - ok
12:03:05.0012 3356 [ 8C2BA6BEA949EE6E68385F5692BAFB94 ] DPS C:\Windows\system32\dps.dll
12:03:05.0012 3356 DPS - ok
12:03:05.0090 3356 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:03:05.0106 3356 drmkaud - ok
12:03:05.0215 3356 [ 7CB7D2B73813CE05C7BC0F5F95D27CEC ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:03:05.0246 3356 DXGKrnl - ok
12:03:05.0761 3356 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
12:03:06.0214 3356 EapHost - ok
12:03:06.0401 3356 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
12:03:06.0479 3356 ebdrv - ok
12:03:06.0557 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] EFS C:\Windows\System32\lsass.exe
12:03:06.0604 3356 EFS - ok
12:03:07.0056 3356 [ B91D81B3B54A54CCAFC03733DBC2E29E ] ehRecvr C:\Windows\ehome\ehRecvr.exe
12:03:07.0087 3356 ehRecvr - ok
12:03:07.0087 3356 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
12:03:07.0103 3356 ehSched - ok
12:03:07.0134 3356 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
12:03:07.0165 3356 elxstor - ok
12:03:07.0165 3356 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
12:03:07.0196 3356 ErrDev - ok
12:03:07.0274 3356 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
12:03:07.0290 3356 EventSystem - ok
12:03:07.0352 3356 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
12:03:07.0368 3356 exfat - ok
12:03:07.0384 3356 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:03:07.0384 3356 fastfat - ok
12:03:07.0477 3356 [ D607B2F1BEE3992AA6C2C92C0A2F0855 ] Fax C:\Windows\system32\fxssvc.exe
12:03:07.0493 3356 Fax - ok
12:03:07.0493 3356 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
12:03:07.0508 3356 fdc - ok
12:03:07.0524 3356 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
12:03:07.0524 3356 fdPHost - ok
12:03:07.0555 3356 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
12:03:07.0555 3356 FDResPub - ok
12:03:07.0555 3356 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:03:07.0571 3356 FileInfo - ok
12:03:07.0571 3356 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:03:07.0571 3356 Filetrace - ok
12:03:07.0586 3356 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
12:03:07.0586 3356 flpydisk - ok
12:03:07.0664 3356 [ F7866AF72ABBAF84B1FA5AA195378C59 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:03:07.0711 3356 FltMgr - ok
12:03:08.0039 3356 [ 8AC4CB4EA61E41009FAE9AE7B2B5DA3A ] FontCache C:\Windows\system32\FntCache.dll
12:03:08.0132 3356 FontCache - ok
12:03:08.0210 3356 [ 8D89E3131C27FDD6932189CB785E1B7A ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:03:08.0226 3356 FontCache3.0.0.0 - ok
12:03:08.0335 3356 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
12:03:08.0335 3356 FsDepends - ok
12:03:08.0351 3356 [ E95EF8547DE20CF0603557C0CF7A9462 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:03:08.0351 3356 Fs_Rec - ok
12:03:08.0413 3356 [ B8B2A6E1558F8F5DE5CE431C5B2C7B09 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
12:03:08.0429 3356 fvevol - ok
12:03:08.0444 3356 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
12:03:08.0444 3356 gagp30kx - ok
12:03:08.0663 3356 [ FE5AB4525BC2EC68B9119A6E5D40128B ] gpsvc C:\Windows\System32\gpsvc.dll
12:03:08.0678 3356 gpsvc - ok
12:03:08.0912 3356 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:03:08.0912 3356 gupdate - ok
12:03:08.0928 3356 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:03:08.0928 3356 gupdatem - ok
12:03:08.0959 3356 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
12:03:08.0959 3356 hcw85cir - ok
12:03:09.0084 3356 [ 6410F6F415B2A5A9037224C41DA8BF12 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:03:09.0162 3356 HdAudAddService - ok
12:03:09.0739 3356 [ 0A49913402747A0B67DE940FB42CBDBB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
12:03:09.0739 3356 HDAudBus - ok
12:03:09.0755 3356 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
12:03:09.0803 3356 HidBatt - ok
12:03:09.0893 3356 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
12:03:09.0896 3356 HidBth - ok
12:03:09.0983 3356 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
12:03:10.0018 3356 HidIr - ok
12:03:10.0169 3356 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
12:03:10.0234 3356 hidserv - ok
12:03:10.0442 3356 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
12:03:10.0517 3356 HidUsb - ok
12:03:10.0592 3356 [ EFA58EDE58DD74388FFD04CB32681518 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:03:10.0651 3356 hkmsvc - ok
12:03:11.0009 3356 [ 046B2673767CA626E2CFB7FDF735E9E8 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:03:11.0103 3356 HomeGroupListener - ok
12:03:11.0344 3356 [ 06A7422224D9865A5613710A089987DF ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:03:11.0372 3356 HomeGroupProvider - ok
12:03:11.0419 3356 [ 0886D440058F203EBA0E1825E4355914 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
