kontrola logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

kontrola logu

Příspěvekod JStep » 21 říj 2012 18:11

Dobrý večer,

Win. vista po startu notebooku zamrznou. V nouzovém režimu běží normálně. Prosím o kontrolu logu. Děkuji. J


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 17:45:19, on 21.10.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
Boot mode: Safe mode with network support

Running processes:
C:\windows\Explorer.EXE
C:\windows\system32\wbem\unsecapp.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jirka\Downloads\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Jirka\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Jirka\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [accrdsub] "c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\windows\tsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: APSHook.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\system32\NLSSRV32.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8903 bytes

Reklama
Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Orcus » 21 říj 2012 20:24

Odinstaluj:

QIP Search Bar
Spybot-Search&Destroy

Fixni:

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Jirka\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Jirka\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe" /c

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

===================================================

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 21 říj 2012 21:40

Nedaří se mi odstranit z Exploreru QIP Search Bar. Jen jsem ho zakázal. Jak mám postupovat, abych ho vymazal?

Log z Malwarebytes' Anti-Malware:


Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.65.1.1000
http://www.malwarebytes.org

Verze databáze: v2012.10.21.05

Windows Vista Service Pack 2 x86 NTFS (Safe Mode s podporou sítě)
Internet Explorer 7.0.6002.18005
Jirka :: JIRKA-PC [administrátor]

Ochrana: Zakázána

21.10.2012 21:42:56
mbam-log-2012-10-21 (21-42-56).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 195289
Uplynulý čas: 6 minut, 46 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Dík. J

