Ga naar inhoud

Opschonen na verwijdering Trojan FakeSysdef


Aanbevolen berichten

Dag, met behulp van jullie tips over het verwijderen van de Trojan Horse FakeSysdef heb ik mijn PC weer aan de praat. Helemaal geweldig!

Ik blijf echter problemen ondervinden met printen, met het vinden van (nog steeds als verborgen geregistreerde) bestanden en toegang tot netwerk / DropBox en het draaien van sommige programma's.

Weet iemand welke instellingen ik moet herstellen nadat FakeSysdef verwijderd is? Ik heb Malwarebytes verschillende keren gerund, van TSassist (dat het TH vermoedelijk installeerde) ben ik af.

Hoor graag!

Link naar reactie
Delen op andere sites

Dag John,

Welkom op PCH!

Ik zie dat dit jouw eerste bericht is op het forum. Heeft iemand jou in privé bericht verder geholpen??

Mbam is een goede anti malware tool, maar niet altijd sterk genoeg voor de ergere virussen volledig te verwijderen.

Daarvoor bestaan meer gespecialiseerde tools.

Voer toch nog is een Hijacthis scan uit als je wilt:

1. Download HijackThis. (klik er op)

Klik op HijackThis.msi en de download start automatisch na 5 seconden.

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere pc en het bestand met een usb stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable (HijackThis.exe) downloaden.

Sla deze op in een nieuwe map op de C schijf (bvb C:\hijackthis) en start hijackthis dan vanaf deze map.

De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)


3. Na het plaatsen van je logje wordt dit door een expert (Kape of Kweezie Wabbit) nagekeken en begeleidt hij jou verder door het ganse proces.

Tip!

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.

Link naar reactie
Delen op andere sites

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 18:43:44, on 5-5-2012

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\HPLamp.exe

C:\Windows\System32\hkcmd.exe

C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe

C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = World's Largest Professional Network | LinkedIn

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll

O2 - BHO: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: RewardsArcadeSuite - {B6EF6C45-5E8D-4c3b-B580-A5073261A381} - C:\Program Files\RewardsArcadeSuite\RewardsArcadeSuite.dll

O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\BROWSE~1.DLL

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Lamp] "C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Edison] "C:\Program Files\Verdiem\PowerManager\PowerManager.exe" /autolaunched

O4 - HKLM\..\Run: [DLSService] "C:\Program Files\DYMO\DYMO Label Software\DLSService.exe"

O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE

O4 - HKLM\..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe

O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Animated Wallpaper] C:\Program Files\Animated Wallpaper Maker\Wallpaper Manager.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [EPSON Kleurenprinter op Server2 (1 omgeleid)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /FU "C:\Windows\TEMP\E_SE7CD.tmp" /EF "HKCU" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [EPSON Kleurenprinter op Server2 (1 omgeleid)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /FU "C:\Windows\TEMP\E_SE7CD.tmp" /EF "HKCU" (User 'Default user')

O4 - Startup: Dropbox.lnk = John\AppData\Roaming\Dropbox\bin\Dropbox.exe

O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: MSN Music: Home

O15 - Trusted Zone: http://*.mcafee.com (HKLM)

O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)

O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)

O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)

O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)

O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/68.16/uploader2.cab

O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Athtek\Athtek Skype Recorder\accsky.dll

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - AppInit_DLLs: C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll

O23 - Service: ArcSoft Exchange Service (ADExchange) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

O23 - Service: DYMO PnP Service (DymoPnpService) - Sanford, L.P. - C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe

O23 - Service: HP Power Manager Service (edsvc) - Verdiem - C:\Program Files\Verdiem\PowerManager\edsvc.exe

O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe

O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe

O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

O23 - Service: KPN Back-up Online SC - KPN - C:\Program Files\KPN Back-up Online\BackupSC.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe

O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--

End of file - 13228 bytes

Link naar reactie
Delen op andere sites

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O2 - BHO: RewardsArcadeSuite - {B6EF6C45-5E8D-4c3b-B580-A5073261A381} - C:\Program Files\RewardsArcadeSuite\RewardsArcadeSuite.dll

O2 - BHO: DataMngr - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\BROWSE~1.DLL

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

O3 - Toolbar: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE

O4 - HKCU\..\Run: [Animated Wallpaper] C:\Program Files\Animated Wallpaper Maker\Wallpaper Manager.exe

O20 - AppInit_DLLs: C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll

Klik op 'Fix checked' om de items te verwijderen.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.

Download MBAM (Malwarebytes Anti-Malware)

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.

MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.

Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.

Download TDSSKiller en plaats het op je bureaublad.

Pak de bestanden in tdsskiller.zip uit.

Open de map tdsskiller en dubbelklik op TDSSKiller.exe om de tool te starten.

Windows 7 en Windows Vista gebruikers:

Rechtsklik op TDSSKiller.exe -> Uitvoeren als Administrator om de tool te starten.

Als TDSSKiller bericht geeft van een beschikbare update, dan voer je deze eerst uit.

Klik op de knop "Start Scan" en volg de instructies.

Wanneer de scan klaar is klik je op de knop "Report".

Er opent een kladblokbestand. Post de inhoud van dit bestand.

Herstart de pc als TDSSKiller die optie geeft. (Reboot now)

Wanneer er een herstart nodig was, vind je de logfile in C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt

En hang ook dit logje, samen met de twxee anderen, in een volgend bericht.

Link naar reactie
Delen op andere sites

Geplaatst: (aangepast)

Beste Kape, dank voor je reactie. Uitgevoerd, zie onderstaande logs:

======

MBAM log:

Malwarebytes Anti-Malware (-evaluatieversie-) 1.61.0.1400

www.malwarebytes.org

Databaseversie: v2012.05.05.07

Windows 7 Service Pack 1 x86 NTFS

Internet Explorer 9.0.8112.16421

John :: VS43-HP [administrator]

Realtime bescherming: Ingeschakeld

5-5-2012 19:58:48

mbam-log-2012-05-05 (19-58-48).txt

Scantype: Snelle scan

Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scanopties: P2P

Objecten gescand: 262386

Verstreken tijd: 10 minuut/minuten,

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

(einde)

===============================================================================

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:30:25, on 5-5-2012

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\HPLamp.exe

C:\Windows\System32\hkcmd.exe

C:\Program Files\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe

C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe

C:\Windows\WindowsMobile\wmdc.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Woopra\Woopra.exe

C:\Windows\system32\notepad.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HP | MSN

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = World's Largest Professional Network | LinkedIn

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll

O2 - BHO: Wincore Mediabar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll

O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Lamp] "C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Edison] "C:\Program Files\Verdiem\PowerManager\PowerManager.exe" /autolaunched

O4 - HKLM\..\Run: [DLSService] "C:\Program Files\DYMO\DYMO Label Software\DLSService.exe"

O4 - HKLM\..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe

O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [EPSON Kleurenprinter op Server2 (1 omgeleid)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /FU "C:\Windows\TEMP\E_SE4C4.tmp" /EF "HKCU" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [EPSON Kleurenprinter op Server2 (1 omgeleid)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /FU "C:\Windows\TEMP\E_SE4C4.tmp" /EF "HKCU" (User 'Default user')

O4 - Startup: Dropbox.lnk = John\AppData\Roaming\Dropbox\bin\Dropbox.exe

O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

O9 - Extra button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 9\Mm8InternetExplorer.dll

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: MSN Music: Home

O15 - Trusted Zone: http://*.mcafee.com (HKLM)

O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)

O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)

O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)

O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)

O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)