12:03:11.0479 3356 HpSAMD - ok
12:03:11.0919 3356 [ CEE049CAC4EFA7F4E1E4AD014414A5D4 ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:03:11.0969 3356 HTTP - ok
12:03:12.0070 3356 [ F17766A19145F111856378DF337A5D79 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
12:03:12.0070 3356 hwpolicy - ok
12:03:12.0176 3356 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
12:03:12.0206 3356 i8042prt - ok
12:03:12.0590 3356 [ D83EFB6FD45DF9D55E9A1AFC63640D50 ] iaStorV C:\Windows\system32\DRIVERS\iaStorV.sys
12:03:12.0641 3356 iaStorV - ok
12:03:13.0261 3356 [ 2F2BE70D3E02B6FA877921AB9516D43C ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:03:13.0355 3356 idsvc - ok
12:03:13.0461 3356 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
12:03:13.0500 3356 iirsp - ok
12:03:14.0147 3356 [ C5B4683680DF085B57BC53E5EF34861F ] IKEEXT C:\Windows\System32\ikeext.dll
12:03:14.0315 3356 IKEEXT - ok
12:03:14.0506 3356 [ FE18B2510232B3D8BD88C880F9B45482 ] inspect C:\Windows\system32\DRIVERS\inspect.sys
12:03:14.0507 3356 inspect - ok
12:03:14.0623 3356 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\DRIVERS\intelide.sys
12:03:14.0624 3356 intelide - ok
12:03:14.0698 3356 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
12:03:14.0779 3356 intelppm - ok
12:03:14.0886 3356 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
12:03:14.0913 3356 IPBusEnum - ok
12:03:15.0033 3356 [ 722DD294DF62483CECAAE6E094B4D695 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:03:15.0054 3356 IpFilterDriver - ok
12:03:15.0340 3356 [ F8E058D17363EC580E4B7232778B6CB5 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:03:15.0359 3356 iphlpsvc - ok
12:03:15.0415 3356 [ E2B4A4494DB7CB9B89B55CA268C337C5 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:03:15.0440 3356 IPMIDRV - ok
12:03:15.0483 3356 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
12:03:15.0509 3356 IPNAT - ok
12:03:15.0639 3356 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:03:15.0717 3356 IRENUM - ok
12:03:15.0874 3356 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
12:03:15.0927 3356 isapnp - ok
12:03:16.0100 3356 [ FA4D2557DE56D45B0A346F93564BE6E1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
12:03:16.0115 3356 iScsiPrt - ok
12:03:16.0223 3356 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
12:03:16.0224 3356 kbdclass - ok
12:03:16.0334 3356 [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
12:03:16.0428 3356 kbdhid - ok
12:03:16.0499 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] KeyIso C:\Windows\system32\lsass.exe
12:03:16.0500 3356 KeyIso - ok
12:03:16.0579 3356 [ E8B6FCC9C83535C67F835D407620BD27 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:03:16.0610 3356 KSecDD - ok
12:03:16.0696 3356 [ BBE1BF6D9B661C354D4857D5FADB943B ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
12:03:16.0733 3356 KSecPkg - ok
12:03:16.0798 3356 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
12:03:16.0851 3356 ksthunk - ok
12:03:16.0993 3356 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
12:03:17.0016 3356 KtmRm - ok
12:03:17.0178 3356 [ C926920B8978DE6ACFE9E15C709E9B57 ] LanmanServer C:\Windows\system32\srvsvc.dll
12:03:17.0225 3356 LanmanServer - ok
12:03:17.0380 3356 [ 27026EAC8818E8A6C00A1CAD2F11D29A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:03:17.0395 3356 LanmanWorkstation - ok
12:03:17.0629 3356 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:03:17.0645 3356 lltdio - ok
12:03:17.0793 3356 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:03:17.0805 3356 lltdsvc - ok
12:03:17.0831 3356 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:03:17.0832 3356 lmhosts - ok
12:03:17.0859 3356 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
12:03:17.0865 3356 LSI_FC - ok
12:03:17.0965 3356 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
12:03:17.0977 3356 LSI_SAS - ok
12:03:18.0096 3356 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:03:18.0119 3356 LSI_SAS2 - ok
12:03:18.0208 3356 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:03:18.0243 3356 LSI_SCSI - ok
12:03:18.0258 3356 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
12:03:18.0274 3356 luafv - ok
12:03:18.0298 3356 [ F84C8F1000BC11E3B7B23CBD3BAFF111 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
12:03:18.0306 3356 Mcx2Svc - ok
12:03:18.0377 3356 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
12:03:18.0413 3356 megasas - ok
12:03:18.0510 3356 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
12:03:18.0548 3356 MegaSR - ok
12:03:18.0752 3356 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
12:03:18.0779 3356 MMCSS - ok
12:03:18.0798 3356 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
12:03:18.0832 3356 Modem - ok
12:03:18.0881 3356 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:03:18.0894 3356 monitor - ok