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Žbeky » 21 říj 2012 22:55

Smažem ho

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 21 říj 2012 23:17

23:01:02.0063 0904 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
23:01:02.0328 0904 ============================================================
23:01:02.0328 0904 Current date / time: 2012/10/21 23:01:02.0328
23:01:02.0328 0904 SystemInfo:
23:01:02.0328 0904
23:01:02.0328 0904 OS Version: 6.0.6002 ServicePack: 2.0
23:01:02.0328 0904 Product type: Workstation
23:01:02.0328 0904 ComputerName: JIRKA-PC
23:01:02.0328 0904 UserName: Jirka
23:01:02.0328 0904 Windows directory: C:\windows
23:01:02.0328 0904 System windows directory: C:\windows
23:01:02.0328 0904 Processor architecture: Intel x86
23:01:02.0328 0904 Number of processors: 2
23:01:02.0328 0904 Page size: 0x1000
23:01:02.0328 0904 Boot type: Safe boot with network
23:01:02.0328 0904 ============================================================
23:01:02.0828 0904 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
23:01:02.0828 0904 ============================================================
23:01:02.0828 0904 \Device\Harddisk0\DR0:
23:01:02.0828 0904 MBR partitions:
23:01:02.0828 0904 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1BDC3FC1
23:01:02.0828 0904 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xC, StartLBA 0x1BDC4000, BlocksNum 0x200800
23:01:02.0828 0904 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1BFC4970, BlocksNum 0xFA07F8
23:01:02.0828 0904 ============================================================
23:01:02.0843 0904 C: <-> \Device\Harddisk0\DR0\Partition1
23:01:02.0874 0904 D: <-> \Device\Harddisk0\DR0\Partition3
23:01:02.0890 0904 F: <-> \Device\Harddisk0\DR0\Partition2
23:01:02.0890 0904 ============================================================
23:01:02.0890 0904 Initialize success
23:01:02.0890 0904 ============================================================
23:01:18.0974 0448 ============================================================
23:01:18.0974 0448 Scan started
23:01:18.0974 0448 Mode: Manual;
23:01:18.0974 0448 ============================================================
23:01:20.0128 0448 ================ Scan system memory ========================
23:01:20.0128 0448 System memory - ok
23:01:20.0128 0448 ================ Scan services =============================
23:01:20.0331 0448 [ D7C84AE1EB1C725B0113D92E16849BD1 ] 0VsNdis08 C:\Program Files\INS\VitalAgent\Program\VsNdis08.sys
23:01:20.0331 0448 0VsNdis08 - ok
23:01:20.0518 0448 [ A9B917777841B76F299E2EA946E03ADF ] Accelerometer C:\windows\system32\DRIVERS\Accelerometer.sys
23:01:20.0518 0448 Accelerometer - ok
23:01:20.0596 0448 [ EC4A5D4E36A8E49261CD823450E0BA51 ] accoca c:\Program Files\ActivIdentity\ActivClient\accoca.exe
23:01:20.0596 0448 accoca - ok
23:01:20.0643 0448 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\windows\system32\drivers\acpi.sys
23:01:20.0643 0448 ACPI - ok
23:01:20.0690 0448 [ 364A903711E84EB1386FA04106681B7A ] ADIHdAudAddService C:\windows\system32\drivers\ADIHdAud.sys
23:01:20.0690 0448 ADIHdAudAddService - ok
23:01:20.0752 0448 [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
23:01:20.0752 0448 Adobe LM Service - ok
23:01:20.0846 0448 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
23:01:20.0846 0448 AdobeARMservice - ok
23:01:20.0924 0448 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
23:01:20.0924 0448 adp94xx - ok
23:01:20.0955 0448 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\windows\system32\drivers\adpahci.sys
23:01:20.0955 0448 adpahci - ok
23:01:20.0986 0448 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\windows\system32\drivers\adpu160m.sys
23:01:20.0986 0448 adpu160m - ok
23:01:21.0033 0448 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\windows\system32\drivers\adpu320.sys
23:01:21.0033 0448 adpu320 - ok
23:01:21.0095 0448 [ 585F5793BB5D79C8754EE63BCBAF2B3A ] AEADIFilters C:\windows\system32\AEADISRV.EXE
23:01:21.0095 0448 AEADIFilters - ok
23:01:21.0142 0448 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\windows\System32\aelupsvc.dll
23:01:21.0142 0448 AeLookupSvc - ok
23:01:21.0220 0448 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\windows\system32\drivers\afd.sys
23:01:21.0236 0448 AFD - ok
23:01:21.0314 0448 [ 8ED60797908FD394EEE0D6949F493224 ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe
23:01:21.0314 0448 AgereModemAudio - ok
23:01:21.0423 0448 [ 3712986CC3ABF0DC656B43525B9D1279 ] AgereSoftModem C:\windows\system32\DRIVERS\AGRSM.sys
23:01:21.0438 0448 AgereSoftModem - ok
23:01:21.0485 0448 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\windows\system32\drivers\agp440.sys
23:01:21.0485 0448 agp440 - ok
23:01:21.0532 0448 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\windows\system32\drivers\djsvs.sys
23:01:21.0532 0448 aic78xx - ok
23:01:21.0548 0448 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\windows\System32\alg.exe
23:01:21.0548 0448 ALG - ok
23:01:21.0579 0448 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\windows\system32\drivers\aliide.sys
23:01:21.0579 0448 aliide - ok
23:01:21.0610 0448 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\windows\system32\drivers\amdagp.sys
23:01:21.0610 0448 amdagp - ok
23:01:21.0626 0448 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\windows\system32\drivers\amdide.sys
23:01:21.0626 0448 amdide - ok
23:01:21.0657 0448 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\windows\system32\drivers\amdk7.sys
23:01:21.0657 0448 AmdK7 - ok
23:01:21.0688 0448 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys
23:01:21.0688 0448 AmdK8 - ok
23:01:21.0719 0448 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\windows\System32\appinfo.dll
23:01:21.0719 0448 Appinfo - ok
23:01:21.0750 0448 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\windows\system32\drivers\arc.sys
23:01:21.0750 0448 arc - ok
23:01:21.0782 0448 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\windows\system32\drivers\arcsas.sys
23:01:21.0782 0448 arcsas - ok
23:01:21.0860 0448 [ 46BA50DE5ADD62AA4CE173EDA629245A ] ASBroker c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
23:01:21.0875 0448 ASBroker - ok
23:01:21.0891 0448 [ 7BEC093B781A2AC8B270EBD4695ADC97 ] ASChannel c:\Program Files\Hewlett-Packard\IAM\Bin\AsChnl.dll
23:01:21.0891 0448 ASChannel - ok
23:01:21.0969 0448 [ 40C145F12FF461A0220303BDA134F598 ] aspnet_state C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
23:01:21.0969 0448 aspnet_state - ok
23:01:22.0016 0448 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\windows\system32\drivers\aswFsBlk.sys
23:01:22.0016 0448 aswFsBlk - ok
23:01:22.0047 0448 [ F76E51561562AC4105DBBE53FC99BC10 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
23:01:22.0062 0448 aswMonFlt - ok
23:01:22.0078 0448 [ B7D5E4486BA658ED08624D8084ABB830 ] aswRdr C:\windows\system32\drivers\aswRdr.sys
23:01:22.0078 0448 aswRdr - ok
23:01:22.0125 0448 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\windows\system32\drivers\aswSnx.sys
23:01:22.0125 0448 aswSnx - ok
23:01:22.0156 0448 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\windows\system32\drivers\aswSP.sys
23:01:22.0172 0448 aswSP - ok
23:01:22.0203 0448 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\windows\system32\drivers\aswTdi.sys
23:01:22.0203 0448 aswTdi - ok
23:01:22.0234 0448 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
23:01:22.0234 0448 AsyncMac - ok
23:01:22.0250 0448 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\windows\system32\drivers\atapi.sys
23:01:22.0250 0448 atapi - ok
23:01:22.0296 0448 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
23:01:22.0296 0448 AudioEndpointBuilder - ok
23:01:22.0312 0448 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\windows\System32\Audiosrv.dll
23:01:22.0312 0448 Audiosrv - ok
23:01:22.0374 0448 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
23:01:22.0374 0448 avast! Antivirus - ok
23:01:22.0421 0448 [ 502F1C30BD50B32D00CE4DCAECC3D3C7 ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
23:01:22.0421 0448 b57nd60x - ok
23:01:22.0515 0448 [ 3F5E7621CDF6867D3D8417D13A098277 ] BCM43XX C:\windows\system32\DRIVERS\bcmwl6.sys
23:01:22.0515 0448 BCM43XX - ok
23:01:22.0562 0448 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\windows\system32\drivers\Beep.sys
23:01:22.0562 0448 Beep - ok
23:01:22.0608 0448 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\windows\System32\bfe.dll
23:01:22.0608 0448 BFE - ok
23:01:22.0671 0448 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\windows\System32\qmgr.dll
23:01:22.0686 0448 BITS - ok
23:01:22.0718 0448 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\windows\system32\drivers\blbdrive.sys
23:01:22.0718 0448 blbdrive - ok
23:01:22.0749 0448 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\windows\system32\DRIVERS\bowser.sys
23:01:22.0749 0448 bowser - ok
23:01:22.0780 0448 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\drivers\brfiltlo.sys
23:01:22.0780 0448 BrFiltLo - ok
23:01:22.0796 0448 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\drivers\brfiltup.sys
23:01:22.0796 0448 BrFiltUp - ok
23:01:22.0827 0448 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\windows\System32\browser.dll
23:01:22.0827 0448 Browser - ok
23:01:22.0874 0448 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\windows\system32\drivers\brserid.sys
23:01:22.0874 0448 Brserid - ok
23:01:22.0889 0448 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\system32\drivers\brserwdm.sys
23:01:22.0889 0448 BrSerWdm - ok
23:01:22.0920 0448 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\system32\drivers\brusbmdm.sys
23:01:22.0920 0448 BrUsbMdm - ok
23:01:22.0936 0448 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\system32\drivers\brusbser.sys
23:01:22.0936 0448 BrUsbSer - ok
23:01:22.0967 0448 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\windows\system32\DRIVERS\BthEnum.sys
23:01:22.0967 0448 BthEnum - ok
23:01:22.0998 0448 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys
23:01:22.0998 0448 BTHMODEM - ok
23:01:23.0030 0448 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
23:01:23.0030 0448 BthPan - ok
23:01:23.0092 0448 [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT C:\windows\system32\Drivers\BTHport.sys
23:01:23.0092 0448 BTHPORT - ok
23:01:23.0123 0448 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\windows\System32\bthserv.dll
23:01:23.0123 0448 BthServ - ok
23:01:23.0139 0448 [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB C:\windows\system32\Drivers\BTHUSB.sys
23:01:23.0139 0448 BTHUSB - ok
23:01:23.0201 0448 [ 99AEEA7CEFDFC6E4151A8F620D682088 ] btwaudio C:\windows\system32\drivers\btwaudio.sys
23:01:23.0201 0448 btwaudio - ok
23:01:23.0217 0448 [ 195872E48A7FB01F8BC9B800F70F4054 ] btwavdt C:\windows\system32\drivers\btwavdt.sys
23:01:23.0217 0448 btwavdt - ok
23:01:23.0232 0448 [ 0724E7D6C9B6A289EDDDA33FA8176E80 ] btwrchid C:\windows\system32\DRIVERS\btwrchid.sys
23:01:23.0232 0448 btwrchid - ok
23:01:23.0264 0448 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
23:01:23.0264 0448 cdfs - ok
23:01:23.0310 0448 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
