V Mbam nech vše smazat a dodej log
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje "Smazání- Finished "
- Klikni na "Zprávy " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
prosím o kontrolu logu
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: prosím o kontrolu logu
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Verze: v2013.04.15.07
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
všichni :: VSICHNI-PC [administrátor]
15.4.2013 18:34:27
mbam-log-2013-04-15 (18-34-27).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 195039
Uplynulý čas: 5 minut, 55 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Users\všichni\AppData\Roaming\dclogs (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
Nalezené soubory: 3
C:\Users\všichni\AppData\Roaming\dclogs\2013-04-11-5.dc (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
C:\Users\všichni\AppData\Roaming\dclogs\2013-04-12-6.dc (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
C:\Users\všichni\Desktop\winlogon.com (Heuristics.Reserved.Word.Exploit) -> Přesun do karantény a smazání se zdařilo.
(konec)
www.malwarebytes.org
Verze: v2013.04.15.07
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
všichni :: VSICHNI-PC [administrátor]
15.4.2013 18:34:27
mbam-log-2013-04-15 (18-34-27).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 195039
Uplynulý čas: 5 minut, 55 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Přesun do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Users\všichni\AppData\Roaming\dclogs (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
Nalezené soubory: 3
C:\Users\všichni\AppData\Roaming\dclogs\2013-04-11-5.dc (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
C:\Users\všichni\AppData\Roaming\dclogs\2013-04-12-6.dc (Stolen.Data) -> Přesun do karantény a smazání se zdařilo.
C:\Users\všichni\Desktop\winlogon.com (Heuristics.Reserved.Word.Exploit) -> Přesun do karantény a smazání se zdařilo.
(konec)
Re: prosím o kontrolu logu
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/
Operační systém : Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : všichni [Práva správce]
Mód : Odebrat -- Datum : 04/15/2013 18:54:53
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP PATH] eGdpSvc.exe -- C:\ProgramData\eSafe\eGdpSvc.exe [7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: ST9200827AS +++++
--- User ---
[MBR] 24fa79e2aed1d14e360fb2872ff3b4dd
[BSP] c83f6d3cdea8c218388548da794008b8 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 10001 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20484096 | Size: 180779 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[3]_D_04152013_02d1854.txt >>
RKreport[1]_S_04152013_02d1212.txt ; RKreport[2]_S_04152013_02d1853.txt ; RKreport[3]_D_04152013_02d1854.txt
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/
Operační systém : Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : všichni [Práva správce]
Mód : Odebrat -- Datum : 04/15/2013 18:54:53
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[SUSP PATH] eGdpSvc.exe -- C:\ProgramData\eSafe\eGdpSvc.exe [7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 2 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: ST9200827AS +++++
--- User ---
[MBR] 24fa79e2aed1d14e360fb2872ff3b4dd
[BSP] c83f6d3cdea8c218388548da794008b8 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 10001 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20484096 | Size: 180779 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[3]_D_04152013_02d1854.txt >>
RKreport[1]_S_04152013_02d1212.txt ; RKreport[2]_S_04152013_02d1853.txt ; RKreport[3]_D_04152013_02d1854.txt
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu
Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu
13:09:37.0837 1660 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:09:38.0134 1660 ============================================================
13:09:38.0134 1660 Current date / time: 2013/04/16 13:09:38.0134
13:09:38.0134 1660 SystemInfo:
13:09:38.0134 1660
13:09:38.0134 1660 OS Version: 6.0.6001 ServicePack: 1.0
13:09:38.0134 1660 Product type: Workstation
13:09:38.0134 1660 ComputerName: VSICHNI-PC
13:09:38.0134 1660 UserName: všichni
13:09:38.0134 1660 Windows directory: C:\Windows
13:09:38.0134 1660 System windows directory: C:\Windows
13:09:38.0134 1660 Processor architecture: Intel x86
13:09:38.0134 1660 Number of processors: 2
13:09:38.0134 1660 Page size: 0x1000
13:09:38.0134 1660 Boot type: Normal boot
13:09:38.0134 1660 ============================================================
13:09:38.0836 1660 Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:09:38.0883 1660 ============================================================
13:09:38.0883 1660 \Device\Harddisk0\DR0:
13:09:38.0883 1660 MBR partitions:
13:09:38.0883 1660 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1389000, BlocksNum 0x16115800
13:09:38.0883 1660 ============================================================
13:09:38.0898 1660 C: <-> \Device\Harddisk0\DR0\Partition1
13:09:38.0898 1660 ============================================================
13:09:38.0898 1660 Initialize success
13:09:38.0898 1660 ============================================================
13:09:43.0563 5744 ============================================================
13:09:43.0563 5744 Scan started
13:09:43.0563 5744 Mode: Manual;
13:09:43.0563 5744 ============================================================
13:09:43.0859 5744 ================ Scan system memory ========================
13:09:43.0859 5744 System memory - ok
13:09:43.0859 5744 ================ Scan services =============================
13:09:44.0015 5744 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
13:09:44.0015 5744 ACPI - ok
13:09:44.0062 5744 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:09:44.0062 5744 adp94xx - ok
13:09:44.0093 5744 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:09:44.0109 5744 adpahci - ok
13:09:44.0124 5744 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:09:44.0140 5744 adpu160m - ok
13:09:44.0155 5744 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:09:44.0171 5744 adpu320 - ok
13:09:44.0280 5744 [ 609A6F49B6AF0F25837F8A0EDDDB0745 ] ADSMService C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
13:09:44.0296 5744 ADSMService - ok
13:09:44.0311 5744 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:09:44.0327 5744 AeLookupSvc - ok
13:09:44.0405 5744 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
13:09:44.0405 5744 AFD - ok
13:09:44.0452 5744 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:09:44.0452 5744 agp440 - ok
13:09:44.0499 5744 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:09:44.0499 5744 aic78xx - ok
13:09:44.0530 5744 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:09:44.0530 5744 ALG - ok
13:09:44.0545 5744 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:09:44.0545 5744 aliide - ok
13:09:44.0592 5744 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:09:44.0592 5744 amdagp - ok
13:09:44.0608 5744 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:09:44.0608 5744 amdide - ok
13:09:44.0639 5744 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:09:44.0639 5744 AmdK7 - ok
13:09:44.0655 5744 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:09:44.0655 5744 AmdK8 - ok
13:09:44.0701 5744 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:09:44.0701 5744 Appinfo - ok
13:09:44.0733 5744 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:09:44.0733 5744 arc - ok
13:09:44.0764 5744 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:09:44.0779 5744 arcsas - ok
13:09:44.0826 5744 [ 4385E371C25C94C804E9D3152BD9E1F7 ] AsDsm C:\Windows\system32\drivers\AsDsm.sys
13:09:44.0842 5744 AsDsm - ok
13:09:44.0904 5744 [ 5A055A4777CBBC8845DD598CB2EEBF69 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
13:09:44.0920 5744 ASLDRService - ok
13:09:44.0935 5744 [ 7B4D08D2017AC06689D422E06C43F0AA ] ASMMAP C:\Program Files\ATKGFNEX\ASMMAP.sys
13:09:44.0935 5744 ASMMAP - ok
13:09:45.0045 5744 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:09:45.0216 5744 aspnet_state - ok
13:09:45.0263 5744 [ CCDA8D84FD02AEC52E62F296433AE9DC ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
13:09:45.0263 5744 aswFsBlk - ok
13:09:45.0310 5744 [ A65FC444F7660F0CAC9A9E22203FD4BA ] aswFW C:\Windows\system32\drivers\aswFW.sys
13:09:45.0310 5744 aswFW - ok
13:09:45.0341 5744 [ 4691B3FE3717F9D9C64A5282C8543D4D ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
13:09:45.0341 5744 aswKbd - ok
13:09:45.0357 5744 [ A6E20E62871A28A0F1C05B1681848FA7 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
13:09:45.0357 5744 aswMonFlt - ok
13:09:45.0372 5744 [ 7B948E3657BEA62E437BC46CA6EF6012 ] aswNdis C:\Windows\system32\DRIVERS\aswNdis.sys
13:09:45.0372 5744 aswNdis - ok
13:09:45.0388 5744 [ 672A45E2AA1FA8178DB8CF1A39BEFC83 ] aswNdis2 C:\Windows\system32\drivers\aswNdis2.sys
13:09:45.0388 5744 aswNdis2 - ok
13:09:45.0403 5744 [ C1A411B7CCD604554D96EFDAC2F83617 ] AswRdr C:\Windows\system32\drivers\AswRdr.sys
13:09:45.0403 5744 AswRdr - ok
13:09:45.0419 5744 [ 657A61979F40D67CA29716149766FFA7 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
13:09:45.0419 5744 aswRvrt - ok
13:09:45.0466 5744 [ 0E604867FC28F00D91CB0B00D2EC830D ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
13:09:45.0481 5744 aswSnx - ok
13:09:45.0528 5744 [ 6FC4AA106AA505394C908D37CCCB9148 ] aswSP C:\Windows\system32\drivers\aswSP.sys
13:09:45.0528 5744 aswSP - ok
13:09:45.0544 5744 [ 33E21FFB063CA6C7E00D568467DC72E4 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
13:09:45.0544 5744 aswTdi - ok
13:09:45.0575 5744 [ EDB0C9BA44B748E420CCA989FD8B826E ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
13:09:45.0575 5744 aswVmm - ok
13:09:45.0622 5744 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:09:45.0637 5744 AsyncMac - ok
13:09:45.0637 5744 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:09:45.0637 5744 atapi - ok
13:09:45.0700 5744 [ 4DF523F49694B2884F8E5D870BF3E253 ] athr C:\Windows\system32\DRIVERS\athr.sys
13:09:45.0747 5744 athr - ok
13:09:45.0778 5744 [ 7C157574A181B19B9DCF5F339E25337E ] ATKGFNEXSrv C:\Program Files\ATKGFNEX\GFNEXSrv.exe
13:09:45.0778 5744 ATKGFNEXSrv - ok
13:09:45.0825 5744 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:09:45.0825 5744 AudioEndpointBuilder - ok
13:09:45.0840 5744 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:09:45.0856 5744 Audiosrv - ok
13:09:45.0949 5744 [ 41735B82DB57E4EBE9504EC400FD120E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
13:09:45.0949 5744 avast! Antivirus - ok
13:09:46.0012 5744 [ DA387EDDBA421A7A8132E256343C2799 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
13:09:46.0012 5744 avast! Firewall - ok
13:09:46.0043 5744 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:09:46.0059 5744 Beep - ok
13:09:46.0105 5744 [ 8582E233C346AEFE759833E8A30DD697 ] BFE C:\Windows\System32\bfe.dll
13:09:46.0105 5744 BFE - ok
13:09:46.0215 5744 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
13:09:46.0308 5744 BITS - ok
13:09:46.0339 5744 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:09:46.0355 5744 blbdrive - ok
13:09:46.0386 5744 [ 74B442B2BE1260B7588C136177CEAC66 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:09:46.0386 5744 bowser - ok
13:09:46.0417 5744 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:09:46.0417 5744 BrFiltLo - ok
13:09:46.0449 5744 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:09:46.0449 5744 BrFiltUp - ok
13:09:46.0527 5744 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:09:46.0542 5744 Browser - ok
13:09:46.0558 5744 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:09:46.0573 5744 Brserid - ok
13:09:46.0573 5744 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:09:46.0589 5744 BrSerWdm - ok
13:09:46.0589 5744 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:09:46.0605 5744 BrUsbMdm - ok
13:09:46.0605 5744 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:09:46.0620 5744 BrUsbSer - ok
13:09:46.0651 5744 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
13:09:46.0651 5744 BTHMODEM - ok
13:09:46.0683 5744 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:09:46.0683 5744 cdfs - ok
13:09:46.0714 5744 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:09:46.0714 5744 cdrom - ok
13:09:46.0745 5744 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
13:09:46.0761 5744 CertPropSvc - ok
13:09:46.0776 5744 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
13:09:46.0776 5744 circlass - ok
13:09:46.0792 5744 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
13:09:46.0823 5744 CLFS - ok
13:09:46.0885 5744 [ A4AF4201BD519971F8F34724F3CA9DBB ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:09:46.0901 5744 clr_optimization_v2.0.50727_32 - ok
13:09:46.0995 5744 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:09:47.0026 5744 clr_optimization_v4.0.30319_32 - ok
13:09:47.0057 5744 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:09:47.0057 5744 CmBatt - ok
13:09:47.0088 5744 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:09:47.0088 5744 cmdide - ok
13:09:47.0119 5744 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:09:47.0119 5744 Compbatt - ok
13:09:47.0119 5744 COMSysApp - ok
13:09:47.0135 5744 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:09:47.0135 5744 crcdisk - ok
13:09:47.0166 5744 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:09:47.0166 5744 Crusoe - ok
13:09:47.0229 5744 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:09:47.0275 5744 CryptSvc - ok
13:09:47.0338 5744 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:09:47.0431 5744 DcomLaunch - ok
13:09:47.0525 5744 [ 105108175F6E49E41713E503599B6E72 ] desksvc C:\Program Files\Desk 365\deskSvc.exe
13:09:47.0556 5744 desksvc - ok
13:09:47.0587 5744 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:09:47.0603 5744 DfsC - ok
13:09:47.0681 5744 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
13:09:47.0743 5744 DFSR - ok
13:09:47.0806 5744 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:09:47.0837 5744 Dhcp - ok
13:09:47.0884 5744 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
13:09:47.0884 5744 disk - ok
13:09:47.0931 5744 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:09:47.0962 5744 Dnscache - ok
13:09:48.0009 5744 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
13:09:48.0024 5744 dot3svc - ok
13:09:48.0055 5744 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:09:48.0133 5744 DPS - ok
13:09:48.0149 5744 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:09:48.0165 5744 drmkaud - ok
13:09:48.0289 5744 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:09:48.0321 5744 DXGKrnl - ok
13:09:48.0336 5744 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:09:48.0352 5744 E1G60 - ok
13:09:48.0352 5744 EagleXNt - ok
13:09:48.0399 5744 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:09:48.0430 5744 EapHost - ok
13:09:48.0461 5744 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:09:48.0477 5744 Ecache - ok
13:09:48.0726 5744 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:09:48.0742 5744 ehRecvr - ok
13:09:48.0773 5744 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:09:48.0789 5744 ehSched - ok
13:09:48.0804 5744 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:09:48.0804 5744 ehstart - ok
13:09:48.0851 5744 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:09:48.0867 5744 elxstor - ok
13:09:48.0929 5744 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:09:48.0991 5744 EMDMgmt - ok
13:09:49.0023 5744 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:09:49.0023 5744 ErrDev - ok
13:09:49.0288 5744 [ A048327067D7BAB53402B0CDC5A11754 ] eSafeSvc C:\ProgramData\eSafe\eGdpSvc.exe
13:09:49.0335 5744 eSafeSvc - ok
13:09:49.0381 5744 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
13:09:49.0413 5744 EventSystem - ok
13:09:49.0459 5744 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
13:09:49.0475 5744 exfat - ok
13:09:49.0506 5744 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:09:49.0522 5744 fastfat - ok
13:09:49.0553 5744 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:09:49.0553 5744 fdc - ok
13:09:49.0584 5744 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:09:49.0631 5744 fdPHost - ok
13:09:49.0662 5744 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:09:49.0709 5744 FDResPub - ok
13:09:49.0725 5744 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:09:49.0725 5744 FileInfo - ok
13:09:49.0740 5744 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:09:49.0756 5744 Filetrace - ok
13:09:49.0771 5744 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:09:49.0771 5744 flpydisk - ok
13:09:49.0803 5744 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:09:49.0818 5744 FltMgr - ok
13:09:49.0865 5744 [ 993883524AA9CF1C90E1545411A9AC9C ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:09:49.0881 5744 FontCache3.0.0.0 - ok
13:09:49.0896 5744 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:09:49.0896 5744 Fs_Rec - ok
13:09:49.0927 5744 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:09:49.0943 5744 gagp30kx - ok
13:09:49.0990 5744 [ 31B40F40E09513ADDC460F6A297AD474 ] ghaio C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
13:09:49.0990 5744 ghaio - ok
13:09:50.0068 5744 [ 9E37E0C528E1E3A79E215B6A4EEA2143 ] GoogleDesktopManager-092308-165331 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
13:09:50.0083 5744 GoogleDesktopManager-092308-165331 - ok
13:09:50.0208 5744 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
13:09:50.0255 5744 gpsvc - ok
13:09:50.0286 5744 [ 649F407A844DDE2B97BC086AF97D663B ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
13:09:50.0286 5744 gusvc - ok
13:09:50.0333 5744 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:09:50.0349 5744 HdAudAddService - ok
13:09:50.0364 5744 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:09:50.0364 5744 HDAudBus - ok
13:09:50.0395 5744 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:09:50.0395 5744 HidBth - ok
13:09:50.0411 5744 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
13:09:50.0427 5744 HidIr - ok
13:09:50.0458 5744 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
13:09:50.0505 5744 hidserv - ok
13:09:50.0520 5744 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:09:50.0520 5744 HidUsb - ok
13:09:50.0551 5744 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:09:50.0598 5744 hkmsvc - ok
13:09:50.0614 5744 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:09:50.0629 5744 HpCISSs - ok
13:09:50.0661 5744 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:09:50.0676 5744 HTTP - ok
13:09:50.0692 5744 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:09:50.0692 5744 i2omp - ok
13:09:50.0739 5744 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:09:50.0739 5744 i8042prt - ok
13:09:50.0770 5744 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
13:09:50.0785 5744 iaStor - ok
13:09:50.0848 5744 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:09:50.0879 5744 iaStorV - ok
13:09:50.0941 5744 [ E7CC3AEAED9893A88876744CD439F76C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:09:51.0019 5744 idsvc - ok