12:03:18.0957 3356 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
12:03:18.0957 3356 mouclass - ok
12:03:19.0073 3356 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
12:03:19.0100 3356 mouhid - ok
12:03:19.0190 3356 [ 791AF66C4D0E7C90A3646066386FB571 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
12:03:19.0194 3356 mountmgr - ok
12:03:19.0246 3356 [ 609D1D87649ECC19796F4D76D4C15CEA ] mpio C:\Windows\system32\DRIVERS\mpio.sys
12:03:19.0252 3356 mpio - ok
12:03:19.0288 3356 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:03:19.0310 3356 mpsdrv - ok
12:03:19.0442 3356 [ AECAB449567D1846DAD63ECE49E893E3 ] MpsSvc C:\Windows\system32\mpssvc.dll
12:03:19.0471 3356 MpsSvc - ok
12:03:19.0491 3356 [ 30524261BB51D96D6FCBAC20C810183C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:03:19.0506 3356 MRxDAV - ok
12:03:19.0533 3356 [ CFDCD8CA87C2A657DEBC150AC35B5E08 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:03:19.0557 3356 mrxsmb - ok
12:03:19.0612 3356 [ 1BEE517B220B7F024F411AEC1571DD5A ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:03:19.0635 3356 mrxsmb10 - ok
12:03:19.0660 3356 [ 6B2D5FEF385828B6E485C1C90AFB8195 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:03:19.0678 3356 mrxsmb20 - ok
12:03:19.0740 3356 [ 5C37497276E3B3A5488B23A326A754B7 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
12:03:19.0748 3356 msahci - ok
12:03:19.0783 3356 [ 8D27B597229AED79430FB9DB3BCBFBD0 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
12:03:19.0806 3356 msdsm - ok
12:03:19.0838 3356 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
12:03:19.0854 3356 MSDTC - ok
12:03:19.0929 3356 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:03:19.0940 3356 Msfs - ok
12:03:19.0976 3356 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
12:03:20.0044 3356 mshidkmdf - ok
12:03:20.0073 3356 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
12:03:20.0073 3356 msisadrv - ok
12:03:20.0157 3356 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:03:20.0172 3356 MSiSCSI - ok
12:03:20.0176 3356 msiserver - ok
12:03:20.0215 3356 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:03:20.0223 3356 MSKSSRV - ok
12:03:20.0239 3356 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:03:20.0261 3356 MSPCLOCK - ok
12:03:20.0273 3356 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:03:20.0286 3356 MSPQM - ok
12:03:20.0342 3356 [ 89CB141AA8616D8C6A4610FA26C60964 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:03:20.0356 3356 MsRPC - ok
12:03:20.0470 3356 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
12:03:20.0471 3356 mssmbios - ok
12:03:20.0519 3356 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:03:20.0540 3356 MSTEE - ok
12:03:20.0546 3356 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
12:03:20.0559 3356 MTConfig - ok
12:03:20.0600 3356 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
12:03:20.0601 3356 Mup - ok
12:03:20.0639 3356 [ 4987E079A4530FA737A128BE54B63B12 ] napagent C:\Windows\system32\qagentRT.dll
12:03:20.0823 3356 napagent - ok
12:03:20.0911 3356 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:03:20.0949 3356 NativeWifiP - ok
12:03:21.0112 3356 [ CAD515DBD07D082BB317D9928CE8962C ] NDIS C:\Windows\system32\drivers\ndis.sys
12:03:21.0145 3356 NDIS - ok
12:03:21.0157 3356 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
12:03:21.0173 3356 NdisCap - ok
12:03:21.0173 3356 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:03:21.0173 3356 NdisTapi - ok
12:03:21.0189 3356 [ F105BA1E22BF1F2EE8F005D4305E4BEC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:03:21.0189 3356 Ndisuio - ok
12:03:21.0204 3356 [ 557DFAB9CA1FCB036AC77564C010DAD3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:03:21.0228 3356 NdisWan - ok
12:03:21.0276 3356 [ 659B74FB74B86228D6338D643CD3E3CF ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:03:21.0287 3356 NDProxy - ok
12:03:21.0344 3356 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:03:21.0368 3356 NetBIOS - ok
12:03:21.0417 3356 [ 9162B273A44AB9DCE5B44362731D062A ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
12:03:21.0459 3356 NetBT - ok
12:03:21.0470 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] Netlogon C:\Windows\system32\lsass.exe
12:03:21.0472 3356 Netlogon - ok
12:03:21.0572 3356 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
12:03:21.0610 3356 Netman - ok
12:03:21.0727 3356 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
12:03:21.0733 3356 netprofm - ok
12:03:21.0756 3356 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:03:21.0868 3356 NetTcpPortSharing - ok
12:03:21.0947 3356 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
12:03:21.0968 3356 nfrd960 - ok
12:03:22.0110 3356 [ D9A0CE66046D6EFA0C61BAA885CBA0A8 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:03:22.0128 3356 NlaSvc - ok
