moc prosím o pomoc :-) Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 13 lis 2012 19:31

Dobrý den, potřebuju pomoc, notebook stále pracuje na cca 80%.....padá Wi-Fi síť a než něco udělá, tak to je věčnost.....
Posílám HJT a MB log a ten druhý program něco našel :-(

HJT log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:25:53, on 13.11.2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18444)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\ASUSTPE.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Eliška\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

--
End of file - 4961 bytes


a MalwareBytes něco našel:
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.11.05.02

Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
Eliška :: NOTEBOOK [administrátor]

Ochrana: Povolena

5.11.2012 12:53:40
mbam-log-2012-11-05 (12-53-40).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 187311
Uplynulý čas: 15 minut, 7 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 5
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.
HKCR\CLSID\{055FD26D-3A88-4e15-963D-DC8493744B1D} (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.
HKCR\TypeLib\{77D6DDFA-7834-4541-B2B3-A8B0FB0E3924} (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{055FD26D-3A88-4E15-963D-DC8493744B1D} (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D} (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
C:\Program Files\ICQToolbar\toolbaru.dll (Trojan.BHO) -> Umístnění do karantény a smazání se zdařilo.

(konec)

Reklama
Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Žbeky » 13 lis 2012 20:30

Fixni:

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si TDSSKiller

Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 17 lis 2012 08:23

Nedá se to vůbec připojit....přes Wi-Fi mi to stále hodně padá, asi bych měla vyzkoušet, jestli by to nešlo lépe přes kabel, ale teď nemám kde..dávám sem ty LOGy, ale z jiného počítače, než se přihlásím na Vaše stránky, tak mi to trvá třeby i půl hodiny :-(

Vyčištěno s ATF, ale to jsem dělala i dřív....

17:22:52.0993 4016 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:22:53.0071 4016 ============================================================
17:22:53.0071 4016 Current date / time: 2012/11/14 17:22:53.0071
17:22:53.0071 4016 SystemInfo:
17:22:53.0071 4016
17:22:53.0071 4016 OS Version: 6.0.6001 ServicePack: 1.0
17:22:53.0071 4016 Product type: Workstation
17:22:53.0072 4016 ComputerName: NOTEBOOK
17:22:53.0072 4016 UserName: Eliška
17:22:53.0072 4016 Windows directory: C:\Windows
17:22:53.0072 4016 System windows directory: C:\Windows
17:22:53.0072 4016 Processor architecture: Intel x86
17:22:53.0072 4016 Number of processors: 2
17:22:53.0072 4016 Page size: 0x1000
17:22:53.0072 4016 Boot type: Normal boot
17:22:53.0072 4016 ============================================================
17:22:56.0067 4016 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x93E52, SectorsPerTrack: 0x4, TracksPerCylinder: 0x81, Type 'K0', Flags 0x00000050
17:22:56.0138 4016 Drive \Device\Harddisk2\DR2 - Size: 0x7AFFFE00 (1.92 Gb), SectorSize: 0x200, Cylinders: 0xFA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:22:56.0141 4016 ============================================================
17:22:56.0141 4016 \Device\Harddisk0\DR0:
17:22:56.0141 4016 MBR partitions:
17:22:56.0141 4016 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xDAC800, BlocksNum 0x950C800
17:22:56.0159 4016 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xA2B9800, BlocksNum 0x875F800
17:22:56.0159 4016 \Device\Harddisk2\DR2:
17:22:56.0162 4016 MBR partitions:
17:22:56.0162 4016 \Device\Harddisk2\DR2\Partition1: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0x3D7FC0
17:22:56.0162 4016 ============================================================
17:22:56.0701 4016 C: <-> \Device\Harddisk0\DR0\Partition1
17:22:56.0855 4016 D: <-> \Device\Harddisk0\DR0\Partition2
17:22:56.0855 4016 ============================================================
17:22:56.0856 4016 Initialize success
17:22:56.0856 4016 ============================================================
17:23:22.0572 3268 ============================================================
17:23:22.0573 3268 Scan started
17:23:22.0573 3268 Mode: Manual;
17:23:22.0573 3268 ============================================================
17:23:24.0432 3268 ================ Scan system memory ========================
17:23:24.0432 3268 System memory - ok
17:23:24.0433 3268 ================ Scan services =============================
17:23:25.0489 3268 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
17:23:25.0534 3268 ACPI - ok
17:23:25.0861 3268 [ 11A52CF7B265631DEEB24C6149309EFF ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:23:25.0885 3268 AdobeARMservice - ok
17:23:26.0088 3268 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
17:23:26.0155 3268 adp94xx - ok
17:23:26.0229 3268 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
17:23:26.0774 3268 adpahci - ok
17:23:26.0800 3268 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
17:23:26.0818 3268 adpu160m - ok
17:23:26.0929 3268 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
17:23:26.0944 3268 adpu320 - ok
17:23:27.0036 3268 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:23:27.0038 3268 AeLookupSvc - ok
17:23:27.0156 3268 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
17:23:27.0224 3268 AFD - ok
17:23:27.0341 3268 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
17:23:27.0430 3268 agp440 - ok
17:23:27.0510 3268 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
17:23:27.0593 3268 aic78xx - ok
17:23:27.0712 3268 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
17:23:27.0733 3268 ALG - ok
17:23:27.0770 3268 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
17:23:27.0783 3268 aliide - ok
17:23:27.0831 3268 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:23:27.0847 3268 amdagp - ok
17:23:27.0881 3268 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
17:23:27.0883 3268 amdide - ok
17:23:27.0924 3268 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
17:23:27.0937 3268 AmdK7 - ok
17:23:27.0976 3268 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
17:23:27.0993 3268 AmdK8 - ok
17:23:28.0047 3268 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
17:23:28.0062 3268 Appinfo - ok
17:23:28.0125 3268 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
17:23:28.0128 3268 arc - ok
17:23:28.0166 3268 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
17:23:28.0169 3268 arcsas - ok
17:23:28.0245 3268 [ 66597AD6098352D11239C0C42100B176 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
17:23:28.0418 3268 ASLDRService - ok
17:23:28.0480 3268 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:23:28.0503 3268 AsyncMac - ok
17:23:28.0728 3268 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
17:23:28.0729 3268 atapi - ok
17:23:29.0033 3268 [ 96FDFC9ACFD9C34EDE8E9E7BCA76CD1C ] Atc002 C:\Windows\system32\DRIVERS\L260x86.sys
17:23:29.0105 3268 Atc002 - ok
17:23:29.0505 3268 [ 0C8DFA21B1D9D2EF14B692104AE68A69 ] athr C:\Windows\system32\DRIVERS\athr.sys
17:23:29.0594 3268 athr - ok
17:23:29.0845 3268 [ 3481D12334F065BBA19C16399C9CB171 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
17:23:29.0990 3268 Ati External Event Utility - ok
17:23:30.0063 3268 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:23:30.0070 3268 AudioEndpointBuilder - ok
17:23:30.0091 3268 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:23:30.0096 3268 Audiosrv - ok
17:23:30.0208 3268 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
17:23:30.0238 3268 Beep - ok
17:23:30.0295 3268 [ 8582E233C346AEFE759833E8A30DD697 ] BFE C:\Windows\System32\bfe.dll
17:23:30.0303 3268 BFE - ok
17:23:30.0495 3268 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\system32\qmgr.dll
17:23:30.0532 3268 BITS - ok
17:23:30.0629 3268 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:23:30.0670 3268 bowser - ok
17:23:30.0739 3268 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
17:23:30.0741 3268 BrFiltLo - ok
17:23:30.0778 3268 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
17:23:30.0798 3268 BrFiltUp - ok
17:23:30.0843 3268 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
17:23:30.0847 3268 Browser - ok
17:23:30.0900 3268 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
17:23:30.0903 3268 Brserid - ok
17:23:30.0947 3268 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
17:23:30.0950 3268 BrSerWdm - ok
17:23:30.0985 3268 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
17:23:30.0987 3268 BrUsbMdm - ok
17:23:31.0014 3268 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
17:23:31.0015 3268 BrUsbSer - ok
17:23:31.0079 3268 [ DA7B195275BDA7F8FCF79B40E0F45DDE ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
17:23:31.0094 3268 BthEnum - ok
17:23:31.0163 3268 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
17:23:31.0174 3268 BTHMODEM - ok
17:23:31.0225 3268 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
17:23:31.0548 3268 BthPan - ok
17:23:31.0692 3268 [ 4A74BBB2B6761789F42A6613479BDB1D ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
17:23:31.0708 3268 BTHPORT - ok
17:23:31.0773 3268 [ 58EE7F5E68310BC8D4E7CEBD8358C12E ] BthServ C:\Windows\System32\bthserv.dll
17:23:31.0796 3268 BthServ - ok
17:23:31.0840 3268 [ 1A407F9B707A06F55AA150F9AA072B09 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
17:23:31.0855 3268 BTHUSB - ok
17:23:31.0892 3268 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:23:31.0905 3268 cdfs - ok
17:23:31.0964 3268 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:23:31.0967 3268 cdrom - ok
17:23:32.0052 3268 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
17:23:32.0053 3268 CertPropSvc - ok
17:23:32.0136 3268 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
17:23:32.0176 3268 circlass - ok
17:23:32.0291 3268 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
17:23:32.0447 3268 CLFS - ok
17:23:33.0283 3268 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:23:33.0463 3268 clr_optimization_v2.0.50727_32 - ok
17:23:33.0621 3268 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:23:33.0709 3268 CmBatt - ok
17:23:33.0833 3268 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:23:33.0921 3268 cmdide - ok
17:23:34.0099 3268 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:23:34.0147 3268 Compbatt - ok
17:23:34.0162 3268 COMSysApp - ok
17:23:34.0339 3268 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
17:23:34.0447 3268 crcdisk - ok
17:23:34.0580 3268 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
17:23:34.0656 3268 Crusoe - ok
17:23:35.0121 3268 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:23:35.0339 3268 CryptSvc - ok
17:23:36.0168 3268 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
17:23:37.0334 3268 DcomLaunch - ok
17:23:37.0427 3268 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:23:37.0519 3268 DfsC - ok
17:23:37.0905 3268 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
17:23:38.0878 3268 DFSR - ok
17:23:39.0067 3268 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
17:23:39.0081 3268 Dhcp - ok
17:23:39.0148 3268 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
17:23:39.0162 3268 disk - ok
17:23:39.0224 3268 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:23:39.0246 3268 Dnscache - ok
17:23:39.0301 3268 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
17:23:39.0309 3268 dot3svc - ok
17:23:39.0394 3268 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
17:23:39.0409 3268 DPS - ok
17:23:39.0549 3268 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:23:39.0563 3268 drmkaud - ok
17:23:39.0663 3268 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:23:39.0907 3268 DXGKrnl - ok
17:23:39.0979 3268 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
17:23:39.0996 3268 E1G60 - ok
17:23:40.0037 3268 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
17:23:40.0049 3268 EapHost - ok
17:23:40.0183 3268 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
17:23:40.0239 3268 Ecache - ok
17:23:40.0383 3268 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:23:40.0417 3268 ehRecvr - ok
17:23:40.0486 3268 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
17:23:40.0504 3268 ehSched - ok
17:23:40.0559 3268 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
17:23:40.0562 3268 ehstart - ok
17:23:40.0718 3268 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
17:23:40.0863 3268 elxstor - ok
17:23:41.0098 3268 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
17:23:41.0778 3268 EMDMgmt - ok
17:23:42.0053 3268 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
17:23:42.0304 3268 EventSystem - ok
17:23:42.0446 3268 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
17:23:42.0564 3268 exfat - ok
17:23:42.0686 3268 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:23:42.0766 3268 fastfat - ok
17:23:42.0857 3268 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:23:42.0885 3268 fdc - ok
17:23:42.0959 3268 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
17:23:42.0980 3268 fdPHost - ok
17:23:43.0094 3268 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
17:23:43.0134 3268 FDResPub - ok
17:23:43.0177 3268 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:23:43.0189 3268 FileInfo - ok
17:23:43.0241 3268 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:23:43.0254 3268 Filetrace - ok
17:23:43.0332 3268 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:23:43.0343 3268 flpydisk - ok
17:23:43.0467 3268 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:23:43.0812 3268 FltMgr - ok
17:23:44.0228 3268 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:23:44.0255 3268 FontCache3.0.0.0 - ok
17:23:44.0341 3268 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:23:44.0355 3268 Fs_Rec - ok
17:23:44.0668 3268 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
17:23:44.0735 3268 gagp30kx - ok
17:23:45.0041 3268 [ BA4A798183529FE251A3DCFA650670BF ] ghaio C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys
17:23:45.0487 3268 ghaio - ok
17:23:46.0236 3268 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
17:23:46.0574 3268 gpsvc - ok
17:23:46.0680 3268 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:23:46.0687 3268 HdAudAddService - ok
17:23:46.0733 3268 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
17:23:46.0744 3268 HDAudBus - ok
17:23:46.0788 3268 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
17:23:46.0791 3268 HidBth - ok
17:23:46.0835 3268 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
17:23:46.0850 3268 HidIr - ok
17:23:46.0944 3268 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\System32\hidserv.dll
17:23:46.0963 3268 hidserv - ok
17:23:47.0051 3268 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:23:47.0088 3268 HidUsb - ok
17:23:47.0209 3268 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:23:47.0263 3268 hkmsvc - ok
17:23:47.0361 3268 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
17:23:47.0386 3268 HpCISSs - ok
17:23:47.0527 3268 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:23:47.0537 3268 HTTP - ok
17:23:47.0579 3268 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
17:23:47.0592 3268 i2omp - ok
17:23:47.0698 3268 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:23:47.0717 3268 i8042prt - ok
17:23:47.0767 3268 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
17:23:47.0774 3268 iaStorV - ok
17:23:48.0102 3268 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:23:48.0569 3268 idsvc - ok
17:23:48.0619 3268 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
17:23:48.0635 3268 iirsp - ok
17:23:48.0822 3268 [ A3BC480A2BF8AA8E4DABD2D5DCE0AFAC ] IKEEXT C:\Windows\System32\ikeext.dll
17:23:49.0013 3268 IKEEXT - ok
17:23:49.0100 3268 [ AEA4C9BB21C12E8BE4078D836DD98F86 ] InCDfs C:\Windows\system32\drivers\InCDFs.sys
17:23:49.0116 3268 InCDfs - ok
17:23:49.0150 3268 [ 507CA5B34CCEE17FE5AF5B14A718775B ] InCDPass C:\Windows\system32\drivers\InCDPass.sys
17:23:49.0161 3268 InCDPass - ok
17:23:49.0205 3268 [ 2E977F77A1D479CF12950FC1ED70B415 ] InCDrec C:\Windows\system32\drivers\InCDrec.sys
17:23:49.0218 3268 InCDrec - ok
17:23:49.0242 3268 [ 3B98D9EB9E63F5AFFB532F977C09162F ] incdrm C:\Windows\system32\drivers\InCDRm.sys
17:23:49.0256 3268 incdrm - ok
17:23:49.0530 3268 [ 219CD67AC3547B0B29B7CDA0513E50BA ] InCDsrv C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
17:23:49.0883 3268 InCDsrv - ok
17:23:50.0499 3268 [ AEF2FA29204056B81BC4CBF30260DEE1 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
17:23:50.0796 3268 IntcAzAudAddService - ok
17:23:50.0853 3268 [ 97469037714070E45194ED318D636401 ] intelide C:\Windows\system32\drivers\intelide.sys
17:23:50.0856 3268 intelide - ok
17:23:50.0899 3268 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:23:50.0902 3268 intelppm - ok
17:23:50.0945 3268 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:23:50.0965 3268 IPBusEnum - ok
17:23:51.0031 3268 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:23:51.0044 3268 IpFilterDriver - ok
17:23:51.0086 3268 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:23:51.0094 3268 iphlpsvc - ok
17:23:51.0113 3268 IpInIp - ok
17:23:51.0169 3268 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
17:23:51.0173 3268 IPMIDRV - ok
17:23:51.0213 3268 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
17:23:51.0218 3268 IPNAT - ok
17:23:51.0467 3268 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:23:51.0657 3268 IRENUM - ok
17:23:51.0822 3268 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:23:51.0875 3268 isapnp - ok
17:23:52.0000 3268 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
17:23:52.0102 3268 iScsiPrt - ok
17:23:52.0184 3268 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
17:23:52.0207 3268 iteatapi - ok
17:23:52.0304 3268 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
17:23:52.0372 3268 iteraid - ok
17:23:52.0484 3268 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:23:52.0520 3268 kbdclass - ok
17:23:52.0618 3268 [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:23:52.0663 3268 kbdhid - ok
17:23:52.0767 3268 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
17:23:52.0810 3268 KeyIso - ok
17:23:53.0012 3268 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:23:53.0301 3268 KSecDD - ok
17:23:53.0544 3268 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
17:23:53.0689 3268 KtmRm - ok
17:23:53.0794 3268 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\System32\srvsvc.dll
17:23:53.0807 3268 LanmanServer - ok
17:23:54.0000 3268 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:23:54.0059 3268 LanmanWorkstation - ok
17:23:54.0254 3268 [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
17:23:54.0273 3268 LightScribeService - ok
17:23:54.0341 3268 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:23:54.0365 3268 lltdio - ok
17:23:54.0447 3268 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:23:54.0465 3268 lltdsvc - ok
17:23:54.0534 3268 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:23:54.0566 3268 lmhosts - ok
17:23:54.0666 3268 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
17:23:54.0690 3268 LSI_FC - ok
17:23:54.0728 3268 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
17:23:54.0737 3268 LSI_SAS - ok
17:23:54.0783 3268 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
17:23:54.0825 3268 LSI_SCSI - ok
17:23:54.0904 3268 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
17:23:54.0922 3268 luafv - ok
17:23:55.0095 3268 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:23:55.0103 3268 MBAMProtector - ok
17:23:55.0251 3268 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:23:55.0397 3268 MBAMScheduler - ok
17:23:55.0614 3268 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:23:55.0947 3268 MBAMService - ok
17:23:55.0990 3268 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:23:56.0004 3268 Mcx2Svc - ok
17:23:56.0123 3268 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
17:23:56.0138 3268 megasas - ok
17:23:57.0008 3268 [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
17:23:57.0021 3268 Microsoft Office Groove Audit Service - ok
17:23:57.0086 3268 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
17:23:57.0134 3268 MMCSS - ok
17:23:57.0203 3268 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
17:23:57.0220 3268 Modem - ok
17:23:57.0298 3268 [ CBB59C41F19EFEA1A000793E08070A62 ] MODEMCSA C:\Windows\system32\drivers\MODEMCSA.sys
17:23:57.0312 3268 MODEMCSA - ok
17:23:57.0387 3268 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:23:57.0400 3268 monitor - ok
17:23:57.0448 3268 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:23:57.0456 3268 mouclass - ok
17:23:57.0515 3268 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:23:57.0523 3268 mouhid - ok
17:23:57.0585 3268 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
17:23:57.0603 3268 MountMgr - ok
17:23:57.0734 3268 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:23:57.0761 3268 MozillaMaintenance - ok
17:23:57.0852 3268 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
17:23:57.0877 3268 MpFilter - ok
17:23:57.0944 3268 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
17:23:57.0976 3268 mpio - ok
17:23:58.0292 3268 [ A69630D039C38018689190234F866D77 ] MpKsl614977fa C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\MpKsl614977fa.sys
17:23:59.0813 3268 MpKsl614977fa - ok
17:24:00.0082 3268 [ A69630D039C38018689190234F866D77 ] MpKslf7ba8293 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\MpKslf7ba8293.sys
17:24:00.0084 3268 MpKslf7ba8293 - ok
17:24:00.0238 3268 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:24:00.0282 3268 mpsdrv - ok
17:24:00.0600 3268 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
17:24:01.0012 3268 MpsSvc - ok
17:24:01.0213 3268 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
17:24:01.0491 3268 Mraid35x - ok
17:24:01.0772 3268 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:24:01.0993 3268 MRxDAV - ok
17:24:02.0126 3268 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:24:02.0210 3268 mrxsmb - ok
17:24:02.0411 3268 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:24:02.0499 3268 mrxsmb10 - ok
17:24:02.0576 3268 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:24:02.0620 3268 mrxsmb20 - ok
17:24:02.0733 3268 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
17:24:02.0783 3268 msahci - ok
17:24:02.0867 3268 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:24:02.0907 3268 msdsm - ok
17:24:02.0961 3268 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
17:24:02.0982 3268 MSDTC - ok
17:24:03.0023 3268 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:24:03.0046 3268 Msfs - ok
17:24:03.0150 3268 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:24:03.0163 3268 msisadrv - ok
17:24:03.0221 3268 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:24:03.0257 3268 MSiSCSI - ok
17:24:03.0289 3268 msiserver - ok
17:24:03.0332 3268 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:24:03.0347 3268 MSKSSRV - ok
17:24:03.0455 3268 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
17:24:03.0469 3268 MsMpSvc - ok
17:24:03.0516 3268 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:24:03.0535 3268 MSPCLOCK - ok
17:24:03.0578 3268 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:24:03.0602 3268 MSPQM - ok
17:24:03.0699 3268 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:24:03.0720 3268 MsRPC - ok
17:24:03.0761 3268 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:24:03.0773 3268 mssmbios - ok
17:24:03.0835 3268 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:24:03.0850 3268 MSTEE - ok
17:24:03.0914 3268 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
17:24:03.0925 3268 MTsensor - ok
17:24:03.0978 3268 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
17:24:03.0992 3268 Mup - ok
17:24:04.0076 3268 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
17:24:04.0188 3268 napagent - ok
17:24:04.0373 3268 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:24:04.0411 3268 NativeWifiP - ok
17:24:04.0594 3268 [ 8F3357621D24ED31D98F96E18147FDAF ] NBService C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
17:24:04.0918 3268 NBService - ok
17:24:05.0125 3268 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:24:05.0346 3268 NDIS - ok
17:24:05.0413 3268 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:24:05.0422 3268 NdisTapi - ok
17:24:05.0486 3268 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:24:05.0489 3268 Ndisuio - ok
17:24:05.0545 3268 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:24:05.0563 3268 NdisWan - ok
17:24:05.0627 3268 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:24:05.0642 3268 NDProxy - ok
17:24:05.0715 3268 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:24:05.0753 3268 NetBIOS - ok
17:24:05.0836 3268 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
17:24:05.0914 3268 netbt - ok
17:24:05.0947 3268 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
17:24:05.0960 3268 Netlogon - ok
17:24:06.0085 3268 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
17:24:06.0192 3268 Netman - ok
17:24:06.0323 3268 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
17:24:06.0783 3268 netprofm - ok
17:24:06.0828 3268 [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:24:06.0846 3268 NetTcpPortSharing - ok
17:24:07.0304 3268 [ A15F219208843A5A210C8CB391384453 ] NETw3v32 C:\Windows\system32\DRIVERS\NETw3v32.sys
17:24:08.0110 3268 NETw3v32 - ok
17:24:08.0162 3268 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
17:24:08.0179 3268 nfrd960 - ok
17:24:08.0277 3268 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:24:08.0355 3268 NlaSvc - ok
17:24:08.0606 3268 [ FFD209EA219A2599F2F551B80AE6B0BF ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
17:24:08.0625 3268 NMIndexingService - ok
17:24:08.0685 3268 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:24:08.0709 3268 Npfs - ok
17:24:08.0778 3268 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
17:24:08.0792 3268 nsi - ok
17:24:08.0859 3268 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:24:08.0874 3268 nsiproxy - ok
17:24:09.0082 3268 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:24:09.0517 3268 Ntfs - ok
17:24:09.0572 3268 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
17:24:09.0575 3268 ntrigdigi - ok
17:24:09.0658 3268 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
17:24:09.0659 3268 Null - ok
17:24:12.0430 3268 [ CFDDEDC1151839DD71F78472645214A5 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:24:15.0298 3268 nvlddmkm - ok
17:24:15.0450 3268 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:24:15.0463 3268 nvraid - ok
17:24:15.0522 3268 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:24:15.0539 3268 nvstor - ok
17:24:15.0576 3268 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:24:15.0592 3268 nv_agp - ok
17:24:15.0604 3268 NwlnkFlt - ok
17:24:15.0630 3268 NwlnkFwd - ok
17:24:15.0840 3268 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:24:16.0063 3268 odserv - ok
17:24:16.0149 3268 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
17:24:17.0505 3268 ohci1394 - ok
17:24:17.0593 3268 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:24:17.0622 3268 ose - ok
17:24:17.0809 3268 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
17:24:17.0893 3268 p2pimsvc - ok
17:24:18.0085 3268 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
17:24:18.0100 3268 p2psvc - ok
17:24:18.0249 3268 [ 01907300EB52206B06FACB9608F369A9 ] PanService C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
17:24:18.0288 3268 PanService - ok
17:24:18.0341 3268 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
17:24:20.0606 3268 Parport - ok
17:24:20.0651 3268 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:24:22.0095 3268 partmgr - ok
17:24:22.0185 3268 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
17:24:24.0106 3268 Parvdm - ok
17:24:24.0178 3268 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
17:24:24.0199 3268 PcaSvc - ok
17:24:24.0278 3268 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
17:24:25.0645 3268 pci - ok
17:24:25.0699 3268 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
17:24:25.0701 3268 pciide - ok
17:24:25.0796 3268 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:24:25.0886 3268 pcmcia - ok
17:24:26.0125 3268 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:24:26.0749 3268 PEAUTH - ok
17:24:27.0107 3268 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
17:24:27.0800 3268 pla - ok
17:24:27.0907 3268 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:24:27.0939 3268 PlugPlay - ok
17:24:28.0126 3268 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
17:24:28.0398 3268 PNRPAutoReg - ok
17:24:28.0551 3268 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
17:24:28.0566 3268 PNRPsvc - ok
17:24:28.0714 3268 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:24:28.0770 3268 PolicyAgent - ok
17:24:28.0851 3268 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:24:28.0874 3268 PptpMiniport - ok
17:24:28.0953 3268 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
17:24:28.0996 3268 Processor - ok
17:24:29.0040 3268 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
17:24:29.0061 3268 ProfSvc - ok
17:24:29.0086 3268 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:24:29.0104 3268 ProtectedStorage - ok
17:24:29.0220 3268 [ A114CFE308C24B8235B03CFDFFE11E99 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
17:24:29.0232 3268 PSched - ok
17:24:29.0476 3268 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:24:29.0898 3268 ql2300 - ok
17:24:29.0972 3268 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:24:29.0986 3268 ql40xx - ok
17:24:30.0103 3268 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
17:24:30.0125 3268 QWAVE - ok
17:24:30.0201 3268 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:24:30.0219 3268 QWAVEdrv - ok
17:24:30.0548 3268 [ 252826C4BC88B01E945C2D3C6603F3B0 ] R300 C:\Windows\system32\DRIVERS\atikmdag.sys
17:24:30.0969 3268 R300 - ok
17:24:31.0147 3268 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:24:31.0178 3268 RasAcd - ok
17:24:31.0243 3268 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
17:24:31.0443 3268 RasAuto - ok
17:24:31.0572 3268 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:24:31.0590 3268 Rasl2tp - ok
17:24:31.0679 3268 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
17:24:31.0802 3268 RasMan - ok
17:24:31.0842 3268 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:24:31.0855 3268 RasPppoe - ok
17:24:31.0894 3268 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:24:31.0949 3268 RasSstp - ok
17:24:32.0025 3268 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:24:32.0057 3268 rdbss - ok
17:24:32.0147 3268 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:24:32.0150 3268 RDPCDD - ok
17:24:32.0258 3268 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
17:24:32.0381 3268 rdpdr - ok
17:24:32.0395 3268 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:24:32.0403 3268 RDPENCDD - ok
17:24:32.0529 3268 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:24:32.0570 3268 RDPWD - ok
17:24:32.0623 3268 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
17:24:32.0637 3268 RemoteAccess - ok
17:24:32.0744 3268 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:24:32.0763 3268 RemoteRegistry - ok
17:24:32.0849 3268 [ 34CC78C06587718C2AD6D3AA83B1F072 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
17:24:32.0865 3268 RFCOMM - ok
17:24:32.0934 3268 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
17:24:32.0946 3268 RpcLocator - ok
17:24:33.0098 3268 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
17:24:33.0321 3268 RpcSs - ok
17:24:33.0374 3268 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:24:33.0395 3268 rspndr - ok
17:24:33.0461 3268 [ 283392AF1860ECDB5E0F8EBD7F3D72DF ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
17:24:33.0474 3268 RTL8169 - ok
17:24:33.0506 3268 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
17:24:33.0518 3268 SamSs - ok
17:24:33.0591 3268 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:24:33.0599 3268 sbp2port - ok
17:24:33.0665 3268 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:24:33.0681 3268 SCardSvr - ok
17:24:33.0868 3268 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
17:24:34.0079 3268 Schedule - ok
17:24:34.0110 3268 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
17:24:34.0113 3268 SCPolicySvc - ok
17:24:34.0181 3268 [ 4339A2585708C7D9B0C0CE5AAD3DD6FF ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
17:24:34.0184 3268 sdbus - ok
17:24:34.0241 3268 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:24:34.0262 3268 SDRSVC - ok
17:24:34.0295 3268 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:24:34.0297 3268 secdrv - ok
17:24:34.0342 3268 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
17:24:34.0354 3268 seclogon - ok
17:24:34.0449 3268 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
17:24:34.0459 3268 SENS - ok
17:24:34.0545 3268 [ 6CD8DC61304BF5CA16FE48DC3039CC05 ] Ser2pl C:\Windows\system32\DRIVERS\ser2pl.sys
17:24:34.0555 3268 Ser2pl - ok
17:24:34.0594 3268 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:24:34.0596 3268 Serenum - ok

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 17 lis 2012 08:23

17:24:34.0627 3268 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
17:24:34.0631 3268 Serial - ok
17:24:34.0680 3268 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:24:34.0682 3268 sermouse - ok
17:24:34.0823 3268 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
17:24:34.0870 3268 SessionEnv - ok
17:24:34.0903 3268 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:24:34.0905 3268 sffdisk - ok
17:24:34.0954 3268 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:24:34.0970 3268 sffp_mmc - ok
17:24:35.0011 3268 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:24:35.0030 3268 sffp_sd - ok
17:24:35.0064 3268 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:24:35.0097 3268 sfloppy - ok
17:24:35.0171 3268 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:24:35.0227 3268 SharedAccess - ok
17:24:35.0309 3268 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:24:35.0353 3268 ShellHWDetection - ok
17:24:35.0406 3268 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:24:35.0444 3268 sisagp - ok
17:24:35.0470 3268 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
17:24:35.0499 3268 SiSRaid2 - ok
17:24:35.0526 3268 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:24:35.0559 3268 SiSRaid4 - ok
17:24:35.0772 3268 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:24:35.0874 3268 SkypeUpdate - ok
17:24:36.0649 3268 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
17:24:37.0625 3268 slsvc - ok
17:24:37.0707 3268 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
17:24:37.0719 3268 SLUINotify - ok
17:24:37.0747 3268 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:24:37.0761 3268 Smb - ok
17:24:38.0010 3268 [ D9BFD2298F5CF116D8EAAE3B02DCEE2E ] smserial C:\Windows\system32\DRIVERS\smserial.sys
17:24:38.0532 3268 smserial - ok
17:24:38.0598 3268 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:24:38.0625 3268 SNMPTRAP - ok
17:24:38.0704 3268 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
17:24:38.0715 3268 spldr - ok
17:24:38.0841 3268 [ D1E30EEA74ED4C65A72AFDE5B6FA36EE ] spmgr C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
17:24:38.0867 3268 spmgr - ok
17:24:38.0931 3268 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
17:24:38.0946 3268 Spooler - ok
17:24:39.0020 3268 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:24:39.0176 3268 srv - ok
17:24:39.0217 3268 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:24:39.0224 3268 srv2 - ok
17:24:39.0259 3268 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:24:39.0270 3268 srvnet - ok
17:24:39.0350 3268 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:24:39.0442 3268 SSDPSRV - ok
17:24:39.0868 3268 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:24:39.0938 3268 SstpSvc - ok
17:24:40.0104 3268 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
17:24:40.0226 3268 stisvc - ok
17:24:40.0480 3268 [ 8181A2ECC2B5ECCD26B05F6DAD1A8736 ] StkCMini C:\Windows\system32\Drivers\StkCMini.sys
17:24:40.0990 3268 StkCMini - ok
17:24:41.0101 3268 [ 54FB71D9645AE6754BA3390813280DBD ] StkSSrv C:\Windows\System32\StkCSrv.exe
17:24:41.0124 3268 StkSSrv - ok
17:24:41.0149 3268 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:24:41.0162 3268 swenum - ok
17:24:41.0636 3268 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
17:24:41.0770 3268 swprv - ok
17:24:41.0872 3268 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
17:24:41.0897 3268 Symc8xx - ok
17:24:41.0964 3268 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
17:24:41.0975 3268 Sym_hi - ok
17:24:42.0049 3268 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
17:24:42.0069 3268 Sym_u3 - ok
17:24:42.0187 3268 [ 24B43E9A3E6CACF9AFC69F48E9DEB690 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
17:24:42.0274 3268 SynTP - ok
17:24:42.0525 3268 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
17:24:42.0747 3268 SysMain - ok
17:24:42.0835 3268 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:24:42.0850 3268 TabletInputService - ok
17:24:43.0013 3268 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
17:24:43.0060 3268 TapiSrv - ok
17:24:43.0104 3268 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
17:24:43.0117 3268 TBS - ok
17:24:43.0422 3268 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:24:43.0800 3268 Tcpip - ok
17:24:44.0043 3268 [ 782568AB6A43160A159B6215B70BCCE9 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
17:24:44.0061 3268 Tcpip6 - ok
17:24:44.0111 3268 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:24:44.0129 3268 tcpipreg - ok
17:24:44.0182 3268 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:24:44.0201 3268 TDPIPE - ok
17:24:44.0257 3268 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:24:44.0269 3268 TDTCP - ok
17:24:44.0328 3268 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:24:44.0340 3268 tdx - ok
17:24:44.0365 3268 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:24:44.0380 3268 TermDD - ok
17:24:44.0541 3268 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
17:24:44.0731 3268 TermService - ok
17:24:44.0793 3268 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
17:24:44.0834 3268 Themes - ok
17:24:44.0875 3268 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
17:24:44.0891 3268 THREADORDER - ok
17:24:45.0027 3268 [ 8D624D3BD1F2D78BD1C01A2D4E954B4E ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys
17:24:48.0176 3268 tosporte - ok
17:24:48.0276 3268 [ A594DBD80CA5426E2E558BF79195A110 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys
17:24:49.0508 3268 tosrfbd - ok
17:24:49.0594 3268 [ 90C8525BC578AAFFE87C2D0ED4379E9E ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys
17:24:49.0968 3268 tosrfbnp - ok
17:24:50.0086 3268 [ 5BA1CA3B3CDDB1DDC67DF473F05D1EC2 ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys
17:24:50.0893 3268 Tosrfcom - ok
17:24:51.0574 3268 [ 28099A4E52148319AFA685D93A2244D0 ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys
17:24:53.0590 3268 Tosrfhid - ok
17:24:53.0934 3268 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys
17:24:53.0956 3268 tosrfnds - ok
17:24:54.0011 3268 [ 20CC46C5D3326122E1A0A8C9DAD00E0D ] Tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys
17:24:54.0263 3268 Tosrfusb - ok
17:24:54.0340 3268 [ 6D9AD3534A9CF7E4B86C6EAE8BC335F6 ] TPM C:\Windows\system32\drivers\tpm.sys
17:24:54.0358 3268 TPM - ok
17:24:54.0465 3268 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
17:24:54.0494 3268 TrkWks - ok
17:24:54.0652 3268 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:24:54.0668 3268 TrustedInstaller - ok
17:24:54.0715 3268 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:24:54.0719 3268 tssecsrv - ok
17:24:54.0770 3268 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
17:24:54.0793 3268 tunmp - ok
17:24:54.0855 3268 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:24:54.0872 3268 tunnel - ok
17:24:54.0913 3268 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:24:54.0918 3268 uagp35 - ok
17:24:54.0972 3268 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:24:54.0994 3268 udfs - ok
17:24:55.0064 3268 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:24:55.0080 3268 UI0Detect - ok
17:24:55.0126 3268 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:24:55.0149 3268 uliagpkx - ok
17:24:55.0221 3268 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
17:24:55.0367 3268 uliahci - ok
17:24:55.0448 3268 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
17:24:55.0466 3268 UlSata - ok
17:24:55.0532 3268 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
17:24:55.0556 3268 ulsata2 - ok
17:24:55.0641 3268 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:24:55.0674 3268 umbus - ok
17:24:55.0800 3268 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
17:24:55.0901 3268 upnphost - ok
17:24:56.0042 3268 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:24:56.0061 3268 usbccgp - ok
17:24:56.0151 3268 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:24:56.0198 3268 usbcir - ok
17:24:56.0274 3268 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:24:56.0452 3268 usbehci - ok
17:24:56.0681 3268 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:24:56.0771 3268 usbhub - ok
17:24:56.0813 3268 [ 7BDB7B0E7D45AC0402D78B90789EF47C ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:24:56.0825 3268 usbohci - ok
17:24:56.0876 3268 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:24:56.0890 3268 usbprint - ok
17:24:56.0966 3268 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:24:56.0985 3268 usbscan - ok
17:24:57.0050 3268 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:24:57.0054 3268 USBSTOR - ok
17:24:57.0105 3268 [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:24:57.0129 3268 usbuhci - ok
17:24:57.0192 3268 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
17:24:57.0207 3268 UxSms - ok
17:24:57.0362 3268 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
17:24:57.0507 3268 vds - ok
17:24:57.0619 3268 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:24:57.0635 3268 vga - ok
17:24:57.0704 3268 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
17:24:57.0716 3268 VgaSave - ok
17:24:57.0748 3268 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:24:57.0762 3268 viaagp - ok
17:24:57.0831 3268 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:24:57.0847 3268 ViaC7 - ok
17:24:57.0901 3268 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
17:24:57.0973 3268 viaide - ok
17:24:58.0008 3268 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:24:58.0016 3268 volmgr - ok
17:24:58.0106 3268 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:24:58.0206 3268 volmgrx - ok
17:24:58.0251 3268 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:24:58.0292 3268 volsnap - ok
17:24:58.0364 3268 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:24:58.0382 3268 vsmraid - ok
17:24:58.0665 3268 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
17:24:59.0065 3268 VSS - ok
17:24:59.0165 3268 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
17:24:59.0277 3268 W32Time - ok
17:24:59.0328 3268 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:24:59.0332 3268 WacomPen - ok
17:24:59.0397 3268 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
17:24:59.0400 3268 Wanarp - ok
17:24:59.0420 3268 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:24:59.0423 3268 Wanarpv6 - ok
17:24:59.0639 3268 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:24:59.0827 3268 wcncsvc - ok
17:24:59.0886 3268 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:24:59.0904 3268 WcsPlugInService - ok
17:24:59.0963 3268 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
17:25:00.0013 3268 Wd - ok
17:25:00.0227 3268 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:25:00.0649 3268 Wdf01000 - ok
17:25:00.0732 3268 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:25:00.0803 3268 WdiServiceHost - ok
17:25:00.0823 3268 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:25:00.0830 3268 WdiSystemHost - ok
17:25:00.0991 3268 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
17:25:01.0125 3268 WebClient - ok
17:25:01.0253 3268 [ 905214925A88311FCE52F66153DE7610 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:25:01.0807 3268 Wecsvc - ok
17:25:02.0048 3268 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:25:02.0107 3268 wercplsupport - ok
17:25:02.0171 3268 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
17:25:02.0202 3268 WerSvc - ok
17:25:02.0406 3268 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:25:02.0529 3268 WinDefend - ok
17:25:02.0557 3268 WinHttpAutoProxySvc - ok
17:25:02.0975 3268 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:25:03.0037 3268 Winmgmt - ok
17:25:03.0313 3268 [ 20FC93FDC916843CFDFCAA7A1B0DB16F ] WinRM C:\Windows\system32\WsmSvc.dll
17:25:03.0670 3268 WinRM - ok
17:25:03.0822 3268 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:25:03.0878 3268 Wlansvc - ok
17:25:03.0938 3268 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:25:03.0958 3268 WmiAcpi - ok
17:25:04.0005 3268 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:25:04.0041 3268 wmiApSrv - ok
17:25:04.0218 3268 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:25:04.0428 3268 WMPNetworkSvc - ok
17:25:04.0656 3268 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:25:05.0156 3268 WPCSvc - ok
17:25:05.0723 3268 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:25:05.0860 3268 WPDBusEnum - ok
17:25:06.0038 3268 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
17:25:06.0101 3268 WpdUsb - ok
17:25:06.0171 3268 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:25:06.0212 3268 ws2ifsl - ok
17:25:06.0485 3268 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\system32\wscsvc.dll
17:25:06.0620 3268 wscsvc - ok
17:25:06.0631 3268 WSearch - ok
17:25:07.0118 3268 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
17:25:08.0171 3268 wuauserv - ok
17:25:08.0259 3268 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:25:08.0313 3268 WUDFRd - ok
17:25:08.0377 3268 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:25:08.0401 3268 wudfsvc - ok
17:25:08.0556 3268 ================ Scan global ===============================
17:25:08.0767 3268 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
17:25:08.0996 3268 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
17:25:09.0295 3268 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
17:25:09.0448 3268 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
17:25:09.0566 3268 [Global] - ok
17:25:09.0567 3268 ================ Scan MBR ==================================
17:25:09.0620 3268 [ 64B1E91C5C6C2157642651010728F90F ] \Device\Harddisk0\DR0
17:25:12.0545 3268 \Device\Harddisk0\DR0 - ok
17:25:12.0559 3268 [ E5FA06ACA0D60BA9C870D0EF3D9898C9 ] \Device\Harddisk2\DR2
17:25:21.0070 3268 \Device\Harddisk2\DR2 - ok
17:25:21.0070 3268 ================ Scan VBR ==================================
17:25:21.0094 3268 [ 5456B3E64501BD8401FEF31921EC4469 ] \Device\Harddisk0\DR0\Partition1
17:25:21.0129 3268 \Device\Harddisk0\DR0\Partition1 - ok
17:25:21.0176 3268 [ 04224F8E1D74AAA9C8B2A56834B24E96 ] \Device\Harddisk0\DR0\Partition2
17:25:21.0194 3268 \Device\Harddisk0\DR0\Partition2 - ok
17:25:21.0204 3268 [ DD049007F8D9C1CFC40B22342FFD80CF ] \Device\Harddisk2\DR2\Partition1
17:25:21.0207 3268 \Device\Harddisk2\DR2\Partition1 - ok
17:25:21.0208 3268 ============================================================
17:25:21.0208 3268 Scan finished
17:25:21.0208 3268 ============================================================
17:25:21.0901 0804 Detected object count: 0
17:25:21.0901 0804 Actual detected object count: 0
18:12:58.0200 2268 Deinitialize success

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 17 lis 2012 08:24

ComboFix 12-11-14.01 - Eliška 14.11.2012 19:18:54.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.895.275 [GMT 1:00]
Spuštěný z: c:\users\EliÜka\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msvcr71.dll
c:\windows\PFRO.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-14 do 2012-11-14 )))))))))))))))))))))))))))))))
.
.
2012-11-14 18:39 . 2012-11-14 18:40 -------- d-----w- c:\users\Eliška\AppData\Local\temp
2012-11-14 18:39 . 2012-11-14 18:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-14 16:19 . 2012-11-14 16:19 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\MpKslf7ba8293.sys
2012-11-14 13:57 . 2012-11-14 13:57 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\MpKsl614977fa.sys
2012-11-13 19:14 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-11-13 19:14 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2012-11-13 19:11 . 2012-11-13 19:11 -------- d-----w- c:\program files\Microsoft Works
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\windows\PCHEALTH
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\program files\Microsoft.NET
2012-11-13 18:59 . 2012-11-13 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-11-13 18:55 . 2012-11-13 18:55 -------- d-----r- C:\MSOCache
2012-11-13 18:32 . 2010-09-06 16:23 17920 ----a-w- c:\windows\system32\netevent.dll
2012-11-13 18:32 . 2010-09-06 16:24 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-11-13 18:32 . 2011-02-16 15:29 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-11-13 18:32 . 2010-06-16 15:12 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-11-13 18:32 . 2011-02-16 13:24 292864 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 18:31 . 2010-08-31 15:41 954752 ----a-w- c:\windows\system32\mfc40.dll
2012-11-13 18:31 . 2010-08-31 15:41 954288 ----a-w- c:\windows\system32\mfc40u.dll
2012-11-13 18:30 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2012-11-13 18:30 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2012-11-13 18:30 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2012-11-13 18:30 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2012-11-13 18:30 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2012-11-13 18:29 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-13 18:27 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-11-13 16:58 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\mpengine.dll
2012-11-13 16:34 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-11-13 16:34 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-11-13 16:34 . 2011-04-29 12:49 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-11-13 16:34 . 2011-04-29 12:49 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-11-13 16:33 . 2011-05-02 16:00 766464 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2012-11-13 16:33 . 2010-04-05 16:08 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2012-11-13 16:33 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2012-11-13 16:32 . 2010-12-20 15:39 563200 ----a-w- c:\windows\system32\oleaut32.dll
2012-11-13 16:07 . 2012-11-13 16:07 -------- d-----w- c:\users\Eliška\AppData\Roaming\WinRAR
2012-11-13 15:45 . 2010-04-16 16:10 501760 ----a-w- c:\windows\system32\usp10.dll
2012-11-13 15:45 . 2010-12-28 14:56 57344 ----a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2012-11-13 15:45 . 2010-12-28 14:56 253952 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-11-13 15:45 . 2010-12-28 14:56 180224 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-11-13 15:45 . 2010-12-28 14:57 409600 ----a-w- c:\windows\system32\odbc32.dll
2012-11-13 15:45 . 2010-12-28 14:56 241664 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-11-13 15:45 . 2010-12-28 14:56 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-11-13 15:44 . 2011-02-22 12:51 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-11-13 15:44 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2012-11-13 15:43 . 2010-06-18 16:43 36352 ----a-w- c:\windows\system32\rtutils.dll
2012-11-13 15:43 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2012-11-13 15:42 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
2012-11-13 15:42 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
2012-11-13 15:40 . 2010-12-17 16:43 2067456 ----a-w- c:\windows\system32\mstscax.dll
2012-11-13 15:40 . 2010-12-17 15:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-11-13 14:41 . 2012-11-13 14:41 -------- d-----w- c:\users\Eliška\AppData\Local\Mozilla
2012-11-13 14:40 . 2012-11-13 14:40 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-11-10 13:06 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-11-10 12:47 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-11-10 12:47 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-11-10 12:47 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-11-10 12:47 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-11-10 12:47 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-11-06 20:41 . 2010-10-15 14:08 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-11-06 20:41 . 2010-10-15 13:48 1205080 ----a-w- c:\windows\system32\ntdll.dll
2012-11-06 20:41 . 2010-10-15 14:08 3600272 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-11-06 20:30 . 2011-03-03 14:56 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-11-06 20:30 . 2011-03-03 13:01 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-11-06 20:11 . 2010-01-29 16:22 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2012-11-06 20:11 . 2010-05-27 19:16 81920 ----a-w- c:\windows\system32\iccvid.dll
2012-11-06 20:11 . 2011-02-18 13:31 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2012-11-06 20:11 . 2011-07-06 14:56 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-11-06 20:11 . 2011-04-29 12:49 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-11-06 20:11 . 2011-04-29 12:49 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-11-06 19:42 . 2010-05-04 18:39 248832 ----a-w- c:\windows\system32\msshsq.dll
2012-11-06 19:42 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-11-06 19:41 . 2011-05-02 15:58 738816 ----a-w- c:\windows\system32\inetcomm.dll
2012-11-06 19:31 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-11-06 19:31 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-11-06 19:31 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-11-06 19:24 . 2011-03-10 16:12 1136640 ----a-w- c:\windows\system32\mfc42.dll
2012-11-06 19:24 . 2011-03-10 16:12 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2012-11-06 19:24 . 2010-06-28 16:15 1315840 ----a-w- c:\windows\system32\ole32.dll
2012-11-06 19:24 . 2010-06-28 14:31 339968 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2012-11-06 19:24 . 2010-08-26 16:07 157184 ----a-w- c:\windows\system32\t2embed.dll
2012-11-06 19:24 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 19:24 . 2011-04-21 13:16 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-11-06 19:23 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2012-11-06 18:57 . 2010-08-17 13:32 126464 ----a-w- c:\windows\system32\spoolsv.exe
2012-11-06 18:47 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde.dll
2012-11-06 18:47 . 2010-12-29 17:41 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-11-06 18:47 . 2010-12-29 17:41 323072 ----a-w- c:\windows\system32\sbe.dll
2012-11-06 18:47 . 2010-12-29 17:39 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2012-11-06 18:47 . 2010-12-29 17:41 153088 ----a-w- c:\windows\system32\sbeio.dll
2012-11-06 18:42 . 2010-06-11 15:30 1257472 ----a-w- c:\windows\system32\msxml3.dll
2012-11-06 18:42 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2012-11-06 18:42 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2012-11-06 18:42 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2012-11-06 18:42 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-11-06 18:42 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2012-11-06 18:42 . 2008-05-20 02:07 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-11-06 18:42 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2012-11-06 18:41 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-06 18:40 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\wshom.ocx
2012-11-06 18:40 . 2008-05-08 21:59 90112 ----a-w- c:\windows\system32\wshext.dll
2012-11-06 18:40 . 2008-05-08 21:59 155648 ----a-w- c:\windows\system32\wscript.exe
2012-11-06 18:40 . 2008-05-08 21:59 180224 ----a-w- c:\windows\system32\scrobj.dll
2012-11-06 18:40 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\cscript.exe
2012-11-06 18:40 . 2008-05-08 21:59 172032 ----a-w- c:\windows\system32\scrrun.dll
2012-11-06 18:12 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
2012-11-05 11:57 . 2012-11-05 11:57 -------- d-----w- c:\program files\CCleaner
2012-11-05 11:43 . 2012-11-05 11:43 -------- d-----w- c:\users\Eliška\AppData\Roaming\Malwarebytes
2012-11-05 11:42 . 2012-11-05 11:42 -------- d-----w- c:\programdata\Malwarebytes
2012-11-05 11:42 . 2012-11-05 11:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-05 11:42 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-05 11:38 . 2012-11-05 11:39 -------- d-----w- c:\program files\Common Files\Adobe
2012-11-05 11:30 . 2012-11-05 11:30 -------- d-----w- c:\program files\Common Files\Java
2012-11-05 11:30 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-05 11:30 . 2012-11-05 11:28 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-11-05 11:30 . 2012-11-05 11:28 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-11-05 11:29 . 2012-11-05 11:28 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-05 11:27 . 2012-11-05 11:27 -------- d-----w- c:\program files\Java
2012-11-05 10:24 . 2012-11-05 10:24 -------- d-----w- C:\PerfLogs
2012-11-05 09:14 . 2012-11-05 09:17 -------- d-----w- c:\program files\Microsoft Security Client
2012-11-04 15:46 . 2012-11-04 15:48 33874278 ----a-w- c:\windows\hklmSY.reg
2012-11-04 15:45 . 2012-11-04 15:53 155602356 ----a-w- c:\windows\hklmSW.reg
2012-11-04 15:44 . 2012-11-04 15:48 35510380 ----a-w- c:\windows\hkcrRT.reg
2012-11-04 14:42 . 2012-11-04 14:42 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{30BB8745-2D17-4069-A155-1327C93E0CB5}\offreg.dll
2012-11-04 14:14 . 2012-10-12 05:56 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{30BB8745-2D17-4069-A155-1327C93E0CB5}\mpengine.dll
2012-11-04 13:48 . 2012-11-04 13:48 -------- d-----w- c:\programdata\MicroWorld
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-14 13:54 . 2007-09-29 03:50 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-11-05 08:58 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-11-05 08:58 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-11-04 15:47 . 2012-11-04 15:44 22 ----a-w- c:\windows\REGBK00.ZIP
2012-08-30 21:03 . 2012-08-30 21:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-10-11 01:05 . 2012-11-13 14:39 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-23 815104]
"ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2006-12-12 106496]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eliška^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Eliška\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2007-09-29 03:21 37232 ----a-w- c:\windows\ASScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2007-09-29 03:21 33136 ----a-w- c:\windows\ASScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2007-03-26 18:42 1057328 ----a-w- c:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-26 19:12 161328 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2008-12-02 09:02 111928 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 45989881
*NewlyCreated* - MPKSLF7BA8293
*Deregistered* - 45989881
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-14 c:\windows\Tasks\User_Feed_Synchronization-{4A1D7AC6-FB4A-4B1C-B962-F4E257684AFE}.job
- c:\windows\system32\msfeedssync.exe [2008-07-01 07:33]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 168.95.1.1
FF - ProfilePath - c:\users\Eliška\AppData\Roaming\Mozilla\Firefox\Profiles\2ddebrif.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-14 19:39
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2012-11-14 19:48:08
ComboFix-quarantined-files.txt 2012-11-14 18:47
.
Před spuštěním: Volných bajtů: 19 742 158 848
Po spuštění: Volných bajtů: 20 228 825 088
.
- - End Of File - - B05C8DE7CFE67188A22495BC9ED94EE9

Uživatelský avatar
Žbeky
Moderátor
Guru Level 13
Guru Level 13
Příspěvky: 22288
Registrován: květen 08
Bydliště: Vsetín - Pardubice
Pohlaví: Muž
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Žbeky » 17 lis 2012 10:24

Toto znáš?
c:\windows\hklmSY.reg
c:\windows\hklmSW.reg
c:\windows\hkcrRT.reg


Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.

HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 17 lis 2012 11:20

.....tak tohle mi nic neříká :-)
c:\windows\hklmSY.reg
c:\windows\hklmSW.reg
c:\windows\hkcrRT.reg


Tady je ten log, výkon notebooku už je nižší a i aplikace běží rychleji....

ComboFix 12-11-16.02 - Eliška 17.11.2012 10:59:31.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.895.266 [GMT 1:00]
Spuštěný z: c:\users\EliÜka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\EliÜka\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-17 do 2012-11-17 )))))))))))))))))))))))))))))))
.
.
2012-11-17 10:11 . 2012-11-17 10:11 -------- d-----w- c:\users\Eliška\AppData\Local\temp
2012-11-17 10:11 . 2012-11-17 10:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-13 19:14 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-11-13 19:14 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2012-11-13 19:11 . 2012-11-13 19:11 -------- d-----w- c:\program files\Microsoft Works
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\windows\PCHEALTH
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\program files\Microsoft.NET
2012-11-13 18:59 . 2012-11-13 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-11-13 18:55 . 2012-11-13 18:55 -------- d-----r- C:\MSOCache
2012-11-13 18:32 . 2010-09-06 16:23 17920 ----a-w- c:\windows\system32\netevent.dll
2012-11-13 18:32 . 2010-09-06 16:24 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-11-13 18:32 . 2011-02-16 15:29 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-11-13 18:32 . 2010-06-16 15:12 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-11-13 18:32 . 2011-02-16 13:24 292864 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 18:31 . 2010-08-31 15:41 954752 ----a-w- c:\windows\system32\mfc40.dll
2012-11-13 18:31 . 2010-08-31 15:41 954288 ----a-w- c:\windows\system32\mfc40u.dll
2012-11-13 18:30 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2012-11-13 18:30 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2012-11-13 18:30 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2012-11-13 18:30 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2012-11-13 18:30 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2012-11-13 18:29 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-13 18:27 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-11-13 16:58 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FA5EAC76-322E-42E8-A74C-775D7A056AA8}\mpengine.dll
2012-11-13 16:34 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-11-13 16:34 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-11-13 16:34 . 2011-04-29 12:49 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-11-13 16:34 . 2011-04-29 12:49 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-11-13 16:33 . 2011-05-02 16:00 766464 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2012-11-13 16:33 . 2010-04-05 16:08 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2012-11-13 16:33 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2012-11-13 16:32 . 2010-12-20 15:39 563200 ----a-w- c:\windows\system32\oleaut32.dll
2012-11-13 16:07 . 2012-11-13 16:07 -------- d-----w- c:\users\Eliška\AppData\Roaming\WinRAR
2012-11-13 15:45 . 2010-04-16 16:10 501760 ----a-w- c:\windows\system32\usp10.dll
2012-11-13 15:45 . 2010-12-28 14:56 57344 ----a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2012-11-13 15:45 . 2010-12-28 14:56 253952 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-11-13 15:45 . 2010-12-28 14:56 180224 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-11-13 15:45 . 2010-12-28 14:57 409600 ----a-w- c:\windows\system32\odbc32.dll
2012-11-13 15:45 . 2010-12-28 14:56 241664 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-11-13 15:45 . 2010-12-28 14:56 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-11-13 15:44 . 2011-02-22 12:51 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-11-13 15:44 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2012-11-13 15:43 . 2010-06-18 16:43 36352 ----a-w- c:\windows\system32\rtutils.dll
2012-11-13 15:43 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2012-11-13 15:42 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
2012-11-13 15:42 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
2012-11-13 15:40 . 2010-12-17 16:43 2067456 ----a-w- c:\windows\system32\mstscax.dll
2012-11-13 15:40 . 2010-12-17 15:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-11-13 14:41 . 2012-11-13 14:41 -------- d-----w- c:\users\Eliška\AppData\Local\Mozilla
2012-11-13 14:40 . 2012-11-13 14:40 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-11-10 13:06 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-11-10 12:47 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-11-10 12:47 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-11-10 12:47 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-11-10 12:47 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-11-10 12:47 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-11-06 20:41 . 2010-10-15 14:08 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-11-06 20:41 . 2010-10-15 13:48 1205080 ----a-w- c:\windows\system32\ntdll.dll
2012-11-06 20:41 . 2010-10-15 14:08 3600272 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-11-06 20:30 . 2011-03-03 14:56 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-11-06 20:30 . 2011-03-03 13:01 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-11-06 20:11 . 2010-01-29 16:22 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2012-11-06 20:11 . 2010-05-27 19:16 81920 ----a-w- c:\windows\system32\iccvid.dll
2012-11-06 20:11 . 2011-02-18 13:31 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2012-11-06 20:11 . 2011-07-06 14:56 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-11-06 20:11 . 2011-04-29 12:49 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-11-06 20:11 . 2011-04-29 12:49 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-11-06 19:42 . 2010-05-04 18:39 248832 ----a-w- c:\windows\system32\msshsq.dll
2012-11-06 19:42 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-11-06 19:41 . 2011-05-02 15:58 738816 ----a-w- c:\windows\system32\inetcomm.dll
2012-11-06 19:31 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-11-06 19:31 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-11-06 19:31 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-11-06 19:24 . 2011-03-10 16:12 1136640 ----a-w- c:\windows\system32\mfc42.dll
2012-11-06 19:24 . 2011-03-10 16:12 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2012-11-06 19:24 . 2010-06-28 16:15 1315840 ----a-w- c:\windows\system32\ole32.dll
2012-11-06 19:24 . 2010-06-28 14:31 339968 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2012-11-06 19:24 . 2010-08-26 16:07 157184 ----a-w- c:\windows\system32\t2embed.dll
2012-11-06 19:24 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 19:24 . 2011-04-21 13:16 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-11-06 19:23 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2012-11-06 18:57 . 2010-08-17 13:32 126464 ----a-w- c:\windows\system32\spoolsv.exe
2012-11-06 18:47 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde.dll
2012-11-06 18:47 . 2010-12-29 17:41 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-11-06 18:47 . 2010-12-29 17:41 323072 ----a-w- c:\windows\system32\sbe.dll
2012-11-06 18:47 . 2010-12-29 17:39 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2012-11-06 18:47 . 2010-12-29 17:41 153088 ----a-w- c:\windows\system32\sbeio.dll
2012-11-06 18:42 . 2010-06-11 15:30 1257472 ----a-w- c:\windows\system32\msxml3.dll
2012-11-06 18:42 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2012-11-06 18:42 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2012-11-06 18:42 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2012-11-06 18:42 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-11-06 18:42 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2012-11-06 18:42 . 2008-05-20 02:07 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-11-06 18:42 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2012-11-06 18:41 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-06 18:40 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\wshom.ocx
2012-11-06 18:40 . 2008-05-08 21:59 90112 ----a-w- c:\windows\system32\wshext.dll
2012-11-06 18:40 . 2008-05-08 21:59 155648 ----a-w- c:\windows\system32\wscript.exe
2012-11-06 18:40 . 2008-05-08 21:59 180224 ----a-w- c:\windows\system32\scrobj.dll
2012-11-06 18:40 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\cscript.exe
2012-11-06 18:40 . 2008-05-08 21:59 172032 ----a-w- c:\windows\system32\scrrun.dll
2012-11-06 18:12 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
2012-11-05 11:57 . 2012-11-05 11:57 -------- d-----w- c:\program files\CCleaner
2012-11-05 11:43 . 2012-11-05 11:43 -------- d-----w- c:\users\Eliška\AppData\Roaming\Malwarebytes
2012-11-05 11:42 . 2012-11-05 11:42 -------- d-----w- c:\programdata\Malwarebytes
2012-11-05 11:42 . 2012-11-05 11:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-05 11:42 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-05 11:38 . 2012-11-05 11:39 -------- d-----w- c:\program files\Common Files\Adobe
2012-11-05 11:30 . 2012-11-05 11:30 -------- d-----w- c:\program files\Common Files\Java
2012-11-05 11:30 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-05 11:30 . 2012-11-05 11:28 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-11-05 11:30 . 2012-11-05 11:28 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-11-05 11:29 . 2012-11-05 11:28 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-05 11:27 . 2012-11-05 11:27 -------- d-----w- c:\program files\Java
2012-11-05 10:24 . 2012-11-05 10:24 -------- d-----w- C:\PerfLogs
2012-11-05 09:14 . 2012-11-05 09:17 -------- d-----w- c:\program files\Microsoft Security Client
2012-11-04 15:46 . 2012-11-04 15:48 33874278 ----a-w- c:\windows\hklmSY.reg
2012-11-04 15:45 . 2012-11-04 15:53 155602356 ----a-w- c:\windows\hklmSW.reg
2012-11-04 15:44 . 2012-11-04 15:48 35510380 ----a-w- c:\windows\hkcrRT.reg
2012-11-04 14:42 . 2012-11-04 14:42 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{30BB8745-2D17-4069-A155-1327C93E0CB5}\offreg.dll
2012-11-04 14:14 . 2012-10-12 05:56 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{30BB8745-2D17-4069-A155-1327C93E0CB5}\mpengine.dll
2012-11-04 13:48 . 2012-11-04 13:48 -------- d-----w- c:\programdata\MicroWorld
2012-11-04 11:16 . 2012-11-04 11:16 -------- d-----w- c:\users\Eliška\AppData\Roaming\VSRevoGroup
2012-11-04 11:06 . 2012-11-04 11:06 -------- d-----w- c:\users\Eliška\AppData\Local\Seven Zip
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-17 09:42 . 2007-09-29 03:50 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-11-05 08:58 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-11-05 08:58 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-11-04 15:47 . 2012-11-04 15:44 22 ----a-w- c:\windows\REGBK00.ZIP
2012-08-30 21:03 . 2012-08-30 21:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-10-11 01:05 . 2012-11-13 14:39 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-23 815104]
"ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2006-12-12 106496]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eliška^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Eliška\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2007-09-29 03:21 37232 ----a-w- c:\windows\ASScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2007-09-29 03:21 33136 ----a-w- c:\windows\ASScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2007-03-26 18:42 1057328 ----a-w- c:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-26 19:12 161328 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2008-12-02 09:02 111928 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-17 c:\windows\Tasks\User_Feed_Synchronization-{4A1D7AC6-FB4A-4B1C-B962-F4E257684AFE}.job
- c:\windows\system32\msfeedssync.exe [2008-07-01 07:33]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 168.95.1.1
FF - ProfilePath - c:\users\Eliška\AppData\Roaming\Mozilla\Firefox\Profiles\2ddebrif.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2012-11-17 11:15:48
ComboFix-quarantined-files.txt 2012-11-17 10:15
ComboFix2.txt 2012-11-14 18:48
.
Před spuštěním: Volných bajtů: 20 514 082 816
Po spuštění: Volných bajtů: 20 381 028 352
.
- - End Of File - - B8B62E668C1781BF537D5DF15409D0C8

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod jaro3 » 18 lis 2012 10:54

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
Collect::
c:\windows\hklmSY.reg
c:\windows\hklmSW.reg
c:\windows\hkcrRT.reg

Folder::
c:\windows\REGBK00.ZIP

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000

RegLog::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 18 lis 2012 14:42

Tak první lig z ComboFix

ComboFix 12-11-16.02 - Eliška 18.11.2012 11:20:56.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.895.206 [GMT 1:00]
Spuštěný z: c:\users\EliÜka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\EliÜka\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\PFRO.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-18 do 2012-11-18 )))))))))))))))))))))))))))))))
.
.
2012-11-18 10:47 . 2012-11-18 10:47 -------- d-----w- c:\users\Eliška\AppData\Local\temp
2012-11-18 10:47 . 2012-11-18 10:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-18 10:01 . 2012-11-18 10:02 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E019C960-5E24-4B79-9BED-0F30D3D27E7F}\MpKslbefa9194.sys
2012-11-17 14:12 . 2012-11-17 14:12 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E019C960-5E24-4B79-9BED-0F30D3D27E7F}\MpKsl6474955a.sys
2012-11-17 12:11 . 2010-09-10 16:35 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2012-11-17 12:11 . 2010-09-10 16:37 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2012-11-17 12:09 . 2011-04-21 13:08 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-17 12:09 . 2011-04-21 15:02 634648 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2012-11-17 12:09 . 2010-05-04 16:53 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-17 12:09 . 2011-04-21 13:28 389632 ----a-w- c:\windows\system32\html.iec
2012-11-17 12:08 . 2011-04-21 15:00 833024 ----a-w- c:\windows\system32\wininet.dll
2012-11-17 12:08 . 2011-04-21 14:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-11-17 12:07 . 2008-04-05 01:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2012-11-17 12:07 . 2008-04-05 03:34 15360 ----a-w- c:\windows\system32\pacerprf.dll
2012-11-17 12:07 . 2010-06-17 15:49 150016 ----a-w- c:\program files\Movie Maker\MOVIEMK.exe
2012-11-17 12:07 . 2010-06-17 17:15 10926592 ----a-w- c:\program files\Movie Maker\MOVIEMK.dll
2012-11-17 12:05 . 2008-05-27 05:17 11776 ----a-w- c:\windows\system32\msshooks.dll
2012-11-17 12:05 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2012-11-17 12:05 . 2008-05-27 04:59 106605 ----a-w- c:\windows\system32\StructuredQuerySchema.bin
2012-11-17 12:05 . 2008-05-27 05:17 34816 ----a-w- c:\windows\system32\msscb.dll
2012-11-17 12:02 . 2010-04-14 17:46 80896 ----a-w- c:\windows\system32\MSNP.ax
2012-11-17 12:02 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2012-11-17 12:02 . 2010-04-14 17:47 217088 ----a-w- c:\windows\system32\psisrndr.ax
2012-11-17 11:37 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2012-11-17 11:36 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2012-11-17 11:36 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
2012-11-17 11:36 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
2012-11-17 11:36 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2012-11-17 11:36 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\winrssrv.dll
2012-11-17 11:07 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E019C960-5E24-4B79-9BED-0F30D3D27E7F}\mpengine.dll
2012-11-17 11:02 . 2012-10-11 21:56 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-13 19:14 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-11-13 19:14 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2012-11-13 19:11 . 2012-11-13 19:11 -------- d-----w- c:\program files\Microsoft Works
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\windows\PCHEALTH
2012-11-13 19:04 . 2012-11-13 19:04 -------- d-----w- c:\program files\Microsoft.NET
2012-11-13 18:59 . 2012-11-13 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-11-13 18:55 . 2012-11-13 18:55 -------- d-----r- C:\MSOCache
2012-11-13 18:32 . 2010-09-06 16:23 17920 ----a-w- c:\windows\system32\netevent.dll
2012-11-13 18:32 . 2010-09-06 16:24 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-11-13 18:32 . 2011-02-16 15:29 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-11-13 18:32 . 2010-06-16 15:12 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-11-13 18:32 . 2011-02-16 13:24 292864 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 18:31 . 2010-08-31 15:41 954752 ----a-w- c:\windows\system32\mfc40.dll
2012-11-13 18:31 . 2010-08-31 15:41 954288 ----a-w- c:\windows\system32\mfc40u.dll
2012-11-13 18:30 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2012-11-13 18:30 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2012-11-13 18:30 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2012-11-13 18:30 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2012-11-13 18:30 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2012-11-13 18:29 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-13 18:27 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-11-13 16:34 . 2009-05-04 10:11 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-11-13 16:34 . 2011-03-02 14:49 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-11-13 16:34 . 2011-04-29 12:49 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-11-13 16:34 . 2011-04-29 12:49 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-11-13 16:33 . 2011-05-02 16:00 766464 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2012-11-13 16:33 . 2010-04-05 16:08 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2012-11-13 16:33 . 2011-02-16 15:35 430080 ----a-w- c:\windows\system32\vbscript.dll
2012-11-13 16:32 . 2010-12-20 15:39 563200 ----a-w- c:\windows\system32\oleaut32.dll
2012-11-13 16:07 . 2012-11-13 16:07 -------- d-----w- c:\users\Eliška\AppData\Roaming\WinRAR
2012-11-13 15:45 . 2010-04-16 16:10 501760 ----a-w- c:\windows\system32\usp10.dll
2012-11-13 15:45 . 2010-12-28 14:56 57344 ----a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2012-11-13 15:45 . 2010-12-28 14:56 253952 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-11-13 15:45 . 2010-12-28 14:56 180224 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-11-13 15:45 . 2010-12-28 14:57 409600 ----a-w- c:\windows\system32\odbc32.dll
2012-11-13 15:45 . 2010-12-28 14:56 241664 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-11-13 15:45 . 2010-12-28 14:56 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-11-13 15:44 . 2011-02-22 12:51 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-11-13 15:44 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2012-11-13 15:43 . 2010-06-18 16:43 36352 ----a-w- c:\windows\system32\rtutils.dll
2012-11-13 15:43 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2012-11-13 15:42 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
2012-11-13 15:42 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
2012-11-13 15:40 . 2010-12-17 16:43 2067456 ----a-w- c:\windows\system32\mstscax.dll
2012-11-13 15:40 . 2010-12-17 15:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-11-13 14:41 . 2012-11-13 14:41 -------- d-----w- c:\users\Eliška\AppData\Local\Mozilla
2012-11-13 14:40 . 2012-11-13 14:40 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-11-10 13:06 . 2011-04-14 14:24 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-11-10 12:47 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-11-10 12:47 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-11-10 12:47 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-11-10 12:47 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-11-10 12:47 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-11-06 20:41 . 2010-10-15 14:08 3548048 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-11-06 20:41 . 2010-10-15 13:48 1205080 ----a-w- c:\windows\system32\ntdll.dll
2012-11-06 20:41 . 2010-10-15 14:08 3600272 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-11-06 20:30 . 2011-03-03 14:56 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-11-06 20:30 . 2011-03-03 13:01 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-11-06 20:11 . 2010-01-29 16:22 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2012-11-06 20:11 . 2010-05-27 19:16 81920 ----a-w- c:\windows\system32\iccvid.dll
2012-11-06 20:11 . 2011-02-18 13:31 304640 ----a-w- c:\windows\system32\drivers\srv.sys
2012-11-06 20:11 . 2011-07-06 14:56 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-11-06 20:11 . 2011-04-29 12:49 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-11-06 20:11 . 2011-04-29 12:49 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-11-06 19:42 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-11-06 19:41 . 2011-05-02 15:58 738816 ----a-w- c:\windows\system32\inetcomm.dll
2012-11-06 19:31 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-11-06 19:31 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-11-06 19:31 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-11-06 19:24 . 2011-03-10 16:12 1136640 ----a-w- c:\windows\system32\mfc42.dll
2012-11-06 19:24 . 2011-03-10 16:12 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2012-11-06 19:24 . 2010-06-28 16:15 1315840 ----a-w- c:\windows\system32\ole32.dll
2012-11-06 19:24 . 2010-06-28 14:31 339968 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2012-11-06 19:24 . 2010-08-26 16:07 157184 ----a-w- c:\windows\system32\t2embed.dll
2012-11-06 19:24 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 19:24 . 2011-04-21 13:16 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-11-06 19:23 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2012-11-06 18:57 . 2010-08-17 13:32 126464 ----a-w- c:\windows\system32\spoolsv.exe
2012-11-06 18:47 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde.dll
2012-11-06 18:47 . 2010-12-29 17:41 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-11-06 18:47 . 2010-12-29 17:41 323072 ----a-w- c:\windows\system32\sbe.dll
2012-11-06 18:47 . 2010-12-29 17:39 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2012-11-06 18:47 . 2010-12-29 17:41 153088 ----a-w- c:\windows\system32\sbeio.dll
2012-11-06 18:42 . 2010-06-11 15:30 1257472 ----a-w- c:\windows\system32\msxml3.dll
2012-11-06 18:42 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2012-11-06 18:42 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2012-11-06 18:42 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2012-11-06 18:42 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-11-06 18:42 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2012-11-06 18:42 . 2008-05-20 02:07 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-11-06 18:42 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2012-11-06 18:41 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-06 18:40 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\wshom.ocx
2012-11-06 18:40 . 2008-05-08 21:59 90112 ----a-w- c:\windows\system32\wshext.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-18 10:00 . 2007-09-29 03:50 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-11-05 08:58 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-11-05 08:58 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-11-04 15:47 . 2012-11-04 15:44 22 ----a-w- c:\windows\REGBK00.ZIP
2012-08-30 21:03 . 2012-08-30 21:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-10-11 01:05 . 2012-11-13 14:39 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-23 815104]
"ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2006-12-12 106496]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eliška^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Eliška\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2007-09-29 03:21 37232 ----a-w- c:\windows\ASScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2007-09-29 03:21 33136 ----a-w- c:\windows\ASScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2007-03-26 18:42 1057328 ----a-w- c:\program files\Nero\Nero 7\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-26 19:12 161328 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2008-12-02 09:02 111928 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSLBEFA9194
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-18 c:\windows\Tasks\User_Feed_Synchronization-{4A1D7AC6-FB4A-4B1C-B962-F4E257684AFE}.job
- c:\windows\system32\msfeedssync.exe [2008-07-01 07:33]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 168.95.1.1
FF - ProfilePath - c:\users\Eliška\AppData\Roaming\Mozilla\Firefox\Profiles\2ddebrif.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-18 11:47
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2012-11-18 11:52:20
ComboFix-quarantined-files.txt 2012-11-18 10:52
ComboFix2.txt 2012-11-17 10:15
ComboFix3.txt 2012-11-14 18:48
.
Před spuštěním: Volných bajtů: 19 487 891 456
Po spuštění: Volných bajtů: 19 331 104 768
.
- - End Of File - - 7A2CA5A71EA14EDC23F57D1244DBE416

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 18 lis 2012 14:43

MBR.....

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-18 13:25:30
-----------------------------
13:25:30.307 OS Version: Windows 6.0.6001 Service Pack 1
13:25:30.307 Number of processors: 2 586 0xE0C
13:25:30.309 ComputerName: NOTEBOOK UserName: Eliška
13:25:35.138 Initialize success
13:25:54.867 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
13:25:54.874 Disk 0 Vendor: ST9160821AS 3.ALC Size: 152627MB BusType: 3
13:25:54.919 Disk 0 MBR read successfully
13:25:54.926 Disk 0 MBR scan
13:25:54.935 Disk 0 unknown MBR code
13:25:54.956 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 7000 MB offset 2048
13:25:54.972 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76313 MB offset 14338048
13:25:54.981 Disk 0 Partition - 00 0F Extended LBA 69312 MB offset 170627072
13:25:55.010 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 69311 MB offset 170629120
13:25:55.048 Disk 0 scanning sectors +312578048
13:25:55.134 Disk 0 scanning C:\Windows\system32\drivers
13:26:05.148 Service scanning
13:26:14.155 Service MpKslbefa9194 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E019C960-5E24-4B79-9BED-0F30D3D27E7F}\MpKslbefa9194.sys **LOCKED** 32
13:26:25.712 Modules scanning
13:26:39.338 Disk 0 trace - called modules:
13:26:39.381 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys tcpip.sys NETIO.SYS
13:26:39.396 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84bc3ac8]
13:26:39.412 3 CLASSPNP.SYS[863a9745] -> nt!IofCallDriver -> [0x8443d860]
13:26:39.428 5 acpi.sys[806936a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84428ba0]
13:26:39.443 Scan finished successfully
13:27:24.903 Disk 0 MBR has been saved successfully to "C:\Users\Eliška\Desktop\MBR.dat"
13:27:24.918 The log file has been saved successfully to "C:\Users\Eliška\Desktop\aswMBR.txt"

Elis.CHA
nováček
Příspěvky: 14
Registrován: listopad 12
Pohlaví: Žena
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod Elis.CHA » 18 lis 2012 14:44

....a ten poslední je zase z HJT

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:01:17, on 18.11.2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\ASUSTPE.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Users\Eliška\Desktop\HijackThis.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

--
End of file - 4957 bytes

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: moc prosím o pomoc :-)

Příspěvekod memphisto » 18 lis 2012 18:46

Combofix se neprovedl úplně. Zkus v nouzovém režimu tenhle skript:

Kód: Vybrat vše

KillAll::
Folder::
c:\windows\REGBK00.ZIP

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000

RegLog::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 111 hostů