kontrola logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 02 črc 2014 11:01

:41.0513 0x0380 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
10:55:41.0544 0x0380 Netman - ok
10:55:41.0638 0x0380 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:55:41.0654 0x0380 NetMsmqActivator - ok
10:55:41.0716 0x0380 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:55:41.0732 0x0380 NetPipeActivator - ok
10:55:41.0826 0x0380 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
10:55:41.0873 0x0380 netprofm - ok
10:55:41.0935 0x0380 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:55:41.0951 0x0380 NetTcpActivator - ok
10:55:41.0982 0x0380 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:55:42.0013 0x0380 NetTcpPortSharing - ok
10:55:42.0076 0x0380 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
10:55:42.0107 0x0380 nfrd960 - ok
10:55:42.0185 0x0380 [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc C:\Windows\System32\nlasvc.dll
10:55:42.0232 0x0380 NlaSvc - ok
10:55:42.0279 0x0380 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
10:55:42.0294 0x0380 Npfs - ok
10:55:42.0357 0x0380 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
10:55:42.0357 0x0380 nsi - ok
10:55:42.0419 0x0380 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
10:55:42.0419 0x0380 nsiproxy - ok
10:55:42.0591 0x0380 [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
10:55:42.0669 0x0380 Ntfs - ok
10:55:42.0748 0x0380 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
10:55:42.0763 0x0380 Null - ok
10:55:42.0841 0x0380 [ 380C36D4BD68C0B63074D1BF230CE503, 8AC3BB1066DF1616C7F4DAC88A77953F58B4C31E0D4F91E67907CBD0EA0A4688 ] nvmpu401 C:\Windows\system32\drivers\nvmpu401.sys
10:55:42.0841 0x0380 nvmpu401 - ok
10:55:42.0888 0x0380 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys
10:55:42.0904 0x0380 nvraid - ok
10:55:42.0966 0x0380 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
10:55:42.0998 0x0380 nvstor - ok
10:55:43.0060 0x0380 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
10:55:43.0076 0x0380 nv_agp - ok
10:55:43.0138 0x0380 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
10:55:43.0138 0x0380 ohci1394 - ok
10:55:43.0279 0x0380 [ 2F09B7B4A9FB1F998BD9ECFC468A80A2, 8E0748BF4CDA53F7B3865DC7E12F069960C733531055E6286B01698B910DADDE ] P17 C:\Windows\system32\drivers\P17.sys
10:55:43.0388 0x0380 P17 - ok
10:55:43.0466 0x0380 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
10:55:43.0498 0x0380 p2pimsvc - ok
10:55:43.0591 0x0380 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
10:55:43.0623 0x0380 p2psvc - ok
10:55:43.0732 0x0380 [ AD66BC56DD6A030174C03395B3DC0720, 54EB86DEBF2BBA961E3CE34FFC186FA16FD0C7A593E1CDC5CA088D0471AA8CEB ] PAC7302 C:\Windows\system32\DRIVERS\PAC7302.SYS
10:55:43.0763 0x0380 PAC7302 - ok
10:55:43.0841 0x0380 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
10:55:43.0841 0x0380 Parport - ok
10:55:43.0919 0x0380 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys
10:55:43.0919 0x0380 partmgr - ok
10:55:43.0966 0x0380 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
10:55:43.0966 0x0380 Parvdm - ok
10:55:44.0076 0x0380 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
10:55:44.0107 0x0380 PcaSvc - ok
10:55:44.0169 0x0380 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
10:55:44.0185 0x0380 pci - ok
10:55:44.0263 0x0380 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
10:55:44.0263 0x0380 pciide - ok
10:55:44.0357 0x0380 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
10:55:44.0373 0x0380 pcmcia - ok
10:55:44.0419 0x0380 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
10:55:44.0435 0x0380 pcw - ok
10:55:44.0544 0x0380 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
10:55:44.0623 0x0380 PEAUTH - ok
10:55:44.0810 0x0380 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
10:55:44.0919 0x0380 PeerDistSvc - ok
10:55:45.0341 0x0380 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
10:55:45.0482 0x0380 pla - ok
10:55:45.0576 0x0380 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
10:55:45.0607 0x0380 PlugPlay - ok
10:55:45.0685 0x0380 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
10:55:45.0701 0x0380 PNRPAutoReg - ok
10:55:45.0763 0x0380 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
10:55:45.0779 0x0380 PNRPsvc - ok
10:55:45.0873 0x0380 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
10:55:45.0935 0x0380 PolicyAgent - ok
10:55:46.0029 0x0380 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
10:55:46.0060 0x0380 Power - ok
10:55:46.0123 0x0380 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
10:55:46.0123 0x0380 PptpMiniport - ok
10:55:46.0185 0x0380 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
10:55:46.0185 0x0380 Processor - ok
10:55:46.0263 0x0380 [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc C:\Windows\system32\profsvc.dll
10:55:46.0279 0x0380 ProfSvc - ok
10:55:46.0341 0x0380 [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] ProtectedStorage C:\Windows\system32\lsass.exe
10:55:46.0341 0x0380 ProtectedStorage - ok
10:55:46.0404 0x0380 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
10:55:46.0419 0x0380 Psched - ok
10:55:46.0591 0x0380 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
10:55:46.0716 0x0380 ql2300 - ok
10:55:46.0779 0x0380 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
10:55:46.0794 0x0380 ql40xx - ok
10:55:46.0873 0x0380 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
10:55:46.0904 0x0380 QWAVE - ok
10:55:46.0951 0x0380 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
10:55:46.0966 0x0380 QWAVEdrv - ok
10:55:47.0044 0x0380 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
10:55:47.0044 0x0380 RasAcd - ok
10:55:47.0107 0x0380 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
10:55:47.0107 0x0380 RasAgileVpn - ok
10:55:47.0185 0x0380 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
10:55:47.0201 0x0380 RasAuto - ok
10:55:47.0263 0x0380 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
10:55:47.0263 0x0380 Rasl2tp - ok
10:55:47.0388 0x0380 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
10:55:47.0435 0x0380 RasMan - ok
10:55:47.0498 0x0380 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
10:55:47.0513 0x0380 RasPppoe - ok
10:55:47.0576 0x0380 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
10:55:47.0576 0x0380 RasSstp - ok
10:55:47.0685 0x0380 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
10:55:47.0701 0x0380 rdbss - ok
10:55:47.0763 0x0380 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
10:55:47.0763 0x0380 rdpbus - ok
10:55:47.0857 0x0380 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
10:55:47.0857 0x0380 RDPCDD - ok
10:55:47.0982 0x0380 [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
10:55:47.0982 0x0380 RDPDR - ok
10:55:48.0044 0x0380 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
10:55:48.0044 0x0380 RDPENCDD - ok
10:55:48.0123 0x0380 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
10:55:48.0123 0x0380 RDPREFMP - ok
10:55:48.0216 0x0380 [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
10:55:48.0232 0x0380 RdpVideoMiniport - ok
10:55:48.0326 0x0380 [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
10:55:48.0341 0x0380 RDPWD - ok
10:55:48.0466 0x0380 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
10:55:48.0498 0x0380 rdyboost - ok
10:55:48.0576 0x0380 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
10:55:48.0591 0x0380 RemoteAccess - ok
10:55:48.0654 0x0380 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
10:55:48.0685 0x0380 RemoteRegistry - ok
10:55:48.0748 0x0380 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
10:55:48.0779 0x0380 RpcEptMapper - ok
10:55:48.0841 0x0380 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
10:55:48.0857 0x0380 RpcLocator - ok
10:55:48.0982 0x0380 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
10:55:49.0013 0x0380 RpcSs - ok
10:55:49.0091 0x0380 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
10:55:49.0107 0x0380 rspndr - ok
10:55:49.0169 0x0380 [ 4E20765744BFBC16F6D6E5BD5598786B, CDB5AB7F8BE3C0085D08DC00CC8DB3266ABA16228B2F022380482C9D05070839 ] RTL8023xp C:\Windows\system32\DRIVERS\Rtnicxp.sys
10:55:49.0169 0x0380 RTL8023xp - ok
10:55:49.0232 0x0380 [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys
10:55:49.0232 0x0380 s3cap - ok
10:55:49.0279 0x0380 [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] SamSs C:\Windows\system32\lsass.exe
10:55:49.0294 0x0380 SamSs - ok
10:55:49.0388 0x0380 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
10:55:49.0404 0x0380 sbp2port - ok
10:55:49.0482 0x0380 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
