Prosím o kontrolu logu. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu logu.

Příspěvekod junebag » 26 črc 2012 15:15

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:14:58, on 26.7.2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\totalcmd\TOTALCMD.EXE
C:\Users\Tomas\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=113665 ... 1fd0a38255
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7668 bytes

Reklama
Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod memphisto » 26 črc 2012 15:39

Odinstaluj:
uTorrent Control Bar

fixni:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=113665 ... 1fd0a38255
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab

nainstaluj Anivir. Doporučuji Avira, Avast, AVG, MSE

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 26 črc 2012 15:49

Vůbec nemám představu,jak smazat "uTorrent Control Bar". Nějaký program na to ? Normálně v programech to nejde.

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 26 črc 2012 16:22

Tak nějak sem to smazal z FF alespoň.
Pak sem to šel "Fixnout" a chyba.
http://www.pixhost.org/show/2472/13540512_jack.jpg
U obou "Localhost" ,co s tím dál,prosím ?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod jaro3 » 26 črc 2012 21:17

Pokračuj dalším programem.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 26 črc 2012 21:44

Přikládám log z Malwarebytes´

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org

Verze databáze: v2012.07.26.14

Windows Vista Service Pack 1 x64 NTFS
Internet Explorer 7.0.6001.18000
Tomas :: TOMAS-PC [administrátor]

Ochrana: Povolena

26.7.2012 21:39:52
mbam-log-2012-07-26 (21-43-10).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 189536
Uplynulý čas: 3 minut, 4 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 3
C:\Users\Tomas\Desktop\SoftonicDownloader_for_windows-vista-service-pack-2.exe (PUP.ToolbarDownloader) -> Žádná instrukce nebyla provedena.
C:\Users\Tomas\Desktop\SoftonicDownloader_para_service-pack-2-para-windows-vista.exe (PUP.ToolbarDownloader) -> Žádná instrukce nebyla provedena.
C:\Windows\KMSEmulator.exe (RiskWare.Tool.CK) -> Žádná instrukce nebyla provedena.

(konec)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod jaro3 » 26 črc 2012 21:45

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Můžeš sem pak vložit nový log z MbAM.

Stáhni si TDSSKiller

Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 26 črc 2012 22:45

! MbAM !

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org

Verze databáze: v2012.07.26.14

Windows Vista Service Pack 1 x64 NTFS
Internet Explorer 7.0.6001.18000
Tomas :: TOMAS-PC [administrátor]

Ochrana: Povolena

26.7.2012 21:48:31
mbam-log-2012-07-26 (21-48-31).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 189556
Uplynulý čas: 2 minut, 8 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 3
C:\Users\Tomas\Desktop\SoftonicDownloader_for_windows-vista-service-pack-2.exe (PUP.ToolbarDownloader) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Tomas\Desktop\SoftonicDownloader_para_service-pack-2-para-windows-vista.exe (PUP.ToolbarDownloader) -> Umístnění do karantény a smazání se zdařilo.
C:\Windows\KMSEmulator.exe (RiskWare.Tool.CK) -> Umístnění do karantény a smazání se zdařilo.

(konec)
___________________________________________________________________________
! TDSSKiller !

