# AdwCleaner v2.109 - Logfile created 01/31/2013 at 22:39:00
# Updated 26/01/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)
# User :
# Boot Mode : Normal
# Running from : D:\Stažené soubory\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
File Found : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Found : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\Askcom.xml
File Found : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\SweetIm.xml
Folder Found : C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Found : C:\Documents and Settings\All Users\Data aplikací\SweetIM
Folder Found : C:\Documents and Settings\Fr\Data aplikací\OpenCandy
***** [Registry] *****
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14656
-\\ Mozilla Firefox v18.0.1 (cs)
File : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\prefs.js
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Found : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Found : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1359356607040");
Found : user_pref("sweetim.toolbar.Visibility.enable", "true");
Found : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Found : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Found : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...]
Found : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Found : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Found : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Found : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?la[...]
Found : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Found : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...]
Found : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Found : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Found : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Found : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...]
Found : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Found : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[...]
Found : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Found : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Found : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Found : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Found : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Found : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...]
Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Found : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Found : user_pref("sweetim.toolbar.mode.debug", "false");
Found : user_pref("sweetim.toolbar.newtab.created", "false");
Found : user_pref("sweetim.toolbar.newtab.enable", "true");
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Found : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_V[...]
Found : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Found : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Found : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(http://www.|apps.)?facebook\\.com.*");
Found : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Found : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Found : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Found : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Found : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(http://www.|apps.)?facebook\\.com.*");
Found : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Found : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Found : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Found : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Found : user_pref("sweetim.toolbar.scripts.2.callback", "");
Found : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...]
Found : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Found : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Found : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Found : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?[...]
Found : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
Found : user_pref("sweetim.toolbar.search.history.capacity", "10");
Found : user_pref("sweetim.toolbar.searchguard.enable", "false");
Found : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Found : user_pref("sweetim.toolbar.version", "1.9.0.0");
*************************
AdwCleaner[R1].txt - [8712 octets] - [31/01/2013 22:39:00]
########## EOF - C:\AdwCleaner[R1].txt - [8772 octets] ##########
Úplně zamrzá - prosím o kontrolu Vyřešeno
Re: Úplně zamrzá - prosím o kontrolu
Naposledy upravil(a) patricia dne 31 led 2013 22:52, celkem upraveno 1 x.
Re: Úplně zamrzá - prosím o kontrolu
22:43:51.0671 2804 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
22:43:53.0312 2804 ============================================================
22:43:53.0312 2804 Current date / time: 2013/01/31 22:43:53.0312
22:43:53.0312 2804 SystemInfo:
22:43:53.0312 2804
22:43:53.0312 2804 OS Version: 5.1.2600 ServicePack: 2.0
22:43:53.0312 2804 Product type: Workstation
22:43:53.0312 2804 ComputerName:
22:43:53.0312 2804 UserName:
22:43:53.0312 2804 Windows directory: C:\WINDOWS
22:43:53.0312 2804 System windows directory: C:\WINDOWS
22:43:53.0312 2804 Processor architecture: Intel x86
22:43:53.0312 2804 Number of processors: 1
22:43:53.0312 2804 Page size: 0x1000
22:43:53.0312 2804 Boot type: Normal boot
22:43:53.0312 2804 ============================================================
22:43:53.0765 2804 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:43:53.0781 2804 ============================================================
22:43:53.0781 2804 \Device\Harddisk0\DR0:
22:43:53.0781 2804 MBR partitions:
22:43:53.0781 2804 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1470177
22:43:53.0781 2804 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x14701F5, BlocksNum 0x115A4A0B
22:43:53.0781 2804 ============================================================
22:43:53.0796 2804 C: <-> \Device\Harddisk0\DR0\Partition1
22:43:53.0812 2804 D: <-> \Device\Harddisk0\DR0\Partition2
22:43:53.0812 2804 ============================================================
22:43:53.0812 2804 Initialize success
22:43:53.0812 2804 ============================================================
22:44:02.0890 3928 ============================================================
22:44:02.0890 3928 Scan started
22:44:02.0890 3928 Mode: Manual;
22:44:02.0890 3928 ============================================================
22:44:03.0187 3928 ================ Scan system memory ========================
22:44:03.0187 3928 System memory - ok
22:44:03.0187 3928 ================ Scan services =============================
22:44:03.0281 3928 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
22:44:03.0281 3928 Aavmker4 - ok
22:44:03.0281 3928 Abiosdsk - ok
22:44:03.0296 3928 abp480n5 - ok
22:44:03.0328 3928 [ FA2FBCDA96D2385F773B059FE5A125A6 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:44:03.0328 3928 ACPI - ok
22:44:03.0359 3928 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:44:03.0359 3928 ACPIEC - ok
22:44:03.0421 3928 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:44:03.0437 3928 AdobeFlashPlayerUpdateSvc - ok
22:44:03.0453 3928 adpu160m - ok
22:44:03.0468 3928 [ 841F385C6CFAF66B58FBD898722BB4F0 ] aec C:\WINDOWS\system32\drivers\aec.sys
22:44:03.0484 3928 aec - ok
22:44:03.0500 3928 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys
22:44:03.0515 3928 AFD - ok
22:44:03.0515 3928 Aha154x - ok
22:44:03.0531 3928 aic78u2 - ok
22:44:03.0546 3928 aic78xx - ok
22:44:03.0640 3928 [ 35045A23957A71BA649740741E69408C ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS
22:44:03.0703 3928 ALCXWDM - ok
22:44:03.0734 3928 [ 026DDAA7E6F8D49DF82C7A98BAE5D0D1 ] Alerter C:\WINDOWS\system32\alrsvc.dll
22:44:03.0734 3928 Alerter - ok
22:44:03.0750 3928 [ B3F690BF43F93A012A52F28F234FAA1B ] ALG C:\WINDOWS\System32\alg.exe
22:44:03.0750 3928 ALG - ok
22:44:03.0765 3928 AliIde - ok
22:44:03.0765 3928 amsint - ok
22:44:03.0796 3928 [ 421184F91EAE5C6E78E653C6B32AAE84 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:44:03.0812 3928 AppMgmt - ok
22:44:03.0812 3928 asc - ok
22:44:03.0828 3928 asc3350p - ok
22:44:03.0828 3928 asc3550 - ok
22:44:03.0890 3928 [ D33C507942299753868204CC7642FA27 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:44:03.0906 3928 aspnet_state - ok
22:44:03.0937 3928 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
22:44:03.0937 3928 aswFsBlk - ok
22:44:03.0953 3928 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
22:44:03.0953 3928 aswMon2 - ok
22:44:03.0984 3928 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
22:44:04.0000 3928 aswRdr - ok
22:44:04.0062 3928 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
22:44:04.0078 3928 aswSnx - ok
22:44:04.0125 3928 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
22:44:04.0140 3928 aswSP - ok
22:44:04.0156 3928 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
22:44:04.0156 3928 aswTdi - ok
22:44:04.0187 3928 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:44:04.0187 3928 AsyncMac - ok
22:44:04.0234 3928 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:44:04.0234 3928 atapi - ok
22:44:04.0234 3928 Atdisk - ok
22:44:04.0296 3928 [ F57801F641E6DF9F4FD4B29D6DEB422C ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
22:44:04.0312 3928 Ati HotKey Poller - ok
22:44:04.0343 3928 [ 9459F0247D8911CFDF1DC509517AF5B6 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe
22:44:04.0359 3928 ATI Smart - ok
22:44:04.0453 3928 [ BF94A12F9D86B28FECF00B24B7129013 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
22:44:04.0515 3928 ati2mtag - ok
22:44:04.0546 3928 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:44:04.0546 3928 Atmarpc - ok
22:44:04.0562 3928 [ 40D78F514C8588EF12EC718D2AF0FC4E ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:44:04.0562 3928 AudioSrv - ok
22:44:04.0593 3928 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:44:04.0593 3928 audstub - ok
22:44:04.0656 3928 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:44:04.0671 3928 avast! Antivirus - ok
22:44:04.0687 3928 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
22:44:04.0687 3928 Beep - ok
22:44:04.0734 3928 [ E774A26610EC92674273486612C11CFC ] BITS C:\WINDOWS\system32\qmgr.dll
22:44:04.0781 3928 BITS - ok
22:44:04.0796 3928 [ F219E27E88107A50544153898DD8178E ] Browser C:\WINDOWS\System32\browser.dll