13:09:51.0441 5744 [ 9378D57E2B96C0A185D844770AD49948 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
13:09:51.0519 5744 igfx - ok
13:09:51.0550 5744 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:09:51.0565 5744 iirsp - ok
13:09:51.0597 5744 [ A3BC480A2BF8AA8E4DABD2D5DCE0AFAC ] IKEEXT C:\Windows\System32\ikeext.dll
13:09:51.0659 5744 IKEEXT - ok
13:09:51.0784 5744 [ 4E38A2883DF3BA382A59132B3E7D709E ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:09:51.0846 5744 IntcAzAudAddService - ok
13:09:51.0877 5744 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:09:51.0893 5744 intelide - ok
13:09:51.0909 5744 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:09:51.0924 5744 intelppm - ok
13:09:51.0955 5744 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:09:51.0987 5744 IPBusEnum - ok
13:09:52.0018 5744 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:09:52.0018 5744 IpFilterDriver - ok
13:09:52.0049 5744 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:09:52.0143 5744 iphlpsvc - ok
13:09:52.0143 5744 IpInIp - ok
13:09:52.0174 5744 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:09:52.0174 5744 IPMIDRV - ok
13:09:52.0205 5744 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:09:52.0205 5744 IPNAT - ok
13:09:52.0221 5744 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:09:52.0236 5744 IRENUM - ok
13:09:52.0252 5744 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:09:52.0252 5744 isapnp - ok
13:09:52.0299 5744 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:09:52.0330 5744 iScsiPrt - ok
13:09:52.0345 5744 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:09:52.0345 5744 iteatapi - ok
13:09:52.0361 5744 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:09:52.0377 5744 iteraid - ok
13:09:52.0392 5744 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:09:52.0392 5744 kbdclass - ok
13:09:52.0423 5744 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:09:52.0423 5744 kbdhid - ok
13:09:52.0470 5744 [ CC2A86D7BBF14977340DCA61BBCBA771 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys
13:09:52.0470 5744 kbfiltr - ok
13:09:52.0501 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
13:09:52.0548 5744 KeyIso - ok
13:09:52.0579 5744 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:09:52.0626 5744 KSecDD - ok
13:09:52.0657 5744 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:09:52.0735 5744 KtmRm - ok
13:09:52.0767 5744 [ 05CE901A4472B3FBF9407C94AD1DB693 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:09:52.0860 5744 LanmanServer - ok
13:09:52.0891 5744 [ DEC1A338B86C5D582C25C40836DD76C3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:09:53.0001 5744 LanmanWorkstation - ok
13:09:53.0063 5744 [ ABF90FC5A127F481219B873C1B8DFC1C ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:09:53.0079 5744 LightScribeService - ok
13:09:53.0125 5744 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:09:53.0141 5744 lltdio - ok
13:09:53.0172 5744 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:09:53.0235 5744 lltdsvc - ok
13:09:53.0250 5744 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:09:53.0297 5744 lmhosts - ok
13:09:53.0328 5744 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:09:53.0344 5744 LSI_FC - ok
13:09:53.0375 5744 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:09:53.0375 5744 LSI_SAS - ok
13:09:53.0391 5744 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:09:53.0406 5744 LSI_SCSI - ok
13:09:53.0422 5744 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:09:53.0437 5744 luafv - ok
13:09:53.0469 5744 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:09:53.0531 5744 Mcx2Svc - ok
13:09:53.0578 5744 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:09:53.0578 5744 megasas - ok
13:09:53.0609 5744 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:09:53.0640 5744 MegaSR - ok
13:09:53.0671 5744 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:09:53.0734 5744 MMCSS - ok
13:09:53.0765 5744 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:09:53.0765 5744 Modem - ok
13:09:53.0781 5744 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:09:53.0796 5744 monitor - ok
13:09:53.0812 5744 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:09:53.0827 5744 mouclass - ok
13:09:53.0827 5744 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:09:53.0843 5744 mouhid - ok
13:09:53.0859 5744 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:09:53.0874 5744 MountMgr - ok
13:09:53.0905 5744 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
13:09:53.0905 5744 mpio - ok
13:09:53.0937 5744 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:09:53.0937 5744 mpsdrv - ok
13:09:53.0968 5744 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
13:09:54.0046 5744 MpsSvc - ok
13:09:54.0061 5744 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:09:54.0077 5744 Mraid35x - ok
13:09:54.0093 5744 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:09:54.0108 5744 MRxDAV - ok
13:09:54.0108 5744 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:09:54.0124 5744 mrxsmb - ok
13:09:54.0139 5744 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:09:54.0155 5744 mrxsmb10 - ok
13:09:54.0171 5744 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:09:54.0186 5744 mrxsmb20 - ok
13:09:54.0202 5744 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
13:09:54.0217 5744 msahci - ok
13:09:54.0249 5744 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:09:54.0249 5744 msdsm - ok
13:09:54.0264 5744 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:09:54.0342 5744 MSDTC - ok
13:09:54.0358 5744 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:09:54.0389 5744 Msfs - ok
13:09:54.0405 5744 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:09:54.0405 5744 msisadrv - ok
13:09:54.0436 5744 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:09:54.0498 5744 MSiSCSI - ok
13:09:54.0498 5744 msiserver - ok
13:09:54.0545 5744 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:09:54.0545 5744 MSKSSRV - ok
13:09:54.0561 5744 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:09:54.0561 5744 MSPCLOCK - ok
13:09:54.0607 5744 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:09:54.0623 5744 MSPQM - ok
13:09:54.0670 5744 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:09:54.0685 5744 MsRPC - ok
13:09:54.0701 5744 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:09:54.0717 5744 mssmbios - ok
13:09:54.0748 5744 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:09:54.0748 5744 MSTEE - ok
13:09:54.0810 5744 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
13:09:54.0810 5744 MTsensor - ok
13:09:54.0826 5744 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
13:09:54.0841 5744 Mup - ok
13:09:54.0888 5744 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
13:09:54.0966 5744 napagent - ok
13:09:55.0013 5744 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:09:55.0029 5744 NativeWifiP - ok
13:09:55.0060 5744 [ C8560010A542B5DCA94C62468DC20784 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:09:55.0091 5744 NDIS - ok
13:09:55.0107 5744 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:09:55.0107 5744 NdisTapi - ok
13:09:55.0122 5744 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:09:55.0138 5744 Ndisuio - ok
13:09:55.0138 5744 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:09:55.0153 5744 NdisWan - ok
13:09:55.0169 5744 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:09:55.0169 5744 NDProxy - ok
13:09:55.0185 5744 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:09:55.0200 5744 NetBIOS - ok
13:09:55.0216 5744 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:09:55.0231 5744 netbt - ok
13:09:55.0247 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
13:09:55.0278 5744 Netlogon - ok
13:09:55.0325 5744 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:09:55.0387 5744 Netman - ok
13:09:55.0419 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0419 5744 NetMsmqActivator - ok
13:09:55.0434 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0434 5744 NetPipeActivator - ok
13:09:55.0465 5744 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:09:55.0543 5744 netprofm - ok
13:09:55.0559 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0559 5744 NetTcpActivator - ok
13:09:55.0575 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0590 5744 NetTcpPortSharing - ok
13:09:55.0637 5744 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:09:55.0653 5744 nfrd960 - ok
13:09:55.0699 5744 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:09:55.0762 5744 NlaSvc - ok
13:09:55.0777 5744 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:09:55.0793 5744 Npfs - ok
13:09:55.0824 5744 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:09:55.0902 5744 nsi - ok
13:09:55.0918 5744 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:09:55.0918 5744 nsiproxy - ok
13:09:56.0027 5744 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:09:56.0074 5744 Ntfs - ok
13:09:56.0089 5744 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:09:56.0105 5744 ntrigdigi - ok
13:09:56.0136 5744 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:09:56.0136 5744 Null - ok
13:09:56.0167 5744 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:09:56.0183 5744 nvraid - ok
13:09:56.0199 5744 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:09:56.0199 5744 nvstor - ok
13:09:56.0230 5744 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:09:56.0230 5744 nv_agp - ok
13:09:56.0245 5744 NwlnkFlt - ok
13:09:56.0261 5744 NwlnkFwd - ok
13:09:56.0495 5744 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:09:56.0542 5744 odserv - ok
13:09:56.0573 5744 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
13:09:56.0573 5744 ohci1394 - ok
13:09:56.0620 5744 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:09:56.0620 5744 ose - ok
13:09:56.0869 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:09:56.0979 5744 p2pimsvc - ok
13:09:57.0010 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
13:09:57.0072 5744 p2psvc - ok
13:09:57.0166 5744 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:09:57.0181 5744 Parport - ok
13:09:57.0213 5744 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:09:57.0213 5744 partmgr - ok
13:09:57.0228 5744 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:09:57.0228 5744 Parvdm - ok
13:09:57.0275 5744 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:09:57.0337 5744 PcaSvc - ok
13:09:57.0369 5744 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
13:09:57.0384 5744 pci - ok
13:09:57.0415 5744 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
13:09:57.0415 5744 pciide - ok
13:09:57.0462 5744 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:09:57.0462 5744 pcmcia - ok
13:09:57.0525 5744 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:09:57.0571 5744 PEAUTH - ok
13:09:57.0930 5744 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:09:58.0055 5744 pla - ok
13:09:58.0133 5744 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:09:58.0227 5744 PlugPlay - ok
13:09:58.0273 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:09:58.0336 5744 PNRPAutoReg - ok
13:09:58.0507 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:09:58.0570 5744 PNRPsvc - ok
13:09:58.0695 5744 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:09:58.0788 5744 PolicyAgent - ok
13:09:58.0819 5744 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:09:58.0835 5744 PptpMiniport - ok
13:09:58.0851 5744 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
13:09:58.0851 5744 Processor - ok
13:09:58.0897 5744 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
13:09:58.0991 5744 ProfSvc - ok
13:09:59.0007 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:09:59.0038 5744 ProtectedStorage - ok
13:09:59.0069 5744 [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:09:59.0069 5744 PSched - ok
13:09:59.0100 5744 [ 49452BFCEC22F36A7A9B9C2181BC3042 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
13:09:59.0116 5744 PxHelp20 - ok
13:09:59.0178 5744 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:09:59.0256 5744 ql2300 - ok
13:09:59.0272 5744 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:09:59.0272 5744 ql40xx - ok
13:09:59.0319 5744 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:09:59.0397 5744 QWAVE - ok
13:09:59.0412 5744 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:09:59.0428 5744 QWAVEdrv - ok
13:09:59.0443 5744 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:09:59.0459 5744 RasAcd - ok
13:09:59.0475 5744 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:09:59.0568 5744 RasAuto - ok
13:09:59.0599 5744 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:09:59.0615 5744 Rasl2tp - ok
13:09:59.0631 5744 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
13:09:59.0724 5744 RasMan - ok
13:09:59.0740 5744 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:09:59.0755 5744 RasPppoe - ok
13:09:59.0755 5744 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:09:59.0771 5744 RasSstp - ok
13:09:59.0802 5744 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:09:59.0802 5744 rdbss - ok
13:09:59.0818 5744 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:09:59.0818 5744 RDPCDD - ok
13:09:59.0849 5744 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:09:59.0865 5744 rdpdr - ok
13:09:59.0880 5744 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:09:59.0880 5744 RDPENCDD - ok
13:09:59.0911 5744 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:09:59.0927 5744 RDPWD - ok
13:09:59.0958 5744 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:10:00.0036 5744 RemoteAccess - ok
13:10:00.0067 5744 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:10:00.0145 5744 RemoteRegistry - ok
13:10:00.0208 5744 [ C35CA13D3627EBD9DD12A23CE781BC3D ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
13:10:00.0223 5744 rimmptsk - ok
13:10:00.0239 5744 [ C398BCA91216755B098679A8DA8A2300 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
13:10:00.0255 5744 rimsptsk - ok
13:10:00.0286 5744 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:10:00.0333 5744 RpcLocator - ok
13:10:00.0364 5744 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
13:10:00.0426 5744 RpcSs - ok
13:10:00.0535 5744 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:10:00.0535 5744 rspndr - ok
13:10:00.0582 5744 [ 5C5612756B380BCEDBF566A780FF9AFE ] RTL8023xp C:\Windows\system32\DRIVERS\Rtnicxp.sys
13:10:00.0582 5744 RTL8023xp - ok
13:10:00.0598 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
13:10:00.0645 5744 SamSs - ok
13:10:00.0660 5744 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:10:00.0691 5744 sbp2port - ok
13:10:00.0738 5744 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:10:00.0832 5744 SCardSvr - ok
13:10:00.0941 5744 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
13:10:01.0066 5744 Schedule - ok
13:10:01.0081 5744 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
13:10:01.0097 5744 SCPolicySvc - ok
13:10:01.0144 5744 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
13:10:01.0175 5744 sdbus - ok
13:10:01.0222 5744 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:10:01.0284 5744 SDRSVC - ok
13:10:01.0300 5744 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:10:01.0315 5744 secdrv - ok
13:10:01.0331 5744 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:10:01.0425 5744 seclogon - ok
13:10:01.0456 5744 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
13:10:01.0534 5744 SENS - ok
13:10:01.0549 5744 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
13:10:01.0565 5744 Serenum - ok
13:10:01.0596 5744 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:10:01.0596 5744 Serial - ok
13:10:01.0627 5744 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:10:01.0627 5744 sermouse - ok
13:10:01.0674 5744 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:10:01.0783 5744 SessionEnv - ok
13:10:01.0799 5744 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:10:01.0815 5744 sffdisk - ok
13:10:01.0830 5744 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:10:01.0846 5744 sffp_mmc - ok
13:10:01.0861 5744 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:10:01.0877 5744 sffp_sd - ok
13:10:01.0908 5744 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
13:10:01.0908 5744 sfloppy - ok
13:10:02.0142 5744 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:10:02.0189 5744 SharedAccess - ok
13:10:02.0220 5744 [ 27F10F348E508243F6254846F8370D0D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:10:02.0314 5744 ShellHWDetection - ok
13:10:02.0361 5744 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:10:02.0361 5744 sisagp - ok
13:10:02.0376 5744 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:10:02.0392 5744 SiSRaid2 - ok
13:10:02.0407 5744 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:10:02.0423 5744 SiSRaid4 - ok
13:10:02.0595 5744 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
13:10:02.0688 5744 Skype C2C Service - ok
13:10:02.0704 5744 [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:10:02.0704 5744 SkypeUpdate - ok
13:10:03.0141 5744 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
13:10:03.0297 5744 slsvc - ok
13:10:03.0312 5744 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:10:03.0421 5744 SLUINotify - ok
13:10:03.0437 5744 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:10:03.0437 5744 Smb - ok
13:10:03.0577 5744 [ D9BFD2298F5CF116D8EAAE3B02DCEE2E ] smserial C:\Windows\system32\DRIVERS\smserial.sys
13:10:03.0624 5744 smserial - ok
13:10:03.0671 5744 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:10:03.0765 5744 SNMPTRAP - ok
13:10:03.0780 5744 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:10:03.0796 5744 spldr - ok
13:10:03.0827 5744 [ 739DB668DBD812285ECC553E64A5E212 ] spmgr C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
13:10:03.0827 5744 spmgr - ok
13:10:03.0874 5744 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
13:10:03.0952 5744 Spooler - ok
13:10:03.0983 5744 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:10:03.0999 5744 srv - ok
13:10:04.0030 5744 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:10:04.0045 5744 srv2 - ok
13:10:04.0077 5744 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:10:04.0077 5744 srvnet - ok
13:10:04.0123 5744 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:10:04.0217 5744 SSDPSRV - ok
13:10:04.0264 5744 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:10:04.0357 5744 SstpSvc - ok
13:10:04.0420 5744 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
13:10:04.0560 5744 stisvc - ok
13:10:04.0591 5744 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:10:04.0607 5744 swenum - ok
13:10:04.0701 5744 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
13:10:04.0794 5744 swprv - ok
13:10:04.0825 5744 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:10:04.0841 5744 Symc8xx - ok
13:10:04.0857 5744 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:10:04.0857 5744 Sym_hi - ok
13:10:04.0872 5744 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:10:04.0872 5744 Sym_u3 - ok
