Předem děkuji za vaší ochotu.
Takže v čem mám problém....používám mozzilu a když chci vyhledat něco přímo zadáním do místa pro adresu vyhledá mi to místo v googlo počád buďto v centrum.cz nebo icq.com už jsme to opravoval několikrát a stále je to tam znova. potom když spustím PC mozzila mi vyhodí chybu že přestala pracovat asi čtyři okna, ty zavřu a pak vše v pohodě. PC se smi zdá spomalený a taky si myslím že se stále spouští plno blbostí.
Díky
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:54:55, on 1.8.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal
Running processes:
C:\test\svchost.exe
C:\Program Files (x86)\ICQ7.5\ICQ.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe
C:\Program Files (x86)\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112555 ... 618601e903
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 5.132.136.137 pes09pcgate-e.winning-eleven.net
O1 - Hosts: 5.132.136.137 pes2009web.winning-eleven.net
O1 - Hosts: stun.xten.com pes7stun-e.winning-eleven.net
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {1C6A7DE2-27A9-337C-5162-777A023D70C9} - C:\Windows\SysWow64\msoobjs.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [mspaint] "C:\Windows\system32\Paint.exe" -autocheck
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HKLM] C:\Windows\install\messenger.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [DynamicUSB] "C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [HKCU] C:\Windows\install\messenger.exe
O4 - HKCU\..\Run: [msnmsgsr] C:\test\svchost.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\Windows\install\messenger.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\Windows\install\messenger.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-854367754-585167149-2272254232-501\..\Run: [HKCU] C:\Windows\install\messenger.exe (User 'Guest')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService.exe) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 16675 bytes
Prosím o kontrolu LOGU
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu LOGU
Odinstaluj SweetIM Toolbar a Babylon Toolbar
Fixni:
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
Fixni:
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112555 ... 618601e903
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 5.132.136.137 pes09pcgate-e.winning-eleven.net
O1 - Hosts: 5.132.136.137 pes2009web.winning-eleven.net
O1 - Hosts: stun.xten.com pes7stun-e.winning-eleven.net
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [mspaint] "C:\Windows\system32\Paint.exe" -autocheck
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HKLM] C:\Windows\install\messenger.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [HKCU] C:\Windows\install\messenger.exe
O4 - HKCU\..\Run: [msnmsgsr] C:\test\svchost.exe
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\Windows\install\messenger.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\Windows\install\messenger.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-854367754-585167149-2272254232-501\..\Run: [HKCU] C:\Windows\install\messenger.exe (User 'Guest')
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
- Pokud používáš Firefox, klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
- Pokud používáš Chrome, nic dalšího nevybírej a dej Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Update Malwarebytes' Anti-Malware (Aktualizace Malwarebytes' Anti-Malware) a Launch Malwarebytes' Anti-Malware (Spustit aplikaci Malwarebytes' Anti-Malware), pokud jo tak klikni na tlačítko Finish
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Perform Quick Scan (Provést rychlý sken) a klikni na tlačítko Scan (Skenovat)
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- pak zvol možnost Save Logfile a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(ZATÍM SÁM NIC NEMAŽ!).
Vlož sem pak obsah toho logu.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Prosím o kontrolu LOGU
Provedeno
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org
Verze databáze: v2012.08.01.07
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Dusan :: DUSAN-PC [administrátor]
Ochrana: Povolena
1.8.2012 22:29:35
LOG.txt
Typ: Blesková kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: Registr | Systémové soubory | P2P
Kontrolované objekty: 179359
Uplynulý čas: 24 sekund
Nalezené procesy v paměti: 1
C:\test\svchost.exe (Malware.Packer.T) -> 4152 -> Žádná instrukce nebyla provedena.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 5
HKCR\CLSID\{88RT8-U084T6Q-B9Q96-PDG1KN-1CKWCELQV} (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{88RT8-U084T6Q-B9Q96-PDG1KN-1CKWCELQV} (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Žádná instrukce nebyla provedena.
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 7
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msnmsgsr (Malware.Packer.T) -> Data: C:\test\svchost.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mspaint (Trojan.VB) -> Data: "C:\Windows\system32\Paint.exe" -autocheck -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKCU (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft|kr_done1 (Malware.Trace) -> Data: 1257532284 -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files (x86)\KEEPprivacy (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
Nalezené soubory: 17
C:\test\svchost.exe (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
C:\Windows\System32\Paint.exe (Trojan.VB) -> Žádná instrukce nebyla provedena.
C:\Windows\install\messenger.exe (Malware.Gen) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\svchots.exe (Trojan.Agent.Gen) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\cgs8h0.exe (Exploit.Drop.GS) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\local.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\data.dat (Stolen.Data) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\logs.dat (Bifrose.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Roaming\logs.dat (Bifrose.Trace) -> Žádná instrukce nebyla provedena.
C:\Windows\System32\kr_done1 (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Windows\SysWOW64\kr_done1 (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Program Files (x86)\KEEPprivacy\mdata.dat (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
C:\Program Files (x86)\KEEPprivacy\trackingsitedata (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
(konec)
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org
Verze databáze: v2012.08.01.07
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Dusan :: DUSAN-PC [administrátor]
Ochrana: Povolena
1.8.2012 22:29:35
LOG.txt
Typ: Blesková kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: Registr | Systémové soubory | P2P
Kontrolované objekty: 179359
Uplynulý čas: 24 sekund
Nalezené procesy v paměti: 1
C:\test\svchost.exe (Malware.Packer.T) -> 4152 -> Žádná instrukce nebyla provedena.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 5
HKCR\CLSID\{88RT8-U084T6Q-B9Q96-PDG1KN-1CKWCELQV} (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{88RT8-U084T6Q-B9Q96-PDG1KN-1CKWCELQV} (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Žádná instrukce nebyla provedena.
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Žádná instrukce nebyla provedena.
Nalezené hodnoty v registru: 7
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msnmsgsr (Malware.Packer.T) -> Data: C:\test\svchost.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mspaint (Trojan.VB) -> Data: "C:\Windows\system32\Paint.exe" -autocheck -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKCU (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft|kr_done1 (Malware.Trace) -> Data: 1257532284 -> Žádná instrukce nebyla provedena.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 1
C:\Program Files (x86)\KEEPprivacy (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
Nalezené soubory: 17
C:\test\svchost.exe (Malware.Packer.T) -> Žádná instrukce nebyla provedena.
C:\Windows\System32\Paint.exe (Trojan.VB) -> Žádná instrukce nebyla provedena.
C:\Windows\install\messenger.exe (Malware.Gen) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\svchots.exe (Trojan.Agent.Gen) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\cgs8h0.exe (Exploit.Drop.GS) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\local.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\data.dat (Stolen.Data) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Roaming\logs.dat (Bifrose.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Roaming\logs.dat (Bifrose.Trace) -> Žádná instrukce nebyla provedena.
C:\Windows\System32\kr_done1 (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Windows\SysWOW64\kr_done1 (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Dusan\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Users\Guest\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Program Files (x86)\KEEPprivacy\mdata.dat (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
C:\Program Files (x86)\KEEPprivacy\trackingsitedata (Rogue.KeepPrivacy) -> Žádná instrukce nebyla provedena.
(konec)
- Žbeky
- Moderátor
-
Guru Level 13
- Příspěvky: 22288
- Registrován: květen 08
- Bydliště: Vsetín - Pardubice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu LOGU
Znovu spusť MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit
Stáhni si TDSSKiller
Na svojí plochu. Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
V SZ řeším jen záležitosti týkající se fóra. Na prosby a žádosti o technickou podporu nereaguji. Díky za pochopení.
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
HiJackThis + návod - HW Monitor - Jak označit příspěvek za vyřešený - Pravidla fóra
Re: Prosím o kontrolu LOGU
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org
Verze databáze: v2012.08.01.07
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Dusan :: DUSAN-PC [administrátor]
Ochrana: Povolena
1.8.2012 22:43:04
mbam-log-2012-08-01 (22-43-04).txt
Typ: Blesková kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: Registr | Systémové soubory | P2P
Kontrolované objekty: 179480
Uplynulý čas: 24 sekund
Nalezené procesy v paměti: 1
C:\test\svchost.exe (Malware.Packer.T) -> 4152 -> Bude smazán při restartu.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKCR\CLSID\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKCU (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 6
C:\test\svchost.exe (Malware.Packer.T) -> Bude smazán při restartu.
C:\Windows\install\messenger.exe (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Dusan\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Guest\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Dusan\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Guest\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
(konec)
www.malwarebytes.org
Verze databáze: v2012.08.01.07
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Dusan :: DUSAN-PC [administrátor]
Ochrana: Povolena
1.8.2012 22:43:04
mbam-log-2012-08-01 (22-43-04).txt
Typ: Blesková kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: Registr | Systémové soubory | P2P
Kontrolované objekty: 179480
Uplynulý čas: 24 sekund
Nalezené procesy v paměti: 1
C:\test\svchost.exe (Malware.Packer.T) -> 4152 -> Bude smazán při restartu.
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKCR\CLSID\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500} (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
Nalezené hodnoty v registru: 4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKCU (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Policies (Malware.Gen) -> Data: C:\Windows\install\messenger.exe -> Umístnění do karantény a smazání se zdařilo.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené soubory: 6
C:\test\svchost.exe (Malware.Packer.T) -> Bude smazán při restartu.
C:\Windows\install\messenger.exe (Malware.Gen) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Dusan\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Guest\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Dusan\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
C:\Users\Guest\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Umístnění do karantény a smazání se zdařilo.