23:01:23.0310 0448 cdrom - ok
23:01:23.0357 0448 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\windows\System32\certprop.dll
23:01:23.0357 0448 CertPropSvc - ok
23:01:23.0373 0448 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\windows\system32\drivers\circlass.sys
23:01:23.0373 0448 circlass - ok
23:01:23.0404 0448 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\windows\system32\CLFS.sys
23:01:23.0404 0448 CLFS - ok
23:01:23.0466 0448 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:01:23.0466 0448 clr_optimization_v2.0.50727_32 - ok
23:01:23.0544 0448 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:01:23.0544 0448 clr_optimization_v4.0.30319_32 - ok
23:01:23.0576 0448 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
23:01:23.0576 0448 CmBatt - ok
23:01:23.0591 0448 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\windows\system32\drivers\cmdide.sys
23:01:23.0607 0448 cmdide - ok
23:01:23.0654 0448 [ 7795F8CEBC284A426B53F541E538695F ] Com4QLBEx C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
23:01:23.0669 0448 Com4QLBEx - ok
23:01:23.0669 0448 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys
23:01:23.0685 0448 Compbatt - ok
23:01:23.0685 0448 COMSysApp - ok
23:01:23.0716 0448 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
23:01:23.0716 0448 crcdisk - ok
23:01:23.0732 0448 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\windows\system32\drivers\crusoe.sys
23:01:23.0732 0448 Crusoe - ok
23:01:23.0794 0448 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\windows\system32\cryptsvc.dll
23:01:23.0794 0448 CryptSvc - ok
23:01:23.0841 0448 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\windows\system32\rpcss.dll
23:01:23.0856 0448 DcomLaunch - ok
23:01:23.0888 0448 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\windows\system32\Drivers\dfsc.sys
23:01:23.0888 0448 DfsC - ok
23:01:23.0997 0448 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\windows\system32\DFSR.exe
23:01:24.0028 0448 DFSR - ok
23:01:24.0075 0448 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\windows\System32\dhcpcsvc.dll
23:01:24.0075 0448 Dhcp - ok
23:01:24.0106 0448 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\windows\system32\drivers\disk.sys
23:01:24.0106 0448 disk - ok
23:01:24.0153 0448 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\windows\System32\dnsrslvr.dll
23:01:24.0153 0448 Dnscache - ok
23:01:24.0184 0448 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\windows\System32\dot3svc.dll
23:01:24.0184 0448 dot3svc - ok
23:01:24.0231 0448 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\windows\system32\dps.dll
23:01:24.0231 0448 DPS - ok
23:01:24.0278 0448 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
23:01:24.0278 0448 drmkaud - ok
23:01:24.0324 0448 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
23:01:24.0324 0448 DXGKrnl - ok
23:01:24.0371 0448 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\windows\system32\DRIVERS\E1G60I32.sys
23:01:24.0371 0448 E1G60 - ok
23:01:24.0434 0448 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\windows\System32\eapsvc.dll
23:01:24.0434 0448 EapHost - ok
23:01:24.0465 0448 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\windows\system32\drivers\ecache.sys
23:01:24.0465 0448 Ecache - ok
23:01:24.0512 0448 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\windows\system32\drivers\elxstor.sys
23:01:24.0512 0448 elxstor - ok
23:01:24.0574 0448 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\windows\system32\emdmgmt.dll
23:01:24.0574 0448 EMDMgmt - ok
23:01:24.0605 0448 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\windows\system32\drivers\errdev.sys
23:01:24.0605 0448 ErrDev - ok
23:01:24.0652 0448 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\windows\system32\es.dll
23:01:24.0652 0448 EventSystem - ok
23:01:24.0730 0448 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\windows\system32\drivers\exfat.sys
23:01:24.0730 0448 exfat - ok
23:01:24.0761 0448 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\windows\system32\drivers\fastfat.sys
23:01:24.0761 0448 fastfat - ok
23:01:24.0792 0448 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\windows\system32\DRIVERS\fdc.sys
23:01:24.0792 0448 fdc - ok
23:01:24.0824 0448 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\windows\system32\fdPHost.dll
23:01:24.0824 0448 fdPHost - ok
23:01:24.0855 0448 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\windows\system32\fdrespub.dll
23:01:24.0855 0448 FDResPub - ok
23:01:24.0870 0448 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\windows\system32\drivers\fileinfo.sys
23:01:24.0870 0448 FileInfo - ok
23:01:24.0886 0448 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\windows\system32\drivers\filetrace.sys
23:01:24.0886 0448 Filetrace - ok
23:01:24.0917 0448 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys
23:01:24.0917 0448 flpydisk - ok
23:01:24.0948 0448 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
23:01:24.0948 0448 FltMgr - ok
23:01:25.0026 0448 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\windows\system32\FntCache.dll
23:01:25.0042 0448 FontCache - ok
23:01:25.0104 0448 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
23:01:25.0104 0448 FontCache3.0.0.0 - ok
23:01:25.0151 0448 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
23:01:25.0151 0448 Fs_Rec - ok
23:01:25.0182 0448 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
23:01:25.0182 0448 gagp30kx - ok
23:01:25.0229 0448 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\windows\system32\giveio.sys
23:01:25.0229 0448 giveio - ok
23:01:25.0260 0448 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\windows\System32\gpsvc.dll
23:01:25.0276 0448 gpsvc - ok
23:01:25.0323 0448 [ 88A78635B41ED4B261365FADEB28FE81 ] HBtnKey C:\windows\system32\DRIVERS\cpqbttn.sys
23:01:25.0323 0448 HBtnKey - ok
23:01:25.0385 0448 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
23:01:25.0385 0448 HdAudAddService - ok
23:01:25.0448 0448 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
23:01:25.0448 0448 HDAudBus - ok
23:01:25.0494 0448 [ FCB3F4BE408F72C1BD81BCABA87FC22F ] HidBth C:\windows\system32\DRIVERS\hidbth.sys
23:01:25.0494 0448 HidBth - ok
23:01:25.0510 0448 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\windows\system32\drivers\hidir.sys
23:01:25.0510 0448 HidIr - ok
23:01:25.0541 0448 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\windows\system32\hidserv.dll
23:01:25.0541 0448 hidserv - ok
23:01:25.0572 0448 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
23:01:25.0572 0448 HidUsb - ok
23:01:25.0619 0448 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\windows\system32\kmsvc.dll
23:01:25.0619 0448 hkmsvc - ok
23:01:25.0682 0448 [ 07A85D6C053A0999FF450BBCA9825FB2 ] HP ProtectTools Service c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
23:01:25.0697 0448 HP ProtectTools Service - ok
23:01:25.0713 0448 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\windows\system32\drivers\hpcisss.sys
23:01:25.0713 0448 HpCISSs - ok
23:01:25.0744 0448 [ 3520A74FCA88A5AEFBBE7B937BEA75F7 ] hpdskflt C:\windows\system32\DRIVERS\hpdskflt.sys
23:01:25.0744 0448 hpdskflt - ok
23:01:25.0775 0448 [ EB734EF9D7C4D02760F2D1342331BA41 ] HpFkCryptService c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
23:01:25.0775 0448 HpFkCryptService - ok
23:01:25.0806 0448 [ EF55CD76A05A0675FE930036B7773943 ] HPFSService C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
23:01:25.0806 0448 HPFSService - ok
23:01:25.0853 0448 [ 35956140E686D53BF676CF0C778880FC ] HpqKbFiltr C:\windows\system32\DRIVERS\HpqKbFiltr.sys
23:01:25.0853 0448 HpqKbFiltr - ok
23:01:25.0884 0448 [ 1665C7121A026DF10C903DB9BC5E9D43 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
23:01:25.0884 0448 hpqwmiex - ok
23:01:25.0900 0448 [ 3E940775A4970410F094E428BA94BBB7 ] hpsrv C:\windows\system32\Hpservice.exe
23:01:25.0900 0448 hpsrv - ok
23:01:25.0947 0448 [ 0EEECA26C8D4BDE2A4664DB058A81937 ] HTTP C:\windows\system32\drivers\HTTP.sys
23:01:25.0947 0448 HTTP - ok
23:01:25.0978 0448 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\windows\system32\drivers\i2omp.sys
23:01:25.0978 0448 i2omp - ok
23:01:26.0025 0448 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
23:01:26.0025 0448 i8042prt - ok
23:01:26.0087 0448 [ 3AD7614C487C948ADD435662265750FB ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
23:01:26.0087 0448 IAANTMON - ok
23:01:26.0134 0448 [ DB0CC620B27A928D968C1A1E9CD9CB87 ] iaStor C:\windows\system32\drivers\iastor.sys
23:01:26.0134 0448 iaStor - ok
23:01:26.0150 0448 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\windows\system32\drivers\iastorv.sys
23:01:26.0150 0448 iaStorV - ok
23:01:26.0212 0448 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
23:01:26.0212 0448 IDriverT - ok
23:01:26.0290 0448 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:01:26.0306 0448 idsvc - ok
23:01:26.0399 0448 [ D97E70E4E243C9660F91C1112E36C73B ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
23:01:26.0415 0448 igfx - ok
23:01:26.0446 0448 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\windows\system32\drivers\iirsp.sys
23:01:26.0446 0448 iirsp - ok
23:01:26.0493 0448 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\windows\System32\ikeext.dll
23:01:26.0508 0448 IKEEXT - ok
23:01:26.0540 0448 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\windows\system32\drivers\intelide.sys
23:01:26.0540 0448 intelide - ok
23:01:26.0571 0448 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
23:01:26.0571 0448 intelppm - ok
23:01:26.0602 0448 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\windows\system32\ipbusenum.dll
23:01:26.0602 0448 IPBusEnum - ok
23:01:26.0633 0448 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
23:01:26.0633 0448 IpFilterDriver - ok
23:01:26.0664 0448 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
23:01:26.0664 0448 iphlpsvc - ok
23:01:26.0680 0448 IpInIp - ok
23:01:26.0711 0448 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\windows\system32\drivers\ipmidrv.sys
23:01:26.0711 0448 IPMIDRV - ok
23:01:26.0727 0448 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\windows\system32\DRIVERS\ipnat.sys
23:01:26.0742 0448 IPNAT - ok
23:01:26.0758 0448 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\windows\system32\drivers\irenum.sys
23:01:26.0758 0448 IRENUM - ok
23:01:26.0774 0448 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\windows\system32\drivers\isapnp.sys
23:01:26.0774 0448 isapnp - ok
23:01:26.0805 0448 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\windows\system32\DRIVERS\msiscsi.sys
23:01:26.0805 0448 iScsiPrt - ok
23:01:26.0820 0448 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\windows\system32\drivers\iteatapi.sys
23:01:26.0820 0448 iteatapi - ok
23:01:26.0836 0448 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\windows\system32\drivers\iteraid.sys
23:01:26.0836 0448 iteraid - ok
23:01:26.0898 0448 [ 213822072085B5BBAD9AF30AB577D817 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
23:01:26.0898 0448 IviRegMgr - ok
23:01:26.0914 0448 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
23:01:26.0914 0448 kbdclass - ok