O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/68.16/uploader2.cab

O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Athtek\Athtek Skype Recorder\accsky.dll

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O23 - Service: ArcSoft Exchange Service (ADExchange) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

O23 - Service: DYMO PnP Service (DymoPnpService) - Sanford, L.P. - C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe

O23 - Service: HP Power Manager Service (edsvc) - Verdiem - C:\Program Files\Verdiem\PowerManager\edsvc.exe

O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe

O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe

O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

O23 - Service: KPN Back-up Online SC - KPN - C:\Program Files\KPN Back-up Online\BackupSC.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--

End of file - 12195 bytes

======================================================================

20:32:03.0487 5552 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18

20:32:03.0862 5552 ============================================================

20:32:03.0862 5552 Current date / time: 2012/05/05 20:32:03.0862

20:32:03.0862 5552 SystemInfo:

20:32:03.0862 5552

20:32:03.0862 5552 OS Version: 6.1.7601 ServicePack: 1.0

20:32:03.0862 5552 Product type: Workstation

20:32:03.0862 5552 ComputerName: VS43-HP

20:32:03.0862 5552 UserName: John

20:32:03.0862 5552 Windows directory: C:\Windows

20:32:03.0862 5552 System windows directory: C:\Windows

20:32:03.0862 5552 Processor architecture: Intel x86

20:32:03.0862 5552 Number of processors: 4

20:32:03.0862 5552 Page size: 0x1000

20:32:03.0862 5552 Boot type: Normal boot

20:32:03.0862 5552 ============================================================

20:32:04.0314 5552 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050

20:32:04.0314 5552 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050

20:32:04.0345 5552 ============================================================

20:32:04.0345 5552 \Device\Harddisk0\DR0:

20:32:04.0345 5552 MBR partitions:

20:32:04.0345 5552 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3FF800

20:32:04.0345 5552 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x400000, BlocksNum 0x39056000

20:32:04.0345 5552 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x39456000, BlocksNum 0xF2B000

20:32:04.0345 5552 \Device\Harddisk1\DR1:

20:32:04.0345 5552 MBR partitions:

20:32:04.0345 5552 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384800

20:32:04.0345 5552 ============================================================

20:32:04.0376 5552 C: <-> \Device\Harddisk0\DR0\Partition1

20:32:04.0408 5552 D: <-> \Device\Harddisk0\DR0\Partition2

20:32:04.0423 5552 K: <-> \Device\Harddisk1\DR1\Partition0

20:32:04.0423 5552 ============================================================

20:32:04.0423 5552 Initialize success

20:32:04.0423 5552 ============================================================

20:32:08.0698 5172 ============================================================

20:32:08.0698 5172 Scan started

20:32:08.0698 5172 Mode: Manual;

20:32:08.0698 5172 ============================================================

20:32:09.0478 5172 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys

20:32:09.0478 5172 1394ohci - ok

20:32:09.0556 5172 61883 (beb5e6a8c17c3c7485563281e0f9e77e) C:\Windows\system32\DRIVERS\61883.sys

20:32:09.0556 5172 61883 - ok

20:32:09.0618 5172 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys

20:32:09.0634 5172 ACPI - ok

20:32:09.0680 5172 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys

20:32:09.0680 5172 AcpiPmi - ok

20:32:09.0790 5172 ADExchange (99721e1dac2c89e8202f70b773fb14f4) C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe

20:32:09.0790 5172 ADExchange - ok

20:32:09.0946 5172 AdobeActiveFileMonitor6.0 (e8fe4fce23d2809bd88bcc1d0f8408ce) C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

20:32:09.0946 5172 AdobeActiveFileMonitor6.0 - ok

20:32:10.0039 5172 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

20:32:10.0055 5172 AdobeFlashPlayerUpdateSvc - ok

20:32:10.0117 5172 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys

20:32:10.0133 5172 adp94xx - ok

20:32:10.0164 5172 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys

20:32:10.0164 5172 adpahci - ok

20:32:10.0195 5172 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys

20:32:10.0195 5172 adpu320 - ok

20:32:10.0226 5172 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll

20:32:10.0226 5172 AeLookupSvc - ok

20:32:10.0320 5172 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys

20:32:10.0320 5172 AFD - ok

20:32:10.0382 5172 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys

20:32:10.0382 5172 agp440 - ok

20:32:10.0429 5172 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys

20:32:10.0429 5172 aic78xx - ok

20:32:10.0460 5172 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe

20:32:10.0460 5172 ALG - ok

20:32:10.0476 5172 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys

20:32:10.0476 5172 aliide - ok

20:32:10.0523 5172 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys

20:32:10.0523 5172 amdagp - ok

20:32:10.0523 5172 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys

20:32:10.0523 5172 amdide - ok

20:32:10.0554 5172 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys

20:32:10.0570 5172 AmdK8 - ok

20:32:10.0570 5172 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys

20:32:10.0570 5172 AmdPPM - ok

20:32:10.0632 5172 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys

20:32:10.0632 5172 amdsata - ok

20:32:10.0648 5172 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys

20:32:10.0648 5172 amdsbs - ok

20:32:10.0663 5172 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys

20:32:10.0663 5172 amdxata - ok

20:32:10.0757 5172 APC UPS Service (29deb59de57ea97553b1566f04b39d11) C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

20:32:10.0757 5172 APC UPS Service - ok

20:32:10.0804 5172 Apowersoft_AudioDevice (85ece26f326c2d07ba77a60343468272) C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys

20:32:10.0804 5172 Apowersoft_AudioDevice - ok

20:32:10.0850 5172 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys

20:32:10.0866 5172 AppID - ok

20:32:10.0897 5172 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll

20:32:10.0897 5172 AppIDSvc - ok

20:32:11.0178 5172 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll

20:32:11.0178 5172 Appinfo - ok

20:32:11.0209 5172 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll

20:32:11.0209 5172 AppMgmt - ok

20:32:11.0240 5172 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys

20:32:11.0240 5172 arc - ok

20:32:11.0256 5172 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys

20:32:11.0256 5172 arcsas - ok

20:32:11.0287 5172 ASPI32 - ok

20:32:11.0303 5172 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys

20:32:11.0303 5172 AsyncMac - ok

20:32:11.0365 5172 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys

20:32:11.0365 5172 atapi - ok

20:32:11.0474 5172 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll

20:32:11.0474 5172 AudioEndpointBuilder - ok

20:32:11.0490 5172 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll

20:32:11.0490 5172 Audiosrv - ok

20:32:11.0584 5172 Avc (c44bdd77e06053cf5afe046f3a47c16b) C:\Windows\system32\DRIVERS\avc.sys

20:32:11.0584 5172 Avc - ok

20:32:11.0646 5172 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll

20:32:11.0646 5172 AxInstSV - ok

20:32:11.0708 5172 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys

20:32:11.0708 5172 b06bdrv - ok

20:32:11.0755 5172 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys

20:32:11.0755 5172 b57nd60x - ok

20:32:11.0864 5172 BBSvc (825f81a6f7dd073509db101f0ba6dc59) C:\Program Files\Microsoft\BingBar\BBSvc.EXE

20:32:11.0864 5172 BBSvc - ok

20:32:11.0974 5172 BcmSqlStartupSvc (6163664c7e9cd110af70180c126c3fdc) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

20:32:11.0974 5172 BcmSqlStartupSvc - ok

20:32:12.0005 5172 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll

20:32:12.0005 5172 BDESVC - ok

20:32:12.0036 5172 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys

20:32:12.0036 5172 Beep - ok

20:32:12.0098 5172 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll

20:32:12.0114 5172 BFE - ok

20:32:12.0192 5172 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\System32\qmgr.dll

