:) naskočil, sice bez plochy a opět s hláškou DirectPort Invalid error
- použil jsem obnovu systému a už ti z něj píšu .)
- CD nemám je to OEM
budu dál postupovat podle toho co mi psal Jaro3 vložím logy a uvidíme.
kontrola logu HJT - pomalý start NTB
Re: kontrola logu HJT - pomalý start NTB
Fajn, aspon že to pomohlo. Máš tam rootkity, možná díky nim bude poškozený systém, uvidíme.
Re: kontrola logu HJT - pomalý start NTB
kaspersky běží.....
ComboFix log
ComboFix 11-07-08.03 - tereza 09.07.2011 12:46:01.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3066.1898 [GMT 2:00]
Spuštěný z: c:\users\tereza\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\tereza\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\tereza\AppData\Local\BITB635.tmp"
"c:\users\tereza\AppData\Local\BITE252.tmp"
"c:\users\tereza\AppData\Local\BITE7DF.tmp"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\tereza\AppData\Local\BITB635.tmp
c:\users\tereza\AppData\Local\BITE252.tmp
c:\users\tereza\AppData\Local\BITE7DF.tmp
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ccnkwomw
-------\Service_exejesch
-------\Service_lhxdfvhu
-------\Service_mdqjjgvm
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-09 do 2011-07-09 )))))))))))))))))))))))))))))))
.
.
2011-07-09 10:56 . 2011-07-09 11:06 -------- d-----w- c:\users\tereza\AppData\Local\temp
2011-07-09 10:56 . 2011-07-09 10:56 -------- d-----w- c:\users\tereza_2\AppData\Local\temp
2011-07-09 10:56 . 2011-07-09 10:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-08 23:04 . 2011-07-09 10:43 -------- d-----w- C:\32788R22FWJFW
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\users\tereza\AppData\Roaming\Malwarebytes
2011-07-08 21:45 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-08 21:45 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 21:38 . 2011-07-08 21:39 -------- d-----w- C:\rsit
2011-07-08 19:40 . 2011-07-08 19:40 388096 ----a-r- c:\users\tereza\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-08 19:40 . 2011-07-08 21:38 -------- d-----w- c:\program files\Trend Micro
2011-07-08 16:53 . 2011-06-20 06:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{328E12BE-1C89-4786-BEC9-45730DE5D53F}\mpengine.dll
2011-07-08 13:24 . 2011-07-08 21:33 -------- d-----w- c:\program files\CCleaner
2011-07-08 04:04 . 2002-01-05 09:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-07-08 04:04 . 2002-01-05 03:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-07-08 04:04 . 2002-01-05 04:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-07-08 04:04 . 2000-05-22 14:58 608448 ----a-w- c:\windows\system32\comctl32.ocx
2011-07-08 04:04 . 2011-07-08 04:04 -------- d-----w- c:\program files\AML Products
2011-07-08 03:22 . 2011-07-08 03:22 -------- d-----w- c:\users\tereza\AppData\Roaming\Avira
2011-07-08 03:18 . 2011-07-08 17:10 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-08 03:18 . 2011-07-08 17:10 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-08 03:18 . 2011-07-08 03:18 -------- d-----w- c:\programdata\Avira
2011-07-08 03:18 . 2011-07-08 03:18 -------- d-----w- c:\program files\Avira
2011-07-08 01:31 . 2011-07-08 01:31 -------- d-----w- c:\users\tereza\AppData\Local\Microsoft_Corporation
2011-06-29 16:09 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll
2011-06-20 18:03 . 2011-06-20 18:03 0 ---ha-w- c:\users\tereza\AppData\Local\BITBD26.tmp
2011-06-16 10:52 . 2011-04-28 16:03 129024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 10:52 . 2011-04-21 16:04 834048 ----a-w- c:\windows\system32\wininet.dll
2011-06-16 10:52 . 2011-04-21 14:15 389632 ----a-w- c:\windows\system32\html.iec
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2009-10-03 08:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-05-02 19:51 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-02 39408]
"NokiaPCInternetAccess"="c:\program files\Nokia\PC Internet Access\NPCIA.exe" [2008-08-05 536576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-13 6139904]
"FSCRecovery"="c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe" [2008-05-08 268096]
"OSD"="c:\program files\OEM\OSD_1.16\osd.exe" [2008-06-18 376832]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-09 92704]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2008-05-29 381200]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R1 MpKsl00661330;MpKsl00661330;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl00661330.sys [x]
R1 MpKsl00ee679e;MpKsl00ee679e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl00ee679e.sys [x]
R1 MpKsl042e5512;MpKsl042e5512;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl042e5512.sys [x]
R1 MpKsl0b8e0a87;MpKsl0b8e0a87;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl0b8e0a87.sys [x]
R1 MpKsl0bbca1c3;MpKsl0bbca1c3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE94202-FF07-49DA-B889-A55A3CA3BE50}\MpKsl0bbca1c3.sys [x]
R1 MpKsl0bce7e94;MpKsl0bce7e94;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl0bce7e94.sys [x]
R1 MpKsl0e53511c;MpKsl0e53511c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl0e53511c.sys [x]
R1 MpKsl0f371154;MpKsl0f371154;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl0f371154.sys [x]
R1 MpKsl0ffa4b51;MpKsl0ffa4b51;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl0ffa4b51.sys [x]
R1 MpKsl10f8e693;MpKsl10f8e693;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52430B60-2CF1-4481-B36B-D55D8B11B237}\MpKsl10f8e693.sys [x]
R1 MpKsl1462806a;MpKsl1462806a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl1462806a.sys [x]
R1 MpKsl1727dcdf;MpKsl1727dcdf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl1727dcdf.sys [x]
R1 MpKsl17893391;MpKsl17893391;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D2D0B4FD-B6C0-46D0-B47A-2C5987328CCB}\MpKsl17893391.sys [x]
R1 MpKsl19394478;MpKsl19394478;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl19394478.sys [x]
R1 MpKsl1b6e0179;MpKsl1b6e0179;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl1b6e0179.sys [x]
R1 MpKsl1c018873;MpKsl1c018873;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKsl1c018873.sys [x]
R1 MpKsl1f5bc180;MpKsl1f5bc180;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52FC3FA7-0BBD-4137-94D1-4FC4CD171E28}\MpKsl1f5bc180.sys [x]
R1 MpKsl2117989e;MpKsl2117989e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl2117989e.sys [x]
R1 MpKsl226c0e87;MpKsl226c0e87;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl226c0e87.sys [x]
R1 MpKsl229fbd5a;MpKsl229fbd5a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl229fbd5a.sys [x]
R1 MpKsl25ddbcce;MpKsl25ddbcce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl25ddbcce.sys [x]
R1 MpKsl268f2a49;MpKsl268f2a49;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsl268f2a49.sys [x]
R1 MpKsl26b29a7c;MpKsl26b29a7c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65C567E3-4E44-4B67-965C-B691F2180524}\MpKsl26b29a7c.sys [x]
R1 MpKsl27e8e0d4;MpKsl27e8e0d4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl27e8e0d4.sys [x]
R1 MpKsl28a56f97;MpKsl28a56f97;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5ED73-0937-4955-BC35-81C92A6103BD}\MpKsl28a56f97.sys [x]
R1 MpKsl28d72cb5;MpKsl28d72cb5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsl28d72cb5.sys [x]
R1 MpKsl2a0931a6;MpKsl2a0931a6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3FD697A8-A8B0-4F98-B9D7-F37CDF09F4E7}\MpKsl2a0931a6.sys [x]
R1 MpKsl2bbd5359;MpKsl2bbd5359;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl2bbd5359.sys [x]
R1 MpKsl2c6b8dd3;MpKsl2c6b8dd3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{609493F4-C4C0-459F-97FF-75B5429EEEE4}\MpKsl2c6b8dd3.sys [x]
R1 MpKsl33bffd0f;MpKsl33bffd0f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl33bffd0f.sys [x]
R1 MpKsl34657df8;MpKsl34657df8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl34657df8.sys [x]
R1 MpKsl353b69e7;MpKsl353b69e7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl353b69e7.sys [x]
R1 MpKsl366d7dd3;MpKsl366d7dd3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl366d7dd3.sys [x]
R1 MpKsl373c4c25;MpKsl373c4c25;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22E32C7D-9793-4581-B129-D3C769232F79}\MpKsl373c4c25.sys [x]
R1 MpKsl3855985d;MpKsl3855985d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl3855985d.sys [x]
R1 MpKsl39d4945d;MpKsl39d4945d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D945E4BE-FF5A-406D-BB41-26F359FFF644}\MpKsl39d4945d.sys [x]
R1 MpKsl3bb6c002;MpKsl3bb6c002;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl3bb6c002.sys [x]
R1 MpKsl3c32d0f4;MpKsl3c32d0f4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{927E159D-94BC-4BE4-970B-D0435E957EE6}\MpKsl3c32d0f4.sys [x]
R1 MpKsl3d8fd7ce;MpKsl3d8fd7ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3d8fd7ce.sys [x]
R1 MpKsl3dbf9f3e;MpKsl3dbf9f3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3dbf9f3e.sys [x]
R1 MpKsl3e1ec1a4;MpKsl3e1ec1a4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl3e1ec1a4.sys [x]
R1 MpKsl3e455fba;MpKsl3e455fba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl3e455fba.sys [x]
R1 MpKsl3ef5e2cc;MpKsl3ef5e2cc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3ef5e2cc.sys [x]
R1 MpKsl3f4276ec;MpKsl3f4276ec;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl3f4276ec.sys [x]
R1 MpKsl406c6213;MpKsl406c6213;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CE0AA59C-B8BB-454B-B4AC-F24F587F69A3}\MpKsl406c6213.sys [x]
R1 MpKsl41f6c24d;MpKsl41f6c24d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl41f6c24d.sys [x]
R1 MpKsl42ad10ce;MpKsl42ad10ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD78FE8-0387-491F-BC10-1AB612E107CD}\MpKsl42ad10ce.sys [x]
R1 MpKsl42fe9763;MpKsl42fe9763;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKsl42fe9763.sys [x]
R1 MpKsl4395ca23;MpKsl4395ca23;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl4395ca23.sys [x]
R1 MpKsl4421a1d2;MpKsl4421a1d2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D06CFFD-1057-4B2E-87F2-2242A3337A73}\MpKsl4421a1d2.sys [x]
R1 MpKsl448f080b;MpKsl448f080b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl448f080b.sys [x]
R1 MpKsl44d88e31;MpKsl44d88e31;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsl44d88e31.sys [x]
R1 MpKsl46228957;MpKsl46228957;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C1534429-D993-4688-BDF7-D7DD2E795242}\MpKsl46228957.sys [x]
R1 MpKsl46917562;MpKsl46917562;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl46917562.sys [x]
R1 MpKsl474e1e27;MpKsl474e1e27;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl474e1e27.sys [x]
R1 MpKsl47bed66f;MpKsl47bed66f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3010ADB6-B7F6-4FA0-B6D6-77C3FCBD0B54}\MpKsl47bed66f.sys [x]