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 21 říj 2012 23:18

23:01:26.0961 0448 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
23:01:26.0961 0448 kbdhid - ok
23:01:26.0992 0448 [ A3E186B4B935905B829219502557314E ] KeyIso C:\windows\system32\lsass.exe
23:01:26.0992 0448 KeyIso - ok
23:01:27.0039 0448 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
23:01:27.0039 0448 KSecDD - ok
23:01:27.0101 0448 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\windows\system32\msdtckrm.dll
23:01:27.0101 0448 KtmRm - ok
23:01:27.0132 0448 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\windows\system32\srvsvc.dll
23:01:27.0132 0448 LanmanServer - ok
23:01:27.0179 0448 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\windows\System32\wkssvc.dll
23:01:27.0195 0448 LanmanWorkstation - ok
23:01:27.0257 0448 [ C215E09622118383B236DD56C2065183 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
23:01:27.0257 0448 LightScribeService - ok
23:01:27.0288 0448 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
23:01:27.0288 0448 lltdio - ok
23:01:27.0320 0448 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\windows\System32\lltdsvc.dll
23:01:27.0320 0448 lltdsvc - ok
23:01:27.0335 0448 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\windows\System32\lmhsvc.dll
23:01:27.0335 0448 lmhosts - ok
23:01:27.0366 0448 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
23:01:27.0366 0448 LSI_FC - ok
23:01:27.0382 0448 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
23:01:27.0382 0448 LSI_SAS - ok
23:01:27.0398 0448 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
23:01:27.0398 0448 LSI_SCSI - ok
23:01:27.0398 0448 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\windows\system32\drivers\luafv.sys
23:01:27.0398 0448 luafv - ok
23:01:27.0429 0448 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\windows\system32\drivers\mbam.sys
23:01:27.0444 0448 MBAMProtector - ok
23:01:27.0538 0448 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:01:27.0538 0448 MBAMScheduler - ok
23:01:27.0585 0448 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
23:01:27.0600 0448 MBAMService - ok
23:01:27.0647 0448 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\windows\system32\drivers\megasas.sys
23:01:27.0647 0448 megasas - ok
23:01:27.0663 0448 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\windows\system32\drivers\megasr.sys
23:01:27.0678 0448 MegaSR - ok
23:01:27.0694 0448 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\windows\system32\mmcss.dll
23:01:27.0694 0448 MMCSS - ok
23:01:27.0710 0448 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\windows\system32\drivers\modem.sys
23:01:27.0710 0448 Modem - ok
23:01:27.0725 0448 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\windows\system32\DRIVERS\monitor.sys
23:01:27.0725 0448 monitor - ok
23:01:27.0741 0448 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
23:01:27.0741 0448 mouclass - ok
23:01:27.0756 0448 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
23:01:27.0756 0448 mouhid - ok
23:01:27.0772 0448 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\windows\system32\drivers\mountmgr.sys
23:01:27.0772 0448 MountMgr - ok
23:01:27.0803 0448 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\windows\system32\drivers\mpio.sys
23:01:27.0803 0448 mpio - ok
23:01:27.0819 0448 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
23:01:27.0819 0448 mpsdrv - ok
23:01:27.0850 0448 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\windows\system32\mpssvc.dll
23:01:27.0866 0448 MpsSvc - ok
23:01:27.0881 0448 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\windows\system32\drivers\mraid35x.sys
23:01:27.0881 0448 Mraid35x - ok
23:01:27.0944 0448 [ 9BD4DCB5412921864A7AACDEDFBD1923 ] MREMP50 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
23:01:27.0944 0448 MREMP50 - ok
23:01:27.0959 0448 MREMP50a64 - ok
23:01:27.0959 0448 MREMPR5 - ok
23:01:27.0975 0448 MRENDIS5 - ok
23:01:28.0022 0448 [ 07C02C892E8E1A72D6BF35004F0E9C5E ] MRESP50 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
23:01:28.0022 0448 MRESP50 - ok
23:01:28.0022 0448 MRESP50a64 - ok
23:01:28.0053 0448 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
23:01:28.0053 0448 MRxDAV - ok
23:01:28.0084 0448 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
23:01:28.0100 0448 mrxsmb - ok
23:01:28.0131 0448 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
23:01:28.0131 0448 mrxsmb10 - ok
23:01:28.0146 0448 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
23:01:28.0146 0448 mrxsmb20 - ok
23:01:28.0193 0448 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\windows\system32\drivers\msahci.sys
23:01:28.0193 0448 msahci - ok
23:01:28.0193 0448 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\windows\system32\drivers\msdsm.sys
23:01:28.0193 0448 msdsm - ok
23:01:28.0224 0448 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\windows\System32\msdtc.exe
23:01:28.0224 0448 MSDTC - ok
23:01:28.0256 0448 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\windows\system32\drivers\Msfs.sys
23:01:28.0256 0448 Msfs - ok
23:01:28.0271 0448 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
23:01:28.0271 0448 msisadrv - ok
23:01:28.0318 0448 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\windows\system32\iscsiexe.dll
23:01:28.0318 0448 MSiSCSI - ok
23:01:28.0318 0448 msiserver - ok
23:01:28.0334 0448 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
23:01:28.0334 0448 MSKSSRV - ok
23:01:28.0380 0448 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
23:01:28.0380 0448 MSPCLOCK - ok
23:01:28.0427 0448 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\windows\system32\drivers\MSPQM.sys
23:01:28.0427 0448 MSPQM - ok
23:01:28.0443 0448 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\windows\system32\drivers\MsRPC.sys
23:01:28.0458 0448 MsRPC - ok
23:01:28.0474 0448 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
23:01:28.0474 0448 mssmbios - ok
23:01:28.0505 0448 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\windows\system32\drivers\MSTEE.sys
23:01:28.0505 0448 MSTEE - ok
23:01:28.0521 0448 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\windows\system32\Drivers\mup.sys
23:01:28.0521 0448 Mup - ok
23:01:28.0568 0448 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\windows\system32\qagentRT.dll
23:01:28.0568 0448 napagent - ok
23:01:28.0614 0448 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
23:01:28.0614 0448 NativeWifiP - ok
23:01:28.0661 0448 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\windows\system32\drivers\ndis.sys
23:01:28.0661 0448 NDIS - ok
23:01:28.0692 0448 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
23:01:28.0692 0448 NdisTapi - ok
23:01:28.0692 0448 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
23:01:28.0708 0448 Ndisuio - ok
23:01:28.0739 0448 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
23:01:28.0739 0448 NdisWan - ok
23:01:28.0755 0448 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
23:01:28.0755 0448 NDProxy - ok
23:01:28.0786 0448 [ 949941E4DE88DF1FAF49A4B3CFFB756F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
23:01:28.0786 0448 Net Driver HPZ12 - ok
23:01:28.0802 0448 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
23:01:28.0802 0448 NetBIOS - ok
23:01:28.0833 0448 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\windows\system32\DRIVERS\netbt.sys
23:01:28.0848 0448 netbt - ok
23:01:28.0864 0448 [ A3E186B4B935905B829219502557314E ] Netlogon C:\windows\system32\lsass.exe
23:01:28.0864 0448 Netlogon - ok
23:01:28.0895 0448 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\windows\System32\netman.dll
23:01:28.0895 0448 Netman - ok
23:01:28.0926 0448 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\windows\System32\netprofm.dll
23:01:28.0926 0448 netprofm - ok
23:01:28.0958 0448 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
23:01:28.0958 0448 NetTcpPortSharing - ok
23:01:29.0004 0448 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
23:01:29.0004 0448 nfrd960 - ok
23:01:29.0020 0448 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\windows\System32\nlasvc.dll
23:01:29.0020 0448 NlaSvc - ok
23:01:29.0051 0448 [ 087D74074361C82DAF7611ACC91E030A ] nlsX86cc C:\windows\system32\NLSSRV32.EXE
23:01:29.0051 0448 nlsX86cc - ok
23:01:29.0082 0448 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\windows\system32\drivers\Npfs.sys
23:01:29.0082 0448 Npfs - ok
23:01:29.0098 0448 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\windows\system32\nsisvc.dll
23:01:29.0114 0448 nsi - ok
23:01:29.0114 0448 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
23:01:29.0114 0448 nsiproxy - ok
23:01:29.0160 0448 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
23:01:29.0160 0448 Ntfs - ok
23:01:29.0192 0448 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\windows\system32\drivers\ntrigdigi.sys
23:01:29.0192 0448 ntrigdigi - ok
23:01:29.0207 0448 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\windows\system32\drivers\Null.sys
23:01:29.0207 0448 Null - ok
23:01:29.0254 0448 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\windows\system32\drivers\nvraid.sys
23:01:29.0254 0448 nvraid - ok
23:01:29.0270 0448 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\windows\system32\drivers\nvstor.sys
23:01:29.0270 0448 nvstor - ok
23:01:29.0285 0448 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\windows\system32\drivers\nv_agp.sys
23:01:29.0285 0448 nv_agp - ok
23:01:29.0301 0448 NwlnkFlt - ok
23:01:29.0301 0448 NwlnkFwd - ok
23:01:29.0394 0448 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:01:29.0394 0448 odserv - ok
23:01:29.0457 0448 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\windows\system32\DRIVERS\ohci1394.sys
23:01:29.0457 0448 ohci1394 - ok
23:01:29.0488 0448 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:01:29.0504 0448 ose - ok
23:01:29.0550 0448 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\windows\system32\p2psvc.dll
23:01:29.0550 0448 p2pimsvc - ok
23:01:29.0566 0448 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\windows\system32\p2psvc.dll
23:01:29.0582 0448 p2psvc - ok
23:01:29.0613 0448 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\windows\system32\DRIVERS\parport.sys
23:01:29.0613 0448 Parport - ok
23:01:29.0644 0448 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\windows\system32\drivers\partmgr.sys
23:01:29.0644 0448 partmgr - ok
23:01:29.0660 0448 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\windows\system32\DRIVERS\parvdm.sys
23:01:29.0660 0448 Parvdm - ok
23:01:29.0691 0448 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\windows\System32\pcasvc.dll
23:01:29.0691 0448 PcaSvc - ok
23:01:29.0722 0448 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\windows\system32\drivers\pci.sys
23:01:29.0722 0448 pci - ok
23:01:29.0753 0448 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\windows\system32\drivers\pciide.sys
23:01:29.0753 0448 pciide - ok
23:01:29.0784 0448 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys
23:01:29.0784 0448 pcmcia - ok
23:01:29.0831 0448 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\windows\system32\drivers\peauth.sys
23:01:29.0847 0448 PEAUTH - ok
23:01:29.0940 0448 [ B1689DF169143F57053F795390C99DB3 ] pla C:\windows\system32\pla.dll
23:01:29.0956 0448 pla - ok
23:01:30.0003 0448 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\windows\system32\umpnpmgr.dll
23:01:30.0003 0448 PlugPlay - ok
