20:33:35.0453 0x03f4 ================ Scan global ===============================
20:33:35.0468 0x03f4 [ F36278E42C8C5DF03CE17DAC8231C91C, D012A3C8F394DF4F0BF5D5A4C10E73BBF427762B7D3DB6CF5FAB96536E082B7A ] C:\WINDOWS\system32\basesrv.dll
20:33:35.0500 0x03f4 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
20:33:35.0515 0x03f4 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
20:33:35.0546 0x03f4 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] C:\WINDOWS\system32\services.exe
20:33:35.0546 0x03f4 [ Global ] - ok
20:33:35.0546 0x03f4 ================ Scan MBR ==================================
20:33:35.0562 0x03f4 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:33:35.0859 0x03f4 \Device\Harddisk0\DR0 - ok
20:33:35.0859 0x03f4 ================ Scan VBR ==================================
20:33:35.0859 0x03f4 [ D6E0AEF7A81E0DD5F7977D01F0ED391C ] \Device\Harddisk0\DR0\Partition1
20:33:35.0859 0x03f4 \Device\Harddisk0\DR0\Partition1 - ok
20:33:35.0875 0x03f4 [ 1D88D1890DC4C9543263F386A98DB995 ] \Device\Harddisk0\DR0\Partition2
20:33:35.0875 0x03f4 \Device\Harddisk0\DR0\Partition2 - ok
20:33:35.0890 0x03f4 [ AAB4E8460700D9B1CEF3ACE4758EBF18 ] \Device\Harddisk0\DR0\Partition3
20:33:35.0890 0x03f4 \Device\Harddisk0\DR0\Partition3 - ok
20:33:35.0890 0x03f4 Waiting for KSN requests completion. In queue: 151
20:33:36.0890 0x03f4 Waiting for KSN requests completion. In queue: 151
20:33:37.0890 0x03f4 Waiting for KSN requests completion. In queue: 151
20:33:38.0937 0x03f4 Win FW state via NFM: disabled
20:33:41.0359 0x03f4 ============================================================
20:33:41.0359 0x03f4 Scan finished
20:33:41.0359 0x03f4 ============================================================
20:33:41.0359 0x0654 Detected object count: 0
20:33:41.0359 0x0654 Actual detected object count: 0
20:35:27.0640 0x0da4 ============================================================
20:35:27.0640 0x0da4 Scan started
20:35:27.0640 0x0da4 Mode: Manual;
20:35:27.0640 0x0da4 ============================================================
20:35:27.0640 0x0da4 KSN ping started
20:35:41.0968 0x0da4 KSN ping finished: true
20:35:42.0312 0x0da4 ================ Scan system memory ========================
20:35:42.0312 0x0da4 System memory - ok
20:35:42.0312 0x0da4 ================ Scan services =============================
20:35:42.0421 0x0da4 Abiosdsk - ok
20:35:42.0421 0x0da4 abp480n5 - ok
20:35:42.0468 0x0da4 [ 4FE34F1F3126B61FCC6B2043AA8112C9, DE370865E47A5D2A4B227EEFFB42384F67F08D622BF936A9C9CEF70CC47F324B ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:35:42.0468 0x0da4 ACPI - ok
20:35:42.0500 0x0da4 [ AFDFF022A01F0B11C776F0860C3B282F, 135E5257B62D921B76271014301E9EA1E2383D5DBB04E475DC3A7EFFD2561F56 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
20:35:42.0500 0x0da4 ACPIEC - ok
20:35:42.0531 0x0da4 [ 0158F4027C0808FF65ED3B3D683339C9, 382FBE4E74FA3ABBCF60B6E1E293BC0324F9689AA7C485D9926C07FEA9FCF597 ] ADIHdAudAddService C:\WINDOWS\system32\drivers\ADIHdAud.sys
20:35:42.0531 0x0da4 ADIHdAudAddService - ok
20:35:42.0625 0x0da4 [ 438F31336B3DC248ABC632F1C8F34A24, 94C1218E7EC2EC6D4870A6FDC118097D7D3A359DA073DCD3A9770F399F830991 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:35:42.0625 0x0da4 AdobeFlashPlayerUpdateSvc - ok
20:35:42.0625 0x0da4 adpu160m - ok
20:35:42.0656 0x0da4 [ 358063AB6C1C4173B735525CDFA65F94, E2C7E27F8E0B4C6A662313FEEE61AF02D9166F4DC40E709DBB6C73EB489A5CC5 ] AEAudio C:\WINDOWS\system32\drivers\AEAudio.sys
20:35:42.0656 0x0da4 AEAudio - ok
20:35:42.0687 0x0da4 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
20:35:42.0687 0x0da4 aec - ok
20:35:42.0703 0x0da4 [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
20:35:42.0703 0x0da4 AFD - ok
20:35:42.0718 0x0da4 Aha154x - ok
20:35:42.0718 0x0da4 aic78u2 - ok
20:35:42.0718 0x0da4 aic78xx - ok
20:35:42.0750 0x0da4 [ E0A6FA244B8624D78FE5FF6F56A33BAE, 26B828FDB03AE4A4F1DC7A1792F9BAD69CF947897D47F5E567F24F4B6D5CB541 ] Alerter C:\WINDOWS\system32\alrsvc.dll
20:35:42.0750 0x0da4 Alerter - ok
20:35:42.0765 0x0da4 [ 88842DE939A827577BF24243699AC80A, A49C9A6A9941F3A2FBBCFE1F6DB48B632739D00670AC98ECCCBC7FD9E786B21A ] ALG C:\WINDOWS\System32\alg.exe
20:35:42.0765 0x0da4 ALG - ok
20:35:42.0765 0x0da4 AliIde - ok
20:35:42.0765 0x0da4 amsint - ok
20:35:42.0796 0x0da4 [ 6B8E7A90E576D4FE308F97C69060A171, 6CE49BC78715737D78E05DECAC23E26A5672ACD2CF3D10154FEA9D47B318D47C ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
20:35:42.0796 0x0da4 AppMgmt - ok
20:35:42.0828 0x0da4 [ B5B8A80875C1DEDEDA8B02765642C32F, AD0C71D73B1B8225351FBF4FFB43001A32B4DAE69504C59970CD2428BB33D4EF ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
20:35:42.0828 0x0da4 Arp1394 - ok
20:35:42.0828 0x0da4 asc - ok
20:35:42.0843 0x0da4 asc3350p - ok
20:35:42.0843 0x0da4 asc3550 - ok
20:35:42.0875 0x0da4 [ 9D8CB58B9A9E177DDD599791A58A654D, B3E645E8817696FA5D5E2255F9328F3B6A2E5FCE91737F4D654FF155DC9851E5 ] AsIO C:\WINDOWS\system32\drivers\AsIO.sys
20:35:42.0875 0x0da4 AsIO - ok
20:35:42.0953 0x0da4 [ 0E5E4957549056E2BF2C49F4F6B601AD, F7F19FDC906B719A3516D30A9B4A2262C8CC5B36B94E3D4195C345EC4610FF2B ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:35:42.0953 0x0da4 aspnet_state - ok
20:35:42.0968 0x0da4 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:35:42.0968 0x0da4 AsyncMac - ok
20:35:42.0984 0x0da4 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
20:35:42.0984 0x0da4 atapi - ok
20:35:43.0000 0x0da4 Atdisk - ok
20:35:43.0031 0x0da4 [ 121F65BB9401126D3292695CD8D0DF95, 863977266A89795EA50149F014378934036A86CB8D8203EE692FD3A862C2C545 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
20:35:43.0046 0x0da4 Ati HotKey Poller - ok
20:35:43.0281 0x0da4 [ 4B994DD3EC6F9C0457038AA1D8A315E4, CAD692B54681BEECF70D7568460A68741B6F72642B2D11F64D5DF1C8F1C0D40D ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:35:43.0390 0x0da4 ati2mtag - ok
20:35:43.0437 0x0da4 [ 0E4BB35C5305099AC82053AC992E3E0E, 51621C0E64B4FF576ED57143306F4E4A9D283815975CA6BA41452D2FFC6C313A ] ATITool C:\WINDOWS\system32\DRIVERS\ATITool.sys
20:35:43.0437 0x0da4 ATITool - ok
20:35:43.0453 0x0da4 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:35:43.0453 0x0da4 Atmarpc - ok
20:35:43.0468 0x0da4 [ DE31B88962A8645DBA5A37B993E7B0F1, CA93F25A3FD0CE68BB9B8E3AB6B813BF38DE3EDDFC990291B3957FAA59B2B274 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
20:35:43.0468 0x0da4 AudioSrv - ok
20:35:43.0500 0x0da4 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
20:35:43.0500 0x0da4 audstub - ok
20:35:43.0531 0x0da4 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
20:35:43.0531 0x0da4 Beep - ok
20:35:43.0562 0x0da4 [ 19395D092FD85DDC2D9C7729CF5A2AC8, 7640F36BA19698EE8A6257BF78A8C57DD9D734BED9CA6BB9B68603BAEA092412 ] BITS C:\WINDOWS\system32\qmgr.dll
20:35:43.0578 0x0da4 BITS - ok
20:35:43.0593 0x0da4 [ 89E739BBA5F636297EA5B5F811189E06, 151B32B12F5DD0D388134DA2471FE9741CF22B9C408DA58FEF8019D3C4EC836B ] Browser C:\WINDOWS\System32\browser.dll
20:35:43.0593 0x0da4 Browser - ok
20:35:43.0625 0x0da4 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
20:35:43.0625 0x0da4 cbidf2k - ok
20:35:43.0625 0x0da4 cd20xrnt - ok
20:35:43.0640 0x0da4 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
20:35:43.0640 0x0da4 Cdaudio - ok
20:35:43.0656 0x0da4 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
20:35:43.0656 0x0da4 Cdfs - ok
20:35:43.0671 0x0da4 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:35:43.0671 0x0da4 Cdrom - ok
20:35:43.0671 0x0da4 Changer - ok
20:35:43.0703 0x0da4 [ E390DC1D7C461D7D56EC53402F329928, FB37F84E71353CD83FCDDD39C898C6D84C05130C5F1BEF022E3DFDE160398C0E ] CiSvc C:\WINDOWS\system32\cisvc.exe
20:35:43.0703 0x0da4 CiSvc - ok
20:35:43.0718 0x0da4 [ 064507A8DFA8C5C7E2FFDDD3E6F424FA, 1725067BC759484A7185A4F1A44ED3CBE481529D187FE98EF279425B79177EB1 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
20:35:43.0734 0x0da4 ClipSrv - ok
20:35:43.0750 0x0da4 [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:35:43.0750 0x0da4 clr_optimization_v2.0.50727_32 - ok
20:35:43.0765 0x0da4 CmdIde - ok
20:35:43.0765 0x0da4 COMSysApp - ok
20:35:43.0921 0x0da4 [ DFA689CFD323F38FD12F3AC22ED4C5B6, 5F94A29346937CE044156CAA00AC2BA5794ECE5F6A02E5CBA46CB46C7708ED30 ] CoordinatorServiceHost C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
20:35:43.0921 0x0da4 CoordinatorServiceHost - ok
20:35:43.0937 0x0da4 Cpqarray - ok
20:35:43.0953 0x0da4 [ F3AB0933CBD166D271992F411C27CCAF, 50E01F3B058F814BE914FA5050B2D972E8584A467719A5ABCF9D9EBD596A54A7 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
20:35:43.0953 0x0da4 CryptSvc - ok
20:35:43.0953 0x0da4 dac2w2k - ok
20:35:43.0968 0x0da4 dac960nt - ok
20:35:44.0000 0x0da4 [ BE27674D1CBC3214AEC84B4336A38BBF, 3DF5F9A9E97595A61314B2731DF4F3D3C19D1B9D2291624A63B8E1861FFC2D76 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
20:35:44.0000 0x0da4 DcomLaunch - ok
20:35:44.0031 0x0da4 [ 8C9A53E285AC5E6704844D0459EC85BE, 9E86AF4C06CEC007C9B1590B6E056319603E4D79BED0C2471C6F1BC251B380CF ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
20:35:44.0031 0x0da4 Dhcp - ok
20:35:44.0062 0x0da4 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