R1 MpKsl47ea9343;MpKsl47ea9343;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl47ea9343.sys [x]
R1 MpKsl489d8aef;MpKsl489d8aef;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl489d8aef.sys [x]
R1 MpKsl49dcc843;MpKsl49dcc843;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsl49dcc843.sys [x]
R1 MpKsl4bf28a30;MpKsl4bf28a30;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl4bf28a30.sys [x]
R1 MpKsl4d9d523f;MpKsl4d9d523f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl4d9d523f.sys [x]
R1 MpKsl4ef27b8d;MpKsl4ef27b8d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl4ef27b8d.sys [x]
R1 MpKsl4f910b79;MpKsl4f910b79;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKsl4f910b79.sys [x]
R1 MpKsl4fccc15a;MpKsl4fccc15a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKsl4fccc15a.sys [x]
R1 MpKsl50ad2634;MpKsl50ad2634;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl50ad2634.sys [x]
R1 MpKsl51ed120c;MpKsl51ed120c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl51ed120c.sys [x]
R1 MpKsl51ff3aea;MpKsl51ff3aea;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5ED73-0937-4955-BC35-81C92A6103BD}\MpKsl51ff3aea.sys [x]
R1 MpKsl531a33af;MpKsl531a33af;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{25AF1356-DAAD-4574-965F-CCC683B10FC0}\MpKsl531a33af.sys [x]
R1 MpKsl53703817;MpKsl53703817;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl53703817.sys [x]
R1 MpKsl53710bc7;MpKsl53710bc7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl53710bc7.sys [x]
R1 MpKsl569130c2;MpKsl569130c2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl569130c2.sys [x]
R1 MpKsl56df77aa;MpKsl56df77aa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl56df77aa.sys [x]
R1 MpKsl57adca47;MpKsl57adca47;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl57adca47.sys [x]
R1 MpKsl57f985a1;MpKsl57f985a1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl57f985a1.sys [x]
R1 MpKsl58667485;MpKsl58667485;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl58667485.sys [x]
R1 MpKsl59214de0;MpKsl59214de0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl59214de0.sys [x]
R1 MpKsl5a66b7b5;MpKsl5a66b7b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl5a66b7b5.sys [x]
R1 MpKsl5cbd194d;MpKsl5cbd194d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKsl5cbd194d.sys [x]
R1 MpKsl5cbe7e34;MpKsl5cbe7e34;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl5cbe7e34.sys [x]
R1 MpKsl5f22b948;MpKsl5f22b948;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl5f22b948.sys [x]
R1 MpKsl5f633c8f;MpKsl5f633c8f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl5f633c8f.sys [x]
R1 MpKsl601a8265;MpKsl601a8265;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C1534429-D993-4688-BDF7-D7DD2E795242}\MpKsl601a8265.sys [x]
R1 MpKsl613bf7b5;MpKsl613bf7b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl613bf7b5.sys [x]
R1 MpKsl644af590;MpKsl644af590;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl644af590.sys [x]
R1 MpKsl64ce169a;MpKsl64ce169a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4B5B8A6-FFF5-4D3F-9A28-8171C321BD82}\MpKsl64ce169a.sys [x]
R1 MpKsl6769104a;MpKsl6769104a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl6769104a.sys [x]
R1 MpKsl677ccc23;MpKsl677ccc23;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl677ccc23.sys [x]
R1 MpKsl68498b56;MpKsl68498b56;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl68498b56.sys [x]
R1 MpKsl69fee950;MpKsl69fee950;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BDC1C736-0C04-4AFC-879A-DAFEA67B75CC}\MpKsl69fee950.sys [x]
R1 MpKsl6afba45e;MpKsl6afba45e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl6afba45e.sys [x]
R1 MpKsl6b2ce2c8;MpKsl6b2ce2c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52430B60-2CF1-4481-B36B-D55D8B11B237}\MpKsl6b2ce2c8.sys [x]
R1 MpKsl6c3b1d96;MpKsl6c3b1d96;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl6c3b1d96.sys [x]
R1 MpKsl6d6b3ad6;MpKsl6d6b3ad6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl6d6b3ad6.sys [x]
R1 MpKsl711d3d84;MpKsl711d3d84;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl711d3d84.sys [x]
R1 MpKsl722d3a40;MpKsl722d3a40;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl722d3a40.sys [x]
R1 MpKsl72ac89b4;MpKsl72ac89b4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl72ac89b4.sys [x]
R1 MpKsl72af3fee;MpKsl72af3fee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl72af3fee.sys [x]
R1 MpKsl74669fc5;MpKsl74669fc5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl74669fc5.sys [x]
R1 MpKsl75f0f28b;MpKsl75f0f28b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl75f0f28b.sys [x]
R1 MpKsl77956e72;MpKsl77956e72;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl77956e72.sys [x]
R1 MpKsl795b72dd;MpKsl795b72dd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl795b72dd.sys [x]
R1 MpKsl7ab093cd;MpKsl7ab093cd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl7ab093cd.sys [x]
R1 MpKsl7c669b6e;MpKsl7c669b6e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKsl7c669b6e.sys [x]
R1 MpKsl7c89e565;MpKsl7c89e565;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl7c89e565.sys [x]
R1 MpKsl7cc8ac8a;MpKsl7cc8ac8a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl7cc8ac8a.sys [x]
R1 MpKsl7dd96d92;MpKsl7dd96d92;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl7dd96d92.sys [x]
R1 MpKsl7fab728b;MpKsl7fab728b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl7fab728b.sys [x]
R1 MpKsl802325dc;MpKsl802325dc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl802325dc.sys [x]
R1 MpKsl809719f1;MpKsl809719f1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl809719f1.sys [x]
R1 MpKsl817c40f0;MpKsl817c40f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42975E51-4BB1-452A-95E7-CFDE2E8609DB}\MpKsl817c40f0.sys [x]
R1 MpKsl81a1ce90;MpKsl81a1ce90;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10A908C2-D027-4015-893F-9FE5ECCE9302}\MpKsl81a1ce90.sys [x]
R1 MpKsl828bfd28;MpKsl828bfd28;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl828bfd28.sys [x]
R1 MpKsl833d56e8;MpKsl833d56e8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl833d56e8.sys [x]
R1 MpKsl83bb4e9f;MpKsl83bb4e9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl83bb4e9f.sys [x]
R1 MpKsl83cb5344;MpKsl83cb5344;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl83cb5344.sys [x]
R1 MpKsl840eecf9;MpKsl840eecf9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl840eecf9.sys [x]
R1 MpKsl84a972b6;MpKsl84a972b6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl84a972b6.sys [x]
R1 MpKsl84fc220a;MpKsl84fc220a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsl84fc220a.sys [x]
R1 MpKsl854365c8;MpKsl854365c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsl854365c8.sys [x]
R1 MpKsl86af166a;MpKsl86af166a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C364634F-A730-46B2-82C4-2CCE16DF047F}\MpKsl86af166a.sys [x]
R1 MpKsl87344a00;MpKsl87344a00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl87344a00.sys [x]
R1 MpKsl891b9792;MpKsl891b9792;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl891b9792.sys [x]
R1 MpKsl8b1394cf;MpKsl8b1394cf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl8b1394cf.sys [x]
R1 MpKsl8c752809;MpKsl8c752809;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{931B9C56-AE10-45C0-AC3B-6E76348F2049}\MpKsl8c752809.sys [x]
R1 MpKsl91eaa851;MpKsl91eaa851;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl91eaa851.sys [x]
R1 MpKsl92c582c0;MpKsl92c582c0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B70D06D4-9C91-4BBB-AF0F-E6C12FC13431}\MpKsl92c582c0.sys [x]
R1 MpKsl93f17f38;MpKsl93f17f38;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl93f17f38.sys [x]
R1 MpKsl94153848;MpKsl94153848;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl94153848.sys [x]
R1 MpKsl95196493;MpKsl95196493;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl95196493.sys [x]
R1 MpKsl959f5a2f;MpKsl959f5a2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl959f5a2f.sys [x]
R1 MpKsl96179a00;MpKsl96179a00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl96179a00.sys [x]
R1 MpKsl974594f0;MpKsl974594f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl974594f0.sys [x]
R1 MpKsl98d518e2;MpKsl98d518e2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl98d518e2.sys [x]
R1 MpKsl99077615;MpKsl99077615;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl99077615.sys [x]
R1 MpKsl9922169c;MpKsl9922169c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12380E66-DBF4-4DCF-9407-FA434A12A5A6}\MpKsl9922169c.sys [x]
R1 MpKsl998582c1;MpKsl998582c1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{931B9C56-AE10-45C0-AC3B-6E76348F2049}\MpKsl998582c1.sys [x]
R1 MpKsl9aa5946b;MpKsl9aa5946b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl9aa5946b.sys [x]
R1 MpKsl9b932c9d;MpKsl9b932c9d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl9b932c9d.sys [x]
R1 MpKsl9c0bbe27;MpKsl9c0bbe27;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl9c0bbe27.sys [x]
R1 MpKsl9ce97093;MpKsl9ce97093;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsl9ce97093.sys [x]
R1 MpKsl9d3f0cb7;MpKsl9d3f0cb7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl9d3f0cb7.sys [x]
R1 MpKsl9f64025e;MpKsl9f64025e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E36614DF-C1B0-4840-9A96-CA72146F566C}\MpKsl9f64025e.sys [x]
R1 MpKsla1c2c875;MpKsla1c2c875;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsla1c2c875.sys [x]
R1 MpKsla3c726b8;MpKsla3c726b8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10A908C2-D027-4015-893F-9FE5ECCE9302}\MpKsla3c726b8.sys [x]
R1 MpKsla4a21c37;MpKsla4a21c37;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsla4a21c37.sys [x]
R1 MpKsla4b0b083;MpKsla4b0b083;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsla4b0b083.sys [x]
R1 MpKsla4be9c08;MpKsla4be9c08;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsla4be9c08.sys [x]
R1 MpKsla4fa09af;MpKsla4fa09af;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsla4fa09af.sys [x]
R1 MpKsla539e858;MpKsla539e858;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsla539e858.sys [x]
R1 MpKsla5fb3aa9;MpKsla5fb3aa9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsla5fb3aa9.sys [x]
R1 MpKsla639272d;MpKsla639272d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B631F05E-7FA1-42E1-8CEA-91A57F0A643E}\MpKsla639272d.sys [x]
R1 MpKsla7176285;MpKsla7176285;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsla7176285.sys [x]
R1 MpKsla9725781;MpKsla9725781;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsla9725781.sys [x]
R1 MpKslac0d4135;MpKslac0d4135;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslac0d4135.sys [x]
R1 MpKslb642e450;MpKslb642e450;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EC8D5160-B0B8-4D0D-BAC8-B3D979ADE808}\MpKslb642e450.sys [x]