23:01:30.0018 0448 [ 2F4CA141A609CAF5C98F6E4760EF1B9B ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
23:01:30.0034 0448 Pml Driver HPZ12 - ok
23:01:30.0065 0448 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\windows\system32\p2psvc.dll
23:01:30.0081 0448 PNRPAutoReg - ok
23:01:30.0081 0448 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\windows\system32\p2psvc.dll
23:01:30.0096 0448 PNRPsvc - ok
23:01:30.0143 0448 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
23:01:30.0143 0448 PolicyAgent - ok
23:01:30.0190 0448 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
23:01:30.0190 0448 PptpMiniport - ok
23:01:30.0206 0448 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\windows\system32\drivers\processr.sys
23:01:30.0206 0448 Processor - ok
23:01:30.0252 0448 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\windows\system32\profsvc.dll
23:01:30.0268 0448 ProfSvc - ok
23:01:30.0284 0448 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\windows\system32\lsass.exe
23:01:30.0284 0448 ProtectedStorage - ok
23:01:30.0299 0448 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\windows\system32\DRIVERS\pacer.sys
23:01:30.0299 0448 PSched - ok
23:01:30.0330 0448 [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
23:01:30.0330 0448 PxHelp20 - ok
23:01:30.0424 0448 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\windows\system32\drivers\ql2300.sys
23:01:30.0440 0448 ql2300 - ok
23:01:30.0455 0448 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\windows\system32\drivers\ql40xx.sys
23:01:30.0455 0448 ql40xx - ok
23:01:30.0533 0448 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\windows\system32\qwave.dll
23:01:30.0533 0448 QWAVE - ok
23:01:30.0549 0448 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
23:01:30.0549 0448 QWAVEdrv - ok
23:01:30.0564 0448 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
23:01:30.0564 0448 RasAcd - ok
23:01:30.0580 0448 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\windows\System32\rasauto.dll
23:01:30.0580 0448 RasAuto - ok
23:01:30.0611 0448 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
23:01:30.0627 0448 Rasl2tp - ok
23:01:30.0658 0448 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\windows\System32\rasmans.dll
23:01:30.0658 0448 RasMan - ok
23:01:30.0689 0448 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
23:01:30.0689 0448 RasPppoe - ok
23:01:30.0705 0448 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
23:01:30.0705 0448 RasSstp - ok
23:01:30.0720 0448 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
23:01:30.0720 0448 rdbss - ok
23:01:30.0736 0448 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
23:01:30.0736 0448 RDPCDD - ok
23:01:30.0752 0448 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\windows\system32\drivers\rdpdr.sys
23:01:30.0767 0448 rdpdr - ok
23:01:30.0767 0448 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
23:01:30.0767 0448 RDPENCDD - ok
23:01:30.0814 0448 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\windows\system32\drivers\RDPWD.sys
23:01:30.0814 0448 RDPWD - ok
23:01:30.0876 0448 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\windows\System32\mprdim.dll
23:01:30.0876 0448 RemoteAccess - ok
23:01:30.0923 0448 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\windows\system32\regsvc.dll
23:01:30.0923 0448 RemoteRegistry - ok
23:01:30.0970 0448 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
23:01:30.0970 0448 RFCOMM - ok
23:01:31.0001 0448 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\windows\system32\locator.exe
23:01:31.0001 0448 RpcLocator - ok
23:01:31.0032 0448 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\windows\system32\rpcss.dll
23:01:31.0032 0448 RpcSs - ok
23:01:31.0064 0448 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
23:01:31.0064 0448 rspndr - ok
23:01:31.0095 0448 [ 3BEEFE509C414F3A6E55E5C7C4024581 ] RsvLock C:\windows\system32\drivers\RsvLock.sys
23:01:31.0095 0448 RsvLock - ok
23:01:31.0126 0448 [ 06847AA6F3A9BF7C44134D00A2E578C0 ] s125bus C:\windows\system32\DRIVERS\s125bus.sys
23:01:31.0126 0448 s125bus - ok
23:01:31.0173 0448 [ F83F88E1B125308FB5015EA0349502B0 ] s125mdfl C:\windows\system32\DRIVERS\s125mdfl.sys
23:01:31.0173 0448 s125mdfl - ok
23:01:31.0188 0448 [ 402A97756C14940AD6AE5169C2FB105E ] s125mdm C:\windows\system32\DRIVERS\s125mdm.sys
23:01:31.0188 0448 s125mdm - ok
23:01:31.0220 0448 [ 82B14C51DE76825EC769A6374E4C57D6 ] s125mgmt C:\windows\system32\DRIVERS\s125mgmt.sys
23:01:31.0220 0448 s125mgmt - ok
23:01:31.0251 0448 [ BEDFC5707C356FD073BF1A4AFE442D91 ] s125obex C:\windows\system32\DRIVERS\s125obex.sys
23:01:31.0251 0448 s125obex - ok
23:01:31.0266 0448 [ 2A5EEDCB22A5D6BB0231E38A38E7A7D9 ] SafeBoot C:\windows\system32\drivers\SafeBoot.sys
23:01:31.0266 0448 SafeBoot - ok
23:01:31.0298 0448 [ A3E186B4B935905B829219502557314E ] SamSs C:\windows\system32\lsass.exe
23:01:31.0298 0448 SamSs - ok
23:01:31.0298 0448 [ 52DCDE2D1787217E15FFDCA1CBF8CCE9 ] SbAlg C:\windows\system32\drivers\SbAlg.sys
23:01:31.0298 0448 SbAlg - ok
23:01:31.0329 0448 [ 69A5AF9CE49A0982E7AE7C7D62BDB2B1 ] SbFsLock C:\windows\system32\drivers\SbFsLock.sys
23:01:31.0329 0448 SbFsLock - ok
23:01:31.0344 0448 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
23:01:31.0344 0448 sbp2port - ok
23:01:31.0376 0448 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\windows\System32\SCardSvr.dll
23:01:31.0376 0448 SCardSvr - ok
23:01:31.0407 0448 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\windows\system32\schedsvc.dll
23:01:31.0407 0448 Schedule - ok
23:01:31.0422 0448 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\windows\System32\certprop.dll
23:01:31.0438 0448 SCPolicySvc - ok
23:01:31.0469 0448 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\windows\System32\SDRSVC.dll
23:01:31.0469 0448 SDRSVC - ok
23:01:31.0500 0448 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
23:01:31.0500 0448 secdrv - ok
23:01:31.0516 0448 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\windows\system32\seclogon.dll
23:01:31.0516 0448 seclogon - ok
23:01:31.0547 0448 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\windows\System32\sens.dll
23:01:31.0547 0448 SENS - ok
23:01:31.0563 0448 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\windows\system32\drivers\serenum.sys
23:01:31.0563 0448 Serenum - ok
23:01:31.0594 0448 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\windows\system32\drivers\serial.sys
23:01:31.0594 0448 Serial - ok
23:01:31.0610 0448 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\windows\system32\drivers\sermouse.sys
23:01:31.0610 0448 sermouse - ok
23:01:31.0688 0448 [ 8C1F87F5FDD92229D1754B98F073913F ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
23:01:31.0703 0448 ServiceLayer - ok
23:01:31.0750 0448 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\windows\system32\sessenv.dll
23:01:31.0750 0448 SessionEnv - ok
23:01:31.0781 0448 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\windows\system32\drivers\sffdisk.sys
23:01:31.0781 0448 sffdisk - ok
23:01:31.0812 0448 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
23:01:31.0812 0448 sffp_mmc - ok
23:01:31.0828 0448 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
23:01:31.0828 0448 sffp_sd - ok
23:01:31.0844 0448 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
23:01:31.0844 0448 sfloppy - ok
23:01:31.0890 0448 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\windows\System32\ipnathlp.dll
23:01:31.0890 0448 SharedAccess - ok
23:01:31.0922 0448 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\windows\System32\shsvcs.dll
23:01:31.0922 0448 ShellHWDetection - ok
23:01:31.0953 0448 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\windows\system32\drivers\sisagp.sys
23:01:31.0953 0448 sisagp - ok
23:01:31.0984 0448 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\windows\system32\drivers\sisraid2.sys
23:01:31.0984 0448 SiSRaid2 - ok
23:01:32.0015 0448 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
23:01:32.0015 0448 SiSRaid4 - ok
23:01:32.0062 0448 [ 649DEE8CEE75B152F9C8979737C6DC35 ] slabbus C:\windows\system32\DRIVERS\slabbus.sys
23:01:32.0062 0448 slabbus - ok
23:01:32.0109 0448 [ 61E8A285532F609AECED3200A75E40BE ] slabser C:\windows\system32\DRIVERS\slabser.sys
23:01:32.0109 0448 slabser - ok
23:01:32.0218 0448 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\windows\system32\SLsvc.exe
23:01:32.0234 0448 slsvc - ok
23:01:32.0265 0448 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\windows\system32\SLUINotify.dll
23:01:32.0265 0448 SLUINotify - ok
23:01:32.0280 0448 SMARTMouseFilterx86 - ok
23:01:32.0296 0448 SMARTVHidMini2000x86 - ok
23:01:32.0327 0448 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\windows\system32\DRIVERS\smb.sys
23:01:32.0327 0448 Smb - ok
23:01:32.0374 0448 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\windows\System32\snmptrap.exe
23:01:32.0374 0448 SNMPTRAP - ok
23:01:32.0468 0448 [ 50660E6B082A7BF86751A003C3BB5210 ] SNP2UVC C:\windows\system32\DRIVERS\snp2uvc.sys
23:01:32.0483 0448 SNP2UVC - ok
23:01:32.0514 0448 [ 3FA2E254BFBCE52B3C6F1BF23AAB6911 ] speedfan C:\windows\system32\speedfan.sys
23:01:32.0514 0448 speedfan - ok
23:01:32.0561 0448 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\windows\system32\drivers\spldr.sys
23:01:32.0561 0448 spldr - ok
23:01:32.0592 0448 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\windows\System32\spoolsv.exe
23:01:32.0592 0448 Spooler - ok
23:01:32.0639 0448 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\windows\system32\DRIVERS\srv.sys
23:01:32.0639 0448 srv - ok
23:01:32.0670 0448 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\windows\system32\DRIVERS\srv2.sys
23:01:32.0686 0448 srv2 - ok
23:01:32.0686 0448 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
23:01:32.0686 0448 srvnet - ok
23:01:32.0733 0448 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
23:01:32.0733 0448 SSDPSRV - ok
23:01:32.0764 0448 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\windows\system32\sstpsvc.dll
23:01:32.0764 0448 SstpSvc - ok
23:01:32.0811 0448 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\windows\System32\wiaservc.dll
23:01:32.0811 0448 stisvc - ok
23:01:32.0842 0448 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\windows\system32\DRIVERS\swenum.sys
23:01:32.0842 0448 swenum - ok
23:01:32.0873 0448 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\windows\System32\swprv.dll
23:01:32.0873 0448 swprv - ok
23:01:32.0889 0448 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\windows\system32\drivers\symc8xx.sys
23:01:32.0889 0448 Symc8xx - ok
23:01:32.0904 0448 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\windows\system32\drivers\sym_hi.sys
23:01:32.0904 0448 Sym_hi - ok
23:01:32.0936 0448 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\windows\system32\drivers\sym_u3.sys
23:01:32.0936 0448 Sym_u3 - ok
23:01:32.0967 0448 [ F5D926807BD9BC0AF68F9376144DE425 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
23:01:32.0967 0448 SynTP - ok
23:01:32.0998 0448 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\windows\system32\sysmain.dll
23:01:33.0014 0448 SysMain - ok
23:01:33.0045 0448 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\windows\System32\TabSvc.dll
23:01:33.0045 0448 TabletInputService - ok
23:01:33.0076 0448 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\windows\System32\tapisrv.dll
23:01:33.0092 0448 TapiSrv - ok
23:01:33.0107 0448 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\windows\System32\tbssvc.dll
23:01:33.0107 0448 TBS - ok
