Ganhe dinheiro  escrevendo tutoriais para o Fórum do BABOO! Conheça os Tutoriais Pagos 2016

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Chiitus

Um problema fez com que o programa parasse de funcionar corretamente

15 posts neste tópico

Gente eu venho tendo um problema muito chato que vem acontecendo em alguns executáveis, uns ocorre toda hora outros pouco, mas está enchendo esse erro, e apesar de eu ter tentado alguns programas, não resolveu..
 
Esté é o erro:
 

Um problema fez com que o programa parasse de funcionar corretamente

 
Eu também fiz um log do HijackThis porque a maioria dos profissa pede, então ta aí:
 
 
 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:38:47, on 02/01/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal
 
Running processes:
C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
D:\Arquivos de programas\Internet Download Manager\IEMonitor.exe
C:\Users\Matheus\Downloads\JOGOS\OT\Styller Yourots {Editado 2.0}(Sem dlls )(8.60)\Styller Yourots.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Matheus\Desktop\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Arquivos de programas\Internet Download Manager\IDMIECC.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\KWIEBar.dll
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [iDMan] D:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Dashlane] C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Memory Cleaner] C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe boot
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [PSwitch] C:\Program Files (x86)\Portable\Proxy Switcher Pro v5.6.1.6308 Portable\ProxySwitcher.exe
O4 - HKCU\..\Run: [Proxifier] "C:\Users\Matheus\Downloads\PROGRAMAS\Initex.Software.Proxifier.v3.21\Initex.Software.Proxifier.v3.21.Portable.Edition.Incl.Keymaker-ZWT\Proxifier PE\Proxifier.exe" -autorun
O4 - HKCU\..\Run: [GarenaPlus] "C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe
O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Fazer o download usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEExt.htm
O9 - Extra button: Dashlane Button - {40354A83-504E-4611-ACAE-3D137F6F595E} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 antivírus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @oem8.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
 
--
End of file - 9050 bytes

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o Malwarebytes' Anti-Malware (MBAM) ou aqui.

Salve ou imprima estas instruções:

Dê um duplo-clique no mbam-setup.exe, escolha a linguagem e na instalação, aceite todas as opções padrão.

Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas e clique então, em Concluir.

Se houver atualizações a serem feitas, serão baixadas e instaladas.

Ao final da atualização, com o programa aberto, marque Verificação Rápida e clique no botão Verificar.

Começará então o exame. Aguarde, pois pode demorar.

Ao acabar o exame, clique em OK, depois no botão Mostrar Resultados para ver o relatório.

Se houver ítens encontrados, certifique-se de que, estão todos marcados e clique no botão Remover.

Ao final da desinfecção, abrirá o Bloco de notas com um Log e poderá aparecer um aviso se quer reiniciar o PC. (Ver Nota abaixo)

O Log é automaticamente salvo pelo MBAM e para vê-lo, clique na aba Logs na janela principal do Programa.

NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar

Selecione, copie e cole o conteúdo do Log do MBAM na sua próxima resposta + um novo Log do HijackThis .



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Eu já tinha feito isso do Malwarebytes, mas hoje antes de você responder eu fiz uma completa, oque estou postando é da completa.

 

EDIT : aqui não anexa dá este erro : You aren't permitted to upload this kind of file

 

Então vou postar em quotes.

 

Log do Malwarebytes (log novo):

Malwarebytes Anti-Malware (PRO) 1.70.0.1100

www.malwarebytes.org

 

Versão da Base de Dados:  v2013.01.02.02

 

Windows 8 x64 NTFS

Internet Explorer 10.0.9200.16466

Matheus :: MATHEUS-PC [administrador]

 

Proteção: Não permitir

 

02/01/2013 13:27:50

mbam-log-2013-01-02 (13-27-50).txt

 

Tipo de Verificação:  Verificação Completa  (C:\|D:\|)

Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos  | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opções de verificação desativadas: P2P

Objetos escaneados:  462712

Tempo decorrido: 1 hora(s), 15 minuto(s), 46 segundo(s)

 

Processos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Valores de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Pastas Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Arquivos Detectados: 5

C:\Users\Matheus\Downloads\PROGRAMAS\Initex.Software.Proxifier.v3.21\Initex.Software.Proxifier.v3.21.Portable.Edition.Incl.Keymaker-ZWT\keygen.exe (RiskWare.Tool.CK) -> Enviado para a Quarentena e deletado com sucesso.

C:\Users\Matheus\Downloads\PROGRAMAS\WiN8MaN.1.0.4.Engh3\CORE10k.EXE (Dont.Steal.Our.Software) -> Enviado para a Quarentena e deletado com sucesso.

D:\Arquivos de programas\Internet Download Manager\IDM.v6.xx.release.3-patch.exe (PUP.Hacktool.Patcher) -> Enviado para a Quarentena e deletado com sucesso.

D:\Documents and Settings\Administrador\Meus documentos\Downloads\EvOlUtIoN-4.5.9\ElfCrack.exe (Spyware.PWS) -> Enviado para a Quarentena e deletado com sucesso.

D:\Documents and Settings\Administrador\Meus documentos\Downloads\Initex.Software.Proxifier.v3.21.Portable.Edition.Incl.Keymaker-ZWT\keygen.exe (RiskWare.Tool.CK) -> Enviado para a Quarentena e deletado com sucesso.

 

(fim)

 

Log novo do HijackThis:

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 17:16:56, on 02/01/2013

Platform: Unknown Windows (WinNT 6.02.1008)

MSIE: Internet Explorer v10.0 (10.00.9200.16453)

Boot mode: Normal

 

Running processes:

C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Users\Matheus\Downloads\JOGOS\OT\Styller Yourots {Editado 2.0}(Sem dlls )(8.60)\Styller Yourots.exe

C:\Users\Matheus\Desktop\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 

F2 - REG:system.ini: UserInit=userinit.exe,

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll

O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll

O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\KWIEBar.dll

O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r

O4 - HKCU\..\Run: [Dashlane] C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe

O4 - HKCU\..\Run: [Memory Cleaner] C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe boot

O4 - HKCU\..\Run: [iDMan] D:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Dashlane Button - {40354A83-504E-4611-ACAE-3D137F6F595E} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 antivírus\x86\ekrn.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe

O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @oem8.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

 

--

End of file - 7774 bytes

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Não use quote para responder, copie e cole os logs no própio post.

Desabilite o seu Antivírus, AntiSpyware e Firewall para não haver conflitos. Mantenha-os desativados até terminar as instruções.

Download ComboFix

Salve no seu Desktop ( Para que a Ferramenta seja executada corretamente é necessário que esteja no Desktop (Área de trabalho)

Feche todas as janelas e programas.

É necessário estar conectado durante o procedimento com o ComboFix;

Execute o combofix.exe, tecle "Sim" para prosseguir. Aguarde, pois é um pouco demorado.

OBS: Caso não queira que seja instalado o Console de Recuperação do Windows, clique em "Não" e depois concorde para que a verificação prossiga.

Ao ser instalado o Console, na Inicialização do Sistema será apresentada a tela para Seleção dos Sistemas Operacionais.

Mais informações sobre o Console: http://support.micro...kb/307654/pt-br

O ComboFix reiniciará o PC automaticamente para completar o processo de remoção. Caso isso não aconteça, reinicie manualmente.

Quando acabar, será gerado um Log, que estará em C:\ComboFix.txt. Selecione, copie e cole o conteúdo do ComboFix.txt na sua próxima resposta + um novo Log do HijackThis .

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Para parar ou sair do ComboFix, tecle "N".

OBS 2: Não execute o ComboFix mais do que uma vez. Isso irá sobreescrever o Log e dificultará a remoção do(s) malware(s)

Caso ocorra algum erro, reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e repita o procedimento.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Infelizmente eu uso Windows 8 e o ComboFix não funciona nele :/

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Download o Kaspersky Virus Removal Tool.

Você será conduzido a uma página da Kaspersky, solicitando um email para cadastro, nome e sobrenome. Somente o campo "email" é obrigatório.

Informe seu email depois clique no botão Submit Form.

A página será recarregada. Clique no botão Download

Salve-o em sua Área de trabalho.

Duplo clique no arquivo "setup" e aguarde a instalação;

Na próxima tela marque I accept the licence agreement e clique em Start

Clique no botão f4uZX.png e marque:

  • Meu Computador
  • Disco local (C:) (a letra do disco local pode variar)
Clique em Actions e marque os dois quadros ( se já não estiverem marcados):

Zqewdl.jpg

- Clique na aba Automatic Scan e aguarde o término da verificação.

- Clique no botão AouIc.png, em Detected threats e no botão "Save".

- Copie o conteúdo do arquivo salvo (se houver algo detectado) e poste na sua próxima resposta.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desculpe a demora mas estava dando um erro de DLL e o programa não estava deletando as ameaças...

 

Eu dei umas pesquisada sobre o erro e disseram pra usar este programa : http://www.malwarecrawler.com/a-v-z.exe

 

Oque você me recomenda fazer ?

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Nem pensar.....

Download bouton-telecharger.png Salve-o no Desktop. (Área de Trabalho)

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista ou do Windows 7, clicar com o botão direito do mouse no arquivo e selecionar:Executar como administrador

AdwCleanerCustom-1.jpg

Clique [Delete]

Salve o Log criado.

Donload 1268r49.png Salve no seu Desktop (Área de trabalho).

Dê um duplo-clique para executar o Junkware Removal Tool (JRT)

* No Windows Vista e Windows 7:

Clique com o botão direito do mousesobre o JRT.exe e selecione run_as_adm1.png

A Ferramenta começará o exame do seu Sistema. Tenha paciência pois pode demorar um pouco, dependendo da quantidades de ítens a serem examinados.

Ao final, um Log se abrirá e salvo no Desktop com o nome de JRT.txt.

