RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : DiTečka [Práva správce]
Mód : Odebrat -- Datum : 03/30/2014 13:19:08
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[RUN][SUSP UNIC] HKCU\[...]\Run : okwi.exe (C:\Users\DiTečka\AppData\Roaming\Kevog\okwi.exe [x]) -> VYMAZÁNO
[RUN][SUSP UNIC] HKUS\S-1-5-21-2837769118-3272812729-1211413634-1000\[...]\Run : okwi.exe (C:\Users\DiTečka\AppData\Roaming\Kevog\okwi.exe [x]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Address] EAT @explorer.exe (DllCanUnloadNow) : WINSPOOL.DRV -> HOOKED (C:\Windows\System32\SndVolSSO.dll @ 0x7530155F)
[Address] EAT @explorer.exe (DllGetClassObject) : WINSPOOL.DRV -> HOOKED (C:\Windows\System32\SndVolSSO.dll @ 0x75304852)
[Address] EAT @explorer.exe (DllMain) : WINSPOOL.DRV -> HOOKED (C:\Windows\System32\SndVolSSO.dll @ 0x753012FB)
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST9500325AS ATA Device +++++
--- User ---
[MBR] 0d07d72b43e182bc687c3bcc8ad63bab
[BSP] e0823f4dc0bb9d171d421cfb9854e463 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 12000 MB
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 24579450 | Size: 238464 MB
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 512955450 | Size: 226471 MB
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) SanDisk Cruzer USB Device +++++
--- User ---
[MBR] bfc2508142cb31e56488e57ad8f80c9c
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 30532 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] Po?adavek není podporován. )
Dokončeno : << RKreport[0]_D_03302014_131908.txt >>
RKreport[0]_S_03292014_140157.txt;RKreport[0]_S_03302014_131859.txt
Prosím o kontrolu logu, zdvojené háčky a čárky Vyřešeno
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
13:21:45.0860 5044 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:21:45.0907 5044 ============================================================
13:21:45.0907 5044 Current date / time: 2014/03/30 13:21:45.0907
13:21:45.0907 5044 SystemInfo:
13:21:45.0907 5044
13:21:45.0907 5044 OS Version: 6.0.6002 ServicePack: 2.0
13:21:45.0907 5044 Product type: Workstation
13:21:45.0907 5044 ComputerName: PC
13:21:45.0907 5044 UserName: DiTečka
13:21:45.0907 5044 Windows directory: C:\Windows
13:21:45.0907 5044 System windows directory: C:\Windows
13:21:45.0907 5044 Processor architecture: Intel x86
13:21:45.0907 5044 Number of processors: 2
13:21:45.0907 5044 Page size: 0x1000
13:21:45.0907 5044 Boot type: Normal boot
13:21:45.0907 5044 ============================================================
13:21:47.0202 5044 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:21:47.0202 5044 Drive \Device\Harddisk1\DR1 - Size: 0x774488000 (29.82 Gb), SectorSize: 0x200, Cylinders: 0xF34, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:21:47.0202 5044 ============================================================
13:21:47.0202 5044 \Device\Harddisk0\DR0:
13:21:47.0202 5044 MBR partitions:
13:21:47.0202 5044 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1770000
13:21:47.0202 5044 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1770D7A, BlocksNum 0x1D1C06C0
13:21:47.0233 5044 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1E931479, BlocksNum 0x1BA537C8
13:21:47.0233 5044 \Device\Harddisk1\DR1:
13:21:47.0233 5044 MBR partitions:
13:21:47.0233 5044 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x3BA2420
13:21:47.0233 5044 ============================================================
13:21:47.0280 5044 C: <-> \Device\Harddisk0\DR0\Partition2
13:21:47.0326 5044 D: <-> \Device\Harddisk0\DR0\Partition3
13:21:47.0373 5044 I: <-> \Device\Harddisk0\DR0\Partition1
13:21:47.0373 5044 ============================================================
13:21:47.0373 5044 Initialize success
13:21:47.0373 5044 ============================================================
13:21:50.0556 5116 ============================================================
13:21:50.0556 5116 Scan started
13:21:50.0556 5116 Mode: Manual;
13:21:50.0556 5116 ============================================================
13:21:52.0147 5116 ================ Scan system memory ========================
13:21:52.0147 5116 System memory - ok
13:21:52.0147 5116 ================ Scan services =============================
13:21:52.0350 5116 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:21:52.0350 5116 ACPI - ok
13:21:52.0521 5116 [ 1474F121C3DF1232D3E7239C03691EE6 ] AdobeActiveFileMonitor9.0 C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
13:21:52.0521 5116 AdobeActiveFileMonitor9.0 - ok
13:21:52.0630 5116 [ 9D96B0D5855FD1B98023B3EEC9F06786 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:21:52.0630 5116 AdobeFlashPlayerUpdateSvc - ok
13:21:52.0724 5116 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:21:52.0724 5116 adp94xx - ok
13:21:52.0755 5116 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:21:52.0755 5116 adpahci - ok
13:21:52.0786 5116 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:21:52.0786 5116 adpu160m - ok
13:21:52.0802 5116 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:21:52.0802 5116 adpu320 - ok
13:21:52.0864 5116 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:21:52.0864 5116 AeLookupSvc - ok
13:21:52.0927 5116 [ A201207363AA900ABF1A388468688570 ] AFD C:\Windows\system32\drivers\afd.sys
13:21:52.0927 5116 AFD - ok
13:21:52.0974 5116 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:21:52.0989 5116 agp440 - ok
13:21:53.0005 5116 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:21:53.0005 5116 aic78xx - ok
13:21:53.0020 5116 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:21:53.0020 5116 ALG - ok
13:21:53.0036 5116 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:21:53.0036 5116 aliide - ok
13:21:53.0083 5116 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:21:53.0083 5116 amdagp - ok
13:21:53.0098 5116 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:21:53.0098 5116 amdide - ok
13:21:53.0114 5116 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:21:53.0114 5116 AmdK7 - ok
13:21:53.0145 5116 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:21:53.0145 5116 AmdK8 - ok
13:21:53.0208 5116 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:21:53.0208 5116 Appinfo - ok
13:21:53.0254 5116 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:21:53.0254 5116 arc - ok
13:21:53.0317 5116 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:21:53.0317 5116 arcsas - ok
13:21:53.0379 5116 [ 5A055A4777CBBC8845DD598CB2EEBF69 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
13:21:53.0379 5116 ASLDRService - ok
13:21:53.0442 5116 [ 6F1505608202BBD179095A6A150D103F ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
13:21:53.0457 5116 aswMonFlt - ok
13:21:53.0488 5116 [ B269C41DF93EFF71DF0986BD982D1C46 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
13:21:53.0504 5116 aswRdr - ok
13:21:53.0520 5116 [ F385467DF95D0A73775CB3B076B8B969 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
13:21:53.0520 5116 aswRvrt - ok
13:21:53.0566 5116 [ 0F639D0526820BA7872C963813E0EB8D ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
13:21:53.0582 5116 aswSnx - ok
13:21:53.0613 5116 [ 7BA7543EA7936A7ADA615F6DE7C95494 ] aswSP C:\Windows\system32\drivers\aswSP.sys
13:21:53.0613 5116 aswSP - ok
13:21:53.0629 5116 [ 875D2B1054F2ECD8F575D6CBE78DD7BA ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
13:21:53.0629 5116 aswTdi - ok
13:21:53.0691 5116 [ 1B0662514A68C3A42E60D240C5ABEF28 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
13:21:53.0691 5116 aswVmm - ok
13:21:53.0738 5116 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:21:53.0738 5116 AsyncMac - ok
13:21:53.0785 5116 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
13:21:53.0785 5116 atapi - ok
13:21:53.0863 5116 [ 11A2F8D47E6208A6F68711AACDEDBD48 ] athr C:\Windows\system32\DRIVERS\athr.sys
13:21:53.0863 5116 athr - ok
13:21:53.0941 5116 [ B8D7C3CD847E4ACA2ECF9A69FCC52749 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
13:21:53.0956 5116 Ati External Event Utility - ok
13:21:54.0128 5116 [ E1696E95447C87DE1E37E854DB91028C ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:21:54.0175 5116 atikmdag - ok
13:21:54.0362 5116 [ 72BC628AF75C4C3250F2A3BAC260265A ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
13:21:54.0362 5116 atksgt - ok
13:21:54.0518 5116 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:21:54.0534 5116 AudioEndpointBuilder - ok
13:21:54.0549 5116 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:21:54.0549 5116 Audiosrv - ok
13:21:54.0643 5116 [ D74884939D53612FD84AC82C59CCFE27 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
13:21:54.0643 5116 avast! Antivirus - ok
13:21:54.0690 5116 [ 59629EDD214C35A01E2527AC3B8A7FB3 ] Axtmvflt C:\Windows\system32\DRIVERS\Axtmvflt.sys
13:21:54.0705 5116 Axtmvflt - ok
13:21:54.0721 5116 [ 37E23B1756ECA768656097F72C0B458D ] Axtmvmdm C:\Windows\system32\DRIVERS\Axtmvmdm.sys
13:21:54.0721 5116 Axtmvmdm - ok
13:21:54.0783 5116 [ 2C7170BE24EACC0B432EB1832FEE0DDC ] Axtmvprt C:\Windows\system32\Drivers\Axtmvprt.sys
13:21:54.0783 5116 Axtmvprt - ok
13:21:54.0846 5116 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:21:54.0846 5116 Beep - ok
13:21:54.0924 5116 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
13:21:54.0924 5116 BFE - ok
13:21:55.0017 5116 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
13:21:55.0033 5116 BITS - ok
13:21:55.0080 5116 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:21:55.0080 5116 blbdrive - ok
13:21:55.0095 5116 [ 74B442B2BE1260B7588C136177CEAC66 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:21:55.0095 5116 bowser - ok
13:21:55.0158 5116 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:21:55.0158 5116 BrFiltLo - ok
13:21:55.0173 5116 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:21:55.0173 5116 BrFiltUp - ok
13:21:55.0220 5116 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:21:55.0236 5116 Browser - ok
13:21:55.0251 5116 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:21:55.0267 5116 Brserid - ok
13:21:55.0267 5116 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:21:55.0267 5116 BrSerWdm - ok
13:21:55.0282 5116 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:21:55.0282 5116 BrUsbMdm - ok
13:21:55.0298 5116 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:21:55.0298 5116 BrUsbSer - ok
13:21:55.0360 5116 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
13:21:55.0360 5116 BthEnum - ok
13:21:55.0407 5116 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:21:55.0407 5116 BTHMODEM - ok
13:21:55.0423 5116 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:21:55.0423 5116 BthPan - ok
13:21:55.0501 5116 [ 5A3ABAA2F8EECE7AEFB942773766E3DB ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
13:21:55.0516 5116 BTHPORT - ok
13:21:55.0563 5116 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
13:21:55.0563 5116 BthServ - ok
13:21:55.0579 5116 [ 94E2941280E3756A5E0BCB467865C43A ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
13:21:55.0594 5116 BTHUSB - ok
13:21:55.0657 5116 [ 7E826BE3B3558208D5C9B00034E51BE5 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
13:21:55.0657 5116 btwaudio - ok
13:21:55.0750 5116 [ AF9148C3E844131AC954CB53FF43D971 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
13:21:55.0750 5116 btwavdt - ok
13:21:55.0860 5116 [ 0E3EE2BC0EC56BFE869FCDE3E5806684 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
13:21:55.0860 5116 btwdins - ok
13:21:55.0906 5116 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
13:21:55.0906 5116 btwl2cap - ok
13:21:55.0969 5116 [ 480B3D195854B2E55299CDDDDC50BCF9 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
13:21:55.0969 5116 btwrchid - ok
13:21:56.0016 5116 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:21:56.0016 5116 cdfs - ok
13:21:56.0078 5116 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:21:56.0078 5116 cdrom - ok
13:21:56.0140 5116 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
13:21:56.0140 5116 CertPropSvc - ok
13:21:56.0156 5116 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
13:21:56.0156 5116 circlass - ok
13:21:56.0187 5116 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
13:21:56.0187 5116 CLFS - ok
13:21:56.0296 5116 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:21:56.0296 5116 clr_optimization_v2.0.50727_32 - ok
13:21:56.0421 5116 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:21:56.0421 5116 clr_optimization_v4.0.30319_32 - ok
13:21:56.0499 5116 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:21:56.0499 5116 CmBatt - ok
13:21:56.0546 5116 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:21:56.0546 5116 cmdide - ok
13:21:56.0562 5116 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:21:56.0562 5116 Compbatt - ok
13:21:56.0577 5116 COMSysApp - ok
13:21:56.0593 5116 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:21:56.0593 5116 crcdisk - ok
13:21:56.0608 5116 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:21:56.0608 5116 Crusoe - ok
13:21:56.0686 5116 [ FB27772BEAF8E1D28CCD825C09DA939B ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:21:56.0702 5116 CryptSvc - ok
13:21:56.0780 5116 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:21:56.0796 5116 DcomLaunch - ok
13:21:56.0811 5116 [ 218D8AE46C88E82014F5D73D0236D9B2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:21:56.0811 5116 DfsC - ok
13:21:56.0920 5116 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
13:21:56.0952 5116 DFSR - ok
13:21:57.0030 5116 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:21:57.0030 5116 Dhcp - ok
13:21:57.0108 5116 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
13:21:57.0108 5116 disk - ok
13:21:57.0123 5116 [ 30A08728740E71947AE1E073B5CE69B4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:21:57.0123 5116 Dnscache - ok
13:21:57.0154 5116 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:21:57.0154 5116 dot3svc - ok
13:21:57.0201 5116 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:21:57.0217 5116 DPS - ok
13:21:57.0264 5116 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:21:57.0264 5116 drmkaud - ok
13:21:57.0310 5116 [ 5C7E2097B91D689DED7A6FF90F0F3A25 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:21:57.0310 5116 DXGKrnl - ok
13:21:57.0373 5116 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:21:57.0373 5116 E1G60 - ok
13:21:57.0435 5116 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:21:57.0451 5116 EapHost - ok
13:21:57.0513 5116 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:21:57.0513 5116 Ecache - ok
13:21:57.0607 5116 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:21:57.0607 5116 ehRecvr - ok
13:21:57.0622 5116 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:21:57.0622 5116 ehSched - ok
13:21:57.0654 5116 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:21:57.0654 5116 ehstart - ok
13:21:57.0716 5116 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:21:57.0716 5116 elxstor - ok
13:21:57.0778 5116 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:21:57.0810 5116 EMDMgmt - ok
13:21:57.0966 5116 [ A85679BC541F3530D5B06D0A4FAA1512 ] ergonomic_firebird C:\Program Files\Ergonomic Soft\Ergonomic Setup Center\firebird\bin\fbserver.exe
13:21:57.0997 5116 ergonomic_firebird - ok
13:21:58.0059 5116 [ A81AB23EDDB4693612014D87367D014C ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:21:58.0059 5116 ErrDev - ok
13:21:58.0137 5116 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
13:21:58.0153 5116 EventSystem - ok
13:21:58.0246 5116 [ 898AD7D508F6ADE242D94752E09F4152 ] EverestDriver C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt
13:21:58.0246 5116 EverestDriver - ok
13:21:58.0465 5116 [ 4B36D96340200512C7974307D0F7D8B3 ] ewusbnet C:\Windows\system32\DRIVERS\ewusbnet.sys
13:21:58.0465 5116 ewusbnet - ok
13:21:58.0574 5116 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
13:21:58.0574 5116 exfat - ok
13:21:58.0621 5116 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:21:58.0621 5116 fastfat - ok
13:21:58.0699 5116 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:21:58.0699 5116 fdc - ok
13:21:58.0761 5116 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:21:58.0777 5116 fdPHost - ok
13:21:58.0792 5116 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:21:58.0808 5116 FDResPub - ok
13:21:58.0886 5116 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:21:58.0886 5116 FileInfo - ok
13:21:58.0902 5116 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:21:58.0902 5116 Filetrace - ok
13:21:58.0980 5116 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:21:58.0980 5116 FLEXnet Licensing Service - ok
13:21:59.0026 5116 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:21:59.0026 5116 flpydisk - ok
13:21:59.0058 5116 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:21:59.0058 5116 FltMgr - ok
13:21:59.0214 5116 [ D96CCB0F24EF05B35DDA3727BAA5807F ] FontCache C:\Windows\system32\FntCache.dll
13:21:59.0307 5116 FontCache - ok