23:01:33.0154 0448 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\windows\system32\drivers\tcpip.sys
23:01:33.0154 0448 Tcpip - ok
23:01:33.0170 0448 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\windows\system32\DRIVERS\tcpip.sys
23:01:33.0185 0448 Tcpip6 - ok
23:01:33.0216 0448 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
23:01:33.0216 0448 tcpipreg - ok
23:01:33.0232 0448 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
23:01:33.0232 0448 TDPIPE - ok
23:01:33.0248 0448 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
23:01:33.0248 0448 TDTCP - ok
23:01:33.0279 0448 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\windows\system32\DRIVERS\tdx.sys
23:01:33.0279 0448 tdx - ok
23:01:33.0294 0448 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\windows\system32\DRIVERS\termdd.sys
23:01:33.0294 0448 TermDD - ok
23:01:33.0326 0448 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\windows\System32\termsrv.dll
23:01:33.0341 0448 TermService - ok
23:01:33.0357 0448 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\windows\system32\shsvcs.dll
23:01:33.0357 0448 Themes - ok
23:01:33.0372 0448 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\windows\system32\mmcss.dll
23:01:33.0388 0448 THREADORDER - ok
23:01:33.0419 0448 [ CB258C2F726F1BE73C507022BE33EBB3 ] TPM C:\windows\system32\drivers\tpm.sys
23:01:33.0419 0448 TPM - ok
23:01:33.0450 0448 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\windows\System32\trkwks.dll
23:01:33.0450 0448 TrkWks - ok
23:01:33.0497 0448 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
23:01:33.0497 0448 TrustedInstaller - ok
23:01:33.0513 0448 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
23:01:33.0513 0448 tssecsrv - ok
23:01:33.0575 0448 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\windows\system32\DRIVERS\tunmp.sys
23:01:33.0575 0448 tunmp - ok
23:01:33.0606 0448 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
23:01:33.0606 0448 tunnel - ok
23:01:33.0638 0448 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\windows\system32\drivers\uagp35.sys
23:01:33.0638 0448 uagp35 - ok
23:01:33.0669 0448 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\windows\system32\DRIVERS\udfs.sys
23:01:33.0669 0448 udfs - ok
23:01:33.0716 0448 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\windows\system32\UI0Detect.exe
23:01:33.0716 0448 UI0Detect - ok
23:01:33.0731 0448 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
23:01:33.0731 0448 uliagpkx - ok
23:01:33.0762 0448 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\windows\system32\drivers\uliahci.sys
23:01:33.0762 0448 uliahci - ok
23:01:33.0778 0448 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\windows\system32\drivers\ulsata.sys
23:01:33.0778 0448 UlSata - ok
23:01:33.0809 0448 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\windows\system32\drivers\ulsata2.sys
23:01:33.0809 0448 ulsata2 - ok
23:01:33.0825 0448 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\windows\system32\DRIVERS\umbus.sys
23:01:33.0825 0448 umbus - ok
23:01:33.0840 0448 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\windows\System32\upnphost.dll
23:01:33.0840 0448 upnphost - ok
23:01:33.0872 0448 upperdev - ok
23:01:33.0903 0448 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
23:01:33.0903 0448 usbccgp - ok
23:01:33.0934 0448 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\windows\system32\drivers\usbcir.sys
23:01:33.0950 0448 usbcir - ok
23:01:33.0981 0448 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
23:01:33.0981 0448 usbehci - ok
23:01:34.0012 0448 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
23:01:34.0012 0448 usbhub - ok
23:01:34.0043 0448 [ 7BDB7B0E7D45AC0402D78B90789EF47C ] usbohci C:\windows\system32\DRIVERS\usbohci.sys
23:01:34.0043 0448 usbohci - ok
23:01:34.0059 0448 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\windows\system32\drivers\usbprint.sys
23:01:34.0059 0448 usbprint - ok
23:01:34.0090 0448 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
23:01:34.0090 0448 USBSTOR - ok
23:01:34.0106 0448 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\windows\system32\DRIVERS\usbuhci.sys
23:01:34.0106 0448 usbuhci - ok
23:01:34.0152 0448 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys
23:01:34.0152 0448 usbvideo - ok
23:01:34.0199 0448 [ 830D5D8456B822C1247C1E59B4C464FA ] usb_rndis C:\windows\system32\DRIVERS\usb8023.sys
23:01:34.0199 0448 usb_rndis - ok
23:01:34.0230 0448 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\windows\System32\uxsms.dll
23:01:34.0230 0448 UxSms - ok
23:01:34.0277 0448 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\windows\System32\vds.exe
23:01:34.0277 0448 vds - ok
23:01:34.0324 0448 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
23:01:34.0324 0448 vga - ok
23:01:34.0355 0448 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\windows\System32\drivers\vga.sys
23:01:34.0355 0448 VgaSave - ok
23:01:34.0386 0448 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\windows\system32\drivers\viaagp.sys
23:01:34.0386 0448 viaagp - ok
23:01:34.0402 0448 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\windows\system32\drivers\viac7.sys
23:01:34.0402 0448 ViaC7 - ok
23:01:34.0433 0448 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\windows\system32\drivers\viaide.sys
23:01:34.0433 0448 viaide - ok
23:01:34.0449 0448 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\windows\system32\drivers\volmgr.sys
23:01:34.0449 0448 volmgr - ok
23:01:34.0480 0448 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
23:01:34.0496 0448 volmgrx - ok
23:01:34.0511 0448 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\windows\system32\drivers\volsnap.sys
23:01:34.0511 0448 volsnap - ok
23:01:34.0542 0448 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
23:01:34.0558 0448 vsmraid - ok
23:01:34.0636 0448 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\windows\system32\vssvc.exe
23:01:34.0636 0448 VSS - ok
23:01:34.0667 0448 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\windows\system32\w32time.dll
23:01:34.0667 0448 W32Time - ok
23:01:34.0698 0448 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\windows\system32\drivers\wacompen.sys
23:01:34.0698 0448 WacomPen - ok
23:01:34.0730 0448 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\windows\system32\DRIVERS\wanarp.sys
23:01:34.0730 0448 Wanarp - ok
23:01:34.0730 0448 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
23:01:34.0730 0448 Wanarpv6 - ok
23:01:34.0776 0448 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\windows\System32\wcncsvc.dll
23:01:34.0776 0448 wcncsvc - ok
23:01:34.0823 0448 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
23:01:34.0823 0448 WcsPlugInService - ok
23:01:34.0854 0448 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\windows\system32\drivers\wd.sys
23:01:34.0854 0448 Wd - ok
23:01:34.0886 0448 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
23:01:34.0901 0448 Wdf01000 - ok
23:01:34.0917 0448 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\windows\system32\wdi.dll
23:01:34.0917 0448 WdiServiceHost - ok
23:01:34.0917 0448 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\windows\system32\wdi.dll
23:01:34.0932 0448 WdiSystemHost - ok
23:01:34.0948 0448 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\windows\System32\webclnt.dll
23:01:34.0948 0448 WebClient - ok
23:01:34.0995 0448 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\windows\system32\wecsvc.dll
23:01:35.0010 0448 Wecsvc - ok
23:01:35.0042 0448 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\windows\System32\wercplsupport.dll
23:01:35.0042 0448 wercplsupport - ok
23:01:35.0073 0448 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\windows\System32\WerSvc.dll
23:01:35.0073 0448 WerSvc - ok
23:01:35.0120 0448 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
23:01:35.0120 0448 WinDefend - ok
23:01:35.0120 0448 WinHttpAutoProxySvc - ok
23:01:35.0182 0448 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
23:01:35.0182 0448 Winmgmt - ok
23:01:35.0229 0448 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\windows\system32\WsmSvc.dll
23:01:35.0244 0448 WinRM - ok
23:01:35.0291 0448 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\windows\System32\wlansvc.dll
23:01:35.0291 0448 Wlansvc - ok
23:01:35.0307 0448 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\windows\system32\DRIVERS\wmiacpi.sys
23:01:35.0322 0448 WmiAcpi - ok
23:01:35.0354 0448 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
23:01:35.0354 0448 wmiApSrv - ok
23:01:35.0432 0448 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
23:01:35.0432 0448 WMPNetworkSvc - ok
23:01:35.0463 0448 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\windows\System32\wpcsvc.dll
23:01:35.0478 0448 WPCSvc - ok
23:01:35.0525 0448 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
23:01:35.0525 0448 WPDBusEnum - ok
23:01:35.0588 0448 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\windows\system32\DRIVERS\wpdusb.sys
23:01:35.0588 0448 WpdUsb - ok
23:01:35.0697 0448 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:01:35.0712 0448 WPFFontCache_v0400 - ok
23:01:35.0728 0448 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
23:01:35.0728 0448 ws2ifsl - ok
23:01:35.0759 0448 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\windows\System32\wscsvc.dll
23:01:35.0759 0448 wscsvc - ok
23:01:35.0775 0448 WSearch - ok
23:01:35.0837 0448 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\windows\system32\wuaueng.dll
23:01:35.0853 0448 wuauserv - ok
23:01:35.0884 0448 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
23:01:35.0884 0448 WUDFRd - ok
23:01:35.0915 0448 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\windows\System32\WUDFSvc.dll
23:01:35.0915 0448 wudfsvc - ok
23:01:35.0962 0448 [ F72D4BFFA37E857D195048C498AFC61B ] yukonwlh C:\windows\system32\DRIVERS\yk60x86.sys
23:01:35.0962 0448 yukonwlh - ok
23:01:36.0009 0448 ================ Scan global ===============================
23:01:36.0024 0448 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\windows\system32\basesrv.dll
23:01:36.0071 0448 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\windows\system32\winsrv.dll
23:01:36.0071 0448 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\windows\system32\winsrv.dll
23:01:36.0102 0448 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\windows\system32\services.exe
23:01:36.0118 0448 [Global] - ok
23:01:36.0118 0448 ================ Scan MBR ==================================
23:01:36.0118 0448 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
23:01:36.0461 0448 \Device\Harddisk0\DR0 - ok
23:01:36.0461 0448 ================ Scan VBR ==================================
23:01:36.0461 0448 [ C942DBBB6E0DA8916E85BDD76A7B9B29 ] \Device\Harddisk0\DR0\Partition1
23:01:36.0461 0448 \Device\Harddisk0\DR0\Partition1 - ok
23:01:36.0539 0448 [ DCE8DA96672F1C6120BEE271EDD0B5EA ] \Device\Harddisk0\DR0\Partition2
23:01:36.0539 0448 \Device\Harddisk0\DR0\Partition2 - ok
23:01:36.0555 0448 [ 6A0E40271827A9F741159D4EE726370C ] \Device\Harddisk0\DR0\Partition3
23:01:36.0555 0448 \Device\Harddisk0\DR0\Partition3 - ok
23:01:36.0555 0448 ============================================================
23:01:36.0555 0448 Scan finished
23:01:36.0555 0448 ============================================================
23:01:36.0570 0308 Detected object count: 0
23:01:36.0570 0308 Actual detected object count: 0
23:03:22.0983 0468 Deinitialize success