R1 MpKslb6db25dd;MpKslb6db25dd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb6db25dd.sys [x]
R1 MpKslb6fa6c57;MpKslb6fa6c57;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb6fa6c57.sys [x]
R1 MpKslb7b47b3c;MpKslb7b47b3c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb7b47b3c.sys [x]
R1 MpKslb853ac9f;MpKslb853ac9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKslb853ac9f.sys [x]
R1 MpKslb8657819;MpKslb8657819;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKslb8657819.sys [x]
R1 MpKslb9ff1b83;MpKslb9ff1b83;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKslb9ff1b83.sys [x]
R1 MpKslbdcd50b0;MpKslbdcd50b0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKslbdcd50b0.sys [x]
R1 MpKslbdf8119e;MpKslbdf8119e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B631F05E-7FA1-42E1-8CEA-91A57F0A643E}\MpKslbdf8119e.sys [x]
R1 MpKslbe34c1f2;MpKslbe34c1f2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslbe34c1f2.sys [x]
R1 MpKslc02a3112;MpKslc02a3112;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKslc02a3112.sys [x]
R1 MpKslc070d136;MpKslc070d136;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKslc070d136.sys [x]
R1 MpKslc0f99f01;MpKslc0f99f01;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D06CFFD-1057-4B2E-87F2-2242A3337A73}\MpKslc0f99f01.sys [x]
R1 MpKslc271d012;MpKslc271d012;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EC8D5160-B0B8-4D0D-BAC8-B3D979ADE808}\MpKslc271d012.sys [x]
R1 MpKslc3e785ed;MpKslc3e785ed;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKslc3e785ed.sys [x]
R1 MpKslc52b45e7;MpKslc52b45e7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKslc52b45e7.sys [x]
R1 MpKslc53b9ca6;MpKslc53b9ca6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslc53b9ca6.sys [x]
R1 MpKslc6b772c5;MpKslc6b772c5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslc6b772c5.sys [x]
R1 MpKslc9f7277b;MpKslc9f7277b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslc9f7277b.sys [x]
R1 MpKslca35e457;MpKslca35e457;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslca35e457.sys [x]
R1 MpKslcadf34a3;MpKslcadf34a3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4B5B8A6-FFF5-4D3F-9A28-8171C321BD82}\MpKslcadf34a3.sys [x]
R1 MpKslcafdb963;MpKslcafdb963;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKslcafdb963.sys [x]
R1 MpKslcbe8f479;MpKslcbe8f479;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKslcbe8f479.sys [x]
R1 MpKslcc166041;MpKslcc166041;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65C567E3-4E44-4B67-965C-B691F2180524}\MpKslcc166041.sys [x]
R1 MpKsld2518466;MpKsld2518466;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsld2518466.sys [x]
R1 MpKsld2cc9022;MpKsld2cc9022;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C364634F-A730-46B2-82C4-2CCE16DF047F}\MpKsld2cc9022.sys [x]
R1 MpKsld314e62a;MpKsld314e62a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsld314e62a.sys [x]
R1 MpKsld3a2dffc;MpKsld3a2dffc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsld3a2dffc.sys [x]
R1 MpKsld74372b5;MpKsld74372b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B70D06D4-9C91-4BBB-AF0F-E6C12FC13431}\MpKsld74372b5.sys [x]
R1 MpKsld744cb9c;MpKsld744cb9c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B2D14FBC-88B7-4B02-ACE9-B4AC151590C7}\MpKsld744cb9c.sys [x]
R1 MpKsld7ebd460;MpKsld7ebd460;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsld7ebd460.sys [x]
R1 MpKsld7ff117d;MpKsld7ff117d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsld7ff117d.sys [x]
R1 MpKslda2dc59f;MpKslda2dc59f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslda2dc59f.sys [x]
R1 MpKslda5d57b8;MpKslda5d57b8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslda5d57b8.sys [x]
R1 MpKsldc02b767;MpKsldc02b767;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsldc02b767.sys [x]
R1 MpKsldc2e566c;MpKsldc2e566c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsldc2e566c.sys [x]
R1 MpKsle140e7ce;MpKsle140e7ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsle140e7ce.sys [x]
R1 MpKsle2fc639f;MpKsle2fc639f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsle2fc639f.sys [x]
R1 MpKsle337cc0a;MpKsle337cc0a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKsle337cc0a.sys [x]
R1 MpKsle358b18d;MpKsle358b18d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsle358b18d.sys [x]
R1 MpKsle450c2fa;MpKsle450c2fa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsle450c2fa.sys [x]
R1 MpKsle59fe791;MpKsle59fe791;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsle59fe791.sys [x]
R1 MpKslea5a63ba;MpKslea5a63ba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKslea5a63ba.sys [x]
R1 MpKsleabbb194;MpKsleabbb194;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EA803D43-7C56-4480-94FF-D9DB1E2917F6}\MpKsleabbb194.sys [x]
R1 MpKslead998bc;MpKslead998bc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{47C090CB-0559-40B5-B3D0-3C29ED131441}\MpKslead998bc.sys [x]
R1 MpKsleb49c42c;MpKsleb49c42c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsleb49c42c.sys [x]
R1 MpKsleb9d37d9;MpKsleb9d37d9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsleb9d37d9.sys [x]
R1 MpKslecbabc02;MpKslecbabc02;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKslecbabc02.sys [x]
R1 MpKslee204621;MpKslee204621;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42975E51-4BB1-452A-95E7-CFDE2E8609DB}\MpKslee204621.sys [x]
R1 MpKslee41f06b;MpKslee41f06b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKslee41f06b.sys [x]
R1 MpKslf149dd9b;MpKslf149dd9b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKslf149dd9b.sys [x]
R1 MpKslf1919b3d;MpKslf1919b3d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD78FE8-0387-491F-BC10-1AB612E107CD}\MpKslf1919b3d.sys [x]
R1 MpKslf2875193;MpKslf2875193;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslf2875193.sys [x]
R1 MpKslf2a0a9a0;MpKslf2a0a9a0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKslf2a0a9a0.sys [x]
R1 MpKslf2f72f3c;MpKslf2f72f3c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C711F2E6-5D1F-4230-8CC8-305A85D4B44C}\MpKslf2f72f3c.sys [x]
R1 MpKslf4d9817f;MpKslf4d9817f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslf4d9817f.sys [x]
R1 MpKslf657ccee;MpKslf657ccee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKslf657ccee.sys [x]
R1 MpKslf73a71f7;MpKslf73a71f7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKslf73a71f7.sys [x]
R1 MpKslfa04d3a5;MpKslfa04d3a5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKslfa04d3a5.sys [x]
R1 MpKslfa3a30b2;MpKslfa3a30b2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKslfa3a30b2.sys [x]
R1 MpKslfb306130;MpKslfb306130;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKslfb306130.sys [x]
R1 MpKslfbea2ec8;MpKslfbea2ec8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKslfbea2ec8.sys [x]
R1 MpKslfcd27abd;MpKslfcd27abd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKslfcd27abd.sys [x]
R1 MpKslfe1dd800;MpKslfe1dd800;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKslfe1dd800.sys [x]
R1 MpKslfe2dc51d;MpKslfe2dc51d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslfe2dc51d.sys [x]
R1 MpKslfea7cdb3;MpKslfea7cdb3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslfea7cdb3.sys [x]
R1 MpKslfeeb715a;MpKslfeeb715a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE94202-FF07-49DA-B889-A55A3CA3BE50}\MpKslfeeb715a.sys [x]
R1 MpKslff7be31f;MpKslff7be31f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKslff7be31f.sys [x]
R1 tlmbxgsz;tlmbxgsz;c:\windows\system32\drivers\tlmbxgsz.sys [x]
R1 xosdvkqf;xosdvkqf;c:\windows\system32\drivers\xosdvkqf.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GpdDevDPort;GpdDevDPort;c:\windows\system32\directport.sys [2008-06-17 7168]
R3 GpdKbFilter;GpdKbFilter;c:\windows\system32\kbfiltr.sys [2008-03-31 8192]
R3 gupdate1c9f0e247a0afb0;Služba Google Update (gupdate1c9f0e247a0afb0);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 133104]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 133104]
R3 IpwP;IPWireless 3G Network Adapter;c:\windows\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 OsdService;OSD Service;c:\program files\OEM\OSD_1.16\OsdService.exe [2008-02-22 94208]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-07-08 136360]
S2 Ethpdrv;Ethernet Packet Driver;c:\windows\system32\DRIVERS\ethpdrv.sys [2007-08-01 16376]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-05-01 3660800]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-09 c:\windows\Tasks\User_Feed_Synchronization-{BFCBACF4-3D38-4CA7-8CF4-64C5B77314B5}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 213.46.172.36 192.168.1.254
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\PEV.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2011-07-09 13:11:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-09 11:11
ComboFix2.txt 2011-07-08 23:16
.
Před spuštěním: Volných bajtů: 54 378 893 312
Po spuštění: Volných bajtů: 54 214 762 496
.
- - End Of File - - D0E027A0B6F34443370DC891417C1CB8
HJT log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:43:30, on 9.7.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [FSCRecovery] c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe
O4 - HKLM\..\Run: [OSD] C:\Program Files\OEM\OSD_1.16\osd.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729)" -"http://www8.agame.com/games/shockwave/m/my_3d_room_2/My3DRoom_2_www_girlsgogames_com.htm"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\tereza\Desktop\PartyPoker.lnk
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\tereza\Desktop\PartyPoker.lnk
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate1c9f0e247a0afb0) (gupdate1c9f0e247a0afb0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Fujitsu Diagnostic Testhandler (TestHandler) - Fujitsu Technology Solutions - C:\Program Files\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
--
End of file - 8378 bytes
ComboFix log
ComboFix 11-07-08.03 - tereza 09.07.2011 12:46:01.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3066.1898 [GMT 2:00]
Spuštěný z: c:\users\tereza\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\tereza\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\tereza\AppData\Local\BITB635.tmp"
"c:\users\tereza\AppData\Local\BITE252.tmp"
"c:\users\tereza\AppData\Local\BITE7DF.tmp"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\tereza\AppData\Local\BITB635.tmp
c:\users\tereza\AppData\Local\BITE252.tmp
c:\users\tereza\AppData\Local\BITE7DF.tmp
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ccnkwomw
-------\Service_exejesch
-------\Service_lhxdfvhu
-------\Service_mdqjjgvm
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-09 do 2011-07-09 )))))))))))))))))))))))))))))))
.
.