20:35:44.0062 0x0da4 Disk - ok
20:35:44.0078 0x0da4 dmadmin - ok
20:35:44.0109 0x0da4 [ DB5FD2BF5B07DC54BFCB3664FF05BD7C, 46074FBBC5E4A40A7B3A45636089DEDD2A619778C7DCD797571C2BB64D775F7E ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
20:35:44.0125 0x0da4 dmboot - ok
20:35:44.0171 0x0da4 [ FFF1720AF51171F32F1EAD5CF71F2810, 2E40D63DC7670C1E88A532DB8923A98ABC8481C351C4D915C2753E10BA77F36D ] dmio C:\WINDOWS\system32\drivers\dmio.sys
20:35:44.0171 0x0da4 dmio - ok
20:35:44.0187 0x0da4 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
20:35:44.0187 0x0da4 dmload - ok
20:35:44.0203 0x0da4 [ 2BFEFE9E865655A76982F050450B9591, 15C7D093D638770519AA43E7D8897310F32AB1F217027F5750D799494A985C35 ] dmserver C:\WINDOWS\System32\dmserver.dll
20:35:44.0203 0x0da4 dmserver - ok
20:35:44.0234 0x0da4 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
20:35:44.0234 0x0da4 DMusic - ok
20:35:44.0250 0x0da4 [ DFAA406BF19F4EE806A6F8D4342137F7, EE2C11B3E37565FC009E323607B2F5F148F9219012EDF848CEFC1B273DAA98A9 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
20:35:44.0250 0x0da4 Dnscache - ok
20:35:44.0281 0x0da4 [ 4A3E2BD20157A0946751229E92EB8621, D8C00CC2C18C517F7262EBC3C511C062E5ABA797056AEB22AC5DEB306BA8C526 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
20:35:44.0281 0x0da4 Dot3svc - ok
20:35:44.0281 0x0da4 dpti2o - ok
20:35:44.0312 0x0da4 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
20:35:44.0312 0x0da4 drmkaud - ok
20:35:44.0343 0x0da4 [ C0C7CECCB6C85994C2BC92D58E52D3F2, 993483E6667D8D3AD2E64FD5A689DCB28B3910824B1E036DB626F334996DEAC9 ] dtsoftbus01 C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
20:35:44.0343 0x0da4 dtsoftbus01 - ok
20:35:44.0375 0x0da4 [ 0887D9C2BE8D940778CAD1E3B85F2A41, 2E30DC06D46A5E174B7CAA2D70BDB697015495942572E90425E2EE7AC541BCF4 ] EapHost C:\WINDOWS\System32\eapsvc.dll
20:35:44.0375 0x0da4 EapHost - ok
20:35:44.0390 0x0da4 [ A2A4912798F2BE706ABADD3D30800D16, CCCCA389D22525D984DE9B59E4CEBE0EEEF315F725176EB5C4DC1A5B6157234A ] ERSvc C:\WINDOWS\System32\ersvc.dll
20:35:44.0390 0x0da4 ERSvc - ok
20:35:44.0421 0x0da4 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] Eventlog C:\WINDOWS\system32\services.exe
20:35:44.0421 0x0da4 Eventlog - ok
20:35:44.0468 0x0da4 [ A371F11EF07653591C8DE26AFB13CE7F, 1192EDC8B146F1C27E8CD7E126DDC044F8B368C2E891A90CD81620D48C9550B6 ] EventSystem C:\WINDOWS\system32\es.dll
20:35:44.0468 0x0da4 EventSystem - ok
20:35:44.0500 0x0da4 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
20:35:44.0500 0x0da4 Fastfat - ok
20:35:44.0531 0x0da4 [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
20:35:44.0531 0x0da4 FastUserSwitchingCompatibility - ok
20:35:44.0562 0x0da4 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
20:35:44.0562 0x0da4 Fdc - ok
20:35:44.0578 0x0da4 [ AC366695A0796560AA37215AD5762AAF, 6ADC7443EA42D77199D4879AF3C33A07914116C69A34B895D8CB8444EE50077F ] Fips C:\WINDOWS\system32\drivers\Fips.sys
20:35:44.0578 0x0da4 Fips - ok
20:35:44.0656 0x0da4 [ 73081CF28F0AE20A52CA4F67CEE6E6B0, 806C769F3638D25FF1892C7223E7250AA3B9F627DF3AD83BC5AE1FEF7016F86A ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
20:35:44.0671 0x0da4 FLEXnet Licensing Service - ok
20:35:44.0703 0x0da4 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:35:44.0703 0x0da4 Flpydisk - ok
20:35:44.0734 0x0da4 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
20:35:44.0734 0x0da4 FltMgr - ok
20:35:44.0781 0x0da4 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:35:44.0781 0x0da4 FontCache3.0.0.0 - ok
20:35:44.0781 0x0da4 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:35:44.0781 0x0da4 Fs_Rec - ok
20:35:44.0812 0x0da4 [ 4E664D8541DB4A66B73A24257E322E1F, 17A2140AFE2B41E579FCCAFB82532853AD90A6EDBCB13DE80741DAE0AD5B4CC9 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:35:44.0828 0x0da4 Ftdisk - ok
20:35:44.0843 0x0da4 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:35:44.0843 0x0da4 Gpc - ok
20:35:44.0890 0x0da4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
20:35:44.0890 0x0da4 gupdate - ok
20:35:44.0906 0x0da4 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
20:35:44.0906 0x0da4 gupdatem - ok
20:35:44.0921 0x0da4 [ 573C7D0A32852B48F3058CFD8026F511, BC384BBA394AFDCDA1A9ABC858C692AA84A1F0A31AF3DDF7F38D120C027927FB ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:35:44.0921 0x0da4 HDAudBus - ok
20:35:44.0984 0x0da4 [ FCFE31FB75F8A6295B6B0AF87A626282, 6BA385797DBC73EB29EFE3293B80C21B1B8A1E9B87A462476E73C526C9565E5F ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:35:44.0984 0x0da4 helpsvc - ok
20:35:45.0000 0x0da4 [ 00E25EE90166B3E1BE6E74AEBF858306, 92C2F020EF14DE3B4F09E2C5DFF3D2F35D8C50F6D0188F9CEEFE3B6075602EFE ] HidServ C:\WINDOWS\System32\hidserv.dll
20:35:45.0000 0x0da4 HidServ - ok
20:35:45.0031 0x0da4 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:35:45.0031 0x0da4 hidusb - ok
20:35:45.0062 0x0da4 [ 7A6B320928F86BC851530D63C82965D9, 1F628759D31098DFBC05244735B5A62ACD8E45DBC5C9D236260D68EB8F1E28F5 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
20:35:45.0062 0x0da4 hkmsvc - ok
20:35:45.0078 0x0da4 hpn - ok
20:35:45.0109 0x0da4 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
20:35:45.0109 0x0da4 HTTP - ok
20:35:45.0140 0x0da4 [ 58FE2F2DA3BC5573F4A35B3760D3125F, B241ACCE426402EC64DC34C49CECB8CDC0851986D54BFCCED7040D6C43F5787A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
20:35:45.0140 0x0da4 HTTPFilter - ok
20:35:45.0156 0x0da4 i2omgmt - ok
20:35:45.0156 0x0da4 i2omp - ok
20:35:45.0187 0x0da4 [ C528E27945367191E7BAE364930B6932, 1B95C7B49B4CAE734DC6C9EC22555C5356EEC856B8491C761C777479264CF854 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:35:45.0187 0x0da4 i8042prt - ok
20:35:45.0250 0x0da4 [ DAF66902F08796F9C694901660E5A64A, F4A4764DED05980426BAB54AAF040BC27A39C80315F5161E8D0B4C7F694BD8E6 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
20:35:45.0250 0x0da4 IDriverT - ok
20:35:45.0296 0x0da4 [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:35:45.0312 0x0da4 idsvc - ok
20:35:45.0328 0x0da4 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
20:35:45.0343 0x0da4 Imapi - ok
20:35:45.0359 0x0da4 [ F7B93AAFAD33B2320954C17E26C8D361, 8CFDB11A68B59E195F280BE08B25FA59F1F70833832919B8BECCE17616999934 ] ImapiService C:\WINDOWS\system32\imapi.exe
20:35:45.0359 0x0da4 ImapiService - ok
20:35:45.0375 0x0da4 ini910u - ok
20:35:45.0375 0x0da4 IntelIde - ok
20:35:45.0390 0x0da4 [ 27B290D632AF2CF3CF40BFDDB7370985, 2C266777B4A96706658B8C9A7B30D15D6E495C815FAE23A0A1FC747E9B5AE363 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:35:45.0390 0x0da4 intelppm - ok
20:35:45.0421 0x0da4 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
20:35:45.0421 0x0da4 Ip6Fw - ok
20:35:45.0437 0x0da4 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:35:45.0437 0x0da4 IpFilterDriver - ok
20:35:45.0453 0x0da4 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:35:45.0453 0x0da4 IpInIp - ok
20:35:45.0484 0x0da4 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:35:45.0500 0x0da4 IpNat - ok
20:35:45.0515 0x0da4 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:35:45.0515 0x0da4 IPSec - ok
20:35:45.0546 0x0da4 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
20:35:45.0546 0x0da4 IRENUM - ok
20:35:45.0578 0x0da4 [ CC9F8A2D60AED1A51A3AC34C59B987AE, CBF69817BE3D9A4617390B1A3306074CB8581F21562CD1357D32BC3E542F3CEE ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:35:45.0578 0x0da4 isapnp - ok
20:35:45.0656 0x0da4 [ 80A79264302910C7C24BA7E44267EFEF, 6080C233478350C8E07515D20D2D60C3758C4A65432B04E8C8B816248621A3EF ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
20:35:45.0656 0x0da4 JavaQuickStarterService - ok
20:35:45.0671 0x0da4 [ 1B6162FE7F66B1A71A4B70F941C4AA9B, C2EA494BAB0513A6027414FB1E75834F980A77852D0DC8559E8942FC222A075A ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:35:45.0671 0x0da4 Kbdclass - ok
20:35:45.0687 0x0da4 [ 86C8F23616C6C6E5B2776901C17B945B, 211B63FC405A2DDB126D204D61E779D66C7211882CC0374521926C633E180B91 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:35:45.0687 0x0da4 kbdhid - ok
20:35:45.0703 0x0da4 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
20:35:45.0703 0x0da4 kmixer - ok
20:35:45.0750 0x0da4 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
20:35:45.0750 0x0da4 KSecDD - ok
20:35:45.0765 0x0da4 [ FE12CDEA33DC5430E4A3F55D1D0F73BF, 949D349CC8B37AA3C4C0C32869ECB693074452DE77F8C6071BA5E4E02B967AD1 ] kvpndev C:\WINDOWS\system32\DRIVERS\kvpndrv.sys
20:35:45.0765 0x0da4 kvpndev - ok
20:35:45.0796 0x0da4 [ 3428E8F86F8ADD36B42FB23542C7B3E4, 9CF643D1A70AF08407ACD5FD6FE4B8777521DDF41B5E63C2E6E1E4CAAC69A403 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
20:35:45.0812 0x0da4 lanmanserver - ok
20:35:45.0828 0x0da4 [ 936C1D110232D23B621CB0196E4F80F0, 2DE3AF93E20F1DC7A6FF31B18054EA4D2350387E4DA91C4B16D451384F0C57E2 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
20:35:45.0828 0x0da4 lanmanworkstation - ok
20:35:45.0828 0x0da4 lbrtfdc - ok
20:35:45.0875 0x0da4 [ 0AB159F536E3E8F7F07113702A07CCA5, 3218C553183E6697C663B6D12790E09756B50505590858DD5AC62411D37CDD7C ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