Jdu na Combofix. Děkuji. J

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 22 říj 2012 00:45

Log:

ComboFix 12-10-21.02 - Jirka 21.10.2012 23:56:06.2.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.1976.1525 [GMT 2:00]
Spuštěný z: c:\users\Jirka\Downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
ADS - windows: deleted 0 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\users\Jirka\AppData\Roaming\inst.exe
c:\users\Jirka\AppData\Roaming\vso_ts_preview.xml
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-21 do 2012-10-21 )))))))))))))))))))))))))))))))
.
.
2012-10-21 22:02 . 2012-10-21 22:02 -------- d-----w- c:\users\Jirka\AppData\Local\temp
2012-10-21 22:02 . 2012-10-21 22:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-21 21:42 . 2012-10-21 21:42 -------- d-----w- C:\f4a52c7477f1165425cbc207a8
2012-10-21 21:10 . 2012-10-21 21:10 -------- d-----w- C:\ade06b9859b9a3cac9284dcd9710
2012-10-21 21:06 . 2012-10-21 21:06 -------- d-----w- c:\users\Jirka\AppData\Local\Adobe
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\users\Jirka\AppData\Roaming\Malwarebytes
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\programdata\Malwarebytes
2012-10-21 19:41 . 2012-09-29 17:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-21 19:06 . 2012-10-21 19:06 -------- d-----w- c:\users\Jirka\AppData\Local\VS Revo Group
2012-10-21 16:27 . 2012-10-21 16:27 -------- d-----w- c:\program files\Lavalys
2012-10-21 09:34 . 2012-10-21 09:34 -------- d-----w- C:\f6b7abfc2792f27f3074a02b163e25
2012-10-20 21:19 . 2012-10-20 21:19 -------- d-----w- C:\7596b2d098b48db6eec3f5f05e7b
2012-10-20 20:29 . 2012-10-20 20:30 -------- d-----w- C:\13dd9809f06427afbbd1100d
2012-10-20 17:45 . 2012-10-20 18:25 -------- d-----w- c:\users\Jirka\AppData\Roaming\GetRightToGo
2012-10-20 16:34 . 2012-10-20 16:35 -------- d-----w- c:\users\Jirka\záložky google chrome 20 října
2012-10-20 16:19 . 2012-10-20 16:19 -------- d-----w- c:\program files\BurnAware Free
2012-10-16 21:04 . 2012-10-20 18:01 -------- d-----w- C:\8c920fc7608760022aa87ec70e
2012-10-15 18:27 . 2012-10-20 18:01 -------- d-----w- C:\ac2986adf44e94bf092949ea37
2012-10-15 18:14 . 2012-10-20 18:01 -------- d-----w- C:\f46b175089723b1d0afc429d29
2012-10-15 18:12 . 2012-10-15 18:12 -------- d-----w- c:\program files\ESET
2012-10-15 18:00 . 2012-10-20 18:01 -------- d-----w- C:\b57d285135f104f6821ae807254e
2012-10-15 15:37 . 2012-10-20 18:01 -------- d-----w- C:\6fdbb982528c9aebd3c4f18170ed9b68
2012-10-14 22:12 . 2012-10-14 22:12 -------- d-----w- C:\1d400337df1e4b15fba07c5b638b
2012-10-14 18:34 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F9ADDCC0-C8C6-4013-BE11-CE5977E39AF6}\mpengine.dll
2012-10-12 18:03 . 2012-10-20 18:01 -------- d-----w- C:\b628274257cef4b25dfae96f0d4215
2012-10-10 19:18 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 19:18 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 19:18 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 19:18 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 19:18 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-10 19:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-10 19:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-03 19:51 . 2012-10-03 19:51 -------- d-----w- C:\found.000
2012-09-23 17:56 . 2012-08-24 15:53 834048 ----a-w- c:\windows\system32\wininet.dll
2012-09-23 17:56 . 2012-08-24 14:07 389632 ----a-w- c:\windows\system32\html.iec
2012-09-23 17:55 . 2012-08-24 15:53 129024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-09-23 17:55 . 2012-08-24 13:41 1383424 ----a-w- c:\windows\system32\mshtml.tlb
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 09:13 . 2011-12-04 20:20 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2011-12-04 20:20 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2011-12-04 20:20 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2011-12-04 20:20 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2011-12-04 20:20 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2011-12-04 20:20 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2011-12-04 20:19 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2011-12-04 20:19 227648 ----a-w- c:\windows\system32\aswBoot.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2012-09-24 3129184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-18 178712]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2008-05-21 24848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-10 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-10 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-10 145944]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-04 1314816]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-30 262144]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll c:\windows\System32\APSHook.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
backup=c:\windows\pss\Secunia PSI Tray.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\File Sanitizer]
2008-05-02 20:17 10244096 ----a-w- c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 13:50 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2008-04-15 21:51 488752 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-03-18 00:59 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2009-11-25 19:42 54672 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
2008-05-08 00:34 238984 ----a-w- c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-05-14 18:26 177456 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
2008-04-21 18:21 197904 ----a-w- c:\program files\InterVideo\DVD Check\DVDCheck.exe
.
R2 0VsNdis08;VitalAgent Network Driver 8.1;c:\program files\INS\VitalAgent\Program\VsNdis08.sys [x]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
Cognizance REG_MULTI_SZ ASBroker ASChannel
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-18 00:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004Core.job
- c:\users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-13 15:19]
.
2012-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004UA.job
- c:\users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-13 15:19]
.
2010-12-19 c:\windows\Tasks\User_Feed_Synchronization-{16640E34-8B66-4B2E-9326-17240BAED200}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-HP Health Check Scheduler - c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
MSConfigStartUp-PDF Complete - c:\program files\PDF Complete\pdfsty.exe
MSConfigStartUp-SMART Board Service - c:\program files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
MSConfigStartUp-SMART SNMP Agent - c:\program files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe
MSConfigStartUp-Sony Ericsson PC Suite - c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
MSConfigStartUp-SoundMAX - c:\program files\Analog Devices\SoundMAX\soundmax.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-22 00:02
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3566519359-2709819587-331994186-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i*n*i*^Iók\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1688)
c:\program files\Hewlett-Packard\File Sanitizer\HPPMDesktopIcon.dll
.
Celkový čas: 2012-10-22 00:04:48
ComboFix-quarantined-files.txt 2012-10-21 22:04
.
Před spuštěním: Volných bajtů: 104 634 580 992
Po spuštění: Volných bajtů: 104 550 268 928
.
- - End Of File - - 33F9DC6A8AFC64A9A300342D49CEBD3D

