21:02:41.0992 1856 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:02:43.0250 1856 ============================================================
21:02:43.0250 1856 Current date / time: 2013/12/03 21:02:43.0250
21:02:43.0250 1856 SystemInfo:
21:02:43.0250 1856
21:02:43.0250 1856 OS Version: 6.2.9200 ServicePack: 0.0
21:02:43.0250 1856 Product type: Workstation
21:02:43.0250 1856 ComputerName: PETR
21:02:43.0250 1856 UserName: Petr Jurecek
21:02:43.0250 1856 Windows directory: C:\Windows
21:02:43.0250 1856 System windows directory: C:\Windows
21:02:43.0250 1856 Running under WOW64
21:02:43.0250 1856 Processor architecture: Intel x64
21:02:43.0250 1856 Number of processors: 2
21:02:43.0250 1856 Page size: 0x1000
21:02:43.0250 1856 Boot type: Normal boot
21:02:43.0250 1856 ============================================================
21:02:44.0217 1856 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:02:44.0233 1856 ============================================================
21:02:44.0233 1856 \Device\Harddisk0\DR0:
21:02:44.0234 1856 MBR partitions:
21:02:44.0234 1856 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A385000
21:02:44.0234 1856 ============================================================
21:02:44.0234 1856 C: <-> \Device\Harddisk0\DR0\Partition1
21:02:44.0234 1856 ============================================================
21:02:44.0234 1856 Initialize success
21:02:44.0234 1856 ============================================================
21:02:45.0406 3904 ============================================================
21:02:45.0406 3904 Scan started
21:02:45.0406 3904 Mode: Manual;
21:02:45.0406 3904 ============================================================
21:02:47.0125 3904 ================ Scan system memory ========================
21:02:47.0125 3904 System memory - ok
21:02:47.0125 3904 ================ Scan services =============================
21:02:47.0938 3904 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
21:02:47.0938 3904 1394ohci - ok
21:02:47.0970 3904 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
21:02:47.0970 3904 3ware - ok
21:02:48.0016 3904 [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer C:\Windows\system32\DRIVERS\Accelerometer.sys
21:02:48.0016 3904 Accelerometer - ok
21:02:48.0063 3904 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:02:48.0079 3904 ACPI - ok
21:02:48.0094 3904 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
21:02:48.0094 3904 acpiex - ok
21:02:48.0110 3904 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
21:02:48.0110 3904 acpipagr - ok
21:02:48.0126 3904 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
21:02:48.0126 3904 AcpiPmi - ok
21:02:48.0126 3904 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
21:02:48.0126 3904 acpitime - ok
21:02:48.0210 3904 [ D0B11E40EA74A98A5E133DF1F5276240 ] acsock C:\Windows\system32\DRIVERS\acsock64.sys
21:02:48.0210 3904 acsock - ok
21:02:48.0323 3904 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:02:48.0339 3904 AdobeARMservice - ok
21:02:48.0698 3904 [ A283108E14F3970432C21AF4C0CB1BCE ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:02:48.0714 3904 AdobeFlashPlayerUpdateSvc - ok
21:02:48.0761 3904 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
21:02:48.0776 3904 adp94xx - ok
21:02:48.0776 3904 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
21:02:48.0776 3904 adpahci - ok
21:02:48.0808 3904 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
21:02:48.0808 3904 adpu320 - ok
21:02:48.0854 3904 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:02:48.0854 3904 AeLookupSvc - ok
21:02:48.0979 3904 [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe
21:02:48.0979 3904 AESTFilters - ok
21:02:49.0042 3904 [ 7C0E0EDF18D6CC565D7BFBB451709FA5 ] AFD C:\Windows\system32\drivers\afd.sys
21:02:49.0057 3904 AFD - ok
21:02:49.0104 3904 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
21:02:49.0104 3904 agp440 - ok
21:02:49.0120 3904 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
21:02:49.0135 3904 ALG - ok
21:02:49.0166 3904 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
21:02:49.0166 3904 AllUserInstallAgent - ok
21:02:49.0213 3904 [ E20DDDFBD0DBE7D8EAD4D7A51D654367 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:02:49.0229 3904 AMD External Events Utility - ok
21:02:49.0260 3904 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
21:02:49.0260 3904 AmdK8 - ok
21:02:49.0541 3904 [ 4284FB1240537A33E6EC417EFD87D40F ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
21:02:49.0603 3904 amdkmdag - ok
21:02:49.0666 3904 [ 6C25C497E05EFD0CB6033A0444FC9B51 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
21:02:49.0666 3904 amdkmdap - ok
21:02:49.0681 3904 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
21:02:49.0681 3904 AmdPPM - ok
21:02:49.0729 3904 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:02:49.0729 3904 amdsata - ok
21:02:49.0761 3904 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
21:02:49.0761 3904 amdsbs - ok
21:02:49.0776 3904 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:02:49.0776 3904 amdxata - ok
21:02:49.0792 3904 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
21:02:49.0792 3904 AppID - ok
21:02:49.0839 3904 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:02:49.0839 3904 AppIDSvc - ok
21:02:49.0886 3904 [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo C:\Windows\System32\appinfo.dll
21:02:49.0886 3904 Appinfo - ok
21:02:49.0995 3904 [ 30E3850F303EAE5C364782EA78579CC9 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:02:49.0995 3904 Apple Mobile Device - ok
21:02:50.0042 3904 [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt C:\Windows\System32\appmgmts.dll
21:02:50.0042 3904 AppMgmt - ok
21:02:50.0073 3904 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
21:02:50.0073 3904 arc - ok
21:02:50.0104 3904 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
21:02:50.0104 3904 arcsas - ok
21:02:50.0120 3904 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:02:50.0120 3904 AsyncMac - ok
21:02:50.0135 3904 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
21:02:50.0135 3904 atapi - ok
21:02:50.0182 3904 [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
21:02:50.0198 3904 AudioEndpointBuilder - ok
21:02:50.0291 3904 [ 599B3F685A263A114FFAF3BE29C49C75 ] Audiosrv C:\Windows\System32\Audiosrv.dll
21:02:50.0322 3904 Audiosrv - ok
21:02:50.0432 3904 [ F431DC5D94F4B2FDBC927655D8A9B10E ] Autodesk Content Service C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
21:02:50.0432 3904 Autodesk Content Service - ok
21:02:50.0525 3904 [ 9F29157695EE58875B06724743CE9C42 ] Autodesk Licensing Service C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
21:02:50.0541 3904 Autodesk Licensing Service - ok
21:02:50.0556 3904 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:02:50.0572 3904 AxInstSV - ok
21:02:50.0619 3904 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
21:02:50.0634 3904 b06bdrv - ok
21:02:50.0650 3904 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
21:02:50.0666 3904 BasicDisplay - ok
21:02:50.0681 3904 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
21:02:50.0681 3904 BasicRender - ok
21:02:50.0728 3904 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
21:02:50.0744 3904 BDESVC - ok
21:02:50.0775 3904 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
21:02:50.0775 3904 Beep - ok
21:02:50.0853 3904 [ 53AA55632B94622F2DC3695E86EF9363 ] BFE C:\Windows\System32\bfe.dll
21:02:50.0884 3904 BFE - ok
21:02:50.0915 3904 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
21:02:50.0947 3904 BITS - ok
21:02:51.0025 3904 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:02:51.0041 3904 Bonjour Service - ok
21:02:51.0088 3904 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:02:51.0088 3904 bowser - ok
21:02:51.0150 3904 [ 038FA1B55531E7020DB705B42FCCE373 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
21:02:51.0150 3904 BrokerInfrastructure - ok
21:02:51.0212 3904 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
21:02:51.0212 3904 Browser - ok
21:02:51.0275 3904 [ 6695200F455E251F0BCC9CE4D0978D59 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
21:02:51.0275 3904 BthAvrcpTg - ok
21:02:51.0322 3904 [ A8B20D852B07AE19A13B5D47EC4E4C3B ] BthEnum C:\Windows\System32\drivers\BthEnum.sys
21:02:51.0322 3904 BthEnum - ok
21:02:51.0353 3904 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
21:02:51.0353 3904 BthHFEnum - ok
21:02:51.0384 3904 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
21:02:51.0384 3904 bthhfhid - ok
21:02:51.0431 3904 [ EB4CBCB3288233CD964716D0A5E1CFC5 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
21:02:51.0431 3904 BTHMODEM - ok
21:02:51.0462 3904 [ 091BB978E9504D0AD14586929431A957 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
21:02:51.0462 3904 BthPan - ok
21:02:51.0493 3904 [ 13795CAA34239D97A7211E7F9D96E012 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
21:02:51.0509 3904 BTHPORT - ok
21:02:51.0540 3904 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
21:02:51.0540 3904 bthserv - ok
21:02:51.0578 3904 [ 1F715957F5236D30B6020A19A4271F6A ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
21:02:51.0578 3904 BTHUSB - ok
21:02:51.0610 3904 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:02:51.0610 3904 cdfs - ok
21:02:51.0625 3904 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
21:02:51.0625 3904 cdrom - ok
21:02:51.0656 3904 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
21:02:51.0656 3904 CertPropSvc - ok
21:02:51.0679 3904 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
21:02:51.0679 3904 circlass - ok
21:02:51.0710 3904 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
21:02:51.0725 3904 CLFS - ok
21:02:51.0788 3904 [ 9573E8C7C3B3D1625FD941841FD0859C ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
21:02:51.0788 3904 clwvd - ok
21:02:51.0803 3904 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
21:02:51.0803 3904 CmBatt - ok
21:02:51.0850 3904 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
21:02:51.0866 3904 CNG - ok
21:02:51.0881 3904 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
21:02:51.0881 3904 CompositeBus - ok
21:02:51.0881 3904 COMSysApp - ok
21:02:51.0897 3904 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
21:02:51.0897 3904 condrv - ok
21:02:51.0944 3904 [ 5CE2742F063731EC10C1B2EE386A2C08 ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:02:51.0944 3904 CryptSvc - ok
21:02:52.0006 3904 [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC C:\Windows\system32\drivers\csc.sys
21:02:52.0006 3904 CSC - ok
21:02:52.0053 3904 [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService C:\Windows\System32\cscsvc.dll
21:02:52.0084 3904 CscService - ok
21:02:52.0131 3904 [ FAEF4C245BE832DB41B15DAAC336AFB7 ] dam C:\Windows\system32\drivers\dam.sys
21:02:52.0131 3904 dam - ok
21:02:52.0178 3904 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
21:02:52.0209 3904 DcomLaunch - ok
21:02:52.0224 3904 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
21:02:52.0240 3904 defragsvc - ok
21:02:52.0271 3904 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
21:02:52.0271 3904 DeviceAssociationService - ok
21:02:52.0334 3904 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
21:02:52.0334 3904 DeviceInstall - ok
21:02:52.0365 3904 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
21:02:52.0365 3904 Dfsc - ok
21:02:52.0412 3904 [ E428DFFA96FAD07D8CA3C9082563A225 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
21:02:52.0412 3904 dg_ssudbus - ok
21:02:52.0474 3904 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
21:02:52.0490 3904 Dhcp - ok
21:02:52.0521 3904 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
21:02:52.0521 3904 discache - ok
21:02:52.0536 3904 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
21:02:52.0536 3904 disk - ok
21:02:52.0563 3904 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
21:02:52.0563 3904 dmvsc - ok
21:02:52.0606 3904 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:02:52.0606 3904 Dnscache - ok
21:02:52.0652 3904 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
21:02:52.0668 3904 dot3svc - ok
21:02:52.0683 3904 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
21:02:52.0699 3904 DPS - ok
21:02:52.0730 3904 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:02:52.0730 3904 drmkaud - ok
21:02:52.0793 3904 [ F87F4AAAF6664906248D11D5E579A53B ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
21:02:52.0793 3904 DsmSvc - ok
21:02:52.0839 3904 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\System32\drivers\dtsoftbus01.sys
21:02:52.0839 3904 dtsoftbus01 - ok
21:02:52.0902 3904 [ 6D1B8A9A2C0BD4851D8AF1AB43E67AD9 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:02:52.0917 3904 DXGKrnl - ok
21:02:52.0964 3904 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
21:02:52.0964 3904 Eaphost - ok
21:02:53.0073 3904 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
21:02:53.0089 3904 ebdrv - ok
21:02:53.0151 3904 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
21:02:53.0151 3904 EFS - ok
21:02:53.0183 3904 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
21:02:53.0183 3904 EhStorClass - ok
21:02:53.0214 3904 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
21:02:53.0214 3904 EhStorTcgDrv - ok
21:02:53.0245 3904 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
21:02:53.0245 3904 ErrDev - ok
21:02:53.0307 3904 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
21:02:53.0323 3904 EventSystem - ok
21:02:53.0403 3904 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
21:02:53.0403 3904 exfat - ok
21:02:53.0434 3904 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:02:53.0434 3904 fastfat - ok
21:02:53.0481 3904 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
21:02:53.0512 3904 Fax - ok
21:02:53.0543 3904 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
21:02:53.0543 3904 fdc - ok
21:02:53.0574 3904 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
21:02:53.0590 3904 fdPHost - ok
21:02:53.0606 3904 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
21:02:53.0606 3904 FDResPub - ok
21:02:53.0652 3904 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
21:02:53.0652 3904 fhsvc - ok
21:02:53.0684 3904 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:02:53.0684 3904 FileInfo - ok
21:02:53.0699 3904 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:02:53.0715 3904 Filetrace - ok
21:02:53.0777 3904 [ DFADECE1B66095F3F247ACC0EBDC5F8D ] FlexNet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
21:02:53.0824 3904 FlexNet Licensing Service - ok
21:02:53.0918 3904 [ 64AB6F28047744B9B19C97459C2AB31B ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
21:02:53.0980 3904 FLEXnet Licensing Service 64 - ok
21:02:54.0011 3904 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
21:02:54.0011 3904 flpydisk - ok
21:02:54.0042 3904 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:02:54.0042 3904 FltMgr - ok
21:02:54.0120 3904 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
21:02:54.0167 3904 FontCache - ok
21:02:54.0277 3904 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:02:54.0277 3904 FontCache3.0.0.0 - ok
21:02:54.0308 3904 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:02:54.0308 3904 FsDepends - ok
21:02:54.0339 3904 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:02:54.0339 3904 Fs_Rec - ok
21:02:54.0386 3904 [ C1646A95EAC515F60CDB2A7A8A013C1E ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:02:54.0401 3904 fvevol - ok
21:02:54.0448 3904 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
21:02:54.0448 3904 FxPPM - ok
21:02:54.0479 3904 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
21:02:54.0479 3904 gagp30kx - ok
21:02:54.0526 3904 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:02:54.0526 3904 GEARAspiWDM - ok
21:02:54.0557 3904 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
21:02:54.0573 3904 gencounter - ok