2011-07-09 10:56 . 2011-07-09 11:06 -------- d-----w- c:\users\tereza\AppData\Local\temp
2011-07-09 10:56 . 2011-07-09 10:56 -------- d-----w- c:\users\tereza_2\AppData\Local\temp
2011-07-09 10:56 . 2011-07-09 10:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-08 23:04 . 2011-07-09 10:43 -------- d-----w- C:\32788R22FWJFW
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\users\tereza\AppData\Roaming\Malwarebytes
2011-07-08 21:45 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 21:45 . 2011-07-08 21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-08 21:45 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 21:38 . 2011-07-08 21:39 -------- d-----w- C:\rsit
2011-07-08 19:40 . 2011-07-08 19:40 388096 ----a-r- c:\users\tereza\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-08 19:40 . 2011-07-08 21:38 -------- d-----w- c:\program files\Trend Micro
2011-07-08 16:53 . 2011-06-20 06:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{328E12BE-1C89-4786-BEC9-45730DE5D53F}\mpengine.dll
2011-07-08 13:24 . 2011-07-08 21:33 -------- d-----w- c:\program files\CCleaner
2011-07-08 04:04 . 2002-01-05 09:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-07-08 04:04 . 2002-01-05 03:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-07-08 04:04 . 2002-01-05 04:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-07-08 04:04 . 2000-05-22 14:58 608448 ----a-w- c:\windows\system32\comctl32.ocx
2011-07-08 04:04 . 2011-07-08 04:04 -------- d-----w- c:\program files\AML Products
2011-07-08 03:22 . 2011-07-08 03:22 -------- d-----w- c:\users\tereza\AppData\Roaming\Avira
2011-07-08 03:18 . 2011-07-08 17:10 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-07-08 03:18 . 2011-07-08 17:10 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-07-08 03:18 . 2011-07-08 03:18 -------- d-----w- c:\programdata\Avira
2011-07-08 03:18 . 2011-07-08 03:18 -------- d-----w- c:\program files\Avira
2011-07-08 01:31 . 2011-07-08 01:31 -------- d-----w- c:\users\tereza\AppData\Local\Microsoft_Corporation
2011-06-29 16:09 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll
2011-06-20 18:03 . 2011-06-20 18:03 0 ---ha-w- c:\users\tereza\AppData\Local\BITBD26.tmp
2011-06-16 10:52 . 2011-04-28 16:03 129024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 10:52 . 2011-04-21 16:04 834048 ----a-w- c:\windows\system32\wininet.dll
2011-06-16 10:52 . 2011-04-21 14:15 389632 ----a-w- c:\windows\system32\html.iec
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-24 17:14 . 2009-10-03 08:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-05-02 19:51 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-02 39408]
"NokiaPCInternetAccess"="c:\program files\Nokia\PC Internet Access\NPCIA.exe" [2008-08-05 536576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-13 6139904]
"FSCRecovery"="c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe" [2008-05-08 268096]
"OSD"="c:\program files\OEM\OSD_1.16\osd.exe" [2008-06-18 376832]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-09 92704]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2008-05-29 381200]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R1 MpKsl00661330;MpKsl00661330;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl00661330.sys [x]
R1 MpKsl00ee679e;MpKsl00ee679e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl00ee679e.sys [x]
R1 MpKsl042e5512;MpKsl042e5512;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl042e5512.sys [x]
R1 MpKsl0b8e0a87;MpKsl0b8e0a87;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl0b8e0a87.sys [x]
R1 MpKsl0bbca1c3;MpKsl0bbca1c3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE94202-FF07-49DA-B889-A55A3CA3BE50}\MpKsl0bbca1c3.sys [x]
R1 MpKsl0bce7e94;MpKsl0bce7e94;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl0bce7e94.sys [x]
R1 MpKsl0e53511c;MpKsl0e53511c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl0e53511c.sys [x]
R1 MpKsl0f371154;MpKsl0f371154;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl0f371154.sys [x]
R1 MpKsl0ffa4b51;MpKsl0ffa4b51;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl0ffa4b51.sys [x]
R1 MpKsl10f8e693;MpKsl10f8e693;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52430B60-2CF1-4481-B36B-D55D8B11B237}\MpKsl10f8e693.sys [x]
R1 MpKsl1462806a;MpKsl1462806a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl1462806a.sys [x]
R1 MpKsl1727dcdf;MpKsl1727dcdf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl1727dcdf.sys [x]
R1 MpKsl17893391;MpKsl17893391;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D2D0B4FD-B6C0-46D0-B47A-2C5987328CCB}\MpKsl17893391.sys [x]
R1 MpKsl19394478;MpKsl19394478;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl19394478.sys [x]
R1 MpKsl1b6e0179;MpKsl1b6e0179;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl1b6e0179.sys [x]
R1 MpKsl1c018873;MpKsl1c018873;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKsl1c018873.sys [x]
R1 MpKsl1f5bc180;MpKsl1f5bc180;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52FC3FA7-0BBD-4137-94D1-4FC4CD171E28}\MpKsl1f5bc180.sys [x]
R1 MpKsl2117989e;MpKsl2117989e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl2117989e.sys [x]
R1 MpKsl226c0e87;MpKsl226c0e87;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl226c0e87.sys [x]
R1 MpKsl229fbd5a;MpKsl229fbd5a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl229fbd5a.sys [x]
R1 MpKsl25ddbcce;MpKsl25ddbcce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl25ddbcce.sys [x]
R1 MpKsl268f2a49;MpKsl268f2a49;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsl268f2a49.sys [x]
R1 MpKsl26b29a7c;MpKsl26b29a7c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65C567E3-4E44-4B67-965C-B691F2180524}\MpKsl26b29a7c.sys [x]
R1 MpKsl27e8e0d4;MpKsl27e8e0d4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl27e8e0d4.sys [x]
R1 MpKsl28a56f97;MpKsl28a56f97;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5ED73-0937-4955-BC35-81C92A6103BD}\MpKsl28a56f97.sys [x]
R1 MpKsl28d72cb5;MpKsl28d72cb5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsl28d72cb5.sys [x]
R1 MpKsl2a0931a6;MpKsl2a0931a6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3FD697A8-A8B0-4F98-B9D7-F37CDF09F4E7}\MpKsl2a0931a6.sys [x]
R1 MpKsl2bbd5359;MpKsl2bbd5359;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl2bbd5359.sys [x]
R1 MpKsl2c6b8dd3;MpKsl2c6b8dd3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{609493F4-C4C0-459F-97FF-75B5429EEEE4}\MpKsl2c6b8dd3.sys [x]
R1 MpKsl33bffd0f;MpKsl33bffd0f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl33bffd0f.sys [x]
R1 MpKsl34657df8;MpKsl34657df8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl34657df8.sys [x]
R1 MpKsl353b69e7;MpKsl353b69e7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl353b69e7.sys [x]
R1 MpKsl366d7dd3;MpKsl366d7dd3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl366d7dd3.sys [x]
R1 MpKsl373c4c25;MpKsl373c4c25;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22E32C7D-9793-4581-B129-D3C769232F79}\MpKsl373c4c25.sys [x]
R1 MpKsl3855985d;MpKsl3855985d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl3855985d.sys [x]
R1 MpKsl39d4945d;MpKsl39d4945d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D945E4BE-FF5A-406D-BB41-26F359FFF644}\MpKsl39d4945d.sys [x]
R1 MpKsl3bb6c002;MpKsl3bb6c002;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl3bb6c002.sys [x]
R1 MpKsl3c32d0f4;MpKsl3c32d0f4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{927E159D-94BC-4BE4-970B-D0435E957EE6}\MpKsl3c32d0f4.sys [x]
R1 MpKsl3d8fd7ce;MpKsl3d8fd7ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3d8fd7ce.sys [x]
R1 MpKsl3dbf9f3e;MpKsl3dbf9f3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3dbf9f3e.sys [x]
R1 MpKsl3e1ec1a4;MpKsl3e1ec1a4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl3e1ec1a4.sys [x]
R1 MpKsl3e455fba;MpKsl3e455fba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl3e455fba.sys [x]
R1 MpKsl3ef5e2cc;MpKsl3ef5e2cc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl3ef5e2cc.sys [x]
R1 MpKsl3f4276ec;MpKsl3f4276ec;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl3f4276ec.sys [x]
R1 MpKsl406c6213;MpKsl406c6213;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CE0AA59C-B8BB-454B-B4AC-F24F587F69A3}\MpKsl406c6213.sys [x]
R1 MpKsl41f6c24d;MpKsl41f6c24d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl41f6c24d.sys [x]
R1 MpKsl42ad10ce;MpKsl42ad10ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD78FE8-0387-491F-BC10-1AB612E107CD}\MpKsl42ad10ce.sys [x]
R1 MpKsl42fe9763;MpKsl42fe9763;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKsl42fe9763.sys [x]
R1 MpKsl4395ca23;MpKsl4395ca23;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl4395ca23.sys [x]
R1 MpKsl4421a1d2;MpKsl4421a1d2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D06CFFD-1057-4B2E-87F2-2242A3337A73}\MpKsl4421a1d2.sys [x]
R1 MpKsl448f080b;MpKsl448f080b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl448f080b.sys [x]
R1 MpKsl44d88e31;MpKsl44d88e31;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsl44d88e31.sys [x]
R1 MpKsl46228957;MpKsl46228957;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C1534429-D993-4688-BDF7-D7DD2E795242}\MpKsl46228957.sys [x]
R1 MpKsl46917562;MpKsl46917562;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl46917562.sys [x]
R1 MpKsl474e1e27;MpKsl474e1e27;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl474e1e27.sys [x]
R1 MpKsl47bed66f;MpKsl47bed66f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3010ADB6-B7F6-4FA0-B6D6-77C3FCBD0B54}\MpKsl47bed66f.sys [x]
R1 MpKsl47ea9343;MpKsl47ea9343;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl47ea9343.sys [x]
R1 MpKsl489d8aef;MpKsl489d8aef;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl489d8aef.sys [x]
R1 MpKsl49dcc843;MpKsl49dcc843;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsl49dcc843.sys [x]
R1 MpKsl4bf28a30;MpKsl4bf28a30;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl4bf28a30.sys [x]
R1 MpKsl4d9d523f;MpKsl4d9d523f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl4d9d523f.sys [x]
R1 MpKsl4ef27b8d;MpKsl4ef27b8d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl4ef27b8d.sys [x]
R1 MpKsl4f910b79;MpKsl4f910b79;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKsl4f910b79.sys [x]
R1 MpKsl4fccc15a;MpKsl4fccc15a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKsl4fccc15a.sys [x]
R1 MpKsl50ad2634;MpKsl50ad2634;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl50ad2634.sys [x]
R1 MpKsl51ed120c;MpKsl51ed120c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl51ed120c.sys [x]
R1 MpKsl51ff3aea;MpKsl51ff3aea;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A7A5ED73-0937-4955-BC35-81C92A6103BD}\MpKsl51ff3aea.sys [x]
R1 MpKsl531a33af;MpKsl531a33af;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{25AF1356-DAAD-4574-965F-CCC683B10FC0}\MpKsl531a33af.sys [x]
R1 MpKsl53703817;MpKsl53703817;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl53703817.sys [x]
R1 MpKsl53710bc7;MpKsl53710bc7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl53710bc7.sys [x]
R1 MpKsl569130c2;MpKsl569130c2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl569130c2.sys [x]
R1 MpKsl56df77aa;MpKsl56df77aa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl56df77aa.sys [x]
R1 MpKsl57adca47;MpKsl57adca47;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl57adca47.sys [x]
R1 MpKsl57f985a1;MpKsl57f985a1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsl57f985a1.sys [x]
R1 MpKsl58667485;MpKsl58667485;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl58667485.sys [x]
R1 MpKsl59214de0;MpKsl59214de0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl59214de0.sys [x]
R1 MpKsl5a66b7b5;MpKsl5a66b7b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl5a66b7b5.sys [x]
R1 MpKsl5cbd194d;MpKsl5cbd194d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKsl5cbd194d.sys [x]
R1 MpKsl5cbe7e34;MpKsl5cbe7e34;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72522CF9-F811-45B5-80D2-781574A323B7}\MpKsl5cbe7e34.sys [x]
R1 MpKsl5f22b948;MpKsl5f22b948;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl5f22b948.sys [x]
R1 MpKsl5f633c8f;MpKsl5f633c8f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl5f633c8f.sys [x]
R1 MpKsl601a8265;MpKsl601a8265;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C1534429-D993-4688-BDF7-D7DD2E795242}\MpKsl601a8265.sys [x]
R1 MpKsl613bf7b5;MpKsl613bf7b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl613bf7b5.sys [x]
R1 MpKsl644af590;MpKsl644af590;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl644af590.sys [x]
R1 MpKsl64ce169a;MpKsl64ce169a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4B5B8A6-FFF5-4D3F-9A28-8171C321BD82}\MpKsl64ce169a.sys [x]