20:35:45.0875 0x0da4 LmHosts - ok
20:35:45.0890 0x0da4 [ 4470E3C1E0C3378E4CAB137893C12C3A, CA8E66356F0E671D5454E561E7EAD74DE25DCF53BE452369F96ECACFA8709489 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
20:35:45.0890 0x0da4 MBAMProtector - ok
20:35:45.0937 0x0da4 [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
20:35:45.0953 0x0da4 MBAMScheduler - ok
20:35:45.0984 0x0da4 [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
20:35:46.0000 0x0da4 MBAMService - ok
20:35:46.0015 0x0da4 [ 221CD1C815B8A6B79389C3F5D1018DE8, 6D0D25D6669C4F9452F74EC72C6138A41D9408E01AF5FD01C08F27BE7BC9C905 ] Messenger C:\WINDOWS\System32\msgsvc.dll
20:35:46.0015 0x0da4 Messenger - ok
20:35:46.0078 0x0da4 [ FAFE367D032ED82E9332B4C741A20216, 7B123766E360570E0FCB211835B7910D6A1806C25A06BCA9227AB9E993376CA8 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
20:35:46.0093 0x0da4 Microsoft Office Groove Audit Service - ok
20:35:46.0125 0x0da4 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
20:35:46.0125 0x0da4 mnmdd - ok
20:35:46.0140 0x0da4 [ 9A57D046F88F4B69751B11FD40088A61, 62F65433024CE411F111A88723747B8A83B31076FBAF4CFF40FD02A53D7FF7DF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
20:35:46.0140 0x0da4 mnmsrvc - ok
20:35:46.0156 0x0da4 [ 44032B0C6D9954D3FD26438330B99EE7, A49749A4C00D50F57170AA5DA9E2DEECC8C524A48B144C8B784894F2C202FBEE ] Modem C:\WINDOWS\system32\drivers\Modem.sys
20:35:46.0156 0x0da4 Modem - ok
20:35:46.0171 0x0da4 [ 4CB582831DBDE63CE43B45D771218374, 6D470B26197C5B388983D9213D48D2CDE934C9591572876DC7790FE4B59E0845 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:35:46.0171 0x0da4 Mouclass - ok
20:35:46.0187 0x0da4 [ BB269EBA740737AB749B214D568B6812, ABF41D9B521EBBE674E76981CAD31F8FD05976DE7070266C3956FDB67C83C4C2 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:35:46.0187 0x0da4 mouhid - ok
20:35:46.0218 0x0da4 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
20:35:46.0218 0x0da4 MountMgr - ok
20:35:46.0265 0x0da4 [ 5D494509432897338AFC19DB78A76DCB, 873F61F45D4A96096E17F9E266B1A20CCD65E4678DDB21DDE3DB98E831E524D3 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:35:46.0265 0x0da4 MozillaMaintenance - ok
20:35:46.0265 0x0da4 mraid35x - ok
20:35:46.0281 0x0da4 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:35:46.0296 0x0da4 MRxDAV - ok
20:35:46.0328 0x0da4 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:35:46.0343 0x0da4 MRxSmb - ok
20:35:46.0375 0x0da4 [ 6DB4D1521CABA9A5FFAB54ADE0AE867D, 78D63EE2C0B0852F0771071C099643242EBC9F4DA28847B93BCE9C3CC1091938 ] MSDTC C:\WINDOWS\system32\msdtc.exe
20:35:46.0375 0x0da4 MSDTC - ok
20:35:46.0406 0x0da4 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
20:35:46.0406 0x0da4 Msfs - ok
20:35:46.0406 0x0da4 MSIServer - ok
20:35:46.0421 0x0da4 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:35:46.0421 0x0da4 MSKSSRV - ok
20:35:46.0437 0x0da4 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:35:46.0437 0x0da4 MSPCLOCK - ok
20:35:46.0453 0x0da4 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
20:35:46.0453 0x0da4 MSPQM - ok
20:35:46.0468 0x0da4 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:35:46.0468 0x0da4 mssmbios - ok
20:35:46.0625 0x0da4 [ 73FA09B84B23A1897809A84F976D5D99, 8ADBEE035DF08DB860D56597C88230F4ECE80B214A13AF22D5D5475C9B7FEFC1 ] msvsmon80 C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
20:35:46.0671 0x0da4 msvsmon80 - ok
20:35:46.0703 0x0da4 [ D48659BB24C48345D926ECB45C1EBDF5, EDEDE58316827530C25F8085F62AD48EA6D44B0F8AC1917B940F53B02CF72EA6 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
20:35:46.0703 0x0da4 MTsensor - ok
20:35:46.0734 0x0da4 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
20:35:46.0734 0x0da4 Mup - ok
20:35:46.0765 0x0da4 [ 6EA362E9DB03D44F6B996F4D8BE237E9, FE6B4C546D26C4A2832CF4CB280B86B1723E10E46A3C24AF6C9856FCCAE9D1FC ] napagent C:\WINDOWS\System32\qagentrt.dll
20:35:46.0765 0x0da4 napagent - ok
20:35:46.0796 0x0da4 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
20:35:46.0812 0x0da4 NDIS - ok
20:35:46.0828 0x0da4 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:35:46.0828 0x0da4 NdisTapi - ok
20:35:46.0843 0x0da4 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:35:46.0843 0x0da4 Ndisuio - ok
20:35:46.0859 0x0da4 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:35:46.0875 0x0da4 NdisWan - ok
20:35:46.0890 0x0da4 [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
20:35:46.0890 0x0da4 NDProxy - ok
20:35:46.0921 0x0da4 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
20:35:46.0921 0x0da4 NetBIOS - ok
20:35:46.0953 0x0da4 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
20:35:46.0953 0x0da4 NetBT - ok
20:35:46.0968 0x0da4 [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDE C:\WINDOWS\system32\netdde.exe
20:35:46.0968 0x0da4 NetDDE - ok
20:35:46.0984 0x0da4 [ 933DE774986EC85E48210C44AB431DE6, B8C85085003792B8744D96585CE6F2BC474EEEEC364A100CCBCE08176D91E75C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
20:35:46.0984 0x0da4 NetDDEdsdm - ok
20:35:47.0015 0x0da4 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] Netlogon C:\WINDOWS\system32\lsass.exe
20:35:47.0015 0x0da4 Netlogon - ok
20:35:47.0031 0x0da4 [ 72E1E9E2977BE08BDEEDB6D8FD9D4D40, 588C8BA14A7255FD36A88960CBE34341301773765ECF2A9A0F1760A509A08A5B ] Netman C:\WINDOWS\System32\netman.dll
20:35:47.0046 0x0da4 Netman - ok
20:35:47.0062 0x0da4 [ D34612C5D02D026535B3095D620626AE, 1BBCCCBF49EB8807240A77DCB43C25C21682073CC5356594E2C4F53EF36BF657 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:35:47.0078 0x0da4 NetTcpPortSharing - ok
20:35:47.0093 0x0da4 [ E9E47CFB2D461FA0FC75B7A74C6383EA, 544136F5BFD4DC23D45E90F12FA48B82FD9EAEA9EAF3E0F5F0BD27E23D672C3E ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
20:35:47.0093 0x0da4 NIC1394 - ok
20:35:47.0109 0x0da4 [ 39EE7C3BFBC64BA87CC8CF67386E814C, B93CCB625CE370D9A49C9374D24C939D7C9FEF81401F4F822C51E12677D77E01 ] Nla C:\WINDOWS\System32\mswsock.dll
20:35:47.0125 0x0da4 Nla - ok
20:35:47.0140 0x0da4 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
20:35:47.0140 0x0da4 Npfs - ok
20:35:47.0187 0x0da4 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
20:35:47.0187 0x0da4 Ntfs - ok
20:35:47.0203 0x0da4 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
20:35:47.0203 0x0da4 NtLmSsp - ok
20:35:47.0234 0x0da4 [ 023DD70573D644F3D9C8B1258A7BFD08, 9A1D3210ED5FD8BEDF92ED577A9B30E37035408A73EB66A8C950B75AB7539B83 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
20:35:47.0250 0x0da4 NtmsSvc - ok
20:35:47.0281 0x0da4 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
20:35:47.0281 0x0da4 Null - ok
20:35:47.0296 0x0da4 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:35:47.0296 0x0da4 NwlnkFlt - ok
20:35:47.0312 0x0da4 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:35:47.0312 0x0da4 NwlnkFwd - ok
20:35:47.0390 0x0da4 [ 84DE1DD996B48B05ACE31AD015FA108A, 4B9D1E4EF83ECED6C77F23D9879C124534F7053D7423E3A2D0F67A4A720CEA94 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
20:35:47.0406 0x0da4 odserv - ok
20:35:47.0421 0x0da4 [ CA33832DF41AFB202EE7AEB05145922F, 9DD0089C2E13C7F81214C3B5A4A61276292052F9BBFEA7FCD0F6AA27815D5F95 ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
20:35:47.0421 0x0da4 ohci1394 - ok
20:35:47.0453 0x0da4 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:35:47.0453 0x0da4 ose - ok
20:35:47.0468 0x0da4 [ 46F8DB73B4A53E543F8E371DC7C75BAE, F6C5E7DE4B4AE0ED785DB075BE14EA6A0FC9050C95669B26DEF2B82D7B7D3B2C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
20:35:47.0484 0x0da4 Parport - ok
20:35:47.0500 0x0da4 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
20:35:47.0500 0x0da4 PartMgr - ok
20:35:47.0500 0x0da4 [ 1FAE19D0457176318BBA4A8795656EBC, 5F3D6CABA203A0485D67F63A6A81151724EE200BE49ED095CFCB1EF29C19D19F ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
20:35:47.0500 0x0da4 ParVdm - ok
20:35:47.0531 0x0da4 [ 6CE351D149CB4BEFC702951E471E1730, 758327683BB45F01D5AE550AF21856822B4CF55E17F2A4F452F559088D242B37 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
20:35:47.0531 0x0da4 PCI - ok
20:35:47.0531 0x0da4 PCIDump - ok
20:35:47.0562 0x0da4 [ 2DA4EC85E0EA7A45C6B2A05820492D5A, A8C6BD93D3BC33A5B36EB523997EF9E0783B6E6EAFB6E7F58BCC2629009BDCF9 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
20:35:47.0562 0x0da4 PCIIde - ok
20:35:47.0593 0x0da4 [ 4FC31E6C19A5CE5198B1ABFF94CAE758, A031E21EC1F15DA5E8429269F435337FA961C3C06D535DAFD448C7355F33FD0C ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
20:35:47.0593 0x0da4 Pcmcia - ok
20:35:47.0593 0x0da4 PDCOMP - ok
20:35:47.0609 0x0da4 PDFRAME - ok
20:35:47.0609 0x0da4 PDRELI - ok
20:35:47.0625 0x0da4 PDRFRAME - ok
20:35:47.0625 0x0da4 perc2 - ok
20:35:47.0640 0x0da4 perc2hib - ok
20:35:47.0671 0x0da4 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] PlugPlay C:\WINDOWS\system32\services.exe
20:35:47.0671 0x0da4 PlugPlay - ok
20:35:47.0703 0x0da4 [ 205E1B699FD3F2F9B036EEA2EC30C620, 9D5C8009BC3F6F76438FC82C3DAAA3E9CC87F74CDE841A0ADD9EF00E98DB6890 ] PnkBstrA C:\WINDOWS\system32\PnkBstrA.exe
20:35:47.0703 0x0da4 PnkBstrA - ok