12:03:22.0148 3356 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:03:22.0163 3356 Npfs - ok
12:03:22.0305 3356 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
12:03:22.0307 3356 nsi - ok
12:03:22.0320 3356 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:03:22.0321 3356 nsiproxy - ok
12:03:22.0546 3356 [ 356698A13C4630D5B31C37378D469196 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:03:22.0565 3356 Ntfs - ok
12:03:22.0594 3356 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
12:03:22.0595 3356 Null - ok
12:03:22.0643 3356 [ 3E38712941E9BB4DDBEE00AFFE3FED3D ] nvraid C:\Windows\system32\DRIVERS\nvraid.sys
12:03:22.0649 3356 nvraid - ok
12:03:22.0693 3356 [ 477DC4D6DEB99BE37084C9AC6D013DA1 ] nvstor C:\Windows\system32\DRIVERS\nvstor.sys
12:03:22.0716 3356 nvstor - ok
12:03:22.0757 3356 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
12:03:22.0759 3356 nv_agp - ok
12:03:22.0795 3356 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
12:03:22.0796 3356 ohci1394 - ok
12:03:22.0881 3356 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
12:03:22.0899 3356 p2pimsvc - ok
12:03:22.0929 3356 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
12:03:22.0944 3356 p2psvc - ok
12:03:22.0965 3356 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
12:03:22.0966 3356 Parport - ok
12:03:22.0971 3356 [ 7DAA117143316C4A1537E074A5A9EAF0 ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:03:22.0972 3356 partmgr - ok
12:03:22.0998 3356 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
12:03:23.0002 3356 PcaSvc - ok
12:03:23.0032 3356 [ F36F6504009F2FB0DFD1B17A116AD74B ] pci C:\Windows\system32\DRIVERS\pci.sys
12:03:23.0051 3356 pci - ok
12:03:23.0086 3356 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\DRIVERS\pciide.sys
12:03:23.0087 3356 pciide - ok
12:03:23.0104 3356 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
12:03:23.0112 3356 pcmcia - ok
12:03:23.0129 3356 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
12:03:23.0130 3356 pcw - ok
12:03:23.0164 3356 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:03:23.0214 3356 PEAUTH - ok
12:03:23.0299 3356 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
12:03:23.0330 3356 PeerDistSvc - ok
12:03:24.0131 3356 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
12:03:24.0133 3356 PerfHost - ok
12:03:24.0198 3356 [ 557E9A86F65F0DE18C9B6751DFE9D3F1 ] pla C:\Windows\system32\pla.dll
12:03:24.0223 3356 pla - ok
12:03:24.0337 3356 [ 23157D583244400E1D7FBAEE2E4B31B7 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:03:24.0348 3356 PlugPlay - ok
12:03:24.0367 3356 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
12:03:24.0379 3356 PNRPAutoReg - ok
12:03:24.0439 3356 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
12:03:24.0442 3356 PNRPsvc - ok
12:03:24.0538 3356 [ 166EB40D1F5B47E615DE3D0FFFE5F243 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:03:24.0550 3356 PolicyAgent - ok
12:03:24.0561 3356 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
12:03:24.0570 3356 Power - ok
12:03:24.0632 3356 [ 27CC19E81BA5E3403C48302127BDA717 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:03:24.0639 3356 PptpMiniport - ok
12:03:24.0686 3356 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
12:03:24.0686 3356 Processor - ok
12:03:24.0873 3356 [ F381975E1F4346DE875CB07339CE8D3A ] ProfSvc C:\Windows\system32\profsvc.dll
12:03:24.0884 3356 ProfSvc - ok
12:03:24.0897 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] ProtectedStorage C:\Windows\system32\lsass.exe
12:03:24.0899 3356 ProtectedStorage - ok
12:03:24.0961 3356 [ EE992183BD8EAEFD9973F352E587A299 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
12:03:24.0966 3356 Psched - ok
12:03:25.0227 3356 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
12:03:25.0244 3356 ql2300 - ok
12:03:25.0304 3356 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
12:03:25.0309 3356 ql40xx - ok
12:03:25.0350 3356 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
12:03:25.0360 3356 QWAVE - ok
12:03:25.0370 3356 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:03:25.0376 3356 QWAVEdrv - ok
12:03:25.0385 3356 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:03:25.0393 3356 RasAcd - ok
12:03:25.0469 3356 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
12:03:25.0480 3356 RasAgileVpn - ok
12:03:25.0501 3356 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
12:03:25.0508 3356 RasAuto - ok
12:03:25.0569 3356 [ 87A6E852A22991580D6D39ADC4790463 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:03:25.0583 3356 Rasl2tp - ok
12:03:25.0647 3356 [ 47394ED3D16D053F5906EFE5AB51CC83 ] RasMan C:\Windows\System32\rasmans.dll
12:03:25.0689 3356 RasMan - ok
12:03:25.0728 3356 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:03:25.0758 3356 RasPppoe - ok