R1 MpKsl6769104a;MpKsl6769104a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl6769104a.sys [x]
R1 MpKsl677ccc23;MpKsl677ccc23;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsl677ccc23.sys [x]
R1 MpKsl68498b56;MpKsl68498b56;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl68498b56.sys [x]
R1 MpKsl69fee950;MpKsl69fee950;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BDC1C736-0C04-4AFC-879A-DAFEA67B75CC}\MpKsl69fee950.sys [x]
R1 MpKsl6afba45e;MpKsl6afba45e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKsl6afba45e.sys [x]
R1 MpKsl6b2ce2c8;MpKsl6b2ce2c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52430B60-2CF1-4481-B36B-D55D8B11B237}\MpKsl6b2ce2c8.sys [x]
R1 MpKsl6c3b1d96;MpKsl6c3b1d96;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl6c3b1d96.sys [x]
R1 MpKsl6d6b3ad6;MpKsl6d6b3ad6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl6d6b3ad6.sys [x]
R1 MpKsl711d3d84;MpKsl711d3d84;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl711d3d84.sys [x]
R1 MpKsl722d3a40;MpKsl722d3a40;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl722d3a40.sys [x]
R1 MpKsl72ac89b4;MpKsl72ac89b4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl72ac89b4.sys [x]
R1 MpKsl72af3fee;MpKsl72af3fee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl72af3fee.sys [x]
R1 MpKsl74669fc5;MpKsl74669fc5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl74669fc5.sys [x]
R1 MpKsl75f0f28b;MpKsl75f0f28b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl75f0f28b.sys [x]
R1 MpKsl77956e72;MpKsl77956e72;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl77956e72.sys [x]
R1 MpKsl795b72dd;MpKsl795b72dd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl795b72dd.sys [x]
R1 MpKsl7ab093cd;MpKsl7ab093cd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsl7ab093cd.sys [x]
R1 MpKsl7c669b6e;MpKsl7c669b6e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKsl7c669b6e.sys [x]
R1 MpKsl7c89e565;MpKsl7c89e565;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl7c89e565.sys [x]
R1 MpKsl7cc8ac8a;MpKsl7cc8ac8a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKsl7cc8ac8a.sys [x]
R1 MpKsl7dd96d92;MpKsl7dd96d92;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl7dd96d92.sys [x]
R1 MpKsl7fab728b;MpKsl7fab728b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl7fab728b.sys [x]
R1 MpKsl802325dc;MpKsl802325dc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl802325dc.sys [x]
R1 MpKsl809719f1;MpKsl809719f1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKsl809719f1.sys [x]
R1 MpKsl817c40f0;MpKsl817c40f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42975E51-4BB1-452A-95E7-CFDE2E8609DB}\MpKsl817c40f0.sys [x]
R1 MpKsl81a1ce90;MpKsl81a1ce90;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10A908C2-D027-4015-893F-9FE5ECCE9302}\MpKsl81a1ce90.sys [x]
R1 MpKsl828bfd28;MpKsl828bfd28;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl828bfd28.sys [x]
R1 MpKsl833d56e8;MpKsl833d56e8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsl833d56e8.sys [x]
R1 MpKsl83bb4e9f;MpKsl83bb4e9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsl83bb4e9f.sys [x]
R1 MpKsl83cb5344;MpKsl83cb5344;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl83cb5344.sys [x]
R1 MpKsl840eecf9;MpKsl840eecf9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKsl840eecf9.sys [x]
R1 MpKsl84a972b6;MpKsl84a972b6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl84a972b6.sys [x]
R1 MpKsl84fc220a;MpKsl84fc220a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsl84fc220a.sys [x]
R1 MpKsl854365c8;MpKsl854365c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsl854365c8.sys [x]
R1 MpKsl86af166a;MpKsl86af166a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C364634F-A730-46B2-82C4-2CCE16DF047F}\MpKsl86af166a.sys [x]
R1 MpKsl87344a00;MpKsl87344a00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKsl87344a00.sys [x]
R1 MpKsl891b9792;MpKsl891b9792;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl891b9792.sys [x]
R1 MpKsl8b1394cf;MpKsl8b1394cf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl8b1394cf.sys [x]
R1 MpKsl8c752809;MpKsl8c752809;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{931B9C56-AE10-45C0-AC3B-6E76348F2049}\MpKsl8c752809.sys [x]
R1 MpKsl91eaa851;MpKsl91eaa851;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsl91eaa851.sys [x]
R1 MpKsl92c582c0;MpKsl92c582c0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B70D06D4-9C91-4BBB-AF0F-E6C12FC13431}\MpKsl92c582c0.sys [x]
R1 MpKsl93f17f38;MpKsl93f17f38;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKsl93f17f38.sys [x]
R1 MpKsl94153848;MpKsl94153848;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsl94153848.sys [x]
R1 MpKsl95196493;MpKsl95196493;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsl95196493.sys [x]
R1 MpKsl959f5a2f;MpKsl959f5a2f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl959f5a2f.sys [x]
R1 MpKsl96179a00;MpKsl96179a00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E17C006-F2D1-485B-A4A9-686490887450}\MpKsl96179a00.sys [x]
R1 MpKsl974594f0;MpKsl974594f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKsl974594f0.sys [x]
R1 MpKsl98d518e2;MpKsl98d518e2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl98d518e2.sys [x]
R1 MpKsl99077615;MpKsl99077615;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsl99077615.sys [x]
R1 MpKsl9922169c;MpKsl9922169c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12380E66-DBF4-4DCF-9407-FA434A12A5A6}\MpKsl9922169c.sys [x]
R1 MpKsl998582c1;MpKsl998582c1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{931B9C56-AE10-45C0-AC3B-6E76348F2049}\MpKsl998582c1.sys [x]
R1 MpKsl9aa5946b;MpKsl9aa5946b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl9aa5946b.sys [x]
R1 MpKsl9b932c9d;MpKsl9b932c9d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BB7257F-77AE-4909-9672-C6A8F6190033}\MpKsl9b932c9d.sys [x]
R1 MpKsl9c0bbe27;MpKsl9c0bbe27;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsl9c0bbe27.sys [x]
R1 MpKsl9ce97093;MpKsl9ce97093;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsl9ce97093.sys [x]
R1 MpKsl9d3f0cb7;MpKsl9d3f0cb7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKsl9d3f0cb7.sys [x]
R1 MpKsl9f64025e;MpKsl9f64025e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E36614DF-C1B0-4840-9A96-CA72146F566C}\MpKsl9f64025e.sys [x]
R1 MpKsla1c2c875;MpKsla1c2c875;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsla1c2c875.sys [x]
R1 MpKsla3c726b8;MpKsla3c726b8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10A908C2-D027-4015-893F-9FE5ECCE9302}\MpKsla3c726b8.sys [x]
R1 MpKsla4a21c37;MpKsla4a21c37;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsla4a21c37.sys [x]
R1 MpKsla4b0b083;MpKsla4b0b083;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsla4b0b083.sys [x]
R1 MpKsla4be9c08;MpKsla4be9c08;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKsla4be9c08.sys [x]
R1 MpKsla4fa09af;MpKsla4fa09af;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKsla4fa09af.sys [x]
R1 MpKsla539e858;MpKsla539e858;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsla539e858.sys [x]
R1 MpKsla5fb3aa9;MpKsla5fb3aa9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKsla5fb3aa9.sys [x]
R1 MpKsla639272d;MpKsla639272d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B631F05E-7FA1-42E1-8CEA-91A57F0A643E}\MpKsla639272d.sys [x]
R1 MpKsla7176285;MpKsla7176285;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsla7176285.sys [x]
R1 MpKsla9725781;MpKsla9725781;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsla9725781.sys [x]
R1 MpKslac0d4135;MpKslac0d4135;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslac0d4135.sys [x]
R1 MpKslb642e450;MpKslb642e450;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EC8D5160-B0B8-4D0D-BAC8-B3D979ADE808}\MpKslb642e450.sys [x]
R1 MpKslb6db25dd;MpKslb6db25dd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb6db25dd.sys [x]
R1 MpKslb6fa6c57;MpKslb6fa6c57;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb6fa6c57.sys [x]
R1 MpKslb7b47b3c;MpKslb7b47b3c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslb7b47b3c.sys [x]
R1 MpKslb853ac9f;MpKslb853ac9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKslb853ac9f.sys [x]
R1 MpKslb8657819;MpKslb8657819;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7F1BFB8-30C8-4AB8-BEEB-F1E3FD7D5C53}\MpKslb8657819.sys [x]
R1 MpKslb9ff1b83;MpKslb9ff1b83;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKslb9ff1b83.sys [x]
R1 MpKslbdcd50b0;MpKslbdcd50b0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A82BE1C-93FD-4C1C-9CEA-B558107103BD}\MpKslbdcd50b0.sys [x]
R1 MpKslbdf8119e;MpKslbdf8119e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B631F05E-7FA1-42E1-8CEA-91A57F0A643E}\MpKslbdf8119e.sys [x]
R1 MpKslbe34c1f2;MpKslbe34c1f2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslbe34c1f2.sys [x]
R1 MpKslc02a3112;MpKslc02a3112;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEE23885-22E7-4785-BA57-7A562D8C091E}\MpKslc02a3112.sys [x]
R1 MpKslc070d136;MpKslc070d136;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKslc070d136.sys [x]
R1 MpKslc0f99f01;MpKslc0f99f01;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D06CFFD-1057-4B2E-87F2-2242A3337A73}\MpKslc0f99f01.sys [x]
R1 MpKslc271d012;MpKslc271d012;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EC8D5160-B0B8-4D0D-BAC8-B3D979ADE808}\MpKslc271d012.sys [x]
R1 MpKslc3e785ed;MpKslc3e785ed;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8CFC53F7-8517-4E61-A8B3-5B905795A1C3}\MpKslc3e785ed.sys [x]
R1 MpKslc52b45e7;MpKslc52b45e7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKslc52b45e7.sys [x]
R1 MpKslc53b9ca6;MpKslc53b9ca6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslc53b9ca6.sys [x]
R1 MpKslc6b772c5;MpKslc6b772c5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslc6b772c5.sys [x]
R1 MpKslc9f7277b;MpKslc9f7277b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslc9f7277b.sys [x]
R1 MpKslca35e457;MpKslca35e457;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslca35e457.sys [x]
R1 MpKslcadf34a3;MpKslcadf34a3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A4B5B8A6-FFF5-4D3F-9A28-8171C321BD82}\MpKslcadf34a3.sys [x]
R1 MpKslcafdb963;MpKslcafdb963;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKslcafdb963.sys [x]
R1 MpKslcbe8f479;MpKslcbe8f479;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKslcbe8f479.sys [x]
R1 MpKslcc166041;MpKslcc166041;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65C567E3-4E44-4B67-965C-B691F2180524}\MpKslcc166041.sys [x]
R1 MpKsld2518466;MpKsld2518466;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKsld2518466.sys [x]
R1 MpKsld2cc9022;MpKsld2cc9022;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C364634F-A730-46B2-82C4-2CCE16DF047F}\MpKsld2cc9022.sys [x]
R1 MpKsld314e62a;MpKsld314e62a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsld314e62a.sys [x]
R1 MpKsld3a2dffc;MpKsld3a2dffc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F34D7955-3C6F-49BB-9027-ABF53BD9AEA6}\MpKsld3a2dffc.sys [x]
R1 MpKsld74372b5;MpKsld74372b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B70D06D4-9C91-4BBB-AF0F-E6C12FC13431}\MpKsld74372b5.sys [x]
R1 MpKsld744cb9c;MpKsld744cb9c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B2D14FBC-88B7-4B02-ACE9-B4AC151590C7}\MpKsld744cb9c.sys [x]
R1 MpKsld7ebd460;MpKsld7ebd460;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsld7ebd460.sys [x]
R1 MpKsld7ff117d;MpKsld7ff117d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsld7ff117d.sys [x]
R1 MpKslda2dc59f;MpKslda2dc59f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslda2dc59f.sys [x]
R1 MpKslda5d57b8;MpKslda5d57b8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CD77B736-B26B-48E3-9CE7-81B1D8899F38}\MpKslda5d57b8.sys [x]
R1 MpKsldc02b767;MpKsldc02b767;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B535EB8E-9FD7-4993-A520-A5AB7F465227}\MpKsldc02b767.sys [x]
R1 MpKsldc2e566c;MpKsldc2e566c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A177C744-DD76-4D80-9229-D16EEC1CC256}\MpKsldc2e566c.sys [x]
R1 MpKsle140e7ce;MpKsle140e7ce;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F04C8098-B5EA-4268-B612-1F5F08584AE8}\MpKsle140e7ce.sys [x]
R1 MpKsle2fc639f;MpKsle2fc639f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKsle2fc639f.sys [x]
R1 MpKsle337cc0a;MpKsle337cc0a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKsle337cc0a.sys [x]
R1 MpKsle358b18d;MpKsle358b18d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKsle358b18d.sys [x]
R1 MpKsle450c2fa;MpKsle450c2fa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{22F65E04-3CED-402E-8D3B-BB406E295320}\MpKsle450c2fa.sys [x]