20:35:47.0718 0x0da4 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
20:35:47.0718 0x0da4 PolicyAgent - ok
20:35:47.0718 0x0da4 PortmapperService - ok
20:35:47.0750 0x0da4 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:35:47.0750 0x0da4 PptpMiniport - ok
20:35:47.0781 0x0da4 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
20:35:47.0781 0x0da4 ProtectedStorage - ok
20:35:47.0796 0x0da4 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
20:35:47.0796 0x0da4 PSched - ok
20:35:47.0812 0x0da4 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:35:47.0828 0x0da4 Ptilink - ok
20:35:47.0828 0x0da4 ql1080 - ok
20:35:47.0828 0x0da4 Ql10wnt - ok
20:35:47.0843 0x0da4 ql12160 - ok
20:35:47.0843 0x0da4 ql1240 - ok
20:35:47.0859 0x0da4 ql1280 - ok
20:35:47.0875 0x0da4 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:35:47.0875 0x0da4 RasAcd - ok
20:35:47.0906 0x0da4 [ 2B5E44EA009F2F374B980E1E9A70635D, 62D8FDB80C8ACBA2C42C12760B785587C43BEDFE015EC5C41B25F2BB735EFEB0 ] RasAuto C:\WINDOWS\System32\rasauto.dll
20:35:47.0906 0x0da4 RasAuto - ok
20:35:47.0921 0x0da4 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:35:47.0921 0x0da4 Rasl2tp - ok
20:35:47.0937 0x0da4 [ D57554C664B64604BD1EE13EA2C07E77, B090C05B91EA602BFF9A5E89AB1A0FFDE869611961FF749DA8B3F4D00F04E756 ] RasMan C:\WINDOWS\System32\rasmans.dll
20:35:47.0937 0x0da4 RasMan - ok
20:35:47.0968 0x0da4 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:35:47.0968 0x0da4 RasPppoe - ok
20:35:47.0984 0x0da4 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
20:35:47.0984 0x0da4 Raspti - ok
20:35:48.0000 0x0da4 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:35:48.0015 0x0da4 Rdbss - ok
20:35:48.0015 0x0da4 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:35:48.0015 0x0da4 RDPCDD - ok
20:35:48.0062 0x0da4 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:35:48.0062 0x0da4 rdpdr - ok
20:35:48.0093 0x0da4 [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
20:35:48.0093 0x0da4 RDPWD - ok
20:35:48.0109 0x0da4 [ C0D9D9711CB74EE9BC66353D8CBDAB0E, F1AF9A26910707E76BF213D8DE5C902B0088D8A29EBDFF72DE6A4D867E298CC8 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
20:35:48.0109 0x0da4 RDSessMgr - ok
20:35:48.0125 0x0da4 [ 611BFD220305BE3A85AE876EA47D4AA5, FDF87878EB3886649025E5A12F1C3FC9072D66CCD3217944710085C1F8A4512E ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
20:35:48.0125 0x0da4 redbook - ok
20:35:48.0156 0x0da4 [ 127C26B5371651043450E52542099ABA, 98AADAD8D5211CB894AA7C59B6299861B1F44B6D8F46AB5837E7D2F5B615B14A ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
20:35:48.0156 0x0da4 RemoteAccess - ok
20:35:48.0187 0x0da4 [ 8F31505484A190D5B22274708799F4EC, 170FF8193C95CEE73B9342B6FB7D83DF4E80B2CCBB27DF41F4AB5F2FB9AF60E1 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
20:35:48.0187 0x0da4 RemoteRegistry - ok
20:35:48.0203 0x0da4 [ 718B3BDC0BC3C2F7D065A53D26202AF9, 9E58243628F1E1396AB82A80D046FF50803A230EE07B007E0CA5D744C77B091A ] RpcLocator C:\WINDOWS\system32\locator.exe
20:35:48.0203 0x0da4 RpcLocator - ok
20:35:48.0234 0x0da4 [ BE27674D1CBC3214AEC84B4336A38BBF, 3DF5F9A9E97595A61314B2731DF4F3D3C19D1B9D2291624A63B8E1861FFC2D76 ] RpcSs C:\WINDOWS\system32\rpcss.dll
20:35:48.0250 0x0da4 RpcSs - ok
20:35:48.0265 0x0da4 [ 09AB2E71E58B078038E3BFDBA7FFC984, 8CA277DEEF6376B0F48C6BA5DBBC3E8AF2245983BA9AF6AB83D1A920D35FAF93 ] RSVP C:\WINDOWS\system32\rsvp.exe
20:35:48.0265 0x0da4 RSVP - ok
20:35:48.0296 0x0da4 [ 1E11171C0B9989E1BDAA59E96B2E81C4, C49D3E63DF561800AA498BDE587EFDEDF675BD0A0A7FA35E436365691C539F7E ] RTL8023xp C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
20:35:48.0296 0x0da4 RTL8023xp - ok
20:35:48.0328 0x0da4 [ 05552E37B5C0B53B7E4B95A850447E85, 1B0C8943B590C6EC26A72B0E2E5076CFD3E84A4C033DA8BB3DB8CD93BA0704F6 ] RTLWUSB C:\WINDOWS\system32\DRIVERS\RTL8187.sys
20:35:48.0328 0x0da4 RTLWUSB - ok
20:35:48.0343 0x0da4 [ ED0A176354487CEED65B80A7148AB739, 71295D7D7684539DBD2924B437660960C01E073A521FE12D1519969327EC8DC4 ] SamSs C:\WINDOWS\system32\lsass.exe
20:35:48.0343 0x0da4 SamSs - ok
20:35:48.0375 0x0da4 [ 410046E401EB11E1E6749E9DEEA41D4A, 9507268ACD24EF51E994DC418E8EB3E10DEDE61EE892226A22A5DA7662397E25 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
20:35:48.0375 0x0da4 SCardSvr - ok
20:35:48.0406 0x0da4 [ 3FF232A7731621B8902D81D42418C93C, 2030C9A843D9555170179883BD4CC1E978D5FC5EC0D7FCA56518224E428BE421 ] Schedule C:\WINDOWS\system32\schedsvc.dll
20:35:48.0406 0x0da4 Schedule - ok
20:35:48.0421 0x0da4 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:35:48.0421 0x0da4 Secdrv - ok
20:35:48.0453 0x0da4 [ 477E2C3CC5E4A0D635BCB0EA8DCAC3C6, 82EEB2345AC19050FAB202DE76C2CDD93E753F5AB67789A86A1726D3040C02E5 ] seclogon C:\WINDOWS\System32\seclogon.dll
20:35:48.0453 0x0da4 seclogon - ok
20:35:48.0484 0x0da4 [ B6A6B409FDA9D9EBD3AADB838D3D7173, 0A9A4C15C83AACBA9FC87B674CB17375DE988B41448A65101647AE67BDD15377 ] SenFiltService C:\WINDOWS\system32\drivers\Senfilt.sys
20:35:48.0500 0x0da4 SenFiltService - ok
20:35:48.0515 0x0da4 [ A530B75C10C23C9AB28FDB6CE719E21F, 14568DF6457758E2F534A46A8E6245C364895C3993BEF2B5A889B98DBB201A27 ] SENS C:\WINDOWS\system32\sens.dll
20:35:48.0515 0x0da4 SENS - ok
20:35:48.0515 0x0da4 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
20:35:48.0515 0x0da4 serenum - ok
20:35:48.0546 0x0da4 [ B842729337C9B921615C40D3C1A1AF96, 503670A56423B996C6ED6AE95F07FB88910767C4A2041A4BE9070C57A016E7FA ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
20:35:48.0546 0x0da4 Serial - ok
20:35:48.0593 0x0da4 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
20:35:48.0593 0x0da4 Sfloppy - ok
20:35:48.0609 0x0da4 [ F58FACA9621D2DB01BD0927D9A0A208E, 239C87E09261BC9D1DBE99DABCFC4787D42289E8769563A5EFB323BE6F177C9A ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
20:35:48.0625 0x0da4 SharedAccess - ok
20:35:48.0640 0x0da4 [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
20:35:48.0640 0x0da4 ShellHWDetection - ok
20:35:48.0656 0x0da4 Simbad - ok
20:35:48.0687 0x0da4 [ F07AF60B152221472FBDB2FECEC4896D, A18FDCE8462A48429E249C44F0E49F844F2E3A4B5215349DE104F34D935EF983 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
20:35:48.0687 0x0da4 SkypeUpdate - ok
20:35:48.0734 0x0da4 [ 4945020BC094C322571184A6E8056B3A, 9E09257411F7C3631537D0198E0E64CDD1A697D80430F6379139B15A2BA8A6C9 ] SolidWorks Licensing Service C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
20:35:48.0734 0x0da4 SolidWorks Licensing Service - ok
20:35:48.0734 0x0da4 Sparrow - ok
20:35:48.0765 0x0da4 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
20:35:48.0765 0x0da4 splitter - ok
20:35:48.0796 0x0da4 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
20:35:48.0796 0x0da4 Spooler - ok
20:35:48.0812 0x0da4 [ 94610C8653635E4459316A0050D55CE7, D148D33B3D2B0757060531C526F2161504A8D7C4E5957D092C7EBDB007271339 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
20:35:48.0812 0x0da4 sr - ok
20:35:48.0828 0x0da4 [ 35B91147124F64AC8081A2EDB9EA4DEE, 1609D19156DAC6EE3C2D2350B062966B64D9CDC289E9B8FEB6D244AAEBE90BBF ] srservice C:\WINDOWS\system32\srsvc.dll
20:35:48.0828 0x0da4 srservice - ok
20:35:48.0859 0x0da4 [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
20:35:48.0875 0x0da4 Srv - ok
20:35:48.0875 0x0da4 [ BECD5271DC4E3B7C3D035F790FCBC1E5, D63B9DB81332553C963EC5057D241CE2287AF652387333C1FD79AF8C9B5F2BA7 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
20:35:48.0890 0x0da4 SSDPSRV - ok
20:35:48.0921 0x0da4 [ C1CDD9275F6A115BB0AE1D55D8D27BA6, CD0511FD7F6AD832CBEB931C605AB3AD217631C57399CB8033248D27619541E4 ] stisvc C:\WINDOWS\system32\wiaservc.dll
20:35:48.0937 0x0da4 stisvc - ok
20:35:48.0953 0x0da4 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
20:35:48.0953 0x0da4 swenum - ok
20:35:48.0968 0x0da4 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
20:35:48.0984 0x0da4 swmidi - ok
20:35:48.0984 0x0da4 SwPrv - ok
20:35:49.0000 0x0da4 symc810 - ok
20:35:49.0000 0x0da4 symc8xx - ok
20:35:49.0000 0x0da4 sym_hi - ok
20:35:49.0015 0x0da4 sym_u3 - ok
20:35:49.0031 0x0da4 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
20:35:49.0031 0x0da4 sysaudio - ok
20:35:49.0046 0x0da4 [ CE06F01B88ACE199A1BF460CAC29C110, 3CD89E5B8E53203287D889C107E4795225742DB6C6ACA2DC0611BD9728382A27 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
20:35:49.0046 0x0da4 SysmonLog - ok
20:35:49.0062 0x0da4 [ C2546CD7A398476F9DF5614B2AE160E8, 11C8435BA983553E9C0806494E9B3C7080515C0375B0604F029D89B50726161A ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
20:35:49.0078 0x0da4 TapiSrv - ok
20:35:49.0093 0x0da4 [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:35:49.0109 0x0da4 Tcpip - ok
20:35:49.0125 0x0da4 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
20:35:49.0125 0x0da4 TDPIPE - ok
20:35:49.0140 0x0da4 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
20:35:49.0140 0x0da4 TDTCP - ok
20:35:49.0156 0x0da4 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
20:35:49.0171 0x0da4 TermDD - ok
20:35:49.0203 0x0da4 [ A75DD6FC3DBEE4FFF5EBC9F2C28BB66E, 3D2B1D899061448EAD993CDE97D1EF50DD64728E9F44D80FEAE591198A937653 ] TermService C:\WINDOWS\System32\termsrv.dll
20:35:49.0203 0x0da4 TermService - ok