21:02:54.0604 3904 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
21:02:54.0604 3904 GPIOClx0101 - ok
21:02:54.0651 3904 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
21:02:54.0698 3904 gpsvc - ok
21:02:54.0760 3904 [ 630555943E5A3FE21010CE91EC7FC84F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:02:54.0760 3904 HdAudAddService - ok
21:02:54.0838 3904 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
21:02:54.0838 3904 HDAudBus - ok
21:02:54.0869 3904 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
21:02:54.0869 3904 HidBatt - ok
21:02:54.0916 3904 [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth C:\Windows\System32\drivers\hidbth.sys
21:02:54.0916 3904 HidBth - ok
21:02:54.0947 3904 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
21:02:54.0947 3904 hidi2c - ok
21:02:54.0978 3904 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
21:02:54.0978 3904 HidIr - ok
21:02:55.0010 3904 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
21:02:55.0010 3904 hidserv - ok
21:02:55.0056 3904 [ 012C354B4AB48E9A7A657DF39E3A2073 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
21:02:55.0056 3904 HidUsb - ok
21:02:55.0103 3904 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:02:55.0103 3904 hkmsvc - ok
21:02:55.0150 3904 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:02:55.0166 3904 HomeGroupListener - ok
21:02:55.0212 3904 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:02:55.0212 3904 HomeGroupProvider - ok
21:02:55.0260 3904 [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt C:\Windows\system32\DRIVERS\hpdskflt.sys
21:02:55.0260 3904 hpdskflt - ok
21:02:55.0292 3904 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
21:02:55.0292 3904 HpSAMD - ok
21:02:55.0323 3904 [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv C:\Windows\system32\Hpservice.exe
21:02:55.0323 3904 hpsrv - ok
21:02:55.0385 3904 [ F4A91D985EB9D1D2717D538F3424603C ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:02:55.0401 3904 HTTP - ok
21:02:55.0463 3904 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:02:55.0463 3904 hwpolicy - ok
21:02:55.0494 3904 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
21:02:55.0494 3904 hyperkbd - ok
21:02:55.0510 3904 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
21:02:55.0510 3904 HyperVideo - ok
21:02:55.0526 3904 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
21:02:55.0541 3904 i8042prt - ok
21:02:55.0573 3904 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:02:55.0573 3904 iaStorV - ok
21:02:55.0588 3904 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
21:02:55.0588 3904 iirsp - ok
21:02:55.0666 3904 [ E455C83E029121270BED73CDAC381F37 ] IKEEXT C:\Windows\System32\ikeext.dll
21:02:55.0697 3904 IKEEXT - ok
21:02:55.0729 3904 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
21:02:55.0729 3904 intelide - ok
21:02:55.0760 3904 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
21:02:55.0775 3904 intelppm - ok
21:02:55.0806 3904 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:02:55.0822 3904 IpFilterDriver - ok
21:02:55.0869 3904 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:02:55.0900 3904 iphlpsvc - ok
21:02:55.0931 3904 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
21:02:55.0931 3904 IPMIDRV - ok
21:02:55.0947 3904 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:02:55.0947 3904 IPNAT - ok
21:02:56.0009 3904 [ 33B286326BD2B1A7748C43391058FB19 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
21:02:56.0025 3904 iPod Service - ok
21:02:56.0040 3904 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:02:56.0040 3904 IRENUM - ok
21:02:56.0072 3904 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
21:02:56.0072 3904 isapnp - ok
21:02:56.0103 3904 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
21:02:56.0103 3904 iScsiPrt - ok
21:02:56.0150 3904 [ 54DF9EAFB54A98E1A2AC3DB69C16CF05 ] JMCR C:\Windows\system32\DRIVERS\jmcr.sys
21:02:56.0150 3904 JMCR - ok
21:02:56.0181 3904 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
21:02:56.0181 3904 kbdclass - ok
21:02:56.0212 3904 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
21:02:56.0212 3904 kbdhid - ok
21:02:56.0243 3904 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
21:02:56.0243 3904 kdnic - ok
21:02:56.0259 3904 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
21:02:56.0259 3904 KeyIso - ok
21:02:56.0306 3904 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:02:56.0306 3904 KSecDD - ok
21:02:56.0368 3904 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:02:56.0368 3904 KSecPkg - ok
21:02:56.0384 3904 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
21:02:56.0384 3904 ksthunk - ok
21:02:56.0446 3904 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
21:02:56.0462 3904 KtmRm - ok
21:02:56.0508 3904 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
21:02:56.0540 3904 LanmanServer - ok
21:02:56.0571 3904 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:02:56.0586 3904 LanmanWorkstation - ok
21:02:56.0602 3904 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:02:56.0618 3904 lltdio - ok
21:02:56.0664 3904 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:02:56.0664 3904 lltdsvc - ok
21:02:56.0696 3904 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
21:02:56.0711 3904 lmhosts - ok
21:02:56.0742 3904 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
21:02:56.0742 3904 LSI_SAS - ok
21:02:56.0758 3904 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
21:02:56.0774 3904 LSI_SAS2 - ok
21:02:56.0789 3904 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
21:02:56.0789 3904 LSI_SCSI - ok
21:02:56.0789 3904 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
21:02:56.0789 3904 LSI_SSS - ok
21:02:56.0836 3904 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
21:02:56.0852 3904 LSM - ok
21:02:56.0883 3904 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
21:02:56.0883 3904 luafv - ok
21:02:56.0914 3904 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
Prosím o kontrolu logu Vyřešeno
Re: Prosím o kontrolu logu
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
Re: Prosím o kontrolu logu
21:02:56.0914 3904 megasas - ok
21:02:56.0945 3904 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
21:02:56.0945 3904 MegaSR - ok
21:02:57.0024 3904 Microsoft SharePoint Workspace Audit Service - ok
21:02:57.0056 3904 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
21:02:57.0056 3904 MMCSS - ok
21:02:57.0087 3904 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
21:02:57.0087 3904 Modem - ok
21:02:57.0134 3904 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
21:02:57.0134 3904 monitor - ok
21:02:57.0149 3904 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
21:02:57.0149 3904 mouclass - ok
21:02:57.0196 3904 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
21:02:57.0196 3904 mouhid - ok
21:02:57.0212 3904 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:02:57.0212 3904 mountmgr - ok
21:02:57.0274 3904 [ 5E0686615A80A6279B2314E13CD23F6E ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:02:57.0274 3904 MozillaMaintenance - ok
21:02:57.0321 3904 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:02:57.0321 3904 mpsdrv - ok
21:02:57.0394 3904 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:02:57.0425 3904 MpsSvc - ok
21:02:57.0441 3904 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:02:57.0457 3904 MRxDAV - ok
21:02:57.0504 3904 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:02:57.0519 3904 mrxsmb - ok
21:02:57.0550 3904 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:02:57.0550 3904 mrxsmb10 - ok
21:02:57.0582 3904 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:02:57.0597 3904 mrxsmb20 - ok
21:02:57.0613 3904 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
21:02:57.0613 3904 MsBridge - ok
21:02:57.0675 3904 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
21:02:57.0675 3904 MSDTC - ok
21:02:57.0722 3904 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:02:57.0722 3904 Msfs - ok
21:02:57.0753 3904 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
21:02:57.0753 3904 msgpiowin32 - ok
21:02:57.0784 3904 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:02:57.0784 3904 mshidkmdf - ok
21:02:57.0800 3904 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
21:02:57.0800 3904 mshidumdf - ok
21:02:57.0800 3904 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:02:57.0800 3904 msisadrv - ok
21:02:57.0857 3904 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:02:57.0857 3904 MSiSCSI - ok
21:02:57.0857 3904 msiserver - ok
21:02:57.0889 3904 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:02:57.0889 3904 MSKSSRV - ok
21:02:57.0908 3904 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
21:02:57.0908 3904 MsLldp - ok
21:02:57.0925 3904 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:02:57.0925 3904 MSPCLOCK - ok
21:02:57.0925 3904 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:02:57.0925 3904 MSPQM - ok
21:02:57.0957 3904 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:02:57.0972 3904 MsRPC - ok
21:02:57.0988 3904 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
21:02:57.0988 3904 mssmbios - ok
21:02:58.0003 3904 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:02:58.0003 3904 MSTEE - ok
21:02:58.0026 3904 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
21:02:58.0026 3904 MTConfig - ok
21:02:58.0041 3904 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
21:02:58.0057 3904 Mup - ok
21:02:58.0072 3904 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
21:02:58.0072 3904 mvumis - ok
21:02:58.0119 3904 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
21:02:58.0135 3904 napagent - ok
21:02:58.0166 3904 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:02:58.0182 3904 NativeWifiP - ok
21:02:58.0213 3904 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
21:02:58.0228 3904 NcaSvc - ok
21:02:58.0244 3904 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
21:02:58.0244 3904 NcdAutoSetup - ok
21:02:58.0306 3904 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:02:58.0322 3904 NDIS - ok
21:02:58.0353 3904 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:02:58.0369 3904 NdisCap - ok
21:02:58.0400 3904 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
21:02:58.0400 3904 NdisImPlatform - ok
21:02:58.0447 3904 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:02:58.0462 3904 NdisTapi - ok
21:02:58.0478 3904 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:02:58.0478 3904 Ndisuio - ok
21:02:58.0509 3904 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:02:58.0509 3904 NdisWan - ok
21:02:58.0509 3904 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
21:02:58.0509 3904 NDISWANLEGACY - ok
21:02:58.0572 3904 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:02:58.0572 3904 NDProxy - ok
21:02:58.0587 3904 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
21:02:58.0587 3904 Ndu - ok
21:02:58.0603 3904 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:02:58.0603 3904 NetBIOS - ok
21:02:58.0681 3904 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:02:58.0681 3904 NetBT - ok
21:02:58.0712 3904 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
21:02:58.0712 3904 Netlogon - ok
21:02:58.0743 3904 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
21:02:58.0759 3904 Netman - ok
21:02:58.0806 3904 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
21:02:58.0821 3904 netprofm - ok
21:02:58.0884 3904 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:02:58.0915 3904 NetTcpPortSharing - ok
21:02:59.0133 3904 [ 57B9C04D673F236D41FAB03842C8640B ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
21:02:59.0180 3904 NETwNs64 - ok
21:02:59.0211 3904 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
21:02:59.0211 3904 nfrd960 - ok
21:02:59.0274 3904 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:02:59.0274 3904 NlaSvc - ok
21:02:59.0305 3904 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:02:59.0305 3904 Npfs - ok
21:02:59.0336 3904 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
21:02:59.0336 3904 npsvctrig - ok
21:02:59.0352 3904 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
21:02:59.0352 3904 nsi - ok
21:02:59.0383 3904 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:02:59.0383 3904 nsiproxy - ok
21:02:59.0479 3904 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:02:59.0479 3904 Ntfs - ok
21:02:59.0494 3904 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
21:02:59.0494 3904 Null - ok
21:02:59.0526 3904 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:02:59.0526 3904 nvraid - ok
21:02:59.0541 3904 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:02:59.0541 3904 nvstor - ok
21:02:59.0572 3904 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:02:59.0572 3904 nv_agp - ok
21:02:59.0635 3904 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:02:59.0635 3904 ose64 - ok
21:02:59.0806 3904 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:02:59.0838 3904 osppsvc - ok
21:02:59.0884 3904 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:02:59.0900 3904 p2pimsvc - ok
21:02:59.0931 3904 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
21:02:59.0962 3904 p2psvc - ok
21:02:59.0994 3904 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
21:02:59.0994 3904 Parport - ok
21:03:00.0040 3904 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:03:00.0040 3904 partmgr - ok
21:03:00.0103 3904 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:03:00.0118 3904 PcaSvc - ok
21:03:00.0150 3904 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
21:03:00.0150 3904 pci - ok
21:03:00.0181 3904 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
21:03:00.0181 3904 pciide - ok
21:03:00.0196 3904 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
21:03:00.0196 3904 pcmcia - ok
21:03:00.0228 3904 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
21:03:00.0228 3904 pcw - ok
21:03:00.0274 3904 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
21:03:00.0274 3904 pdc - ok
21:03:00.0384 3904 [ 20372BE109FEE1C37E2D5216680DB9EB ] PDF Architect Helper Service C:\Program Files (x86)\PDF Architect\HelperService.exe
21:03:00.0384 3904 PDF Architect Helper Service - ok
21:03:00.0430 3904 [ B90A279073A815A4AA2C45A09EE004FA ] PDF Architect Service C:\Program Files (x86)\PDF Architect\ConversionService.exe
21:03:00.0446 3904 PDF Architect Service - ok
21:03:00.0493 3904 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:03:00.0508 3904 PEAUTH - ok
21:03:00.0571 3904 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:03:00.0680 3904 PeerDistSvc - ok
21:03:00.0774 3904 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
21:03:00.0774 3904 PerfHost - ok
21:03:00.0852 3904 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
21:03:00.0884 3904 pla - ok
21:03:00.0930 3904 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:03:00.0946 3904 PlugPlay - ok
21:03:00.0962 3904 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:03:00.0977 3904 PNRPAutoReg - ok
21:03:01.0008 3904 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:03:01.0008 3904 PNRPsvc - ok
21:03:01.0055 3904 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:03:01.0071 3904 PolicyAgent - ok
21:03:01.0118 3904 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
21:03:01.0118 3904 Power - ok
21:03:01.0149 3904 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:03:01.0149 3904 PptpMiniport - ok
21:03:01.0274 3904 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
21:03:01.0358 3904 PrintNotify - ok
21:03:01.0405 3904 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
21:03:01.0405 3904 Processor - ok
21:03:01.0436 3904 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
21:03:01.0452 3904 ProfSvc - ok
21:03:01.0483 3904 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:03:01.0498 3904 Psched - ok
21:03:01.0514 3904 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
