08:35:30.0937 0x0888 TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57 08:35:30.0968 0x0888 ============================================================ 08:35:30.0968 0x0888 Current date / time: 2015/08/03 08:35:30.0968 08:35:30.0968 0x0888 SystemInfo: 08:35:30.0968 0x0888 08:35:30.0968 0x0888 OS Version: 5.1.2600 ServicePack: 3.0 08:35:30.0968 0x0888 Product type: Workstation 08:35:30.0968 0x0888 ComputerName: SEKRETARIAT 08:35:30.0968 0x0888 UserName: Sekretariat 08:35:30.0968 0x0888 Windows directory: C:\WINDOWS 08:35:30.0968 0x0888 System windows directory: C:\WINDOWS 08:35:30.0968 0x0888 Processor architecture: Intel x86 08:35:30.0968 0x0888 Number of processors: 2 08:35:30.0968 0x0888 Page size: 0x1000 08:35:30.0968 0x0888 Boot type: Normal boot 08:35:30.0968 0x0888 ============================================================ 08:35:30.0968 0x0888 BG loaded 08:35:35.0015 0x0888 System UUID: {54C2AC23-D3F6-7960-8449-6FAD8BC10C37} 08:36:32.0250 0x0888 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000044 08:36:33.0796 0x0888 ============================================================ 08:36:33.0796 0x0888 \Device\Harddisk0\DR0: 08:36:33.0843 0x0888 MBR partitions: 08:36:33.0843 0x0888 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC34F28D 08:36:33.0875 0x0888 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC34F30B, BlocksNum 0x10E713B5 08:36:33.0875 0x0888 ============================================================ 08:36:35.0312 0x0888 C: <-> \Device\Harddisk0\DR0\Partition1 08:36:35.0968 0x0888 D: <-> \Device\Harddisk0\DR0\Partition2 08:36:36.0046 0x0888 ============================================================ 08:36:36.0046 0x0888 Initialize success 08:36:36.0046 0x0888 ============================================================ 08:36:55.0234 0x0cf8 ============================================================ 08:36:55.0234 0x0cf8 Scan started 08:36:55.0234 0x0cf8 Mode: Manual; 08:36:55.0234 0x0cf8 ============================================================ 08:36:55.0234 0x0cf8 KSN ping started 08:36:56.0890 0x0cf8 KSN ping finished: false 08:37:15.0750 0x0cf8 ================ Scan system memory ======================== 08:37:15.0750 0x0cf8 System memory - ok 08:37:15.0750 0x0cf8 ================ Scan services ============================= 08:37:15.0796 0x0cf8 Suspicious service (NoAccess): 6edf95fac9406c4e 08:37:31.0921 0x0cf8 [ 436173B92BBAFE6F3FBD018B9C166116, 189BE78DD115BB456EEC06B79997895206B435DB8E4A54FEBAD40D16AC5BECA7 ] 6edf95fac9406c4e C:\WINDOWS\System32\Drivers\6edf95fac9406c4e.sys 08:37:31.0984 0x0cf8 Suspicious file ( NoAccess ): C:\WINDOWS\System32\Drivers\6edf95fac9406c4e.sys. md5: 436173B92BBAFE6F3FBD018B9C166116, sha256: 189BE78DD115BB456EEC06B79997895206B435DB8E4A54FEBAD40D16AC5BECA7 08:37:42.0562 0x0cf8 6edf95fac9406c4e - detected Rootkit.Win32.Necurs.gen ( 0 ) 08:37:43.0437 0x0cf8 6edf95fac9406c4e ( Rootkit.Win32.Necurs.gen ) - infected 08:37:43.0437 0x0cf8 Force sending object to P2P due to detect: 6edf95fac9406c4e 08:37:43.0468 0x0cf8 Object send P2P result: false 08:37:43.0500 0x0cf8 Abiosdsk - ok 08:37:43.0500 0x0cf8 abp480n5 - ok 08:37:47.0968 0x0cf8 [ 05118282F5D039595A2B92B4A4AFE197, 390EBD6088E96571636CE0925E4899D58893D9E5DF2389C09BABBD47A5838B52 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 08:37:48.0015 0x0cf8 ACPI - ok 08:37:48.0218 0x0cf8 [ 66A42B7DB194E24B973BBCCE840A0F3F, 2550F8E5B5ACD88E4191656194E46FB8EC8CCC65AFD4B5E6D5CED9FE297B573F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 08:37:48.0218 0x0cf8 ACPIEC - ok 08:37:59.0296 0x0cf8 [ 0158F4027C0808FF65ED3B3D683339C9, 382FBE4E74FA3ABBCF60B6E1E293BC0324F9689AA7C485D9926C07FEA9FCF597 ] ADIHdAudAddService C:\WINDOWS\system32\drivers\ADIHdAud.sys 08:37:59.0375 0x0cf8 ADIHdAudAddService - ok 08:37:59.0375 0x0cf8 adpu160m - ok 08:37:59.0421 0x0cf8 [ 358063AB6C1C4173B735525CDFA65F94, E2C7E27F8E0B4C6A662313FEEE61AF02D9166F4DC40E709DBB6C73EB489A5CC5 ] AEAudio C:\WINDOWS\system32\drivers\AEAudio.sys 08:37:59.0437 0x0cf8 AEAudio - ok 08:38:00.0468 0x0cf8 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys 08:38:00.0578 0x0cf8 aec - ok 08:38:19.0359 0x0cf8 [ F6B7B1ECD7B41736BDB6FF4B092BCB79, B892C7303E08238C025409D602CB2F58D273B19B81CF04E26EA52A27EE7706DB ] AFD C:\WINDOWS\System32\drivers\afd.sys 08:38:19.0468 0x0cf8 AFD - ok 08:38:19.0500 0x0cf8 Aha154x - ok 08:38:19.0531 0x0cf8 aic78u2 - ok 08:38:19.0531 0x0cf8 aic78xx - ok 08:38:27.0687 0x0cf8 [ 27AF056D8C42F0AB3CF1DFDCBBEB3243, 9D893C6C0E8619B0B0DA9EAEB5E470A29C9D730F89EC5632134C3F753DE51AC5 ] Alerter C:\WINDOWS\system32\alrsvc.dll 08:38:27.0703 0x0cf8 Alerter - ok 08:38:30.0484 0x0cf8 [ D1738DDDFF196C5CEE6D867C136AF745, DD4780276465CB18D14B4DDBB4E70117B374B3A61C618D68B5290714330DB91F ] ALG C:\WINDOWS\System32\alg.exe 08:38:30.0484 0x0cf8 ALG - ok 08:38:30.0531 0x0cf8 AliIde - ok 08:38:30.0531 0x0cf8 amsint - ok 08:38:30.0531 0x0cf8 AppMgmt - ok 08:38:30.0531 0x0cf8 asc - ok 08:38:30.0531 0x0cf8 asc3350p - ok 08:38:30.0562 0x0cf8 asc3550 - ok 08:39:21.0578 0x0cf8 [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 08:39:22.0328 0x0cf8 aspnet_state - ok 08:39:22.0593 0x0cf8 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 08:39:22.0671 0x0cf8 AsyncMac - ok 08:39:22.0765 0x0cf8 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 08:39:22.0843 0x0cf8 atapi - ok 08:39:22.0875 0x0cf8 Atdisk - ok 08:39:22.0937 0x0cf8 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 08:39:22.0968 0x0cf8 Atmarpc - ok 08:39:23.0078 0x0cf8 [ 3A28D3E7BAD0EED3810CD918B2525B54, EFC7CEF39D58E846613E419E78ECBD300DFB18630B70110AB2936737EB2B19C1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 08:39:23.0140 0x0cf8 AudioSrv - ok 08:39:45.0765 0x0cf8 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 08:39:45.0812 0x0cf8 audstub - ok 08:40:20.0093 0x0cf8 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys 08:40:20.0140 0x0cf8 Beep - ok 08:40:58.0750 0x0cf8 [ 78200FAA6FD9C69394134C238C87FB7F, 4E70BD89BB40222CB0647E8F73DBBAB1020594AEC313848C911048D080D0F26A ] BITS C:\WINDOWS\system32\qmgr.dll 08:41:01.0156 0x0cf8 BITS - ok 08:41:11.0015 0x0cf8 [ 70CD6D71FC48BBBD1385D7B35AEADECC, B4F899D3072F4B6CAA9FFED8FD805EC8FB6B5BCF29875553FBBF3B90D3DAA4DF ] BMLoad C:\WINDOWS\system32\drivers\BMLoad.sys 08:41:11.0140 0x0cf8 BMLoad - ok 08:41:11.0203 0x0cf8 [ B98ED6D85339A66A73F32FB569EB6C01, 