21:53:10.0147 1864 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
21:53:12.0149 1864 ============================================================
21:53:12.0149 1864 Current date / time: 2012/07/26 21:53:12.0149
21:53:12.0149 1864 SystemInfo:
21:53:12.0149 1864
21:53:12.0149 1864 OS Version: 6.0.6001 ServicePack: 1.0
21:53:12.0149 1864 Product type: Workstation
21:53:12.0149 1864 ComputerName: TOMAS-PC
21:53:12.0149 1864 UserName: Tomas
21:53:12.0149 1864 Windows directory: C:\Windows
21:53:12.0149 1864 System windows directory: C:\Windows
21:53:12.0149 1864 Running under WOW64
21:53:12.0149 1864 Processor architecture: Intel x64
21:53:12.0149 1864 Number of processors: 4
21:53:12.0149 1864 Page size: 0x1000
21:53:12.0149 1864 Boot type: Normal boot
21:53:12.0149 1864 ============================================================
21:53:14.0491 1864 Drive \Device\Harddisk0\DR0 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:53:14.0495 1864 ============================================================
21:53:14.0495 1864 \Device\Harddisk0\DR0:
21:53:14.0496 1864 MBR partitions:
21:53:14.0496 1864 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x186A0000
21:53:14.0496 1864 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x186A0800, BlocksNum 0x21CE4000
21:53:14.0496 1864 ============================================================
21:53:14.0518 1864 C: <-> \Device\Harddisk0\DR0\Partition0
21:53:14.0643 1864 D: <-> \Device\Harddisk0\DR0\Partition1
21:53:14.0643 1864 ============================================================
21:53:14.0643 1864 Initialize success
21:53:14.0643 1864 ============================================================
21:53:21.0443 3728 ============================================================
21:53:21.0443 3728 Scan started
21:53:21.0443 3728 Mode: Manual;
21:53:21.0443 3728 ============================================================
21:53:23.0137 3728 ACPI (8c99ed256a889d647935a97c543b7b85) C:\Windows\system32\drivers\acpi.sys
21:53:23.0143 3728 ACPI - ok
21:53:23.0256 3728 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:53:23.0257 3728 AdobeARMservice - ok
21:53:23.0563 3728 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:53:23.0581 3728 AdobeFlashPlayerUpdateSvc - ok
21:53:23.0653 3728 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
21:53:23.0661 3728 adp94xx - ok
21:53:23.0693 3728 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
21:53:23.0706 3728 adpahci - ok
21:53:23.0715 3728 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
21:53:23.0717 3728 adpu160m - ok
21:53:23.0729 3728 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
21:53:23.0732 3728 adpu320 - ok
21:53:23.0765 3728 AeLookupSvc (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
21:53:23.0766 3728 AeLookupSvc - ok
21:53:23.0811 3728 AFD (9bb97042fa331a0fb4bdd98b9280a50a) C:\Windows\system32\drivers\afd.sys
21:53:23.0823 3728 AFD - ok
21:53:23.0847 3728 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
21:53:23.0849 3728 agp440 - ok
21:53:23.0876 3728 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
21:53:23.0878 3728 aic78xx - ok
21:53:23.0885 3728 ALG (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
21:53:23.0887 3728 ALG - ok
21:53:23.0891 3728 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
21:53:23.0892 3728 aliide - ok
21:53:23.0897 3728 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
21:53:23.0898 3728 amdide - ok
21:53:23.0952 3728 amdide64 (d52a2e98c5eeff88ced28793b6b04d84) C:\Windows\system32\DRIVERS\amdide64.sys
21:53:23.0954 3728 amdide64 - ok
21:53:23.0963 3728 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
21:53:23.0965 3728 AmdK8 - ok
21:53:24.0184 3728 AntiVirFirewallService (6b4479e48bffbc52fc97a16ddb3f4526) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
21:53:24.0194 3728 AntiVirFirewallService - ok
21:53:24.0236 3728 AntiVirMailService (fa9cf5a058732cf518eb62104ff56d5b) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
21:53:24.0239 3728 AntiVirMailService - ok
21:53:24.0277 3728 AntiVirSchedulerService (a0cca65a17ff3d110c4c63ed1570daa7) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
21:53:24.0278 3728 AntiVirSchedulerService - ok
21:53:24.0303 3728 AntiVirService (04972a4491de1f7f098f3e48ad550d3b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
21:53:24.0304 3728 AntiVirService - ok
21:53:24.0340 3728 AntiVirWebService (c3377384082bb2b278895e209b7dbd5a) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
21:53:24.0343 3728 AntiVirWebService - ok
21:53:24.0624 3728 Appinfo (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
21:53:24.0626 3728 Appinfo - ok
21:53:24.0704 3728 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
21:53:24.0706 3728 arc - ok
21:53:24.0738 3728 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
21:53:24.0741 3728 arcsas - ok
21:53:24.0759 3728 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
21:53:24.0760 3728 AsyncMac - ok
21:53:24.0767 3728 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
21:53:24.0768 3728 atapi - ok
21:53:24.0863 3728 Ati External Event Utility (aacb4e6173ef832dd76b2833b8035395) C:\Windows\system32\Ati2evxx.exe
21:53:24.0879 3728 Ati External Event Utility - ok
21:53:25.0411 3728 atikmdag (6d88ada1d1ebd75e075ae167408a425c) C:\Windows\system32\DRIVERS\atikmdag.sys
21:53:25.0492 3728 atikmdag - ok
21:53:25.0708 3728 AtiPcie (db0d3de15edc96e7529fc0d3f7760894) C:\Windows\system32\DRIVERS\AtiPcie.sys
21:53:25.0709 3728 AtiPcie - ok
21:53:25.0774 3728 AudioEndpointBuilder (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll
21:53:25.0783 3728 AudioEndpointBuilder - ok
21:53:25.0792 3728 AudioSrv (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll
21:53:25.0798 3728 AudioSrv - ok
21:53:25.0848 3728 avfwim (886ceddeb9e347f7c37263ca234eae65) C:\Windows\system32\DRIVERS\avfwim.sys
21:53:25.0850 3728 avfwim - ok
21:53:25.0908 3728 avfwot (10ce27cb8e47feb48f557e0cd8d1874d) C:\Windows\system32\DRIVERS\avfwot.sys
21:53:25.0910 3728 avfwot - ok
21:53:25.0931 3728 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys
21:53:25.0933 3728 avgntflt - ok
21:53:25.0963 3728 avipbb (d959309ececca73fc79f8ef8521346b2) C:\Windows\system32\DRIVERS\avipbb.sys
21:53:25.0966 3728 avipbb - ok
21:53:25.0987 3728 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
21:53:25.0988 3728 avkmgr - ok
21:53:26.0054 3728 BFE (bc4737aaffa5964e4f8827c9b8c0eb8e) C:\Windows\System32\bfe.dll
21:53:26.0084 3728 BFE - ok
21:53:26.0162 3728 BITS (d896a0d43f8ab81ecb1fc6c24decfd58) C:\Windows\System32\qmgr.dll
21:53:26.0179 3728 BITS - ok
21:53:26.0299 3728 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
21:53:26.0301 3728 blbdrive - ok
21:53:26.0336 3728 bowser (f0f035fcec3554cc1b70c5611bd87951) C:\Windows\system32\DRIVERS\bowser.sys
21:53:26.0338 3728 bowser - ok
21:53:26.0361 3728 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
21:53:26.0362 3728 BrFiltLo - ok
21:53:26.0369 3728 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
21:53:26.0370 3728 BrFiltUp - ok
21:53:26.0399 3728 Browser (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
21:53:26.0401 3728 Browser - ok
21:53:26.0410 3728 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
21:53:26.0413 3728 Brserid - ok
21:53:26.0421 3728 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
21:53:26.0422 3728 BrSerWdm - ok
21:53:26.0438 3728 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
21:53:26.0440 3728 BrUsbMdm - ok
21:53:26.0447 3728 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
21:53:26.0448 3728 BrUsbSer - ok
21:53:26.0459 3728 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
21:53:26.0461 3728 BTHMODEM - ok
21:53:26.0472 3728 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
21:53:26.0475 3728 cdfs - ok
21:53:26.0485 3728 cdrom (3b2fb35363423ed60c8fbf15fc8680bd) C:\Windows\system32\DRIVERS\cdrom.sys
21:53:26.0487 3728 cdrom - ok
21:53:26.0511 3728 CertPropSvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll
21:53:26.0513 3728 CertPropSvc - ok
21:53:26.0519 3728 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
21:53:26.0521 3728 circlass - ok
21:53:26.0554 3728 CLFS (caeda2572b7042b11062f327f099251d) C:\Windows\system32\CLFS.sys
21:53:26.0566 3728 CLFS - ok
21:53:26.0685 3728 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:53:26.0687 3728 clr_optimization_v2.0.50727_32 - ok
21:53:26.0745 3728 clr_optimization_v2.0.50727_64 (fa58b51ed71c9133e141164eaa7c54eb) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:53:26.0747 3728 clr_optimization_v2.0.50727_64 - ok
21:53:26.0899 3728 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:53:26.0901 3728 clr_optimization_v4.0.30319_32 - ok
21:53:26.0950 3728 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:53:26.0954 3728 clr_optimization_v4.0.30319_64 - ok
21:53:27.0004 3728 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
21:53:27.0006 3728 cmdide - ok
21:53:27.0014 3728 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
21:53:27.0016 3728 Compbatt - ok
