Kontrola Logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Kontrola Logu

Příspěvekod Max583 » 17 srp 2014 09:48

Prosím o kontrolu Logu:
Zlobí mě připojení k internetu. Zřizovatel tvrdí, že je vše v pořádku. Vyměnil jsem router a stejně mě hrozně dlouho nabíhají schránky a k tomu se občas sekne PC.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:44:29, on 17.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\WScript.exe
C:\Users\Bohouš\AppData\Local\Temp\Rar$EX01.035\HotkeyP.exe
D:\Programy\RocketDock\RocketDock.exe
D:\Programy\Rainlendar2\Rainlendar2.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera_crashreporter.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
C:\Program Files\Opera\23.0.1522.75_0\opera.exe
D:\Plánovače\čištění\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.creativetoolbars.com/?src ... martbar&g=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CrossriderApp0042822 - {11111111-1111-1111-1111-110411281122} - C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho.dll
O2 - BHO: CrossriderApp0061752 - {11111111-1111-1111-1111-110611171152} - C:\Program Files\Internet Speed Checker\Internet Speed Checker-bho.dll
O2 - BHO: CrossriderApp0061908 - {11111111-1111-1111-1111-110611191108} - C:\Program Files\SavePass 1.1\SavePass 1.1-bho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [msopgrmuSrv] "C:\Windows\system32\msopgrmu.vbe" msrdxkbs msjocuxd
O4 - HKLM\..\Run: [mncwlpoSrv] C:\Windows\system32\mncwlpo.vbe
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKLM\..\Run: [mncqtxmSrv] C:\Windows\system32\mncqtxm.vbe
O4 - HKCU\..\Run: [HotkeyP] C:\Users\Bohouš\AppData\Local\Temp\Rar$EX01.035\HotkeyP.exe 0
O4 - HKCU\..\Run: [RocketDock] "D:\Programy\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Rainlendar2] D:\Programy\Rainlendar2\Rainlendar2.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/CZ/Core/ ... _Win32.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCData\StartHelp.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe

--
End of file - 5183 bytes

Reklama
Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Kontrola Logu

Příspěvekod Orcus » 17 srp 2014 11:49

Máš tam bitcoin miner, který zatěžuje CPU, proto pomalé načítání.

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 17 srp 2014 13:10

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 17.8.2014
Scan Time: 12:25:27
Logfile: Mal.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.08.16.08
Rootkit Database: v2014.08.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: BohouA!

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289469
Time Elapsed: 19 min, 9 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 4
Trojan.BitMiner, C:\Program Files\PCData\dgen.exe, 1164, Delete-on-Reboot, [8eba4582374477bf1692ebc4c938aa56]
PUP.BitCoinMiner, C:\Windows\System32\lcpmncqtxm.exe, 3320, Delete-on-Reboot, [e167e1e63a413ff7184725f445bce41c]
PUP.BitCoinMiner, C:\Windows\System32\lcpmncwlpo.exe, 4284, Delete-on-Reboot, [a99f883fa2d9e84ec996d247917057a9]
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\382cd932-f57d-4d05-9619-28d485fa6a71.exe, 1844, Delete-on-Reboot, [5fe97f4878035bdb2cbd07d29d65e11f]

Modules: 0
(No malicious items detected)

Registry Keys: 115
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411281122}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440444284422}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550455285522}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660466286622}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0042822.BHO.1, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411281122}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0042822.BHO, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110411281122}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110411281122}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220422282222}, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0042822.Sandbox.1, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0042822.Sandbox, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411281122}\INPROCSERVER32, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611171152}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644174452}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655175552}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666176652}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061752.BHO.1, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611171152}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061752.BHO, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110611171152}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110611171152}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622172252}, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061752.Sandbox.1, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061752.Sandbox, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611171152}\INPROCSERVER32, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\TYPELIB\{A0EE0278-2986-4E5A-884E-A3BF0357E476}, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\INTERFACE\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd.1, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, Quarantined, [46022e99f18abb7ba7cfe18f1be7fc04],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, Quarantined, [46022e99f18abb7ba7cfe18f1be7fc04],
PUP.Optional.Babylon.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Quarantined, [92b656719ae17cba453d23487d855da3],
PUP.Optional.Datamngr.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, Quarantined, [1533f2d5d9a2e1559046c5e0dc269f61],
PUP.Optional.SearchApp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}, Quarantined, [2f19c2051467e155840427819e6439c7],
PUP.Optional.SearchApp.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}, Quarantined, [2f19c2051467e155840427819e6439c7],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}, Quarantined, [3414685f1c5fd95d1c45244c26dcff01],
PUP.Optional.InternetSpeedChecker.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Internet Speed Checker, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\Datamngr, Quarantined, [61e790375625c175552ded03946ee11f],
PUP.Optional.InternetSpeedChecker, HKLM\SOFTWARE\Internet Speed Checker, Quarantined, [63e520a784f76acc13a4f0f0c53dec14],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\SavePass 1.1, Quarantined, [440409be5328ac8a3698de017e8453ad],
PUP.Optional.ShopAndUp.A, HKLM\SOFTWARE\Shop_an_Upi_1.6, Quarantined, [4701547398e3e452033b23c6f210d62a],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CostMin.CostMin, Quarantined, [b98f963182f9e254467ea2699370d927],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CostMin.CostMin.2.2, Quarantined, [ec5c6364c3b8de58e8dc57b4f40f40c0],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061908.BHO, Quarantined, [c1877b4c4d2ec76f4ec3b82c37cb1ee2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061908.BHO.1, Quarantined, [cf791aad611a68ced43d60842cd6f20e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061908.Sandbox, Quarantined, [b2963394dc9ffb3bb75aa044b54d3bc5],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0061908.Sandbox.1, Quarantined, [c3853e893d3e5dd936db07dda45e51af],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [65e3478066155fd7fccade07a2605aa6],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\23586, Quarantined, [3414ddea3249ac8a41b9bf410003a060],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [35139a2d621940f67c7ef10feb18639d],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\7359, Quarantined, [133570571b60ef47db1ff50bb350728e],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\bitguard.exe, Quarantined, [b5934c7b89f2c670db2769dc808402fe],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\bprotect.exe, Quarantined, [71d7992eabd039fdbf446dd8c1438080],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\bpsvc.exe, Quarantined, [4ff94d7a601ba195f113054053b143bd],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\browserdefender.exe, Quarantined, [2b1dc9feb8c30333877e7fc663a10ff1],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\browserprotect.exe, Quarantined, [3810b215ed8e0b2b81850d38e123aa56],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\browsersafeguard.exe, Quarantined, [bd8be4e38deea2946a9d6dd8f01423dd],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\dprotectsvc.exe, Quarantined, [ef590eb9e89381b564a4db6a2ed603fd],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\jumpflip, Quarantined, [4ff99b2c007b01350405c87d5fa58c74],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\protectedsearch.exe, Quarantined, [60e821a6d8a3fe3878927fc6768ef20e],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\searchinstaller.exe, Quarantined, [10388c3b63185cdaef1c063fd0340ef2],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\searchprotection.exe, Quarantined, [ed5bab1c007bc0767f8da2a346be0ef2],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\searchprotector.exe, Quarantined, [143411b6df9c51e57f8ea1a457add828],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\searchsettings.exe, Quarantined, [192f96313f3c7fb755b9dc69bb49ed13],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\searchsettings64.exe, Quarantined, [b494e5e2bbc04ee8b05f5aeb659fb947],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\snapdo.exe, Quarantined, [86c214b383f8dc5ae22e9fa6659f58a8],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\stinst32.exe, Quarantined, [1a2e16b11c5f1026ea275beaa55f46ba],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\stinst64.exe, Quarantined, [a8a0dfe8a2d9bc7acf42a0a5cc38936d],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\umbrella.exe, Quarantined, [ba8ecdfabfbc43f34bc7a4a19a6ac63a],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\utiljumpflip.exe, Quarantined, [77d13790354661d566ad98ad29dbdd23],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\volaro, Quarantined, [1a2e5176a9d240f632e285c0be46847c],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\vonteera, Quarantined, [7fc98047f48743f32ce99fa6d33155ab],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\websteroids.exe, Quarantined, [1e2a4582d9a256e0090db4917f85ff01],
PUP.Optional.IFEO.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\websteroidsservice.exe, Quarantined, [8dbb3e8995e6b97dae69f154fd0754ac],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [a5a305c2b7c4191dd2f5d86e768e7b85],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [2a1eb80f82f9251143852c1a64a03ec2],
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\SYSTWEAK\RegClean Pro, Quarantined, [2028f4d3770444f2fc97d0179f6316ea],
PUP.Optional.InternetSpeedChecker, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Internet Speed Checker, Quarantined, [0e3adaed1d5ea2949c1ce3fd7f837090],
PUP.Optional.SavePass.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Quarantined, [e3656265e29981b5607029b65ba73fc1],
PUP.Optional.ShopAndUp.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Shop_an_Upi_1.6, Quarantined, [0d3b0eb98af1989e49f7b831f60c34cc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [87c1c8ff94e764d2dbec81b63dc76e92],
PUP.Optional.InternetSpeedChecker, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Internet Speed Checker, Quarantined, [1a2ec205106bc571e1d73ca4ee14f50b],
PUP.Optional.SavePass.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Quarantined, [fd4b06c17ffcd75f9e323da26c96f40c],
PUP.Optional.ShopAndUp.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Shop_an_Upi_1.6, Quarantined, [6fd9fec9413a73c319275b8e976ba15f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\23586, Quarantined, [e7615a6d7a01fa3c41a7449b4cb6f10f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [83c54681d0ab5dd94e9aeef10ef47c84],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\7359, Quarantined, [f751c205fc7fac8a7d6becf3fe0444bc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\OB, Quarantined, [2721d6f1ec8f33032eac5589b9495ea2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Speedchecker, Quarantined, [0840c403f784cf6761f6e327cf3447b9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Winportal, Quarantined, [96b2e6e1087338fe96ceb649d82a8080],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611191108}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644194408}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655195508}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666196608}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611191108}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110611191108}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKU\S-1-5-21-2306539700-457595284-510098243-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110611191108}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622192208}, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611191108}\INPROCSERVER32, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],

Registry Values: 4
Trojan.Agent.SCR, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, Quarantined, [4ff914b3f7841b1bd3b8e2189c666d93]
Trojan.Script, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|msopgrmuSrv, "C:\Windows\system32\msopgrmu.vbe" msrdxkbs msjocuxd, Quarantined, [67e1ac1b0378fd3940b63dd00df6b64a]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [65e3478066155fd7fccade07a2605aa6]
PUP.Optional.DataMangr.A, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER\APPCERTDLLS|x64, c:\program files\movies app\datamngr\x64\apcrtldr.dll, Quarantined, [96b24087e3984bebb02c98ad38cc3bc5]

Registry Data: 0
(No malicious items detected)

Folders: 11
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.Datamngr.A, C:\Users\BohouA!\AppData\LocalLow\DataMngr, Quarantined, [8bbd10b75f1c85b13285833bb54d5ba5],
PUP.Optional.CostMin.A, C:\ProgramData\CostMin, Quarantined, [bc8c96313249280ec39b31953bc703fd],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{42CC5C69-BF2B-4FBC-A7F3-E91DA610221C}, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1, Delete-on-Reboot, [5fe97f4878035bdb2cbd07d29d65e11f],