R1 MpKsle59fe791;MpKsle59fe791;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E66564B3-2DA4-4AD6-8B64-36E7D41267D2}\MpKsle59fe791.sys [x]
R1 MpKslea5a63ba;MpKslea5a63ba;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54916130-63C1-4669-906A-76B97FC07C6D}\MpKslea5a63ba.sys [x]
R1 MpKsleabbb194;MpKsleabbb194;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EA803D43-7C56-4480-94FF-D9DB1E2917F6}\MpKsleabbb194.sys [x]
R1 MpKslead998bc;MpKslead998bc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{47C090CB-0559-40B5-B3D0-3C29ED131441}\MpKslead998bc.sys [x]
R1 MpKsleb49c42c;MpKsleb49c42c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKsleb49c42c.sys [x]
R1 MpKsleb9d37d9;MpKsleb9d37d9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18E47B2F-0F70-4F0D-84D2-37DED08C50C0}\MpKsleb9d37d9.sys [x]
R1 MpKslecbabc02;MpKslecbabc02;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKslecbabc02.sys [x]
R1 MpKslee204621;MpKslee204621;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42975E51-4BB1-452A-95E7-CFDE2E8609DB}\MpKslee204621.sys [x]
R1 MpKslee41f06b;MpKslee41f06b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKslee41f06b.sys [x]
R1 MpKslf149dd9b;MpKslf149dd9b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23BA3640-B3F8-4F86-8414-525697F3F732}\MpKslf149dd9b.sys [x]
R1 MpKslf1919b3d;MpKslf1919b3d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD78FE8-0387-491F-BC10-1AB612E107CD}\MpKslf1919b3d.sys [x]
R1 MpKslf2875193;MpKslf2875193;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslf2875193.sys [x]
R1 MpKslf2a0a9a0;MpKslf2a0a9a0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E12122BB-2CC9-402B-B150-FF229C92AB0C}\MpKslf2a0a9a0.sys [x]
R1 MpKslf2f72f3c;MpKslf2f72f3c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C711F2E6-5D1F-4230-8CC8-305A85D4B44C}\MpKslf2f72f3c.sys [x]
R1 MpKslf4d9817f;MpKslf4d9817f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BC644583-D50D-47FE-9A59-C415585C9DF9}\MpKslf4d9817f.sys [x]
R1 MpKslf657ccee;MpKslf657ccee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F607A6B-A42D-4BAE-A64B-7644C506DE1A}\MpKslf657ccee.sys [x]
R1 MpKslf73a71f7;MpKslf73a71f7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKslf73a71f7.sys [x]
R1 MpKslfa04d3a5;MpKslfa04d3a5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65F20C53-0D1E-42AD-8CC9-5FFF43508AC6}\MpKslfa04d3a5.sys [x]
R1 MpKslfa3a30b2;MpKslfa3a30b2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E822272-DF30-40DF-BF5B-47D2DC4FE75A}\MpKslfa3a30b2.sys [x]
R1 MpKslfb306130;MpKslfb306130;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1E6257F-736B-4DA1-B686-7D2BCDF94B73}\MpKslfb306130.sys [x]
R1 MpKslfbea2ec8;MpKslfbea2ec8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{06B049FC-5887-49FA-9B8A-A1DBECCBA990}\MpKslfbea2ec8.sys [x]
R1 MpKslfcd27abd;MpKslfcd27abd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC1F60FC-D221-47F1-833A-D0FCE50D4838}\MpKslfcd27abd.sys [x]
R1 MpKslfe1dd800;MpKslfe1dd800;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1C4C60F-DAD8-4031-A629-734FC83F6530}\MpKslfe1dd800.sys [x]
R1 MpKslfe2dc51d;MpKslfe2dc51d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2489977-5628-41DA-87A1-7950F11F26CD}\MpKslfe2dc51d.sys [x]
R1 MpKslfea7cdb3;MpKslfea7cdb3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F5E53789-CDC0-4F4C-A6E9-5EAC3FA5725D}\MpKslfea7cdb3.sys [x]
R1 MpKslfeeb715a;MpKslfeeb715a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE94202-FF07-49DA-B889-A55A3CA3BE50}\MpKslfeeb715a.sys [x]
R1 MpKslff7be31f;MpKslff7be31f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{349DCBB8-A946-41B7-92E4-02491AA3B0F8}\MpKslff7be31f.sys [x]
R1 tlmbxgsz;tlmbxgsz;c:\windows\system32\drivers\tlmbxgsz.sys [x]
R1 xosdvkqf;xosdvkqf;c:\windows\system32\drivers\xosdvkqf.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GpdDevDPort;GpdDevDPort;c:\windows\system32\directport.sys [2008-06-17 7168]
R3 GpdKbFilter;GpdKbFilter;c:\windows\system32\kbfiltr.sys [2008-03-31 8192]
R3 gupdate1c9f0e247a0afb0;Služba Google Update (gupdate1c9f0e247a0afb0);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 133104]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-19 133104]
R3 IpwP;IPWireless 3G Network Adapter;c:\windows\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 OsdService;OSD Service;c:\program files\OEM\OSD_1.16\OsdService.exe [2008-02-22 94208]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-07-08 136360]
S2 Ethpdrv;Ethernet Packet Driver;c:\windows\system32\DRIVERS\ethpdrv.sys [2007-08-01 16376]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-05-01 3660800]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-09 c:\windows\Tasks\User_Feed_Synchronization-{BFCBACF4-3D38-4CA7-8CF4-64C5B77314B5}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 213.46.172.36 192.168.1.254
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\PEV.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2011-07-09 13:11:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-09 11:11
ComboFix2.txt 2011-07-08 23:16
.
Před spuštěním: Volných bajtů: 54 378 893 312
Po spuštění: Volných bajtů: 54 214 762 496
.
- - End Of File - - D0E027A0B6F34443370DC891417C1CB8
HJT log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:43:30, on 9.7.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [FSCRecovery] c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe
O4 - HKLM\..\Run: [OSD] C:\Program Files\OEM\OSD_1.16\osd.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729)" -"http://www8.agame.com/games/shockwave/m/my_3d_room_2/My3DRoom_2_www_girlsgogames_com.htm"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\tereza\Desktop\PartyPoker.lnk
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\tereza\Desktop\PartyPoker.lnk
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate1c9f0e247a0afb0) (gupdate1c9f0e247a0afb0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Fujitsu Diagnostic Testhandler (TestHandler) - Fujitsu Technology Solutions - C:\Program Files\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
--
End of file - 8378 bytes
Re: kontrola logu HJT - pomalý start NTB
Fajn, už možná i vím, kde byl předtím problém. Asi se nepodařilo comboficu opravit tohle, a proto ses nedostal do pc.
nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Re: kontrola logu HJT - pomalý start NTB
ok počkám až dojede kaspersky a postnu log a uvidíme co dál
Re: kontrola logu HJT - pomalý start NTB
Soubor je opraven, uvidíme pak co dál, ještě se mi něco v combofixu nelíbí, asi bych pak provedla test na rootkity.
Re: kontrola logu HJT - pomalý start NTB
KAS log
Gathering system information: completed 7 minutes ago (events: 216, time: 00:01:39)
9.7.2011 20:28:40 Task completed Gathering system information
9.7.2011 20:28:40 Main script of analysis
9.7.2011 20:28:40 Deleting service/driver: ujiznze1
9.7.2011 20:28:40 Delete file:C:\Windows\system32\Drivers\utiznze1.sys
9.7.2011 20:28:40 [microprogram of healing]> registry key deleted HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\utiznze1
9.7.2011 20:28:40 Deleting service/driver: utiznze1
9.7.2011 20:28:40 System Analysis - complete
9.7.2011 20:27:49 System Analysis in progress
9.7.2011 20:27:48 >> Windows Explorer - show extensions of known file types
9.7.2011 20:27:48 >> Disable removable media autorun
9.7.2011 20:27:48 >> Disable CD/DVD autorun
9.7.2011 20:27:48 >> Disable autorun from network drives
9.7.2011 20:27:48 >> Disable HDD autorun
9.7.2011 20:27:44 >> Security: sending Remote Assistant queries is enabled
9.7.2011 20:27:43 >> Security: anonymous user access is enabled
9.7.2011 20:27:43 >> Security: administrative shares (C$, D$ ...) are enabled
9.7.2011 20:27:43 >> Security: disk drives' autorun is enabled
9.7.2011 20:27:43 > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: Schedule (Plánovač úloh)
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: TermService (Terminálová služba)
9.7.2011 20:27:08 Checking - complete
9.7.2011 20:27:08 Driver loaded successfully
9.7.2011 20:27:08 1.5 Checking of IRP handlers
9.7.2011 20:27:08 Checking not performed: extended monitoring driver (AVZPM) is not installed
9.7.2011 20:27:08 1.4 Searching for masking processes and drivers
9.7.2011 20:27:06 Checking IDT and SYSENTER - complete
9.7.2011 20:27:06 CmpCallCallBacks = 00000000
9.7.2011 20:27:06 Analysis for CPU 2
9.7.2011 20:27:06 Analysis for CPU 1
9.7.2011 20:27:06 1.3 Checking IDT and SYSENTER
9.7.2011 20:27:06 Functions checked: 391, intercepted: 52, restored: 52
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtCreateUserProcess (17F) intercepted (821D1BA6->9EB927AE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtCreateThreadEx (17E) intercepted (82223F94->9EB904CE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtWriteVirtualMemory (166) intercepted (822158BD->9EB90306), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtUnmapViewOfSection (15C) intercepted (82218AED->9EB93D0E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtTerminateThread (14F) intercepted (822244DF->9EB90170), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtTerminateProcess (14E) intercepted (821F90D3->9EB9021A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSystemDebugControl (14C) intercepted (82200E51->9EB931FA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSuspendThread (14B) intercepted (821A292D->9EB941E6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSuspendProcess (14A) intercepted (8229B457->9EB940AC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetSystemInformation (13D) intercepted (821EEE83->9EB93FBA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetSecurityObject (13A) intercepted (821C8008->9EB93566), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetInformationToken (133) intercepted (821CDC2E->9EB9290A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetContextThread (121) intercepted (8229A867->9EB905EC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSecureConnectPort (11E) intercepted (821D56A4->9EB912C4), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSaveKey (11B) intercepted (8225AF29->9EB8E676), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtResumeThread (11A) intercepted (82223AF5->9EB94386), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtRestoreKey (118) intercepted (8225AD72->9EB8EA56), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtRequestWaitReplyPort (114) intercepted (8224BF40->9EB93070), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplyWaitReceivePort (10F) intercepted (82241E59->9EB91EA8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplyPort (10E) intercepted (821E96DF->9EB91FE2), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplaceKey (10C) intercepted (8225BF76->9EB8E6DE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQueueApcThread (FF) intercepted (821B9837->9EB9375C), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQuerySection (F2) intercepted (8222868B->9EB93E6A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQueryDirectoryObject (DB) intercepted (822196BE->9EB92868), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenThread (C9) intercepted (822244AA->9EB8FF64), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenSemaphore (C6) intercepted (821ADEBE->9EB91C7E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenSection (C5) intercepted (822195FD->9EB938CA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenProcess (C2) intercepted (82228F58->9EB90074), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenMutant (BF) intercepted (82219AF1->9EB91A3E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenFile (BA) intercepted (8220E37D->9EB907CC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenEvent (B8) intercepted (82201D5F->9EB91B5E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtMapViewOfSection (B1) intercepted (8221882A->9EB93B30), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtLoadDriver (A5) intercepted (82173DEE->9EB933C8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtFsControlFile (96) intercepted (8224E094->9EB90CB6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDuplicateObject (81) intercepted (822004E1->9EB944E4), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDeviceIoControlFile (7F) intercepted (82250478->9EB90EA8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDebugActiveProcess (74) intercepted (8226CCE2->9EB932D6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateWaitablePort (73) intercepted (82182D04->9EB91918), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateThread (4E) intercepted (82299B98->9EB903D0), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateSemaphore (4C) intercepted (821DFCC3->9EB91BE8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateSection (4B) intercepted (82239D95->9EB8FBCC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreatePort (47) intercepted (8218DA42->9EB91882), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateNamedPipeFile (44) intercepted (821D6718->9EB8FA24), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateMutant (43) intercepted (822287BC->9EB919AE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateFile (3C) intercepted (8224A2EB->9EB90A26), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateEvent (3A) intercepted (8221AD37->9EB91AC8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtConnectPort (36) intercepted (821D5ACB->9EB9157E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtClose (30) intercepted (82242CC1->9EB9074A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcSendWaitReceivePort (26) intercepted (8224596B->9EB92564), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcCreatePort (16) intercepted (821C2943->9EB922EE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcConnectPort (15) intercepted (821F281F->9EB92074), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAdjustPrivilegesToken (0C) intercepted (821F85E2->9EB8FE36), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 KiST = 820B486C (391)