21:53:27.0023 3728 COMSysApp - ok
21:53:27.0034 3728 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
21:53:27.0036 3728 crcdisk - ok
21:53:27.0083 3728 CryptSvc (4374f784121d8b3bb466b03f5e5ebd33) C:\Windows\system32\cryptsvc.dll
21:53:27.0088 3728 CryptSvc - ok
21:53:27.0257 3728 DcomLaunch (52cdade8289ff21f1f2215ff51a5f36c) C:\Windows\system32\rpcss.dll
21:53:27.0271 3728 DcomLaunch - ok
21:53:27.0316 3728 DfsC (3725c43c9e90731eca651d506cc599a3) C:\Windows\system32\Drivers\dfsc.sys
21:53:27.0318 3728 DfsC - ok
21:53:27.0545 3728 DFSR (1781f99840979ee7b126c9073c377fd0) C:\Windows\system32\DFSR.exe
21:53:27.0656 3728 DFSR - ok
21:53:27.0754 3728 Dhcp (fdaa0edfcfb70cd529589ad654651b40) C:\Windows\System32\dhcpcsvc.dll
21:53:27.0772 3728 Dhcp - ok
21:53:27.0816 3728 disk (2dc415fc05fb8a079f896cbbacb19324) C:\Windows\system32\drivers\disk.sys
21:53:27.0818 3728 disk - ok
21:53:27.0846 3728 Dnscache (daf05293c1264e251d3a25e7e24b2ddf) C:\Windows\System32\dnsrslvr.dll
21:53:27.0849 3728 Dnscache - ok
21:53:27.0878 3728 dot3svc (cc661867677627f2911c2a4970dee0f1) C:\Windows\System32\dot3svc.dll
21:53:27.0888 3728 dot3svc - ok
21:53:27.0921 3728 DPS (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
21:53:27.0924 3728 DPS - ok
21:53:27.0940 3728 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
21:53:27.0941 3728 drmkaud - ok
21:53:28.0004 3728 DXGKrnl (412964040ce920ff83aff6b5b551bf99) C:\Windows\System32\drivers\dxgkrnl.sys
21:53:28.0027 3728 DXGKrnl - ok
21:53:28.0066 3728 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
21:53:28.0071 3728 E1G60 - ok
21:53:28.0089 3728 EapHost (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
21:53:28.0092 3728 EapHost - ok
21:53:28.0117 3728 Ecache (7343d950a34a95dcb7441642e3e6beef) C:\Windows\system32\drivers\ecache.sys
21:53:28.0120 3728 Ecache - ok
21:53:28.0259 3728 ehRecvr (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
21:53:28.0262 3728 ehRecvr - ok
21:53:28.0333 3728 ehSched (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
21:53:28.0336 3728 ehSched - ok
21:53:28.0355 3728 ehstart (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
21:53:28.0356 3728 ehstart - ok
21:53:28.0395 3728 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\Windows\system32\Drivers\ElbyCDIO.sys
21:53:28.0396 3728 ElbyCDIO - ok
21:53:28.0446 3728 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
21:53:28.0491 3728 elxstor - ok
21:53:28.0545 3728 EMDMgmt (e4eb76d0a8fc43db7f36302e1f33791f) C:\Windows\system32\emdmgmt.dll
21:53:28.0562 3728 EMDMgmt - ok
21:53:28.0569 3728 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
21:53:28.0571 3728 ErrDev - ok
21:53:28.0644 3728 EventSystem (6b1a97bf9fefbdc83f3c7c7d0f826c66) C:\Windows\system32\es.dll
21:53:28.0650 3728 EventSystem - ok
21:53:28.0661 3728 exfat (2a546b9a84658b0554b1ec35cd9adaf5) C:\Windows\system32\drivers\exfat.sys
21:53:28.0664 3728 exfat - ok
21:53:28.0676 3728 fastfat (fe731d345ed9eeabbc72a59b35941834) C:\Windows\system32\drivers\fastfat.sys
21:53:28.0679 3728 fastfat - ok
21:53:28.0695 3728 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
21:53:28.0696 3728 fdc - ok
21:53:28.0713 3728 fdPHost (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
21:53:28.0714 3728 fdPHost - ok
21:53:28.0720 3728 FDResPub (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
21:53:28.0722 3728 FDResPub - ok
21:53:28.0728 3728 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
21:53:28.0730 3728 FileInfo - ok
21:53:28.0737 3728 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
21:53:28.0738 3728 Filetrace - ok
21:53:28.0743 3728 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
21:53:28.0745 3728 flpydisk - ok
21:53:28.0768 3728 FltMgr (7dacf1a3a4219575070c6dc7c957428a) C:\Windows\system32\drivers\fltmgr.sys
21:53:28.0772 3728 FltMgr - ok
21:53:28.0901 3728 FontCache3.0.0.0 (73d0f1d32edae3dcc4e84468bf910add) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:53:28.0904 3728 FontCache3.0.0.0 - ok
21:53:28.0911 3728 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
21:53:28.0913 3728 Fs_Rec - ok
21:53:28.0925 3728 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
21:53:28.0927 3728 gagp30kx - ok
21:53:28.0967 3728 gdrv (f51fb25e1328fa14f446a8b24ac52709) C:\Windows\gdrv.sys
21:53:28.0968 3728 gdrv - ok
21:53:29.0068 3728 gpsvc (9e5b254d58232ec8921ec3c5a94c81ed) C:\Windows\System32\gpsvc.dll
21:53:29.0100 3728 gpsvc - ok
21:53:29.0251 3728 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:53:29.0255 3728 gupdate - ok
21:53:29.0260 3728 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:53:29.0262 3728 gupdatem - ok
21:53:29.0329 3728 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
21:53:29.0336 3728 HdAudAddService - ok
21:53:29.0384 3728 HDAudBus (0c0d0f8a3ff09ecc81963d09ec6a0a84) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:53:29.0385 3728 HDAudBus - ok
21:53:29.0391 3728 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
21:53:29.0393 3728 HidBth - ok
21:53:29.0412 3728 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
21:53:29.0414 3728 HidIr - ok
21:53:29.0436 3728 hidserv (0aa154538544e988429da2d5aa803a6c) C:\Windows\system32\hidserv.dll
21:53:29.0438 3728 hidserv - ok
21:53:29.0446 3728 HidUsb (d02c82cb3a20f391c8aeff94e8e0baa1) C:\Windows\system32\DRIVERS\hidusb.sys
21:53:29.0448 3728 HidUsb - ok
21:53:29.0467 3728 hkmsvc (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
21:53:29.0472 3728 hkmsvc - ok
21:53:29.0491 3728 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
21:53:29.0493 3728 HpCISSs - ok
21:53:29.0554 3728 HTTP (e690736da6c543f5d99c8fa27bea31db) C:\Windows\system32\drivers\HTTP.sys
21:53:29.0567 3728 HTTP - ok
21:53:29.0575 3728 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
21:53:29.0576 3728 i2omp - ok
21:53:29.0596 3728 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
21:53:29.0598 3728 i8042prt - ok
21:53:29.0625 3728 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
21:53:29.0630 3728 iaStorV - ok
21:53:29.0755 3728 idsvc (76ea63cdb2d88dae7209691d089bef1d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:53:29.0780 3728 idsvc - ok
21:53:29.0785 3728 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
21:53:29.0787 3728 iirsp - ok
21:53:29.0837 3728 IKEEXT (3a3b232140c33376e134e7b61a0eaa44) C:\Windows\System32\ikeext.dll
21:53:29.0848 3728 IKEEXT - ok
21:53:30.0281 3728 IntcAzAudAddService (46cb3abe8150e7b181e86d4906de17e8) C:\Windows\system32\drivers\RTKVHD64.sys
21:53:30.0312 3728 IntcAzAudAddService - ok
21:53:30.0557 3728 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
21:53:30.0559 3728 intelide - ok
21:53:30.0584 3728 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
21:53:30.0587 3728 intelppm - ok
21:53:30.0617 3728 IPBusEnum (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
21:53:30.0622 3728 IPBusEnum - ok
21:53:30.0633 3728 IpFilterDriver (99b821f5bebd6a3cc3fe564f802ae0fd) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:53:30.0635 3728 IpFilterDriver - ok
21:53:30.0683 3728 iphlpsvc (3a0427f35e7f8c16bbc5b1be32b8de76) C:\Windows\System32\iphlpsvc.dll
21:53:30.0691 3728 iphlpsvc - ok
21:53:30.0696 3728 IpInIp - ok
21:53:30.0706 3728 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
21:53:30.0708 3728 IPMIDRV - ok
21:53:30.0762 3728 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
21:53:30.0776 3728 IPNAT - ok
21:53:30.0809 3728 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
21:53:30.0812 3728 IRENUM - ok
21:53:30.0834 3728 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
21:53:30.0835 3728 isapnp - ok
21:53:30.0898 3728 iScsiPrt (49e4ccbf74783fce5d2cc1ff6480e1f4) C:\Windows\system32\DRIVERS\msiscsi.sys
21:53:30.0902 3728 iScsiPrt - ok
21:53:30.0907 3728 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
21:53:30.0908 3728 iteatapi - ok
21:53:30.0940 3728 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
21:53:30.0941 3728 iteraid - ok
21:53:30.0946 3728 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
21:53:30.0947 3728 kbdclass - ok
21:53:30.0952 3728 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys
21:53:30.0966 3728 kbdhid - ok
21:53:30.0992 3728 KeyIso (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe
21:53:30.0994 3728 KeyIso - ok
21:53:31.0048 3728 KSecDD (ccdcce6224e1e207e953af826b98a9d9) C:\Windows\system32\Drivers\ksecdd.sys
21:53:31.0100 3728 KSecDD - ok
21:53:31.0105 3728 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
21:53:31.0106 3728 ksthunk - ok
21:53:31.0313 3728 KtmRm (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
21:53:31.0374 3728 KtmRm - ok
21:53:31.0417 3728 LanmanServer (3f27c9cdae606d74431e3ab39571a7f3) C:\Windows\system32\srvsvc.dll
21:53:31.0426 3728 LanmanServer - ok
21:53:31.0501 3728 LanmanWorkstation (6e25ffc6fead6544c6e9f1d23329570c) C:\Windows\System32\wkssvc.dll
21:53:31.0507 3728 LanmanWorkstation - ok
21:53:31.0546 3728 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
21:53:31.0549 3728 lltdio - ok