10:55:49.0513 0x0380 SCardSvr - ok
10:55:49.0560 0x0380 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
10:55:49.0560 0x0380 scfilter - ok
10:55:49.0685 0x0380 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
10:55:49.0748 0x0380 Schedule - ok
10:55:49.0810 0x0380 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
10:55:49.0810 0x0380 SCPolicySvc - ok
10:55:49.0888 0x0380 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
10:55:49.0904 0x0380 SDRSVC - ok
10:55:49.0998 0x0380 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
10:55:50.0013 0x0380 secdrv - ok
10:55:50.0076 0x0380 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
10:55:50.0091 0x0380 seclogon - ok
10:55:50.0154 0x0380 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\system32\sens.dll
10:55:50.0169 0x0380 SENS - ok
10:55:50.0216 0x0380 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
10:55:50.0248 0x0380 SensrSvc - ok
10:55:50.0279 0x0380 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
10:55:50.0294 0x0380 Serenum - ok
10:55:50.0357 0x0380 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
10:55:50.0373 0x0380 Serial - ok
10:55:50.0419 0x0380 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
10:55:50.0435 0x0380 sermouse - ok
10:55:50.0544 0x0380 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
10:55:50.0576 0x0380 SessionEnv - ok
10:55:50.0654 0x0380 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
10:55:50.0669 0x0380 sffdisk - ok
10:55:50.0716 0x0380 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
10:55:50.0716 0x0380 sffp_mmc - ok
10:55:50.0763 0x0380 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
10:55:50.0763 0x0380 sffp_sd - ok
10:55:50.0841 0x0380 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
10:55:50.0857 0x0380 sfloppy - ok
10:55:50.0951 0x0380 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
10:55:50.0982 0x0380 SharedAccess - ok
10:55:51.0107 0x0380 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
10:55:51.0138 0x0380 ShellHWDetection - ok
10:55:51.0216 0x0380 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
10:55:51.0216 0x0380 sisagp - ok
10:55:51.0279 0x0380 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:55:51.0294 0x0380 SiSRaid2 - ok
10:55:51.0357 0x0380 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
10:55:51.0373 0x0380 SiSRaid4 - ok
10:55:51.0466 0x0380 [ 50D9949020E02B847CD48F1243FCB895, 5BDAD5E44DE5B412645142810C5FCE4B2D9685F928FF4A6B836A9DCE7725BD78 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
10:55:51.0482 0x0380 SkypeUpdate - ok
10:55:51.0529 0x0380 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
10:55:51.0544 0x0380 Smb - ok
10:55:51.0654 0x0380 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
10:55:51.0669 0x0380 SNMPTRAP - ok
10:55:51.0732 0x0380 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
10:55:51.0732 0x0380 spldr - ok
10:55:51.0857 0x0380 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe
10:55:51.0888 0x0380 Spooler - ok
10:55:52.0560 0x0380 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
10:55:52.0794 0x0380 sppsvc - ok
10:55:52.0888 0x0380 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
10:55:52.0904 0x0380 sppuinotify - ok
10:55:53.0013 0x0380 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys
10:55:53.0044 0x0380 srv - ok
10:55:53.0185 0x0380 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
10:55:53.0216 0x0380 srv2 - ok
10:55:53.0279 0x0380 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
10:55:53.0294 0x0380 srvnet - ok
10:55:53.0388 0x0380 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
10:55:53.0419 0x0380 SSDPSRV - ok
10:55:53.0498 0x0380 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
10:55:53.0529 0x0380 SstpSvc - ok
10:55:53.0591 0x0380 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
10:55:53.0607 0x0380 stexstor - ok
10:55:53.0701 0x0380 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
10:55:53.0763 0x0380 StiSvc - ok
10:55:53.0826 0x0380 [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys
10:55:53.0841 0x0380 storflt - ok
10:55:53.0919 0x0380 [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys
10:55:53.0919 0x0380 storvsc - ok
10:55:53.0998 0x0380 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
10:55:54.0013 0x0380 swenum - ok
10:55:54.0107 0x0380 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
10:55:54.0138 0x0380 swprv - ok
10:55:54.0201 0x0380 Synth3dVsc - ok
10:55:54.0435 0x0380 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
10:55:54.0529 0x0380 SysMain - ok
10:55:54.0638 0x0380 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
10:55:54.0654 0x0380 TabletInputService - ok
10:55:54.0763 0x0380 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
10:55:54.0794 0x0380 TapiSrv - ok
10:55:54.0873 0x0380 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
10:55:54.0888 0x0380 TBS - ok
10:55:55.0169 0x0380 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
10:55:55.0263 0x0380 Tcpip - ok
10:55:55.0560 0x0380 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
10:55:55.0638 0x0380 TCPIP6 - ok
10:55:55.0748 0x0380 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
10:55:55.0748 0x0380 tcpipreg - ok
10:55:55.0857 0x0380 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
10:55:55.0857 0x0380 TDPIPE - ok
10:55:55.0935 0x0380 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
10:55:55.0951 0x0380 TDTCP - ok
10:55:56.0044 0x0380 [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
10:55:56.0044 0x0380 tdx - ok
10:55:56.0107 0x0380 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
10:55:56.0107 0x0380 TermDD - ok
10:55:56.0294 0x0380 [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService C:\Windows\System32\termsrv.dll
10:55:56.0357 0x0380 TermService - ok
10:55:56.0419 0x0380 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
10:55:56.0435 0x0380 Themes - ok
10:55:56.0482 0x0380 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
10:55:56.0482 0x0380 THREADORDER - ok
10:55:56.0576 0x0380 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
10:55:56.0591 0x0380 TrkWks - ok
10:55:56.0763 0x0380 [ F2AEE22231046CAD8D2F94D2C0F9BEFB, 6D4068DD104EB80BA87C142276FA25F71336000ECD2679EE985C0436C162C1B0 ] trufos C:\Windows\system32\drivers\trufos.sys
10:55:56.0810 0x0380 trufos - ok
10:55:56.0935 0x0380 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
10:55:56.0951 0x0380 TrustedInstaller - ok
10:55:57.0029 0x0380 [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
10:55:57.0044 0x0380 tssecsrv - ok
10:55:57.0107 0x0380 [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
10:55:57.0107 0x0380 TsUsbFlt - ok
10:55:57.0185 0x0380 tsusbhub - ok
10:55:57.0263 0x0380 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
10:55:57.0263 0x0380 tunnel - ok
10:55:57.0326 0x0380 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
10:55:57.0341 0x0380 uagp35 - ok
10:55:57.0435 0x0380 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
10:55:57.0451 0x0380 udfs - ok
10:55:57.0560 0x0380 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
10:55:57.0576 0x0380 UI0Detect - ok
10:55:57.0638 0x0380 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
10:55:57.0654 0x0380 uliagpkx - ok
10:55:57.0701 0x0380 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
10:55:57.0701 0x0380 umbus - ok
10:55:57.0763 0x0380 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
10:55:57.0779 0x0380 UmPass - ok
10:55:57.0873 0x0380 [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll
10:55:57.0904 0x0380 UmRdpService - ok
10:55:57.0998 0x0380 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
10:55:58.0044 0x0380 upnphost - ok
10:55:58.0123 0x0380 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
10:55:58.0138 0x0380 usbccgp - ok
10:55:58.0201 0x0380 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
10:55:58.0216 0x0380 usbcir - ok
10:55:58.0263 0x0380 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
10:55:58.0279 0x0380 usbehci - ok
10:55:58.0388 0x0380 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
10:55:58.0435 0x0380 usbhub - ok
10:55:58.0482 0x0380 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\drivers\usbohci.sys
10:55:58.0482 0x0380 usbohci - ok
10:55:58.0544 0x0380 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
10:55:58.0560 0x0380 usbprint - ok
10:55:58.0607 0x0380 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:55:58.0623 0x0380 USBSTOR - ok
10:55:58.0701 0x0380 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
10:55:58.0716 0x0380 usbuhci - ok