20:32:12.0239 5172 BITS - ok

20:32:12.0270 5172 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys

20:32:12.0270 5172 blbdrive - ok

20:32:12.0301 5172 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys

20:32:12.0301 5172 bowser - ok

20:32:12.0317 5172 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys

20:32:12.0317 5172 BrFiltLo - ok

20:32:12.0332 5172 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys

20:32:12.0332 5172 BrFiltUp - ok

20:32:12.0379 5172 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll

20:32:12.0395 5172 Browser - ok

20:32:12.0426 5172 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys

20:32:12.0426 5172 Brserid - ok

20:32:12.0442 5172 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys

20:32:12.0442 5172 BrSerWdm - ok

20:32:12.0457 5172 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys

20:32:12.0457 5172 BrUsbMdm - ok

20:32:12.0457 5172 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys

20:32:12.0457 5172 BrUsbSer - ok

20:32:12.0473 5172 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys

20:32:12.0473 5172 BTHMODEM - ok

20:32:12.0504 5172 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll

20:32:12.0504 5172 bthserv - ok

20:32:12.0613 5172 CamDrL (0f5ca31bb3fdb5c1e63c170cfbecc93b) C:\Windows\system32\DRIVERS\Camdrl.sys

20:32:12.0629 5172 CamDrL - ok

20:32:12.0660 5172 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys

20:32:12.0660 5172 cdfs - ok

20:32:12.0722 5172 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys

20:32:12.0738 5172 cdrom - ok

20:32:12.0800 5172 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll

20:32:12.0800 5172 CertPropSvc - ok

20:32:12.0816 5172 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys

20:32:12.0816 5172 circlass - ok

20:32:12.0832 5172 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys

20:32:12.0847 5172 CLFS - ok

20:32:12.0894 5172 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

20:32:12.0894 5172 clr_optimization_v2.0.50727_32 - ok

20:32:13.0003 5172 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

20:32:13.0019 5172 clr_optimization_v4.0.30319_32 - ok

20:32:13.0019 5172 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys

20:32:13.0019 5172 CmBatt - ok

20:32:13.0066 5172 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys

20:32:13.0066 5172 cmdide - ok

20:32:13.0144 5172 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys

20:32:13.0144 5172 CNG - ok

20:32:13.0190 5172 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys

20:32:13.0190 5172 Compbatt - ok

20:32:13.0253 5172 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys

20:32:13.0253 5172 CompositeBus - ok

20:32:13.0268 5172 COMSysApp - ok

20:32:13.0284 5172 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys

20:32:13.0284 5172 crcdisk - ok

20:32:13.0362 5172 CryptSvc (a585bebf7d054bd9618eda0922d5484a) C:\Windows\system32\cryptsvc.dll

20:32:13.0378 5172 CryptSvc - ok

20:32:13.0440 5172 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys

20:32:13.0456 5172 CSC - ok

20:32:13.0518 5172 CscService (15f93b37f6801943360d9eb42485d5d3) C:\Windows\System32\cscsvc.dll

20:32:13.0549 5172 CscService - ok

20:32:13.0596 5172 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll

20:32:13.0596 5172 DcomLaunch - ok

20:32:13.0627 5172 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll

20:32:13.0627 5172 defragsvc - ok

20:32:13.0705 5172 dfmirage (699ef0fd9ae72b7f5ad756e382c73e0e) C:\Windows\system32\DRIVERS\dfmirage.sys

20:32:13.0705 5172 dfmirage - ok

20:32:13.0752 5172 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys

20:32:13.0752 5172 DfsC - ok

20:32:13.0830 5172 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll

20:32:13.0830 5172 Dhcp - ok

20:32:13.0861 5172 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys

20:32:13.0877 5172 discache - ok

20:32:13.0908 5172 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys

20:32:13.0908 5172 Disk - ok

20:32:13.0955 5172 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll

20:32:13.0955 5172 Dnscache - ok

20:32:14.0017 5172 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll

20:32:14.0017 5172 dot3svc - ok

20:32:14.0080 5172 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll

20:32:14.0080 5172 DPS - ok

20:32:14.0095 5172 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys

20:32:14.0095 5172 drmkaud - ok

20:32:14.0173 5172 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys

20:32:14.0204 5172 DXGKrnl - ok

20:32:14.0345 5172 DymoPnpService (2f51e9f3a587391704bbe9f418bb289b) C:\Program Files\DYMO\DYMO Label Software\DymoPnpService.exe

20:32:14.0360 5172 DymoPnpService - ok

20:32:14.0376 5172 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll

20:32:14.0392 5172 EapHost - ok

20:32:14.0563 5172 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys

20:32:14.0610 5172 ebdrv - ok

20:32:14.0735 5172 edsvc (33fa356f10fd6ea1a418d2cb7c08b10f) C:\Program Files\Verdiem\PowerManager\edsvc.exe

20:32:14.0735 5172 edsvc - ok

20:32:14.0844 5172 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe

20:32:14.0844 5172 EFS - ok

20:32:14.0938 5172 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe

20:32:14.0984 5172 ehRecvr - ok

20:32:15.0016 5172 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe

20:32:15.0016 5172 ehSched - ok

20:32:15.0078 5172 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys

20:32:15.0109 5172 elxstor - ok

20:32:15.0250 5172 EPSON_PM_RPCV4_01 (8fe6ab59cab8f2c038fea9522a5eeba7) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE

20:32:15.0250 5172 EPSON_PM_RPCV4_01 - ok

20:32:15.0312 5172 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys

20:32:15.0312 5172 ErrDev - ok

20:32:15.0359 5172 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll

20:32:15.0359 5172 EventSystem - ok

20:32:15.0406 5172 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys

20:32:15.0406 5172 exfat - ok

20:32:15.0421 5172 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys

20:32:15.0437 5172 fastfat - ok

20:32:15.0515 5172 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe

20:32:15.0562 5172 Fax - ok

20:32:15.0577 5172 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys

20:32:15.0577 5172 fdc - ok

20:32:15.0624 5172 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll

20:32:15.0624 5172 fdPHost - ok

20:32:15.0640 5172 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll

20:32:15.0655 5172 FDResPub - ok

20:32:15.0655 5172 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys

20:32:15.0655 5172 FileInfo - ok

20:32:15.0671 5172 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys

20:32:15.0671 5172 Filetrace - ok

20:32:15.0780 5172 FLEXnet Licensing Service (227846995afeefa70d328bf5334a86a5) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

20:32:15.0827 5172 FLEXnet Licensing Service - ok

20:32:15.0858 5172 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys

20:32:15.0858 5172 flpydisk - ok

20:32:15.0905 5172 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys

20:32:15.0905 5172 FltMgr - ok

20:32:15.0998 5172 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll

20:32:16.0045 5172 FontCache - ok

20:32:16.0123 5172 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

20:32:16.0139 5172 FontCache3.0.0.0 - ok

20:32:16.0139 5172 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys

20:32:16.0139 5172 FsDepends - ok

20:32:16.0186 5172 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys

20:32:16.0186 5172 fssfltr - ok

20:32:16.0310 5172 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files\Windows Live\Family Safety\fsssvc.exe