Files: 132
Trojan.BitMiner, C:\Program Files\PCData\dgen.exe, Delete-on-Reboot, [8eba4582374477bf1692ebc4c938aa56],
PUP.BitCoinMiner, C:\Windows\System32\lcpmncqtxm.exe, Delete-on-Reboot, [e167e1e63a413ff7184725f445bce41c],
PUP.BitCoinMiner, C:\Windows\System32\lcpmncwlpo.exe, Delete-on-Reboot, [a99f883fa2d9e84ec996d247917057a9],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho.dll, Quarantined, [0c3c487f5c1f32047d827226a95803fd],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker-bho.dll, Quarantined, [6cdcd4f3c9b28fa764a44f4c4cb58d73],
PUP.Optional.SoftwareUpdater, C:\Users\BohouA!\AppData\Local\1cdc1152-ac0b-425e-68bc-ea01bd8176d8\1cdc1152-ac0b-425e-68bc-ea01bd8176d8.exe, Quarantined, [4cfc1fa83942092d822adb9c13efab55],
PUP.Optional.Bitcoin, C:\Windows\System32\acumncqtxm.exe, Quarantined, [ed5be1e65427df57a76d466f71904ab6],
PUP.Optional.Bitcoin, C:\Windows\System32\acumncwlpo.exe, Quarantined, [0a3e7453e29915211cf86d48e91845bb],
Trojan.BitMiner, C:\Windows\System32\dcgmncqtxm.exe, Quarantined, [2820e2e5f685979fa86a477f5da4b848],
Trojan.BitMiner, C:\Windows\System32\dcgmncwlpo.exe, Quarantined, [fb4d24a3ed8e10263ed44d79788929d7],
PUP.Optional.SimpleFiles, C:\Windows\System32\Tasks\Update Service SimpleFiles, Quarantined, [d078794ecdae0f273977a737dd25817f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-1, Quarantined, [a1a77651017ab0862a974c9935cd31cf],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-11, Quarantined, [72d65770750646f07849776e0cf635cb],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-2, Quarantined, [83c5b61197e4221499284c993bc7629e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-4, Quarantined, [ab9daa1da3d8cd6990316d788d759a66],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-5, Quarantined, [192f37904a314aec17aa5e87fb07d62a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-1, Quarantined, [c583d9eeb8c347ef913085604db5e61a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-11, Quarantined, [41078b3c275443f312af638221e1ed13],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-2, Quarantined, [51f712b594e7a492ebd623c29b6704fc],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-4, Quarantined, [ed5b64631e5d5ed86c55f5f035cdaf51],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-5, Quarantined, [14341aad1f5c1e18e2dfc81de919bf41],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-1, Quarantined, [ba8e8b3c5f1cbc7ab908667f25dd956b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-10, Quarantined, [7acea4235e1d2c0a1aa7c421d9297b85],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-11, Quarantined, [63e527a0d2a9ce68bf02667f976b619f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-2, Quarantined, [66e20dba8cefa88ebf02e104af538c74],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-4, Quarantined, [f355794e3b400c2a328f549102007b85],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-5, Quarantined, [bb8d76510675d066f5cc9f46e91950b0],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\background.html, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c-11.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c-2.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c-4.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c-5.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c.crx, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\086576dd-9534-4021-9e67-f61985d34f4c.xpi, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\1293297481.mxaddon, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\159a54b7-c261-44ce-86ae-a1c7df36e3dc.crx, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\16554f49-14de-4597-a3a9-fc290f4b550a.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\23942c9e-4b9f-4c14-8b64-4e8d6148ec3c.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker-bg.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker-buttonutil.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker-buttonutil.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker-codedownloader.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Internet Speed Checker.ico, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Interop.IWshRuntimeLibrary.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Newtonsoft.Json.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\SuperSocket.ClientEngine.Common.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\SuperSocket.ClientEngine.Core.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\SuperSocket.ClientEngine.Protocol.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\Uninstall.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\utils.exe, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.Optional.InternetSpeedChecker.A, C:\Program Files\Internet Speed Checker\WebSocket4Net.dll, Quarantined, [56f2992e6d0e4fe7766a1ec94cb6c43c],
PUP.SoftwareUpdater.A, C:\Windows\System32\Tasks\AmiUpdXp, Quarantined, [77d18b3c710acf670577d812da28b848],
PUP.Optional.YourfileDownloader.A, C:\Windows\System32\Tasks\YourFile DownloaderUpdate, Quarantined, [c97fdfe8661581b5a8d69b4fff030ef2],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, Quarantined, [4ff914b3f7841b1bd3b8e2189c666d93],
Trojan.Script, C:\Windows\System32\msjocuxd.vbe, Quarantined, [75d3dfe8205b30064da9878609fa3ac6],
Trojan.Script, C:\Windows\System32\msopgrmu.vbe, Quarantined, [67e1ac1b0378fd3940b63dd00df6b64a],
Trojan.Script, C:\Windows\System32\msrdxkbs.vbe, Quarantined, [0246facd22597bbb1cda010c20e36799],
PUP.Software.Updater, C:\Windows\Tasks\AmiUpdXp.job, Quarantined, [1f290bbcc9b2979fd014a470a95a669a],
Malware.Trace, C:\Windows\inf\ntvdm.vbe, Quarantined, [5fe93394f18ab086d8c9a57fd92bd927],
Malware.Trace, C:\Windows\inf\ntvdm.inf, Quarantined, [8dbb07c0166542f43270899b986c629e],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-1.job, Quarantined, [440427a013688bab92aaa3a1bd47619f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-11.job, Quarantined, [8bbd596ef883a59198a444009371e21e],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-2.job, Quarantined, [d177c1066f0cbd7950ecad97dd270df3],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-4.job, Quarantined, [70d8cdfaa0db88ae1b21e361838116ea],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-5.job, Quarantined, [92b65a6dd7a4dc5a3606b292c83c34cc],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\086576dd-9534-4021-9e67-f61985d34f4c-5_user.job, Quarantined, [b890cafd661503334def4ef619eba759],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-1.job, Quarantined, [82c60eb9c6b586b019231e26c73ded13],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-11.job, Quarantined, [c0884582156659dd77c5b88c8480dc24],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-2.job, Quarantined, [91b721a6fa8141f5ba82d76dfe06a55b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-4.job, Quarantined, [06420bbcbfbc7abc48f41a2a11f338c8],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-5.job, Quarantined, [d27614b3a9d273c3dc60d86cb54f49b7],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\50779f3c-e2f9-4070-825c-a6dced59dd38-5_user.job, Quarantined, [440405c2cbb0f24451eb71d3a4605da3],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-1.job, Quarantined, [4107e9dea6d5d264ee4ea4a00afab749],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-10.job, Quarantined, [0b3d3f88d6a534022b117ec6b84c45bb],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-11.job, Quarantined, [2523f7d081fa48eeab91aa9a43c1738d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-2.job, Quarantined, [d96ffdcac6b5a98d1b21e06455af30d0],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-4.job, Quarantined, [a3a5f3d41863d3639e9ee36145bf08f8],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-5.job, Quarantined, [7bcd95327605142297a5d96be61e35cb],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [bd8b596e3843d16570e2083c44c07c84],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [43059a2dee8dac8a11427dc7659f9070],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [bc8cb512fe7de056aba95de7a65eeb15],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [b98f1aad582349edfb5ac18355aff50b],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\16554f49-14de-4597-a3a9-fc290f4b550a.job, Quarantined, [7ccc40874734ce68685dbb8b9f6504fc],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\23942c9e-4b9f-4c14-8b64-4e8d6148ec3c.job, Quarantined, [a3a505c29fdc270f586d66e053b11de3],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\382cd932-f57d-4d05-9619-28d485fa6a71.job, Quarantined, [4602e9dec9b205318d38f84e897b2dd3],
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\16554f49-14de-4597-a3a9-fc290f4b550a, Quarantined, [30184c7ba2d930061bab380e49bb629e],
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\382cd932-f57d-4d05-9619-28d485fa6a71, Quarantined, [2e1a319678035bdb586e281eeb190df3],
PUP.Optional.Datamngr.A, C:\Users\BohouA!\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64, Quarantined, [8bbd10b75f1c85b13285833bb54d5ba5],
PUP.Optional.CostMin.A, C:\ProgramData\CostMin\mHJ8XLUQ.dat, Quarantined, [bc8c96313249280ec39b31953bc703fd],
PUP.Optional.CostMin.A, C:\ProgramData\CostMin\mHJ8XLUQ.exe, Quarantined, [bc8c96313249280ec39b31953bc703fd],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\1293297481.mxaddon, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\360-42822.crx, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\42822.xpi, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\background.html, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-10.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-11.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-2.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-4.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-5.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5.crx, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bg.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6-codedownloader.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6.ico, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\Uninstall.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.ShopAndUp.A, C:\Program Files\Shop_an_Upi_1.6\utils.exe, Quarantined, [d0784285fb80ce6820f8349c28da20e0],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [f35511b6abd00c2ab4b5b2200101758b],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\1293297481.mxaddon, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\382cd932-f57d-4d05-9619-28d485fa6a71.exe, Delete-on-Reboot, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38-11.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38-2.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38-4.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38-5.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38.crx, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\50779f3c-e2f9-4070-825c-a6dced59dd38.xpi, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\51ec7fe7-8a6c-478c-899e-5ec35b4d1915.crx, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\background.html, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\SavePass 1.1-bg.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\SavePass 1.1-bho.dll, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\SavePass 1.1-codedownloader.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\SavePass 1.1.ico, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\Uninstall.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],
PUP.Optional.SavePass.A, C:\Program Files\SavePass 1.1\utils.exe, Quarantined, [5fe97f4878035bdb2cbd07d29d65e11f],

Physical Sectors: 0
(No malicious items detected)


(end)

# AdwCleaner v3.307 - Report created 17/08/2014 at 12:13:48
# Updated 17/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Bohouš - BOHOUŠ-PC
# Running from : D:\Stažené soubory\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : ProtectMonitor

***** [ Files / Folders ] *****

File Found : C:\Users\Bohouš\daemonprocess.txt
File Found : C:\Windows\system32\GroupPolicy\Machine\Registry.pol
Folder Found : C:\Program Files\FLVM Player
Folder Found : C:\Program Files\globalUpdate
Folder Found : C:\Program Files\goforfiles
Folder Found : C:\Program Files\Internet Speed Checker
Folder Found : C:\Program Files\MyPC Backup
Folder Found : C:\Program Files\SavePass 1.1
Folder Found : C:\Program Files\Shop_an_Upi_1.6
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\CostMin
Folder Found : C:\ProgramData\CostMin
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\Users\Administrator\AppData\Local\torch
Folder Found : C:\Users\Bohouš\AppData\Local\Babylon
Folder Found : C:\Users\Bohouš\AppData\Local\globalUpdate
Folder Found : C:\Users\Bohouš\AppData\Local\Mobogenie
Folder Found : C:\Users\Bohouš\AppData\Local\torch
Folder Found : C:\Users\Bohouš\AppData\LocalLow\DataMngr
Folder Found : C:\Users\Bohouš\AppData\LocalLow\Internet Speed Checker
Folder Found : C:\Users\Bohouš\AppData\Roaming\Babylon
Folder Found : C:\Users\Bohouš\AppData\Roaming\goforfiles
Folder Found : C:\Users\Bohouš\AppData\Roaming\SimpleFiles
Folder Found : C:\Users\Guest\AppData\Local\torch
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\torch

***** [ Scheduled Tasks ] *****

Task Found : AmiUpdXp
Task Found : globalUpdateUpdateTaskMachineCore
Task Found : globalUpdateUpdateTaskMachineUA
Task Found : GoforFilesUpdate
Task Found : LaunchSignup
Task Found : Update Service SimpleFiles
Task Found : YourFile DownloaderUpdate
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-1
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-11
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-2
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-4
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-5
Task Found : 086576dd-9534-4021-9e67-f61985d34f4c-5_user
Task Found : 16554f49-14de-4597-a3a9-fc290f4b550a
Task Found : 23942c9e-4b9f-4c14-8b64-4e8d6148ec3c
Task Found : 382cd932-f57d-4d05-9619-28d485fa6a71
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-1
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-11
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-2
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-4
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-5
Task Found : 50779f3c-e2f9-4070-825c-a6dced59dd38-5_user
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-1
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-10
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-11
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-2
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-4
Task Found : d8f74118-7758-4a73-8216-f3d5e66779f5-5

