Problém s průzkumníkem Windows Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Problém s průzkumníkem Windows

Příspěvekod Babis » 15 lis 2013 11:37

Ahoj,

občas se mi stane, že průzkumník Windows přestane pracovat, tak prosím o preventivku.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:32:57, on 15.11.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16736)
Boot mode: Normal

Running processes:
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [{CDF13D74-E6AA-4006-818A-B360D6A3573C}] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4294684165-2381958560-516515606-1037\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4294684165-2381958560-516515606-1037\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{85FB1321-7304-46C6-9C8B-E96A4725BC7B}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{F63DB7B2-4D5D-43FC-95F4-991232ADFF6E}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Lenovo Instant Reset Service (DamageGuardSvc) - Lenovo (Beijing) Limited - C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 10004 bytes

Reklama
Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 15 lis 2013 11:37

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.11.15.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
Míra :: MIRA-PC [administrátor]

15.11.2013 11:22:08
mbam-log-2013-11-15 (11-22-08).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 250226
Uplynulý čas: 5 minut, 30 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 15 lis 2013 11:37

# AdwCleaner v3.012 - Report created 15/11/2013 at 11:33:44
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Míra - MIRA-PC
# Running from : C:\Users\Míra\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Uninstall.exe
Folder Found C:\ProgramData\Partner

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Alexa Internet
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Found : [x64] HKCU\Software\Alexa Internet
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16736


-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.57

[ File : C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1086 octets] - [15/11/2013 11:33:44]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1146 octets] ##########

Používám Chrome, takže ATF není potřeba. TFC jsem použil nedávno.

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod memphisto » 15 lis 2013 16:39

V adw nehc vše smazat a dodej log po smazání

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Stáhni si Junkware Removal Tool

na svojí plochu.
Deaktivuj si svůj antivirový program.
Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 16 lis 2013 13:51

# AdwCleaner v3.012 - Report created 16/11/2013 at 13:46:14
# Updated 11/11/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Míra - MIRA-PC
# Running from : C:\Users\Míra\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Program Files (x86)\Uninstall.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Alexa Internet

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16736


-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.57

[ File : C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1230 octets] - [15/11/2013 11:33:44]
AdwCleaner[R1].txt - [1253 octets] - [16/11/2013 13:45:00]
AdwCleaner[S0].txt - [1136 octets] - [16/11/2013 13:46:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1196 octets] ##########

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 16 lis 2013 14:36

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Mˇra on so 16.11.2013 at 13:53:47,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Mˇra\appdata\local\{D9831725-0566-45C8-8A8B-C6D14D61796E}
Successfully deleted: [Empty Folder] C:\Users\Mˇra\appdata\local\{F3385348-5877-4BD9-8BAB-B42E2C5C09CF}



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 16.11.2013 at 14:33:48,34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 16 lis 2013 14:43

RogueKiller V8.7.8 _x64_ [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Míra [Práva správce]
Mód : Kontrola -- Datum : 11/16/2013 14:40:21
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST750LM022 HN-M750MBB +++++
--- User ---
[MBR] 744dff2d41b560f0bd22b5969e7da959
[BSP] 27bdfeb7fd2d350b34563b6b829d3a52 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 669122 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1370773504 | Size: 26080 Mo
3 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1424185344 | Size: 20001 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_11162013_144021.txt >>

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod jaro3 » 17 lis 2013 10:08

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.

Stáhni si Memtest:

Do políčka vlož největší velikost Tvé jednotlivé paměti RAM (256,512 nebo 1024,2048) dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.


Je třeba zkontrolovat HDD na chyby , zkusit jeho defragmentaci ..

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 17 lis 2013 11:41

RogueKiller V8.7.8 _x64_ [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Míra [Práva správce]
Mód : Odebrat -- Datum : 11/17/2013 11:34:48
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NAHRAZENO (2)
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> NAHRAZENO (2)
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST750LM022 HN-M750MBB +++++
--- User ---
[MBR] 744dff2d41b560f0bd22b5969e7da959
[BSP] 27bdfeb7fd2d350b34563b6b829d3a52 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 200 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 411648 | Size: 669122 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1370773504 | Size: 26080 Mo
3 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1424185344 | Size: 20001 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_11172013_113448.txt >>
RKreport[0]_S_11162013_144021.txt;RKreport[0]_S_11172013_113347.txt

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 17 lis 2013 11:44

----------------------------------------------------------------------------
CrystalDiskInfo 6.0.0 (C) 2008-2013 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x64)
Date : 2013/11/17 11:43:37

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- TSSTcorp CDDVDW SN-208AB
- ST750LM022 HN-M750MBB

-- Disk List ---------------------------------------------------------------
(1) ST750LM022 HN-M750MBB : 750,1 GB [0/0/1, pd1] - st