13:21:59.0557 5116 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:21:59.0557 5116 FontCache3.0.0.0 - ok
13:21:59.0635 5116 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:21:59.0635 5116 Fs_Rec - ok
13:21:59.0666 5116 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:21:59.0666 5116 gagp30kx - ok
13:21:59.0713 5116 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
13:21:59.0744 5116 gpsvc - ok
13:21:59.0822 5116 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
13:21:59.0822 5116 gupdate - ok
13:21:59.0853 5116 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
13:21:59.0853 5116 gupdatem - ok
13:21:59.0916 5116 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
13:21:59.0916 5116 gusvc - ok
13:21:59.0978 5116 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:21:59.0978 5116 HdAudAddService - ok
13:22:00.0040 5116 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:22:00.0056 5116 HDAudBus - ok
13:22:00.0072 5116 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:22:00.0072 5116 HidBth - ok
13:22:00.0087 5116 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
13:22:00.0087 5116 HidIr - ok
13:22:00.0134 5116 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
13:22:00.0150 5116 hidserv - ok
13:22:00.0165 5116 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:22:00.0165 5116 HidUsb - ok
13:22:00.0196 5116 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:22:00.0196 5116 hkmsvc - ok
13:22:00.0212 5116 [ 7EBEC5EB56B90ED65A8BBD91464E5CFB ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:22:00.0212 5116 HpCISSs - ok
13:22:00.0243 5116 [ ABBC72793F1C588B1A7DB0CAC69A4FE8 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:22:00.0243 5116 HTTP - ok
13:22:00.0321 5116 [ 1FC7A63148E4F2BD831DAB0DC732026D ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys
13:22:00.0321 5116 hwdatacard - ok
13:22:00.0368 5116 [ A259D3619AA23D4562581067F85E2006 ] hwusbdev C:\Windows\system32\DRIVERS\ewusbdev.sys
13:22:00.0384 5116 hwusbdev - ok
13:22:00.0430 5116 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:22:00.0430 5116 i2omp - ok
13:22:00.0493 5116 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:22:00.0493 5116 i8042prt - ok
13:22:00.0524 5116 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:22:00.0524 5116 iaStorV - ok
13:22:00.0602 5116 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:22:00.0618 5116 idsvc - ok
13:22:00.0633 5116 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:22:00.0633 5116 iirsp - ok
13:22:00.0696 5116 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
13:22:00.0711 5116 IKEEXT - ok
13:22:00.0930 5116 [ 0DBEF9CD5A2CD71240DD5AFCEE56D073 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:22:00.0976 5116 IntcAzAudAddService - ok
13:22:01.0023 5116 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:22:01.0023 5116 intelide - ok
13:22:01.0086 5116 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:22:01.0086 5116 intelppm - ok
13:22:01.0132 5116 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:22:01.0132 5116 IPBusEnum - ok
13:22:01.0148 5116 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:22:01.0148 5116 IpFilterDriver - ok
13:22:01.0179 5116 [ 7F83B06A929A981BC001B2EA304D2036 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:22:01.0179 5116 iphlpsvc - ok
13:22:01.0195 5116 IpInIp - ok
13:22:01.0210 5116 [ 4B9C0F4D4A3ACC535F9771039ECD6365 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:22:01.0210 5116 IPMIDRV - ok
13:22:01.0242 5116 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:22:01.0242 5116 IPNAT - ok
13:22:01.0257 5116 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:22:01.0257 5116 IRENUM - ok
13:22:01.0273 5116 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:22:01.0273 5116 isapnp - ok
13:22:01.0335 5116 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:22:01.0335 5116 iScsiPrt - ok
13:22:01.0366 5116 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:22:01.0366 5116 iteatapi - ok
13:22:01.0382 5116 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:22:01.0382 5116 iteraid - ok
13:22:01.0398 5116 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:22:01.0398 5116 kbdclass - ok
13:22:01.0429 5116 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:22:01.0429 5116 kbdhid - ok
13:22:01.0476 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] KeyIso C:\Windows\system32\lsass.exe
13:22:01.0476 5116 KeyIso - ok
13:22:01.0507 5116 [ EA7F1D605518486269F45BD80FA00907 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:22:01.0522 5116 KSecDD - ok
13:22:01.0569 5116 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:22:01.0585 5116 KtmRm - ok
13:22:01.0632 5116 [ 43446F197C74EF2030F84B3A4F39D570 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:22:01.0632 5116 LanmanServer - ok
13:22:01.0647 5116 [ DEC1A338B86C5D582C25C40836DD76C3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:22:01.0663 5116 LanmanWorkstation - ok
13:22:01.0741 5116 [ 4127E8B6DDB4090E815C1F8852C277D3 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
13:22:01.0741 5116 lirsgt - ok
13:22:01.0756 5116 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:22:01.0756 5116 lltdio - ok
13:22:01.0819 5116 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:22:01.0819 5116 lltdsvc - ok
13:22:01.0834 5116 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:22:01.0850 5116 lmhosts - ok
13:22:01.0897 5116 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:22:01.0897 5116 LSI_FC - ok
13:22:01.0912 5116 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:22:01.0928 5116 LSI_SAS - ok
13:22:01.0944 5116 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:22:01.0944 5116 LSI_SCSI - ok
13:22:01.0959 5116 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:22:01.0975 5116 luafv - ok
13:22:02.0037 5116 [ A3E700D78EEC390F1208098CDCA5C6B6 ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus.sys
13:22:02.0037 5116 MarvinBus - ok
13:22:02.0068 5116 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:22:02.0068 5116 MBAMProtector - ok
13:22:02.0162 5116 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
13:22:02.0178 5116 MBAMScheduler - ok
13:22:02.0209 5116 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
13:22:02.0224 5116 MBAMService - ok
13:22:02.0302 5116 [ D77A5C1FEE2F46170F52FC13F9C8F0E9 ] MbnExt C:\Program Files\T-Mobile\T-Mobile Internet Manager\MbnExt.dll
13:22:02.0302 5116 MbnExt - ok
13:22:02.0349 5116 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:22:02.0365 5116 Mcx2Svc - ok
13:22:02.0412 5116 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:22:02.0412 5116 megasas - ok
13:22:02.0490 5116 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:22:02.0490 5116 MegaSR - ok
13:22:02.0536 5116 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:22:02.0552 5116 MMCSS - ok
13:22:02.0568 5116 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:22:02.0568 5116 Modem - ok
13:22:02.0630 5116 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:22:02.0630 5116 monitor - ok
13:22:02.0661 5116 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:22:02.0661 5116 mouclass - ok
13:22:02.0677 5116 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:22:02.0677 5116 mouhid - ok
13:22:02.0708 5116 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:22:02.0708 5116 MountMgr - ok
13:22:02.0786 5116 [ 96AA8BA23142CC8E2B30F3CAE0C80254 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:22:02.0802 5116 MozillaMaintenance - ok
13:22:02.0817 5116 [ 5DA347912FD3AF24D7BFB3DE519D4BD0 ] mpio C:\Windows\system32\drivers\mpio.sys
13:22:02.0817 5116 mpio - ok
13:22:02.0833 5116 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:22:02.0833 5116 mpsdrv - ok
13:22:02.0895 5116 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
13:22:02.0911 5116 MpsSvc - ok
13:22:02.0926 5116 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:22:02.0926 5116 Mraid35x - ok
13:22:02.0958 5116 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:22:02.0958 5116 MRxDAV - ok
13:22:02.0973 5116 [ 317EB668973951BAD512EE8BEBF9ED25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:22:02.0973 5116 mrxsmb - ok
13:22:03.0004 5116 [ 05716F0203B5C774A87384A1FF7B968F ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:22:03.0004 5116 mrxsmb10 - ok
13:22:03.0020 5116 [ C70C50D101B92B45C42BA11EA9FE6CD1 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:22:03.0020 5116 mrxsmb20 - ok
13:22:03.0067 5116 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
13:22:03.0067 5116 msahci - ok
13:22:03.0082 5116 [ 2C563AEF15B8D0014C36C5F27742AC7B ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:22:03.0098 5116 msdsm - ok
13:22:03.0145 5116 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:22:03.0145 5116 MSDTC - ok
13:22:03.0207 5116 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:22:03.0207 5116 Msfs - ok
13:22:03.0254 5116 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:22:03.0254 5116 msisadrv - ok
13:22:03.0316 5116 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:22:03.0316 5116 MSiSCSI - ok
13:22:03.0332 5116 msiserver - ok
13:22:03.0379 5116 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:22:03.0379 5116 MSKSSRV - ok
13:22:03.0394 5116 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:22:03.0394 5116 MSPCLOCK - ok
13:22:03.0410 5116 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:22:03.0410 5116 MSPQM - ok
13:22:03.0441 5116 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:22:03.0441 5116 MsRPC - ok
13:22:03.0472 5116 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:22:03.0472 5116 mssmbios - ok
13:22:03.0488 5116 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:22:03.0488 5116 MSTEE - ok
13:22:03.0535 5116 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
13:22:03.0535 5116 MTsensor - ok
13:22:03.0550 5116 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
13:22:03.0550 5116 Mup - ok
13:22:03.0613 5116 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
13:22:03.0644 5116 napagent - ok
13:22:03.0691 5116 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:22:03.0706 5116 NativeWifiP - ok
13:22:03.0753 5116 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:22:03.0769 5116 NDIS - ok
13:22:03.0784 5116 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:22:03.0784 5116 NdisTapi - ok
13:22:03.0800 5116 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:22:03.0800 5116 Ndisuio - ok
13:22:03.0831 5116 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:22:03.0831 5116 NdisWan - ok
13:22:03.0847 5116 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:22:03.0847 5116 NDProxy - ok
13:22:03.0878 5116 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:22:03.0878 5116 NetBIOS - ok
13:22:03.0894 5116 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:22:03.0894 5116 netbt - ok
13:22:03.0925 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] Netlogon C:\Windows\system32\lsass.exe
13:22:03.0925 5116 Netlogon - ok
13:22:03.0972 5116 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:22:04.0003 5116 Netman - ok
13:22:04.0018 5116 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:22:04.0034 5116 netprofm - ok
13:22:04.0081 5116 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:21:45.0907 5044 ============================================================
13:21:45.0907 5044 Current date / time: 2014/03/30 13:21:45.0907
13:21:45.0907 5044 SystemInfo:
13:21:45.0907 5044
13:21:45.0907 5044 OS Version: 6.0.6002 ServicePack: 2.0
13:21:45.0907 5044 Product type: Workstation
13:21:45.0907 5044 ComputerName: PC
13:21:45.0907 5044 UserName: DiTečka
13:21:45.0907 5044 Windows directory: C:\Windows
13:21:45.0907 5044 System windows directory: C:\Windows
13:21:45.0907 5044 Processor architecture: Intel x86
13:21:45.0907 5044 Number of processors: 2
13:21:45.0907 5044 Page size: 0x1000
13:21:45.0907 5044 Boot type: Normal boot
13:21:45.0907 5044 ============================================================
13:21:47.0202 5044 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:21:47.0202 5044 Drive \Device\Harddisk1\DR1 - Size: 0x774488000 (29.82 Gb), SectorSize: 0x200, Cylinders: 0xF34, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:21:47.0202 5044 ============================================================
13:21:47.0202 5044 \Device\Harddisk0\DR0:
13:21:47.0202 5044 MBR partitions:
13:21:47.0202 5044 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1770000
13:21:47.0202 5044 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1770D7A, BlocksNum 0x1D1C06C0
13:21:47.0233 5044 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1E931479, BlocksNum 0x1BA537C8
13:21:47.0233 5044 \Device\Harddisk1\DR1:
13:21:47.0233 5044 MBR partitions:
13:21:47.0233 5044 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x3BA2420
13:21:47.0233 5044 ============================================================
13:21:47.0280 5044 C: <-> \Device\Harddisk0\DR0\Partition2
13:21:47.0326 5044 D: <-> \Device\Harddisk0\DR0\Partition3
13:21:47.0373 5044 I: <-> \Device\Harddisk0\DR0\Partition1
13:21:47.0373 5044 ============================================================
13:21:47.0373 5044 Initialize success
13:21:47.0373 5044 ============================================================
13:21:50.0556 5116 ============================================================
13:21:50.0556 5116 Scan started
13:21:50.0556 5116 Mode: Manual;
13:21:50.0556 5116 ============================================================
13:21:52.0147 5116 ================ Scan system memory ========================
13:21:52.0147 5116 System memory - ok
13:21:52.0147 5116 ================ Scan services =============================
13:21:52.0350 5116 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:21:52.0350 5116 ACPI - ok
13:21:52.0521 5116 [ 1474F121C3DF1232D3E7239C03691EE6 ] AdobeActiveFileMonitor9.0 C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
13:21:52.0521 5116 AdobeActiveFileMonitor9.0 - ok
13:21:52.0630 5116 [ 9D96B0D5855FD1B98023B3EEC9F06786 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:21:52.0630 5116 AdobeFlashPlayerUpdateSvc - ok
13:21:52.0724 5116 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:21:52.0724 5116 adp94xx - ok
13:21:52.0755 5116 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:21:52.0755 5116 adpahci - ok
13:21:52.0786 5116 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:21:52.0786 5116 adpu160m - ok
13:21:52.0802 5116 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:21:52.0802 5116 adpu320 - ok
13:21:52.0864 5116 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:21:52.0864 5116 AeLookupSvc - ok
13:21:52.0927 5116 [ A201207363AA900ABF1A388468688570 ] AFD C:\Windows\system32\drivers\afd.sys
13:21:52.0927 5116 AFD - ok
13:21:52.0974 5116 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:21:52.0989 5116 agp440 - ok
13:21:53.0005 5116 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:21:53.0005 5116 aic78xx - ok
13:21:53.0020 5116 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:21:53.0020 5116 ALG - ok
13:21:53.0036 5116 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:21:53.0036 5116 aliide - ok
13:21:53.0083 5116 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:21:53.0083 5116 amdagp - ok
13:21:53.0098 5116 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:21:53.0098 5116 amdide - ok
13:21:53.0114 5116 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:21:53.0114 5116 AmdK7 - ok
13:21:53.0145 5116 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:21:53.0145 5116 AmdK8 - ok
13:21:53.0208 5116 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:21:53.0208 5116 Appinfo - ok
13:21:53.0254 5116 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:21:53.0254 5116 arc - ok
13:21:53.0317 5116 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:21:53.0317 5116 arcsas - ok
13:21:53.0379 5116 [ 5A055A4777CBBC8845DD598CB2EEBF69 ] ASLDRService C:\Program Files\ATK Hotkey\ASLDRSrv.exe
13:21:53.0379 5116 ASLDRService - ok
13:21:53.0442 5116 [ 6F1505608202BBD179095A6A150D103F ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
13:21:53.0457 5116 aswMonFlt - ok
13:21:53.0488 5116 [ B269C41DF93EFF71DF0986BD982D1C46 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
13:21:53.0504 5116 aswRdr - ok
13:21:53.0520 5116 [ F385467DF95D0A73775CB3B076B8B969 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
13:21:53.0520 5116 aswRvrt - ok
13:21:53.0566 5116 [ 0F639D0526820BA7872C963813E0EB8D ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
13:21:53.0582 5116 aswSnx - ok
13:21:53.0613 5116 [ 7BA7543EA7936A7ADA615F6DE7C95494 ] aswSP C:\Windows\system32\drivers\aswSP.sys
13:21:53.0613 5116 aswSP - ok
13:21:53.0629 5116 [ 875D2B1054F2ECD8F575D6CBE78DD7BA ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
13:21:53.0629 5116 aswTdi - ok
13:21:53.0691 5116 [ 1B0662514A68C3A42E60D240C5ABEF28 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
13:21:53.0691 5116 aswVmm - ok