13:10:04.0903 5744 [ 55F6E55CC2430CA8713387106FA79817 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
13:10:04.0919 5744 SynTP - ok
13:10:04.0966 5744 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
13:10:05.0075 5744 SysMain - ok
13:10:05.0091 5744 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:10:05.0169 5744 TabletInputService - ok
13:10:05.0200 5744 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
13:10:05.0309 5744 TapiSrv - ok
13:10:05.0309 5744 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:10:05.0418 5744 TBS - ok
13:10:05.0496 5744 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:10:05.0543 5744 Tcpip - ok
13:10:05.0590 5744 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:10:05.0605 5744 Tcpip6 - ok
13:10:05.0637 5744 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:10:05.0668 5744 tcpipreg - ok
13:10:05.0683 5744 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:10:05.0699 5744 TDPIPE - ok
13:10:05.0730 5744 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:10:05.0730 5744 TDTCP - ok
13:10:05.0761 5744 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:10:05.0761 5744 tdx - ok
13:10:05.0777 5744 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:10:05.0808 5744 TermDD - ok
13:10:05.0839 5744 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
13:10:05.0980 5744 TermService - ok
13:10:06.0011 5744 [ 27F10F348E508243F6254846F8370D0D ] Themes C:\Windows\system32\shsvcs.dll
13:10:06.0089 5744 Themes - ok
13:10:06.0120 5744 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:10:06.0167 5744 THREADORDER - ok
13:10:06.0214 5744 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:10:06.0307 5744 TrkWks - ok
13:10:06.0354 5744 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:10:06.0370 5744 TrustedInstaller - ok
13:10:06.0385 5744 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:10:06.0401 5744 tssecsrv - ok
13:10:06.0432 5744 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:10:06.0432 5744 tunmp - ok
13:10:06.0463 5744 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:10:06.0495 5744 tunnel - ok
13:10:06.0526 5744 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:10:06.0541 5744 uagp35 - ok
13:10:06.0557 5744 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:10:06.0557 5744 udfs - ok
13:10:06.0604 5744 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:10:06.0713 5744 UI0Detect - ok
13:10:06.0729 5744 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:10:06.0744 5744 uliagpkx - ok
13:10:06.0760 5744 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:10:06.0775 5744 uliahci - ok
13:10:06.0791 5744 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:10:06.0807 5744 UlSata - ok
13:10:06.0822 5744 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:10:06.0838 5744 ulsata2 - ok
13:10:06.0853 5744 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:10:06.0869 5744 umbus - ok
13:10:06.0916 5744 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:10:07.0056 5744 upnphost - ok
13:10:07.0119 5744 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:10:07.0134 5744 usbccgp - ok
13:10:07.0165 5744 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:10:07.0181 5744 usbcir - ok
13:10:07.0212 5744 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:10:07.0228 5744 usbehci - ok
13:10:07.0259 5744 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:10:07.0275 5744 usbhub - ok
13:10:07.0290 5744 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:10:07.0306 5744 usbohci - ok
13:10:07.0321 5744 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
13:10:07.0321 5744 usbprint - ok
13:10:07.0337 5744 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:10:07.0353 5744 USBSTOR - ok
13:10:07.0368 5744 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:10:07.0384 5744 usbuhci - ok
13:10:07.0415 5744 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:10:07.0431 5744 usbvideo - ok
13:10:07.0462 5744 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
13:10:07.0555 5744 UxSms - ok
13:10:07.0587 5744 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
13:10:07.0696 5744 vds - ok
13:10:07.0727 5744 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:10:07.0743 5744 vga - ok
13:10:07.0774 5744 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:10:07.0774 5744 VgaSave - ok
13:10:07.0805 5744 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:10:07.0805 5744 viaagp - ok
13:10:07.0821 5744 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:10:07.0836 5744 ViaC7 - ok
13:10:07.0852 5744 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:10:07.0867 5744 viaide - ok
13:10:07.0883 5744 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:10:07.0899 5744 volmgr - ok
13:10:07.0899 5744 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:10:07.0914 5744 volmgrx - ok
13:10:07.0930 5744 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:10:07.0945 5744 volsnap - ok
13:10:07.0977 5744 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:10:07.0977 5744 vsmraid - ok
13:10:08.0164 5744 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
13:10:08.0289 5744 VSS - ok
13:10:08.0335 5744 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
13:10:08.0476 5744 W32Time - ok
13:10:08.0491 5744 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:10:08.0507 5744 WacomPen - ok
13:10:08.0523 5744 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:10:08.0538 5744 Wanarp - ok
13:10:08.0538 5744 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:10:08.0554 5744 Wanarpv6 - ok
13:10:08.0601 5744 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:10:08.0694 5744 wcncsvc - ok
13:10:08.0710 5744 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:10:08.0850 5744 WcsPlugInService - ok
13:10:08.0897 5744 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:10:08.0913 5744 Wd - ok
13:10:08.0944 5744 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:10:08.0959 5744 Wdf01000 - ok
13:10:08.0991 5744 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:10:09.0100 5744 WdiServiceHost - ok
13:10:09.0100 5744 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:10:09.0193 5744 WdiSystemHost - ok
13:10:09.0256 5744 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
13:10:09.0427 5744 WebClient - ok
13:10:09.0459 5744 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:10:09.0583 5744 Wecsvc - ok
13:10:09.0615 5744 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:10:09.0708 5744 wercplsupport - ok
13:10:09.0739 5744 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
13:10:09.0895 5744 WerSvc - ok
13:10:09.0989 5744 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:10:09.0989 5744 WinDefend - ok
13:10:10.0020 5744 WinHttpAutoProxySvc - ok
13:10:10.0083 5744 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:10:10.0129 5744 Winmgmt - ok
13:10:10.0192 5744 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
13:10:10.0348 5744 WinRM - ok
13:10:10.0426 5744 [ 4B40FF01DB5357299DCBDB5A5746AD21 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:10:10.0551 5744 Wlansvc - ok
13:10:10.0566 5744 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:10:10.0582 5744 WmiAcpi - ok
13:10:10.0660 5744 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:10:10.0675 5744 wmiApSrv - ok
13:10:10.0753 5744 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:10:10.0800 5744 WMPNetworkSvc - ok
13:10:10.0847 5744 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:10:10.0987 5744 WPCSvc - ok
13:10:11.0034 5744 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:10:11.0128 5744 WPDBusEnum - ok
13:10:11.0221 5744 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:10:11.0284 5744 WPFFontCache_v0400 - ok
13:10:11.0315 5744 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:10:11.0315 5744 ws2ifsl - ok
13:10:11.0362 5744 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
13:10:11.0455 5744 wscsvc - ok
13:10:11.0471 5744 WSearch - ok
13:10:11.0705 5744 [ D79538B67FA641E986855DEF651E78FE ] wuauserv C:\Windows\system32\wuaueng.dll
13:10:11.0908 5744 wuauserv - ok
13:10:11.0939 5744 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:10:11.0939 5744 WUDFRd - ok
13:10:11.0970 5744 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:10:12.0064 5744 wudfsvc - ok
13:10:12.0126 5744 [ 7D1F3B131D503EF43EE594B5A2B9B427 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
13:10:12.0142 5744 yukonwlh - ok
13:10:12.0142 5744 ================ Scan global ===============================
13:10:12.0173 5744 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:10:12.0235 5744 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
13:10:12.0329 5744 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
13:10:12.0438 5744 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
13:10:12.0532 5744 [Global] - ok
13:10:12.0532 5744 ================ Scan MBR ==================================
13:10:12.0547 5744 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:10:13.0140 5744 \Device\Harddisk0\DR0 - ok
13:10:13.0140 5744 ================ Scan VBR ==================================
13:10:13.0187 5744 [ C74AF310874807A52CDDA6ED419FCD30 ] \Device\Harddisk0\DR0\Partition1
13:10:13.0203 5744 \Device\Harddisk0\DR0\Partition1 - ok
13:10:13.0203 5744 ============================================================
13:10:13.0203 5744 Scan finished
13:10:13.0203 5744 ============================================================
13:10:13.0234 5924 Detected object count: 0
13:10:13.0234 5924 Actual detected object count: 0
13:12:02.0096 4208 Deinitialize success
13:09:38.0134 1660 ============================================================
13:09:38.0134 1660 Current date / time: 2013/04/16 13:09:38.0134
13:09:38.0134 1660 SystemInfo:
13:09:38.0134 1660
13:09:38.0134 1660 OS Version: 6.0.6001 ServicePack: 1.0
13:09:38.0134 1660 Product type: Workstation
13:09:38.0134 1660 ComputerName: VSICHNI-PC
13:09:38.0134 1660 UserName: všichni
13:09:38.0134 1660 Windows directory: C:\Windows
13:09:38.0134 1660 System windows directory: C:\Windows
13:09:38.0134 1660 Processor architecture: Intel x86
13:09:38.0134 1660 Number of processors: 2
13:09:38.0134 1660 Page size: 0x1000
13:09:38.0134 1660 Boot type: Normal boot
13:09:38.0134 1660 ============================================================
13:09:38.0836 1660 Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:09:38.0883 1660 ============================================================
13:09:38.0883 1660 \Device\Harddisk0\DR0:
13:09:38.0883 1660 MBR partitions:
13:09:38.0883 1660 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1389000, BlocksNum 0x16115800
13:09:38.0883 1660 ============================================================
13:09:38.0898 1660 C: <-> \Device\Harddisk0\DR0\Partition1
13:09:38.0898 1660 ============================================================
13:09:38.0898 1660 Initialize success
13:09:38.0898 1660 ============================================================
13:09:43.0563 5744 ============================================================
13:09:43.0563 5744 Scan started
13:09:43.0563 5744 Mode: Manual;
13:09:43.0563 5744 ============================================================
13:09:43.0859 5744 ================ Scan system memory ========================
13:09:43.0859 5744 System memory - ok
13:09:43.0859 5744 ================ Scan services =============================
13:09:44.0015 5744 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
13:09:44.0015 5744 ACPI - ok
13:09:44.0062 5744 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:09:44.0062 5744 adp94xx - ok
13:09:44.0093 5744 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:09:44.0109 5744 adpahci - ok
13:09:44.0124 5744 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:09:44.0140 5744 adpu160m - ok
13:09:44.0155 5744 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:09:44.0171 5744 adpu320 - ok
13:09:44.0280 5744 [ 609A6F49B6AF0F25837F8A0EDDDB0745 ] ADSMService C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
13:09:44.0296 5744 ADSMService - ok
13:09:44.0311 5744 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:09:44.0327 5744 AeLookupSvc - ok
13:09:44.0405 5744 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
13:09:44.0405 5744 AFD - ok
13:09:44.0452 5744 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:09:44.0452 5744 agp440 - ok
13:09:44.0499 5744 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:09:44.0499 5744 aic78xx - ok
13:09:44.0530 5744 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:09:44.0530 5744 ALG - ok
13:09:44.0545 5744 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:09:44.0545 5744 aliide - ok
13:09:44.0592 5744 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:09:44.0592 5744 amdagp - ok
13:09:44.0608 5744 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:09:44.0608 5744 amdide - ok
13:09:44.0639 5744 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:09:44.0639 5744 AmdK7 - ok
13:09:44.0655 5744 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:09:44.0655 5744 AmdK8 - ok
13:09:44.0701 5744 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:09:44.0701 5744 Appinfo - ok
13:09:44.0733 5744 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:09:44.0733 5744 arc - ok
13:09:44.0764 5744 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:09:44.0779 5744 arcsas - ok
13:09:44.0826 5744 [ 4385E371C25C94C804E9D3152BD9E1F7 ] AsDsm C:\Windows\system32\drivers\AsDsm.sys
13:09:44.0842 5744 AsDsm - ok
13:09:44.0904 5744 [ 5A055A4777CBBC8845DD598CB2EEBF69 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
13:09:44.0920 5744 ASLDRService - ok
13:09:44.0935 5744 [ 7B4D08D2017AC06689D422E06C43F0AA ] ASMMAP C:\Program Files\ATKGFNEX\ASMMAP.sys
13:09:44.0935 5744 ASMMAP - ok
13:09:45.0045 5744 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:09:45.0216 5744 aspnet_state - ok
13:09:45.0263 5744 [ CCDA8D84FD02AEC52E62F296433AE9DC ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
13:09:45.0263 5744 aswFsBlk - ok
13:09:45.0310 5744 [ A65FC444F7660F0CAC9A9E22203FD4BA ] aswFW C:\Windows\system32\drivers\aswFW.sys
13:09:45.0310 5744 aswFW - ok
13:09:45.0341 5744 [ 4691B3FE3717F9D9C64A5282C8543D4D ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
13:09:45.0341 5744 aswKbd - ok
13:09:45.0357 5744 [ A6E20E62871A28A0F1C05B1681848FA7 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
13:09:45.0357 5744 aswMonFlt - ok
13:09:45.0372 5744 [ 7B948E3657BEA62E437BC46CA6EF6012 ] aswNdis C:\Windows\system32\DRIVERS\aswNdis.sys
13:09:45.0372 5744 aswNdis - ok
13:09:45.0388 5744 [ 672A45E2AA1FA8178DB8CF1A39BEFC83 ] aswNdis2 C:\Windows\system32\drivers\aswNdis2.sys
13:09:45.0388 5744 aswNdis2 - ok
13:09:45.0403 5744 [ C1A411B7CCD604554D96EFDAC2F83617 ] AswRdr C:\Windows\system32\drivers\AswRdr.sys
13:09:45.0403 5744 AswRdr - ok
13:09:45.0419 5744 [ 657A61979F40D67CA29716149766FFA7 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
13:09:45.0419 5744 aswRvrt - ok
13:09:45.0466 5744 [ 0E604867FC28F00D91CB0B00D2EC830D ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
13:09:45.0481 5744 aswSnx - ok
13:09:45.0528 5744 [ 6FC4AA106AA505394C908D37CCCB9148 ] aswSP C:\Windows\system32\drivers\aswSP.sys
13:09:45.0528 5744 aswSP - ok
13:09:45.0544 5744 [ 33E21FFB063CA6C7E00D568467DC72E4 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
13:09:45.0544 5744 aswTdi - ok
13:09:45.0575 5744 [ EDB0C9BA44B748E420CCA989FD8B826E ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
13:09:45.0575 5744 aswVmm - ok
13:09:45.0622 5744 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:09:45.0637 5744 AsyncMac - ok
13:09:45.0637 5744 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:09:45.0637 5744 atapi - ok
13:09:45.0700 5744 [ 4DF523F49694B2884F8E5D870BF3E253 ] athr C:\Windows\system32\DRIVERS\athr.sys
13:09:45.0747 5744 athr - ok
13:09:45.0778 5744 [ 7C157574A181B19B9DCF5F339E25337E ] ATKGFNEXSrv C:\Program Files\ATKGFNEX\GFNEXSrv.exe
13:09:45.0778 5744 ATKGFNEXSrv - ok
13:09:45.0825 5744 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:09:45.0825 5744 AudioEndpointBuilder - ok
13:09:45.0840 5744 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:09:45.0856 5744 Audiosrv - ok
13:09:45.0949 5744 [ 41735B82DB57E4EBE9504EC400FD120E ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
13:09:45.0949 5744 avast! Antivirus - ok
13:09:46.0012 5744 [ DA387EDDBA421A7A8132E256343C2799 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
13:09:46.0012 5744 avast! Firewall - ok
13:09:46.0043 5744 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:09:46.0059 5744 Beep - ok
13:09:46.0105 5744 [ 8582E233C346AEFE759833E8A30DD697 ] BFE C:\Windows\System32\bfe.dll
13:09:46.0105 5744 BFE - ok
13:09:46.0215 5744 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
13:09:46.0308 5744 BITS - ok
13:09:46.0339 5744 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:09:46.0355 5744 blbdrive - ok
13:09:46.0386 5744 [ 74B442B2BE1260B7588C136177CEAC66 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:09:46.0386 5744 bowser - ok
13:09:46.0417 5744 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:09:46.0417 5744 BrFiltLo - ok
13:09:46.0449 5744 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:09:46.0449 5744 BrFiltUp - ok
13:09:46.0527 5744 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:09:46.0542 5744 Browser - ok
13:09:46.0558 5744 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:09:46.0573 5744 Brserid - ok
13:09:46.0573 5744 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:09:46.0589 5744 BrSerWdm - ok
13:09:46.0589 5744 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:09:46.0605 5744 BrUsbMdm - ok
13:09:46.0605 5744 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:09:46.0620 5744 BrUsbSer - ok
13:09:46.0651 5744 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
13:09:46.0651 5744 BTHMODEM - ok
13:09:46.0683 5744 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:09:46.0683 5744 cdfs - ok
13:09:46.0714 5744 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:09:46.0714 5744 cdrom - ok
13:09:46.0745 5744 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
13:09:46.0761 5744 CertPropSvc - ok
13:09:46.0776 5744 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
13:09:46.0776 5744 circlass - ok
13:09:46.0792 5744 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
13:09:46.0823 5744 CLFS - ok
13:09:46.0885 5744 [ A4AF4201BD519971F8F34724F3CA9DBB ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:09:46.0901 5744 clr_optimization_v2.0.50727_32 - ok
13:09:46.0995 5744 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:09:47.0026 5744 clr_optimization_v4.0.30319_32 - ok
13:09:47.0057 5744 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:09:47.0057 5744 CmBatt - ok
13:09:47.0088 5744 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:09:47.0088 5744 cmdide - ok
13:09:47.0119 5744 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:09:47.0119 5744 Compbatt - ok
13:09:47.0119 5744 COMSysApp - ok
13:09:47.0135 5744 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:09:47.0135 5744 crcdisk - ok