10:55:58.0763 0x0380 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
10:55:58.0779 0x0380 UxSms - ok
10:55:58.0826 0x0380 [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] VaultSvc C:\Windows\system32\lsass.exe
10:55:58.0841 0x0380 VaultSvc - ok
10:55:58.0904 0x0380 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
10:55:58.0919 0x0380 vdrvroot - ok
10:55:59.0013 0x0380 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
10:55:59.0060 0x0380 vds - ok
10:55:59.0138 0x0380 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
10:55:59.0154 0x0380 vga - ok
10:55:59.0201 0x0380 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
10:55:59.0201 0x0380 VgaSave - ok
10:55:59.0248 0x0380 VGPU - ok
10:55:59.0357 0x0380 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
10:55:59.0373 0x0380 vhdmp - ok
10:55:59.0419 0x0380 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
10:55:59.0435 0x0380 viaagp - ok
10:55:59.0482 0x0380 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
10:55:59.0498 0x0380 ViaC7 - ok
10:55:59.0560 0x0380 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
10:55:59.0576 0x0380 viaide - ok
10:55:59.0638 0x0380 [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys
10:55:59.0654 0x0380 vmbus - ok
10:55:59.0716 0x0380 [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
10:55:59.0716 0x0380 VMBusHID - ok
10:55:59.0779 0x0380 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
10:55:59.0779 0x0380 volmgr - ok
10:55:59.0873 0x0380 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
10:55:59.0904 0x0380 volmgrx - ok
10:55:59.0982 0x0380 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
10:55:59.0998 0x0380 volsnap - ok
10:56:00.0060 0x0380 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
10:56:00.0076 0x0380 vsmraid - ok
10:56:00.0341 0x0380 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
10:56:00.0435 0x0380 VSS - ok
10:56:00.0498 0x0380 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
10:56:00.0513 0x0380 vwifibus - ok
10:56:00.0638 0x0380 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
10:56:00.0685 0x0380 W32Time - ok
10:56:00.0763 0x0380 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
10:56:00.0779 0x0380 WacomPen - ok
10:56:00.0841 0x0380 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
10:56:00.0857 0x0380 WANARP - ok
10:56:00.0904 0x0380 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
10:56:00.0904 0x0380 Wanarpv6 - ok
10:56:01.0232 0x0380 [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
10:56:01.0341 0x0380 WatAdminSvc - ok
10:56:01.0623 0x0380 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
10:56:01.0732 0x0380 wbengine - ok
10:56:01.0826 0x0380 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
10:56:01.0841 0x0380 WbioSrvc - ok
10:56:01.0982 0x0380 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
10:56:02.0013 0x0380 wcncsvc - ok
10:56:02.0107 0x0380 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
10:56:02.0123 0x0380 WcsPlugInService - ok
10:56:02.0169 0x0380 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
10:56:02.0185 0x0380 Wd - ok
10:56:02.0279 0x0380 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
10:56:02.0326 0x0380 Wdf01000 - ok
10:56:02.0388 0x0380 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
10:56:02.0419 0x0380 WdiServiceHost - ok
10:56:02.0451 0x0380 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
10:56:02.0466 0x0380 WdiSystemHost - ok
10:56:02.0576 0x0380 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll
10:56:02.0591 0x0380 WebClient - ok
10:56:02.0669 0x0380 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
10:56:02.0685 0x0380 Wecsvc - ok
10:56:02.0748 0x0380 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
10:56:02.0779 0x0380 wercplsupport - ok
10:56:02.0841 0x0380 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
10:56:02.0873 0x0380 WerSvc - ok
10:56:02.0919 0x0380 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
10:56:02.0919 0x0380 WfpLwf - ok
10:56:02.0982 0x0380 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
10:56:02.0982 0x0380 WIMMount - ok
10:56:03.0123 0x0380 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
10:56:03.0169 0x0380 WinDefend - ok
10:56:03.0248 0x0380 WinHttpAutoProxySvc - ok
10:56:03.0341 0x0380 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
10:56:03.0357 0x0380 Winmgmt - ok
10:56:03.0623 0x0380 [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM C:\Windows\system32\WsmSvc.dll
10:56:03.0732 0x0380 WinRM - ok
10:56:03.0873 0x0380 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
10:56:03.0888 0x0380 WinUsb - ok
10:56:04.0107 0x0380 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
10:56:04.0185 0x0380 Wlansvc - ok
10:56:04.0248 0x0380 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
10:56:04.0263 0x0380 WmiAcpi - ok
10:56:04.0357 0x0380 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
10:56:04.0373 0x0380 wmiApSrv - ok
10:56:04.0529 0x0380 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
10:56:04.0654 0x0380 WMPNetworkSvc - ok
10:56:04.0716 0x0380 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
10:56:04.0716 0x0380 WPCSvc - ok
10:56:04.0794 0x0380 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
10:56:04.0810 0x0380 WPDBusEnum - ok
10:56:04.0888 0x0380 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
10:56:04.0888 0x0380 ws2ifsl - ok
10:56:04.0951 0x0380 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\system32\wscsvc.dll
10:56:04.0982 0x0380 wscsvc - ok
10:56:05.0013 0x0380 WSearch - ok
10:56:05.0435 0x0380 [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
10:56:05.0576 0x0380 wuauserv - ok
10:56:05.0685 0x0380 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
10:56:05.0701 0x0380 WudfPf - ok
10:56:05.0779 0x0380 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
10:56:05.0794 0x0380 WUDFRd - ok
10:56:05.0873 0x0380 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
10:56:05.0888 0x0380 wudfsvc - ok
10:56:05.0966 0x0380 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\Windows\System32\wwansvc.dll
10:56:05.0998 0x0380 WwanSvc - ok
10:56:06.0076 0x0380 ================ Scan global ===============================
10:56:06.0169 0x0380 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
10:56:06.0248 0x0380 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
10:56:06.0310 0x0380 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
10:56:06.0373 0x0380 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
10:56:06.0435 0x0380 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
10:56:06.0498 0x0380 [ Global ] - ok
10:56:06.0498 0x0380 ================ Scan MBR ==================================
10:56:06.0529 0x0380 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
10:56:07.0263 0x0380 \Device\Harddisk0\DR0 - ok
10:56:07.0310 0x0380 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
10:56:07.0404 0x0380 \Device\Harddisk1\DR1 - ok
10:56:07.0419 0x0380 ================ Scan VBR ==================================
10:56:07.0435 0x0380 [ F1AFEC336907D917B3BDBA84B1FC8C35 ] \Device\Harddisk0\DR0\Partition1
10:56:07.0466 0x0380 \Device\Harddisk0\DR0\Partition1 - ok
10:56:07.0498 0x0380 [ 5C89720F7EEAFB5719C56F5ED145E0BD ] \Device\Harddisk1\DR1\Partition1
10:56:07.0498 0x0380 \Device\Harddisk1\DR1\Partition1 - ok
10:56:07.0544 0x0380 [ D0AD9D843949C72E94F2B6FECAD4BAFE ] \Device\Harddisk1\DR1\Partition2
10:56:07.0544 0x0380 \Device\Harddisk1\DR1\Partition2 - ok
10:56:07.0560 0x0380 ================ Scan generic autorun ======================
10:56:08.0232 0x0380 [ 0F01BAC5042F046553D2EC0EE5E52B81, A6C694F037CDFF7FB6A39AB48174B6071CF091A94FB916BB107AE3EC12AD8D35 ] C:\Program Files\ESET\ESET Smart Security\egui.exe
10:56:08.0498 0x0380 egui - ok
10:56:08.0529 0x0380 Waiting for KSN requests completion. In queue: 375
10:56:09.0529 0x0380 Waiting for KSN requests completion. In queue: 375
10:56:10.0529 0x0380 Waiting for KSN requests completion. In queue: 203
10:56:11.0529 0x0380 Waiting for KSN requests completion. In queue: 62
10:56:12.0623 0x0380 AV detected via SS2: ESET Smart Security 7.0, C:\Program Files\ESET\ESET Smart Security\ecmd.exe ( 7.0.317.0 ), 0x41000 ( enabled : updated )
10:56:12.0638 0x0380 FW detected via SS2: ESET Personální firewall, C:\Program Files\ESET\ESET Smart Security\ecmd.exe ( 7.0.317.0 ), 0x41010 ( enabled )
10:56:15.0513 0x0380 ============================================================
10:56:15.0513 0x0380 Scan finished
10:56:15.0513 0x0380 ============================================================
10:56:15.0544 0x0abc Detected object count: 0
10:56:15.0544 0x0abc Actual detected object count: 0