12:03:25.0829 3356 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:03:25.0871 3356 RasSstp - ok
12:03:26.0038 3356 [ 3BAC8142102C15D59A87757C1D41DCE5 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:03:26.0078 3356 rdbss - ok
12:03:26.0104 3356 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
12:03:26.0142 3356 rdpbus - ok
12:03:26.0165 3356 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:03:26.0187 3356 RDPCDD - ok
12:03:26.0254 3356 [ 9706B84DBABFC4B4CA46C5A82B14DFA3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
12:03:26.0265 3356 RDPDR - ok
12:03:26.0498 3356 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:03:26.0544 3356 RDPENCDD - ok
12:03:26.0585 3356 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
12:03:26.0638 3356 RDPREFMP - ok
12:03:26.0740 3356 [ 8A3E6BEA1C53EA6177FE2B6EBA2C80D7 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:03:26.0764 3356 RDPWD - ok
12:03:26.0910 3356 [ 634B9A2181D98F15941236886164EC8B ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
12:03:26.0944 3356 rdyboost - ok
12:03:26.0988 3356 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:03:26.0999 3356 RemoteAccess - ok
12:03:27.0181 3356 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:03:27.0217 3356 RemoteRegistry - ok
12:03:27.0333 3356 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
12:03:27.0367 3356 RpcEptMapper - ok
12:03:27.0451 3356 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
12:03:27.0470 3356 RpcLocator - ok
12:03:27.0701 3356 [ 7266972E86890E2B30C0C322E906B027 ] RpcSs C:\Windows\system32\rpcss.dll
12:03:27.0705 3356 RpcSs - ok
12:03:27.0795 3356 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:03:27.0819 3356 rspndr - ok
12:03:28.0140 3356 [ 7F4F11527AF5A7E4526CB6A146B3E40C ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
12:03:28.0145 3356 RTL8167 - ok
12:03:28.0342 3356 [ 2B38C905492F36FE42B59DA52D6B4EB7 ] RtNdPt60 C:\Windows\system32\DRIVERS\RtNdPt60.sys
12:03:28.0353 3356 RtNdPt60 - ok
12:03:28.0470 3356 [ 8DF706A5A12A4832A3291A1FF26A7CC1 ] RTTEAMPT C:\Windows\system32\DRIVERS\RtTeam60.sys
12:03:28.0486 3356 RTTEAMPT - ok
12:03:28.0517 3356 [ ED0624ED83121E1BC141F49B1316CAA0 ] RTVLANPT C:\Windows\system32\DRIVERS\RtVlan620.sys
12:03:28.0548 3356 RTVLANPT - ok
12:03:28.0595 3356 [ 88AF6E02AB19DF7FD07ECDF9C91E9AF6 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
12:03:28.0595 3356 s3cap - ok
12:03:28.0626 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] SamSs C:\Windows\system32\lsass.exe
12:03:28.0626 3356 SamSs - ok
12:03:28.0694 3356 [ E3BBB89983DAF5622C1D50CF49F28227 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
12:03:28.0709 3356 sbp2port - ok
12:03:28.0904 3356 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:03:28.0916 3356 SCardSvr - ok
12:03:28.0962 3356 [ C94DA20C7E3BA1DCA269BC8460D98387 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
12:03:28.0975 3356 scfilter - ok
12:03:29.0274 3356 [ EC56B171F85C7E855E7B0588AC503EEA ] Schedule C:\Windows\system32\schedsvc.dll
12:03:29.0302 3356 Schedule - ok
12:03:29.0358 3356 [ 312E2F82AF11E79906898AC3E3D58A1F ] SCPolicySvc C:\Windows\System32\certprop.dll
12:03:29.0359 3356 SCPolicySvc - ok
12:03:29.0396 3356 [ 765A27C3279CE11D14CB9E4F5869FCA5 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:03:29.0421 3356 SDRSVC - ok
12:03:29.0514 3356 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:03:29.0528 3356 secdrv - ok
12:03:29.0559 3356 [ 463B386EBC70F98DA5DFF85F7E654346 ] seclogon C:\Windows\system32\seclogon.dll
12:03:29.0573 3356 seclogon - ok
12:03:29.0591 3356 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
12:03:29.0593 3356 SENS - ok
12:03:29.0632 3356 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
12:03:29.0641 3356 SensrSvc - ok
12:03:29.0706 3356 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:03:29.0716 3356 Serenum - ok
12:03:29.0742 3356 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:03:29.0757 3356 Serial - ok
12:03:29.0784 3356 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
12:03:29.0832 3356 sermouse - ok
12:03:29.0878 3356 [ C3BC61CE47FF6F4E88AB8A3B429A36AF ] SessionEnv C:\Windows\system32\sessenv.dll
12:03:29.0894 3356 SessionEnv - ok
12:03:29.0910 3356 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
12:03:29.0910 3356 sffdisk - ok
12:03:29.0925 3356 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:03:29.0925 3356 sffp_mmc - ok
12:03:29.0941 3356 [ 5588B8C6193EB1522490C122EB94DFFA ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
12:03:29.0941 3356 sffp_sd - ok
12:03:29.0988 3356 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
12:03:30.0003 3356 sfloppy - ok
12:03:30.0128 3356 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:03:30.0128 3356 SharedAccess - ok
12:03:30.0237 3356 [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:03:30.0253 3356 ShellHWDetection - ok