9.7.2011 20:27:05 SDT = 8213FB00
9.7.2011 20:27:05 Kernel ntkrnlpa.exe found in memory at address 82008000
9.7.2011 20:27:05 SDT found (RVA=137B00)
9.7.2011 20:27:05 Driver loaded successfully
9.7.2011 20:27:05 1.2 Searching for kernel-mode API hooks
9.7.2011 20:27:04 Analysis: netapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: urlmon.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: rasapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: wininet.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: ws2_32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: advapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: user32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: ntdll.dll, export table found in section .text
9.7.2011 20:27:04 IAT modification detected: GetProcAddress - 01950390<>7754903B
9.7.2011 20:27:04 IAT modification detected: LoadLibraryA - 01950320<>775294DC
9.7.2011 20:27:04 IAT modification detected: LoadLibraryW - 019502B0<>77529362
9.7.2011 20:27:04 IAT modification detected: CreateProcessW - 019501D0<>77501BF3
9.7.2011 20:27:04 IAT modification detected: GetModuleFileNameW - 01950160<>7754B27E
9.7.2011 20:27:04 IAT modification detected: FreeLibrary - 019500F0<>77543DB4
9.7.2011 20:27:04 IAT modification detected: GetModuleFileNameA - 01950080<>7754B6BD
9.7.2011 20:27:04 IAT modification detected: CreateProcessA - 01950010<>77501C28
9.7.2011 20:27:04 Analysis: kernel32.dll, export table found in section .text
9.7.2011 20:27:04 1.1 Searching for user-mode API hooks
9.7.2011 20:27:03 System Restore: enabled
9.7.2011 20:27:03 Windows version: Windows Vista (TM) Home Premium, Build=6002, SP="Service Pack 2"
9.7.2011 20:27:02 Main script of analysis
9.7.2011 20:27:01 Task started Gathering system information
Gathering system information: completed 6 minutes ago (events: 60, time: 00:00:59)
9.7.2011 20:29:45 Task completed Gathering system information
9.7.2011 20:29:45 Main script of analysis
9.7.2011 20:29:45 Deleting service/driver: ujiznze1
9.7.2011 20:29:45 Delete file:C:\Windows\system32\Drivers\utiznze1.sys
9.7.2011 20:29:45 [microprogram of healing]> registry key deleted HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\utiznze1
9.7.2011 20:29:45 Deleting service/driver: utiznze1
9.7.2011 20:29:45 System Analysis - complete
9.7.2011 20:29:29 System Analysis in progress
9.7.2011 20:29:28 >> Windows Explorer - show extensions of known file types
9.7.2011 20:29:27 >> Disable removable media autorun
9.7.2011 20:29:27 >> Disable CD/DVD autorun
9.7.2011 20:29:27 >> Disable autorun from network drives
9.7.2011 20:29:27 >> Disable HDD autorun
9.7.2011 20:29:23 >> Security: sending Remote Assistant queries is enabled
9.7.2011 20:29:23 >> Security: anonymous user access is enabled
9.7.2011 20:29:23 >> Security: administrative shares (C$, D$ ...) are enabled
9.7.2011 20:29:23 >> Security: disk drives' autorun is enabled
9.7.2011 20:29:23 > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: Schedule (Plánovač úloh)
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: TermService (Terminálová služba)
9.7.2011 20:28:51 Checking - complete
9.7.2011 20:28:51 Driver loaded successfully
9.7.2011 20:28:51 1.5 Checking of IRP handlers
9.7.2011 20:28:51 Checking not performed: extended monitoring driver (AVZPM) is not installed
9.7.2011 20:28:51 1.4 Searching for masking processes and drivers
9.7.2011 20:28:49 Checking IDT and SYSENTER - complete
9.7.2011 20:28:49 CmpCallCallBacks = 00000000
9.7.2011 20:28:49 Analysis for CPU 2
9.7.2011 20:28:49 Analysis for CPU 1
9.7.2011 20:28:49 1.3 Checking IDT and SYSENTER
9.7.2011 20:28:49 Functions checked: 391, intercepted: 0, restored: 0
9.7.2011 20:28:49 KiST = 820B486C (391)
9.7.2011 20:28:49 SDT = 8213FB00
9.7.2011 20:28:49 Kernel ntkrnlpa.exe found in memory at address 82008000
9.7.2011 20:28:49 SDT found (RVA=137B00)
9.7.2011 20:28:49 Driver loaded successfully
9.7.2011 20:28:49 1.2 Searching for kernel-mode API hooks
9.7.2011 20:28:48 Analysis: netapi32.dll, export table found in section .text
9.7.2011 20:28:48 Analysis: urlmon.dll, export table found in section .text
9.7.2011 20:28:48 Analysis: rasapi32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: wininet.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: ws2_32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: advapi32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: user32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: ntdll.dll, export table found in section .text
9.7.2011 20:28:47 IAT modification detected: GetProcAddress - 01950390<>7754903B
9.7.2011 20:28:47 IAT modification detected: LoadLibraryA - 01950320<>775294DC
9.7.2011 20:28:47 IAT modification detected: LoadLibraryW - 019502B0<>77529362
9.7.2011 20:28:47 IAT modification detected: CreateProcessW - 019501D0<>77501BF3
9.7.2011 20:28:47 IAT modification detected: GetModuleFileNameW - 01950160<>7754B27E
9.7.2011 20:28:47 IAT modification detected: FreeLibrary - 019500F0<>77543DB4
9.7.2011 20:28:47 IAT modification detected: GetModuleFileNameA - 01950080<>7754B6BD
9.7.2011 20:28:47 IAT modification detected: CreateProcessA - 01950010<>77501C28
9.7.2011 20:28:47 Analysis: kernel32.dll, export table found in section .text
9.7.2011 20:28:47 1.1 Searching for user-mode API hooks
9.7.2011 20:28:46 System Restore: enabled
9.7.2011 20:28:46 Windows version: Windows Vista (TM) Home Premium, Build=6002, SP="Service Pack 2"
9.7.2011 20:28:46 Main script of analysis
9.7.2011 20:28:46 Task started Gathering system information
Gathering system information: completed 7 minutes ago (events: 216, time: 00:01:39)
9.7.2011 20:28:40 Task completed Gathering system information
9.7.2011 20:28:40 Main script of analysis
9.7.2011 20:28:40 Deleting service/driver: ujiznze1
9.7.2011 20:28:40 Delete file:C:\Windows\system32\Drivers\utiznze1.sys
9.7.2011 20:28:40 [microprogram of healing]> registry key deleted HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\utiznze1
9.7.2011 20:28:40 Deleting service/driver: utiznze1
9.7.2011 20:28:40 System Analysis - complete
9.7.2011 20:27:49 System Analysis in progress
9.7.2011 20:27:48 >> Windows Explorer - show extensions of known file types
9.7.2011 20:27:48 >> Disable removable media autorun
9.7.2011 20:27:48 >> Disable CD/DVD autorun
9.7.2011 20:27:48 >> Disable autorun from network drives
9.7.2011 20:27:48 >> Disable HDD autorun
9.7.2011 20:27:44 >> Security: sending Remote Assistant queries is enabled
9.7.2011 20:27:43 >> Security: anonymous user access is enabled
9.7.2011 20:27:43 >> Security: administrative shares (C$, D$ ...) are enabled
9.7.2011 20:27:43 >> Security: disk drives' autorun is enabled
9.7.2011 20:27:43 > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: Schedule (Plánovač úloh)
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
9.7.2011 20:27:43 >> Services: potentially dangerous service allowed: TermService (Terminálová služba)
9.7.2011 20:27:08 Checking - complete
9.7.2011 20:27:08 Driver loaded successfully
9.7.2011 20:27:08 1.5 Checking of IRP handlers
9.7.2011 20:27:08 Checking not performed: extended monitoring driver (AVZPM) is not installed
9.7.2011 20:27:08 1.4 Searching for masking processes and drivers
9.7.2011 20:27:06 Checking IDT and SYSENTER - complete
9.7.2011 20:27:06 CmpCallCallBacks = 00000000
9.7.2011 20:27:06 Analysis for CPU 2
9.7.2011 20:27:06 Analysis for CPU 1
9.7.2011 20:27:06 1.3 Checking IDT and SYSENTER
9.7.2011 20:27:06 Functions checked: 391, intercepted: 52, restored: 52
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtCreateUserProcess (17F) intercepted (821D1BA6->9EB927AE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtCreateThreadEx (17E) intercepted (82223F94->9EB904CE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtWriteVirtualMemory (166) intercepted (822158BD->9EB90306), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtUnmapViewOfSection (15C) intercepted (82218AED->9EB93D0E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtTerminateThread (14F) intercepted (822244DF->9EB90170), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtTerminateProcess (14E) intercepted (821F90D3->9EB9021A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSystemDebugControl (14C) intercepted (82200E51->9EB931FA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSuspendThread (14B) intercepted (821A292D->9EB941E6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSuspendProcess (14A) intercepted (8229B457->9EB940AC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetSystemInformation (13D) intercepted (821EEE83->9EB93FBA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetSecurityObject (13A) intercepted (821C8008->9EB93566), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetInformationToken (133) intercepted (821CDC2E->9EB9290A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSetContextThread (121) intercepted (8229A867->9EB905EC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSecureConnectPort (11E) intercepted (821D56A4->9EB912C4), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtSaveKey (11B) intercepted (8225AF29->9EB8E676), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtResumeThread (11A) intercepted (82223AF5->9EB94386), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtRestoreKey (118) intercepted (8225AD72->9EB8EA56), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtRequestWaitReplyPort (114) intercepted (8224BF40->9EB93070), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplyWaitReceivePort (10F) intercepted (82241E59->9EB91EA8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplyPort (10E) intercepted (821E96DF->9EB91FE2), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtReplaceKey (10C) intercepted (8225BF76->9EB8E6DE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQueueApcThread (FF) intercepted (821B9837->9EB9375C), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQuerySection (F2) intercepted (8222868B->9EB93E6A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtQueryDirectoryObject (DB) intercepted (822196BE->9EB92868), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenThread (C9) intercepted (822244AA->9EB8FF64), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenSemaphore (C6) intercepted (821ADEBE->9EB91C7E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenSection (C5) intercepted (822195FD->9EB938CA), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenProcess (C2) intercepted (82228F58->9EB90074), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenMutant (BF) intercepted (82219AF1->9EB91A3E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenFile (BA) intercepted (8220E37D->9EB907CC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtOpenEvent (B8) intercepted (82201D5F->9EB91B5E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtMapViewOfSection (B1) intercepted (8221882A->9EB93B30), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtLoadDriver (A5) intercepted (82173DEE->9EB933C8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:06 >>> Hook code blocked
9.7.2011 20:27:06 >>> Function restored successfully !