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\Internet Speed Checker
Key Found : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKCU\Software\AppDataLow\Software\Shop_an_Upi_1.6
Key Found : HKCU\Software\ExpressFiles
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\GoforFiles
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411281122}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611171152}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611191108}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411281122}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171152}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611191108}
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : HKCU\Software\SimpleFiles
Key Found : HKCU\Software\torch
Key Found : HKLM\SOFTWARE\b1.org
Key Found : HKLM\SOFTWARE\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411281122}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171152}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611191108}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422282222}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172252}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622192208}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CostMin.CostMin
Key Found : HKLM\SOFTWARE\Classes\CostMin.CostMin.2.2
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0042822.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0042822.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0042822.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0042822.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061752.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061752.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061752.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061752.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061908.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061908.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061908.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0061908.Sandbox.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455285522}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175552}
Key Found : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655195508}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466286622}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176652}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666196608}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440444284422}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440444284422}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174452}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174452}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644194408}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644194408}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Found : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\ExpressFiles
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\GoforFiles
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\Internet Speed Checker
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411281122}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191108}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Speed Checker
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Found : HKLM\SOFTWARE\SavePass 1.1
Key Found : HKLM\SOFTWARE\Shop_an_Upi_1.6
Key Found : HKLM\SOFTWARE\SimpleFiles
Key Found : HKLM\SOFTWARE\systweak
Key Found : HKLM\SOFTWARE\torch
Key Found : HKLM\SOFTWARE\YourFileDownloader
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.creativetoolbars.com/?src ... martbar&g=

-\\ Google Chrome v

[ File : C:\Users\Bohouš\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [17775 octets] - [17/08/2014 12:13:48]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [17836 octets] ##########

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola Logu

Příspěvekod jaro3 » 17 srp 2014 19:05

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 17 srp 2014 19:48

# AdwCleaner v3.307 - Report created 17/08/2014 at 19:19:31
# Updated 17/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Bohouš - BOHOUŠ-PC
# Running from : C:\Users\Bohouš\Desktop\AdwCleaner (3).exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : ProtectMonitor

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Program Files\FLVM Player
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\goforfiles
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Bohouš\AppData\Local\Babylon
Folder Deleted : C:\Users\Bohouš\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Bohouš\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Bohouš\AppData\Local\torch
Folder Deleted : C:\Users\Bohouš\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Bohouš\AppData\Roaming\goforfiles
Folder Deleted : C:\Users\Bohouš\AppData\Roaming\SimpleFiles
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
File Deleted : C:\Windows\system32\GroupPolicy\Machine\Registry.pol
File Deleted : C:\Users\Bohouš\daemonprocess.txt

***** [ Scheduled Tasks ] *****

Task Deleted : GoforFilesUpdate
Task Deleted : LaunchSignup
Task Deleted : Update Service SimpleFiles
Task Deleted : YourFile DownloaderUpdate

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\GoforFiles
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\SimpleFiles
Key Deleted : HKCU\Software\torch
Key Deleted : HKLM\SOFTWARE\b1.org
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\ExpressFiles
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\GoforFiles
Key Deleted : HKLM\SOFTWARE\SimpleFiles
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\torch
Key Deleted : HKLM\SOFTWARE\YourFileDownloader

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v36.0.1985.143

[ File : C:\Users\Bohouš\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.certified-toolbar.com?si= ... tid=592&q={searchTerms}

*************************

AdwCleaner[R0].txt - [17917 octets] - [17/08/2014 12:13:48]
AdwCleaner[R1].txt - [6181 octets] - [17/08/2014 19:18:00]
AdwCleaner[S0].txt - [6319 octets] - [17/08/2014 19:19:31]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6379 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Bohouç on ne 17.08.2014 at 19:26:38,74
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15E91EFE-BB4B-46F1-B818-7B817A1CD252}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{821E3663-2154-498A-91B5-F257F78BB99A}



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 17.08.2014 at 19:30:08,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RogueKiller V9.2.8.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Bohouš [Práva správce]
Mód : Kontrola -- Datum : 08/17/2014 19:44:52

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NALEZENO
[PUM.Policies] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NALEZENO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NALEZENO
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST340014A ATA Device +++++
--- User ---
[MBR] c739e60b57ac8abc11d8279d7a5ac0a7
[BSP] ab99cc4c3e011a3a9cca4b69a968049e : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 38063 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD5000AVDS-63U7B1 ATA Device +++++
--- User ---
[MBR] b4dd07df154ef37bcc0d73bbec167488
[BSP] 6a52188395639a4256825024f288b9ff : HP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK
User = LL2 ... OK

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola Logu

Příspěvekod jaro3 » 17 srp 2014 22:21

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:


- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)

- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 19 srp 2014 07:09

RogueKiller V9.2.8.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : Bohouš [Práva správce]
Mód : Odebrat -- Datum : 08/18/2014 07:20:16

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 11 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{3DCF8740-518D-40BD-940E-62F2FED3196D} | DhcpNameServer : 77.237.128.2 77.237.128.1 192.168.1.1 -> NAHRAZENO ()
[PUM.Policies] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> VYMAZÁNO
[PUM.Policies] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> VYMAZÁNO
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-2306539700-457595284-510098243-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST340014A ATA Device +++++
--- User ---
[MBR] c739e60b57ac8abc11d8279d7a5ac0a7
[BSP] ab99cc4c3e011a3a9cca4b69a968049e : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 38063 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD5000AVDS-63U7B1 ATA Device +++++
--- User ---
[MBR] b4dd07df154ef37bcc0d73bbec167488
[BSP] 6a52188395639a4256825024f288b9ff : HP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476937 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_08172014_194452.log - RKreport_SCN_08182014_071854.log