(konec)
Re: Prosím o kontrolu LOGU
22:44:53.0093 7936 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
22:44:53.0279 7936 ============================================================
22:44:53.0279 7936 Current date / time: 2012/08/01 22:44:53.0279
22:44:53.0279 7936 SystemInfo:
22:44:53.0279 7936
22:44:53.0279 7936 OS Version: 6.1.7600 ServicePack: 0.0
22:44:53.0279 7936 Product type: Workstation
22:44:53.0279 7936 ComputerName: DUSAN-PC
22:44:53.0279 7936 UserName: Dusan
22:44:53.0279 7936 Windows directory: C:\Windows
22:44:53.0279 7936 System windows directory: C:\Windows
22:44:53.0279 7936 Running under WOW64
22:44:53.0279 7936 Processor architecture: Intel x64
22:44:53.0279 7936 Number of processors: 4
22:44:53.0279 7936 Page size: 0x1000
22:44:53.0279 7936 Boot type: Normal boot
22:44:53.0279 7936 ============================================================
22:44:54.0789 7936 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:44:54.0797 7936 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:44:54.0816 7936 ============================================================
22:44:54.0816 7936 \Device\Harddisk0\DR0:
22:44:54.0816 7936 MBR partitions:
22:44:54.0816 7936 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x30D3C74
22:44:54.0822 7936 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x30D3CF2, BlocksNum 0x1A0EC9CE
22:44:54.0822 7936 \Device\Harddisk1\DR1:
22:44:54.0822 7936 MBR partitions:
22:44:54.0822 7936 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:44:54.0822 7936 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x57513000
22:44:54.0822 7936 ============================================================
22:44:54.0840 7936 C: <-> \Device\Harddisk1\DR1\Partition1
22:44:54.0891 7936 E: <-> \Device\Harddisk0\DR0\Partition0
22:44:54.0931 7936 F: <-> \Device\Harddisk0\DR0\Partition1
22:44:54.0931 7936 ============================================================
22:44:54.0931 7936 Initialize success
22:44:54.0931 7936 ============================================================
22:45:40.0480 8108 ============================================================
22:45:40.0480 8108 Scan started
22:45:40.0480 8108 Mode: Manual;
22:45:40.0480 8108 ============================================================
22:45:41.0463 8108 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:45:41.0465 8108 1394ohci - ok
22:45:41.0499 8108 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:45:41.0502 8108 ACPI - ok
22:45:41.0512 8108 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:45:41.0513 8108 AcpiPmi - ok
22:45:41.0605 8108 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:45:41.0606 8108 AdobeARMservice - ok
22:45:41.0714 8108 AdobeFlashPlayerUpdateSvc (6c40d5ed8951ab7b90d08af655224ee4) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:45:41.0717 8108 AdobeFlashPlayerUpdateSvc - ok
22:45:41.0759 8108 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:45:41.0770 8108 adp94xx - ok
22:45:41.0801 8108 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:45:41.0805 8108 adpahci - ok
22:45:41.0825 8108 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:45:41.0827 8108 adpu320 - ok
22:45:41.0853 8108 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:45:41.0854 8108 AeLookupSvc - ok
22:45:41.0907 8108 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
22:45:41.0919 8108 AFD - ok
22:45:41.0932 8108 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:45:41.0933 8108 agp440 - ok
22:45:41.0947 8108 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:45:41.0948 8108 ALG - ok
22:45:41.0965 8108 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:45:41.0965 8108 aliide - ok
22:45:41.0993 8108 AMD External Events Utility (6edb5d627aa83863da21f1d1b2b523b4) C:\Windows\system32\atiesrxx.exe
22:45:41.0996 8108 AMD External Events Utility - ok
22:45:42.0006 8108 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:45:42.0007 8108 amdide - ok
22:45:42.0015 8108 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:45:42.0016 8108 AmdK8 - ok
22:45:42.0035 8108 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:45:42.0036 8108 AmdPPM - ok
22:45:42.0066 8108 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\DRIVERS\amdsata.sys
22:45:42.0067 8108 amdsata - ok
22:45:42.0097 8108 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:45:42.0099 8108 amdsbs - ok
22:45:42.0109 8108 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\DRIVERS\amdxata.sys
22:45:42.0110 8108 amdxata - ok
22:45:42.0149 8108 androidusb (4de0d5d747a73797c95a97dcce5018b5) C:\Windows\system32\Drivers\ssadadb.sys
22:45:42.0150 8108 androidusb - ok
22:45:42.0164 8108 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:45:42.0165 8108 AppID - ok
22:45:42.0180 8108 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:45:42.0181 8108 AppIDSvc - ok
22:45:42.0203 8108 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:45:42.0204 8108 Appinfo - ok
22:45:42.0251 8108 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
22:45:42.0254 8108 AppMgmt - ok
22:45:42.0268 8108 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:45:42.0269 8108 arc - ok
22:45:42.0284 8108 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:45:42.0287 8108 arcsas - ok
22:45:42.0395 8108 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:45:42.0396 8108 aspnet_state - ok
22:45:42.0417 8108 aswFsBlk (e6dee1ff3ec08c146ae607257b2ac25e) C:\Windows\system32\drivers\aswFsBlk.sys
22:45:42.0417 8108 aswFsBlk - ok
22:45:42.0452 8108 aswMonFlt (976e731bc951d76237e960fad7402741) C:\Windows\system32\drivers\aswMonFlt.sys
22:45:42.0453 8108 aswMonFlt - ok
22:45:42.0461 8108 aswRdr (10fde4d126dd0d09d59a84f703449244) C:\Windows\system32\drivers\aswRdr.sys
22:45:42.0462 8108 aswRdr - ok
22:45:42.0487 8108 aswSP (0211624896d0b05f24533540e22fc740) C:\Windows\system32\drivers\aswSP.sys
22:45:42.0489 8108 aswSP - ok
22:45:42.0499 8108 aswTdi (f0cdae379c90d6e1d873c10b5ca1af0c) C:\Windows\system32\drivers\aswTdi.sys
22:45:42.0500 8108 aswTdi - ok
22:45:42.0510 8108 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:45:42.0510 8108 AsyncMac - ok
22:45:42.0513 8108 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:45:42.0514 8108 atapi - ok
22:45:42.0568 8108 AtiHdmiService (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
22:45:42.0570 8108 AtiHdmiService - ok
22:45:42.0898 8108 atikmdag (b86a300894d3531c4421d93977a2d7ee) C:\Windows\system32\DRIVERS\atikmdag.sys
22:45:42.0986 8108 atikmdag - ok
22:45:43.0077 8108 AtiPcie (db0d3de15edc96e7529fc0d3f7760894) C:\Windows\system32\DRIVERS\AtiPcie.sys
22:45:43.0077 8108 AtiPcie - ok
22:45:43.0133 8108 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:43.0152 8108 AudioEndpointBuilder - ok
22:45:43.0157 8108 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:43.0160 8108 AudioSrv - ok
22:45:43.0229 8108 avast! Antivirus (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0230 8108 avast! Antivirus - ok
22:45:43.0234 8108 avast! Mail Scanner (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0234 8108 avast! Mail Scanner - ok
22:45:43.0237 8108 avast! Web Scanner (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0237 8108 avast! Web Scanner - ok
22:45:43.0264 8108 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:45:43.0266 8108 AxInstSV - ok
22:45:43.0316 8108 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:45:43.0328 8108 b06bdrv - ok
22:45:43.0370 8108 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:45:43.0373 8108 b57nd60a - ok
22:45:43.0393 8108 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:45:43.0394 8108 BDESVC - ok
22:45:43.0417 8108 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:45:43.0417 8108 Beep - ok
22:45:43.0473 8108 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:45:43.0480 8108 BFE - ok
22:45:43.0537 8108 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:45:43.0561 8108 BITS - ok
22:45:43.0605 8108 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:45:43.0606 8108 blbdrive - ok
22:45:43.0680 8108 Bonjour Service (f832f1505ad8b83474bd9a5b1b985e01) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
22:45:43.0681 8108 Bonjour Service - ok
22:45:43.0709 8108 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:45:43.0711 8108 bowser - ok
22:45:43.0735 8108 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:45:43.0735 8108 BrFiltLo - ok
22:45:43.0741 8108 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:45:43.0742 8108 BrFiltUp - ok
22:45:43.0761 8108 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:45:43.0763 8108 Browser - ok
22:45:43.0784 8108 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:45:43.0787 8108 Brserid - ok
22:45:43.0791 8108 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:45:43.0792 8108 BrSerWdm - ok
22:45:43.0805 8108 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:45:43.0806 8108 BrUsbMdm - ok
22:45:43.0815 8108 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:45:43.0816 8108 BrUsbSer - ok
22:45:43.0841 8108 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
22:45:43.0842 8108 BthEnum - ok
22:45:43.0854 8108 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:45:43.0855 8108 BTHMODEM - ok
22:45:43.0902 8108 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
22:45:43.0903 8108 BthPan - ok
22:45:43.0956 8108 BTHPORT (a51fa9d0e85d5adabef72e67f386309c) C:\Windows\system32\Drivers\BTHport.sys
22:45:43.0964 8108 BTHPORT - ok
22:45:44.0007 8108 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:45:44.0008 8108 bthserv - ok
22:45:44.0033 8108 BTHUSB (f740b9a16b2c06700f2130e19986bf3b) C:\Windows\system32\Drivers\BTHUSB.sys
22:45:44.0034 8108 BTHUSB - ok
22:45:44.0064 8108 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:45:44.0066 8108 cdfs - ok
22:45:44.0093 8108 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:45:44.0095 8108 cdrom - ok
22:45:44.0115 8108 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:44.0116 8108 CertPropSvc - ok
22:45:44.0131 8108 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:45:44.0132 8108 circlass - ok
22:45:44.0163 8108 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:45:44.0167 8108 CLFS - ok
22:45:44.0219 8108 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:45:44.0220 8108 clr_optimization_v2.0.50727_32 - ok
22:45:44.0262 8108 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:45:44.0263 8108 clr_optimization_v2.0.50727_64 - ok
22:45:44.0365 8108 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:45:44.0367 8108 clr_optimization_v4.0.30319_32 - ok
22:45:44.0421 8108 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:45:44.0423 8108 clr_optimization_v4.0.30319_64 - ok
22:45:44.0441 8108 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:45:44.0442 8108 CmBatt - ok
22:45:44.0444 8108 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:45:44.0445 8108 cmdide - ok
22:45:44.0481 8108 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
22:45:44.0493 8108 CNG - ok
22:45:44.0519 8108 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:45:44.0521 8108 Compbatt - ok
22:45:44.0541 8108 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:45:44.0542 8108 CompositeBus - ok
22:45:44.0548 8108 COMSysApp - ok
22:45:44.0555 8108 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:45:44.0556 8108 crcdisk - ok
22:45:44.0582 8108 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
22:45:44.0584 8108 CryptSvc - ok
22:45:44.0622 8108 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
22:45:44.0637 8108 CSC - ok
22:45:44.0687 8108 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
22:45:44.0703 8108 CscService - ok
22:45:45.0141 8108 ctxusbm (bf62ff663ae55e4ed99de76881c2c0f1) C:\Windows\system32\DRIVERS\ctxusbm.sys
22:45:45.0142 8108 ctxusbm - ok
22:45:45.0217 8108 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:45.0223 8108 DcomLaunch - ok
22:45:45.0291 8108 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:45:45.0295 8108 defragsvc - ok
22:45:45.0306 8108 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
22:45:45.0308 8108 DfsC - ok
22:45:45.0330 8108 dgderdrv (def365f0f6e017888c4b869d3ba4b8e0) C:\Windows\system32\drivers\dgderdrv.sys
22:45:45.0331 8108 dgderdrv - ok
22:45:45.0346 8108 DgiVecp - ok
22:45:45.0383 8108 dg_ssudbus (6060106ce00f32f63f1a73160e46e9d2) C:\Windows\system32\DRIVERS\ssudbus.sys
22:45:45.0385 8108 dg_ssudbus - ok
22:45:45.0418 8108 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:45:45.0422 8108 Dhcp - ok
22:45:45.0433 8108 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:45:45.0434 8108 discache - ok
22:45:45.0454 8108 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:45:45.0455 8108 Disk - ok
22:45:45.0474 8108 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:45:45.0476 8108 Dnscache - ok
22:45:45.0501 8108 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:45:45.0504 8108 dot3svc - ok
22:45:45.0524 8108 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:45:45.0527 8108 DPS - ok
22:45:45.0550 8108 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:45:45.0551 8108 drmkaud - ok
22:45:45.0610 8108 DualCoreCenter (4bb346300c499de02f99b8789622ceaa) C:\Program Files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys
22:45:45.0610 8108 DualCoreCenter - ok
22:45:45.0685 8108 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
22:45:45.0695 8108 DXGKrnl - ok
22:45:45.0713 8108 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:45:45.0715 8108 EapHost - ok
22:45:45.0911 8108 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:45:45.0964 8108 ebdrv - ok
22:45:46.0046 8108 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
22:45:46.0048 8108 EFS - ok
22:45:46.0112 8108 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:45:46.0123 8108 ehRecvr - ok
22:45:46.0158 8108 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:45:46.0160 8108 ehSched - ok
22:45:46.0213 8108 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:45:46.0246 8108 elxstor - ok
22:45:46.0288 8108 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:45:46.0289 8108 ErrDev - ok