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod jaro3 » 02 črc 2014 19:09

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 02 črc 2014 22:25

ComboFix 14-06-30.01 - Žaneta 02.07.2014 21:51:22.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.1536.1088 [GMT 2:00]
Spuštěný z: c:\users\Äaneta\Desktop\ComboFix.exe
AV: ESET Smart Security 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-02 do 2014-07-02 )))))))))))))))))))))))))))))))
.
.
2014-07-02 20:14 . 2014-07-02 20:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-07-02 20:14 . 2014-07-02 20:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 19:59 . 2014-07-02 15:13 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\offreg.dll
2014-07-01 19:47 . 2014-07-01 19:47 -------- d-----w- c:\programdata\RogueKiller
2014-07-01 16:24 . 2014-07-01 16:24 -------- d-----w- c:\programdata\Malwarebytes
2014-07-01 16:09 . 2014-07-01 16:13 -------- d-----w- C:\AdwCleaner
2014-07-01 08:34 . 2014-07-01 08:34 -------- d-----w- c:\program files\Enigma Software Group
2014-07-01 08:33 . 2014-07-01 08:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-07-01 07:57 . 2014-06-05 10:54 8140904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\mpengine.dll
2014-06-29 20:46 . 2014-06-29 20:46 -------- d-----w- c:\users\Žaneta\AppData\Roaming\SUPERAntiSpyware.com
2014-06-25 23:19 . 2014-06-25 23:19 -------- d-----w- c:\program files\CrystalDiskInfo
2014-06-25 23:00 . 2014-06-25 23:02 -------- d-----w- c:\program files\DVDVideoSoft
2014-06-25 22:24 . 2014-06-25 22:24 -------- d-----w- c:\program files\CCleaner
2014-06-21 00:36 . 2014-06-21 00:36 -------- d-----w- c:\program files\Common Files\Skype
2014-06-21 00:34 . 2014-06-21 00:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-21 00:34 . 2014-06-21 00:34 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----r- c:\program files\Skype
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----w- c:\programdata\Skype
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\VDLL.DLL
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\system32\runouce.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\rundll16.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo1_.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo_1.exe
2014-06-18 09:29 . 2014-06-18 09:29 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-06-18 09:29 . 2014-06-18 09:29 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-06-18 09:29 . 2014-06-18 09:29 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-06-18 09:29 . 2014-06-18 09:29 572928 ----a-w- c:\windows\system32\msvcp90.dll
2014-06-18 09:29 . 2014-06-18 09:29 655872 ----a-w- c:\windows\system32\msvcr90.dll
2014-06-18 09:29 . 2014-06-18 09:29 152808 ----a-w- c:\windows\system32\eEmpty.exe
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\programdata\MicroWorld
2014-06-16 22:50 . 2014-06-20 23:13 -------- d-----w- c:\users\Žaneta\AppData\Local\Chris_Pietschmann_(http__
2014-06-14 09:54 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2014-06-13 17:14 . 2014-07-01 19:47 35152 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-06-10 19:36 . 2014-05-08 09:06 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-10 19:36 . 2014-05-08 09:06 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 02:48 . 2014-06-10 02:48 -------- d-----w- c:\program files\ESET
2014-06-09 23:55 . 2014-06-22 00:56 -------- d-----w- c:\windows\system32\bitstreams
2014-06-09 23:55 . 2013-10-26 18:30 364544 --s-a-w- c:\windows\system32\ssleay32.dll
2014-06-09 23:55 . 2013-06-12 13:15 100864 --s-a-w- c:\windows\system32\zlib1.dll
2014-06-09 23:55 . 2012-05-26 23:36 55808 --s-a-w- c:\windows\system32\pthreadVC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 192512 --s-a-w- c:\windows\system32\libidn-11.dll
2014-06-09 23:55 . 2013-10-26 18:30 171008 --s-a-w- c:\windows\system32\libssh2.dll
2014-06-09 23:55 . 2013-10-26 18:30 133632 --s-a-w- c:\windows\system32\librtmp.dll
2014-06-09 23:55 . 2013-06-12 13:15 119888 --s-a-w- c:\windows\system32\pthreadGC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 538126 --s-a-w- c:\windows\system32\libcurl-4.dll
2014-06-09 23:55 . 2013-10-26 18:30 1704448 --s-a-w- c:\windows\system32\libeay32.dll
2014-06-09 23:55 . 2012-09-25 21:46 472424 --s-a-w- c:\windows\system32\cudart32_50_35.dll
2014-06-07 22:21 . 2014-06-25 23:00 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2014-06-07 21:28 . 2014-06-25 23:00 -------- d-----w- c:\users\Žaneta\AppData\Roaming\DVDVideoSoft
2014-06-05 10:59 . 2014-06-05 10:59 -------- d-----w- c:\users\Žaneta\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-05 04:35 . 2014-05-05 04:35 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-05-05 04:35 . 2014-05-05 04:35 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-04-16 18:26 . 2014-04-16 18:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2014-04-16 18:26 . 2014-04-16 18:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2014-04-12 02:15 . 2014-05-14 13:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:15 . 2014-05-14 13:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:12 . 2014-05-14 13:01 100352 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:12 . 2014-05-14 13:01 15872 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:12 . 2014-05-14 13:01 22016 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:11 . 2014-05-14 13:01 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:11 . 2014-05-14 13:01 22528 ----a-w- c:\windows\system32\lsass.exe
2014-04-11 18:51 . 2014-04-08 05:07 409088 ----a-w- c:\windows\system32\systemcpl.dll
2014-04-11 18:51 . 2014-04-08 05:07 13824 ----a-w- c:\windows\system32\slwga.dll
2014-04-11 18:51 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll
2014-04-11 14:19 . 2014-04-11 14:19 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-04-11 14:19 . 2014-04-11 14:19 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-09 21:59 . 2014-04-09 21:59 194048 ----a-w- c:\windows\system32\elshyph.dll
2014-04-09 21:59 . 2014-04-09 21:59 645120 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-09 21:59 . 2014-04-09 21:59 62464 ----a-w- c:\windows\system32\tdc.ocx
2014-04-09 21:59 . 2014-04-09 21:59 182272 ----a-w- c:\windows\system32\msls31.dll
2014-04-09 21:59 . 2014-04-09 21:59 337408 ----a-w- c:\windows\system32\html.iec
2014-04-09 21:59 . 2014-04-09 21:59 24576 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-09 21:59 . 2014-04-09 21:59 151552 ----a-w- c:\windows\system32\iexpress.exe
2014-04-09 21:59 . 2014-04-09 21:59 139264 ----a-w- c:\windows\system32\wextract.exe
2014-04-09 21:59 . 2014-04-09 21:59 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-09 21:59 . 2014-04-09 21:59 36352 ----a-w- c:\windows\system32\imgutil.dll
2014-04-09 21:59 . 2014-04-09 21:59 13312 ----a-w- c:\windows\system32\mshta.exe
2014-04-09 21:59 . 2014-04-09 21:59 86016 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-09 21:59 . 2014-04-09 21:59 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-09 21:59 . 2014-04-09 21:59 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-09 21:59 . 2014-04-09 21:59 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-09 16:44 . 2014-04-09 16:44 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-08 20:09 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll.old
2014-04-08 18:41 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2014-04-11 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-02-24 5075104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-04-08 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2007-12-10 13:55 323584 ----a-w- c:\windows\PixArt\Pac7302\Monitor.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-04-16 79360]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-05-30 108032]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1343400]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2014-02-24 1343408]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 30707153
*Deregistered* - 30707153
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 07:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-21 00:34]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 10.0.0.138
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-07-02 22:22:11
ComboFix-quarantined-files.txt 2014-07-02 20:22
.
Před spuštěním: Volných bajtů: 20 729 802 752
Po spuštění: Volných bajtů: 22 010 167 296
.
- - End Of File - - 79A9C85E1F2600CF2FC2BFA4A835F4FD
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Orcus » 02 črc 2014 22:58