----------------------------------------------------------------------------
(1) ST750LM022 HN-M750MBB
----------------------------------------------------------------------------
Model : ST750LM022 HN-M750MBB
Firmware : 2AR10001
Serial Number : S2USJ9FC520625
Disk Size : 750,1 GB (8,4/137,4/750,1/750,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1465149168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300 | SATA/300
Power On Hours : 4950 hod.
Power On Count : 1245 krát
Temparature : 48 C (118 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _51 000000000003 Počet chyb čtení
02 252 252 __0 000000000000 Průchodnost disku
03 _89 _89 _25 000000000D7E Čas na roztočení ploten
04 _99 _99 __0 0000000004EF Počet spuštění/zastavení
05 252 252 _10 000000000000 Počet přemapovaných sektorů
07 252 252 _51 000000000000 Počet chybných hledání
08 252 252 _15 000000000000 Čas potřebný na vyhledání
09 100 100 __0 000000001356 Hodin v činnosti
0A 252 252 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000054 Počet pokusů o překalibrování
0C _99 _99 __0 0000000004DD Počet cyklů zapnutí zařízení
BF 100 100 __0 000000000033 Počet udalostí zaznamenaných otřesovým senzorem
C0 252 252 __0 000000000000 Počet vypnutí disku
C2 _52 _42 __0 003A000A0030 Teplota
C3 100 100 __0 000000000000 Počet oprav chybného čtení
C4 252 252 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 252 252 __0 000000000000 Počet podezřelých sektorů
C6 252 252 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 __1 __1 __0 000000011DE3 Počet chyb při zápisu sektorů
DF 100 100 __0 000000000054 Zatížení budiče magnetických hlav způsobené opakovanými úkony
E1 _96 _96 __0 00000000A0A1 Počet cyklů načítání/vymazání

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5332 5553 4A39 4643 3532 3036 3235 2020 2020 2020
020: 0000 4000 0004 3241 5231 3030 3031 5354 3735 304C
030: 4D30 3232 2048 4E2D 4D37 3530 4D42 4220 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0006 3FFF 0001 003F BFC1 000F 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0F06 0004 004C 0048
080: 01FF 0028 746B 7D09 6123 7469 BC09 6123 203F 0055
090: 0055 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 66F0 5754 0000 0000 0000 0000 6003 0000 5000 4CF2
110: 07A9 2EAD 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0021 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003F 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0400 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 BBA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 64 64 03 00 00 00 00 00 00 02 26
010: 00 FC FC 00 00 00 00 00 00 00 03 23 00 59 59 7E
020: 0D 00 00 00 00 00 04 32 00 63 63 EF 04 00 00 00
030: 00 00 05 33 00 FC FC 00 00 00 00 00 00 00 07 2E
040: 00 FC FC 00 00 00 00 00 00 00 08 24 00 FC FC 00
050: 00 00 00 00 00 00 09 32 00 64 64 56 13 00 00 00
060: 00 00 0A 32 00 FC FC 00 00 00 00 00 00 00 0B 32
070: 00 64 64 54 00 00 00 00 00 00 0C 32 00 63 63 DD
080: 04 00 00 00 00 00 BF 22 00 64 64 33 00 00 00 00
090: 00 00 C0 22 00 FC FC 00 00 00 00 00 00 00 C2 02
0A0: 00 34 2A 30 00 0A 00 3A 00 00 C3 3A 00 64 64 00
0B0: 00 00 00 00 00 00 C4 32 00 FC FC 00 00 00 00 00
0C0: 00 00 C5 32 00 FC FC 00 00 00 00 00 00 00 C6 30
0D0: 00 FC FC 00 00 00 00 00 00 00 C7 36 00 C8 C8 00
0E0: 00 00 00 00 00 00 C8 2A 00 01 01 E3 1D 01 00 00
0F0: 00 00 DF 32 00 64 64 54 00 00 00 00 00 00 E1 32
100: 00 60 60 A1 A0 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 7C 29 00 5B
170: 03 00 01 00 02 B1 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CE

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 00 00 00 00 00 00 00 00 00 00 02 00
010: 00 00 00 00 00 00 00 00 00 00 03 19 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 0A 00 00 00 00 00 00 00 00 00 00 07 33
040: 00 00 00 00 00 00 00 00 00 00 08 0F 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 33 00 00 00 00 00 00 00 00 00 00 0B 00
070: 00 00 00 00 00 00 00 00 00 00 0C 00 00 00 00 00
080: 00 00 00 00 00 00 BF 00 00 00 00 00 00 00 00 00
090: 00 00 C0 00 00 00 00 00 00 00 00 00 00 00 C2 00
0A0: 00 00 00 00 00 00 00 00 00 00 C3 00 00 00 00 00
0B0: 00 00 00 00 00 00 C4 00 00 00 00 00 00 00 00 00
0C0: 00 00 C5 00 00 00 00 00 00 00 00 00 00 00 C6 00
0D0: 00 00 00 00 00 00 00 00 00 00 C7 00 00 00 00 00
0E0: 00 00 00 00 00 00 C8 00 00 00 00 00 00 00 00 00
0F0: 00 00 DF 00 00 00 00 00 00 00 00 00 00 00 E1 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3B