Selecione, copie e cole o conteúdo deste Log na sua próxima resposta + o Log do AdwCleaner e um novo Log do HijackThis.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz tudo como você mandou, e aqui estão os logs:

 

Log JRT:

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.3.5 (01.02.2013:3)
OS: Windows 8 Pro x64
Ran by Matheus on 02/01/2013 at 23:40:06,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{0055c089-8582-441b-a0bf-17b458c2a3a8}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{0055c089-8582-441b-a0bf-17b458c2a3a8}
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll
 
 
 
~~~ Folders
 
 
 
~~~ FireFox
 
Emptied folder: C:\Users\Matheus\AppData\Roaming\mozilla\firefox\profiles\01gkcl1a.default\minidumps [1 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02/01/2013 at 23:45:31,17
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Log AdwCleaner:
 
# AdwCleaner v2.104 - Logfile created 01/02/2013 at 23:35:41
# Updated 29/12/2012 by Xplode
# Operating system : Windows 8 Pro  (64 bits)
# User : Matheus - MATHEUS-PC
# Boot Mode : Normal
# Running from : C:\Users\Matheus\Desktop\adwcleaner.exe
# Option [Delete]
 
 
***** [services] *****
 
 
***** [Files / Folders] *****
 
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Deleted : C:\Users\Matheus\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Matheus\AppData\Roaming\Funmoods
 
***** [Registry] *****
 
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
 
***** [internet Browsers] *****
 
-\\ Internet Explorer v10.0.9200.16453
 
[OK] Registry is clean.
 
-\\ Mozilla Firefox v17.0.1 (pt-BR)
 
File : C:\Users\Matheus\AppData\Roaming\Mozilla\Firefox\Profiles\01gkcl1a.default\prefs.js
 
C:\Users\Matheus\AppData\Roaming\Mozilla\Firefox\Profiles\01gkcl1a.default\user.js ... Deleted !
 
Deleted : user_pref("extensions.enabledAddons", "%7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.5,multilinks%40p[...]
Deleted : user_pref("extensions.funmoods.aflt", "pcmega1");
Deleted : user_pref("extensions.funmoods.autoRvrt", false);
Deleted : user_pref("extensions.funmoods.cntry", "BR");
Deleted : user_pref("extensions.funmoods.cv", "cv5");
Deleted : user_pref("extensions.funmoods.dfltLng", "");
Deleted : user_pref("extensions.funmoods.dfltSrch", false);
Deleted : user_pref("extensions.funmoods.dnsErr", true);
Deleted : user_pref("extensions.funmoods.envrmnt", "production");
Deleted : user_pref("extensions.funmoods.excTlbr", false);
Deleted : user_pref("extensions.funmoods.hdrMd5", "B7883B136516C2598795C0CEAB904761");
Deleted : user_pref("extensions.funmoods.hmpg", false);
Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=pcmega1&ir=pcmega1&cd=2Xz[...]
Deleted : user_pref("extensions.funmoods.id", "1078D2B4AF6DB94C");
Deleted : user_pref("extensions.funmoods.instlDay", "15698");
Deleted : user_pref("extensions.funmoods.instlRef", "pcmega1");
Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.221:21:38");
Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Deleted : user_pref("extensions.funmoods.newTab", true);
Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=pcmega1&ir=pcmega1&cd=2[...]
Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
Deleted : user_pref("extensions.funmoods.sg", "none");
Deleted : user_pref("extensions.funmoods.smplGrp", "none");
Deleted : user_pref("extensions.funmoods.srchPrvdr", "Funmoods");
Deleted : user_pref("extensions.funmoods.tlbrId", "base");
Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=pcmega1&ir=pcmega1&cd[...]
Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.221:21:38");
Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
Deleted : user_pref("extensions.funmoods_i.newTab", true);
Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.221:21:38");
 
-\\ Google Chrome v23.0.1271.97
 
File : C:\Users\Matheus\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
Deleted [l.8] : homepage = "hxxp://searchfunmoods.com/?f=1&a=pcmega1&ir=pcmega1&cd=2XzuyEtN2Y1L1QzutCtDyBzz0D[...]
Deleted [l.11] : urls_to_restore_on_startup = [ "hxxp://searchfunmoods.com/?f=1&a=pcmega1&ir=pcmega1&cd=2Xz[...]
Deleted [l.1974] : homepage = "hxxp://searchfunmoods.com/?f=1&a=pcmega1&ir=pcmega1&cd=2XzuyEtN2Y1L1QzutCtDyBzz0DtB0[...]
Deleted [l.2417] : urls_to_restore_on_startup = [ "hxxp://searchfunmoods.com/?f=1&a=pcmega1&ir=pcmega1&cd=2XzuyE[...]
 
*************************
 
AdwCleaner[s1].txt - [4679 octets] - [02/01/2013 23:35:41]
 
########## EOF - C:\AdwCleaner[s1].txt - [4739 octets] ##########
 

Log HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 23:46:02, on 02/01/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe
C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Matheus\Desktop\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\KWIEBar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKCU\..\Run: [Dashlane] C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
O4 - HKCU\..\Run: [Memory Cleaner] C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe boot
O4 - HKCU\..\Run: [iDMan] D:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot
O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe
O4 - Startup: setup_9.0.0.722_02.01.2013_22-27.lnk = Desktop\Virus Removal Tool1\setup_9.0.0.722_02.01.2013_22-27\startup.exe
O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Fazer o download usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEExt.htm
O9 - Extra button: Dashlane Button - {40354A83-504E-4611-ACAE-3D137F6F595E} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 antivírus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @oem8.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
 
--
End of file - 7545 bytes

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Download the TDSSKILLER-zip e descompacte- o em C/:

Execute TDSSKiller.exe

A Ferramenta pode detectar dois tipos de ameaças: malicioso ou suspeito.

Para os itens maliciosos, haverá duas opções: curar ou deletar.

Para os itens suspeitos (Suspicious file), a opção padrão será "ignorar".

Se algo malicioso for detectado, mande deletar e permita que o sistema seja reiniciado.

Se algo suspeito for detectado, marque a opção "ignorar"

Depois, copie o Log e cole na sua resposta. O Log ficará salvo em C:\, com um nome parecido com este:

C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt

Aguarde o escaneamento e a desinfecção se completar.

Reinicie o PC e poste um novo Log do HijackThis, informando a situação atual do PC.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui não constou nenhum item malicioso/suspeito, aqui estão os logs:

 

Log TDSSKiller:

 

 