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok).
Zkopíruj do něj následující celý text označený červeně:

ClearJavaCache::
KillAll::

File::
c:\windows\Tasks\Adobe Flash Player Updater.job

Folder::
c:\program files\Skype\Updater\

Driver::
SkypeUpdate

Registry::
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 07:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe

RegLock::
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.


Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.


- Automaticky se spustí ComboFix, oprava může trvat i déle než 10 minut. ! Nech ComboFix dokončit svou práci !
- Vlož sem log, který vyběhne v závěru čistícího procesu

Upozornění : Může se stát, že po aplikaci skriptu a restartu počítače Windows nenaběhnou, pak znovu restartuj počítač, mačkej F8 a pak zvol poslední známou funkční konfiguraci.

====================================================

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 03 črc 2014 00:46

ComboFix 14-06-30.01 - Žaneta 03.07.2014 0:14.2.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.1536.1097 [GMT 2:00]
Spuštěný z: c:\users\Äaneta\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Äaneta\Desktop\CFScript.txt
AV: ESET Smart Security 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-02 do 2014-07-02 )))))))))))))))))))))))))))))))
.
.
2014-07-02 22:37 . 2014-07-02 22:37 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-07-02 22:37 . 2014-07-02 22:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 19:59 . 2014-07-02 15:13 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\offreg.dll
2014-07-01 19:47 . 2014-07-01 19:47 -------- d-----w- c:\programdata\RogueKiller
2014-07-01 16:24 . 2014-07-01 16:24 -------- d-----w- c:\programdata\Malwarebytes
2014-07-01 16:09 . 2014-07-01 16:13 -------- d-----w- C:\AdwCleaner
2014-07-01 08:34 . 2014-07-01 08:34 -------- d-----w- c:\program files\Enigma Software Group
2014-07-01 08:33 . 2014-07-01 08:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-07-01 07:57 . 2014-06-05 10:54 8140904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\mpengine.dll
2014-06-29 20:46 . 2014-06-29 20:46 -------- d-----w- c:\users\Žaneta\AppData\Roaming\SUPERAntiSpyware.com
2014-06-25 23:19 . 2014-06-25 23:19 -------- d-----w- c:\program files\CrystalDiskInfo
2014-06-25 23:00 . 2014-06-25 23:02 -------- d-----w- c:\program files\DVDVideoSoft
2014-06-25 22:24 . 2014-06-25 22:24 -------- d-----w- c:\program files\CCleaner
2014-06-21 00:36 . 2014-06-21 00:36 -------- d-----w- c:\program files\Common Files\Skype
2014-06-21 00:34 . 2014-06-21 00:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-21 00:34 . 2014-06-21 00:34 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----r- c:\program files\Skype
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----w- c:\programdata\Skype
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\VDLL.DLL
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\system32\runouce.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\rundll16.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo1_.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo_1.exe
2014-06-18 09:29 . 2014-06-18 09:29 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-06-18 09:29 . 2014-06-18 09:29 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-06-18 09:29 . 2014-06-18 09:29 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-06-18 09:29 . 2014-06-18 09:29 572928 ----a-w- c:\windows\system32\msvcp90.dll
2014-06-18 09:29 . 2014-06-18 09:29 655872 ----a-w- c:\windows\system32\msvcr90.dll
2014-06-18 09:29 . 2014-06-18 09:29 152808 ----a-w- c:\windows\system32\eEmpty.exe
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\programdata\MicroWorld
2014-06-16 22:50 . 2014-06-20 23:13 -------- d-----w- c:\users\Žaneta\AppData\Local\Chris_Pietschmann_(http__
2014-06-14 09:54 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2014-06-13 17:14 . 2014-07-01 19:47 35152 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-06-10 19:36 . 2014-05-08 09:06 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-10 19:36 . 2014-05-08 09:06 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 02:48 . 2014-06-10 02:48 -------- d-----w- c:\program files\ESET
2014-06-09 23:55 . 2014-06-22 00:56 -------- d-----w- c:\windows\system32\bitstreams
2014-06-09 23:55 . 2013-10-26 18:30 364544 --s-a-w- c:\windows\system32\ssleay32.dll
2014-06-09 23:55 . 2013-06-12 13:15 100864 --s-a-w- c:\windows\system32\zlib1.dll
2014-06-09 23:55 . 2012-05-26 23:36 55808 --s-a-w- c:\windows\system32\pthreadVC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 192512 --s-a-w- c:\windows\system32\libidn-11.dll
2014-06-09 23:55 . 2013-10-26 18:30 171008 --s-a-w- c:\windows\system32\libssh2.dll
2014-06-09 23:55 . 2013-10-26 18:30 133632 --s-a-w- c:\windows\system32\librtmp.dll
2014-06-09 23:55 . 2013-06-12 13:15 119888 --s-a-w- c:\windows\system32\pthreadGC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 538126 --s-a-w- c:\windows\system32\libcurl-4.dll
2014-06-09 23:55 . 2013-10-26 18:30 1704448 --s-a-w- c:\windows\system32\libeay32.dll
2014-06-09 23:55 . 2012-09-25 21:46 472424 --s-a-w- c:\windows\system32\cudart32_50_35.dll
2014-06-07 22:21 . 2014-06-25 23:00 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2014-06-07 21:28 . 2014-06-25 23:00 -------- d-----w- c:\users\Žaneta\AppData\Roaming\DVDVideoSoft
2014-06-05 10:59 . 2014-06-05 10:59 -------- d-----w- c:\users\Žaneta\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-05 04:35 . 2014-05-05 04:35 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-05-05 04:35 . 2014-05-05 04:35 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-04-16 18:26 . 2014-04-16 18:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2014-04-16 18:26 . 2014-04-16 18:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2014-04-12 02:15 . 2014-05-14 13:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:15 . 2014-05-14 13:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:12 . 2014-05-14 13:01 100352 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:12 . 2014-05-14 13:01 15872 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:12 . 2014-05-14 13:01 22016 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:11 . 2014-05-14 13:01 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:11 . 2014-05-14 13:01 22528 ----a-w- c:\windows\system32\lsass.exe
2014-04-11 18:51 . 2014-04-08 05:07 409088 ----a-w- c:\windows\system32\systemcpl.dll
2014-04-11 18:51 . 2014-04-08 05:07 13824 ----a-w- c:\windows\system32\slwga.dll
2014-04-11 18:51 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll
2014-04-11 14:19 . 2014-04-11 14:19 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-04-11 14:19 . 2014-04-11 14:19 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-09 21:59 . 2014-04-09 21:59 194048 ----a-w- c:\windows\system32\elshyph.dll
2014-04-09 21:59 . 2014-04-09 21:59 645120 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-09 21:59 . 2014-04-09 21:59 62464 ----a-w- c:\windows\system32\tdc.ocx
2014-04-09 21:59 . 2014-04-09 21:59 182272 ----a-w- c:\windows\system32\msls31.dll
2014-04-09 21:59 . 2014-04-09 21:59 337408 ----a-w- c:\windows\system32\html.iec
2014-04-09 21:59 . 2014-04-09 21:59 24576 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-09 21:59 . 2014-04-09 21:59 151552 ----a-w- c:\windows\system32\iexpress.exe
2014-04-09 21:59 . 2014-04-09 21:59 139264 ----a-w- c:\windows\system32\wextract.exe
2014-04-09 21:59 . 2014-04-09 21:59 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-09 21:59 . 2014-04-09 21:59 36352 ----a-w- c:\windows\system32\imgutil.dll
2014-04-09 21:59 . 2014-04-09 21:59 13312 ----a-w- c:\windows\system32\mshta.exe
2014-04-09 21:59 . 2014-04-09 21:59 86016 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-09 21:59 . 2014-04-09 21:59 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-09 21:59 . 2014-04-09 21:59 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-09 21:59 . 2014-04-09 21:59 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-09 16:44 . 2014-04-09 16:44 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-08 20:09 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll.old
2014-04-08 18:41 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2014-04-11 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-02-24 5075104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-04-08 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2007-12-10 13:55 323584 ----a-w- c:\windows\PixArt\Pac7302\Monitor.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-04-16 79360]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-05-30 108032]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1343400]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2014-02-24 1343408]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - 30707153
*Deregistered* - 30707153
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 07:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-21 00:34]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 10.0.0.138
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-07-03 00:45:01
ComboFix-quarantined-files.txt 2014-07-02 22:44
ComboFix2.txt 2014-07-02 20:22
.
Před spuštěním: Volných bajtů: 22 134 026 240
Po spuštění: Volných bajtů: 22 073 524 224
.
- - End Of File - - DF0C29D9CA9C22AA6BB678623EECA2F5
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 03 črc 2014 00:51

aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-07-03 00:48:22
-----------------------------
00:48:22.235 OS Version: Windows 6.1.7601 Service Pack 1
00:48:22.235 Number of processors: 1 586 0x103
00:48:22.235 ComputerName: ŽANETA-PC UserName: Žaneta
00:48:25.047 Initialize success
00:48:25.141 VM: initialized successfully
00:48:25.157 VM: Intel CPU virtualization not supported
00:48:36.138 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
00:48:36.154 Disk 0 Vendor: ST340014A 3.06 Size: 38166MB BusType: 3
00:48:36.169 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-1
00:48:36.169 Disk 1 Vendor: WDC_WD1600JB-00GVC0 08.02D08 Size: 152627MB BusType: 3
00:48:36.341 Disk 0 MBR read successfully
00:48:36.357 Disk 0 MBR scan
00:48:36.357 Disk 0 Windows 7 default MBR code
00:48:36.388 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38164 MB offset 2048
00:48:36.404 Disk 0 Boot: NTFS code=1
00:48:36.419 Disk 0 scanning sectors +78161920
00:48:36.607 Disk 0 scanning C:\Windows\system32\drivers
00:48:45.998 Service scanning
00:49:28.623 Modules scanning
00:49:47.076 Disk 0 trace - called modules:
00:49:47.123 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
00:49:47.138 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85af8190]
00:49:47.169 3 CLASSPNP.SYS[88e7f59e] -> nt!IofCallDriver -> [0x85673898]
00:49:47.185 5 ACPI.sys[886443d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85671030]
00:49:47.216 Scan finished successfully
00:50:09.076 Disk 0 MBR has been saved successfully to "C:\Users\Žaneta\Desktop\MBR.dat"
00:50:09.091 The log file has been saved successfully to "C:\Users\Žaneta\Desktop\aswMBR.txt"

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Orcus » 03 črc 2014 08:24

Skript v Combofixu se neprovedl, takže prosím ještě jednou v nouzovém režimu. :smile:
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 03 črc 2014 10:21