08DF27984060C55F8CDF5F8F9FF73816163B659030B9098F62027FE7303EEDEC ] Browser C:\WINDOWS\System32\browser.dll 08:41:11.0203 0x0cf8 Browser - ok 08:41:11.0250 0x0cf8 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 08:41:11.0265 0x0cf8 cbidf2k - ok 08:41:11.0406 0x0cf8 [ ED5411A69C5BAC78D245C893AF64352A, B7AA6DAE8AE4A6C541C36AD2B90DF3F6AC8F0160E9EE5BA8AD0D776BD5962680 ] cbVSCService C:\Program Files\Cobian Backup 10\cbVSCService.exe 08:41:11.0421 0x0cf8 cbVSCService - ok 08:41:11.0437 0x0cf8 cd20xrnt - ok 08:41:11.0468 0x0cf8 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 08:41:11.0578 0x0cf8 Cdaudio - ok 08:41:11.0625 0x0cf8 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 08:41:11.0625 0x0cf8 Cdfs - ok 08:41:11.0640 0x0cf8 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 08:41:11.0640 0x0cf8 Cdrom - ok 08:41:11.0640 0x0cf8 Changer - ok 08:41:11.0671 0x0cf8 [ 45B63DF2FB498D219FCBB4425CADE676, D58417D5D0E562E2CCBA04C82CF7E176F6F82026CB4877D45F0DC18944B72960 ] CiSvc C:\WINDOWS\system32\cisvc.exe 08:41:11.0671 0x0cf8 CiSvc - ok 08:41:11.0687 0x0cf8 [ C94F1B6F61858D6389C0FA06954FB9C4, 832A8BF5D63FD623632823DE7F36636540DAC9192B40A44C2DE6961D2E086320 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 08:41:11.0687 0x0cf8 ClipSrv - ok 08:41:11.0750 0x0cf8 [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 08:41:11.0750 0x0cf8 clr_optimization_v2.0.50727_32 - ok 08:41:11.0906 0x0cf8 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 08:41:12.0218 0x0cf8 clr_optimization_v4.0.30319_32 - ok 08:41:13.0750 0x0cf8 [ 43F37E8F60F3677E84C6AFC70C784AFD, E4B28481C63857DCD482A01A5FE9AFD3981FEA152891EC853CB664ACB4717857 ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe 08:41:14.0343 0x0cf8 cmdAgent - ok 08:41:14.0500 0x0cf8 [ D58B707F3D12AE410CA07D257FD28098, C34C2485EB10AB2B0242859FFC9064808265716D27A67CFD64CED3B0E06A53DD ] cmderd C:\WINDOWS\system32\DRIVERS\cmderd.sys 08:41:14.0515 0x0cf8 cmderd - ok 08:41:14.0578 0x0cf8 [ 251F906328AF49E7927A1AD12B543A2F, E19DDB51A77591735CF9F80DB3513F1E5EF293AAF6F825A2578A77B99A6CFFC9 ] cmdGuard C:\WINDOWS\system32\DRIVERS\cmdguard.sys 08:41:14.0625 0x0cf8 cmdGuard - ok 08:41:14.0640 0x0cf8 CmdIde - ok 08:41:14.0984 0x0cf8 [ 06302EA7EDA9DCDD7F82CEC2A03D2015, 1E4C8B4EF2145B15EE54FF68C5257CE3E2A81166ECE2734396ED692B76877F22 ] CobianBackup10 C:\Program Files\Cobian Backup 10\cbService.exe 08:41:15.0390 0x0cf8 CobianBackup10 - ok 08:41:15.0390 0x0cf8 COMSysApp - ok 08:41:15.0406 0x0cf8 Cpqarray - ok 08:41:20.0765 0x0cf8 [ 6B105FE95F2E9F0B6346044BA59D41C9, DC41FC89E6C4F4219015856AEE9D9CE365094D3C8012AFFC188C129DC3B6A9A8 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 08:41:20.0781 0x0cf8 CryptSvc - ok 08:41:20.0812 0x0cf8 dac2w2k - ok 08:41:20.0812 0x0cf8 dac960nt - ok 08:41:21.0015 0x0cf8 [ C9E5AC78D9A00B1DE8CE2AD1BDDE7E42, F00DC3529933097303FE97C0031163DC98A38C8AFBA0622805F71A728C4F1069 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 08:41:21.0062 0x0cf8 DcomLaunch - ok 08:41:21.0171 0x0cf8 [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7, 9771808A033C781758AC1356F9F51B198A0750081424F4F7A937CE0D7408CEE1 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 08:41:21.0171 0x0cf8 Dhcp - ok 08:41:21.0218 0x0cf8 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 08:41:21.0218 0x0cf8 Disk - ok 08:41:21.0218 0x0cf8 dmadmin - ok 08:41:22.0531 0x0cf8 [ BC9219ABC5696942E6F9AC8A9B28670F, DEDD84A5FC12664C7767EC5210E3B4D311664EF8BCE01C9DCF16CC98BE16EDE1 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 08:41:22.0593 0x0cf8 dmboot - ok 08:41:22.0640 0x0cf8 [ 5FA232E3BA6E1346F9F5A7E519320CB0, 1C7EEC415C291D3C5FFD479A8454347528AF4FF88F81011EF65EFA8FE8199973 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 08:41:22.0656 0x0cf8 dmio - ok 08:41:22.0687 0x0cf8 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys 08:41:22.0687 0x0cf8 dmload - ok 08:41:22.0718 0x0cf8 [ D858920A05076914D34B0388E8D96CC0, A8F231BA9022F6AEBB24C9DCC1898923F85B79DE3C8E90B696CA0B295B9C99B7 ] dmserver C:\WINDOWS\System32\dmserver.dll 08:41:22.0750 0x0cf8 dmserver - ok 08:41:22.0921 0x0cf8 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 08:41:22.0968 0x0cf8 DMusic - ok 08:41:23.0390 0x0cf8 [ 4CE42967710BEB87AE805D9DA7A87499, E03D2BE7D94B5800A558C55A3F47DCDB52992B69F735AEF7182823C82F7F19DD ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 08:41:23.0406 0x0cf8 Dnscache - ok 08:41:23.0546 0x0cf8 [ E0B7D66CF29D9ADCCF873C77821CD4CA, 09A3D28585B62FC541EF4F2CB4D749DA119BB5F98739393CFD4D745060217C65 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 08:41:23.0562 0x0cf8 Dot3svc - ok 08:41:23.0578 0x0cf8 dpti2o - ok 08:41:23.0640 0x0cf8 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 08:41:23.0687 0x0cf8 drmkaud - ok 08:41:23.0734 0x0cf8 [ 5F256C1AD50FEFDC442CD5AAB58C7DD8, 0FC1F2590195AE4B7CAA802D84CD391B56D73B99CB100BDEBD4D7C002946D06B ] EapHost C:\WINDOWS\System32\eapsvc.dll 08:41:23.0765 0x0cf8 EapHost - ok 08:41:23.0781 0x0cf8 [ ED1B71382C31FD2CF3CDC4672EFAD6EA, AF3CD28B5E6F1ED1D6B7C71C697019B2E2E79AFFE29EB6282253B30BA205F3EA ] ERSvc C:\WINDOWS\System32\ersvc.dll 08:41:23.0796 0x0cf8 ERSvc - ok 08:41:23.0828 0x0cf8 [ 8816E60BF654353E8E0D35ED98875445, 08F271179931BC03E29B47EC55E89E56AC390B52216D6A36EAF3CBAD97D0ED3C ] Eventlog C:\WINDOWS\system32\services.exe 08:41:24.0000 0x0cf8 Eventlog - ok 08:41:24.0234 0x0cf8 [ 5BB3E442E43C7BB0F38203F23C920D3C, EBF4040C740ECDEF6003AFE458F51FAFDE01D92733482A90E671FDF93B37C7C4 ] EventSystem C:\WINDOWS\system32\es.dll 08:41:24.0359 0x0cf8 EventSystem - ok 08:41:24.0921 0x0cf8 [ 57C171EA22F0A7F068FCB0CAEDD1E8E7, 9AAF39AA22372FB8582C1422581C08E61444BF843E1CE2E199EB00FBEA6F9C06 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys 08:41:25.0000 0x0cf8 ew_hwusbdev - ok 08:41:25.0203 0x0cf8 [ 61A973F60E94A551BA7B15F3460444FB, FC2FB69978D99D75673AFE9F08176F3139DCBAEDE4D339BD09DA29CD3EC01005 ] ew_usbenumfilter C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys 08:41:25.0250 0x0cf8 ew_usbenumfilter - ok 08:41:26.0609 0x0cf8 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 08:41:26.0656 0x0cf8 Fastfat - ok 08:41:26.0734 0x0cf8 [ 232D5719F86E05B7FE34F038D4FC84B2, 6FA53B1E2D4D452EEE29E6757C6169C5510A35378302BB4EE1E6B0EA3CBE834C ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 08:41:26.0812 0x0cf8 FastUserSwitchingCompatibility - ok 