13:09:47.0166 5744 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:09:47.0166 5744 Crusoe - ok
13:09:47.0229 5744 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:09:47.0275 5744 CryptSvc - ok
13:09:47.0338 5744 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:09:47.0431 5744 DcomLaunch - ok
13:09:47.0525 5744 [ 105108175F6E49E41713E503599B6E72 ] desksvc C:\Program Files\Desk 365\deskSvc.exe
13:09:47.0556 5744 desksvc - ok
13:09:47.0587 5744 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:09:47.0603 5744 DfsC - ok
13:09:47.0681 5744 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
13:09:47.0743 5744 DFSR - ok
13:09:47.0806 5744 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:09:47.0837 5744 Dhcp - ok
13:09:47.0884 5744 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
13:09:47.0884 5744 disk - ok
13:09:47.0931 5744 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:09:47.0962 5744 Dnscache - ok
13:09:48.0009 5744 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
13:09:48.0024 5744 dot3svc - ok
13:09:48.0055 5744 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:09:48.0133 5744 DPS - ok
13:09:48.0149 5744 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:09:48.0165 5744 drmkaud - ok
13:09:48.0289 5744 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:09:48.0321 5744 DXGKrnl - ok
13:09:48.0336 5744 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:09:48.0352 5744 E1G60 - ok
13:09:48.0352 5744 EagleXNt - ok
13:09:48.0399 5744 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:09:48.0430 5744 EapHost - ok
13:09:48.0461 5744 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:09:48.0477 5744 Ecache - ok
13:09:48.0726 5744 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:09:48.0742 5744 ehRecvr - ok
13:09:48.0773 5744 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:09:48.0789 5744 ehSched - ok
13:09:48.0804 5744 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:09:48.0804 5744 ehstart - ok
13:09:48.0851 5744 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:09:48.0867 5744 elxstor - ok
13:09:48.0929 5744 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:09:48.0991 5744 EMDMgmt - ok
13:09:49.0023 5744 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:09:49.0023 5744 ErrDev - ok
13:09:49.0288 5744 [ A048327067D7BAB53402B0CDC5A11754 ] eSafeSvc C:\ProgramData\eSafe\eGdpSvc.exe
13:09:49.0335 5744 eSafeSvc - ok
13:09:49.0381 5744 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
13:09:49.0413 5744 EventSystem - ok
13:09:49.0459 5744 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
13:09:49.0475 5744 exfat - ok
13:09:49.0506 5744 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:09:49.0522 5744 fastfat - ok
13:09:49.0553 5744 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:09:49.0553 5744 fdc - ok
13:09:49.0584 5744 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:09:49.0631 5744 fdPHost - ok
13:09:49.0662 5744 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:09:49.0709 5744 FDResPub - ok
13:09:49.0725 5744 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:09:49.0725 5744 FileInfo - ok
13:09:49.0740 5744 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:09:49.0756 5744 Filetrace - ok
13:09:49.0771 5744 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:09:49.0771 5744 flpydisk - ok
13:09:49.0803 5744 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:09:49.0818 5744 FltMgr - ok
13:09:49.0865 5744 [ 993883524AA9CF1C90E1545411A9AC9C ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:09:49.0881 5744 FontCache3.0.0.0 - ok
13:09:49.0896 5744 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:09:49.0896 5744 Fs_Rec - ok
13:09:49.0927 5744 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:09:49.0943 5744 gagp30kx - ok
13:09:49.0990 5744 [ 31B40F40E09513ADDC460F6A297AD474 ] ghaio C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
13:09:49.0990 5744 ghaio - ok
13:09:50.0068 5744 [ 9E37E0C528E1E3A79E215B6A4EEA2143 ] GoogleDesktopManager-092308-165331 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
13:09:50.0083 5744 GoogleDesktopManager-092308-165331 - ok
13:09:50.0208 5744 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
13:09:50.0255 5744 gpsvc - ok
13:09:50.0286 5744 [ 649F407A844DDE2B97BC086AF97D663B ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
13:09:50.0286 5744 gusvc - ok
13:09:50.0333 5744 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:09:50.0349 5744 HdAudAddService - ok
13:09:50.0364 5744 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:09:50.0364 5744 HDAudBus - ok
13:09:50.0395 5744 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:09:50.0395 5744 HidBth - ok
13:09:50.0411 5744 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
13:09:50.0427 5744 HidIr - ok
13:09:50.0458 5744 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
13:09:50.0505 5744 hidserv - ok
13:09:50.0520 5744 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:09:50.0520 5744 HidUsb - ok
13:09:50.0551 5744 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:09:50.0598 5744 hkmsvc - ok
13:09:50.0614 5744 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:09:50.0629 5744 HpCISSs - ok
13:09:50.0661 5744 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:09:50.0676 5744 HTTP - ok
13:09:50.0692 5744 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:09:50.0692 5744 i2omp - ok
13:09:50.0739 5744 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:09:50.0739 5744 i8042prt - ok
13:09:50.0770 5744 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
13:09:50.0785 5744 iaStor - ok
13:09:50.0848 5744 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:09:50.0879 5744 iaStorV - ok
13:09:50.0941 5744 [ E7CC3AEAED9893A88876744CD439F76C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:09:51.0019 5744 idsvc - ok
13:09:51.0441 5744 [ 9378D57E2B96C0A185D844770AD49948 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
13:09:51.0519 5744 igfx - ok
13:09:51.0550 5744 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:09:51.0565 5744 iirsp - ok
13:09:51.0597 5744 [ A3BC480A2BF8AA8E4DABD2D5DCE0AFAC ] IKEEXT C:\Windows\System32\ikeext.dll
13:09:51.0659 5744 IKEEXT - ok
13:09:51.0784 5744 [ 4E38A2883DF3BA382A59132B3E7D709E ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:09:51.0846 5744 IntcAzAudAddService - ok
13:09:51.0877 5744 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:09:51.0893 5744 intelide - ok
13:09:51.0909 5744 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:09:51.0924 5744 intelppm - ok
13:09:51.0955 5744 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:09:51.0987 5744 IPBusEnum - ok
13:09:52.0018 5744 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:09:52.0018 5744 IpFilterDriver - ok
13:09:52.0049 5744 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:09:52.0143 5744 iphlpsvc - ok
13:09:52.0143 5744 IpInIp - ok
13:09:52.0174 5744 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:09:52.0174 5744 IPMIDRV - ok
13:09:52.0205 5744 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:09:52.0205 5744 IPNAT - ok
13:09:52.0221 5744 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:09:52.0236 5744 IRENUM - ok
13:09:52.0252 5744 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:09:52.0252 5744 isapnp - ok
13:09:52.0299 5744 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:09:52.0330 5744 iScsiPrt - ok
13:09:52.0345 5744 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:09:52.0345 5744 iteatapi - ok
13:09:52.0361 5744 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:09:52.0377 5744 iteraid - ok
13:09:52.0392 5744 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:09:52.0392 5744 kbdclass - ok
13:09:52.0423 5744 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:09:52.0423 5744 kbdhid - ok
13:09:52.0470 5744 [ CC2A86D7BBF14977340DCA61BBCBA771 ] kbfiltr C:\Windows\system32\DRIVERS\kbfiltr.sys
13:09:52.0470 5744 kbfiltr - ok
13:09:52.0501 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
13:09:52.0548 5744 KeyIso - ok
13:09:52.0579 5744 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:09:52.0626 5744 KSecDD - ok
13:09:52.0657 5744 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:09:52.0735 5744 KtmRm - ok
13:09:52.0767 5744 [ 05CE901A4472B3FBF9407C94AD1DB693 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:09:52.0860 5744 LanmanServer - ok
13:09:52.0891 5744 [ DEC1A338B86C5D582C25C40836DD76C3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:09:53.0001 5744 LanmanWorkstation - ok
13:09:53.0063 5744 [ ABF90FC5A127F481219B873C1B8DFC1C ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:09:53.0079 5744 LightScribeService - ok
13:09:53.0125 5744 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:09:53.0141 5744 lltdio - ok
13:09:53.0172 5744 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:09:53.0235 5744 lltdsvc - ok
13:09:53.0250 5744 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:09:53.0297 5744 lmhosts - ok
13:09:53.0328 5744 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:09:53.0344 5744 LSI_FC - ok
13:09:53.0375 5744 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:09:53.0375 5744 LSI_SAS - ok
13:09:53.0391 5744 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:09:53.0406 5744 LSI_SCSI - ok
13:09:53.0422 5744 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:09:53.0437 5744 luafv - ok
13:09:53.0469 5744 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:09:53.0531 5744 Mcx2Svc - ok
13:09:53.0578 5744 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:09:53.0578 5744 megasas - ok
13:09:53.0609 5744 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:09:53.0640 5744 MegaSR - ok
13:09:53.0671 5744 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:09:53.0734 5744 MMCSS - ok
13:09:53.0765 5744 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:09:53.0765 5744 Modem - ok
13:09:53.0781 5744 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:09:53.0796 5744 monitor - ok
13:09:53.0812 5744 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:09:53.0827 5744 mouclass - ok
13:09:53.0827 5744 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:09:53.0843 5744 mouhid - ok
13:09:53.0859 5744 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:09:53.0874 5744 MountMgr - ok
13:09:53.0905 5744 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
13:09:53.0905 5744 mpio - ok
13:09:53.0937 5744 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:09:53.0937 5744 mpsdrv - ok
13:09:53.0968 5744 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
13:09:54.0046 5744 MpsSvc - ok
13:09:54.0061 5744 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:09:54.0077 5744 Mraid35x - ok
13:09:54.0093 5744 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:09:54.0108 5744 MRxDAV - ok
13:09:54.0108 5744 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:09:54.0124 5744 mrxsmb - ok
13:09:54.0139 5744 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:09:54.0155 5744 mrxsmb10 - ok
13:09:54.0171 5744 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:09:54.0186 5744 mrxsmb20 - ok
13:09:54.0202 5744 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
13:09:54.0217 5744 msahci - ok
13:09:54.0249 5744 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:09:54.0249 5744 msdsm - ok
13:09:54.0264 5744 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:09:54.0342 5744 MSDTC - ok
13:09:54.0358 5744 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:09:54.0389 5744 Msfs - ok
13:09:54.0405 5744 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:09:54.0405 5744 msisadrv - ok
13:09:54.0436 5744 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:09:54.0498 5744 MSiSCSI - ok
13:09:54.0498 5744 msiserver - ok
13:09:54.0545 5744 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:09:54.0545 5744 MSKSSRV - ok
13:09:54.0561 5744 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:09:54.0561 5744 MSPCLOCK - ok
13:09:54.0607 5744 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:09:54.0623 5744 MSPQM - ok
13:09:54.0670 5744 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:09:54.0685 5744 MsRPC - ok
13:09:54.0701 5744 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:09:54.0717 5744 mssmbios - ok
13:09:54.0748 5744 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:09:54.0748 5744 MSTEE - ok
13:09:54.0810 5744 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
13:09:54.0810 5744 MTsensor - ok
13:09:54.0826 5744 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
13:09:54.0841 5744 Mup - ok
13:09:54.0888 5744 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
13:09:54.0966 5744 napagent - ok
13:09:55.0013 5744 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:09:55.0029 5744 NativeWifiP - ok
13:09:55.0060 5744 [ C8560010A542B5DCA94C62468DC20784 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:09:55.0091 5744 NDIS - ok
13:09:55.0107 5744 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:09:55.0107 5744 NdisTapi - ok
13:09:55.0122 5744 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:09:55.0138 5744 Ndisuio - ok
13:09:55.0138 5744 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:09:55.0153 5744 NdisWan - ok
13:09:55.0169 5744 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:09:55.0169 5744 NDProxy - ok
13:09:55.0185 5744 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:09:55.0200 5744 NetBIOS - ok
13:09:55.0216 5744 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:09:55.0231 5744 netbt - ok
13:09:55.0247 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
13:09:55.0278 5744 Netlogon - ok
13:09:55.0325 5744 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:09:55.0387 5744 Netman - ok
13:09:55.0419 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0419 5744 NetMsmqActivator - ok
13:09:55.0434 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0434 5744 NetPipeActivator - ok
13:09:55.0465 5744 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:09:55.0543 5744 netprofm - ok
13:09:55.0559 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0559 5744 NetTcpActivator - ok
13:09:55.0575 5744 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:09:55.0590 5744 NetTcpPortSharing - ok
13:09:55.0637 5744 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:09:55.0653 5744 nfrd960 - ok
13:09:55.0699 5744 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:09:55.0762 5744 NlaSvc - ok
13:09:55.0777 5744 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:09:55.0793 5744 Npfs - ok
13:09:55.0824 5744 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:09:55.0902 5744 nsi - ok
13:09:55.0918 5744 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:09:55.0918 5744 nsiproxy - ok
13:09:56.0027 5744 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:09:56.0074 5744 Ntfs - ok
13:09:56.0089 5744 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:09:56.0105 5744 ntrigdigi - ok
13:09:56.0136 5744 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:09:56.0136 5744 Null - ok
13:09:56.0167 5744 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:09:56.0183 5744 nvraid - ok
13:09:56.0199 5744 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:09:56.0199 5744 nvstor - ok
13:09:56.0230 5744 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:09:56.0230 5744 nv_agp - ok
13:09:56.0245 5744 NwlnkFlt - ok
13:09:56.0261 5744 NwlnkFwd - ok
13:09:56.0495 5744 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:09:56.0542 5744 odserv - ok
13:09:56.0573 5744 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
13:09:56.0573 5744 ohci1394 - ok
13:09:56.0620 5744 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:09:56.0620 5744 ose - ok
13:09:56.0869 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:09:56.0979 5744 p2pimsvc - ok
13:09:57.0010 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
13:09:57.0072 5744 p2psvc - ok
13:09:57.0166 5744 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:09:57.0181 5744 Parport - ok
13:09:57.0213 5744 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:09:57.0213 5744 partmgr - ok
13:09:57.0228 5744 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:09:57.0228 5744 Parvdm - ok
13:09:57.0275 5744 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:09:57.0337 5744 PcaSvc - ok
13:09:57.0369 5744 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
13:09:57.0384 5744 pci - ok
13:09:57.0415 5744 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
13:09:57.0415 5744 pciide - ok
13:09:57.0462 5744 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:09:57.0462 5744 pcmcia - ok
13:09:57.0525 5744 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:09:57.0571 5744 PEAUTH - ok
13:09:57.0930 5744 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:09:58.0055 5744 pla - ok
13:09:58.0133 5744 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:09:58.0227 5744 PlugPlay - ok
13:09:58.0273 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:09:58.0336 5744 PNRPAutoReg - ok
13:09:58.0507 5744 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:09:58.0570 5744 PNRPsvc - ok
13:09:58.0695 5744 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:09:58.0788 5744 PolicyAgent - ok
13:09:58.0819 5744 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:09:58.0835 5744 PptpMiniport - ok
13:09:58.0851 5744 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
13:09:58.0851 5744 Processor - ok
13:09:58.0897 5744 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
13:09:58.0991 5744 ProfSvc - ok
13:09:59.0007 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:09:59.0038 5744 ProtectedStorage - ok
13:09:59.0069 5744 [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:09:59.0069 5744 PSched - ok
13:09:59.0100 5744 [ 49452BFCEC22F36A7A9B9C2181BC3042 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
13:09:59.0116 5744 PxHelp20 - ok
13:09:59.0178 5744 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:09:59.0256 5744 ql2300 - ok
13:09:59.0272 5744 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:09:59.0272 5744 ql40xx - ok
13:09:59.0319 5744 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:09:59.0397 5744 QWAVE - ok
13:09:59.0412 5744 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:09:59.0428 5744 QWAVEdrv - ok
13:09:59.0443 5744 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:09:59.0459 5744 RasAcd - ok
13:09:59.0475 5744 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:09:59.0568 5744 RasAuto - ok
13:09:59.0599 5744 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:09:59.0615 5744 Rasl2tp - ok
13:09:59.0631 5744 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
13:09:59.0724 5744 RasMan - ok
13:09:59.0740 5744 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:09:59.0755 5744 RasPppoe - ok
13:09:59.0755 5744 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:09:59.0771 5744 RasSstp - ok
13:09:59.0802 5744 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:09:59.0802 5744 rdbss - ok
13:09:59.0818 5744 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:09:59.0818 5744 RDPCDD - ok
13:09:59.0849 5744 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:09:59.0865 5744 rdpdr - ok