ComboFix 14-06-30.01 - Žaneta 03.07.2014 9:54.3.1 - x86 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.1536.1087 [GMT 2:00]
Spuštěný z: c:\users\Äaneta\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Äaneta\Desktop\CFScript.txt
AV: ESET Smart Security 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-03 do 2014-07-03 )))))))))))))))))))))))))))))))
.
.
2014-07-03 08:09 . 2014-07-03 08:09 -------- d-----w- c:\users\Žaneta\AppData\Local\temp
2014-07-03 08:09 . 2014-07-03 08:09 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-07-03 08:09 . 2014-07-03 08:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 19:47 . 2014-07-01 19:47 -------- d-----w- c:\programdata\RogueKiller
2014-07-01 16:24 . 2014-07-01 16:24 -------- d-----w- c:\programdata\Malwarebytes
2014-07-01 16:09 . 2014-07-01 16:13 -------- d-----w- C:\AdwCleaner
2014-07-01 08:34 . 2014-07-01 08:34 -------- d-----w- c:\program files\Enigma Software Group
2014-07-01 08:33 . 2014-07-01 08:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-07-01 07:57 . 2014-06-05 10:54 8140904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\mpengine.dll
2014-06-29 20:46 . 2014-06-29 20:46 -------- d-----w- c:\users\Žaneta\AppData\Roaming\SUPERAntiSpyware.com
2014-06-25 23:19 . 2014-06-25 23:19 -------- d-----w- c:\program files\CrystalDiskInfo
2014-06-25 23:00 . 2014-06-25 23:02 -------- d-----w- c:\program files\DVDVideoSoft
2014-06-25 22:24 . 2014-06-25 22:24 -------- d-----w- c:\program files\CCleaner
2014-06-21 00:36 . 2014-06-21 00:36 -------- d-----w- c:\program files\Common Files\Skype
2014-06-21 00:34 . 2014-06-21 00:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-21 00:34 . 2014-06-21 00:34 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----r- c:\program files\Skype
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----w- c:\programdata\Skype
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\VDLL.DLL
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\system32\runouce.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\rundll16.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo1_.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo_1.exe
2014-06-18 09:29 . 2014-06-18 09:29 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-06-18 09:29 . 2014-06-18 09:29 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-06-18 09:29 . 2014-06-18 09:29 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-06-18 09:29 . 2014-06-18 09:29 572928 ----a-w- c:\windows\system32\msvcp90.dll
2014-06-18 09:29 . 2014-06-18 09:29 655872 ----a-w- c:\windows\system32\msvcr90.dll
2014-06-18 09:29 . 2014-06-18 09:29 152808 ----a-w- c:\windows\system32\eEmpty.exe
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\programdata\MicroWorld
2014-06-16 22:50 . 2014-06-20 23:13 -------- d-----w- c:\users\Žaneta\AppData\Local\Chris_Pietschmann_(http__
2014-06-14 09:54 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2014-06-13 17:14 . 2014-07-01 19:47 35152 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-06-10 19:36 . 2014-05-08 09:06 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-10 19:36 . 2014-05-08 09:06 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 02:48 . 2014-06-10 02:48 -------- d-----w- c:\program files\ESET
2014-06-09 23:55 . 2014-06-22 00:56 -------- d-----w- c:\windows\system32\bitstreams
2014-06-09 23:55 . 2013-10-26 18:30 364544 --s-a-w- c:\windows\system32\ssleay32.dll
2014-06-09 23:55 . 2013-06-12 13:15 100864 --s-a-w- c:\windows\system32\zlib1.dll
2014-06-09 23:55 . 2012-05-26 23:36 55808 --s-a-w- c:\windows\system32\pthreadVC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 192512 --s-a-w- c:\windows\system32\libidn-11.dll
2014-06-09 23:55 . 2013-10-26 18:30 171008 --s-a-w- c:\windows\system32\libssh2.dll
2014-06-09 23:55 . 2013-10-26 18:30 133632 --s-a-w- c:\windows\system32\librtmp.dll
2014-06-09 23:55 . 2013-06-12 13:15 119888 --s-a-w- c:\windows\system32\pthreadGC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 538126 --s-a-w- c:\windows\system32\libcurl-4.dll
2014-06-09 23:55 . 2013-10-26 18:30 1704448 --s-a-w- c:\windows\system32\libeay32.dll
2014-06-09 23:55 . 2012-09-25 21:46 472424 --s-a-w- c:\windows\system32\cudart32_50_35.dll
2014-06-07 22:21 . 2014-06-25 23:00 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2014-06-07 21:28 . 2014-06-25 23:00 -------- d-----w- c:\users\Žaneta\AppData\Roaming\DVDVideoSoft
2014-06-05 10:59 . 2014-06-05 10:59 -------- d-----w- c:\users\Žaneta\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-05 04:35 . 2014-05-05 04:35 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-05-05 04:35 . 2014-05-05 04:35 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-04-16 18:26 . 2014-04-16 18:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2014-04-16 18:26 . 2014-04-16 18:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2014-04-12 02:15 . 2014-05-14 13:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:15 . 2014-05-14 13:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:12 . 2014-05-14 13:01 100352 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:12 . 2014-05-14 13:01 15872 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:12 . 2014-05-14 13:01 22016 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:11 . 2014-05-14 13:01 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:11 . 2014-05-14 13:01 22528 ----a-w- c:\windows\system32\lsass.exe
2014-04-11 18:51 . 2014-04-08 05:07 409088 ----a-w- c:\windows\system32\systemcpl.dll
2014-04-11 18:51 . 2014-04-08 05:07 13824 ----a-w- c:\windows\system32\slwga.dll
2014-04-11 18:51 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll
2014-04-11 14:19 . 2014-04-11 14:19 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-04-11 14:19 . 2014-04-11 14:19 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-09 21:59 . 2014-04-09 21:59 194048 ----a-w- c:\windows\system32\elshyph.dll
2014-04-09 21:59 . 2014-04-09 21:59 645120 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-09 21:59 . 2014-04-09 21:59 62464 ----a-w- c:\windows\system32\tdc.ocx
2014-04-09 21:59 . 2014-04-09 21:59 182272 ----a-w- c:\windows\system32\msls31.dll
2014-04-09 21:59 . 2014-04-09 21:59 337408 ----a-w- c:\windows\system32\html.iec
2014-04-09 21:59 . 2014-04-09 21:59 24576 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-09 21:59 . 2014-04-09 21:59 151552 ----a-w- c:\windows\system32\iexpress.exe
2014-04-09 21:59 . 2014-04-09 21:59 139264 ----a-w- c:\windows\system32\wextract.exe
2014-04-09 21:59 . 2014-04-09 21:59 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-09 21:59 . 2014-04-09 21:59 36352 ----a-w- c:\windows\system32\imgutil.dll
2014-04-09 21:59 . 2014-04-09 21:59 13312 ----a-w- c:\windows\system32\mshta.exe
2014-04-09 21:59 . 2014-04-09 21:59 86016 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-09 21:59 . 2014-04-09 21:59 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-09 21:59 . 2014-04-09 21:59 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-09 21:59 . 2014-04-09 21:59 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-09 16:44 . 2014-04-09 16:44 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-08 20:09 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll.old
2014-04-08 18:41 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2014-04-11 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-02-24 5075104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-04-08 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2007-12-10 13:55 323584 ----a-w- c:\windows\PixArt\Pac7302\Monitor.exe
.
R0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
R1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2014-02-24 1343408]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-04-16 79360]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-05-30 108032]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1343400]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 07:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-21 00:34]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 10.0.0.138
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-07-03 10:14:47
ComboFix-quarantined-files.txt 2014-07-03 08:14
ComboFix2.txt 2014-07-02 22:45
ComboFix3.txt 2014-07-02 20:22
.
Před spuštěním: Volných bajtů: 22 033 272 832
Po spuštění: Volných bajtů: 21 952 413 696
.
- - End Of File - - 3A8E5A0808FB83BE0658BF3643E51612
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod jaro3 » 03 črc 2014 18:54

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::

File::
c:\windows\system32\drivers\sp_rsdrv2.sys
c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat

Folder::
c:\program files\Skype\Updater


Driver::
SkypeUpdate

Registry::

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\windows\System32\user32.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 03 črc 2014 20:14