21:53:31.0588 3728 lltdsvc (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
21:53:31.0615 3728 lltdsvc - ok
21:53:31.0620 3728 lmhosts (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
21:53:31.0623 3728 lmhosts - ok
21:53:31.0645 3728 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
21:53:31.0647 3728 LSI_FC - ok
21:53:31.0656 3728 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
21:53:31.0660 3728 LSI_SAS - ok
21:53:31.0669 3728 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
21:53:31.0671 3728 LSI_SCSI - ok
21:53:31.0680 3728 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
21:53:31.0682 3728 luafv - ok
21:53:31.0728 3728 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
21:53:31.0728 3728 MBAMProtector - ok
21:53:31.0886 3728 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:53:31.0891 3728 MBAMService - ok
21:53:31.0948 3728 Mcx2Svc (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
21:53:31.0951 3728 Mcx2Svc - ok
21:53:31.0982 3728 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
21:53:31.0984 3728 megasas - ok
21:53:32.0009 3728 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
21:53:32.0015 3728 MegaSR - ok
21:53:32.0117 3728 Microsoft SharePoint Workspace Audit Service - ok
21:53:32.0194 3728 MMCSS (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
21:53:32.0195 3728 MMCSS - ok
21:53:32.0202 3728 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
21:53:32.0203 3728 Modem - ok
21:53:32.0222 3728 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
21:53:32.0224 3728 monitor - ok
21:53:32.0230 3728 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
21:53:32.0231 3728 mouclass - ok
21:53:32.0236 3728 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
21:53:32.0237 3728 mouhid - ok
21:53:32.0244 3728 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
21:53:32.0246 3728 MountMgr - ok
21:53:32.0354 3728 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:53:32.0355 3728 MozillaMaintenance - ok
21:53:32.0377 3728 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
21:53:32.0380 3728 mpio - ok
21:53:32.0387 3728 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
21:53:32.0389 3728 mpsdrv - ok
21:53:32.0430 3728 MpsSvc (8a670648c755867a3aa38da50ba569aa) C:\Windows\system32\mpssvc.dll
21:53:32.0449 3728 MpsSvc - ok
21:53:32.0457 3728 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
21:53:32.0458 3728 Mraid35x - ok
21:53:32.0471 3728 MRxDAV (fe2706c15f8345c342820e4e4583fea0) C:\Windows\system32\drivers\mrxdav.sys
21:53:32.0475 3728 MRxDAV - ok
21:53:32.0507 3728 mrxsmb (b698eb9acc7ecd4927d99d268918f912) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:53:32.0510 3728 mrxsmb - ok
21:53:32.0541 3728 mrxsmb10 (9a797e27fd28500ee13d43000c931435) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:53:32.0554 3728 mrxsmb10 - ok
21:53:32.0599 3728 mrxsmb20 (f9425d610712533107a264e2d5b2154b) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:53:32.0601 3728 mrxsmb20 - ok
21:53:32.0606 3728 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
21:53:32.0608 3728 msahci - ok
21:53:32.0741 3728 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
21:53:32.0763 3728 msdsm - ok
21:53:32.0776 3728 MSDTC (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
21:53:32.0780 3728 MSDTC - ok
21:53:32.0800 3728 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
21:53:32.0802 3728 Msfs - ok
21:53:32.0811 3728 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
21:53:32.0813 3728 msisadrv - ok
21:53:32.0844 3728 MSiSCSI (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
21:53:32.0855 3728 MSiSCSI - ok
21:53:32.0859 3728 msiserver - ok
21:53:32.0891 3728 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
21:53:32.0893 3728 MSKSSRV - ok
21:53:32.0899 3728 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
21:53:32.0901 3728 MSPCLOCK - ok
21:53:32.0917 3728 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
21:53:32.0918 3728 MSPQM - ok
21:53:32.0943 3728 MsRPC (b8e32e6103fbba9fbb1d0c11ff0d13b5) C:\Windows\system32\drivers\MsRPC.sys
21:53:32.0950 3728 MsRPC - ok
21:53:32.0964 3728 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
21:53:32.0966 3728 mssmbios - ok
21:53:32.0973 3728 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
21:53:32.0975 3728 MSTEE - ok
21:53:32.0986 3728 Mup (ddf133501f68d6988a0f55dfa88637b4) C:\Windows\system32\Drivers\mup.sys
21:53:32.0989 3728 Mup - ok
21:53:33.0028 3728 napagent (c25022cdd18980846973b598900915f8) C:\Windows\system32\qagentRT.dll
21:53:33.0039 3728 napagent - ok
21:53:33.0108 3728 NativeWifiP (73b99c98fa3a2ed1566e02d6fe1913a5) C:\Windows\system32\DRIVERS\nwifi.sys
21:53:33.0112 3728 NativeWifiP - ok
21:53:33.0171 3728 NDIS (2a2ee457af36c5c9a6808c768bd3a12b) C:\Windows\system32\drivers\ndis.sys
21:53:33.0189 3728 NDIS - ok
21:53:33.0194 3728 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
21:53:33.0196 3728 NdisTapi - ok
21:53:33.0200 3728 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
21:53:33.0201 3728 Ndisuio - ok
21:53:33.0211 3728 NdisWan (52e3e8e35101399be9b2938c992aa087) C:\Windows\system32\DRIVERS\ndiswan.sys
21:53:33.0214 3728 NdisWan - ok
21:53:33.0220 3728 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
21:53:33.0221 3728 NDProxy - ok
21:53:33.0239 3728 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
21:53:33.0241 3728 NetBIOS - ok
21:53:33.0271 3728 netbt (7a29ca243a629230799754162d80120f) C:\Windows\system32\DRIVERS\netbt.sys
21:53:33.0275 3728 netbt - ok
21:53:33.0292 3728 Netlogon (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe
21:53:33.0294 3728 Netlogon - ok
21:53:33.0330 3728 Netman (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
21:53:33.0344 3728 Netman - ok
21:53:33.0386 3728 netprofm (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
21:53:33.0401 3728 netprofm - ok
21:53:33.0505 3728 NetTcpPortSharing (b84613b469b98e09f50a748c1d02e132) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:53:33.0508 3728 NetTcpPortSharing - ok
21:53:33.0574 3728 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
21:53:33.0576 3728 nfrd960 - ok
21:53:33.0610 3728 NlaSvc (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
21:53:33.0619 3728 NlaSvc - ok
21:53:33.0635 3728 Npfs (b06154e2a2c91e9be5599fca53bc4cd0) C:\Windows\system32\drivers\Npfs.sys
21:53:33.0637 3728 Npfs - ok
21:53:33.0661 3728 nsi (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll
21:53:33.0665 3728 nsi - ok
21:53:33.0669 3728 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
21:53:33.0670 3728 nsiproxy - ok
21:53:33.0803 3728 Ntfs (fe86ba5ac3b50e2ca911e9c60c07b638) C:\Windows\system32\drivers\Ntfs.sys
21:53:33.0845 3728 Ntfs - ok
21:53:33.0987 3728 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
21:53:34.0002 3728 Null - ok
21:53:34.0015 3728 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
21:53:34.0023 3728 nvraid - ok
21:53:34.0032 3728 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
21:53:34.0040 3728 nvstor - ok
21:53:34.0054 3728 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
21:53:34.0078 3728 nv_agp - ok
21:53:34.0085 3728 NwlnkFlt - ok
21:53:34.0094 3728 NwlnkFwd - ok
21:53:34.0123 3728 ohci1394 (1b30103fde512915a9214b108b6e7a9c) C:\Windows\system32\DRIVERS\ohci1394.sys
21:53:34.0125 3728 ohci1394 - ok
21:53:34.0212 3728 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:53:34.0214 3728 ose64 - ok
21:53:34.0732 3728 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:53:34.0781 3728 osppsvc - ok
21:53:35.0063 3728 p2pimsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
21:53:35.0101 3728 p2pimsvc - ok
21:53:35.0112 3728 p2psvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
21:53:35.0120 3728 p2psvc - ok
21:53:35.0230 3728 PanService (20bd38241edd66d8fdc9e3496a1762a3) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
21:53:35.0246 3728 PanService - ok
21:53:35.0345 3728 Parport (4c6a7fd04ddf4db88791048382e3edb1) C:\Windows\system32\DRIVERS\parport.sys
21:53:35.0348 3728 Parport - ok
21:53:35.0385 3728 partmgr (5ab40c36894f4c06bdab0c9a2fba282d) C:\Windows\system32\drivers\partmgr.sys
21:53:35.0387 3728 partmgr - ok
21:53:35.0422 3728 PcaSvc (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll
21:53:35.0427 3728 PcaSvc - ok
21:53:35.0440 3728 pci (2a5b2a51559066ea84742909b5b2cd69) C:\Windows\system32\drivers\pci.sys
21:53:35.0443 3728 pci - ok
21:53:35.0456 3728 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
21:53:35.0458 3728 pciide - ok
21:53:35.0474 3728 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
21:53:35.0481 3728 pcmcia - ok
21:53:35.0568 3728 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
21:53:35.0585 3728 PEAUTH - ok
21:53:35.0674 3728 PerfHost (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe
21:53:35.0675 3728 PerfHost - ok
21:53:36.0026 3728 pla (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll
21:53:36.0069 3728 pla - ok
21:53:36.0110 3728 PlugPlay (5aaa0c5534b05ed49919fcd9dbd11a5b) C:\Windows\system32\umpnpmgr.dll
21:53:36.0124 3728 PlugPlay - ok