22:44:04.0796 3928 Browser - ok
22:44:04.0828 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:44:04.0843 3928 cbidf2k - ok
22:44:04.0843 3928 cd20xrnt - ok
22:44:04.0859 3928 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:44:04.0859 3928 Cdaudio - ok
22:44:04.0875 3928 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:44:04.0890 3928 Cdfs - ok
22:44:04.0890 3928 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:44:04.0890 3928 Cdrom - ok
22:44:04.0906 3928 Changer - ok
22:44:04.0937 3928 [ 9E21229E04E1D301BB40222FE4641CB2 ] CiSvc C:\WINDOWS\system32\cisvc.exe
22:44:04.0937 3928 CiSvc - ok
22:44:04.0953 3928 [ D3DC45553C8025338E08A60E95B1B91D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:44:04.0953 3928 ClipSrv - ok
22:44:04.0984 3928 [ 3C4D595E7F9B747325AEF28B4ADCAAE5 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:44:05.0015 3928 clr_optimization_v2.0.50727_32 - ok
22:44:05.0031 3928 CmdIde - ok
22:44:05.0046 3928 COMSysApp - ok
22:44:05.0062 3928 Cpqarray - ok
22:44:05.0078 3928 [ 70D2A1756F4B2067658A186C963FCABD ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:44:05.0078 3928 CryptSvc - ok
22:44:05.0093 3928 dac2w2k - ok
22:44:05.0093 3928 dac960nt - ok
22:44:05.0125 3928 [ C72C15EE57E248C66E57C76CAB086CF2 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:44:05.0140 3928 DcomLaunch - ok
22:44:05.0171 3928 [ 562830EFB7CF367FB773FEA5256E67C8 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:44:05.0171 3928 Dhcp - ok
22:44:05.0187 3928 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:44:05.0187 3928 Disk - ok
22:44:05.0187 3928 dmadmin - ok
22:44:05.0234 3928 [ E1968EDEC81C430108FEB23AB07BDB14 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:44:05.0265 3928 dmboot - ok
22:44:05.0281 3928 [ 1B1520A82E396E46B9AE9FA6B03FF6C6 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
22:44:05.0296 3928 dmio - ok
22:44:05.0312 3928 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
22:44:05.0312 3928 dmload - ok
22:44:05.0343 3928 [ 7B3CA72885923EB947221F17F3E3AC59 ] dmserver C:\WINDOWS\System32\dmserver.dll
22:44:05.0343 3928 dmserver - ok
22:44:05.0375 3928 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:44:05.0375 3928 DMusic - ok
22:44:05.0390 3928 [ F605B3F5674D67587C4B6C9E92A3E025 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:44:05.0390 3928 Dnscache - ok
22:44:05.0406 3928 dpti2o - ok
22:44:05.0421 3928 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:44:05.0421 3928 drmkaud - ok
22:44:05.0453 3928 [ D6F7428B201E33BC80066B47144CB568 ] ERSvc C:\WINDOWS\System32\ersvc.dll
22:44:05.0453 3928 ERSvc - ok
22:44:05.0468 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] Eventlog C:\WINDOWS\system32\services.exe
22:44:05.0484 3928 Eventlog - ok
22:44:05.0500 3928 [ 972378B907070F64932A87C90A035487 ] EventSystem C:\WINDOWS\system32\es.dll
22:44:05.0500 3928 EventSystem - ok
22:44:05.0515 3928 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:44:05.0531 3928 Fastfat - ok
22:44:05.0546 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:44:05.0562 3928 FastUserSwitchingCompatibility - ok
22:44:05.0578 3928 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:44:05.0578 3928 Fdc - ok
22:44:05.0593 3928 [ 266DAB58619B17BDF37FABBD48D875CA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
22:44:05.0593 3928 Fips - ok
22:44:05.0609 3928 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:44:05.0609 3928 Flpydisk - ok
22:44:05.0640 3928 [ 157754F0DF355A9E0A6F54721914F9C6 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:44:05.0640 3928 FltMgr - ok
22:44:05.0687 3928 [ B47576825F0A397E1C807C7EC23E1560 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
22:44:05.0687 3928 ForceWare Intelligent Application Manager (IAM) - ok
22:44:05.0718 3928 [ B81F8778F5BB485F3B75114F0C99A49F ] ForcewareWebInterface C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
22:44:05.0718 3928 ForcewareWebInterface - ok
22:44:05.0734 3928 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:44:05.0734 3928 Fs_Rec - ok
22:44:05.0750 3928 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:44:05.0750 3928 Ftdisk - ok
22:44:05.0765 3928 [ 5F92FD09E5610A5995DA7D775EADCD12 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys
22:44:05.0765 3928 gameenum - ok
22:44:05.0781 3928 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:44:05.0781 3928 Gpc - ok
22:44:05.0812 3928 [ F59152272782FED8A8197FA788287F68 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:44:05.0812 3928 helpsvc - ok
22:44:05.0828 3928 HidServ - ok
22:44:05.0828 3928 hpn - ok
22:44:05.0875 3928 [ C19B522A9AE0BBC3293397F3055E80A1 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:44:05.0875 3928 HTTP - ok
22:44:05.0906 3928 [ DA826826C5C9116F47E0CD0CA8CC7C11 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:44:05.0906 3928 HTTPFilter - ok
22:44:05.0921 3928 i2omgmt - ok
22:44:05.0937 3928 i2omp - ok
22:44:05.0968 3928 [ 0F42DE9909B5DBF2C48DD1A79D491AF5 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:44:05.0968 3928 i8042prt - ok
22:44:06.0000 3928 [ F8AA320C6A0409C0380E5D8A99D76EC6 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:44:06.0000 3928 Imapi - ok
22:44:06.0031 3928 [ CF9D286B34CB4912F3B28B4972D5CB33 ] ImapiService C:\WINDOWS\system32\imapi.exe
22:44:06.0046 3928 ImapiService - ok
22:44:06.0062 3928 ini910u - ok
22:44:06.0062 3928 IntelIde - ok
22:44:06.0093 3928 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:44:06.0093 3928 Ip6Fw - ok
22:44:06.0109 3928 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:44:06.0109 3928 IpFilterDriver - ok
22:44:06.0140 3928 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:44:06.0140 3928 IpInIp - ok
22:44:06.0171 3928 [ B5A8E215AC29D24D60B4D1250EF05ACE ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:44:06.0171 3928 IpNat - ok
22:44:06.0187 3928 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:44:06.0203 3928 IPSec - ok
22:44:06.0234 3928 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:44:06.0234 3928 IRENUM - ok
22:44:06.0265 3928 [ 1091528512E4DD7ED5FDDCC4DF1C53D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:44:06.0265 3928 isapnp - ok
22:44:06.0281 3928 [ 6F877BF8DC01A550CD666F3BEDB2213C ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:44:06.0281 3928 Kbdclass - ok
22:44:06.0312 3928 [ D93CAD07C5683DB066B0B2D2D3790EAD ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:44:06.0312 3928 kmixer - ok
22:44:06.0343 3928 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:44:06.0343 3928 KSecDD - ok
22:44:06.0359 3928 [ 6D6BDD68B775986577C48A8DF961A05C ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
22:44:06.0375 3928 lanmanserver - ok
22:44:06.0390 3928 [ 69B0569AAE33F0D5057CA0E8577AAF07 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:44:06.0390 3928 lanmanworkstation - ok
22:44:06.0406 3928 lbrtfdc - ok
22:44:06.0437 3928 [ F9EE6D2AAB0690B34AE35BA9921A1414 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:44:06.0437 3928 LmHosts - ok
22:44:06.0453 3928 [ 8B2FCBD881879B55BE40B41F12FFC431 ] Messenger C:\WINDOWS\System32\msgsvc.dll
22:44:06.0468 3928 Messenger - ok
22:44:06.0484 3928 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:44:06.0484 3928 mnmdd - ok
22:44:06.0531 3928 [ 7D137132D6A9B41EF800E59A771ED48C ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:44:06.0531 3928 mnmsrvc - ok
22:44:06.0546 3928 [ 60210DEB037846AFE521EBF349964F6B ] Modem C:\WINDOWS\system32\drivers\Modem.sys
22:44:06.0546 3928 Modem - ok
22:44:06.0562 3928 [ B160EC94114715675509115986400FD9 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:44:06.0562 3928 Mouclass - ok
22:44:06.0578 3928 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:44:06.0578 3928 MountMgr - ok
22:44:06.0609 3928 [ 9C3758018DED02F4AE53CCA1C5F084A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:44:06.0609 3928 MozillaMaintenance - ok
22:44:06.0625 3928 mraid35x - ok
22:44:06.0640 3928 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:44:06.0640 3928 MRxDAV - ok
22:44:06.0687 3928 [ 1FD607FC67F7F7C633C3DA65BFC53D18 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:44:06.0703 3928 MRxSmb - ok
22:44:06.0734 3928 [ 944A24032AED84C59455B981F6CA1C1A ] MSDTC C:\WINDOWS\system32\msdtc.exe
22:44:06.0734 3928 MSDTC - ok
22:44:06.0750 3928 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:44:06.0750 3928 Msfs - ok
22:44:06.0765 3928 MSIServer - ok
22:44:06.0796 3928 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:44:06.0796 3928 MSKSSRV - ok
22:44:06.0796 3928 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:44:06.0812 3928 MSPCLOCK - ok
22:44:06.0828 3928 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:44:06.0828 3928 MSPQM - ok
22:44:06.0859 3928 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:44:06.0859 3928 mssmbios - ok
22:44:06.0890 3928 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys
22:44:06.0890 3928 ms_mpu401 - ok
22:44:06.0921 3928 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:44:06.0921 3928 MTsensor - ok
22:44:06.0937 3928 [ 82035E0F41C2DD05AE41D27FE6CF7DE1 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
22:44:06.0937 3928 Mup - ok
22:44:06.0953 3928 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:44:06.0968 3928 NDIS - ok
22:44:06.0984 3928 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:44:06.0984 3928 NdisTapi - ok
22:44:07.0015 3928 [ 34D6CD56409DA9A7ED573E1C90A308BF ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:44:07.0015 3928 Ndisuio - ok
22:44:07.0046 3928 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:44:07.0046 3928 NdisWan - ok
22:44:07.0062 3928 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:44:07.0062 3928 NDProxy - ok
22:44:07.0078 3928 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:44:07.0078 3928 NetBIOS - ok
22:44:07.0109 3928 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:44:07.0109 3928 NetBT - ok
22:44:07.0125 3928 [ 818053225BF4AAC5F0F718001E492F70 ] NetDDE C:\WINDOWS\system32\netdde.exe
22:44:07.0140 3928 NetDDE - ok
22:44:07.0156 3928 [ 818053225BF4AAC5F0F718001E492F70 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:44:07.0156 3928 NetDDEdsdm - ok
22:44:07.0187 3928 [ 82A362FE1D4980B71B588D9C10748511 ] Netlogon C:\WINDOWS\system32\lsass.exe
22:44:07.0187 3928 Netlogon - ok
22:44:07.0203 3928 [ AF342D2781225A8769686E0D47E3123E ] Netman C:\WINDOWS\System32\netman.dll
22:44:07.0203 3928 Netman - ok