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 17 lis 2013 11:46

Na ploše mi tady po RK zbylo pár registrů.. můžu je smazat?
Přílohy
Výstřižek.PNG

Uživatelský avatar
Babis
Level 4.5
Level 4.5
Příspěvky: 1885
Registrován: prosinec 12
Pohlaví: Muž
Stav:
Offline

Re: Problém s průzkumníkem Windows

Příspěvekod Babis » 17 lis 2013 11:51

11:49:42.0366 2620 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:49:43.0941 2620 ============================================================
11:49:43.0941 2620 Current date / time: 2013/11/17 11:49:43.0941
11:49:43.0941 2620 SystemInfo:
11:49:43.0941 2620
11:49:43.0941 2620 OS Version: 6.1.7601 ServicePack: 1.0
11:49:43.0941 2620 Product type: Workstation
11:49:43.0941 2620 ComputerName: MIRA-PC
11:49:43.0941 2620 UserName: Míra
11:49:43.0941 2620 Windows directory: C:\Windows
11:49:43.0941 2620 System windows directory: C:\Windows
11:49:43.0941 2620 Running under WOW64
11:49:43.0941 2620 Processor architecture: Intel x64
11:49:43.0941 2620 Number of processors: 4
11:49:43.0941 2620 Page size: 0x1000
11:49:43.0941 2620 Boot type: Normal boot
11:49:43.0941 2620 ============================================================
11:49:44.0409 2620 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:49:44.0409 2620 ============================================================
11:49:44.0409 2620 \Device\Harddisk0\DR0:
11:49:44.0409 2620 MBR partitions:
11:49:44.0409 2620 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
11:49:44.0409 2620 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x51AE1000
11:49:44.0409 2620 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x51B45800, BlocksNum 0x32F0000
11:49:44.0409 2620 ============================================================
11:49:44.0628 2620 C: <-> \Device\Harddisk0\DR0\Partition2
11:49:44.0831 2620 D: <-> \Device\Harddisk0\DR0\Partition3
11:49:44.0831 2620 ============================================================
11:49:44.0831 2620 Initialize success
11:49:44.0831 2620 ============================================================
11:49:45.0876 2840 ============================================================
11:49:45.0876 2840 Scan started
11:49:45.0876 2840 Mode: Manual;
11:49:45.0876 2840 ============================================================
11:49:46.0671 2840 ================ Scan system memory ========================
11:49:46.0671 2840 System memory - ok
11:49:46.0671 2840 ================ Scan services =============================
11:49:47.0997 2840 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:49:47.0997 2840 1394ohci - ok
11:49:48.0060 2840 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:49:48.0060 2840 ACPI - ok
11:49:48.0138 2840 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:49:48.0138 2840 AcpiPmi - ok
11:49:48.0185 2840 [ 5E813B11629007309E4FC0F0FD2B7C30 ] ACPIVPC C:\Windows\system32\DRIVERS\AcpiVpc.sys
11:49:48.0185 2840 ACPIVPC - ok
11:49:48.0372 2840 [ 11A52CF7B265631DEEB24C6149309EFF ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:49:48.0387 2840 Suspicious file (Forged): C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe. Real md5: 11A52CF7B265631DEEB24C6149309EFF, Fake md5: ADDA5E1951B90D3D23C56D3CF0622ADC
11:49:48.0387 2840 AdobeARMservice ( ForgedFile.Multi.Generic ) - warning
11:49:48.0387 2840 AdobeARMservice - detected ForgedFile.Multi.Generic (1)
11:49:48.0621 2840 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
11:49:48.0621 2840 adp94xx - ok
11:49:48.0668 2840 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
11:49:48.0684 2840 adpahci - ok
11:49:48.0731 2840 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
11:49:48.0731 2840 adpu320 - ok
11:49:48.0762 2840 AdvancedSystemCareService7 - ok
11:49:48.0793 2840 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:49:48.0793 2840 AeLookupSvc - ok
11:49:48.0965 2840 [ 79059559E89D06E8B80CE2944BE20228 ] AFD C:\Windows\system32\drivers\afd.sys
11:49:48.0965 2840 AFD - ok
11:49:49.0011 2840 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
11:49:49.0011 2840 agp440 - ok
11:49:49.0058 2840 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
11:49:49.0058 2840 ALG - ok
11:49:49.0152 2840 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
11:49:49.0152 2840 aliide - ok
11:49:49.0199 2840 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
11:49:49.0199 2840 amdide - ok
11:49:49.0230 2840 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
11:49:49.0245 2840 AmdK8 - ok
11:49:49.0245 2840 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
11:49:49.0245 2840 AmdPPM - ok