07:22:49.0114 0x0a44 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
07:22:52.0959 0x0a44 ============================================================
07:22:52.0959 0x0a44 Current date / time: 2014/08/18 07:22:52.0959
07:22:52.0959 0x0a44 SystemInfo:
07:22:52.0959 0x0a44
07:22:52.0959 0x0a44 OS Version: 6.1.7601 ServicePack: 1.0
07:22:52.0959 0x0a44 Product type: Workstation
07:22:52.0960 0x0a44 ComputerName: BOHOUŠ-PC
07:22:52.0960 0x0a44 UserName: Bohouš
07:22:52.0960 0x0a44 Windows directory: C:\Windows
07:22:52.0960 0x0a44 System windows directory: C:\Windows
07:22:52.0960 0x0a44 Processor architecture: Intel x86
07:22:52.0960 0x0a44 Number of processors: 2
07:22:52.0960 0x0a44 Page size: 0x1000
07:22:52.0960 0x0a44 Boot type: Normal boot
07:22:52.0960 0x0a44 ============================================================
07:22:54.0713 0x0a44 KLMD registered as C:\Windows\system32\drivers\47080278.sys
07:22:54.0977 0x0a44 System UUID: {21E92268-455E-7622-F0E4-2A1FFCAE6FA1}
07:22:55.0633 0x0a44 Drive \Device\Harddisk0\DR0 - Size: 0x9515A5E00 ( 37.27 Gb ), SectorSize: 0x200, Cylinders: 0x1431, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
07:22:55.0644 0x0a44 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
07:22:55.0649 0x0a44 ============================================================
07:22:55.0649 0x0a44 \Device\Harddisk0\DR0:
07:22:55.0650 0x0a44 MBR partitions:
07:22:55.0650 0x0a44 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
07:22:55.0650 0x0a44 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x4A57800
07:22:55.0650 0x0a44 \Device\Harddisk1\DR1:
07:22:55.0650 0x0a44 MBR partitions:
07:22:55.0650 0x0a44 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
07:22:55.0650 0x0a44 ============================================================
07:22:55.0705 0x0a44 C: <-> \Device\Harddisk0\DR0\Partition2
07:22:55.0746 0x0a44 D: <-> \Device\Harddisk1\DR1\Partition1
07:22:55.0746 0x0a44 ============================================================
07:22:55.0747 0x0a44 Initialize success
07:22:55.0747 0x0a44 ============================================================
07:23:16.0369 0x046c ============================================================
07:23:16.0369 0x046c Scan started
07:23:16.0369 0x046c Mode: Manual;
07:23:16.0369 0x046c ============================================================
07:23:16.0369 0x046c KSN ping started
07:23:18.0978 0x046c KSN ping finished: true
07:23:20.0119 0x046c ================ Scan system memory ========================
07:23:20.0119 0x046c System memory - ok
07:23:20.0119 0x046c ================ Scan services =============================
07:23:20.0478 0x046c [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
07:23:20.0478 0x046c 1394ohci - ok
07:23:20.0556 0x046c [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys
07:23:20.0556 0x046c ACPI - ok
07:23:20.0634 0x046c [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
07:23:20.0634 0x046c AcpiPmi - ok
07:23:20.0728 0x046c [ A6B6AB9502B63F43A9A56AE6AFB22078, DD1F0BA3D8F3333F52A71EAE3719A001F6EF844D647FFABF0E4C56C6C764ACA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
07:23:20.0728 0x046c AdobeFlashPlayerUpdateSvc - ok
07:23:20.0791 0x046c [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
07:23:20.0791 0x046c adp94xx - ok
07:23:20.0822 0x046c [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
07:23:20.0837 0x046c adpahci - ok
07:23:20.0869 0x046c [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
07:23:20.0869 0x046c adpu320 - ok
07:23:20.0900 0x046c [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
07:23:20.0900 0x046c AeLookupSvc - ok
07:23:20.0962 0x046c [ F81BB7E487EDCEAB630A7EE66CF23913, 7D1638FD7E388EF670FA0A421762E0413351058A20DDF0F9988A383F05395A68 ] AFD C:\Windows\system32\drivers\afd.sys
07:23:20.0962 0x046c AFD - ok
07:23:21.0009 0x046c [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
07:23:21.0009 0x046c agp440 - ok
07:23:21.0056 0x046c [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
07:23:21.0056 0x046c aic78xx - ok
07:23:21.0275 0x046c [ 7997B6F02CBDA0E31FA18CC85871B938, 1960717C0328ADCEDEEF281FB98E1DD899BFFF9FBEC025B732E20D9E9F3A956B ] ALCXWDM C:\Windows\system32\drivers\RTKVAC.SYS
07:23:21.0369 0x046c ALCXWDM - ok
07:23:21.0447 0x046c [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
07:23:21.0447 0x046c ALG - ok
07:23:21.0478 0x046c [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
07:23:21.0478 0x046c aliide - ok
07:23:21.0509 0x046c [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
07:23:21.0509 0x046c amdagp - ok
07:23:21.0556 0x046c [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys
07:23:21.0556 0x046c amdide - ok
07:23:21.0603 0x046c [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
07:23:21.0603 0x046c AmdK8 - ok
07:23:21.0681 0x046c [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
07:23:21.0681 0x046c AmdPPM - ok
07:23:21.0806 0x046c [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys
07:23:21.0806 0x046c amdsata - ok
07:23:21.0853 0x046c [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
07:23:21.0869 0x046c amdsbs - ok
07:23:21.0900 0x046c [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
07:23:21.0900 0x046c amdxata - ok
07:23:21.0947 0x046c [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID C:\Windows\system32\drivers\appid.sys
07:23:21.0947 0x046c AppID - ok
07:23:21.0994 0x046c [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll
07:23:21.0994 0x046c AppIDSvc - ok
07:23:22.0041 0x046c [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll
07:23:22.0041 0x046c Appinfo - ok
07:23:22.0103 0x046c [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll
07:23:22.0103 0x046c AppMgmt - ok
07:23:22.0134 0x046c [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
07:23:22.0134 0x046c arc - ok
07:23:22.0166 0x046c [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
07:23:22.0166 0x046c arcsas - ok
07:23:22.0384 0x046c [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
07:23:22.0400 0x046c aspnet_state - ok
07:23:22.0431 0x046c [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
07:23:22.0431 0x046c AsyncMac - ok
07:23:22.0462 0x046c [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
07:23:22.0462 0x046c atapi - ok
07:23:22.0697 0x046c [ 712D8A95E45B070114C5309ADA7358FF, 1F0285CFB9982637186531489743798511BA75B612B202231E9BC1CF5372C0BB ] atikmdag C:\Windows\system32\drivers\atikmdag.sys
07:23:22.0791 0x046c atikmdag - ok
07:23:22.0869 0x046c [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
07:23:22.0900 0x046c AudioEndpointBuilder - ok
07:23:22.0931 0x046c [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv C:\Windows\System32\Audiosrv.dll
07:23:22.0947 0x046c Audiosrv - ok
07:23:22.0994 0x046c [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll
07:23:22.0994 0x046c AxInstSV - ok
07:23:23.0056 0x046c [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
07:23:23.0056 0x046c b06bdrv - ok
07:23:23.0103 0x046c [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
07:23:23.0103 0x046c b57nd60x - ok
07:23:23.0166 0x046c [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
07:23:23.0166 0x046c BDESVC - ok
07:23:23.0197 0x046c [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
07:23:23.0197 0x046c Beep - ok
07:23:23.0259 0x046c [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll
07:23:23.0306 0x046c BFE - ok
07:23:23.0369 0x046c [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\System32\qmgr.dll
07:23:23.0400 0x046c BITS - ok
07:23:23.0431 0x046c [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
07:23:23.0431 0x046c blbdrive - ok
07:23:23.0478 0x046c [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
07:23:23.0478 0x046c bowser - ok
07:23:23.0494 0x046c [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
07:23:23.0509 0x046c BrFiltLo - ok
07:23:23.0509 0x046c [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
07:23:23.0509 0x046c BrFiltUp - ok
07:23:23.0556 0x046c [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll
07:23:23.0556 0x046c Browser - ok
07:23:23.0587 0x046c [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
07:23:23.0603 0x046c Brserid - ok
07:23:23.0619 0x046c [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
07:23:23.0634 0x046c BrSerWdm - ok
07:23:23.0634 0x046c [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
07:23:23.0634 0x046c BrUsbMdm - ok
07:23:23.0650 0x046c [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
07:23:23.0650 0x046c BrUsbSer - ok
07:23:23.0666 0x046c [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
07:23:23.0666 0x046c BTHMODEM - ok
07:23:23.0712 0x046c [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
07:23:23.0712 0x046c bthserv - ok
07:23:23.0744 0x046c [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
07:23:23.0744 0x046c cdfs - ok
07:23:23.0791 0x046c [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\drivers\cdrom.sys
07:23:23.0806 0x046c cdrom - ok
07:23:23.0837 0x046c [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
07:23:23.0837 0x046c CertPropSvc - ok
07:23:23.0884 0x046c [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
07:23:23.0884 0x046c circlass - ok
07:23:23.0916 0x046c [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys
07:23:23.0916 0x046c CLFS - ok
07:23:24.0041 0x046c [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
07:23:24.0041 0x046c clr_optimization_v2.0.50727_32 - ok
07:23:24.0087 0x046c [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
07:23:24.0134 0x046c clr_optimization_v4.0.30319_32 - ok
07:23:24.0150 0x046c [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
07:23:24.0150 0x046c CmBatt - ok
07:23:24.0197 0x046c [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
07:23:24.0197 0x046c cmdide - ok
07:23:24.0244 0x046c [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG C:\Windows\system32\Drivers\cng.sys
07:23:24.0244 0x046c CNG - ok
07:23:24.0291 0x046c [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
07:23:24.0291 0x046c Compbatt - ok
07:23:24.0306 0x046c [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
07:23:24.0306 0x046c CompositeBus - ok
07:23:24.0337 0x046c COMSysApp - ok
07:23:24.0369 0x046c [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
07:23:24.0369 0x046c crcdisk - ok
07:23:24.0416 0x046c [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc C:\Windows\system32\cryptsvc.dll
07:23:24.0416 0x046c CryptSvc - ok
07:23:24.0478 0x046c [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC C:\Windows\system32\drivers\csc.sys
07:23:24.0478 0x046c CSC - ok
07:23:24.0525 0x046c [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService C:\Windows\System32\cscsvc.dll
07:23:24.0556 0x046c CscService - ok
07:23:24.0619 0x046c [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll
07:23:24.0634 0x046c DcomLaunch - ok
07:23:24.0681 0x046c [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
07:23:24.0681 0x046c defragsvc - ok
07:23:24.0728 0x046c [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
07:23:24.0728 0x046c DfsC - ok
07:23:24.0775 0x046c [ 7F19DBA1A467B838CCB23124A2C55568, 9D7C81AD7C4AAC69E8B263029F292B46FD8BFF9721349C2AB8A111C8CB670BB2 ] DgiVecp C:\Windows\system32\Drivers\DgiVecp.sys
07:23:24.0775 0x046c DgiVecp - ok
07:23:24.0822 0x046c [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
07:23:24.0837 0x046c Dhcp - ok
07:23:24.0853 0x046c [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
07:23:24.0869 0x046c discache - ok
07:23:24.0900 0x046c [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
07:23:24.0900 0x046c Disk - ok
07:23:24.0931 0x046c [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll
07:23:24.0947 0x046c Dnscache - ok
07:23:25.0025 0x046c [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll
07:23:25.0041 0x046c dot3svc - ok
07:23:25.0103 0x046c [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
07:23:25.0103 0x046c DPS - ok
07:23:25.0181 0x046c [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
07:23:25.0181 0x046c drmkaud - ok
07:23:25.0228 0x046c [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
07:23:25.0244 0x046c DXGKrnl - ok
07:23:25.0291 0x046c [ 20DE769B84960606D8DBB2AEC123021A, 3099D99E5D107D9A7301A8521F09EB3FD19C0E934EC061850395BCC1A1279B88 ] E100B C:\Windows\system32\DRIVERS\e100b325.sys
07:23:25.0306 0x046c E100B - ok
07:23:25.0337 0x046c [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
07:23:25.0353 0x046c EapHost - ok
07:23:25.0509 0x046c [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
07:23:25.0587 0x046c ebdrv - ok
07:23:25.0634 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] EFS C:\Windows\System32\lsass.exe
07:23:25.0634 0x046c EFS - ok
07:23:25.0759 0x046c [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
07:23:25.0775 0x046c ehRecvr - ok
07:23:25.0806 0x046c [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
07:23:25.0806 0x046c ehSched - ok
07:23:25.0853 0x046c [ 44996A2ADDD2DB7454F2CA40B67D8941, 94BA62E95147B84CF6C564156824D8939F0F67EBBB5B87C70BAE3B1CA284DC8F ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
07:23:25.0869 0x046c ElbyCDIO - ok
07:23:25.0916 0x046c [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
07:23:25.0931 0x046c elxstor - ok
07:23:25.0962 0x046c [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
07:23:25.0962 0x046c ErrDev - ok
07:23:26.0025 0x046c [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
07:23:26.0056 0x046c EventSystem - ok
07:23:26.0072 0x046c [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
07:23:26.0087 0x046c exfat - ok
07:23:26.0119 0x046c [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
07:23:26.0119 0x046c fastfat - ok
07:23:26.0181 0x046c [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
07:23:26.0197 0x046c Fax - ok
07:23:26.0228 0x046c [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
07:23:26.0228 0x046c fdc - ok
07:23:26.0244 0x046c [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
07:23:26.0244 0x046c fdPHost - ok
07:23:26.0259 0x046c [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
07:23:26.0259 0x046c FDResPub - ok
07:23:26.0291 0x046c [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
07:23:26.0291 0x046c FileInfo - ok
07:23:26.0306 0x046c [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
07:23:26.0306 0x046c Filetrace - ok
07:23:26.0322 0x046c [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
07:23:26.0322 0x046c flpydisk - ok
07:23:26.0337 0x046c [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
07:23:26.0353 0x046c FltMgr - ok
07:23:26.0431 0x046c [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache C:\Windows\system32\FntCache.dll