9.7.2011 20:27:06 Function NtFsControlFile (96) intercepted (8224E094->9EB90CB6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDuplicateObject (81) intercepted (822004E1->9EB944E4), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDeviceIoControlFile (7F) intercepted (82250478->9EB90EA8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtDebugActiveProcess (74) intercepted (8226CCE2->9EB932D6), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateWaitablePort (73) intercepted (82182D04->9EB91918), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateThread (4E) intercepted (82299B98->9EB903D0), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateSemaphore (4C) intercepted (821DFCC3->9EB91BE8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateSection (4B) intercepted (82239D95->9EB8FBCC), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreatePort (47) intercepted (8218DA42->9EB91882), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateNamedPipeFile (44) intercepted (821D6718->9EB8FA24), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateMutant (43) intercepted (822287BC->9EB919AE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateFile (3C) intercepted (8224A2EB->9EB90A26), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtCreateEvent (3A) intercepted (8221AD37->9EB91AC8), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtConnectPort (36) intercepted (821D5ACB->9EB9157E), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtClose (30) intercepted (82242CC1->9EB9074A), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcSendWaitReceivePort (26) intercepted (8224596B->9EB92564), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcCreatePort (16) intercepted (821C2943->9EB922EE), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAlpcConnectPort (15) intercepted (821F281F->9EB92074), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 >>> Hook code blocked
9.7.2011 20:27:05 >>> Function restored successfully !
9.7.2011 20:27:05 Function NtAdjustPrivilegesToken (0C) intercepted (821F85E2->9EB8FE36), hook C:\Windows\system32\DRIVERS\3613614drv.sys, driver recognized as trusted
9.7.2011 20:27:05 KiST = 820B486C (391)
9.7.2011 20:27:05 SDT = 8213FB00
9.7.2011 20:27:05 Kernel ntkrnlpa.exe found in memory at address 82008000
9.7.2011 20:27:05 SDT found (RVA=137B00)
9.7.2011 20:27:05 Driver loaded successfully
9.7.2011 20:27:05 1.2 Searching for kernel-mode API hooks
9.7.2011 20:27:04 Analysis: netapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: urlmon.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: rasapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: wininet.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: ws2_32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: advapi32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: user32.dll, export table found in section .text
9.7.2011 20:27:04 Analysis: ntdll.dll, export table found in section .text
9.7.2011 20:27:04 IAT modification detected: GetProcAddress - 01950390<>7754903B
9.7.2011 20:27:04 IAT modification detected: LoadLibraryA - 01950320<>775294DC
9.7.2011 20:27:04 IAT modification detected: LoadLibraryW - 019502B0<>77529362
9.7.2011 20:27:04 IAT modification detected: CreateProcessW - 019501D0<>77501BF3
9.7.2011 20:27:04 IAT modification detected: GetModuleFileNameW - 01950160<>7754B27E
9.7.2011 20:27:04 IAT modification detected: FreeLibrary - 019500F0<>77543DB4
9.7.2011 20:27:04 IAT modification detected: GetModuleFileNameA - 01950080<>7754B6BD
9.7.2011 20:27:04 IAT modification detected: CreateProcessA - 01950010<>77501C28
9.7.2011 20:27:04 Analysis: kernel32.dll, export table found in section .text
9.7.2011 20:27:04 1.1 Searching for user-mode API hooks
9.7.2011 20:27:03 System Restore: enabled
9.7.2011 20:27:03 Windows version: Windows Vista (TM) Home Premium, Build=6002, SP="Service Pack 2"
9.7.2011 20:27:02 Main script of analysis
9.7.2011 20:27:01 Task started Gathering system information
Gathering system information: completed 6 minutes ago (events: 60, time: 00:00:59)
9.7.2011 20:29:45 Task completed Gathering system information
9.7.2011 20:29:45 Main script of analysis
9.7.2011 20:29:45 Deleting service/driver: ujiznze1
9.7.2011 20:29:45 Delete file:C:\Windows\system32\Drivers\utiznze1.sys
9.7.2011 20:29:45 [microprogram of healing]> registry key deleted HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\utiznze1
9.7.2011 20:29:45 Deleting service/driver: utiznze1
9.7.2011 20:29:45 System Analysis - complete
9.7.2011 20:29:29 System Analysis in progress
9.7.2011 20:29:28 >> Windows Explorer - show extensions of known file types
9.7.2011 20:29:27 >> Disable removable media autorun
9.7.2011 20:29:27 >> Disable CD/DVD autorun
9.7.2011 20:29:27 >> Disable autorun from network drives
9.7.2011 20:29:27 >> Disable HDD autorun
9.7.2011 20:29:23 >> Security: sending Remote Assistant queries is enabled
9.7.2011 20:29:23 >> Security: anonymous user access is enabled
9.7.2011 20:29:23 >> Security: administrative shares (C$, D$ ...) are enabled
9.7.2011 20:29:23 >> Security: disk drives' autorun is enabled
9.7.2011 20:29:23 > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: Schedule (Plánovač úloh)
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: SSDPSRV (SSDP Discovery)
9.7.2011 20:29:23 >> Services: potentially dangerous service allowed: TermService (Terminálová služba)
9.7.2011 20:28:51 Checking - complete
9.7.2011 20:28:51 Driver loaded successfully
9.7.2011 20:28:51 1.5 Checking of IRP handlers
9.7.2011 20:28:51 Checking not performed: extended monitoring driver (AVZPM) is not installed
9.7.2011 20:28:51 1.4 Searching for masking processes and drivers
9.7.2011 20:28:49 Checking IDT and SYSENTER - complete
9.7.2011 20:28:49 CmpCallCallBacks = 00000000
9.7.2011 20:28:49 Analysis for CPU 2
9.7.2011 20:28:49 Analysis for CPU 1
9.7.2011 20:28:49 1.3 Checking IDT and SYSENTER
9.7.2011 20:28:49 Functions checked: 391, intercepted: 0, restored: 0
9.7.2011 20:28:49 KiST = 820B486C (391)
9.7.2011 20:28:49 SDT = 8213FB00
9.7.2011 20:28:49 Kernel ntkrnlpa.exe found in memory at address 82008000
9.7.2011 20:28:49 SDT found (RVA=137B00)
9.7.2011 20:28:49 Driver loaded successfully
9.7.2011 20:28:49 1.2 Searching for kernel-mode API hooks
9.7.2011 20:28:48 Analysis: netapi32.dll, export table found in section .text
9.7.2011 20:28:48 Analysis: urlmon.dll, export table found in section .text
9.7.2011 20:28:48 Analysis: rasapi32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: wininet.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: ws2_32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: advapi32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: user32.dll, export table found in section .text
9.7.2011 20:28:47 Analysis: ntdll.dll, export table found in section .text
9.7.2011 20:28:47 IAT modification detected: GetProcAddress - 01950390<>7754903B
9.7.2011 20:28:47 IAT modification detected: LoadLibraryA - 01950320<>775294DC
9.7.2011 20:28:47 IAT modification detected: LoadLibraryW - 019502B0<>77529362
9.7.2011 20:28:47 IAT modification detected: CreateProcessW - 019501D0<>77501BF3
9.7.2011 20:28:47 IAT modification detected: GetModuleFileNameW - 01950160<>7754B27E
9.7.2011 20:28:47 IAT modification detected: FreeLibrary - 019500F0<>77543DB4
9.7.2011 20:28:47 IAT modification detected: GetModuleFileNameA - 01950080<>7754B6BD
9.7.2011 20:28:47 IAT modification detected: CreateProcessA - 01950010<>77501C28
9.7.2011 20:28:47 Analysis: kernel32.dll, export table found in section .text
9.7.2011 20:28:47 1.1 Searching for user-mode API hooks
9.7.2011 20:28:46 System Restore: enabled
9.7.2011 20:28:46 Windows version: Windows Vista (TM) Home Premium, Build=6002, SP="Service Pack 2"
9.7.2011 20:28:46 Main script of analysis
9.7.2011 20:28:46 Task started Gathering system information
Re: kontrola logu HJT - pomalý start NTB
Z tohoto logu není vidět zda něco mazal. Pokud by Ti to nevadilo, ještě bych si něco ověřila gmerem.
Stahni Gmer http://www.gmer.net/gmer.zip
-rozbal ho a spusť
-po prvním rychlém skenu klikni na tlačítko Save, uloží se log, který mi sem zkopíruješ.
-v pravém sloupci označ všechny položky fajfkou ve čtverečku a klikni na tlačítko scan
-až se sken dokončí, opět tlačítkem Save ulož log, který sem vložíš.
Stahni Gmer http://www.gmer.net/gmer.zip
-rozbal ho a spusť
-po prvním rychlém skenu klikni na tlačítko Save, uloží se log, který mi sem zkopíruješ.
-v pravém sloupci označ všechny položky fajfkou ve čtverečku a klikni na tlačítko scan
-až se sken dokončí, opět tlačítkem Save ulož log, který sem vložíš.
Re: kontrola logu HJT - pomalý start NTB
od kasperskyho mám ješte jeden log ale má 74MB, co jsem koukal tak je tam kontrolovanej řádek po řádku. Chceš to upnout jako rtf/doc soubor? ještě než spustím Gmer
Re: kontrola logu HJT - pomalý start NTB
Ne, udělej rovnou gmer.
Re: kontrola logu HJT - pomalý start NTB
-při spuštění druheho gmeru se ntb kousne a spadne do modré obrazovky (2 pokusy)
-NTB se sevypne - znova se nahodí naskočí obrazovka obnovení windows vyberu normální spuštění a wisty začnou nabíhat - naskočí chyba aplikace s textem- "instrukce na 0x770e2b93 se odkazovala na pamět 0x770e2b93. Požadováná data nebyla umístěna do paměti kvůli vstupní-vystupní chybě na 0xc0000185" , když ji odkliknu chvilku to trvá ale naskočí normálně visty.
-pozitivní že ntb nabíhá už mnohem rychleji ¨
- zkusím potřetí pustit gmer ale chci se zeptat jestli není jiná možnost jak zjistit co potřebuješ
díky
-NTB se sevypne - znova se nahodí naskočí obrazovka obnovení windows vyberu normální spuštění a wisty začnou nabíhat - naskočí chyba aplikace s textem- "instrukce na 0x770e2b93 se odkazovala na pamět 0x770e2b93. Požadováná data nebyla umístěna do paměti kvůli vstupní-vystupní chybě na 0xc0000185" , když ji odkliknu chvilku to trvá ale naskočí normálně visty.
-pozitivní že ntb nabíhá už mnohem rychleji ¨
- zkusím potřetí pustit gmer ale chci se zeptat jestli není jiná možnost jak zjistit co potřebuješ
díky
Re: kontrola logu HJT - pomalý start NTB
NTB spadlo i po třetí ://
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 58 hostů