20:35:49.0218 0x0da4 [ EE9A2B9EA968A792A053C9D1A86BF870, 39798179F2EA42216CBE98F08ADA3675A87BD0C31A66534367B96CB129AF36BA ] Themes C:\WINDOWS\System32\shsvcs.dll
20:35:49.0234 0x0da4 Themes - ok
20:35:49.0250 0x0da4 [ CD0CC7B167D78043A41C98D4921EFB54, 31AAB5D6D6BA52EBDDE1B5DEB8F9B4D9597FFBA4485F959C846F635060CCB5C0 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
20:35:49.0250 0x0da4 TlntSvr - ok
20:35:49.0250 0x0da4 TosIde - ok
20:35:49.0296 0x0da4 [ 5E7BB54CDA00B664938AE4090CF9857F, 8FA2D42C3583B9978A5BA5D02E22F3FFD37BB26DB09AF7D23593B76A48FA54BC ] TotRec7 C:\WINDOWS\system32\drivers\TotRec7.sys
20:35:49.0296 0x0da4 TotRec7 - ok
20:35:49.0312 0x0da4 [ 38853304CCB938D30E0C4CDE8D2C2A8A, 966E7BCC9F63A1A7777F8A12E51C2A91EC688CE96109943ADC4CB4EB58DC34A6 ] TrkWks C:\WINDOWS\system32\trkwks.dll
20:35:49.0328 0x0da4 TrkWks - ok
20:35:49.0359 0x0da4 [ 4196D7BC21786883201747DCC0DC84A0, FF2F2EF2F54E683BF47DFCB90EAF55EB4245517F9062F0D564D3BC43A17C3DC3 ] TuneUp.Defrag C:\WINDOWS\System32\TuneUpDefragService.exe
20:35:49.0375 0x0da4 TuneUp.Defrag - ok
20:35:49.0406 0x0da4 [ 02E5F68A55CD413C5BFB9F2DF677DD01, C85A745586BCC23E1C1F6DBB32C67F46DBBE8020F5E68F82AD054DA45A62CAD6 ] TuneUp.ProgramStatisticsSvc C:\WINDOWS\System32\TUProgSt.exe
20:35:49.0421 0x0da4 TuneUp.ProgramStatisticsSvc - ok
20:35:49.0437 0x0da4 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
20:35:49.0437 0x0da4 Udfs - ok
20:35:49.0437 0x0da4 ultra - ok
20:35:49.0468 0x0da4 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
20:35:49.0484 0x0da4 Update - ok
20:35:49.0500 0x0da4 [ 651BD90DCEE5B7BDC74A2EB7C9266F9E, AF7662BCA0819F82CE5EE0863E47149CC127DE664CB3DC6359B63FBD71DB54F8 ] upnphost C:\WINDOWS\System32\upnphost.dll
20:35:49.0500 0x0da4 upnphost - ok
20:35:49.0531 0x0da4 [ 20A0F6A11959E92908717D09E87D670D, 3DD6C99AB0F70FAA43DF470B30078B8A51B8AF735CD5C50DBB195FEA70F4C36E ] UPS C:\WINDOWS\System32\ups.exe
20:35:49.0531 0x0da4 UPS - ok
20:35:49.0546 0x0da4 [ 1B611611C28D2DF25BC057D79C6F13FC, B0D86F63E44B40413BBAE6402CC088046CFAE082D41BBC2ED5A916293356B846 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:35:49.0546 0x0da4 usbccgp - ok
20:35:49.0562 0x0da4 [ 4BAC8DF07F1D8434FC640E677A62204E, 76C1351AF6752224BF59DEEE0F8665FE699F3DFD679F5BCD01C7D9383E6402A4 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:35:49.0562 0x0da4 usbehci - ok
20:35:49.0578 0x0da4 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:35:49.0578 0x0da4 usbhub - ok
20:35:49.0609 0x0da4 [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
20:35:49.0609 0x0da4 usbprint - ok
20:35:49.0640 0x0da4 [ F8EDE2B6928970DCE3D5614C27D9E7F6, 6E5EBBC8B70C1D593634DAF0C190DEADFDA18C3CBC8F552A76F156F3869EF05B ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:35:49.0640 0x0da4 usbscan - ok
20:35:49.0671 0x0da4 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:35:49.0671 0x0da4 USBSTOR - ok
20:35:49.0703 0x0da4 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:35:49.0718 0x0da4 usbuhci - ok
20:35:49.0750 0x0da4 [ 4360D5653E885479FED75C378E9FAAB3, CC19C61A7FE52C655C6180D03C81068F7336D983C93AD848EBF5233F80D83EF7 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll
20:35:49.0750 0x0da4 UxTuneUp - ok
20:35:49.0781 0x0da4 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
20:35:49.0781 0x0da4 VgaSave - ok
20:35:49.0781 0x0da4 ViaIde - ok
20:35:49.0812 0x0da4 [ 28A4B296B47782173C346E376CB374D1, FE799FE4A41752A2B47027EA88214BF3E39B317302939F4A2D0F2A4EFAAC2F13 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
20:35:49.0812 0x0da4 VolSnap - ok
20:35:49.0906 0x0da4 [ D6BA1A63D9E00933F1CD2A885573AFB2, 36311A060635CEC1DBB6D8A746B8A4D007706EAE97D51A5E12F9958AB16BE486 ] VSS C:\WINDOWS\System32\vssvc.exe
20:35:49.0921 0x0da4 VSS - ok
20:35:49.0937 0x0da4 [ FA4E1CDBA256787F2149F4AAD07BC91F, 1B5FC5248335D70094D04501AA2C30F54782B58FF8D573BE8E784A21529C7CAF ] W32Time C:\WINDOWS\system32\w32time.dll
20:35:49.0937 0x0da4 W32Time - ok
20:35:49.0968 0x0da4 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:35:49.0968 0x0da4 Wanarp - ok
20:35:49.0984 0x0da4 WDICA - ok
20:35:50.0000 0x0da4 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
20:35:50.0000 0x0da4 wdmaud - ok
20:35:50.0031 0x0da4 [ 47AE51048A82DFA1CD6B51D369F7E169, 742F2162B8BDE00D83715093EA9743338964597ED22648B9F4F139D7278235A4 ] WebClient C:\WINDOWS\System32\webclnt.dll
20:35:50.0031 0x0da4 WebClient - ok
20:35:50.0078 0x0da4 [ E488332126E3B1182D2B8A0C35408EC6, F9F60911DF0A539753B2BEF6FAD2D0AED1BC1C3F43509F79D9AF2F810CDE5D9B ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
20:35:50.0078 0x0da4 winmgmt - ok
20:35:50.0109 0x0da4 [ 6199B2AE3F9DB9CB6DB230471A1DC601, E66C788C3E46AAC2ABB76F6E55E912EB28CF3D4C3D74FE6E85A6FABB7F22A5C9 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
20:35:50.0125 0x0da4 WmdmPmSN - ok
20:35:50.0156 0x0da4 [ 0171CFF34BBA8C5977F18C48D8AEF8C6, 0E3E04220157CCFB92F8D029805EB56D101C2A3AB3375354537FA9B5B3CAA0AD ] Wmi C:\WINDOWS\System32\advapi32.dll
20:35:50.0156 0x0da4 Wmi - ok
20:35:50.0203 0x0da4 [ 23F6F03272F7E5679F1F050AED5ACEE6, 87EBE773F3E8FFE2F1E1DB435BB0E8852031AA88112EB791085AD3DA918B49CC ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:35:50.0218 0x0da4 WmiApSrv - ok
20:35:50.0250 0x0da4 [ 6ABE6E225ADB5A751622A9CC3BC19CE8, 4061C5D0F051DFF1730E2A3BFC1CCA97B29602FC50F10F6B44D93B0D28F42024 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:35:50.0250 0x0da4 WS2IFSL - ok
20:35:50.0265 0x0da4 [ 4C86D5FAF78194995AF9CC1075F65DD3, D3B23BB0971E0DBC0A51720067489C224323B603178E91149BF56F779DE352F0 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
20:35:50.0265 0x0da4 wscsvc - ok
20:35:50.0281 0x0da4 [ C1364564800EE9784192145324A23308, 5345BAE00364233594C9CF99CE2CC485E65B5D4FFBB81C86B2950EDA2427584C ] wuauserv C:\WINDOWS\system32\wuauserv.dll
20:35:50.0281 0x0da4 wuauserv - ok
20:35:50.0312 0x0da4 [ A27D4BA7264C0BF52F32D10405BEA1D4, 5F28607CCAB15FB601BEB35FF0B1A5CD27C678C6D1CA724E842C33EED4579B8C ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
20:35:50.0328 0x0da4 WZCSVC - ok
20:35:50.0343 0x0da4 [ EAA4BB9EDB3FB10CF8979FE65E63658F, B80EB477100FD3E26513360E09DB6EBF0C8D8B0618F1F4BF1F387ABA6DEC9B64 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
20:35:50.0359 0x0da4 xmlprov - ok
20:35:50.0406 0x0da4 [ 05D48E56EA2612D39A4E7F0ECC17B917, 8BDCA6BC0C1DC899916A08337646308E59913732BC68317EDABD9EDF15AD18AD ] yukonwxp C:\WINDOWS\system32\DRIVERS\yk51x86.sys
20:35:50.0406 0x0da4 yukonwxp - ok
20:35:50.0421 0x0da4 ================ Scan global ===============================
20:35:50.0453 0x0da4 [ F36278E42C8C5DF03CE17DAC8231C91C, D012A3C8F394DF4F0BF5D5A4C10E73BBF427762B7D3DB6CF5FAB96536E082B7A ] C:\WINDOWS\system32\basesrv.dll
20:35:50.0468 0x0da4 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
20:35:50.0484 0x0da4 [ 4C0AA4ABC4E21672B55D8A700AF2B2A6, FAC6B8E2698D0EB12A0ACE62EA398AD05AB6AC5C39740A1E8BDAAF0BFDD5B4A3 ] C:\WINDOWS\system32\winsrv.dll
20:35:50.0515 0x0da4 [ 9EF697AF07BB8DD82C3B02CA953A95B7, F26033E660B8FF1BDB9E88CDA205CE128C03138AF6BEC05DB3CF2D95C16D86C6 ] C:\WINDOWS\system32\services.exe
20:35:50.0515 0x0da4 [ Global ] - ok
20:35:50.0515 0x0da4 ================ Scan MBR ==================================
20:35:50.0531 0x0da4 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
20:35:50.0828 0x0da4 \Device\Harddisk0\DR0 - ok
20:35:50.0828 0x0da4 ================ Scan VBR ==================================
20:35:50.0828 0x0da4 [ D6E0AEF7A81E0DD5F7977D01F0ED391C ] \Device\Harddisk0\DR0\Partition1
20:35:50.0828 0x0da4 \Device\Harddisk0\DR0\Partition1 - ok
20:35:50.0843 0x0da4 [ 1D88D1890DC4C9543263F386A98DB995 ] \Device\Harddisk0\DR0\Partition2
20:35:50.0843 0x0da4 \Device\Harddisk0\DR0\Partition2 - ok
20:35:50.0859 0x0da4 [ AAB4E8460700D9B1CEF3ACE4758EBF18 ] \Device\Harddisk0\DR0\Partition3
20:35:50.0859 0x0da4 \Device\Harddisk0\DR0\Partition3 - ok
20:35:50.0875 0x0da4 Win FW state via NFM: disabled
20:35:54.0218 0x0da4 ============================================================
20:35:54.0218 0x0da4 Scan finished
20:35:54.0218 0x0da4 ============================================================
20:35:54.0218 0x0928 Detected object count: 0
20:35:54.0218 0x0928 Actual detected object count: 0
20:36:29.0406 0x0780 Deinitialize success
Poprosil bych o kontrolu logu Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosil bych o kontrolu logu
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Poprosil bych o kontrolu logu
ComboFix 13-11-19.01 - WarezBos 20.11.2013 14:54:01.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1493 [GMT 1:00]
Spuštěný z: c:\documents and settings\WarezBos\Dokumenty\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\xp-AntiSpy
c:\program files\xp-AntiSpy\Uninstall.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.chm
c:\program files\xp-AntiSpy\xp-AntiSpy.url
c:\windows\COM+.log
c:\windows\EventSystem.log
c:\windows\msmqinst.log
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
c:\windows\system32\DEBUG.log
c:\windows\system32\FlashPlayerApp.exe
c:\windows\system32\msssc.dll
c:\windows\system32\TZLog.log
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-20 do 2013-11-20 )))))))))))))))))))))))))))))))
.