07:23:26.0478 0x046c FontCache - ok
07:23:26.0541 0x046c [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
07:23:26.0541 0x046c FontCache3.0.0.0 - ok
07:23:26.0572 0x046c [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
07:23:26.0572 0x046c FsDepends - ok
07:23:26.0619 0x046c [ B0082808A6856A252F7CDD939892CE50, 3A069239629C4F54049A2CFC6642AC5102ECEAA74470BAA9DDB1AB108D1060EE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
07:23:26.0619 0x046c fssfltr - ok
07:23:26.0666 0x046c [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
07:23:26.0666 0x046c Fs_Rec - ok
07:23:26.0697 0x046c [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
07:23:26.0712 0x046c fvevol - ok
07:23:26.0744 0x046c [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
07:23:26.0744 0x046c gagp30kx - ok
07:23:26.0806 0x046c [ 93CA4D9A0433BE0EDD0B9F2F26D5E54C, ACD6BBB639CAF092809927F84F5693B7BA11080684A4993029D713ACF67D4C79 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
07:23:26.0806 0x046c ggflt - ok
07:23:26.0837 0x046c [ 17E678AAB82CCDFB80E7614504933895, 43935C8C5C30DA415957B789DC9FA10721C240C603DC8733D9B791A2F58BE1BD ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
07:23:26.0837 0x046c ggsemc - ok
07:23:26.0900 0x046c [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
07:23:26.0931 0x046c gpsvc - ok
07:23:27.0087 0x046c [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
07:23:27.0087 0x046c gupdate - ok
07:23:27.0134 0x046c [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
07:23:27.0134 0x046c gupdatem - ok
07:23:27.0197 0x046c [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
07:23:27.0197 0x046c hcw85cir - ok
07:23:27.0228 0x046c [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
07:23:27.0228 0x046c HDAudBus - ok
07:23:27.0259 0x046c [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
07:23:27.0259 0x046c HidBatt - ok
07:23:27.0275 0x046c [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
07:23:27.0275 0x046c HidBth - ok
07:23:27.0291 0x046c [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
07:23:27.0291 0x046c HidIr - ok
07:23:27.0322 0x046c [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll
07:23:27.0322 0x046c hidserv - ok
07:23:27.0369 0x046c [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
07:23:27.0369 0x046c HidUsb - ok
07:23:27.0400 0x046c [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
07:23:27.0416 0x046c hkmsvc - ok
07:23:27.0462 0x046c [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
07:23:27.0462 0x046c HomeGroupListener - ok
07:23:27.0509 0x046c [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
07:23:27.0525 0x046c HomeGroupProvider - ok
07:23:27.0572 0x046c [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
07:23:27.0572 0x046c HpSAMD - ok
07:23:27.0650 0x046c [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP C:\Windows\system32\drivers\HTTP.sys
07:23:27.0650 0x046c HTTP - ok
07:23:27.0697 0x046c [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
07:23:27.0697 0x046c hwpolicy - ok
07:23:27.0759 0x046c [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
07:23:27.0759 0x046c i8042prt - ok
07:23:27.0822 0x046c [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
07:23:27.0822 0x046c iaStorV - ok
07:23:27.0931 0x046c [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED5C300770B554C4E4794F66BB7 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
07:23:27.0947 0x046c idsvc - ok
07:23:27.0978 0x046c IEEtwCollectorService - ok
07:23:28.0025 0x046c [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
07:23:28.0025 0x046c iirsp - ok
07:23:28.0087 0x046c [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\Windows\System32\ikeext.dll
07:23:28.0119 0x046c IKEEXT - ok
07:23:28.0166 0x046c [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
07:23:28.0166 0x046c intelide - ok
07:23:28.0212 0x046c [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
07:23:28.0212 0x046c intelppm - ok
07:23:28.0244 0x046c [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
07:23:28.0259 0x046c IPBusEnum - ok
07:23:28.0259 0x046c [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
07:23:28.0275 0x046c IpFilterDriver - ok
07:23:28.0322 0x046c [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
07:23:28.0353 0x046c iphlpsvc - ok
07:23:28.0400 0x046c [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
07:23:28.0400 0x046c IPMIDRV - ok
07:23:28.0431 0x046c [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
07:23:28.0447 0x046c IPNAT - ok
07:23:28.0462 0x046c [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
07:23:28.0462 0x046c IRENUM - ok
07:23:28.0494 0x046c [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
07:23:28.0494 0x046c isapnp - ok
07:23:28.0525 0x046c [ CB7A9ABB12B8415BCE5D74994C7BA3AE, 464BFF3F5EEE985BE075E23E1813F5CB82A9A0771A92C6D889B13B867BCDF647 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
07:23:28.0541 0x046c iScsiPrt - ok
07:23:28.0572 0x046c [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
07:23:28.0572 0x046c kbdclass - ok
07:23:28.0634 0x046c [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
07:23:28.0634 0x046c kbdhid - ok
07:23:28.0650 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] KeyIso C:\Windows\system32\lsass.exe
07:23:28.0650 0x046c KeyIso - ok
07:23:28.0697 0x046c [ F286830298323272260332D6ABC905C1, FF4CD182A95CA53119B228690D682EE9214BE131A0DBCB09B6189FBEBBFF902C ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
07:23:28.0697 0x046c KSecDD - ok
07:23:28.0728 0x046c [ D7C760D57B1656DD748B9E4AB6CB5A51, F8AE4185A6A9F7005DEFF1FDC03F395C6189825B482B8C650637FD29DE93AB68 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
07:23:28.0728 0x046c KSecPkg - ok
07:23:28.0791 0x046c [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
07:23:28.0806 0x046c KtmRm - ok
07:23:28.0837 0x046c [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\system32\srvsvc.dll
07:23:28.0853 0x046c LanmanServer - ok
07:23:28.0884 0x046c [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
07:23:28.0884 0x046c LanmanWorkstation - ok
07:23:28.0947 0x046c [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
07:23:28.0947 0x046c lltdio - ok
07:23:28.0978 0x046c [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
07:23:28.0994 0x046c lltdsvc - ok
07:23:29.0009 0x046c [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
07:23:29.0009 0x046c lmhosts - ok
07:23:29.0041 0x046c [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
07:23:29.0041 0x046c LSI_FC - ok
07:23:29.0072 0x046c [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
07:23:29.0087 0x046c LSI_SAS - ok
07:23:29.0087 0x046c [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
07:23:29.0103 0x046c LSI_SAS2 - ok
07:23:29.0119 0x046c [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
07:23:29.0119 0x046c LSI_SCSI - ok
07:23:29.0150 0x046c [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
07:23:29.0150 0x046c luafv - ok
07:23:29.0181 0x046c [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
07:23:29.0181 0x046c Mcx2Svc - ok
07:23:29.0228 0x046c [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
07:23:29.0228 0x046c megasas - ok
07:23:29.0259 0x046c [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
07:23:29.0259 0x046c MegaSR - ok
07:23:29.0384 0x046c Microsoft SharePoint Workspace Audit Service - ok
07:23:29.0416 0x046c [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
07:23:29.0416 0x046c MMCSS - ok
07:23:29.0447 0x046c [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
07:23:29.0447 0x046c Modem - ok
07:23:29.0478 0x046c [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
07:23:29.0478 0x046c monitor - ok
07:23:29.0525 0x046c [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
07:23:29.0525 0x046c mouclass - ok
07:23:29.0572 0x046c [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
07:23:29.0587 0x046c mouhid - ok
07:23:29.0619 0x046c [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
07:23:29.0634 0x046c mountmgr - ok
07:23:29.0681 0x046c [ E77DC03DD3C8E5A388BF9EED2A28F3D1, ED0DAA975D1EC35CE036F02596218E15CC6A054167628D12A0A5AD91B841F422 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
07:23:29.0681 0x046c MpFilter - ok
07:23:29.0712 0x046c [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys
07:23:29.0712 0x046c mpio - ok
07:23:29.0744 0x046c [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
07:23:29.0759 0x046c mpsdrv - ok
07:23:29.0822 0x046c [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll
07:23:29.0837 0x046c MpsSvc - ok
07:23:29.0900 0x046c [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
07:23:29.0900 0x046c MRxDAV - ok
07:23:29.0947 0x046c [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
07:23:29.0947 0x046c mrxsmb - ok
07:23:29.0962 0x046c [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
07:23:29.0978 0x046c mrxsmb10 - ok
07:23:29.0994 0x046c [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
07:23:29.0994 0x046c mrxsmb20 - ok
07:23:30.0041 0x046c [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys
07:23:30.0041 0x046c msahci - ok
07:23:30.0072 0x046c [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys
07:23:30.0072 0x046c msdsm - ok
07:23:30.0103 0x046c [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
07:23:30.0103 0x046c MSDTC - ok
07:23:30.0150 0x046c [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
07:23:30.0150 0x046c Msfs - ok
07:23:30.0166 0x046c [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
07:23:30.0166 0x046c mshidkmdf - ok
07:23:30.0212 0x046c [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
07:23:30.0212 0x046c msisadrv - ok
07:23:30.0259 0x046c [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
07:23:30.0259 0x046c MSiSCSI - ok
07:23:30.0275 0x046c msiserver - ok
07:23:30.0306 0x046c [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
07:23:30.0306 0x046c MSKSSRV - ok
07:23:30.0384 0x046c [ B0F49DA36F30922F5DDC3B623B778FCE, EE025AEFA4A2095AFEABFB3A49639DA77D78068A3F5EEDA6C15D34853AFD5609 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
07:23:30.0384 0x046c MsMpSvc - ok
07:23:30.0416 0x046c [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
07:23:30.0416 0x046c MSPCLOCK - ok
07:23:30.0431 0x046c [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
07:23:30.0431 0x046c MSPQM - ok
07:23:30.0447 0x046c [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
07:23:30.0462 0x046c MsRPC - ok
07:23:30.0494 0x046c [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
07:23:30.0494 0x046c mssmbios - ok
07:23:30.0541 0x046c [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
07:23:30.0541 0x046c MSTEE - ok
07:23:30.0556 0x046c [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
07:23:30.0556 0x046c MTConfig - ok
07:23:30.0572 0x046c [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
07:23:30.0572 0x046c Mup - ok
07:23:30.0619 0x046c [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll
07:23:30.0634 0x046c napagent - ok
07:23:30.0681 0x046c [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
07:23:30.0697 0x046c NativeWifiP - ok
07:23:30.0712 0x046c nawnyute - ok
07:23:30.0791 0x046c [ E7C54812A2AAF43316EB6930C1FFA108, C8A6FC1957FA29A3B372132FEA9145538BC767044A11D77316D3D1A3EAA60630 ] NDIS C:\Windows\system32\drivers\ndis.sys
07:23:30.0806 0x046c NDIS - ok
07:23:30.0837 0x046c [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
07:23:30.0837 0x046c NdisCap - ok
07:23:30.0869 0x046c [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
07:23:30.0869 0x046c NdisTapi - ok
07:23:30.0900 0x046c [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
07:23:30.0900 0x046c Ndisuio - ok
07:23:30.0947 0x046c [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
07:23:30.0947 0x046c NdisWan - ok
07:23:30.0994 0x046c [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
07:23:30.0994 0x046c NDProxy - ok
07:23:31.0056 0x046c [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
07:23:31.0056 0x046c NetBIOS - ok
07:23:31.0087 0x046c [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
07:23:31.0103 0x046c NetBT - ok
07:23:31.0134 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] Netlogon C:\Windows\system32\lsass.exe
07:23:31.0134 0x046c Netlogon - ok
07:23:31.0181 0x046c [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
07:23:31.0197 0x046c Netman - ok
07:23:31.0244 0x046c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
07:23:31.0244 0x046c NetMsmqActivator - ok
07:23:31.0259 0x046c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
07:23:31.0275 0x046c NetPipeActivator - ok
07:23:31.0322 0x046c [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
07:23:31.0337 0x046c netprofm - ok
07:23:31.0384 0x046c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
07:23:31.0384 0x046c NetTcpActivator - ok
07:23:31.0400 0x046c [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
07:23:31.0400 0x046c NetTcpPortSharing - ok
07:23:31.0447 0x046c [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
07:23:31.0447 0x046c nfrd960 - ok
07:23:31.0494 0x046c [ 32FF06EC6D946EF791D98D6C838A3090, 319BDD491CB22D0CCCCE76A2854CF469D7AF046289F9C56CD03AE3D3CBC0275E ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
07:23:31.0494 0x046c NisDrv - ok
07:23:31.0525 0x046c [ 42D33042371BFB1A7D40834590CAFD30, 53DA3618EC10293B2DF686E291A4EF6ACBBD41D116EC762D54106D201A784E87 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
07:23:31.0541 0x046c NisSrv - ok
07:23:31.0572 0x046c [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc C:\Windows\System32\nlasvc.dll
07:23:31.0587 0x046c NlaSvc - ok
07:23:31.0603 0x046c [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
07:23:31.0603 0x046c Npfs - ok
07:23:31.0634 0x046c [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
07:23:31.0634 0x046c nsi - ok
07:23:31.0650 0x046c [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
07:23:31.0650 0x046c nsiproxy - ok
07:23:31.0744 0x046c [ 5E43D2B0EE64123D4880DFA6626DEFDE, 164413A22DE58B19EA2B4120034B46D6BE1F424B80C3421E10BE5C81153D049F ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
07:23:31.0775 0x046c Ntfs - ok
07:23:31.0806 0x046c [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
07:23:31.0806 0x046c Null - ok
07:23:31.0853 0x046c [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys
07:23:31.0869 0x046c nvraid - ok
07:23:31.0884 0x046c [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
07:23:31.0884 0x046c nvstor - ok
07:23:31.0931 0x046c [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
07:23:31.0931 0x046c nv_agp - ok
07:23:31.0978 0x046c [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
0