22:45:46.0329 8108 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:45:46.0334 8108 EventSystem - ok
22:45:46.0352 8108 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:45:46.0354 8108 exfat - ok
22:45:46.0376 8108 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:45:46.0379 8108 fastfat - ok
22:45:46.0434 8108 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:45:46.0478 8108 Fax - ok
22:45:46.0521 8108 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:45:46.0522 8108 fdc - ok
22:45:46.0533 8108 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:45:46.0534 8108 fdPHost - ok
22:45:46.0542 8108 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:45:46.0543 8108 FDResPub - ok
22:45:46.0555 8108 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:45:46.0556 8108 FileInfo - ok
22:45:46.0567 8108 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:45:46.0568 8108 Filetrace - ok
22:45:46.0573 8108 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:45:46.0574 8108 flpydisk - ok
22:45:46.0606 8108 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:45:46.0609 8108 FltMgr - ok
22:45:46.0685 8108 FontCache (bc00505cfda789ed3be95d2ff38c4875) C:\Windows\system32\FntCache.dll
22:45:46.0728 8108 FontCache - ok
22:45:46.0788 8108 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:45:46.0789 8108 FontCache3.0.0.0 - ok
22:45:46.0807 8108 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:45:46.0808 8108 FsDepends - ok
22:45:46.0821 8108 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
22:45:46.0821 8108 Fs_Rec - ok
22:45:46.0856 8108 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:45:46.0858 8108 fvevol - ok
22:45:46.0867 8108 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:45:46.0868 8108 gagp30kx - ok
22:45:46.0942 8108 GGSAFERDriver - ok
22:45:46.0993 8108 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:45:47.0043 8108 gpsvc - ok
22:45:47.0120 8108 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:45:47.0122 8108 gupdate - ok
22:45:47.0139 8108 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:45:47.0140 8108 gupdatem - ok
22:45:47.0162 8108 hamachi (f8f0851d336c3b88dbd7232b6348e09a) C:\Windows\system32\DRIVERS\hamachi.sys
22:45:47.0163 8108 hamachi - ok
22:45:47.0180 8108 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:45:47.0181 8108 hcw85cir - ok
22:45:47.0228 8108 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:45:47.0232 8108 HdAudAddService - ok
22:45:47.0251 8108 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:45:47.0253 8108 HDAudBus - ok
22:45:47.0255 8108 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:45:47.0256 8108 HidBatt - ok
22:45:47.0271 8108 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:45:47.0272 8108 HidBth - ok
22:45:47.0287 8108 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:45:47.0289 8108 HidIr - ok
22:45:47.0299 8108 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:45:47.0300 8108 hidserv - ok
22:45:47.0322 8108 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:45:47.0323 8108 HidUsb - ok
22:45:47.0348 8108 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:45:47.0350 8108 hkmsvc - ok
22:45:47.0376 8108 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:45:47.0379 8108 HomeGroupListener - ok
22:45:47.0405 8108 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:45:47.0408 8108 HomeGroupProvider - ok
22:45:47.0420 8108 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:45:47.0421 8108 HpSAMD - ok
22:45:47.0475 8108 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:45:47.0509 8108 HTTP - ok
22:45:47.0544 8108 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:45:47.0546 8108 hwpolicy - ok
22:45:47.0572 8108 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:45:47.0573 8108 i8042prt - ok
22:45:47.0623 8108 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\DRIVERS\iaStorV.sys
22:45:47.0628 8108 iaStorV - ok
22:45:47.0704 8108 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
22:45:47.0705 8108 IDriverT - ok
22:45:47.0791 8108 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:45:47.0821 8108 idsvc - ok
22:45:47.0892 8108 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:45:47.0893 8108 iirsp - ok
22:45:47.0957 8108 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:45:47.0995 8108 IKEEXT - ok
22:45:48.0146 8108 IntcAzAudAddService (627c6b352718e59df08f02c536e2e0ed) C:\Windows\system32\drivers\RTKVHD64.sys
22:45:48.0179 8108 IntcAzAudAddService - ok
22:45:48.0236 8108 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:45:48.0237 8108 intelide - ok
22:45:48.0259 8108 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:45:48.0260 8108 intelppm - ok
22:45:48.0271 8108 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:45:48.0272 8108 IPBusEnum - ok
22:45:48.0288 8108 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:45:48.0290 8108 IpFilterDriver - ok
22:45:48.0331 8108 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:45:48.0339 8108 iphlpsvc - ok
22:45:48.0349 8108 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:45:48.0351 8108 IPMIDRV - ok
22:45:48.0365 8108 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:45:48.0366 8108 IPNAT - ok
22:45:48.0386 8108 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:45:48.0387 8108 IRENUM - ok
22:45:48.0394 8108 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:45:48.0395 8108 isapnp - ok
22:45:48.0419 8108 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:45:48.0421 8108 iScsiPrt - ok
22:45:48.0435 8108 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:45:48.0437 8108 kbdclass - ok
22:45:48.0453 8108 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:45:48.0454 8108 kbdhid - ok
22:45:48.0476 8108 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:48.0477 8108 KeyIso - ok
22:45:48.0489 8108 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
22:45:48.0490 8108 KSecDD - ok
22:45:48.0512 8108 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
22:45:48.0514 8108 KSecPkg - ok
22:45:48.0525 8108 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:45:48.0526 8108 ksthunk - ok
22:45:48.0557 8108 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:45:48.0562 8108 KtmRm - ok
22:45:48.0587 8108 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:45:48.0590 8108 LanmanServer - ok
22:45:48.0607 8108 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:45:48.0610 8108 LanmanWorkstation - ok
22:45:48.0647 8108 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:45:48.0648 8108 lltdio - ok
22:45:48.0678 8108 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:45:48.0682 8108 lltdsvc - ok
22:45:48.0692 8108 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:45:48.0693 8108 lmhosts - ok
22:45:48.0709 8108 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:45:48.0711 8108 LSI_FC - ok
22:45:48.0722 8108 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:45:48.0723 8108 LSI_SAS - ok
22:45:48.0738 8108 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:45:48.0740 8108 LSI_SAS2 - ok
22:45:48.0750 8108 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:45:48.0751 8108 LSI_SCSI - ok
22:45:48.0775 8108 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:45:48.0777 8108 luafv - ok
22:45:48.0813 8108 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
22:45:48.0814 8108 MBAMProtector - ok
22:45:48.0900 8108 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:45:48.0917 8108 MBAMService - ok
22:45:48.0949 8108 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:45:48.0951 8108 Mcx2Svc - ok
22:45:48.0954 8108 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:45:48.0955 8108 megasas - ok
22:45:48.0980 8108 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:45:48.0983 8108 MegaSR - ok
22:45:49.0043 8108 Microsoft Office Groove Audit Service (7c4c76b39d5525c4a465e0be32528e19) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
22:45:49.0044 8108 Microsoft Office Groove Audit Service - ok
22:45:49.0069 8108 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:49.0070 8108 MMCSS - ok
22:45:49.0078 8108 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:45:49.0079 8108 Modem - ok
22:45:49.0104 8108 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:45:49.0105 8108 monitor - ok
22:45:49.0119 8108 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:45:49.0120 8108 mouclass - ok
22:45:49.0131 8108 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:45:49.0132 8108 mouhid - ok
22:45:49.0150 8108 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:45:49.0151 8108 mountmgr - ok
22:45:49.0200 8108 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:45:49.0200 8108 MozillaMaintenance - ok
22:45:49.0218 8108 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:45:49.0220 8108 mpio - ok
22:45:49.0237 8108 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:45:49.0239 8108 mpsdrv - ok
22:45:49.0294 8108 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:45:49.0314 8108 MpsSvc - ok
22:45:49.0340 8108 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:45:49.0342 8108 MRxDAV - ok
22:45:49.0368 8108 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:45:49.0370 8108 mrxsmb - ok
22:45:49.0391 8108 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:45:49.0394 8108 mrxsmb10 - ok
22:45:49.0435 8108 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:45:49.0437 8108 mrxsmb20 - ok
22:45:49.0443 8108 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:45:49.0443 8108 msahci - ok
22:45:49.0460 8108 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:45:49.0462 8108 msdsm - ok
22:45:49.0479 8108 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:45:49.0481 8108 MSDTC - ok
22:45:49.0488 8108 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:45:49.0489 8108 Msfs - ok
22:45:49.0494 8108 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:45:49.0495 8108 mshidkmdf - ok
22:45:49.0510 8108 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:45:49.0512 8108 msisadrv - ok
22:45:49.0561 8108 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:45:49.0564 8108 MSiSCSI - ok
22:45:49.0566 8108 msiserver - ok
22:45:49.0582 8108 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:45:49.0582 8108 MSKSSRV - ok
22:45:49.0590 8108 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:45:49.0591 8108 MSPCLOCK - ok
22:45:49.0596 8108 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:45:49.0597 8108 MSPQM - ok
22:45:49.0631 8108 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:45:49.0635 8108 MsRPC - ok
22:45:49.0668 8108 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:45:49.0668 8108 mssmbios - ok
22:45:49.0681 8108 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:45:49.0682 8108 MSTEE - ok
22:45:49.0689 8108 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:45:49.0690 8108 MTConfig - ok
22:45:49.0709 8108 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:45:49.0711 8108 Mup - ok
22:45:49.0754 8108 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:45:49.0769 8108 napagent - ok
22:45:49.0801 8108 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:45:49.0806 8108 NativeWifiP - ok
22:45:49.0870 8108 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:45:49.0879 8108 NDIS - ok
22:45:49.0895 8108 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:45:49.0896 8108 NdisCap - ok
22:45:49.0910 8108 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:45:49.0911 8108 NdisTapi - ok
22:45:49.0918 8108 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:45:49.0919 8108 Ndisuio - ok
22:45:49.0938 8108 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:45:49.0940 8108 NdisWan - ok
22:45:49.0956 8108 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:45:49.0957 8108 NDProxy - ok
22:45:49.0965 8108 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:45:49.0966 8108 NetBIOS - ok
22:45:49.0991 8108 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:45:49.0994 8108 NetBT - ok
22:45:50.0005 8108 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:50.0006 8108 Netlogon - ok
22:45:50.0049 8108 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:45:50.0054 8108 Netman - ok
22:45:50.0139 8108 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:50.0141 8108 NetMsmqActivator - ok
22:45:50.0572 8108 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:50.0573 8108 NetPipeActivator - ok
22:45:51.0098 8108 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:45:51.0103 8108 netprofm - ok
22:45:51.0119 8108 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:51.0120 8108 NetTcpActivator - ok
22:45:51.0123 8108 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:51.0123 8108 NetTcpPortSharing - ok
22:45:51.0151 8108 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:45:51.0152 8108 nfrd960 - ok
22:45:51.0183 8108 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:45:51.0187 8108 NlaSvc - ok
22:45:51.0199 8108 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:45:51.0200 8108 Npfs - ok
22:45:51.0217 8108 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:45:51.0219 8108 nsi - ok
22:45:51.0226 8108 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:45:51.0227 8108 nsiproxy - ok
22:45:51.0332 8108 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
22:45:51.0351 8108 Ntfs - ok
22:45:51.0411 8108 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:45:51.0412 8108 Null - ok
22:45:51.0444 8108 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\DRIVERS\nvraid.sys
22:45:51.0446 8108 nvraid - ok
22:45:51.0478 8108 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\DRIVERS\nvstor.sys
22:45:51.0480 8108 nvstor - ok
22:45:51.0501 8108 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:45:51.0503 8108 nv_agp - ok
22:45:51.0594 8108 odserv (1f0e05dff4f5a833168e49be1256f002) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:45:51.0607 8108 odserv - ok
22:45:51.0645 8108 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:45:51.0647 8108 ohci1394 - ok