13:21:53.0738 5116 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:21:53.0738 5116 AsyncMac - ok
13:21:53.0785 5116 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
13:21:53.0785 5116 atapi - ok
13:21:53.0863 5116 [ 11A2F8D47E6208A6F68711AACDEDBD48 ] athr C:\Windows\system32\DRIVERS\athr.sys
13:21:53.0863 5116 athr - ok
13:21:53.0941 5116 [ B8D7C3CD847E4ACA2ECF9A69FCC52749 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
13:21:53.0956 5116 Ati External Event Utility - ok
13:21:54.0128 5116 [ E1696E95447C87DE1E37E854DB91028C ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
13:21:54.0175 5116 atikmdag - ok
13:21:54.0362 5116 [ 72BC628AF75C4C3250F2A3BAC260265A ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
13:21:54.0362 5116 atksgt - ok
13:21:54.0518 5116 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:21:54.0534 5116 AudioEndpointBuilder - ok
13:21:54.0549 5116 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:21:54.0549 5116 Audiosrv - ok
13:21:54.0643 5116 [ D74884939D53612FD84AC82C59CCFE27 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
13:21:54.0643 5116 avast! Antivirus - ok
13:21:54.0690 5116 [ 59629EDD214C35A01E2527AC3B8A7FB3 ] Axtmvflt C:\Windows\system32\DRIVERS\Axtmvflt.sys
13:21:54.0705 5116 Axtmvflt - ok
13:21:54.0721 5116 [ 37E23B1756ECA768656097F72C0B458D ] Axtmvmdm C:\Windows\system32\DRIVERS\Axtmvmdm.sys
13:21:54.0721 5116 Axtmvmdm - ok
13:21:54.0783 5116 [ 2C7170BE24EACC0B432EB1832FEE0DDC ] Axtmvprt C:\Windows\system32\Drivers\Axtmvprt.sys
13:21:54.0783 5116 Axtmvprt - ok
13:21:54.0846 5116 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:21:54.0846 5116 Beep - ok
13:21:54.0924 5116 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
13:21:54.0924 5116 BFE - ok
13:21:55.0017 5116 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
13:21:55.0033 5116 BITS - ok
13:21:55.0080 5116 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:21:55.0080 5116 blbdrive - ok
13:21:55.0095 5116 [ 74B442B2BE1260B7588C136177CEAC66 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:21:55.0095 5116 bowser - ok
13:21:55.0158 5116 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:21:55.0158 5116 BrFiltLo - ok
13:21:55.0173 5116 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:21:55.0173 5116 BrFiltUp - ok
13:21:55.0220 5116 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:21:55.0236 5116 Browser - ok
13:21:55.0251 5116 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:21:55.0267 5116 Brserid - ok
13:21:55.0267 5116 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:21:55.0267 5116 BrSerWdm - ok
13:21:55.0282 5116 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:21:55.0282 5116 BrUsbMdm - ok
13:21:55.0298 5116 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:21:55.0298 5116 BrUsbSer - ok
13:21:55.0360 5116 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
13:21:55.0360 5116 BthEnum - ok
13:21:55.0407 5116 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:21:55.0407 5116 BTHMODEM - ok
13:21:55.0423 5116 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:21:55.0423 5116 BthPan - ok
13:21:55.0501 5116 [ 5A3ABAA2F8EECE7AEFB942773766E3DB ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
13:21:55.0516 5116 BTHPORT - ok
13:21:55.0563 5116 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
13:21:55.0563 5116 BthServ - ok
13:21:55.0579 5116 [ 94E2941280E3756A5E0BCB467865C43A ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
13:21:55.0594 5116 BTHUSB - ok
13:21:55.0657 5116 [ 7E826BE3B3558208D5C9B00034E51BE5 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
13:21:55.0657 5116 btwaudio - ok
13:21:55.0750 5116 [ AF9148C3E844131AC954CB53FF43D971 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
13:21:55.0750 5116 btwavdt - ok
13:21:55.0860 5116 [ 0E3EE2BC0EC56BFE869FCDE3E5806684 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
13:21:55.0860 5116 btwdins - ok
13:21:55.0906 5116 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
13:21:55.0906 5116 btwl2cap - ok
13:21:55.0969 5116 [ 480B3D195854B2E55299CDDDDC50BCF9 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
13:21:55.0969 5116 btwrchid - ok
13:21:56.0016 5116 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:21:56.0016 5116 cdfs - ok
13:21:56.0078 5116 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:21:56.0078 5116 cdrom - ok
13:21:56.0140 5116 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
13:21:56.0140 5116 CertPropSvc - ok
13:21:56.0156 5116 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
13:21:56.0156 5116 circlass - ok
13:21:56.0187 5116 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
13:21:56.0187 5116 CLFS - ok
13:21:56.0296 5116 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:21:56.0296 5116 clr_optimization_v2.0.50727_32 - ok
13:21:56.0421 5116 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:21:56.0421 5116 clr_optimization_v4.0.30319_32 - ok
13:21:56.0499 5116 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:21:56.0499 5116 CmBatt - ok
13:21:56.0546 5116 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:21:56.0546 5116 cmdide - ok
13:21:56.0562 5116 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:21:56.0562 5116 Compbatt - ok
13:21:56.0577 5116 COMSysApp - ok
13:21:56.0593 5116 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:21:56.0593 5116 crcdisk - ok
13:21:56.0608 5116 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:21:56.0608 5116 Crusoe - ok
13:21:56.0686 5116 [ FB27772BEAF8E1D28CCD825C09DA939B ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:21:56.0702 5116 CryptSvc - ok
13:21:56.0780 5116 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:21:56.0796 5116 DcomLaunch - ok
13:21:56.0811 5116 [ 218D8AE46C88E82014F5D73D0236D9B2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:21:56.0811 5116 DfsC - ok
13:21:56.0920 5116 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
13:21:56.0952 5116 DFSR - ok
13:21:57.0030 5116 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:21:57.0030 5116 Dhcp - ok
13:21:57.0108 5116 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
13:21:57.0108 5116 disk - ok
13:21:57.0123 5116 [ 30A08728740E71947AE1E073B5CE69B4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:21:57.0123 5116 Dnscache - ok
13:21:57.0154 5116 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:21:57.0154 5116 dot3svc - ok
13:21:57.0201 5116 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:21:57.0217 5116 DPS - ok
13:21:57.0264 5116 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:21:57.0264 5116 drmkaud - ok
13:21:57.0310 5116 [ 5C7E2097B91D689DED7A6FF90F0F3A25 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:21:57.0310 5116 DXGKrnl - ok
13:21:57.0373 5116 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:21:57.0373 5116 E1G60 - ok
13:21:57.0435 5116 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:21:57.0451 5116 EapHost - ok
13:21:57.0513 5116 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:21:57.0513 5116 Ecache - ok
13:21:57.0607 5116 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:21:57.0607 5116 ehRecvr - ok
13:21:57.0622 5116 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:21:57.0622 5116 ehSched - ok
13:21:57.0654 5116 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:21:57.0654 5116 ehstart - ok
13:21:57.0716 5116 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:21:57.0716 5116 elxstor - ok
13:21:57.0778 5116 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:21:57.0810 5116 EMDMgmt - ok
13:21:57.0966 5116 [ A85679BC541F3530D5B06D0A4FAA1512 ] ergonomic_firebird C:\Program Files\Ergonomic Soft\Ergonomic Setup Center\firebird\bin\fbserver.exe
13:21:57.0997 5116 ergonomic_firebird - ok
13:21:58.0059 5116 [ A81AB23EDDB4693612014D87367D014C ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:21:58.0059 5116 ErrDev - ok
13:21:58.0137 5116 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
13:21:58.0153 5116 EventSystem - ok
13:21:58.0246 5116 [ 898AD7D508F6ADE242D94752E09F4152 ] EverestDriver C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt
13:21:58.0246 5116 EverestDriver - ok
13:21:58.0465 5116 [ 4B36D96340200512C7974307D0F7D8B3 ] ewusbnet C:\Windows\system32\DRIVERS\ewusbnet.sys
13:21:58.0465 5116 ewusbnet - ok
13:21:58.0574 5116 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
13:21:58.0574 5116 exfat - ok
13:21:58.0621 5116 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:21:58.0621 5116 fastfat - ok
13:21:58.0699 5116 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:21:58.0699 5116 fdc - ok
13:21:58.0761 5116 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:21:58.0777 5116 fdPHost - ok
13:21:58.0792 5116 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:21:58.0808 5116 FDResPub - ok
13:21:58.0886 5116 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:21:58.0886 5116 FileInfo - ok
13:21:58.0902 5116 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:21:58.0902 5116 Filetrace - ok
13:21:58.0980 5116 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:21:58.0980 5116 FLEXnet Licensing Service - ok
13:21:59.0026 5116 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:21:59.0026 5116 flpydisk - ok
13:21:59.0058 5116 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:21:59.0058 5116 FltMgr - ok
13:21:59.0214 5116 [ D96CCB0F24EF05B35DDA3727BAA5807F ] FontCache C:\Windows\system32\FntCache.dll
13:21:59.0307 5116 FontCache - ok
13:21:59.0557 5116 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:21:59.0557 5116 FontCache3.0.0.0 - ok
13:21:59.0635 5116 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:21:59.0635 5116 Fs_Rec - ok
13:21:59.0666 5116 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:21:59.0666 5116 gagp30kx - ok
13:21:59.0713 5116 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
13:21:59.0744 5116 gpsvc - ok
13:21:59.0822 5116 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
13:21:59.0822 5116 gupdate - ok
13:21:59.0853 5116 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
13:21:59.0853 5116 gupdatem - ok
13:21:59.0916 5116 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
13:21:59.0916 5116 gusvc - ok
13:21:59.0978 5116 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:21:59.0978 5116 HdAudAddService - ok
13:22:00.0040 5116 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:22:00.0056 5116 HDAudBus - ok
13:22:00.0072 5116 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:22:00.0072 5116 HidBth - ok
13:22:00.0087 5116 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
13:22:00.0087 5116 HidIr - ok
13:22:00.0134 5116 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
13:22:00.0150 5116 hidserv - ok
13:22:00.0165 5116 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:22:00.0165 5116 HidUsb - ok
13:22:00.0196 5116 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:22:00.0196 5116 hkmsvc - ok
13:22:00.0212 5116 [ 7EBEC5EB56B90ED65A8BBD91464E5CFB ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:22:00.0212 5116 HpCISSs - ok
13:22:00.0243 5116 [ ABBC72793F1C588B1A7DB0CAC69A4FE8 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:22:00.0243 5116 HTTP - ok
13:22:00.0321 5116 [ 1FC7A63148E4F2BD831DAB0DC732026D ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys
13:22:00.0321 5116 hwdatacard - ok
13:22:00.0368 5116 [ A259D3619AA23D4562581067F85E2006 ] hwusbdev C:\Windows\system32\DRIVERS\ewusbdev.sys
13:22:00.0384 5116 hwusbdev - ok
13:22:00.0430 5116 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:22:00.0430 5116 i2omp - ok
13:22:00.0493 5116 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:22:00.0493 5116 i8042prt - ok
13:22:00.0524 5116 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:22:00.0524 5116 iaStorV - ok
13:22:00.0602 5116 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:22:00.0618 5116 idsvc - ok
13:22:00.0633 5116 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:22:00.0633 5116 iirsp - ok
13:22:00.0696 5116 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
13:22:00.0711 5116 IKEEXT - ok
13:22:00.0930 5116 [ 0DBEF9CD5A2CD71240DD5AFCEE56D073 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:22:00.0976 5116 IntcAzAudAddService - ok
13:22:01.0023 5116 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:22:01.0023 5116 intelide - ok
13:22:01.0086 5116 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:22:01.0086 5116 intelppm - ok
13:22:01.0132 5116 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:22:01.0132 5116 IPBusEnum - ok
13:22:01.0148 5116 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:22:01.0148 5116 IpFilterDriver - ok
13:22:01.0179 5116 [ 7F83B06A929A981BC001B2EA304D2036 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:22:01.0179 5116 iphlpsvc - ok
13:22:01.0195 5116 IpInIp - ok
13:22:01.0210 5116 [ 4B9C0F4D4A3ACC535F9771039ECD6365 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:22:01.0210 5116 IPMIDRV - ok
13:22:01.0242 5116 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:22:01.0242 5116 IPNAT - ok
13:22:01.0257 5116 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:22:01.0257 5116 IRENUM - ok
13:22:01.0273 5116 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:22:01.0273 5116 isapnp - ok
13:22:01.0335 5116 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:22:01.0335 5116 iScsiPrt - ok
13:22:01.0366 5116 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:22:01.0366 5116 iteatapi - ok
13:22:01.0382 5116 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:22:01.0382 5116 iteraid - ok
13:22:01.0398 5116 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:22:01.0398 5116 kbdclass - ok
13:22:01.0429 5116 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:22:01.0429 5116 kbdhid - ok
13:22:01.0476 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] KeyIso C:\Windows\system32\lsass.exe
13:22:01.0476 5116 KeyIso - ok
13:22:01.0507 5116 [ EA7F1D605518486269F45BD80FA00907 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:22:01.0522 5116 KSecDD - ok
13:22:01.0569 5116 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:22:01.0585 5116 KtmRm - ok
13:22:01.0632 5116 [ 43446F197C74EF2030F84B3A4F39D570 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:22:01.0632 5116 LanmanServer - ok
13:22:01.0647 5116 [ DEC1A338B86C5D582C25C40836DD76C3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:22:01.0663 5116 LanmanWorkstation - ok
13:22:01.0741 5116 [ 4127E8B6DDB4090E815C1F8852C277D3 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
13:22:01.0741 5116 lirsgt - ok
13:22:01.0756 5116 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:22:01.0756 5116 lltdio - ok
13:22:01.0819 5116 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:22:01.0819 5116 lltdsvc - ok
13:22:01.0834 5116 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:22:01.0850 5116 lmhosts - ok
13:22:01.0897 5116 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:22:01.0897 5116 LSI_FC - ok
13:22:01.0912 5116 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:22:01.0928 5116 LSI_SAS - ok
13:22:01.0944 5116 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:22:01.0944 5116 LSI_SCSI - ok
13:22:01.0959 5116 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:22:01.0975 5116 luafv - ok
13:22:02.0037 5116 [ A3E700D78EEC390F1208098CDCA5C6B6 ] MarvinBus C:\Windows\system32\DRIVERS\MarvinBus.sys
13:22:02.0037 5116 MarvinBus - ok
13:22:02.0068 5116 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:22:02.0068 5116 MBAMProtector - ok
13:22:02.0162 5116 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
13:22:02.0178 5116 MBAMScheduler - ok
13:22:02.0209 5116 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
13:22:02.0224 5116 MBAMService - ok
13:22:02.0302 5116 [ D77A5C1FEE2F46170F52FC13F9C8F0E9 ] MbnExt C:\Program Files\T-Mobile\T-Mobile Internet Manager\MbnExt.dll
13:22:02.0302 5116 MbnExt - ok
13:22:02.0349 5116 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:22:02.0365 5116 Mcx2Svc - ok
13:22:02.0412 5116 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:22:02.0412 5116 megasas - ok
13:22:02.0490 5116 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:22:02.0490 5116 MegaSR - ok
13:22:02.0536 5116 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:22:02.0552 5116 MMCSS - ok
13:22:02.0568 5116 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:22:02.0568 5116 Modem - ok
13:22:02.0630 5116 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:22:02.0630 5116 monitor - ok
13:22:02.0661 5116 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:22:02.0661 5116 mouclass - ok
13:22:02.0677 5116 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:22:02.0677 5116 mouhid - ok
13:22:02.0708 5116 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:22:02.0708 5116 MountMgr - ok
13:22:02.0786 5116 [ 96AA8BA23142CC8E2B30F3CAE0C80254 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:22:02.0802 5116 MozillaMaintenance - ok
13:22:02.0817 5116 [ 5DA347912FD3AF24D7BFB3DE519D4BD0 ] mpio C:\Windows\system32\drivers\mpio.sys