21:03:01.0530 3904 QWAVE - ok
21:03:01.0545 3904 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:03:01.0545 3904 QWAVEdrv - ok
21:03:01.0561 3904 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:03:01.0576 3904 RasAcd - ok
21:03:01.0592 3904 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:03:01.0592 3904 RasAgileVpn - ok
21:03:01.0608 3904 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
21:03:01.0623 3904 RasAuto - ok
21:03:01.0639 3904 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:03:01.0639 3904 Rasl2tp - ok
21:03:01.0655 3904 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
21:03:01.0670 3904 RasMan - ok
21:03:01.0686 3904 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:03:01.0686 3904 RasPppoe - ok
21:03:01.0701 3904 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:03:01.0701 3904 RasSstp - ok
21:03:01.0748 3904 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:03:01.0764 3904 rdbss - ok
21:03:01.0779 3904 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
21:03:01.0795 3904 rdpbus - ok
21:03:01.0810 3904 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:03:01.0826 3904 RDPDR - ok
21:03:01.0873 3904 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:03:01.0888 3904 RdpVideoMiniport - ok
21:03:01.0920 3904 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:03:01.0920 3904 RDPWD - ok
21:03:01.0951 3904 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:03:01.0951 3904 rdyboost - ok
21:03:01.0982 3904 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
21:03:01.0982 3904 RemoteAccess - ok
21:03:02.0029 3904 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:03:02.0045 3904 RemoteRegistry - ok
21:03:02.0091 3904 [ CCBFCABDFE2BC22F0645CEAADDB36004 ] RFCOMM C:\Windows\System32\drivers\rfcomm.sys
21:03:02.0091 3904 RFCOMM - ok
21:03:02.0138 3904 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:03:02.0138 3904 RpcEptMapper - ok
21:03:02.0169 3904 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
21:03:02.0169 3904 RpcLocator - ok
21:03:02.0232 3904 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
21:03:02.0247 3904 RpcSs - ok
21:03:02.0263 3904 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:03:02.0263 3904 rspndr - ok
21:03:02.0294 3904 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
21:03:02.0294 3904 RTL8168 - ok
21:03:02.0325 3904 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
21:03:02.0325 3904 s3cap - ok
21:03:02.0357 3904 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
21:03:02.0372 3904 SamSs - ok
21:03:02.0403 3904 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:03:02.0403 3904 sbp2port - ok
21:03:02.0450 3904 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:03:02.0450 3904 SCardSvr - ok
21:03:02.0481 3904 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:03:02.0481 3904 scfilter - ok
21:03:02.0544 3904 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
21:03:02.0575 3904 Schedule - ok
21:03:02.0606 3904 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
21:03:02.0622 3904 SCPolicySvc - ok
21:03:02.0669 3904 [ F58B030A0664385C707B8C1C63682041 ] sdbus C:\Windows\System32\drivers\sdbus.sys
21:03:02.0669 3904 sdbus - ok
21:03:02.0700 3904 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:03:02.0700 3904 SDRSVC - ok
21:03:02.0746 3904 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
21:03:02.0746 3904 sdstor - ok
21:03:02.0762 3904 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:03:02.0762 3904 secdrv - ok
21:03:02.0778 3904 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
21:03:02.0778 3904 seclogon - ok
21:03:02.0809 3904 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
21:03:02.0809 3904 SENS - ok
21:03:02.0843 3904 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:03:02.0849 3904 SensrSvc - ok
21:03:02.0865 3904 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
21:03:02.0881 3904 SerCx - ok
21:03:02.0896 3904 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
21:03:02.0896 3904 Serenum - ok
21:03:02.0912 3904 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
21:03:02.0912 3904 Serial - ok
21:03:02.0959 3904 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
21:03:02.0959 3904 sermouse - ok
21:03:02.0990 3904 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
21:03:02.0990 3904 SessionEnv - ok
21:03:02.0990 3904 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
21:03:02.0990 3904 sfloppy - ok
21:03:03.0068 3904 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:03:03.0083 3904 SharedAccess - ok
21:03:03.0146 3904 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:03:03.0146 3904 ShellHWDetection - ok
21:03:03.0177 3904 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
21:03:03.0177 3904 SiSRaid2 - ok
21:03:03.0193 3904 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
21:03:03.0193 3904 SiSRaid4 - ok
21:03:03.0224 3904 [ F2B755D3835089590E8113F48AA931F7 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
21:03:03.0239 3904 SkypeUpdate - ok
21:03:03.0271 3904 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:03:03.0271 3904 SNMPTRAP - ok
21:03:03.0317 3904 [ FD3AF5575B99871BADB94E7699DBCE08 ] spaceport C:\Windows\system32\drivers\spaceport.sys
21:03:03.0317 3904 spaceport - ok
21:03:03.0333 3904 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
21:03:03.0333 3904 SpbCx - ok
21:03:03.0364 3904 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
21:03:03.0364 3904 Spooler - ok
21:03:03.0536 3904 [ 061A977C920FBE4BF71FF47C966DDDCA ] sppsvc C:\Windows\system32\sppsvc.exe
21:03:03.0567 3904 sppsvc - ok
21:03:03.0598 3904 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:03:03.0598 3904 srv - ok
21:03:03.0645 3904 [ 56218A571ECF8D55E0CDFF8DF2546CF1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:03:03.0645 3904 srv2 - ok
21:03:03.0661 3904 [ 14FC338B80CFF7E04215133B568D15C4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:03:03.0661 3904 srvnet - ok
21:03:03.0801 3904 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:03:03.0817 3904 SSDPSRV - ok
21:03:03.0832 3904 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:03:03.0832 3904 SstpSvc - ok
21:03:03.0879 3904 [ AAF6F247F1DC370C593B4430974EAD9C ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
21:03:03.0879 3904 ssudmdm - ok
21:03:04.0019 3904 [ 7595D53EE8E8B0BAA9A2DDDE867EBB0C ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe
21:03:04.0019 3904 STacSV - ok
21:03:04.0066 3904 [ 2FAD3D9EBDF3A9DDFDFAE8A06B4ED4C9 ] Start8 C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
21:03:04.0066 3904 Start8 - ok
21:03:04.0097 3904 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
21:03:04.0097 3904 stexstor - ok
21:03:04.0144 3904 [ DFFBC024DFC7BB05B2129E05CBC7A201 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
21:03:04.0144 3904 STHDA - ok
21:03:04.0207 3904 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
21:03:04.0238 3904 stisvc - ok
21:03:04.0316 3904 [ B240874B2CA0CD02E8CD11E140B14C57 ] storahci C:\Windows\system32\drivers\storahci.sys
21:03:04.0316 3904 storahci - ok
21:03:04.0363 3904 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
21:03:04.0363 3904 storflt - ok
21:03:04.0394 3904 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
21:03:04.0409 3904 StorSvc - ok
21:03:04.0409 3904 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
21:03:04.0425 3904 storvsc - ok
21:03:04.0456 3904 [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp C:\Windows\System32\drivers\storvsp.sys
21:03:04.0456 3904 storvsp - ok
21:03:04.0472 3904 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
21:03:04.0472 3904 svsvc - ok
21:03:04.0487 3904 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
21:03:04.0487 3904 swenum - ok
21:03:04.0628 3904 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
21:03:04.0628 3904 SwitchBoard - ok
21:03:04.0675 3904 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
21:03:04.0706 3904 swprv - ok
21:03:04.0753 3904 [ AC3CC98B1BDB6540021D3FFB105AC2B9 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
21:03:04.0753 3904 SynTP - ok
21:03:04.0831 3904 [ A06CB9269D29EE3D0F3F5630ABB660B8 ] SysMain C:\Windows\system32\sysmain.dll
21:03:04.0893 3904 SysMain - ok
21:03:04.0940 3904 [ 6FB88606C4A71E1BFAF97D63A676C673 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
21:03:04.0955 3904 SystemEventsBroker - ok
21:03:04.0987 3904 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
21:03:04.0987 3904 TabletInputService - ok
21:03:05.0018 3904 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
21:03:05.0033 3904 TapiSrv - ok
21:03:05.0158 3904 [ 37D85E873C9531A2F88DD9C63D3F8A9E ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:03:05.0174 3904 Tcpip - ok
21:03:05.0236 3904 [ 37D85E873C9531A2F88DD9C63D3F8A9E ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:03:05.0252 3904 TCPIP6 - ok
21:03:05.0283 3904 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:03:05.0283 3904 tcpipreg - ok
21:03:05.0299 3904 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:03:05.0299 3904 tdx - ok
21:03:05.0314 3904 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
21:03:05.0314 3904 terminpt - ok
21:03:05.0377 3904 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
21:03:05.0423 3904 TermService - ok
21:03:05.0439 3904 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
21:03:05.0439 3904 Themes - ok
21:03:05.0501 3904 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
21:03:05.0501 3904 THREADORDER - ok
21:03:05.0564 3904 [ 4515B9E4140F04FB3907692DF89FCA87 ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
21:03:05.0564 3904 TimeBroker - ok
21:03:05.0626 3904 [ E94F7A7B48C7638D1F3F8089344C97B7 ] TPM C:\Windows\system32\drivers\tpm.sys
21:03:05.0626 3904 TPM - ok
21:03:05.0657 3904 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
21:03:05.0673 3904 TrkWks - ok
21:03:05.0798 3904 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:03:05.0813 3904 TrustedInstaller - ok
21:03:05.0845 3904 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
21:03:05.0845 3904 TsUsbFlt - ok
21:03:05.0860 3904 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
21:03:05.0860 3904 TsUsbGD - ok
21:03:05.0891 3904 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:03:05.0891 3904 tunnel - ok
21:03:05.0907 3904 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
21:03:05.0907 3904 uagp35 - ok
21:03:05.0923 3904 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
21:03:05.0923 3904 UASPStor - ok
21:03:05.0970 3904 [ 061BA3EE0D2BE17944990544008CF190 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
21:03:05.0970 3904 UCX01000 - ok
21:03:06.0017 3904 [ 25C50F4EDF70D0A831E0566BD181CCF2 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:03:06.0017 3904 udfs - ok
21:03:06.0063 3904 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:03:06.0063 3904 UI0Detect - ok
21:03:06.0110 3904 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:03:06.0110 3904 uliagpkx - ok
21:03:06.0141 3904 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
21:03:06.0141 3904 umbus - ok
21:03:06.0157 3904 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
21:03:06.0173 3904 UmPass - ok
21:03:06.0219 3904 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
21:03:06.0219 3904 UmRdpService - ok
21:03:06.0344 3904 [ FFF49A8E94E2F108F10CA72383FBF16F ] Update SquirrelWeb C:\Program Files (x86)\SquirrelWeb\updateSquirrelWeb.exe
21:03:06.0344 3904 Update SquirrelWeb - ok
21:03:06.0407 3904 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
21:03:06.0438 3904 upnphost - ok
21:03:06.0485 3904 [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64 C:\Windows\System32\Drivers\usbaapl64.sys
21:03:06.0485 3904 USBAAPL64 - ok
21:03:06.0531 3904 [ C976C4306F9AE133D6BBD47FDFC3BF92 ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
21:03:06.0547 3904 usbccgp - ok
21:03:06.0594 3904 [ 427B6DB8C05A5A977E8C3525370A2595 ] usbcir C:\Windows\System32\drivers\usbcir.sys
21:03:06.0594 3904 usbcir - ok
21:03:06.0656 3904 [ B24FDEB1B18496F1B463782235AA3AF1 ] usbehci C:\Windows\System32\drivers\usbehci.sys
21:03:06.0672 3904 usbehci - ok
21:03:06.0734 3904 [ F8C2A832DF9403F5EA8080CBDBDA95FB ] usbhub C:\Windows\System32\drivers\usbhub.sys
21:03:06.0734 3904 usbhub - ok
21:03:06.0781 3904 [ B1E910DDC08A8536116214326124903C ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
21:03:06.0797 3904 USBHUB3 - ok
21:03:06.0843 3904 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
21:03:06.0843 3904 usbohci - ok
21:03:06.0890 3904 [ 9FDBA6982582A6F2354144980F641E7B ] usbprint C:\Windows\System32\drivers\usbprint.sys
21:03:06.0890 3904 usbprint - ok
21:03:06.0921 3904 [ AD91D1BBE5D3CF4501887DC1C09384FD ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:03:06.0921 3904 usbscan - ok
21:03:06.0968 3904 [ BFC7FE4AAEB61317A921871B4085EF4B ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
21:03:06.0968 3904 USBSTOR - ok
21:03:07.0015 3904 [ 1ABF657259DB57F7E5558E4DF1357C0C ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
21:03:07.0015 3904 usbuhci - ok
21:03:07.0062 3904 [ 9EF7C01D3ACCBC243B5CB1A95865B2FF ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
21:03:07.0062 3904 usbvideo - ok
21:03:07.0124 3904 [ 8DC398D7B8E02C929A2096E74A170970 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
21:03:07.0124 3904 USBXHCI - ok
21:03:07.0155 3904 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
21:03:07.0155 3904 VaultSvc - ok
21:03:07.0179 3904 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
21:03:07.0179 3904 vdrvroot - ok
21:03:07.0218 3904 [ 1B4488988E5E7512E6C5CD1255E9E973 ] vds C:\Windows\System32\vds.exe
21:03:07.0250 3904 vds - ok
21:03:07.0281 3904 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
21:03:07.0281 3904 VerifierExt - ok
21:03:07.0312 3904 [ 500BE6B2E49883720D0AE8BB859ED7A3 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
21:03:07.0312 3904 vhdmp - ok
21:03:07.0343 3904 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
21:03:07.0343 3904 viaide - ok
21:03:07.0359 3904 [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid C:\Windows\System32\drivers\Vid.sys
21:03:07.0374 3904 Vid - ok
21:03:07.0374 3904 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
21:03:07.0390 3904 vmbus - ok
21:03:07.0390 3904 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
21:03:07.0390 3904 VMBusHID - ok
21:03:07.0405 3904 [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr C:\Windows\System32\drivers\vmbusr.sys
21:03:07.0405 3904 vmbusr - ok
21:03:07.0452 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
21:03:07.0468 3904 vmicheartbeat - ok
21:03:07.0468 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
21:03:07.0468 3904 vmickvpexchange - ok
21:03:07.0483 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
21:03:07.0483 3904 vmicrdv - ok
21:03:07.0499 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
21:03:07.0499 3904 vmicshutdown - ok
21:03:07.0499 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
21:03:07.0499 3904 vmictimesync - ok
21:03:07.0515 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
21:03:07.0515 3904 vmicvss - ok
21:03:07.0546 3904 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:03:07.0546 3904 volmgr - ok
21:03:07.0546 3904 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:03:07.0561 3904 volmgrx - ok
21:03:07.0593 3904 [ 78A5BBA3819FFFC62FFEC3E2220D102D ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:03:07.0593 3904 volsnap - ok
21:03:07.0624 3904 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
21:03:07.0624 3904 vpci - ok
21:03:07.0639 3904 [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp C:\Windows\System32\drivers\vpcivsp.sys
21:03:07.0639 3904 vpcivsp - ok
21:03:07.0749 3904 [ 86C96C079293E2E06708E146A011F4C4 ] vpnagent C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
21:03:07.0749 3904 vpnagent - ok
21:03:07.0780 3904 [ 5932B2999AEF21C4599A792599F28D89 ] vpnva C:\Windows\system32\DRIVERS\vpnva64-6.sys