22:45:51.0688 8108 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:45:51.0689 8108 ose - ok
22:45:51.0729 8108 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:51.0733 8108 p2pimsvc - ok
22:45:51.0759 8108 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:45:51.0765 8108 p2psvc - ok
22:45:51.0853 8108 PanService (20bd38241edd66d8fdc9e3496a1762a3) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
22:45:51.0855 8108 PanService - ok
22:45:51.0905 8108 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:45:51.0907 8108 Parport - ok
22:45:51.0919 8108 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
22:45:51.0920 8108 partmgr - ok
22:45:51.0942 8108 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:45:51.0945 8108 PcaSvc - ok
22:45:51.0964 8108 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:45:51.0965 8108 pci - ok
22:45:51.0973 8108 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:45:51.0974 8108 pciide - ok
22:45:51.0997 8108 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:45:51.0999 8108 pcmcia - ok
22:45:52.0016 8108 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:45:52.0017 8108 pcw - ok
22:45:52.0065 8108 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:45:52.0103 8108 PEAUTH - ok
22:45:52.0213 8108 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
22:45:52.0250 8108 PeerDistSvc - ok
22:45:52.0344 8108 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:45:52.0345 8108 PerfHost - ok
22:45:52.0490 8108 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:45:52.0533 8108 pla - ok
22:45:52.0597 8108 PlugPlay (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll
22:45:52.0608 8108 PlugPlay - ok
22:45:52.0633 8108 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:45:52.0635 8108 PNRPAutoReg - ok
22:45:52.0661 8108 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:52.0663 8108 PNRPsvc - ok
22:45:52.0728 8108 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:45:52.0750 8108 PolicyAgent - ok
22:45:52.0791 8108 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:45:52.0794 8108 Power - ok
22:45:52.0837 8108 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:45:52.0838 8108 PptpMiniport - ok
22:45:52.0858 8108 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:45:52.0859 8108 Processor - ok
22:45:52.0876 8108 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
22:45:52.0879 8108 ProfSvc - ok
22:45:52.0888 8108 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:52.0889 8108 ProtectedStorage - ok
22:45:52.0907 8108 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:45:52.0908 8108 Psched - ok
22:45:53.0013 8108 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:45:53.0047 8108 ql2300 - ok
22:45:53.0145 8108 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:45:53.0146 8108 ql40xx - ok
22:45:53.0173 8108 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:45:53.0176 8108 QWAVE - ok
22:45:53.0193 8108 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:45:53.0194 8108 QWAVEdrv - ok
22:45:53.0200 8108 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:45:53.0200 8108 RasAcd - ok
22:45:53.0221 8108 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:45:53.0222 8108 RasAgileVpn - ok
22:45:53.0237 8108 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:45:53.0239 8108 RasAuto - ok
22:45:53.0260 8108 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:45:53.0262 8108 Rasl2tp - ok
22:45:53.0294 8108 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:45:53.0299 8108 RasMan - ok
22:45:53.0321 8108 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:45:53.0322 8108 RasPppoe - ok
22:45:53.0339 8108 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:45:53.0340 8108 RasSstp - ok
22:44:53.0279 7936 ============================================================
22:44:53.0279 7936 Current date / time: 2012/08/01 22:44:53.0279
22:44:53.0279 7936 SystemInfo:
22:44:53.0279 7936
22:44:53.0279 7936 OS Version: 6.1.7600 ServicePack: 0.0
22:44:53.0279 7936 Product type: Workstation
22:44:53.0279 7936 ComputerName: DUSAN-PC
22:44:53.0279 7936 UserName: Dusan
22:44:53.0279 7936 Windows directory: C:\Windows
22:44:53.0279 7936 System windows directory: C:\Windows
22:44:53.0279 7936 Running under WOW64
22:44:53.0279 7936 Processor architecture: Intel x64
22:44:53.0279 7936 Number of processors: 4
22:44:53.0279 7936 Page size: 0x1000
22:44:53.0279 7936 Boot type: Normal boot
22:44:53.0279 7936 ============================================================
22:44:54.0789 7936 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:44:54.0797 7936 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:44:54.0816 7936 ============================================================
22:44:54.0816 7936 \Device\Harddisk0\DR0:
22:44:54.0816 7936 MBR partitions:
22:44:54.0816 7936 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x30D3C74
22:44:54.0822 7936 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x30D3CF2, BlocksNum 0x1A0EC9CE
22:44:54.0822 7936 \Device\Harddisk1\DR1:
22:44:54.0822 7936 MBR partitions:
22:44:54.0822 7936 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:44:54.0822 7936 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x57513000
22:44:54.0822 7936 ============================================================
22:44:54.0840 7936 C: <-> \Device\Harddisk1\DR1\Partition1
22:44:54.0891 7936 E: <-> \Device\Harddisk0\DR0\Partition0
22:44:54.0931 7936 F: <-> \Device\Harddisk0\DR0\Partition1
22:44:54.0931 7936 ============================================================
22:44:54.0931 7936 Initialize success
22:44:54.0931 7936 ============================================================
22:45:40.0480 8108 ============================================================
22:45:40.0480 8108 Scan started
22:45:40.0480 8108 Mode: Manual;
22:45:40.0480 8108 ============================================================
22:45:41.0463 8108 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
22:45:41.0465 8108 1394ohci - ok
22:45:41.0499 8108 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
22:45:41.0502 8108 ACPI - ok
22:45:41.0512 8108 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
22:45:41.0513 8108 AcpiPmi - ok
22:45:41.0605 8108 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:45:41.0606 8108 AdobeARMservice - ok
22:45:41.0714 8108 AdobeFlashPlayerUpdateSvc (6c40d5ed8951ab7b90d08af655224ee4) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:45:41.0717 8108 AdobeFlashPlayerUpdateSvc - ok
22:45:41.0759 8108 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:45:41.0770 8108 adp94xx - ok
22:45:41.0801 8108 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:45:41.0805 8108 adpahci - ok
22:45:41.0825 8108 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:45:41.0827 8108 adpu320 - ok
22:45:41.0853 8108 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
22:45:41.0854 8108 AeLookupSvc - ok
22:45:41.0907 8108 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
22:45:41.0919 8108 AFD - ok
22:45:41.0932 8108 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
22:45:41.0933 8108 agp440 - ok
22:45:41.0947 8108 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
22:45:41.0948 8108 ALG - ok
22:45:41.0965 8108 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
22:45:41.0965 8108 aliide - ok
22:45:41.0993 8108 AMD External Events Utility (6edb5d627aa83863da21f1d1b2b523b4) C:\Windows\system32\atiesrxx.exe
22:45:41.0996 8108 AMD External Events Utility - ok
22:45:42.0006 8108 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
22:45:42.0007 8108 amdide - ok
22:45:42.0015 8108 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:45:42.0016 8108 AmdK8 - ok
22:45:42.0035 8108 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:45:42.0036 8108 AmdPPM - ok
22:45:42.0066 8108 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\DRIVERS\amdsata.sys
22:45:42.0067 8108 amdsata - ok
22:45:42.0097 8108 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:45:42.0099 8108 amdsbs - ok
22:45:42.0109 8108 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\DRIVERS\amdxata.sys
22:45:42.0110 8108 amdxata - ok
22:45:42.0149 8108 androidusb (4de0d5d747a73797c95a97dcce5018b5) C:\Windows\system32\Drivers\ssadadb.sys
22:45:42.0150 8108 androidusb - ok
22:45:42.0164 8108 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
22:45:42.0165 8108 AppID - ok
22:45:42.0180 8108 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
22:45:42.0181 8108 AppIDSvc - ok
22:45:42.0203 8108 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
22:45:42.0204 8108 Appinfo - ok
22:45:42.0251 8108 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
22:45:42.0254 8108 AppMgmt - ok
22:45:42.0268 8108 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:45:42.0269 8108 arc - ok
22:45:42.0284 8108 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:45:42.0287 8108 arcsas - ok
22:45:42.0395 8108 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:45:42.0396 8108 aspnet_state - ok
22:45:42.0417 8108 aswFsBlk (e6dee1ff3ec08c146ae607257b2ac25e) C:\Windows\system32\drivers\aswFsBlk.sys
22:45:42.0417 8108 aswFsBlk - ok
22:45:42.0452 8108 aswMonFlt (976e731bc951d76237e960fad7402741) C:\Windows\system32\drivers\aswMonFlt.sys
22:45:42.0453 8108 aswMonFlt - ok
22:45:42.0461 8108 aswRdr (10fde4d126dd0d09d59a84f703449244) C:\Windows\system32\drivers\aswRdr.sys
22:45:42.0462 8108 aswRdr - ok
22:45:42.0487 8108 aswSP (0211624896d0b05f24533540e22fc740) C:\Windows\system32\drivers\aswSP.sys
22:45:42.0489 8108 aswSP - ok
22:45:42.0499 8108 aswTdi (f0cdae379c90d6e1d873c10b5ca1af0c) C:\Windows\system32\drivers\aswTdi.sys
22:45:42.0500 8108 aswTdi - ok
22:45:42.0510 8108 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:45:42.0510 8108 AsyncMac - ok
22:45:42.0513 8108 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
22:45:42.0514 8108 atapi - ok
22:45:42.0568 8108 AtiHdmiService (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
22:45:42.0570 8108 AtiHdmiService - ok
22:45:42.0898 8108 atikmdag (b86a300894d3531c4421d93977a2d7ee) C:\Windows\system32\DRIVERS\atikmdag.sys
22:45:42.0986 8108 atikmdag - ok
22:45:43.0077 8108 AtiPcie (db0d3de15edc96e7529fc0d3f7760894) C:\Windows\system32\DRIVERS\AtiPcie.sys
22:45:43.0077 8108 AtiPcie - ok
22:45:43.0133 8108 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:43.0152 8108 AudioEndpointBuilder - ok
22:45:43.0157 8108 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
22:45:43.0160 8108 AudioSrv - ok
22:45:43.0229 8108 avast! Antivirus (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0230 8108 avast! Antivirus - ok
22:45:43.0234 8108 avast! Mail Scanner (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0234 8108 avast! Mail Scanner - ok
22:45:43.0237 8108 avast! Web Scanner (8aaa93cd13e379eb76fbef56ac77d4d4) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
22:45:43.0237 8108 avast! Web Scanner - ok
22:45:43.0264 8108 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
22:45:43.0266 8108 AxInstSV - ok
22:45:43.0316 8108 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:45:43.0328 8108 b06bdrv - ok
22:45:43.0370 8108 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:45:43.0373 8108 b57nd60a - ok
22:45:43.0393 8108 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
22:45:43.0394 8108 BDESVC - ok
22:45:43.0417 8108 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:45:43.0417 8108 Beep - ok
22:45:43.0473 8108 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
22:45:43.0480 8108 BFE - ok
22:45:43.0537 8108 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
22:45:43.0561 8108 BITS - ok
22:45:43.0605 8108 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:45:43.0606 8108 blbdrive - ok
22:45:43.0680 8108 Bonjour Service (f832f1505ad8b83474bd9a5b1b985e01) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
22:45:43.0681 8108 Bonjour Service - ok
22:45:43.0709 8108 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
22:45:43.0711 8108 bowser - ok
22:45:43.0735 8108 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:45:43.0735 8108 BrFiltLo - ok
22:45:43.0741 8108 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:45:43.0742 8108 BrFiltUp - ok
22:45:43.0761 8108 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
22:45:43.0763 8108 Browser - ok
22:45:43.0784 8108 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:45:43.0787 8108 Brserid - ok
22:45:43.0791 8108 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:45:43.0792 8108 BrSerWdm - ok
22:45:43.0805 8108 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:45:43.0806 8108 BrUsbMdm - ok
22:45:43.0815 8108 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:45:43.0816 8108 BrUsbSer - ok
22:45:43.0841 8108 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
22:45:43.0842 8108 BthEnum - ok
22:45:43.0854 8108 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:45:43.0855 8108 BTHMODEM - ok
22:45:43.0902 8108 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
22:45:43.0903 8108 BthPan - ok
22:45:43.0956 8108 BTHPORT (a51fa9d0e85d5adabef72e67f386309c) C:\Windows\system32\Drivers\BTHport.sys
22:45:43.0964 8108 BTHPORT - ok
22:45:44.0007 8108 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
22:45:44.0008 8108 bthserv - ok
22:45:44.0033 8108 BTHUSB (f740b9a16b2c06700f2130e19986bf3b) C:\Windows\system32\Drivers\BTHUSB.sys
22:45:44.0034 8108 BTHUSB - ok
22:45:44.0064 8108 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:45:44.0066 8108 cdfs - ok
22:45:44.0093 8108 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
22:45:44.0095 8108 cdrom - ok
22:45:44.0115 8108 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:44.0116 8108 CertPropSvc - ok
22:45:44.0131 8108 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:45:44.0132 8108 circlass - ok
22:45:44.0163 8108 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:45:44.0167 8108 CLFS - ok
22:45:44.0219 8108 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:45:44.0220 8108 clr_optimization_v2.0.50727_32 - ok
22:45:44.0262 8108 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:45:44.0263 8108 clr_optimization_v2.0.50727_64 - ok