21:53:36.0138 3728 PnkBstrA - ok
21:53:36.0198 3728 PNRPAutoReg (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
21:53:36.0206 3728 PNRPAutoReg - ok
21:53:36.0218 3728 PNRPsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
21:53:36.0225 3728 PNRPsvc - ok
21:53:36.0318 3728 PolicyAgent (eef3688d5e9592cbbbed00de71dda1ef) C:\Windows\System32\ipsecsvc.dll
21:53:36.0340 3728 PolicyAgent - ok
21:53:36.0497 3728 PptpMiniport (f5739f2c6db2534c384ad5150808e8f5) C:\Windows\system32\DRIVERS\raspptp.sys
21:53:36.0511 3728 PptpMiniport - ok
21:53:36.0534 3728 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\DRIVERS\processr.sys
21:53:36.0537 3728 Processor - ok
21:53:36.0563 3728 ProfSvc (b21fe10dad3ab59e78df7aa3fbf41e70) C:\Windows\system32\profsvc.dll
21:53:36.0573 3728 ProfSvc - ok
21:53:36.0601 3728 ProtectedStorage (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe
21:53:36.0602 3728 ProtectedStorage - ok
21:53:36.0633 3728 PSched (0e0e205a296095fe4c631e6a4775ad6c) C:\Windows\system32\DRIVERS\pacer.sys
21:53:36.0635 3728 PSched - ok
21:53:36.0754 3728 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
21:53:36.0800 3728 ql2300 - ok
21:53:36.0814 3728 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
21:53:36.0817 3728 ql40xx - ok
21:53:36.0844 3728 QWAVE (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll
21:53:36.0859 3728 QWAVE - ok
21:53:36.0864 3728 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
21:53:36.0865 3728 QWAVEdrv - ok
21:53:36.0869 3728 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
21:53:36.0870 3728 RasAcd - ok
21:53:36.0902 3728 RasAuto (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll
21:53:36.0905 3728 RasAuto - ok
21:53:36.0921 3728 Rasl2tp (3b9085f91ef00abd15a6f36570e90e12) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:53:36.0924 3728 Rasl2tp - ok
21:53:36.0948 3728 RasMan (2a63d46b01685fd4be9778ca3c231c2d) C:\Windows\System32\rasmans.dll
21:53:36.0963 3728 RasMan - ok
21:53:36.0971 3728 RasPppoe (2ce1703c27196094fb6e4c6e439f2c21) C:\Windows\system32\DRIVERS\raspppoe.sys
21:53:36.0973 3728 RasPppoe - ok
21:53:36.0985 3728 RasSstp (fcd04fa67e8b40fa0ad361dd38593942) C:\Windows\system32\DRIVERS\rassstp.sys
21:53:36.0987 3728 RasSstp - ok
21:53:37.0004 3728 rdbss (33fa5b6136d92ee0f53f021c79091300) C:\Windows\system32\DRIVERS\rdbss.sys
21:53:37.0008 3728 rdbss - ok
21:53:37.0014 3728 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:53:37.0016 3728 RDPCDD - ok
21:53:37.0073 3728 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
21:53:37.0078 3728 rdpdr - ok
21:53:37.0082 3728 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
21:53:37.0084 3728 RDPENCDD - ok
21:53:37.0101 3728 RDPWD (7747082f672aa2846235c9cea42e2e72) C:\Windows\system32\drivers\RDPWD.sys
21:53:37.0105 3728 RDPWD - ok
21:53:37.0128 3728 RemoteAccess (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll
21:53:37.0131 3728 RemoteAccess - ok
21:53:37.0155 3728 RemoteRegistry (416c611369cbe49074b89cee2f83abef) C:\Windows\system32\regsvc.dll
21:53:37.0164 3728 RemoteRegistry - ok
21:53:37.0185 3728 RpcLocator (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe
21:53:37.0186 3728 RpcLocator - ok
21:53:37.0252 3728 RpcSs (52cdade8289ff21f1f2215ff51a5f36c) C:\Windows\system32\rpcss.dll
21:53:37.0258 3728 RpcSs - ok
21:53:37.0355 3728 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
21:53:37.0358 3728 rspndr - ok
21:53:37.0418 3728 RTHDMIAzAudService (f8da8fc39ce5859c0d8c0fe6524ce465) C:\Windows\system32\drivers\RtHDMIVX.sys
21:53:37.0428 3728 RTHDMIAzAudService - ok
21:53:37.0540 3728 RTL8169 (a2cbe070fba458357acef41c3f3906ca) C:\Windows\system32\DRIVERS\Rtlh64.sys
21:53:37.0554 3728 RTL8169 - ok
21:53:37.0592 3728 SamSs (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe
21:53:37.0595 3728 SamSs - ok
21:53:37.0618 3728 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
21:53:37.0620 3728 sbp2port - ok
21:53:37.0653 3728 SCardSvr (f024d560fea06f8b56d673849eb89ae6) C:\Windows\System32\SCardSvr.dll
21:53:37.0658 3728 SCardSvr - ok
21:53:37.0871 3728 Schedule (ce75d26e0a1106129f4d156851e298ed) C:\Windows\system32\schedsvc.dll
21:53:37.0915 3728 Schedule - ok
21:53:37.0944 3728 SCPolicySvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll
21:53:37.0945 3728 SCPolicySvc - ok
21:53:37.0968 3728 SDRSVC (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll
21:53:37.0979 3728 SDRSVC - ok
21:53:38.0001 3728 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
21:53:38.0003 3728 secdrv - ok
21:53:38.0012 3728 seclogon (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll
21:53:38.0016 3728 seclogon - ok
21:53:38.0036 3728 SENS (90973a64b96cd647ff81c79443618eed) C:\Windows\System32\sens.dll
21:53:38.0041 3728 SENS - ok
21:53:38.0062 3728 Serenum (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
21:53:38.0064 3728 Serenum - ok
21:53:38.0105 3728 Serial (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
21:53:38.0108 3728 Serial - ok
21:53:38.0114 3728 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
21:53:38.0116 3728 sermouse - ok
21:53:38.0131 3728 SessionEnv (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll
21:53:38.0134 3728 SessionEnv - ok
21:53:38.0141 3728 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
21:53:38.0143 3728 sffdisk - ok
21:53:38.0150 3728 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
21:53:38.0151 3728 sffp_mmc - ok
21:53:38.0160 3728 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
21:53:38.0161 3728 sffp_sd - ok
21:53:38.0170 3728 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
21:53:38.0172 3728 sfloppy - ok
21:53:38.0242 3728 SharedAccess (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll
21:53:38.0248 3728 SharedAccess - ok
21:53:38.0306 3728 ShellHWDetection (9235ec680d3db17464b39c7c7decb4dd) C:\Windows\System32\shsvcs.dll
21:53:38.0311 3728 ShellHWDetection - ok
21:53:38.0317 3728 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
21:53:38.0318 3728 SiSRaid2 - ok
21:53:38.0325 3728 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
21:53:38.0327 3728 SiSRaid4 - ok
21:53:38.0493 3728 SkypeUpdate (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files (x86)\Skype\Updater\Updater.exe
21:53:38.0494 3728 SkypeUpdate - ok
21:53:38.0917 3728 slsvc (a301d2cefb4747dfe0c24425dcbe0b78) C:\Windows\system32\SLsvc.exe
21:53:39.0015 3728 slsvc - ok
21:53:39.0396 3728 SLUINotify (f5ddf7c0af85eb72cb295171f8c3cb35) C:\Windows\system32\SLUINotify.dll
21:53:39.0414 3728 SLUINotify - ok
21:53:39.0556 3728 Smb (41eb2e8e005feedcafce301983eff932) C:\Windows\system32\DRIVERS\smb.sys
21:53:39.0585 3728 Smb - ok
21:53:39.0654 3728 SNMPTRAP (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe
21:53:39.0656 3728 SNMPTRAP - ok
21:53:39.0669 3728 spldr (f9cb0672162f7f04248e2b82c1ff4617) C:\Windows\system32\drivers\spldr.sys
21:53:39.0670 3728 spldr - ok
21:53:39.0738 3728 Spooler (92e6738d25c2123be9515c0eac0776cd) C:\Windows\System32\spoolsv.exe
21:53:39.0745 3728 Spooler - ok
21:53:40.0045 3728 srv (a8abd7d0d907b45cf3831f4dd8644349) C:\Windows\system32\DRIVERS\srv.sys
21:53:40.0064 3728 srv - ok
21:53:40.0110 3728 srv2 (6c72eea39e1c37b436a6d1532999f9ec) C:\Windows\system32\DRIVERS\srv2.sys
21:53:40.0119 3728 srv2 - ok
21:53:40.0162 3728 srvnet (7f69bcf9e6fa3d93c82ee6b87812666d) C:\Windows\system32\DRIVERS\srvnet.sys
21:53:40.0165 3728 srvnet - ok
21:53:40.0195 3728 SSDPSRV (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll
21:53:40.0204 3728 SSDPSRV - ok
21:53:40.0230 3728 SstpSvc (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll
21:53:40.0234 3728 SstpSvc - ok
21:53:40.0272 3728 stisvc (f14f7d7d68a66777fb999d5d0f21138d) C:\Windows\System32\wiaservc.dll
21:53:40.0286 3728 stisvc - ok
21:53:40.0312 3728 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
21:53:40.0313 3728 swenum - ok
21:53:40.0345 3728 swprv (da34d6eb4a3154c0bebaeb0a2483ef3e) C:\Windows\System32\swprv.dll
21:53:40.0380 3728 swprv - ok
21:53:40.0385 3728 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
21:53:40.0387 3728 Symc8xx - ok
21:53:40.0392 3728 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
21:53:40.0394 3728 Sym_hi - ok
21:53:40.0399 3728 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
21:53:40.0401 3728 Sym_u3 - ok
21:53:40.0447 3728 SysMain (bea0d5521ed21df8f6ffeed86daede7b) C:\Windows\system32\sysmain.dll
21:53:40.0469 3728 SysMain - ok
21:53:40.0488 3728 TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll
21:53:40.0493 3728 TabletInputService - ok
21:53:40.0531 3728 TapiSrv (52091001caf20ae84cf47023ee21b4bb) C:\Windows\System32\tapisrv.dll
21:53:40.0553 3728 TapiSrv - ok
21:53:40.0585 3728 TBS (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll
21:53:40.0588 3728 TBS - ok
21:53:40.0679 3728 Tcpip (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\drivers\tcpip.sys
21:53:40.0701 3728 Tcpip - ok
21:53:40.0716 3728 Tcpip6 (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\DRIVERS\tcpip.sys
21:53:40.0727 3728 Tcpip6 - ok