20:32:16.0342 5172 fsssvc - ok

20:32:16.0513 5172 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys

20:32:16.0513 5172 Fs_Rec - ok

20:32:16.0576 5172 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys

20:32:16.0576 5172 fvevol - ok

20:32:16.0591 5172 fyqrgreo - ok

20:32:16.0622 5172 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys

20:32:16.0622 5172 gagp30kx - ok

20:32:16.0700 5172 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll

20:32:16.0732 5172 gpsvc - ok

20:32:16.0888 5172 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe

20:32:16.0888 5172 gupdate - ok

20:32:16.0903 5172 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe

20:32:16.0903 5172 gupdatem - ok

20:32:16.0981 5172 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

20:32:16.0981 5172 gusvc - ok

20:32:16.0997 5172 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys

20:32:16.0997 5172 hcw85cir - ok

20:32:17.0059 5172 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys

20:32:17.0075 5172 HdAudAddService - ok

20:32:17.0106 5172 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys

20:32:17.0106 5172 HDAudBus - ok

20:32:17.0137 5172 HECI (a88485dc6a7136c10d9a6c7e38fdfe3c) C:\Windows\system32\DRIVERS\HECI.sys

20:32:17.0137 5172 HECI - ok

20:32:17.0153 5172 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys

20:32:17.0153 5172 HidBatt - ok

20:32:17.0168 5172 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys

20:32:17.0168 5172 HidBth - ok

20:32:17.0184 5172 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys

20:32:17.0184 5172 HidIr - ok

20:32:17.0231 5172 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll

20:32:17.0231 5172 hidserv - ok

20:32:17.0246 5172 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys

20:32:17.0246 5172 HidUsb - ok

20:32:17.0262 5172 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll

20:32:17.0278 5172 hkmsvc - ok

20:32:17.0309 5172 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll

20:32:17.0309 5172 HomeGroupListener - ok

20:32:17.0371 5172 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll

20:32:17.0371 5172 HomeGroupProvider - ok

20:32:17.0480 5172 HP Support Assistant Service (170233b8d743efe35f462a5d516b93e3) C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe

20:32:17.0480 5172 HP Support Assistant Service - ok

20:32:17.0558 5172 HPDrvMntSvc.exe (bcc4a8b2e2e902f52e7f2e7d8e125765) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe

20:32:17.0558 5172 HPDrvMntSvc.exe - ok

20:32:17.0652 5172 hpqwmiex (ec9739a46f1f83c6e52a7a4697f44a65) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe

20:32:17.0668 5172 hpqwmiex - ok

20:32:17.0777 5172 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys

20:32:17.0777 5172 HpSAMD - ok

20:32:17.0824 5172 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys

20:32:17.0824 5172 HTTP - ok

20:32:17.0855 5172 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys

20:32:17.0855 5172 hwpolicy - ok

20:32:17.0870 5172 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys

20:32:17.0870 5172 i8042prt - ok

20:32:17.0933 5172 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\drivers\iastor.sys

20:32:17.0933 5172 iaStor - ok

20:32:17.0995 5172 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys

20:32:18.0042 5172 iaStorV - ok

20:32:18.0151 5172 IDriverT (daf66902f08796f9c694901660e5a64a) C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

20:32:18.0151 5172 IDriverT - ok

20:32:18.0245 5172 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

20:32:18.0292 5172 idsvc - ok

20:32:18.0666 5172 igfx (00fdedf8c1d7b85a6f6a7832527a54db) C:\Windows\system32\DRIVERS\igdkmd32.sys

20:32:18.0806 5172 igfx - ok

20:32:18.0884 5172 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys

20:32:18.0884 5172 iirsp - ok

20:32:18.0978 5172 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll

20:32:19.0009 5172 IKEEXT - ok

20:32:19.0040 5172 Impcd (a8ed88b2aae108b938816ddb5bb39b54) C:\Windows\system32\DRIVERS\Impcd.sys

20:32:19.0040 5172 Impcd - ok

20:32:19.0228 5172 IntcAzAudAddService (c877ecc52d2279818cfb0a7dd3dcb906) C:\Windows\system32\drivers\RTKVHDA.sys

20:32:19.0306 5172 IntcAzAudAddService - ok

20:32:19.0399 5172 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys

20:32:19.0399 5172 intelide - ok

20:32:19.0415 5172 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys

20:32:19.0415 5172 intelppm - ok

20:32:19.0446 5172 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll

20:32:19.0446 5172 IPBusEnum - ok

20:32:19.0462 5172 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys

20:32:19.0462 5172 IpFilterDriver - ok

20:32:19.0540 5172 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll

20:32:19.0540 5172 iphlpsvc - ok

20:32:19.0633 5172 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys

20:32:19.0664 5172 IPMIDRV - ok

20:32:19.0680 5172 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys

20:32:19.0680 5172 IPNAT - ok

20:32:19.0696 5172 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys

20:32:19.0696 5172 IRENUM - ok

20:32:19.0742 5172 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys

20:32:19.0742 5172 isapnp - ok

20:32:19.0805 5172 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys

20:32:19.0805 5172 iScsiPrt - ok

20:32:19.0867 5172 IviRegMgr (213822072085b5bbad9af30ab577d817) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

20:32:19.0867 5172 IviRegMgr - ok

20:32:19.0898 5172 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys

20:32:19.0898 5172 kbdclass - ok

20:32:19.0961 5172 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys

20:32:19.0961 5172 kbdhid - ok

20:32:20.0008 5172 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe

20:32:20.0008 5172 KeyIso - ok

20:32:20.0132 5172 KPN Back-up Online SC (7822b200747ff2e94660c2ad8afe5392) C:\Program Files\KPN Back-up Online\BackupSC.exe

20:32:20.0148 5172 KPN Back-up Online SC - ok

20:32:20.0164 5172 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys

20:32:20.0164 5172 KSecDD - ok

20:32:20.0179 5172 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys

20:32:20.0179 5172 KSecPkg - ok

20:32:20.0210 5172 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll

20:32:20.0226 5172 KtmRm - ok

20:32:20.0273 5172 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\system32\srvsvc.dll

20:32:20.0273 5172 LanmanServer - ok

20:32:20.0320 5172 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll

20:32:20.0335 5172 LanmanWorkstation - ok

20:32:20.0366 5172 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys

20:32:20.0366 5172 lltdio - ok

20:32:20.0398 5172 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll

20:32:20.0413 5172 lltdsvc - ok

20:32:20.0413 5172 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll

20:32:20.0413 5172 lmhosts - ok

20:32:20.0460 5172 LPDSVC (9a84f41e421287a712c90e5384400e4f) C:\Windows\system32\lpdsvc.dll

20:32:20.0460 5172 LPDSVC - ok

20:32:20.0491 5172 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys

20:32:20.0491 5172 LSI_FC - ok

20:32:20.0507 5172 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys

20:32:20.0507 5172 LSI_SAS - ok

20:32:20.0522 5172 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys

20:32:20.0522 5172 LSI_SAS2 - ok

20:32:20.0554 5172 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys

20:32:20.0554 5172 LSI_SCSI - ok

20:32:20.0554 5172 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys

20:32:20.0554 5172 luafv - ok

20:32:20.0616 5172 LVUSBSta (64bc29c3a0388bfc580bb8b1346f7659) C:\Windows\system32\drivers\LVUSBSta.sys