13:09:59.0880 5744 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:09:59.0880 5744 RDPENCDD - ok
13:09:59.0911 5744 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:09:59.0927 5744 RDPWD - ok
13:09:59.0958 5744 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:10:00.0036 5744 RemoteAccess - ok
13:10:00.0067 5744 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:10:00.0145 5744 RemoteRegistry - ok
13:10:00.0208 5744 [ C35CA13D3627EBD9DD12A23CE781BC3D ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
13:10:00.0223 5744 rimmptsk - ok
13:10:00.0239 5744 [ C398BCA91216755B098679A8DA8A2300 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
13:10:00.0255 5744 rimsptsk - ok
13:10:00.0286 5744 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:10:00.0333 5744 RpcLocator - ok
13:10:00.0364 5744 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
13:10:00.0426 5744 RpcSs - ok
13:10:00.0535 5744 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:10:00.0535 5744 rspndr - ok
13:10:00.0582 5744 [ 5C5612756B380BCEDBF566A780FF9AFE ] RTL8023xp C:\Windows\system32\DRIVERS\Rtnicxp.sys
13:10:00.0582 5744 RTL8023xp - ok
13:10:00.0598 5744 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
13:10:00.0645 5744 SamSs - ok
13:10:00.0660 5744 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:10:00.0691 5744 sbp2port - ok
13:10:00.0738 5744 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:10:00.0832 5744 SCardSvr - ok
13:10:00.0941 5744 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
13:10:01.0066 5744 Schedule - ok
13:10:01.0081 5744 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
13:10:01.0097 5744 SCPolicySvc - ok
13:10:01.0144 5744 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
13:10:01.0175 5744 sdbus - ok
13:10:01.0222 5744 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:10:01.0284 5744 SDRSVC - ok
13:10:01.0300 5744 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:10:01.0315 5744 secdrv - ok
13:10:01.0331 5744 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:10:01.0425 5744 seclogon - ok
13:10:01.0456 5744 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
13:10:01.0534 5744 SENS - ok
13:10:01.0549 5744 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
13:10:01.0565 5744 Serenum - ok
13:10:01.0596 5744 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:10:01.0596 5744 Serial - ok
13:10:01.0627 5744 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:10:01.0627 5744 sermouse - ok
13:10:01.0674 5744 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:10:01.0783 5744 SessionEnv - ok
13:10:01.0799 5744 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:10:01.0815 5744 sffdisk - ok
13:10:01.0830 5744 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:10:01.0846 5744 sffp_mmc - ok
13:10:01.0861 5744 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:10:01.0877 5744 sffp_sd - ok
13:10:01.0908 5744 [ C33BFBD6E9E41FCD9FFEF9729E9FAED6 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
13:10:01.0908 5744 sfloppy - ok
13:10:02.0142 5744 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:10:02.0189 5744 SharedAccess - ok
13:10:02.0220 5744 [ 27F10F348E508243F6254846F8370D0D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:10:02.0314 5744 ShellHWDetection - ok
13:10:02.0361 5744 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:10:02.0361 5744 sisagp - ok
13:10:02.0376 5744 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:10:02.0392 5744 SiSRaid2 - ok
13:10:02.0407 5744 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:10:02.0423 5744 SiSRaid4 - ok
13:10:02.0595 5744 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
13:10:02.0688 5744 Skype C2C Service - ok
13:10:02.0704 5744 [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:10:02.0704 5744 SkypeUpdate - ok
13:10:03.0141 5744 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
13:10:03.0297 5744 slsvc - ok
13:10:03.0312 5744 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:10:03.0421 5744 SLUINotify - ok
13:10:03.0437 5744 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:10:03.0437 5744 Smb - ok
13:10:03.0577 5744 [ D9BFD2298F5CF116D8EAAE3B02DCEE2E ] smserial C:\Windows\system32\DRIVERS\smserial.sys
13:10:03.0624 5744 smserial - ok
13:10:03.0671 5744 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:10:03.0765 5744 SNMPTRAP - ok
13:10:03.0780 5744 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:10:03.0796 5744 spldr - ok
13:10:03.0827 5744 [ 739DB668DBD812285ECC553E64A5E212 ] spmgr C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
13:10:03.0827 5744 spmgr - ok
13:10:03.0874 5744 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
13:10:03.0952 5744 Spooler - ok
13:10:03.0983 5744 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:10:03.0999 5744 srv - ok
13:10:04.0030 5744 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:10:04.0045 5744 srv2 - ok
13:10:04.0077 5744 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:10:04.0077 5744 srvnet - ok
13:10:04.0123 5744 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:10:04.0217 5744 SSDPSRV - ok
13:10:04.0264 5744 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:10:04.0357 5744 SstpSvc - ok
13:10:04.0420 5744 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
13:10:04.0560 5744 stisvc - ok
13:10:04.0591 5744 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:10:04.0607 5744 swenum - ok
13:10:04.0701 5744 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
13:10:04.0794 5744 swprv - ok
13:10:04.0825 5744 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:10:04.0841 5744 Symc8xx - ok
13:10:04.0857 5744 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:10:04.0857 5744 Sym_hi - ok
13:10:04.0872 5744 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:10:04.0872 5744 Sym_u3 - ok
13:10:04.0903 5744 [ 55F6E55CC2430CA8713387106FA79817 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
13:10:04.0919 5744 SynTP - ok
13:10:04.0966 5744 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
13:10:05.0075 5744 SysMain - ok
13:10:05.0091 5744 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:10:05.0169 5744 TabletInputService - ok
13:10:05.0200 5744 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
13:10:05.0309 5744 TapiSrv - ok
13:10:05.0309 5744 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:10:05.0418 5744 TBS - ok
13:10:05.0496 5744 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:10:05.0543 5744 Tcpip - ok
13:10:05.0590 5744 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:10:05.0605 5744 Tcpip6 - ok
13:10:05.0637 5744 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:10:05.0668 5744 tcpipreg - ok
13:10:05.0683 5744 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:10:05.0699 5744 TDPIPE - ok
13:10:05.0730 5744 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:10:05.0730 5744 TDTCP - ok
13:10:05.0761 5744 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:10:05.0761 5744 tdx - ok
13:10:05.0777 5744 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:10:05.0808 5744 TermDD - ok
13:10:05.0839 5744 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
13:10:05.0980 5744 TermService - ok
13:10:06.0011 5744 [ 27F10F348E508243F6254846F8370D0D ] Themes C:\Windows\system32\shsvcs.dll
13:10:06.0089 5744 Themes - ok
13:10:06.0120 5744 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:10:06.0167 5744 THREADORDER - ok
13:10:06.0214 5744 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:10:06.0307 5744 TrkWks - ok
13:10:06.0354 5744 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:10:06.0370 5744 TrustedInstaller - ok
13:10:06.0385 5744 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:10:06.0401 5744 tssecsrv - ok
13:10:06.0432 5744 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:10:06.0432 5744 tunmp - ok
13:10:06.0463 5744 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:10:06.0495 5744 tunnel - ok
13:10:06.0526 5744 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:10:06.0541 5744 uagp35 - ok
13:10:06.0557 5744 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:10:06.0557 5744 udfs - ok
13:10:06.0604 5744 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:10:06.0713 5744 UI0Detect - ok
13:10:06.0729 5744 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:10:06.0744 5744 uliagpkx - ok
13:10:06.0760 5744 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:10:06.0775 5744 uliahci - ok
13:10:06.0791 5744 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:10:06.0807 5744 UlSata - ok
13:10:06.0822 5744 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:10:06.0838 5744 ulsata2 - ok
13:10:06.0853 5744 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:10:06.0869 5744 umbus - ok
13:10:06.0916 5744 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:10:07.0056 5744 upnphost - ok
13:10:07.0119 5744 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:10:07.0134 5744 usbccgp - ok
13:10:07.0165 5744 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:10:07.0181 5744 usbcir - ok
13:10:07.0212 5744 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:10:07.0228 5744 usbehci - ok
13:10:07.0259 5744 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:10:07.0275 5744 usbhub - ok
13:10:07.0290 5744 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:10:07.0306 5744 usbohci - ok
13:10:07.0321 5744 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
13:10:07.0321 5744 usbprint - ok
13:10:07.0337 5744 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:10:07.0353 5744 USBSTOR - ok
13:10:07.0368 5744 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:10:07.0384 5744 usbuhci - ok
13:10:07.0415 5744 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:10:07.0431 5744 usbvideo - ok
13:10:07.0462 5744 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
13:10:07.0555 5744 UxSms - ok
13:10:07.0587 5744 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
13:10:07.0696 5744 vds - ok
13:10:07.0727 5744 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:10:07.0743 5744 vga - ok
13:10:07.0774 5744 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:10:07.0774 5744 VgaSave - ok
13:10:07.0805 5744 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:10:07.0805 5744 viaagp - ok
13:10:07.0821 5744 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:10:07.0836 5744 ViaC7 - ok
13:10:07.0852 5744 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:10:07.0867 5744 viaide - ok
13:10:07.0883 5744 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:10:07.0899 5744 volmgr - ok
13:10:07.0899 5744 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:10:07.0914 5744 volmgrx - ok
13:10:07.0930 5744 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:10:07.0945 5744 volsnap - ok
13:10:07.0977 5744 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:10:07.0977 5744 vsmraid - ok
13:10:08.0164 5744 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
13:10:08.0289 5744 VSS - ok
13:10:08.0335 5744 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
13:10:08.0476 5744 W32Time - ok
13:10:08.0491 5744 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:10:08.0507 5744 WacomPen - ok
13:10:08.0523 5744 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:10:08.0538 5744 Wanarp - ok
13:10:08.0538 5744 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:10:08.0554 5744 Wanarpv6 - ok
13:10:08.0601 5744 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:10:08.0694 5744 wcncsvc - ok
13:10:08.0710 5744 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:10:08.0850 5744 WcsPlugInService - ok
13:10:08.0897 5744 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:10:08.0913 5744 Wd - ok
13:10:08.0944 5744 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:10:08.0959 5744 Wdf01000 - ok
13:10:08.0991 5744 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:10:09.0100 5744 WdiServiceHost - ok
13:10:09.0100 5744 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:10:09.0193 5744 WdiSystemHost - ok
13:10:09.0256 5744 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
13:10:09.0427 5744 WebClient - ok
13:10:09.0459 5744 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:10:09.0583 5744 Wecsvc - ok
13:10:09.0615 5744 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:10:09.0708 5744 wercplsupport - ok
13:10:09.0739 5744 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
13:10:09.0895 5744 WerSvc - ok
13:10:09.0989 5744 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:10:09.0989 5744 WinDefend - ok
13:10:10.0020 5744 WinHttpAutoProxySvc - ok
13:10:10.0083 5744 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:10:10.0129 5744 Winmgmt - ok
13:10:10.0192 5744 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
13:10:10.0348 5744 WinRM - ok
13:10:10.0426 5744 [ 4B40FF01DB5357299DCBDB5A5746AD21 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:10:10.0551 5744 Wlansvc - ok
13:10:10.0566 5744 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
13:10:10.0582 5744 WmiAcpi - ok
13:10:10.0660 5744 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:10:10.0675 5744 wmiApSrv - ok
13:10:10.0753 5744 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:10:10.0800 5744 WMPNetworkSvc - ok
13:10:10.0847 5744 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:10:10.0987 5744 WPCSvc - ok
13:10:11.0034 5744 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:10:11.0128 5744 WPDBusEnum - ok
13:10:11.0221 5744 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:10:11.0284 5744 WPFFontCache_v0400 - ok
13:10:11.0315 5744 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:10:11.0315 5744 ws2ifsl - ok
13:10:11.0362 5744 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
13:10:11.0455 5744 wscsvc - ok
13:10:11.0471 5744 WSearch - ok
13:10:11.0705 5744 [ D79538B67FA641E986855DEF651E78FE ] wuauserv C:\Windows\system32\wuaueng.dll
13:10:11.0908 5744 wuauserv - ok
13:10:11.0939 5744 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:10:11.0939 5744 WUDFRd - ok
13:10:11.0970 5744 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:10:12.0064 5744 wudfsvc - ok
13:10:12.0126 5744 [ 7D1F3B131D503EF43EE594B5A2B9B427 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
13:10:12.0142 5744 yukonwlh - ok
13:10:12.0142 5744 ================ Scan global ===============================
13:10:12.0173 5744 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:10:12.0235 5744 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
13:10:12.0329 5744 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
13:10:12.0438 5744 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
13:10:12.0532 5744 [Global] - ok
13:10:12.0532 5744 ================ Scan MBR ==================================
13:10:12.0547 5744 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:10:13.0140 5744 \Device\Harddisk0\DR0 - ok
13:10:13.0140 5744 ================ Scan VBR ==================================
13:10:13.0187 5744 [ C74AF310874807A52CDDA6ED419FCD30 ] \Device\Harddisk0\DR0\Partition1
13:10:13.0203 5744 \Device\Harddisk0\DR0\Partition1 - ok
13:10:13.0203 5744 ============================================================
13:10:13.0203 5744 Scan finished
13:10:13.0203 5744 ============================================================
13:10:13.0234 5924 Detected object count: 0
13:10:13.0234 5924 Actual detected object count: 0
13:12:02.0096 4208 Deinitialize success
Re: prosím o kontrolu logu
ComboFix 13-04-15.01 - všichni 16.04.2013 13:29:37.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.1105 [GMT 2:00]
Spuštěný z: C:\Users\vÜichni\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\337
C:\Program Files\Common Files\337\libcef\1.1364.1123\icudt.dll
C:\Program Files\Common Files\337\libcef\1.1364.1123\libcef.dll
C:\Program Files\Common Files\337\libcef\1.1364.1123\locales\en-US.pak
C:\Windows\PFRO.log
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-16 do 2013-04-16 )))))))))))))))))))))))))))))))
2013-04-16 11:47:51 . 2013-04-16 11:47:51 -------- d-----w- C:\Users\Default\AppData\Local\temp
2013-04-15 10:17:00 . 2013-04-15 10:17:00 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-15 10:16:58 . 2013-04-15 16:33:37 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2013-04-15 10:16:58 . 2013-04-04 12:50:32 22856 ----a-w- C:\Windows\system32\drivers\mbam.sys
2013-04-13 11:02:00 . 2013-04-13 11:02:00 -------- d-----w- C:\Program Files\Trend Micro
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\VDLL.DLL
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\system32\runouce.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\rundll16.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\RUNDL132.EXE
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo1_.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo_1.exe
2013-04-12 07:26:58 . 2013-04-12 07:26:57 632064 ----a-w- C:\Windows\system32\msvcr80.dll
2013-04-12 07:26:56 . 2013-04-12 07:26:55 554240 ----a-w- C:\Windows\system32\msvcp80.dll
2013-04-12 07:26:55 . 2013-04-12 07:26:54 34048 ----a-w- C:\Windows\system32\eEmpty.exe
2013-04-12 07:26:51 . 2013-04-12 07:26:51 -------- d-----w- C:\Program Files\Common Files\MicroWorld
2013-04-12 07:26:43 . 2013-04-12 07:26:51 -------- d-----w- C:\ProgramData\MicroWorld
2013-04-12 07:21:21 . 2013-04-13 11:15:15 -------- d-----w- C:\Program Files\CCleaner
2013-04-11 18:28:03 . 2013-04-16 10:19:55 -------- d-----w- C:\ProgramData\eSafe
2013-04-11 18:27:36 . 2013-04-11 18:27:31 773712 ----a-w- C:\Windows\system32\msvcr100.dll
2013-04-11 18:27:36 . 2013-04-11 18:27:31 420944 ----a-w- C:\Windows\system32\msvcp100.dll
2013-04-11 18:27:33 . 2013-04-16 11:34:27 -------- d-----w- C:\Program Files\Desk 365
2013-04-11 17:22:14 . 2013-04-11 17:22:15 -------- dc-h--w- C:\ProgramData\{3F35882A-B5EA-473D-BCE8-67F488C1E747}
2013-04-11 17:21:53 . 2013-04-11 17:21:53 -------- dc----w- C:\ProgramData\{4EBE13A3-4899-48EA-B064-02551A69BCF6}
2013-04-11 16:57:23 . 2008-11-14 15:09:44 -------- d-----w- C:\Windows\system32\McAffe
2013-04-11 15:51:43 . 2010-04-14 17:46:15 80896 ----a-w- C:\Windows\system32\MSNP.ax
2013-04-11 15:51:38 . 2010-04-14 17:47:01 293376 ----a-w- C:\Windows\system32\psisdecd.dll
2013-04-11 15:51:37 . 2010-04-14 17:47:00 217088 ----a-w- C:\Windows\system32\psisrndr.ax
2013-04-11 15:46:45 . 2010-02-20 23:39:35 24064 ----a-w- C:\Windows\system32\nshhttp.dll
2013-04-11 15:46:43 . 2010-02-20 21:18:40 411136 ----a-w- C:\Windows\system32\drivers\http.sys
2013-04-11 15:46:42 . 2010-02-20 23:37:20 31232 ----a-w- C:\Windows\system32\httpapi.dll
2013-04-11 14:59:51 . 2013-03-06 22:33:23 199384 ----a-w- C:\Windows\system32\drivers\aswNdis2.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 21576 ----a-w- C:\Windows\system32\drivers\aswKbd.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 101656 ----a-w- C:\Windows\system32\drivers\aswFW.sys