22:44:07.0234 3928 [ 64C078BD4EFD441C3F159EDC5EA4420A ] Nla C:\WINDOWS\System32\mswsock.dll
22:44:07.0234 3928 Nla - ok
22:44:07.0250 3928 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:44:07.0250 3928 Npfs - ok
22:44:07.0281 3928 [ CF0FA7F8366002692BF7E46805F531B9 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
22:44:07.0281 3928 nSvcIp - ok
22:44:07.0296 3928 [ ACE9C161B76C066288A17FEA4BB7BFFC ] nSvcLog C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
22:44:07.0296 3928 nSvcLog - ok
22:44:07.0343 3928 [ B78BE402C3F63DD55521F73876951CDD ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:44:07.0359 3928 Ntfs - ok
22:44:07.0359 3928 [ 82A362FE1D4980B71B588D9C10748511 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
22:44:07.0375 3928 NtLmSsp - ok
22:44:07.0406 3928 [ D8D2B13BA93AE830B1A637DF571D1195 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:44:07.0421 3928 NtmsSvc - ok
22:44:07.0437 3928 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
22:44:07.0437 3928 Null - ok
22:44:07.0812 3928 [ 6733E80A193FC36F41C24142B0C45C0E ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:44:08.0109 3928 nv - ok
22:44:08.0140 3928 [ DCE353985C988BFB7E84FD942068151F ] nvata C:\WINDOWS\system32\DRIVERS\nvata.sys
22:44:08.0140 3928 nvata - ok
22:44:08.0156 3928 [ 720CC533EECB65553BD86B139CA04433 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
22:44:08.0156 3928 NVENETFD - ok
22:44:08.0171 3928 [ 5F9F545CC5904DD8765F84EE1D056406 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
22:44:08.0187 3928 nvnetbus - ok
22:44:08.0203 3928 [ 2E6ED9FE65A9B3EC606603ED0F33DD7D ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
22:44:08.0218 3928 NVSvc - ok
22:44:08.0328 3928 [ 3C09CC7992A8ADECD1FDDFD5D8E69BAE ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
22:44:08.0375 3928 nvUpdatusService - ok
22:44:08.0406 3928 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:44:08.0406 3928 NwlnkFlt - ok
22:44:08.0421 3928 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:44:08.0437 3928 NwlnkFwd - ok
22:44:08.0453 3928 [ 76A18CAA2FEFB28A4CED38D76837E86E ] Parport C:\WINDOWS\system32\drivers\Parport.sys
22:44:08.0453 3928 Parport - ok
22:44:08.0468 3928 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:44:08.0468 3928 PartMgr - ok
22:44:08.0500 3928 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:44:08.0500 3928 ParVdm - ok
22:44:08.0515 3928 [ B7979F37BB7B9DF2230046134955E6E7 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:44:08.0515 3928 PCI - ok
22:44:08.0531 3928 PCIDump - ok
22:44:08.0546 3928 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:44:08.0546 3928 PCIIde - ok
22:44:08.0578 3928 [ 90505755634407D4EF4C6DEA60FC1DF9 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:44:08.0578 3928 Pcmcia - ok
22:44:08.0593 3928 PDCOMP - ok
22:44:08.0593 3928 PDFRAME - ok
22:44:08.0609 3928 PDRELI - ok
22:44:08.0609 3928 PDRFRAME - ok
22:44:08.0625 3928 perc2 - ok
22:44:08.0640 3928 perc2hib - ok
22:44:08.0671 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] PlugPlay C:\WINDOWS\system32\services.exe
22:44:08.0687 3928 PlugPlay - ok
22:44:08.0703 3928 [ 82A362FE1D4980B71B588D9C10748511 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
22:44:08.0703 3928 PolicyAgent - ok
22:44:08.0718 3928 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:44:08.0734 3928 PptpMiniport - ok
22:44:08.0765 3928 [ 9A10E4FD13824823DA50D4758BD0A645 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
22:44:08.0765 3928 Processor - ok
22:44:08.0765 3928 [ 82A362FE1D4980B71B588D9C10748511 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:44:08.0781 3928 ProtectedStorage - ok
22:44:08.0796 3928 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:44:08.0796 3928 PSched - ok
22:44:08.0812 3928 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:44:08.0812 3928 Ptilink - ok
22:44:08.0828 3928 ql1080 - ok
22:44:08.0828 3928 Ql10wnt - ok
22:44:08.0843 3928 ql12160 - ok
22:44:08.0859 3928 ql1240 - ok
22:44:08.0859 3928 ql1280 - ok
22:44:08.0875 3928 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:44:08.0875 3928 RasAcd - ok
22:44:08.0890 3928 [ E68B6F9A726A444059705AB43B5656D1 ] RasAuto C:\WINDOWS\System32\rasauto.dll
22:44:08.0906 3928 RasAuto - ok
22:44:08.0921 3928 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:44:08.0921 3928 Rasl2tp - ok
22:44:08.0953 3928 [ 6E519D777C91E90592403C9F981FDF03 ] RasMan C:\WINDOWS\System32\rasmans.dll
22:44:08.0968 3928 RasMan - ok
22:44:08.0984 3928 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:44:08.0984 3928 RasPppoe - ok
22:44:08.0984 3928 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:44:09.0000 3928 Raspti - ok
22:44:09.0015 3928 [ 29D66245ADBA878FFF574CD66ABD2884 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:44:09.0015 3928 Rdbss - ok
22:44:09.0031 3928 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:44:09.0031 3928 RDPCDD - ok
22:44:09.0062 3928 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:44:09.0078 3928 rdpdr - ok
22:44:09.0109 3928 [ D4F5643D7714EF499AE9527FDCD50894 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:44:09.0125 3928 RDPWD - ok
22:44:09.0140 3928 [ 125ACF258DA9633F748131A0E0185AF3 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:44:09.0140 3928 RDSessMgr - ok
22:44:09.0156 3928 [ ABA13D33E1F888C9A68599A48A8840D6 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:44:09.0156 3928 redbook - ok
22:44:09.0187 3928 [ EB5E1A601E5A1908A87E4D5A41803D98 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:44:09.0203 3928 RemoteAccess - ok
22:44:09.0203 3928 [ 5B21208FCF8970BB61FE98E19D828714 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:44:09.0218 3928 RemoteRegistry - ok
22:44:09.0234 3928 [ C8A3B668985D61249F2DC71716C58DE8 ] RpcLocator C:\WINDOWS\system32\locator.exe
22:44:09.0250 3928 RpcLocator - ok
22:44:09.0265 3928 [ C72C15EE57E248C66E57C76CAB086CF2 ] RpcSs C:\WINDOWS\System32\rpcss.dll
22:44:09.0281 3928 RpcSs - ok
22:44:09.0312 3928 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP C:\WINDOWS\system32\rsvp.exe
22:44:09.0328 3928 RSVP - ok
22:44:09.0343 3928 [ 82A362FE1D4980B71B588D9C10748511 ] SamSs C:\WINDOWS\system32\lsass.exe
22:44:09.0343 3928 SamSs - ok
22:44:09.0375 3928 [ C177354E995CC1AA1F767BCD9980434A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:44:09.0375 3928 SCardSvr - ok
22:44:09.0406 3928 [ 29AC93307C6182DBE336BCA314947F28 ] Schedule C:\WINDOWS\system32\schedsvc.dll
22:44:09.0421 3928 Schedule - ok
22:44:09.0437 3928 [ D26E26EA516450AF9D072635C60387F4 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:44:09.0453 3928 Secdrv - ok
22:44:09.0468 3928 [ C76CB8A133374FAC6805F83FF7B7DA03 ] seclogon C:\WINDOWS\System32\seclogon.dll
22:44:09.0468 3928 seclogon - ok
22:44:09.0484 3928 [ 220AD85BA9C5B3011296354011B901CC ] SENS C:\WINDOWS\system32\sens.dll
22:44:09.0500 3928 SENS - ok
22:44:09.0515 3928 [ C1DDBC85251551A840212999DA3D95F3 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
22:44:09.0515 3928 Serial - ok
22:44:09.0531 3928 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:44:09.0531 3928 Sfloppy - ok
22:44:09.0562 3928 [ 6A93501BCDEBF159109429B022C0FF83 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:44:09.0562 3928 SharedAccess - ok
22:44:09.0593 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:44:09.0593 3928 ShellHWDetection - ok
22:44:09.0609 3928 Simbad - ok
22:44:09.0625 3928 Sparrow - ok
22:44:09.0625 3928 [ 8E186B8F23295D1E42C573B82B80D548 ] splitter C:\WINDOWS\system32\drivers\splitter.sys
22:44:09.0625 3928 splitter - ok
22:44:09.0640 3928 [ 21B6FAA88044A41640E03EBB68BE93E8 ] Spooler C:\WINDOWS\system32\spoolsv.exe
22:44:09.0656 3928 Spooler - ok
22:44:09.0703 3928 [ A199171385BE17973FD800FA91F8F78A ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
22:44:09.0703 3928 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: A199171385BE17973FD800FA91F8F78A
22:44:09.0718 3928 sptd ( LockedFile.Multi.Generic ) - warning
22:44:09.0718 3928 sptd - detected LockedFile.Multi.Generic (1)
22:44:09.0734 3928 [ A74035EA526DB97D9D50D2143A55F5CF ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:44:09.0750 3928 sr - ok
22:44:09.0765 3928 [ 3CD57F31A64D32FDB28918B16D1E6AAC ] srservice C:\WINDOWS\system32\srsvc.dll
22:44:09.0781 3928 srservice - ok
22:44:09.0812 3928 [ 20B7E396720353E4117D64D9DCB926CA ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:44:09.0812 3928 Srv - ok
22:44:09.0843 3928 [ 88C28F53F53438DAFCD95E99C837C61E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:44:09.0859 3928 SSDPSRV - ok
22:44:09.0875 3928 [ 0645CCDDDD27F96EEA3534C1DEF736D9 ] stisvc C:\WINDOWS\system32\wiaservc.dll
22:44:09.0890 3928 stisvc - ok
22:44:09.0921 3928 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:44:09.0921 3928 swenum - ok
22:44:09.0937 3928 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:44:09.0937 3928 swmidi - ok
22:44:09.0953 3928 SwPrv - ok
22:44:09.0953 3928 symc810 - ok
22:44:09.0968 3928 symc8xx - ok
22:44:09.0984 3928 sym_hi - ok
22:44:09.0984 3928 sym_u3 - ok
22:44:10.0015 3928 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:44:10.0015 3928 sysaudio - ok
22:44:10.0031 3928 [ D9C9ECFF4904E6151525C533AEEDF8F4 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:44:10.0046 3928 SysmonLog - ok
22:44:10.0062 3928 [ 37162D29CD61519E6F5EA0DE99786FF6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:44:10.0078 3928 TapiSrv - ok
22:44:10.0109 3928 [ 9F4B36614A0FC234525BA224957DE55C ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:44:10.0125 3928 Tcpip - ok
22:44:10.0140 3928 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:44:10.0140 3928 TDPIPE - ok
22:44:10.0156 3928 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:44:10.0171 3928 TDTCP - ok
22:44:10.0187 3928 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:44:10.0187 3928 TermDD - ok
22:44:10.0218 3928 [ 2F5919F2F6EE7A845893D9C3AA2BC56A ] TermService C:\WINDOWS\System32\termsrv.dll
22:44:10.0234 3928 TermService - ok
22:44:10.0265 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] Themes C:\WINDOWS\System32\shsvcs.dll
22:44:10.0265 3928 Themes - ok
22:44:10.0281 3928 [ 535C2FB97336BAFA509F4783DD1E5746 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:44:10.0296 3928 TlntSvr - ok
22:44:10.0312 3928 TosIde - ok
22:44:10.0328 3928 [ 4DCE17221B1A87FB47E36842F3E38753 ] TrkWks C:\WINDOWS\system32\trkwks.dll
22:44:10.0328 3928 TrkWks - ok