21:53:40.0763 3728 tcpipreg (c29d4b3b08ad0b7e8564814e4ff6a57b) C:\Windows\system32\drivers\tcpipreg.sys
21:53:40.0765 3728 tcpipreg - ok
21:53:40.0780 3728 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
21:53:40.0782 3728 TDPIPE - ok
21:53:40.0790 3728 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
21:53:40.0792 3728 TDTCP - ok
21:53:40.0801 3728 tdx (8c39c72e0e853de04748c0337d9b9216) C:\Windows\system32\DRIVERS\tdx.sys
21:53:40.0803 3728 tdx - ok
21:53:40.0810 3728 TermDD (3f0ebf6ee609f2a276c0d5faf244ec90) C:\Windows\system32\DRIVERS\termdd.sys
21:53:40.0812 3728 TermDD - ok
21:53:40.0852 3728 TermService (f870a5589d6a94b426efb13689023946) C:\Windows\System32\termsrv.dll
21:53:40.0869 3728 TermService - ok
21:53:40.0913 3728 Themes (9235ec680d3db17464b39c7c7decb4dd) C:\Windows\system32\shsvcs.dll
21:53:40.0917 3728 Themes - ok
21:53:40.0944 3728 THREADORDER (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
21:53:40.0945 3728 THREADORDER - ok
21:53:40.0961 3728 TrkWks (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll
21:53:40.0964 3728 TrkWks - ok
21:53:40.0984 3728 TrustedInstaller (ac6ff1df22ed90bad6417ee5a4c6e2f0) C:\Windows\servicing\TrustedInstaller.exe
21:53:40.0985 3728 TrustedInstaller - ok
21:53:40.0993 3728 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:53:40.0995 3728 tssecsrv - ok
21:53:41.0008 3728 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
21:53:41.0009 3728 tunmp - ok
21:53:41.0041 3728 tunnel (2dc2c423572946e9a3131425bda73cb6) C:\Windows\system32\DRIVERS\tunnel.sys
21:53:41.0043 3728 tunnel - ok
21:53:41.0050 3728 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
21:53:41.0054 3728 uagp35 - ok
21:53:41.0075 3728 udfs (eca6629e33f122afff18a2ab7c3eb033) C:\Windows\system32\DRIVERS\udfs.sys
21:53:41.0080 3728 udfs - ok
21:53:41.0091 3728 UI0Detect (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe
21:53:41.0093 3728 UI0Detect - ok
21:53:41.0111 3728 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
21:53:41.0113 3728 uliagpkx - ok
21:53:41.0131 3728 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
21:53:41.0135 3728 uliahci - ok
21:53:41.0145 3728 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
21:53:41.0148 3728 UlSata - ok
21:53:41.0159 3728 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
21:53:41.0162 3728 ulsata2 - ok
21:53:41.0168 3728 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
21:53:41.0169 3728 umbus - ok
21:53:41.0194 3728 upnphost (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll
21:53:41.0208 3728 upnphost - ok
21:53:41.0231 3728 usbccgp (66627c6008319def7909f21fb75a8991) C:\Windows\system32\DRIVERS\usbccgp.sys
21:53:41.0233 3728 usbccgp - ok
21:53:41.0240 3728 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
21:53:41.0242 3728 usbcir - ok
21:53:41.0271 3728 usbehci (da6d8d8ed0a53c63ac6f4bd40fe83fbe) C:\Windows\system32\DRIVERS\usbehci.sys
21:53:41.0272 3728 usbehci - ok
21:53:41.0301 3728 usbhub (99045369ae3216216573d0775fd7ed56) C:\Windows\system32\DRIVERS\usbhub.sys
21:53:41.0309 3728 usbhub - ok
21:53:41.0333 3728 usbohci (540b622da0949695c40cdc9d5d497a8b) C:\Windows\system32\DRIVERS\usbohci.sys
21:53:41.0334 3728 usbohci - ok
21:53:41.0339 3728 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys
21:53:41.0340 3728 usbprint - ok
21:53:41.0390 3728 USBSTOR (586d9876a4945779c8eea926c0d16889) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:53:41.0392 3728 USBSTOR - ok
21:53:41.0396 3728 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
21:53:41.0398 3728 usbuhci - ok
21:53:41.0418 3728 UxSms (9190f03c82547afa87367f1ceca88f3b) C:\Windows\System32\uxsms.dll
21:53:41.0423 3728 UxSms - ok
21:53:41.0467 3728 VClone (fd911873c0bb6945fa38c16e9a2b58f9) C:\Windows\system32\DRIVERS\VClone.sys
21:53:41.0469 3728 VClone - ok
21:53:41.0559 3728 vds (c15a4a550cba7b9f1f68b72528e04ce1) C:\Windows\System32\vds.exe
21:53:41.0583 3728 vds - ok
21:53:41.0631 3728 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
21:53:41.0633 3728 vga - ok
21:53:41.0638 3728 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
21:53:41.0639 3728 VgaSave - ok
21:53:41.0660 3728 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
21:53:41.0662 3728 viaide - ok
21:53:41.0673 3728 volmgr (793d9b32a1c462c91f6f70358283ac97) C:\Windows\system32\drivers\volmgr.sys
21:53:41.0675 3728 volmgr - ok
21:53:41.0700 3728 volmgrx (5aa217da5dc4ff5b9ac9ab86563b3223) C:\Windows\system32\drivers\volmgrx.sys
21:53:41.0706 3728 volmgrx - ok
21:53:41.0721 3728 volsnap (de4307412d98050239026e56a7dff3c0) C:\Windows\system32\drivers\volsnap.sys
21:53:41.0725 3728 volsnap - ok
21:53:41.0735 3728 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
21:53:41.0738 3728 vsmraid - ok
21:53:41.0819 3728 VSS (186bd53f8a408ad20f5a056c05678629) C:\Windows\system32\vssvc.exe
21:53:41.0849 3728 VSS - ok
21:53:41.0880 3728 W32Time (ba29f34a61cb55c0dee29e787542edf4) C:\Windows\system32\w32time.dll
21:53:41.0891 3728 W32Time - ok
21:53:41.0922 3728 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
21:53:41.0924 3728 WacomPen - ok
21:53:41.0943 3728 Wanarp (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys
21:53:41.0946 3728 Wanarp - ok
21:53:41.0953 3728 Wanarpv6 (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys
21:53:41.0954 3728 Wanarpv6 - ok
21:53:42.0005 3728 wcncsvc (055449247c490e24b968b44fe8a969eb) C:\Windows\System32\wcncsvc.dll
21:53:42.0026 3728 wcncsvc - ok
21:53:42.0060 3728 WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll
21:53:42.0065 3728 WcsPlugInService - ok
21:53:42.0074 3728 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
21:53:42.0077 3728 Wd - ok
21:53:42.0128 3728 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
21:53:42.0141 3728 Wdf01000 - ok
21:53:42.0153 3728 WdiServiceHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
21:53:42.0158 3728 WdiServiceHost - ok
21:53:42.0162 3728 WdiSystemHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
21:53:42.0164 3728 WdiSystemHost - ok
21:53:42.0192 3728 WebClient (3d4ab55f8178fd0cd3ca45cd0ec9cf5b) C:\Windows\System32\webclnt.dll
21:53:42.0202 3728 WebClient - ok
21:53:42.0239 3728 Wecsvc (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll
21:53:42.0248 3728 Wecsvc - ok
21:53:42.0270 3728 wercplsupport (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll
21:53:42.0273 3728 wercplsupport - ok
21:53:42.0318 3728 WerSvc (fc25242b3bcaf7e84d9184082274ae08) C:\Windows\System32\WerSvc.dll
21:53:42.0322 3728 WerSvc - ok
21:53:42.0360 3728 WinDefend - ok
21:53:42.0367 3728 WinHttpAutoProxySvc - ok
21:53:42.0472 3728 Winmgmt (ac98f38feab066a8f983d54ff3f4fd4c) C:\Windows\system32\wbem\WMIsvc.dll
21:53:42.0500 3728 Winmgmt - ok
21:53:42.0748 3728 WinRM (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll
21:53:42.0817 3728 WinRM - ok
21:53:43.0089 3728 Wlansvc (0a69955261c1b54206adc9beb89517de) C:\Windows\System32\wlansvc.dll
21:53:43.0129 3728 Wlansvc - ok
21:53:43.0226 3728 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys
21:53:43.0228 3728 WmiAcpi - ok
21:53:43.0343 3728 wmiApSrv (d303322dd577c3deda1251ed2e7a496c) C:\Windows\system32\wbem\WmiApSrv.exe
21:53:43.0353 3728 wmiApSrv - ok
21:53:43.0426 3728 WMPNetworkSvc - ok
21:53:43.0502 3728 WPCSvc (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll
21:53:43.0509 3728 WPCSvc - ok
21:53:43.0564 3728 WPDBusEnum (a27c8f92d84e2ddc151978e4692c978e) C:\Windows\system32\wpdbusenum.dll
21:53:43.0576 3728 WPDBusEnum - ok
21:53:43.0607 3728 WpdUsb (6329d1990db931073b86ab5946d8e317) C:\Windows\system32\DRIVERS\wpdusb.sys
21:53:43.0608 3728 WpdUsb - ok
21:53:43.0959 3728 WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:53:43.0968 3728 WPFFontCache_v0400 - ok
21:53:44.0008 3728 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
21:53:44.0010 3728 ws2ifsl - ok
21:53:44.0043 3728 wscsvc (cb8ea6d95949384925ccfca21cc6dfd8) C:\Windows\System32\wscsvc.dll
21:53:44.0047 3728 wscsvc - ok
21:53:44.0051 3728 WSearch - ok
21:53:44.0257 3728 wuauserv (69f2bc7b46e3e15c8ec688f42a65b57f) C:\Windows\system32\wuaueng.dll
21:53:44.0312 3728 wuauserv - ok
21:53:44.0488 3728 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:53:44.0513 3728 WUDFRd - ok
21:53:44.0579 3728 wudfsvc (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll
21:53:44.0585 3728 wudfsvc - ok
21:53:44.0624 3728 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
21:53:45.0079 3728 \Device\Harddisk0\DR0 - ok
21:53:45.0106 3728 Boot (0x1200) (0692382a2fa6ff71d56e053a7c3b8ea4) \Device\Harddisk0\DR0\Partition0
21:53:45.0132 3728 \Device\Harddisk0\DR0\Partition0 - ok
21:53:45.0163 3728 Boot (0x1200) (ba32d2596a101bff8a483799b43e6173) \Device\Harddisk0\DR0\Partition1
21:53:45.0180 3728 \Device\Harddisk0\DR0\Partition1 - ok
21:53:45.0181 3728 ============================================================
21:53:45.0181 3728 Scan finished
21:53:45.0181 3728 ============================================================
21:53:45.0199 4244 Detected object count: 0
21:53:45.0199 4244 Actual detected object count: 0