2013-04-11 14:59:30 . 2013-03-06 22:11:20 12112 ----a-w- C:\Windows\system32\drivers\aswNdis.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 49760 ----a-w- C:\Windows\system32\drivers\aswRdr.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 368176 ----a-w- C:\Windows\system32\drivers\aswSP.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:22 29816 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 765736 ----a-w- C:\Windows\system32\drivers\aswSnx.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 62376 ----a-w- C:\Windows\system32\drivers\aswTdi.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 164736 ----a-w- C:\Windows\system32\drivers\aswVmm.sys
2013-04-11 14:54:41 . 2013-03-06 22:33:24 49248 ----a-w- C:\Windows\system32\drivers\aswRvrt.sys
2013-04-11 14:54:39 . 2013-03-06 22:33:23 66336 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2013-04-11 14:54:39 . 2013-03-06 22:32:42 228600 ----a-w- C:\Windows\system32\aswBoot.exe
2013-04-11 14:53:25 . 2013-03-06 22:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-04-11 14:53:00 . 2013-04-11 14:53:00 -------- d-----w- C:\Program Files\AVAST Software
2013-04-11 14:52:04 . 2013-04-11 14:53:00 -------- d-----w- C:\ProgramData\AVAST Software
2013-04-11 13:18:07 . 2013-04-11 13:18:08 -------- d-----w- C:\Minecraft_Backup
2013-04-11 12:56:30 . 2009-11-08 17:55:31 49472 ----a-w- C:\Windows\system32\netfxperf.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 99176 ----a-w- C:\Windows\system32\PresentationHostProxy.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 297808 ----a-w- C:\Windows\system32\mscoree.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 295264 ----a-w- C:\Windows\system32\PresentationHost.exe
2013-04-11 12:56:29 . 2009-11-08 17:55:31 1130824 ----a-w- C:\Windows\system32\dfshim.dll
2013-04-11 12:07:28 . 2013-04-11 12:07:28 -------- d-----w- C:\Program Files\Common Files\Java
2013-04-11 12:07:21 . 2013-04-11 12:06:39 861088 ----a-w- C:\Windows\system32\npDeployJava1.dll
2013-04-11 12:07:21 . 2013-04-11 12:06:38 782240 ----a-w- C:\Windows\system32\deployJava1.dll
2013-04-11 12:07:03 . 2013-04-11 12:06:47 94112 ----a-w- C:\Windows\system32\WindowsAccessBridge.dll
2013-04-11 12:06:34 . 2013-04-11 12:06:34 -------- d-----w- C:\Program Files\Java
2013-04-11 06:22:40 . 2010-10-28 12:56:58 2048 ----a-w- C:\Windows\system32\tzres.dll
2013-04-11 06:22:11 . 2011-04-14 14:24:14 75264 ----a-w- C:\Windows\system32\drivers\dfsc.sys
2013-04-11 06:20:49 . 2010-10-12 15:48:28 33280 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2013-04-11 06:20:49 . 2010-10-12 13:52:20 66048 ----a-w- C:\Program Files\Windows Mail\wabmig.exe
2013-04-11 06:20:49 . 2010-10-12 13:52:20 515584 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-04-11 06:19:53 . 2008-06-06 03:27:13 38912 ----a-w- C:\Windows\system32\xolehlp.dll
2013-04-11 06:19:53 . 2008-06-06 03:27:05 562176 ----a-w- C:\Windows\system32\msdtcprx.dll
2013-04-11 06:18:04 . 2010-05-27 19:16:09 81920 ----a-w- C:\Windows\system32\iccvid.dll
2013-04-11 06:17:11 . 2011-02-18 13:31:24 304640 ----a-w- C:\Windows\system32\drivers\srv.sys
2013-04-11 06:17:08 . 2011-07-06 14:56:47 213504 ----a-w- C:\Windows\system32\drivers\mrxsmb10.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:44 79360 ----a-w- C:\Windows\system32\drivers\mrxsmb20.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:35 105984 ----a-w- C:\Windows\system32\drivers\mrxsmb.sys
2013-04-11 06:17:06 . 2011-03-02 14:49:43 86528 ----a-w- C:\Windows\system32\dnsrslvr.dll
2013-04-11 06:17:06 . 2009-05-04 10:11:27 25088 ----a-w- C:\Windows\system32\dnscacheugc.exe
2013-04-11 06:17:03 . 2008-12-06 04:42:11 376832 ----a-w- C:\Windows\system32\winhttp.dll
2013-04-11 06:17:02 . 2010-04-05 16:07:19 67072 ----a-w- C:\Windows\system32\asycfilt.dll
2013-04-11 06:16:59 . 2009-07-17 14:35:11 71680 ----a-w- C:\Windows\system32\atl.dll
2013-04-11 06:16:06 . 2008-10-21 05:25:18 296960 ----a-w- C:\Windows\system32\gdi32.dll
2013-04-11 06:16:04 . 2010-08-17 13:32:33 126464 ----a-w- C:\Windows\system32\spoolsv.exe
2013-04-11 06:16:02 . 2011-05-02 16:00:55 766464 ----a-w- C:\Program Files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-04-11 06:16:00 . 2010-08-26 16:07:25 157184 ----a-w- C:\Windows\system32\t2embed.dll
2013-04-11 06:15:58 . 2011-06-02 12:59:29 2042368 ----a-w- C:\Windows\system32\win32k.sys
2013-04-11 06:15:56 . 2011-04-21 13:16:42 273408 ----a-w- C:\Windows\system32\drivers\afd.sys
2013-04-11 06:10:38 . 2010-12-14 15:49:30 1169408 ----a-w- C:\Windows\system32\sdclt.exe
2013-04-11 06:10:30 . 2010-06-17 17:15:33 10926592 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.dll
2013-04-11 06:10:25 . 2010-06-17 15:49:15 150016 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.exe
2013-04-11 06:10:19 . 2011-04-29 12:49:57 146432 ----a-w- C:\Windows\system32\drivers\srv2.sys
2013-04-11 06:10:19 . 2011-04-29 12:49:55 102400 ----a-w- C:\Windows\system32\drivers\srvnet.sys
2013-04-11 06:10:00 . 2009-04-23 12:42:53 636928 ----a-w- C:\Windows\system32\localspl.dll
2013-04-11 06:09:57 . 2010-12-20 15:39:14 563200 ----a-w- C:\Windows\system32\oleaut32.dll
2013-04-11 06:09:54 . 2010-04-05 16:08:52 317952 ----a-w- C:\Windows\system32\MP4SDECD.DLL
2013-04-11 06:09:50 . 2011-02-16 15:35:41 430080 ----a-w- C:\Windows\system32\vbscript.dll
2013-04-11 06:04:00 . 2010-06-18 16:43:54 36352 ----a-w- C:\Windows\system32\rtutils.dll
2013-04-11 06:02:59 . 2010-12-29 17:41:21 323072 ----a-w- C:\Windows\system32\sbe.dll
2013-04-11 06:01:15 . 2008-08-12 03:39:08 443392 ----a-w- C:\Windows\system32\win32spl.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 712704 ----a-w- C:\Windows\system32\WindowsCodecs.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 347136 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:09 425472 ----a-w- C:\Windows\system32\PhotoMetadataHandler.dll
2013-04-11 06:01:10 . 2010-10-18 14:01:05 81920 ----a-w- C:\Windows\system32\consent.exe
2013-04-11 06:01:06 . 2010-06-11 15:30:23 1257472 ----a-w- C:\Windows\system32\msxml3.dll
2013-04-11 06:01:03 . 2010-01-15 00:04:50 98304 ----a-w- C:\Windows\system32\cabview.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:07 125952 ----a-w- C:\Windows\system32\wersvc.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:02 147456 ----a-w- C:\Windows\system32\Faultrep.dll
2013-04-11 05:58:58 . 2011-04-20 14:47:25 375808 ----a-w- C:\Windows\system32\winsrv.dll
2013-04-11 05:56:59 . 2010-09-20 09:25:01 231936 ----a-w- C:\Windows\system32\msshsq.dll
2013-04-10 18:12:27 . 2013-04-10 18:12:27 -------- d-----w- C:\Program Files\Common Files\Skype
2013-04-10 18:12:09 . 2013-04-10 18:13:45 -------- d-----r- C:\Program Files\Skype
2013-04-10 18:11:05 . 2013-04-10 18:11:05 -------- d-----w- C:\Program Files\Seznam.cz
2013-04-10 18:10:35 . 2013-04-10 18:13:45 -------- d-----w- C:\ProgramData\Skype
2013-04-10 17:21:36 . 2009-09-10 15:21:15 1418752 ----a-w- C:\Program Files\Windows Media Player\setup_wm.exe
2013-04-10 17:21:34 . 2009-09-10 15:21:07 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2013-04-10 17:21:30 . 2009-09-10 15:21:05 168960 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\msdxm.ocx
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\dxmasf.dll
2013-04-10 17:21:29 . 2009-07-14 12:58:44 7680 ----a-w- C:\Windows\system32\spwmp.dll
2013-04-10 17:21:29 . 2009-07-14 10:59:32 107520 ----a-w- C:\Program Files\Windows Media Player\wmpconfig.exe
2013-04-10 17:21:29 . 2009-07-14 10:58:54 107520 ----a-w- C:\Program Files\Windows Media Player\wmpshare.exe
2013-04-10 17:21:27 . 2009-09-10 15:21:53 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2013-04-10 17:20:12 . 2009-12-28 12:32:32 31744 ----a-w- C:\Windows\system32\msvidc32.dll
2013-04-10 17:20:12 . 2009-12-28 12:32:25 13312 ----a-w- C:\Windows\system32\msrle32.dll
2013-04-10 17:20:11 . 2009-12-28 12:35:50 11776 ----a-w- C:\Windows\system32\tsbyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:32:34 22528 ----a-w- C:\Windows\system32\msyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:31:01 50176 ----a-w- C:\Windows\system32\iyuv_32.dll
2013-04-10 17:20:11 . 2009-12-28 12:28:43 91136 ----a-w- C:\Windows\system32\avifil32.dll
2013-04-10 17:20:10 . 2009-12-28 12:31:22 82944 ----a-w- C:\Windows\system32\mciavi32.dll
2013-04-10 17:20:10 . 2009-12-28 12:28:43 65024 ----a-w- C:\Windows\system32\avicap32.dll
2013-04-10 17:20:09 . 2009-12-28 12:32:32 123904 ----a-w- C:\Windows\system32\msvfw32.dll
2013-04-10 17:19:43 . 2008-09-10 03:40:14 1334272 ----a-w- C:\Windows\system32\msxml6.dll
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-04-15 17:31:56 . 2008-11-04 06:16:08 45056 ----a-w- C:\Windows\system32\acovcnt.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32:29 121968 ----a-w- C:\Program Files\AVAST Software\Avast\ashShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08:18 143360 ----a-w- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 03:52:16 104936]
"P2Go_Menu"="C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 02:11:32 210216]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-04 05:29:15 30192]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-18 03:04:00 7737344]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-22 02:35:05 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-22 02:34:45 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-22 02:34:57 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 04:35:57 4702208]
"Skytel"="Skytel.exe" [2007-10-11 03:04:03 1826816]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 09:31:25 630784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 10:12:43 1029416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 20:16:00 39792]
"seznam-listicka-distribuce"="C:\Program Files\Seznam.cz\distribution\szninstall.exe" [2013-03-21 09:26:26 1061960]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 07:04:54 252848]
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2013-03-06 22:32:44 4767304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - 97425144
*Deregistered* - 97425144
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14:42 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
------- Doplňkový sken -------
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-16 13:48:08
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
C:\ADSM_PData_0150
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
Celkový čas: 2013-04-16 13:49:56
ComboFix-quarantined-files.txt 2013-04-16 11:49:53
Před spuštěním: Volných bajtů: 166 247 161 856
Po spuštění: Volných bajtů: 166 183 878 656
- - End Of File - - A523CB8500E18DE8672FBE96903201A0
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.1105 [GMT 2:00]
Spuštěný z: C:\Users\vÜichni\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\337
C:\Program Files\Common Files\337\libcef\1.1364.1123\icudt.dll
C:\Program Files\Common Files\337\libcef\1.1364.1123\libcef.dll
C:\Program Files\Common Files\337\libcef\1.1364.1123\locales\en-US.pak
C:\Windows\PFRO.log
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-16 do 2013-04-16 )))))))))))))))))))))))))))))))
2013-04-16 11:47:51 . 2013-04-16 11:47:51 -------- d-----w- C:\Users\Default\AppData\Local\temp
2013-04-15 10:17:00 . 2013-04-15 10:17:00 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-15 10:16:58 . 2013-04-15 16:33:37 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2013-04-15 10:16:58 . 2013-04-04 12:50:32 22856 ----a-w- C:\Windows\system32\drivers\mbam.sys
2013-04-13 11:02:00 . 2013-04-13 11:02:00 -------- d-----w- C:\Program Files\Trend Micro
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\VDLL.DLL
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\system32\runouce.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\rundll16.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\RUNDL132.EXE
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo1_.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo_1.exe
2013-04-12 07:26:58 . 2013-04-12 07:26:57 632064 ----a-w- C:\Windows\system32\msvcr80.dll
2013-04-12 07:26:56 . 2013-04-12 07:26:55 554240 ----a-w- C:\Windows\system32\msvcp80.dll
2013-04-12 07:26:55 . 2013-04-12 07:26:54 34048 ----a-w- C:\Windows\system32\eEmpty.exe
2013-04-12 07:26:51 . 2013-04-12 07:26:51 -------- d-----w- C:\Program Files\Common Files\MicroWorld
2013-04-12 07:26:43 . 2013-04-12 07:26:51 -------- d-----w- C:\ProgramData\MicroWorld
2013-04-12 07:21:21 . 2013-04-13 11:15:15 -------- d-----w- C:\Program Files\CCleaner
2013-04-11 18:28:03 . 2013-04-16 10:19:55 -------- d-----w- C:\ProgramData\eSafe
2013-04-11 18:27:36 . 2013-04-11 18:27:31 773712 ----a-w- C:\Windows\system32\msvcr100.dll
2013-04-11 18:27:36 . 2013-04-11 18:27:31 420944 ----a-w- C:\Windows\system32\msvcp100.dll
2013-04-11 18:27:33 . 2013-04-16 11:34:27 -------- d-----w- C:\Program Files\Desk 365
2013-04-11 17:22:14 . 2013-04-11 17:22:15 -------- dc-h--w- C:\ProgramData\{3F35882A-B5EA-473D-BCE8-67F488C1E747}
2013-04-11 17:21:53 . 2013-04-11 17:21:53 -------- dc----w- C:\ProgramData\{4EBE13A3-4899-48EA-B064-02551A69BCF6}
2013-04-11 16:57:23 . 2008-11-14 15:09:44 -------- d-----w- C:\Windows\system32\McAffe
2013-04-11 15:51:43 . 2010-04-14 17:46:15 80896 ----a-w- C:\Windows\system32\MSNP.ax
2013-04-11 15:51:38 . 2010-04-14 17:47:01 293376 ----a-w- C:\Windows\system32\psisdecd.dll
2013-04-11 15:51:37 . 2010-04-14 17:47:00 217088 ----a-w- C:\Windows\system32\psisrndr.ax
2013-04-11 15:46:45 . 2010-02-20 23:39:35 24064 ----a-w- C:\Windows\system32\nshhttp.dll
2013-04-11 15:46:43 . 2010-02-20 21:18:40 411136 ----a-w- C:\Windows\system32\drivers\http.sys
2013-04-11 15:46:42 . 2010-02-20 23:37:20 31232 ----a-w- C:\Windows\system32\httpapi.dll
2013-04-11 14:59:51 . 2013-03-06 22:33:23 199384 ----a-w- C:\Windows\system32\drivers\aswNdis2.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 21576 ----a-w- C:\Windows\system32\drivers\aswKbd.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 101656 ----a-w- C:\Windows\system32\drivers\aswFW.sys
2013-04-11 14:59:30 . 2013-03-06 22:11:20 12112 ----a-w- C:\Windows\system32\drivers\aswNdis.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 49760 ----a-w- C:\Windows\system32\drivers\aswRdr.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 368176 ----a-w- C:\Windows\system32\drivers\aswSP.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:22 29816 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 765736 ----a-w- C:\Windows\system32\drivers\aswSnx.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 62376 ----a-w- C:\Windows\system32\drivers\aswTdi.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 164736 ----a-w- C:\Windows\system32\drivers\aswVmm.sys
2013-04-11 14:54:41 . 2013-03-06 22:33:24 49248 ----a-w- C:\Windows\system32\drivers\aswRvrt.sys
2013-04-11 14:54:39 . 2013-03-06 22:33:23 66336 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2013-04-11 14:54:39 . 2013-03-06 22:32:42 228600 ----a-w- C:\Windows\system32\aswBoot.exe
2013-04-11 14:53:25 . 2013-03-06 22:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-04-11 14:53:00 . 2013-04-11 14:53:00 -------- d-----w- C:\Program Files\AVAST Software
2013-04-11 14:52:04 . 2013-04-11 14:53:00 -------- d-----w- C:\ProgramData\AVAST Software
2013-04-11 13:18:07 . 2013-04-11 13:18:08 -------- d-----w- C:\Minecraft_Backup
2013-04-11 12:56:30 . 2009-11-08 17:55:31 49472 ----a-w- C:\Windows\system32\netfxperf.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 99176 ----a-w- C:\Windows\system32\PresentationHostProxy.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 297808 ----a-w- C:\Windows\system32\mscoree.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 295264 ----a-w- C:\Windows\system32\PresentationHost.exe
2013-04-11 12:56:29 . 2009-11-08 17:55:31 1130824 ----a-w- C:\Windows\system32\dfshim.dll
2013-04-11 12:07:28 . 2013-04-11 12:07:28 -------- d-----w- C:\Program Files\Common Files\Java
2013-04-11 12:07:21 . 2013-04-11 12:06:39 861088 ----a-w- C:\Windows\system32\npDeployJava1.dll
2013-04-11 12:07:21 . 2013-04-11 12:06:38 782240 ----a-w- C:\Windows\system32\deployJava1.dll
2013-04-11 12:07:03 . 2013-04-11 12:06:47 94112 ----a-w- C:\Windows\system32\WindowsAccessBridge.dll
2013-04-11 12:06:34 . 2013-04-11 12:06:34 -------- d-----w- C:\Program Files\Java
2013-04-11 06:22:40 . 2010-10-28 12:56:58 2048 ----a-w- C:\Windows\system32\tzres.dll
2013-04-11 06:22:11 . 2011-04-14 14:24:14 75264 ----a-w- C:\Windows\system32\drivers\dfsc.sys
2013-04-11 06:20:49 . 2010-10-12 15:48:28 33280 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2013-04-11 06:20:49 . 2010-10-12 13:52:20 66048 ----a-w- C:\Program Files\Windows Mail\wabmig.exe
2013-04-11 06:20:49 . 2010-10-12 13:52:20 515584 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-04-11 06:19:53 . 2008-06-06 03:27:13 38912 ----a-w- C:\Windows\system32\xolehlp.dll
2013-04-11 06:19:53 . 2008-06-06 03:27:05 562176 ----a-w- C:\Windows\system32\msdtcprx.dll
2013-04-11 06:18:04 . 2010-05-27 19:16:09 81920 ----a-w- C:\Windows\system32\iccvid.dll
2013-04-11 06:17:11 . 2011-02-18 13:31:24 304640 ----a-w- C:\Windows\system32\drivers\srv.sys
2013-04-11 06:17:08 . 2011-07-06 14:56:47 213504 ----a-w- C:\Windows\system32\drivers\mrxsmb10.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:44 79360 ----a-w- C:\Windows\system32\drivers\mrxsmb20.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:35 105984 ----a-w- C:\Windows\system32\drivers\mrxsmb.sys
2013-04-11 06:17:06 . 2011-03-02 14:49:43 86528 ----a-w- C:\Windows\system32\dnsrslvr.dll
2013-04-11 06:17:06 . 2009-05-04 10:11:27 25088 ----a-w- C:\Windows\system32\dnscacheugc.exe
2013-04-11 06:17:03 . 2008-12-06 04:42:11 376832 ----a-w- C:\Windows\system32\winhttp.dll
2013-04-11 06:17:02 . 2010-04-05 16:07:19 67072 ----a-w- C:\Windows\system32\asycfilt.dll
2013-04-11 06:16:59 . 2009-07-17 14:35:11 71680 ----a-w- C:\Windows\system32\atl.dll
2013-04-11 06:16:06 . 2008-10-21 05:25:18 296960 ----a-w- C:\Windows\system32\gdi32.dll
2013-04-11 06:16:04 . 2010-08-17 13:32:33 126464 ----a-w- C:\Windows\system32\spoolsv.exe
2013-04-11 06:16:02 . 2011-05-02 16:00:55 766464 ----a-w- C:\Program Files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-04-11 06:16:00 . 2010-08-26 16:07:25 157184 ----a-w- C:\Windows\system32\t2embed.dll
2013-04-11 06:15:58 . 2011-06-02 12:59:29 2042368 ----a-w- C:\Windows\system32\win32k.sys
2013-04-11 06:15:56 . 2011-04-21 13:16:42 273408 ----a-w- C:\Windows\system32\drivers\afd.sys
2013-04-11 06:10:38 . 2010-12-14 15:49:30 1169408 ----a-w- C:\Windows\system32\sdclt.exe
2013-04-11 06:10:30 . 2010-06-17 17:15:33 10926592 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.dll
2013-04-11 06:10:25 . 2010-06-17 15:49:15 150016 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.exe
2013-04-11 06:10:19 . 2011-04-29 12:49:57 146432 ----a-w- C:\Windows\system32\drivers\srv2.sys
2013-04-11 06:10:19 . 2011-04-29 12:49:55 102400 ----a-w- C:\Windows\system32\drivers\srvnet.sys
2013-04-11 06:10:00 . 2009-04-23 12:42:53 636928 ----a-w- C:\Windows\system32\localspl.dll
2013-04-11 06:09:57 . 2010-12-20 15:39:14 563200 ----a-w- C:\Windows\system32\oleaut32.dll
2013-04-11 06:09:54 . 2010-04-05 16:08:52 317952 ----a-w- C:\Windows\system32\MP4SDECD.DLL
2013-04-11 06:09:50 . 2011-02-16 15:35:41 430080 ----a-w- C:\Windows\system32\vbscript.dll
2013-04-11 06:04:00 . 2010-06-18 16:43:54 36352 ----a-w- C:\Windows\system32\rtutils.dll
2013-04-11 06:02:59 . 2010-12-29 17:41:21 323072 ----a-w- C:\Windows\system32\sbe.dll