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 19 srp 2014 07:11

07:23:32.0041 0x046c [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
07:23:32.0056 0x046c ose - ok
07:23:32.0322 0x046c [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
07:23:32.0431 0x046c osppsvc - ok
07:23:32.0494 0x046c [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
07:23:32.0509 0x046c p2pimsvc - ok
07:23:32.0541 0x046c [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
07:23:32.0556 0x046c p2psvc - ok
07:23:32.0587 0x046c [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
07:23:32.0587 0x046c Parport - ok
07:23:32.0634 0x046c [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys
07:23:32.0634 0x046c partmgr - ok
07:23:32.0650 0x046c [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
07:23:32.0666 0x046c Parvdm - ok
07:23:32.0697 0x046c [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
07:23:32.0697 0x046c PcaSvc - ok
07:23:32.0728 0x046c [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
07:23:32.0744 0x046c pci - ok
07:23:32.0775 0x046c [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
07:23:32.0775 0x046c pciide - ok
07:23:32.0806 0x046c [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
07:23:32.0822 0x046c pcmcia - ok
07:23:32.0837 0x046c [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
07:23:32.0837 0x046c pcw - ok
07:23:32.0900 0x046c [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
07:23:32.0916 0x046c PEAUTH - ok
07:23:32.0994 0x046c [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
07:23:33.0056 0x046c PeerDistSvc - ok
07:23:33.0181 0x046c [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
07:23:33.0259 0x046c pla - ok
07:23:33.0322 0x046c [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
07:23:33.0337 0x046c PlugPlay - ok
07:23:33.0369 0x046c [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
07:23:33.0369 0x046c PNRPAutoReg - ok
07:23:33.0400 0x046c [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
07:23:33.0400 0x046c PNRPsvc - ok
07:23:33.0462 0x046c [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
07:23:33.0478 0x046c PolicyAgent - ok
07:23:33.0541 0x046c [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
07:23:33.0541 0x046c Power - ok
07:23:33.0587 0x046c [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
07:23:33.0587 0x046c PptpMiniport - ok
07:23:33.0619 0x046c [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
07:23:33.0619 0x046c Processor - ok
07:23:33.0650 0x046c [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc C:\Windows\system32\profsvc.dll
07:23:33.0666 0x046c ProfSvc - ok
07:23:33.0681 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] ProtectedStorage C:\Windows\system32\lsass.exe
07:23:33.0681 0x046c ProtectedStorage - ok
07:23:33.0728 0x046c [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
07:23:33.0728 0x046c Psched - ok
07:23:33.0806 0x046c [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
07:23:33.0837 0x046c ql2300 - ok
07:23:33.0869 0x046c [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
07:23:33.0869 0x046c ql40xx - ok
07:23:33.0916 0x046c [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
07:23:33.0916 0x046c QWAVE - ok
07:23:33.0931 0x046c [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
07:23:33.0931 0x046c QWAVEdrv - ok
07:23:33.0962 0x046c [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
07:23:33.0962 0x046c RasAcd - ok
07:23:33.0994 0x046c [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
07:23:33.0994 0x046c RasAgileVpn - ok
07:23:34.0025 0x046c [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
07:23:34.0041 0x046c RasAuto - ok
07:23:34.0072 0x046c [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
07:23:34.0072 0x046c Rasl2tp - ok
07:23:34.0119 0x046c [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
07:23:34.0134 0x046c RasMan - ok
07:23:34.0166 0x046c [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
07:23:34.0166 0x046c RasPppoe - ok
07:23:34.0197 0x046c [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
07:23:34.0197 0x046c RasSstp - ok
07:23:34.0244 0x046c [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
07:23:34.0244 0x046c rdbss - ok
07:23:34.0275 0x046c [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
07:23:34.0275 0x046c rdpbus - ok
07:23:34.0322 0x046c [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
07:23:34.0322 0x046c RDPCDD - ok
07:23:34.0384 0x046c [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
07:23:34.0384 0x046c RDPDR - ok
07:23:34.0431 0x046c [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
07:23:34.0431 0x046c RDPENCDD - ok
07:23:34.0447 0x046c [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
07:23:34.0447 0x046c RDPREFMP - ok
07:23:34.0494 0x046c [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
07:23:34.0494 0x046c RdpVideoMiniport - ok
07:23:34.0541 0x046c [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
07:23:34.0541 0x046c RDPWD - ok
07:23:34.0603 0x046c [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
07:23:34.0603 0x046c rdyboost - ok
07:23:34.0650 0x046c [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
07:23:34.0650 0x046c RemoteAccess - ok
07:23:34.0681 0x046c [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
07:23:34.0697 0x046c RemoteRegistry - ok
07:23:34.0712 0x046c [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
07:23:34.0712 0x046c RpcEptMapper - ok
07:23:34.0744 0x046c [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
07:23:34.0744 0x046c RpcLocator - ok
07:23:34.0791 0x046c [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
07:23:34.0806 0x046c RpcSs - ok
07:23:34.0853 0x046c [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
07:23:34.0853 0x046c rspndr - ok
07:23:34.0900 0x046c [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys
07:23:34.0900 0x046c s3cap - ok
07:23:34.0916 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] SamSs C:\Windows\system32\lsass.exe
07:23:34.0916 0x046c SamSs - ok
07:23:34.0962 0x046c [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
07:23:34.0962 0x046c sbp2port - ok
07:23:35.0009 0x046c [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
07:23:35.0025 0x046c SCardSvr - ok
07:23:35.0056 0x046c [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
07:23:35.0056 0x046c scfilter - ok
07:23:35.0134 0x046c [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
07:23:35.0166 0x046c Schedule - ok
07:23:35.0197 0x046c [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
07:23:35.0197 0x046c SCPolicySvc - ok
07:23:35.0244 0x046c [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
07:23:35.0259 0x046c SDRSVC - ok
07:23:35.0291 0x046c [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
07:23:35.0291 0x046c secdrv - ok
07:23:35.0322 0x046c [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
07:23:35.0322 0x046c seclogon - ok
07:23:35.0337 0x046c [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll
07:23:35.0337 0x046c SENS - ok
07:23:35.0369 0x046c [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
07:23:35.0384 0x046c SensrSvc - ok
07:23:35.0416 0x046c [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
07:23:35.0416 0x046c Serenum - ok
07:23:35.0447 0x046c [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
07:23:35.0447 0x046c Serial - ok
07:23:35.0478 0x046c [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
07:23:35.0478 0x046c sermouse - ok
07:23:35.0541 0x046c [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
07:23:35.0556 0x046c SessionEnv - ok
07:23:35.0603 0x046c [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
07:23:35.0603 0x046c sffdisk - ok
07:23:35.0619 0x046c [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
07:23:35.0619 0x046c sffp_mmc - ok
07:23:35.0650 0x046c [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
07:23:35.0666 0x046c sffp_sd - ok
07:23:35.0697 0x046c [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
07:23:35.0697 0x046c sfloppy - ok
07:23:35.0744 0x046c [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
07:23:35.0759 0x046c SharedAccess - ok
07:23:35.0791 0x046c [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
07:23:35.0806 0x046c ShellHWDetection - ok
07:23:35.0837 0x046c [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
07:23:35.0837 0x046c sisagp - ok
07:23:35.0884 0x046c [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
07:23:35.0884 0x046c SiSRaid2 - ok
07:23:35.0900 0x046c [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
07:23:35.0900 0x046c SiSRaid4 - ok
07:23:35.0916 0x046c [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
07:23:35.0931 0x046c Smb - ok
07:23:35.0962 0x046c [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
07:23:35.0962 0x046c SNMPTRAP - ok
07:23:36.0103 0x046c [ 3A4F2C0BB87A0895ABEBA341AA1E341B, 4DADEEF3C5D181502D6F4A00FBBF3B001FA626E49569FB330D7AE2955CC7DE08 ] Sony PC Companion C:\Program Files\Sony\Sony PC Companion\PCCService.exe
07:23:36.0103 0x046c Sony PC Companion - ok
07:23:36.0134 0x046c [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
07:23:36.0134 0x046c spldr - ok
07:23:36.0181 0x046c [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe
07:23:36.0197 0x046c Spooler - ok
07:23:36.0369 0x046c [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
07:23:36.0541 0x046c sppsvc - ok
07:23:36.0603 0x046c [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
07:23:36.0603 0x046c sppuinotify - ok
07:23:36.0650 0x046c [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys
07:23:36.0666 0x046c srv - ok
07:23:36.0697 0x046c [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
07:23:36.0697 0x046c srv2 - ok
07:23:36.0728 0x046c [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
07:23:36.0728 0x046c srvnet - ok
07:23:36.0775 0x046c [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
07:23:36.0775 0x046c SSDPSRV - ok
07:23:36.0806 0x046c [ EF3458337D7341A05169CEFC73709264, C9D0AE966CFA02F7B72586C2A6E2AFA9818C9F4856A4E9625B79BC5A886FC193 ] SSPORT C:\Windows\system32\Drivers\SSPORT.sys
07:23:36.0806 0x046c SSPORT - ok
07:23:36.0837 0x046c [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
07:23:36.0837 0x046c SstpSvc - ok
07:23:36.0869 0x046c [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
07:23:36.0869 0x046c stexstor - ok
07:23:36.0931 0x046c [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
07:23:36.0947 0x046c StiSvc - ok
07:23:36.0978 0x046c [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys
07:23:36.0978 0x046c storflt - ok
07:23:37.0025 0x046c [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys
07:23:37.0025 0x046c storvsc - ok
07:23:37.0072 0x046c [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
07:23:37.0072 0x046c swenum - ok
07:23:37.0119 0x046c [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
07:23:37.0134 0x046c swprv - ok
07:23:37.0166 0x046c Synth3dVsc - ok
07:23:37.0244 0x046c [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
07:23:37.0291 0x046c SysMain - ok
07:23:37.0353 0x046c [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
07:23:37.0353 0x046c TabletInputService - ok
07:23:37.0400 0x046c [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
07:23:37.0416 0x046c TapiSrv - ok
07:23:37.0447 0x046c [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
07:23:37.0462 0x046c TBS - ok
07:23:37.0556 0x046c [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] Tcpip C:\Windows\system32\drivers\tcpip.sys
07:23:37.0587 0x046c Tcpip - ok
07:23:37.0697 0x046c [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
07:23:37.0728 0x046c TCPIP6 - ok
07:23:37.0775 0x046c [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
07:23:37.0791 0x046c tcpipreg - ok
07:23:37.0822 0x046c [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
07:23:37.0822 0x046c TDPIPE - ok
07:23:37.0837 0x046c [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
07:23:37.0837 0x046c TDTCP - ok
07:23:37.0884 0x046c [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
07:23:37.0884 0x046c tdx - ok
07:23:37.0916 0x046c [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
07:23:37.0916 0x046c TermDD - ok
07:23:37.0978 0x046c [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService C:\Windows\System32\termsrv.dll
07:23:38.0009 0x046c TermService - ok
07:23:38.0041 0x046c [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
07:23:38.0056 0x046c Themes - ok
07:23:38.0072 0x046c [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
07:23:38.0072 0x046c THREADORDER - ok
07:23:38.0103 0x046c [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
07:23:38.0103 0x046c TrkWks - ok