20:32:20.0616 5172 LVUSBSta - ok

20:32:20.0663 5172 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys

20:32:20.0678 5172 MBAMProtector - ok

20:32:20.0803 5172 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

20:32:20.0866 5172 MBAMService - ok

20:32:20.0975 5172 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe

20:32:20.0975 5172 McComponentHostService - ok

20:32:21.0037 5172 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll

20:32:21.0053 5172 Mcx2Svc - ok

20:32:21.0068 5172 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys

20:32:21.0068 5172 megasas - ok

20:32:21.0100 5172 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys

20:32:21.0100 5172 MegaSR - ok

20:32:21.0146 5172 MfeAVFK (64b96de8c492bd435372d9130a535f1d) C:\Windows\system32\drivers\MfeAVFK.sys

20:32:21.0146 5172 MfeAVFK - ok

20:32:21.0146 5172 MfeBOPK (078e87a89d36cc3516f19d5fb518bddc) C:\Windows\system32\drivers\MfeBOPK.sys

20:32:21.0146 5172 MfeBOPK - ok

20:32:21.0178 5172 mfehidk (168c565101fd5b9db694efdec91fafa9) C:\Windows\system32\drivers\mfehidk.sys

20:32:21.0178 5172 mfehidk - ok

20:32:21.0178 5172 MfeRKDK (e0842f67dc9bc4d21d1e319610ebe9e5) C:\Windows\system32\drivers\MfeRKDK.sys

20:32:21.0178 5172 MfeRKDK - ok

20:32:21.0193 5172 mfetdik (43a7acbbd70ecd62f0b63486c72089a3) C:\Windows\system32\drivers\mfetdik.sys

20:32:21.0209 5172 mfetdik - ok

20:32:21.0224 5172 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll

20:32:21.0224 5172 MMCSS - ok

20:32:21.0240 5172 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys

20:32:21.0240 5172 Modem - ok

20:32:21.0302 5172 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys

20:32:21.0302 5172 monitor - ok

20:32:21.0349 5172 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys

20:32:21.0349 5172 mouclass - ok

20:32:21.0349 5172 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys

20:32:21.0349 5172 mouhid - ok

20:32:21.0396 5172 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys

20:32:21.0412 5172 mountmgr - ok

20:32:21.0505 5172 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

20:32:21.0505 5172 MozillaMaintenance - ok

20:32:21.0552 5172 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys

20:32:21.0552 5172 mpio - ok

20:32:21.0568 5172 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys

20:32:21.0568 5172 mpsdrv - ok

20:32:21.0646 5172 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll

20:32:21.0661 5172 MpsSvc - ok

20:32:21.0708 5172 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys

20:32:21.0708 5172 MRxDAV - ok

20:32:21.0770 5172 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys

20:32:21.0770 5172 mrxsmb - ok

20:32:21.0817 5172 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys

20:32:21.0817 5172 mrxsmb10 - ok

20:32:21.0833 5172 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys

20:32:21.0833 5172 mrxsmb20 - ok

20:32:21.0848 5172 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys

20:32:21.0848 5172 msahci - ok

20:32:21.0895 5172 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys

20:32:21.0895 5172 msdsm - ok

20:32:21.0926 5172 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe

20:32:21.0926 5172 MSDTC - ok

20:32:21.0989 5172 MSDV (114b67c324d64c8195fd3bf93b4df02a) C:\Windows\system32\DRIVERS\msdv.sys

20:32:21.0989 5172 MSDV - ok

20:32:22.0020 5172 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys

20:32:22.0020 5172 Msfs - ok

20:32:22.0020 5172 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys

20:32:22.0020 5172 mshidkmdf - ok

20:32:22.0036 5172 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys

20:32:22.0036 5172 msisadrv - ok

20:32:22.0067 5172 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll

20:32:22.0067 5172 MSiSCSI - ok

20:32:22.0067 5172 msiserver - ok

20:32:22.0098 5172 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys

20:32:22.0098 5172 MSKSSRV - ok

20:32:22.0098 5172 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys

20:32:22.0098 5172 MSPCLOCK - ok

20:32:22.0114 5172 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys

20:32:22.0114 5172 MSPQM - ok

20:32:22.0129 5172 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys

20:32:22.0129 5172 MsRPC - ok

20:32:22.0176 5172 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys

20:32:22.0176 5172 mssmbios - ok

20:32:22.0363 5172 MSSQL$MSSMLBIZ - ok

20:32:22.0504 5172 MSSQL$TRM - ok

20:32:22.0597 5172 MSSQLServerADHelper (1d89eb4e2a99cabd4e81225f4f4c4b25) C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe

20:32:22.0597 5172 MSSQLServerADHelper - ok

20:32:22.0613 5172 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys

20:32:22.0613 5172 MSTEE - ok

20:32:22.0613 5172 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys

20:32:22.0628 5172 MTConfig - ok

20:32:22.0644 5172 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys

20:32:22.0644 5172 Mup - ok

20:32:22.0706 5172 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll

20:32:22.0706 5172 napagent - ok

20:32:22.0753 5172 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys

20:32:22.0753 5172 NativeWifiP - ok

20:32:22.0800 5172 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys

20:32:22.0800 5172 NDIS - ok

20:32:22.0831 5172 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys

20:32:22.0831 5172 NdisCap - ok

20:32:22.0847 5172 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys

20:32:22.0847 5172 NdisTapi - ok

20:32:22.0894 5172 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys

20:32:22.0894 5172 Ndisuio - ok

20:32:22.0972 5172 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys

20:32:22.0987 5172 NdisWan - ok

20:32:23.0050 5172 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys

20:32:23.0050 5172 NDProxy - ok

20:32:23.0065 5172 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys

20:32:23.0065 5172 NetBIOS - ok

20:32:23.0112 5172 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys

20:32:23.0112 5172 NetBT - ok

20:32:23.0174 5172 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe

20:32:23.0174 5172 Netlogon - ok

20:32:23.0221 5172 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll

20:32:23.0221 5172 Netman - ok

20:32:23.0268 5172 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll

20:32:23.0299 5172 netprofm - ok

20:32:23.0393 5172 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

20:32:23.0393 5172 NetTcpPortSharing - ok

20:32:23.0424 5172 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys

20:32:23.0424 5172 nfrd960 - ok

20:32:23.0486 5172 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll

20:32:23.0486 5172 NlaSvc - ok

20:32:23.0533 5172 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys

20:32:23.0533 5172 Npfs - ok

20:32:23.0580 5172 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll

20:32:23.0580 5172 nsi - ok

20:32:23.0596 5172 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys

20:32:23.0596 5172 nsiproxy - ok

20:32:23.0689 5172 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys

20:32:23.0705 5172 Ntfs - ok

20:32:23.0783 5172 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys

20:32:23.0783 5172 Null - ok

20:32:23.0845 5172 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys

20:32:23.0845 5172 nvraid - ok

20:32:23.0908 5172 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys

20:32:23.0908 5172 nvstor - ok

20:32:23.0923 5172 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys

20:32:23.0923 5172 nv_agp - ok

20:32:24.0032 5172 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE

20:32:24.0048 5172 odserv - ok

20:32:24.0095 5172 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys

20:32:24.0095 5172 ohci1394 - ok

20:32:24.0126 5172 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE

20:32:24.0142 5172 ose - ok

20:32:24.0157 5172 oxgqiwuu - ok

20:32:24.0204 5172 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll

20:32:24.0204 5172 p2pimsvc - ok

20:32:24.0251 5172 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll

20:32:24.0251 5172 p2psvc - ok

20:32:24.0282 5172 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys

20:32:24.0282 5172 Parport - ok

20:32:24.0329 5172 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys

20:32:24.0329 5172 partmgr - ok

20:32:24.0344 5172 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys

20:32:24.0360 5172 Parvdm - ok

20:32:24.0376 5172 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll

20:32:24.0391 5172 PcaSvc - ok

20:32:24.0438 5172 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys

20:32:24.0438 5172 pci - ok

20:32:24.0485 5172 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys

20:32:24.0485 5172 pciide - ok

20:32:24.0516 5172 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys

20:32:24.0516 5172 pcmcia - ok

20:32:24.0532 5172 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys

20:32:24.0532 5172 pcw - ok

20:32:24.0563 5172 pdfcDispatcher - ok

20:32:24.0610 5172 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys

20:32:24.0610 5172 PEAUTH - ok

20:32:24.0672 5172 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll

20:32:24.0688 5172 PeerDistSvc - ok

20:32:24.0812 5172 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll

20:32:24.0844 5172 pla - ok

20:32:25.0000 5172 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll

20:32:25.0000 5172 PlugPlay - ok

20:32:25.0031 5172 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll

20:32:25.0031 5172 PNRPAutoReg - ok

20:32:25.0062 5172 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll

20:32:25.0062 5172 PNRPsvc - ok

20:32:25.0124 5172 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll

20:32:25.0140 5172 PolicyAgent - ok

20:32:25.0202 5172 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll

20:32:25.0218 5172 Power - ok

20:32:25.0234 5172 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys

20:32:25.0249 5172 PptpMiniport - ok

20:32:25.0249 5172 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys

20:32:25.0265 5172 Processor - ok

20:32:25.0327 5172 ProfSvc (43ca4ccc22d52fb58e8988f0198851d0) C:\Windows\system32\profsvc.dll

20:32:25.0327 5172 ProfSvc - ok

20:32:25.0374 5172 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe

20:32:25.0374 5172 ProtectedStorage - ok

20:32:25.0405 5172 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys

20:32:25.0405 5172 Psched - ok

20:32:25.0468 5172 PSI_SVC_2 (a6a7ad767bf5141665f5c675f671b3e1) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

20:32:25.0468 5172 PSI_SVC_2 - ok

20:32:25.0530 5172 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys

20:32:25.0530 5172 PxHelp20 - ok

20:32:25.0608 5172 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys

20:32:25.0624 5172 ql2300 - ok

20:32:25.0733 5172 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys

20:32:25.0733 5172 ql40xx - ok

20:32:25.0764 5172 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll

20:32:25.0780 5172 QWAVE - ok

20:32:25.0795 5172 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys

20:32:25.0795 5172 QWAVEdrv - ok

20:32:25.0873 5172 RapiMgr (8f97d374ad1857e1eed85a79f29a1d3d) C:\Windows\WindowsMobile\rapimgr.dll

20:32:25.0873 5172 RapiMgr - ok

20:32:25.0889 5172 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys

20:32:25.0889 5172 RasAcd - ok

20:32:25.0920 5172 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys

20:32:25.0920 5172 RasAgileVpn - ok

20:32:25.0936 5172 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll

20:32:25.0936 5172 RasAuto - ok

20:32:25.0951 5172 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys

20:32:25.0967 5172 Rasl2tp - ok

20:32:26.0029 5172 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll

20:32:26.0029 5172 RasMan - ok

20:32:26.0060 5172 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys

20:32:26.0060 5172 RasPppoe - ok

20:32:26.0060 5172 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys

20:32:26.0060 5172 RasSstp - ok

20:32:26.0123 5172 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys

20:32:26.0123 5172 rdbss - ok

20:32:26.0138 5172 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys

20:32:26.0138 5172 rdpbus - ok

20:32:26.0185 5172 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys

20:32:26.0185 5172 RDPCDD - ok

20:32:26.0232 5172 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys

20:32:26.0232 5172 RDPDR - ok

20:32:26.0263 5172 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys

20:32:26.0263 5172 RDPENCDD - ok

20:32:26.0279 5172 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys

20:32:26.0279 5172 RDPREFMP - ok

20:32:26.0326 5172 RDPWD (244c83332f44589ae98fc347f11b2693) C:\Windows\system32\drivers\RDPWD.sys

20:32:26.0341 5172 RDPWD - ok

20:32:26.0388 5172 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys

20:32:26.0388 5172 rdyboost - ok

20:32:26.0419 5172 regi (001b4278407f4303efc902a2b16f2453) C:\Windows\system32\drivers\regi.sys

20:32:26.0419 5172 regi - ok

20:32:26.0435 5172 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll

20:32:26.0450 5172 RemoteAccess - ok

20:32:26.0482 5172 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll

20:32:26.0482 5172 RemoteRegistry - ok

20:32:26.0513 5172 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll

20:32:26.0513 5172 RpcEptMapper - ok

20:32:26.0528 5172 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe

20:32:26.0528 5172 RpcLocator - ok

20:32:26.0606 5172 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll

20:32:26.0606 5172 RpcSs - ok

20:32:26.0622 5172 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys

20:32:26.0638 5172 rspndr - ok

20:32:26.0669 5172 RTL8167 (aa9c3881a74a6d66a2ad869b03e8d3f5) C:\Windows\system32\DRIVERS\Rt86win7.sys

20:32:26.0684 5172 RTL8167 - ok

20:32:26.0700 5172 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys

20:32:26.0700 5172 s3cap - ok

20:32:26.0747 5172 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe

20:32:26.0747 5172 SamSs - ok

20:32:26.0809 5172 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys

20:32:26.0809 5172 sbp2port - ok

20:32:26.0840 5172 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll

20:32:26.0840 5172 SCardSvr - ok

20:32:26.0887 5172 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys

20:32:26.0887 5172 scfilter - ok

20:32:26.0965 5172 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll

20:32:26.0981 5172 Schedule - ok

20:32:27.0043 5172 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll

20:32:27.0043 5172 SCPolicySvc - ok

20:32:27.0090 5172 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll

20:32:27.0090 5172 SDRSVC - ok

20:32:27.0199 5172 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files\Microsoft\BingBar\SeaPort.EXE

20:32:27.0215 5172 SeaPort - ok

20:32:27.0277 5172 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys

20:32:27.0277 5172 secdrv - ok

20:32:27.0293 5172 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll

20:32:27.0293 5172 seclogon - ok

20:32:27.0293 5172 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll

20:32:27.0293 5172 SENS - ok

20:32:27.0324 5172 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll

20:32:27.0324 5172 SensrSvc - ok

20:32:27.0324 5172 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys

20:32:27.0324 5172 Serenum - ok

20:32:27.0340 5172 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys

20:32:27.0340 5172 Serial - ok

20:32:27.0386 5172 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys

20:32:27.0386 5172 sermouse - ok

20:32:27.0449 5172 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll

20:32:27.0449 5172 SessionEnv - ok

20:32:27.0496 5172 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys

20:32:27.0496 5172 sffdisk - ok

20:32:27.0511 5172 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys

20:32:27.0511 5172 sffp_mmc - ok

20:32:27.0527 5172 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys

20:32:27.0527 5172 sffp_sd - ok

20:32:27.0542 5172 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys

20:32:27.0542 5172 sfloppy - ok

20:32:27.0574 5172 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll

20:32:27.0620 5172 SharedAccess - ok

20:32:27.0714 5172 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll

20:32:27.0730 5172 ShellHWDetection - ok

20:32:27.0776 5172 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys

20:32:27.0776 5172 sisagp - ok

20:32:27.0808 5172 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys

20:32:27.0808 5172 SiSRaid2 - ok

20:32:27.0823 5172 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys

20:32:27.0823 5172 SiSRaid4 - ok

20:32:27.0839 5172 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys

20:32:27.0854 5172 Smb - ok

20:32:27.0886 5172 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe

20:32:27.0901 5172 SNMPTRAP - ok

20:32:27.0995 5172 Sony SCSI Helper Service (3bb48f7e33c2b76184ddf233000c09cd) C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