2013-04-11 06:01:15 . 2008-08-12 03:39:08 443392 ----a-w- C:\Windows\system32\win32spl.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 712704 ----a-w- C:\Windows\system32\WindowsCodecs.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 347136 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:09 425472 ----a-w- C:\Windows\system32\PhotoMetadataHandler.dll
2013-04-11 06:01:10 . 2010-10-18 14:01:05 81920 ----a-w- C:\Windows\system32\consent.exe
2013-04-11 06:01:06 . 2010-06-11 15:30:23 1257472 ----a-w- C:\Windows\system32\msxml3.dll
2013-04-11 06:01:03 . 2010-01-15 00:04:50 98304 ----a-w- C:\Windows\system32\cabview.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:07 125952 ----a-w- C:\Windows\system32\wersvc.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:02 147456 ----a-w- C:\Windows\system32\Faultrep.dll
2013-04-11 05:58:58 . 2011-04-20 14:47:25 375808 ----a-w- C:\Windows\system32\winsrv.dll
2013-04-11 05:56:59 . 2010-09-20 09:25:01 231936 ----a-w- C:\Windows\system32\msshsq.dll
2013-04-10 18:12:27 . 2013-04-10 18:12:27 -------- d-----w- C:\Program Files\Common Files\Skype
2013-04-10 18:12:09 . 2013-04-10 18:13:45 -------- d-----r- C:\Program Files\Skype
2013-04-10 18:11:05 . 2013-04-10 18:11:05 -------- d-----w- C:\Program Files\Seznam.cz
2013-04-10 18:10:35 . 2013-04-10 18:13:45 -------- d-----w- C:\ProgramData\Skype
2013-04-10 17:21:36 . 2009-09-10 15:21:15 1418752 ----a-w- C:\Program Files\Windows Media Player\setup_wm.exe
2013-04-10 17:21:34 . 2009-09-10 15:21:07 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2013-04-10 17:21:30 . 2009-09-10 15:21:05 168960 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\msdxm.ocx
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\dxmasf.dll
2013-04-10 17:21:29 . 2009-07-14 12:58:44 7680 ----a-w- C:\Windows\system32\spwmp.dll
2013-04-10 17:21:29 . 2009-07-14 10:59:32 107520 ----a-w- C:\Program Files\Windows Media Player\wmpconfig.exe
2013-04-10 17:21:29 . 2009-07-14 10:58:54 107520 ----a-w- C:\Program Files\Windows Media Player\wmpshare.exe
2013-04-10 17:21:27 . 2009-09-10 15:21:53 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2013-04-10 17:20:12 . 2009-12-28 12:32:32 31744 ----a-w- C:\Windows\system32\msvidc32.dll
2013-04-10 17:20:12 . 2009-12-28 12:32:25 13312 ----a-w- C:\Windows\system32\msrle32.dll
2013-04-10 17:20:11 . 2009-12-28 12:35:50 11776 ----a-w- C:\Windows\system32\tsbyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:32:34 22528 ----a-w- C:\Windows\system32\msyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:31:01 50176 ----a-w- C:\Windows\system32\iyuv_32.dll
2013-04-10 17:20:11 . 2009-12-28 12:28:43 91136 ----a-w- C:\Windows\system32\avifil32.dll
2013-04-10 17:20:10 . 2009-12-28 12:31:22 82944 ----a-w- C:\Windows\system32\mciavi32.dll
2013-04-10 17:20:10 . 2009-12-28 12:28:43 65024 ----a-w- C:\Windows\system32\avicap32.dll
2013-04-10 17:20:09 . 2009-12-28 12:32:32 123904 ----a-w- C:\Windows\system32\msvfw32.dll
2013-04-10 17:19:43 . 2008-09-10 03:40:14 1334272 ----a-w- C:\Windows\system32\msxml6.dll
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-04-15 17:31:56 . 2008-11-04 06:16:08 45056 ----a-w- C:\Windows\system32\acovcnt.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32:29 121968 ----a-w- C:\Program Files\AVAST Software\Avast\ashShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08:18 143360 ----a-w- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 03:52:16 104936]
"P2Go_Menu"="C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 02:11:32 210216]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-04 05:29:15 30192]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-18 03:04:00 7737344]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-22 02:35:05 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-22 02:34:45 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-22 02:34:57 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 04:35:57 4702208]
"Skytel"="Skytel.exe" [2007-10-11 03:04:03 1826816]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 09:31:25 630784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 10:12:43 1029416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 20:16:00 39792]
"seznam-listicka-distribuce"="C:\Program Files\Seznam.cz\distribution\szninstall.exe" [2013-03-21 09:26:26 1061960]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 07:04:54 252848]
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2013-03-06 22:32:44 4767304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - 97425144
*Deregistered* - 97425144
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14:42 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
------- Doplňkový sken -------
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-16 13:48:08
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
C:\ADSM_PData_0150
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
Celkový čas: 2013-04-16 13:49:56
ComboFix-quarantined-files.txt 2013-04-16 11:49:53
Před spuštěním: Volných bajtů: 166 247 161 856
Po spuštění: Volných bajtů: 166 183 878 656
- - End Of File - - A523CB8500E18DE8672FBE96903201A0
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
Folder::
C:\Windows\system32\McAffe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000
DDS::
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: prosím o kontrolu logu
ComboFix 13-04-15.01 - všichni 17.04.2013 11:57:08.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.1060 [GMT 2:00]
Spuštěný z: C:\Users\vÜichni\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Users\vÜichni\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-17 do 2013-04-17 )))))))))))))))))))))))))))))))
2013-04-17 10:20:20 . 2013-04-17 10:20:20 -------- d-----w- C:\Users\Default\AppData\Local\temp
2013-04-15 10:17:00 . 2013-04-15 10:17:00 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-15 10:16:58 . 2013-04-15 16:33:37 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2013-04-15 10:16:58 . 2013-04-04 12:50:32 22856 ----a-w- C:\Windows\system32\drivers\mbam.sys
2013-04-13 11:02:00 . 2013-04-13 11:02:00 -------- d-----w- C:\Program Files\Trend Micro
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\VDLL.DLL
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\system32\runouce.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\rundll16.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\RUNDL132.EXE
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo1_.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo_1.exe
2013-04-12 07:26:58 . 2013-04-12 07:26:57 632064 ----a-w- C:\Windows\system32\msvcr80.dll
2013-04-12 07:26:56 . 2013-04-12 07:26:55 554240 ----a-w- C:\Windows\system32\msvcp80.dll
2013-04-12 07:26:55 . 2013-04-12 07:26:54 34048 ----a-w- C:\Windows\system32\eEmpty.exe
2013-04-12 07:26:51 . 2013-04-12 07:26:51 -------- d-----w- C:\Program Files\Common Files\MicroWorld
2013-04-12 07:26:43 . 2013-04-12 07:26:51 -------- d-----w- C:\ProgramData\MicroWorld
2013-04-12 07:21:21 . 2013-04-13 11:15:15 -------- d-----w- C:\Program Files\CCleaner
2013-04-11 18:28:03 . 2013-04-16 10:19:55 -------- d-----w- C:\ProgramData\eSafe
2013-04-11 18:27:36 . 2013-04-11 18:27:31 773712 ----a-w- C:\Windows\system32\msvcr100.dll
2013-04-11 18:27:36 . 2013-04-11 18:27:31 420944 ----a-w- C:\Windows\system32\msvcp100.dll
2013-04-11 18:27:33 . 2013-04-16 11:59:01 -------- d-----w- C:\Program Files\Desk 365
2013-04-11 17:22:14 . 2013-04-11 17:22:15 -------- dc-h--w- C:\ProgramData\{3F35882A-B5EA-473D-BCE8-67F488C1E747}
2013-04-11 17:21:53 . 2013-04-11 17:21:53 -------- dc----w- C:\ProgramData\{4EBE13A3-4899-48EA-B064-02551A69BCF6}
2013-04-11 16:57:23 . 2008-11-14 15:09:44 -------- d-----w- C:\Windows\system32\McAffe
2013-04-11 15:51:43 . 2010-04-14 17:46:15 80896 ----a-w- C:\Windows\system32\MSNP.ax
2013-04-11 15:51:38 . 2010-04-14 17:47:01 293376 ----a-w- C:\Windows\system32\psisdecd.dll
2013-04-11 15:51:37 . 2010-04-14 17:47:00 217088 ----a-w- C:\Windows\system32\psisrndr.ax
2013-04-11 15:46:45 . 2010-02-20 23:39:35 24064 ----a-w- C:\Windows\system32\nshhttp.dll
2013-04-11 15:46:43 . 2010-02-20 21:18:40 411136 ----a-w- C:\Windows\system32\drivers\http.sys
2013-04-11 15:46:42 . 2010-02-20 23:37:20 31232 ----a-w- C:\Windows\system32\httpapi.dll
2013-04-11 14:59:51 . 2013-03-06 22:33:23 199384 ----a-w- C:\Windows\system32\drivers\aswNdis2.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 21576 ----a-w- C:\Windows\system32\drivers\aswKbd.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 101656 ----a-w- C:\Windows\system32\drivers\aswFW.sys
2013-04-11 14:59:30 . 2013-03-06 22:11:20 12112 ----a-w- C:\Windows\system32\drivers\aswNdis.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 49760 ----a-w- C:\Windows\system32\drivers\aswRdr.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 368176 ----a-w- C:\Windows\system32\drivers\aswSP.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:22 29816 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 765736 ----a-w- C:\Windows\system32\drivers\aswSnx.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 62376 ----a-w- C:\Windows\system32\drivers\aswTdi.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 164736 ----a-w- C:\Windows\system32\drivers\aswVmm.sys
2013-04-11 14:54:41 . 2013-03-06 22:33:24 49248 ----a-w- C:\Windows\system32\drivers\aswRvrt.sys
2013-04-11 14:54:39 . 2013-03-06 22:33:23 66336 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2013-04-11 14:54:39 . 2013-03-06 22:32:42 228600 ----a-w- C:\Windows\system32\aswBoot.exe
2013-04-11 14:53:25 . 2013-03-06 22:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-04-11 14:53:00 . 2013-04-11 14:53:00 -------- d-----w- C:\Program Files\AVAST Software
2013-04-11 14:52:04 . 2013-04-11 14:53:00 -------- d-----w- C:\ProgramData\AVAST Software
2013-04-11 13:18:07 . 2013-04-11 13:18:08 -------- d-----w- C:\Minecraft_Backup
2013-04-11 12:56:30 . 2009-11-08 17:55:31 49472 ----a-w- C:\Windows\system32\netfxperf.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 99176 ----a-w- C:\Windows\system32\PresentationHostProxy.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 297808 ----a-w- C:\Windows\system32\mscoree.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 295264 ----a-w- C:\Windows\system32\PresentationHost.exe
2013-04-11 12:56:29 . 2009-11-08 17:55:31 1130824 ----a-w- C:\Windows\system32\dfshim.dll
2013-04-11 12:07:28 . 2013-04-11 12:07:28 -------- d-----w- C:\Program Files\Common Files\Java
2013-04-11 12:07:21 . 2013-04-11 12:06:39 861088 ----a-w- C:\Windows\system32\npDeployJava1.dll
2013-04-11 12:07:21 . 2013-04-11 12:06:38 782240 ----a-w- C:\Windows\system32\deployJava1.dll
2013-04-11 12:07:03 . 2013-04-11 12:06:47 94112 ----a-w- C:\Windows\system32\WindowsAccessBridge.dll
2013-04-11 12:06:34 . 2013-04-11 12:06:34 -------- d-----w- C:\Program Files\Java
2013-04-11 06:22:40 . 2010-10-28 12:56:58 2048 ----a-w- C:\Windows\system32\tzres.dll
2013-04-11 06:22:11 . 2011-04-14 14:24:14 75264 ----a-w- C:\Windows\system32\drivers\dfsc.sys
2013-04-11 06:20:49 . 2010-10-12 15:48:28 33280 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2013-04-11 06:20:49 . 2010-10-12 13:52:20 66048 ----a-w- C:\Program Files\Windows Mail\wabmig.exe
2013-04-11 06:20:49 . 2010-10-12 13:52:20 515584 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-04-11 06:19:53 . 2008-06-06 03:27:13 38912 ----a-w- C:\Windows\system32\xolehlp.dll
2013-04-11 06:19:53 . 2008-06-06 03:27:05 562176 ----a-w- C:\Windows\system32\msdtcprx.dll
2013-04-11 06:18:04 . 2010-05-27 19:16:09 81920 ----a-w- C:\Windows\system32\iccvid.dll
2013-04-11 06:17:11 . 2011-02-18 13:31:24 304640 ----a-w- C:\Windows\system32\drivers\srv.sys
2013-04-11 06:17:08 . 2011-07-06 14:56:47 213504 ----a-w- C:\Windows\system32\drivers\mrxsmb10.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:44 79360 ----a-w- C:\Windows\system32\drivers\mrxsmb20.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:35 105984 ----a-w- C:\Windows\system32\drivers\mrxsmb.sys
2013-04-11 06:17:06 . 2011-03-02 14:49:43 86528 ----a-w- C:\Windows\system32\dnsrslvr.dll
2013-04-11 06:17:06 . 2009-05-04 10:11:27 25088 ----a-w- C:\Windows\system32\dnscacheugc.exe
2013-04-11 06:17:03 . 2008-12-06 04:42:11 376832 ----a-w- C:\Windows\system32\winhttp.dll
2013-04-11 06:17:02 . 2010-04-05 16:07:19 67072 ----a-w- C:\Windows\system32\asycfilt.dll
2013-04-11 06:16:59 . 2009-07-17 14:35:11 71680 ----a-w- C:\Windows\system32\atl.dll
2013-04-11 06:16:06 . 2008-10-21 05:25:18 296960 ----a-w- C:\Windows\system32\gdi32.dll
2013-04-11 06:16:04 . 2010-08-17 13:32:33 126464 ----a-w- C:\Windows\system32\spoolsv.exe
2013-04-11 06:16:02 . 2011-05-02 16:00:55 766464 ----a-w- C:\Program Files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-04-11 06:16:00 . 2010-08-26 16:07:25 157184 ----a-w- C:\Windows\system32\t2embed.dll
2013-04-11 06:15:58 . 2011-06-02 12:59:29 2042368 ----a-w- C:\Windows\system32\win32k.sys
2013-04-11 06:15:56 . 2011-04-21 13:16:42 273408 ----a-w- C:\Windows\system32\drivers\afd.sys
2013-04-11 06:10:38 . 2010-12-14 15:49:30 1169408 ----a-w- C:\Windows\system32\sdclt.exe
2013-04-11 06:10:30 . 2010-06-17 17:15:33 10926592 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.dll
2013-04-11 06:10:25 . 2010-06-17 15:49:15 150016 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.exe
2013-04-11 06:10:19 . 2011-04-29 12:49:57 146432 ----a-w- C:\Windows\system32\drivers\srv2.sys
2013-04-11 06:10:19 . 2011-04-29 12:49:55 102400 ----a-w- C:\Windows\system32\drivers\srvnet.sys
2013-04-11 06:10:00 . 2009-04-23 12:42:53 636928 ----a-w- C:\Windows\system32\localspl.dll
2013-04-11 06:09:57 . 2010-12-20 15:39:14 563200 ----a-w- C:\Windows\system32\oleaut32.dll
2013-04-11 06:09:54 . 2010-04-05 16:08:52 317952 ----a-w- C:\Windows\system32\MP4SDECD.DLL
2013-04-11 06:09:50 . 2011-02-16 15:35:41 430080 ----a-w- C:\Windows\system32\vbscript.dll
2013-04-11 06:04:00 . 2010-06-18 16:43:54 36352 ----a-w- C:\Windows\system32\rtutils.dll
2013-04-11 06:02:59 . 2010-12-29 17:41:21 323072 ----a-w- C:\Windows\system32\sbe.dll
2013-04-11 06:01:15 . 2008-08-12 03:39:08 443392 ----a-w- C:\Windows\system32\win32spl.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 712704 ----a-w- C:\Windows\system32\WindowsCodecs.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 347136 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:09 425472 ----a-w- C:\Windows\system32\PhotoMetadataHandler.dll
2013-04-11 06:01:10 . 2010-10-18 14:01:05 81920 ----a-w- C:\Windows\system32\consent.exe
2013-04-11 06:01:06 . 2010-06-11 15:30:23 1257472 ----a-w- C:\Windows\system32\msxml3.dll
2013-04-11 06:01:03 . 2010-01-15 00:04:50 98304 ----a-w- C:\Windows\system32\cabview.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:07 125952 ----a-w- C:\Windows\system32\wersvc.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:02 147456 ----a-w- C:\Windows\system32\Faultrep.dll
2013-04-11 05:58:58 . 2011-04-20 14:47:25 375808 ----a-w- C:\Windows\system32\winsrv.dll
2013-04-11 05:56:59 . 2010-09-20 09:25:01 231936 ----a-w- C:\Windows\system32\msshsq.dll
2013-04-10 18:12:27 . 2013-04-10 18:12:27 -------- d-----w- C:\Program Files\Common Files\Skype
2013-04-10 18:12:09 . 2013-04-10 18:13:45 -------- d-----r- C:\Program Files\Skype
2013-04-10 18:11:05 . 2013-04-10 18:11:05 -------- d-----w- C:\Program Files\Seznam.cz
2013-04-10 18:10:35 . 2013-04-10 18:13:45 -------- d-----w- C:\ProgramData\Skype
2013-04-10 17:21:36 . 2009-09-10 15:21:15 1418752 ----a-w- C:\Program Files\Windows Media Player\setup_wm.exe
2013-04-10 17:21:34 . 2009-09-10 15:21:07 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2013-04-10 17:21:30 . 2009-09-10 15:21:05 168960 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\msdxm.ocx
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\dxmasf.dll
2013-04-10 17:21:29 . 2009-07-14 12:58:44 7680 ----a-w- C:\Windows\system32\spwmp.dll
2013-04-10 17:21:29 . 2009-07-14 10:59:32 107520 ----a-w- C:\Program Files\Windows Media Player\wmpconfig.exe
2013-04-10 17:21:29 . 2009-07-14 10:58:54 107520 ----a-w- C:\Program Files\Windows Media Player\wmpshare.exe
2013-04-10 17:21:27 . 2009-09-10 15:21:53 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2013-04-10 17:20:12 . 2009-12-28 12:32:32 31744 ----a-w- C:\Windows\system32\msvidc32.dll
2013-04-10 17:20:12 . 2009-12-28 12:32:25 13312 ----a-w- C:\Windows\system32\msrle32.dll
2013-04-10 17:20:11 . 2009-12-28 12:35:50 11776 ----a-w- C:\Windows\system32\tsbyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:32:34 22528 ----a-w- C:\Windows\system32\msyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:31:01 50176 ----a-w- C:\Windows\system32\iyuv_32.dll
2013-04-10 17:20:11 . 2009-12-28 12:28:43 91136 ----a-w- C:\Windows\system32\avifil32.dll
2013-04-10 17:20:10 . 2009-12-28 12:31:22 82944 ----a-w- C:\Windows\system32\mciavi32.dll
2013-04-10 17:20:10 . 2009-12-28 12:28:43 65024 ----a-w- C:\Windows\system32\avicap32.dll
2013-04-10 17:20:09 . 2009-12-28 12:32:32 123904 ----a-w- C:\Windows\system32\msvfw32.dll
2013-04-10 17:19:43 . 2008-09-10 03:40:14 1334272 ----a-w- C:\Windows\system32\msxml6.dll
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-04-16 11:56:13 . 2008-11-04 06:16:08 45056 ----a-w- C:\Windows\system32\acovcnt.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32:29 121968 ----a-w- C:\Program Files\AVAST Software\Avast\ashShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08:18 143360 ----a-w- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 03:52:16 104936]
"P2Go_Menu"="C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 02:11:32 210216]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-04 05:29:15 30192]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-18 03:04:00 7737344]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-22 02:35:05 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-22 02:34:45 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-22 02:34:57 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 04:35:57 4702208]
"Skytel"="Skytel.exe" [2007-10-11 03:04:03 1826816]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 09:31:25 630784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 10:12:43 1029416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 20:16:00 39792]
"seznam-listicka-distribuce"="C:\Program Files\Seznam.cz\distribution\szninstall.exe" [2013-03-21 09:26:26 1061960]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 07:04:54 252848]
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2013-03-06 22:32:44 4767304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - WS2IFSL
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14:42 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
------- Doplňkový sken -------
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-17 12:20:26
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(2352)
C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
Celkový čas: 2013-04-17 12:21:59
ComboFix-quarantined-files.txt 2013-04-17 10:21:57
ComboFix2.txt 2013-04-16 11:49:57
Před spuštěním: Volných bajtů: 166 031 749 120
Po spuštění: Volných bajtů: 165 999 345 664
- - End Of File - - 49FF66580C5399E851541EB1DA550F17