08:41:26.0812 0x0cf8 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 08:41:26.0843 0x0cf8 Fdc - ok 08:41:26.0906 0x0cf8 [ F8946C6D013FC9E6DB03FBCF32294799, 276C55D9AB9D08E10D6750AC65DB044734BCC1F94073A9D232452457195FC380 ] filtertdidriver C:\WINDOWS\system32\drivers\ewfiltertdidriver.sys 08:41:26.0937 0x0cf8 filtertdidriver - ok 08:41:27.0625 0x0cf8 [ 09E2A4D33F81A06A8AAB2BA0A0B5D235, D71C2D4212C7ABB1D8EE08B21C59CA25D7195F1A0E92E5BDA1DC5226A0E62CB0 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 08:41:27.0640 0x0cf8 Fips - ok 08:41:27.0640 0x0cf8 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 08:41:27.0656 0x0cf8 Flpydisk - ok 08:41:27.0718 0x0cf8 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 08:41:27.0750 0x0cf8 FltMgr - ok 08:41:29.0140 0x0cf8 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 08:41:29.0250 0x0cf8 FontCache3.0.0.0 - ok 08:41:29.0328 0x0cf8 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 08:41:29.0359 0x0cf8 Fs_Rec - ok 08:41:29.0406 0x0cf8 [ ED6D921D8AB423138FB35BEEE6D6A6CB, CF133B76960207595C44181A235E63B84C5A5A4E7BDDDC2E6A01DA837E55832D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 08:41:29.0437 0x0cf8 Ftdisk - ok 08:41:29.0500 0x0cf8 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 08:41:29.0578 0x0cf8 Gpc - ok 08:41:30.0390 0x0cf8 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 08:41:30.0390 0x0cf8 HDAudBus - ok 08:41:30.0484 0x0cf8 [ AF752014F7EB61542E3F35B9374D7E76, 8D9F1D1B03D5AF9F592C396C4B6353E17F2E852A2A7F1F468F83763C0731435D ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 08:41:30.0500 0x0cf8 helpsvc - ok 08:41:30.0546 0x0cf8 [ 1776C3B6069EEECC8042535296C1866A, 57B516B7E0C12EF16568647B069441731C0484C0D0E87900D1F2E895BD67FF18 ] HidServ C:\WINDOWS\System32\hidserv.dll 08:41:30.0562 0x0cf8 HidServ - ok 08:41:30.0593 0x0cf8 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys 08:41:30.0593 0x0cf8 hidusb - ok 08:41:30.0671 0x0cf8 [ F0273916DA6FB64CC88E0BD77619554F, C6E3B5C367CE52174251B1CE548F0DF8708AEDD228D5AD74D3F6F31FC3857460 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 08:41:30.0687 0x0cf8 hkmsvc - ok 08:41:32.0578 0x0cf8 [ 16959F84844DC9B2CEF0D5B1A412370F, 60FAE3931AC8DB4B351F42AD49D1189D90BF037739BA02EBEBC2F24A22114D3A ] HP LaserJet Service C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe 08:41:32.0625 0x0cf8 HP LaserJet Service - ok 08:41:32.0734 0x0cf8 [ 6F98A555ACF3C1B68FCC1F50E0FD2091, 2A37C2B9BD4B38A6D832CE847B8B65B7AA1E8B38D3463A3502DD4C5E12E5D7EC ] HPFXBULKLEDM C:\WINDOWS\system32\drivers\hppcbulkio.sys 08:41:32.0734 0x0cf8 HPFXBULKLEDM - ok 08:41:32.0781 0x0cf8 [ 7F854BD9C113B4569CE6579EA3847A2A, 5C9AE7588EBC1C14C948FD4EC117C8E6CB3C421282AF27281659F76C1FD8832D ] HPFXFAX C:\WINDOWS\system32\drivers\hppcfaxio.sys 08:41:32.0828 0x0cf8 HPFXFAX - ok 08:41:32.0828 0x0cf8 hpn - ok 08:41:38.0390 0x0cf8 [ 937031C085718C1C04A9C0864625EC6B, B812A70063750090202D646F466BD7F0377413F74AD109F8097CB2A1FB42466B ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 08:41:38.0406 0x0cf8 HTTP - ok 08:41:38.0453 0x0cf8 [ AA268079AC119F3A596E5E27AEE4BD17, 2FD9B52A0627B3ECE618BAC855C19002CA6F5339636D11DF9F998E588027292A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 08:41:38.0718 0x0cf8 HTTPFilter - ok 08:41:39.0656 0x0cf8 [ F44461E66F1B7DD267957FE9BAA63ED0, 5B51692F1670A43A8C1B9E2EECB4042AB04BA92AAA347405A61D3EA8C478BC5A ] huawei_enumerator C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys 08:41:39.0703 0x0cf8 huawei_enumerator - ok 08:41:40.0640 0x0cf8 [ 5EF3427AE503B5C03A48F7C9FF458B69, C75D6E860AA9A1EA0351388B137FE39CE47E96471841BDCA96FF63C87CE99132 ] HWDeviceService.exe C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\DatacardService\HWDeviceService.exe 08:41:40.0640 0x0cf8 HWDeviceService.exe - ok 08:41:40.0671 0x0cf8 i2omgmt - ok 08:41:40.0671 0x0cf8 i2omp - ok 08:41:40.0703 0x0cf8 [ 177B372AF55C4460D0968B5F1D02AA1C, 39406139B0D42C650F2C1986D85DB2260107D427963BC2C85A11D71561986DEB ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 08:41:40.0734 0x0cf8 i8042prt - ok 08:41:42.0421 0x0cf8 [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 08:41:42.0750 0x0cf8 idsvc - ok 08:41:42.0796 0x0cf8 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 08:41:42.0812 0x0cf8 Imapi - ok 08:41:42.0828 0x0cf8 [ 9125AF650608A921F98A789E5C5BA864, E530C4FE52EB66549D91490B3039EF8DBC6866E4F9B55213F21E3757892B06CE ] ImapiService C:\WINDOWS\system32\imapi.exe 08:41:42.0875 0x0cf8 ImapiService - ok 08:41:42.0890 0x0cf8 ini910u - ok 08:41:42.0906 0x0cf8 IntelIde - ok 08:41:42.0921 0x0cf8 [ DA153EDC09DE8C4F846C085CAA39D1CC, 7669572FDCC2B458A8DCBA910D0260806E6DD7845221B81C509E627AB82ED7B4 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 08:41:42.0937 0x0cf8 intelppm - ok 08:41:43.0796 0x0cf8 [ 80A3CB16C3ABAB616D33C1D8B2DB0ECE, 7DE3D5445BB1BD4563E1DF81D01366032F28F4AD445FF80D4ED4DE35DD22269A ] Internet Manager. RunOuc C:\Program Files\T-Mobile\InternetManager_H\UpdateDog\ouc.exe 08:41:43.0843 0x0cf8 Internet Manager. RunOuc - ok 08:41:43.0953 0x0cf8 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 08:41:43.0968 0x0cf8 Ip6Fw - ok 08:41:44.0031 0x0cf8 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 08:41:44.0046 0x0cf8 IpFilterDriver - ok 08:41:44.0125 0x0cf8 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 08:41:44.0140 0x0cf8 IpInIp - ok 08:41:44.0187 0x0cf8 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 08:41:44.0203 0x0cf8 IpNat - ok 08:41:44.0234 0x0cf8 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 08:41:44.0265 0x0cf8 IPSec - ok 08:41:44.0343 0x0cf8 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 08:41:44.0343 0x0cf8 IRENUM - ok 08:41:44.0375 0x0cf8 [ C8EEF2E93835B81BD335DE2123121283, DF7CCA1141CE15050D5EA516C75BF677B095EABA9E08828880E8917EBDEB2418 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 08:41:44.0390 0x0cf8 isapnp - ok 08:41:45.0140 0x0cf8 [ 9DBA73C2F1E76EC4CB837E67C5743596, 73789DCC37276DA097245E11F0686E59A686A97CCAB14404823113925C21C6AE ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 08:41:45.0171 0x0cf8 JavaQuickStarterService - ok 08:41:45.0234 0x0cf8 [ E78F71264C6C14D752C09454CFA29076, 12A3807548721A79CF34357281273507BE3826A676E9C932FC96B3A87311953B ] Jraid C:\WINDOWS\system32\drivers\Jraid.sys 08:41:45.0234 0x0cf8 Jraid - ok 08:41:45.0281 0x0cf8 [ 2AECA45D4AEAACBDCB77AD11184E4601, 