08:29:11.0354 148844  TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
08:29:12.0253 148844  ============================================================
08:29:12.0253 148844  Current date / time: 2013/01/03 08:29:12.0253
08:29:12.0253 148844  SystemInfo:
08:29:12.0253 148844  
08:29:12.0253 148844  OS Version: 6.2.9200 ServicePack: 0.0
08:29:12.0253 148844  Product type: Workstation
08:29:12.0253 148844  ComputerName: MATHEUS-PC
08:29:12.0253 148844  UserName: Matheus
08:29:12.0253 148844  Windows directory: C:\Windows
08:29:12.0253 148844  System windows directory: C:\Windows
08:29:12.0253 148844  Running under WOW64
08:29:12.0253 148844  Processor architecture: Intel x64
08:29:12.0253 148844  Number of processors: 4
08:29:12.0253 148844  Page size: 0x1000
08:29:12.0253 148844  Boot type: Normal boot
08:29:12.0253 148844  ============================================================
08:29:12.0723 148844  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
08:29:12.0725 148844  ============================================================
08:29:12.0726 148844  \Device\Harddisk0\DR0:
08:29:12.0726 148844  MBR partitions:
08:29:12.0726 148844  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1388AFC
08:29:12.0726 148844  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1389000, BlocksNum 0x38FFC800
08:29:12.0726 148844  ============================================================
08:29:12.0766 148844  C: <-> \Device\Harddisk0\DR0\Partition2
08:29:12.0787 148844  D: <-> \Device\Harddisk0\DR0\Partition1
08:29:12.0787 148844  ============================================================
08:29:12.0788 148844  Initialize success
08:29:12.0788 148844  ============================================================
08:29:17.0352 149324  ============================================================
08:29:17.0352 149324  Scan started
08:29:17.0352 149324  Mode: Manual; 
08:29:17.0352 149324  ============================================================
08:29:17.0714 149324  ================ Scan system memory ========================
08:29:17.0714 149324  System memory - ok
08:29:17.0715 149324  ================ Scan services =============================
08:29:17.0834 149324  [ 6C5461EEB3FFA1B1DCF9A07F8C3B3AFE ] 00214041        C:\Windows\system32\DRIVERS\00214041.sys
08:29:17.0836 149324  00214041 - ok
08:29:17.0852 149324  [ 3EC7DFDA521B4FB22CE9F76DF15DB099 ] 00214042        C:\Windows\system32\DRIVERS\00214042.sys
08:29:17.0853 149324  00214042 - ok
08:29:17.0882 149324  [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci        C:\Windows\System32\drivers\1394ohci.sys
08:29:17.0884 149324  1394ohci - ok
08:29:17.0905 149324  [ 6C5461EEB3FFA1B1DCF9A07F8C3B3AFE ] 20064711        C:\Windows\system32\DRIVERS\20064711.sys
08:29:17.0907 149324  20064711 - ok
08:29:17.0933 149324  [ 3EC7DFDA521B4FB22CE9F76DF15DB099 ] 20064712        C:\Windows\system32\DRIVERS\20064712.sys
08:29:17.0934 149324  20064712 - ok
08:29:17.0949 149324  [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware           C:\Windows\system32\drivers\3ware.sys
08:29:17.0951 149324  3ware - ok
08:29:17.0991 149324  [ 975AABEB243B800C23626D6B652C5A9C ] ACPI            C:\Windows\system32\drivers\ACPI.sys
08:29:17.0995 149324  ACPI - ok
08:29:18.0006 149324  [ DC968C37822117E576B933F34A2D130C ] acpiex          C:\Windows\system32\Drivers\acpiex.sys
08:29:18.0007 149324  acpiex - ok
08:29:18.0021 149324  [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr        C:\Windows\System32\drivers\acpipagr.sys
08:29:18.0022 149324  acpipagr - ok
08:29:18.0027 149324  [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi         C:\Windows\System32\drivers\acpipmi.sys
08:29:18.0028 149324  AcpiPmi - ok
08:29:18.0033 149324  [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime        C:\Windows\System32\drivers\acpitime.sys
08:29:18.0034 149324  acpitime - ok
08:29:18.0073 149324  [ 93C6388592B99925C1D1576E465BC80F ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
08:29:18.0078 149324  adp94xx - ok
08:29:18.0095 149324  [ D27763E0247292654E7F7D16444C7C72 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
08:29:18.0099 149324  adpahci - ok
08:29:18.0113 149324  [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
08:29:18.0115 149324  adpu320 - ok
08:29:18.0149 149324  [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
08:29:18.0151 149324  AeLookupSvc - ok
08:29:18.0187 149324  [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD             C:\Windows\system32\drivers\afd.sys
08:29:18.0192 149324  AFD - ok
08:29:18.0207 149324  [ 01590377A5AB19E792528C628A2A68F9 ] agp440          C:\Windows\system32\drivers\agp440.sys
08:29:18.0208 149324  agp440 - ok
08:29:18.0231 149324  [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG             C:\Windows\System32\alg.exe
08:29:18.0232 149324  ALG - ok
08:29:18.0247 149324  [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
08:29:18.0249 149324  AllUserInstallAgent - ok
08:29:18.0272 149324  [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8           C:\Windows\System32\drivers\amdk8.sys
08:29:18.0274 149324  AmdK8 - ok
08:29:18.0293 149324  [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM          C:\Windows\System32\drivers\amdppm.sys
08:29:18.0294 149324  AmdPPM - ok
08:29:18.0301 149324  [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
08:29:18.0302 149324  amdsata - ok
08:29:18.0325 149324  [ 00452671904F5EE94B50BF0219C97164 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
08:29:18.0328 149324  amdsbs - ok
08:29:18.0338 149324  [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
08:29:18.0339 149324  amdxata - ok
08:29:18.0353 149324  [ 83B3682CE922FB0F415734B26D9D6233 ] AppID           C:\Windows\system32\drivers\appid.sys
08:29:18.0355 149324  AppID - ok
08:29:18.0369 149324  [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
08:29:18.0371 149324  AppIDSvc - ok
08:29:18.0386 149324  [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo         C:\Windows\System32\appinfo.dll
08:29:18.0387 149324  Appinfo - ok
08:29:18.0404 149324  [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt         C:\Windows\System32\appmgmts.dll
08:29:18.0407 149324  AppMgmt - ok
08:29:18.0415 149324  [ E933401B392387F4BE34DE8BAF1722A7 ] arc             C:\Windows\system32\drivers\arc.sys
08:29:18.0416 149324  arc - ok
08:29:18.0420 149324  [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
08:29:18.0421 149324  arcsas - ok
08:29:18.0427 149324  [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
08:29:18.0427 149324  AsyncMac - ok
08:29:18.0444 149324  [ A721FF570C2387E383BDDEA9632863C9 ] atapi           C:\Windows\system32\drivers\atapi.sys
08:29:18.0444 149324  atapi - ok
08:29:18.0472 149324  [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
08:29:18.0473 149324  AudioEndpointBuilder - ok
08:29:18.0505 149324  [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
08:29:18.0508 149324  Audiosrv - ok
08:29:18.0524 149324  [ 89491EF71D5EA011127832C588002853 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
08:29:18.0525 149324  AxInstSV - ok
08:29:18.0555 149324  [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
08:29:18.0558 149324  b06bdrv - ok
08:29:18.0571 149324  [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay    C:\Windows\System32\drivers\BasicDisplay.sys
08:29:18.0572 149324  BasicDisplay - ok
08:29:18.0580 149324  [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender     C:\Windows\System32\drivers\BasicRender.sys
08:29:18.0580 149324  BasicRender - ok
08:29:18.0609 149324  [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC          C:\Windows\System32\bdesvc.dll
08:29:18.0611 149324  BDESVC - ok
08:29:18.0625 149324  [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep            C:\Windows\system32\drivers\Beep.sys
08:29:18.0625 149324  Beep - ok
08:29:18.0642 149324  [ 7253B5371136DAF5D38AFB2C42D2B78F ] BFE             C:\Windows\System32\bfe.dll
08:29:18.0646 149324  BFE - ok
08:29:18.0679 149324  [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS            C:\Windows\System32\qmgr.dll
08:29:18.0684 149324  BITS - ok
08:29:18.0692 149324  [ B17AC10B47C7FCB44D22A1F06415840E ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
08:29:18.0694 149324  bowser - ok
08:29:18.0724 149324  [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
08:29:18.0725 149324  BrokerInfrastructure - ok
08:29:18.0744 149324  [ 310068BDA80B1D55C36580FD8A873FAF ] Browser         C:\Windows\System32\browser.dll
08:29:18.0746 149324  Browser - ok
08:29:18.0772 149324  [ FC79BE6D8FBC8699E9980F657D281BE9 ] BthAvrcpTg      C:\Windows\System32\drivers\BthAvrcpTg.sys
08:29:18.0773 149324  BthAvrcpTg - ok
08:29:18.0793 149324  [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum       C:\Windows\System32\drivers\bthhfenum.sys
08:29:18.0793 149324  BthHFEnum - ok
08:29:18.0797 149324  [ 6F7368071FCDDB96C0527A6E5D7C1906 ] bthhfhid        C:\Windows\System32\drivers\BthHFHid.sys
08:29:18.0797 149324  bthhfhid - ok
08:29:18.0808 149324  [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM        C:\Windows\System32\drivers\bthmodem.sys
08:29:18.0808 149324  BTHMODEM - ok
08:29:18.0825 149324  [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv         C:\Windows\system32\bthserv.dll
08:29:18.0826 149324  bthserv - ok
08:29:18.0842 149324  [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
08:29:18.0843 149324  cdfs - ok
08:29:18.0848 149324  [ 339BFF85D788268752DA8C9644B188EE ] cdrom           C:\Windows\System32\drivers\cdrom.sys
08:29:18.0849 149324  cdrom - ok
08:29:18.0862 149324  [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc     C:\Windows\System32\certprop.dll
08:29:18.0863 149324  CertPropSvc - ok
08:29:18.0872 149324  [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass        C:\Windows\System32\drivers\circlass.sys
08:29:18.0873 149324  circlass - ok
08:29:18.0891 149324  [ 9905168708DB68849B879B5548F68AB3 ] CLFS            C:\Windows\system32\drivers\CLFS.sys
08:29:18.0893 149324  CLFS - ok
08:29:18.0923 149324  [ 2DC8538A2260647484A6C921CA837313 ] CmBatt          C:\Windows\System32\drivers\CmBatt.sys
08:29:18.0924 149324  CmBatt - ok
08:29:18.0956 149324  [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG             C:\Windows\system32\Drivers\cng.sys
08:29:18.0958 149324  CNG - ok
08:29:18.0973 149324  [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus    C:\Windows\System32\drivers\CompositeBus.sys
08:29:18.0974 149324  CompositeBus - ok
08:29:18.0977 149324  COMSysApp - ok
08:29:18.0985 149324  [ D9CB0782AF819548072AA45B70F8B22D ] condrv          C:\Windows\system32\drivers\condrv.sys
08:29:18.0986 149324  condrv - ok
08:29:19.0056 149324  [ 78AF1C499BF02F9814DF959A04A4F9C9 ] cphs            C:\Windows\SysWow64\IntelCpHeciSvc.exe
08:29:19.0058 149324  cphs - ok
08:29:19.0070 149324  [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc        C:\Windows\system32\cryptsvc.dll
08:29:19.0070 149324  CryptSvc - ok
08:29:19.0099 149324  [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC             C:\Windows\system32\drivers\csc.sys
08:29:19.0101 149324  CSC - ok
08:29:19.0124 149324  [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService      C:\Windows\System32\cscsvc.dll
08:29:19.0128 149324  CscService - ok
08:29:19.0152 149324  [ C4D01BD86D6B207275FC143EEA951D75 ] dam             C:\Windows\system32\drivers\dam.sys
08:29:19.0153 149324  dam - ok
08:29:19.0185 149324  [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch      C:\Windows\system32\rpcss.dll
08:29:19.0189 149324  DcomLaunch - ok
08:29:19.0217 149324  [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc       C:\Windows\System32\defragsvc.dll
08:29:19.0219 149324  defragsvc - ok
08:29:19.0237 149324  [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
08:29:19.0241 149324  DeviceAssociationService - ok
08:29:19.0277 149324  [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall   C:\Windows\system32\umpnpmgr.dll
08:29:19.0282 149324  DeviceInstall - ok
08:29:19.0304 149324  [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc            C:\Windows\system32\Drivers\dfsc.sys
08:29:19.0305 149324  Dfsc - ok
08:29:19.0333 149324  [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp            C:\Windows\system32\dhcpcore.dll
08:29:19.0337 149324  Dhcp - ok
08:29:19.0348 149324  [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache        C:\Windows\system32\drivers\discache.sys
08:29:19.0348 149324  discache - ok
08:29:19.0357 149324  [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk            C:\Windows\system32\drivers\disk.sys
08:29:19.0360 149324  disk - ok
08:29:19.0404 149324  [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc           C:\Windows\System32\drivers\dmvsc.sys
08:29:19.0405 149324  dmvsc - ok
08:29:19.0440 149324  [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
08:29:19.0443 149324  Dnscache - ok
08:29:19.0466 149324  [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc         C:\Windows\System32\dot3svc.dll