________________________________________________________________________________________________
! ComboFix !
Nedaří se mi,aby se dokončila úloha.Dokončena fáze 32 a dál to nejde,prostě zásek,několikrát odzkoušeno.Jediný co mi to udělalo,bylo to,že v C:/ se mi udělal "odkaz" na ComboFix s tím,že když najedu kurzorem,vyjede "Zobrazí diskové jednotky a HW připojený k tomuto PC" Po rozkliknutí se otevře to stejný,jako kdyybch otevřel Tento Počítat.

Dále mi navíc po naběhnutí systému vyskočí hláška,kterou jsem tu dosud neměl.
http://www.pixhost.org/show/1480/13542972_chyba.jpg

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod Žbeky » 27 črc 2012 06:20

Zkus combofix v nouzáku
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 27 črc 2012 08:25

Dodávám log z Combofix

ComboFix 12-07-27.02 - Tomas 27.07.2012 8:13.4.4 - x64 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2046.1565 [GMT 2:00]
Spuštěný z: c:\users\Tomas\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: FireWall *Disabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-27 do 2012-07-27 )))))))))))))))))))))))))))))))
.
.
2012-07-27 06:19 . 2012-07-27 06:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-27 02:57 . 2012-07-27 05:18 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-07-26 19:38 . 2012-07-26 19:38 -------- d-----w- c:\programdata\Malwarebytes
2012-07-26 19:38 . 2012-07-26 19:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-26 19:38 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-26 15:43 . 2012-07-27 03:51 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-07-26 15:43 . 2012-07-27 03:51 139360 ----a-w- c:\windows\system32\drivers\avfwot.sys
2012-07-26 15:43 . 2012-07-27 03:51 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-07-26 15:43 . 2012-07-27 03:51 114128 ----a-w- c:\windows\system32\drivers\avfwim.sys
2012-07-26 15:43 . 2011-09-15 21:55 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-07-26 15:43 . 2012-07-26 15:43 -------- d-----w- c:\programdata\Avira
2012-07-26 15:43 . 2012-07-26 15:43 -------- d-----w- c:\program files (x86)\Avira
2012-07-26 12:50 . 2012-07-26 12:50 -------- d-----w- c:\program files\Defraggler
2012-07-24 19:57 . 2012-07-24 19:57 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-07-24 07:36 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0414AE77-DE38-4F13-9C4F-194A921C8A8A}\mpengine.dll
2012-07-24 07:26 . 2012-07-24 07:26 647168 ----a-w- c:\windows\AutoKMS.exe
2012-07-24 07:08 . 2012-07-24 07:08 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\windows\PCHEALTH
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-07-24 07:02 . 2012-07-24 07:02 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-07-24 07:00 . 2012-07-24 07:00 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-07-24 07:00 . 2012-07-24 07:00 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-07-24 06:59 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Office
2012-07-24 06:59 . 2012-07-26 21:30 -------- d-----w- c:\programdata\Microsoft Help
2012-07-24 06:59 . 2012-07-24 06:59 -------- d-----r- C:\MSOCache
2012-07-17 10:51 . 2012-07-17 10:52 -------- d-----w- c:\program files\CCleaner
2012-07-17 10:51 . 2012-07-17 10:51 -------- d-----w- c:\program files (x86)\Google
2012-07-17 10:36 . 2012-07-17 10:36 512 ----a-w- C:\PhysicalMBR.bin
2012-07-12 09:55 . 2012-07-12 09:55 -------- d-----w- c:\program files (x86)\Secure Folder
2012-07-12 09:54 . 2012-07-12 09:54 -------- d-----w- c:\windows\SysWow64\ShellExt
2012-07-10 05:53 . 2012-07-10 05:53 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-07-08 07:19 . 2012-07-08 07:19 -------- d-----w- c:\programdata\Readon
2012-07-03 04:45 . 2010-09-20 12:14 316416 ----a-w- c:\windows\system32\msshsq.dll
2012-07-03 04:45 . 2010-09-20 09:25 231936 ----a-w- c:\windows\SysWow64\msshsq.dll
2012-07-02 06:14 . 2009-08-24 12:24 442368 ----a-w- c:\windows\system32\winhttp.dll
2012-07-02 06:14 . 2009-08-24 12:16 378368 ----a-w- c:\windows\SysWow64\winhttp.dll
2012-07-02 06:14 . 2009-11-04 04:20 32256 ----a-w- c:\windows\system32\drivers\cs-CZ\http.sys.mui
2012-07-02 06:14 . 2010-09-06 16:24 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-07-02 06:14 . 2010-09-06 16:23 17920 ----a-w- c:\windows\SysWow64\netevent.dll
2012-07-02 06:14 . 2010-09-06 15:59 179712 ----a-w- c:\windows\system32\srvsvc.dll
2012-07-02 06:14 . 2010-09-06 15:59 12288 ----a-w- c:\windows\system32\sscore.dll
2012-07-02 06:14 . 2010-09-06 15:57 17920 ----a-w- c:\windows\system32\netevent.dll
2012-07-02 04:33 . 2012-07-24 07:06 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-07-02 04:31 . 2009-11-08 08:55 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-07-02 04:31 . 2009-11-08 08:55 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-07-02 04:31 . 2009-11-08 08:55 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-07-02 04:31 . 2009-11-08 08:55 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-07-02 04:31 . 2009-11-08 08:55 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-07-02 04:31 . 2009-11-08 08:55 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-07-02 04:31 . 2009-11-08 08:55 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-07-02 04:31 . 2009-11-08 08:55 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-07-02 04:31 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-07-02 04:31 . 2009-11-08 08:55 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-07-01 17:17 . 2012-07-01 17:17 250 ----a-w- C:\user.js
2012-07-01 17:17 . 2012-07-01 17:17 -------- d-----w- c:\programdata\Babylon
2012-07-01 17:09 . 2012-07-17 10:59 -------- d-----w- c:\program files (x86)\ChatZum Toolbar
2012-07-01 16:22 . 2012-07-01 16:22 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-07-01 16:22 . 2012-07-01 16:22 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-01 15:31 . 2012-07-01 16:02 -------- d-----w- c:\program files (x86)\Mass Effect 3
2012-07-01 15:21 . 2008-06-20 01:16 49160 ----a-w- c:\windows\system32\infocardcpl.cpl
2012-07-01 15:21 . 2008-06-20 01:14 37384 ----a-w- c:\windows\SysWow64\infocardcpl.cpl
2012-07-01 15:21 . 2008-06-20 01:16 11264 ----a-w- c:\windows\system32\icardres.dll
2012-07-01 15:21 . 2008-06-20 01:14 11264 ----a-w- c:\windows\SysWow64\icardres.dll
2012-07-01 15:20 . 2008-06-20 01:17 1168928 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:16 167432 ----a-w- c:\windows\system32\infocardapi.dll
2012-07-01 15:20 . 2008-06-20 01:14 781344 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:14 97800 ----a-w- c:\windows\SysWow64\infocardapi.dll
2012-07-01 15:20 . 2008-06-20 01:14 622080 ----a-w- c:\windows\SysWow64\icardagt.exe
2012-07-01 15:20 . 2008-06-20 01:16 1383936 ----a-w- c:\windows\system32\icardagt.exe
2012-07-01 15:20 . 2008-06-20 01:17 126520 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:14 105016 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2012-07-01 15:12 . 2008-07-27 18:03 158720 ----a-w- c:\windows\SysWow64\mscorier.dll
2012-07-01 15:12 . 2008-07-27 18:01 158208 ----a-w- c:\windows\system32\mscorier.dll
2012-07-01 15:12 . 2008-07-27 18:01 76288 ----a-w- c:\windows\system32\mscories.dll
2012-07-01 15:12 . 2008-07-27 18:03 83968 ----a-w- c:\windows\SysWow64\mscories.dll
2012-07-01 15:09 . 2010-02-24 09:28 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-07-01 15:05 . 2010-02-20 23:44 32768 ----a-w- c:\windows\system32\nshhttp.dll
2012-07-01 15:05 . 2010-02-20 23:39 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll
2012-07-01 15:05 . 2010-02-20 23:42 33792 ----a-w- c:\windows\system32\httpapi.dll
2012-07-01 15:05 . 2010-02-20 23:37 31232 ----a-w- c:\windows\SysWow64\httpapi.dll
2012-07-01 15:05 . 2010-02-20 21:40 610304 ----a-w- c:\windows\system32\drivers\http.sys
2012-07-01 14:59 . 2010-04-14 18:33 101376 ----a-w- c:\windows\system32\MSNP.ax
2012-07-01 14:59 . 2010-04-14 17:46 80896 ----a-w- c:\windows\SysWow64\MSNP.ax
2012-07-01 14:59 . 2008-04-23 05:05 73216 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-07-01 14:59 . 2008-04-23 04:41 57856 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-07-01 14:59 . 2010-04-14 18:35 375808 ----a-w- c:\windows\system32\psisdecd.dll
2012-07-01 14:59 . 2010-04-14 18:35 289792 ----a-w- c:\windows\system32\psisrndr.ax
2012-07-01 14:59 . 2010-04-14 17:47 293376 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-07-01 14:59 . 2010-04-14 17:47 217088 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-07-01 14:57 . 2009-10-09 21:56 2048 ----a-w- c:\windows\SysWow64\winrsmgr.dll
2012-07-01 14:57 . 2009-10-09 21:35 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2012-07-01 14:57 . 2009-10-09 21:35 13312 ----a-w- c:\windows\system32\wsmplpxy.dll
2012-07-01 14:57 . 2009-10-09 21:34 13312 ----a-w- c:\windows\system32\winrssrv.dll
2012-07-01 14:57 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\wsmplpxy.dll
2012-07-01 14:57 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\winrssrv.dll
2012-07-01 14:46 . 2012-07-01 14:46 -------- d-----w- C:\8915d614d040d981e41a
2012-07-01 14:42 . 2012-07-01 14:42 -------- d-----w- c:\windows\system32\EventProviders
2012-07-01 14:40 . 2008-04-30 05:56 589824 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2012-07-01 14:40 . 2008-04-30 05:36 454656 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadce.dll
2012-07-01 14:30 . 2012-07-01 14:30 -------- d-----w- c:\windows\system32\WindowsPowerShell
2012-07-01 14:30 . 2010-04-05 16:51 84480 ----a-w- c:\windows\system32\asycfilt.dll
2012-07-01 14:30 . 2010-04-05 16:07 67072 ----a-w- c:\windows\SysWow64\asycfilt.dll
2012-07-01 14:21 . 2008-05-30 12:19 511496 ----a-w- c:\windows\system32\XAudio2_1.dll
2012-07-01 13:50 . 2012-07-01 13:50 -------- d-----w- c:\program files (x86)\VideoLAN
2012-07-01 13:35 . 2012-07-01 13:36 -------- d-----w- c:\program files (x86)\The KMPlayer
2012-07-01 13:32 . 2012-07-01 13:32 -------- d-----w- c:\program files (x86)\PANDORA.TV
2012-07-01 12:23 . 2012-07-26 14:53 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-07-01 11:33 . 2012-07-26 14:53 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-07-01 11:33 . 2012-07-01 12:20 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-07-01 11:33 . 2012-07-01 11:51 674600 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-07-01 11:01 . 2012-07-19 14:49 -------- d-----w- c:\programdata\Xfire
2012-07-01 11:01 . 2012-07-01 14:32 -------- d-----w- c:\program files (x86)\Xfire
2012-07-01 10:52 . 2009-09-10 15:48 1486848 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2012-07-01 10:51 . 2010-11-06 04:35 854528 ----a-w- c:\windows\system32\schedsvc.dll
2012-07-01 10:50 . 2010-10-28 13:17 2048 ----a-w- c:\windows\system32\tzres.dll
2012-07-01 10:46 . 2012-05-31 10:25 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-07-01 10:41 . 2010-08-31 15:40 531968 ----a-w- c:\windows\SysWow64\comctl32.dll
2012-07-01 10:41 . 2010-08-31 15:21 633856 ----a-w- c:\windows\system32\comctl32.dll
2012-07-01 10:40 . 2009-04-02 12:39 818688 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-07-01 10:40 . 2009-04-02 12:37 604672 ----a-w- c:\windows\SysWow64\WMSPDMOD.DLL
2012-07-01 10:40 . 2008-06-26 02:25 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2012-07-01 10:40 . 2008-06-26 01:45 12240896 ----a-w- c:\windows\SysWow64\NlsLexicons0007.dll
2012-07-01 10:40 . 2008-06-26 02:25 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 01:00 . 2006-11-02 12:35 59701280 ----a-w- c:\windows\system32\mrt.exe
2012-06-14 20:44 . 2012-06-14 20:44 3826112 ----a-w- C:\chatzum.exe
2012-05-03 02:54 . 2012-05-03 02:54 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-05-03 02:54 . 2012-05-03 02:54 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-06-07 17425072]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-07-27 348624]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 60687391;60687391; [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-16 250056]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ECACHE
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Obsah adresáře 'Naplánované úlohy'
.
2012-07-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 02:26]
.
2012-07-27 c:\windows\Tasks\AutoKMS.job
- c:\windows\AutoKMS.exe [2012-07-24 07:26]
.
2012-07-27 c:\windows\Tasks\AutoKMSDaily.job
- c:\windows\AutoKMS.exe [2012-07-24 07:26]
.
2012-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-17 10:51]
.
2012-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-17 10:51]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-03 6430208]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\fdd1bws4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - uTorrentControl2 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=113665 ... 1fd0a38255
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113665&tt=280612_6_
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - bc32b816000000000000001fd0a38255
FF - user.js: extensions.BabylonToolbar_i.hardId - bc32b816000000000000001fd0a38255
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15522
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1719:17
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Celkový čas: 2012-07-27 08:22:02
ComboFix-quarantined-files.txt 2012-07-27 06:22
.
Před spuštěním: Volných bajtů: 40 260 521 984
Po spuštění: Volných bajtů: 40 040 579 072
.
- - End Of File - - 9BD128CAE8B8FF67CBFA8FE45E09A2AF