07:23:38.0166 0x046c [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
07:23:38.0166 0x046c TrustedInstaller - ok
07:23:38.0212 0x046c [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
07:23:38.0212 0x046c tssecsrv - ok
07:23:38.0259 0x046c [ 9CE253214ACAA5A7D323327D2055EFAA, 15E7DB578EDF36DD2FD5BA960C3941B2353037323B6B96702CDCDC07588EA724 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
07:23:38.0259 0x046c TsUsbFlt - ok
07:23:38.0259 0x046c tsusbhub - ok
07:23:38.0322 0x046c [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
07:23:38.0322 0x046c tunnel - ok
07:23:38.0353 0x046c [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
07:23:38.0353 0x046c uagp35 - ok
07:23:38.0384 0x046c [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
07:23:38.0400 0x046c udfs - ok
07:23:38.0447 0x046c [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
07:23:38.0447 0x046c UI0Detect - ok
07:23:38.0478 0x046c [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
07:23:38.0494 0x046c uliagpkx - ok
07:23:38.0541 0x046c [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
07:23:38.0541 0x046c umbus - ok
07:23:38.0572 0x046c [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
07:23:38.0572 0x046c UmPass - ok
07:23:38.0619 0x046c [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll
07:23:38.0634 0x046c UmRdpService - ok
07:23:38.0681 0x046c [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
07:23:38.0697 0x046c upnphost - ok
07:23:38.0728 0x046c [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
07:23:38.0744 0x046c usbccgp - ok
07:23:38.0791 0x046c [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
07:23:38.0791 0x046c usbcir - ok
07:23:38.0837 0x046c [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
07:23:38.0837 0x046c usbehci - ok
07:23:38.0884 0x046c [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
07:23:38.0884 0x046c usbhub - ok
07:23:38.0931 0x046c [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\drivers\usbohci.sys
07:23:38.0931 0x046c usbohci - ok
07:23:38.0978 0x046c [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
07:23:38.0978 0x046c usbprint - ok
07:23:39.0009 0x046c [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
07:23:39.0009 0x046c USBSTOR - ok
07:23:39.0056 0x046c [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
07:23:39.0056 0x046c usbuhci - ok
07:23:39.0087 0x046c [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
07:23:39.0087 0x046c UxSms - ok
07:23:39.0119 0x046c [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] VaultSvc C:\Windows\system32\lsass.exe
07:23:39.0119 0x046c VaultSvc - ok
07:23:39.0166 0x046c [ 94D73B62E458FB56C9CE60AA96D914F9, EF0FAC91A1207DA28600000141C26686A7BD6B70EE05F5B78459D3D615454151 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
07:23:39.0166 0x046c VClone - ok
07:23:39.0212 0x046c [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
07:23:39.0212 0x046c vdrvroot - ok
07:23:39.0275 0x046c [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
07:23:39.0291 0x046c vds - ok
07:23:39.0322 0x046c [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
07:23:39.0337 0x046c vga - ok
07:23:39.0337 0x046c [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
07:23:39.0337 0x046c VgaSave - ok
07:23:39.0353 0x046c VGPU - ok
07:23:39.0384 0x046c [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
07:23:39.0400 0x046c vhdmp - ok
07:23:39.0431 0x046c [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
07:23:39.0431 0x046c viaagp - ok
07:23:39.0462 0x046c [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
07:23:39.0462 0x046c ViaC7 - ok
07:23:39.0509 0x046c [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
07:23:39.0509 0x046c viaide - ok
07:23:39.0556 0x046c [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys
07:23:39.0556 0x046c vmbus - ok
07:23:39.0603 0x046c [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
07:23:39.0603 0x046c VMBusHID - ok
07:23:39.0650 0x046c [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
07:23:39.0650 0x046c volmgr - ok
07:23:39.0697 0x046c [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
07:23:39.0697 0x046c volmgrx - ok
07:23:39.0728 0x046c [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
07:23:39.0744 0x046c volsnap - ok
07:23:39.0791 0x046c [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
07:23:39.0791 0x046c vsmraid - ok
07:23:39.0869 0x046c [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
07:23:39.0900 0x046c VSS - ok
07:23:39.0916 0x046c [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
07:23:39.0916 0x046c vwifibus - ok
07:23:39.0962 0x046c [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
07:23:39.0978 0x046c W32Time - ok
07:23:40.0009 0x046c [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
07:23:40.0025 0x046c WacomPen - ok
07:23:40.0056 0x046c [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
07:23:40.0056 0x046c WANARP - ok
07:23:40.0072 0x046c [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
07:23:40.0072 0x046c Wanarpv6 - ok
07:23:40.0181 0x046c [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
07:23:40.0212 0x046c WatAdminSvc - ok
07:23:40.0306 0x046c [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
07:23:40.0337 0x046c wbengine - ok
07:23:40.0384 0x046c [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
07:23:40.0384 0x046c WbioSrvc - ok
07:23:40.0447 0x046c [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
07:23:40.0462 0x046c wcncsvc - ok
07:23:40.0494 0x046c [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
07:23:40.0494 0x046c WcsPlugInService - ok
07:23:40.0525 0x046c [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
07:23:40.0525 0x046c Wd - ok
07:23:40.0587 0x046c [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
07:23:40.0587 0x046c Wdf01000 - ok
07:23:40.0634 0x046c [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
07:23:40.0650 0x046c WdiServiceHost - ok
07:23:40.0666 0x046c [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
07:23:40.0666 0x046c WdiSystemHost - ok
07:23:40.0712 0x046c [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll
07:23:40.0712 0x046c WebClient - ok
07:23:40.0744 0x046c [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
07:23:40.0759 0x046c Wecsvc - ok
07:23:40.0775 0x046c [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
07:23:40.0775 0x046c wercplsupport - ok
07:23:40.0822 0x046c [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
07:23:40.0837 0x046c WerSvc - ok
07:23:40.0869 0x046c [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
07:23:40.0869 0x046c WfpLwf - ok
07:23:40.0884 0x046c [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
07:23:40.0884 0x046c WIMMount - ok
07:23:40.0962 0x046c [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
07:23:40.0994 0x046c WinDefend - ok
07:23:41.0041 0x046c WinHttpAutoProxySvc - ok
07:23:41.0150 0x046c [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
07:23:41.0150 0x046c Winmgmt - ok
07:23:41.0244 0x046c [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM C:\Windows\system32\WsmSvc.dll
07:23:41.0306 0x046c WinRM - ok
07:23:41.0353 0x046c [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
07:23:41.0353 0x046c WinUsb - ok
07:23:41.0416 0x046c [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
07:23:41.0462 0x046c Wlansvc - ok
07:23:41.0587 0x046c [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
07:23:41.0634 0x046c wlidsvc - ok
07:23:41.0681 0x046c [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
07:23:41.0681 0x046c WmiAcpi - ok
07:23:41.0728 0x046c [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
07:23:41.0728 0x046c wmiApSrv - ok
07:23:41.0853 0x046c [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
07:23:41.0884 0x046c WMPNetworkSvc - ok
07:23:41.0916 0x046c [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
07:23:41.0931 0x046c WPCSvc - ok
07:23:41.0962 0x046c [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
07:23:41.0962 0x046c WPDBusEnum - ok
07:23:42.0009 0x046c [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
07:23:42.0009 0x046c ws2ifsl - ok
07:23:42.0041 0x046c [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll
07:23:42.0041 0x046c wscsvc - ok
07:23:42.0056 0x046c WSearch - ok
07:23:42.0181 0x046c [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll
07:23:42.0259 0x046c wuauserv - ok
07:23:42.0306 0x046c [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
07:23:42.0306 0x046c WudfPf - ok
07:23:42.0353 0x046c [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
07:23:42.0369 0x046c WUDFRd - ok
07:23:42.0400 0x046c [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
07:23:42.0416 0x046c wudfsvc - ok
07:23:42.0447 0x046c [ 3C5E51C05BE9B56EAFF4E388C3AB25E4, 10D9FDEDAB1FB2E76D54661AFA5C1A6B1B0980525F38F5D061537077841C6AEE ] WwanSvc C:\Windows\System32\wwansvc.dll
07:23:42.0462 0x046c WwanSvc - ok
07:23:42.0478 0x046c ================ Scan global ===============================
07:23:42.0509 0x046c [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
07:23:42.0541 0x046c [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
07:23:42.0572 0x046c [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
07:23:42.0603 0x046c [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
07:23:42.0634 0x046c [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
07:23:42.0650 0x046c [ Global ] - ok
07:23:42.0650 0x046c ================ Scan MBR ==================================
07:23:42.0666 0x046c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
07:23:43.0353 0x046c \Device\Harddisk0\DR0 - ok
07:23:43.0353 0x046c [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1
07:23:43.0369 0x046c \Device\Harddisk1\DR1 - ok
07:23:43.0369 0x046c ================ Scan VBR ==================================
07:23:43.0400 0x046c [ 02495B6568F4CA9589CF5B50624C4433 ] \Device\Harddisk0\DR0\Partition1
07:23:43.0400 0x046c \Device\Harddisk0\DR0\Partition1 - ok
07:23:43.0416 0x046c [ FE9F7C695E2177A60D19EBFE90246F75 ] \Device\Harddisk0\DR0\Partition2
07:23:43.0431 0x046c \Device\Harddisk0\DR0\Partition2 - ok
07:23:43.0431 0x046c [ 7E22CC4DC916E2D23010F0CF89C4A395 ] \Device\Harddisk1\DR1\Partition1
07:23:43.0447 0x046c \Device\Harddisk1\DR1\Partition1 - ok
07:23:43.0447 0x046c ================ Scan generic autorun ======================
07:23:43.0525 0x046c [ B70BCC55743C5A5BD7C7C6D6A02BB6F9, 3D0FDBDF7E280D2597732C582DAA99726A0D2EEC60FB1D0FD797EF834A49FD22 ] C:\Windows\SOUNDMAN.EXE
07:23:43.0525 0x046c SoundMan - ok
07:23:43.0603 0x046c [ 03396637E1E1B4E333D00AED86178918, CF582487E856D01C960392AC658E8D36A92F2B2B4B9AEA9BFC9E6F75FBAD6571 ] C:\Program Files\Microsoft Security Client\msseces.exe
07:23:43.0619 0x046c MSC - ok
07:23:43.0650 0x046c [ EEB76D8A9B8AF31F39A97BCB4996B025, 6D12F43930AD7AC5063DD5730835637B53AEAFE882CA8C00B149C5493CD8A0E3 ] C:\Windows\system32\mncwlpo.vbe
07:23:43.0666 0x046c mncwlpoSrv - ok
07:23:43.0681 0x046c [ EEB76D8A9B8AF31F39A97BCB4996B025, 6D12F43930AD7AC5063DD5730835637B53AEAFE882CA8C00B149C5493CD8A0E3 ] C:\Windows\system32\mncqtxm.vbe
07:23:43.0681 0x046c mncqtxmSrv - ok
07:23:43.0775 0x046c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
07:23:43.0806 0x046c Sidebar - ok
07:23:43.0853 0x046c [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
07:23:43.0853 0x046c mctadmin - ok
07:23:43.0931 0x046c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
07:23:43.0962 0x046c Sidebar - ok
07:23:43.0978 0x046c [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
07:23:43.0978 0x046c mctadmin - ok
07:23:44.0072 0x046c [ 7DFCCC67990B6DE7F30F553A4E4612A4, 9FF98D6FD2539CEFC9F42103A7F72388BED6EE590400559B92BC7430228DA36A ] D:\Programy\RocketDock\RocketDock.exe
07:23:44.0087 0x046c RocketDock - ok
07:23:44.0244 0x046c [ 6F2C019C8F823DE0224AFCF1EB67940A, 79C0B8A6DE6C48F40E6169D200B9971ACD2CD0CE57C7271E517AB0E3EAEA8A32 ] D:\Programy\Rainlendar2\Rainlendar2.exe
07:23:44.0306 0x046c Rainlendar2 - ok
07:23:44.0306 0x046c Waiting for KSN requests completion. In queue: 47
07:23:45.0306 0x046c Waiting for KSN requests completion. In queue: 47
07:23:46.0306 0x046c Waiting for KSN requests completion. In queue: 47
07:23:47.0322 0x046c AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x60000 ( disabled : updated )
07:23:47.0322 0x046c Win FW state via NFP2: disabled
07:23:49.0978 0x046c ============================================================
07:23:49.0978 0x046c Scan finished
07:23:49.0978 0x046c ============================================================
07:23:49.0994 0x0ad8 Detected object count: 0
07:23:49.0994 0x0ad8 Actual detected object count: 0
07:24:22.0994 0x0c94 Deinitialize success