08:29:19.0470 149324  dot3svc - ok
08:29:19.0488 149324  [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS             C:\Windows\system32\dps.dll
08:29:19.0492 149324  DPS - ok
08:29:19.0514 149324  [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
08:29:19.0515 149324  drmkaud - ok
08:29:19.0538 149324  [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc          C:\Windows\System32\DeviceSetupManager.dll
08:29:19.0541 149324  DsmSvc - ok
08:29:19.0576 149324  [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01     C:\Windows\System32\drivers\dtsoftbus01.sys
08:29:19.0579 149324  dtsoftbus01 - ok
08:29:19.0634 149324  [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
08:29:19.0646 149324  DXGKrnl - ok
08:29:19.0692 149324  [ D00EAE9C735A7DEE8049E50D73D25434 ] eamonm          C:\Windows\system32\DRIVERS\eamonm.sys
08:29:19.0694 149324  eamonm - ok
08:29:19.0711 149324  [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost         C:\Windows\System32\eapsvc.dll
08:29:19.0714 149324  Eaphost - ok
08:29:19.0777 149324  [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
08:29:19.0799 149324  ebdrv - ok
08:29:19.0819 149324  [ F702AB6181513303AB0FC8D59E52708B ] EFS             C:\Windows\System32\lsass.exe
08:29:19.0820 149324  EFS - ok
08:29:19.0834 149324  [ E5EDDE3C8158DD0CBC5812F201DCDED0 ] ehdrv           C:\Windows\system32\DRIVERS\ehdrv.sys
08:29:19.0835 149324  ehdrv - ok
08:29:19.0850 149324  [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass     C:\Windows\system32\drivers\EhStorClass.sys
08:29:19.0850 149324  EhStorClass - ok
08:29:19.0864 149324  [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv    C:\Windows\system32\drivers\EhStorTcgDrv.sys
08:29:19.0866 149324  EhStorTcgDrv - ok
08:29:19.0940 149324  [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn            C:\Program Files\ESET\ESET NOD32 antivírus\x86\ekrn.exe
08:29:19.0948 149324  ekrn - ok
08:29:19.0999 149324  [ 3EBB7FD3C605262B942868A1D840F4F1 ] epfwwfpr        C:\Windows\system32\DRIVERS\epfwwfpr.sys
08:29:20.0001 149324  epfwwfpr - ok
08:29:20.0010 149324  [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev          C:\Windows\System32\drivers\errdev.sys
08:29:20.0011 149324  ErrDev - ok
08:29:20.0058 149324  [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem     C:\Windows\system32\es.dll
08:29:20.0064 149324  EventSystem - ok
08:29:20.0085 149324  [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat           C:\Windows\system32\drivers\exfat.sys
08:29:20.0088 149324  exfat - ok
08:29:20.0108 149324  [ 60996602A7111FD2D086E803F33E4282 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
08:29:20.0111 149324  fastfat - ok
08:29:20.0133 149324  [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax             C:\Windows\system32\fxssvc.exe
08:29:20.0139 149324  Fax - ok
08:29:20.0150 149324  [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc             C:\Windows\System32\drivers\fdc.sys
08:29:20.0151 149324  fdc - ok
08:29:20.0167 149324  [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost         C:\Windows\system32\fdPHost.dll
08:29:20.0168 149324  fdPHost - ok
08:29:20.0172 149324  [ 872506AAB591E8908DF4461475AF92DF ] FDResPub        C:\Windows\system32\fdrespub.dll
08:29:20.0173 149324  FDResPub - ok
08:29:20.0207 149324  [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc           C:\Windows\system32\fhsvc.dll
08:29:20.0208 149324  fhsvc - ok
08:29:20.0225 149324  [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
08:29:20.0226 149324  FileInfo - ok
08:29:20.0238 149324  [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
08:29:20.0239 149324  Filetrace - ok
08:29:20.0243 149324  [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk        C:\Windows\System32\drivers\flpydisk.sys
08:29:20.0244 149324  flpydisk - ok
08:29:20.0256 149324  [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
08:29:20.0259 149324  FltMgr - ok
08:29:20.0301 149324  [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache       C:\Windows\system32\FntCache.dll
08:29:20.0307 149324  FontCache - ok
08:29:20.0405 149324  [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
08:29:20.0406 149324  FontCache3.0.0.0 - ok
08:29:20.0423 149324  [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
08:29:20.0424 149324  FsDepends - ok
08:29:20.0437 149324  [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
08:29:20.0438 149324  Fs_Rec - ok
08:29:20.0476 149324  [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
08:29:20.0479 149324  fvevol - ok
08:29:20.0503 149324  [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM           C:\Windows\System32\drivers\fxppm.sys
08:29:20.0504 149324  FxPPM - ok
08:29:20.0529 149324  [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
08:29:20.0530 149324  gagp30kx - ok
08:29:20.0548 149324  [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter      C:\Windows\System32\drivers\vmgencounter.sys
08:29:20.0549 149324  gencounter - ok
08:29:20.0619 149324  GGSAFERDriver - ok
08:29:20.0629 149324  [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101     C:\Windows\system32\Drivers\msgpioclx.sys
08:29:20.0631 149324  GPIOClx0101 - ok
08:29:20.0668 149324  [ 5358678C6370F2ADC5291849F6503262 ] gpsvc           C:\Windows\System32\gpsvc.dll
08:29:20.0680 149324  gpsvc - ok
08:29:20.0747 149324  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
08:29:20.0748 149324  gupdate - ok
08:29:20.0753 149324  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
08:29:20.0755 149324  gupdatem - ok
08:29:20.0784 149324  [ C1B577B2169900F4CF7190C39F085794 ] gusvc           C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
08:29:20.0786 149324  gusvc - ok
08:29:20.0805 149324  [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
08:29:20.0808 149324  HdAudAddService - ok
08:29:20.0835 149324  [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus        C:\Windows\System32\drivers\HDAudBus.sys
08:29:20.0837 149324  HDAudBus - ok
08:29:20.0864 149324  [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt         C:\Windows\System32\drivers\HidBatt.sys
08:29:20.0865 149324  HidBatt - ok
08:29:20.0877 149324  [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth          C:\Windows\System32\drivers\hidbth.sys
08:29:20.0878 149324  HidBth - ok
08:29:20.0908 149324  [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c          C:\Windows\System32\drivers\hidi2c.sys
08:29:20.0909 149324  hidi2c - ok
08:29:20.0925 149324  [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr           C:\Windows\System32\drivers\hidir.sys
08:29:20.0927 149324  HidIr - ok
08:29:20.0951 149324  [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv         C:\Windows\system32\hidserv.dll
08:29:20.0952 149324  hidserv - ok
08:29:20.0962 149324  [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb          C:\Windows\System32\drivers\hidusb.sys
08:29:20.0963 149324  HidUsb - ok
08:29:20.0986 149324  [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc          C:\Windows\system32\kmsvc.dll
08:29:20.0988 149324  hkmsvc - ok
08:29:21.0018 149324  [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
08:29:21.0021 149324  HomeGroupListener - ok
08:29:21.0046 149324  [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
08:29:21.0053 149324  HomeGroupProvider - ok
08:29:21.0058 149324  [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
08:29:21.0060 149324  HpSAMD - ok
08:29:21.0100 149324  [ 29CB98187BB5711F7759540976D295FC ] HTTP            C:\Windows\system32\drivers\HTTP.sys
08:29:21.0107 149324  HTTP - ok
08:29:21.0127 149324  [ 2A98301068801700906C06649860FE94 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
08:29:21.0128 149324  hwpolicy - ok
08:29:21.0135 149324  [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd        C:\Windows\System32\drivers\hyperkbd.sys
08:29:21.0135 149324  hyperkbd - ok
08:29:21.0141 149324  [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo      C:\Windows\system32\DRIVERS\HyperVideo.sys
08:29:21.0142 149324  HyperVideo - ok
08:29:21.0149 149324  [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt        C:\Windows\System32\drivers\i8042prt.sys
08:29:21.0150 149324  i8042prt - ok
08:29:21.0168 149324  [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
08:29:21.0170 149324  iaStorV - ok
08:29:21.0202 149324  [ 3CBC834892B5E04CE635BB60FB0EE6FF ] IDMWFP          C:\Windows\system32\DRIVERS\idmwfp.sys
08:29:21.0203 149324  IDMWFP - ok
08:29:21.0292 149324  [ A1CF07D24EDCDC6870535471654D957C ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
08:29:21.0314 149324  igfx - ok
08:29:21.0318 149324  [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
08:29:21.0319 149324  iirsp - ok
08:29:21.0356 149324  [ A8FE84361B11953F651DFDF1B9A36F88 ] IKEEXT          C:\Windows\System32\ikeext.dll
08:29:21.0361 149324  IKEEXT - ok
08:29:21.0366 149324  [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide        C:\Windows\system32\drivers\intelide.sys
08:29:21.0367 149324  intelide - ok
08:29:21.0394 149324  [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm        C:\Windows\System32\drivers\intelppm.sys
08:29:21.0395 149324  intelppm - ok
08:29:21.0412 149324  [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:29:21.0413 149324  IpFilterDriver - ok
08:29:21.0441 149324  [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
08:29:21.0446 149324  iphlpsvc - ok
08:29:21.0450 149324  [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV         C:\Windows\System32\drivers\IPMIDrv.sys
08:29:21.0451 149324  IPMIDRV - ok
08:29:21.0456 149324  [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
08:29:21.0457 149324  IPNAT - ok
08:29:21.0468 149324  [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM          C:\Windows\system32\drivers\irenum.sys
08:29:21.0469 149324  IRENUM - ok
08:29:21.0472 149324  [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
08:29:21.0473 149324  isapnp - ok
08:29:21.0497 149324  [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt        C:\Windows\System32\drivers\msiscsi.sys
08:29:21.0499 149324  iScsiPrt - ok
08:29:21.0517 149324  [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass        C:\Windows\System32\drivers\kbdclass.sys
08:29:21.0518 149324  kbdclass - ok
08:29:21.0525 149324  [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid          C:\Windows\System32\drivers\kbdhid.sys
08:29:21.0525 149324  kbdhid - ok
08:29:21.0536 149324  [ FB6C185092E18011EF49989425C2AA87 ] kdnic           C:\Windows\system32\DRIVERS\kdnic.sys
08:29:21.0537 149324  kdnic - ok
08:29:21.0552 149324  [ F702AB6181513303AB0FC8D59E52708B ] KeyIso          C:\Windows\system32\lsass.exe
08:29:21.0553 149324  KeyIso - ok
08:29:21.0580 149324  [ DFA480F6DED551464F3A5B959F437800 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
08:29:21.0581 149324  KSecDD - ok
08:29:21.0609 149324  [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
08:29:21.0610 149324  KSecPkg - ok
08:29:21.0619 149324  [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
08:29:21.0620 149324  ksthunk - ok
08:29:21.0638 149324  [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm           C:\Windows\system32\msdtckrm.dll
08:29:21.0641 149324  KtmRm - ok
08:29:21.0661 149324  [ 8412D334F6B18F655BFF430E9DB1ABC6 ] L1C             C:\Windows\system32\DRIVERS\L1C63x64.sys
08:29:21.0663 149324  L1C - ok
08:29:21.0685 149324  [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer    C:\Windows\system32\srvsvc.dll
08:29:21.0690 149324  LanmanServer - ok
08:29:21.0718 149324  [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
08:29:21.0722 149324  LanmanWorkstation - ok
08:29:21.0731 149324  [ CEEFD29FC551F289810B0B9381B321DC ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
08:29:21.0732 149324  lltdio - ok
08:29:21.0750 149324  [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc         C:\Windows\System32\lltdsvc.dll
08:29:21.0754 149324  lltdsvc - ok
08:29:21.0768 149324  [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts         C:\Windows\System32\lmhsvc.dll
08:29:21.0770 149324  lmhosts - ok
08:29:21.0785 149324  [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
08:29:21.0787 149324  LSI_SAS - ok
08:29:21.0794 149324  [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
08:29:21.0796 149324  LSI_SAS2 - ok
08:29:21.0804 149324  [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
08:29:21.0806 149324  LSI_SCSI - ok
08:29:21.0821 149324  [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS         C:\Windows\system32\drivers\lsi_sss.sys
08:29:21.0822 149324  LSI_SSS - ok
08:29:21.0846 149324  [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM             C:\Windows\System32\lsm.dll
08:29:21.0851 149324  LSM - ok
08:29:21.0863 149324  [ 2BDC5D711FA61307CE6190D47C956368 ] luafv           C:\Windows\system32\drivers\luafv.sys
08:29:21.0865 149324  luafv - ok
08:29:21.0892 149324  [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