12:03:30.0300 3356 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:03:30.0346 3356 SiSRaid2 - ok
12:03:30.0362 3356 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
12:03:30.0378 3356 SiSRaid4 - ok
12:03:30.0424 3356 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:03:30.0434 3356 Smb - ok
12:03:30.0497 3356 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:03:30.0512 3356 SNMPTRAP - ok
12:03:30.0567 3356 [ 12583AF6CBE0050651EAF2723B3AD7B3 ] speedfan C:\Windows\syswow64\speedfan.sys
12:03:30.0569 3356 speedfan - ok
12:03:30.0615 3356 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
12:03:30.0615 3356 spldr - ok
12:03:30.0698 3356 [ 89E8550C5862999FCF482EA562B0E98E ] Spooler C:\Windows\System32\spoolsv.exe
12:03:30.0710 3356 Spooler - ok
12:03:31.0400 3356 [ 913D843498553A1BC8F8DBAD6358E49F ] sppsvc C:\Windows\system32\sppsvc.exe
12:03:31.0416 3356 sppsvc - ok
12:03:31.0451 3356 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
12:03:31.0467 3356 sppuinotify - ok
12:03:31.0563 3356 [ EC8F67289105BF270498095F14963464 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:03:31.0577 3356 srv - ok
12:03:31.0765 3356 [ F773D2ED090B7BAA1C1A034F3CA476C8 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:03:31.0775 3356 srv2 - ok
12:03:31.0782 3356 [ 26E84D3649019C3244622E654DFCD75B ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:03:31.0785 3356 srvnet - ok
12:03:31.0903 3356 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:03:31.0917 3356 SSDPSRV - ok
12:03:31.0930 3356 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:03:31.0936 3356 SstpSvc - ok
12:03:31.0965 3356 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
12:03:31.0967 3356 stexstor - ok
12:03:32.0002 3356 [ 52D0E33B681BD0F33FDC08812FEE4F7D ] stisvc C:\Windows\System32\wiaservc.dll
12:03:32.0019 3356 stisvc - ok
12:03:32.0059 3356 [ FFD7A6F15B14234B5B0E5D49E7961895 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
12:03:32.0060 3356 storflt - ok
12:03:32.0090 3356 [ 8FCCBEFC5C440B3C23454656E551B09A ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
12:03:32.0098 3356 storvsc - ok
12:03:32.0107 3356 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
12:03:32.0107 3356 swenum - ok
12:03:32.0156 3356 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
12:03:32.0180 3356 swprv - ok
12:03:32.0415 3356 [ 3C1284516A62078FB68F768DE4F1A7BE ] SysMain C:\Windows\system32\sysmain.dll
12:03:32.0445 3356 SysMain - ok
12:03:32.0541 3356 [ 238935C3CF2854886DC7CBB2A0E2CC66 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:03:32.0552 3356 TabletInputService - ok
12:03:32.0635 3356 [ 884264AC597B690C5707C89723BB8E7B ] TapiSrv C:\Windows\System32\tapisrv.dll
12:03:32.0658 3356 TapiSrv - ok
12:03:32.0696 3356 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
12:03:32.0717 3356 TBS - ok
12:03:32.0964 3356 [ 912107716BAB424C7870E8E6AF5E07E1 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:03:32.0994 3356 Tcpip - ok
12:03:33.0102 3356 [ 912107716BAB424C7870E8E6AF5E07E1 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
12:03:33.0115 3356 TCPIP6 - ok
12:03:33.0174 3356 [ 76D078AF6F587B162D50210F761EB9ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:03:33.0198 3356 tcpipreg - ok
12:03:33.0216 3356 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:03:33.0237 3356 TDPIPE - ok
12:03:33.0246 3356 [ E4245BDA3190A582D55ED09E137401A9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:03:33.0247 3356 TDTCP - ok
12:03:33.0286 3356 [ 079125C4B17B01FCAEEBCE0BCB290C0F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:03:33.0303 3356 tdx - ok
12:03:33.0359 3356 [ 8DF706A5A12A4832A3291A1FF26A7CC1 ] TEAM C:\Windows\system32\DRIVERS\RtTeam60.sys
12:03:33.0360 3356 TEAM - ok
12:03:33.0372 3356 [ C448651339196C0E869A355171875522 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
12:03:33.0373 3356 TermDD - ok
12:03:33.0473 3356 [ 0F05EC2887BFE197AD82A13287D2F404 ] TermService C:\Windows\System32\termsrv.dll
12:03:33.0489 3356 TermService - ok
12:03:33.0509 3356 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
12:03:33.0750 3356 Themes - ok
12:03:33.0768 3356 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
12:03:33.0770 3356 THREADORDER - ok
12:03:33.0877 3356 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
12:03:33.0897 3356 TrkWks - ok
12:03:34.0007 3356 [ 840F7FB849F5887A49BA18C13B2DA920 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:03:34.0070 3356 TrustedInstaller - ok
12:03:34.0103 3356 [ 61B96C26131E37B24E93327A0BD1FB95 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:03:34.0116 3356 tssecsrv - ok
12:03:34.0214 3356 [ 3836171A2CDF3AF8EF10856DB9835A70 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:03:34.0248 3356 tunnel - ok
12:03:34.0298 3356 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