11:49:49.0277 2840 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:49:49.0277 2840 amdsata - ok
11:49:49.0386 2840 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
11:49:49.0401 2840 amdsbs - ok
11:49:49.0433 2840 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:49:49.0433 2840 amdxata - ok
11:49:49.0479 2840 [ 64053D3AA5CFEF3D81CD152F00EC09F5 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
11:49:49.0479 2840 AmUStor - ok
11:49:49.0526 2840 AntiVirSchedulerService - ok
11:49:49.0557 2840 AntiVirService - ok
11:49:49.0620 2840 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
11:49:49.0635 2840 AppID - ok
11:49:49.0651 2840 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:49:49.0651 2840 AppIDSvc - ok
11:49:49.0713 2840 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
11:49:49.0713 2840 Appinfo - ok
11:49:49.0745 2840 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
11:49:49.0745 2840 arc - ok
11:49:49.0776 2840 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
11:49:49.0776 2840 arcsas - ok
11:49:49.0932 2840 aspnet_state - ok
11:49:49.0963 2840 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:49:49.0963 2840 AsyncMac - ok
11:49:50.0041 2840 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
11:49:50.0041 2840 atapi - ok
11:49:50.0088 2840 [ 185F180536188C1A4ED605234721A5B9 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
11:49:50.0088 2840 AthBTPort - ok
11:49:50.0291 2840 [ 846DBF46408C30941E6182E2EF084223 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
11:49:50.0291 2840 AtherosSvc - ok
11:49:50.0384 2840 [ DE9FB3DADE8FD39AE2C587DF22D36B8E ] athr C:\Windows\system32\DRIVERS\athrx.sys
11:49:50.0400 2840 athr - ok
11:49:50.0478 2840 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:49:50.0493 2840 AudioEndpointBuilder - ok
11:49:50.0540 2840 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
11:49:50.0540 2840 AudioSrv - ok
11:49:50.0556 2840 avgntflt - ok
11:49:50.0665 2840 [ E26B3C8E9C3DDE047B32C5719955D715 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
11:49:50.0665 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\avipbb.sys. Real md5: E26B3C8E9C3DDE047B32C5719955D715, Fake md5: DBAB18B20FDA2542EEF8C588D878B7B5
11:49:50.0665 2840 avipbb ( ForgedFile.Multi.Generic ) - warning
11:49:50.0665 2840 avipbb - detected ForgedFile.Multi.Generic (1)
11:49:50.0696 2840 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
11:49:50.0696 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\avkmgr.sys. Real md5: 490FA25161BF3E51993EB724ECF0ACEB, Fake md5: 390184FAD8FCC1B6DA25AEBAE928C3B6
11:49:50.0696 2840 avkmgr ( ForgedFile.Multi.Generic ) - warning
11:49:50.0696 2840 avkmgr - detected ForgedFile.Multi.Generic (1)
11:49:50.0743 2840 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:49:50.0743 2840 AxInstSV - ok
11:49:50.0790 2840 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
11:49:50.0790 2840 b06bdrv - ok
11:49:50.0837 2840 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
11:49:50.0837 2840 b57nd60a - ok
11:49:50.0899 2840 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
11:49:50.0915 2840 BDESVC - ok
11:49:50.0946 2840 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
11:49:50.0946 2840 Beep - ok
11:49:51.0008 2840 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
11:49:51.0008 2840 BFE - ok
11:49:51.0195 2840 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
11:49:51.0195 2840 BITS - ok
11:49:51.0227 2840 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:49:51.0227 2840 blbdrive - ok
11:49:51.0273 2840 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:49:51.0273 2840 bowser - ok
11:49:51.0320 2840 [ AAA4F992F879977A000FE8B8C730CD2C ] BPntDrv C:\Windows\system32\drivers\BPntDrv.sys
11:49:51.0320 2840 BPntDrv - ok
11:49:51.0336 2840 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
11:49:51.0336 2840 BrFiltLo - ok
11:49:51.0367 2840 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
11:49:51.0367 2840 BrFiltUp - ok
11:49:51.0398 2840 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
11:49:51.0398 2840 Browser - ok
11:49:51.0476 2840 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:49:51.0476 2840 Brserid - ok
11:49:51.0476 2840 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:49:51.0476 2840 BrSerWdm - ok
11:49:51.0492 2840 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:49:51.0492 2840 BrUsbMdm - ok
11:49:51.0507 2840 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:49:51.0507 2840 BrUsbSer - ok
11:49:51.0539 2840 [ 58C4425368625D275BFC412B59363CE9 ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