08:29:21.0893 149324  MBAMProtector - ok
08:29:21.0942 149324  [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler   C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
08:29:21.0946 149324  MBAMScheduler - ok
08:29:21.0971 149324  [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService     C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
08:29:21.0977 149324  MBAMService - ok
08:29:21.0983 149324  [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas         C:\Windows\system32\drivers\megasas.sys
08:29:21.0985 149324  megasas - ok
08:29:21.0999 149324  [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
08:29:22.0002 149324  MegaSR - ok
08:29:22.0023 149324  [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64          C:\Windows\System32\drivers\HECIx64.sys
08:29:22.0024 149324  MEIx64 - ok
08:29:22.0054 149324  [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS           C:\Windows\system32\mmcss.dll
08:29:22.0056 149324  MMCSS - ok
08:29:22.0063 149324  [ 780098AD5DA8A4822E2563984C85EF7B ] Modem           C:\Windows\system32\drivers\modem.sys
08:29:22.0064 149324  Modem - ok
08:29:22.0083 149324  [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
08:29:22.0084 149324  monitor - ok
08:29:22.0097 149324  [ 618446B98C79776654340CE27C73485E ] mouclass        C:\Windows\System32\drivers\mouclass.sys
08:29:22.0098 149324  mouclass - ok
08:29:22.0110 149324  [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid          C:\Windows\System32\drivers\mouhid.sys
08:29:22.0111 149324  mouhid - ok
08:29:22.0145 149324  [ 89D263DBF08119CE16273991C120D6DD ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
08:29:22.0147 149324  mountmgr - ok
08:29:22.0174 149324  [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
08:29:22.0176 149324  mpsdrv - ok
08:29:22.0221 149324  [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc          C:\Windows\system32\mpssvc.dll
08:29:22.0229 149324  MpsSvc - ok
08:29:22.0272 149324  [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
08:29:22.0275 149324  MRxDAV - ok
08:29:22.0308 149324  [ 877D60D6E4156EC4A2E0B6871D41BED9 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
08:29:22.0312 149324  mrxsmb - ok
08:29:22.0321 149324  [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:29:22.0324 149324  mrxsmb10 - ok
08:29:22.0358 149324  [ E078446D4B8622AA6030C7B8A1A08962 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:29:22.0361 149324  mrxsmb20 - ok
08:29:22.0372 149324  [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge        C:\Windows\system32\DRIVERS\bridge.sys
08:29:22.0375 149324  MsBridge - ok
08:29:22.0394 149324  [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC           C:\Windows\System32\msdtc.exe
08:29:22.0398 149324  MSDTC - ok
08:29:22.0423 149324  [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
08:29:22.0424 149324  Msfs - ok
08:29:22.0438 149324  [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32     C:\Windows\System32\drivers\msgpiowin32.sys
08:29:22.0439 149324  msgpiowin32 - ok
08:29:22.0451 149324  [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
08:29:22.0452 149324  mshidkmdf - ok
08:29:22.0462 149324  [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf       C:\Windows\System32\drivers\mshidumdf.sys
08:29:22.0462 149324  mshidumdf - ok
08:29:22.0479 149324  [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
08:29:22.0480 149324  msisadrv - ok
08:29:22.0500 149324  [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
08:29:22.0504 149324  MSiSCSI - ok
08:29:22.0509 149324  msiserver - ok
08:29:22.0524 149324  [ 509809566E49F4411055864EA8D437CD ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
08:29:22.0525 149324  MSKSSRV - ok
08:29:22.0548 149324  [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp          C:\Windows\system32\DRIVERS\mslldp.sys
08:29:22.0549 149324  MsLldp - ok
08:29:22.0555 149324  [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
08:29:22.0555 149324  MSPCLOCK - ok
08:29:22.0561 149324  [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
08:29:22.0562 149324  MSPQM - ok
08:29:22.0580 149324  [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
08:29:22.0584 149324  MsRPC - ok
08:29:22.0594 149324  [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios        C:\Windows\System32\drivers\mssmbios.sys
08:29:22.0595 149324  mssmbios - ok
08:29:22.0600 149324  [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
08:29:22.0601 149324  MSTEE - ok
08:29:22.0607 149324  [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig        C:\Windows\System32\drivers\MTConfig.sys
08:29:22.0609 149324  MTConfig - ok
08:29:22.0615 149324  [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup             C:\Windows\system32\Drivers\mup.sys
08:29:22.0617 149324  Mup - ok
08:29:22.0621 149324  [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis          C:\Windows\system32\drivers\mvumis.sys
08:29:22.0622 149324  mvumis - ok
08:29:22.0648 149324  [ 4B18840511D720BA118D3017E8165875 ] napagent        C:\Windows\system32\qagentRT.dll
08:29:22.0652 149324  napagent - ok
08:29:22.0674 149324  [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
08:29:22.0676 149324  NativeWifiP - ok
08:29:22.0701 149324  [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc          C:\Windows\System32\ncasvc.dll
08:29:22.0703 149324  NcaSvc - ok
08:29:22.0727 149324  [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup    C:\Windows\System32\NcdAutoSetup.dll
08:29:22.0730 149324  NcdAutoSetup - ok
08:29:22.0773 149324  [ 0F89AE618DBA5D8AB7A2DFCC375F4159 ] NDIS            C:\Windows\system32\drivers\ndis.sys
08:29:22.0778 149324  NDIS - ok
08:29:22.0800 149324  [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
08:29:22.0800 149324  NdisCap - ok
08:29:22.0813 149324  [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform  C:\Windows\system32\DRIVERS\NdisImPlatform.sys
08:29:22.0815 149324  NdisImPlatform - ok
08:29:22.0836 149324  [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
08:29:22.0837 149324  NdisTapi - ok
08:29:22.0851 149324  [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
08:29:22.0851 149324  Ndisuio - ok
08:29:22.0868 149324  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
08:29:22.0869 149324  NdisWan - ok
08:29:22.0874 149324  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY   C:\Windows\system32\DRIVERS\ndiswan.sys
08:29:22.0875 149324  NDISWANLEGACY - ok
08:29:22.0888 149324  [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
08:29:22.0889 149324  NDProxy - ok
08:29:22.0894 149324  [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu             C:\Windows\system32\drivers\Ndu.sys
08:29:22.0895 149324  Ndu - ok
08:29:22.0901 149324  [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
08:29:22.0902 149324  NetBIOS - ok
08:29:22.0915 149324  [ 7CEC25C682D319D484630B3952C31A11 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
08:29:22.0917 149324  NetBT - ok
08:29:22.0920 149324  [ F702AB6181513303AB0FC8D59E52708B ] Netlogon        C:\Windows\system32\lsass.exe
08:29:22.0922 149324  Netlogon - ok
08:29:22.0937 149324  [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman          C:\Windows\System32\netman.dll
08:29:22.0940 149324  Netman - ok
08:29:22.0957 149324  [ 20F6FD63E6D456114BC8056D62792786 ] netprofm        C:\Windows\System32\netprofmsvc.dll
08:29:22.0961 149324  netprofm - ok
08:29:23.0007 149324  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
08:29:23.0008 149324  NetTcpPortSharing - ok
08:29:23.0016 149324  [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
08:29:23.0017 149324  nfrd960 - ok
08:29:23.0050 149324  [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc          C:\Windows\System32\nlasvc.dll
08:29:23.0053 149324  NlaSvc - ok
08:29:23.0062 149324  [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
08:29:23.0062 149324  Npfs - ok
08:29:23.0072 149324  [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig       C:\Windows\System32\drivers\npsvctrig.sys
08:29:23.0073 149324  npsvctrig - ok
08:29:23.0090 149324  [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi             C:\Windows\system32\nsisvc.dll
08:29:23.0092 149324  nsi - ok
08:29:23.0102 149324  [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
08:29:23.0103 149324  nsiproxy - ok
08:29:23.0149 149324  [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
08:29:23.0158 149324  Ntfs - ok
08:29:23.0170 149324  [ 4163ADE07DB51843AE31F65B94F5398D ] Null            C:\Windows\system32\drivers\Null.sys
08:29:23.0171 149324  Null - ok
08:29:23.0175 149324  [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
08:29:23.0176 149324  nvraid - ok
08:29:23.0188 149324  [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
08:29:23.0190 149324  nvstor - ok
08:29:23.0202 149324  [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
08:29:23.0203 149324  nv_agp - ok
08:29:23.0220 149324  [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
08:29:23.0222 149324  p2pimsvc - ok
08:29:23.0235 149324  [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc          C:\Windows\system32\p2psvc.dll
08:29:23.0238 149324  p2psvc - ok
08:29:23.0242 149324  [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport         C:\Windows\System32\drivers\parport.sys
08:29:23.0243 149324  Parport - ok
08:29:23.0256 149324  [ C1D7BA7F0DE487DFEEB51BF8D3EC5562 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
08:29:23.0257 149324  partmgr - ok
08:29:23.0290 149324  [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc          C:\Windows\System32\pcasvc.dll
08:29:23.0294 149324  PcaSvc - ok
08:29:23.0312 149324  [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci             C:\Windows\system32\drivers\pci.sys
08:29:23.0313 149324  pci - ok
08:29:23.0324 149324  [ F9908D274D458220F91E89B54D78D837 ] pciide          C:\Windows\system32\drivers\pciide.sys
08:29:23.0325 149324  pciide - ok
08:29:23.0338 149324  [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
08:29:23.0339 149324  pcmcia - ok
08:29:23.0362 149324  [ CEBBAD5391C2644560C55628A40BFD27 ] pcw             C:\Windows\system32\drivers\pcw.sys
08:29:23.0363 149324  pcw - ok
08:29:23.0389 149324  [ EF9B4F3136B4C45F421ADE6871659FB6 ] pdc             C:\Windows\system32\drivers\pdc.sys
08:29:23.0390 149324  pdc - ok
08:29:23.0413 149324  [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
08:29:23.0416 149324  PEAUTH - ok
08:29:23.0464 149324  [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
08:29:23.0475 149324  PeerDistSvc - ok
08:29:23.0575 149324  [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost        C:\Windows\SysWow64\perfhost.exe
08:29:23.0577 149324  PerfHost - ok
08:29:23.0614 149324  [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla             C:\Windows\system32\pla.dll
08:29:23.0622 149324  pla - ok
08:29:23.0644 149324  [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
08:29:23.0646 149324  PlugPlay - ok
08:29:23.0649 149324  PnkBstrA - ok
08:29:23.0652 149324  PnkBstrB - ok
08:29:23.0669 149324  [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
08:29:23.0671 149324  PNRPAutoReg - ok
08:29:23.0686 149324  [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
08:29:23.0689 149324  PNRPsvc - ok
08:29:23.0706 149324  [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
08:29:23.0709 149324  PolicyAgent - ok
08:29:23.0737 149324  [ F1E067F56373F11EA4B785CAE823740A ] Power           C:\Windows\system32\umpo.dll
08:29:23.0739 149324  Power - ok
08:29:23.0754 149324  [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
08:29:23.0755 149324  PptpMiniport - ok
08:29:23.0834 149324  [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify     C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
08:29:23.0845 149324  PrintNotify - ok
08:29:23.0876 149324  [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor       C:\Windows\System32\drivers\processr.sys
08:29:23.0877 149324  Processor - ok
08:29:23.0911 149324  [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc         C:\Windows\system32\profsvc.dll
08:29:23.0913 149324  ProfSvc - ok
08:29:23.0925 149324  [ EB8034147D4820CD31BFCB11A2A652DF ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
08:29:23.0926 149324  Psched - ok
08:29:23.0948 149324  [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE           C:\Windows\system32\qwave.dll
08:29:23.0951 149324  QWAVE - ok
08:29:23.0958 149324  [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
08:29:23.0959 149324  QWAVEdrv - ok
08:29:23.0990 149324  [ 873C60F8178100557740A832FCE10B5F ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
08:29:23.0991 149324  RasAcd - ok
08:29:24.0024 149324  [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
08:29:24.0024 149324  RasAgileVpn - ok
08:29:24.0039 149324  [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto         C:\Windows\System32\rasauto.dll
08:29:24.0042 149324  RasAuto - ok
08:29:24.0055 149324  [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