13:22:02.0817 5116 mpio - ok
13:22:02.0833 5116 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:22:02.0833 5116 mpsdrv - ok
13:22:02.0895 5116 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
13:22:02.0911 5116 MpsSvc - ok
13:22:02.0926 5116 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:22:02.0926 5116 Mraid35x - ok
13:22:02.0958 5116 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:22:02.0958 5116 MRxDAV - ok
13:22:02.0973 5116 [ 317EB668973951BAD512EE8BEBF9ED25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:22:02.0973 5116 mrxsmb - ok
13:22:03.0004 5116 [ 05716F0203B5C774A87384A1FF7B968F ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:22:03.0004 5116 mrxsmb10 - ok
13:22:03.0020 5116 [ C70C50D101B92B45C42BA11EA9FE6CD1 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:22:03.0020 5116 mrxsmb20 - ok
13:22:03.0067 5116 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
13:22:03.0067 5116 msahci - ok
13:22:03.0082 5116 [ 2C563AEF15B8D0014C36C5F27742AC7B ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:22:03.0098 5116 msdsm - ok
13:22:03.0145 5116 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:22:03.0145 5116 MSDTC - ok
13:22:03.0207 5116 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:22:03.0207 5116 Msfs - ok
13:22:03.0254 5116 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:22:03.0254 5116 msisadrv - ok
13:22:03.0316 5116 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:22:03.0316 5116 MSiSCSI - ok
13:22:03.0332 5116 msiserver - ok
13:22:03.0379 5116 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:22:03.0379 5116 MSKSSRV - ok
13:22:03.0394 5116 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:22:03.0394 5116 MSPCLOCK - ok
13:22:03.0410 5116 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:22:03.0410 5116 MSPQM - ok
13:22:03.0441 5116 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:22:03.0441 5116 MsRPC - ok
13:22:03.0472 5116 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:22:03.0472 5116 mssmbios - ok
13:22:03.0488 5116 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:22:03.0488 5116 MSTEE - ok
13:22:03.0535 5116 [ 97AFFA9D95FFE20EEE6229BC6BE166CF ] MTsensor C:\Windows\system32\DRIVERS\ATKACPI.sys
13:22:03.0535 5116 MTsensor - ok
13:22:03.0550 5116 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
13:22:03.0550 5116 Mup - ok
13:22:03.0613 5116 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
13:22:03.0644 5116 napagent - ok
13:22:03.0691 5116 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:22:03.0706 5116 NativeWifiP - ok
13:22:03.0753 5116 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:22:03.0769 5116 NDIS - ok
13:22:03.0784 5116 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:22:03.0784 5116 NdisTapi - ok
13:22:03.0800 5116 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:22:03.0800 5116 Ndisuio - ok
13:22:03.0831 5116 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:22:03.0831 5116 NdisWan - ok
13:22:03.0847 5116 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:22:03.0847 5116 NDProxy - ok
13:22:03.0878 5116 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:22:03.0878 5116 NetBIOS - ok
13:22:03.0894 5116 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:22:03.0894 5116 netbt - ok
13:22:03.0925 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] Netlogon C:\Windows\system32\lsass.exe
13:22:03.0925 5116 Netlogon - ok
13:22:03.0972 5116 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:22:04.0003 5116 Netman - ok
13:22:04.0018 5116 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:22:04.0034 5116 netprofm - ok
13:22:04.0081 5116 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
13:22:04.0081 5116 NetTcpPortSharing - ok
13:22:04.0128 5116 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:22:04.0143 5116 nfrd960 - ok
13:22:04.0159 5116 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:22:04.0159 5116 NlaSvc - ok
13:22:04.0252 5116 [ B1EF4686961986DFFB7FE8F18E6FCB5B ] nlsX86cc C:\Windows\system32\nlssrv32.exe
13:22:04.0252 5116 nlsX86cc - ok
13:22:04.0315 5116 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
13:22:04.0315 5116 nmwcd - ok
13:22:04.0377 5116 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
13:22:04.0377 5116 nmwcdc - ok
13:22:04.0424 5116 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:22:04.0424 5116 Npfs - ok
13:22:04.0471 5116 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:22:04.0486 5116 nsi - ok
13:22:04.0486 5116 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:22:04.0486 5116 nsiproxy - ok
13:22:04.0564 5116 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:22:04.0580 5116 Ntfs - ok
13:22:04.0596 5116 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:22:04.0596 5116 ntrigdigi - ok
13:22:04.0627 5116 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:22:04.0627 5116 Null - ok
13:22:04.0658 5116 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:22:04.0658 5116 nvraid - ok
13:22:04.0720 5116 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:22:04.0720 5116 nvstor - ok
13:22:04.0752 5116 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:22:04.0752 5116 nv_agp - ok
13:22:04.0767 5116 NwlnkFlt - ok
13:22:04.0767 5116 NwlnkFwd - ok
13:22:04.0830 5116 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:22:04.0830 5116 ohci1394 - ok
13:22:04.0892 5116 [ F4CB9C1991314B1352DDBD8A968E4471 ] OlyCamComm C:\Windows\system32\DRIVERS\OlyCamComm.sys
13:22:04.0892 5116 OlyCamComm - ok
13:22:04.0954 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:22:04.0970 5116 p2pimsvc - ok
13:22:05.0001 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
13:22:05.0017 5116 p2psvc - ok
13:22:05.0079 5116 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:22:05.0079 5116 Parport - ok
13:22:05.0126 5116 [ 57389FA59A36D96B3EB09D0CB91E9CDC ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:22:05.0126 5116 partmgr - ok
13:22:05.0142 5116 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:22:05.0142 5116 Parvdm - ok
13:22:05.0173 5116 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:22:05.0173 5116 PcaSvc - ok
13:22:05.0220 5116 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
13:22:05.0220 5116 pccsmcfd - ok
13:22:05.0251 5116 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
13:22:05.0251 5116 pci - ok
13:22:05.0298 5116 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
13:22:05.0298 5116 pciide - ok
13:22:05.0313 5116 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:22:05.0313 5116 pcmcia - ok
13:22:05.0376 5116 [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
13:22:05.0391 5116 pcouffin - ok
13:22:05.0454 5116 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:22:05.0469 5116 PEAUTH - ok
13:22:05.0578 5116 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:22:05.0641 5116 pla - ok
13:22:05.0688 5116 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:22:05.0703 5116 PlugPlay - ok
13:22:05.0734 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:22:05.0750 5116 PNRPAutoReg - ok
13:22:05.0781 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:22:05.0797 5116 PNRPsvc - ok
13:22:05.0844 5116 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:22:05.0875 5116 PolicyAgent - ok
13:22:05.0922 5116 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:22:05.0937 5116 PptpMiniport - ok
13:22:05.0953 5116 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
13:22:05.0953 5116 Processor - ok
13:22:06.0000 5116 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
13:22:06.0015 5116 ProfSvc - ok
13:22:06.0031 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] ProtectedStorage C:\Windows\system32\lsass.exe
13:22:06.0031 5116 ProtectedStorage - ok
13:22:06.0046 5116 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:22:06.0062 5116 PSched - ok
13:22:06.0124 5116 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
13:22:06.0124 5116 PxHelp20 - ok
13:22:06.0218 5116 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:22:06.0234 5116 ql2300 - ok
13:22:06.0249 5116 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:22:06.0249 5116 ql40xx - ok
13:22:06.0312 5116 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:22:06.0327 5116 QWAVE - ok
13:22:06.0343 5116 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:22:06.0343 5116 QWAVEdrv - ok
13:22:06.0358 5116 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:22:06.0358 5116 RasAcd - ok
13:22:06.0390 5116 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:22:06.0405 5116 RasAuto - ok
13:22:06.0421 5116 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:22:06.0421 5116 Rasl2tp - ok
13:22:06.0436 5116 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
13:22:06.0468 5116 RasMan - ok
13:22:06.0483 5116 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:22:06.0483 5116 RasPppoe - ok
13:22:06.0546 5116 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:22:06.0546 5116 RasSstp - ok
13:22:06.0561 5116 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:22:06.0577 5116 rdbss - ok
13:22:06.0577 5116 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:22:06.0592 5116 RDPCDD - ok
13:22:06.0608 5116 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:22:06.0624 5116 rdpdr - ok
13:22:06.0624 5116 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:22:06.0624 5116 RDPENCDD - ok
13:22:06.0670 5116 [ 30BFBDFB7F95559EDE971F9DDB9A00BA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:22:06.0670 5116 RDPWD - ok
13:22:06.0733 5116 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:22:06.0733 5116 RemoteAccess - ok
13:22:06.0780 5116 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:22:06.0780 5116 RemoteRegistry - ok
13:22:06.0826 5116 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
13:22:06.0826 5116 RFCOMM - ok
13:22:06.0873 5116 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:22:06.0889 5116 RpcLocator - ok
13:22:06.0920 5116 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
13:22:06.0936 5116 RpcSs - ok
13:22:06.0982 5116 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:22:06.0982 5116 rspndr - ok
13:22:07.0060 5116 [ E38B785802C666782D2880738D01AC10 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIV.sys
13:22:07.0060 5116 RTHDMIAzAudService - ok
13:22:07.0076 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] SamSs C:\Windows\system32\lsass.exe
13:22:07.0076 5116 SamSs - ok
13:22:07.0107 5116 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:22:07.0107 5116 sbp2port - ok
13:22:07.0154 5116 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:22:07.0170 5116 SCardSvr - ok
13:22:07.0248 5116 [ 20B2751CD4C8F3FD989739CA661B9F30 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
13:22:07.0248 5116 SCDEmu - ok
13:22:07.0279 5116 [ 323AE0BDFD2EB15B668DDA50CC597329 ] Schedule C:\Windows\system32\schedsvc.dll
13:22:07.0294 5116 Schedule - ok
13:22:07.0310 5116 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:22:07.0310 5116 SCPolicySvc - ok
13:22:07.0326 5116 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:22:07.0326 5116 SDRSVC - ok
13:22:07.0341 5116 secdrv - ok
13:22:07.0388 5116 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:22:07.0404 5116 seclogon - ok
13:22:07.0419 5116 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
13:22:07.0419 5116 SENS - ok
13:22:07.0435 5116 Serenum - ok
13:22:07.0482 5116 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:22:07.0482 5116 Serial - ok
13:22:07.0513 5116 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:22:07.0513 5116 sermouse - ok
13:22:07.0575 5116 [ C3BB6CF8F9EE199005A2AAE2815AD756 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
13:22:07.0575 5116 ServiceLayer - ok
13:22:07.0638 5116 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:22:07.0653 5116 SessionEnv - ok
13:22:07.0700 5116 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:22:07.0700 5116 sffdisk - ok
13:22:07.0716 5116 [ E5EAFE85815BD89095FEF3144A09AB68 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:22:07.0716 5116 sffp_mmc - ok
13:22:07.0747 5116 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:22:07.0747 5116 sffp_sd - ok
13:22:07.0762 5116 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:22:07.0762 5116 sfloppy - ok
13:22:07.0825 5116 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:22:07.0825 5116 SharedAccess - ok
13:22:07.0887 5116 [ C818C44C201898399BF999BB6B35D4E3 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:22:07.0918 5116 ShellHWDetection - ok
13:22:07.0965 5116 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:22:07.0965 5116 sisagp - ok
13:22:08.0043 5116 [ F7DA61BD62A16510227656C3477E2B52 ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSGB6.sys
13:22:08.0043 5116 SiSGbeLH - ok
13:22:08.0059 5116 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:22:08.0059 5116 SiSRaid2 - ok
13:22:08.0074 5116 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:22:08.0090 5116 SiSRaid4 - ok
13:22:08.0215 5116 [ 50D9949020E02B847CD48F1243FCB895 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:22:08.0215 5116 SkypeUpdate - ok
13:22:08.0355 5116 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
13:22:08.0386 5116 slsvc - ok
13:22:08.0464 5116 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:22:08.0464 5116 SLUINotify - ok
13:22:08.0511 5116 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:22:08.0511 5116 Smb - ok
13:22:08.0558 5116 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:22:08.0574 5116 SNMPTRAP - ok
13:22:08.0667 5116 [ 03210C439D0C1224EB36865C8010DAB6 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
13:22:08.0683 5116 SNP2UVC - ok
13:22:08.0745 5116 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:22:08.0745 5116 spldr - ok
13:22:08.0792 5116 [ 524BFBEA40E6E404737CCBC754647A2E ] Spooler C:\Windows\System32\spoolsv.exe
13:22:08.0808 5116 Spooler - ok
13:22:08.0854 5116 [ BAA6018A27857B5FF0C03CE756B4A7A2 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:22:08.0854 5116 srv - ok
13:22:08.0886 5116 [ D69B44E3B000C2FF583F10C65489B4FB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:22:08.0886 5116 srv2 - ok
13:22:08.0901 5116 [ 2D10DE9022822772ADAA120B15A9BD03 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:22:08.0901 5116 srvnet - ok
13:22:08.0932 5116 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:22:08.0948 5116 SSDPSRV - ok
13:22:09.0010 5116 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:22:09.0026 5116 SstpSvc - ok
13:22:09.0057 5116 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
13:22:09.0073 5116 stisvc - ok
13:22:09.0120 5116 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:22:09.0120 5116 swenum - ok
13:22:09.0260 5116 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
13:22:09.0260 5116 SwitchBoard - ok
13:22:09.0322 5116 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
13:22:09.0338 5116 swprv - ok
13:22:09.0385 5116 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:22:09.0385 5116 Symc8xx - ok
13:22:09.0400 5116 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:22:09.0400 5116 Sym_hi - ok
13:22:09.0432 5116 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:22:09.0432 5116 Sym_u3 - ok
13:22:09.0463 5116 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
13:22:09.0510 5116 SysMain - ok
13:22:09.0510 5116 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:22:09.0525 5116 TabletInputService - ok
13:22:09.0556 5116 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:22:09.0572 5116 TapiSrv - ok
13:22:09.0603 5116 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:22:09.0619 5116 TBS - ok
13:22:09.0650 5116 [ 0E6B0885C3D5E4643ED2D043DE3433D8 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:22:09.0666 5116 Tcpip - ok
13:22:09.0712 5116 [ 0E6B0885C3D5E4643ED2D043DE3433D8 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:22:09.0728 5116 Tcpip6 - ok
13:22:09.0775 5116 [ B085A1C98F96BA7882A27B001BECF5AC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:22:09.0790 5116 tcpipreg - ok
13:22:09.0884 5116 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:22:09.0884 5116 TDPIPE - ok
13:22:09.0931 5116 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:22:09.0931 5116 TDTCP - ok
13:22:09.0946 5116 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:22:09.0946 5116 tdx - ok
13:22:10.0118 5116 [ 33966A658FF37E0C65D46E59F37E2380 ] TeamViewer7 C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
13:22:10.0149 5116 TeamViewer7 - ok
13:22:10.0196 5116 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:22:10.0196 5116 TermDD - ok
13:22:10.0258 5116 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
13:22:10.0274 5116 TermService - ok
13:22:10.0305 5116 [ C818C44C201898399BF999BB6B35D4E3 ] Themes C:\Windows\system32\shsvcs.dll
13:22:10.0305 5116 Themes - ok
13:22:10.0336 5116 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:22:10.0336 5116 THREADORDER - ok