11:49:51.0554 2840 BTATH_A2DP - ok
11:49:51.0570 2840 [ 31D4AC3BE7BD37328D49885C380EC506 ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
11:49:51.0570 2840 btath_avdt - ok
11:49:51.0601 2840 [ E6B734A37ADE36FE1A77035F4E484C8C ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
11:49:51.0601 2840 BTATH_BUS - ok
11:49:51.0632 2840 [ FB3833E63FF602B69C2FF085846DCF43 ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
11:49:51.0632 2840 BTATH_HCRP - ok
11:49:51.0648 2840 [ 371A11C1333BA526263A987A93ACDE3D ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
11:49:51.0648 2840 BTATH_LWFLT - ok
11:49:51.0679 2840 [ ABCD3C16CA850A7594CEB9AD5D966810 ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
11:49:51.0679 2840 BTATH_RCP - ok
11:49:51.0726 2840 [ 0EE0D4ECFE459C5937FEC7639C13E26E ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
11:49:51.0726 2840 BtFilter - ok
11:49:51.0788 2840 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
11:49:51.0788 2840 BthEnum - ok
11:49:51.0835 2840 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
11:49:51.0835 2840 BTHMODEM - ok
11:49:51.0866 2840 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
11:49:51.0866 2840 BthPan - ok
11:49:51.0913 2840 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
11:49:51.0929 2840 BTHPORT - ok
11:49:51.0991 2840 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
11:49:51.0991 2840 bthserv - ok
11:49:52.0022 2840 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
11:49:52.0038 2840 BTHUSB - ok
11:49:52.0085 2840 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:49:52.0085 2840 cdfs - ok
11:49:52.0147 2840 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
11:49:52.0147 2840 cdrom - ok
11:49:52.0178 2840 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
11:49:52.0178 2840 CertPropSvc - ok
11:49:52.0209 2840 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
11:49:52.0209 2840 circlass - ok
11:49:52.0241 2840 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
11:49:52.0241 2840 CLFS - ok
11:49:52.0334 2840 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:49:52.0334 2840 clr_optimization_v2.0.50727_32 - ok
11:49:52.0365 2840 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:49:52.0365 2840 clr_optimization_v2.0.50727_64 - ok
11:49:52.0506 2840 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:49:52.0506 2840 clr_optimization_v4.0.30319_32 - ok
11:49:52.0584 2840 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:49:52.0584 2840 clr_optimization_v4.0.30319_64 - ok
11:49:52.0615 2840 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
11:49:52.0631 2840 clwvd - ok
11:49:52.0677 2840 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:49:52.0677 2840 CmBatt - ok
11:49:52.0740 2840 cmdAgent - ok
11:49:52.0771 2840 [ 61B161931BE763DE43FF9E61E7F2B553 ] cmderd C:\Windows\system32\DRIVERS\cmderd.sys
11:49:52.0771 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\cmderd.sys. Real md5: 61B161931BE763DE43FF9E61E7F2B553, Fake md5: E34DF9613C8D24C5CB6F8DF8D74E5586
11:49:52.0771 2840 cmderd ( ForgedFile.Multi.Generic ) - warning
11:49:52.0771 2840 cmderd - detected ForgedFile.Multi.Generic (1)
11:49:52.0927 2840 [ CB1D1909C7EB846B606E0CFEC91D6770 ] cmdGuard C:\Windows\system32\DRIVERS\cmdguard.sys
11:49:52.0927 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\cmdguard.sys. Real md5: CB1D1909C7EB846B606E0CFEC91D6770, Fake md5: D8E4A9A691BBA24EE242A1FDDF6EBAA1
11:49:52.0927 2840 cmdGuard ( ForgedFile.Multi.Generic ) - warning
11:49:52.0927 2840 cmdGuard - detected ForgedFile.Multi.Generic (1)
11:49:52.0958 2840 [ 019C060753B4CB99BACF06569F03FF7F ] cmdHlp C:\Windows\system32\DRIVERS\cmdhlp.sys
11:49:52.0958 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\cmdhlp.sys. Real md5: 019C060753B4CB99BACF06569F03FF7F, Fake md5: F6B424B925B67C306BAA85AC79F7A5CC
11:49:52.0958 2840 cmdHlp ( ForgedFile.Multi.Generic ) - warning
11:49:52.0958 2840 cmdHlp - detected ForgedFile.Multi.Generic (1)
11:49:52.0989 2840 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:49:52.0989 2840 cmdide - ok
11:49:52.0989 2840 cmdvirth - ok
11:49:53.0114 2840 [ EBF28856F69CF094A902F884CF989706 ] CNG C:\Windows\system32\Drivers\cng.sys
11:49:53.0130 2840 CNG - ok
11:49:53.0177 2840 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
11:49:53.0177 2840 Compbatt - ok
11:49:53.0208 2840 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
11:49:53.0208 2840 CompositeBus - ok
11:49:53.0223 2840 COMSysApp - ok
11:49:53.0707 2840 [ 236172C3A418B9A0F26B416A72F5A556 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