58724D00A0D6FA17CCAF69DC069EF59E535F08C870C199BF2C9269BC22273A63 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 08:41:45.0312 0x0cf8 Kbdclass - ok 08:41:47.0140 0x0cf8 [ F718DCDDAC2544BC693F22977D06F78B, 8C107E6969DA588E329212F2521A9FFE18B44A38CD1FF38BC0ACE37319C8960E ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 08:41:47.0156 0x0cf8 kbdhid - ok 08:41:49.0937 0x0cf8 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 08:41:50.0078 0x0cf8 kmixer - ok 08:41:50.0437 0x0cf8 [ C6EBF1D6AD71DF30DB49B8D3287E1368, 09A8F5BCE774BA8881195AB390692048C3B05EDC8C0BF3ACBC673FD391A29D72 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 08:41:50.0453 0x0cf8 KSecDD - ok 08:41:50.0546 0x0cf8 [ 061A4BB67C324AC8C176E0D77923B212, C2877FD13FCF7EB422441D08B5BF76D9B1DCE6E9D7A19487E0D7DE14254E0F60 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 08:41:50.0578 0x0cf8 LanmanServer - ok 08:41:50.0640 0x0cf8 [ 31D2FE1091E94354336B4E85DB818745, 4660FCD78E78735CB803DD8DF23E24F3C7335344C8FFC0184FB22209C0CBBCA8 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 08:41:50.0734 0x0cf8 lanmanworkstation - ok 08:41:50.0734 0x0cf8 lbrtfdc - ok 08:41:50.0796 0x0cf8 [ 437AA83D68F9FAC234CA68DBD40DB705, 49B4A9E30778FB6D08AA7F9D66AF173572B86F74863477FFE7A66BBF2E6BCE93 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 08:41:50.0796 0x0cf8 LmHosts - ok 08:41:50.0968 0x0cf8 [ C3ED67C05F3923F9A8FEBA7A996337E1, 0A092A22339A9BFFAAB4A8A7C795480C058C0360C743BDF5D5DE042825F464A7 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe 08:41:51.0468 0x0cf8 McComponentHostService - ok 08:41:52.0687 0x0cf8 [ 11F714F85530A2BD134074DC30E99FCA, BDB5FD3B2DF4ADD19B31965B3E789768B59E872B3EA85912B1FFB32B2AF9D5D8 ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 08:41:52.0734 0x0cf8 MDM - ok 08:41:52.0750 0x0cf8 [ 36F3AB18B1BE303DA51DE90A67DE3942, E364FF831EFBDC5FF026CE620EE951C129D4E0C79DD0FED823BC767F36ED0021 ] Messenger C:\WINDOWS\System32\msgsvc.dll 08:41:52.0765 0x0cf8 Messenger - ok 08:41:52.0812 0x0cf8 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 08:41:52.0812 0x0cf8 mnmdd - ok 08:41:52.0859 0x0cf8 [ 845814A8CB9D704D030F076E1BCE83F3, F35FD4B6CE78A06A6FCF207A75EADF5A8315F2254A3E84ED070928F196D32AF4 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 08:41:52.0859 0x0cf8 mnmsrvc - ok 08:41:52.0906 0x0cf8 [ 4A068DB7DC37D5AFEDB6512D2931D7B3, 491F58509188054EE35962B66A13F0029BDF66CC59ED3B5E4058393146CE001C ] Modem C:\WINDOWS\system32\drivers\Modem.sys 08:41:52.0906 0x0cf8 Modem - ok 08:41:52.0937 0x0cf8 [ FBED3DF6B884F8CF00447B73507F2C48, 2CAA78DF3DB8BB19C10FD046B6EDC34167D8CA67EF137912703FE751D70803A2 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 08:41:52.0937 0x0cf8 Mouclass - ok 08:41:52.0968 0x0cf8 [ ECEC1E6CD558AB80F944F31326E9D3B5, E61B7124FDFE36D7C9081ABA7745F87F83592CE683AB49F7C31359D393B2E691 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 08:41:53.0000 0x0cf8 mouhid - ok 08:41:53.0031 0x0cf8 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 08:41:53.0046 0x0cf8 MountMgr - ok 08:41:53.0046 0x0cf8 mraid35x - ok 08:41:53.0109 0x0cf8 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 08:41:53.0203 0x0cf8 MRxDAV - ok 08:41:55.0125 0x0cf8 [ FB2FCCC70F7174C7BF64F48E96D3ADF4, 484B4DF0A500CAE8AFA4F3A6393615A3963D91C95939025DF1A172C9A67D951D ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 08:41:55.0453 0x0cf8 MRxSmb - ok 08:41:55.0593 0x0cf8 [ A54C5EECC7D3424824410BAE0AA6C371, C0C80211DD9A69A529B5277B0751FFABCBB6586292D06A79ED7B842277FBF78A ] MSDTC C:\WINDOWS\system32\msdtc.exe 08:41:55.0687 0x0cf8 MSDTC - ok 08:41:55.0781 0x0cf8 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 08:41:55.0796 0x0cf8 Msfs - ok 08:41:55.0796 0x0cf8 MSIServer - ok 08:41:55.0968 0x0cf8 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 08:41:56.0031 0x0cf8 MSKSSRV - ok 08:41:57.0984 0x0cf8 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 08:41:58.0140 0x0cf8 MSPCLOCK - ok 08:41:58.0812 0x0cf8 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 08:41:58.0843 0x0cf8 MSPQM - ok 08:41:59.0062 0x0cf8 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 08:41:59.0140 0x0cf8 mssmbios - ok 08:41:59.0312 0x0cf8 [ D48659BB24C48345D926ECB45C1EBDF5, EDEDE58316827530C25F8085F62AD48EA6D44B0F8AC1917B940F53B02CF72EA6 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys 08:41:59.0437 0x0cf8 MTsensor - ok 08:41:59.0765 0x0cf8 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 08:41:59.0859 0x0cf8 Mup - ok 08:42:01.0968 0x0cf8 [ 14CB8528E17D1221C50FC8CA88B1795F, E908EAE9A0E606084926941B1802E9F48AE1AC4AE6C6136345DD5699B8B9B526 ] napagent C:\WINDOWS\System32\qagentrt.dll 08:42:02.0593 0x0cf8 napagent - ok 08:42:12.0203 0x0cf8 [ 13AA2130F2A104DD775EAD0F0EE5417B, EBA07599FC2D10750CE6372EA6BA94EDDAFFF732223A1135F1971B958A6B57A2 ] NAUpdate C:\Program Files\Nero\Update\NASvc.exe 08:42:12.0453 0x0cf8 NAUpdate - ok 08:43:13.0625 0x0cf8 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 08:43:14.0031 0x0cf8 NDIS - ok 08:43:15.0578 0x0cf8 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 08:43:15.0625 0x0cf8 NdisTapi - ok 08:43:15.0984 0x0cf8 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 08:43:16.0000 0x0cf8 Ndisuio - ok 08:43:16.0015 0x0cf8 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 08:43:16.0015 0x0cf8 NdisWan - ok 08:43:16.0093 0x0cf8 [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 08:43:16.0109 0x0cf8 NDProxy - ok 08:43:16.0343 0x0cf8 [ 80B7A96F908DA13617E7E6832C5C6A64, 08B81AFE120B8064B6E001BDF424168305D55F38AE2071300F57C8EA32BEAE56 ] Net Driver HPZ12 C:\WINDOWS\system32\HPZinw12.dll 08:43:16.0656 0x0cf8 Net Driver HPZ12 - ok 08:43:16.0703 0x0cf8 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 08:43:16.0734 0x0cf8 NetBIOS - ok 08:43:17.0281 0x0cf8 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 08:43:17.0312 0x0cf8 NetBT - ok 08:43:17.0562 0x0cf8 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDE C:\WINDOWS\system32\netdde.exe 08:43:17.0984 0x0cf8 NetDDE - ok 08:43:18.0078 0x0cf8 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 08:43:18.0078 0x0cf8 NetDDEdsdm - ok 08:43:18.0250 0x0cf8 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] Netlogon C:\WINDOWS\system32\lsass.exe 08:43:18.0281 0x0cf8 Netlogon - ok 08:43:18.0390 0x0cf8 [ 4FE97D0B1B182DF2A9BDD4C02155EF5E, 