13:22:10.0352 5116 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:22:10.0368 5116 TrkWks - ok
13:22:10.0446 5116 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:22:10.0446 5116 TrustedInstaller - ok
13:22:10.0477 5116 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:22:10.0477 5116 tssecsrv - ok
13:22:10.0555 5116 [ 1F855378A1FB733350F8531BB509179A ] TS_AR5416 C:\Windows\system32\DRIVERS\ts_athw.sys
13:22:10.0570 5116 TS_AR5416 - ok
13:22:10.0633 5116 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:22:10.0633 5116 tunmp - ok
13:22:10.0648 5116 [ 119B8184E106BAEDC83FCE5DDF3950DA ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:22:10.0648 5116 tunnel - ok
13:22:10.0664 5116 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:22:10.0664 5116 uagp35 - ok
13:22:10.0695 5116 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:22:10.0695 5116 udfs - ok
13:22:10.0758 5116 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:22:10.0773 5116 UI0Detect - ok
13:22:10.0804 5116 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:22:10.0820 5116 uliagpkx - ok
13:22:10.0836 5116 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:22:10.0836 5116 uliahci - ok
13:22:10.0851 5116 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:22:10.0867 5116 UlSata - ok
13:22:10.0882 5116 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:22:10.0882 5116 ulsata2 - ok
13:22:10.0898 5116 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:22:10.0898 5116 umbus - ok
13:22:10.0992 5116 [ BB879DCFD22926EFBEB3298129898CBB ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
13:22:10.0992 5116 UnlockerDriver5 - ok
13:22:11.0038 5116 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:22:11.0070 5116 upnphost - ok
13:22:11.0148 5116 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
13:22:11.0148 5116 upperdev - ok
13:22:11.0226 5116 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:22:11.0226 5116 usbccgp - ok
13:22:11.0272 5116 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:22:11.0288 5116 usbcir - ok
13:22:11.0335 5116 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:22:11.0335 5116 usbehci - ok
13:22:11.0350 5116 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:22:11.0350 5116 usbhub - ok
13:22:11.0382 5116 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:22:11.0382 5116 usbohci - ok
13:22:11.0413 5116 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:22:11.0413 5116 usbprint - ok
13:22:11.0475 5116 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:22:11.0475 5116 usbscan - ok
13:22:11.0538 5116 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
13:22:11.0538 5116 usbser - ok
13:22:11.0616 5116 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
13:22:11.0616 5116 UsbserFilt - ok
13:22:11.0662 5116 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:22:11.0662 5116 USBSTOR - ok
13:22:11.0725 5116 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:22:11.0725 5116 usbuhci - ok
13:22:11.0772 5116 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:22:11.0772 5116 usbvideo - ok
13:22:11.0818 5116 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
13:22:11.0834 5116 UxSms - ok
13:22:11.0850 5116 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
13:22:11.0865 5116 vds - ok
13:22:11.0928 5116 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:22:11.0928 5116 vga - ok
13:22:11.0959 5116 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:22:11.0959 5116 VgaSave - ok
13:22:11.0974 5116 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:22:11.0974 5116 viaagp - ok
13:22:11.0990 5116 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:22:11.0990 5116 ViaC7 - ok
13:22:12.0006 5116 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:22:12.0006 5116 viaide - ok
13:22:12.0037 5116 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:22:12.0037 5116 volmgr - ok
13:22:12.0068 5116 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:22:12.0068 5116 volmgrx - ok
13:22:12.0099 5116 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:22:12.0099 5116 volsnap - ok
13:22:12.0130 5116 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:22:12.0130 5116 vsmraid - ok
13:22:12.0224 5116 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
13:22:12.0240 5116 VSS - ok
13:22:12.0318 5116 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
13:22:12.0333 5116 W32Time - ok
13:22:12.0349 5116 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:22:12.0349 5116 WacomPen - ok
13:22:12.0396 5116 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:22:12.0411 5116 Wanarp - ok
13:22:12.0411 5116 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:22:12.0411 5116 Wanarpv6 - ok
13:22:12.0442 5116 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:22:12.0458 5116 wcncsvc - ok
13:22:12.0474 5116 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:22:12.0489 5116 WcsPlugInService - ok
13:22:12.0505 5116 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:22:12.0505 5116 Wd - ok
13:22:12.0567 5116 [ D6EFAF429FD30C5DF613D220E344CCE7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam.sys
13:22:12.0567 5116 WDC_SAM - ok
13:22:12.0676 5116 [ B5B84712111414DD1B14C2346E9868BE ] WDDriveService C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
13:22:12.0676 5116 WDDriveService - ok
13:22:12.0739 5116 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:22:12.0754 5116 Wdf01000 - ok
13:22:12.0786 5116 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:22:12.0801 5116 WdiServiceHost - ok
13:22:12.0817 5116 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:22:12.0817 5116 WdiSystemHost - ok
13:22:12.0848 5116 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
13:22:12.0864 5116 WebClient - ok
13:22:12.0879 5116 [ 905214925A88311FCE52F66153DE7610 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:22:12.0879 5116 Wecsvc - ok
13:22:12.0895 5116 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:22:12.0910 5116 wercplsupport - ok
13:22:12.0942 5116 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
13:22:12.0957 5116 WerSvc - ok
13:22:13.0035 5116 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:22:13.0035 5116 WinDefend - ok
13:22:13.0051 5116 WinHttpAutoProxySvc - ok
13:22:13.0129 5116 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:22:13.0129 5116 Winmgmt - ok
13:22:13.0222 5116 [ 01874D4689C212460FBABF0ECD7CB7F7 ] WinRM C:\Windows\system32\WsmSvc.dll
13:22:13.0254 5116 WinRM - ok
13:22:13.0363 5116 [ 766FDCF7E9AED0D0BEF8A36C27D0EF91 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:22:13.0378 5116 Wlansvc - ok
13:22:13.0425 5116 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:22:13.0441 5116 WmiAcpi - ok
13:22:13.0488 5116 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:22:13.0488 5116 wmiApSrv - ok
13:22:13.0581 5116 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:22:13.0597 5116 WMPNetworkSvc - ok
13:22:13.0644 5116 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:22:13.0659 5116 WPCSvc - ok
13:22:13.0706 5116 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:22:13.0722 5116 WPDBusEnum - ok
13:22:13.0753 5116 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:22:13.0753 5116 WpdUsb - ok
13:22:13.0909 5116 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:22:13.0909 5116 WPFFontCache_v0400 - ok
13:22:13.0940 5116 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:22:13.0940 5116 ws2ifsl - ok
13:22:13.0987 5116 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
13:22:14.0002 5116 wscsvc - ok
13:22:14.0002 5116 WSearch - ok
13:22:14.0096 5116 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
13:22:14.0190 5116 wuauserv - ok
13:22:14.0236 5116 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:22:14.0252 5116 WudfPf - ok
13:22:14.0330 5116 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:22:14.0330 5116 WUDFRd - ok
13:22:14.0346 5116 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:22:14.0361 5116 wudfsvc - ok
13:22:14.0439 5116 [ C2B6CC114CBE2656FD9C2D58CF9AABE1 ] XICTAMDM C:\Windows\system32\DRIVERS\XICTAMDM.sys
13:22:14.0439 5116 XICTAMDM - ok
13:22:14.0502 5116 [ 11C8EC7ECACFFFC05EDE3877FDE2E30A ] XICTANmea C:\Windows\system32\DRIVERS\XICTANmea.sys
13:22:14.0502 5116 XICTANmea - ok
13:22:14.0533 5116 [ 94E8F9062038FAFBD5A0583C36E8E655 ] XICTAVSP C:\Windows\system32\DRIVERS\XICTAVSP.sys
13:22:14.0548 5116 XICTAVSP - ok
13:22:14.0595 5116 ================ Scan global ===============================
13:22:14.0642 5116 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:22:14.0704 5116 [ 40864DA48A14EBC68A0D6BFD08BA21EB ] C:\Windows\system32\winsrv.dll
13:22:14.0736 5116 [ 40864DA48A14EBC68A0D6BFD08BA21EB ] C:\Windows\system32\winsrv.dll
13:22:14.0798 5116 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:22:14.0814 5116 [Global] - ok
13:22:14.0814 5116 ================ Scan MBR ==================================
13:22:14.0845 5116 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
13:22:15.0406 5116 \Device\Harddisk0\DR0 - ok
13:22:15.0406 5116 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
13:22:15.0422 5116 \Device\Harddisk1\DR1 - ok
13:22:15.0422 5116 ================ Scan VBR ==================================
13:22:15.0438 5116 [ 7FC8BF7A23EEBFB1290CE1AA69F6263B ] \Device\Harddisk0\DR0\Partition1
13:22:15.0438 5116 \Device\Harddisk0\DR0\Partition1 - ok
13:22:15.0453 5116 [ 1DFEFC0A45166B12E4BA5B92D61EF062 ] \Device\Harddisk0\DR0\Partition2
13:22:15.0453 5116 \Device\Harddisk0\DR0\Partition2 - ok
13:22:15.0484 5116 [ CAB02284349D4415FD5072FF6E85E267 ] \Device\Harddisk0\DR0\Partition3
13:22:15.0484 5116 \Device\Harddisk0\DR0\Partition3 - ok
13:22:15.0500 5116 [ E89B34154F7295A7FF4700EC2982E1E5 ] \Device\Harddisk1\DR1\Partition1
13:22:15.0500 5116 \Device\Harddisk1\DR1\Partition1 - ok
13:22:15.0500 5116 ============================================================
13:22:15.0500 5116 Scan finished
13:22:15.0500 5116 ============================================================
13:22:15.0516 3916 Detected object count: 0
13:22:15.0516 3916 Actual detected object count: 0
13:22:23.0191 5304 Deinitialize success
13:22:04.0128 5116 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:22:04.0143 5116 nfrd960 - ok
13:22:04.0159 5116 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:22:04.0159 5116 NlaSvc - ok
13:22:04.0252 5116 [ B1EF4686961986DFFB7FE8F18E6FCB5B ] nlsX86cc C:\Windows\system32\nlssrv32.exe
13:22:04.0252 5116 nlsX86cc - ok
13:22:04.0315 5116 [ F6C40E0A565EE3CE5AEEB325E10054F2 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
13:22:04.0315 5116 nmwcd - ok
13:22:04.0377 5116 [ 2A394E9E1FA3565E4B2FEA470FFE4D6B ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
13:22:04.0377 5116 nmwcdc - ok
13:22:04.0424 5116 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:22:04.0424 5116 Npfs - ok
13:22:04.0471 5116 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:22:04.0486 5116 nsi - ok
13:22:04.0486 5116 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:22:04.0486 5116 nsiproxy - ok
13:22:04.0564 5116 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:22:04.0580 5116 Ntfs - ok
13:22:04.0596 5116 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:22:04.0596 5116 ntrigdigi - ok
13:22:04.0627 5116 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:22:04.0627 5116 Null - ok
13:22:04.0658 5116 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:22:04.0658 5116 nvraid - ok
13:22:04.0720 5116 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:22:04.0720 5116 nvstor - ok
13:22:04.0752 5116 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:22:04.0752 5116 nv_agp - ok
13:22:04.0767 5116 NwlnkFlt - ok
13:22:04.0767 5116 NwlnkFwd - ok
13:22:04.0830 5116 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:22:04.0830 5116 ohci1394 - ok
13:22:04.0892 5116 [ F4CB9C1991314B1352DDBD8A968E4471 ] OlyCamComm C:\Windows\system32\DRIVERS\OlyCamComm.sys
13:22:04.0892 5116 OlyCamComm - ok
13:22:04.0954 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:22:04.0970 5116 p2pimsvc - ok
13:22:05.0001 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
13:22:05.0017 5116 p2psvc - ok
13:22:05.0079 5116 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:22:05.0079 5116 Parport - ok
13:22:05.0126 5116 [ 57389FA59A36D96B3EB09D0CB91E9CDC ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:22:05.0126 5116 partmgr - ok
13:22:05.0142 5116 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:22:05.0142 5116 Parvdm - ok
13:22:05.0173 5116 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:22:05.0173 5116 PcaSvc - ok
13:22:05.0220 5116 [ F451DCACBAA67F3307305EBD4A39EA07 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
13:22:05.0220 5116 pccsmcfd - ok
13:22:05.0251 5116 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
13:22:05.0251 5116 pci - ok
13:22:05.0298 5116 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
13:22:05.0298 5116 pciide - ok
13:22:05.0313 5116 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:22:05.0313 5116 pcmcia - ok
13:22:05.0376 5116 [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
13:22:05.0391 5116 pcouffin - ok
13:22:05.0454 5116 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:22:05.0469 5116 PEAUTH - ok
13:22:05.0578 5116 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:22:05.0641 5116 pla - ok
13:22:05.0688 5116 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:22:05.0703 5116 PlugPlay - ok
13:22:05.0734 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:22:05.0750 5116 PNRPAutoReg - ok
13:22:05.0781 5116 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:22:05.0797 5116 PNRPsvc - ok
13:22:05.0844 5116 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:22:05.0875 5116 PolicyAgent - ok
13:22:05.0922 5116 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:22:05.0937 5116 PptpMiniport - ok
13:22:05.0953 5116 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
13:22:05.0953 5116 Processor - ok
13:22:06.0000 5116 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
13:22:06.0015 5116 ProfSvc - ok
13:22:06.0031 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] ProtectedStorage C:\Windows\system32\lsass.exe
13:22:06.0031 5116 ProtectedStorage - ok
13:22:06.0046 5116 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:22:06.0062 5116 PSched - ok
13:22:06.0124 5116 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
13:22:06.0124 5116 PxHelp20 - ok
13:22:06.0218 5116 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:22:06.0234 5116 ql2300 - ok
13:22:06.0249 5116 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:22:06.0249 5116 ql40xx - ok
13:22:06.0312 5116 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:22:06.0327 5116 QWAVE - ok
13:22:06.0343 5116 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:22:06.0343 5116 QWAVEdrv - ok
13:22:06.0358 5116 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:22:06.0358 5116 RasAcd - ok
13:22:06.0390 5116 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:22:06.0405 5116 RasAuto - ok
13:22:06.0421 5116 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:22:06.0421 5116 Rasl2tp - ok
13:22:06.0436 5116 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
13:22:06.0468 5116 RasMan - ok
13:22:06.0483 5116 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:22:06.0483 5116 RasPppoe - ok
13:22:06.0546 5116 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:22:06.0546 5116 RasSstp - ok
13:22:06.0561 5116 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:22:06.0577 5116 rdbss - ok
13:22:06.0577 5116 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:22:06.0592 5116 RDPCDD - ok
13:22:06.0608 5116 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:22:06.0624 5116 rdpdr - ok
13:22:06.0624 5116 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:22:06.0624 5116 RDPENCDD - ok
13:22:06.0670 5116 [ 30BFBDFB7F95559EDE971F9DDB9A00BA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:22:06.0670 5116 RDPWD - ok
13:22:06.0733 5116 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:22:06.0733 5116 RemoteAccess - ok
13:22:06.0780 5116 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:22:06.0780 5116 RemoteRegistry - ok
13:22:06.0826 5116 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
13:22:06.0826 5116 RFCOMM - ok
13:22:06.0873 5116 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:22:06.0889 5116 RpcLocator - ok
13:22:06.0920 5116 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
13:22:06.0936 5116 RpcSs - ok
13:22:06.0982 5116 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:22:06.0982 5116 rspndr - ok
13:22:07.0060 5116 [ E38B785802C666782D2880738D01AC10 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIV.sys
13:22:07.0060 5116 RTHDMIAzAudService - ok
13:22:07.0076 5116 [ DCF733788C7D088D814E5F80EB4B3E0F ] SamSs C:\Windows\system32\lsass.exe
13:22:07.0076 5116 SamSs - ok
13:22:07.0107 5116 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:22:07.0107 5116 sbp2port - ok