11:49:53.0707 2840 Suspicious file (Forged): C:\Windows\SysWow64\IntelCpHeciSvc.exe. Real md5: 236172C3A418B9A0F26B416A72F5A556, Fake md5: 815F3180B5117E42E422188E9CCC89C6
11:49:53.0707 2840 cphs ( ForgedFile.Multi.Generic ) - warning
11:49:53.0707 2840 cphs - detected ForgedFile.Multi.Generic (1)
11:49:53.0738 2840 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
11:49:53.0738 2840 crcdisk - ok
11:49:53.0801 2840 [ 6B400F211BEE880A37A1ED0368776BF4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:49:53.0801 2840 CryptSvc - ok
11:49:53.0894 2840 [ 56F4750B7F0CE969E43DE2A76DDA5A5F ] DamageGuard C:\Windows\system32\DRIVERS\DamageGuardX64.sys
11:49:53.0894 2840 DamageGuard - ok
11:49:54.0035 2840 [ 75974DA59BA3D2E3DCE9386493A31F54 ] DamageGuardSvc C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe
11:49:54.0035 2840 DamageGuardSvc - ok
11:49:54.0081 2840 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
11:49:54.0081 2840 DcomLaunch - ok
11:49:54.0144 2840 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
11:49:54.0144 2840 defragsvc - ok
11:49:54.0191 2840 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:49:54.0191 2840 DfsC - ok
11:49:54.0206 2840 [ 5014042B07FE6CBE0E6C737AA3F1EBFC ] dgFltr C:\Windows\system32\drivers\dgFltrX64.sys
11:49:54.0206 2840 dgFltr - ok
11:49:54.0237 2840 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
11:49:54.0253 2840 Dhcp - ok
11:49:54.0300 2840 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
11:49:54.0300 2840 discache - ok
11:49:54.0347 2840 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
11:49:54.0347 2840 Disk - ok
11:49:54.0347 2840 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:49:54.0362 2840 Dnscache - ok
11:49:54.0409 2840 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
11:49:54.0409 2840 dot3svc - ok
11:49:54.0487 2840 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
11:49:54.0487 2840 DPS - ok
11:49:54.0534 2840 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:49:54.0534 2840 drmkaud - ok
11:49:54.0737 2840 [ 88612F1CE3BF42256913BF6E61C70D52 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:49:54.0752 2840 DXGKrnl - ok
11:49:54.0799 2840 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
11:49:54.0799 2840 EapHost - ok
11:49:55.0002 2840 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
11:49:55.0017 2840 ebdrv - ok
11:49:55.0064 2840 [ 4D71227301DD8D09097B9E4CC6527E5A ] EFS C:\Windows\System32\lsass.exe
11:49:55.0064 2840 EFS - ok
11:49:55.0173 2840 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:49:55.0173 2840 ehRecvr - ok
11:49:55.0189 2840 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
11:49:55.0189 2840 ehSched - ok
11:49:55.0236 2840 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
11:49:55.0251 2840 elxstor - ok
11:49:55.0251 2840 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:49:55.0251 2840 ErrDev - ok
11:49:55.0298 2840 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
11:49:55.0298 2840 EventSystem - ok
11:49:55.0376 2840 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
11:49:55.0376 2840 exfat - ok
11:49:55.0439 2840 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:49:55.0439 2840 fastfat - ok
11:49:55.0501 2840 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
11:49:55.0517 2840 Fax - ok
11:49:55.0548 2840 [ 0BDD7984DB7AAFF6DFEFD11D82D473DB ] fbfmon C:\Windows\system32\drivers\fbfmon.sys
11:49:55.0548 2840 fbfmon - ok
11:49:55.0579 2840 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
11:49:55.0579 2840 fdc - ok
11:49:55.0626 2840 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
11:49:55.0626 2840 fdPHost - ok
11:49:55.0657 2840 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
11:49:55.0657 2840 FDResPub - ok
11:49:55.0673 2840 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:49:55.0673 2840 FileInfo - ok
11:49:55.0704 2840 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:49:55.0704 2840 Filetrace - ok
11:49:55.0719 2840 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
11:49:55.0719 2840 flpydisk - ok
11:49:55.0751 2840 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:49:55.0751 2840 FltMgr - ok
11:49:55.0829 2840 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
11:49:55.0875 2840 FontCache - ok
11:49:55.0922 2840 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:49:55.0922 2840 FontCache3.0.0.0 - ok
11:49:55.0969 2840 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:49:55.0969 2840 FsDepends - ok
11:49:56.0016 2840 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
11:49:56.0016 2840 fssfltr - ok
11:49:56.0375 2840 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
11:49:56.0390 2840 fsssvc - ok
11:49:56.0437 2840 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:49:56.0437 2840 Fs_Rec - ok
11:49:56.0499 2840 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:49:56.0499 2840 fvevol - ok
11:49:56.0562 2840 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
11:49:56.0562 2840 gagp30kx - ok
11:49:56.0733 2840 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
11:49:56.0749 2840 gpsvc - ok
11:49:56.0843 2840 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:49:56.0843 2840 gupdate - ok
11:49:56.0843 2840 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:49:56.0843 2840 gupdatem - ok
11:49:56.0874 2840 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:49:56.0874 2840 hcw85cir - ok
11:49:56.0905 2840 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:49:56.0921 2840 HdAudAddService - ok
11:49:56.0952 2840 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
11:49:56.0952 2840 HDAudBus - ok
11:49:56.0983 2840 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
11:49:56.0983 2840 HidBatt - ok
11:49:56.0999 2840 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
11:49:56.0999 2840 HidBth - ok
11:49:57.0030 2840 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
11:49:57.0030 2840 HidIr - ok
11:49:57.0092 2840 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
11:49:57.0123 2840 hidserv - ok
11:49:57.0170 2840 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
11:49:57.0170 2840 HidUsb - ok
11:49:57.0201 2840 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:49:57.0201 2840 hkmsvc - ok
11:49:57.0217 2840 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:49:57.0217 2840 HomeGroupListener - ok
11:49:57.0279 2840 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:49:57.0279 2840 HomeGroupProvider - ok
11:49:57.0326 2840 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:49:57.0326 2840 HpSAMD - ok
11:49:57.0373 2840 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:49:57.0373 2840 HTTP - ok
11:49:57.0389 2840 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:49:57.0389 2840 hwpolicy - ok
11:49:57.0435 2840 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
11:49:57.0435 2840 i8042prt - ok
11:49:57.0482 2840 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:49:57.0482 2840 iaStor - ok
11:49:57.0591 2840 [ 7D4B9A48430ED57ACA6373B71D5904CA ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
11:49:57.0591 2840 IAStorDataMgrSvc - ok
11:49:57.0654 2840 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:49:57.0669 2840 iaStorV - ok
11:49:57.0716 2840 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:49:57.0732 2840 idsvc - ok
11:49:58.0028 2840 [ 3FB253E8059A1AAC3A8B83A31D094CC5 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
11:49:58.0044 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\igdkmd64.sys. Real md5: 3FB253E8059A1AAC3A8B83A31D094CC5, Fake md5: 348214F96642FD4FEF630DE021BA3540
11:49:58.0075 2840 igfx ( ForgedFile.Multi.Generic ) - warning
11:49:58.0075 2840 igfx - detected ForgedFile.Multi.Generic (1)
11:49:58.0106 2840 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
11:49:58.0106 2840 iirsp - ok
11:49:58.0153 2840 [ 344789398EC3EE5A4E00C52B31847946 ] IKEEXT C:\Windows\System32\ikeext.dll
11:49:58.0169 2840 IKEEXT - ok
11:49:58.0200 2840 [ 90E3AA0093BDD43C6EAD3985F039F1D8 ] inspect C:\Windows\system32\DRIVERS\inspect.sys
11:49:58.0200 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\inspect.sys. Real md5: 90E3AA0093BDD43C6EAD3985F039F1D8, Fake md5: 7D3B8880385ACFA47174847983C4A7FA
11:49:58.0200 2840 inspect ( ForgedFile.Multi.Generic ) - warning
11:49:58.0200 2840 inspect - detected ForgedFile.Multi.Generic (1)
11:49:58.0371 2840 [ BB0D3D57C25D6C5215077A8FAA7AD4B3 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:49:58.0387 2840 Suspicious file (Forged): C:\Windows\system32\drivers\RTKVHD64.sys. Real md5: BB0D3D57C25D6C5215077A8FAA7AD4B3, Fake md5: D739148367AAE1DA0C12160DE141ECED
11:49:58.0403 2840 IntcAzAudAddService ( ForgedFile.Multi.Generic ) - warning
11:49:58.0403 2840 IntcAzAudAddService - detected ForgedFile.Multi.Generic (1)
11:49:58.0481 2840 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
11:49:58.0481 2840 IntcDAud - ok
11:49:58.0574 2840 [ 2D66067C7A8A0112156BCD1C0BAA7042 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
11:49:58.0590 2840 Intel(R) Capability Licensing Service Interface - ok
11:49:58.0652 2840 [ C9DCE1CB628AEED3C0C30ABBF4F1E718 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
11:49:58.0652 2840 Intel(R) ME Service - ok
11:49:58.0683 2840 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
11:49:58.0699 2840 intelide - ok
11:49:58.0730 2840 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:49:58.0730 2840 intelppm - ok
11:49:58.0777 2840 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:49:58.0777 2840 IPBusEnum - ok
11:49:58.0808 2840 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:49:58.0808 2840 IpFilterDriver - ok
11:49:58.0855 2840 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:49:58.0871 2840 iphlpsvc - ok
11:49:58.0871 2840 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:49:58.0871 2840 IPMIDRV - ok
11:49:58.0886 2840 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:49:58.0886 2840 IPNAT - ok
11:49:58.0917 2840 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:49:58.0917 2840 IRENUM - ok
11:49:58.0949 2840 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:49:58.0949 2840 isapnp - ok
11:49:58.0995 2840 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:49:59.0011 2840 iScsiPrt - ok
11:49:59.0042 2840 [ 6BCEF45131C8B8E1C558BE540B190B3C ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
11:49:59.0042 2840 iusb3hcs - ok
11:49:59.0073 2840 [ F080EADA8715F811B58BD35BB774F2F9 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
11:49:59.0073 2840 iusb3hub - ok
11:49:59.0105 2840 [ 0F1756D9396740F053221FA6260FCE66 ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
11:49:59.0120 2840 iusb3xhc - ok
11:49:59.0167 2840 [ 3628933AF5305EAB8173949BFF912F04 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
11:49:59.0167 2840 jhi_service - ok
11:49:59.0183 2840 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:49:59.0183 2840 kbdclass - ok
11:49:59.0214 2840 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
11:49:59.0214 2840 kbdhid - ok
11:49:59.0245 2840 [ 4D71227301DD8D09097B9E4CC6527E5A ] KeyIso C:\Windows\system32\lsass.exe
11:49:59.0245 2840 KeyIso - ok
11:49:59.0276 2840 [ 8F489706472F7E9A06BAAA198703FA64 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:49:59.0292 2840 KSecDD - ok
11:49:59.0307 2840 [ 868A2CAAB12EFC7A021682BCA0EEC54C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:49:59.0323 2840 KSecPkg - ok
11:49:59.0354 2840 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
11:49:59.0354 2840 ksthunk - ok
11:49:59.0401 2840 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
11:49:59.0401 2840 KtmRm - ok
11:49:59.0432 2840 [ E84DA1A93978B3700EA63414357B9BA3 ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
11:49:59.0432 2840 L1C - ok
11:49:59.0495 2840 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
11:49:59.0495 2840 LanmanServer - ok
11:49:59.0526 2840 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:49:59.0541 2840 LanmanWorkstation - ok
11:49:59.0573 2840 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
11:49:59.0573 2840 LHDmgr - ok
11:49:59.0604 2840 LiveUpdateSvc - ok
11:49:59.0651 2840 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:49:59.0651 2840 lltdio - ok
11:49:59.0697 2840 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:49:59.0697 2840 lltdsvc - ok
11:49:59.0713 2840 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:49:59.0729 2840 lmhosts - ok
11:49:59.0760 2840 [ BF22ACF4CF3734D61357E67F0521BC03 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:49:59.0760 2840 LMS - ok
11:49:59.0807 2840 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
11:49:59.0807 2840 LSI_FC - ok
11:49:59.0807 2840 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
11:49:59.0807 2840 LSI_SAS - ok
11:49:59.0822 2840 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
11:49:59.0822 2840 LSI_SAS2 - ok
11:49:59.0838 2840 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
11:49:59.0838 2840 LSI_SCSI - ok
11:49:59.0853 2840 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
11:49:59.0869 2840 luafv - ok
11:49:59.0900 2840 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:49:59.0916 2840 Mcx2Svc - ok
11:49:59.0931 2840 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
11:49:59.0931 2840 megasas - ok
11:49:59.0963 2840 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
11:49:59.0963 2840 MegaSR - ok
11:49:59.0994 2840 [ 6B01B7414A105B9E51652089A03027CF ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
11:49:59.0994 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\HECIx64.sys. Real md5: 6B01B7414A105B9E51652089A03027CF, Fake md5: 772A1DEEDFDBC244183B5C805D1B7D85


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 107 hostů