08:29:24.0056 149324  Rasl2tp - ok
08:29:24.0077 149324  [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan          C:\Windows\System32\rasmans.dll
08:29:24.0080 149324  RasMan - ok
08:29:24.0095 149324  [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
08:29:24.0096 149324  RasPppoe - ok
08:29:24.0110 149324  [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
08:29:24.0111 149324  RasSstp - ok
08:29:24.0118 149324  [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
08:29:24.0120 149324  rdbss - ok
08:29:24.0131 149324  [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus          C:\Windows\System32\drivers\rdpbus.sys
08:29:24.0132 149324  rdpbus - ok
08:29:24.0149 149324  [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
08:29:24.0150 149324  RDPDR - ok
08:29:24.0170 149324  [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
08:29:24.0171 149324  RdpVideoMiniport - ok
08:29:24.0186 149324  [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
08:29:24.0188 149324  RDPWD - ok
08:29:24.0213 149324  [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
08:29:24.0215 149324  rdyboost - ok
08:29:24.0240 149324  [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess    C:\Windows\System32\mprdim.dll
08:29:24.0242 149324  RemoteAccess - ok
08:29:24.0257 149324  [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry  C:\Windows\system32\regsvc.dll
08:29:24.0260 149324  RemoteRegistry - ok
08:29:24.0274 149324  [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
08:29:24.0276 149324  RpcEptMapper - ok
08:29:24.0297 149324  [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator      C:\Windows\system32\locator.exe
08:29:24.0298 149324  RpcLocator - ok
08:29:24.0326 149324  [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs           C:\Windows\system32\rpcss.dll
08:29:24.0331 149324  RpcSs - ok
08:29:24.0338 149324  [ E04E770DD198B9399640717145E79EBF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
08:29:24.0339 149324  rspndr - ok
08:29:24.0348 149324  [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap           C:\Windows\System32\drivers\vms3cap.sys
08:29:24.0348 149324  s3cap - ok
08:29:24.0360 149324  [ F702AB6181513303AB0FC8D59E52708B ] SamSs           C:\Windows\system32\lsass.exe
08:29:24.0361 149324  SamSs - ok
08:29:24.0370 149324  [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
08:29:24.0371 149324  sbp2port - ok
08:29:24.0385 149324  [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr        C:\Windows\System32\SCardSvr.dll
08:29:24.0387 149324  SCardSvr - ok
08:29:24.0397 149324  [ 5D7733A12756B267FCA021672B26BC9E ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
08:29:24.0398 149324  scfilter - ok
08:29:24.0425 149324  [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule        C:\Windows\system32\schedsvc.dll
08:29:24.0432 149324  Schedule - ok
08:29:24.0453 149324  [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc     C:\Windows\System32\certprop.dll
08:29:24.0454 149324  SCPolicySvc - ok
08:29:24.0482 149324  [ AAAB993BDFA5C0D1CB505E16E4D7B4A2 ] sdbus           C:\Windows\System32\drivers\sdbus.sys
08:29:24.0483 149324  sdbus - ok
08:29:24.0500 149324  [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC          C:\Windows\System32\SDRSVC.dll
08:29:24.0501 149324  SDRSVC - ok
08:29:24.0523 149324  [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor          C:\Windows\System32\drivers\sdstor.sys
08:29:24.0523 149324  sdstor - ok
08:29:24.0536 149324  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
08:29:24.0536 149324  secdrv - ok
08:29:24.0551 149324  [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon        C:\Windows\system32\seclogon.dll
08:29:24.0553 149324  seclogon - ok
08:29:24.0560 149324  [ 9C51620998F0763039DFA6BF68E475ED ] SENS            C:\Windows\System32\sens.dll
08:29:24.0562 149324  SENS - ok
08:29:24.0578 149324  [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc        C:\Windows\system32\sensrsvc.dll
08:29:24.0580 149324  SensrSvc - ok
08:29:24.0601 149324  [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx           C:\Windows\system32\drivers\SerCx.sys
08:29:24.0602 149324  SerCx - ok
08:29:24.0619 149324  [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum         C:\Windows\System32\drivers\serenum.sys
08:29:24.0619 149324  Serenum - ok
08:29:24.0632 149324  [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial          C:\Windows\System32\drivers\serial.sys
08:29:24.0633 149324  Serial - ok
08:29:24.0644 149324  [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse        C:\Windows\System32\drivers\sermouse.sys
08:29:24.0645 149324  sermouse - ok
08:29:24.0662 149324  [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv      C:\Windows\system32\sessenv.dll
08:29:24.0664 149324  SessionEnv - ok
08:29:24.0715 149324  [ 8423DB42808E94847EC4E53EFDA6BEE2 ] setup_9.0.0.722_02.01.2013_22-27drv C:\Windows\system32\DRIVERS\2006471.sys
08:29:24.0717 149324  setup_9.0.0.722_02.01.2013_22-27drv - ok
08:29:24.0726 149324  [ 7EE65419B29302C795714FF8073969A1 ] sfloppy         C:\Windows\System32\drivers\sfloppy.sys
08:29:24.0726 149324  sfloppy - ok
08:29:24.0756 149324  [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
08:29:24.0759 149324  SharedAccess - ok
08:29:24.0780 149324  [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
08:29:24.0784 149324  ShellHWDetection - ok
08:29:24.0787 149324  [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
08:29:24.0788 149324  SiSRaid2 - ok
08:29:24.0802 149324  [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
08:29:24.0803 149324  SiSRaid4 - ok
08:29:24.0810 149324  [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
08:29:24.0811 149324  SNMPTRAP - ok
08:29:24.0831 149324  [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport       C:\Windows\system32\drivers\spaceport.sys
08:29:24.0833 149324  spaceport - ok
08:29:24.0836 149324  [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx           C:\Windows\system32\drivers\SpbCx.sys
08:29:24.0837 149324  SpbCx - ok
08:29:24.0851 149324  [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler         C:\Windows\System32\spoolsv.exe
08:29:24.0856 149324  Spooler - ok
08:29:24.0920 149324  [ EC84D961501054F87A6878EC5D53388F ] sppsvc          C:\Windows\system32\sppsvc.exe
08:29:24.0941 149324  sppsvc - ok
08:29:24.0964 149324  [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv             C:\Windows\system32\DRIVERS\srv.sys
08:29:24.0966 149324  srv - ok
08:29:24.0999 149324  [ C2106BB710AA34A046126AED7BCA6964 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
08:29:25.0002 149324  srv2 - ok
08:29:25.0018 149324  [ 9400C71F5A1A380B494B6922F007D485 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
08:29:25.0020 149324  srvnet - ok
08:29:25.0029 149324  [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
08:29:25.0031 149324  SSDPSRV - ok
08:29:25.0042 149324  [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc         C:\Windows\system32\sstpsvc.dll
08:29:25.0044 149324  SstpSvc - ok
08:29:25.0072 149324  Steam Client Service - ok
08:29:25.0083 149324  [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
08:29:25.0084 149324  stexstor - ok
08:29:25.0108 149324  [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc          C:\Windows\System32\wiaservc.dll
08:29:25.0112 149324  stisvc - ok
08:29:25.0116 149324  [ C588BBD37B432CE3204E5765B459E6B2 ] storahci        C:\Windows\system32\drivers\storahci.sys
08:29:25.0117 149324  storahci - ok
08:29:25.0133 149324  [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt         C:\Windows\system32\DRIVERS\vmstorfl.sys
08:29:25.0134 149324  storflt - ok
08:29:25.0141 149324  [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc         C:\Windows\system32\storsvc.dll
08:29:25.0143 149324  StorSvc - ok
08:29:25.0146 149324  [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
08:29:25.0147 149324  storvsc - ok
08:29:25.0152 149324  [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp         C:\Windows\System32\drivers\storvsp.sys
08:29:25.0153 149324  storvsp - ok
08:29:25.0163 149324  [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc           C:\Windows\system32\svsvc.dll
08:29:25.0166 149324  svsvc - ok
08:29:25.0181 149324  [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum          C:\Windows\System32\drivers\swenum.sys
08:29:25.0182 149324  swenum - ok
08:29:25.0199 149324  [ 502F9488540051F3E6C39889ECFA76BB ] swprv           C:\Windows\System32\swprv.dll
08:29:25.0203 149324  swprv - ok
08:29:25.0232 149324  [ DC21E1F06343773D7E24362DCEF7944B ] SysMain         C:\Windows\system32\sysmain.dll
08:29:25.0239 149324  SysMain - ok
08:29:25.0260 149324  [ 079244F281621FEDCC161D3923E858FE ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
08:29:25.0262 149324  SystemEventsBroker - ok
08:29:25.0277 149324  [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
08:29:25.0279 149324  TabletInputService - ok
08:29:25.0295 149324  [ B08740047145B9BCE15BF75CA0F9718A ] tap0901t        C:\Windows\system32\DRIVERS\tap0901t.sys
08:29:25.0296 149324  tap0901t - ok
08:29:25.0311 149324  [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv         C:\Windows\System32\tapisrv.dll
08:29:25.0314 149324  TapiSrv - ok
08:29:25.0366 149324  [ 1D644E2D0FC395A055AB1C23C3B43631 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
08:29:25.0376 149324  Tcpip - ok
08:29:25.0409 149324  [ 1D644E2D0FC395A055AB1C23C3B43631 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
08:29:25.0418 149324  TCPIP6 - ok
08:29:25.0440 149324  [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
08:29:25.0441 149324  tcpipreg - ok
08:29:25.0449 149324  [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
08:29:25.0450 149324  tdx - ok
08:29:25.0527 149324  [ 9F3E7CABE86BBDECA009DE291DB6D9E2 ] TeamViewer8     C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
08:29:25.0541 149324  TeamViewer8 - ok
08:29:25.0549 149324  [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt        C:\Windows\System32\drivers\terminpt.sys
08:29:25.0550 149324  terminpt - ok
08:29:25.0571 149324  [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService     C:\Windows\System32\termsrv.dll
08:29:25.0576 149324  TermService - ok
08:29:25.0588 149324  [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes          C:\Windows\system32\themeservice.dll
08:29:25.0589 149324  Themes - ok
08:29:25.0620 149324  [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER     C:\Windows\system32\mmcss.dll
08:29:25.0623 149324  THREADORDER - ok
08:29:25.0656 149324  [ 52066C139CC189468845D5BE557B25EB ] TimeBroker      C:\Windows\System32\TimeBrokerServer.dll
08:29:25.0660 149324  TimeBroker - ok
08:29:25.0690 149324  [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM             C:\Windows\system32\drivers\tpm.sys
08:29:25.0693 149324  TPM - ok
08:29:25.0721 149324  [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks          C:\Windows\System32\trkwks.dll
08:29:25.0725 149324  TrkWks - ok
08:29:25.0772 149324  [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
08:29:25.0774 149324  TrustedInstaller - ok
08:29:25.0791 149324  [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
08:29:25.0792 149324  TsUsbFlt - ok
08:29:25.0806 149324  [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD         C:\Windows\System32\drivers\TsUsbGD.sys
08:29:25.0807 149324  TsUsbGD - ok
08:29:25.0824 149324  [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
08:29:25.0826 149324  tunnel - ok
08:29:25.0896 149324  [ 2FD0FE0A0C721C8E47C5A3AE16E519B1 ] TunngleService  C:\Program Files (x86)\Tunngle\TnglCtrl.exe
08:29:25.0902 149324  TunngleService - ok
08:29:25.0908 149324  [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35          C:\Windows\system32\drivers\uagp35.sys
08:29:25.0910 149324  uagp35 - ok
08:29:25.0916 149324  [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor        C:\Windows\System32\drivers\uaspstor.sys
08:29:25.0917 149324  UASPStor - ok
08:29:25.0940 149324  [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000        C:\Windows\System32\drivers\ucx01000.sys
08:29:25.0942 149324  UCX01000 - ok
08:29:25.0960 149324  [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
08:29:25.0963 149324  udfs - ok
08:29:25.0990 149324  [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect       C:\Windows\system32\UI0Detect.exe
08:29:25.0993 149324  UI0Detect - ok
08:29:26.0006 149324  [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
08:29:26.0008 149324  uliagpkx - ok
08:29:26.0028 149324  [ 02CEB3FE6152668A7BA420B93B664860 ] umbus           C:\Windows\System32\drivers\umbus.sys
08:29:26.0029 149324  umbus - ok
08:29:26.0033 149324  [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass          C:\Windows\System32\drivers\umpass.sys
08:29:26.0033 149324  UmPass - ok
08:29:26.0047 149324  [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService    C:\Windows\System32\umrdp.dll
08:29:26.0050 149324  UmRdpService - ok