13:22:07.0154 5116 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:22:07.0170 5116 SCardSvr - ok
13:22:07.0248 5116 [ 20B2751CD4C8F3FD989739CA661B9F30 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
13:22:07.0248 5116 SCDEmu - ok
13:22:07.0279 5116 [ 323AE0BDFD2EB15B668DDA50CC597329 ] Schedule C:\Windows\system32\schedsvc.dll
13:22:07.0294 5116 Schedule - ok
13:22:07.0310 5116 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:22:07.0310 5116 SCPolicySvc - ok
13:22:07.0326 5116 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:22:07.0326 5116 SDRSVC - ok
13:22:07.0341 5116 secdrv - ok
13:22:07.0388 5116 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:22:07.0404 5116 seclogon - ok
13:22:07.0419 5116 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
13:22:07.0419 5116 SENS - ok
13:22:07.0435 5116 Serenum - ok
13:22:07.0482 5116 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:22:07.0482 5116 Serial - ok
13:22:07.0513 5116 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:22:07.0513 5116 sermouse - ok
13:22:07.0575 5116 [ C3BB6CF8F9EE199005A2AAE2815AD756 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
13:22:07.0575 5116 ServiceLayer - ok
13:22:07.0638 5116 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:22:07.0653 5116 SessionEnv - ok
13:22:07.0700 5116 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:22:07.0700 5116 sffdisk - ok
13:22:07.0716 5116 [ E5EAFE85815BD89095FEF3144A09AB68 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:22:07.0716 5116 sffp_mmc - ok
13:22:07.0747 5116 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:22:07.0747 5116 sffp_sd - ok
13:22:07.0762 5116 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:22:07.0762 5116 sfloppy - ok
13:22:07.0825 5116 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:22:07.0825 5116 SharedAccess - ok
13:22:07.0887 5116 [ C818C44C201898399BF999BB6B35D4E3 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:22:07.0918 5116 ShellHWDetection - ok
13:22:07.0965 5116 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:22:07.0965 5116 sisagp - ok
13:22:08.0043 5116 [ F7DA61BD62A16510227656C3477E2B52 ] SiSGbeLH C:\Windows\system32\DRIVERS\SiSGB6.sys
13:22:08.0043 5116 SiSGbeLH - ok
13:22:08.0059 5116 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:22:08.0059 5116 SiSRaid2 - ok
13:22:08.0074 5116 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:22:08.0090 5116 SiSRaid4 - ok
13:22:08.0215 5116 [ 50D9949020E02B847CD48F1243FCB895 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:22:08.0215 5116 SkypeUpdate - ok
13:22:08.0355 5116 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
13:22:08.0386 5116 slsvc - ok
13:22:08.0464 5116 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:22:08.0464 5116 SLUINotify - ok
13:22:08.0511 5116 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:22:08.0511 5116 Smb - ok
13:22:08.0558 5116 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:22:08.0574 5116 SNMPTRAP - ok
13:22:08.0667 5116 [ 03210C439D0C1224EB36865C8010DAB6 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
13:22:08.0683 5116 SNP2UVC - ok
13:22:08.0745 5116 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:22:08.0745 5116 spldr - ok
13:22:08.0792 5116 [ 524BFBEA40E6E404737CCBC754647A2E ] Spooler C:\Windows\System32\spoolsv.exe
13:22:08.0808 5116 Spooler - ok
13:22:08.0854 5116 [ BAA6018A27857B5FF0C03CE756B4A7A2 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:22:08.0854 5116 srv - ok
13:22:08.0886 5116 [ D69B44E3B000C2FF583F10C65489B4FB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:22:08.0886 5116 srv2 - ok
13:22:08.0901 5116 [ 2D10DE9022822772ADAA120B15A9BD03 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:22:08.0901 5116 srvnet - ok
13:22:08.0932 5116 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:22:08.0948 5116 SSDPSRV - ok
13:22:09.0010 5116 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:22:09.0026 5116 SstpSvc - ok
13:22:09.0057 5116 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
13:22:09.0073 5116 stisvc - ok
13:22:09.0120 5116 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:22:09.0120 5116 swenum - ok
13:22:09.0260 5116 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
13:22:09.0260 5116 SwitchBoard - ok
13:22:09.0322 5116 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
13:22:09.0338 5116 swprv - ok
13:22:09.0385 5116 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:22:09.0385 5116 Symc8xx - ok
13:22:09.0400 5116 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:22:09.0400 5116 Sym_hi - ok
13:22:09.0432 5116 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:22:09.0432 5116 Sym_u3 - ok
13:22:09.0463 5116 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
13:22:09.0510 5116 SysMain - ok
13:22:09.0510 5116 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:22:09.0525 5116 TabletInputService - ok
13:22:09.0556 5116 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:22:09.0572 5116 TapiSrv - ok
13:22:09.0603 5116 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:22:09.0619 5116 TBS - ok
13:22:09.0650 5116 [ 0E6B0885C3D5E4643ED2D043DE3433D8 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:22:09.0666 5116 Tcpip - ok
13:22:09.0712 5116 [ 0E6B0885C3D5E4643ED2D043DE3433D8 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:22:09.0728 5116 Tcpip6 - ok
13:22:09.0775 5116 [ B085A1C98F96BA7882A27B001BECF5AC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:22:09.0790 5116 tcpipreg - ok
13:22:09.0884 5116 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:22:09.0884 5116 TDPIPE - ok
13:22:09.0931 5116 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:22:09.0931 5116 TDTCP - ok
13:22:09.0946 5116 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:22:09.0946 5116 tdx - ok
13:22:10.0118 5116 [ 33966A658FF37E0C65D46E59F37E2380 ] TeamViewer7 C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
13:22:10.0149 5116 TeamViewer7 - ok
13:22:10.0196 5116 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:22:10.0196 5116 TermDD - ok
13:22:10.0258 5116 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
13:22:10.0274 5116 TermService - ok
13:22:10.0305 5116 [ C818C44C201898399BF999BB6B35D4E3 ] Themes C:\Windows\system32\shsvcs.dll
13:22:10.0305 5116 Themes - ok
13:22:10.0336 5116 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:22:10.0336 5116 THREADORDER - ok
13:22:10.0352 5116 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:22:10.0368 5116 TrkWks - ok
13:22:10.0446 5116 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:22:10.0446 5116 TrustedInstaller - ok
13:22:10.0477 5116 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:22:10.0477 5116 tssecsrv - ok
13:22:10.0555 5116 [ 1F855378A1FB733350F8531BB509179A ] TS_AR5416 C:\Windows\system32\DRIVERS\ts_athw.sys
13:22:10.0570 5116 TS_AR5416 - ok
13:22:10.0633 5116 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:22:10.0633 5116 tunmp - ok
13:22:10.0648 5116 [ 119B8184E106BAEDC83FCE5DDF3950DA ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:22:10.0648 5116 tunnel - ok
13:22:10.0664 5116 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:22:10.0664 5116 uagp35 - ok
13:22:10.0695 5116 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:22:10.0695 5116 udfs - ok
13:22:10.0758 5116 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:22:10.0773 5116 UI0Detect - ok
13:22:10.0804 5116 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:22:10.0820 5116 uliagpkx - ok
13:22:10.0836 5116 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:22:10.0836 5116 uliahci - ok
13:22:10.0851 5116 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:22:10.0867 5116 UlSata - ok
13:22:10.0882 5116 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:22:10.0882 5116 ulsata2 - ok
13:22:10.0898 5116 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:22:10.0898 5116 umbus - ok
13:22:10.0992 5116 [ BB879DCFD22926EFBEB3298129898CBB ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
13:22:10.0992 5116 UnlockerDriver5 - ok
13:22:11.0038 5116 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:22:11.0070 5116 upnphost - ok
13:22:11.0148 5116 [ 47F5F9D837D80FFD5882A14DB9DA0A67 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
13:22:11.0148 5116 upperdev - ok
13:22:11.0226 5116 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:22:11.0226 5116 usbccgp - ok
13:22:11.0272 5116 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:22:11.0288 5116 usbcir - ok
13:22:11.0335 5116 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:22:11.0335 5116 usbehci - ok
13:22:11.0350 5116 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:22:11.0350 5116 usbhub - ok
13:22:11.0382 5116 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:22:11.0382 5116 usbohci - ok
13:22:11.0413 5116 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:22:11.0413 5116 usbprint - ok
13:22:11.0475 5116 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:22:11.0475 5116 usbscan - ok
13:22:11.0538 5116 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
13:22:11.0538 5116 usbser - ok
13:22:11.0616 5116 [ E44F0D17BE0908B58DCC99CCB99C6C32 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
13:22:11.0616 5116 UsbserFilt - ok
13:22:11.0662 5116 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:22:11.0662 5116 USBSTOR - ok
13:22:11.0725 5116 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:22:11.0725 5116 usbuhci - ok
13:22:11.0772 5116 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:22:11.0772 5116 usbvideo - ok
13:22:11.0818 5116 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
13:22:11.0834 5116 UxSms - ok
13:22:11.0850 5116 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
13:22:11.0865 5116 vds - ok
13:22:11.0928 5116 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:22:11.0928 5116 vga - ok
13:22:11.0959 5116 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:22:11.0959 5116 VgaSave - ok
13:22:11.0974 5116 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:22:11.0974 5116 viaagp - ok
13:22:11.0990 5116 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:22:11.0990 5116 ViaC7 - ok
13:22:12.0006 5116 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:22:12.0006 5116 viaide - ok
13:22:12.0037 5116 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:22:12.0037 5116 volmgr - ok
13:22:12.0068 5116 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:22:12.0068 5116 volmgrx - ok
13:22:12.0099 5116 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:22:12.0099 5116 volsnap - ok
13:22:12.0130 5116 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:22:12.0130 5116 vsmraid - ok
13:22:12.0224 5116 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
13:22:12.0240 5116 VSS - ok
13:22:12.0318 5116 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
13:22:12.0333 5116 W32Time - ok
13:22:12.0349 5116 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:22:12.0349 5116 WacomPen - ok
13:22:12.0396 5116 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:22:12.0411 5116 Wanarp - ok
13:22:12.0411 5116 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:22:12.0411 5116 Wanarpv6 - ok
13:22:12.0442 5116 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:22:12.0458 5116 wcncsvc - ok
13:22:12.0474 5116 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:22:12.0489 5116 WcsPlugInService - ok
13:22:12.0505 5116 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:22:12.0505 5116 Wd - ok
13:22:12.0567 5116 [ D6EFAF429FD30C5DF613D220E344CCE7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam.sys
13:22:12.0567 5116 WDC_SAM - ok
13:22:12.0676 5116 [ B5B84712111414DD1B14C2346E9868BE ] WDDriveService C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
13:22:12.0676 5116 WDDriveService - ok
13:22:12.0739 5116 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:22:12.0754 5116 Wdf01000 - ok
13:22:12.0786 5116 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:22:12.0801 5116 WdiServiceHost - ok
13:22:12.0817 5116 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:22:12.0817 5116 WdiSystemHost - ok
13:22:12.0848 5116 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
13:22:12.0864 5116 WebClient - ok
13:22:12.0879 5116 [ 905214925A88311FCE52F66153DE7610 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:22:12.0879 5116 Wecsvc - ok
13:22:12.0895 5116 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:22:12.0910 5116 wercplsupport - ok
13:22:12.0942 5116 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
13:22:12.0957 5116 WerSvc - ok
13:22:13.0035 5116 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:22:13.0035 5116 WinDefend - ok
13:22:13.0051 5116 WinHttpAutoProxySvc - ok
13:22:13.0129 5116 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:22:13.0129 5116 Winmgmt - ok
13:22:13.0222 5116 [ 01874D4689C212460FBABF0ECD7CB7F7 ] WinRM C:\Windows\system32\WsmSvc.dll
13:22:13.0254 5116 WinRM - ok
13:22:13.0363 5116 [ 766FDCF7E9AED0D0BEF8A36C27D0EF91 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:22:13.0378 5116 Wlansvc - ok
13:22:13.0425 5116 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:22:13.0441 5116 WmiAcpi - ok
13:22:13.0488 5116 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:22:13.0488 5116 wmiApSrv - ok
13:22:13.0581 5116 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:22:13.0597 5116 WMPNetworkSvc - ok
13:22:13.0644 5116 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:22:13.0659 5116 WPCSvc - ok
13:22:13.0706 5116 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:22:13.0722 5116 WPDBusEnum - ok
13:22:13.0753 5116 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:22:13.0753 5116 WpdUsb - ok
13:22:13.0909 5116 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:22:13.0909 5116 WPFFontCache_v0400 - ok
13:22:13.0940 5116 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:22:13.0940 5116 ws2ifsl - ok
13:22:13.0987 5116 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
13:22:14.0002 5116 wscsvc - ok
13:22:14.0002 5116 WSearch - ok
13:22:14.0096 5116 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
13:22:14.0190 5116 wuauserv - ok
13:22:14.0236 5116 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:22:14.0252 5116 WudfPf - ok
13:22:14.0330 5116 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:22:14.0330 5116 WUDFRd - ok
13:22:14.0346 5116 [ 2C0206FF8D2C75AC027D1096FA2FAFDA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:22:14.0361 5116 wudfsvc - ok
13:22:14.0439 5116 [ C2B6CC114CBE2656FD9C2D58CF9AABE1 ] XICTAMDM C:\Windows\system32\DRIVERS\XICTAMDM.sys
13:22:14.0439 5116 XICTAMDM - ok
13:22:14.0502 5116 [ 11C8EC7ECACFFFC05EDE3877FDE2E30A ] XICTANmea C:\Windows\system32\DRIVERS\XICTANmea.sys
13:22:14.0502 5116 XICTANmea - ok
13:22:14.0533 5116 [ 94E8F9062038FAFBD5A0583C36E8E655 ] XICTAVSP C:\Windows\system32\DRIVERS\XICTAVSP.sys
13:22:14.0548 5116 XICTAVSP - ok
13:22:14.0595 5116 ================ Scan global ===============================
13:22:14.0642 5116 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:22:14.0704 5116 [ 40864DA48A14EBC68A0D6BFD08BA21EB ] C:\Windows\system32\winsrv.dll
13:22:14.0736 5116 [ 40864DA48A14EBC68A0D6BFD08BA21EB ] C:\Windows\system32\winsrv.dll
13:22:14.0798 5116 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:22:14.0814 5116 [Global] - ok
13:22:14.0814 5116 ================ Scan MBR ==================================
13:22:14.0845 5116 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
13:22:15.0406 5116 \Device\Harddisk0\DR0 - ok
13:22:15.0406 5116 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
13:22:15.0422 5116 \Device\Harddisk1\DR1 - ok
13:22:15.0422 5116 ================ Scan VBR ==================================
13:22:15.0438 5116 [ 7FC8BF7A23EEBFB1290CE1AA69F6263B ] \Device\Harddisk0\DR0\Partition1
13:22:15.0438 5116 \Device\Harddisk0\DR0\Partition1 - ok
13:22:15.0453 5116 [ 1DFEFC0A45166B12E4BA5B92D61EF062 ] \Device\Harddisk0\DR0\Partition2
13:22:15.0453 5116 \Device\Harddisk0\DR0\Partition2 - ok
13:22:15.0484 5116 [ CAB02284349D4415FD5072FF6E85E267 ] \Device\Harddisk0\DR0\Partition3
13:22:15.0484 5116 \Device\Harddisk0\DR0\Partition3 - ok
13:22:15.0500 5116 [ E89B34154F7295A7FF4700EC2982E1E5 ] \Device\Harddisk1\DR1\Partition1
13:22:15.0500 5116 \Device\Harddisk1\DR1\Partition1 - ok
13:22:15.0500 5116 ============================================================
13:22:15.0500 5116 Scan finished
13:22:15.0500 5116 ============================================================
13:22:15.0516 3916 Detected object count: 0
13:22:15.0516 3916 Actual detected object count: 0
13:22:23.0191 5304 Deinitialize success
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
ComboFix 14-03-24.01 - DiTečka 31.03.2014 11:16:41.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1950 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
ADS - system32: deleted 12 bytes in 1 streams.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-28 do 2014-03-31 )))))))))))))))))))))))))))))))
.