20:32:27.0995 5172 Sony SCSI Helper Service - ok

20:32:28.0010 5172 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys

20:32:28.0010 5172 spldr - ok

20:32:28.0073 5172 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe

20:32:28.0073 5172 Spooler - ok

20:32:28.0260 5172 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe

20:32:28.0322 5172 sppsvc - ok

20:32:28.0447 5172 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll

20:32:28.0447 5172 sppuinotify - ok

20:32:28.0556 5172 SQLBrowser (86ebd8b1f23e743aad21f4d5b4d40985) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe

20:32:28.0572 5172 SQLBrowser - ok

20:32:28.0634 5172 SQLWriter (d89083c4eb02daca8f944b0e05e57f9d) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

20:32:28.0634 5172 SQLWriter - ok

20:32:28.0712 5172 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys

20:32:28.0712 5172 srv - ok

20:32:28.0728 5172 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys

20:32:28.0728 5172 srv2 - ok

20:32:28.0759 5172 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys

20:32:28.0759 5172 srvnet - ok

20:32:28.0790 5172 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll

20:32:28.0790 5172 SSDPSRV - ok

20:32:28.0806 5172 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll

20:32:28.0822 5172 SstpSvc - ok

20:32:28.0837 5172 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys

20:32:28.0837 5172 stexstor - ok

20:32:28.0915 5172 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll

20:32:28.0915 5172 StiSvc - ok

20:32:28.0962 5172 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys

20:32:28.0962 5172 storflt - ok

20:32:28.0978 5172 StorSvc (0bf669f0a910beda4a32258d363af2a5) C:\Windows\system32\storsvc.dll

20:32:28.0978 5172 StorSvc - ok

20:32:28.0993 5172 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys

20:32:29.0009 5172 storvsc - ok

20:32:29.0009 5172 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys

20:32:29.0009 5172 swenum - ok

20:32:29.0040 5172 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll

20:32:29.0040 5172 swprv - ok

20:32:29.0165 5172 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll

20:32:29.0180 5172 SysMain - ok

20:32:29.0227 5172 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll

20:32:29.0227 5172 TabletInputService - ok

20:32:29.0290 5172 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll

20:32:29.0290 5172 TapiSrv - ok

20:32:29.0305 5172 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll

20:32:29.0321 5172 TBS - ok

20:32:29.0446 5172 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys

20:32:29.0461 5172 Tcpip - ok

20:32:29.0586 5172 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys

20:32:29.0602 5172 TCPIP6 - ok

20:32:29.0695 5172 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys

20:32:29.0695 5172 tcpipreg - ok

20:32:29.0742 5172 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys

20:32:29.0742 5172 TDPIPE - ok

20:32:29.0773 5172 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys

20:32:29.0773 5172 TDTCP - ok

20:32:29.0804 5172 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys

20:32:29.0804 5172 tdx - ok

20:32:29.0851 5172 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys

20:32:29.0851 5172 TermDD - ok

20:32:29.0929 5172 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll

20:32:29.0945 5172 TermService - ok

20:32:29.0960 5172 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll

20:32:29.0960 5172 Themes - ok

20:32:29.0992 5172 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll

20:32:29.0992 5172 THREADORDER - ok

20:32:30.0023 5172 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll

20:32:30.0023 5172 TrkWks - ok

20:32:30.0085 5172 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe

20:32:30.0101 5172 TrustedInstaller - ok

20:32:30.0116 5172 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys

20:32:30.0116 5172 tssecsrv - ok

20:32:30.0179 5172 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys

20:32:30.0179 5172 TsUsbFlt - ok

20:32:30.0257 5172 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys

20:32:30.0257 5172 tunnel - ok

20:32:30.0288 5172 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys

20:32:30.0288 5172 uagp35 - ok

20:32:30.0350 5172 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys

20:32:30.0350 5172 udfs - ok

20:32:30.0366 5172 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe

20:32:30.0366 5172 UI0Detect - ok

20:32:30.0413 5172 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys

20:32:30.0413 5172 uliagpkx - ok

20:32:30.0460 5172 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys

20:32:30.0460 5172 umbus - ok

20:32:30.0475 5172 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys

20:32:30.0475 5172 UmPass - ok

20:32:30.0522 5172 UmRdpService (409994a8eaceee4e328749c0353527a0) C:\Windows\System32\umrdp.dll

20:32:30.0538 5172 UmRdpService - ok

20:32:30.0569 5172 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll

20:32:30.0569 5172 upnphost - ok

20:32:30.0600 5172 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys

20:32:30.0600 5172 usbaudio - ok

20:32:30.0616 5172 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys

20:32:30.0616 5172 usbccgp - ok

20:32:30.0647 5172 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys

20:32:30.0662 5172 usbcir - ok

20:32:30.0662 5172 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys

20:32:30.0662 5172 usbehci - ok

20:32:30.0709 5172 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys

20:32:30.0709 5172 usbhub - ok

20:32:30.0725 5172 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys

20:32:30.0725 5172 usbohci - ok

20:32:30.0772 5172 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys

20:32:30.0772 5172 usbprint - ok

20:32:30.0834 5172 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys

20:32:30.0834 5172 usbscan - ok

20:32:30.0850 5172 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS

20:32:30.0850 5172 USBSTOR - ok

20:32:30.0865 5172 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys

20:32:30.0865 5172 usbuhci - ok

20:32:30.0912 5172 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys

20:32:30.0912 5172 usb_rndisx - ok

20:32:30.0928 5172 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll

20:32:30.0928 5172 UxSms - ok

20:32:30.0990 5172 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe

20:32:30.0990 5172 VaultSvc - ok

20:32:31.0037 5172 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys

20:32:31.0037 5172 vdrvroot - ok

20:32:31.0115 5172 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe

20:32:31.0146 5172 vds - ok

20:32:31.0208 5172 vfsmrx - ok

20:32:31.0224 5172 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys

20:32:31.0224 5172 vga - ok

20:32:31.0240 5172 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys

20:32:31.0240 5172 VgaSave - ok

20:32:31.0286 5172 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys

20:32:31.0286 5172 vhdmp - ok

20:32:31.0302 5172 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys

20:32:31.0302 5172 viaagp - ok

20:32:31.0318 5172 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys

20:32:31.0318 5172 ViaC7 - ok

20:32:31.0333 5172 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys

20:32:31.0333 5172 viaide - ok

20:32:31.0380 5172 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys

20:32:31.0380 5172 vmbus - ok

20:32:31.0427 5172 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys

20:32:31.0427 5172 VMBusHID - ok

20:32:31.0442 5172 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys

20:32:31.0442 5172 volmgr - ok

20:32:31.0474 5172 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys

20:32:31.0474 5172 volmgrx - ok

20:32:31.0536 5172 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys

20:32:31.0536 5172 volsnap - ok

20:32:31.0567 5172 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys

20:32:31.0567 5172 vsmraid - ok

20:32:31.0661 5172 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe

20:32:31.0676 5172 VSS - ok

20:32:31.0692 5172 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys

20:32:31.0692 5172 vwifibus - ok

20:32:31.0739 5172 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll

20:32:31.0754 5172 W32Time - ok

20:32:31.0770 5172 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys

20:32:31.0770 5172 WacomPen - ok

20:32:31.0832 5172 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys

20:32:31.0832 5172 WANARP - ok

20:32:31.0832 5172 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys

20:32:31.0832 5172 Wanarpv6 - ok

20:32:31.0957 5172 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe

20:32:31.0973 5172 WatAdminSvc - ok

20:32:32.0098 5172 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe

20:32:32.0113 5172 wbengine - ok

20:32:32.0144 5172 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll

20:32:32.0144 5172 WbioSrvc - ok

20:32:32.0238 5172 WcesComm (59e19bd13c3bdb857646b9e436ba27f7) C:\Windows\WindowsMobile\wcescomm.dll