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.1060 [GMT 2:00]
Spuštěný z: C:\Users\vÜichni\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Users\vÜichni\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-17 do 2013-04-17 )))))))))))))))))))))))))))))))
2013-04-17 10:20:20 . 2013-04-17 10:20:20 -------- d-----w- C:\Users\Default\AppData\Local\temp
2013-04-15 10:17:00 . 2013-04-15 10:17:00 -------- d-----w- C:\ProgramData\Malwarebytes
2013-04-15 10:16:58 . 2013-04-15 16:33:37 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2013-04-15 10:16:58 . 2013-04-04 12:50:32 22856 ----a-w- C:\Windows\system32\drivers\mbam.sys
2013-04-13 11:02:00 . 2013-04-13 11:02:00 -------- d-----w- C:\Program Files\Trend Micro
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\VDLL.DLL
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\system32\runouce.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\rundll16.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\RUNDL132.EXE
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo1_.exe
2013-04-12 07:41:24 . 2013-04-12 07:41:24 -------- d---a-w- C:\Windows\logo_1.exe
2013-04-12 07:26:58 . 2013-04-12 07:26:57 632064 ----a-w- C:\Windows\system32\msvcr80.dll
2013-04-12 07:26:56 . 2013-04-12 07:26:55 554240 ----a-w- C:\Windows\system32\msvcp80.dll
2013-04-12 07:26:55 . 2013-04-12 07:26:54 34048 ----a-w- C:\Windows\system32\eEmpty.exe
2013-04-12 07:26:51 . 2013-04-12 07:26:51 -------- d-----w- C:\Program Files\Common Files\MicroWorld
2013-04-12 07:26:43 . 2013-04-12 07:26:51 -------- d-----w- C:\ProgramData\MicroWorld
2013-04-12 07:21:21 . 2013-04-13 11:15:15 -------- d-----w- C:\Program Files\CCleaner
2013-04-11 18:28:03 . 2013-04-16 10:19:55 -------- d-----w- C:\ProgramData\eSafe
2013-04-11 18:27:36 . 2013-04-11 18:27:31 773712 ----a-w- C:\Windows\system32\msvcr100.dll
2013-04-11 18:27:36 . 2013-04-11 18:27:31 420944 ----a-w- C:\Windows\system32\msvcp100.dll
2013-04-11 18:27:33 . 2013-04-16 11:59:01 -------- d-----w- C:\Program Files\Desk 365
2013-04-11 17:22:14 . 2013-04-11 17:22:15 -------- dc-h--w- C:\ProgramData\{3F35882A-B5EA-473D-BCE8-67F488C1E747}
2013-04-11 17:21:53 . 2013-04-11 17:21:53 -------- dc----w- C:\ProgramData\{4EBE13A3-4899-48EA-B064-02551A69BCF6}
2013-04-11 16:57:23 . 2008-11-14 15:09:44 -------- d-----w- C:\Windows\system32\McAffe
2013-04-11 15:51:43 . 2010-04-14 17:46:15 80896 ----a-w- C:\Windows\system32\MSNP.ax
2013-04-11 15:51:38 . 2010-04-14 17:47:01 293376 ----a-w- C:\Windows\system32\psisdecd.dll
2013-04-11 15:51:37 . 2010-04-14 17:47:00 217088 ----a-w- C:\Windows\system32\psisrndr.ax
2013-04-11 15:46:45 . 2010-02-20 23:39:35 24064 ----a-w- C:\Windows\system32\nshhttp.dll
2013-04-11 15:46:43 . 2010-02-20 21:18:40 411136 ----a-w- C:\Windows\system32\drivers\http.sys
2013-04-11 15:46:42 . 2010-02-20 23:37:20 31232 ----a-w- C:\Windows\system32\httpapi.dll
2013-04-11 14:59:51 . 2013-03-06 22:33:23 199384 ----a-w- C:\Windows\system32\drivers\aswNdis2.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 21576 ----a-w- C:\Windows\system32\drivers\aswKbd.sys
2013-04-11 14:59:51 . 2013-03-06 22:33:22 101656 ----a-w- C:\Windows\system32\drivers\aswFW.sys
2013-04-11 14:59:30 . 2013-03-06 22:11:20 12112 ----a-w- C:\Windows\system32\drivers\aswNdis.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 49760 ----a-w- C:\Windows\system32\drivers\aswRdr.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:24 368176 ----a-w- C:\Windows\system32\drivers\aswSP.sys
2013-04-11 14:54:43 . 2013-03-06 22:33:22 29816 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 765736 ----a-w- C:\Windows\system32\drivers\aswSnx.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 62376 ----a-w- C:\Windows\system32\drivers\aswTdi.sys
2013-04-11 14:54:42 . 2013-03-06 22:33:24 164736 ----a-w- C:\Windows\system32\drivers\aswVmm.sys
2013-04-11 14:54:41 . 2013-03-06 22:33:24 49248 ----a-w- C:\Windows\system32\drivers\aswRvrt.sys
2013-04-11 14:54:39 . 2013-03-06 22:33:23 66336 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2013-04-11 14:54:39 . 2013-03-06 22:32:42 228600 ----a-w- C:\Windows\system32\aswBoot.exe
2013-04-11 14:53:25 . 2013-03-06 22:32:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-04-11 14:53:00 . 2013-04-11 14:53:00 -------- d-----w- C:\Program Files\AVAST Software
2013-04-11 14:52:04 . 2013-04-11 14:53:00 -------- d-----w- C:\ProgramData\AVAST Software
2013-04-11 13:18:07 . 2013-04-11 13:18:08 -------- d-----w- C:\Minecraft_Backup
2013-04-11 12:56:30 . 2009-11-08 17:55:31 49472 ----a-w- C:\Windows\system32\netfxperf.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 99176 ----a-w- C:\Windows\system32\PresentationHostProxy.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 297808 ----a-w- C:\Windows\system32\mscoree.dll
2013-04-11 12:56:29 . 2009-11-08 17:55:31 295264 ----a-w- C:\Windows\system32\PresentationHost.exe
2013-04-11 12:56:29 . 2009-11-08 17:55:31 1130824 ----a-w- C:\Windows\system32\dfshim.dll
2013-04-11 12:07:28 . 2013-04-11 12:07:28 -------- d-----w- C:\Program Files\Common Files\Java
2013-04-11 12:07:21 . 2013-04-11 12:06:39 861088 ----a-w- C:\Windows\system32\npDeployJava1.dll
2013-04-11 12:07:21 . 2013-04-11 12:06:38 782240 ----a-w- C:\Windows\system32\deployJava1.dll
2013-04-11 12:07:03 . 2013-04-11 12:06:47 94112 ----a-w- C:\Windows\system32\WindowsAccessBridge.dll
2013-04-11 12:06:34 . 2013-04-11 12:06:34 -------- d-----w- C:\Program Files\Java
2013-04-11 06:22:40 . 2010-10-28 12:56:58 2048 ----a-w- C:\Windows\system32\tzres.dll
2013-04-11 06:22:11 . 2011-04-14 14:24:14 75264 ----a-w- C:\Windows\system32\drivers\dfsc.sys
2013-04-11 06:20:49 . 2010-10-12 15:48:28 33280 ----a-w- C:\Program Files\Windows Mail\wabfind.dll
2013-04-11 06:20:49 . 2010-10-12 13:52:20 66048 ----a-w- C:\Program Files\Windows Mail\wabmig.exe
2013-04-11 06:20:49 . 2010-10-12 13:52:20 515584 ----a-w- C:\Program Files\Windows Mail\wab.exe
2013-04-11 06:19:53 . 2008-06-06 03:27:13 38912 ----a-w- C:\Windows\system32\xolehlp.dll
2013-04-11 06:19:53 . 2008-06-06 03:27:05 562176 ----a-w- C:\Windows\system32\msdtcprx.dll
2013-04-11 06:18:04 . 2010-05-27 19:16:09 81920 ----a-w- C:\Windows\system32\iccvid.dll
2013-04-11 06:17:11 . 2011-02-18 13:31:24 304640 ----a-w- C:\Windows\system32\drivers\srv.sys
2013-04-11 06:17:08 . 2011-07-06 14:56:47 213504 ----a-w- C:\Windows\system32\drivers\mrxsmb10.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:44 79360 ----a-w- C:\Windows\system32\drivers\mrxsmb20.sys
2013-04-11 06:17:08 . 2011-04-29 12:49:35 105984 ----a-w- C:\Windows\system32\drivers\mrxsmb.sys
2013-04-11 06:17:06 . 2011-03-02 14:49:43 86528 ----a-w- C:\Windows\system32\dnsrslvr.dll
2013-04-11 06:17:06 . 2009-05-04 10:11:27 25088 ----a-w- C:\Windows\system32\dnscacheugc.exe
2013-04-11 06:17:03 . 2008-12-06 04:42:11 376832 ----a-w- C:\Windows\system32\winhttp.dll
2013-04-11 06:17:02 . 2010-04-05 16:07:19 67072 ----a-w- C:\Windows\system32\asycfilt.dll
2013-04-11 06:16:59 . 2009-07-17 14:35:11 71680 ----a-w- C:\Windows\system32\atl.dll
2013-04-11 06:16:06 . 2008-10-21 05:25:18 296960 ----a-w- C:\Windows\system32\gdi32.dll
2013-04-11 06:16:04 . 2010-08-17 13:32:33 126464 ----a-w- C:\Windows\system32\spoolsv.exe
2013-04-11 06:16:02 . 2011-05-02 16:00:55 766464 ----a-w- C:\Program Files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-04-11 06:16:00 . 2010-08-26 16:07:25 157184 ----a-w- C:\Windows\system32\t2embed.dll
2013-04-11 06:15:58 . 2011-06-02 12:59:29 2042368 ----a-w- C:\Windows\system32\win32k.sys
2013-04-11 06:15:56 . 2011-04-21 13:16:42 273408 ----a-w- C:\Windows\system32\drivers\afd.sys
2013-04-11 06:10:38 . 2010-12-14 15:49:30 1169408 ----a-w- C:\Windows\system32\sdclt.exe
2013-04-11 06:10:30 . 2010-06-17 17:15:33 10926592 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.dll
2013-04-11 06:10:25 . 2010-06-17 15:49:15 150016 ----a-w- C:\Program Files\Movie Maker\MOVIEMK.exe
2013-04-11 06:10:19 . 2011-04-29 12:49:57 146432 ----a-w- C:\Windows\system32\drivers\srv2.sys
2013-04-11 06:10:19 . 2011-04-29 12:49:55 102400 ----a-w- C:\Windows\system32\drivers\srvnet.sys
2013-04-11 06:10:00 . 2009-04-23 12:42:53 636928 ----a-w- C:\Windows\system32\localspl.dll
2013-04-11 06:09:57 . 2010-12-20 15:39:14 563200 ----a-w- C:\Windows\system32\oleaut32.dll
2013-04-11 06:09:54 . 2010-04-05 16:08:52 317952 ----a-w- C:\Windows\system32\MP4SDECD.DLL
2013-04-11 06:09:50 . 2011-02-16 15:35:41 430080 ----a-w- C:\Windows\system32\vbscript.dll
2013-04-11 06:04:00 . 2010-06-18 16:43:54 36352 ----a-w- C:\Windows\system32\rtutils.dll
2013-04-11 06:02:59 . 2010-12-29 17:41:21 323072 ----a-w- C:\Windows\system32\sbe.dll
2013-04-11 06:01:15 . 2008-08-12 03:39:08 443392 ----a-w- C:\Windows\system32\win32spl.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 712704 ----a-w- C:\Windows\system32\WindowsCodecs.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:11 347136 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll
2013-04-11 06:01:12 . 2008-08-28 03:40:09 425472 ----a-w- C:\Windows\system32\PhotoMetadataHandler.dll
2013-04-11 06:01:10 . 2010-10-18 14:01:05 81920 ----a-w- C:\Windows\system32\consent.exe
2013-04-11 06:01:06 . 2010-06-11 15:30:23 1257472 ----a-w- C:\Windows\system32\msxml3.dll
2013-04-11 06:01:03 . 2010-01-15 00:04:50 98304 ----a-w- C:\Windows\system32\cabview.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:07 125952 ----a-w- C:\Windows\system32\wersvc.dll
2013-04-11 06:01:00 . 2008-09-18 04:56:02 147456 ----a-w- C:\Windows\system32\Faultrep.dll
2013-04-11 05:58:58 . 2011-04-20 14:47:25 375808 ----a-w- C:\Windows\system32\winsrv.dll
2013-04-11 05:56:59 . 2010-09-20 09:25:01 231936 ----a-w- C:\Windows\system32\msshsq.dll
2013-04-10 18:12:27 . 2013-04-10 18:12:27 -------- d-----w- C:\Program Files\Common Files\Skype
2013-04-10 18:12:09 . 2013-04-10 18:13:45 -------- d-----r- C:\Program Files\Skype
2013-04-10 18:11:05 . 2013-04-10 18:11:05 -------- d-----w- C:\Program Files\Seznam.cz
2013-04-10 18:10:35 . 2013-04-10 18:13:45 -------- d-----w- C:\ProgramData\Skype
2013-04-10 17:21:36 . 2009-09-10 15:21:15 1418752 ----a-w- C:\Program Files\Windows Media Player\setup_wm.exe
2013-04-10 17:21:34 . 2009-09-10 15:21:07 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2013-04-10 17:21:30 . 2009-09-10 15:21:05 168960 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\msdxm.ocx
2013-04-10 17:21:29 . 2009-07-14 12:59:28 4096 ----a-w- C:\Windows\system32\dxmasf.dll
2013-04-10 17:21:29 . 2009-07-14 12:58:44 7680 ----a-w- C:\Windows\system32\spwmp.dll
2013-04-10 17:21:29 . 2009-07-14 10:59:32 107520 ----a-w- C:\Program Files\Windows Media Player\wmpconfig.exe
2013-04-10 17:21:29 . 2009-07-14 10:58:54 107520 ----a-w- C:\Program Files\Windows Media Player\wmpshare.exe
2013-04-10 17:21:27 . 2009-09-10 15:21:53 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2013-04-10 17:20:12 . 2009-12-28 12:32:32 31744 ----a-w- C:\Windows\system32\msvidc32.dll
2013-04-10 17:20:12 . 2009-12-28 12:32:25 13312 ----a-w- C:\Windows\system32\msrle32.dll
2013-04-10 17:20:11 . 2009-12-28 12:35:50 11776 ----a-w- C:\Windows\system32\tsbyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:32:34 22528 ----a-w- C:\Windows\system32\msyuv.dll
2013-04-10 17:20:11 . 2009-12-28 12:31:01 50176 ----a-w- C:\Windows\system32\iyuv_32.dll
2013-04-10 17:20:11 . 2009-12-28 12:28:43 91136 ----a-w- C:\Windows\system32\avifil32.dll
2013-04-10 17:20:10 . 2009-12-28 12:31:22 82944 ----a-w- C:\Windows\system32\mciavi32.dll
2013-04-10 17:20:10 . 2009-12-28 12:28:43 65024 ----a-w- C:\Windows\system32\avicap32.dll
2013-04-10 17:20:09 . 2009-12-28 12:32:32 123904 ----a-w- C:\Windows\system32\msvfw32.dll
2013-04-10 17:19:43 . 2008-09-10 03:40:14 1334272 ----a-w- C:\Windows\system32\msxml6.dll
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2013-04-16 11:56:13 . 2008-11-04 06:16:08 45056 ----a-w- C:\Windows\system32\acovcnt.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-13 11:02:01 . 2013-04-13 11:02:00 388096 ----a-r- C:\Users\všichni\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
2013-04-11 17:49:30 . 2013-04-11 17:49:30 7680 --shatr- C:\Users\všichni\AppData\Roaming\Microsoft\Windows\Templates\bootres.exe
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32:29 121968 ----a-w- C:\Program Files\AVAST Software\Avast\ashShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08:18 143360 ----a-w- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 03:52:16 104936]
"P2Go_Menu"="C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 02:11:32 210216]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-04 05:29:15 30192]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-18 03:04:00 7737344]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-22 02:35:05 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-22 02:34:45 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-22 02:34:57 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 04:35:57 4702208]
"Skytel"="Skytel.exe" [2007-10-11 03:04:03 1826816]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 09:31:25 630784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 10:12:43 1029416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 20:16:00 39792]
"seznam-listicka-distribuce"="C:\Program Files\Seznam.cz\distribution\szninstall.exe" [2013-03-21 09:26:26 1061960]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 07:04:54 252848]
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2013-03-06 22:32:44 4767304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - WS2IFSL
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14:42 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
------- Doplňkový sken -------
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-17 12:20:26
Windows 6.0.6001 Service Pack 1 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(2352)
C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
Celkový čas: 2013-04-17 12:21:59
ComboFix-quarantined-files.txt 2013-04-17 10:21:57
ComboFix2.txt 2013-04-16 11:49:57
Před spuštěním: Volných bajtů: 166 031 749 120
Po spuštění: Volných bajtů: 165 999 345 664
- - End Of File - - 49FF66580C5399E851541EB1DA550F17
Re: prosím o kontrolu logu
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:04:47, on 17.4.2013
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Desk 365\desk365.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Desk 365 service (desksvc) - 337 Technology Limited. - C:\Program Files\Desk 365\deskSvc.exe
O23 - Service: eSafe Service (eSafeSvc) - eSafe Security Co., Ltd. - C:\ProgramData\eSafe\eGdpSvc.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Skype C2C Service - Unknown owner - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
--
End of file - 5979 bytes
Scan saved at 13:04:47, on 17.4.2013
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Desk 365\desk365.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Desk 365 service (desksvc) - 337 Technology Limited. - C:\Program Files\Desk 365\deskSvc.exe
O23 - Service: eSafe Service (eSafeSvc) - eSafe Security Co., Ltd. - C:\ProgramData\eSafe\eGdpSvc.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Skype C2C Service - Unknown owner - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
--
End of file - 5979 bytes
Re: prosím o kontrolu logu
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-04-17 13:09:46
-----------------------------
13:09:46.236 OS Version: Windows 6.0.6001 Service Pack 1
13:09:46.237 Number of processors: 2 586 0xF0D
13:09:46.238 ComputerName: VSICHNI-PC UserName: všichni
13:09:47.183 Initialize success
13:09:47.337 AVAST engine defs: 13041600
13:09:55.126 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
13:09:55.129 Disk 0 Vendor: ST920082 3.AA Size: 190782MB BusType: 3
13:09:55.261 Disk 0 MBR read successfully
13:09:55.265 Disk 0 MBR scan
13:09:55.269 Disk 0 Windows 7 default MBR code
13:09:55.274 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 10001 MB offset 63
13:09:55.303 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 180779 MB offset 20484096
13:09:55.328 Disk 0 scanning sectors +390719488
13:09:55.415 Disk 0 scanning C:\Windows\system32\drivers
13:10:04.226 Service scanning
13:10:21.432 Modules scanning
13:10:25.594 Disk 0 trace - called modules:
13:10:25.626 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys halmacpi.dll iaStor.sys tcpip.sys NETIO.SYS dxgkrnl.sys igdkmd32.sys
13:10:25.633 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863db6e0]
13:10:25.640 3 CLASSPNP.SYS[887a2745] -> nt!IofCallDriver -> [0x85220900]
13:10:25.646 5 acpi.sys[806966a0] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x85226028]
13:10:26.414 AVAST engine scan C:\Windows
13:10:30.677 AVAST engine scan C:\Windows\system32
13:12:17.186 AVAST engine scan C:\Windows\system32\drivers
13:12:26.497 AVAST engine scan C:\Users\všichni
13:12:59.566 Disk 0 MBR has been saved successfully to "C:\Users\všichni\Desktop\MBR.dat"
13:12:59.576 The log file has been saved successfully to "C:\Users\všichni\Desktop\aswMBR.txt"
Run date: 2013-04-17 13:09:46
-----------------------------
13:09:46.236 OS Version: Windows 6.0.6001 Service Pack 1
13:09:46.237 Number of processors: 2 586 0xF0D
13:09:46.238 ComputerName: VSICHNI-PC UserName: všichni
13:09:47.183 Initialize success
13:09:47.337 AVAST engine defs: 13041600
13:09:55.126 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
13:09:55.129 Disk 0 Vendor: ST920082 3.AA Size: 190782MB BusType: 3
13:09:55.261 Disk 0 MBR read successfully
13:09:55.265 Disk 0 MBR scan
13:09:55.269 Disk 0 Windows 7 default MBR code
13:09:55.274 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 10001 MB offset 63
13:09:55.303 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 180779 MB offset 20484096
13:09:55.328 Disk 0 scanning sectors +390719488
13:09:55.415 Disk 0 scanning C:\Windows\system32\drivers
13:10:04.226 Service scanning
13:10:21.432 Modules scanning
13:10:25.594 Disk 0 trace - called modules:
13:10:25.626 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys halmacpi.dll iaStor.sys tcpip.sys NETIO.SYS dxgkrnl.sys igdkmd32.sys
13:10:25.633 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863db6e0]
13:10:25.640 3 CLASSPNP.SYS[887a2745] -> nt!IofCallDriver -> [0x85220900]
13:10:25.646 5 acpi.sys[806966a0] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x85226028]
13:10:26.414 AVAST engine scan C:\Windows
13:10:30.677 AVAST engine scan C:\Windows\system32
13:12:17.186 AVAST engine scan C:\Windows\system32\drivers
13:12:26.497 AVAST engine scan C:\Users\všichni
13:12:59.566 Disk 0 MBR has been saved successfully to "C:\Users\všichni\Desktop\MBR.dat"
13:12:59.576 The log file has been saved successfully to "C:\Users\všichni\Desktop\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: prosím o kontrolu logu
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Ten script v Combofixu udělej znovu v nouz. režimu , zkopíruj celé ( je tam posuvník!)-
Návod
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1365704839
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
Ten script v Combofixu udělej znovu v nouz. režimu , zkopíruj celé ( je tam posuvník!)-
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 83 hostů