.
2014-03-31 09:18 . 2014-03-31 09:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-03-30 20:46 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-03-29 12:25 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"EPSON Stylus Photo RX585 Series"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATICLE.EXE" [2007-03-30 182272]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\AutoRun\command - J:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be6f-d7be-11e0-8d07-00248c987266}]
\shell\AutoRun\command - H:\StartUpCDMA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be70-d7be-11e0-8d07-00248c987266}]
\shell\AutoRun\command - J:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39c3-70e2-11e0-aa3b-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39d1-70e2-11e0-aa3b-001e101f7fb6}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e3afd-70e2-11e0-aa3b-001e101f8891}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13fb25ad-85ed-11e0-96d0-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd1955b-478a-11e3-9266-806e6f6e6963}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd195ae-478a-11e3-9266-98aa793c4cfe}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1447b-7fbd-11e0-933f-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1448a-7fbd-11e0-933f-001e101fa1f5}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda571-7eac-11e0-b2a5-001e101f3d58}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5cf-7eac-11e0-b2a5-001e101fdb29}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5e1-7eac-11e0-b2a5-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5f0-7eac-11e0-b2a5-001e101f3da8}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda615-7eac-11e0-b2a5-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda624-7eac-11e0-b2a5-001e101f951b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda63b-7eac-11e0-b2a5-001e101f5bfc}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac5f-ac06-11e0-87c6-001e101f82a0}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac80-ac06-11e0-87c6-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac8f-ac06-11e0-87c6-001e101fb681}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3112-e108-11e0-affc-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3121-e108-11e0-affc-001e101f82a7}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1df6-0166-11e1-b665-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1e02-0166-11e1-b665-001e101f2500}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{587037ac-2658-11e1-ac14-e9b6c1793b67}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000d3-20b1-11e1-9793-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000e5-20b1-11e1-9793-001e101f4da1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e23e-1d10-11e1-90d7-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e24c-1d10-11e1-90d7-001e101f1ed9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63e441a4-74b0-11e0-a8d9-001e101f21c1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a44b-e05b-11e1-ba53-9f8db99d8c3d}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a45a-e05b-11e1-ba53-a2e9d7b30f8b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91a0105a-3b71-11e0-888e-00248c987266}]
\shell\AutoRun\command - G:\Axesstel_Setup.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed1641-dd7b-11e0-81d1-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed165e-dd7b-11e0-81d1-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed166d-dd7b-11e0-81d1-001e101fe3a9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae339b-8503-11e2-b8ab-801085e27521}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef47-ffbb-11e0-b2f2-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef56-ffbb-11e0-b2f2-001e101fe70e}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff06e-ffbb-11e0-b2f2-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff07d-ffbb-11e0-b2f2-001e101f36d9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff19a-ffbb-11e0-b2f2-001e101f864d}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a836ea8f-e4a1-11e1-8c84-a4af5c6045f3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e1-0158-11e1-90a9-00248c987266}]
\shell\AutoRun\command - G:\StartUpCDMA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e2-0158-11e1-90a9-00248c987266}]
\shell\AutoRun\command - H:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b24cfc60-19b0-11e2-b6a3-c7ab13b1a4e3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c286-9205-11e0-8e68-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c295-9205-11e0-8e68-001e101fa1f5}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2ab921c-9082-11e2-8a76-851dce0fa26f}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037011-2626-11e1-8786-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037023-2626-11e1-8786-001e101fe5e1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365b0-0153-11e1-88ca-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365c2-0153-11e1-88ca-001e101f21c1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84deef-86ac-11e0-8391-001e101f859f}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df2d-86ac-11e0-8391-001e101fe70e}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df3e-86ac-11e0-8391-001e101f7f74}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df4b-86ac-11e0-8391-001e101f63cf}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5c4-7ccf-11e0-9a24-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5d0-7ccf-11e0-9a24-001e101f8ed0}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e06e1023-8505-11e2-9d4b-a1f1416dc87e}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7baf3e5-9c7a-11e2-b38e-f6684cc8df01}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eef671e3-82cf-11e0-a5e2-001e101f2463}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5b7-e3cb-11e0-8360-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5c7-e3cb-11e0-8360-001e101f86a3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa59cf4c-405d-11e3-a512-fa750cf8ab3b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffaba5-846e-11e0-bc59-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffabb1-846e-11e0-bc59-001e101f1838}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffac03-846e-11e0-bc59-001e101f24f1}]
\shell\AutoRun\command - G:\Autorun.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
URLSearchHooks-{06bb13d3-251b-4fbd-adb2-70a6994a4bcd} - (no file)
URLSearchHooks-{32b29df0-2237-4370-9a29-37cebb730e9b} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{06BB13D3-251B-4FBD-ADB2-70A6994A4BCD} - (no file)
HKCU-Run-ICQ - ~c:\program files\ICQ7.7\ICQ.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-TaskTray - (no file)
MSConfigStartUp-msnmsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
AddRemove-Driver Genius Professional Edition_is1 - c:\program files\Driver-Soft\DriverGenius\unins000.exe
AddRemove-Super Ovladač_is1 - c:\program files\Driver-Soft\SuperOvladac\unins000.exe
AddRemove-{95174FE5-D61C-48F1-B427-9F9F8DC416C7} - c:\progra~2\TARMAI~1\{95174~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-31 11:18
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1800)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
c:\program files\Pinnacle\Studio 15\Import\programs\DivX.DivX9\divx_source_dmf_ds.ax
c:\program files\K-Lite Codec Pack\ffdshow\ffdshow.ax
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\ffdshow.ax
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\libavcodec.dll
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\libmplayer.dll
.
Celkový čas: 2014-03-31 11:21:15
ComboFix-quarantined-files.txt 2014-03-31 09:20
.
Před spuštěním: 5 109 944 320
Po spuštění: 5 036 941 312
.
- - End Of File - - 6701A648687A2381F6D7B350FC63D7E8
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1950 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
ADS - system32: deleted 12 bytes in 1 streams.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-02-28 do 2014-03-31 )))))))))))))))))))))))))))))))
.
.
2014-03-31 09:18 . 2014-03-31 09:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-03-30 20:46 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-03-29 12:25 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"EPSON Stylus Photo RX585 Series"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATICLE.EXE" [2007-03-30 182272]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\AutoRun\command - J:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be6f-d7be-11e0-8d07-00248c987266}]
\shell\AutoRun\command - H:\StartUpCDMA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be70-d7be-11e0-8d07-00248c987266}]
\shell\AutoRun\command - J:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39c3-70e2-11e0-aa3b-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39d1-70e2-11e0-aa3b-001e101f7fb6}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e3afd-70e2-11e0-aa3b-001e101f8891}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13fb25ad-85ed-11e0-96d0-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd1955b-478a-11e3-9266-806e6f6e6963}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd195ae-478a-11e3-9266-98aa793c4cfe}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1447b-7fbd-11e0-933f-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1448a-7fbd-11e0-933f-001e101fa1f5}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda571-7eac-11e0-b2a5-001e101f3d58}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5cf-7eac-11e0-b2a5-001e101fdb29}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5e1-7eac-11e0-b2a5-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5f0-7eac-11e0-b2a5-001e101f3da8}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda615-7eac-11e0-b2a5-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda624-7eac-11e0-b2a5-001e101f951b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda63b-7eac-11e0-b2a5-001e101f5bfc}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac5f-ac06-11e0-87c6-001e101f82a0}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac80-ac06-11e0-87c6-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac8f-ac06-11e0-87c6-001e101fb681}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3112-e108-11e0-affc-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3121-e108-11e0-affc-001e101f82a7}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1df6-0166-11e1-b665-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1e02-0166-11e1-b665-001e101f2500}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{587037ac-2658-11e1-ac14-e9b6c1793b67}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000d3-20b1-11e1-9793-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000e5-20b1-11e1-9793-001e101f4da1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e23e-1d10-11e1-90d7-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e24c-1d10-11e1-90d7-001e101f1ed9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63e441a4-74b0-11e0-a8d9-001e101f21c1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a44b-e05b-11e1-ba53-9f8db99d8c3d}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a45a-e05b-11e1-ba53-a2e9d7b30f8b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91a0105a-3b71-11e0-888e-00248c987266}]
\shell\AutoRun\command - G:\Axesstel_Setup.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed1641-dd7b-11e0-81d1-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed165e-dd7b-11e0-81d1-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed166d-dd7b-11e0-81d1-001e101fe3a9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae339b-8503-11e2-b8ab-801085e27521}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef47-ffbb-11e0-b2f2-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef56-ffbb-11e0-b2f2-001e101fe70e}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff06e-ffbb-11e0-b2f2-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff07d-ffbb-11e0-b2f2-001e101f36d9}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff19a-ffbb-11e0-b2f2-001e101f864d}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a836ea8f-e4a1-11e1-8c84-a4af5c6045f3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e1-0158-11e1-90a9-00248c987266}]
\shell\AutoRun\command - G:\StartUpCDMA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e2-0158-11e1-90a9-00248c987266}]
\shell\AutoRun\command - H:\StartUpHSPA.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b24cfc60-19b0-11e2-b6a3-c7ab13b1a4e3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c286-9205-11e0-8e68-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c295-9205-11e0-8e68-001e101fa1f5}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2ab921c-9082-11e2-8a76-851dce0fa26f}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037011-2626-11e1-8786-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037023-2626-11e1-8786-001e101fe5e1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365b0-0153-11e1-88ca-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365c2-0153-11e1-88ca-001e101f21c1}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84deef-86ac-11e0-8391-001e101f859f}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df2d-86ac-11e0-8391-001e101fe70e}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df3e-86ac-11e0-8391-001e101f7f74}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df4b-86ac-11e0-8391-001e101f63cf}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5c4-7ccf-11e0-9a24-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5d0-7ccf-11e0-9a24-001e101f8ed0}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e06e1023-8505-11e2-9d4b-a1f1416dc87e}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7baf3e5-9c7a-11e2-b38e-f6684cc8df01}]
\shell\AutoRun\command - F:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eef671e3-82cf-11e0-a5e2-001e101f2463}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5b7-e3cb-11e0-8360-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5c7-e3cb-11e0-8360-001e101f86a3}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa59cf4c-405d-11e3-a512-fa750cf8ab3b}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffaba5-846e-11e0-bc59-00248c987266}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffabb1-846e-11e0-bc59-001e101f1838}]
\shell\AutoRun\command - G:\Autorun.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffac03-846e-11e0-bc59-001e101f24f1}]
\shell\AutoRun\command - G:\Autorun.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-03-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
URLSearchHooks-{06bb13d3-251b-4fbd-adb2-70a6994a4bcd} - (no file)
URLSearchHooks-{32b29df0-2237-4370-9a29-37cebb730e9b} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{06BB13D3-251B-4FBD-ADB2-70A6994A4BCD} - (no file)
HKCU-Run-ICQ - ~c:\program files\ICQ7.7\ICQ.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-TaskTray - (no file)
MSConfigStartUp-msnmsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
AddRemove-Driver Genius Professional Edition_is1 - c:\program files\Driver-Soft\DriverGenius\unins000.exe
AddRemove-Super Ovladač_is1 - c:\program files\Driver-Soft\SuperOvladac\unins000.exe
AddRemove-{95174FE5-D61C-48F1-B427-9F9F8DC416C7} - c:\progra~2\TARMAI~1\{95174~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-31 11:18
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(1800)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
c:\program files\Pinnacle\Studio 15\Import\programs\DivX.DivX9\divx_source_dmf_ds.ax
c:\program files\K-Lite Codec Pack\ffdshow\ffdshow.ax
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\ffdshow.ax
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\libavcodec.dll
c:\program files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\libmplayer.dll
.
Celkový čas: 2014-03-31 11:21:15
ComboFix-quarantined-files.txt 2014-03-31 09:20
.
Před spuštěním: 5 109 944 320
Po spuštění: 5 036 941 312
.