.
2013-11-19 18:15 . 2013-11-19 18:15 -------- d-----w- c:\windows\ERUNT
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\WarezBos\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-19 15:34 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-19 15:08 . 2013-11-19 18:09 -------- d-----w- C:\AdwCleaner
2013-11-17 11:14 . 2013-11-17 11:14 -------- d-sh--w- c:\documents and settings\WarezBos\IETldCache
2013-11-17 00:35 . 2013-10-13 07:12 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-11-17 00:35 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-11-17 00:34 . 2013-10-13 07:12 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-11-17 00:34 . 2013-10-13 07:12 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-11-17 00:34 . 2013-10-13 07:12 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-11-17 00:34 . 2013-10-13 07:12 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-11-17 00:34 . 2013-10-13 07:12 2006016 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-11-17 00:34 . 2013-10-13 07:12 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-11-17 00:34 . 2013-10-13 07:12 11113472 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-11-17 00:33 . 2013-11-17 00:34 -------- dc-h--w- c:\windows\ie8
2013-11-16 23:22 . 2013-11-16 23:22 -------- d-----w- c:\program files\MSXML 4.0
2013-11-16 21:44 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-11-16 21:38 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-11-16 21:36 . 2013-11-16 21:36 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\ESET
2013-11-16 21:36 . 2013-11-19 18:01 -------- d-----w- c:\program files\TNod User & Password Finder
2013-11-16 21:36 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-11-16 21:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-11-16 21:32 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-11-16 21:32 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-11-16 21:29 . 2013-11-16 21:29 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\McAfee
2013-11-16 21:28 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-11-16 21:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-11-16 21:27 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2013-11-16 21:27 . 2013-07-03 01:59 14976 -c----w- c:\windows\system32\dllcache\usbscan.sys
2013-11-16 21:25 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-11-16 21:25 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-11-16 21:23 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-11-16 21:23 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-11-16 21:23 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-11-16 21:23 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-11-16 21:23 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-11-16 21:23 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-11-16 21:23 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-11-16 21:04 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-11-16 21:00 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-11-16 20:59 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-11-16 20:59 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2013-11-16 20:59 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2013-11-16 20:59 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2013-11-16 20:53 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2013-11-16 20:51 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-11-16 20:49 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-11-16 20:49 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-11-16 20:37 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2013-11-16 20:37 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2013-11-16 20:37 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2013-11-16 20:37 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2013-11-16 20:35 . 2010-12-09 15:15 713216 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-11-16 20:35 . 2013-07-04 07:34 2072320 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2013-11-16 20:35 . 2013-07-04 07:34 2195712 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2013-11-16 20:35 . 2013-07-04 07:34 2151936 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2013-11-16 20:35 . 2013-07-04 07:33 2030592 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2013-11-16 20:35 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-11-16 20:34 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-11-16 20:34 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-11-16 20:34 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2013-11-16 20:23 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-11-16 20:02 . 2013-11-17 11:25 -------- d--h--w- c:\windows\$hf_mig$
2013-11-16 20:02 . 2013-11-16 20:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\McAfee
2013-11-16 15:24 . 2013-11-16 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-11-16 14:50 . 2013-11-16 14:50 -------- d-----w- c:\program files\Common Files\Java
2013-11-16 14:50 . 2013-10-08 06:29 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-11-16 14:50 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\windows\system32\xlive
2013-11-14 17:32 . 2013-11-15 14:13 -------- d-----w- c:\program files\AGEIA Technologies
2013-11-14 17:32 . 2013-11-14 17:32 -------- d-----w- c:\windows\system32\AGEIA
2013-11-14 17:32 . 2013-11-15 14:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-16 20:02 . 2011-07-30 12:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 11:42 . 2007-06-05 16:28 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:12 . 2007-06-05 16:13 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:12 . 2004-08-17 15:49 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-13 07:12 . 2004-08-17 15:49 18944 ------w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2004-08-17 15:44 385024 ------w- c:\windows\system32\html.iec
2013-10-12 15:57 . 2004-08-17 15:49 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:13 . 2007-06-05 16:27 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-07 11:00 . 2004-08-17 15:49 606208 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 06:25 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-09-29 15:28 . 2011-07-30 12:53 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-09-29 15:25 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-08-29 07:01 . 2007-06-05 16:25 1878656 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-08-26 895376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-11 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamePark klient 2.lnk
backup=c:\windows\pss\GamePark klient 2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 11:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-08-26 21:31 895376 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"WebClient"=3 (0x3)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=3 (0x3)
"RSVP"=3 (0x3)
"mnmsrvc"=3 (0x3)
"UPS"=3 (0x3)
"CiSvc"=3 (0x3)
"upnphost"=3 (0x3)
"WZCSVC"=2 (0x2)
"WmiApSrv"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Infium"="c:\program files\QIP 2010\qip.exe" /autorun
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" /MINIMIZED
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe"
"Kerio VPN Client"="c:\program files\Kerio\VPN Client\kvpnclient.exe" /tryauto
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\GAMES\\CoD 2 play\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\QIP 2010\\qip.exe"=
"c:\\Hry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Hry\\Batman.Arkham.Asylum-RELOADED\\batman\\Binaries\\ShippingPC-BmGame.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58431:TCP"= 58431:TCP:Pando Media Booster
"58431:UDP"= 58431:UDP:Pando Media Booster
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [16.10.2011 18:39 232512]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.11.2013 16:34 701512]
R3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [16.1.2008 8:58 65024]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.11.2013 16:34 22856]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [13.9.2011 21:50 176128]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [31.7.2012 19:03 125960]
S2 PortmapperService;PortmapperService;c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe --> c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [27.9.2011 3:00 89160]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-15 06:06 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-20 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 20:02]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-03 00:31]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-03 00:31]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://qip.ru/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\yd6i5vyn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-TNOD UP - c:\program files\TNod User & Password Finder\TNODUP.exe
MSConfigStartUp-SiteRanker - c:\program files\SiteRanker\SiteRankTray.exe
AddRemove-Driver Genius_is1 - c:\program files\Driver-Soft\DriverGenius\unins000.exe
AddRemove-TNod - c:\program files\TNod User & Password Finder\uninst-TNod.exe
AddRemove-xp-AntiSpy - c:\program files\xp-AntiSpy\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-20 14:57
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PortmapperService]
"ImagePath"="c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1708)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(2200)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2013-11-20 15:00:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-20 14:00
.
Před spuštěním: Volných bajtů: 23 401 484 288
Po spuštění: Volných bajtů: 23 320 829 952
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
; This boot.ini was automatically generated by NeoSmart Technologies' BootGrabber.exe
; Use EasyBCD from http://neosmart.net/dl.php?id=1 to manage your bootloader
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP on D:\" /fastdetect
.
- - End Of File - - 837A858E51146C6895B485A2C9443C81
413FC2A0C716421B3158746D63736515
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1493 [GMT 1:00]
Spuštěný z: c:\documents and settings\WarezBos\Dokumenty\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\xp-AntiSpy
c:\program files\xp-AntiSpy\Uninstall.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.exe
c:\program files\xp-AntiSpy\xp-AntiSpy.chm
c:\program files\xp-AntiSpy\xp-AntiSpy.url
c:\windows\COM+.log
c:\windows\EventSystem.log
c:\windows\msmqinst.log
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
c:\windows\system32\DEBUG.log
c:\windows\system32\FlashPlayerApp.exe
c:\windows\system32\msssc.dll
c:\windows\system32\TZLog.log
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-20 do 2013-11-20 )))))))))))))))))))))))))))))))
.
.
2013-11-19 18:15 . 2013-11-19 18:15 -------- d-----w- c:\windows\ERUNT
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\WarezBos\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-19 15:34 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-19 15:08 . 2013-11-19 18:09 -------- d-----w- C:\AdwCleaner
2013-11-17 11:14 . 2013-11-17 11:14 -------- d-sh--w- c:\documents and settings\WarezBos\IETldCache
2013-11-17 00:35 . 2013-10-13 07:12 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-11-17 00:35 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-11-17 00:34 . 2013-10-13 07:12 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-11-17 00:34 . 2013-10-13 07:12 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-11-17 00:34 . 2013-10-13 07:12 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-11-17 00:34 . 2013-10-13 07:12 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-11-17 00:34 . 2013-10-13 07:12 2006016 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-11-17 00:34 . 2013-10-13 07:12 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-11-17 00:34 . 2013-10-13 07:12 11113472 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-11-17 00:33 . 2013-11-17 00:34 -------- dc-h--w- c:\windows\ie8
2013-11-16 23:22 . 2013-11-16 23:22 -------- d-----w- c:\program files\MSXML 4.0
2013-11-16 21:44 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-11-16 21:38 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-11-16 21:36 . 2013-11-16 21:36 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\ESET
2013-11-16 21:36 . 2013-11-19 18:01 -------- d-----w- c:\program files\TNod User & Password Finder
2013-11-16 21:36 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-11-16 21:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-11-16 21:32 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-11-16 21:32 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-11-16 21:29 . 2013-11-16 21:29 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\McAfee
2013-11-16 21:28 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-11-16 21:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-11-16 21:27 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2013-11-16 21:27 . 2013-07-03 01:59 14976 -c----w- c:\windows\system32\dllcache\usbscan.sys
2013-11-16 21:25 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-11-16 21:25 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-11-16 21:23 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-11-16 21:23 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-11-16 21:23 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-11-16 21:23 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-11-16 21:23 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-11-16 21:23 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-11-16 21:23 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-11-16 21:04 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-11-16 21:00 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-11-16 20:59 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-11-16 20:59 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2013-11-16 20:59 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2013-11-16 20:59 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2013-11-16 20:53 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2013-11-16 20:51 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-11-16 20:49 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-11-16 20:49 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-11-16 20:37 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2013-11-16 20:37 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2013-11-16 20:37 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2013-11-16 20:37 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2013-11-16 20:35 . 2010-12-09 15:15 713216 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-11-16 20:35 . 2013-07-04 07:34 2072320 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2013-11-16 20:35 . 2013-07-04 07:34 2195712 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2013-11-16 20:35 . 2013-07-04 07:34 2151936 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2013-11-16 20:35 . 2013-07-04 07:33 2030592 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2013-11-16 20:35 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-11-16 20:34 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-11-16 20:34 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-11-16 20:34 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2013-11-16 20:23 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-11-16 20:02 . 2013-11-17 11:25 -------- d--h--w- c:\windows\$hf_mig$
2013-11-16 20:02 . 2013-11-16 20:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\McAfee
2013-11-16 15:24 . 2013-11-16 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-11-16 14:50 . 2013-11-16 14:50 -------- d-----w- c:\program files\Common Files\Java
2013-11-16 14:50 . 2013-10-08 06:29 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-11-16 14:50 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\windows\system32\xlive
2013-11-14 17:32 . 2013-11-15 14:13 -------- d-----w- c:\program files\AGEIA Technologies
2013-11-14 17:32 . 2013-11-14 17:32 -------- d-----w- c:\windows\system32\AGEIA
2013-11-14 17:32 . 2013-11-15 14:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-16 20:02 . 2011-07-30 12:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 11:42 . 2007-06-05 16:28 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:12 . 2007-06-05 16:13 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:12 . 2004-08-17 15:49 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-13 07:12 . 2004-08-17 15:49 18944 ------w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2004-08-17 15:44 385024 ------w- c:\windows\system32\html.iec
2013-10-12 15:57 . 2004-08-17 15:49 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:13 . 2007-06-05 16:27 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-07 11:00 . 2004-08-17 15:49 606208 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 06:25 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-09-29 15:28 . 2011-07-30 12:53 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-09-29 15:25 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-08-29 07:01 . 2007-06-05 16:25 1878656 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-08-26 895376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-11 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamePark klient 2.lnk
backup=c:\windows\pss\GamePark klient 2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 11:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-08-26 21:31 895376 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"WebClient"=3 (0x3)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=3 (0x3)
"RSVP"=3 (0x3)
"mnmsrvc"=3 (0x3)
"UPS"=3 (0x3)
"CiSvc"=3 (0x3)
"upnphost"=3 (0x3)
"WZCSVC"=2 (0x2)
"WmiApSrv"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Infium"="c:\program files\QIP 2010\qip.exe" /autorun
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" /MINIMIZED
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe"
"Kerio VPN Client"="c:\program files\Kerio\VPN Client\kvpnclient.exe" /tryauto
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\GAMES\\CoD 2 play\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\QIP 2010\\qip.exe"=
"c:\\Hry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Hry\\Batman.Arkham.Asylum-RELOADED\\batman\\Binaries\\ShippingPC-BmGame.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58431:TCP"= 58431:TCP:Pando Media Booster
"58431:UDP"= 58431:UDP:Pando Media Booster
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [16.10.2011 18:39 232512]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.11.2013 16:34 701512]
R3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [16.1.2008 8:58 65024]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.11.2013 16:34 22856]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [13.9.2011 21:50 176128]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [31.7.2012 19:03 125960]
S2 PortmapperService;PortmapperService;c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe --> c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [27.9.2011 3:00 89160]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-15 06:06 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-20 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 20:02]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-03 00:31]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-03 00:31]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://qip.ru/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\yd6i5vyn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-TNOD UP - c:\program files\TNod User & Password Finder\TNODUP.exe
MSConfigStartUp-SiteRanker - c:\program files\SiteRanker\SiteRankTray.exe
AddRemove-Driver Genius_is1 - c:\program files\Driver-Soft\DriverGenius\unins000.exe
AddRemove-TNod - c:\program files\TNod User & Password Finder\uninst-TNod.exe
AddRemove-xp-AntiSpy - c:\program files\xp-AntiSpy\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-20 14:57
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PortmapperService]
"ImagePath"="c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1708)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(2200)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2013-11-20 15:00:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-20 14:00
.