ComboFix 14-06-30.01 - Žaneta 03.07.2014 19:41:09.4.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.1536.1086 [GMT 2:00]
Spuštěný z: c:\users\Äaneta\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Äaneta\Desktop\CFScript.txt
AV: ESET Smart Security 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-03 do 2014-07-03 )))))))))))))))))))))))))))))))
.
.
2014-07-03 18:04 . 2014-07-03 18:04 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-07-03 18:04 . 2014-07-03 18:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-03 08:14 . 2014-07-03 18:04 -------- d-----w- c:\users\Žaneta\AppData\Local\temp
2014-07-01 19:47 . 2014-07-01 19:47 -------- d-----w- c:\programdata\RogueKiller
2014-07-01 16:24 . 2014-07-01 16:24 -------- d-----w- c:\programdata\Malwarebytes
2014-07-01 16:09 . 2014-07-01 16:13 -------- d-----w- C:\AdwCleaner
2014-07-01 08:34 . 2014-07-01 08:34 -------- d-----w- c:\program files\Enigma Software Group
2014-07-01 08:33 . 2014-07-01 08:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2014-07-01 07:57 . 2014-06-05 10:54 8140904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5C77805D-5499-43CC-ACDA-F5AEB227048C}\mpengine.dll
2014-06-29 20:46 . 2014-06-29 20:46 -------- d-----w- c:\users\Žaneta\AppData\Roaming\SUPERAntiSpyware.com
2014-06-25 23:19 . 2014-06-25 23:19 -------- d-----w- c:\program files\CrystalDiskInfo
2014-06-25 23:00 . 2014-06-25 23:02 -------- d-----w- c:\program files\DVDVideoSoft
2014-06-25 22:24 . 2014-06-25 22:24 -------- d-----w- c:\program files\CCleaner
2014-06-21 00:36 . 2014-06-21 00:36 -------- d-----w- c:\program files\Common Files\Skype
2014-06-21 00:34 . 2014-06-21 00:34 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-06-21 00:34 . 2014-06-21 00:34 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----r- c:\program files\Skype
2014-06-21 00:30 . 2014-06-21 00:36 -------- d-----w- c:\programdata\Skype
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\VDLL.DLL
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\system32\runouce.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\rundll16.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo1_.exe
2014-06-18 09:36 . 2014-06-18 09:36 -------- d---a-w- c:\windows\logo_1.exe
2014-06-18 09:29 . 2014-06-18 09:29 343456 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-06-18 09:29 . 2014-06-18 09:29 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-06-18 09:29 . 2014-06-18 09:29 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-06-18 09:29 . 2014-06-18 09:29 572928 ----a-w- c:\windows\system32\msvcp90.dll
2014-06-18 09:29 . 2014-06-18 09:29 655872 ----a-w- c:\windows\system32\msvcr90.dll
2014-06-18 09:29 . 2014-06-18 09:29 152808 ----a-w- c:\windows\system32\eEmpty.exe
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-06-18 09:28 . 2014-06-18 09:28 -------- d-----w- c:\programdata\MicroWorld
2014-06-16 22:50 . 2014-06-20 23:13 -------- d-----w- c:\users\Žaneta\AppData\Local\Chris_Pietschmann_(http__
2014-06-14 09:54 . 2011-06-21 09:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2014-06-13 17:14 . 2014-07-01 19:47 35152 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-06-10 19:36 . 2014-05-08 09:06 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-10 19:36 . 2014-05-08 09:06 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 02:48 . 2014-06-10 02:48 -------- d-----w- c:\program files\ESET
2014-06-09 23:55 . 2014-06-22 00:56 -------- d-----w- c:\windows\system32\bitstreams
2014-06-09 23:55 . 2013-10-26 18:30 364544 --s-a-w- c:\windows\system32\ssleay32.dll
2014-06-09 23:55 . 2013-06-12 13:15 100864 --s-a-w- c:\windows\system32\zlib1.dll
2014-06-09 23:55 . 2012-05-26 23:36 55808 --s-a-w- c:\windows\system32\pthreadVC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 192512 --s-a-w- c:\windows\system32\libidn-11.dll
2014-06-09 23:55 . 2013-10-26 18:30 171008 --s-a-w- c:\windows\system32\libssh2.dll
2014-06-09 23:55 . 2013-10-26 18:30 133632 --s-a-w- c:\windows\system32\librtmp.dll
2014-06-09 23:55 . 2013-06-12 13:15 119888 --s-a-w- c:\windows\system32\pthreadGC2.dll
2014-06-09 23:55 . 2013-10-26 18:30 538126 --s-a-w- c:\windows\system32\libcurl-4.dll
2014-06-09 23:55 . 2013-10-26 18:30 1704448 --s-a-w- c:\windows\system32\libeay32.dll
2014-06-09 23:55 . 2012-09-25 21:46 472424 --s-a-w- c:\windows\system32\cudart32_50_35.dll
2014-06-07 22:21 . 2014-06-25 23:00 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2014-06-07 21:28 . 2014-06-25 23:00 -------- d-----w- c:\users\Žaneta\AppData\Roaming\DVDVideoSoft
2014-06-05 10:59 . 2014-06-05 10:59 -------- d-----w- c:\users\Žaneta\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-05 04:35 . 2014-05-05 04:35 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-05-05 04:35 . 2014-05-05 04:35 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-04-16 18:26 . 2014-04-16 18:26 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2014-04-16 18:26 . 2014-04-16 18:26 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2014-04-12 02:15 . 2014-05-14 13:01 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:15 . 2014-05-14 13:01 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:12 . 2014-05-14 13:01 100352 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:12 . 2014-05-14 13:01 15872 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:12 . 2014-05-14 13:01 22016 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:11 . 2014-05-14 13:01 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:11 . 2014-05-14 13:01 22528 ----a-w- c:\windows\system32\lsass.exe
2014-04-11 18:51 . 2014-04-08 05:07 409088 ----a-w- c:\windows\system32\systemcpl.dll
2014-04-11 18:51 . 2014-04-08 05:07 13824 ----a-w- c:\windows\system32\slwga.dll
2014-04-11 18:51 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll
2014-04-11 14:19 . 2014-04-11 14:19 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-04-11 14:19 . 2014-04-11 14:19 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 435 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-10 17:16 . 2014-04-10 17:16 360 ----a-w- c:\users\Žaneta\AppData\Local\LMIR0001.tmp_r.bat
2014-04-09 21:59 . 2014-04-09 21:59 194048 ----a-w- c:\windows\system32\elshyph.dll
2014-04-09 21:59 . 2014-04-09 21:59 645120 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-09 21:59 . 2014-04-09 21:59 62464 ----a-w- c:\windows\system32\tdc.ocx
2014-04-09 21:59 . 2014-04-09 21:59 182272 ----a-w- c:\windows\system32\msls31.dll
2014-04-09 21:59 . 2014-04-09 21:59 337408 ----a-w- c:\windows\system32\html.iec
2014-04-09 21:59 . 2014-04-09 21:59 24576 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-09 21:59 . 2014-04-09 21:59 151552 ----a-w- c:\windows\system32\iexpress.exe
2014-04-09 21:59 . 2014-04-09 21:59 139264 ----a-w- c:\windows\system32\wextract.exe
2014-04-09 21:59 . 2014-04-09 21:59 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-09 21:59 . 2014-04-09 21:59 36352 ----a-w- c:\windows\system32\imgutil.dll
2014-04-09 21:59 . 2014-04-09 21:59 13312 ----a-w- c:\windows\system32\mshta.exe
2014-04-09 21:59 . 2014-04-09 21:59 86016 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-09 21:59 . 2014-04-09 21:59 74240 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-09 21:59 . 2014-04-09 21:59 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-09 21:59 . 2014-04-09 21:59 111616 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-09 16:44 . 2014-04-09 16:44 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-04-08 20:09 . 2014-04-08 05:09 811520 ----a-w- c:\windows\system32\user32.dll.old
2014-04-08 18:41 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2014-04-11 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-02-24 5075104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-04-08 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2007-12-10 13:55 323584 ----a-w- c:\windows\PixArt\Pac7302\Monitor.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-04-16 79360]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-05-30 108032]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1343400]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 49240]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 37416]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2014-02-24 1343408]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 07:20 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-21 00:34]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 10.0.0.138
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_125_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-07-03 20:11:31
ComboFix-quarantined-files.txt 2014-07-03 18:11
ComboFix2.txt 2014-07-03 08:14
ComboFix3.txt 2014-07-02 22:45
ComboFix4.txt 2014-07-02 20:22
.
Před spuštěním: Volných bajtů: 22 118 961 152
Po spuštění: Volných bajtů: 22 062 264 320
.
- - End Of File - - 01CF3BF8D8A0923A8164922765F745A3
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
BAJLA
Level 3
Level 3
Příspěvky: 545
Registrován: duben 14
Bydliště: Olomoucký kraj
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod BAJLA » 03 črc 2014 20:17

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 20:16:06, on 3.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!


Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Users\Žaneta\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 2466 bytes



Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 95 hostů