- - End Of File - - 6701A648687A2381F6D7B350FC63D7E8
5C616939100B85E558DA92B899A0FC36
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
Jinak... háčky už fungují skvěle, tak velice mockrát děkuji, sama bych to nezvládla 

- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
G:\Autorun.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\program files\Google\Update
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be6f-d7be-11e0-8d07-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1104be70-d7be-11e0-8d07-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39c3-70e2-11e0-aa3b-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e39d1-70e2-11e0-aa3b-001e101f7fb6}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{134e3afd-70e2-11e0-aa3b-001e101f8891}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13fb25ad-85ed-11e0-96d0-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd1955b-478a-11e3-9266-806e6f6e6963}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd195ae-478a-11e3-9266-98aa793c4cfe}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1447b-7fbd-11e0-933f-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25c1448a-7fbd-11e0-933f-001e101fa1f5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda571-7eac-11e0-b2a5-001e101f3d58}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5cf-7eac-11e0-b2a5-001e101fdb29}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5e1-7eac-11e0-b2a5-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda5f0-7eac-11e0-b2a5-001e101f3da8}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda615-7eac-11e0-b2a5-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda624-7eac-11e0-b2a5-001e101f951b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26bda63b-7eac-11e0-b2a5-001e101f5bfc}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac5f-ac06-11e0-87c6-001e101f82a0}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac80-ac06-11e0-87c6-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d42ac8f-ac06-11e0-87c6-001e101fb681}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3112-e108-11e0-affc-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5e3121-e108-11e0-affc-001e101f82a7}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1df6-0166-11e1-b665-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53bd1e02-0166-11e1-b665-001e101f2500}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{587037ac-2658-11e1-ac14-e9b6c1793b67}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000d3-20b1-11e1-9793-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee000e5-20b1-11e1-9793-001e101f4da1}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e23e-1d10-11e1-90d7-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6052e24c-1d10-11e1-90d7-001e101f1ed9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63e441a4-74b0-11e0-a8d9-001e101f21c1}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a44b-e05b-11e1-ba53-9f8db99d8c3d}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8da9a45a-e05b-11e1-ba53-a2e9d7b30f8b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91a0105a-3b71-11e0-888e-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed1641-dd7b-11e0-81d1-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed165e-dd7b-11e0-81d1-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94ed166d-dd7b-11e0-81d1-001e101fe3a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae339b-8503-11e2-b8ab-801085e27521}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef47-ffbb-11e0-b2f2-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bfef56-ffbb-11e0-b2f2-001e101fe70e}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff06e-ffbb-11e0-b2f2-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff07d-ffbb-11e0-b2f2-001e101f36d9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97bff19a-ffbb-11e0-b2f2-001e101f864d}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a836ea8f-e4a1-11e1-8c84-a4af5c6045f3}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e1-0158-11e1-90a9-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae45f7e2-0158-11e1-90a9-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b24cfc60-19b0-11e2-b6a3-c7ab13b1a4e3}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c286-9205-11e0-8e68-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be88c295-9205-11e0-8e68-001e101fa1f5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2ab921c-9082-11e2-8a76-851dce0fa26f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037011-2626-11e1-8786-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6037023-2626-11e1-8786-001e101fe5e1}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365b0-0153-11e1-88ca-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca9365c2-0153-11e1-88ca-001e101f21c1}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84deef-86ac-11e0-8391-001e101f859f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df2d-86ac-11e0-8391-001e101fe70e}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df3e-86ac-11e0-8391-001e101f7f74}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd84df4b-86ac-11e0-8391-001e101f63cf}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5c4-7ccf-11e0-9a24-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dda9d5d0-7ccf-11e0-9a24-001e101f8ed0}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e06e1023-8505-11e2-9d4b-a1f1416dc87e}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7baf3e5-9c7a-11e2-b38e-f6684cc8df01}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eef671e3-82cf-11e0-a5e2-001e101f2463}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5b7-e3cb-11e0-8360-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef16f5c7-e3cb-11e0-8360-001e101f86a3}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa59cf4c-405d-11e3-a512-fa750cf8ab3b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffaba5-846e-11e0-bc59-00248c987266}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffabb1-846e-11e0-bc59-001e101f1838}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{feffac03-846e-11e0-bc59-001e101f24f1}]
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
ComboFix 14-03-24.01 - DiTečka 01.04.2014 11:23:02.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1752 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\DiTeŔka\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\ASPG_icon.ico
c:\windows\PFRO.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 09:34 . 2014-04-01 09:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-03-31 20:24 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-03-29 12:25 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: Interfaces\{EAAF58B7-0743-43F9-B3CA-73F06AF32837}: NameServer = 93.153.117.33 93.153.117.1
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-01 11:34
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2014-04-01 11:37:01
ComboFix-quarantined-files.txt 2014-04-01 09:36
ComboFix2.txt 2014-03-31 09:21
.
Před spuštěním: 2 447 777 792
Po spuštění: 2 293 690 368
.
- - End Of File - - D5A354E09DDC95FA77B230061F3B2877
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1752 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\DiTeŔka\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\ASPG_icon.ico
c:\windows\PFRO.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 09:34 . 2014-04-01 09:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-03-31 20:24 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-03-29 12:25 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: Interfaces\{EAAF58B7-0743-43F9-B3CA-73F06AF32837}: NameServer = 93.153.117.33 93.153.117.1
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-01 11:34
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2014-04-01 11:37:01
ComboFix-quarantined-files.txt 2014-04-01 09:36
ComboFix2.txt 2014-03-31 09:21
.
Před spuštěním: 2 447 777 792
Po spuštění: 2 293 690 368
.
- - End Of File - - D5A354E09DDC95FA77B230061F3B2877
5C616939100B85E558DA92B899A0FC36
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:52:44, on 1.4.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\T-Mobile\T-Mobile Internet Manager\Manager.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE
C:\Windows\system32\spool\DRIVERS\W32X86\3\CNABFSWK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nástroj WD Drive Unlocker] C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
O4 - HKLM\..\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download with FileServe Manager - C:\Program Files\FileServe Manager\GetUrl.htm
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ergonomic_firebird - Firebird Project - C:\Program Files\Ergonomic Soft\Ergonomic Setup Center\firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\nlssrv32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
--
End of file - 10613 bytes
Scan saved at 11:52:44, on 1.4.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\T-Mobile\T-Mobile Internet Manager\Manager.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE
C:\Windows\system32\spool\DRIVERS\W32X86\3\CNABFSWK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nástroj WD Drive Unlocker] C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
O4 - HKLM\..\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download with FileServe Manager - C:\Program Files\FileServe Manager\GetUrl.htm
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Active File Monitor V9 (AdobeActiveFileMonitor9.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ergonomic_firebird - Firebird Project - C:\Program Files\Ergonomic Soft\Ergonomic Setup Center\firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\nlssrv32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
--
End of file - 10613 bytes
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-04-01 11:55:27
-----------------------------
11:55:27.010 OS Version: Windows 6.0.6002 Service Pack 2
11:55:27.010 Number of processors: 2 586 0x170A
11:55:27.010 ComputerName: PC UserName:
11:55:32.611 Initialize success
11:55:36.183 AVAST engine defs: 14040100
11:55:38.773 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
11:55:38.788 Disk 0 Vendor: ST9500325AS 0002SDM1 Size: 476940MB BusType: 3
11:55:39.007 Disk 0 MBR read successfully
11:55:39.007 Disk 0 MBR scan
11:55:39.022 Disk 0 Windows VISTA default MBR code
11:55:39.022 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 12000 MB offset 2048
11:55:39.053 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238464 MB offset 24579450
11:55:39.053 Disk 0 Partition - 00 0F Extended LBA 226471 MB offset 512955450
11:55:39.085 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 226470 MB offset 512955513
11:55:39.085 Disk 0 scanning sectors +976768065
11:55:39.319 Disk 0 scanning C:\Windows\system32\drivers
11:55:55.387 Service scanning
11:56:25.994 Modules scanning
11:56:34.761 Disk 0 trace - called modules:
11:56:34.792 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
11:56:34.808 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x874399a8]
11:56:34.823 3 CLASSPNP.SYS[8bbaa8b3] -> nt!IofCallDriver -> [0x8638a4b8]
11:56:34.823 5 acpi.sys[8068b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x86385030]
11:56:35.884 AVAST engine scan C:\Windows
11:56:40.455 AVAST engine scan C:\Windows\system32
12:00:58.822 AVAST engine scan C:\Windows\system32\drivers
12:01:57.151 AVAST engine scan C:\Users\DiTečka
13:10:37.922 AVAST engine scan C:\ProgramData
13:26:01.005 Scan finished successfully
13:46:51.392 Disk 0 MBR has been saved successfully to "C:\Users\DiTečka\Desktop\MBR.dat"
13:46:51.392 The log file has been saved successfully to "C:\Users\DiTečka\Desktop\aswMBR.txt"
Run date: 2014-04-01 11:55:27
-----------------------------
11:55:27.010 OS Version: Windows 6.0.6002 Service Pack 2
11:55:27.010 Number of processors: 2 586 0x170A
11:55:27.010 ComputerName: PC UserName:
11:55:32.611 Initialize success
11:55:36.183 AVAST engine defs: 14040100
11:55:38.773 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
11:55:38.788 Disk 0 Vendor: ST9500325AS 0002SDM1 Size: 476940MB BusType: 3
11:55:39.007 Disk 0 MBR read successfully
11:55:39.007 Disk 0 MBR scan
11:55:39.022 Disk 0 Windows VISTA default MBR code
11:55:39.022 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 12000 MB offset 2048
11:55:39.053 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238464 MB offset 24579450
11:55:39.053 Disk 0 Partition - 00 0F Extended LBA 226471 MB offset 512955450
11:55:39.085 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 226470 MB offset 512955513
11:55:39.085 Disk 0 scanning sectors +976768065
11:55:39.319 Disk 0 scanning C:\Windows\system32\drivers
11:55:55.387 Service scanning
11:56:25.994 Modules scanning
11:56:34.761 Disk 0 trace - called modules:
11:56:34.792 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
11:56:34.808 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x874399a8]
11:56:34.823 3 CLASSPNP.SYS[8bbaa8b3] -> nt!IofCallDriver -> [0x8638a4b8]
11:56:34.823 5 acpi.sys[8068b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x86385030]
11:56:35.884 AVAST engine scan C:\Windows
11:56:40.455 AVAST engine scan C:\Windows\system32
12:00:58.822 AVAST engine scan C:\Windows\system32\drivers
12:01:57.151 AVAST engine scan C:\Users\DiTečka
13:10:37.922 AVAST engine scan C:\ProgramData
13:26:01.005 Scan finished successfully
13:46:51.392 Disk 0 MBR has been saved successfully to "C:\Users\DiTečka\Desktop\MBR.dat"
13:46:51.392 The log file has been saved successfully to "C:\Users\DiTečka\Desktop\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Návod
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" –atboottime
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
Folder::
c:\program files\Google\Update
RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-8002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu logu, zdvojené háčky a čárky
ComboFix 14-03-24.01 - DiTečka 01.04.2014 15:57:55.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.2122 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\DiTeŔka\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 14:00 . 2014-04-01 14:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-04-01 13:39 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-04-01 13:11 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-01 16:00
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4552)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Celkový čas: 2014-04-01 16:02:28
ComboFix-quarantined-files.txt 2014-04-01 14:02
ComboFix2.txt 2014-03-31 09:21
.
Před spuštěním: 2 133 520 384
Po spuštění: 2 081 968 128
.
- - End Of File - - EA5E94014A246920281EAAC94DF66F38
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.2122 [GMT 2:00]
Spuštěný z: c:\users\DiTeŔka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\DiTeŔka\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 14:00 . 2014-04-01 14:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-30 11:05 . 2014-04-01 13:39 5464 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2014-03-29 12:25 . 2014-04-01 13:11 -------- d-----w- c:\users\DiTečka\AppData\Local\CrashDumps
2014-03-29 12:02 . 2014-03-29 12:02 -------- d-----w- c:\windows\ERUNT
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\ATI
2014-03-28 18:34 . 2014-03-28 18:34 -------- d-----w- c:\users\DiTečka\AppData\Local\Adobe
2014-03-28 15:41 . 2014-03-29 12:36 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Kevog
2014-03-28 15:37 . 2014-03-29 11:51 -------- d-----w- C:\AdwCleaner
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 -------- d-----w- c:\program files\Trend Micro
2014-03-26 17:26 . 2014-03-28 14:26 -------- d-----w- c:\users\DiTečka\AppData\Roaming\Ydobg
2014-03-22 10:42 . 2014-03-22 10:42 -------- d-----w- c:\users\DiTečka\AppData\Local\Skype
2014-03-22 10:41 . 2014-03-22 10:41 -------- d-----w- c:\program files\Common Files\Skype
2014-03-14 12:09 . 2014-03-14 12:09 -------- d-----w- c:\program files\CELOT-Wireless
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAVSP.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTANmea.sys
2014-03-14 12:09 . 2010-07-17 08:33 168024 ----a-w- c:\windows\system32\drivers\XICTAMDM.sys
2014-03-14 12:09 . 2010-05-20 06:21 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-28 13:43 . 2014-03-28 13:43 388096 ----a-r- c:\users\DiTečka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-03-12 14:27 . 2012-09-01 10:05 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 14:27 . 2011-06-23 07:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-05 19:46 . 2014-01-05 19:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-05 19:46 . 2011-06-07 04:52 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-05 19:46 . 2010-11-28 00:02 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-05 19:46 . 2010-11-28 00:02 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-05 19:46 . 2014-01-05 19:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-05 19:46 . 2010-11-28 00:02 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-05 19:46 . 2010-11-28 00:02 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-05 19:46 . 2010-11-27 23:59 43152 ----a-w- c:\windows\avastSS.scr
2014-01-05 19:46 . 2010-11-27 23:59 270240 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-02 04:22 . 2010-06-02 04:22 89944 ----a-w- c:\program files\DSETUP.dll
2010-06-02 04:22 . 2010-06-02 04:22 537432 ----a-w- c:\program files\DXSETUP.exe
2010-06-02 04:22 . 2010-06-02 04:22 1801048 ----a-w- c:\program files\dsetup32.dll
2008-07-02 02:28 . 2008-07-02 02:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2012-08-13 18:39 . 2011-05-30 20:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-05 19:45 259464 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2012-06-26 1516632]
"T-Mobile CManager"="c:\program files\T-Mobile\T-Mobile Internet Manager\Manager.exe" [2013-10-31 2166552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"Zoner Photo Studio Autoupdate"="c:\program files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 98304]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-24 159744]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-13 11487848]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"Nástroj WD Drive Unlocker"="c:\program files\Western Digital\WD Security\WDDriveAutoUnlock.exe" [2012-09-06 1688008]
"CNAP2 Launcher"="c:\windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-10-14 226784]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2014-01-05 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^DiTečka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\DiTečka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileServe Manager Task]
2011-09-02 16:11 954648 ----a-w- c:\program files\FileServe Manager\FSStarter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2012-01-10 17:36 1083264 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 13:18 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VueMinder]
2012-03-04 20:55 7970816 ----a-w- c:\program files\VueSoft\VueMinder\VueMinder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebcamMaxAutoRun]
2011-07-17 04:56 1038848 ----a-w- c:\program files\WebcamMax\wcmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
2012-12-04 16:20 773728 ----a-w- c:\program files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
.
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
MbnExt REG_MULTI_SZ MbnExt
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-01 14:27]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-27 23:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with FileServe Manager - c:\program files\FileServe Manager\GetUrl.htm
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
FF - ProfilePath - c:\users\DiTečka\AppData\Roaming\Mozilla\Firefox\Profiles\csnhkzpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lide.cz
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-04-01 16:00
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4552)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Celkový čas: 2014-04-01 16:02:28
ComboFix-quarantined-files.txt 2014-04-01 14:02
ComboFix2.txt 2014-03-31 09:21
.
Před spuštěním: 2 133 520 384
Po spuštění: 2 081 968 128
.
- - End Of File - - EA5E94014A246920281EAAC94DF66F38
5C616939100B85E558DA92B899A0FC36
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 123 hostů