Před spuštěním: Volných bajtů: 23 401 484 288
Po spuštění: Volných bajtů: 23 320 829 952
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
; This boot.ini was automatically generated by NeoSmart Technologies' BootGrabber.exe
; Use EasyBCD from http://neosmart.net/dl.php?id=1 to manage your bootloader
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP on D:\" /fastdetect
.
- - End Of File - - 837A858E51146C6895B485A2C9443C81
413FC2A0C716421B3158746D63736515
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosil bych o kontrolu logu
Spuštěný z: c:\documents and settings\WarezBos\Dokumenty\Downloads\ComboFix.exe
Přesuň Combofix.exe na plochu!
Odinstaluj:
TNod User & Password Finder
Spybot - Search & Destroy
Pokud najdeš..
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\program files\TNod User & Password Finder
c:\program files\Spybot - Search & Destroy
c:\program files\Skype\Updater
c:\program files\Google\Update
Driver::
PortmapperService
SkypeUpdate
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PortmapperService]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Poprosil bych o kontrolu logu
ComboFix 13-11-19.01 - WarezBos 20.11.2013 19:22:05.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1463 [GMT 1:00]
Spuštěný z: c:\documents and settings\WarezBos\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\WarezBos\Plocha\CFScript.txt
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.165\goopdate.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.165\psmachine.dll
c:\program files\Google\Update\1.3.21.165\psuser.dll
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.57\31.0.1650.57_31.0.1650.48_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SKYPEUPDATE
-------\Service_SkypeUpdate
-------\Legacy_gupdate
-------\Legacy_gupdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-20 do 2013-11-20 )))))))))))))))))))))))))))))))
.
.
2013-11-20 15:31 . 2013-08-29 11:07 36152 ----a-w- c:\windows\system32\uxtuneup.dll
2013-11-20 15:12 . 2013-11-20 15:12 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\Avg2014
2013-11-20 14:38 . 2013-11-20 14:38 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2013-11-20 14:38 . 2013-08-29 11:07 36664 ----a-w- c:\windows\system32\TURegOpt.exe
2013-11-20 14:37 . 2013-11-20 14:38 -------- d-----w- c:\program files\TuneUp Utilities 2014
2013-11-20 14:37 . 2013-11-20 14:49 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-11-20 14:37 . 2013-11-20 14:37 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2013-11-20 14:24 . 2008-04-28 11:03 42552 ----a-w- c:\windows\system32\drivers\AmdTools.sys
2013-11-20 14:24 . 2013-11-20 14:24 -------- d-----w- c:\program files\AMD GPU Clock Tool
2013-11-20 14:14 . 2013-11-20 14:31 -------- d-----w- c:\program files\MSI Afterburner
2013-11-20 14:14 . 2013-11-20 14:14 -------- d-----w- c:\program files\MSI Kombustor 2.5
2013-11-19 18:15 . 2013-11-19 18:15 -------- d-----w- c:\windows\ERUNT
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\WarezBos\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-19 15:34 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-19 15:08 . 2013-11-19 18:09 -------- d-----w- C:\AdwCleaner
2013-11-17 11:14 . 2013-11-17 11:14 -------- d-sh--w- c:\documents and settings\WarezBos\IETldCache
2013-11-17 00:35 . 2013-10-13 07:12 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-11-17 00:35 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-11-17 00:34 . 2013-10-13 07:12 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-11-17 00:34 . 2013-10-13 07:12 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-11-17 00:34 . 2013-10-13 07:12 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-11-17 00:34 . 2013-10-13 07:12 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-11-17 00:34 . 2013-10-13 07:12 2006016 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-11-17 00:34 . 2013-10-13 07:12 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-11-17 00:34 . 2013-10-13 07:12 11113472 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-11-17 00:33 . 2013-11-17 00:34 -------- dc-h--w- c:\windows\ie8
2013-11-16 23:22 . 2013-11-16 23:22 -------- d-----w- c:\program files\MSXML 4.0
2013-11-16 21:44 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-11-16 21:38 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-11-16 21:36 . 2013-11-16 21:36 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\ESET
2013-11-16 21:36 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-11-16 21:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-11-16 21:32 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-11-16 21:32 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-11-16 21:29 . 2013-11-16 21:29 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\McAfee
2013-11-16 21:28 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-11-16 21:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-11-16 21:27 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2013-11-16 21:27 . 2013-07-03 01:59 14976 -c----w- c:\windows\system32\dllcache\usbscan.sys
2013-11-16 21:25 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-11-16 21:25 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-11-16 21:23 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-11-16 21:23 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-11-16 21:23 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-11-16 21:23 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-11-16 21:23 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-11-16 21:23 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-11-16 21:23 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-11-16 21:04 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-11-16 21:00 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-11-16 20:59 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-11-16 20:59 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2013-11-16 20:59 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2013-11-16 20:59 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2013-11-16 20:53 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2013-11-16 20:51 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-11-16 20:49 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-11-16 20:49 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-11-16 20:37 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2013-11-16 20:37 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2013-11-16 20:37 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2013-11-16 20:37 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2013-11-16 20:35 . 2010-12-09 15:15 713216 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-11-16 20:35 . 2013-07-04 07:34 2072320 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2013-11-16 20:35 . 2013-07-04 07:34 2195712 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2013-11-16 20:35 . 2013-07-04 07:34 2151936 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2013-11-16 20:35 . 2013-07-04 07:33 2030592 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2013-11-16 20:35 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-11-16 20:34 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-11-16 20:34 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-11-16 20:34 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2013-11-16 20:23 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-11-16 20:02 . 2013-11-17 11:25 -------- d--h--w- c:\windows\$hf_mig$
2013-11-16 20:02 . 2013-11-16 20:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\McAfee
2013-11-16 15:24 . 2013-11-16 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-11-16 14:50 . 2013-11-16 14:50 -------- d-----w- c:\program files\Common Files\Java
2013-11-16 14:50 . 2013-10-08 06:29 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-11-16 14:50 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\windows\system32\xlive
2013-11-14 17:32 . 2013-11-15 14:13 -------- d-----w- c:\program files\AGEIA Technologies
2013-11-14 17:32 . 2013-11-14 17:32 -------- d-----w- c:\windows\system32\AGEIA
2013-11-14 17:32 . 2013-11-15 14:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-16 20:02 . 2011-07-30 12:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 11:42 . 2007-06-05 16:28 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:12 . 2007-06-05 16:13 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:12 . 2004-08-17 15:49 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-13 07:12 . 2004-08-17 15:49 18944 ------w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2004-08-17 15:44 385024 ------w- c:\windows\system32\html.iec
2013-10-12 15:57 . 2004-08-17 15:49 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:13 . 2007-06-05 16:27 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-07 11:00 . 2004-08-17 15:49 606208 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 06:25 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-09-29 15:28 . 2011-07-30 12:53 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-09-29 15:25 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-08-29 07:01 . 2007-06-05 16:25 1878656 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-08-26 895376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-11 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamePark klient 2.lnk
backup=c:\windows\pss\GamePark klient 2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 11:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-08-26 21:31 895376 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"WebClient"=3 (0x3)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=3 (0x3)
"RSVP"=3 (0x3)
"mnmsrvc"=3 (0x3)
"UPS"=3 (0x3)
"CiSvc"=3 (0x3)
"upnphost"=3 (0x3)
"WZCSVC"=2 (0x2)
"WmiApSrv"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Infium"="c:\program files\QIP 2010\qip.exe" /autorun
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" /MINIMIZED
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe"
"Kerio VPN Client"="c:\program files\Kerio\VPN Client\kvpnclient.exe" /tryauto
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\GAMES\\CoD 2 play\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\QIP 2010\\qip.exe"=
"c:\\Hry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Hry\\Batman.Arkham.Asylum-RELOADED\\batman\\Binaries\\ShippingPC-BmGame.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58431:TCP"= 58431:TCP:Pando Media Booster
"58431:UDP"= 58431:UDP:Pando Media Booster
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [16.10.2011 18:39 232512]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.11.2013 16:34 701512]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [29.8.2013 12:07 1740600]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [20.11.2013 15:24 42552]
R3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [16.1.2008 8:58 65024]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.11.2013 16:34 22856]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [13.9.2011 21:50 176128]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [31.7.2012 19:03 125960]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [21.8.2013 19:53 12320]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [27.9.2011 3:00 89160]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-15 06:06 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 20:02]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://qip.ru/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\yd6i5vyn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - ExtSQL: 2013-11-20 16:15; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\WarezBos\Data aplikacĂÂ\Mozilla\Firefox\Profiles\yd6i5vyn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-20 19:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1708)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(4080)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2013-11-20 19:29:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-20 18:29
ComboFix2.txt 2013-11-20 14:00
.
Před spuštěním: Volných bajtů: 22 501 056 512
Po spuštění: Volných bajtů: 22 321 856 512
.
- - End Of File - - A4237D94885B564EF2F2BBE6DA4A66EC
413FC2A0C716421B3158746D63736515
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1463 [GMT 1:00]
Spuštěný z: c:\documents and settings\WarezBos\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\WarezBos\Plocha\CFScript.txt
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.165\goopdate.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.165\psmachine.dll
c:\program files\Google\Update\1.3.21.165\psuser.dll
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.57\31.0.1650.57_31.0.1650.48_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SKYPEUPDATE
-------\Service_SkypeUpdate
-------\Legacy_gupdate
-------\Legacy_gupdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-20 do 2013-11-20 )))))))))))))))))))))))))))))))
.
.