08:29:26.0066 149324  [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost        C:\Windows\System32\upnphost.dll
08:29:26.0071 149324  upnphost - ok
08:29:26.0084 149324  [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp         C:\Windows\System32\drivers\usbccgp.sys
08:29:26.0085 149324  usbccgp - ok
08:29:26.0099 149324  [ B395B62B62F28106218FA6FB17F4C797 ] usbcir          C:\Windows\System32\drivers\usbcir.sys
08:29:26.0100 149324  usbcir - ok
08:29:26.0126 149324  [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci         C:\Windows\System32\drivers\usbehci.sys
08:29:26.0127 149324  usbehci - ok
08:29:26.0168 149324  [ FBB6794E3BBAD92D66D59D206C1F849F ] usbhub          C:\Windows\System32\drivers\usbhub.sys
08:29:26.0171 149324  usbhub - ok
08:29:26.0199 149324  [ B7A948501424805571BF562BB0BFE31D ] USBHUB3         C:\Windows\System32\drivers\UsbHub3.sys
08:29:26.0202 149324  USBHUB3 - ok
08:29:26.0213 149324  [ 325F6179009B5A7F6118951A5BA422AB ] usbohci         C:\Windows\System32\drivers\usbohci.sys
08:29:26.0215 149324  usbohci - ok
08:29:26.0219 149324  [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint        C:\Windows\System32\drivers\usbprint.sys
08:29:26.0220 149324  usbprint - ok
08:29:26.0234 149324  [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR         C:\Windows\System32\drivers\USBSTOR.SYS
08:29:26.0235 149324  USBSTOR - ok
08:29:26.0248 149324  [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci         C:\Windows\System32\drivers\usbuhci.sys
08:29:26.0249 149324  usbuhci - ok
08:29:26.0264 149324  [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI         C:\Windows\System32\drivers\USBXHCI.SYS
08:29:26.0266 149324  USBXHCI - ok
08:29:26.0285 149324  [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc        C:\Windows\system32\lsass.exe
08:29:26.0286 149324  VaultSvc - ok
08:29:26.0300 149324  [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
08:29:26.0301 149324  vdrvroot - ok
08:29:26.0325 149324  [ 00FBA165A1167738802DA5D0EE78EF10 ] vds             C:\Windows\System32\vds.exe
08:29:26.0331 149324  vds - ok
08:29:26.0344 149324  [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt     C:\Windows\system32\drivers\VerifierExt.sys
08:29:26.0345 149324  VerifierExt - ok
08:29:26.0360 149324  [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp           C:\Windows\System32\drivers\vhdmp.sys
08:29:26.0363 149324  vhdmp - ok
08:29:26.0403 149324  [ D86967ACFE0783CEE2909A9AF0787045 ] VIAHdAudAddService C:\Windows\system32\drivers\viahduaa.sys
08:29:26.0411 149324  VIAHdAudAddService - ok
08:29:26.0425 149324  [ F5B4A14B00E89250C50982AC762DDD1D ] viaide          C:\Windows\system32\drivers\viaide.sys
08:29:26.0426 149324  viaide - ok
08:29:26.0439 149324  [ 9A12B5AC0E983E0309371DBA058019A4 ] VIAKaraokeService C:\Windows\system32\viakaraokesrv.exe
08:29:26.0441 149324  VIAKaraokeService - ok
08:29:26.0456 149324  [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid             C:\Windows\System32\drivers\Vid.sys
08:29:26.0458 149324  Vid - ok
08:29:26.0470 149324  [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
08:29:26.0471 149324  vmbus - ok
08:29:26.0476 149324  [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID        C:\Windows\System32\drivers\VMBusHID.sys
08:29:26.0477 149324  VMBusHID - ok
08:29:26.0485 149324  [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr          C:\Windows\System32\drivers\vmbusr.sys
08:29:26.0486 149324  vmbusr - ok
08:29:26.0513 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat   C:\Windows\System32\ICSvc.dll
08:29:26.0516 149324  vmicheartbeat - ok
08:29:26.0522 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
08:29:26.0525 149324  vmickvpexchange - ok
08:29:26.0539 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv         C:\Windows\System32\ICSvc.dll
08:29:26.0542 149324  vmicrdv - ok
08:29:26.0548 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown    C:\Windows\System32\ICSvc.dll
08:29:26.0550 149324  vmicshutdown - ok
08:29:26.0556 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync    C:\Windows\System32\ICSvc.dll
08:29:26.0558 149324  vmictimesync - ok
08:29:26.0563 149324  [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss         C:\Windows\System32\ICSvc.dll
08:29:26.0566 149324  vmicvss - ok
08:29:26.0586 149324  [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
08:29:26.0587 149324  volmgr - ok
08:29:26.0593 149324  [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
08:29:26.0595 149324  volmgrx - ok
08:29:26.0601 149324  [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap         C:\Windows\system32\drivers\volsnap.sys
08:29:26.0603 149324  volsnap - ok
08:29:26.0619 149324  [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci            C:\Windows\System32\drivers\vpci.sys
08:29:26.0620 149324  vpci - ok
08:29:26.0623 149324  [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp         C:\Windows\System32\drivers\vpcivsp.sys
08:29:26.0624 149324  vpcivsp - ok
08:29:26.0629 149324  [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
08:29:26.0630 149324  vsmraid - ok
08:29:26.0665 149324  [ EA658570314042C914964FC72AB50E6B ] VSS             C:\Windows\system32\vssvc.exe
08:29:26.0673 149324  VSS - ok
08:29:26.0687 149324  [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID        C:\Windows\system32\drivers\vstxraid.sys
08:29:26.0688 149324  VSTXRAID - ok
08:29:26.0699 149324  [ 62460A45435A26A334907E3F2EA45611 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
08:29:26.0700 149324  vwifibus - ok
08:29:26.0728 149324  [ F690B6EEAA94576727B24376D7ED3601 ] W32Time         C:\Windows\system32\w32time.dll
08:29:26.0731 149324  W32Time - ok
08:29:26.0735 149324  [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen        C:\Windows\System32\drivers\wacompen.sys
08:29:26.0736 149324  WacomPen - ok
08:29:26.0760 149324  [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
08:29:26.0761 149324  Wanarp - ok
08:29:26.0765 149324  [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
08:29:26.0766 149324  Wanarpv6 - ok
08:29:26.0796 149324  [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine        C:\Windows\system32\wbengine.exe
08:29:26.0804 149324  wbengine - ok
08:29:26.0834 149324  [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
08:29:26.0837 149324  WbioSrvc - ok
08:29:26.0850 149324  [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc          C:\Windows\System32\wcmsvc.dll
08:29:26.0852 149324  Wcmsvc - ok
08:29:26.0873 149324  [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
08:29:26.0877 149324  wcncsvc - ok
08:29:26.0890 149324  [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
08:29:26.0892 149324  WcsPlugInService - ok
08:29:26.0898 149324  [ B3A4D918DAB90505B6BC7B70632913CB ] Wd              C:\Windows\system32\drivers\wd.sys
08:29:26.0899 149324  Wd - ok
08:29:26.0914 149324  [ 260F8DFC4D5748F4CCB9B19CFB0E58EA ] WdBoot          C:\Windows\system32\drivers\WdBoot.sys
08:29:26.0915 149324  WdBoot - ok
08:29:26.0935 149324  [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
08:29:26.0939 149324  Wdf01000 - ok
08:29:26.0951 149324  [ 880FFFC4D5BBBB4187B6B04AB2E8C32A ] WdFilter        C:\Windows\system32\drivers\WdFilter.sys
08:29:26.0952 149324  WdFilter - ok
08:29:26.0956 149324  [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
08:29:26.0959 149324  WdiServiceHost - ok
08:29:26.0962 149324  [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost   C:\Windows\system32\wdi.dll
08:29:26.0965 149324  WdiSystemHost - ok
08:29:26.0993 149324  [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient       C:\Windows\System32\webclnt.dll
08:29:26.0996 149324  WebClient - ok
08:29:27.0004 149324  [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc          C:\Windows\system32\wecsvc.dll
08:29:27.0007 149324  Wecsvc - ok
08:29:27.0018 149324  [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport   C:\Windows\System32\wercplsupport.dll
08:29:27.0020 149324  wercplsupport - ok
08:29:27.0032 149324  [ 8E2426162ED6749A127B35D235F21E11 ] WerSvc          C:\Windows\System32\WerSvc.dll
08:29:27.0035 149324  WerSvc - ok
08:29:27.0061 149324  [ F09BB0754A64733F04707B0395391911 ] WFPLWFS         C:\Windows\system32\DRIVERS\wfplwfs.sys
08:29:27.0062 149324  WFPLWFS - ok
08:29:27.0083 149324  [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc          C:\Windows\System32\wiarpc.dll
08:29:27.0085 149324  WiaRpc - ok
08:29:27.0104 149324  [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
08:29:27.0105 149324  WIMMount - ok
08:29:27.0113 149324  WinDefend - ok
08:29:27.0155 149324  [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
08:29:27.0159 149324  WinHttpAutoProxySvc - ok
08:29:27.0208 149324  [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
08:29:27.0209 149324  Winmgmt - ok
08:29:27.0260 149324  [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM           C:\Windows\system32\WsmSvc.dll
08:29:27.0274 149324  WinRM - ok
08:29:27.0317 149324  [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc         C:\Windows\System32\wlansvc.dll
08:29:27.0324 149324  WlanSvc - ok
08:29:27.0376 149324  [ 08EFA13A2234C8C3B8A99E4B88BE7E9B ] wlidsvc         C:\Windows\system32\wlidsvc.dll
08:29:27.0386 149324  wlidsvc - ok
08:29:27.0399 149324  [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi         C:\Windows\System32\drivers\wmiacpi.sys
08:29:27.0399 149324  WmiAcpi - ok
08:29:27.0413 149324  [ D113499052C5E541906B727779F0F959 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
08:29:27.0414 149324  wmiApSrv - ok
08:29:27.0444 149324  WMPNetworkSvc - ok
08:29:27.0459 149324  [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr         C:\Windows\system32\DRIVERS\wpcfltr.sys
08:29:27.0460 149324  wpcfltr - ok
08:29:27.0475 149324  [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
08:29:27.0477 149324  WPCSvc - ok
08:29:27.0496 149324  [ 94AA5150E35B3ABB7191FE641E3C2473 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
08:29:27.0499 149324  WPDBusEnum - ok
08:29:27.0514 149324  [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr       C:\Windows\system32\drivers\WpdUpFltr.sys
08:29:27.0515 149324  WpdUpFltr - ok
08:29:27.0541 149324  [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
08:29:27.0542 149324  ws2ifsl - ok
08:29:27.0561 149324  [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc          C:\Windows\System32\wscsvc.dll
08:29:27.0564 149324  wscsvc - ok
08:29:27.0566 149324  WSearch - ok
08:29:27.0613 149324  [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService       C:\Windows\System32\WSService.dll
08:29:27.0624 149324  WSService - ok
08:29:27.0709 149324  [ F2CF90BBFB637AA2DC3CAAF64661EA43 ] wuauserv        C:\Windows\system32\wuaueng.dll
08:29:27.0727 149324  wuauserv - ok
08:29:27.0745 149324  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
08:29:27.0746 149324  WudfPf - ok
08:29:27.0766 149324  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\Windows\System32\drivers\WUDFRd.sys
08:29:27.0767 149324  WUDFRd - ok
08:29:27.0771 149324  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP    C:\Windows\system32\DRIVERS\WUDFRd.sys
08:29:27.0773 149324  WUDFSensorLP - ok
08:29:27.0790 149324  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
08:29:27.0793 149324  wudfsvc - ok
08:29:27.0808 149324  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs       C:\Windows\system32\DRIVERS\WUDFRd.sys
08:29:27.0809 149324  WUDFWpdFs - ok
08:29:27.0836 149324  [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc         C:\Windows\System32\wwansvc.dll
08:29:27.0842 149324  WwanSvc - ok
08:29:27.0853 149324  ================ Scan global ===============================
08:29:27.0890 149324  [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
08:29:27.0913 149324  [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
08:29:27.0940 149324  [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
08:29:27.0970 149324  [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
08:29:27.0976 149324  [Global] - ok
08:29:27.0977 149324  ================ Scan MBR ==================================
08:29:27.0989 149324  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
08:29:28.0194 149324  \Device\Harddisk0\DR0 - ok
08:29:28.0194 149324  ================ Scan VBR ==================================
08:29:28.0197 149324  [ 1E0FF299EE0BCA322122C5A09776B20B ] \Device\Harddisk0\DR0\Partition1
08:29:28.0199 149324  \Device\Harddisk0\DR0\Partition1 - ok
08:29:28.0209 149324  [ BED3C0CD63C7ED88CB6B04B4440FF419 ] \Device\Harddisk0\DR0\Partition2
08:29:28.0211 149324  \Device\Harddisk0\DR0\Partition2 - ok
08:29:28.0212 149324  ============================================================
08:29:28.0212 149324  Scan finished
08:29:28.0212 149324  ============================================================
08:29:28.0222 149316  Detected object count: 0
08:29:28.0222 149316  Actual detected object count: 0
08:29:44.0274 148820  Deinitialize success
 