46F3F4FEB501E1987B49AB1595AADC06432B70E39CA6E9CC67C6410B13DA7B7A ] Netman C:\WINDOWS\System32\netman.dll 08:43:18.0421 0x0cf8 Netman - ok 08:43:18.0593 0x0cf8 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 08:43:19.0343 0x0cf8 NetTcpPortSharing - ok 08:43:19.0453 0x0cf8 [ BF80D884E1C60DED1C7CEA3EC6F9DC28, F202CC6D27A0AC107C52E5BD77F9624BC0C02ED295040FD2E7CB4B850309AE80 ] Nla C:\WINDOWS\System32\mswsock.dll 08:43:19.0468 0x0cf8 Nla - ok 08:43:19.0578 0x0cf8 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 08:43:19.0593 0x0cf8 Npfs - ok 08:43:19.0718 0x0cf8 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 08:43:19.0859 0x0cf8 Ntfs - ok 08:43:19.0859 0x0cf8 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] NtLmSsp C:\WINDOWS\system32\lsass.exe 08:43:19.0875 0x0cf8 NtLmSsp - ok 08:43:20.0093 0x0cf8 [ 3FB5399DBB7001A80D58EDAD64C98225, A790DB873DAADB2B241F2C2426B51C0B73D4E13AC4D804B8EBBF5A74B4A41797 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 08:43:20.0156 0x0cf8 NtmsSvc - ok 08:43:20.0234 0x0cf8 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys 08:43:20.0234 0x0cf8 Null - ok 08:43:21.0500 0x0cf8 [ CD9ED87B4FC6EC41D3B5BE0B923843FC, 17E53B0913B8F58F7A6B7E636E53186E791596EB544668D11F79360346186A98 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 08:43:24.0515 0x0cf8 nv - ok 08:43:24.0765 0x0cf8 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 08:43:24.0765 0x0cf8 NwlnkFlt - ok 08:43:24.0843 0x0cf8 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 08:43:24.0875 0x0cf8 NwlnkFwd - ok 08:43:25.0296 0x0cf8 [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 08:43:25.0484 0x0cf8 ose - ok 08:43:26.0609 0x0cf8 [ 2D4CDAEBCED17743AA9E25D3016DC229, F5D138644F114861DD045975136904325304081221B85FB2C151CD9A411097CE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 08:43:26.0640 0x0cf8 Parport - ok 08:43:26.0703 0x0cf8 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 08:43:26.0718 0x0cf8 PartMgr - ok 08:43:26.0781 0x0cf8 [ 453EC2C2A20A1382F564541918520EEB, 797ED3127131BAE255AE793B8327D0E3BB6D054421F8D90511B315937BEBB6B0 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 08:43:26.0812 0x0cf8 ParVdm - ok 08:43:26.0843 0x0cf8 [ 6862C69168D787B85A7D95CCD33C694E, 6B7912156A0BAB6AED4F00FE37034488D10646B17435E86DE0D7DBD5951E8FB9 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 08:43:26.0906 0x0cf8 PCI - ok 08:43:26.0906 0x0cf8 PCIDump - ok 08:43:26.0921 0x0cf8 [ 548CF2D6369EAE441A4C6BAA75BC4F0A, C659E9E8A16DD4CBEC97FFB50784D8585E02F20FA360D2280D322D975F00A994 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 08:43:26.0953 0x0cf8 PCIIde - ok 08:43:27.0171 0x0cf8 [ 8DB27F1AE9593C94095485305A583862, 4FDB24BA306944743B50C3B0E39EFC75BD196A4DA1B0A3C859B974E8599B5128 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 08:43:27.0187 0x0cf8 Pcmcia - ok 08:43:27.0203 0x0cf8 PDCOMP - ok 08:43:27.0203 0x0cf8 PDFRAME - ok 08:43:27.0203 0x0cf8 PDRELI - ok 08:43:27.0234 0x0cf8 PDRFRAME - ok 08:43:27.0234 0x0cf8 perc2 - ok 08:43:27.0234 0x0cf8 perc2hib - ok 08:43:27.0296 0x0cf8 [ 8816E60BF654353E8E0D35ED98875445, 08F271179931BC03E29B47EC55E89E56AC390B52216D6A36EAF3CBAD97D0ED3C ] PlugPlay C:\WINDOWS\system32\services.exe 08:43:27.0515 0x0cf8 PlugPlay - ok 08:43:27.0578 0x0cf8 [ 0C155C5D8942B3CBCF9506A9D376B9AD, 37F4878548DD7063CA31FB21D6955A45C25F648C332A736DA84DEA5AAE7486AF ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.dll 08:43:27.0593 0x0cf8 Pml Driver HPZ12 - ok 08:43:27.0625 0x0cf8 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] PolicyAgent C:\WINDOWS\system32\lsass.exe 08:43:27.0625 0x0cf8 PolicyAgent - ok 08:43:27.0687 0x0cf8 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 08:43:27.0718 0x0cf8 PptpMiniport - ok 08:43:27.0750 0x0cf8 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 08:43:27.0750 0x0cf8 ProtectedStorage - ok 08:43:27.0781 0x0cf8 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 08:43:27.0781 0x0cf8 PSched - ok 08:43:27.0828 0x0cf8 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 08:43:27.0843 0x0cf8 Ptilink - ok 08:43:27.0843 0x0cf8 ql1080 - ok 08:43:27.0843 0x0cf8 Ql10wnt - ok 08:43:27.0843 0x0cf8 ql12160 - ok 08:43:27.0843 0x0cf8 ql1240 - ok 08:43:27.0843 0x0cf8 ql1280 - ok 08:43:27.0859 0x0cf8 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 08:43:27.0875 0x0cf8 RasAcd - ok 08:43:27.0906 0x0cf8 [ BC22C5E1238D4D36D65679E249C483C3, 9B01F8D9541F3558F7D6A3E079580EC87DC748EFCA43E10682C83953B8885C3B ] RasAuto C:\WINDOWS\System32\rasauto.dll 08:43:27.0937 0x0cf8 RasAuto - ok 08:43:28.0109 0x0cf8 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 08:43:28.0109 0x0cf8 Rasl2tp - ok 08:43:28.0640 0x0cf8 [ 0C392E397B8D34AAAF19EC6119CBB788, 843C0B52A92A7F62E0D503A62FE56A020655AD98BC287AE8669ACE93B6A02ECA ] RasMan C:\WINDOWS\System32\rasmans.dll 08:43:28.0703 0x0cf8 RasMan - ok 08:43:28.0718 0x0cf8 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 08:43:28.0750 0x0cf8 RasPppoe - ok 08:43:28.0828 0x0cf8 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 08:43:28.0843 0x0cf8 Raspti - ok 08:43:29.0078 0x0cf8 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 08:43:29.0109 0x0cf8 Rdbss - ok 08:43:29.0234 0x0cf8 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 08:43:29.0234 0x0cf8 RDPCDD - ok 08:43:29.0312 0x0cf8 [ FC105DD312ED64EB66BFF111E8EC6EAC, 1B29D928DDD43A1929D5A788648536603EA60AF6D4EC9BF0B20AD7F71BD88ACB ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 08:43:29.0421 0x0cf8 RDPWD - ok 08:43:29.0671 0x0cf8 [ F83907A9A038DB2E35329B039628D293, 683D478C9EC30102BB5A4CB6D200C4772C8BF5DF7BFC757AFA0B5B44DA1F8961 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 08:43:29.0687 0x0cf8 RDSessMgr - ok 08:43:29.0875 0x0cf8 [ E0C7BBD18040B58651BAC700C804861D, 91AE8D3C7D9FB391725664996479DAFDA91CB91C31E446BFE9ECF0C4FC86BE2F ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 08:43:29.0906 0x0cf8 redbook - ok 08:43:30.0046 0x0cf8 [ B3F57E6115BCD4DBADE9874F300655E3, DFF4D6AEA1B22C531216ED5A94B01C88D2C61D0EC3BB34744B4572C672EF89E6 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 08:43:30.0093 0x0cf8 RemoteAccess - ok 08:43:30.0312 0x0cf8 [ 6BC4D5A70F46EA27DDC14E5414C862A5, D78921FF982CFF26A012A413F19331AACA4F66E53D38C626FE712B4108744E31 ] RpcLocator C:\WINDOWS\system32\locator.exe 08:43:30.0421 0x0cf8 RpcLocator - ok 08:43:30.0531 0x0cf8 [ C9E5AC78D9A00B1DE8CE2AD1BDDE7E42, F00DC3529933097303FE97C0031163DC98A38C8AFBA0622805F71A728C4F1069 ] RpcSs C:\WINDOWS\system32\rpcss.dll 08:43:30.0718 0x0cf8 RpcSs - ok 08:43:31.0468 0x0cf8 [ 9ACEE3313020A01235336C2A483AFD1A, 87DD3B037FB80DC5BB9F3E335C9A0F3926481012EF9A8DE2CEF53C5386F69009 ] RSVP C:\WINDOWS\system32\rsvp.exe 08:43:31.0500 0x0cf8 RSVP - ok 08:43:31.0890 0x0cf8 [ E47C52F0380F0950E2BC9F1BCDC0DE9B, 8AC25B5F6F618DE8BAB3A3A795ECF05B4D45A00CBBB9527EA5F08FCF6E8651A7 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 08:43:31.0906 0x0cf8 RTLE8023xp - ok 08:43:31.0921 0x0cf8 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] SamSs C:\WINDOWS\system32\lsass.exe 08:43:31.0921 0x0cf8 SamSs - ok 08:43:31.0953 0x0cf8 [ C6F479218E94896738C06AF5BA6AB3D3, 4077BDDE1A44E2A415FF76A8BB3EAD226D7A29696C0218E81381B81E750CD0BA ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 08:43:31.0968 0x0cf8 SCardSvr - ok 08:43:32.0015 0x0cf8 [ DD73C11A5C4D14945846384B90A61A4B, C3C6BD62FB976E27C9E2C4C239D01B5458B7D270E9563A90EFBC9801B5DC55EA ] Schedule C:\WINDOWS\system32\schedsvc.dll 08:43:32.0015 0x0cf8 Schedule - ok 08:43:32.0078 0x0cf8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 08:43:32.0078 0x0cf8 Secdrv - ok 08:43:32.0109 0x0cf8 [ 2AAD9026648120FFFE2A8D871BB2BBC7, 8F9B35717CBE8B1C30FF15992DA8A857470A96F1A043CDA42CB89E4C6723B4A4 ] seclogon C:\WINDOWS\System32\seclogon.dll 08:43:32.0109 0x0cf8 seclogon - ok 08:43:32.0140 0x0cf8 [ B6A6B409FDA9D9EBD3AADB838D3D7173, 0A9A4C15C83AACBA9FC87B674CB17375DE988B41448A65101647AE67BDD15377 ] SenFiltService C:\WINDOWS\system32\drivers\Senfilt.sys 08:43:32.0203 0x0cf8 SenFiltService - ok 08:43:32.0250 0x0cf8 [ 9D01E29D59723EB73B72107B208DAFE6, D334E807C6B41CF08EB64DCF8B2C8F68FA553971130FAB2E14C3EEE4D3B968F7 ] SENS C:\WINDOWS\system32\sens.dll 08:43:32.0250 0x0cf8 SENS - ok 08:43:32.0265 0x0cf8 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 08:43:32.0265 0x0cf8 serenum - ok 08:43:32.0281 0x0cf8 [ D07B02F88165E69B9F17162CF592C8A6, B494941FC05FC2439F54D4D999B1A65F9709BC296D5AC470C8F73ACFC5DC4729 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 08:43:32.0296 0x0cf8 Serial - ok 08:43:32.0343 0x0cf8 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 08:43:32.0359 0x0cf8 Sfloppy - ok 08:43:32.0375 0x0cf8 [ DA5C015911F68F22ED821E9EE49AB233, 53694B0E70F77C775CE936F5DB458F724F051314704B6F69E5C2728180F0DC2C ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 08:43:32.0390 0x0cf8 SharedAccess - ok 08:43:32.0421 0x0cf8 [ 232D5719F86E05B7FE34F038D4FC84B2, 6FA53B1E2D4D452EEE29E6757C6169C5510A35378302BB4EE1E6B0EA3CBE834C ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 08:43:32.0484 0x0cf8 ShellHWDetection - ok 08:43:32.0515 0x0cf8 [ C17EAD2A29695916EBA59CEC1F7F96A0, 3CC2B2FEEACCBE37158DA81DF01B182DC6D4C2419E18567FFF29DF266E11F084 ] Si3112 C:\WINDOWS\system32\drivers\Si3112.sys 08:43:32.0546 0x0cf8 Si3112 - ok 08:43:32.0562 0x0cf8 [ 62B429C87ED5D3655B70D574D31B807B, 71B49FBBBC24EE05A9655A3E4AF15CDFD2006D4DAD2BE1FB1F09D03557D8E051 ] Si3114r5 C:\WINDOWS\system32\drivers\Si3114r5.sys 08:43:32.0578 0x0cf8 Si3114r5 - ok 08:43:32.0578 0x0cf8 [ AAAA385FFBAAF3FD89F8CE26FF0D0751, ACD381F508E93083252A65852DB3F60BEEAFB9C63B1FC6E702761BB67E6BB859 ] Si3124 C:\WINDOWS\system32\drivers\Si3124.sys 08:43:32.0593 0x0cf8 Si3124 - ok 08:43:32.0593 0x0cf8 [ 4CDAF939DF995B0EEFD91E069BFDA30D, F5E8DC41AD75025AD5ECF49A14FACA4C44A2FE7F6A156844014D7F5C3A6394B3 ] Si3132 C:\WINDOWS\system32\drivers\Si3132.sys 08:43:32.0609 0x0cf8 Si3132 - ok 08:43:32.0640 0x0cf8 [ 0A5DF632416FDFA8A265F6CA2B80F23B, 7377A1CC449D4E96CC3652D4713B9EE18ADE6D063CB8985193EEB17E972AFE2B ] Si3132r5 C:\WINDOWS\system32\drivers\Si3132r5.sys 08:43:32.0656 0x0cf8 Si3132r5 - ok 08:43:32.0687 0x0cf8 [ 93BEACC3815A4653A655C8BD7622FF63, 511DBFCE8DA6876BD062216EBA168F47A84F439C201885987A170783D4FEB197 ] Si3531 C:\WINDOWS\system32\drivers\Si3531.sys 08:43:32.0703 0x0cf8 Si3531 - ok 08:43:32.0703 0x0cf8 Simbad - ok 08:43:32.0734 0x0cf8 Sparrow - ok 08:43:32.0765 0x0cf8 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys 08:43:32.0781 0x0cf8 splitter - ok 08:43:32.0812 0x0cf8 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe 08:43:32.0812 0x0cf8 Spooler - ok 08:43:32.0843 0x0cf8 [ EB032822BE406EF220D546DDFFCF0002, 916299B409925AB7326CB5F744799B34FD08CA4C4B447215DA5060FF446FEEBE ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 08:43:32.0859 0x0cf8 sr - ok 08:43:32.0875 0x0cf8 [ 316D0E66074AE4CDE641C50D3A1C5148, 8429F815AFB4B39F6C1C56FB1CA009E5338C1467A4A02DD8E7E35BADBB8D5221 ] srservice C:\WINDOWS\system32\srsvc.dll 08:43:32.0875 0x0cf8 srservice - ok 08:43:32.0921 0x0cf8 [ 9B390283569EA58D43D2586032B892F5, FADC0AD9D8F715290F02A6A59B284A6AD53C5BD13933B1D3ECC03C558C9D5885 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 08:43:32.0937 0x0cf8 Srv - ok 08:43:32.0953 0x0cf8 [ 2C0B1224AA36B4CA1753302BAA855882, F8C90ECBF5BD7C3984E7C82EB00042DFD85A62F263C0205E6790205B6D64E101 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 08:43:32.0953 0x0cf8 SSDPSRV - ok 08:43:33.0000 0x0cf8 [ 41508EA375C97DC2B56E5F1AFC067187, 94D8D49AE3634E861DE501E72813C5320F059C49CC61FA01B2867C99E8B36DB4 ] stisvc C:\WINDOWS\system32\wiaservc.dll 08:43:33.0031 0x0cf8 stisvc - ok 08:43:33.0109 0x0cf8 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 08:43:33.0140 0x0cf8 swenum - ok 08:43:33.0265 0x0cf8 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 08:43:33.0296 0x0cf8 swmidi - ok 08:43:33.0296 0x0cf8 SwPrv - ok 08:43:33.0296 0x0cf8 symc810 - ok 08:43:33.0312 0x0cf8 symc8xx - ok 08:43:33.0312 0x0cf8 sym_hi - ok 08:43:33.0312 0x0cf8 sym_u3 - ok 08:43:33.0484 0x0cf8 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 08:43:33.0500 0x0cf8 sysaudio - ok 08:43:33.0593 0x0cf8 [ E42048198518F9162027A9984CBB7B5C, 2634DE2B1AE9D856966F40BFB41AD951A41E11C557C4B27E61CFF63288B53D52 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 08:43:33.0625 0x0cf8 SysmonLog - ok 08:43:33.0671 0x0cf8 [ 2340E6977548038C88E39A9ECBB3FADC, B8992F5E0689B307B8CC162032B398950FB07C4B4EF997431F7B344351406586 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 08:43:33.0703 0x0cf8 TapiSrv - ok 08:43:33.0734 0x0cf8 [ AD978A1B783B5719720CFF204B666C8E, FA50A3664522C58E1637C06731B9CB9D56FF14F0A5F8AB496A1945585E8A2C16 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 08:43:33.0750 0x0cf8 Tcpip - ok 