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola Logu

Příspěvekod jaro3 » 19 srp 2014 10:00

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 20 srp 2014 10:35

ComboFix 14-08-19.01 - Bohouš 20.08.2014 10:21:14.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1309 [GMT 2:00]
Spuštěný z: c:\users\BohouÜ\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\Bohouš\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnbbhiabfbpofkploignhnfeldnhbli\2.2\manifest.json
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-20 do 2014-08-20 )))))))))))))))))))))))))))))))
.
.
2014-08-20 08:30 . 2014-08-20 08:30 -------- d-----w- c:\users\Bohouš\AppData\Local\temp
2014-08-19 05:06 . 2014-08-07 09:05 8581864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{58792505-19CE-4963-9C1A-4FD6DBB1B0D4}\mpengine.dll
2014-08-17 17:36 . 2014-08-18 05:11 33512 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-08-17 17:36 . 2014-08-17 17:36 -------- d-----w- c:\programdata\RogueKiller
2014-08-17 17:32 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-08-17 17:26 . 2014-08-17 17:26 -------- d-----w- c:\windows\ERUNT
2014-08-17 14:10 . 2014-08-17 14:11 -------- d-----w- c:\program files\Google
2014-08-17 10:25 . 2014-08-17 11:02 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-17 10:24 . 2014-08-17 10:24 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-08-17 10:24 . 2014-08-17 10:24 -------- d-----w- c:\programdata\Malwarebytes
2014-08-17 10:24 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-17 10:24 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-17 10:24 . 2014-05-12 05:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-17 10:23 . 2014-08-17 10:23 -------- d-----w- c:\users\Bohouš\AppData\Local\Programs
2014-08-17 10:17 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-08-17 10:13 . 2014-08-17 17:20 -------- d-----w- C:\AdwCleaner
2014-08-17 09:12 . 2014-08-17 09:12 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-08-17 09:12 . 2014-08-17 09:12 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-08-17 09:12 . 2014-08-17 09:12 34048 ----a-w- c:\windows\system32\eEmpty.exe
2014-08-17 09:12 . 2014-08-17 09:12 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-08-17 09:12 . 2014-08-17 09:12 -------- d-----w- c:\programdata\MicroWorld
2014-08-17 09:08 . 2014-08-17 09:08 -------- d-----w- c:\users\Bohouš\DoctorWeb
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-17 07:19 . 2014-08-17 07:19 -------- d-----w- c:\users\Bohouš\AppData\Roaming\QuickScan
2014-08-15 08:35 . 2014-05-04 03:32 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3D116DC-B418-470E-B2D3-8AE2A0D1F202}\gapaengine.dll
2014-08-11 09:45 . 2014-08-11 09:45 287 ----a-w- C:\cleaner.bat
2014-08-07 09:19 . 2014-08-07 09:19 -------- d-----w- c:\users\Bohouš\AppData\Local\Apps
2014-08-07 09:01 . 2013-02-18 16:46 4216840 ----a-w- c:\program files\Common Files\vcredist_2008_sp1_x86.exe
2014-08-07 08:42 . 2014-08-07 08:42 -------- d-----w- c:\users\Bohouš\AppData\Local\Sony
2014-08-03 18:27 . 2014-08-03 18:27 1174979 ----a-w- c:\windows\unins000.exe
2014-08-03 18:26 . 2014-08-03 18:26 -------- d-----w- c:\users\Bohouš\AppData\Roaming\ZJMedia
2014-08-03 18:26 . 2014-08-03 18:26 -------- d-----w- c:\users\Bohouš\AppData\Local\ZJMedia
2014-08-01 11:31 . 2014-08-11 09:47 -------- d-----w- c:\programdata\GlarySoft
2014-07-24 09:31 . 2014-07-24 09:31 -------- d-----w- c:\windows\system32\20-20 Technologies
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-19 16:05 . 2014-06-11 08:43 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-11 06:54 . 2014-01-25 11:21 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-11 06:54 . 2014-01-25 11:21 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="d:\programy\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Rainlendar2"="d:\programy\Rainlendar2\Rainlendar2.exe" [2012-07-02 2498048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"mncwlpoSrv"="c:\windows\system32\mncwlpo.vbe" [2014-03-05 7670]
"mncqtxmSrv"="c:\windows\system32\mncqtxm.vbe" [2014-03-05 7670]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-01-25 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2012-11-05 14:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
2013-05-16 13:25 1062472 ----a-w- c:\users\Bohouš\AppData\Roaming\Seznam.cz\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
2013-04-12 08:10 92664 ----a-w- c:\users\Bohouš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
2013-05-16 13:25 1062472 ----a-w- c:\program files\Seznam.cz\distribution\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2009-06-17 11:44 85160 ----a-w- c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
R1 nawnyute;nawnyute;c:\windows\system32\drivers\nawnyute.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2014-04-08 12400]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-01-25 1343400]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-03-02 5120]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-17 14:11 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-25 06:54]
.
2014-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-08-17 14:10]
.
2014-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-08-17 14:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 77.237.128.2 77.237.128.1 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
Toolbar-10 - (no file)
AddRemove-{F4231BE4-2C31-D6DF-85CF-307B6E80C9AD}_is1 - c:\program files\Winrar 4.20-cz+key
AddRemove-Update Service SimpleFiles - c:\program files\SimpleFilesUpdater\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-08-20 10:33:01
ComboFix-quarantined-files.txt 2014-08-20 08:33
.
Před spuštěním: Volných bajtů: 14 878 339 072
Po spuštění: Volných bajtů: 14 652 538 880
.
- - End Of File - - D88CD2021E7F2DC54E316764017933E4
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola Logu

Příspěvekod jaro3 » 20 srp 2014 18:52

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
Collect::
c:\windows\system32\drivers\nawnyute.sys

File::
c:\windows\system32\mncwlpo.vbe
c:\windows\system32\mncqtxm.vbe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Folder::
c:\program files\Google\Update

Driver::
nawnyute

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mncwlpoSrv"=-
"mncqtxmSrv"=-
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"=-

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.

Nemáš málo volného místa na disku?

antivir MSE bych vyměnil za Avast nebo Aviru.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Max583
Level 2.5
Level 2.5
Příspěvky: 289
Registrován: červen 10
Bydliště: Most
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola Logu

Příspěvekod Max583 » 21 srp 2014 10:56

ComboFix 14-08-19.01 - Bohouš 21.08.2014 10:25:03.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2048.1436 [GMT 2:00]
Spuštěný z: c:\users\BohouÜ\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\BohouÜ\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Bohouš\AppData\Local\Google\Chrome\User Data\Default\Preferences
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-21 do 2014-08-21 )))))))))))))))))))))))))))))))
.
.
2014-08-21 08:33 . 2014-08-21 08:33 -------- d-----w- c:\users\Bohouš\AppData\Local\temp
2014-08-21 08:33 . 2014-08-21 08:33 -------- d-----w- c:\users\HomeGroupUser$\AppData\Local\temp
2014-08-21 08:33 . 2014-08-21 08:33 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-08-21 08:33 . 2014-08-21 08:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-21 08:33 . 2014-08-21 08:33 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-08-20 13:14 . 2014-08-07 09:05 8581864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{00A1DCBC-A617-42E6-AAE5-5495ECCEB339}\mpengine.dll
2014-08-19 05:06 . 2014-08-07 09:05 8581864 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-08-17 17:36 . 2014-08-18 05:11 33512 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-08-17 17:36 . 2014-08-17 17:36 -------- d-----w- c:\programdata\RogueKiller
2014-08-17 17:26 . 2014-08-17 17:26 -------- d-----w- c:\windows\ERUNT
2014-08-17 14:10 . 2014-08-17 14:11 -------- d-----w- c:\program files\Google
2014-08-17 10:25 . 2014-08-17 11:02 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-17 10:24 . 2014-08-17 10:24 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-08-17 10:24 . 2014-08-17 10:24 -------- d-----w- c:\programdata\Malwarebytes
2014-08-17 10:24 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-17 10:24 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-17 10:24 . 2014-05-12 05:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-17 10:23 . 2014-08-17 10:23 -------- d-----w- c:\users\Bohouš\AppData\Local\Programs
2014-08-17 10:17 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-08-17 10:13 . 2014-08-17 17:20 -------- d-----w- C:\AdwCleaner
2014-08-17 09:12 . 2014-08-17 09:12 632064 ----a-w- c:\windows\system32\msvcr80.dll
2014-08-17 09:12 . 2014-08-17 09:12 554240 ----a-w- c:\windows\system32\msvcp80.dll
2014-08-17 09:12 . 2014-08-17 09:12 34048 ----a-w- c:\windows\system32\eEmpty.exe
2014-08-17 09:12 . 2014-08-17 09:12 -------- d-----w- c:\program files\Common Files\MicroWorld
2014-08-17 09:12 . 2014-08-17 09:12 -------- d-----w- c:\programdata\MicroWorld
2014-08-17 09:08 . 2014-08-17 09:08 -------- d-----w- c:\users\Bohouš\DoctorWeb
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-17 07:19 . 2014-08-17 07:19 -------- d-----w- c:\users\Bohouš\AppData\Roaming\QuickScan
2014-08-15 08:35 . 2014-05-04 03:32 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E3D116DC-B418-470E-B2D3-8AE2A0D1F202}\gapaengine.dll
2014-08-11 09:45 . 2014-08-11 09:45 287 ----a-w- C:\cleaner.bat
2014-08-07 09:19 . 2014-08-07 09:19 -------- d-----w- c:\users\Bohouš\AppData\Local\Apps
2014-08-07 09:01 . 2013-02-18 16:46 4216840 ----a-w- c:\program files\Common Files\vcredist_2008_sp1_x86.exe
2014-08-07 08:42 . 2014-08-07 08:42 -------- d-----w- c:\users\Bohouš\AppData\Local\Sony
2014-08-03 18:27 . 2014-08-03 18:27 1174979 ----a-w- c:\windows\unins000.exe
2014-08-03 18:26 . 2014-08-03 18:26 -------- d-----w- c:\users\Bohouš\AppData\Roaming\ZJMedia
2014-08-03 18:26 . 2014-08-03 18:26 -------- d-----w- c:\users\Bohouš\AppData\Local\ZJMedia
2014-08-01 11:31 . 2014-08-11 09:47 -------- d-----w- c:\programdata\GlarySoft
2014-07-24 09:31 . 2014-07-24 09:31 -------- d-----w- c:\windows\system32\20-20 Technologies
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-19 16:05 . 2014-06-11 08:43 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-17 07:43 . 2014-08-17 07:43 388096 ----a-r- c:\users\Bohouš\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2014-08-11 06:54 . 2014-01-25 11:21 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-11 06:54 . 2014-01-25 11:21 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="d:\programy\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Rainlendar2"="d:\programy\Rainlendar2\Rainlendar2.exe" [2012-07-02 2498048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"mncwlpoSrv"="c:\windows\system32\mncwlpo.vbe" [2014-03-05 7670]
"mncqtxmSrv"="c:\windows\system32\mncqtxm.vbe" [2014-03-05 7670]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-01-25 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2012-11-05 14:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
2013-05-16 13:25 1062472 ----a-w- c:\users\Bohouš\AppData\Roaming\Seznam.cz\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
2013-04-12 08:10 92664 ----a-w- c:\users\Bohouš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
2013-05-16 13:25 1062472 ----a-w- c:\program files\Seznam.cz\distribution\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2009-06-17 11:44 85160 ----a-w- c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
R1 nawnyute;nawnyute;c:\windows\system32\drivers\nawnyute.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2014-04-08 12400]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-01-25 1343400]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-03-02 5120]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-17 14:11 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-25 06:54]
.
2014-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-08-17 14:10]
.
2014-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-08-17 14:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 77.237.128.2 77.237.128.1 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-08-21 10:36:17
ComboFix-quarantined-files.txt 2014-08-21 08:36
ComboFix2.txt 2014-08-20 08:33
.
Před spuštěním: Volných bajtů: 14 856 560 640
Po spuštění: Volných bajtů: 14 813 868 032
.
- - End Of File - - F0B6A7883DFEB4FC94A3AA5A7E6A85DC
A36C5E4F47E84449FF07ED3517B43A31

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:53:23, on 21.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SOUNDMAN.EXE
D:\Programy\Rainlendar2\Rainlendar2.exe
C:\Windows\explorer.exe
C:\Windows\system32\taskhost.exe
D:\Plánovaèe\èištìní\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [mncwlpoSrv] C:\Windows\system32\mncwlpo.vbe
O4 - HKLM\..\Run: [mncqtxmSrv] C:\Windows\system32\mncqtxm.vbe
O4 - HKCU\..\Run: [RocketDock] "D:\Programy\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Rainlendar2] D:\Programy\Rainlendar2\Rainlendar2.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/CZ/Core/ ... _Win32.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe

--
End of file - 3492 bytes

aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-08-21 10:45:25
-----------------------------
10:45:25.944 OS Version: Windows 6.1.7601 Service Pack 1
10:45:25.944 Number of processors: 2 586 0x409
10:45:25.944 ComputerName: BOHOUŠ-PC UserName: Bohouš
10:45:27.584 Initialize success
10:45:27.584 VM: initialized successfully
10:45:27.600 VM: Intel CPU virtualization not supported
10:45:49.163 The log file has been saved successfully to "C:\Users\Bohouš\Desktop\aswMBR.txt"


Avast jsem používal ale připadli mi, že hrozně zpomaluje PC . Aviru neznám ale můžu jí zkusit. Ještě jsem uvažoval o Kasperskym.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Seznam[Bot] a 110 hostů