22:45:44.0365 8108 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:45:44.0367 8108 clr_optimization_v4.0.30319_32 - ok
22:45:44.0421 8108 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:45:44.0423 8108 clr_optimization_v4.0.30319_64 - ok
22:45:44.0441 8108 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:45:44.0442 8108 CmBatt - ok
22:45:44.0444 8108 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
22:45:44.0445 8108 cmdide - ok
22:45:44.0481 8108 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
22:45:44.0493 8108 CNG - ok
22:45:44.0519 8108 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:45:44.0521 8108 Compbatt - ok
22:45:44.0541 8108 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:45:44.0542 8108 CompositeBus - ok
22:45:44.0548 8108 COMSysApp - ok
22:45:44.0555 8108 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:45:44.0556 8108 crcdisk - ok
22:45:44.0582 8108 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
22:45:44.0584 8108 CryptSvc - ok
22:45:44.0622 8108 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
22:45:44.0637 8108 CSC - ok
22:45:44.0687 8108 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
22:45:44.0703 8108 CscService - ok
22:45:45.0141 8108 ctxusbm (bf62ff663ae55e4ed99de76881c2c0f1) C:\Windows\system32\DRIVERS\ctxusbm.sys
22:45:45.0142 8108 ctxusbm - ok
22:45:45.0217 8108 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:45.0223 8108 DcomLaunch - ok
22:45:45.0291 8108 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
22:45:45.0295 8108 defragsvc - ok
22:45:45.0306 8108 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
22:45:45.0308 8108 DfsC - ok
22:45:45.0330 8108 dgderdrv (def365f0f6e017888c4b869d3ba4b8e0) C:\Windows\system32\drivers\dgderdrv.sys
22:45:45.0331 8108 dgderdrv - ok
22:45:45.0346 8108 DgiVecp - ok
22:45:45.0383 8108 dg_ssudbus (6060106ce00f32f63f1a73160e46e9d2) C:\Windows\system32\DRIVERS\ssudbus.sys
22:45:45.0385 8108 dg_ssudbus - ok
22:45:45.0418 8108 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
22:45:45.0422 8108 Dhcp - ok
22:45:45.0433 8108 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:45:45.0434 8108 discache - ok
22:45:45.0454 8108 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:45:45.0455 8108 Disk - ok
22:45:45.0474 8108 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
22:45:45.0476 8108 Dnscache - ok
22:45:45.0501 8108 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
22:45:45.0504 8108 dot3svc - ok
22:45:45.0524 8108 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
22:45:45.0527 8108 DPS - ok
22:45:45.0550 8108 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:45:45.0551 8108 drmkaud - ok
22:45:45.0610 8108 DualCoreCenter (4bb346300c499de02f99b8789622ceaa) C:\Program Files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys
22:45:45.0610 8108 DualCoreCenter - ok
22:45:45.0685 8108 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
22:45:45.0695 8108 DXGKrnl - ok
22:45:45.0713 8108 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
22:45:45.0715 8108 EapHost - ok
22:45:45.0911 8108 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:45:45.0964 8108 ebdrv - ok
22:45:46.0046 8108 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
22:45:46.0048 8108 EFS - ok
22:45:46.0112 8108 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
22:45:46.0123 8108 ehRecvr - ok
22:45:46.0158 8108 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
22:45:46.0160 8108 ehSched - ok
22:45:46.0213 8108 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:45:46.0246 8108 elxstor - ok
22:45:46.0288 8108 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
22:45:46.0289 8108 ErrDev - ok
22:45:46.0329 8108 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
22:45:46.0334 8108 EventSystem - ok
22:45:46.0352 8108 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:45:46.0354 8108 exfat - ok
22:45:46.0376 8108 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:45:46.0379 8108 fastfat - ok
22:45:46.0434 8108 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
22:45:46.0478 8108 Fax - ok
22:45:46.0521 8108 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:45:46.0522 8108 fdc - ok
22:45:46.0533 8108 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
22:45:46.0534 8108 fdPHost - ok
22:45:46.0542 8108 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
22:45:46.0543 8108 FDResPub - ok
22:45:46.0555 8108 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:45:46.0556 8108 FileInfo - ok
22:45:46.0567 8108 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:45:46.0568 8108 Filetrace - ok
22:45:46.0573 8108 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:45:46.0574 8108 flpydisk - ok
22:45:46.0606 8108 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
22:45:46.0609 8108 FltMgr - ok
22:45:46.0685 8108 FontCache (bc00505cfda789ed3be95d2ff38c4875) C:\Windows\system32\FntCache.dll
22:45:46.0728 8108 FontCache - ok
22:45:46.0788 8108 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:45:46.0789 8108 FontCache3.0.0.0 - ok
22:45:46.0807 8108 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:45:46.0808 8108 FsDepends - ok
22:45:46.0821 8108 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
22:45:46.0821 8108 Fs_Rec - ok
22:45:46.0856 8108 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:45:46.0858 8108 fvevol - ok
22:45:46.0867 8108 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:45:46.0868 8108 gagp30kx - ok
22:45:46.0942 8108 GGSAFERDriver - ok
22:45:46.0993 8108 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
22:45:47.0043 8108 gpsvc - ok
22:45:47.0120 8108 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:45:47.0122 8108 gupdate - ok
22:45:47.0139 8108 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:45:47.0140 8108 gupdatem - ok
22:45:47.0162 8108 hamachi (f8f0851d336c3b88dbd7232b6348e09a) C:\Windows\system32\DRIVERS\hamachi.sys
22:45:47.0163 8108 hamachi - ok
22:45:47.0180 8108 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:45:47.0181 8108 hcw85cir - ok
22:45:47.0228 8108 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
22:45:47.0232 8108 HdAudAddService - ok
22:45:47.0251 8108 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:45:47.0253 8108 HDAudBus - ok
22:45:47.0255 8108 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:45:47.0256 8108 HidBatt - ok
22:45:47.0271 8108 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:45:47.0272 8108 HidBth - ok
22:45:47.0287 8108 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:45:47.0289 8108 HidIr - ok
22:45:47.0299 8108 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
22:45:47.0300 8108 hidserv - ok
22:45:47.0322 8108 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
22:45:47.0323 8108 HidUsb - ok
22:45:47.0348 8108 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
22:45:47.0350 8108 hkmsvc - ok
22:45:47.0376 8108 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
22:45:47.0379 8108 HomeGroupListener - ok
22:45:47.0405 8108 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
22:45:47.0408 8108 HomeGroupProvider - ok
22:45:47.0420 8108 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:45:47.0421 8108 HpSAMD - ok
22:45:47.0475 8108 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
22:45:47.0509 8108 HTTP - ok
22:45:47.0544 8108 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
22:45:47.0546 8108 hwpolicy - ok
22:45:47.0572 8108 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
22:45:47.0573 8108 i8042prt - ok
22:45:47.0623 8108 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\DRIVERS\iaStorV.sys
22:45:47.0628 8108 iaStorV - ok
22:45:47.0704 8108 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
22:45:47.0705 8108 IDriverT - ok
22:45:47.0791 8108 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:45:47.0821 8108 idsvc - ok
22:45:47.0892 8108 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:45:47.0893 8108 iirsp - ok
22:45:47.0957 8108 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
22:45:47.0995 8108 IKEEXT - ok
22:45:48.0146 8108 IntcAzAudAddService (627c6b352718e59df08f02c536e2e0ed) C:\Windows\system32\drivers\RTKVHD64.sys
22:45:48.0179 8108 IntcAzAudAddService - ok
22:45:48.0236 8108 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
22:45:48.0237 8108 intelide - ok
22:45:48.0259 8108 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:45:48.0260 8108 intelppm - ok
22:45:48.0271 8108 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
22:45:48.0272 8108 IPBusEnum - ok
22:45:48.0288 8108 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:45:48.0290 8108 IpFilterDriver - ok
22:45:48.0331 8108 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
22:45:48.0339 8108 iphlpsvc - ok
22:45:48.0349 8108 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:45:48.0351 8108 IPMIDRV - ok
22:45:48.0365 8108 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:45:48.0366 8108 IPNAT - ok
22:45:48.0386 8108 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:45:48.0387 8108 IRENUM - ok
22:45:48.0394 8108 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
22:45:48.0395 8108 isapnp - ok
22:45:48.0419 8108 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
22:45:48.0421 8108 iScsiPrt - ok
22:45:48.0435 8108 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
22:45:48.0437 8108 kbdclass - ok
22:45:48.0453 8108 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
22:45:48.0454 8108 kbdhid - ok
22:45:48.0476 8108 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:48.0477 8108 KeyIso - ok
22:45:48.0489 8108 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
22:45:48.0490 8108 KSecDD - ok
22:45:48.0512 8108 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
22:45:48.0514 8108 KSecPkg - ok
22:45:48.0525 8108 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:45:48.0526 8108 ksthunk - ok
22:45:48.0557 8108 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
22:45:48.0562 8108 KtmRm - ok
22:45:48.0587 8108 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
22:45:48.0590 8108 LanmanServer - ok
22:45:48.0607 8108 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
22:45:48.0610 8108 LanmanWorkstation - ok
22:45:48.0647 8108 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:45:48.0648 8108 lltdio - ok
22:45:48.0678 8108 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
22:45:48.0682 8108 lltdsvc - ok
22:45:48.0692 8108 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
22:45:48.0693 8108 lmhosts - ok
22:45:48.0709 8108 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:45:48.0711 8108 LSI_FC - ok
22:45:48.0722 8108 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:45:48.0723 8108 LSI_SAS - ok
22:45:48.0738 8108 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:45:48.0740 8108 LSI_SAS2 - ok
22:45:48.0750 8108 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:45:48.0751 8108 LSI_SCSI - ok
22:45:48.0775 8108 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:45:48.0777 8108 luafv - ok
22:45:48.0813 8108 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
22:45:48.0814 8108 MBAMProtector - ok
22:45:48.0900 8108 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:45:48.0917 8108 MBAMService - ok
22:45:48.0949 8108 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
22:45:48.0951 8108 Mcx2Svc - ok
22:45:48.0954 8108 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:45:48.0955 8108 megasas - ok
22:45:48.0980 8108 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:45:48.0983 8108 MegaSR - ok
22:45:49.0043 8108 Microsoft Office Groove Audit Service (7c4c76b39d5525c4a465e0be32528e19) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
22:45:49.0044 8108 Microsoft Office Groove Audit Service - ok
22:45:49.0069 8108 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:49.0070 8108 MMCSS - ok
22:45:49.0078 8108 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:45:49.0079 8108 Modem - ok
22:45:49.0104 8108 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:45:49.0105 8108 monitor - ok
22:45:49.0119 8108 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
22:45:49.0120 8108 mouclass - ok
22:45:49.0131 8108 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:45:49.0132 8108 mouhid - ok
22:45:49.0150 8108 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
22:45:49.0151 8108 mountmgr - ok
22:45:49.0200 8108 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:45:49.0200 8108 MozillaMaintenance - ok
22:45:49.0218 8108 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
22:45:49.0220 8108 mpio - ok
22:45:49.0237 8108 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:45:49.0239 8108 mpsdrv - ok
22:45:49.0294 8108 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
22:45:49.0314 8108 MpsSvc - ok
22:45:49.0340 8108 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
22:45:49.0342 8108 MRxDAV - ok
22:45:49.0368 8108 mrxsmb (b7f3d2c40bdf8ffb73ebfb19c77734e2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:45:49.0370 8108 mrxsmb - ok
22:45:49.0391 8108 mrxsmb10 (86c6f88b5168ce21cf8d69d0b3ff5d19) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:45:49.0394 8108 mrxsmb10 - ok
22:45:49.0435 8108 mrxsmb20 (b081069251c8e9f42cb8769d07148f9c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:45:49.0437 8108 mrxsmb20 - ok
22:45:49.0443 8108 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
22:45:49.0443 8108 msahci - ok
22:45:49.0460 8108 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
22:45:49.0462 8108 msdsm - ok
22:45:49.0479 8108 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
22:45:49.0481 8108 MSDTC - ok
22:45:49.0488 8108 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:45:49.0489 8108 Msfs - ok
22:45:49.0494 8108 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:45:49.0495 8108 mshidkmdf - ok
22:45:49.0510 8108 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
22:45:49.0512 8108 msisadrv - ok
22:45:49.0561 8108 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