08:43:33.0796 0x0cf8 [ 74905EBCBB8CBDB1F3C0B1778BBCB4BC, D869FDFD98B9C972933FB6B7C521BB6181A47698D27D53CBEF329EE26C12F1BA ] tcpipBM C:\WINDOWS\system32\drivers\tcpipBM.sys 08:43:33.0796 0x0cf8 tcpipBM - ok 08:43:33.0828 0x0cf8 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 08:43:33.0828 0x0cf8 TDPIPE - ok 08:43:33.0843 0x0cf8 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 08:43:33.0843 0x0cf8 TDTCP - ok 08:43:33.0875 0x0cf8 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 08:43:33.0890 0x0cf8 TermDD - ok 08:43:33.0984 0x0cf8 [ 52E0505408EDD4AB5CCC7F83B67B4299, 93DBA3282025C81DC43D4B43861A6CB30C9557CD0108D4D7E0C3B1269699CF22 ] TermService C:\WINDOWS\System32\termsrv.dll 08:43:34.0000 0x0cf8 TermService - ok 08:43:34.0031 0x0cf8 [ 232D5719F86E05B7FE34F038D4FC84B2, 6FA53B1E2D4D452EEE29E6757C6169C5510A35378302BB4EE1E6B0EA3CBE834C ] Themes C:\WINDOWS\System32\shsvcs.dll 08:43:34.0031 0x0cf8 Themes - ok 08:43:34.0031 0x0cf8 TosIde - ok 08:43:34.0046 0x0cf8 [ 9E70EB419D7785C286DC458A019BAB9B, 3901C6B9C9C197FED9C1039F2EBE0C5ACE240512ABBFECB388CAD201CE032760 ] TrkWks C:\WINDOWS\system32\trkwks.dll 08:43:34.0062 0x0cf8 TrkWks - ok 08:43:34.0078 0x0cf8 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 08:43:34.0078 0x0cf8 Udfs - ok 08:43:34.0078 0x0cf8 ultra - ok 08:43:34.0125 0x0cf8 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 08:43:34.0187 0x0cf8 Update - ok 08:43:34.0203 0x0cf8 [ E96A6BAEE0B2A14A38B45830D6E30697, 12314B1D96E025718F965C091E3CAD2865EDDAACA2E60A1A0DAF25630AE66B72 ] upnphost C:\WINDOWS\System32\upnphost.dll 08:43:34.0218 0x0cf8 upnphost - ok 08:43:34.0250 0x0cf8 [ EB90E28B28541EC845E5345609355CA7, 60C8DF04EB5839AB1B8625C385F4B2089C63FE613463026F779B331D9BC4D4D6 ] UPS C:\WINDOWS\System32\ups.exe 08:43:34.0250 0x0cf8 UPS - ok 08:43:34.0265 0x0cf8 [ 173F317CE0DB8E21322E71B7E60A27E8, 7042441BA63AE38AE9D7BE0BC5CA7404FC9EE5BB3F084604A68F01E82769652A ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 08:43:34.0281 0x0cf8 usbccgp - ok 08:43:34.0296 0x0cf8 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 08:43:34.0328 0x0cf8 usbehci - ok 08:43:34.0359 0x0cf8 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 08:43:34.0375 0x0cf8 usbhub - ok 08:43:34.0437 0x0cf8 [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 08:43:34.0453 0x0cf8 usbprint - ok 08:43:34.0468 0x0cf8 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 08:43:34.0484 0x0cf8 usbscan - ok 08:43:34.0578 0x0cf8 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 08:43:34.0609 0x0cf8 USBSTOR - ok 08:43:34.0625 0x0cf8 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 08:43:34.0640 0x0cf8 usbuhci - ok 08:43:34.0656 0x0cf8 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 08:43:34.0671 0x0cf8 VgaSave - ok 08:43:34.0671 0x0cf8 ViaIde - ok 08:43:34.0687 0x0cf8 [ 56B191AC5FC0DF219949C95A6C87AFE7, 5DCD42BD686869B394CFB9EFD727DCEEEAE239326DDE3D1655C456FCAE949D9F ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 08:43:34.0703 0x0cf8 VolSnap - ok 08:43:34.0718 0x0cf8 [ 7F2D7BFFC4554E1C742DD3629FD1FB1B, 4BFFC8A67F98AF69039DF0AFF1FDA11CFAD6464066E8ED92090D48392C43B6ED ] VSS C:\WINDOWS\System32\vssvc.exe 08:43:34.0750 0x0cf8 VSS - ok 08:43:34.0796 0x0cf8 [ A672CA3981352F8E9C30FEA056E80A62, 9AD34EFEB11EFEB234A246639FADF036F49FC67E542C4DE78D7C01E75BC62B59 ] W32Time C:\WINDOWS\system32\w32time.dll 08:43:34.0812 0x0cf8 W32Time - ok 08:43:34.0843 0x0cf8 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 08:43:34.0859 0x0cf8 Wanarp - ok 08:43:34.0906 0x0cf8 [ 5AE4BFD04563AFE55A0F666DA23F252F, 83D09469150B2E4680185618B2ED1F2822B711AB62782ADEB61D464DF312C20E ] WDDMService C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe 08:43:34.0921 0x0cf8 WDDMService - ok 08:43:34.0968 0x0cf8 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC, 06FC132E0E256B9A4E4DDD05D3AF4D75E40C750ECCF94A76251B104C65CFFCDF ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys 08:43:35.0015 0x0cf8 Wdf01000 - ok 08:43:35.0015 0x0cf8 WDICA - ok 08:43:35.0031 0x0cf8 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 08:43:35.0046 0x0cf8 wdmaud - ok 08:43:35.0062 0x0cf8 [ 81FB88B975E25D76E00B69879D8A434C, 2340CEE200CA3F0A546F88AAD3AFDCFD0805DB027E8480B4280D92E14F6C1F69 ] WebClient C:\WINDOWS\System32\webclnt.dll 08:43:35.0078 0x0cf8 WebClient - ok 08:43:35.0156 0x0cf8 [ 70C22297534A88B0AD0568900AB5A6D9, 2457D9B21CD8633D6A59FC053B70B9282A64066789EC020A9F2C937141E95C61 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 08:43:35.0171 0x0cf8 winmgmt - ok 08:43:35.0203 0x0cf8 [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 08:43:35.0203 0x0cf8 WmdmPmSN - ok 08:43:35.0234 0x0cf8 [ A2B12D80A1670511B047A7D8BB647598, BDE141A77034608D926624583D252650D01B64EC2B3E8156A61D735C79E2A0E6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 08:43:35.0250 0x0cf8 WmiApSrv - ok 08:43:35.0312 0x0cf8 [ CDFA647AA82FDBA6C9C7A06155AFCB40, 4ACF2E90E4A933A5C662AFECFFB52997BED865953E452C80A772DF1B049060FD ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 08:43:35.0718 0x0cf8 WMPNetworkSvc - ok 08:43:36.0000 0x0cf8 [ CF4DEF1BF66F06964DC0D91844239104, CC1D9CECE2056D29A9651D51BB57C3F4F9BF9E90A4808CF7496C683C874FBD51 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 08:43:36.0015 0x0cf8 WpdUsb - ok 08:43:36.0515 0x0cf8 [ DCF3E3EDF5109EE8BC02FE6E1F045795, 4B8E14B1CFB095982D34DAEC336114F5039D7793080FB787DC95A63B6B945DD0 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 08:43:36.0671 0x0cf8 WPFFontCache_v0400 - ok 08:43:36.0843 0x0cf8 [ B6669F49D42E09BC0F9889FAA0F3336D, B6147A60F763E562E26495A6ACAE759492A52AE3BEFEA4BF40B8874E4CF069F1 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 08:43:36.0875 0x0cf8 wscsvc - ok 08:43:37.0156 0x0cf8 [ 04550D5EB7EE82C115DB547C01DF09FD, 6A4D1E5F4E1C641B47BB48489D4205531597E942E02ECD75BCFA856F60A938B0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 08:43:37.0203 0x0cf8 wuauserv - ok 08:43:37.0281 0x0cf8 [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 08:43:37.0312 0x0cf8 WudfPf - ok 08:43:37.0375 0x0cf8 [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 08:43:37.0406 0x0cf8 WudfRd - ok 08:43:37.0468 0x0cf8 [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 08:43:37.0468 0x0cf8 WudfSvc - ok 08:43:37.0593 0x0cf8 [ C2842273AAA77AC031EDB87FA19A2147, 8542392E337C543BCD9EDC7A15DC6E8DE8E9B8041CC7A8D707217C9FF0446882 