22:44:10.0359 3928 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:44:10.0359 3928 Udfs - ok
22:44:10.0406 3928 [ 3B7E264485F361EA5A65FEEF89F2352F ] UltiDev Cassini Web Server for ASP.NET 2.0 C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
22:44:10.0406 3928 UltiDev Cassini Web Server for ASP.NET 2.0 - ok
22:44:10.0421 3928 ultra - ok
22:44:10.0453 3928 [ AFF2E5045961BBC0A602BB6F95EB1345 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
22:44:10.0468 3928 Update - ok
22:44:10.0484 3928 [ 984FC1518B0D5B31D76F0E63608E0500 ] upnphost C:\WINDOWS\System32\upnphost.dll
22:44:10.0500 3928 upnphost - ok
22:44:10.0515 3928 [ 6148A3BA4D9CC628357FC92014FEA30E ] UPS C:\WINDOWS\System32\ups.exe
22:44:10.0531 3928 UPS - ok
22:44:10.0562 3928 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:44:10.0562 3928 usbccgp - ok
22:44:10.0593 3928 [ 15E993BA2F6946B2BFBBFCD30398621E ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:44:10.0593 3928 usbehci - ok
22:44:10.0609 3928 [ C72F40947F92CEA56A8FB532EDF025F1 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:44:10.0609 3928 usbhub - ok
22:44:10.0625 3928 [ BDFE799A8531BAD8A5A985821FE78760 ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
22:44:10.0625 3928 usbohci - ok
22:44:10.0656 3928 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:44:10.0671 3928 usbprint - ok
22:44:10.0703 3928 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:44:10.0703 3928 usbscan - ok
22:44:10.0734 3928 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:44:10.0734 3928 USBSTOR - ok
22:44:10.0750 3928 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:44:10.0750 3928 VgaSave - ok
22:44:10.0765 3928 ViaIde - ok
22:44:10.0781 3928 [ CD8CCE067F7E9CBD762C00BDDDECAA34 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:44:10.0781 3928 VolSnap - ok
22:44:10.0812 3928 [ 043539881667BB37B07524032D6FFC3E ] VSS C:\WINDOWS\System32\vssvc.exe
22:44:10.0828 3928 VSS - ok
22:44:10.0859 3928 [ 2CEEBB402187AE56B585701F3D191FB3 ] W32Time C:\WINDOWS\system32\w32time.dll
22:44:10.0875 3928 W32Time - ok
22:44:10.0890 3928 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:44:10.0890 3928 Wanarp - ok
22:44:10.0906 3928 WDICA - ok
22:44:10.0921 3928 [ 2797F33EBF50466020C430EE4F037933 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:44:10.0921 3928 wdmaud - ok
22:44:10.0937 3928 [ 3791ADF1D3466AC6B4B662D3F79CBFEC ] WebClient C:\WINDOWS\System32\webclnt.dll
22:44:10.0953 3928 WebClient - ok
22:44:11.0015 3928 [ E12084EA622BDF2262C637BEF15DD85C ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:44:11.0015 3928 winmgmt - ok
22:44:11.0062 3928 [ E02E913B3841717A890A644EE167B9A5 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
22:44:11.0078 3928 WmdmPmSN - ok
22:44:11.0125 3928 [ 0CDC4A0C6B820FAD99FB4CA74CD0C476 ] Wmi C:\WINDOWS\System32\advapi32.dll
22:44:11.0140 3928 Wmi - ok
22:44:11.0171 3928 [ BCD21B989F0FD4ACE78287FC01B4693D ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:44:11.0187 3928 WmiApSrv - ok
22:44:11.0218 3928 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:44:11.0218 3928 WS2IFSL - ok
22:44:11.0250 3928 [ 4ADED1ADEF25041D9827F9A79C0FDA13 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
22:44:11.0250 3928 wscsvc - ok
22:44:11.0281 3928 [ 21F5169CA14E0B25C757644456F637DF ] wuauserv C:\WINDOWS\system32\wuauserv.dll
22:44:11.0281 3928 wuauserv - ok
22:44:11.0312 3928 [ 325CEDEF696EF4B649DDCD3968D085C9 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:44:11.0328 3928 WZCSVC - ok
22:44:11.0359 3928 [ 9B835D4C64860B155A1701D5092EC9E4 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
22:44:11.0375 3928 xmlprov - ok
22:44:11.0375 3928 ================ Scan global ===============================
22:44:11.0390 3928 [ F642F3368D2839798DA79E7BA9218481 ] C:\WINDOWS\system32\basesrv.dll
22:44:11.0421 3928 [ E4E57FBA176F2752527B1D53A663D2D7 ] C:\WINDOWS\system32\winsrv.dll
22:44:11.0437 3928 [ E4E57FBA176F2752527B1D53A663D2D7 ] C:\WINDOWS\system32\winsrv.dll
22:44:11.0468 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] C:\WINDOWS\system32\services.exe
22:44:11.0468 3928 [Global] - ok
22:44:11.0468 3928 ================ Scan MBR ==================================
22:44:11.0500 3928 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
22:44:11.0578 3928 \Device\Harddisk0\DR0 - ok
22:44:11.0578 3928 ================ Scan VBR ==================================
22:44:11.0593 3928 [ 5F7089D7AF07FF80FEDE5B53ABEAAE3C ] \Device\Harddisk0\DR0\Partition1
22:44:11.0593 3928 \Device\Harddisk0\DR0\Partition1 - ok
22:44:11.0609 3928 [ 9DB004839D1CF6650FACEB67E6531D4C ] \Device\Harddisk0\DR0\Partition2
22:44:11.0609 3928 \Device\Harddisk0\DR0\Partition2 - ok
22:44:11.0609 3928 ============================================================
22:44:11.0609 3928 Scan finished
22:44:11.0609 3928 ============================================================
22:44:11.0625 3880 Detected object count: 1
22:44:11.0625 3880 Actual detected object count: 1
22:45:01.0796 3880 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:45:01.0796 3880 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
22:43:53.0312 2804 ============================================================
22:43:53.0312 2804 Current date / time: 2013/01/31 22:43:53.0312
22:43:53.0312 2804 SystemInfo:
22:43:53.0312 2804
22:43:53.0312 2804 OS Version: 5.1.2600 ServicePack: 2.0
22:43:53.0312 2804 Product type: Workstation
22:43:53.0312 2804 ComputerName:
22:43:53.0312 2804 UserName:
22:43:53.0312 2804 Windows directory: C:\WINDOWS
22:43:53.0312 2804 System windows directory: C:\WINDOWS
22:43:53.0312 2804 Processor architecture: Intel x86
22:43:53.0312 2804 Number of processors: 1
22:43:53.0312 2804 Page size: 0x1000
22:43:53.0312 2804 Boot type: Normal boot
22:43:53.0312 2804 ============================================================
22:43:53.0765 2804 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:43:53.0781 2804 ============================================================
22:43:53.0781 2804 \Device\Harddisk0\DR0:
22:43:53.0781 2804 MBR partitions:
22:43:53.0781 2804 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1470177
22:43:53.0781 2804 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x14701F5, BlocksNum 0x115A4A0B
22:43:53.0781 2804 ============================================================
22:43:53.0796 2804 C: <-> \Device\Harddisk0\DR0\Partition1
22:43:53.0812 2804 D: <-> \Device\Harddisk0\DR0\Partition2
22:43:53.0812 2804 ============================================================
22:43:53.0812 2804 Initialize success
22:43:53.0812 2804 ============================================================
22:44:02.0890 3928 ============================================================
22:44:02.0890 3928 Scan started
22:44:02.0890 3928 Mode: Manual;
22:44:02.0890 3928 ============================================================
22:44:03.0187 3928 ================ Scan system memory ========================
22:44:03.0187 3928 System memory - ok
22:44:03.0187 3928 ================ Scan services =============================
22:44:03.0281 3928 [ 149A8F7ADF9742554DC323E290551E3E ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
22:44:03.0281 3928 Aavmker4 - ok
22:44:03.0281 3928 Abiosdsk - ok
22:44:03.0296 3928 abp480n5 - ok
22:44:03.0328 3928 [ FA2FBCDA96D2385F773B059FE5A125A6 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:44:03.0328 3928 ACPI - ok
22:44:03.0359 3928 [ AFDFF022A01F0B11C776F0860C3B282F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:44:03.0359 3928 ACPIEC - ok
22:44:03.0421 3928 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:44:03.0437 3928 AdobeFlashPlayerUpdateSvc - ok
22:44:03.0453 3928 adpu160m - ok
22:44:03.0468 3928 [ 841F385C6CFAF66B58FBD898722BB4F0 ] aec C:\WINDOWS\system32\drivers\aec.sys
22:44:03.0484 3928 aec - ok
22:44:03.0500 3928 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys
22:44:03.0515 3928 AFD - ok
22:44:03.0515 3928 Aha154x - ok
22:44:03.0531 3928 aic78u2 - ok
22:44:03.0546 3928 aic78xx - ok
22:44:03.0640 3928 [ 35045A23957A71BA649740741E69408C ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS
22:44:03.0703 3928 ALCXWDM - ok
22:44:03.0734 3928 [ 026DDAA7E6F8D49DF82C7A98BAE5D0D1 ] Alerter C:\WINDOWS\system32\alrsvc.dll
22:44:03.0734 3928 Alerter - ok
22:44:03.0750 3928 [ B3F690BF43F93A012A52F28F234FAA1B ] ALG C:\WINDOWS\System32\alg.exe
22:44:03.0750 3928 ALG - ok
22:44:03.0765 3928 AliIde - ok
22:44:03.0765 3928 amsint - ok
22:44:03.0796 3928 [ 421184F91EAE5C6E78E653C6B32AAE84 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:44:03.0812 3928 AppMgmt - ok
22:44:03.0812 3928 asc - ok
22:44:03.0828 3928 asc3350p - ok
22:44:03.0828 3928 asc3550 - ok
22:44:03.0890 3928 [ D33C507942299753868204CC7642FA27 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:44:03.0906 3928 aspnet_state - ok
22:44:03.0937 3928 [ DE6ED95AEF259979B2830450072A627B ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
22:44:03.0937 3928 aswFsBlk - ok
22:44:03.0953 3928 [ 84F0BE324EE111338589F448C3E8BAB2 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
22:44:03.0953 3928 aswMon2 - ok
22:44:03.0984 3928 [ 7C9F0A2AB17D52261A9252A2EB320884 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
22:44:04.0000 3928 aswRdr - ok
22:44:04.0062 3928 [ B32E9AD44A1DBB3E8095E80F8DF32B03 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
22:44:04.0078 3928 aswSnx - ok
22:44:04.0125 3928 [ 67B558895695545FB0568B7541F3BCA7 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
22:44:04.0140 3928 aswSP - ok
22:44:04.0156 3928 [ E3E73B2B73A4DFADFDDF557192C4B08A ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
22:44:04.0156 3928 aswTdi - ok
22:44:04.0187 3928 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:44:04.0187 3928 AsyncMac - ok
22:44:04.0234 3928 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:44:04.0234 3928 atapi - ok
22:44:04.0234 3928 Atdisk - ok
22:44:04.0296 3928 [ F57801F641E6DF9F4FD4B29D6DEB422C ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
22:44:04.0312 3928 Ati HotKey Poller - ok
22:44:04.0343 3928 [ 9459F0247D8911CFDF1DC509517AF5B6 ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe
22:44:04.0359 3928 ATI Smart - ok
22:44:04.0453 3928 [ BF94A12F9D86B28FECF00B24B7129013 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
22:44:04.0515 3928 ati2mtag - ok
22:44:04.0546 3928 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:44:04.0546 3928 Atmarpc - ok
22:44:04.0562 3928 [ 40D78F514C8588EF12EC718D2AF0FC4E ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:44:04.0562 3928 AudioSrv - ok
22:44:04.0593 3928 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:44:04.0593 3928 audstub - ok
22:44:04.0656 3928 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:44:04.0671 3928 avast! Antivirus - ok
22:44:04.0687 3928 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
22:44:04.0687 3928 Beep - ok
22:44:04.0734 3928 [ E774A26610EC92674273486612C11CFC ] BITS C:\WINDOWS\system32\qmgr.dll
22:44:04.0781 3928 BITS - ok
22:44:04.0796 3928 [ F219E27E88107A50544153898DD8178E ] Browser C:\WINDOWS\System32\browser.dll
22:44:04.0796 3928 Browser - ok
22:44:04.0828 3928 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:44:04.0843 3928 cbidf2k - ok
22:44:04.0843 3928 cd20xrnt - ok
22:44:04.0859 3928 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:44:04.0859 3928 Cdaudio - ok
22:44:04.0875 3928 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:44:04.0890 3928 Cdfs - ok
22:44:04.0890 3928 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:44:04.0890 3928 Cdrom - ok
22:44:04.0906 3928 Changer - ok
22:44:04.0937 3928 [ 9E21229E04E1D301BB40222FE4641CB2 ] CiSvc C:\WINDOWS\system32\cisvc.exe
22:44:04.0937 3928 CiSvc - ok
22:44:04.0953 3928 [ D3DC45553C8025338E08A60E95B1B91D ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:44:04.0953 3928 ClipSrv - ok
22:44:04.0984 3928 [ 3C4D595E7F9B747325AEF28B4ADCAAE5 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:44:05.0015 3928 clr_optimization_v2.0.50727_32 - ok
22:44:05.0031 3928 CmdIde - ok
22:44:05.0046 3928 COMSysApp - ok
22:44:05.0062 3928 Cpqarray - ok
22:44:05.0078 3928 [ 70D2A1756F4B2067658A186C963FCABD ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:44:05.0078 3928 CryptSvc - ok
22:44:05.0093 3928 dac2w2k - ok
22:44:05.0093 3928 dac960nt - ok
22:44:05.0125 3928 [ C72C15EE57E248C66E57C76CAB086CF2 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:44:05.0140 3928 DcomLaunch - ok
22:44:05.0171 3928 [ 562830EFB7CF367FB773FEA5256E67C8 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:44:05.0171 3928 Dhcp - ok
22:44:05.0187 3928 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:44:05.0187 3928 Disk - ok
22:44:05.0187 3928 dmadmin - ok
22:44:05.0234 3928 [ E1968EDEC81C430108FEB23AB07BDB14 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:44:05.0265 3928 dmboot - ok
22:44:05.0281 3928 [ 1B1520A82E396E46B9AE9FA6B03FF6C6 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
22:44:05.0296 3928 dmio - ok
22:44:05.0312 3928 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
22:44:05.0312 3928 dmload - ok
22:44:05.0343 3928 [ 7B3CA72885923EB947221F17F3E3AC59 ] dmserver C:\WINDOWS\System32\dmserver.dll
22:44:05.0343 3928 dmserver - ok
22:44:05.0375 3928 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:44:05.0375 3928 DMusic - ok
22:44:05.0390 3928 [ F605B3F5674D67587C4B6C9E92A3E025 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:44:05.0390 3928 Dnscache - ok
22:44:05.0406 3928 dpti2o - ok
22:44:05.0421 3928 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:44:05.0421 3928 drmkaud - ok
22:44:05.0453 3928 [ D6F7428B201E33BC80066B47144CB568 ] ERSvc C:\WINDOWS\System32\ersvc.dll
22:44:05.0453 3928 ERSvc - ok
22:44:05.0468 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] Eventlog C:\WINDOWS\system32\services.exe
22:44:05.0484 3928 Eventlog - ok
22:44:05.0500 3928 [ 972378B907070F64932A87C90A035487 ] EventSystem C:\WINDOWS\system32\es.dll
22:44:05.0500 3928 EventSystem - ok
22:44:05.0515 3928 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:44:05.0531 3928 Fastfat - ok
22:44:05.0546 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:44:05.0562 3928 FastUserSwitchingCompatibility - ok
22:44:05.0578 3928 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:44:05.0578 3928 Fdc - ok
22:44:05.0593 3928 [ 266DAB58619B17BDF37FABBD48D875CA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
22:44:05.0593 3928 Fips - ok
22:44:05.0609 3928 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:44:05.0609 3928 Flpydisk - ok
22:44:05.0640 3928 [ 157754F0DF355A9E0A6F54721914F9C6 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:44:05.0640 3928 FltMgr - ok
22:44:05.0687 3928 [ B47576825F0A397E1C807C7EC23E1560 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
22:44:05.0687 3928 ForceWare Intelligent Application Manager (IAM) - ok
22:44:05.0718 3928 [ B81F8778F5BB485F3B75114F0C99A49F ] ForcewareWebInterface C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
22:44:05.0718 3928 ForcewareWebInterface - ok
22:44:05.0734 3928 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:44:05.0734 3928 Fs_Rec - ok
22:44:05.0750 3928 [ 4E664D8541DB4A66B73A24257E322E1F ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:44:05.0750 3928 Ftdisk - ok
22:44:05.0765 3928 [ 5F92FD09E5610A5995DA7D775EADCD12 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys
22:44:05.0765 3928 gameenum - ok
22:44:05.0781 3928 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:44:05.0781 3928 Gpc - ok
22:44:05.0812 3928 [ F59152272782FED8A8197FA788287F68 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:44:05.0812 3928 helpsvc - ok
22:44:05.0828 3928 HidServ - ok
22:44:05.0828 3928 hpn - ok
22:44:05.0875 3928 [ C19B522A9AE0BBC3293397F3055E80A1 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:44:05.0875 3928 HTTP - ok
22:44:05.0906 3928 [ DA826826C5C9116F47E0CD0CA8CC7C11 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:44:05.0906 3928 HTTPFilter - ok
22:44:05.0921 3928 i2omgmt - ok
22:44:05.0937 3928 i2omp - ok
22:44:05.0968 3928 [ 0F42DE9909B5DBF2C48DD1A79D491AF5 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:44:05.0968 3928 i8042prt - ok
22:44:06.0000 3928 [ F8AA320C6A0409C0380E5D8A99D76EC6 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:44:06.0000 3928 Imapi - ok
22:44:06.0031 3928 [ CF9D286B34CB4912F3B28B4972D5CB33 ] ImapiService C:\WINDOWS\system32\imapi.exe
22:44:06.0046 3928 ImapiService - ok
22:44:06.0062 3928 ini910u - ok
22:44:06.0062 3928 IntelIde - ok
22:44:06.0093 3928 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:44:06.0093 3928 Ip6Fw - ok
22:44:06.0109 3928 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:44:06.0109 3928 IpFilterDriver - ok
22:44:06.0140 3928 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:44:06.0140 3928 IpInIp - ok
22:44:06.0171 3928 [ B5A8E215AC29D24D60B4D1250EF05ACE ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:44:06.0171 3928 IpNat - ok
22:44:06.0187 3928 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:44:06.0203 3928 IPSec - ok
22:44:06.0234 3928 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:44:06.0234 3928 IRENUM - ok
22:44:06.0265 3928 [ 1091528512E4DD7ED5FDDCC4DF1C53D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:44:06.0265 3928 isapnp - ok
22:44:06.0281 3928 [ 6F877BF8DC01A550CD666F3BEDB2213C ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:44:06.0281 3928 Kbdclass - ok
22:44:06.0312 3928 [ D93CAD07C5683DB066B0B2D2D3790EAD ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:44:06.0312 3928 kmixer - ok
22:44:06.0343 3928 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:44:06.0343 3928 KSecDD - ok
22:44:06.0359 3928 [ 6D6BDD68B775986577C48A8DF961A05C ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
22:44:06.0375 3928 lanmanserver - ok
22:44:06.0390 3928 [ 69B0569AAE33F0D5057CA0E8577AAF07 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:44:06.0390 3928 lanmanworkstation - ok
22:44:06.0406 3928 lbrtfdc - ok
22:44:06.0437 3928 [ F9EE6D2AAB0690B34AE35BA9921A1414 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:44:06.0437 3928 LmHosts - ok
22:44:06.0453 3928 [ 8B2FCBD881879B55BE40B41F12FFC431 ] Messenger C:\WINDOWS\System32\msgsvc.dll
22:44:06.0468 3928 Messenger - ok
22:44:06.0484 3928 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:44:06.0484 3928 mnmdd - ok
22:44:06.0531 3928 [ 7D137132D6A9B41EF800E59A771ED48C ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:44:06.0531 3928 mnmsrvc - ok
22:44:06.0546 3928 [ 60210DEB037846AFE521EBF349964F6B ] Modem C:\WINDOWS\system32\drivers\Modem.sys
22:44:06.0546 3928 Modem - ok
22:44:06.0562 3928 [ B160EC94114715675509115986400FD9 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:44:06.0562 3928 Mouclass - ok
22:44:06.0578 3928 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:44:06.0578 3928 MountMgr - ok
22:44:06.0609 3928 [ 9C3758018DED02F4AE53CCA1C5F084A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:44:06.0609 3928 MozillaMaintenance - ok
22:44:06.0625 3928 mraid35x - ok
22:44:06.0640 3928 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:44:06.0640 3928 MRxDAV - ok
22:44:06.0687 3928 [ 1FD607FC67F7F7C633C3DA65BFC53D18 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:44:06.0703 3928 MRxSmb - ok
22:44:06.0734 3928 [ 944A24032AED84C59455B981F6CA1C1A ] MSDTC C:\WINDOWS\system32\msdtc.exe
22:44:06.0734 3928 MSDTC - ok
22:44:06.0750 3928 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:44:06.0750 3928 Msfs - ok
22:44:06.0765 3928 MSIServer - ok
22:44:06.0796 3928 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:44:06.0796 3928 MSKSSRV - ok
22:44:06.0796 3928 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:44:06.0812 3928 MSPCLOCK - ok
22:44:06.0828 3928 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:44:06.0828 3928 MSPQM - ok
22:44:06.0859 3928 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:44:06.0859 3928 mssmbios - ok
22:44:06.0890 3928 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys
22:44:06.0890 3928 ms_mpu401 - ok
22:44:06.0921 3928 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:44:06.0921 3928 MTsensor - ok
22:44:06.0937 3928 [ 82035E0F41C2DD05AE41D27FE6CF7DE1 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
22:44:06.0937 3928 Mup - ok
22:44:06.0953 3928 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:44:06.0968 3928 NDIS - ok
22:44:06.0984 3928 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:44:06.0984 3928 NdisTapi - ok
22:44:07.0015 3928 [ 34D6CD56409DA9A7ED573E1C90A308BF ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:44:07.0015 3928 Ndisuio - ok
22:44:07.0046 3928 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:44:07.0046 3928 NdisWan - ok
22:44:07.0062 3928 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:44:07.0062 3928 NDProxy - ok
22:44:07.0078 3928 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:44:07.0078 3928 NetBIOS - ok
22:44:07.0109 3928 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:44:07.0109 3928 NetBT - ok
22:44:07.0125 3928 [ 818053225BF4AAC5F0F718001E492F70 ] NetDDE C:\WINDOWS\system32\netdde.exe
22:44:07.0140 3928 NetDDE - ok
22:44:07.0156 3928 [ 818053225BF4AAC5F0F718001E492F70 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:44:07.0156 3928 NetDDEdsdm - ok
22:44:07.0187 3928 [ 82A362FE1D4980B71B588D9C10748511 ] Netlogon C:\WINDOWS\system32\lsass.exe
22:44:07.0187 3928 Netlogon - ok
22:44:07.0203 3928 [ AF342D2781225A8769686E0D47E3123E ] Netman C:\WINDOWS\System32\netman.dll
22:44:07.0203 3928 Netman - ok
22:44:07.0234 3928 [ 64C078BD4EFD441C3F159EDC5EA4420A ] Nla C:\WINDOWS\System32\mswsock.dll
22:44:07.0234 3928 Nla - ok
22:44:07.0250 3928 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:44:07.0250 3928 Npfs - ok
22:44:07.0281 3928 [ CF0FA7F8366002692BF7E46805F531B9 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
22:44:07.0281 3928 nSvcIp - ok
22:44:07.0296 3928 [ ACE9C161B76C066288A17FEA4BB7BFFC ] nSvcLog C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
22:44:07.0296 3928 nSvcLog - ok
22:44:07.0343 3928 [ B78BE402C3F63DD55521F73876951CDD ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:44:07.0359 3928 Ntfs - ok
22:44:07.0359 3928 [ 82A362FE1D4980B71B588D9C10748511 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
22:44:07.0375 3928 NtLmSsp - ok
22:44:07.0406 3928 [ D8D2B13BA93AE830B1A637DF571D1195 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:44:07.0421 3928 NtmsSvc - ok
22:44:07.0437 3928 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
22:44:07.0437 3928 Null - ok
22:44:07.0812 3928 [ 6733E80A193FC36F41C24142B0C45C0E ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:44:08.0109 3928 nv - ok
22:44:08.0140 3928 [ DCE353985C988BFB7E84FD942068151F ] nvata C:\WINDOWS\system32\DRIVERS\nvata.sys
22:44:08.0140 3928 nvata - ok
22:44:08.0156 3928 [ 720CC533EECB65553BD86B139CA04433 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
22:44:08.0156 3928 NVENETFD - ok
22:44:08.0171 3928 [ 5F9F545CC5904DD8765F84EE1D056406 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
22:44:08.0187 3928 nvnetbus - ok
22:44:08.0203 3928 [ 2E6ED9FE65A9B3EC606603ED0F33DD7D ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
22:44:08.0218 3928 NVSvc - ok
22:44:08.0328 3928 [ 3C09CC7992A8ADECD1FDDFD5D8E69BAE ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
22:44:08.0375 3928 nvUpdatusService - ok
22:44:08.0406 3928 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:44:08.0406 3928 NwlnkFlt - ok
22:44:08.0421 3928 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:44:08.0437 3928 NwlnkFwd - ok
22:44:08.0453 3928 [ 76A18CAA2FEFB28A4CED38D76837E86E ] Parport C:\WINDOWS\system32\drivers\Parport.sys
22:44:08.0453 3928 Parport - ok
22:44:08.0468 3928 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:44:08.0468 3928 PartMgr - ok
22:44:08.0500 3928 [ 1FAE19D0457176318BBA4A8795656EBC ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:44:08.0500 3928 ParVdm - ok
22:44:08.0515 3928 [ B7979F37BB7B9DF2230046134955E6E7 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:44:08.0515 3928 PCI - ok
22:44:08.0531 3928 PCIDump - ok
22:44:08.0546 3928 [ 2DA4EC85E0EA7A45C6B2A05820492D5A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:44:08.0546 3928 PCIIde - ok
22:44:08.0578 3928 [ 90505755634407D4EF4C6DEA60FC1DF9 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:44:08.0578 3928 Pcmcia - ok
22:44:08.0593 3928 PDCOMP - ok
22:44:08.0593 3928 PDFRAME - ok
22:44:08.0609 3928 PDRELI - ok
22:44:08.0609 3928 PDRFRAME - ok
22:44:08.0625 3928 perc2 - ok
22:44:08.0640 3928 perc2hib - ok
22:44:08.0671 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] PlugPlay C:\WINDOWS\system32\services.exe
22:44:08.0687 3928 PlugPlay - ok
22:44:08.0703 3928 [ 82A362FE1D4980B71B588D9C10748511 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
22:44:08.0703 3928 PolicyAgent - ok
22:44:08.0718 3928 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:44:08.0734 3928 PptpMiniport - ok
22:44:08.0765 3928 [ 9A10E4FD13824823DA50D4758BD0A645 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
22:44:08.0765 3928 Processor - ok
22:44:08.0765 3928 [ 82A362FE1D4980B71B588D9C10748511 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:44:08.0781 3928 ProtectedStorage - ok
22:44:08.0796 3928 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:44:08.0796 3928 PSched - ok
22:44:08.0812 3928 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:44:08.0812 3928 Ptilink - ok
22:44:08.0828 3928 ql1080 - ok
22:44:08.0828 3928 Ql10wnt - ok
22:44:08.0843 3928 ql12160 - ok
22:44:08.0859 3928 ql1240 - ok
22:44:08.0859 3928 ql1280 - ok
22:44:08.0875 3928 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:44:08.0875 3928 RasAcd - ok
22:44:08.0890 3928 [ E68B6F9A726A444059705AB43B5656D1 ] RasAuto C:\WINDOWS\System32\rasauto.dll
22:44:08.0906 3928 RasAuto - ok
22:44:08.0921 3928 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:44:08.0921 3928 Rasl2tp - ok
22:44:08.0953 3928 [ 6E519D777C91E90592403C9F981FDF03 ] RasMan C:\WINDOWS\System32\rasmans.dll
22:44:08.0968 3928 RasMan - ok
22:44:08.0984 3928 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:44:08.0984 3928 RasPppoe - ok
22:44:08.0984 3928 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:44:09.0000 3928 Raspti - ok
22:44:09.0015 3928 [ 29D66245ADBA878FFF574CD66ABD2884 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:44:09.0015 3928 Rdbss - ok
22:44:09.0031 3928 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:44:09.0031 3928 RDPCDD - ok
22:44:09.0062 3928 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:44:09.0078 3928 rdpdr - ok
22:44:09.0109 3928 [ D4F5643D7714EF499AE9527FDCD50894 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:44:09.0125 3928 RDPWD - ok
22:44:09.0140 3928 [ 125ACF258DA9633F748131A0E0185AF3 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:44:09.0140 3928 RDSessMgr - ok
22:44:09.0156 3928 [ ABA13D33E1F888C9A68599A48A8840D6 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:44:09.0156 3928 redbook - ok
22:44:09.0187 3928 [ EB5E1A601E5A1908A87E4D5A41803D98 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:44:09.0203 3928 RemoteAccess - ok
22:44:09.0203 3928 [ 5B21208FCF8970BB61FE98E19D828714 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:44:09.0218 3928 RemoteRegistry - ok
22:44:09.0234 3928 [ C8A3B668985D61249F2DC71716C58DE8 ] RpcLocator C:\WINDOWS\system32\locator.exe
22:44:09.0250 3928 RpcLocator - ok
22:44:09.0265 3928 [ C72C15EE57E248C66E57C76CAB086CF2 ] RpcSs C:\WINDOWS\System32\rpcss.dll
22:44:09.0281 3928 RpcSs - ok
22:44:09.0312 3928 [ 09AB2E71E58B078038E3BFDBA7FFC984 ] RSVP C:\WINDOWS\system32\rsvp.exe
22:44:09.0328 3928 RSVP - ok
22:44:09.0343 3928 [ 82A362FE1D4980B71B588D9C10748511 ] SamSs C:\WINDOWS\system32\lsass.exe
22:44:09.0343 3928 SamSs - ok
22:44:09.0375 3928 [ C177354E995CC1AA1F767BCD9980434A ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:44:09.0375 3928 SCardSvr - ok
22:44:09.0406 3928 [ 29AC93307C6182DBE336BCA314947F28 ] Schedule C:\WINDOWS\system32\schedsvc.dll
22:44:09.0421 3928 Schedule - ok
22:44:09.0437 3928 [ D26E26EA516450AF9D072635C60387F4 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:44:09.0453 3928 Secdrv - ok
22:44:09.0468 3928 [ C76CB8A133374FAC6805F83FF7B7DA03 ] seclogon C:\WINDOWS\System32\seclogon.dll
22:44:09.0468 3928 seclogon - ok
22:44:09.0484 3928 [ 220AD85BA9C5B3011296354011B901CC ] SENS C:\WINDOWS\system32\sens.dll
22:44:09.0500 3928 SENS - ok
22:44:09.0515 3928 [ C1DDBC85251551A840212999DA3D95F3 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
22:44:09.0515 3928 Serial - ok
22:44:09.0531 3928 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:44:09.0531 3928 Sfloppy - ok
22:44:09.0562 3928 [ 6A93501BCDEBF159109429B022C0FF83 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:44:09.0562 3928 SharedAccess - ok
22:44:09.0593 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:44:09.0593 3928 ShellHWDetection - ok
22:44:09.0609 3928 Simbad - ok
22:44:09.0625 3928 Sparrow - ok
22:44:09.0625 3928 [ 8E186B8F23295D1E42C573B82B80D548 ] splitter C:\WINDOWS\system32\drivers\splitter.sys
22:44:09.0625 3928 splitter - ok
22:44:09.0640 3928 [ 21B6FAA88044A41640E03EBB68BE93E8 ] Spooler C:\WINDOWS\system32\spoolsv.exe
22:44:09.0656 3928 Spooler - ok
22:44:09.0703 3928 [ A199171385BE17973FD800FA91F8F78A ] sptd C:\WINDOWS\system32\Drivers\sptd.sys
22:44:09.0703 3928 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: A199171385BE17973FD800FA91F8F78A
22:44:09.0718 3928 sptd ( LockedFile.Multi.Generic ) - warning
22:44:09.0718 3928 sptd - detected LockedFile.Multi.Generic (1)
22:44:09.0734 3928 [ A74035EA526DB97D9D50D2143A55F5CF ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:44:09.0750 3928 sr - ok
22:44:09.0765 3928 [ 3CD57F31A64D32FDB28918B16D1E6AAC ] srservice C:\WINDOWS\system32\srsvc.dll
22:44:09.0781 3928 srservice - ok
22:44:09.0812 3928 [ 20B7E396720353E4117D64D9DCB926CA ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:44:09.0812 3928 Srv - ok
22:44:09.0843 3928 [ 88C28F53F53438DAFCD95E99C837C61E ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:44:09.0859 3928 SSDPSRV - ok
22:44:09.0875 3928 [ 0645CCDDDD27F96EEA3534C1DEF736D9 ] stisvc C:\WINDOWS\system32\wiaservc.dll
22:44:09.0890 3928 stisvc - ok
22:44:09.0921 3928 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:44:09.0921 3928 swenum - ok
22:44:09.0937 3928 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:44:09.0937 3928 swmidi - ok
22:44:09.0953 3928 SwPrv - ok
22:44:09.0953 3928 symc810 - ok
22:44:09.0968 3928 symc8xx - ok
22:44:09.0984 3928 sym_hi - ok
22:44:09.0984 3928 sym_u3 - ok
22:44:10.0015 3928 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:44:10.0015 3928 sysaudio - ok
22:44:10.0031 3928 [ D9C9ECFF4904E6151525C533AEEDF8F4 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:44:10.0046 3928 SysmonLog - ok
22:44:10.0062 3928 [ 37162D29CD61519E6F5EA0DE99786FF6 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:44:10.0078 3928 TapiSrv - ok
22:44:10.0109 3928 [ 9F4B36614A0FC234525BA224957DE55C ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:44:10.0125 3928 Tcpip - ok
22:44:10.0140 3928 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:44:10.0140 3928 TDPIPE - ok
22:44:10.0156 3928 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:44:10.0171 3928 TDTCP - ok
22:44:10.0187 3928 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:44:10.0187 3928 TermDD - ok
22:44:10.0218 3928 [ 2F5919F2F6EE7A845893D9C3AA2BC56A ] TermService C:\WINDOWS\System32\termsrv.dll
22:44:10.0234 3928 TermService - ok
22:44:10.0265 3928 [ 8BA76BD2A943F642F267A296A15776D2 ] Themes C:\WINDOWS\System32\shsvcs.dll
22:44:10.0265 3928 Themes - ok
22:44:10.0281 3928 [ 535C2FB97336BAFA509F4783DD1E5746 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:44:10.0296 3928 TlntSvr - ok
22:44:10.0312 3928 TosIde - ok
22:44:10.0328 3928 [ 4DCE17221B1A87FB47E36842F3E38753 ] TrkWks C:\WINDOWS\system32\trkwks.dll
22:44:10.0328 3928 TrkWks - ok
22:44:10.0359 3928 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:44:10.0359 3928 Udfs - ok
22:44:10.0406 3928 [ 3B7E264485F361EA5A65FEEF89F2352F ] UltiDev Cassini Web Server for ASP.NET 2.0 C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
22:44:10.0406 3928 UltiDev Cassini Web Server for ASP.NET 2.0 - ok
22:44:10.0421 3928 ultra - ok
22:44:10.0453 3928 [ AFF2E5045961BBC0A602BB6F95EB1345 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
22:44:10.0468 3928 Update - ok
22:44:10.0484 3928 [ 984FC1518B0D5B31D76F0E63608E0500 ] upnphost C:\WINDOWS\System32\upnphost.dll
22:44:10.0500 3928 upnphost - ok
22:44:10.0515 3928 [ 6148A3BA4D9CC628357FC92014FEA30E ] UPS C:\WINDOWS\System32\ups.exe
22:44:10.0531 3928 UPS - ok
22:44:10.0562 3928 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:44:10.0562 3928 usbccgp - ok
22:44:10.0593 3928 [ 15E993BA2F6946B2BFBBFCD30398621E ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:44:10.0593 3928 usbehci - ok
22:44:10.0609 3928 [ C72F40947F92CEA56A8FB532EDF025F1 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:44:10.0609 3928 usbhub - ok
22:44:10.0625 3928 [ BDFE799A8531BAD8A5A985821FE78760 ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
22:44:10.0625 3928 usbohci - ok
22:44:10.0656 3928 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:44:10.0671 3928 usbprint - ok
22:44:10.0703 3928 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:44:10.0703 3928 usbscan - ok
22:44:10.0734 3928 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:44:10.0734 3928 USBSTOR - ok
22:44:10.0750 3928 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:44:10.0750 3928 VgaSave - ok
22:44:10.0765 3928 ViaIde - ok
22:44:10.0781 3928 [ CD8CCE067F7E9CBD762C00BDDDECAA34 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:44:10.0781 3928 VolSnap - ok
22:44:10.0812 3928 [ 043539881667BB37B07524032D6FFC3E ] VSS C:\WINDOWS\System32\vssvc.exe
22:44:10.0828 3928 VSS - ok
22:44:10.0859 3928 [ 2CEEBB402187AE56B585701F3D191FB3 ] W32Time C:\WINDOWS\system32\w32time.dll
22:44:10.0875 3928 W32Time - ok
22:44:10.0890 3928 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:44:10.0890 3928 Wanarp - ok
22:44:10.0906 3928 WDICA - ok
22:44:10.0921 3928 [ 2797F33EBF50466020C430EE4F037933 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:44:10.0921 3928 wdmaud - ok
22:44:10.0937 3928 [ 3791ADF1D3466AC6B4B662D3F79CBFEC ] WebClient C:\WINDOWS\System32\webclnt.dll
22:44:10.0953 3928 WebClient - ok
22:44:11.0015 3928 [ E12084EA622BDF2262C637BEF15DD85C ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:44:11.0015 3928 winmgmt - ok
22:44:11.0062 3928 [ E02E913B3841717A890A644EE167B9A5 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
22:44:11.0078 3928 WmdmPmSN - ok
22:44:11.0125 3928 [ 0CDC4A0C6B820FAD99FB4CA74CD0C476 ] Wmi C:\WINDOWS\System32\advapi32.dll
22:44:11.0140 3928 Wmi - ok
22:44:11.0171 3928 [ BCD21B989F0FD4ACE78287FC01B4693D ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:44:11.0187 3928 WmiApSrv - ok
22:44:11.0218 3928 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:44:11.0218 3928 WS2IFSL - ok
22:44:11.0250 3928 [ 4ADED1ADEF25041D9827F9A79C0FDA13 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
22:44:11.0250 3928 wscsvc - ok
22:44:11.0281 3928 [ 21F5169CA14E0B25C757644456F637DF ] wuauserv C:\WINDOWS\system32\wuauserv.dll
22:44:11.0281 3928 wuauserv - ok
22:44:11.0312 3928 [ 325CEDEF696EF4B649DDCD3968D085C9 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:44:11.0328 3928 WZCSVC - ok
22:44:11.0359 3928 [ 9B835D4C64860B155A1701D5092EC9E4 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
22:44:11.0375 3928 xmlprov - ok
22:44:11.0375 3928 ================ Scan global ===============================
22:44:11.0390 3928 [ F642F3368D2839798DA79E7BA9218481 ] C:\WINDOWS\system32\basesrv.dll
22:44:11.0421 3928 [ E4E57FBA176F2752527B1D53A663D2D7 ] C:\WINDOWS\system32\winsrv.dll
22:44:11.0437 3928 [ E4E57FBA176F2752527B1D53A663D2D7 ] C:\WINDOWS\system32\winsrv.dll
22:44:11.0468 3928 [ 6E401E61F952FBBF708AFBECEFAFAE81 ] C:\WINDOWS\system32\services.exe
22:44:11.0468 3928 [Global] - ok
22:44:11.0468 3928 ================ Scan MBR ==================================
22:44:11.0500 3928 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk0\DR0
22:44:11.0578 3928 \Device\Harddisk0\DR0 - ok
22:44:11.0578 3928 ================ Scan VBR ==================================
22:44:11.0593 3928 [ 5F7089D7AF07FF80FEDE5B53ABEAAE3C ] \Device\Harddisk0\DR0\Partition1
22:44:11.0593 3928 \Device\Harddisk0\DR0\Partition1 - ok
22:44:11.0609 3928 [ 9DB004839D1CF6650FACEB67E6531D4C ] \Device\Harddisk0\DR0\Partition2
22:44:11.0609 3928 \Device\Harddisk0\DR0\Partition2 - ok
22:44:11.0609 3928 ============================================================
22:44:11.0609 3928 Scan finished
22:44:11.0609 3928 ============================================================
22:44:11.0625 3880 Detected object count: 1
22:44:11.0625 3880 Actual detected object count: 1
22:45:01.0796 3880 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:45:01.0796 3880 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Úplně zamrzá - prosím o kontrolu
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
Klikni na „ Delete“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Klikni na „ Delete“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Úplně zamrzá - prosím o kontrolu
# AdwCleaner v2.109 - Logfile created 02/01/2013 at 20:47:59
# Updated 26/01/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)
# User :
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Fr\Plocha\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\Askcom.xml
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\SweetIm.xml
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\SweetIM
Folder Deleted : C:\Documents and Settings\Fr\Data aplikací\OpenCandy
***** [Registry] *****
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14656 --> hxxp://www.google.com
-\\ Mozilla Firefox v18.0.1 (cs)
File : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\prefs.js
C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\user.js ... Deleted !
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Deleted : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Deleted : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1359356607040");
Deleted : user_pref("sweetim.toolbar.Visibility.enable", "true");
Deleted : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Deleted : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Deleted : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...]
Deleted : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Deleted : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Deleted : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?la[...]
Deleted : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Deleted : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...]
Deleted : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Deleted : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...]
Deleted : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Deleted : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[...]
Deleted : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Deleted : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Deleted : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Deleted : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Deleted : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...]
Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Deleted : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.mode.debug", "false");
Deleted : user_pref("sweetim.toolbar.newtab.created", "false");
Deleted : user_pref("sweetim.toolbar.newtab.enable", "true");
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Deleted : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_V[...]
Deleted : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(http://www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(http://www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Deleted : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.callback", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...]
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Deleted : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Deleted : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?[...]
Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10");
Deleted : user_pref("sweetim.toolbar.searchguard.enable", "false");
Deleted : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Deleted : user_pref("sweetim.toolbar.version", "1.9.0.0");
*************************
AdwCleaner[R2].txt - [8841 octets] - [01/02/2013 20:41:00]
AdwCleaner[S1].txt - [9130 octets] - [01/02/2013 20:47:59]
########## EOF - C:\AdwCleaner[S1].txt - [9190 octets] ##########
# Updated 26/01/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)
# User :
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Fr\Plocha\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\Askcom.xml
File Deleted : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\searchplugins\SweetIm.xml
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\SweetIM
Folder Deleted : C:\Documents and Settings\Fr\Data aplikací\OpenCandy
***** [Registry] *****
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook
Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://eu.ask.com/?l=dis&o=14656 --> hxxp://www.google.com
-\\ Mozilla Firefox v18.0.1 (cs)
File : C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\prefs.js
C:\Documents and Settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\user.js ... Deleted !
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Deleted : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Deleted : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1359356607040");
Deleted : user_pref("sweetim.toolbar.Visibility.enable", "true");
Deleted : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Deleted : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Deleted : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Deleted : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...]
Deleted : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Deleted : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Deleted : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?la[...]
Deleted : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Deleted : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...]
Deleted : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Deleted : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...]
Deleted : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Deleted : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Deleted : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[...]
Deleted : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Deleted : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Deleted : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Deleted : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Deleted : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Deleted : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...]
Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Deleted : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Deleted : user_pref("sweetim.toolbar.mode.debug", "false");
Deleted : user_pref("sweetim.toolbar.newtab.created", "false");
Deleted : user_pref("sweetim.toolbar.newtab.enable", "true");
Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Deleted : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_V[...]
Deleted : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(http://www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Deleted : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Deleted : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(http://www.|apps.)?facebook\\.com.*");
Deleted : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Deleted : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Deleted : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Deleted : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.callback", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...]
Deleted : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Deleted : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Deleted : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Deleted : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Deleted : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?[...]
Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10");
Deleted : user_pref("sweetim.toolbar.searchguard.enable", "false");
Deleted : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Deleted : user_pref("sweetim.toolbar.version", "1.9.0.0");
*************************
AdwCleaner[R2].txt - [8841 octets] - [01/02/2013 20:41:00]
AdwCleaner[S1].txt - [9130 octets] - [01/02/2013 20:47:59]
########## EOF - C:\AdwCleaner[S1].txt - [9190 octets] ##########
Re: Úplně zamrzá - prosím o kontrolu
ComboFix 13-02-01.04 - Fr 01.02.2013 21:16:36.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.240 [GMT 1:00]
Spuštěný z: d:\stažené soubory\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: NVIDIA Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-01 do 2013-02-01 )))))))))))))))))))))))))))))))
.
.
2013-01-30 20:33 . 2013-01-30 20:33 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-30 20:33 . 2013-01-30 20:33 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-30 19:52 . 2013-01-30 19:52 -------- d-----w- c:\program files\CPUID
2013-01-30 11:03 . 2013-01-30 11:03 -------- d-----w- c:\program files\Trend Micro
2013-01-27 17:48 . 2013-01-27 17:48 -------- d-sh--w- c:\documents and settings\Fr\PrivacIE
2013-01-27 17:41 . 2013-01-27 17:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2013-01-27 17:40 . 2013-01-27 17:40 -------- d-sh--w- c:\documents and settings\Fr\IETldCache
2013-01-27 17:38 . 2013-01-30 12:27 -------- d-----w- c:\program files\Seznam.cz
2013-01-27 17:38 . 2009-01-07 17:20 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2013-01-27 17:38 . 2013-01-27 17:38 -------- dc-h--w- c:\windows\ie8
2013-01-27 17:38 . 2013-01-27 17:38 -------- d-----w- c:\windows\system32\cs-CZ
2013-01-22 11:03 . 2013-01-22 11:03 -------- d-----w- C:\found.002
2013-01-10 21:24 . 2013-01-10 21:24 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-10 16:54 -------- d-----w- c:\documents and settings\Fr\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-10 16:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-11 07:42 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-01-10 16:54 . 2013-01-10 16:54 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2013-01-10 16:52 . 2013-01-10 16:52 -------- d-----w- c:\documents and settings\Fr\Data aplikací\.minecraft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-16 20:10 . 2013-01-27 07:15 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 266240]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\Fr\Nabídka Start\Programy\Po spuštění\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-08-03 11:49 13892200 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-07-05 08:08 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 20:32 53248 ------w- c:\program files\REGSHAVE\REGSHAVE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-06-20 13:42 77824 ----a-r- c:\windows\SOUNDMAN.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.11.2011 18:01 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20.9.2011 18:13 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.9.2011 18:13 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.9.2011 18:13 21256]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0;c:\program files\UltiDev\Cassini Web Server for ASP.NET 2.0\ULTIDEVCASSINWEBSERVER2A.EXE [8.2.2007 0:06 49152]
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-30 20:33]
.
2013-02-01 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-01 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} -
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
TCP: DhcpNameServer = 192.168.17.1 8.8.8.8
FF - ProfilePath - c:\documents and settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-01-11 08:27; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\Fr\Data aplikacĂÂ\Mozilla\Firefox\Profiles\zeecnpih.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
AddRemove-Firestarter, Shadowgrounds_is1 - D:\Firestarter
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-01 21:21
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(788)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(876)
c:\windows\system32\nvappfilter.dll
.
- - - - - - - > 'explorer.exe'(316)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Celkový čas: 2013-02-01 21:22:13
ComboFix-quarantined-files.txt 2013-02-01 20:22
.
Před spuštěním: 2 555 576 320
Po spuštění: 2 528 681 984
.
- - End Of File - - DDD6E7E923D1444AF78C68DCEDB1EF3C
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.240 [GMT 1:00]
Spuštěný z: d:\stažené soubory\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: NVIDIA Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-01-01 do 2013-02-01 )))))))))))))))))))))))))))))))
.
.
2013-01-30 20:33 . 2013-01-30 20:33 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-30 20:33 . 2013-01-30 20:33 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-30 19:52 . 2013-01-30 19:52 -------- d-----w- c:\program files\CPUID
2013-01-30 11:03 . 2013-01-30 11:03 -------- d-----w- c:\program files\Trend Micro
2013-01-27 17:48 . 2013-01-27 17:48 -------- d-sh--w- c:\documents and settings\Fr\PrivacIE
2013-01-27 17:41 . 2013-01-27 17:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2013-01-27 17:40 . 2013-01-27 17:40 -------- d-sh--w- c:\documents and settings\Fr\IETldCache
2013-01-27 17:38 . 2013-01-30 12:27 -------- d-----w- c:\program files\Seznam.cz
2013-01-27 17:38 . 2009-01-07 17:20 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2013-01-27 17:38 . 2013-01-27 17:38 -------- dc-h--w- c:\windows\ie8
2013-01-27 17:38 . 2013-01-27 17:38 -------- d-----w- c:\windows\system32\cs-CZ
2013-01-22 11:03 . 2013-01-22 11:03 -------- d-----w- C:\found.002
2013-01-10 21:24 . 2013-01-10 21:24 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-10 16:54 -------- d-----w- c:\documents and settings\Fr\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-10 16:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2013-01-10 16:54 . 2013-01-11 07:42 -------- d-sh--w- c:\documents and settings\All Users\Data aplikací\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-01-10 16:54 . 2013-01-10 16:54 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2013-01-10 16:52 . 2013-01-10 16:52 -------- d-----w- c:\documents and settings\Fr\Data aplikací\.minecraft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-16 20:10 . 2013-01-27 07:15 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 266240]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\Fr\Nabídka Start\Programy\Po spuštění\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-08-03 11:49 13892200 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-07-05 08:08 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 20:32 53248 ------w- c:\program files\REGSHAVE\REGSHAVE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-06-20 13:42 77824 ----a-r- c:\windows\SOUNDMAN.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.11.2011 18:01 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20.9.2011 18:13 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.9.2011 18:13 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.9.2011 18:13 21256]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0;c:\program files\UltiDev\Cassini Web Server for ASP.NET 2.0\ULTIDEVCASSINWEBSERVER2A.EXE [8.2.2007 0:06 49152]
.
Obsah adresáře 'Naplánované úlohy'
.
2013-02-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-30 20:33]
.
2013-02-01 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-01 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: {{0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} -
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
TCP: DhcpNameServer = 192.168.17.1 8.8.8.8
FF - ProfilePath - c:\documents and settings\Fr\Data aplikací\Mozilla\Firefox\Profiles\zeecnpih.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-01-11 08:27; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\Fr\Data aplikacĂÂ\Mozilla\Firefox\Profiles\zeecnpih.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - (no file)
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
AddRemove-Firestarter, Shadowgrounds_is1 - D:\Firestarter
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-01 21:21
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(788)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(876)
c:\windows\system32\nvappfilter.dll
.
- - - - - - - > 'explorer.exe'(316)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Celkový čas: 2013-02-01 21:22:13
ComboFix-quarantined-files.txt 2013-02-01 20:22
.
Před spuštěním: 2 555 576 320
Po spuštění: 2 528 681 984
.
- - End Of File - - DDD6E7E923D1444AF78C68DCEDB1EF3C
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Úplně zamrzá - prosím o kontrolu
Máš strašně málo volného místa na systémovém disku. 2,5 GB pro plynulý chod nebude stačit. Uvolni více místa. Mělo by být volno cca 15 % kapacity disku. Jinak může docházet právě k zamrzání, nestabilitě apod.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Úplně zamrzá - prosím o kontrolu
myslíš na c?Celkovou kapacitu mám 10,2GB,z toho přes 2GB volné.
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Úplně zamrzá - prosím o kontrolu
10GB je na XP strašně málo
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC na plochu, spusť jej a klikni na Clean up!
+ Nový log z HJT
Jak se chová PC?
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
vyčisti systém CCleanerem
Stáhni si OTC na plochu, spusť jej a klikni na Clean up!
+ Nový log z HJT
Jak se chová PC?
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Úplně zamrzá - prosím o kontrolu
uvolnila jsem ještě nějaké místo,mám 3,4-mělo by to stačit.Vím že je to málo těch 10,ale s tím už zřejmě nic nejde.Pořád to hlídám,to je první co kontroluju,když pc vázne.Zatím jede,ale třeba ve hře se sekne.A naskočila cedulka,že je malá virtuální paměť.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:50:23, on 5.2.2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
D:\Stažené soubory\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1659004503-1450960922-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\WINDOWS\system32\shdocvw.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: UltiDev Cassini Web Server for ASP.NET 2.0 - UltiDev LLC - C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
--
End of file - 5955 bytes
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:50:23, on 5.2.2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
D:\Stažené soubory\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1659004503-1450960922-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\WINDOWS\system32\shdocvw.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: UltiDev Cassini Web Server for ASP.NET 2.0 - UltiDev LLC - C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
--
End of file - 5955 bytes
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Úplně zamrzá - prosím o kontrolu
Máš staré updaty. Už je SP3 a máš pořád SP2. Navíc s tím málo místem na disku máš pravděpodobně malý stránkovací soubor a proto ten problém. Bohužel už nemám po ruce XP, tak neřeknu, kde přesně zkontroluješ jeho velikost. Bylo to nějak přes klik pravým na tento počítač - vlastnosti - Výkon, apod.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Úplně zamrzá - prosím o kontrolu
takže stáhnout SP3?
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Úplně zamrzá - prosím o kontrolu
V rámci pravidelných aktualizací systému by se měl stáhnout sám. Musíš je mít ovšem povolené a legální systém Windows.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 101 hostů