22:45:49.0564 8108 MSiSCSI - ok
22:45:49.0566 8108 msiserver - ok
22:45:49.0582 8108 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:45:49.0582 8108 MSKSSRV - ok
22:45:49.0590 8108 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:45:49.0591 8108 MSPCLOCK - ok
22:45:49.0596 8108 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:45:49.0597 8108 MSPQM - ok
22:45:49.0631 8108 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
22:45:49.0635 8108 MsRPC - ok
22:45:49.0668 8108 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
22:45:49.0668 8108 mssmbios - ok
22:45:49.0681 8108 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:45:49.0682 8108 MSTEE - ok
22:45:49.0689 8108 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:45:49.0690 8108 MTConfig - ok
22:45:49.0709 8108 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:45:49.0711 8108 Mup - ok
22:45:49.0754 8108 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
22:45:49.0769 8108 napagent - ok
22:45:49.0801 8108 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:45:49.0806 8108 NativeWifiP - ok
22:45:49.0870 8108 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
22:45:49.0879 8108 NDIS - ok
22:45:49.0895 8108 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:45:49.0896 8108 NdisCap - ok
22:45:49.0910 8108 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:45:49.0911 8108 NdisTapi - ok
22:45:49.0918 8108 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
22:45:49.0919 8108 Ndisuio - ok
22:45:49.0938 8108 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:45:49.0940 8108 NdisWan - ok
22:45:49.0956 8108 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
22:45:49.0957 8108 NDProxy - ok
22:45:49.0965 8108 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:45:49.0966 8108 NetBIOS - ok
22:45:49.0991 8108 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
22:45:49.0994 8108 NetBT - ok
22:45:50.0005 8108 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:50.0006 8108 Netlogon - ok
22:45:50.0049 8108 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
22:45:50.0054 8108 Netman - ok
22:45:50.0139 8108 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:50.0141 8108 NetMsmqActivator - ok
22:45:50.0572 8108 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:50.0573 8108 NetPipeActivator - ok
22:45:51.0098 8108 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
22:45:51.0103 8108 netprofm - ok
22:45:51.0119 8108 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:51.0120 8108 NetTcpActivator - ok
22:45:51.0123 8108 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:45:51.0123 8108 NetTcpPortSharing - ok
22:45:51.0151 8108 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:45:51.0152 8108 nfrd960 - ok
22:45:51.0183 8108 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
22:45:51.0187 8108 NlaSvc - ok
22:45:51.0199 8108 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:45:51.0200 8108 Npfs - ok
22:45:51.0217 8108 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
22:45:51.0219 8108 nsi - ok
22:45:51.0226 8108 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:45:51.0227 8108 nsiproxy - ok
22:45:51.0332 8108 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
22:45:51.0351 8108 Ntfs - ok
22:45:51.0411 8108 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:45:51.0412 8108 Null - ok
22:45:51.0444 8108 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\DRIVERS\nvraid.sys
22:45:51.0446 8108 nvraid - ok
22:45:51.0478 8108 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\DRIVERS\nvstor.sys
22:45:51.0480 8108 nvstor - ok
22:45:51.0501 8108 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
22:45:51.0503 8108 nv_agp - ok
22:45:51.0594 8108 odserv (1f0e05dff4f5a833168e49be1256f002) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:45:51.0607 8108 odserv - ok
22:45:51.0645 8108 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
22:45:51.0647 8108 ohci1394 - ok
22:45:51.0688 8108 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:45:51.0689 8108 ose - ok
22:45:51.0729 8108 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:51.0733 8108 p2pimsvc - ok
22:45:51.0759 8108 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
22:45:51.0765 8108 p2psvc - ok
22:45:51.0853 8108 PanService (20bd38241edd66d8fdc9e3496a1762a3) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
22:45:51.0855 8108 PanService - ok
22:45:51.0905 8108 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:45:51.0907 8108 Parport - ok
22:45:51.0919 8108 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
22:45:51.0920 8108 partmgr - ok
22:45:51.0942 8108 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
22:45:51.0945 8108 PcaSvc - ok
22:45:51.0964 8108 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
22:45:51.0965 8108 pci - ok
22:45:51.0973 8108 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
22:45:51.0974 8108 pciide - ok
22:45:51.0997 8108 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:45:51.0999 8108 pcmcia - ok
22:45:52.0016 8108 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:45:52.0017 8108 pcw - ok
22:45:52.0065 8108 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:45:52.0103 8108 PEAUTH - ok
22:45:52.0213 8108 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
22:45:52.0250 8108 PeerDistSvc - ok
22:45:52.0344 8108 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
22:45:52.0345 8108 PerfHost - ok
22:45:52.0490 8108 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
22:45:52.0533 8108 pla - ok
22:45:52.0597 8108 PlugPlay (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll
22:45:52.0608 8108 PlugPlay - ok
22:45:52.0633 8108 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
22:45:52.0635 8108 PNRPAutoReg - ok
22:45:52.0661 8108 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
22:45:52.0663 8108 PNRPsvc - ok
22:45:52.0728 8108 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
22:45:52.0750 8108 PolicyAgent - ok
22:45:52.0791 8108 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
22:45:52.0794 8108 Power - ok
22:45:52.0837 8108 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
22:45:52.0838 8108 PptpMiniport - ok
22:45:52.0858 8108 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:45:52.0859 8108 Processor - ok
22:45:52.0876 8108 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
22:45:52.0879 8108 ProfSvc - ok
22:45:52.0888 8108 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:52.0889 8108 ProtectedStorage - ok
22:45:52.0907 8108 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
22:45:52.0908 8108 Psched - ok
22:45:53.0013 8108 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:45:53.0047 8108 ql2300 - ok
22:45:53.0145 8108 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:45:53.0146 8108 ql40xx - ok
22:45:53.0173 8108 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
22:45:53.0176 8108 QWAVE - ok
22:45:53.0193 8108 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:45:53.0194 8108 QWAVEdrv - ok
22:45:53.0200 8108 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:45:53.0200 8108 RasAcd - ok
22:45:53.0221 8108 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:45:53.0222 8108 RasAgileVpn - ok
22:45:53.0237 8108 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
22:45:53.0239 8108 RasAuto - ok
22:45:53.0260 8108 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:45:53.0262 8108 Rasl2tp - ok
22:45:53.0294 8108 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
22:45:53.0299 8108 RasMan - ok
22:45:53.0321 8108 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:45:53.0322 8108 RasPppoe - ok
22:45:53.0339 8108 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:45:53.0340 8108 RasSstp - ok
Re: Prosím o kontrolu LOGU
22:45:53.0370 8108 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
22:45:53.0373 8108 rdbss - ok
22:45:53.0386 8108 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:45:53.0387 8108 rdpbus - ok
22:45:53.0393 8108 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:45:53.0394 8108 RDPCDD - ok
22:45:53.0423 8108 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
22:45:53.0425 8108 RDPDR - ok
22:45:53.0443 8108 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:45:53.0444 8108 RDPENCDD - ok
22:45:53.0456 8108 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:45:53.0457 8108 RDPREFMP - ok
22:45:53.0483 8108 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
22:45:53.0486 8108 RDPWD - ok
22:45:53.0513 8108 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
22:45:53.0515 8108 rdyboost - ok
22:45:53.0540 8108 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:45:53.0542 8108 RemoteAccess - ok
22:45:53.0574 8108 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:45:53.0577 8108 RemoteRegistry - ok
22:45:53.0621 8108 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
22:45:53.0623 8108 RFCOMM - ok
22:45:53.0646 8108 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:45:53.0648 8108 RpcEptMapper - ok
22:45:53.0666 8108 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:45:53.0667 8108 RpcLocator - ok
22:45:53.0697 8108 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:53.0700 8108 RpcSs - ok
22:45:53.0724 8108 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:45:53.0725 8108 rspndr - ok
22:45:53.0766 8108 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
22:45:53.0768 8108 RTL8167 - ok
22:45:53.0823 8108 RushTopDevice2 (f86ed44261ac62e915fb0e4b2133039d) C:\Program Files (x86)\MSI\GreenPowerCenterII\RushTop64.sys
22:45:53.0824 8108 RushTopDevice2 - ok
22:45:53.0844 8108 RushTopDevice_J (ed4061d042a21961a94bab25fd505f6a) C:\Program Files (x86)\MSI\GreenPowerCenterII\RushJ64.sys
22:45:53.0846 8108 RushTopDevice_J - ok
22:45:53.0856 8108 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
22:45:53.0857 8108 s3cap - ok
22:45:53.0872 8108 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:53.0873 8108 SamSs - ok
22:45:53.0887 8108 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:45:53.0889 8108 sbp2port - ok
22:45:53.0918 8108 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:45:53.0921 8108 SCardSvr - ok
22:45:53.0937 8108 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:45:53.0938 8108 scfilter - ok
22:45:54.0019 8108 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:45:54.0045 8108 Schedule - ok
22:45:54.0082 8108 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:54.0082 8108 SCPolicySvc - ok
22:45:54.0104 8108 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:45:54.0107 8108 SDRSVC - ok
22:45:54.0136 8108 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:45:54.0137 8108 secdrv - ok
22:45:54.0150 8108 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:45:54.0152 8108 seclogon - ok
22:45:54.0167 8108 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:45:54.0169 8108 SENS - ok
22:45:54.0178 8108 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:45:54.0180 8108 SensrSvc - ok
22:45:54.0199 8108 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:45:54.0200 8108 Serenum - ok
22:45:54.0214 8108 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:45:54.0216 8108 Serial - ok
22:45:54.0226 8108 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:45:54.0227 8108 sermouse - ok
22:45:54.0249 8108 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:45:54.0251 8108 SessionEnv - ok
22:45:54.0262 8108 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:45:54.0263 8108 sffdisk - ok
22:45:54.0267 8108 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:45:54.0268 8108 sffp_mmc - ok
22:45:54.0274 8108 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:45:54.0275 8108 sffp_sd - ok
22:45:54.0282 8108 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:45:54.0283 8108 sfloppy - ok
22:45:54.0318 8108 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:45:54.0323 8108 SharedAccess - ok
22:45:54.0361 8108 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:45:54.0365 8108 ShellHWDetection - ok
22:45:54.0378 8108 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:45:54.0379 8108 SiSRaid2 - ok
22:45:54.0396 8108 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:45:54.0398 8108 SiSRaid4 - ok
22:45:54.0641 8108 Skype C2C Service (0f97e7a47a52f4a36969f0fc319654c2) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:45:54.0688 8108 Skype C2C Service - ok
22:45:54.0765 8108 SkypeUpdate (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:45:54.0766 8108 SkypeUpdate - ok
22:45:54.0865 8108 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:45:54.0866 8108 Smb - ok
22:45:54.0890 8108 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:45:54.0891 8108 SNMPTRAP - ok
22:45:54.0905 8108 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:45:54.0906 8108 spldr - ok
22:45:54.0946 8108 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:45:54.0973 8108 Spooler - ok
22:45:55.0189 8108 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:45:55.0249 8108 sppsvc - ok
22:45:55.0359 8108 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:45:55.0361 8108 sppuinotify - ok
22:45:55.0452 8108 sptd (88e5162e58c8919cc873f5d8946197cf) C:\Windows\system32\Drivers\sptd.sys
22:45:55.0453 8108 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88e5162e58c8919cc873f5d8946197cf
22:45:55.0455 8108 sptd ( LockedFile.Multi.Generic ) - warning
22:45:55.0455 8108 sptd - detected LockedFile.Multi.Generic (1)
22:45:55.0492 8108 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
22:45:55.0505 8108 srv - ok
22:45:55.0541 8108 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
22:45:55.0546 8108 srv2 - ok
22:45:55.0565 8108 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
22:45:55.0568 8108 srvnet - ok
22:45:55.0619 8108 ssadbus (8f8324ed1de63ffc7b1a02cd2d963c72) C:\Windows\system32\DRIVERS\ssadbus.sys
22:45:55.0621 8108 ssadbus - ok
22:45:55.0654 8108 ssadmdfl (58221efcb74167b73667f0024c661ce0) C:\Windows\system32\DRIVERS\ssadmdfl.sys
22:45:55.0655 8108 ssadmdfl - ok