12:03:34.0308 3356 uagp35 - ok
12:03:34.0364 3356 [ D47BAEAD86C65D4F4069D7CE0A4EDCEB ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:03:34.0372 3356 udfs - ok
12:03:34.0439 3356 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:03:34.0451 3356 UI0Detect - ok
12:03:34.0497 3356 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
12:03:34.0520 3356 uliagpkx - ok
12:03:34.0556 3356 [ EAB6C35E62B1B0DB0D1B48B671D3A117 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
12:03:34.0578 3356 umbus - ok
12:03:34.0605 3356 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
12:03:34.0617 3356 UmPass - ok
12:03:34.0668 3356 [ AF0AC98EE5077EB844413EB54287FDE3 ] UmRdpService C:\Windows\System32\umrdp.dll
12:03:34.0687 3356 UmRdpService - ok
12:03:34.0765 3356 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
12:03:34.0790 3356 upnphost - ok
12:03:34.0873 3356 [ 77B01BC848298223A95D4EC23E1785A1 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
12:03:34.0888 3356 usbaudio - ok
12:03:34.0934 3356 [ B26AFB54A534D634523C4FB66765B026 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:03:34.0955 3356 usbccgp - ok
12:03:35.0028 3356 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
12:03:35.0038 3356 usbcir - ok
12:03:35.0071 3356 [ 2EA4AFF7BE7EB4632E3AA8595B0803B5 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:03:35.0076 3356 usbehci - ok
12:03:35.0186 3356 [ 4C9042B8DF86C1E8E6240C218B99B39B ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:03:35.0202 3356 usbhub - ok
12:03:35.0226 3356 [ 58E546BBAF87664FC57E0F6081E4F609 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
12:03:35.0241 3356 usbohci - ok
12:03:35.0270 3356 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:03:35.0279 3356 usbprint - ok
12:03:35.0339 3356 [ 080D3820DA6C046BE82FC8B45A893E83 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:03:35.0365 3356 USBSTOR - ok
12:03:35.0414 3356 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
12:03:35.0425 3356 usbuhci - ok
12:03:35.0518 3356 [ D501E12614B00A3252073101D6A1A74B ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
12:03:35.0553 3356 usbvideo - ok
12:03:35.0605 3356 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
12:03:35.0625 3356 UxSms - ok
12:03:35.0649 3356 [ 0793F40B9B8A1BDD266296409DBD91EA ] VaultSvc C:\Windows\system32\lsass.exe
12:03:35.0650 3356 VaultSvc - ok
12:03:35.0707 3356 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
12:03:35.0707 3356 vdrvroot - ok
12:03:35.0836 3356 [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds C:\Windows\System32\vds.exe
12:03:35.0867 3356 vds - ok
12:03:35.0961 3356 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:03:35.0992 3356 vga - ok
12:03:36.0023 3356 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
12:03:36.0039 3356 VgaSave - ok
12:03:36.0101 3356 [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
12:03:36.0117 3356 vhdmp - ok
12:03:36.0148 3356 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
12:03:36.0163 3356 viaide - ok
12:03:36.0210 3356 [ 1501699D7EDA984ABC4155A7DA5738D1 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
12:03:36.0210 3356 vmbus - ok
12:03:36.0257 3356 [ AE10C35761889E65A6F7176937C5592C ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
12:03:36.0257 3356 VMBusHID - ok
12:03:36.0304 3356 [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
12:03:36.0319 3356 volmgr - ok
12:03:36.0370 3356 [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:03:36.0379 3356 volmgrx - ok
12:03:36.0400 3356 [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
12:03:36.0404 3356 volsnap - ok
12:03:36.0462 3356 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
12:03:36.0476 3356 vsmraid - ok
12:03:36.0784 3356 [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS C:\Windows\system32\vssvc.exe
12:03:36.0803 3356 VSS - ok
12:03:36.0820 3356 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
12:03:36.0828 3356 vwifibus - ok
12:03:36.0883 3356 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
12:03:36.0894 3356 W32Time - ok
12:03:36.0930 3356 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
12:03:36.0941 3356 WacomPen - ok
12:03:36.0990 3356 [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
12:03:36.0992 3356 WANARP - ok
12:03:37.0012 3356 [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:03:37.0013 3356 Wanarpv6 - ok
12:03:37.0151 3356 [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine C:\Windows\system32\wbengine.exe
12:03:37.0194 3356 wbengine - ok
12:03:37.0200 3356 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:03:37.0204 3356 WbioSrvc - ok
12:03:37.0230 3356 [ 8321C2CA3B62B61B293CDA3451984468 ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:03:37.0235 3356 wcncsvc - ok
12:03:37.0240 3356 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:03:37.0243 3356 WcsPlugInService - ok