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod memphisto » 27 črc 2012 08:55

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::
File::
c:\windows\KMSEmulator.exe
c:\windows\AutoKMS.exe
C:\chatzum.exe
c:\windows\Tasks\AutoKMS.job
c:\windows\Tasks\AutoKMSDaily.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\programdata\Babylon
c:\program files (x86)\ChatZum Toolbar

DirLook::
C:\8915d614d040d981e41a

Firefox::
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\fdd1bws4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - uTorrentControl2 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=113665 ... 1fd0a38255
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113665&tt=280612_6_
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - bc32b816000000000000001fd0a38255
FF - user.js: extensions.BabylonToolbar_i.hardId - bc32b816000000000000001fd0a38255
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15522
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1719:17
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť?.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

junebag
Level 1.5
Level 1.5
Příspěvky: 115
Registrován: červenec 12
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu.

Příspěvekod junebag » 27 črc 2012 12:21

Děláno na dvakrát,poprvé se to zastavilo při vytváření logu.Spuštěno v nouzovém režimu.

Log zde..

ComboFix 12-07-27.02 - Tomas 27.07.2012 12:06:15.7.4 - x64 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2046.1452 [GMT 2:00]
Spuštěný z: c:\users\Tomas\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Tomas\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: FireWall *Disabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\chatzum.exe"
"c:\windows\AutoKMS.exe"
"c:\windows\KMSEmulator.exe"
"c:\windows\Tasks\AutoKMS.job"
"c:\windows\Tasks\AutoKMSDaily.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\chatzum.exe
c:\windows\AutoKMS.exe
c:\windows\KMSEmulator.exe
c:\windows\Tasks\AutoKMS.job
c:\windows\Tasks\AutoKMSDaily.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-27 do 2012-07-27 )))))))))))))))))))))))))))))))
.
.
2012-07-27 10:12 . 2012-07-27 10:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-26 19:38 . 2012-07-26 19:38 -------- d-----w- c:\programdata\Malwarebytes
2012-07-26 19:38 . 2012-07-26 19:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-26 19:38 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-26 15:43 . 2012-07-27 03:51 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-07-26 15:43 . 2012-07-27 03:51 139360 ----a-w- c:\windows\system32\drivers\avfwot.sys
2012-07-26 15:43 . 2012-07-27 03:51 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-07-26 15:43 . 2012-07-27 03:51 114128 ----a-w- c:\windows\system32\drivers\avfwim.sys
2012-07-26 15:43 . 2011-09-15 21:55 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-07-26 15:43 . 2012-07-26 15:43 -------- d-----w- c:\programdata\Avira
2012-07-26 15:43 . 2012-07-26 15:43 -------- d-----w- c:\program files (x86)\Avira
2012-07-26 12:50 . 2012-07-26 12:50 -------- d-----w- c:\program files\Defraggler
2012-07-24 19:57 . 2012-07-24 19:57 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-07-24 07:36 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0414AE77-DE38-4F13-9C4F-194A921C8A8A}\mpengine.dll
2012-07-24 07:08 . 2012-07-24 07:08 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\windows\PCHEALTH
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-07-24 07:06 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-07-24 07:02 . 2012-07-24 07:02 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-07-24 07:00 . 2012-07-24 07:00 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-07-24 07:00 . 2012-07-24 07:00 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-07-24 06:59 . 2012-07-24 07:06 -------- d-----w- c:\program files\Microsoft Office
2012-07-24 06:59 . 2012-07-26 21:30 -------- d-----w- c:\programdata\Microsoft Help
2012-07-24 06:59 . 2012-07-24 06:59 -------- d-----r- C:\MSOCache
2012-07-17 10:51 . 2012-07-17 10:52 -------- d-----w- c:\program files\CCleaner
2012-07-17 10:51 . 2012-07-17 10:51 -------- d-----w- c:\program files (x86)\Google
2012-07-17 10:36 . 2012-07-17 10:36 512 ----a-w- C:\PhysicalMBR.bin
2012-07-12 09:55 . 2012-07-12 09:55 -------- d-----w- c:\program files (x86)\Secure Folder
2012-07-12 09:54 . 2012-07-12 09:54 -------- d-----w- c:\windows\SysWow64\ShellExt
2012-07-10 05:53 . 2012-07-10 05:53 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-07-08 07:19 . 2012-07-08 07:19 -------- d-----w- c:\programdata\Readon
2012-07-03 04:45 . 2010-09-20 12:14 316416 ----a-w- c:\windows\system32\msshsq.dll
2012-07-03 04:45 . 2010-09-20 09:25 231936 ----a-w- c:\windows\SysWow64\msshsq.dll
2012-07-02 06:14 . 2009-08-24 12:24 442368 ----a-w- c:\windows\system32\winhttp.dll
2012-07-02 06:14 . 2009-08-24 12:16 378368 ----a-w- c:\windows\SysWow64\winhttp.dll
2012-07-02 06:14 . 2009-11-04 04:20 32256 ----a-w- c:\windows\system32\drivers\cs-CZ\http.sys.mui
2012-07-02 06:14 . 2010-09-06 16:24 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-07-02 06:14 . 2010-09-06 16:23 17920 ----a-w- c:\windows\SysWow64\netevent.dll
2012-07-02 06:14 . 2010-09-06 15:59 179712 ----a-w- c:\windows\system32\srvsvc.dll
2012-07-02 06:14 . 2010-09-06 15:59 12288 ----a-w- c:\windows\system32\sscore.dll
2012-07-02 06:14 . 2010-09-06 15:57 17920 ----a-w- c:\windows\system32\netevent.dll
2012-07-02 04:33 . 2012-07-24 07:06 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-07-02 04:31 . 2009-11-08 08:55 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-07-02 04:31 . 2009-11-08 08:55 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-07-02 04:31 . 2009-11-08 08:55 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-07-02 04:31 . 2009-11-08 08:55 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-07-02 04:31 . 2009-11-08 08:55 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-07-02 04:31 . 2009-11-08 08:55 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-07-02 04:31 . 2009-11-08 08:55 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-07-02 04:31 . 2009-11-08 08:55 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-07-02 04:31 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-07-02 04:31 . 2009-11-08 08:55 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-07-01 17:17 . 2012-07-01 17:17 250 ----a-w- C:\user.js
2012-07-01 16:22 . 2012-07-01 16:22 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-07-01 16:22 . 2012-07-01 16:22 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-01 15:31 . 2012-07-01 16:02 -------- d-----w- c:\program files (x86)\Mass Effect 3
2012-07-01 15:21 . 2008-06-20 01:16 49160 ----a-w- c:\windows\system32\infocardcpl.cpl
2012-07-01 15:21 . 2008-06-20 01:14 37384 ----a-w- c:\windows\SysWow64\infocardcpl.cpl
2012-07-01 15:21 . 2008-06-20 01:16 11264 ----a-w- c:\windows\system32\icardres.dll
2012-07-01 15:21 . 2008-06-20 01:14 11264 ----a-w- c:\windows\SysWow64\icardres.dll
2012-07-01 15:20 . 2008-06-20 01:17 1168928 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:16 167432 ----a-w- c:\windows\system32\infocardapi.dll
2012-07-01 15:20 . 2008-06-20 01:14 781344 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:14 97800 ----a-w- c:\windows\SysWow64\infocardapi.dll
2012-07-01 15:20 . 2008-06-20 01:14 622080 ----a-w- c:\windows\SysWow64\icardagt.exe
2012-07-01 15:20 . 2008-06-20 01:16 1383936 ----a-w- c:\windows\system32\icardagt.exe
2012-07-01 15:20 . 2008-06-20 01:17 126520 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2012-07-01 15:20 . 2008-06-20 01:14 105016 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2012-07-01 15:12 . 2008-07-27 18:03 158720 ----a-w- c:\windows\SysWow64\mscorier.dll
2012-07-01 15:12 . 2008-07-27 18:01 158208 ----a-w- c:\windows\system32\mscorier.dll
2012-07-01 15:12 . 2008-07-27 18:01 76288 ----a-w- c:\windows\system32\mscories.dll
2012-07-01 15:12 . 2008-07-27 18:03 83968 ----a-w- c:\windows\SysWow64\mscories.dll
2012-07-01 15:09 . 2010-02-24 09:28 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-07-01 15:05 . 2010-02-20 23:44 32768 ----a-w- c:\windows\system32\nshhttp.dll
2012-07-01 15:05 . 2010-02-20 23:39 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll
2012-07-01 15:05 . 2010-02-20 23:42 33792 ----a-w- c:\windows\system32\httpapi.dll
2012-07-01 15:05 . 2010-02-20 23:37 31232 ----a-w- c:\windows\SysWow64\httpapi.dll
2012-07-01 15:05 . 2010-02-20 21:40 610304 ----a-w- c:\windows\system32\drivers\http.sys
2012-07-01 14:59 . 2010-04-14 18:33 101376 ----a-w- c:\windows\system32\MSNP.ax
2012-07-01 14:59 . 2010-04-14 17:46 80896 ----a-w- c:\windows\SysWow64\MSNP.ax
2012-07-01 14:59 . 2008-04-23 05:05 73216 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-07-01 14:59 . 2008-04-23 04:41 57856 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-07-01 14:59 . 2010-04-14 18:35 375808 ----a-w- c:\windows\system32\psisdecd.dll
2012-07-01 14:59 . 2010-04-14 18:35 289792 ----a-w- c:\windows\system32\psisrndr.ax
2012-07-01 14:59 . 2010-04-14 17:47 293376 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-07-01 14:59 . 2010-04-14 17:47 217088 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-07-01 14:57 . 2009-10-09 21:56 2048 ----a-w- c:\windows\SysWow64\winrsmgr.dll
2012-07-01 14:57 . 2009-10-09 21:35 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2012-07-01 14:57 . 2009-10-09 21:35 13312 ----a-w- c:\windows\system32\wsmplpxy.dll
2012-07-01 14:57 . 2009-10-09 21:34 13312 ----a-w- c:\windows\system32\winrssrv.dll
2012-07-01 14:57 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\wsmplpxy.dll
2012-07-01 14:57 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\winrssrv.dll
2012-07-01 14:46 . 2012-07-01 14:46 -------- d-----w- C:\8915d614d040d981e41a
2012-07-01 14:42 . 2012-07-01 14:42 -------- d-----w- c:\windows\system32\EventProviders
2012-07-01 14:40 . 2008-04-30 05:56 589824 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2012-07-01 14:40 . 2008-04-30 05:36 454656 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadce.dll
2012-07-01 14:30 . 2012-07-01 14:30 -------- d-----w- c:\windows\system32\WindowsPowerShell
2012-07-01 14:30 . 2010-04-05 16:51 84480 ----a-w- c:\windows\system32\asycfilt.dll
2012-07-01 14:30 . 2010-04-05 16:07 67072 ----a-w- c:\windows\SysWow64\asycfilt.dll
2012-07-01 14:21 . 2008-05-30 12:19 511496 ----a-w- c:\windows\system32\XAudio2_1.dll
2012-07-01 13:50 . 2012-07-01 13:50 -------- d-----w- c:\program files (x86)\VideoLAN
2012-07-01 13:35 . 2012-07-01 13:36 -------- d-----w- c:\program files (x86)\The KMPlayer
2012-07-01 13:32 . 2012-07-01 13:32 -------- d-----w- c:\program files (x86)\PANDORA.TV
2012-07-01 12:23 . 2012-07-26 14:53 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-07-01 11:33 . 2012-07-26 14:53 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-07-01 11:33 . 2012-07-01 12:20 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-07-01 11:33 . 2012-07-01 11:51 674600 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-07-01 11:01 . 2012-07-19 14:49 -------- d-----w- c:\programdata\Xfire
2012-07-01 11:01 . 2012-07-01 14:32 -------- d-----w- c:\program files (x86)\Xfire
2012-07-01 10:52 . 2009-09-10 15:48 1486848 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2012-07-01 10:51 . 2010-11-06 04:35 854528 ----a-w- c:\windows\system32\schedsvc.dll
2012-07-01 10:50 . 2010-10-28 13:17 2048 ----a-w- c:\windows\system32\tzres.dll
2012-07-01 10:46 . 2012-05-31 10:25 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-07-01 10:41 . 2010-08-31 15:40 531968 ----a-w- c:\windows\SysWow64\comctl32.dll
2012-07-01 10:41 . 2010-08-31 15:21 633856 ----a-w- c:\windows\system32\comctl32.dll
2012-07-01 10:40 . 2009-04-02 12:39 818688 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-07-01 10:40 . 2009-04-02 12:37 604672 ----a-w- c:\windows\SysWow64\WMSPDMOD.DLL
2012-07-01 10:40 . 2008-06-26 02:25 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2012-07-01 10:40 . 2008-06-26 01:45 12240896 ----a-w- c:\windows\SysWow64\NlsLexicons0007.dll
2012-07-01 10:40 . 2008-06-26 02:25 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2012-07-01 10:40 . 2008-06-26 01:45 2644480 ----a-w- c:\windows\SysWow64\NlsLexicons0009.dll
2012-07-01 10:40 . 2008-06-26 03:56 1361920 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2012-07-01 10:40 . 2008-06-26 03:29 801280 ----a-w- c:\windows\SysWow64\NaturalLanguage6.dll
2012-07-01 10:38 . 2012-07-01 10:38 -------- d-s---w- c:\program files (x86)\HLSW
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 01:00 . 2006-11-02 12:35 59701280 ----a-w- c:\windows\system32\mrt.exe
2012-05-03 02:54 . 2012-05-03 02:54 42392 ----a-w- c:\windows\SysWow64\xfcodec.dll
2012-05-03 02:54 . 2012-05-03 02:54 28056 ----a-w- c:\windows\system32\xfcodec64.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\8915d614d040d981e41a ----
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-06-07 17425072]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-07-27 348624]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R3 60687391;60687391; [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-16 250056]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Obsah adresáře 'Naplánované úlohy'
.
2012-07-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 02:26]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-03 6430208]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\fdd1bws4.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\sched.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Celkový čas: 2012-07-27 12:19:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-27 10:19
ComboFix2.txt 2012-07-27 06:22
.
Před spuštěním: Volných bajtů: 39 903 813 632
Po spuštění: Volných bajtů: 37 690 703 872
.
- - End Of File - - 34ED967C834A400121767EF73BD0AA78


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 105 hostů