20:32:32.0254 5172 WcesComm - ok

20:32:32.0316 5172 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll

20:32:32.0316 5172 wcncsvc - ok

20:32:32.0332 5172 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll

20:32:32.0347 5172 WcsPlugInService - ok

20:32:32.0378 5172 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys

20:32:32.0378 5172 Wd - ok

20:32:32.0410 5172 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys

20:32:32.0410 5172 Wdf01000 - ok

20:32:32.0441 5172 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll

20:32:32.0441 5172 WdiServiceHost - ok

20:32:32.0441 5172 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll

20:32:32.0441 5172 WdiSystemHost - ok

20:32:32.0503 5172 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll

20:32:32.0519 5172 WebClient - ok

20:32:32.0534 5172 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll

20:32:32.0534 5172 Wecsvc - ok

20:32:32.0550 5172 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll

20:32:32.0550 5172 wercplsupport - ok

20:32:32.0597 5172 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll

20:32:32.0597 5172 WerSvc - ok

20:32:32.0597 5172 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys

20:32:32.0597 5172 WfpLwf - ok

20:32:32.0612 5172 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys

20:32:32.0612 5172 WIMMount - ok

20:32:32.0706 5172 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll

20:32:32.0722 5172 WinDefend - ok

20:32:32.0722 5172 WinHttpAutoProxySvc - ok

20:32:32.0784 5172 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll

20:32:32.0784 5172 Winmgmt - ok

20:32:32.0862 5172 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll

20:32:32.0862 5172 WinRM - ok

20:32:32.0956 5172 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys

20:32:32.0956 5172 WinUsb - ok

20:32:33.0065 5172 WinVNC4 (18afdadec4c33eb0ee7181df35f7a213) C:\Program Files\RealVNC\VNC4\WinVNC4.exe

20:32:33.0080 5172 WinVNC4 - ok

20:32:33.0143 5172 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll

20:32:33.0174 5172 Wlansvc - ok

20:32:33.0268 5172 wlcrasvc (6067acef367e79914af628fa1e9b5330) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

20:32:33.0268 5172 wlcrasvc - ok

20:32:33.0392 5172 wlidsvc (0a70f4022ec2e14c159efc4f69aa2477) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

20:32:33.0408 5172 wlidsvc - ok

20:32:33.0486 5172 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys

20:32:33.0486 5172 WmiAcpi - ok

20:32:33.0564 5172 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe

20:32:33.0564 5172 wmiApSrv - ok

20:32:33.0689 5172 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe

20:32:33.0704 5172 WMPNetworkSvc - ok

20:32:33.0767 5172 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll

20:32:33.0767 5172 WPCSvc - ok

20:32:33.0814 5172 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll

20:32:33.0814 5172 WPDBusEnum - ok

20:32:33.0845 5172 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys

20:32:33.0845 5172 ws2ifsl - ok

20:32:33.0845 5172 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\System32\wscsvc.dll

20:32:33.0860 5172 wscsvc - ok

20:32:33.0860 5172 WSearch - ok

20:32:34.0001 5172 wuauserv (3026418a50c5b4761befa632cedb7406) C:\Windows\system32\wuaueng.dll

20:32:34.0032 5172 wuauserv - ok

20:32:34.0110 5172 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys

20:32:34.0110 5172 WudfPf - ok

20:32:34.0141 5172 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys

20:32:34.0141 5172 WUDFRd - ok

20:32:34.0204 5172 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll

20:32:34.0204 5172 wudfsvc - ok

20:32:34.0235 5172 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll

20:32:34.0235 5172 WwanSvc - ok

20:32:34.0235 5172 zhqyzxtn - ok

20:32:34.0266 5172 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0

20:32:34.0313 5172 \Device\Harddisk0\DR0 - ok

20:32:34.0328 5172 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1

20:32:34.0328 5172 \Device\Harddisk1\DR1 - ok

20:32:34.0328 5172 Boot (0x1200) (44ee8df06b191452e1e86f020b8c3867) \Device\Harddisk0\DR0\Partition0

20:32:34.0328 5172 \Device\Harddisk0\DR0\Partition0 - ok

20:32:34.0344 5172 Boot (0x1200) (b47077e777d3c91e9c1433a6bd87e484) \Device\Harddisk0\DR0\Partition1

20:32:34.0344 5172 \Device\Harddisk0\DR0\Partition1 - ok

20:32:34.0375 5172 Boot (0x1200) (b195bea2def612284e0be5edd2c8c0e9) \Device\Harddisk0\DR0\Partition2

20:32:34.0375 5172 \Device\Harddisk0\DR0\Partition2 - ok

20:32:34.0391 5172 Boot (0x1200) (a7678ce4ebc5d6cd222658e1c21c8148) \Device\Harddisk1\DR1\Partition0

20:32:34.0391 5172 \Device\Harddisk1\DR1\Partition0 - ok

20:32:34.0391 5172 ============================================================

20:32:34.0391 5172 Scan finished

20:32:34.0391 5172 ============================================================

20:32:34.0406 1372 Detected object count: 0

20:32:34.0406 1372 Actual detected object count: 0

=========

Hm, mijn ongeduld doet de overzichtelijkheid geen goed. Een keer of drie gepost, zie ik. Mijn excuses!

aangepast door kape
dubbellogs verwijderd
Link naar reactie
Delen op andere sites

Download Unhide.exe naar het bureaublad, als u een melding krijgt dat het bestand mogelijk onveilig is kunt u dit negeren.

  • Dubbelklik op "Unhide.exe" om de tool te starten.
  • Let op!!! Windows Vista & 7 gebruikers dienen "Unhide.exe" als administrator uit te voeren "Rechtermuisknop uitvoeren als administrator",
  • Wacht rustig af totdat de tool gereed is en doe in de tussentijd verder niets op de computer.
  • Als de tool gereed is krijgt u het onderstaande scherm te zien, met de melding "Your files should now be visible"
    • 4d9d78e700801-unhide..jpg

    [*] Vermeld in uw volgende bericht of u deze melding heeft gekregen.

Link naar reactie
Delen op andere sites

Dag Kape,

Dank voor je bericht en de link. Ik heb Unhide gedraaid, mijn files zijn weer zichtbaar. Snelkoppelingen doen het weer, dropbox is er weer en ik kan weer over het netwerk. Alleen de printers zijn er nog niet, dat is het enige nog.

Veel dank tot dusver, ik hoor nog graag.

Dankbare groet, John

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.