12:03:37.0258 3356 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
12:03:37.0259 3356 Wd - ok
12:03:37.0270 3356 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:03:37.0284 3356 Wdf01000 - ok
12:03:37.0339 3356 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:03:37.0341 3356 WdiServiceHost - ok
12:03:37.0341 3356 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:03:37.0341 3356 WdiSystemHost - ok
12:03:37.0404 3356 [ 8A438CBB8C032A0C798B0C642FFBE572 ] WebClient C:\Windows\System32\webclnt.dll
12:03:37.0404 3356 WebClient - ok
12:03:37.0458 3356 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:03:37.0463 3356 Wecsvc - ok
12:03:37.0498 3356 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:03:37.0501 3356 wercplsupport - ok
12:03:37.0547 3356 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
12:03:37.0559 3356 WerSvc - ok
12:03:37.0601 3356 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
12:03:37.0601 3356 WfpLwf - ok
12:03:37.0612 3356 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:03:37.0613 3356 WIMMount - ok
12:03:37.0630 3356 WinDefend - ok
12:03:37.0636 3356 WinHttpAutoProxySvc - ok
12:03:37.0745 3356 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:03:37.0748 3356 Winmgmt - ok
12:03:38.0100 3356 [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM C:\Windows\system32\WsmSvc.dll
12:03:38.0150 3356 WinRM - ok
12:03:38.0387 3356 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
12:03:38.0402 3356 Wlansvc - ok
12:03:38.0447 3356 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
12:03:38.0463 3356 WmiAcpi - ok
12:03:38.0519 3356 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:03:38.0534 3356 wmiApSrv - ok
12:03:38.0562 3356 WMPNetworkSvc - ok
12:03:38.0599 3356 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:03:38.0611 3356 WPCSvc - ok
12:03:38.0645 3356 [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:03:38.0662 3356 WPDBusEnum - ok
12:03:38.0694 3356 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:03:38.0704 3356 ws2ifsl - ok
12:03:38.0743 3356 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
12:03:38.0752 3356 wscsvc - ok
12:03:38.0756 3356 WSearch - ok
12:03:39.0075 3356 [ 38340204A2D0228F1E87740FC5E554A7 ] wuauserv C:\Windows\system32\wuaueng.dll
12:03:39.0106 3356 wuauserv - ok
12:03:39.0138 3356 [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:03:39.0152 3356 WudfPf - ok
12:03:39.0224 3356 [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:03:39.0260 3356 WUDFRd - ok
12:03:39.0341 3356 [ B551D6637AA0E132C18AC6E504F7B79B ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:03:39.0348 3356 wudfsvc - ok
12:03:39.0442 3356 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
12:03:39.0451 3356 WwanSvc - ok
12:03:39.0471 3356 ================ Scan global ===============================
12:03:39.0515 3356 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
12:03:39.0588 3356 [ 457B44AB6D502E55F64A867D4F35C76C ] C:\Windows\system32\winsrv.dll
12:03:39.0666 3356 [ 457B44AB6D502E55F64A867D4F35C76C ] C:\Windows\system32\winsrv.dll
12:03:39.0721 3356 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
12:03:39.0827 3356 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
12:03:39.0859 3356 [Global] - ok
12:03:39.0860 3356 ================ Scan MBR ==================================
12:03:39.0884 3356 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:03:40.0433 3356 \Device\Harddisk0\DR0 - ok
12:03:40.0435 3356 ================ Scan VBR ==================================
12:03:40.0448 3356 [ 905BF177134C22739FF1283804E6A791 ] \Device\Harddisk0\DR0\Partition1
12:03:40.0450 3356 \Device\Harddisk0\DR0\Partition1 - ok
12:03:40.0450 3356 ============================================================
12:03:40.0450 3356 Scan finished
12:03:40.0450 3356 ============================================================
12:03:40.0460 3348 Detected object count: 0
12:03:40.0460 3348 Actual detected object count: 0


Mogę się już brać za zmienianie bezpiecznie haseł z pewnością, że nigdzie nie zostaną wysłane?
  • 0

#4 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 06 01 2013 - 13:25

już czysto
jeszcze kosmetycznie
Uruchom OTL w okienku Własne opcje skanowania/skrypt wklej:
:OTL
O4 - HKCU..\Run: [Certificate Policy Engine] C:\Users\Frixon\AppData\Roaming\Microsoft\Windows\Templates\CertPolEng.exe File not found


Kliknij Wykonaj skrypt nie będzie restartu
Następnie:

  • 1

#5 Frixon

Frixon

    Początkujący

  • 43 postów

Napisano 06 01 2013 - 13:41

Dziękuję bardzo bardzo bardzo za pomoc. Czyli moja kariera nie legła w gruzach i mogę spać spokojnie, hehe.
Okej wykonam jeszcze ten skan, operację kosmetyczną i biorę się do roboty.
Jeszcze raz dzięki i oczywiście + leci.

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych