Tady je roguekiller:
RogueKiller V8.8.9 [Feb 24 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : PEKY [Práva správce]
Mód : Odebrat -- Datum : 02/27/2014 18:31:01
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 2 ¤¤¤
[SUSP PATH] PirritService.exe -- C:\Users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] PirritDesktop.exe -- C:\Users\PEKY\AppData\Local\PirritSuggestor\PirritDesktop.exe [7] -> SMAZÁNO [TermProc]
¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Inline] EAT @explorer.exe (FwDoNothingOnObject) : FirewallAPI.dll -> HOOKED (Unknown @ 0x3617CF66)
[Inline] EAT @explorer.exe (FwEnableMemTracing) : FirewallAPI.dll -> HOOKED (Unknown @ 0x3617CF66)
[Inline] EAT @explorer.exe (FwSetMemLeakPolicy) : FirewallAPI.dll -> HOOKED (Unknown @ 0x3617CF66)
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) TOSHIBA MK1234GSX ATA Device +++++
--- User ---
[MBR] 2aa6c08b4051626f746d5407e9936f94
[BSP] d99d0bb998557bf20e58a401e24762c7 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 10013 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 20508672 | Size: 104459 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[0]_D_02272014_183101.txt >>
RKreport[0]_D_02272014_175744.txt;RKreport[0]_S_02262014_214533.txt;RKreport[0]_S_02272014_175729.txt
RKreport[0]_S_02272014_183050.txt
Při používání Firefoxu vyskakují reklamy, prosím o kontrolu Vyřešeno
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
18:47:03.0134 5136 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:47:18.0716 5136 ============================================================
18:47:18.0716 5136 Current date / time: 2014/02/27 18:47:18.0716
18:47:18.0716 5136 SystemInfo:
18:47:18.0716 5136
18:47:18.0716 5136 OS Version: 6.0.6001 ServicePack: 1.0
18:47:18.0716 5136 Product type: Workstation
18:47:18.0716 5136 ComputerName: KAMILA-PC
18:47:18.0717 5136 UserName: PEKY
18:47:18.0717 5136 Windows directory: C:\Windows
18:47:18.0717 5136 System windows directory: C:\Windows
18:47:18.0717 5136 Processor architecture: Intel x86
18:47:18.0717 5136 Number of processors: 2
18:47:18.0717 5136 Page size: 0x1000
18:47:18.0717 5136 Boot type: Normal boot
18:47:18.0717 5136 ============================================================
18:47:20.0443 5136 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:47:20.0446 5136 ============================================================
18:47:20.0446 5136 \Device\Harddisk0\DR0:
18:47:20.0447 5136 MBR partitions:
18:47:20.0447 5136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x138F000, BlocksNum 0xCC05800
18:47:20.0447 5136 ============================================================
18:47:20.0484 5136 C: <-> \Device\Harddisk0\DR0\Partition1
18:47:20.0485 5136 ============================================================
18:47:20.0485 5136 Initialize success
18:47:20.0485 5136 ============================================================
18:47:40.0353 5496 ============================================================
18:47:40.0353 5496 Scan started
18:47:40.0353 5496 Mode: Manual;
18:47:40.0354 5496 ============================================================
18:47:42.0204 5496 ================ Scan system memory ========================
18:47:42.0204 5496 System memory - ok
18:47:42.0204 5496 ================ Scan services =============================
18:47:42.0472 5496 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
18:47:42.0478 5496 ACPI - ok
18:47:42.0629 5496 [ B362181ED3771DC03B4141927C80F801 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:47:42.0632 5496 AdobeARMservice - ok
18:47:42.0729 5496 [ F7AB315A4D400CA876381D1E188A2E20 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:47:42.0731 5496 AdobeFlashPlayerUpdateSvc - ok
18:47:42.0798 5496 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
18:47:42.0809 5496 adp94xx - ok
18:47:42.0859 5496 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
18:47:42.0866 5496 adpahci - ok
18:47:42.0895 5496 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
18:47:42.0898 5496 adpu160m - ok
18:47:42.0948 5496 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
18:47:42.0952 5496 adpu320 - ok
18:47:43.0015 5496 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:47:43.0016 5496 AeLookupSvc - ok
18:47:43.0087 5496 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
18:47:43.0094 5496 AFD - ok
18:47:43.0145 5496 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:47:43.0147 5496 agp440 - ok
18:47:43.0181 5496 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
18:47:43.0184 5496 aic78xx - ok
18:47:43.0237 5496 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
18:47:43.0239 5496 ALG - ok
18:47:43.0246 5496 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
18:47:43.0247 5496 aliide - ok
18:47:43.0255 5496 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:47:43.0257 5496 amdagp - ok
18:47:43.0304 5496 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
18:47:43.0306 5496 amdide - ok
18:47:43.0325 5496 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
18:47:43.0327 5496 AmdK7 - ok
18:47:43.0353 5496 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
18:47:43.0355 5496 AmdK8 - ok
18:47:43.0386 5496 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
18:47:43.0387 5496 Appinfo - ok
18:47:43.0403 5496 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
18:47:43.0405 5496 arc - ok
18:47:43.0421 5496 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
18:47:43.0424 5496 arcsas - ok
18:47:43.0577 5496 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:47:43.0747 5496 aspnet_state - ok
18:47:43.0793 5496 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:47:43.0795 5496 AsyncMac - ok
18:47:43.0832 5496 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
18:47:43.0833 5496 atapi - ok
18:47:43.0907 5496 [ 43910B02626930CA20DD25D2A1EE1B46 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
18:47:43.0919 5496 Ati External Event Utility - ok
18:47:44.0076 5496 [ 20108CDEB79864C30B966DEE5160F62E ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:47:44.0126 5496 atikmdag - ok
18:47:44.0204 5496 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:47:44.0212 5496 AudioEndpointBuilder - ok
18:47:44.0222 5496 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:47:44.0224 5496 Audiosrv - ok
18:47:44.0251 5496 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
18:47:44.0252 5496 Beep - ok
18:47:44.0308 5496 [ D3E6D78285529962349A7F1617035938 ] BFE C:\Windows\System32\bfe.dll
18:47:44.0316 5496 BFE - ok
18:47:44.0414 5496 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
18:47:44.0421 5496 BITS - ok
18:47:44.0426 5496 blbdrive - ok
18:47:44.0475 5496 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:47:44.0478 5496 bowser - ok
18:47:44.0524 5496 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
18:47:44.0526 5496 BrFiltLo - ok
18:47:44.0532 5496 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
18:47:44.0533 5496 BrFiltUp - ok
18:47:44.0575 5496 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
18:47:44.0578 5496 Browser - ok
18:47:44.0614 5496 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
18:47:44.0617 5496 Brserid - ok
18:47:44.0624 5496 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
18:47:44.0627 5496 BrSerWdm - ok
18:47:44.0653 5496 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
18:47:44.0655 5496 BrUsbMdm - ok
18:47:44.0660 5496 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
18:47:44.0662 5496 BrUsbSer - ok
18:47:44.0669 5496 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
18:47:44.0671 5496 BTHMODEM - ok
18:47:44.0709 5496 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:47:44.0709 5496 cdfs - ok
18:47:44.0752 5496 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
18:47:44.0755 5496 cdrom - ok
18:47:44.0794 5496 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
18:47:44.0796 5496 CertPropSvc - ok
18:47:44.0836 5496 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
18:47:44.0844 5496 circlass - ok
18:47:44.0895 5496 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
18:47:44.0902 5496 CLFS - ok
18:47:44.0979 5496 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:47:45.0026 5496 clr_optimization_v2.0.50727_32 - ok
18:47:45.0092 5496 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:47:45.0144 5496 clr_optimization_v4.0.30319_32 - ok
18:47:45.0205 5496 CLTNetCnService - ok
18:47:45.0256 5496 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:47:45.0258 5496 CmBatt - ok
18:47:45.0297 5496 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:47:45.0319 5496 cmdide - ok
18:47:45.0373 5496 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:47:45.0376 5496 Compbatt - ok
18:47:45.0382 5496 COMSysApp - ok
18:47:45.0389 5496 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
18:47:45.0391 5496 crcdisk - ok
18:47:45.0435 5496 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
18:47:45.0437 5496 Crusoe - ok
18:47:45.0522 5496 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:47:45.0525 5496 CryptSvc - ok
18:47:45.0607 5496 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:47:45.0620 5496 DcomLaunch - ok
18:47:45.0664 5496 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:47:45.0667 5496 DfsC - ok
18:47:45.0798 5496 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
18:47:45.0850 5496 DFSR - ok
18:47:45.0921 5496 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
18:47:45.0926 5496 Dhcp - ok
18:47:45.0972 5496 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
18:47:45.0974 5496 disk - ok
18:47:46.0025 5496 [ F206E28ED74C491FD5D7C0A1119CE37F ] DMICall C:\Windows\system32\DRIVERS\DMICall.sys
18:47:46.0027 5496 DMICall - ok
18:47:46.0084 5496 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:47:46.0087 5496 Dnscache - ok
18:47:46.0151 5496 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
18:47:46.0156 5496 dot3svc - ok
18:47:46.0201 5496 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
18:47:46.0205 5496 DPS - ok
18:47:46.0258 5496 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:47:46.0259 5496 drmkaud - ok
18:47:46.0317 5496 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:47:46.0329 5496 DXGKrnl - ok
18:47:46.0391 5496 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
18:47:46.0394 5496 E1G60 - ok
18:47:46.0440 5496 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
18:47:46.0442 5496 EapHost - ok
18:47:46.0490 5496 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
18:47:46.0494 5496 Ecache - ok
18:47:46.0574 5496 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:47:46.0581 5496 ehRecvr - ok
18:47:46.0623 5496 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
18:47:46.0627 5496 ehSched - ok
18:47:46.0642 5496 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
18:47:46.0643 5496 ehstart - ok
18:47:46.0691 5496 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
18:47:46.0706 5496 elxstor - ok
18:47:46.0792 5496 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
18:47:46.0805 5496 EMDMgmt - ok
18:47:46.0896 5496 esgiguard - ok
18:47:46.0962 5496 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
18:47:46.0964 5496 EventSystem - ok
18:47:47.0044 5496 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
18:47:47.0048 5496 exfat - ok
18:47:47.0084 5496 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:47:47.0088 5496 fastfat - ok
18:47:47.0157 5496 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:47:47.0159 5496 fdc - ok
18:47:47.0212 5496 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
18:47:47.0213 5496 fdPHost - ok
18:47:47.0270 5496 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
18:47:47.0271 5496 FDResPub - ok
18:47:47.0302 5496 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:47:47.0305 5496 FileInfo - ok
18:47:47.0311 5496 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:47:47.0313 5496 Filetrace - ok
18:47:47.0319 5496 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:47:47.0320 5496 flpydisk - ok
18:47:47.0369 5496 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:47:47.0374 5496 FltMgr - ok
18:47:47.0455 5496 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:47:47.0458 5496 FontCache3.0.0.0 - ok
18:47:47.0499 5496 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:47:47.0500 5496 Fs_Rec - ok
18:47:47.0535 5496 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
18:47:47.0538 5496 gagp30kx - ok
18:47:47.0624 5496 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
18:47:47.0648 5496 gpsvc - ok
18:47:47.0685 5496 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:47:47.0691 5496 HdAudAddService - ok
18:47:47.0727 5496 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
18:47:47.0728 5496 HDAudBus - ok
18:47:18.0716 5136 ============================================================
18:47:18.0716 5136 Current date / time: 2014/02/27 18:47:18.0716
18:47:18.0716 5136 SystemInfo:
18:47:18.0716 5136
18:47:18.0716 5136 OS Version: 6.0.6001 ServicePack: 1.0
18:47:18.0716 5136 Product type: Workstation
18:47:18.0716 5136 ComputerName: KAMILA-PC
18:47:18.0717 5136 UserName: PEKY
18:47:18.0717 5136 Windows directory: C:\Windows
18:47:18.0717 5136 System windows directory: C:\Windows
18:47:18.0717 5136 Processor architecture: Intel x86
18:47:18.0717 5136 Number of processors: 2
18:47:18.0717 5136 Page size: 0x1000
18:47:18.0717 5136 Boot type: Normal boot
18:47:18.0717 5136 ============================================================
18:47:20.0443 5136 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:47:20.0446 5136 ============================================================
18:47:20.0446 5136 \Device\Harddisk0\DR0:
18:47:20.0447 5136 MBR partitions:
18:47:20.0447 5136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x138F000, BlocksNum 0xCC05800
18:47:20.0447 5136 ============================================================
18:47:20.0484 5136 C: <-> \Device\Harddisk0\DR0\Partition1
18:47:20.0485 5136 ============================================================
18:47:20.0485 5136 Initialize success
18:47:20.0485 5136 ============================================================
18:47:40.0353 5496 ============================================================
18:47:40.0353 5496 Scan started
18:47:40.0353 5496 Mode: Manual;
18:47:40.0354 5496 ============================================================
18:47:42.0204 5496 ================ Scan system memory ========================
18:47:42.0204 5496 System memory - ok
18:47:42.0204 5496 ================ Scan services =============================
18:47:42.0472 5496 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
18:47:42.0478 5496 ACPI - ok
18:47:42.0629 5496 [ B362181ED3771DC03B4141927C80F801 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:47:42.0632 5496 AdobeARMservice - ok
18:47:42.0729 5496 [ F7AB315A4D400CA876381D1E188A2E20 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:47:42.0731 5496 AdobeFlashPlayerUpdateSvc - ok
18:47:42.0798 5496 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
18:47:42.0809 5496 adp94xx - ok
18:47:42.0859 5496 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
18:47:42.0866 5496 adpahci - ok
18:47:42.0895 5496 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
18:47:42.0898 5496 adpu160m - ok
18:47:42.0948 5496 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
18:47:42.0952 5496 adpu320 - ok
18:47:43.0015 5496 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:47:43.0016 5496 AeLookupSvc - ok
18:47:43.0087 5496 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
18:47:43.0094 5496 AFD - ok
18:47:43.0145 5496 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:47:43.0147 5496 agp440 - ok
18:47:43.0181 5496 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
18:47:43.0184 5496 aic78xx - ok
18:47:43.0237 5496 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
18:47:43.0239 5496 ALG - ok
18:47:43.0246 5496 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
18:47:43.0247 5496 aliide - ok
18:47:43.0255 5496 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:47:43.0257 5496 amdagp - ok
18:47:43.0304 5496 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
18:47:43.0306 5496 amdide - ok
18:47:43.0325 5496 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
18:47:43.0327 5496 AmdK7 - ok
18:47:43.0353 5496 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
18:47:43.0355 5496 AmdK8 - ok
18:47:43.0386 5496 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
18:47:43.0387 5496 Appinfo - ok
18:47:43.0403 5496 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
18:47:43.0405 5496 arc - ok
18:47:43.0421 5496 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
18:47:43.0424 5496 arcsas - ok
18:47:43.0577 5496 [ 2FE0D5DB69014980A970D3BF9A85D2B1 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:47:43.0747 5496 aspnet_state - ok
18:47:43.0793 5496 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:47:43.0795 5496 AsyncMac - ok
18:47:43.0832 5496 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
18:47:43.0833 5496 atapi - ok
18:47:43.0907 5496 [ 43910B02626930CA20DD25D2A1EE1B46 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
18:47:43.0919 5496 Ati External Event Utility - ok
18:47:44.0076 5496 [ 20108CDEB79864C30B966DEE5160F62E ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:47:44.0126 5496 atikmdag - ok
18:47:44.0204 5496 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:47:44.0212 5496 AudioEndpointBuilder - ok
18:47:44.0222 5496 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:47:44.0224 5496 Audiosrv - ok
18:47:44.0251 5496 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
18:47:44.0252 5496 Beep - ok
18:47:44.0308 5496 [ D3E6D78285529962349A7F1617035938 ] BFE C:\Windows\System32\bfe.dll
18:47:44.0316 5496 BFE - ok
18:47:44.0414 5496 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\System32\qmgr.dll
18:47:44.0421 5496 BITS - ok
18:47:44.0426 5496 blbdrive - ok
18:47:44.0475 5496 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:47:44.0478 5496 bowser - ok
18:47:44.0524 5496 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
18:47:44.0526 5496 BrFiltLo - ok
18:47:44.0532 5496 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
18:47:44.0533 5496 BrFiltUp - ok
18:47:44.0575 5496 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
18:47:44.0578 5496 Browser - ok
18:47:44.0614 5496 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
18:47:44.0617 5496 Brserid - ok
18:47:44.0624 5496 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
18:47:44.0627 5496 BrSerWdm - ok
18:47:44.0653 5496 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
18:47:44.0655 5496 BrUsbMdm - ok
18:47:44.0660 5496 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
18:47:44.0662 5496 BrUsbSer - ok
18:47:44.0669 5496 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
18:47:44.0671 5496 BTHMODEM - ok
18:47:44.0709 5496 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:47:44.0709 5496 cdfs - ok
18:47:44.0752 5496 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
18:47:44.0755 5496 cdrom - ok
18:47:44.0794 5496 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
18:47:44.0796 5496 CertPropSvc - ok
18:47:44.0836 5496 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
18:47:44.0844 5496 circlass - ok
18:47:44.0895 5496 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
18:47:44.0902 5496 CLFS - ok
18:47:44.0979 5496 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:47:45.0026 5496 clr_optimization_v2.0.50727_32 - ok
18:47:45.0092 5496 [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:47:45.0144 5496 clr_optimization_v4.0.30319_32 - ok
18:47:45.0205 5496 CLTNetCnService - ok
18:47:45.0256 5496 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:47:45.0258 5496 CmBatt - ok
18:47:45.0297 5496 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:47:45.0319 5496 cmdide - ok
18:47:45.0373 5496 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:47:45.0376 5496 Compbatt - ok
18:47:45.0382 5496 COMSysApp - ok
18:47:45.0389 5496 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
18:47:45.0391 5496 crcdisk - ok
18:47:45.0435 5496 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
18:47:45.0437 5496 Crusoe - ok
18:47:45.0522 5496 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:47:45.0525 5496 CryptSvc - ok
18:47:45.0607 5496 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:47:45.0620 5496 DcomLaunch - ok
18:47:45.0664 5496 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:47:45.0667 5496 DfsC - ok
18:47:45.0798 5496 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
18:47:45.0850 5496 DFSR - ok
18:47:45.0921 5496 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
18:47:45.0926 5496 Dhcp - ok
18:47:45.0972 5496 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
18:47:45.0974 5496 disk - ok
18:47:46.0025 5496 [ F206E28ED74C491FD5D7C0A1119CE37F ] DMICall C:\Windows\system32\DRIVERS\DMICall.sys
18:47:46.0027 5496 DMICall - ok
18:47:46.0084 5496 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:47:46.0087 5496 Dnscache - ok
18:47:46.0151 5496 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
18:47:46.0156 5496 dot3svc - ok
18:47:46.0201 5496 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
18:47:46.0205 5496 DPS - ok
18:47:46.0258 5496 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:47:46.0259 5496 drmkaud - ok
18:47:46.0317 5496 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:47:46.0329 5496 DXGKrnl - ok
18:47:46.0391 5496 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
18:47:46.0394 5496 E1G60 - ok
18:47:46.0440 5496 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
18:47:46.0442 5496 EapHost - ok
18:47:46.0490 5496 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
18:47:46.0494 5496 Ecache - ok
18:47:46.0574 5496 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:47:46.0581 5496 ehRecvr - ok
18:47:46.0623 5496 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
18:47:46.0627 5496 ehSched - ok
18:47:46.0642 5496 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
18:47:46.0643 5496 ehstart - ok
18:47:46.0691 5496 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
18:47:46.0706 5496 elxstor - ok
18:47:46.0792 5496 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
18:47:46.0805 5496 EMDMgmt - ok
18:47:46.0896 5496 esgiguard - ok
18:47:46.0962 5496 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
18:47:46.0964 5496 EventSystem - ok
18:47:47.0044 5496 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
18:47:47.0048 5496 exfat - ok
18:47:47.0084 5496 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:47:47.0088 5496 fastfat - ok
18:47:47.0157 5496 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:47:47.0159 5496 fdc - ok
18:47:47.0212 5496 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
18:47:47.0213 5496 fdPHost - ok
18:47:47.0270 5496 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
18:47:47.0271 5496 FDResPub - ok
18:47:47.0302 5496 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:47:47.0305 5496 FileInfo - ok
18:47:47.0311 5496 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:47:47.0313 5496 Filetrace - ok
18:47:47.0319 5496 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:47:47.0320 5496 flpydisk - ok
18:47:47.0369 5496 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:47:47.0374 5496 FltMgr - ok
18:47:47.0455 5496 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:47:47.0458 5496 FontCache3.0.0.0 - ok
18:47:47.0499 5496 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:47:47.0500 5496 Fs_Rec - ok
18:47:47.0535 5496 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
18:47:47.0538 5496 gagp30kx - ok
18:47:47.0624 5496 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
18:47:47.0648 5496 gpsvc - ok
18:47:47.0685 5496 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:47:47.0691 5496 HdAudAddService - ok
18:47:47.0727 5496 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
18:47:47.0728 5496 HDAudBus - ok
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
18:47:47.0734 5496 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
18:47:47.0736 5496 HidBth - ok
18:47:47.0743 5496 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
18:47:47.0745 5496 HidIr - ok
18:47:47.0774 5496 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
18:47:47.0775 5496 hidserv - ok
18:47:47.0805 5496 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:47:47.0807 5496 HidUsb - ok
18:47:47.0841 5496 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:47:47.0845 5496 hkmsvc - ok
18:47:47.0904 5496 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
18:47:47.0906 5496 HpCISSs - ok
18:47:47.0982 5496 [ 7BC42C65B5C6281777C1A7605B253BA8 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
18:47:48.0015 5496 HSF_DPV - ok
18:47:48.0051 5496 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
18:47:48.0056 5496 HSXHWAZL - ok
18:47:48.0122 5496 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:47:48.0131 5496 HTTP - ok
18:47:48.0195 5496 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
18:47:48.0197 5496 i2omp - ok
18:47:48.0255 5496 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
18:47:48.0257 5496 i8042prt - ok
18:47:48.0315 5496 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
18:47:48.0321 5496 iaStorV - ok
18:47:48.0403 5496 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
18:47:48.0407 5496 IDriverT - ok
18:47:48.0526 5496 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:47:48.0545 5496 idsvc - ok
18:47:48.0654 5496 [ 040BCB496D604A9859657088F400F0EB ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
18:47:48.0690 5496 igfx - ok
18:47:48.0726 5496 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
18:47:48.0728 5496 iirsp - ok
18:47:48.0824 5496 [ 755519F49906B73C1FE9CBBF75E347EA ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
18:47:48.0827 5496 IJPLMSVC - ok
18:47:48.0892 5496 [ 68E8C415E102E5D79FD7E4A765B8CBA4 ] IKEEXT C:\Windows\System32\ikeext.dll
18:47:48.0903 5496 IKEEXT - ok
18:47:49.0055 5496 [ 2BD6633DB50A98534AA3262E0F9F5A14 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
18:47:49.0092 5496 IntcAzAudAddService - ok
18:47:49.0129 5496 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
18:47:49.0131 5496 intelide - ok
18:47:49.0186 5496 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:47:49.0187 5496 intelppm - ok
18:47:49.0240 5496 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:47:49.0243 5496 IPBusEnum - ok
18:47:49.0288 5496 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:47:49.0290 5496 IpFilterDriver - ok
18:47:49.0319 5496 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:47:49.0322 5496 iphlpsvc - ok
18:47:49.0328 5496 IpInIp - ok
18:47:49.0368 5496 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
18:47:49.0371 5496 IPMIDRV - ok
18:47:49.0405 5496 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
18:47:49.0409 5496 IPNAT - ok
18:47:49.0429 5496 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:47:49.0431 5496 IRENUM - ok
18:47:49.0445 5496 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:47:49.0447 5496 isapnp - ok
18:47:49.0496 5496 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
18:47:49.0500 5496 iScsiPrt - ok
18:47:49.0506 5496 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
18:47:49.0509 5496 iteatapi - ok
18:47:49.0516 5496 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
18:47:49.0518 5496 iteraid - ok
18:47:49.0554 5496 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
18:47:49.0556 5496 kbdclass - ok
18:47:49.0609 5496 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
18:47:49.0611 5496 kbdhid - ok
18:47:49.0647 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
18:47:49.0648 5496 KeyIso - ok
18:47:49.0694 5496 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:47:49.0704 5496 KSecDD - ok
18:47:49.0808 5496 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
18:47:49.0811 5496 KtmRm - ok
18:47:49.0871 5496 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\system32\srvsvc.dll
18:47:49.0876 5496 LanmanServer - ok
18:47:49.0940 5496 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:47:49.0946 5496 LanmanWorkstation - ok
18:47:50.0194 5496 [ 010FD2B41E75A98E3A4D23F44405F5C9 ] LiveUpdate C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
18:47:50.0285 5496 LiveUpdate - ok
18:47:50.0315 5496 LiveUpdate Notice Ex - ok
18:47:50.0429 5496 [ 2D1389E05A807D956829F44BD4B60389 ] LiveUpdate Notice Service C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
18:47:50.0433 5496 LiveUpdate Notice Service - ok
18:47:50.0479 5496 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:47:50.0480 5496 lltdio - ok
18:47:50.0519 5496 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:47:50.0524 5496 lltdsvc - ok
18:47:50.0557 5496 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:47:50.0559 5496 lmhosts - ok
18:47:50.0610 5496 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
18:47:50.0613 5496 LSI_FC - ok
18:47:50.0620 5496 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
18:47:50.0623 5496 LSI_SAS - ok
18:47:50.0652 5496 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
18:47:50.0654 5496 LSI_SCSI - ok
18:47:50.0726 5496 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
18:47:50.0728 5496 luafv - ok
18:47:50.0786 5496 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
18:47:50.0787 5496 MBAMProtector - ok
18:47:50.0912 5496 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:47:50.0928 5496 MBAMScheduler - ok
18:47:50.0978 5496 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:47:50.0993 5496 MBAMService - ok
18:47:51.0045 5496 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:47:51.0048 5496 Mcx2Svc - ok
18:47:51.0149 5496 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
18:47:51.0157 5496 MDM - ok
18:47:51.0201 5496 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
18:47:51.0203 5496 mdmxsdk - ok
18:47:51.0235 5496 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
18:47:51.0237 5496 megasas - ok
18:47:51.0289 5496 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
18:47:51.0292 5496 Microsoft Office Groove Audit Service - ok
18:47:51.0343 5496 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
18:47:51.0346 5496 MMCSS - ok
18:47:51.0376 5496 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
18:47:51.0378 5496 Modem - ok
18:47:51.0429 5496 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:47:51.0430 5496 monitor - ok
18:47:51.0457 5496 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:47:51.0459 5496 mouclass - ok
18:47:51.0514 5496 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:47:51.0516 5496 mouhid - ok
18:47:51.0560 5496 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
18:47:51.0562 5496 MountMgr - ok
18:47:51.0619 5496 [ E77DC03DD3C8E5A388BF9EED2A28F3D1 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
18:47:51.0624 5496 MpFilter - ok
18:47:51.0673 5496 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
18:47:51.0676 5496 mpio - ok
18:47:51.0711 5496 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:47:51.0713 5496 mpsdrv - ok
18:47:51.0822 5496 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
18:47:51.0832 5496 MpsSvc - ok
18:47:51.0857 5496 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
18:47:51.0859 5496 Mraid35x - ok
18:47:51.0918 5496 [ 9BD4DCB5412921864A7AACDEDFBD1923 ] MREMP50 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
18:47:51.0920 5496 MREMP50 - ok
18:47:51.0936 5496 MREMP50a64 - ok
18:47:51.0943 5496 MREMPR5 - ok
18:47:51.0950 5496 MRENDIS5 - ok
18:47:52.0007 5496 [ 07C02C892E8E1A72D6BF35004F0E9C5E ] MRESP50 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
18:47:52.0009 5496 MRESP50 - ok
18:47:52.0013 5496 MRESP50a64 - ok
18:47:52.0057 5496 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:47:52.0079 5496 MRxDAV - ok
18:47:52.0144 5496 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:47:52.0148 5496 mrxsmb - ok
18:47:52.0200 5496 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:47:52.0206 5496 mrxsmb10 - ok
18:47:52.0243 5496 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:47:52.0246 5496 mrxsmb20 - ok
18:47:52.0296 5496 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
18:47:52.0298 5496 msahci - ok
18:47:52.0377 5496 [ 8E46A7BAC823DD82D4FB2A34C3DF4C1D ] MSCSPTISRV C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
18:47:52.0379 5496 MSCSPTISRV - ok
18:47:52.0413 5496 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:47:52.0416 5496 msdsm - ok
18:47:52.0472 5496 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
18:47:52.0477 5496 MSDTC - ok
18:47:52.0513 5496 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:47:52.0514 5496 Msfs - ok
18:47:52.0561 5496 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:47:52.0563 5496 msisadrv - ok
18:47:52.0614 5496 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:47:52.0618 5496 MSiSCSI - ok
18:47:52.0626 5496 msiserver - ok
18:47:52.0654 5496 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:47:52.0656 5496 MSKSSRV - ok
18:47:52.0754 5496 [ B0F49DA36F30922F5DDC3B623B778FCE ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
18:47:52.0754 5496 MsMpSvc - ok
18:47:52.0804 5496 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:47:52.0806 5496 MSPCLOCK - ok
18:47:52.0820 5496 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:47:52.0823 5496 MSPQM - ok
18:47:52.0851 5496 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:47:52.0856 5496 MsRPC - ok
18:47:52.0875 5496 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
18:47:52.0876 5496 mssmbios - ok
18:47:52.0931 5496 MSSQL$VAIO_VEDB - ok
18:47:52.0976 5496 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
18:47:52.0991 5496 MSSQLServerADHelper - ok
18:47:53.0014 5496 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:47:53.0015 5496 MSTEE - ok
18:47:53.0060 5496 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
18:47:53.0063 5496 Mup - ok
18:47:53.0100 5496 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
18:47:53.0109 5496 napagent - ok
18:47:53.0189 5496 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:47:53.0193 5496 NativeWifiP - ok
18:47:53.0287 5496 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:47:53.0299 5496 NDIS - ok
18:47:53.0328 5496 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:47:53.0330 5496 NdisTapi - ok
18:47:53.0362 5496 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:47:53.0381 5496 Ndisuio - ok
18:47:53.0428 5496 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:47:53.0431 5496 NdisWan - ok
18:47:53.0457 5496 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:47:53.0460 5496 NDProxy - ok
18:47:53.0477 5496 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:47:53.0479 5496 NetBIOS - ok
18:47:53.0510 5496 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
18:47:53.0515 5496 netbt - ok
18:47:53.0558 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
18:47:53.0559 5496 Netlogon - ok
18:47:53.0603 5496 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
18:47:53.0607 5496 Netman - ok
18:47:53.0699 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0736 5496 NetMsmqActivator - ok
18:47:53.0767 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0769 5496 NetPipeActivator - ok
18:47:53.0815 5496 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
18:47:53.0821 5496 netprofm - ok
18:47:53.0828 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0829 5496 NetTcpActivator - ok
18:47:53.0836 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0838 5496 NetTcpPortSharing - ok
18:47:53.0928 5496 [ A15F219208843A5A210C8CB391384453 ] NETw3v32 C:\Windows\system32\DRIVERS\NETw3v32.sys
18:47:53.0984 5496 NETw3v32 - ok
18:47:54.0123 5496 [ 25ACCCFC33DD448B9D3037C5E439E830 ] NETw4v32 C:\Windows\system32\DRIVERS\NETw4v32.sys
18:47:54.0137 5496 NETw4v32 - ok
18:47:54.0182 5496 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
18:47:54.0185 5496 nfrd960 - ok
18:47:54.0241 5496 [ 32FF06EC6D946EF791D98D6C838A3090 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
18:47:54.0244 5496 NisDrv - ok
18:47:54.0306 5496 [ 42D33042371BFB1A7D40834590CAFD30 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
18:47:54.0313 5496 NisSrv - ok
18:47:54.0355 5496 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:47:54.0361 5496 NlaSvc - ok
18:47:54.0409 5496 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
18:47:54.0411 5496 nmwcd - ok
18:47:54.0461 5496 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
18:47:54.0463 5496 nmwcdc - ok
18:47:54.0505 5496 [ 99B224F8026CB534724AA3C408561E45 ] nmwcdnsu C:\Windows\system32\drivers\nmwcdnsu.sys
18:47:54.0509 5496 nmwcdnsu - ok
18:47:54.0550 5496 [ D23257682D349A5E2E4507ED33DECC16 ] nmwcdnsuc C:\Windows\system32\drivers\nmwcdnsuc.sys
18:47:54.0551 5496 nmwcdnsuc - ok
18:47:54.0587 5496 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:47:54.0589 5496 Npfs - ok
18:47:54.0622 5496 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
18:47:54.0625 5496 nsi - ok
18:47:54.0658 5496 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:47:54.0660 5496 nsiproxy - ok
18:47:54.0741 5496 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:47:54.0775 5496 Ntfs - ok
18:47:54.0829 5496 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
18:47:54.0831 5496 ntrigdigi - ok
18:47:54.0887 5496 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
18:47:54.0888 5496 Null - ok
18:47:54.0895 5496 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:47:54.0899 5496 nvraid - ok
18:47:54.0926 5496 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:47:54.0928 5496 nvstor - ok
18:47:54.0976 5496 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:47:54.0980 5496 nv_agp - ok
18:47:54.0985 5496 NwlnkFlt - ok
18:47:54.0992 5496 NwlnkFwd - ok
18:47:55.0080 5496 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:47:55.0091 5496 odserv - ok
18:47:55.0130 5496 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
18:47:55.0130 5496 ohci1394 - ok
18:47:55.0167 5496 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:47:55.0173 5496 ose - ok
18:47:55.0258 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
18:47:55.0274 5496 p2pimsvc - ok
18:47:55.0290 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
18:47:55.0296 5496 p2psvc - ok
18:47:55.0351 5496 [ 753A8F339F231D2B857E2CCD51A6E6CA ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
18:47:55.0373 5496 PACSPTISVR - ok
18:47:55.0426 5496 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
18:47:55.0429 5496 Parport - ok
18:47:55.0467 5496 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:47:55.0469 5496 partmgr - ok
18:47:55.0475 5496 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
18:47:55.0477 5496 Parvdm - ok
18:47:55.0507 5496 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
18:47:55.0509 5496 PcaSvc - ok
18:47:55.0551 5496 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
18:47:55.0553 5496 pccsmcfd - ok
18:47:55.0614 5496 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
18:47:55.0619 5496 pci - ok
18:47:55.0649 5496 [ 3B1901E401473E03EB8C874271E50C26 ] pciide C:\Windows\system32\drivers\pciide.sys
18:47:55.0651 5496 pciide - ok
18:47:55.0699 5496 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:47:55.0704 5496 pcmcia - ok
18:47:55.0780 5496 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:47:55.0799 5496 PEAUTH - ok
18:47:55.0970 5496 [ 8ECE08EF255693EC4B1A335FD80DC509 ] PirritDesktop C:\Users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
18:47:55.0980 5496 PirritDesktop - ok
18:47:56.0066 5496 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
18:47:56.0097 5496 pla - ok
18:47:56.0174 5496 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:47:56.0182 5496 PlugPlay - ok
18:47:56.0225 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
18:47:56.0231 5496 PNRPAutoReg - ok
18:47:56.0248 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
18:47:56.0253 5496 PNRPsvc - ok
18:47:56.0322 5496 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:47:56.0344 5496 PolicyAgent - ok
18:47:56.0392 5496 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:47:56.0394 5496 PptpMiniport - ok
18:47:56.0454 5496 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
18:47:56.0456 5496 Processor - ok
18:47:56.0518 5496 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
18:47:56.0524 5496 ProfSvc - ok
18:47:56.0546 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:47:56.0548 5496 ProtectedStorage - ok
18:47:56.0554 5496 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
18:47:56.0556 5496 PxHelp20 - ok
18:47:56.0644 5496 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
18:47:56.0663 5496 ql2300 - ok
18:47:56.0690 5496 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
18:47:56.0693 5496 ql40xx - ok
18:47:56.0732 5496 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
18:47:56.0738 5496 QWAVE - ok
18:47:56.0759 5496 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:47:56.0762 5496 QWAVEdrv - ok
18:47:56.0790 5496 [ 9C9D24115F13AF3AEA05E1343A032BB1 ] R5U870FLx86 C:\Windows\system32\Drivers\R5U870FLx86.sys
18:47:56.0793 5496 R5U870FLx86 - ok
18:47:56.0806 5496 [ 18B4C879647661DE37B49C2E48D65820 ] R5U870FUx86 C:\Windows\system32\Drivers\R5U870FUx86.sys
18:47:56.0808 5496 R5U870FUx86 - ok
18:47:56.0823 5496 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:47:56.0824 5496 RasAcd - ok
18:47:56.0839 5496 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
18:47:56.0843 5496 RasAuto - ok
18:47:56.0859 5496 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:47:56.0863 5496 Rasl2tp - ok
18:47:56.0887 5496 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
18:47:56.0890 5496 RasMan - ok
18:47:56.0899 5496 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:47:56.0901 5496 RasPppoe - ok
18:47:56.0935 5496 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:47:56.0951 5496 RasSstp - ok
18:47:56.0974 5496 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:47:56.0979 5496 rdbss - ok
18:47:56.0988 5496 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:47:56.0990 5496 RDPCDD - ok
18:47:57.0064 5496 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
18:47:57.0071 5496 rdpdr - ok
18:47:57.0124 5496 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:47:57.0126 5496 RDPENCDD - ok
18:47:57.0182 5496 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:47:57.0188 5496 RDPWD - ok
18:47:57.0250 5496 [ 91A60C9B73DC6F433001DD2EC861A338 ] regi C:\Windows\system32\drivers\regi.sys
18:47:57.0252 5496 regi - ok
18:47:57.0295 5496 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:47:57.0298 5496 RemoteAccess - ok
18:47:57.0333 5496 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:47:57.0338 5496 RemoteRegistry - ok
18:47:57.0376 5496 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
18:47:57.0379 5496 RpcLocator - ok
18:47:57.0451 5496 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
18:47:57.0457 5496 RpcSs - ok
18:47:57.0502 5496 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:47:57.0505 5496 rspndr - ok
18:47:57.0547 5496 [ 904FD29EC1FF2709099AE2CD1C09A913 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
18:47:57.0550 5496 RTL8169 - ok
18:47:57.0591 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
18:47:57.0592 5496 SamSs - ok
18:47:57.0657 5496 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:47:57.0660 5496 sbp2port - ok
18:47:57.0689 5496 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:47:57.0693 5496 SCardSvr - ok
18:47:57.0758 5496 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
18:47:57.0773 5496 Schedule - ok
18:47:57.0816 5496 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
18:47:57.0817 5496 SCPolicySvc - ok
18:47:57.0870 5496 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:47:57.0887 5496 SDRSVC - ok
18:47:57.0911 5496 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:47:57.0912 5496 secdrv - ok
18:47:57.0962 5496 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
18:47:57.0964 5496 seclogon - ok
18:47:58.0023 5496 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
18:47:58.0026 5496 SENS - ok
18:47:58.0031 5496 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
18:47:58.0033 5496 Serenum - ok
18:47:58.0085 5496 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
18:47:58.0088 5496 Serial - ok
18:47:58.0125 5496 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
18:47:58.0126 5496 sermouse - ok
18:47:58.0236 5496 [ C3BB6CF8F9EE199005A2AAE2815AD756 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
18:47:58.0241 5496 ServiceLayer - ok
18:47:58.0277 5496 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
18:47:58.0281 5496 SessionEnv - ok
18:47:58.0287 5496 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:47:58.0289 5496 sffdisk - ok
18:47:58.0295 5496 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:47:58.0297 5496 sffp_mmc - ok
18:47:58.0303 5496 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:47:58.0305 5496 sffp_sd - ok
18:47:58.0311 5496 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
18:47:58.0313 5496 sfloppy - ok
18:47:58.0381 5496 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:47:58.0389 5496 SharedAccess - ok
18:47:58.0431 5496 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:47:58.0438 5496 ShellHWDetection - ok
18:47:58.0471 5496 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:47:58.0486 5496 sisagp - ok
18:47:58.0492 5496 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
18:47:58.0494 5496 SiSRaid2 - ok
18:47:58.0534 5496 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
18:47:58.0537 5496 SiSRaid4 - ok
18:47:58.0609 5496 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:47:58.0610 5496 SkypeUpdate - ok
18:47:58.0756 5496 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
18:47:58.0810 5496 slsvc - ok
18:47:58.0871 5496 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
18:47:58.0874 5496 SLUINotify - ok
18:47:58.0903 5496 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:47:58.0906 5496 Smb - ok
18:47:58.0947 5496 [ DB31D8989B3450569C29780E7FA98C48 ] SNC C:\Windows\system32\Drivers\SonyNC.sys
18:47:58.0962 5496 SNC - ok
18:47:58.0986 5496 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:47:58.0989 5496 SNMPTRAP - ok
18:47:59.0020 5496 [ FFDB6F1CB87B42F41B6DE116CD6EF809 ] SonyImgF C:\Windows\system32\DRIVERS\SonyImgF.sys
18:47:59.0022 5496 SonyImgF - ok
18:47:59.0081 5496 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
18:47:59.0083 5496 spldr - ok
18:47:59.0131 5496 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
18:47:59.0136 5496 Spooler - ok
18:47:59.0179 5496 [ E3E6C96B0EF4492C3C8FD0DEEF4E35A1 ] SPTISRV C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
18:47:59.0182 5496 SPTISRV - ok
18:47:59.0209 5496 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
18:47:59.0215 5496 SQLBrowser - ok
18:47:59.0275 5496 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
18:47:59.0277 5496 SQLWriter - ok
18:47:59.0329 5496 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:47:59.0336 5496 srv - ok
18:47:59.0387 5496 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:47:59.0392 5496 srv2 - ok
18:47:59.0416 5496 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:47:59.0419 5496 srvnet - ok
18:47:59.0467 5496 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:47:59.0472 5496 SSDPSRV - ok
18:47:59.0506 5496 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:47:59.0509 5496 SstpSvc - ok
18:47:59.0574 5496 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
18:47:59.0585 5496 stisvc - ok
18:47:59.0607 5496 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
18:47:59.0609 5496 swenum - ok
18:47:59.0703 5496 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:47:59.0707 5496 SwitchBoard - ok
18:47:59.0782 5496 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
18:47:59.0791 5496 swprv - ok
18:47:59.0943 5496 [ FA2F6A8849219B16460BF44F9D1F3AA7 ] Symantec Core LC C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
18:47:59.0969 5496 Symantec Core LC - ok
18:48:00.0020 5496 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
18:48:00.0022 5496 Symc8xx - ok
18:48:00.0071 5496 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
18:48:00.0074 5496 Sym_hi - ok
18:48:00.0080 5496 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
18:48:00.0082 5496 Sym_u3 - ok
18:48:00.0150 5496 [ 99DA94793332AADBB17BBB521AE56E21 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
18:48:00.0154 5496 SynTP - ok
18:48:00.0214 5496 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
18:48:00.0229 5496 SysMain - ok
18:48:00.0256 5496 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:48:00.0259 5496 TabletInputService - ok
18:48:00.0324 5496 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
18:48:00.0327 5496 TapiSrv - ok
18:48:00.0356 5496 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
18:48:00.0358 5496 TBS - ok
18:48:00.0449 5496 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:48:00.0468 5496 Tcpip - ok
18:48:00.0491 5496 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
18:48:00.0497 5496 Tcpip6 - ok
18:48:00.0503 5496 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:48:00.0505 5496 tcpipreg - ok
18:48:00.0546 5496 [ 009AEDE9FE870C247014450DC1E01D5D ] TcUsb C:\Windows\system32\Drivers\tcusb.sys
18:48:00.0548 5496 TcUsb - ok
18:48:00.0565 5496 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:48:00.0567 5496 TDPIPE - ok
18:48:00.0586 5496 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:48:00.0588 5496 TDTCP - ok
18:48:00.0595 5496 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:48:00.0598 5496 tdx - ok
18:48:00.0746 5496 [ A4D2CE94B028EF1E437CF4AC3D8FF26C ] TeamViewer7 C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
18:48:00.0800 5496 TeamViewer7 - ok
18:48:01.0010 5496 [ 402794A75A899E296AB3EDEC4ECCB9A8 ] TeamViewer8 C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
18:48:01.0037 5496 TeamViewer8 - ok
18:48:01.0077 5496 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
18:48:01.0079 5496 TermDD - ok
18:48:01.0150 5496 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
18:48:01.0173 5496 TermService - ok
18:48:01.0208 5496 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
18:48:01.0212 5496 Themes - ok
18:48:01.0232 5496 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
18:48:01.0234 5496 THREADORDER - ok
18:48:01.0300 5496 [ 909CD987B54A8179C9AEE874D754721A ] ti21sony C:\Windows\system32\drivers\ti21sony.sys
18:48:01.0318 5496 ti21sony - ok
18:48:01.0384 5496 [ 5480ABFC2C6B19972D2871F576EBCAA3 ] TOSHIBA Bluetooth Service C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
18:48:01.0388 5496 TOSHIBA Bluetooth Service - ok
18:48:01.0438 5496 [ 8D624D3BD1F2D78BD1C01A2D4E954B4E ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys
18:48:01.0440 5496 tosporte - ok
18:48:01.0492 5496 [ 42A23FF09BD172FA3F6A3A0A589EF1B0 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys
18:48:01.0496 5496 tosrfbd - ok
18:48:01.0531 5496 [ 90C8525BC578AAFFE87C2D0ED4379E9E ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys
18:48:01.0533 5496 tosrfbnp - ok
18:48:01.0583 5496 [ 5BA1CA3B3CDDB1DDC67DF473F05D1EC2 ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys
18:48:01.0585 5496 Tosrfcom - ok
18:48:01.0592 5496 [ 410AA85D04CFE697A2C3368286DDD128 ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys
18:48:01.0595 5496 Tosrfhid - ok
18:48:01.0638 5496 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys
18:48:01.0640 5496 tosrfnds - ok
18:48:01.0683 5496 [ A4CE9572BC4AC8D329455059B43C5BEA ] TosRfSnd C:\Windows\system32\drivers\tosrfsnd.sys
18:48:01.0685 5496 TosRfSnd - ok
18:48:01.0733 5496 [ 967316FB4777BC6EAAA0E15552FEF768 ] tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys
18:48:01.0735 5496 tosrfusb - ok
18:48:01.0788 5496 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
18:48:01.0792 5496 TrkWks - ok
18:48:01.0874 5496 [ 91B6DFBA0FD7D0F4836FB711D1B5D81C ] TrueSight C:\Windows\system32\TrueSight.sys
18:48:01.0878 5496 TrueSight - ok
18:48:02.0005 5496 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:48:02.0008 5496 TrustedInstaller - ok
18:48:02.0052 5496 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:48:02.0054 5496 tssecsrv - ok
18:48:02.0092 5496 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
18:48:02.0094 5496 tunmp - ok
18:48:02.0151 5496 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:48:02.0152 5496 tunnel - ok
18:48:02.0171 5496 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
18:48:02.0174 5496 uagp35 - ok
18:48:02.0207 5496 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:48:02.0213 5496 udfs - ok
18:48:02.0244 5496 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:48:02.0247 5496 UI0Detect - ok
18:48:02.0287 5496 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:48:02.0290 5496 uliagpkx - ok
18:48:02.0336 5496 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
18:48:02.0342 5496 uliahci - ok
18:48:02.0374 5496 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
18:48:02.0377 5496 UlSata - ok
18:48:02.0435 5496 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
18:48:02.0439 5496 ulsata2 - ok
18:48:02.0486 5496 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
18:48:02.0488 5496 umbus - ok
18:48:02.0543 5496 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
18:48:02.0551 5496 upnphost - ok
18:48:02.0607 5496 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
18:48:02.0608 5496 upperdev - ok
18:48:02.0696 5496 [ 292A25BB75A568AE2C67169BA2C6365A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
18:48:02.0699 5496 usbaudio - ok
18:48:02.0742 5496 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:48:02.0745 5496 usbccgp - ok
18:48:02.0781 5496 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:48:02.0784 5496 usbcir - ok
18:48:02.0828 5496 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:48:02.0831 5496 usbehci - ok
18:48:02.0863 5496 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:48:02.0869 5496 usbhub - ok
18:48:02.0890 5496 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:48:02.0892 5496 usbohci - ok
18:48:02.0927 5496 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:48:02.0929 5496 usbprint - ok
18:48:02.0959 5496 [ A96191470581A7091420D25ECD444502 ] usbser C:\Windows\system32\drivers\usbser.sys
18:48:02.0961 5496 usbser - ok
18:48:03.0010 5496 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
18:48:03.0012 5496 UsbserFilt - ok
18:48:03.0068 5496 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:48:03.0083 5496 USBSTOR - ok
18:48:03.0115 5496 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:48:03.0117 5496 usbuhci - ok
18:48:03.0161 5496 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
18:48:03.0165 5496 usbvideo - ok
18:48:03.0216 5496 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
18:48:03.0219 5496 UxSms - ok
18:48:03.0310 5496 [ 4E9C6BF8D0655BB7538088DC6F2306D9 ] VAIO Entertainment TV Device Arbitration Service C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
18:48:03.0313 5496 VAIO Entertainment TV Device Arbitration Service - ok
18:48:03.0421 5496 [ 8A9F18ADAD471402236CA931553BF79B ] VAIO Event Service C:\Program Files\sony\VAIO Event Service\VESMgr.exe
18:48:03.0425 5496 VAIO Event Service - ok
18:48:03.0618 5496 [ 88DC6B884824A578B0E1E9C3790C105B ] VAIOMediaPlatform-IntegratedServer-AppServer C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
18:48:03.0670 5496 VAIOMediaPlatform-IntegratedServer-AppServer - ok
18:48:03.0726 5496 [ 56E33AAA46CBA8431E72486196AFB3A1 ] VAIOMediaPlatform-IntegratedServer-HTTP C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
18:48:03.0755 5496 VAIOMediaPlatform-IntegratedServer-HTTP - ok
18:48:03.0812 5496 [ ADDF0E4E19BD2FF0A0B852D324FDC281 ] VAIOMediaPlatform-IntegratedServer-UPnP C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
18:48:03.0835 5496 VAIOMediaPlatform-IntegratedServer-UPnP - ok
18:48:03.0919 5496 [ 52D4F568FE7D05AE5026B8717EEB59EB ] VAIOMediaPlatform-UCLS-AppServer C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
18:48:03.0935 5496 VAIOMediaPlatform-UCLS-AppServer - ok
18:48:03.0951 5496 [ 56E33AAA46CBA8431E72486196AFB3A1 ] VAIOMediaPlatform-UCLS-HTTP C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
18:48:03.0954 5496 VAIOMediaPlatform-UCLS-HTTP - ok
18:48:03.0979 5496 [ ADDF0E4E19BD2FF0A0B852D324FDC281 ] VAIOMediaPlatform-UCLS-UPnP C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
18:48:03.0987 5496 VAIOMediaPlatform-UCLS-UPnP - ok
18:48:03.0991 5496 Vcsw - ok
18:48:04.0066 5496 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
18:48:04.0077 5496 vds - ok
18:48:04.0105 5496 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:48:04.0107 5496 vga - ok
18:48:04.0121 5496 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
18:48:04.0123 5496 VgaSave - ok
18:48:04.0130 5496 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:48:04.0132 5496 viaagp - ok
18:48:04.0154 5496 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
18:48:04.0156 5496 ViaC7 - ok
18:48:04.0162 5496 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
18:48:04.0164 5496 viaide - ok
18:48:04.0193 5496 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:48:04.0196 5496 volmgr - ok
18:48:04.0224 5496 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:48:04.0232 5496 volmgrx - ok
18:48:04.0279 5496 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:48:04.0284 5496 volsnap - ok
18:48:04.0311 5496 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
18:48:04.0315 5496 vsmraid - ok
18:48:04.0378 5496 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
18:48:04.0402 5496 VSS - ok
18:48:04.0463 5496 [ 5FEB20D9ED9A2BD4F234222B0A3BB855 ] VzCdbSvc C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
18:48:04.0467 5496 VzCdbSvc - ok
18:48:04.0497 5496 [ 3757DFD3C07896EF660D4060366E7B4E ] VzFw C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
18:48:04.0498 5496 VzFw - ok
18:48:04.0550 5496 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
18:48:04.0579 5496 W32Time - ok
18:48:04.0587 5496 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
18:48:04.0589 5496 WacomPen - ok
18:48:04.0607 5496 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
18:48:04.0610 5496 Wanarp - ok
18:48:04.0614 5496 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:48:04.0616 5496 Wanarpv6 - ok
18:48:04.0652 5496 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:48:04.0681 5496 wcncsvc - ok
18:48:04.0734 5496 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:48:04.0738 5496 WcsPlugInService - ok
18:48:04.0786 5496 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
18:48:04.0788 5496 Wd - ok
18:48:04.0850 5496 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:48:04.0861 5496 Wdf01000 - ok
18:48:04.0899 5496 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:48:04.0902 5496 WdiServiceHost - ok
18:48:04.0907 5496 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:48:04.0910 5496 WdiSystemHost - ok
18:48:04.0958 5496 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
18:48:04.0964 5496 WebClient - ok
18:48:05.0014 5496 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:48:05.0031 5496 Wecsvc - ok
18:48:05.0074 5496 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:48:05.0077 5496 wercplsupport - ok
18:48:05.0133 5496 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
18:48:05.0157 5496 WerSvc - ok
18:48:05.0218 5496 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
18:48:05.0233 5496 winachsf - ok
18:48:05.0286 5496 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:48:05.0293 5496 WinDefend - ok
18:48:05.0304 5496 WinHttpAutoProxySvc - ok
18:48:05.0366 5496 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:48:05.0370 5496 Winmgmt - ok
18:48:05.0444 5496 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
18:48:05.0470 5496 WinRM - ok
18:48:05.0513 5496 [ F065CD1247F838D9A88B3E86D5A9A57B ] WinRST C:\Program Files\WinRST\WinRST.exe
18:48:05.0514 5496 WinRST - ok
18:48:05.0584 5496 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:48:05.0611 5496 Wlansvc - ok
18:48:05.0757 5496 [ D9250B31B353EE3322C1CAD411997E38 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:48:05.0788 5496 wlidsvc - ok
18:48:05.0845 5496 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:48:05.0847 5496 WmiAcpi - ok
18:48:05.0907 5496 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:48:05.0911 5496 wmiApSrv - ok
18:48:06.0006 5496 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:48:06.0026 5496 WMPNetworkSvc - ok
18:48:06.0079 5496 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:48:06.0085 5496 WPCSvc - ok
18:48:06.0117 5496 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:48:06.0121 5496 WPDBusEnum - ok
18:48:06.0170 5496 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
18:48:06.0172 5496 WpdUsb - ok
18:48:06.0351 5496 [ 762CD41257671CE9DD1B57967537E0D9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:48:06.0369 5496 WPFFontCache_v0400 - ok
18:48:06.0405 5496 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:48:06.0407 5496 ws2ifsl - ok
18:48:06.0444 5496 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
18:48:06.0447 5496 wscsvc - ok
18:48:06.0452 5496 WSearch - ok
18:48:06.0567 5496 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
18:48:06.0582 5496 wuauserv - ok
18:48:06.0628 5496 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:48:06.0631 5496 WudfPf - ok
18:48:06.0691 5496 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:48:06.0695 5496 WUDFRd - ok
18:48:06.0727 5496 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:48:06.0731 5496 wudfsvc - ok
18:48:06.0777 5496 [ 88AF537264F2B818DA15479CEEAF5D7C ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
18:48:06.0778 5496 XAudio - ok
18:48:06.0824 5496 [ 15A317674A08DF26BE65164D959E9203 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
18:48:06.0833 5496 XAudioService - ok
18:48:06.0845 5496 ================ Scan global ===============================
18:48:06.0895 5496 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
18:48:06.0962 5496 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
18:48:06.0992 5496 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
18:48:07.0063 5496 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
18:48:07.0071 5496 [Global] - ok
18:48:07.0072 5496 ================ Scan MBR ==================================
18:48:07.0120 5496 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
18:48:07.0398 5496 \Device\Harddisk0\DR0 - ok
18:48:07.0398 5496 ================ Scan VBR ==================================
18:48:07.0401 5496 [ 52E9BD6CD7985C5C105A2F3F9310584D ] \Device\Harddisk0\DR0\Partition1
18:48:07.0403 5496 \Device\Harddisk0\DR0\Partition1 - ok
18:48:07.0404 5496 ============================================================
18:48:07.0404 5496 Scan finished
18:48:07.0404 5496 ============================================================
18:48:07.0416 2376 Detected object count: 0
18:48:07.0416 2376 Actual detected object count: 0
18:48:19.0787 4524 Deinitialize success
18:47:47.0736 5496 HidBth - ok
18:47:47.0743 5496 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
18:47:47.0745 5496 HidIr - ok
18:47:47.0774 5496 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\system32\hidserv.dll
18:47:47.0775 5496 hidserv - ok
18:47:47.0805 5496 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:47:47.0807 5496 HidUsb - ok
18:47:47.0841 5496 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:47:47.0845 5496 hkmsvc - ok
18:47:47.0904 5496 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
18:47:47.0906 5496 HpCISSs - ok
18:47:47.0982 5496 [ 7BC42C65B5C6281777C1A7605B253BA8 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
18:47:48.0015 5496 HSF_DPV - ok
18:47:48.0051 5496 [ 9EBF2D102CCBB6BCDFBF1B7922F8BA2E ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
18:47:48.0056 5496 HSXHWAZL - ok
18:47:48.0122 5496 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:47:48.0131 5496 HTTP - ok
18:47:48.0195 5496 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
18:47:48.0197 5496 i2omp - ok
18:47:48.0255 5496 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
18:47:48.0257 5496 i8042prt - ok
18:47:48.0315 5496 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
18:47:48.0321 5496 iaStorV - ok
18:47:48.0403 5496 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
18:47:48.0407 5496 IDriverT - ok
18:47:48.0526 5496 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:47:48.0545 5496 idsvc - ok
18:47:48.0654 5496 [ 040BCB496D604A9859657088F400F0EB ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
18:47:48.0690 5496 igfx - ok
18:47:48.0726 5496 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
18:47:48.0728 5496 iirsp - ok
18:47:48.0824 5496 [ 755519F49906B73C1FE9CBBF75E347EA ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
18:47:48.0827 5496 IJPLMSVC - ok
18:47:48.0892 5496 [ 68E8C415E102E5D79FD7E4A765B8CBA4 ] IKEEXT C:\Windows\System32\ikeext.dll
18:47:48.0903 5496 IKEEXT - ok
18:47:49.0055 5496 [ 2BD6633DB50A98534AA3262E0F9F5A14 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
18:47:49.0092 5496 IntcAzAudAddService - ok
18:47:49.0129 5496 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
18:47:49.0131 5496 intelide - ok
18:47:49.0186 5496 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:47:49.0187 5496 intelppm - ok
18:47:49.0240 5496 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:47:49.0243 5496 IPBusEnum - ok
18:47:49.0288 5496 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:47:49.0290 5496 IpFilterDriver - ok
18:47:49.0319 5496 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:47:49.0322 5496 iphlpsvc - ok
18:47:49.0328 5496 IpInIp - ok
18:47:49.0368 5496 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
18:47:49.0371 5496 IPMIDRV - ok
18:47:49.0405 5496 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
18:47:49.0409 5496 IPNAT - ok
18:47:49.0429 5496 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:47:49.0431 5496 IRENUM - ok
18:47:49.0445 5496 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:47:49.0447 5496 isapnp - ok
18:47:49.0496 5496 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
18:47:49.0500 5496 iScsiPrt - ok
18:47:49.0506 5496 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
18:47:49.0509 5496 iteatapi - ok
18:47:49.0516 5496 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
18:47:49.0518 5496 iteraid - ok
18:47:49.0554 5496 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
18:47:49.0556 5496 kbdclass - ok
18:47:49.0609 5496 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
18:47:49.0611 5496 kbdhid - ok
18:47:49.0647 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
18:47:49.0648 5496 KeyIso - ok
18:47:49.0694 5496 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:47:49.0704 5496 KSecDD - ok
18:47:49.0808 5496 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
18:47:49.0811 5496 KtmRm - ok
18:47:49.0871 5496 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\system32\srvsvc.dll
18:47:49.0876 5496 LanmanServer - ok
18:47:49.0940 5496 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:47:49.0946 5496 LanmanWorkstation - ok
18:47:50.0194 5496 [ 010FD2B41E75A98E3A4D23F44405F5C9 ] LiveUpdate C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
18:47:50.0285 5496 LiveUpdate - ok
18:47:50.0315 5496 LiveUpdate Notice Ex - ok
18:47:50.0429 5496 [ 2D1389E05A807D956829F44BD4B60389 ] LiveUpdate Notice Service C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
18:47:50.0433 5496 LiveUpdate Notice Service - ok
18:47:50.0479 5496 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:47:50.0480 5496 lltdio - ok
18:47:50.0519 5496 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:47:50.0524 5496 lltdsvc - ok
18:47:50.0557 5496 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:47:50.0559 5496 lmhosts - ok
18:47:50.0610 5496 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
18:47:50.0613 5496 LSI_FC - ok
18:47:50.0620 5496 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
18:47:50.0623 5496 LSI_SAS - ok
18:47:50.0652 5496 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
18:47:50.0654 5496 LSI_SCSI - ok
18:47:50.0726 5496 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
18:47:50.0728 5496 luafv - ok
18:47:50.0786 5496 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
18:47:50.0787 5496 MBAMProtector - ok
18:47:50.0912 5496 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:47:50.0928 5496 MBAMScheduler - ok
18:47:50.0978 5496 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:47:50.0993 5496 MBAMService - ok
18:47:51.0045 5496 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:47:51.0048 5496 Mcx2Svc - ok
18:47:51.0149 5496 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
18:47:51.0157 5496 MDM - ok
18:47:51.0201 5496 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
18:47:51.0203 5496 mdmxsdk - ok
18:47:51.0235 5496 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
18:47:51.0237 5496 megasas - ok
18:47:51.0289 5496 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
18:47:51.0292 5496 Microsoft Office Groove Audit Service - ok
18:47:51.0343 5496 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
18:47:51.0346 5496 MMCSS - ok
18:47:51.0376 5496 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
18:47:51.0378 5496 Modem - ok
18:47:51.0429 5496 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:47:51.0430 5496 monitor - ok
18:47:51.0457 5496 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:47:51.0459 5496 mouclass - ok
18:47:51.0514 5496 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:47:51.0516 5496 mouhid - ok
18:47:51.0560 5496 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
18:47:51.0562 5496 MountMgr - ok
18:47:51.0619 5496 [ E77DC03DD3C8E5A388BF9EED2A28F3D1 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
18:47:51.0624 5496 MpFilter - ok
18:47:51.0673 5496 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
18:47:51.0676 5496 mpio - ok
18:47:51.0711 5496 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:47:51.0713 5496 mpsdrv - ok
18:47:51.0822 5496 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
18:47:51.0832 5496 MpsSvc - ok
18:47:51.0857 5496 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
18:47:51.0859 5496 Mraid35x - ok
18:47:51.0918 5496 [ 9BD4DCB5412921864A7AACDEDFBD1923 ] MREMP50 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
18:47:51.0920 5496 MREMP50 - ok
18:47:51.0936 5496 MREMP50a64 - ok
18:47:51.0943 5496 MREMPR5 - ok
18:47:51.0950 5496 MRENDIS5 - ok
18:47:52.0007 5496 [ 07C02C892E8E1A72D6BF35004F0E9C5E ] MRESP50 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
18:47:52.0009 5496 MRESP50 - ok
18:47:52.0013 5496 MRESP50a64 - ok
18:47:52.0057 5496 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:47:52.0079 5496 MRxDAV - ok
18:47:52.0144 5496 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:47:52.0148 5496 mrxsmb - ok
18:47:52.0200 5496 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:47:52.0206 5496 mrxsmb10 - ok
18:47:52.0243 5496 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:47:52.0246 5496 mrxsmb20 - ok
18:47:52.0296 5496 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
18:47:52.0298 5496 msahci - ok
18:47:52.0377 5496 [ 8E46A7BAC823DD82D4FB2A34C3DF4C1D ] MSCSPTISRV C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
18:47:52.0379 5496 MSCSPTISRV - ok
18:47:52.0413 5496 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:47:52.0416 5496 msdsm - ok
18:47:52.0472 5496 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
18:47:52.0477 5496 MSDTC - ok
18:47:52.0513 5496 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:47:52.0514 5496 Msfs - ok
18:47:52.0561 5496 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:47:52.0563 5496 msisadrv - ok
18:47:52.0614 5496 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:47:52.0618 5496 MSiSCSI - ok
18:47:52.0626 5496 msiserver - ok
18:47:52.0654 5496 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:47:52.0656 5496 MSKSSRV - ok
18:47:52.0754 5496 [ B0F49DA36F30922F5DDC3B623B778FCE ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
18:47:52.0754 5496 MsMpSvc - ok
18:47:52.0804 5496 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:47:52.0806 5496 MSPCLOCK - ok
18:47:52.0820 5496 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:47:52.0823 5496 MSPQM - ok
18:47:52.0851 5496 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:47:52.0856 5496 MsRPC - ok
18:47:52.0875 5496 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
18:47:52.0876 5496 mssmbios - ok
18:47:52.0931 5496 MSSQL$VAIO_VEDB - ok
18:47:52.0976 5496 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
18:47:52.0991 5496 MSSQLServerADHelper - ok
18:47:53.0014 5496 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:47:53.0015 5496 MSTEE - ok
18:47:53.0060 5496 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
18:47:53.0063 5496 Mup - ok
18:47:53.0100 5496 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
18:47:53.0109 5496 napagent - ok
18:47:53.0189 5496 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:47:53.0193 5496 NativeWifiP - ok
18:47:53.0287 5496 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:47:53.0299 5496 NDIS - ok
18:47:53.0328 5496 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:47:53.0330 5496 NdisTapi - ok
18:47:53.0362 5496 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:47:53.0381 5496 Ndisuio - ok
18:47:53.0428 5496 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:47:53.0431 5496 NdisWan - ok
18:47:53.0457 5496 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:47:53.0460 5496 NDProxy - ok
18:47:53.0477 5496 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:47:53.0479 5496 NetBIOS - ok
18:47:53.0510 5496 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
18:47:53.0515 5496 netbt - ok
18:47:53.0558 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
18:47:53.0559 5496 Netlogon - ok
18:47:53.0603 5496 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
18:47:53.0607 5496 Netman - ok
18:47:53.0699 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0736 5496 NetMsmqActivator - ok
18:47:53.0767 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0769 5496 NetPipeActivator - ok
18:47:53.0815 5496 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
18:47:53.0821 5496 netprofm - ok
18:47:53.0828 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0829 5496 NetTcpActivator - ok
18:47:53.0836 5496 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:47:53.0838 5496 NetTcpPortSharing - ok
18:47:53.0928 5496 [ A15F219208843A5A210C8CB391384453 ] NETw3v32 C:\Windows\system32\DRIVERS\NETw3v32.sys
18:47:53.0984 5496 NETw3v32 - ok
18:47:54.0123 5496 [ 25ACCCFC33DD448B9D3037C5E439E830 ] NETw4v32 C:\Windows\system32\DRIVERS\NETw4v32.sys
18:47:54.0137 5496 NETw4v32 - ok
18:47:54.0182 5496 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
18:47:54.0185 5496 nfrd960 - ok
18:47:54.0241 5496 [ 32FF06EC6D946EF791D98D6C838A3090 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
18:47:54.0244 5496 NisDrv - ok
18:47:54.0306 5496 [ 42D33042371BFB1A7D40834590CAFD30 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
18:47:54.0313 5496 NisSrv - ok
18:47:54.0355 5496 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:47:54.0361 5496 NlaSvc - ok
18:47:54.0409 5496 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
18:47:54.0411 5496 nmwcd - ok
18:47:54.0461 5496 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
18:47:54.0463 5496 nmwcdc - ok
18:47:54.0505 5496 [ 99B224F8026CB534724AA3C408561E45 ] nmwcdnsu C:\Windows\system32\drivers\nmwcdnsu.sys
18:47:54.0509 5496 nmwcdnsu - ok
18:47:54.0550 5496 [ D23257682D349A5E2E4507ED33DECC16 ] nmwcdnsuc C:\Windows\system32\drivers\nmwcdnsuc.sys
18:47:54.0551 5496 nmwcdnsuc - ok
18:47:54.0587 5496 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:47:54.0589 5496 Npfs - ok
18:47:54.0622 5496 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
18:47:54.0625 5496 nsi - ok
18:47:54.0658 5496 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:47:54.0660 5496 nsiproxy - ok
18:47:54.0741 5496 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:47:54.0775 5496 Ntfs - ok
18:47:54.0829 5496 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
18:47:54.0831 5496 ntrigdigi - ok
18:47:54.0887 5496 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
18:47:54.0888 5496 Null - ok
18:47:54.0895 5496 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:47:54.0899 5496 nvraid - ok
18:47:54.0926 5496 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:47:54.0928 5496 nvstor - ok
18:47:54.0976 5496 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:47:54.0980 5496 nv_agp - ok
18:47:54.0985 5496 NwlnkFlt - ok
18:47:54.0992 5496 NwlnkFwd - ok
18:47:55.0080 5496 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:47:55.0091 5496 odserv - ok
18:47:55.0130 5496 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
18:47:55.0130 5496 ohci1394 - ok
18:47:55.0167 5496 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:47:55.0173 5496 ose - ok
18:47:55.0258 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
18:47:55.0274 5496 p2pimsvc - ok
18:47:55.0290 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
18:47:55.0296 5496 p2psvc - ok
18:47:55.0351 5496 [ 753A8F339F231D2B857E2CCD51A6E6CA ] PACSPTISVR C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
18:47:55.0373 5496 PACSPTISVR - ok
18:47:55.0426 5496 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
18:47:55.0429 5496 Parport - ok
18:47:55.0467 5496 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:47:55.0469 5496 partmgr - ok
18:47:55.0475 5496 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
18:47:55.0477 5496 Parvdm - ok
18:47:55.0507 5496 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
18:47:55.0509 5496 PcaSvc - ok
18:47:55.0551 5496 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
18:47:55.0553 5496 pccsmcfd - ok
18:47:55.0614 5496 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
18:47:55.0619 5496 pci - ok
18:47:55.0649 5496 [ 3B1901E401473E03EB8C874271E50C26 ] pciide C:\Windows\system32\drivers\pciide.sys
18:47:55.0651 5496 pciide - ok
18:47:55.0699 5496 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:47:55.0704 5496 pcmcia - ok
18:47:55.0780 5496 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:47:55.0799 5496 PEAUTH - ok
18:47:55.0970 5496 [ 8ECE08EF255693EC4B1A335FD80DC509 ] PirritDesktop C:\Users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
18:47:55.0980 5496 PirritDesktop - ok
18:47:56.0066 5496 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
18:47:56.0097 5496 pla - ok
18:47:56.0174 5496 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:47:56.0182 5496 PlugPlay - ok
18:47:56.0225 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
18:47:56.0231 5496 PNRPAutoReg - ok
18:47:56.0248 5496 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
18:47:56.0253 5496 PNRPsvc - ok
18:47:56.0322 5496 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:47:56.0344 5496 PolicyAgent - ok
18:47:56.0392 5496 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:47:56.0394 5496 PptpMiniport - ok
18:47:56.0454 5496 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
18:47:56.0456 5496 Processor - ok
18:47:56.0518 5496 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
18:47:56.0524 5496 ProfSvc - ok
18:47:56.0546 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:47:56.0548 5496 ProtectedStorage - ok
18:47:56.0554 5496 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
18:47:56.0556 5496 PxHelp20 - ok
18:47:56.0644 5496 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
18:47:56.0663 5496 ql2300 - ok
18:47:56.0690 5496 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
18:47:56.0693 5496 ql40xx - ok
18:47:56.0732 5496 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
18:47:56.0738 5496 QWAVE - ok
18:47:56.0759 5496 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:47:56.0762 5496 QWAVEdrv - ok
18:47:56.0790 5496 [ 9C9D24115F13AF3AEA05E1343A032BB1 ] R5U870FLx86 C:\Windows\system32\Drivers\R5U870FLx86.sys
18:47:56.0793 5496 R5U870FLx86 - ok
18:47:56.0806 5496 [ 18B4C879647661DE37B49C2E48D65820 ] R5U870FUx86 C:\Windows\system32\Drivers\R5U870FUx86.sys
18:47:56.0808 5496 R5U870FUx86 - ok
18:47:56.0823 5496 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:47:56.0824 5496 RasAcd - ok
18:47:56.0839 5496 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
18:47:56.0843 5496 RasAuto - ok
18:47:56.0859 5496 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:47:56.0863 5496 Rasl2tp - ok
18:47:56.0887 5496 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
18:47:56.0890 5496 RasMan - ok
18:47:56.0899 5496 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:47:56.0901 5496 RasPppoe - ok
18:47:56.0935 5496 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:47:56.0951 5496 RasSstp - ok
18:47:56.0974 5496 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:47:56.0979 5496 rdbss - ok
18:47:56.0988 5496 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:47:56.0990 5496 RDPCDD - ok
18:47:57.0064 5496 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
18:47:57.0071 5496 rdpdr - ok
18:47:57.0124 5496 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:47:57.0126 5496 RDPENCDD - ok
18:47:57.0182 5496 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:47:57.0188 5496 RDPWD - ok
18:47:57.0250 5496 [ 91A60C9B73DC6F433001DD2EC861A338 ] regi C:\Windows\system32\drivers\regi.sys
18:47:57.0252 5496 regi - ok
18:47:57.0295 5496 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:47:57.0298 5496 RemoteAccess - ok
18:47:57.0333 5496 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:47:57.0338 5496 RemoteRegistry - ok
18:47:57.0376 5496 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
18:47:57.0379 5496 RpcLocator - ok
18:47:57.0451 5496 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
18:47:57.0457 5496 RpcSs - ok
18:47:57.0502 5496 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:47:57.0505 5496 rspndr - ok
18:47:57.0547 5496 [ 904FD29EC1FF2709099AE2CD1C09A913 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
18:47:57.0550 5496 RTL8169 - ok
18:47:57.0591 5496 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
18:47:57.0592 5496 SamSs - ok
18:47:57.0657 5496 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:47:57.0660 5496 sbp2port - ok
18:47:57.0689 5496 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:47:57.0693 5496 SCardSvr - ok
18:47:57.0758 5496 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
18:47:57.0773 5496 Schedule - ok
18:47:57.0816 5496 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
18:47:57.0817 5496 SCPolicySvc - ok
18:47:57.0870 5496 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:47:57.0887 5496 SDRSVC - ok
18:47:57.0911 5496 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:47:57.0912 5496 secdrv - ok
18:47:57.0962 5496 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
18:47:57.0964 5496 seclogon - ok
18:47:58.0023 5496 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
18:47:58.0026 5496 SENS - ok
18:47:58.0031 5496 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
18:47:58.0033 5496 Serenum - ok
18:47:58.0085 5496 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
18:47:58.0088 5496 Serial - ok
18:47:58.0125 5496 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
18:47:58.0126 5496 sermouse - ok
18:47:58.0236 5496 [ C3BB6CF8F9EE199005A2AAE2815AD756 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
18:47:58.0241 5496 ServiceLayer - ok
18:47:58.0277 5496 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
18:47:58.0281 5496 SessionEnv - ok
18:47:58.0287 5496 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:47:58.0289 5496 sffdisk - ok
18:47:58.0295 5496 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:47:58.0297 5496 sffp_mmc - ok
18:47:58.0303 5496 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:47:58.0305 5496 sffp_sd - ok
18:47:58.0311 5496 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
18:47:58.0313 5496 sfloppy - ok
18:47:58.0381 5496 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:47:58.0389 5496 SharedAccess - ok
18:47:58.0431 5496 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:47:58.0438 5496 ShellHWDetection - ok
18:47:58.0471 5496 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:47:58.0486 5496 sisagp - ok
18:47:58.0492 5496 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
18:47:58.0494 5496 SiSRaid2 - ok
18:47:58.0534 5496 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
18:47:58.0537 5496 SiSRaid4 - ok
18:47:58.0609 5496 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:47:58.0610 5496 SkypeUpdate - ok
18:47:58.0756 5496 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
18:47:58.0810 5496 slsvc - ok
18:47:58.0871 5496 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
18:47:58.0874 5496 SLUINotify - ok
18:47:58.0903 5496 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:47:58.0906 5496 Smb - ok
18:47:58.0947 5496 [ DB31D8989B3450569C29780E7FA98C48 ] SNC C:\Windows\system32\Drivers\SonyNC.sys
18:47:58.0962 5496 SNC - ok
18:47:58.0986 5496 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:47:58.0989 5496 SNMPTRAP - ok
18:47:59.0020 5496 [ FFDB6F1CB87B42F41B6DE116CD6EF809 ] SonyImgF C:\Windows\system32\DRIVERS\SonyImgF.sys
18:47:59.0022 5496 SonyImgF - ok
18:47:59.0081 5496 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
18:47:59.0083 5496 spldr - ok
18:47:59.0131 5496 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
18:47:59.0136 5496 Spooler - ok
18:47:59.0179 5496 [ E3E6C96B0EF4492C3C8FD0DEEF4E35A1 ] SPTISRV C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
18:47:59.0182 5496 SPTISRV - ok
18:47:59.0209 5496 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
18:47:59.0215 5496 SQLBrowser - ok
18:47:59.0275 5496 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
18:47:59.0277 5496 SQLWriter - ok
18:47:59.0329 5496 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:47:59.0336 5496 srv - ok
18:47:59.0387 5496 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:47:59.0392 5496 srv2 - ok
18:47:59.0416 5496 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:47:59.0419 5496 srvnet - ok
18:47:59.0467 5496 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:47:59.0472 5496 SSDPSRV - ok
18:47:59.0506 5496 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:47:59.0509 5496 SstpSvc - ok
18:47:59.0574 5496 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
18:47:59.0585 5496 stisvc - ok
18:47:59.0607 5496 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
18:47:59.0609 5496 swenum - ok
18:47:59.0703 5496 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:47:59.0707 5496 SwitchBoard - ok
18:47:59.0782 5496 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
18:47:59.0791 5496 swprv - ok
18:47:59.0943 5496 [ FA2F6A8849219B16460BF44F9D1F3AA7 ] Symantec Core LC C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
18:47:59.0969 5496 Symantec Core LC - ok
18:48:00.0020 5496 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
18:48:00.0022 5496 Symc8xx - ok
18:48:00.0071 5496 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
18:48:00.0074 5496 Sym_hi - ok
18:48:00.0080 5496 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
18:48:00.0082 5496 Sym_u3 - ok
18:48:00.0150 5496 [ 99DA94793332AADBB17BBB521AE56E21 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
18:48:00.0154 5496 SynTP - ok
18:48:00.0214 5496 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
18:48:00.0229 5496 SysMain - ok
18:48:00.0256 5496 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:48:00.0259 5496 TabletInputService - ok
18:48:00.0324 5496 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
18:48:00.0327 5496 TapiSrv - ok
18:48:00.0356 5496 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
18:48:00.0358 5496 TBS - ok
18:48:00.0449 5496 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:48:00.0468 5496 Tcpip - ok
18:48:00.0491 5496 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
18:48:00.0497 5496 Tcpip6 - ok
18:48:00.0503 5496 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:48:00.0505 5496 tcpipreg - ok
18:48:00.0546 5496 [ 009AEDE9FE870C247014450DC1E01D5D ] TcUsb C:\Windows\system32\Drivers\tcusb.sys
18:48:00.0548 5496 TcUsb - ok
18:48:00.0565 5496 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:48:00.0567 5496 TDPIPE - ok
18:48:00.0586 5496 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:48:00.0588 5496 TDTCP - ok
18:48:00.0595 5496 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:48:00.0598 5496 tdx - ok
18:48:00.0746 5496 [ A4D2CE94B028EF1E437CF4AC3D8FF26C ] TeamViewer7 C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
18:48:00.0800 5496 TeamViewer7 - ok
18:48:01.0010 5496 [ 402794A75A899E296AB3EDEC4ECCB9A8 ] TeamViewer8 C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
18:48:01.0037 5496 TeamViewer8 - ok
18:48:01.0077 5496 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
18:48:01.0079 5496 TermDD - ok
18:48:01.0150 5496 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
18:48:01.0173 5496 TermService - ok
18:48:01.0208 5496 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
18:48:01.0212 5496 Themes - ok
18:48:01.0232 5496 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
18:48:01.0234 5496 THREADORDER - ok
18:48:01.0300 5496 [ 909CD987B54A8179C9AEE874D754721A ] ti21sony C:\Windows\system32\drivers\ti21sony.sys
18:48:01.0318 5496 ti21sony - ok
18:48:01.0384 5496 [ 5480ABFC2C6B19972D2871F576EBCAA3 ] TOSHIBA Bluetooth Service C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
18:48:01.0388 5496 TOSHIBA Bluetooth Service - ok
18:48:01.0438 5496 [ 8D624D3BD1F2D78BD1C01A2D4E954B4E ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys
18:48:01.0440 5496 tosporte - ok
18:48:01.0492 5496 [ 42A23FF09BD172FA3F6A3A0A589EF1B0 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys
18:48:01.0496 5496 tosrfbd - ok
18:48:01.0531 5496 [ 90C8525BC578AAFFE87C2D0ED4379E9E ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys
18:48:01.0533 5496 tosrfbnp - ok
18:48:01.0583 5496 [ 5BA1CA3B3CDDB1DDC67DF473F05D1EC2 ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys
18:48:01.0585 5496 Tosrfcom - ok
18:48:01.0592 5496 [ 410AA85D04CFE697A2C3368286DDD128 ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys
18:48:01.0595 5496 Tosrfhid - ok
18:48:01.0638 5496 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys
18:48:01.0640 5496 tosrfnds - ok
18:48:01.0683 5496 [ A4CE9572BC4AC8D329455059B43C5BEA ] TosRfSnd C:\Windows\system32\drivers\tosrfsnd.sys
18:48:01.0685 5496 TosRfSnd - ok
18:48:01.0733 5496 [ 967316FB4777BC6EAAA0E15552FEF768 ] tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys
18:48:01.0735 5496 tosrfusb - ok
18:48:01.0788 5496 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
18:48:01.0792 5496 TrkWks - ok
18:48:01.0874 5496 [ 91B6DFBA0FD7D0F4836FB711D1B5D81C ] TrueSight C:\Windows\system32\TrueSight.sys
18:48:01.0878 5496 TrueSight - ok
18:48:02.0005 5496 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:48:02.0008 5496 TrustedInstaller - ok
18:48:02.0052 5496 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:48:02.0054 5496 tssecsrv - ok
18:48:02.0092 5496 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
18:48:02.0094 5496 tunmp - ok
18:48:02.0151 5496 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:48:02.0152 5496 tunnel - ok
18:48:02.0171 5496 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
18:48:02.0174 5496 uagp35 - ok
18:48:02.0207 5496 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:48:02.0213 5496 udfs - ok
18:48:02.0244 5496 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:48:02.0247 5496 UI0Detect - ok
18:48:02.0287 5496 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:48:02.0290 5496 uliagpkx - ok
18:48:02.0336 5496 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
18:48:02.0342 5496 uliahci - ok
18:48:02.0374 5496 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
18:48:02.0377 5496 UlSata - ok
18:48:02.0435 5496 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
18:48:02.0439 5496 ulsata2 - ok
18:48:02.0486 5496 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
18:48:02.0488 5496 umbus - ok
18:48:02.0543 5496 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
18:48:02.0551 5496 upnphost - ok
18:48:02.0607 5496 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
18:48:02.0608 5496 upperdev - ok
18:48:02.0696 5496 [ 292A25BB75A568AE2C67169BA2C6365A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
18:48:02.0699 5496 usbaudio - ok
18:48:02.0742 5496 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:48:02.0745 5496 usbccgp - ok
18:48:02.0781 5496 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:48:02.0784 5496 usbcir - ok
18:48:02.0828 5496 [ CEBE90821810E76320155BEBA722FCF9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:48:02.0831 5496 usbehci - ok
18:48:02.0863 5496 [ CC6B28E4CE39951357963119CE47B143 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:48:02.0869 5496 usbhub - ok
18:48:02.0890 5496 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:48:02.0892 5496 usbohci - ok
18:48:02.0927 5496 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:48:02.0929 5496 usbprint - ok
18:48:02.0959 5496 [ A96191470581A7091420D25ECD444502 ] usbser C:\Windows\system32\drivers\usbser.sys
18:48:02.0961 5496 usbser - ok
18:48:03.0010 5496 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
18:48:03.0012 5496 UsbserFilt - ok
18:48:03.0068 5496 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:48:03.0083 5496 USBSTOR - ok
18:48:03.0115 5496 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:48:03.0117 5496 usbuhci - ok
18:48:03.0161 5496 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
18:48:03.0165 5496 usbvideo - ok
18:48:03.0216 5496 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
18:48:03.0219 5496 UxSms - ok
18:48:03.0310 5496 [ 4E9C6BF8D0655BB7538088DC6F2306D9 ] VAIO Entertainment TV Device Arbitration Service C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
18:48:03.0313 5496 VAIO Entertainment TV Device Arbitration Service - ok
18:48:03.0421 5496 [ 8A9F18ADAD471402236CA931553BF79B ] VAIO Event Service C:\Program Files\sony\VAIO Event Service\VESMgr.exe
18:48:03.0425 5496 VAIO Event Service - ok
18:48:03.0618 5496 [ 88DC6B884824A578B0E1E9C3790C105B ] VAIOMediaPlatform-IntegratedServer-AppServer C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
18:48:03.0670 5496 VAIOMediaPlatform-IntegratedServer-AppServer - ok
18:48:03.0726 5496 [ 56E33AAA46CBA8431E72486196AFB3A1 ] VAIOMediaPlatform-IntegratedServer-HTTP C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
18:48:03.0755 5496 VAIOMediaPlatform-IntegratedServer-HTTP - ok
18:48:03.0812 5496 [ ADDF0E4E19BD2FF0A0B852D324FDC281 ] VAIOMediaPlatform-IntegratedServer-UPnP C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
18:48:03.0835 5496 VAIOMediaPlatform-IntegratedServer-UPnP - ok
18:48:03.0919 5496 [ 52D4F568FE7D05AE5026B8717EEB59EB ] VAIOMediaPlatform-UCLS-AppServer C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
18:48:03.0935 5496 VAIOMediaPlatform-UCLS-AppServer - ok
18:48:03.0951 5496 [ 56E33AAA46CBA8431E72486196AFB3A1 ] VAIOMediaPlatform-UCLS-HTTP C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
18:48:03.0954 5496 VAIOMediaPlatform-UCLS-HTTP - ok
18:48:03.0979 5496 [ ADDF0E4E19BD2FF0A0B852D324FDC281 ] VAIOMediaPlatform-UCLS-UPnP C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
18:48:03.0987 5496 VAIOMediaPlatform-UCLS-UPnP - ok
18:48:03.0991 5496 Vcsw - ok
18:48:04.0066 5496 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
18:48:04.0077 5496 vds - ok
18:48:04.0105 5496 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:48:04.0107 5496 vga - ok
18:48:04.0121 5496 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
18:48:04.0123 5496 VgaSave - ok
18:48:04.0130 5496 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:48:04.0132 5496 viaagp - ok
18:48:04.0154 5496 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
18:48:04.0156 5496 ViaC7 - ok
18:48:04.0162 5496 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
18:48:04.0164 5496 viaide - ok
18:48:04.0193 5496 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:48:04.0196 5496 volmgr - ok
18:48:04.0224 5496 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:48:04.0232 5496 volmgrx - ok
18:48:04.0279 5496 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:48:04.0284 5496 volsnap - ok
18:48:04.0311 5496 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
18:48:04.0315 5496 vsmraid - ok
18:48:04.0378 5496 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
18:48:04.0402 5496 VSS - ok
18:48:04.0463 5496 [ 5FEB20D9ED9A2BD4F234222B0A3BB855 ] VzCdbSvc C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
18:48:04.0467 5496 VzCdbSvc - ok
18:48:04.0497 5496 [ 3757DFD3C07896EF660D4060366E7B4E ] VzFw C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
18:48:04.0498 5496 VzFw - ok
18:48:04.0550 5496 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
18:48:04.0579 5496 W32Time - ok
18:48:04.0587 5496 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
18:48:04.0589 5496 WacomPen - ok
18:48:04.0607 5496 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
18:48:04.0610 5496 Wanarp - ok
18:48:04.0614 5496 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:48:04.0616 5496 Wanarpv6 - ok
18:48:04.0652 5496 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:48:04.0681 5496 wcncsvc - ok
18:48:04.0734 5496 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:48:04.0738 5496 WcsPlugInService - ok
18:48:04.0786 5496 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
18:48:04.0788 5496 Wd - ok
18:48:04.0850 5496 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:48:04.0861 5496 Wdf01000 - ok
18:48:04.0899 5496 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:48:04.0902 5496 WdiServiceHost - ok
18:48:04.0907 5496 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:48:04.0910 5496 WdiSystemHost - ok
18:48:04.0958 5496 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
18:48:04.0964 5496 WebClient - ok
18:48:05.0014 5496 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:48:05.0031 5496 Wecsvc - ok
18:48:05.0074 5496 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:48:05.0077 5496 wercplsupport - ok
18:48:05.0133 5496 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
18:48:05.0157 5496 WerSvc - ok
18:48:05.0218 5496 [ 5A77AC34A0FFB70CE8B35B524FEDE9BA ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
18:48:05.0233 5496 winachsf - ok
18:48:05.0286 5496 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:48:05.0293 5496 WinDefend - ok
18:48:05.0304 5496 WinHttpAutoProxySvc - ok
18:48:05.0366 5496 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:48:05.0370 5496 Winmgmt - ok
18:48:05.0444 5496 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
18:48:05.0470 5496 WinRM - ok
18:48:05.0513 5496 [ F065CD1247F838D9A88B3E86D5A9A57B ] WinRST C:\Program Files\WinRST\WinRST.exe
18:48:05.0514 5496 WinRST - ok
18:48:05.0584 5496 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:48:05.0611 5496 Wlansvc - ok
18:48:05.0757 5496 [ D9250B31B353EE3322C1CAD411997E38 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:48:05.0788 5496 wlidsvc - ok
18:48:05.0845 5496 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:48:05.0847 5496 WmiAcpi - ok
18:48:05.0907 5496 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:48:05.0911 5496 wmiApSrv - ok
18:48:06.0006 5496 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:48:06.0026 5496 WMPNetworkSvc - ok
18:48:06.0079 5496 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:48:06.0085 5496 WPCSvc - ok
18:48:06.0117 5496 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:48:06.0121 5496 WPDBusEnum - ok
18:48:06.0170 5496 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
18:48:06.0172 5496 WpdUsb - ok
18:48:06.0351 5496 [ 762CD41257671CE9DD1B57967537E0D9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:48:06.0369 5496 WPFFontCache_v0400 - ok
18:48:06.0405 5496 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:48:06.0407 5496 ws2ifsl - ok
18:48:06.0444 5496 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\System32\wscsvc.dll
18:48:06.0447 5496 wscsvc - ok
18:48:06.0452 5496 WSearch - ok
18:48:06.0567 5496 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
18:48:06.0582 5496 wuauserv - ok
18:48:06.0628 5496 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:48:06.0631 5496 WudfPf - ok
18:48:06.0691 5496 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:48:06.0695 5496 WUDFRd - ok
18:48:06.0727 5496 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:48:06.0731 5496 wudfsvc - ok
18:48:06.0777 5496 [ 88AF537264F2B818DA15479CEEAF5D7C ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
18:48:06.0778 5496 XAudio - ok
18:48:06.0824 5496 [ 15A317674A08DF26BE65164D959E9203 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
18:48:06.0833 5496 XAudioService - ok
18:48:06.0845 5496 ================ Scan global ===============================
18:48:06.0895 5496 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
18:48:06.0962 5496 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
18:48:06.0992 5496 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
18:48:07.0063 5496 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
18:48:07.0071 5496 [Global] - ok
18:48:07.0072 5496 ================ Scan MBR ==================================
18:48:07.0120 5496 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
18:48:07.0398 5496 \Device\Harddisk0\DR0 - ok
18:48:07.0398 5496 ================ Scan VBR ==================================
18:48:07.0401 5496 [ 52E9BD6CD7985C5C105A2F3F9310584D ] \Device\Harddisk0\DR0\Partition1
18:48:07.0403 5496 \Device\Harddisk0\DR0\Partition1 - ok
18:48:07.0404 5496 ============================================================
18:48:07.0404 5496 Scan finished
18:48:07.0404 5496 ============================================================
18:48:07.0416 2376 Detected object count: 0
18:48:07.0416 2376 Actual detected object count: 0
18:48:19.0787 4524 Deinitialize success
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
Zdravím, dneska celý den nevyskakovaly žádné reklamy. Jenže k večeru po provedení testu MbAM začaly opět vyskakovat. A navíc před malou chvílí mi ani nešel internet, znovu se zprovoznil až po restartu.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
ComboFix 14-02-24.02 - PEKY 28.02.2014 22:21:15.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.866 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\pt
c:\windows\system32\pt\AuthFWSnapIn.Resources.dll
c:\windows\system32\pt\AuthFWWizFwk.Resources.dll
c:\windows\system32\pt\Narrator.resources.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-28 do 2014-02-28 )))))))))))))))))))))))))))))))
.
.
2014-02-28 21:35 . 2014-02-28 21:35 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-02-28 21:35 . 2014-02-28 21:35 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-02-28 21:08 . 2014-02-28 21:08 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{451A7C3D-F32B-4469-8029-279C438B452F}\offreg.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{451A7C3D-F32B-4469-8029-279C438B452F}\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-25 21:05 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-21 19:53 . 2014-02-25 21:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-02-21 19:53 . 2014-02-25 21:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.cz/cz.special-uninstalla ... er=9.0.914" [?]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\SUPERAntiSpyware\SASSEH.DLL
Notify-chaiglr - c:\users\PEKY\AppData\Local\chaiglr.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
AddRemove-VLC media player - c:\users\PEKY\Desktop\něco jiného mpg\VLC\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-02-28 22:35
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2014-02-28 22:38:22
ComboFix-quarantined-files.txt 2014-02-28 21:38
.
Před spuštěním: 2 218 840 064
Po spuštění: 2 359 771 136
.
- - End Of File - - D72334176E1880A35F07D277B71E6510
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.866 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\pt
c:\windows\system32\pt\AuthFWSnapIn.Resources.dll
c:\windows\system32\pt\AuthFWWizFwk.Resources.dll
c:\windows\system32\pt\Narrator.resources.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-28 do 2014-02-28 )))))))))))))))))))))))))))))))
.
.
2014-02-28 21:35 . 2014-02-28 21:35 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-02-28 21:35 . 2014-02-28 21:35 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-02-28 21:08 . 2014-02-28 21:08 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{451A7C3D-F32B-4469-8029-279C438B452F}\offreg.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{451A7C3D-F32B-4469-8029-279C438B452F}\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-25 21:05 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-21 19:53 . 2014-02-25 21:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-02-21 19:53 . 2014-02-25 21:45 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.cz/cz.special-uninstalla ... er=9.0.914" [?]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\SUPERAntiSpyware\SASSEH.DLL
Notify-chaiglr - c:\users\PEKY\AppData\Local\chaiglr.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
AddRemove-VLC media player - c:\users\PEKY\Desktop\něco jiného mpg\VLC\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-02-28 22:35
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2014-02-28 22:38:22
ComboFix-quarantined-files.txt 2014-02-28 21:38
.
Před spuštěním: 2 218 840 064
Po spuštění: 2 359 771 136
.
- - End Of File - - D72334176E1880A35F07D277B71E6510
5C616939100B85E558DA92B899A0FC36
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
Spuštěný z: c:\users\PEKY\Downloads\ComboFix.exe
přemísti Combofix.exe na plochu!
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
Folder::
c:\programdata\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy 2
c:\program files\Common Files\Symantec Shared
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000000
RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Nemáš málo volného místa na disku? Měl bys mít nejméně 15% volného místa pro chod windows.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
ComboFix 14-02-24.02 - PEKY 01.03.2014 20:21:17.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.337 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEKY\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
c:\program files\Common Files\Symantec Shared\COH\COH64.exe
c:\program files\Common Files\Symantec Shared\COH\COHClean.dll
c:\program files\Common Files\Symantec Shared\COH\sH0007.dll
c:\program files\Common Files\Symantec Shared\Help\LUALL.CHM
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertUi.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcGlobal.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcmhSvar.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcProd.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\09\01\AlertEng.loc
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\fallback.dat
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\lun.ico
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhDSA.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhSched.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhUpgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifCrawl.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep06.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep07.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PollMgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\readme.txt
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\SymHTML.dll
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.grd
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.sig
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.spm
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.grd
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.sig
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.spm
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.grd
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.sig
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.spm
c:\program files\Spybot - Search & Destroy 2
c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-211028.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-221521.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140223-144216.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140224-192933.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2056.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2110.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2112.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2130.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2215.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2311.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140222-1116.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1442.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1448.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140224-1929.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\RootkitQuickScan.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_LiveUpdate Notice Service
-------\Service_CLTNetCnService
-------\Service_LiveUpdate Notice Ex
-------\Service_LiveUpdate Notice Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-01 do 2014-03-01 )))))))))))))))))))))))))))))))
.
.
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\TEr\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-01 19:18 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEC2FC58-E364-43EE-BAD8-38B482C54884}\mpengine.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-01 20:44
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1192)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
c:\program files\TeamViewer\Version8\TeamViewer_Service.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\WinRST\WinRST.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritDesktop.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2014-03-01 20:47:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-03-01 19:47
ComboFix2.txt 2014-02-28 21:38
.
Před spuštěním: Volných bajtů: 21 214 396 416
Po spuštění: Volných bajtů: 20 588 494 848
.
- - End Of File - - 8265A4F6B508DCEDA3AD25BB993CED19
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.337 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEKY\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
c:\program files\Common Files\Symantec Shared\COH\COH64.exe
c:\program files\Common Files\Symantec Shared\COH\COHClean.dll
c:\program files\Common Files\Symantec Shared\COH\sH0007.dll
c:\program files\Common Files\Symantec Shared\Help\LUALL.CHM
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertUi.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcGlobal.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcmhSvar.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcProd.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\09\01\AlertEng.loc
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\fallback.dat
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\lun.ico
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhDSA.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhSched.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhUpgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifCrawl.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep06.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep07.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PollMgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\readme.txt
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\SymHTML.dll
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.grd
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.sig
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.spm
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.grd
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.sig
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.spm
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.grd
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.sig
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.spm
c:\program files\Spybot - Search & Destroy 2
c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-211028.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-221521.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140223-144216.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140224-192933.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2056.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2110.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2112.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2130.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2215.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2311.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140222-1116.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1442.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1448.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140224-1929.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\RootkitQuickScan.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_LiveUpdate Notice Service
-------\Service_CLTNetCnService
-------\Service_LiveUpdate Notice Ex
-------\Service_LiveUpdate Notice Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-01 do 2014-03-01 )))))))))))))))))))))))))))))))
.
.
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\TEr\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-01 19:18 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEC2FC58-E364-43EE-BAD8-38B482C54884}\mpengine.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-01 20:44
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1192)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
c:\program files\TeamViewer\Version8\TeamViewer_Service.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\WinRST\WinRST.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritDesktop.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2014-03-01 20:47:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-03-01 19:47
ComboFix2.txt 2014-02-28 21:38
.
Před spuštěním: Volných bajtů: 21 214 396 416
Po spuštění: Volných bajtů: 20 588 494 848
.
- - End Of File - - 8265A4F6B508DCEDA3AD25BB993CED19
5C616939100B85E558DA92B899A0FC36
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
ComboFix 14-02-24.02 - PEKY 01.03.2014 20:21:17.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.337 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEKY\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
c:\program files\Common Files\Symantec Shared\COH\COH64.exe
c:\program files\Common Files\Symantec Shared\COH\COHClean.dll
c:\program files\Common Files\Symantec Shared\COH\sH0007.dll
c:\program files\Common Files\Symantec Shared\Help\LUALL.CHM
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertUi.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcGlobal.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcmhSvar.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcProd.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\09\01\AlertEng.loc
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\fallback.dat
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\lun.ico
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhDSA.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhSched.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhUpgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifCrawl.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep06.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep07.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PollMgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\readme.txt
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\SymHTML.dll
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.grd
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.sig
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.spm
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.grd
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.sig
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.spm
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.grd
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.sig
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.spm
c:\program files\Spybot - Search & Destroy 2
c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-211028.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-221521.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140223-144216.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140224-192933.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2056.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2110.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2112.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2130.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2215.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2311.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140222-1116.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1442.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1448.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140224-1929.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\RootkitQuickScan.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_LiveUpdate Notice Service
-------\Service_CLTNetCnService
-------\Service_LiveUpdate Notice Ex
-------\Service_LiveUpdate Notice Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-01 do 2014-03-01 )))))))))))))))))))))))))))))))
.
.
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\TEr\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-01 19:18 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEC2FC58-E364-43EE-BAD8-38B482C54884}\mpengine.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-01 20:44
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1192)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
c:\program files\TeamViewer\Version8\TeamViewer_Service.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\WinRST\WinRST.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritDesktop.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2014-03-01 20:47:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-03-01 19:47
ComboFix2.txt 2014-02-28 21:38
.
Před spuštěním: Volných bajtů: 21 214 396 416
Po spuštění: Volných bajtů: 20 588 494 848
.
- - End Of File - - 8265A4F6B508DCEDA3AD25BB993CED19
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.420.1029.18.2038.337 [GMT 1:00]
Spuštěný z: c:\users\PEKY\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEKY\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
c:\program files\Common Files\Symantec Shared\COH\COH64.exe
c:\program files\Common Files\Symantec Shared\COH\COHClean.dll
c:\program files\Common Files\Symantec Shared\COH\sH0007.dll
c:\program files\Common Files\Symantec Shared\Help\LUALL.CHM
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertUi.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcGlobal.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcmhSvar.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\dcProd.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\09\01\AlertEng.loc
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\Languages\fallback.dat
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\lun.ico
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhDSA.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhSched.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\mhUpgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifCrawl.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep06.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifPep07.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PollMgr.dll
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\readme.txt
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\SymHTML.dll
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.grd
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.sig
c:\program files\Common Files\Symantec Shared\SPManifests\AlertEng.spm
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.grd
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.sig
c:\program files\Common Files\Symantec Shared\SPManifests\LuSymProtect.spm
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.grd
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.sig
c:\program files\Common Files\Symantec Shared\SPManifests\PifCore.spm
c:\program files\Spybot - Search & Destroy 2
c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-211028.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140221-221521.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140223-144216.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140224-192933.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2056.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2110.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2112.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2130.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2215.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140221-2311.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140222-1116.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1442.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140223-1448.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140224-1929.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\RootkitQuickScan.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_LiveUpdate Notice Service
-------\Service_CLTNetCnService
-------\Service_LiveUpdate Notice Ex
-------\Service_LiveUpdate Notice Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-01 do 2014-03-01 )))))))))))))))))))))))))))))))
.
.
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Tereza\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\TEr\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-03-01 19:38 . 2014-03-01 19:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-01 19:18 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEC2FC58-E364-43EE-BAD8-38B482C54884}\mpengine.dll
2014-02-27 14:13 . 2014-02-17 00:32 7947048 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-26 20:01 . 2014-02-26 20:01 -------- d-----w- c:\windows\ERUNT
2014-02-25 22:10 . 2014-02-25 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-25 22:10 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-25 21:54 . 2014-02-26 19:51 -------- d-----w- C:\AdwCleaner
2014-02-24 19:07 . 2014-02-24 19:07 -------- d-----w- c:\program files\Enigma Software Group
2014-02-23 21:41 . 2014-02-24 19:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-02-23 13:58 . 2014-02-23 13:58 -------- d-----w- c:\users\Guest\AppData\Local\WinRST
2014-02-23 13:56 . 2014-02-23 13:56 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2014-02-23 12:06 . 2014-02-23 12:06 -------- d-----w- c:\users\PEKY\AppData\Roaming\SUPERAntiSpyware.com
2014-02-23 02:14 . 2014-02-23 02:24 -------- d-----w- c:\windows\system32\MRT
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-22 16:55 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9465F9F-3CDD-48C9-90F4-231BBB8D165F}\gapaengine.dll
2014-02-22 16:41 . 2014-02-22 16:41 -------- d-----w- c:\program files\Microsoft Security Client
2014-02-22 12:14 . 2014-02-22 18:44 -------- d-----w- c:\programdata\Avira
2014-02-22 10:45 . 2014-02-22 10:45 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-02-21 22:32 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\Apple Computer
2014-02-21 22:32 . 2014-02-21 22:33 -------- d-----w- c:\programdata\ProductData
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-02-21 22:31 . 2014-02-21 22:31 -------- d-----w- c:\programdata\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-02-21 22:28 . 2014-02-21 22:31 -------- d-----w- c:\programdata\IObit
2014-02-21 22:27 . 2014-02-21 22:32 -------- d-----w- c:\users\PEKY\AppData\Roaming\IObit
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\users\PEKY\AppData\Local\WinRST
2014-02-21 21:02 . 2014-02-21 21:02 -------- d-----w- c:\program files\WinRST
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Malwarebytes
2014-02-20 21:24 . 2014-02-20 21:24 -------- d-----w- c:\programdata\Malwarebytes
2014-02-19 20:26 . 2014-02-20 22:24 -------- d-----w- c:\programdata\tmp
2014-02-19 20:26 . 2014-02-19 20:26 -------- d-----w- c:\programdata\hps
2014-02-19 20:14 . 2014-02-21 20:37 -------- d-----w- c:\program files\dm
2014-02-14 20:10 . 2014-02-17 09:15 -------- d-----w- c:\users\PEKY\AppData\Local\PirritSuggestor
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Moyea
2014-02-06 20:24 . 2014-02-06 20:24 -------- d-----w- c:\users\PEKY\AppData\Roaming\Leawo
2014-02-06 20:23 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
2014-02-06 20:22 . 2008-10-28 09:10 139264 ----a-w- c:\windows\system32\xvid.ax
2014-02-06 20:22 . 2008-10-08 08:45 606208 ----a-w- c:\windows\system32\xvidcore.dll
2014-02-06 20:22 . 2014-02-06 20:22 -------- d-----w- c:\program files\Leawo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-20 21:42 . 2012-12-27 10:12 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-20 21:42 . 2012-12-27 10:12 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2009-12-16 01:10 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-02-13 22:19 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-19 13:41 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-27 21:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\PEKY\AppData\Roaming\Mozilla\Firefox\Profiles\7m22lln5.default-1393620402588\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-01 20:44
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(1192)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
c:\program files\TeamViewer\Version8\TeamViewer_Service.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\WinRST\WinRST.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\sony\VAIO Event Service\VESMgrSub.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\users\PEKY\AppData\Local\PirritSuggestor\PirritDesktop.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Celkový čas: 2014-03-01 20:47:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-03-01 19:47
ComboFix2.txt 2014-02-28 21:38
.
Před spuštěním: Volných bajtů: 21 214 396 416
Po spuštění: Volných bajtů: 20 588 494 848
.
- - End Of File - - 8265A4F6B508DCEDA3AD25BB993CED19
5C616939100B85E558DA92B899A0FC36
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-03-01 21:01:49
-----------------------------
21:01:49.634 OS Version: Windows 6.0.6001 Service Pack 1
21:01:49.634 Number of processors: 2 586 0xF0D
21:01:49.634 ComputerName: KAMILA-PC UserName: PEKY
21:01:50.788 Initialize success
21:02:00.247 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:02:00.247 Disk 0 Vendor: TOSHIBA_MK1234GSX AH001A Size: 114473MB BusType: 3
21:02:00.247 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000063
21:02:00.247 Disk 1 Vendor: ( Size: 114473MB BusType: 0
21:02:00.247 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000064
21:02:00.262 Disk 2 Vendor: ( Size: 114473MB BusType: 0
21:02:00.371 Disk 0 MBR read successfully
21:02:00.371 Disk 0 MBR scan
21:02:00.371 Disk 0 Windows VISTA default MBR code
21:02:00.387 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10013 MB offset 2048
21:02:00.403 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 104459 MB offset 20508672
21:02:00.403 Disk 0 scanning sectors +234440704
21:02:00.481 Disk 0 scanning C:\Windows\system32\drivers
21:02:08.983 Service scanning
21:02:32.757 Modules scanning
21:02:40.417 Disk 0 trace - called modules:
21:02:40.432 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys watchdog.sys
21:02:40.448 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85458260]
21:02:40.448 3 CLASSPNP.SYS[881a6745] -> nt!IofCallDriver -> [0x84dea8f8]
21:02:40.463 5 acpi.sys[806966a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84dec8a8]
21:02:40.463 Scan finished successfully
21:03:02.272 Disk 0 MBR has been saved successfully to "C:\Users\PEKY\Desktop\MBR.dat"
21:03:02.272 The log file has been saved successfully to "C:\Users\PEKY\Desktop\aswMBR.txt"
Run date: 2014-03-01 21:01:49
-----------------------------
21:01:49.634 OS Version: Windows 6.0.6001 Service Pack 1
21:01:49.634 Number of processors: 2 586 0xF0D
21:01:49.634 ComputerName: KAMILA-PC UserName: PEKY
21:01:50.788 Initialize success
21:02:00.247 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:02:00.247 Disk 0 Vendor: TOSHIBA_MK1234GSX AH001A Size: 114473MB BusType: 3
21:02:00.247 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000063
21:02:00.247 Disk 1 Vendor: ( Size: 114473MB BusType: 0
21:02:00.247 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000064
21:02:00.262 Disk 2 Vendor: ( Size: 114473MB BusType: 0
21:02:00.371 Disk 0 MBR read successfully
21:02:00.371 Disk 0 MBR scan
21:02:00.371 Disk 0 Windows VISTA default MBR code
21:02:00.387 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10013 MB offset 2048
21:02:00.403 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 104459 MB offset 20508672
21:02:00.403 Disk 0 scanning sectors +234440704
21:02:00.481 Disk 0 scanning C:\Windows\system32\drivers
21:02:08.983 Service scanning
21:02:32.757 Modules scanning
21:02:40.417 Disk 0 trace - called modules:
21:02:40.432 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys watchdog.sys
21:02:40.448 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85458260]
21:02:40.448 3 CLASSPNP.SYS[881a6745] -> nt!IofCallDriver -> [0x84dea8f8]
21:02:40.463 5 acpi.sys[806966a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x84dec8a8]
21:02:40.463 Scan finished successfully
21:03:02.272 Disk 0 MBR has been saved successfully to "C:\Users\PEKY\Desktop\MBR.dat"
21:03:02.272 The log file has been saved successfully to "C:\Users\PEKY\Desktop\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Při používání Firefoxu vyskakují reklamy, prosím o kontr
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\program files\WinRST\WinRST.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Toto otestuj na Virustotal
c:\program files\WinRST\WinRST.exe
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 111 hostů