21:03:07.0780 3904 vpnva - ok
21:03:07.0811 3904 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
21:03:07.0811 3904 vsmraid - ok
21:03:07.0889 3904 [ D0C69E44BC1E1D4AD290FD84104623D8 ] VSS C:\Windows\system32\vssvc.exe
21:03:07.0936 3904 VSS - ok
21:03:07.0951 3904 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
21:03:07.0951 3904 VSTXRAID - ok
21:03:07.0983 3904 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
21:03:07.0983 3904 vwifibus - ok
21:03:07.0983 3904 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
21:03:07.0998 3904 vwififlt - ok
21:03:07.0998 3904 [ 73FA1A41A97A5C34ADC03B3577FF1A86 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
21:03:07.0998 3904 vwifimp - ok
21:03:08.0045 3904 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
21:03:08.0076 3904 W32Time - ok
21:03:08.0107 3904 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
21:03:08.0107 3904 WacomPen - ok
21:03:08.0154 3904 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
21:03:08.0154 3904 Wanarp - ok
21:03:08.0154 3904 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:03:08.0170 3904 Wanarpv6 - ok
21:03:08.0232 3904 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
21:03:08.0263 3904 wbengine - ok
21:03:08.0279 3904 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:03:08.0295 3904 WbioSrvc - ok
21:03:08.0342 3904 [ AF1349386D4C6786EF4E34FACEF15042 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
21:03:08.0358 3904 Wcmsvc - ok
21:03:08.0420 3904 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:03:08.0452 3904 wcncsvc - ok
21:03:08.0467 3904 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:03:08.0483 3904 WcsPlugInService - ok
21:03:08.0561 3904 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
21:03:08.0561 3904 Wd - ok
21:03:08.0592 3904 [ FD47DF026B32969B8A68721A0243E8EE ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
21:03:08.0592 3904 WdBoot - ok
21:03:08.0670 3904 [ E2C933EDBC389386EBE6D2BA953F43D8 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:03:08.0686 3904 Wdf01000 - ok
21:03:08.0717 3904 [ 5F425D842DD6ADE9F95A51A0616AFAD7 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
21:03:08.0717 3904 WdFilter - ok
21:03:08.0748 3904 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:03:08.0748 3904 WdiServiceHost - ok
21:03:08.0748 3904 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:03:08.0764 3904 WdiSystemHost - ok
21:03:08.0779 3904 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
21:03:08.0779 3904 WebClient - ok
21:03:08.0795 3904 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:03:08.0795 3904 Wecsvc - ok
21:03:08.0810 3904 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:03:08.0810 3904 wercplsupport - ok
21:03:08.0862 3904 [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc C:\Windows\System32\WerSvc.dll
21:03:08.0877 3904 WerSvc - ok
21:03:08.0940 3904 [ 44BB9C31E6242C4BD1CE7C2B440C2533 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
21:03:08.0940 3904 WFPLWFS - ok
21:03:08.0986 3904 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
21:03:09.0002 3904 WiaRpc - ok
21:03:09.0049 3904 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:03:09.0049 3904 WIMMount - ok
21:03:09.0080 3904 WinDefend - ok
21:03:09.0143 3904 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
21:03:09.0158 3904 WinHttpAutoProxySvc - ok
21:03:09.0205 3904 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:03:09.0205 3904 Winmgmt - ok
21:03:09.0283 3904 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
21:03:09.0345 3904 WinRM - ok
21:03:09.0377 3904 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
21:03:09.0377 3904 WinUsb - ok
21:03:09.0454 3904 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
21:03:09.0501 3904 WlanSvc - ok
21:03:09.0564 3904 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
21:03:09.0626 3904 wlidsvc - ok
21:03:09.0657 3904 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
21:03:09.0657 3904 WmiAcpi - ok
21:03:09.0673 3904 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:03:09.0673 3904 wmiApSrv - ok
21:03:09.0704 3904 WMPNetworkSvc - ok
21:03:09.0720 3904 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
21:03:09.0735 3904 wpcfltr - ok
21:03:09.0767 3904 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:03:09.0767 3904 WPCSvc - ok
21:03:09.0829 3904 [ 3013658A4D327854BEEC4A08D9655194 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:03:09.0829 3904 WPDBusEnum - ok
21:03:09.0860 3904 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
21:03:09.0860 3904 WpdUpFltr - ok
21:03:09.0907 3904 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:03:09.0907 3904 ws2ifsl - ok
21:03:09.0969 3904 [ 012CFE7F0F95266F554EE3B91EE2128A ] wscsvc C:\Windows\System32\wscsvc.dll
21:03:09.0969 3904 wscsvc - ok
21:03:09.0985 3904 WSearch - ok
21:03:10.0078 3904 [ D4D04839F3DFAF09D94BAB1016F7A297 ] WSService C:\Windows\System32\WSService.dll
21:03:10.0172 3904 WSService - ok
21:03:10.0297 3904 [ 5EE919B9C3056B399E488A9B253E258A ] wuauserv C:\Windows\system32\wuaueng.dll
21:03:10.0390 3904 wuauserv - ok
21:03:10.0390 3904 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:03:10.0406 3904 WudfPf - ok
21:03:10.0433 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
21:03:10.0433 3904 WUDFRd - ok
21:03:10.0433 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0433 3904 WUDFSensorLP - ok
21:03:10.0464 3904 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:03:10.0479 3904 wudfsvc - ok
21:03:10.0495 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0495 3904 WUDFWpdFs - ok
21:03:10.0511 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0511 3904 WUDFWpdMtp - ok
21:03:10.0557 3904 [ 6D9E07436B6646EC8F7EFFD39B6BA288 ] WwanSvc C:\Windows\System32\wwansvc.dll
21:03:10.0557 3904 WwanSvc - ok
21:03:10.0604 3904 [ D107AA09E4E233E1AAE126255D8A4057 ] xusb22 C:\Windows\System32\drivers\xusb22.sys
21:03:10.0604 3904 xusb22 - ok
21:03:10.0635 3904 ================ Scan global ===============================
21:03:10.0667 3904 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
21:03:10.0698 3904 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
21:03:10.0729 3904 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
21:03:10.0776 3904 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
21:03:10.0791 3904 [Global] - ok
21:03:10.0791 3904 ================ Scan MBR ==================================
21:03:10.0791 3904 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:03:11.0170 3904 \Device\Harddisk0\DR0 - ok
21:03:11.0170 3904 ================ Scan VBR ==================================
21:03:11.0186 3904 [ 32F2D1CE9974995766A0FE26745614C3 ] \Device\Harddisk0\DR0\Partition1
21:03:11.0186 3904 \Device\Harddisk0\DR0\Partition1 - ok
21:03:11.0186 3904 ============================================================
21:03:11.0186 3904 Scan finished
21:03:11.0186 3904 ============================================================
21:03:11.0186 3596 Detected object count: 0
21:03:11.0186 3596 Actual detected object count: 0
21:03:14.0271 5124 Deinitialize success
21:02:56.0945 3904 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
21:02:56.0945 3904 MegaSR - ok
21:02:57.0024 3904 Microsoft SharePoint Workspace Audit Service - ok
21:02:57.0056 3904 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
21:02:57.0056 3904 MMCSS - ok
21:02:57.0087 3904 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
21:02:57.0087 3904 Modem - ok
21:02:57.0134 3904 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
21:02:57.0134 3904 monitor - ok
21:02:57.0149 3904 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
21:02:57.0149 3904 mouclass - ok
21:02:57.0196 3904 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
21:02:57.0196 3904 mouhid - ok
21:02:57.0212 3904 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:02:57.0212 3904 mountmgr - ok
21:02:57.0274 3904 [ 5E0686615A80A6279B2314E13CD23F6E ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:02:57.0274 3904 MozillaMaintenance - ok
21:02:57.0321 3904 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:02:57.0321 3904 mpsdrv - ok
21:02:57.0394 3904 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:02:57.0425 3904 MpsSvc - ok
21:02:57.0441 3904 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:02:57.0457 3904 MRxDAV - ok
21:02:57.0504 3904 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:02:57.0519 3904 mrxsmb - ok
21:02:57.0550 3904 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:02:57.0550 3904 mrxsmb10 - ok
21:02:57.0582 3904 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:02:57.0597 3904 mrxsmb20 - ok
21:02:57.0613 3904 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
21:02:57.0613 3904 MsBridge - ok
21:02:57.0675 3904 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
21:02:57.0675 3904 MSDTC - ok
21:02:57.0722 3904 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:02:57.0722 3904 Msfs - ok
21:02:57.0753 3904 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
21:02:57.0753 3904 msgpiowin32 - ok
21:02:57.0784 3904 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:02:57.0784 3904 mshidkmdf - ok
21:02:57.0800 3904 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
21:02:57.0800 3904 mshidumdf - ok
21:02:57.0800 3904 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:02:57.0800 3904 msisadrv - ok
21:02:57.0857 3904 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:02:57.0857 3904 MSiSCSI - ok
21:02:57.0857 3904 msiserver - ok
21:02:57.0889 3904 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:02:57.0889 3904 MSKSSRV - ok
21:02:57.0908 3904 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
21:02:57.0908 3904 MsLldp - ok
21:02:57.0925 3904 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:02:57.0925 3904 MSPCLOCK - ok
21:02:57.0925 3904 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:02:57.0925 3904 MSPQM - ok
21:02:57.0957 3904 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:02:57.0972 3904 MsRPC - ok
21:02:57.0988 3904 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
21:02:57.0988 3904 mssmbios - ok
21:02:58.0003 3904 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:02:58.0003 3904 MSTEE - ok
21:02:58.0026 3904 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
21:02:58.0026 3904 MTConfig - ok
21:02:58.0041 3904 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
21:02:58.0057 3904 Mup - ok
21:02:58.0072 3904 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
21:02:58.0072 3904 mvumis - ok
21:02:58.0119 3904 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
21:02:58.0135 3904 napagent - ok
21:02:58.0166 3904 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:02:58.0182 3904 NativeWifiP - ok
21:02:58.0213 3904 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
21:02:58.0228 3904 NcaSvc - ok
21:02:58.0244 3904 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
21:02:58.0244 3904 NcdAutoSetup - ok
21:02:58.0306 3904 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:02:58.0322 3904 NDIS - ok
21:02:58.0353 3904 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:02:58.0369 3904 NdisCap - ok
21:02:58.0400 3904 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
21:02:58.0400 3904 NdisImPlatform - ok
21:02:58.0447 3904 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:02:58.0462 3904 NdisTapi - ok
21:02:58.0478 3904 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:02:58.0478 3904 Ndisuio - ok
21:02:58.0509 3904 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:02:58.0509 3904 NdisWan - ok
21:02:58.0509 3904 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
21:02:58.0509 3904 NDISWANLEGACY - ok
21:02:58.0572 3904 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:02:58.0572 3904 NDProxy - ok
21:02:58.0587 3904 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
21:02:58.0587 3904 Ndu - ok
21:02:58.0603 3904 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:02:58.0603 3904 NetBIOS - ok
21:02:58.0681 3904 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:02:58.0681 3904 NetBT - ok
21:02:58.0712 3904 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
21:02:58.0712 3904 Netlogon - ok
21:02:58.0743 3904 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
21:02:58.0759 3904 Netman - ok
21:02:58.0806 3904 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
21:02:58.0821 3904 netprofm - ok
21:02:58.0884 3904 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:02:58.0915 3904 NetTcpPortSharing - ok
21:02:59.0133 3904 [ 57B9C04D673F236D41FAB03842C8640B ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
21:02:59.0180 3904 NETwNs64 - ok
21:02:59.0211 3904 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
21:02:59.0211 3904 nfrd960 - ok
21:02:59.0274 3904 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:02:59.0274 3904 NlaSvc - ok
21:02:59.0305 3904 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:02:59.0305 3904 Npfs - ok
21:02:59.0336 3904 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
21:02:59.0336 3904 npsvctrig - ok
21:02:59.0352 3904 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
21:02:59.0352 3904 nsi - ok
21:02:59.0383 3904 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:02:59.0383 3904 nsiproxy - ok
21:02:59.0479 3904 [ 76929F4A69E425911A63B407E26C2589 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:02:59.0479 3904 Ntfs - ok
21:02:59.0494 3904 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
21:02:59.0494 3904 Null - ok
21:02:59.0526 3904 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:02:59.0526 3904 nvraid - ok
21:02:59.0541 3904 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:02:59.0541 3904 nvstor - ok
21:02:59.0572 3904 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:02:59.0572 3904 nv_agp - ok
21:02:59.0635 3904 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:02:59.0635 3904 ose64 - ok
21:02:59.0806 3904 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:02:59.0838 3904 osppsvc - ok
21:02:59.0884 3904 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:02:59.0900 3904 p2pimsvc - ok
21:02:59.0931 3904 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
21:02:59.0962 3904 p2psvc - ok
21:02:59.0994 3904 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
21:02:59.0994 3904 Parport - ok
21:03:00.0040 3904 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:03:00.0040 3904 partmgr - ok
21:03:00.0103 3904 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:03:00.0118 3904 PcaSvc - ok
21:03:00.0150 3904 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
21:03:00.0150 3904 pci - ok
21:03:00.0181 3904 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
21:03:00.0181 3904 pciide - ok
21:03:00.0196 3904 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
21:03:00.0196 3904 pcmcia - ok
21:03:00.0228 3904 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
21:03:00.0228 3904 pcw - ok
21:03:00.0274 3904 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
21:03:00.0274 3904 pdc - ok
21:03:00.0384 3904 [ 20372BE109FEE1C37E2D5216680DB9EB ] PDF Architect Helper Service C:\Program Files (x86)\PDF Architect\HelperService.exe
21:03:00.0384 3904 PDF Architect Helper Service - ok
21:03:00.0430 3904 [ B90A279073A815A4AA2C45A09EE004FA ] PDF Architect Service C:\Program Files (x86)\PDF Architect\ConversionService.exe
21:03:00.0446 3904 PDF Architect Service - ok
21:03:00.0493 3904 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:03:00.0508 3904 PEAUTH - ok
21:03:00.0571 3904 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:03:00.0680 3904 PeerDistSvc - ok
21:03:00.0774 3904 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
21:03:00.0774 3904 PerfHost - ok
21:03:00.0852 3904 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
21:03:00.0884 3904 pla - ok
21:03:00.0930 3904 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:03:00.0946 3904 PlugPlay - ok
21:03:00.0962 3904 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:03:00.0977 3904 PNRPAutoReg - ok
21:03:01.0008 3904 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:03:01.0008 3904 PNRPsvc - ok
21:03:01.0055 3904 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:03:01.0071 3904 PolicyAgent - ok
21:03:01.0118 3904 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
21:03:01.0118 3904 Power - ok
21:03:01.0149 3904 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:03:01.0149 3904 PptpMiniport - ok
21:03:01.0274 3904 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
21:03:01.0358 3904 PrintNotify - ok
21:03:01.0405 3904 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
21:03:01.0405 3904 Processor - ok
21:03:01.0436 3904 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
21:03:01.0452 3904 ProfSvc - ok
21:03:01.0483 3904 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:03:01.0498 3904 Psched - ok
21:03:01.0514 3904 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
21:03:01.0530 3904 QWAVE - ok
21:03:01.0545 3904 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:03:01.0545 3904 QWAVEdrv - ok
21:03:01.0561 3904 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:03:01.0576 3904 RasAcd - ok
21:03:01.0592 3904 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:03:01.0592 3904 RasAgileVpn - ok
21:03:01.0608 3904 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
21:03:01.0623 3904 RasAuto - ok
21:03:01.0639 3904 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:03:01.0639 3904 Rasl2tp - ok
21:03:01.0655 3904 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
21:03:01.0670 3904 RasMan - ok
21:03:01.0686 3904 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:03:01.0686 3904 RasPppoe - ok
21:03:01.0701 3904 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:03:01.0701 3904 RasSstp - ok
21:03:01.0748 3904 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:03:01.0764 3904 rdbss - ok
21:03:01.0779 3904 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
21:03:01.0795 3904 rdpbus - ok
21:03:01.0810 3904 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:03:01.0826 3904 RDPDR - ok
21:03:01.0873 3904 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:03:01.0888 3904 RdpVideoMiniport - ok
21:03:01.0920 3904 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:03:01.0920 3904 RDPWD - ok
21:03:01.0951 3904 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:03:01.0951 3904 rdyboost - ok
21:03:01.0982 3904 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
21:03:01.0982 3904 RemoteAccess - ok
21:03:02.0029 3904 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:03:02.0045 3904 RemoteRegistry - ok
21:03:02.0091 3904 [ CCBFCABDFE2BC22F0645CEAADDB36004 ] RFCOMM C:\Windows\System32\drivers\rfcomm.sys
21:03:02.0091 3904 RFCOMM - ok
21:03:02.0138 3904 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:03:02.0138 3904 RpcEptMapper - ok
21:03:02.0169 3904 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
21:03:02.0169 3904 RpcLocator - ok
21:03:02.0232 3904 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
21:03:02.0247 3904 RpcSs - ok
21:03:02.0263 3904 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:03:02.0263 3904 rspndr - ok
21:03:02.0294 3904 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
21:03:02.0294 3904 RTL8168 - ok
21:03:02.0325 3904 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
21:03:02.0325 3904 s3cap - ok
21:03:02.0357 3904 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
21:03:02.0372 3904 SamSs - ok
21:03:02.0403 3904 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:03:02.0403 3904 sbp2port - ok
21:03:02.0450 3904 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:03:02.0450 3904 SCardSvr - ok
21:03:02.0481 3904 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:03:02.0481 3904 scfilter - ok
21:03:02.0544 3904 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
21:03:02.0575 3904 Schedule - ok
21:03:02.0606 3904 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
21:03:02.0622 3904 SCPolicySvc - ok
21:03:02.0669 3904 [ F58B030A0664385C707B8C1C63682041 ] sdbus C:\Windows\System32\drivers\sdbus.sys
21:03:02.0669 3904 sdbus - ok
21:03:02.0700 3904 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:03:02.0700 3904 SDRSVC - ok
21:03:02.0746 3904 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
21:03:02.0746 3904 sdstor - ok
21:03:02.0762 3904 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:03:02.0762 3904 secdrv - ok
21:03:02.0778 3904 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
21:03:02.0778 3904 seclogon - ok
21:03:02.0809 3904 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
21:03:02.0809 3904 SENS - ok
21:03:02.0843 3904 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:03:02.0849 3904 SensrSvc - ok
21:03:02.0865 3904 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
21:03:02.0881 3904 SerCx - ok
21:03:02.0896 3904 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
21:03:02.0896 3904 Serenum - ok
21:03:02.0912 3904 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
21:03:02.0912 3904 Serial - ok
21:03:02.0959 3904 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
21:03:02.0959 3904 sermouse - ok
21:03:02.0990 3904 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
21:03:02.0990 3904 SessionEnv - ok
21:03:02.0990 3904 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
21:03:02.0990 3904 sfloppy - ok
21:03:03.0068 3904 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:03:03.0083 3904 SharedAccess - ok
21:03:03.0146 3904 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:03:03.0146 3904 ShellHWDetection - ok
21:03:03.0177 3904 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
21:03:03.0177 3904 SiSRaid2 - ok
21:03:03.0193 3904 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
21:03:03.0193 3904 SiSRaid4 - ok
21:03:03.0224 3904 [ F2B755D3835089590E8113F48AA931F7 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
21:03:03.0239 3904 SkypeUpdate - ok
21:03:03.0271 3904 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:03:03.0271 3904 SNMPTRAP - ok
21:03:03.0317 3904 [ FD3AF5575B99871BADB94E7699DBCE08 ] spaceport C:\Windows\system32\drivers\spaceport.sys
21:03:03.0317 3904 spaceport - ok
21:03:03.0333 3904 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
21:03:03.0333 3904 SpbCx - ok
21:03:03.0364 3904 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
21:03:03.0364 3904 Spooler - ok
21:03:03.0536 3904 [ 061A977C920FBE4BF71FF47C966DDDCA ] sppsvc C:\Windows\system32\sppsvc.exe
21:03:03.0567 3904 sppsvc - ok
21:03:03.0598 3904 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:03:03.0598 3904 srv - ok
21:03:03.0645 3904 [ 56218A571ECF8D55E0CDFF8DF2546CF1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:03:03.0645 3904 srv2 - ok
21:03:03.0661 3904 [ 14FC338B80CFF7E04215133B568D15C4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:03:03.0661 3904 srvnet - ok
21:03:03.0801 3904 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:03:03.0817 3904 SSDPSRV - ok
21:03:03.0832 3904 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:03:03.0832 3904 SstpSvc - ok
21:03:03.0879 3904 [ AAF6F247F1DC370C593B4430974EAD9C ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
21:03:03.0879 3904 ssudmdm - ok
21:03:04.0019 3904 [ 7595D53EE8E8B0BAA9A2DDDE867EBB0C ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe
21:03:04.0019 3904 STacSV - ok
21:03:04.0066 3904 [ 2FAD3D9EBDF3A9DDFDFAE8A06B4ED4C9 ] Start8 C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
21:03:04.0066 3904 Start8 - ok
21:03:04.0097 3904 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
21:03:04.0097 3904 stexstor - ok
21:03:04.0144 3904 [ DFFBC024DFC7BB05B2129E05CBC7A201 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
21:03:04.0144 3904 STHDA - ok
21:03:04.0207 3904 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
21:03:04.0238 3904 stisvc - ok
21:03:04.0316 3904 [ B240874B2CA0CD02E8CD11E140B14C57 ] storahci C:\Windows\system32\drivers\storahci.sys
21:03:04.0316 3904 storahci - ok
21:03:04.0363 3904 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
21:03:04.0363 3904 storflt - ok
21:03:04.0394 3904 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
21:03:04.0409 3904 StorSvc - ok
21:03:04.0409 3904 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
21:03:04.0425 3904 storvsc - ok
21:03:04.0456 3904 [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp C:\Windows\System32\drivers\storvsp.sys
21:03:04.0456 3904 storvsp - ok
21:03:04.0472 3904 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
21:03:04.0472 3904 svsvc - ok
21:03:04.0487 3904 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
21:03:04.0487 3904 swenum - ok
21:03:04.0628 3904 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
21:03:04.0628 3904 SwitchBoard - ok
21:03:04.0675 3904 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
21:03:04.0706 3904 swprv - ok
21:03:04.0753 3904 [ AC3CC98B1BDB6540021D3FFB105AC2B9 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
21:03:04.0753 3904 SynTP - ok
21:03:04.0831 3904 [ A06CB9269D29EE3D0F3F5630ABB660B8 ] SysMain C:\Windows\system32\sysmain.dll
21:03:04.0893 3904 SysMain - ok
21:03:04.0940 3904 [ 6FB88606C4A71E1BFAF97D63A676C673 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
21:03:04.0955 3904 SystemEventsBroker - ok
21:03:04.0987 3904 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
21:03:04.0987 3904 TabletInputService - ok
21:03:05.0018 3904 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
21:03:05.0033 3904 TapiSrv - ok
21:03:05.0158 3904 [ 37D85E873C9531A2F88DD9C63D3F8A9E ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:03:05.0174 3904 Tcpip - ok
21:03:05.0236 3904 [ 37D85E873C9531A2F88DD9C63D3F8A9E ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:03:05.0252 3904 TCPIP6 - ok
21:03:05.0283 3904 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:03:05.0283 3904 tcpipreg - ok
21:03:05.0299 3904 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:03:05.0299 3904 tdx - ok
21:03:05.0314 3904 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
21:03:05.0314 3904 terminpt - ok
21:03:05.0377 3904 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
21:03:05.0423 3904 TermService - ok
21:03:05.0439 3904 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
21:03:05.0439 3904 Themes - ok
21:03:05.0501 3904 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
21:03:05.0501 3904 THREADORDER - ok
21:03:05.0564 3904 [ 4515B9E4140F04FB3907692DF89FCA87 ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
21:03:05.0564 3904 TimeBroker - ok
21:03:05.0626 3904 [ E94F7A7B48C7638D1F3F8089344C97B7 ] TPM C:\Windows\system32\drivers\tpm.sys
21:03:05.0626 3904 TPM - ok
21:03:05.0657 3904 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
21:03:05.0673 3904 TrkWks - ok
21:03:05.0798 3904 [ 8ABBB5CE0C62E0A6D28F32F44B7F865C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:03:05.0813 3904 TrustedInstaller - ok
21:03:05.0845 3904 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
21:03:05.0845 3904 TsUsbFlt - ok
21:03:05.0860 3904 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
21:03:05.0860 3904 TsUsbGD - ok
21:03:05.0891 3904 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:03:05.0891 3904 tunnel - ok
21:03:05.0907 3904 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
21:03:05.0907 3904 uagp35 - ok
21:03:05.0923 3904 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
21:03:05.0923 3904 UASPStor - ok
21:03:05.0970 3904 [ 061BA3EE0D2BE17944990544008CF190 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
21:03:05.0970 3904 UCX01000 - ok
21:03:06.0017 3904 [ 25C50F4EDF70D0A831E0566BD181CCF2 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:03:06.0017 3904 udfs - ok
21:03:06.0063 3904 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:03:06.0063 3904 UI0Detect - ok
21:03:06.0110 3904 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:03:06.0110 3904 uliagpkx - ok
21:03:06.0141 3904 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
21:03:06.0141 3904 umbus - ok
21:03:06.0157 3904 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
21:03:06.0173 3904 UmPass - ok
21:03:06.0219 3904 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
21:03:06.0219 3904 UmRdpService - ok
21:03:06.0344 3904 [ FFF49A8E94E2F108F10CA72383FBF16F ] Update SquirrelWeb C:\Program Files (x86)\SquirrelWeb\updateSquirrelWeb.exe
21:03:06.0344 3904 Update SquirrelWeb - ok
21:03:06.0407 3904 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
21:03:06.0438 3904 upnphost - ok
21:03:06.0485 3904 [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64 C:\Windows\System32\Drivers\usbaapl64.sys
21:03:06.0485 3904 USBAAPL64 - ok
21:03:06.0531 3904 [ C976C4306F9AE133D6BBD47FDFC3BF92 ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
21:03:06.0547 3904 usbccgp - ok
21:03:06.0594 3904 [ 427B6DB8C05A5A977E8C3525370A2595 ] usbcir C:\Windows\System32\drivers\usbcir.sys
21:03:06.0594 3904 usbcir - ok
21:03:06.0656 3904 [ B24FDEB1B18496F1B463782235AA3AF1 ] usbehci C:\Windows\System32\drivers\usbehci.sys
21:03:06.0672 3904 usbehci - ok
21:03:06.0734 3904 [ F8C2A832DF9403F5EA8080CBDBDA95FB ] usbhub C:\Windows\System32\drivers\usbhub.sys
21:03:06.0734 3904 usbhub - ok
21:03:06.0781 3904 [ B1E910DDC08A8536116214326124903C ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
21:03:06.0797 3904 USBHUB3 - ok
21:03:06.0843 3904 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
21:03:06.0843 3904 usbohci - ok
21:03:06.0890 3904 [ 9FDBA6982582A6F2354144980F641E7B ] usbprint C:\Windows\System32\drivers\usbprint.sys
21:03:06.0890 3904 usbprint - ok
21:03:06.0921 3904 [ AD91D1BBE5D3CF4501887DC1C09384FD ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:03:06.0921 3904 usbscan - ok
21:03:06.0968 3904 [ BFC7FE4AAEB61317A921871B4085EF4B ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
21:03:06.0968 3904 USBSTOR - ok
21:03:07.0015 3904 [ 1ABF657259DB57F7E5558E4DF1357C0C ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
21:03:07.0015 3904 usbuhci - ok
21:03:07.0062 3904 [ 9EF7C01D3ACCBC243B5CB1A95865B2FF ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
21:03:07.0062 3904 usbvideo - ok
21:03:07.0124 3904 [ 8DC398D7B8E02C929A2096E74A170970 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
21:03:07.0124 3904 USBXHCI - ok
21:03:07.0155 3904 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
21:03:07.0155 3904 VaultSvc - ok
21:03:07.0179 3904 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
21:03:07.0179 3904 vdrvroot - ok
21:03:07.0218 3904 [ 1B4488988E5E7512E6C5CD1255E9E973 ] vds C:\Windows\System32\vds.exe
21:03:07.0250 3904 vds - ok
21:03:07.0281 3904 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
21:03:07.0281 3904 VerifierExt - ok
21:03:07.0312 3904 [ 500BE6B2E49883720D0AE8BB859ED7A3 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
21:03:07.0312 3904 vhdmp - ok
21:03:07.0343 3904 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
21:03:07.0343 3904 viaide - ok
21:03:07.0359 3904 [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid C:\Windows\System32\drivers\Vid.sys
21:03:07.0374 3904 Vid - ok
21:03:07.0374 3904 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
21:03:07.0390 3904 vmbus - ok
21:03:07.0390 3904 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
21:03:07.0390 3904 VMBusHID - ok
21:03:07.0405 3904 [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr C:\Windows\System32\drivers\vmbusr.sys
21:03:07.0405 3904 vmbusr - ok
21:03:07.0452 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
21:03:07.0468 3904 vmicheartbeat - ok
21:03:07.0468 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
21:03:07.0468 3904 vmickvpexchange - ok
21:03:07.0483 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
21:03:07.0483 3904 vmicrdv - ok
21:03:07.0499 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
21:03:07.0499 3904 vmicshutdown - ok
21:03:07.0499 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
21:03:07.0499 3904 vmictimesync - ok
21:03:07.0515 3904 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
21:03:07.0515 3904 vmicvss - ok
21:03:07.0546 3904 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:03:07.0546 3904 volmgr - ok
21:03:07.0546 3904 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:03:07.0561 3904 volmgrx - ok
21:03:07.0593 3904 [ 78A5BBA3819FFFC62FFEC3E2220D102D ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:03:07.0593 3904 volsnap - ok
21:03:07.0624 3904 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
21:03:07.0624 3904 vpci - ok
21:03:07.0639 3904 [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp C:\Windows\System32\drivers\vpcivsp.sys
21:03:07.0639 3904 vpcivsp - ok
21:03:07.0749 3904 [ 86C96C079293E2E06708E146A011F4C4 ] vpnagent C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
21:03:07.0749 3904 vpnagent - ok
21:03:07.0780 3904 [ 5932B2999AEF21C4599A792599F28D89 ] vpnva C:\Windows\system32\DRIVERS\vpnva64-6.sys
21:03:07.0780 3904 vpnva - ok
21:03:07.0811 3904 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
21:03:07.0811 3904 vsmraid - ok
21:03:07.0889 3904 [ D0C69E44BC1E1D4AD290FD84104623D8 ] VSS C:\Windows\system32\vssvc.exe
21:03:07.0936 3904 VSS - ok
21:03:07.0951 3904 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
21:03:07.0951 3904 VSTXRAID - ok
21:03:07.0983 3904 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
21:03:07.0983 3904 vwifibus - ok
21:03:07.0983 3904 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
21:03:07.0998 3904 vwififlt - ok
21:03:07.0998 3904 [ 73FA1A41A97A5C34ADC03B3577FF1A86 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
21:03:07.0998 3904 vwifimp - ok
21:03:08.0045 3904 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
21:03:08.0076 3904 W32Time - ok
21:03:08.0107 3904 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
21:03:08.0107 3904 WacomPen - ok
21:03:08.0154 3904 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
21:03:08.0154 3904 Wanarp - ok
21:03:08.0154 3904 [ 61F6972FF9AC9A8D0B4D62076DC30051 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:03:08.0170 3904 Wanarpv6 - ok
21:03:08.0232 3904 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
21:03:08.0263 3904 wbengine - ok
21:03:08.0279 3904 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:03:08.0295 3904 WbioSrvc - ok
21:03:08.0342 3904 [ AF1349386D4C6786EF4E34FACEF15042 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
21:03:08.0358 3904 Wcmsvc - ok
21:03:08.0420 3904 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:03:08.0452 3904 wcncsvc - ok
21:03:08.0467 3904 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:03:08.0483 3904 WcsPlugInService - ok
21:03:08.0561 3904 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
21:03:08.0561 3904 Wd - ok
21:03:08.0592 3904 [ FD47DF026B32969B8A68721A0243E8EE ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
21:03:08.0592 3904 WdBoot - ok
21:03:08.0670 3904 [ E2C933EDBC389386EBE6D2BA953F43D8 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:03:08.0686 3904 Wdf01000 - ok
21:03:08.0717 3904 [ 5F425D842DD6ADE9F95A51A0616AFAD7 ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
21:03:08.0717 3904 WdFilter - ok
21:03:08.0748 3904 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:03:08.0748 3904 WdiServiceHost - ok
21:03:08.0748 3904 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:03:08.0764 3904 WdiSystemHost - ok
21:03:08.0779 3904 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
21:03:08.0779 3904 WebClient - ok
21:03:08.0795 3904 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:03:08.0795 3904 Wecsvc - ok
21:03:08.0810 3904 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:03:08.0810 3904 wercplsupport - ok
21:03:08.0862 3904 [ 5F70EBFC1F75B487DE79501E3CCBDB54 ] WerSvc C:\Windows\System32\WerSvc.dll
21:03:08.0877 3904 WerSvc - ok
21:03:08.0940 3904 [ 44BB9C31E6242C4BD1CE7C2B440C2533 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
21:03:08.0940 3904 WFPLWFS - ok
21:03:08.0986 3904 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
21:03:09.0002 3904 WiaRpc - ok
21:03:09.0049 3904 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:03:09.0049 3904 WIMMount - ok
21:03:09.0080 3904 WinDefend - ok
21:03:09.0143 3904 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
21:03:09.0158 3904 WinHttpAutoProxySvc - ok
21:03:09.0205 3904 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:03:09.0205 3904 Winmgmt - ok
21:03:09.0283 3904 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
21:03:09.0345 3904 WinRM - ok
21:03:09.0377 3904 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
21:03:09.0377 3904 WinUsb - ok
21:03:09.0454 3904 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
21:03:09.0501 3904 WlanSvc - ok
21:03:09.0564 3904 [ B330CE47FB74A6BE9A3FFFF4B3F64D9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
21:03:09.0626 3904 wlidsvc - ok
21:03:09.0657 3904 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
21:03:09.0657 3904 WmiAcpi - ok
21:03:09.0673 3904 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:03:09.0673 3904 wmiApSrv - ok
21:03:09.0704 3904 WMPNetworkSvc - ok
21:03:09.0720 3904 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
21:03:09.0735 3904 wpcfltr - ok
21:03:09.0767 3904 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:03:09.0767 3904 WPCSvc - ok
21:03:09.0829 3904 [ 3013658A4D327854BEEC4A08D9655194 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:03:09.0829 3904 WPDBusEnum - ok
21:03:09.0860 3904 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
21:03:09.0860 3904 WpdUpFltr - ok
21:03:09.0907 3904 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:03:09.0907 3904 ws2ifsl - ok
21:03:09.0969 3904 [ 012CFE7F0F95266F554EE3B91EE2128A ] wscsvc C:\Windows\System32\wscsvc.dll
21:03:09.0969 3904 wscsvc - ok
21:03:09.0985 3904 WSearch - ok
21:03:10.0078 3904 [ D4D04839F3DFAF09D94BAB1016F7A297 ] WSService C:\Windows\System32\WSService.dll
21:03:10.0172 3904 WSService - ok
21:03:10.0297 3904 [ 5EE919B9C3056B399E488A9B253E258A ] wuauserv C:\Windows\system32\wuaueng.dll
21:03:10.0390 3904 wuauserv - ok
21:03:10.0390 3904 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:03:10.0406 3904 WudfPf - ok
21:03:10.0433 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
21:03:10.0433 3904 WUDFRd - ok
21:03:10.0433 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0433 3904 WUDFSensorLP - ok
21:03:10.0464 3904 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:03:10.0479 3904 wudfsvc - ok
21:03:10.0495 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0495 3904 WUDFWpdFs - ok
21:03:10.0511 3904 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
21:03:10.0511 3904 WUDFWpdMtp - ok
21:03:10.0557 3904 [ 6D9E07436B6646EC8F7EFFD39B6BA288 ] WwanSvc C:\Windows\System32\wwansvc.dll
21:03:10.0557 3904 WwanSvc - ok
21:03:10.0604 3904 [ D107AA09E4E233E1AAE126255D8A4057 ] xusb22 C:\Windows\System32\drivers\xusb22.sys
21:03:10.0604 3904 xusb22 - ok
21:03:10.0635 3904 ================ Scan global ===============================
21:03:10.0667 3904 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
21:03:10.0698 3904 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
21:03:10.0729 3904 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
21:03:10.0776 3904 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
21:03:10.0791 3904 [Global] - ok
21:03:10.0791 3904 ================ Scan MBR ==================================
21:03:10.0791 3904 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:03:11.0170 3904 \Device\Harddisk0\DR0 - ok
21:03:11.0170 3904 ================ Scan VBR ==================================
21:03:11.0186 3904 [ 32F2D1CE9974995766A0FE26745614C3 ] \Device\Harddisk0\DR0\Partition1
21:03:11.0186 3904 \Device\Harddisk0\DR0\Partition1 - ok
21:03:11.0186 3904 ============================================================
21:03:11.0186 3904 Scan finished
21:03:11.0186 3904 ============================================================
21:03:11.0186 3596 Detected object count: 0
21:03:11.0186 3596 Actual detected object count: 0
21:03:14.0271 5124 Deinitialize success
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Prosím o kontrolu logu
ComboFix 13-12-01.01 - Petr Jurecek . 12. 2013 22:50:13.1.2 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.4063.2755 [GMT 1:00]
Spuštěný z: c:\users\Petr JureŔek\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\WinZip\Icon_1.ico
c:\windows\SysWow64\FlashPlayerApp.exe
.
Nakažená kopie c:\windows\SysWow64\ntdll.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\WinSxS\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.2.9200.16579_none_bc050522ba460118\ntdll.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_vpnagent
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-03 do 2013-12-03 )))))))))))))))))))))))))))))))
.
.
2013-12-03 21:57 . 2013-12-03 21:57 -------- d-----w- c:\users\p\AppData\Local\temp
2013-12-03 21:57 . 2013-12-03 21:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-03 20:10 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{54512FDD-6BFF-4E7C-A188-72B1F18C3CCB}\mpengine.dll
2013-12-03 18:32 . 2012-01-20 13:14 18816 ----a-w- c:\windows\system32\roboot64.exe
2013-12-03 18:31 . 2013-12-03 20:17 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\systweak
2013-12-03 18:30 . 2013-12-03 18:30 -------- d-----w- c:\program files (x86)\PDF Helper
2013-12-02 19:39 . 2013-12-03 21:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\CrashDumps
2013-12-01 12:01 . 2013-12-01 12:01 -------- d-----w- c:\windows\ERUNT
2013-12-01 00:48 . 2013-12-01 00:48 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Malwarebytes
2013-12-01 00:47 . 2013-12-01 00:47 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 00:47 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 00:47 . 2013-12-01 00:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-01 00:40 . 2013-12-01 11:57 -------- d-----w- C:\AdwCleaner
2013-11-29 06:27 . 2013-10-17 10:14 965000 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B4D85BF-1BFE-4475-81D4-029312689D92}\gapaengine.dll
2013-11-28 10:47 . 2013-11-28 10:47 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
2013-11-27 15:23 . 2013-11-27 15:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\YCanPDF
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\IrfanView
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\program files (x86)\IrfanView
2013-11-27 11:57 . 2013-11-27 11:57 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Zoner
2013-11-27 11:49 . 2013-11-27 11:55 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PhotoScape
2013-11-27 10:47 . 2013-11-27 10:47 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-11-20 16:24 . 2013-11-20 16:24 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-11-13 19:22 . 2013-11-13 19:22 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PDF Architect
2013-11-13 19:18 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDF Architect
2013-11-13 19:17 . 2013-04-09 14:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2013-11-13 19:17 . 2013-01-09 14:52 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2013-11-13 19:17 . 2012-05-05 10:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2013-11-13 19:17 . 2012-05-05 10:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-11-13 19:17 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDFCreator
2013-11-13 19:17 . 2012-05-05 10:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Graphisoft
2013-11-13 18:41 . 2013-12-02 19:36 -------- d-----w- c:\users\Petr Jureček\Graphisoft
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Graphisoft
2013-11-13 18:38 . 2013-11-05 22:58 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-11-13 18:33 . 2013-11-13 18:33 -------- d-----w- c:\program files (x86)\QuickTime
2013-11-13 18:29 . 2013-11-13 18:29 -------- d-----w- c:\program files\GRAPHISOFT
2013-11-13 18:27 . 2013-11-13 18:27 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Install.GS
2013-11-13 07:16 . 2013-11-13 11:43 -------- d-----w- c:\programdata\WarThunder
2013-11-13 07:16 . 2013-11-13 07:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\WarThunder
2013-11-13 07:16 . 2013-11-14 15:45 -------- d-----w- c:\program files (x86)\WarThunder
2013-11-10 12:02 . 2013-11-10 12:03 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StartMenu
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iPod
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iTunes
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 10:21 . 2012-12-20 23:06 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-13 08:41 . 2012-12-20 23:08 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-10-10 21:48 . 2013-10-10 21:48 11152 ----a-w- c:\windows\SysWow64\vpncategories.dll
2013-10-10 21:48 . 2013-10-10 21:48 34192 ----a-w- c:\windows\SysWow64\vpnevents.dll
2013-10-10 21:31 . 2013-08-30 21:53 52080 ----a-w- c:\windows\system32\drivers\vpnva64-6.sys
2013-10-10 21:29 . 2013-10-25 07:07 112496 ----a-r- c:\windows\system32\drivers\acsock64.sys
2013-10-08 05:50 . 2013-10-25 07:06 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-14 01:15 . 2013-10-31 21:53 59416 ----a-w- c:\windows\system32\wuauclt.exe
2013-09-13 22:36 . 2013-10-31 21:53 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2013-09-13 22:36 . 2013-10-31 21:53 628736 ----a-w- c:\windows\SysWow64\wuapi.dll
2013-09-13 22:36 . 2013-10-31 21:53 84992 ----a-w- c:\windows\SysWow64\wudriver.dll
2013-09-13 22:36 . 2013-10-31 21:53 126976 ----a-w- c:\windows\SysWow64\wuwebv.dll
2013-09-13 22:36 . 2013-10-31 21:53 247296 ----a-w- c:\windows\SysWow64\ubpm.dll
2013-09-13 22:34 . 2013-10-31 21:53 40448 ----a-w- c:\windows\system32\wuapp.exe
2013-09-13 22:33 . 2013-10-31 21:53 252928 ----a-w- c:\windows\system32\WUSettingsProvider.dll
2013-09-13 22:33 . 2013-10-31 21:53 142848 ----a-w- c:\windows\system32\wuwebv.dll
2013-09-13 22:33 . 2013-10-31 21:53 3279360 ----a-w- c:\windows\system32\wuaueng.dll
2013-09-13 22:33 . 2013-10-31 21:53 773120 ----a-w- c:\windows\system32\wuapi.dll
2013-09-13 22:33 . 2013-10-31 21:53 1622016 ----a-w- c:\windows\system32\wucltux.dll
2013-09-13 22:33 . 2013-10-31 21:53 99328 ----a-w- c:\windows\system32\wudriver.dll
2013-09-13 22:33 . 2013-10-31 21:53 328192 ----a-w- c:\windows\system32\ubpm.dll
2013-09-13 22:33 . 2013-10-31 21:53 175104 ----a-w- c:\windows\system32\storewuauth.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875944]
"Akamai NetSession Interface"="c:\users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SafeQClient"="c:\program files (x86)\SafeQ\SafeQ_cli.exe" [2013-06-12 476672]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ADSK DLMSession"="c:\program files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe" [2013-02-01 1641368]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2013-10-10 707984]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
Akcelerátor spuštění AutoCADu.lnk - c:\program files (x86)\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2009-5-11 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"disablecad"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-20 21:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Samsung Link"="c:\program files\Samsung\Samsung Link\utils\Samsung Link Launcher.exe" [2013-05-09 407384]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.loc;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: vsb.cz\vpn
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-11-13 20:18; FFPDFArchitectConverter@pdfarchitect.com; c:\program files (x86)\PDF Architect\FFPDFArchitectExt
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
@SACL=(02 0000)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@SACL=(02 0000)
@="\"c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil_ActiveX.exe\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=(02 0000)
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@SACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
.
**************************************************************************
.
Celkový čas: 2013-12-03 23:06:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-03 22:06
.
Před spuštěním: 197 200 695 296 bytes free
Po spuštění: 196 823 482 368 bytes free
.
- - End Of File - - 285494FA1AC19E6DC78EB11F6E192715
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.4063.2755 [GMT 1:00]
Spuštěný z: c:\users\Petr JureŔek\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\WinZip\Icon_1.ico
c:\windows\SysWow64\FlashPlayerApp.exe
.
Nakažená kopie c:\windows\SysWow64\ntdll.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\WinSxS\wow64_microsoft-windows-ntdll_31bf3856ad364e35_6.2.9200.16579_none_bc050522ba460118\ntdll.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_vpnagent
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-03 do 2013-12-03 )))))))))))))))))))))))))))))))
.
.
2013-12-03 21:57 . 2013-12-03 21:57 -------- d-----w- c:\users\p\AppData\Local\temp
2013-12-03 21:57 . 2013-12-03 21:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-03 20:10 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{54512FDD-6BFF-4E7C-A188-72B1F18C3CCB}\mpengine.dll
2013-12-03 18:32 . 2012-01-20 13:14 18816 ----a-w- c:\windows\system32\roboot64.exe
2013-12-03 18:31 . 2013-12-03 20:17 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\systweak
2013-12-03 18:30 . 2013-12-03 18:30 -------- d-----w- c:\program files (x86)\PDF Helper
2013-12-02 19:39 . 2013-12-03 21:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\CrashDumps
2013-12-01 12:01 . 2013-12-01 12:01 -------- d-----w- c:\windows\ERUNT
2013-12-01 00:48 . 2013-12-01 00:48 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Malwarebytes
2013-12-01 00:47 . 2013-12-01 00:47 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 00:47 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 00:47 . 2013-12-01 00:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-01 00:40 . 2013-12-01 11:57 -------- d-----w- C:\AdwCleaner
2013-11-29 06:27 . 2013-10-17 10:14 965000 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B4D85BF-1BFE-4475-81D4-029312689D92}\gapaengine.dll
2013-11-28 10:47 . 2013-11-28 10:47 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
2013-11-27 15:23 . 2013-11-27 15:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\YCanPDF
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\IrfanView
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\program files (x86)\IrfanView
2013-11-27 11:57 . 2013-11-27 11:57 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Zoner
2013-11-27 11:49 . 2013-11-27 11:55 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PhotoScape
2013-11-27 10:47 . 2013-11-27 10:47 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-11-20 16:24 . 2013-11-20 16:24 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-11-13 19:22 . 2013-11-13 19:22 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PDF Architect
2013-11-13 19:18 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDF Architect
2013-11-13 19:17 . 2013-04-09 14:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2013-11-13 19:17 . 2013-01-09 14:52 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2013-11-13 19:17 . 2012-05-05 10:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2013-11-13 19:17 . 2012-05-05 10:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-11-13 19:17 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDFCreator
2013-11-13 19:17 . 2012-05-05 10:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Graphisoft
2013-11-13 18:41 . 2013-12-02 19:36 -------- d-----w- c:\users\Petr Jureček\Graphisoft
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Graphisoft
2013-11-13 18:38 . 2013-11-05 22:58 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-11-13 18:33 . 2013-11-13 18:33 -------- d-----w- c:\program files (x86)\QuickTime
2013-11-13 18:29 . 2013-11-13 18:29 -------- d-----w- c:\program files\GRAPHISOFT
2013-11-13 18:27 . 2013-11-13 18:27 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Install.GS
2013-11-13 07:16 . 2013-11-13 11:43 -------- d-----w- c:\programdata\WarThunder
2013-11-13 07:16 . 2013-11-13 07:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\WarThunder
2013-11-13 07:16 . 2013-11-14 15:45 -------- d-----w- c:\program files (x86)\WarThunder
2013-11-10 12:02 . 2013-11-10 12:03 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StartMenu
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iPod
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iTunes
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 10:21 . 2012-12-20 23:06 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-13 08:41 . 2012-12-20 23:08 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-10-10 21:48 . 2013-10-10 21:48 11152 ----a-w- c:\windows\SysWow64\vpncategories.dll
2013-10-10 21:48 . 2013-10-10 21:48 34192 ----a-w- c:\windows\SysWow64\vpnevents.dll
2013-10-10 21:31 . 2013-08-30 21:53 52080 ----a-w- c:\windows\system32\drivers\vpnva64-6.sys
2013-10-10 21:29 . 2013-10-25 07:07 112496 ----a-r- c:\windows\system32\drivers\acsock64.sys
2013-10-08 05:50 . 2013-10-25 07:06 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-14 01:15 . 2013-10-31 21:53 59416 ----a-w- c:\windows\system32\wuauclt.exe
2013-09-13 22:36 . 2013-10-31 21:53 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2013-09-13 22:36 . 2013-10-31 21:53 628736 ----a-w- c:\windows\SysWow64\wuapi.dll
2013-09-13 22:36 . 2013-10-31 21:53 84992 ----a-w- c:\windows\SysWow64\wudriver.dll
2013-09-13 22:36 . 2013-10-31 21:53 126976 ----a-w- c:\windows\SysWow64\wuwebv.dll
2013-09-13 22:36 . 2013-10-31 21:53 247296 ----a-w- c:\windows\SysWow64\ubpm.dll
2013-09-13 22:34 . 2013-10-31 21:53 40448 ----a-w- c:\windows\system32\wuapp.exe
2013-09-13 22:33 . 2013-10-31 21:53 252928 ----a-w- c:\windows\system32\WUSettingsProvider.dll
2013-09-13 22:33 . 2013-10-31 21:53 142848 ----a-w- c:\windows\system32\wuwebv.dll
2013-09-13 22:33 . 2013-10-31 21:53 3279360 ----a-w- c:\windows\system32\wuaueng.dll
2013-09-13 22:33 . 2013-10-31 21:53 773120 ----a-w- c:\windows\system32\wuapi.dll
2013-09-13 22:33 . 2013-10-31 21:53 1622016 ----a-w- c:\windows\system32\wucltux.dll
2013-09-13 22:33 . 2013-10-31 21:53 99328 ----a-w- c:\windows\system32\wudriver.dll
2013-09-13 22:33 . 2013-10-31 21:53 328192 ----a-w- c:\windows\system32\ubpm.dll
2013-09-13 22:33 . 2013-10-31 21:53 175104 ----a-w- c:\windows\system32\storewuauth.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875944]
"Akamai NetSession Interface"="c:\users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SafeQClient"="c:\program files (x86)\SafeQ\SafeQ_cli.exe" [2013-06-12 476672]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ADSK DLMSession"="c:\program files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe" [2013-02-01 1641368]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2013-10-10 707984]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
Akcelerátor spuštění AutoCADu.lnk - c:\program files (x86)\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2009-5-11 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"disablecad"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-20 21:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Samsung Link"="c:\program files\Samsung\Samsung Link\utils\Samsung Link Launcher.exe" [2013-05-09 407384]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.loc;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: vsb.cz\vpn
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-11-13 20:18; FFPDFArchitectConverter@pdfarchitect.com; c:\program files (x86)\PDF Architect\FFPDFArchitectExt
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
@SACL=(02 0000)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@SACL=(02 0000)
@="\"c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil_ActiveX.exe\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=(02 0000)
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@SACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
.
**************************************************************************
.
Celkový čas: 2013-12-03 23:06:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-03 22:06
.
Před spuštěním: 197 200 695 296 bytes free
Po spuštění: 196 823 482 368 bytes free
.
- - End Of File - - 285494FA1AC19E6DC78EB11F6E192715
A36C5E4F47E84449FF07ED3517B43A31
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\system32\roboot64.exe
Folder::
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
c:\program files (x86)\Skype\Updater
Driver::
SkypeUpdate
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
@SACL=(02 0000)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@SACL=(02 0000)
@="\"c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil_ActiveX.exe\""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=(02 0000)
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=(02 0000)
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=(02 0000)
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=(02 0000)
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@SACL=(02 0000)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@SACL=(02 0000)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
ComboFix 13-12-01.01 - Petr Jurecek . 12. 2013 1:03.2.2 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.4063.2582 [GMT 1:00]
Spuštěný z: c:\users\Petr Jureček\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr Jureček\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\roboot64.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxAPI.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxInstallLog.txt
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi64.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspiWDM.inf
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\gearaspiwdmx64.cat
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\x64\GEARAspiWDM.sys
c:\windows\system32\roboot64.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-05 do 2013-12-05 )))))))))))))))))))))))))))))))
.
.
2013-12-05 00:11 . 2013-12-05 00:11 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
2013-12-05 00:09 . 2013-12-05 00:09 -------- d-----w- c:\users\p\AppData\Local\temp
2013-12-05 00:09 . 2013-12-05 00:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-04 20:32 . 2013-12-04 20:32 -------- d-----w- c:\program files (x86)\VectorDraw
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Application Data
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\program files (x86)\SimilarSites
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Google
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\SimilarSites
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\FilesFrog Update Checker
2013-12-04 09:37 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2924488D-10A2-43B0-8344-1E4539569F16}\mpengine.dll
2013-12-03 18:31 . 2013-12-03 20:17 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\systweak
2013-12-03 18:30 . 2013-12-03 18:30 -------- d-----w- c:\program files (x86)\PDF Helper
2013-12-02 19:39 . 2013-12-04 23:57 -------- d-----w- c:\users\Petr Jureček\AppData\Local\CrashDumps
2013-12-01 12:01 . 2013-12-01 12:01 -------- d-----w- c:\windows\ERUNT
2013-12-01 00:48 . 2013-12-01 00:48 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Malwarebytes
2013-12-01 00:47 . 2013-12-01 00:47 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 00:47 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 00:47 . 2013-12-01 00:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-01 00:40 . 2013-12-01 11:57 -------- d-----w- C:\AdwCleaner
2013-11-29 06:27 . 2013-10-17 10:14 965000 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B4D85BF-1BFE-4475-81D4-029312689D92}\gapaengine.dll
2013-11-27 15:23 . 2013-11-27 15:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\YCanPDF
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\IrfanView
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\program files (x86)\IrfanView
2013-11-27 11:57 . 2013-11-27 11:57 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Zoner
2013-11-27 11:49 . 2013-11-27 11:55 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PhotoScape
2013-11-27 10:47 . 2013-11-27 10:47 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-11-20 16:24 . 2013-11-20 16:24 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-11-13 19:22 . 2013-11-13 19:22 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PDF Architect
2013-11-13 19:18 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDF Architect
2013-11-13 19:17 . 2013-04-09 14:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2013-11-13 19:17 . 2013-01-09 14:52 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2013-11-13 19:17 . 2012-05-05 10:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2013-11-13 19:17 . 2012-05-05 10:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-11-13 19:17 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDFCreator
2013-11-13 19:17 . 2012-05-05 10:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Graphisoft
2013-11-13 18:41 . 2013-12-02 19:36 -------- d-----w- c:\users\Petr Jureček\Graphisoft
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Graphisoft
2013-11-13 18:38 . 2013-11-05 22:58 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-11-13 18:33 . 2013-11-13 18:33 -------- d-----w- c:\program files (x86)\QuickTime
2013-11-13 18:29 . 2013-11-13 18:29 -------- d-----w- c:\program files\GRAPHISOFT
2013-11-13 18:27 . 2013-11-13 18:27 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Install.GS
2013-11-13 07:16 . 2013-11-13 11:43 -------- d-----w- c:\programdata\WarThunder
2013-11-13 07:16 . 2013-11-13 07:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\WarThunder
2013-11-13 07:16 . 2013-11-14 15:45 -------- d-----w- c:\program files (x86)\WarThunder
2013-11-10 12:02 . 2013-11-10 12:03 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StartMenu
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iPod
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iTunes
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 10:21 . 2012-12-20 23:06 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-13 08:41 . 2012-12-20 23:08 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-10-10 21:48 . 2013-10-10 21:48 11152 ----a-w- c:\windows\SysWow64\vpncategories.dll
2013-10-10 21:48 . 2013-10-10 21:48 34192 ----a-w- c:\windows\SysWow64\vpnevents.dll
2013-10-10 21:31 . 2013-08-30 21:53 52080 ----a-w- c:\windows\system32\drivers\vpnva64-6.sys
2013-10-10 21:29 . 2013-10-25 07:07 112496 ----a-r- c:\windows\system32\drivers\acsock64.sys
2013-10-08 05:50 . 2013-10-25 07:06 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-14 01:15 . 2013-10-31 21:53 59416 ----a-w- c:\windows\system32\wuauclt.exe
2013-09-13 22:36 . 2013-10-31 21:53 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2013-09-13 22:36 . 2013-10-31 21:53 628736 ----a-w- c:\windows\SysWow64\wuapi.dll
2013-09-13 22:36 . 2013-10-31 21:53 84992 ----a-w- c:\windows\SysWow64\wudriver.dll
2013-09-13 22:36 . 2013-10-31 21:53 126976 ----a-w- c:\windows\SysWow64\wuwebv.dll
2013-09-13 22:36 . 2013-10-31 21:53 247296 ----a-w- c:\windows\SysWow64\ubpm.dll
2013-09-13 22:34 . 2013-10-31 21:53 40448 ----a-w- c:\windows\system32\wuapp.exe
2013-09-13 22:33 . 2013-10-31 21:53 252928 ----a-w- c:\windows\system32\WUSettingsProvider.dll
2013-09-13 22:33 . 2013-10-31 21:53 142848 ----a-w- c:\windows\system32\wuwebv.dll
2013-09-13 22:33 . 2013-10-31 21:53 3279360 ----a-w- c:\windows\system32\wuaueng.dll
2013-09-13 22:33 . 2013-10-31 21:53 773120 ----a-w- c:\windows\system32\wuapi.dll
2013-09-13 22:33 . 2013-10-31 21:53 1622016 ----a-w- c:\windows\system32\wucltux.dll
2013-09-13 22:33 . 2013-10-31 21:53 99328 ----a-w- c:\windows\system32\wudriver.dll
2013-09-13 22:33 . 2013-10-31 21:53 328192 ----a-w- c:\windows\system32\ubpm.dll
2013-09-13 22:33 . 2013-10-31 21:53 175104 ----a-w- c:\windows\system32\storewuauth.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875944]
"Akamai NetSession Interface"="c:\users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SafeQClient"="c:\program files (x86)\SafeQ\SafeQ_cli.exe" [2013-06-12 476672]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ADSK DLMSession"="c:\program files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe" [2013-02-01 1641368]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2013-10-10 707984]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
Akcelerátor spuštění AutoCADu.lnk - c:\program files (x86)\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2009-5-11 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"disablecad"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-20 21:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Samsung Link"="c:\program files\Samsung\Samsung Link\utils\Samsung Link Launcher.exe" [2013-05-09 407384]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.loc;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: vsb.cz\vpn
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-11-13 20:18; FFPDFArchitectConverter@pdfarchitect.com; c:\program files (x86)\PDF Architect\FFPDFArchitectExt
FF - ExtSQL: 2013-12-04 21:23; WebSiteRecommendation@weliketheweb.com; c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\extensions\WebSiteRecommendation@weliketheweb.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-FLV Player - c:\users\Petr Jureček\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\users\Petr Jurec:\program files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
.
**************************************************************************
.
Celkový čas: 2013-12-05 01:17:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-05 00:17
ComboFix2.txt 2013-12-03 22:06
.
Před spuštěním: 195 659 853 824 bytes free
Po spuštění: 195 692 699 648 bytes free
.
- - End Of File - - 22F3FB258CB7EBAC0E86AF1A85BCABBF
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.4063.2582 [GMT 1:00]
Spuštěný z: c:\users\Petr Jureček\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petr Jureček\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\roboot64.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxAPI.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxInstallLog.txt
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi64.dll
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspiWDM.inf
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\gearaspiwdmx64.cat
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\x64\GEARAspiWDM.sys
c:\windows\system32\roboot64.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-05 do 2013-12-05 )))))))))))))))))))))))))))))))
.
.
2013-12-05 00:11 . 2013-12-05 00:11 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
2013-12-05 00:09 . 2013-12-05 00:09 -------- d-----w- c:\users\p\AppData\Local\temp
2013-12-05 00:09 . 2013-12-05 00:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-04 20:32 . 2013-12-04 20:32 -------- d-----w- c:\program files (x86)\VectorDraw
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Application Data
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\program files (x86)\SimilarSites
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Google
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\SimilarSites
2013-12-04 20:23 . 2013-12-04 20:23 -------- d-----w- c:\users\Petr Jureček\AppData\Local\FilesFrog Update Checker
2013-12-04 09:37 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2924488D-10A2-43B0-8344-1E4539569F16}\mpengine.dll
2013-12-03 18:31 . 2013-12-03 20:17 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\systweak
2013-12-03 18:30 . 2013-12-03 18:30 -------- d-----w- c:\program files (x86)\PDF Helper
2013-12-02 19:39 . 2013-12-04 23:57 -------- d-----w- c:\users\Petr Jureček\AppData\Local\CrashDumps
2013-12-01 12:01 . 2013-12-01 12:01 -------- d-----w- c:\windows\ERUNT
2013-12-01 00:48 . 2013-12-01 00:48 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Malwarebytes
2013-12-01 00:47 . 2013-12-01 00:47 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 00:47 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 00:47 . 2013-12-01 00:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-01 00:40 . 2013-12-01 11:57 -------- d-----w- C:\AdwCleaner
2013-11-29 06:27 . 2013-10-17 10:14 965000 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B4D85BF-1BFE-4475-81D4-029312689D92}\gapaengine.dll
2013-11-27 15:23 . 2013-11-27 15:23 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\YCanPDF
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\IrfanView
2013-11-27 12:09 . 2013-11-27 12:09 -------- d-----w- c:\program files (x86)\IrfanView
2013-11-27 11:57 . 2013-11-27 11:57 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Zoner
2013-11-27 11:49 . 2013-11-27 11:55 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PhotoScape
2013-11-27 10:47 . 2013-11-27 10:47 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-11-20 16:24 . 2013-11-20 16:24 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-11-13 19:22 . 2013-11-13 19:22 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\PDF Architect
2013-11-13 19:18 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDF Architect
2013-11-13 19:17 . 2013-04-09 14:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2013-11-13 19:17 . 2013-01-09 14:52 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2013-11-13 19:17 . 2012-05-05 10:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2013-11-13 19:17 . 2012-05-05 10:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-11-13 19:17 . 2013-11-13 19:18 -------- d-----w- c:\program files (x86)\PDFCreator
2013-11-13 19:17 . 2012-05-05 10:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Local\Graphisoft
2013-11-13 18:41 . 2013-12-02 19:36 -------- d-----w- c:\users\Petr Jureček\Graphisoft
2013-11-13 18:41 . 2013-11-13 18:41 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Graphisoft
2013-11-13 18:38 . 2013-11-05 22:58 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-11-13 18:33 . 2013-11-13 18:33 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-11-13 18:33 . 2013-11-13 18:33 -------- d-----w- c:\program files (x86)\QuickTime
2013-11-13 18:29 . 2013-11-13 18:29 -------- d-----w- c:\program files\GRAPHISOFT
2013-11-13 18:27 . 2013-11-13 18:27 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\Install.GS
2013-11-13 07:16 . 2013-11-13 11:43 -------- d-----w- c:\programdata\WarThunder
2013-11-13 07:16 . 2013-11-13 07:16 -------- d-----w- c:\users\Petr Jureček\AppData\Local\WarThunder
2013-11-13 07:16 . 2013-11-14 15:45 -------- d-----w- c:\program files (x86)\WarThunder
2013-11-10 12:02 . 2013-11-10 12:03 -------- d-----w- c:\users\Petr Jureček\AppData\Roaming\StartMenu
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iPod
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files\iTunes
2013-11-10 12:01 . 2013-11-10 12:01 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 10:21 . 2012-12-20 23:06 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-13 08:41 . 2012-12-20 23:08 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-10-10 21:48 . 2013-10-10 21:48 11152 ----a-w- c:\windows\SysWow64\vpncategories.dll
2013-10-10 21:48 . 2013-10-10 21:48 34192 ----a-w- c:\windows\SysWow64\vpnevents.dll
2013-10-10 21:31 . 2013-08-30 21:53 52080 ----a-w- c:\windows\system32\drivers\vpnva64-6.sys
2013-10-10 21:29 . 2013-10-25 07:07 112496 ----a-r- c:\windows\system32\drivers\acsock64.sys
2013-10-08 05:50 . 2013-10-25 07:06 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-14 01:15 . 2013-10-31 21:53 59416 ----a-w- c:\windows\system32\wuauclt.exe
2013-09-13 22:36 . 2013-10-31 21:53 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2013-09-13 22:36 . 2013-10-31 21:53 628736 ----a-w- c:\windows\SysWow64\wuapi.dll
2013-09-13 22:36 . 2013-10-31 21:53 84992 ----a-w- c:\windows\SysWow64\wudriver.dll
2013-09-13 22:36 . 2013-10-31 21:53 126976 ----a-w- c:\windows\SysWow64\wuwebv.dll
2013-09-13 22:36 . 2013-10-31 21:53 247296 ----a-w- c:\windows\SysWow64\ubpm.dll
2013-09-13 22:34 . 2013-10-31 21:53 40448 ----a-w- c:\windows\system32\wuapp.exe
2013-09-13 22:33 . 2013-10-31 21:53 252928 ----a-w- c:\windows\system32\WUSettingsProvider.dll
2013-09-13 22:33 . 2013-10-31 21:53 142848 ----a-w- c:\windows\system32\wuwebv.dll
2013-09-13 22:33 . 2013-10-31 21:53 3279360 ----a-w- c:\windows\system32\wuaueng.dll
2013-09-13 22:33 . 2013-10-31 21:53 773120 ----a-w- c:\windows\system32\wuapi.dll
2013-09-13 22:33 . 2013-10-31 21:53 1622016 ----a-w- c:\windows\system32\wucltux.dll
2013-09-13 22:33 . 2013-10-31 21:53 99328 ----a-w- c:\windows\system32\wudriver.dll
2013-09-13 22:33 . 2013-10-31 21:53 328192 ----a-w- c:\windows\system32\ubpm.dll
2013-09-13 22:33 . 2013-10-31 21:53 175104 ----a-w- c:\windows\system32\storewuauth.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-12-20 1476104]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875944]
"Akamai NetSession Interface"="c:\users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SafeQClient"="c:\program files (x86)\SafeQ\SafeQ_cli.exe" [2013-06-12 476672]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ADSK DLMSession"="c:\program files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe" [2013-02-01 1641368]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2013-10-10 707984]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
Akcelerátor spuštění AutoCADu.lnk - c:\program files (x86)\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2009-5-11 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"disablecad"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
R3 xusb22;Služba ovladače bezdrátového přijímače Xbox 360, 22;c:\windows\System32\drivers\xusb22.sys;c:\windows\SYSNATIVE\drivers\xusb22.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-20 21:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Samsung Link"="c:\program files\Samsung\Samsung Link\utils\Samsung Link Launcher.exe" [2013-05-09 407384]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.loc;<local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: vsb.cz\vpn
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2013-11-13 20:18; FFPDFArchitectConverter@pdfarchitect.com; c:\program files (x86)\PDF Architect\FFPDFArchitectExt
FF - ExtSQL: 2013-12-04 21:23; WebSiteRecommendation@weliketheweb.com; c:\users\Petr Jureček\AppData\Roaming\Mozilla\Firefox\Profiles\g11xp91n.default\extensions\WebSiteRecommendation@weliketheweb.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-FLV Player - c:\users\Petr Jureček\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\users\Petr Jurec:\program files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
.
**************************************************************************
.
Celkový čas: 2013-12-05 01:17:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-05 00:17
ComboFix2.txt 2013-12-03 22:06
.
Před spuštěním: 195 659 853 824 bytes free
Po spuštění: 195 692 699 648 bytes free
.
- - End Of File - - 22F3FB258CB7EBAC0E86AF1A85BCABBF
A36C5E4F47E84449FF07ED3517B43A31
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
Re: Prosím o kontrolu logu
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:18:51, on 5. 12. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal
Running processes:
C:\Users\Petr Jureček\AppData\Local\FilesFrog Update Checker\update_checker.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
C:\Users\Petr Jureček\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.loc;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SafeQClient] C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe"
O4 - Global Startup: Akcelerátor spuštění AutoCADu.lnk = C:\Program Files (x86)\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @oem2.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9320 bytes
Scan saved at 1:18:51, on 5. 12. 2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal
Running processes:
C:\Users\Petr Jureček\AppData\Local\FilesFrog Update Checker\update_checker.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
C:\Users\Petr Jureček\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.loc;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SafeQClient] C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Petr Jureček\AppData\Local\Akamai\netsession_win.exe"
O4 - Global Startup: Akcelerátor spuštění AutoCADu.lnk = C:\Program Files (x86)\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @oem2.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_960c1f056a541068\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9320 bytes
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
Re: Prosím o kontrolu logu
aswMBR mi nejde, stále mi to píše, že program přestal pracovat
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
aswMBR asi nekompatibilita , zkusna něj kliknout pravým a vybrat :
"odstranit potíže s kompatibilitou"
Co problémy?
Návod
Kód: Vybrat vše
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.loc;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
aswMBR asi nekompatibilita , zkusna něj kliknout pravým a vybrat :
"odstranit potíže s kompatibilitou"
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-12-05 14:01:45
-----------------------------
14:01:45.650 OS Version: Windows x64 5.1.2600 Service Pack 3
14:01:45.651 Number of processors: 2 586 0x170A
14:01:45.652 ComputerName: PETR UserName:
14:01:47.667 Initialize success
14:01:49.824 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003d
14:01:49.826 Disk 0 Vendor: ST9500325AS 0005HPM1 Size: 476940MB BusType: 11
14:01:49.990 Disk 0 MBR read successfully
14:01:49.996 Disk 0 MBR scan
14:01:50.002 Disk 0 Windows 7 default MBR code
14:01:50.007 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476938 MB offset 63
14:01:50.056 Disk 0 scanning C:\Windows\system32\drivers
14:02:02.803 Service scanning
14:02:24.301 Modules scanning
14:02:24.316 Disk 0 trace - called modules:
14:02:24.316
14:02:24.334 Scan finished successfully
14:02:33.647 Disk 0 MBR has been saved successfully to "C:\Users\Petr Jureček\Desktop\MBR.dat"
14:02:33.647 The log file has been saved successfully to "C:\Users\Petr Jureček\Desktop\aswMBR.txt"
Run date: 2013-12-05 14:01:45
-----------------------------
14:01:45.650 OS Version: Windows x64 5.1.2600 Service Pack 3
14:01:45.651 Number of processors: 2 586 0x170A
14:01:45.652 ComputerName: PETR UserName:
14:01:47.667 Initialize success
14:01:49.824 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000003d
14:01:49.826 Disk 0 Vendor: ST9500325AS 0005HPM1 Size: 476940MB BusType: 11
14:01:49.990 Disk 0 MBR read successfully
14:01:49.996 Disk 0 MBR scan
14:01:50.002 Disk 0 Windows 7 default MBR code
14:01:50.007 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476938 MB offset 63
14:01:50.056 Disk 0 scanning C:\Windows\system32\drivers
14:02:02.803 Service scanning
14:02:24.301 Modules scanning
14:02:24.316 Disk 0 trace - called modules:
14:02:24.316
14:02:24.334 Scan finished successfully
14:02:33.647 Disk 0 MBR has been saved successfully to "C:\Users\Petr Jureček\Desktop\MBR.dat"
14:02:33.647 The log file has been saved successfully to "C:\Users\Petr Jureček\Desktop\aswMBR.txt"
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
Re: Prosím o kontrolu logu
Vše provedeno, start systému vypadá dobře :) je ten log z aswMBR správný? Není tam moc údajů
My PC
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
CPU: Intel Core i5-4570, GELID Solution Tranquillo
RAM: CRUCIAL Ballistix Tactical 8GB (2x4GB) DDR3 1600 LP
GPU: MSI N770 TF 2GD5/OC
SSD: Samsung SSD 840 EVO - 120GB
HDD: Seagate Barracuda 7200.14 - 1TB
MB: GIGABYTE GA-H87-HD3 - Intel H87
CASE: CoolerMaster K350
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu
Protože je OK.
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 98 hostů