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 08:43:37.0656 0x0cf8 WZCSVC - ok 08:43:37.0937 0x0cf8 [ 24ED6935771359A5AEF1FE8BF0C56F39, F0C3B781853714F48DE4F42533A7236CE11076208F190E79500F8A77C9CF9849 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 08:43:37.0984 0x0cf8 xmlprov - ok 08:43:38.0000 0x0cf8 ================ Scan global =============================== 08:43:38.0140 0x0cf8 [ 65C782F8CFC1BEBCC58E1532F44B6408, D5EB7357F37AC9CEF96BC1BCACE765B2897E502D699E64145EFA4DD62BCCE80B ] C:\WINDOWS\system32\basesrv.dll 08:43:38.0328 0x0cf8 [ AC6BEF2C41F0A6BCF1F0483281E24A21, 291305875C42A0EBC02F034E93FCF192D52B804E988FA2A4D467E8FD1BCCFDC6 ] C:\WINDOWS\system32\winsrv.dll 08:43:38.0453 0x0cf8 [ AC6BEF2C41F0A6BCF1F0483281E24A21, 291305875C42A0EBC02F034E93FCF192D52B804E988FA2A4D467E8FD1BCCFDC6 ] C:\WINDOWS\system32\winsrv.dll 08:43:38.0484 0x0cf8 [ 8816E60BF654353E8E0D35ED98875445, 08F271179931BC03E29B47EC55E89E56AC390B52216D6A36EAF3CBAD97D0ED3C ] C:\WINDOWS\system32\services.exe 08:43:38.0484 0x0cf8 [ Global ] - ok 08:43:38.0484 0x0cf8 ================ Scan MBR ================================== 08:43:38.0546 0x0cf8 [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 08:43:46.0281 0x0cf8 \Device\Harddisk0\DR0 - ok 08:43:46.0281 0x0cf8 ================ Scan VBR ================================== 08:43:46.0296 0x0cf8 [ 6C8411EF3D5134D4741CBE05128B53EB ] \Device\Harddisk0\DR0\Partition1 08:43:46.0296 0x0cf8 \Device\Harddisk0\DR0\Partition1 - ok 08:43:46.0312 0x0cf8 [ E7F7C604FE5A263F12B7EDA02D0D8DC4 ] \Device\Harddisk0\DR0\Partition2 08:43:46.0328 0x0cf8 \Device\Harddisk0\DR0\Partition2 - ok 08:43:46.0328 0x0cf8 ================ Scan generic autorun ====================== 08:43:46.0468 0x0cf8 [ 895E17BFF96D3114FD19CEC65A0E749E, E421519F1E70D621FD990250B0C6B332E903C21BCDB87EBBAD535C7C35327481 ] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe 08:43:46.0578 0x0cf8 COMODO Internet Security - ok 08:43:46.0921 0x0cf8 [ 1983A11F702BDC5DB65B4B0F376FF6FD, 05F167421B76D8EC1C4D499F1E1A3C50215A8AA287E69CF68C95385950EF93B3 ] C:\Program Files\Analog Devices\Core\smax4pnp.exe 08:43:47.0046 0x0cf8 SoundMAXPnP - ok 08:43:47.0265 0x0cf8 [ AC3197063BF23C53D5DCBA0D575FD2E9, CFCFB4527539F9C2F804ABB20DF7A1C88515A116F2C66D457FF8282D4BF589E5 ] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe 08:43:47.0500 0x0cf8 SoundMAX - ok 08:43:47.0656 0x0cf8 [ 78AB92E3B0AAEC820CEF88F49C6C007E, A2CA6074540D546E2795E38A644D680C31C11F8D2B76FB3B1E04A71908E6094B ] C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe 08:43:47.0671 0x0cf8 ToolboxFX - ok 08:43:48.0562 0x0cf8 [ 9E2944289377456DDC4FE3B50F39B5A0, 4D4BC20A63964FDB2DD433AD1BF5D0DE5BF3F8082CB03C67ADA698F7CE2255EC ] C:\Program Files\Cobian Backup 10\cbInterface.exe 08:43:49.0156 0x0cf8 Cobian Backup 10 Interface - ok 08:43:49.0296 0x0cf8 [ 0AEE5668EB59912F32FF245BFA72465F, 653978E365B0E72D34E8B3ED1BFCF0237B70B41396BD70EBBBEDB31AFD77857B ] C:\Program Files\QuickTime\QTTask.exe 08:43:49.0406 0x0cf8 QuickTime Task - ok 08:43:49.0406 0x0cf8 SunJavaUpdateSched - ok 08:43:49.0421 0x0cf8 Regedit32 - ok 08:43:49.0687 0x0cf8 [ 048EA4B978851788E9F5E8E4F081DF7A, EB62719AC0DCC18FF056F2CD84438BF14B61E38F0619617C81961C6257BDFCEC ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 08:43:49.0750 0x0cf8 Adobe ARM - ok 08:43:49.0937 0x0cf8 [ 0387BBC69D13EEEFAD8FB568883DDF2E, 51C47108DEF994F520AF9E018D79CA8E077738D0CB977BC4163756660419F587 ] C:\WINDOWS\ynydefuk.exe 08:43:58.0031 0x0cf8 uqirqmyv - ok 08:44:00.0312 0x0cf8 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\CTFMON.EXE 08:44:00.0359 0x0cf8 CTFMON.EXE - ok 08:44:02.0671 0x0cf8 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\CTFMON.EXE 08:44:02.0671 0x0cf8 CTFMON.EXE - ok 08:44:02.0671 0x0cf8 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\ctfmon.exe 08:44:02.0687 0x0cf8 CTFMON.EXE - ok 08:44:03.0312 0x0cf8 [ CFEFDC4F940BBDEAAEE76C17647BECB8, 59D3A88E1E2775420417EFE932C6757B8EF1B71C287F4A6141811A86C35E9A25 ] C:\Program Files\Messenger\msmsgs.exe 08:44:03.0734 0x0cf8 MSMSGS - ok 08:44:03.0781 0x0cf8 y1ag2rtq9f - ok 08:44:03.0937 0x0cf8 q.com - ok 08:44:04.0000 0x0cf8 [ DC6DCB8B2D60109E9BCA997193A844EC, 06C061168809B5AEEE6EB5EFA405D7C0B0492F766B2AA870F17804CDA58167B0 ] C:\Documents and Settings\Sekretariat\Dane aplikacji\Citazy\ledi.exe 08:44:04.0000 0x0cf8 {1DF79C7D-1415-1C53-C1F7-6E6D69E47C04} - ok 08:44:04.0203 0x0cf8 [ 4E3C1F913FC78C7582449B8DC34311E2, 78F707671DDABAEEE02C44493A7460D237954F7AC09736F03549C69BC8DAD946 ] C:\Documents and Settings\All Users.WINDOWS\dxhalsz.exe 08:44:04.0234 0x0cf8 dxhalsz.exe - ok 08:44:04.0515 0x0cf8 [ C30662AE6A63014A148F9D5383D3F557, A1BEECFFB957D850E2881220BDF069D6C4400D61FF21319590D0D2B14B3E86DA ] C:\Documents and Settings\Sekretariat\Ustawienia lokalne\Temp\00a1d38d.exe 08:44:04.0593 0x0cf8 00a1d38d.exe - ok 08:44:04.0828 0x0cf8 [ F96713C80E21F9CAF4B96321BB822167, 95424936925A52665E55D7B635199DC337108AB5CE92F5026F16C8CD584AB3FC ] C:\Documents and Settings\Sekretariat\Ustawienia lokalne\Temp\007f30f9.exe 08:44:04.0906 0x0cf8 007f30f9.exe - ok 08:44:05.0093 0x0cf8 [ 6A02BEFFE0E3F1F60C414D17CA6B4222, FC4AFE83B00F8DEEE8AD50E2A7E627B72E26B3E813D244B2C150A90CC7A3C70E ] C:\Documents and Settings\Sekretariat\Ustawienia lokalne\Temp\007f79f8.exe 08:44:05.0171 0x0cf8 007f79f8.exe - ok 08:44:06.0218 0x0cf8 AV detected via SS1: COMODO Antivirus, 3.9, enabled, updated 08:44:06.0375 0x0cf8 Win FW state via NFM: disabled 08:44:06.0515 0x0cf8 ============================================================ 08:44:06.0515 0x0cf8 Scan finished 08:44:06.0515 0x0cf8 ============================================================ 08:44:06.0906 0x0cf0 Detected object count: 1 08:44:06.0906 0x0cf0 Actual detected object count: 1 09:51:47.0859 0x0cf0 C:\WINDOWS\System32\Drivers\6edf95fac9406c4e.sys - copied to quarantine 09:51:47.0953 0x0cf0 HKLM\SYSTEM\ControlSet001\services\6edf95fac9406c4e - will be deleted on reboot 09:51:47.0968 0x0cf0 HKLM\SYSTEM\ControlSet004\services\6edf95fac9406c4e - will be deleted on reboot 09:51:47.0968 0x0cf0 C:\WINDOWS\System32\Drivers\6edf95fac9406c4e.sys - will be deleted on reboot 09:51:47.0968 0x0cf0 6edf95fac9406c4e ( Rootkit.Win32.Necurs.gen ) - User select action: Delete 09:51:48.0937 0x0cf0 KLMD registered as C:\WINDOWS\system32\drivers\82329325.sys 09:51:56.0968 0x0208 Deinitialize success