22:45:55.0686 8108 ssadmdm (4da7c71bfac5ad71255b7e4cab980163) C:\Windows\system32\DRIVERS\ssadmdm.sys
22:45:55.0688 8108 ssadmdm - ok
22:45:55.0725 8108 sscdbus (ed161b91fdf7eaa39469d72d463d5f4e) C:\Windows\system32\DRIVERS\sscdbus.sys
22:45:55.0727 8108 sscdbus - ok
22:45:55.0756 8108 sscdmdfl (4cb09e77593dbd8d7af33b37375ca715) C:\Windows\system32\DRIVERS\sscdmdfl.sys
22:45:55.0757 8108 sscdmdfl - ok
22:45:55.0787 8108 sscdmdm (c7b4cf53497a6e5363f3439427663882) C:\Windows\system32\DRIVERS\sscdmdm.sys
22:45:55.0789 8108 sscdmdm - ok
22:45:55.0824 8108 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:45:55.0827 8108 SSDPSRV - ok
22:45:55.0867 8108 SSPORT (0211ab46b73a2623b86c1cfcb30579ab) C:\Windows\system32\Drivers\SSPORT.sys
22:45:55.0868 8108 SSPORT - ok
22:45:55.0886 8108 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:45:55.0888 8108 SstpSvc - ok
22:45:55.0925 8108 ssudmdm (855335bf5792e56164f98c012e3d92dd) C:\Windows\system32\DRIVERS\ssudmdm.sys
22:45:55.0927 8108 ssudmdm - ok
22:45:55.0940 8108 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:45:55.0941 8108 stexstor - ok
22:45:55.0980 8108 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:45:55.0998 8108 stisvc - ok
22:45:56.0026 8108 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
22:45:56.0027 8108 storflt - ok
22:45:56.0044 8108 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
22:45:56.0045 8108 storvsc - ok
22:45:56.0059 8108 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:45:56.0059 8108 swenum - ok
22:45:56.0659 8108 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:45:56.0665 8108 swprv - ok
22:45:56.0767 8108 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:45:56.0801 8108 SysMain - ok
22:45:56.0894 8108 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:45:56.0897 8108 TabletInputService - ok
22:45:56.0928 8108 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:45:56.0932 8108 TapiSrv - ok
22:45:56.0949 8108 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:45:56.0952 8108 TBS - ok
22:45:57.0082 8108 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
22:45:57.0100 8108 Tcpip - ok
22:45:57.0246 8108 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
22:45:57.0253 8108 TCPIP6 - ok
22:45:57.0316 8108 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:45:57.0317 8108 tcpipreg - ok
22:45:57.0328 8108 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:45:57.0328 8108 TDPIPE - ok
22:45:57.0331 8108 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
22:45:57.0332 8108 TDTCP - ok
22:45:57.0356 8108 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:45:57.0358 8108 tdx - ok
22:45:57.0373 8108 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:45:57.0374 8108 TermDD - ok
22:45:57.0425 8108 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:45:57.0460 8108 TermService - ok
22:45:57.0503 8108 TFsExDisk - ok
22:45:57.0516 8108 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:45:57.0517 8108 Themes - ok
22:45:57.0534 8108 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:57.0535 8108 THREADORDER - ok
22:45:57.0584 8108 TomTomHOMEService (fbd16717fd68b206c4ce3bb3c9ee5cb3) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
22:45:57.0585 8108 TomTomHOMEService - ok
22:45:57.0602 8108 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:45:57.0604 8108 TrkWks - ok
22:45:57.0636 8108 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:45:57.0638 8108 TrustedInstaller - ok
22:45:57.0652 8108 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:45:57.0653 8108 tssecsrv - ok
22:45:57.0683 8108 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:45:57.0686 8108 tunnel - ok
22:45:57.0700 8108 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:45:57.0701 8108 uagp35 - ok
22:45:57.0731 8108 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:45:57.0735 8108 udfs - ok
22:45:57.0756 8108 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:45:57.0758 8108 UI0Detect - ok
22:45:57.0773 8108 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:45:57.0774 8108 uliagpkx - ok
22:45:57.0799 8108 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:45:57.0800 8108 umbus - ok
22:45:57.0820 8108 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:45:57.0821 8108 UmPass - ok
22:45:57.0846 8108 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
22:45:57.0849 8108 UmRdpService - ok
22:45:57.0884 8108 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:45:57.0889 8108 upnphost - ok
22:45:57.0913 8108 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:45:57.0915 8108 usbccgp - ok
22:45:57.0936 8108 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:45:57.0938 8108 usbcir - ok
22:45:57.0956 8108 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
22:45:57.0957 8108 usbehci - ok
22:45:57.0998 8108 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
22:45:58.0001 8108 usbhub - ok
22:45:58.0015 8108 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:45:58.0016 8108 usbohci - ok
22:45:58.0029 8108 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:45:58.0030 8108 usbprint - ok
22:45:58.0047 8108 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
22:45:58.0048 8108 usbscan - ok
22:45:58.0071 8108 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:45:58.0073 8108 USBSTOR - ok
22:45:58.0090 8108 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:45:58.0091 8108 usbuhci - ok
22:45:58.0105 8108 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:45:58.0107 8108 UxSms - ok
22:45:58.0121 8108 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:58.0122 8108 VaultSvc - ok
22:45:58.0133 8108 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:45:58.0134 8108 vdrvroot - ok
22:45:58.0177 8108 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:45:58.0187 8108 vds - ok
22:45:58.0204 8108 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:45:58.0205 8108 vga - ok
22:45:58.0212 8108 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:45:58.0213 8108 VgaSave - ok
22:45:58.0238 8108 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:45:58.0241 8108 vhdmp - ok
22:45:58.0257 8108 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:45:58.0258 8108 viaide - ok
22:45:58.0293 8108 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
22:45:58.0296 8108 vmbus - ok
22:45:58.0319 8108 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
22:45:58.0320 8108 VMBusHID - ok
22:45:58.0329 8108 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:45:58.0330 8108 volmgr - ok
22:45:58.0359 8108 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:45:58.0362 8108 volmgrx - ok
22:45:58.0388 8108 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:45:58.0391 8108 volsnap - ok
22:45:58.0412 8108 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:45:58.0414 8108 vsmraid - ok
22:45:58.0511 8108 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:45:58.0542 8108 VSS - ok
22:45:58.0618 8108 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
22:45:58.0619 8108 vwifibus - ok
22:45:58.0647 8108 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:45:58.0652 8108 W32Time - ok
22:45:58.0667 8108 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:45:58.0668 8108 WacomPen - ok
22:45:58.0698 8108 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:58.0700 8108 WANARP - ok
22:45:58.0702 8108 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:58.0703 8108 Wanarpv6 - ok
22:45:58.0814 8108 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
22:45:58.0848 8108 WatAdminSvc - ok
22:45:58.0945 8108 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:45:58.0980 8108 wbengine - ok
22:45:59.0075 8108 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:45:59.0079 8108 WbioSrvc - ok
22:45:59.0117 8108 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:45:59.0122 8108 wcncsvc - ok
22:45:59.0135 8108 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:45:59.0137 8108 WcsPlugInService - ok
22:45:59.0169 8108 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:45:59.0170 8108 Wd - ok
22:45:59.0190 8108 WDC_SAM (a3d04ebf5227886029b4532f20d026f7) C:\Windows\system32\DRIVERS\wdcsam64.sys
22:45:59.0191 8108 WDC_SAM - ok
22:45:59.0230 8108 WDDMService.exe (eab3c68e3c38646ac5d5225f9d943d12) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
22:45:59.0231 8108 WDDMService.exe - ok
22:45:59.0278 8108 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:45:59.0290 8108 Wdf01000 - ok
22:45:59.0324 8108 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:45:59.0326 8108 WdiServiceHost - ok
22:45:59.0328 8108 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:45:59.0330 8108 WdiSystemHost - ok
22:45:59.0392 8108 WDSmartWareBackgroundService (138ab06adbbf300aa804d7974a5aec82) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
22:45:59.0393 8108 WDSmartWareBackgroundService - ok
22:45:59.0421 8108 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:45:59.0425 8108 WebClient - ok
22:45:59.0447 8108 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:45:59.0451 8108 Wecsvc - ok
22:45:59.0466 8108 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:45:59.0468 8108 wercplsupport - ok
22:45:59.0495 8108 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:45:59.0497 8108 WerSvc - ok
22:45:59.0529 8108 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:45:59.0530 8108 WfpLwf - ok
22:45:59.0540 8108 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:45:59.0541 8108 WIMMount - ok
22:45:59.0542 8108 WinDefend - ok
22:45:59.0548 8108 WinHttpAutoProxySvc - ok
22:45:59.0585 8108 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:45:59.0587 8108 Winmgmt - ok
22:45:59.0716 8108 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:45:59.0744 8108 WinRM - ok
22:45:59.0855 8108 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
22:45:59.0856 8108 WinUsb - ok
22:45:59.0913 8108 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:45:59.0922 8108 Wlansvc - ok
22:46:00.0116 8108 wlidsvc (98f138897ef4246381d197cb81846d62) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:46:00.0145 8108 wlidsvc - ok
22:46:00.0244 8108 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:46:00.0244 8108 WmiAcpi - ok
22:46:00.0292 8108 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:46:00.0294 8108 wmiApSrv - ok
22:46:00.0297 8108 WMPNetworkSvc - ok
22:46:00.0313 8108 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:46:00.0315 8108 WPCSvc - ok
22:46:00.0333 8108 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:46:00.0335 8108 WPDBusEnum - ok
22:46:00.0348 8108 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:46:00.0349 8108 ws2ifsl - ok
22:46:00.0372 8108 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:46:00.0374 8108 wscsvc - ok
22:46:00.0376 8108 WSearch - ok
22:46:00.0528 8108 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
22:46:00.0560 8108 wuauserv - ok
22:46:00.0657 8108 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:46:00.0659 8108 WudfPf - ok
22:46:00.0691 8108 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:46:00.0693 8108 WUDFRd - ok
22:46:00.0710 8108 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:46:00.0712 8108 wudfsvc - ok
22:46:00.0735 8108 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:46:00.0739 8108 WwanSvc - ok
22:46:00.0775 8108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:46:01.0069 8108 \Device\Harddisk0\DR0 - ok
22:46:01.0101 8108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
22:46:01.0228 8108 \Device\Harddisk1\DR1 - ok
22:46:01.0230 8108 Boot (0x1200) (03c57e2351f86cf0435b4bff4d3f3e21) \Device\Harddisk0\DR0\Partition0
22:46:01.0232 8108 \Device\Harddisk0\DR0\Partition0 - ok
22:46:01.0241 8108 Boot (0x1200) (be3c21a2c3d3b2d9da39773b98bd27ee) \Device\Harddisk0\DR0\Partition1
22:46:01.0242 8108 \Device\Harddisk0\DR0\Partition1 - ok
22:46:01.0245 8108 Boot (0x1200) (7c1cca727edd0612f73d7ae3fcb9a043) \Device\Harddisk1\DR1\Partition0
22:46:01.0246 8108 \Device\Harddisk1\DR1\Partition0 - ok
22:46:01.0275 8108 Boot (0x1200) (eb826ece3edd25e56292603c9084a8d2) \Device\Harddisk1\DR1\Partition1
22:46:01.0276 8108 \Device\Harddisk1\DR1\Partition1 - ok
22:46:01.0276 8108 ============================================================
22:46:01.0276 8108 Scan finished
22:46:01.0276 8108 ============================================================
22:46:01.0282 2368 Detected object count: 1
22:46:01.0282 2368 Actual detected object count: 1
22:46:09.0917 2368 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:46:09.0917 2368 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
22:45:53.0373 8108 rdbss - ok
22:45:53.0386 8108 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:45:53.0387 8108 rdpbus - ok
22:45:53.0393 8108 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:45:53.0394 8108 RDPCDD - ok
22:45:53.0423 8108 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
22:45:53.0425 8108 RDPDR - ok
22:45:53.0443 8108 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:45:53.0444 8108 RDPENCDD - ok
22:45:53.0456 8108 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:45:53.0457 8108 RDPREFMP - ok
22:45:53.0483 8108 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
22:45:53.0486 8108 RDPWD - ok
22:45:53.0513 8108 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
22:45:53.0515 8108 rdyboost - ok
22:45:53.0540 8108 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
22:45:53.0542 8108 RemoteAccess - ok
22:45:53.0574 8108 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
22:45:53.0577 8108 RemoteRegistry - ok
22:45:53.0621 8108 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
22:45:53.0623 8108 RFCOMM - ok
22:45:53.0646 8108 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
22:45:53.0648 8108 RpcEptMapper - ok
22:45:53.0666 8108 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
22:45:53.0667 8108 RpcLocator - ok
22:45:53.0697 8108 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
22:45:53.0700 8108 RpcSs - ok
22:45:53.0724 8108 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:45:53.0725 8108 rspndr - ok