2013-11-20 15:31 . 2013-08-29 11:07 36152 ----a-w- c:\windows\system32\uxtuneup.dll
2013-11-20 15:12 . 2013-11-20 15:12 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\Avg2014
2013-11-20 14:38 . 2013-11-20 14:38 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2013-11-20 14:38 . 2013-08-29 11:07 36664 ----a-w- c:\windows\system32\TURegOpt.exe
2013-11-20 14:37 . 2013-11-20 14:38 -------- d-----w- c:\program files\TuneUp Utilities 2014
2013-11-20 14:37 . 2013-11-20 14:49 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-11-20 14:37 . 2013-11-20 14:37 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2013-11-20 14:24 . 2008-04-28 11:03 42552 ----a-w- c:\windows\system32\drivers\AmdTools.sys
2013-11-20 14:24 . 2013-11-20 14:24 -------- d-----w- c:\program files\AMD GPU Clock Tool
2013-11-20 14:14 . 2013-11-20 14:31 -------- d-----w- c:\program files\MSI Afterburner
2013-11-20 14:14 . 2013-11-20 14:14 -------- d-----w- c:\program files\MSI Kombustor 2.5
2013-11-19 18:15 . 2013-11-19 18:15 -------- d-----w- c:\windows\ERUNT
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\WarezBos\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-11-19 15:34 . 2013-11-19 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-19 15:34 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-19 15:08 . 2013-11-19 18:09 -------- d-----w- C:\AdwCleaner
2013-11-17 11:14 . 2013-11-17 11:14 -------- d-sh--w- c:\documents and settings\WarezBos\IETldCache
2013-11-17 00:35 . 2013-10-13 07:12 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-11-17 00:35 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2013-11-17 00:34 . 2013-10-13 07:12 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2013-11-17 00:34 . 2013-10-13 07:12 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2013-11-17 00:34 . 2013-10-13 07:12 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2013-11-17 00:34 . 2013-10-13 07:12 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2013-11-17 00:34 . 2013-10-13 07:12 2006016 -c----w- c:\windows\system32\dllcache\iertutil.dll
2013-11-17 00:34 . 2013-10-13 07:12 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-11-17 00:34 . 2013-10-13 07:12 11113472 -c----w- c:\windows\system32\dllcache\ieframe.dll
2013-11-17 00:33 . 2013-11-17 00:34 -------- dc-h--w- c:\windows\ie8
2013-11-16 23:22 . 2013-11-16 23:22 -------- d-----w- c:\program files\MSXML 4.0
2013-11-16 21:44 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2013-11-16 21:38 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2013-11-16 21:36 . 2013-11-16 21:36 -------- d-----w- c:\documents and settings\WarezBos\Local Settings\Data aplikací\ESET
2013-11-16 21:36 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-11-16 21:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2013-11-16 21:32 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-11-16 21:32 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2013-11-16 21:29 . 2013-11-16 21:29 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\McAfee
2013-11-16 21:28 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-11-16 21:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-11-16 21:27 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2013-11-16 21:27 . 2013-07-03 01:59 14976 -c----w- c:\windows\system32\dllcache\usbscan.sys
2013-11-16 21:25 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2013-11-16 21:25 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2013-11-16 21:23 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2013-11-16 21:23 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2013-11-16 21:23 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2013-11-16 21:23 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2013-11-16 21:23 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2013-11-16 21:23 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2013-11-16 21:23 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2013-11-16 21:04 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-11-16 21:00 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-11-16 20:59 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-11-16 20:59 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2013-11-16 20:59 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2013-11-16 20:59 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2013-11-16 20:59 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2013-11-16 20:53 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2013-11-16 20:51 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-11-16 20:49 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2013-11-16 20:49 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-11-16 20:37 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2013-11-16 20:37 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2013-11-16 20:37 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2013-11-16 20:37 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2013-11-16 20:35 . 2010-12-09 15:15 713216 -c----w- c:\windows\system32\dllcache\ntdll.dll
2013-11-16 20:35 . 2013-07-04 07:34 2072320 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2013-11-16 20:35 . 2013-07-04 07:34 2195712 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2013-11-16 20:35 . 2013-07-04 07:34 2151936 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2013-11-16 20:35 . 2013-07-04 07:33 2030592 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2013-11-16 20:35 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2013-11-16 20:34 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-11-16 20:34 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-11-16 20:34 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2013-11-16 20:23 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-11-16 20:02 . 2013-11-17 11:25 -------- d--h--w- c:\windows\$hf_mig$
2013-11-16 20:02 . 2013-11-16 20:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\McAfee
2013-11-16 15:24 . 2013-11-16 15:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-11-16 14:50 . 2013-11-16 14:50 -------- d-----w- c:\program files\Common Files\Java
2013-11-16 14:50 . 2013-10-08 06:29 145408 ----a-w- c:\windows\system32\javacpl.cpl
2013-11-16 14:50 . 2013-10-08 06:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2013-11-14 17:33 . 2013-11-14 17:33 -------- d-----w- c:\windows\system32\xlive
2013-11-14 17:32 . 2013-11-15 14:13 -------- d-----w- c:\program files\AGEIA Technologies
2013-11-14 17:32 . 2013-11-14 17:32 -------- d-----w- c:\windows\system32\AGEIA
2013-11-14 17:32 . 2013-11-15 14:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-16 20:02 . 2011-07-30 12:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 11:42 . 2007-06-05 16:28 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:12 . 2007-06-05 16:13 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:12 . 2004-08-17 15:49 43520 ------w- c:\windows\system32\licmgr10.dll
2013-10-13 07:12 . 2004-08-17 15:49 18944 ------w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2004-08-17 15:44 385024 ------w- c:\windows\system32\html.iec
2013-10-12 15:57 . 2004-08-17 15:49 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:13 . 2007-06-05 16:27 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-07 11:00 . 2004-08-17 15:49 606208 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 06:25 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-09-29 15:28 . 2011-07-30 12:53 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-09-29 15:27 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-09-29 15:25 . 2011-07-30 12:53 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-08-29 07:01 . 2007-06-05 16:25 1878656 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-08-26 895376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-11 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GamePark klient 2.lnk
backup=c:\windows\pss\GamePark klient 2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 11:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2012-08-26 21:31 895376 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"WebClient"=3 (0x3)
"SysmonLog"=3 (0x3)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=3 (0x3)
"RSVP"=3 (0x3)
"mnmsrvc"=3 (0x3)
"UPS"=3 (0x3)
"CiSvc"=3 (0x3)
"upnphost"=3 (0x3)
"WZCSVC"=2 (0x2)
"WmiApSrv"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Infium"="c:\program files\QIP 2010\qip.exe" /autorun
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" /MINIMIZED
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe"
"Kerio VPN Client"="c:\program files\Kerio\VPN Client\kvpnclient.exe" /tryauto
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\GAMES\\CoD 2 play\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\QIP 2010\\qip.exe"=
"c:\\Hry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Hry\\Batman.Arkham.Asylum-RELOADED\\batman\\Binaries\\ShippingPC-BmGame.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58431:TCP"= 58431:TCP:Pando Media Booster
"58431:UDP"= 58431:UDP:Pando Media Booster
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [16.10.2011 18:39 232512]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19.11.2013 16:34 701512]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [29.8.2013 12:07 1740600]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [20.11.2013 15:24 42552]
R3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [16.1.2008 8:58 65024]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [19.11.2013 16:34 22856]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [13.9.2011 21:50 176128]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [31.7.2012 19:03 125960]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [21.8.2013 19:53 12320]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [27.9.2011 3:00 89160]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-15 06:06 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 20:02]
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = hxxp://qip.ru/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\WarezBos\Data aplikací\Mozilla\Firefox\Profiles\yd6i5vyn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - ExtSQL: 2013-11-20 16:15; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\WarezBos\Data aplikacĂÂ\Mozilla\Firefox\Profiles\yd6i5vyn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-20 19:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1708)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(4080)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2013-11-20 19:29:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-20 18:29
ComboFix2.txt 2013-11-20 14:00
.
Před spuštěním: Volných bajtů: 22 501 056 512
Po spuštění: Volných bajtů: 22 321 856 512
.
- - End Of File - - A4237D94885B564EF2F2BBE6DA4A66EC
413FC2A0C716421B3158746D63736515
Re: Poprosil bych o kontrolu logu
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:32:46, on 20.11.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\WarezBos\Plocha\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qip.ru/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
--
End of file - 7160 bytes
Scan saved at 19:32:46, on 20.11.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\WarezBos\Plocha\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qip.ru/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
--
End of file - 7160 bytes
Re: Poprosil bych o kontrolu logu
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-11-20 19:36:46
-----------------------------
19:36:46.140 OS Version: Windows 5.1.2600 Service Pack 3
19:36:46.140 Number of processors: 2 586 0xF0B
19:36:46.140 ComputerName: WAREZ UserName:
19:36:46.750 Initialize success
19:36:56.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-16
19:36:56.203 Disk 0 Vendor: ST3400620AS 3.AAK Size: 381554MB BusType: 3
19:36:56.296 Disk 0 MBR read successfully
19:36:56.296 Disk 0 MBR scan
19:36:56.296 Disk 0 Windows XP default MBR code
19:36:56.296 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 99998 MB offset 63
19:36:56.296 Disk 0 Partition - 00 0F Extended LBA 281545 MB offset 204796620
19:36:56.312 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 99998 MB offset 204796683
19:36:56.312 Disk 0 Partition - 00 05 Extended 181547 MB offset 409593240
19:36:56.328 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 181547 MB offset 409593303
19:36:56.328 Disk 0 scanning sectors +781401600
19:36:56.359 Disk 0 scanning C:\WINDOWS\system32\drivers
19:37:00.968 Service scanning
19:37:09.125 Modules scanning
19:37:14.359 Disk 0 trace - called modules:
19:37:14.375 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
19:37:14.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89de4ab8]
19:37:14.375 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000073[0x89de9c68]
19:37:14.375 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP5T0L0-16[0x89d7f940]
19:37:14.390 Scan finished successfully
19:38:50.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\WarezBos\Plocha\MBR.dat"
19:38:50.156 The log file has been saved successfully to "C:\Documents and Settings\WarezBos\Plocha\aswMBR_streda.txt"
Run date: 2013-11-20 19:36:46
-----------------------------
19:36:46.140 OS Version: Windows 5.1.2600 Service Pack 3
19:36:46.140 Number of processors: 2 586 0xF0B
19:36:46.140 ComputerName: WAREZ UserName:
19:36:46.750 Initialize success
19:36:56.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-16
19:36:56.203 Disk 0 Vendor: ST3400620AS 3.AAK Size: 381554MB BusType: 3
19:36:56.296 Disk 0 MBR read successfully
19:36:56.296 Disk 0 MBR scan
19:36:56.296 Disk 0 Windows XP default MBR code
19:36:56.296 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 99998 MB offset 63
19:36:56.296 Disk 0 Partition - 00 0F Extended LBA 281545 MB offset 204796620
19:36:56.312 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 99998 MB offset 204796683
19:36:56.312 Disk 0 Partition - 00 05 Extended 181547 MB offset 409593240
19:36:56.328 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 181547 MB offset 409593303
19:36:56.328 Disk 0 scanning sectors +781401600
19:36:56.359 Disk 0 scanning C:\WINDOWS\system32\drivers
19:37:00.968 Service scanning
19:37:09.125 Modules scanning
19:37:14.359 Disk 0 trace - called modules:
19:37:14.375 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
19:37:14.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89de4ab8]
19:37:14.375 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000073[0x89de9c68]
19:37:14.375 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP5T0L0-16[0x89d7f940]
19:37:14.390 Scan finished successfully
19:38:50.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\WarezBos\Plocha\MBR.dat"
19:38:50.156 The log file has been saved successfully to "C:\Documents and Settings\WarezBos\Plocha\aswMBR_streda.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Poprosil bych o kontrolu logu Vyřešeno
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Návod
Kód: Vybrat vše
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qip.ru/
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 99 hostů