Novo Log HijackThis:
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:32:49, on 03/01/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16453)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe
C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
C:\Users\Matheus\Downloads\JOGOS\OT\Styller Yourots {Editado 2.0}(Sem dlls )(8.60)\Styller Yourots.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
D:\Arquivos de programas\Internet Download Manager\IDMan.exe
D:\Arquivos de programas\Internet Download Manager\IEMonitor.exe
C:\Users\Matheus\Desktop\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hidemyass.com/vpn/r6793/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\KWIEBar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKCU\..\Run: [Dashlane] C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Dashlane.exe
O4 - HKCU\..\Run: [Memory Cleaner] C:\Users\Matheus\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe boot
O4 - HKCU\..\Run: [iDMan] D:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot
O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe
O4 - Startup: setup_9.0.0.722_02.01.2013_22-27.lnk = Desktop\Virus Removal Tool1\setup_9.0.0.722_02.01.2013_22-27\startup.exe
O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Fazer o download usando o IDM - D:\Arquivos de programas\Internet Download Manager\IEExt.htm
O9 - Extra button: Dashlane Button - {40354A83-504E-4611-ACAE-3D137F6F595E} - C:\Users\Matheus\AppData\Roaming\Dashlane\bin\Dashlanei.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 antivírus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @oem8.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
 
--
End of file - 7838 bytes

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

O PC está limpo. Por aqui, nada mais a fazer. (Y)



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites
    • 3 Mensagens
    • 182 Visualizações
    • 2 Mensagens
    • 299 Visualizações
    • 5 Mensagens
    • 141 Visualizações
    • 1 Mensagens
    • 105 Visualizações
    • 3 Mensagens
    • 184 Visualizações