Hezký začátek týdne. J

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod memphisto » 22 říj 2012 13:02

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::
DirLook::
C:\f4a52c7477f1165425cbc207a8
C:\ade06b9859b9a3cac9284dcd9710
C:\f6b7abfc2792f27f3074a02b163e25
C:\7596b2d098b48db6eec3f5f05e7b
C:\13dd9809f06427afbbd1100d
C:\8c920fc7608760022aa87ec70e
C:\ac2986adf44e94bf092949ea37
C:\f46b175089723b1d0afc429d29
C:\b57d285135f104f6821ae807254e
C:\6fdbb982528c9aebd3c4f18170ed9b68
C:\1d400337df1e4b15fba07c5b638b
C:\b628274257cef4b25dfae96f0d4215

Folder::
c:\program files\ESET

File::
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004UA.job
c:\windows\Tasks\User_Feed_Synchronization-{16640E34-8B66-4B2E-9326-17240BAED200}.job

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]

RegNull::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť?.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 22 říj 2012 19:38

ComboFix 12-10-21.02 - Jirka 22.10.2012 16:37:23.3.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.1976.1448 [GMT 2:00]
Spuštěný z: c:\users\Jirka\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jirka\Downloads\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\stahovßnÝ\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
ADS - windows: deleted 0 bytes in 1 streams.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-22 do 2012-10-22 )))))))))))))))))))))))))))))))
.
.
2012-10-22 14:43 . 2012-10-22 14:43 -------- d-----w- c:\users\Jirka\AppData\Local\temp
2012-10-22 14:43 . 2012-10-22 14:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-22 14:09 . 2012-10-22 14:09 -------- d-----w- C:\a4f368dbc46d4d37c01d28eee0
2012-10-21 22:36 . 2012-10-21 22:37 -------- d-----w- C:\1155c05f8fa2da95ff49
2012-10-21 21:42 . 2012-10-21 21:42 -------- d-----w- C:\f4a52c7477f1165425cbc207a8
2012-10-21 21:10 . 2012-10-21 21:10 -------- d-----w- C:\ade06b9859b9a3cac9284dcd9710
2012-10-21 21:06 . 2012-10-21 21:06 -------- d-----w- c:\users\Jirka\AppData\Local\Adobe
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\users\Jirka\AppData\Roaming\Malwarebytes
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-10-21 19:41 . 2012-10-21 19:41 -------- d-----w- c:\programdata\Malwarebytes
2012-10-21 19:41 . 2012-09-29 17:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-21 19:06 . 2012-10-21 19:06 -------- d-----w- c:\users\Jirka\AppData\Local\VS Revo Group
2012-10-21 16:27 . 2012-10-21 16:27 -------- d-----w- c:\program files\Lavalys
2012-10-21 09:34 . 2012-10-21 09:34 -------- d-----w- C:\f6b7abfc2792f27f3074a02b163e25
2012-10-20 21:19 . 2012-10-20 21:19 -------- d-----w- C:\7596b2d098b48db6eec3f5f05e7b
2012-10-20 20:29 . 2012-10-20 20:30 -------- d-----w- C:\13dd9809f06427afbbd1100d
2012-10-20 17:45 . 2012-10-20 18:25 -------- d-----w- c:\users\Jirka\AppData\Roaming\GetRightToGo
2012-10-20 16:34 . 2012-10-20 16:35 -------- d-----w- c:\users\Jirka\záložky google chrome 20 října
2012-10-20 16:19 . 2012-10-20 16:19 -------- d-----w- c:\program files\BurnAware Free
2012-10-16 21:04 . 2012-10-20 18:01 -------- d-----w- C:\8c920fc7608760022aa87ec70e
2012-10-15 18:27 . 2012-10-20 18:01 -------- d-----w- C:\ac2986adf44e94bf092949ea37
2012-10-15 18:14 . 2012-10-20 18:01 -------- d-----w- C:\f46b175089723b1d0afc429d29
2012-10-15 18:12 . 2012-10-15 18:12 -------- d-----w- c:\program files\ESET
2012-10-15 18:00 . 2012-10-20 18:01 -------- d-----w- C:\b57d285135f104f6821ae807254e
2012-10-15 15:37 . 2012-10-20 18:01 -------- d-----w- C:\6fdbb982528c9aebd3c4f18170ed9b68
2012-10-14 22:12 . 2012-10-14 22:12 -------- d-----w- C:\1d400337df1e4b15fba07c5b638b
2012-10-14 18:34 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F9ADDCC0-C8C6-4013-BE11-CE5977E39AF6}\mpengine.dll
2012-10-12 18:03 . 2012-10-20 18:01 -------- d-----w- C:\b628274257cef4b25dfae96f0d4215
2012-10-10 19:18 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 19:18 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 19:18 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 19:18 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 19:18 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-10 19:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-10 19:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-03 19:51 . 2012-10-03 19:51 -------- d-----w- C:\found.000
2012-09-23 17:56 . 2012-08-24 15:53 834048 ----a-w- c:\windows\system32\wininet.dll
2012-09-23 17:56 . 2012-08-24 14:07 389632 ----a-w- c:\windows\system32\html.iec
2012-09-23 17:55 . 2012-08-24 15:53 129024 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-09-23 17:55 . 2012-08-24 13:41 1383424 ----a-w- c:\windows\system32\mshtml.tlb
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 09:13 . 2011-12-04 20:20 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2011-12-04 20:20 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2011-12-04 20:20 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2011-12-04 20:20 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2011-12-04 20:20 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2011-12-04 20:20 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2011-12-04 20:19 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2011-12-04 20:19 227648 ----a-w- c:\windows\system32\aswBoot.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2012-09-24 3129184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-18 178712]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2008-05-21 24848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-10 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-10 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-10 145944]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-04 1314816]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-30 262144]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll c:\windows\System32\APSHook.dll c:\windows\System32\APSHook.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
backup=c:\windows\pss\Secunia PSI Tray.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\File Sanitizer]
2008-05-02 20:17 10244096 ----a-w- c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 13:50 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2008-04-15 21:51 488752 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-03-18 00:59 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2009-11-25 19:42 54672 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
2008-05-08 00:34 238984 ----a-w- c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-05-14 18:26 177456 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 12:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
2008-04-21 18:21 197904 ----a-w- c:\program files\InterVideo\DVD Check\DVDCheck.exe
.
R2 0VsNdis08;VitalAgent Network Driver 8.1;c:\program files\INS\VitalAgent\Program\VsNdis08.sys [x]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 22 říj 2012 19:39

--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
Cognizance REG_MULTI_SZ ASBroker ASChannel
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-18 00:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004Core.job
- c:\users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-13 15:19]
.
2012-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3566519359-2709819587-331994186-1004UA.job
- c:\users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-13 15:19]
.
2010-12-19 c:\windows\Tasks\User_Feed_Synchronization-{16640E34-8B66-4B2E-9326-17240BAED200}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Doplňkový sken -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-22 16:43
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3566519359-2709819587-331994186-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i*n*i*^Iók\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1552)
c:\program files\Hewlett-Packard\File Sanitizer\HPPMDesktopIcon.dll
.
Celkový čas: 2012-10-22 16:45:27
ComboFix-quarantined-files.txt 2012-10-22 14:45
ComboFix2.txt 2012-10-21 22:04
.
Před spuštěním: Volných bajtů: 104 671 080 448
Po spuštění: Volných bajtů: 104 101 679 104
.
- - End Of File - - 2222AED553772EA13C1EF60396FC6CA1

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod jaro3 » 22 říj 2012 21:21

C:\f4a52c7477f1165425cbc207a8
C:\ade06b9859b9a3cac9284dcd9710
C:\f6b7abfc2792f27f3074a02b163e25
C:\7596b2d098b48db6eec3f5f05e7b
C:\13dd9809f06427afbbd1100d
C:\8c920fc7608760022aa87ec70e
C:\ac2986adf44e94bf092949ea37
C:\f46b175089723b1d0afc429d29
C:\b57d285135f104f6821ae807254e
C:\6fdbb982528c9aebd3c4f18170ed9b68
C:\1d400337df1e4b15fba07c5b638b
C:\b628274257cef4b25dfae96f0d4215

podívej se , co je v těch složkách..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

JStep
Level 1.5
Level 1.5
Příspěvky: 104
Registrován: říjen 12
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod JStep » 22 říj 2012 21:46

C:\f4a52c7477f1165425cbc207a8
C:\ade06b9859b9a3cac9284dcd9710
C:\f6b7abfc2792f27f3074a02b163e25
C:\7596b2d098b48db6eec3f5f05e7b
C:\13dd9809f06427afbbd1100d
C:\8c920fc7608760022aa87ec70e
C:\ac2986adf44e94bf092949ea37
C:\f46b175089723b1d0afc429d29
C:\b57d285135f104f6821ae807254e
C:\6fdbb982528c9aebd3c4f18170ed9b68
C:\1d400337df1e4b15fba07c5b638b
C:\b628274257cef4b25dfae96f0d4215

Ve všech, kromě posledního jsou aplikace "mrt" nebo "mrtstub". V posledním je soubor "mrt.exe._p"


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 71 hostů