22:45:53.0766 8108 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
22:45:53.0768 8108 RTL8167 - ok
22:45:53.0823 8108 RushTopDevice2 (f86ed44261ac62e915fb0e4b2133039d) C:\Program Files (x86)\MSI\GreenPowerCenterII\RushTop64.sys
22:45:53.0824 8108 RushTopDevice2 - ok
22:45:53.0844 8108 RushTopDevice_J (ed4061d042a21961a94bab25fd505f6a) C:\Program Files (x86)\MSI\GreenPowerCenterII\RushJ64.sys
22:45:53.0846 8108 RushTopDevice_J - ok
22:45:53.0856 8108 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
22:45:53.0857 8108 s3cap - ok
22:45:53.0872 8108 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:53.0873 8108 SamSs - ok
22:45:53.0887 8108 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
22:45:53.0889 8108 sbp2port - ok
22:45:53.0918 8108 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
22:45:53.0921 8108 SCardSvr - ok
22:45:53.0937 8108 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
22:45:53.0938 8108 scfilter - ok
22:45:54.0019 8108 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
22:45:54.0045 8108 Schedule - ok
22:45:54.0082 8108 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
22:45:54.0082 8108 SCPolicySvc - ok
22:45:54.0104 8108 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
22:45:54.0107 8108 SDRSVC - ok
22:45:54.0136 8108 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:45:54.0137 8108 secdrv - ok
22:45:54.0150 8108 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
22:45:54.0152 8108 seclogon - ok
22:45:54.0167 8108 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
22:45:54.0169 8108 SENS - ok
22:45:54.0178 8108 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
22:45:54.0180 8108 SensrSvc - ok
22:45:54.0199 8108 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:45:54.0200 8108 Serenum - ok
22:45:54.0214 8108 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:45:54.0216 8108 Serial - ok
22:45:54.0226 8108 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:45:54.0227 8108 sermouse - ok
22:45:54.0249 8108 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
22:45:54.0251 8108 SessionEnv - ok
22:45:54.0262 8108 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
22:45:54.0263 8108 sffdisk - ok
22:45:54.0267 8108 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:45:54.0268 8108 sffp_mmc - ok
22:45:54.0274 8108 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:45:54.0275 8108 sffp_sd - ok
22:45:54.0282 8108 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:45:54.0283 8108 sfloppy - ok
22:45:54.0318 8108 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
22:45:54.0323 8108 SharedAccess - ok
22:45:54.0361 8108 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
22:45:54.0365 8108 ShellHWDetection - ok
22:45:54.0378 8108 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:45:54.0379 8108 SiSRaid2 - ok
22:45:54.0396 8108 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:45:54.0398 8108 SiSRaid4 - ok
22:45:54.0641 8108 Skype C2C Service (0f97e7a47a52f4a36969f0fc319654c2) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:45:54.0688 8108 Skype C2C Service - ok
22:45:54.0765 8108 SkypeUpdate (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files (x86)\Skype\Updater\Updater.exe
22:45:54.0766 8108 SkypeUpdate - ok
22:45:54.0865 8108 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:45:54.0866 8108 Smb - ok
22:45:54.0890 8108 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
22:45:54.0891 8108 SNMPTRAP - ok
22:45:54.0905 8108 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:45:54.0906 8108 spldr - ok
22:45:54.0946 8108 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
22:45:54.0973 8108 Spooler - ok
22:45:55.0189 8108 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
22:45:55.0249 8108 sppsvc - ok
22:45:55.0359 8108 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
22:45:55.0361 8108 sppuinotify - ok
22:45:55.0452 8108 sptd (88e5162e58c8919cc873f5d8946197cf) C:\Windows\system32\Drivers\sptd.sys
22:45:55.0453 8108 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88e5162e58c8919cc873f5d8946197cf
22:45:55.0455 8108 sptd ( LockedFile.Multi.Generic ) - warning
22:45:55.0455 8108 sptd - detected LockedFile.Multi.Generic (1)
22:45:55.0492 8108 srv (148d50904d2a0df29a19778715eb35bb) C:\Windows\system32\DRIVERS\srv.sys
22:45:55.0505 8108 srv - ok
22:45:55.0541 8108 srv2 (ce2189fe31d36678ac9eb7ddee08ec96) C:\Windows\system32\DRIVERS\srv2.sys
22:45:55.0546 8108 srv2 - ok
22:45:55.0565 8108 srvnet (cb69edeb069a49577592835659cd0e46) C:\Windows\system32\DRIVERS\srvnet.sys
22:45:55.0568 8108 srvnet - ok
22:45:55.0619 8108 ssadbus (8f8324ed1de63ffc7b1a02cd2d963c72) C:\Windows\system32\DRIVERS\ssadbus.sys
22:45:55.0621 8108 ssadbus - ok
22:45:55.0654 8108 ssadmdfl (58221efcb74167b73667f0024c661ce0) C:\Windows\system32\DRIVERS\ssadmdfl.sys
22:45:55.0655 8108 ssadmdfl - ok
22:45:55.0686 8108 ssadmdm (4da7c71bfac5ad71255b7e4cab980163) C:\Windows\system32\DRIVERS\ssadmdm.sys
22:45:55.0688 8108 ssadmdm - ok
22:45:55.0725 8108 sscdbus (ed161b91fdf7eaa39469d72d463d5f4e) C:\Windows\system32\DRIVERS\sscdbus.sys
22:45:55.0727 8108 sscdbus - ok
22:45:55.0756 8108 sscdmdfl (4cb09e77593dbd8d7af33b37375ca715) C:\Windows\system32\DRIVERS\sscdmdfl.sys
22:45:55.0757 8108 sscdmdfl - ok
22:45:55.0787 8108 sscdmdm (c7b4cf53497a6e5363f3439427663882) C:\Windows\system32\DRIVERS\sscdmdm.sys
22:45:55.0789 8108 sscdmdm - ok
22:45:55.0824 8108 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
22:45:55.0827 8108 SSDPSRV - ok
22:45:55.0867 8108 SSPORT (0211ab46b73a2623b86c1cfcb30579ab) C:\Windows\system32\Drivers\SSPORT.sys
22:45:55.0868 8108 SSPORT - ok
22:45:55.0886 8108 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
22:45:55.0888 8108 SstpSvc - ok
22:45:55.0925 8108 ssudmdm (855335bf5792e56164f98c012e3d92dd) C:\Windows\system32\DRIVERS\ssudmdm.sys
22:45:55.0927 8108 ssudmdm - ok
22:45:55.0940 8108 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:45:55.0941 8108 stexstor - ok
22:45:55.0980 8108 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
22:45:55.0998 8108 stisvc - ok
22:45:56.0026 8108 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
22:45:56.0027 8108 storflt - ok
22:45:56.0044 8108 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
22:45:56.0045 8108 storvsc - ok
22:45:56.0059 8108 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
22:45:56.0059 8108 swenum - ok
22:45:56.0659 8108 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
22:45:56.0665 8108 swprv - ok
22:45:56.0767 8108 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
22:45:56.0801 8108 SysMain - ok
22:45:56.0894 8108 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
22:45:56.0897 8108 TabletInputService - ok
22:45:56.0928 8108 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
22:45:56.0932 8108 TapiSrv - ok
22:45:56.0949 8108 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
22:45:56.0952 8108 TBS - ok
22:45:57.0082 8108 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
22:45:57.0100 8108 Tcpip - ok
22:45:57.0246 8108 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
22:45:57.0253 8108 TCPIP6 - ok
22:45:57.0316 8108 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
22:45:57.0317 8108 tcpipreg - ok
22:45:57.0328 8108 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:45:57.0328 8108 TDPIPE - ok
22:45:57.0331 8108 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
22:45:57.0332 8108 TDTCP - ok
22:45:57.0356 8108 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
22:45:57.0358 8108 tdx - ok
22:45:57.0373 8108 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
22:45:57.0374 8108 TermDD - ok
22:45:57.0425 8108 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
22:45:57.0460 8108 TermService - ok
22:45:57.0503 8108 TFsExDisk - ok
22:45:57.0516 8108 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
22:45:57.0517 8108 Themes - ok
22:45:57.0534 8108 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
22:45:57.0535 8108 THREADORDER - ok
22:45:57.0584 8108 TomTomHOMEService (fbd16717fd68b206c4ce3bb3c9ee5cb3) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
22:45:57.0585 8108 TomTomHOMEService - ok
22:45:57.0602 8108 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
22:45:57.0604 8108 TrkWks - ok
22:45:57.0636 8108 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
22:45:57.0638 8108 TrustedInstaller - ok
22:45:57.0652 8108 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:45:57.0653 8108 tssecsrv - ok
22:45:57.0683 8108 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
22:45:57.0686 8108 tunnel - ok
22:45:57.0700 8108 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:45:57.0701 8108 uagp35 - ok
22:45:57.0731 8108 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
22:45:57.0735 8108 udfs - ok
22:45:57.0756 8108 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
22:45:57.0758 8108 UI0Detect - ok
22:45:57.0773 8108 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:45:57.0774 8108 uliagpkx - ok
22:45:57.0799 8108 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
22:45:57.0800 8108 umbus - ok
22:45:57.0820 8108 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:45:57.0821 8108 UmPass - ok
22:45:57.0846 8108 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
22:45:57.0849 8108 UmRdpService - ok
22:45:57.0884 8108 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
22:45:57.0889 8108 upnphost - ok
22:45:57.0913 8108 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
22:45:57.0915 8108 usbccgp - ok
22:45:57.0936 8108 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
22:45:57.0938 8108 usbcir - ok
22:45:57.0956 8108 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
22:45:57.0957 8108 usbehci - ok
22:45:57.0998 8108 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
22:45:58.0001 8108 usbhub - ok
22:45:58.0015 8108 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
22:45:58.0016 8108 usbohci - ok
22:45:58.0029 8108 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:45:58.0030 8108 usbprint - ok
22:45:58.0047 8108 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
22:45:58.0048 8108 usbscan - ok
22:45:58.0071 8108 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:45:58.0073 8108 USBSTOR - ok
22:45:58.0090 8108 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:45:58.0091 8108 usbuhci - ok
22:45:58.0105 8108 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
22:45:58.0107 8108 UxSms - ok
22:45:58.0121 8108 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
22:45:58.0122 8108 VaultSvc - ok
22:45:58.0133 8108 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:45:58.0134 8108 vdrvroot - ok
22:45:58.0177 8108 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
22:45:58.0187 8108 vds - ok
22:45:58.0204 8108 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:45:58.0205 8108 vga - ok
22:45:58.0212 8108 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:45:58.0213 8108 VgaSave - ok
22:45:58.0238 8108 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
22:45:58.0241 8108 vhdmp - ok
22:45:58.0257 8108 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
22:45:58.0258 8108 viaide - ok
22:45:58.0293 8108 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
22:45:58.0296 8108 vmbus - ok
22:45:58.0319 8108 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
22:45:58.0320 8108 VMBusHID - ok
22:45:58.0329 8108 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
22:45:58.0330 8108 volmgr - ok
22:45:58.0359 8108 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
22:45:58.0362 8108 volmgrx - ok
22:45:58.0388 8108 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
22:45:58.0391 8108 volsnap - ok
22:45:58.0412 8108 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:45:58.0414 8108 vsmraid - ok
22:45:58.0511 8108 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
22:45:58.0542 8108 VSS - ok
22:45:58.0618 8108 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
22:45:58.0619 8108 vwifibus - ok
22:45:58.0647 8108 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
22:45:58.0652 8108 W32Time - ok
22:45:58.0667 8108 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:45:58.0668 8108 WacomPen - ok
22:45:58.0698 8108 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:58.0700 8108 WANARP - ok
22:45:58.0702 8108 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
22:45:58.0703 8108 Wanarpv6 - ok
22:45:58.0814 8108 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
22:45:58.0848 8108 WatAdminSvc - ok
22:45:58.0945 8108 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
22:45:58.0980 8108 wbengine - ok
22:45:59.0075 8108 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
22:45:59.0079 8108 WbioSrvc - ok
22:45:59.0117 8108 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
22:45:59.0122 8108 wcncsvc - ok
22:45:59.0135 8108 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
22:45:59.0137 8108 WcsPlugInService - ok
22:45:59.0169 8108 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:45:59.0170 8108 Wd - ok
22:45:59.0190 8108 WDC_SAM (a3d04ebf5227886029b4532f20d026f7) C:\Windows\system32\DRIVERS\wdcsam64.sys
22:45:59.0191 8108 WDC_SAM - ok
22:45:59.0230 8108 WDDMService.exe (eab3c68e3c38646ac5d5225f9d943d12) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
22:45:59.0231 8108 WDDMService.exe - ok
22:45:59.0278 8108 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:45:59.0290 8108 Wdf01000 - ok
22:45:59.0324 8108 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:45:59.0326 8108 WdiServiceHost - ok
22:45:59.0328 8108 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
22:45:59.0330 8108 WdiSystemHost - ok
22:45:59.0392 8108 WDSmartWareBackgroundService (138ab06adbbf300aa804d7974a5aec82) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
22:45:59.0393 8108 WDSmartWareBackgroundService - ok
22:45:59.0421 8108 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
22:45:59.0425 8108 WebClient - ok
22:45:59.0447 8108 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
22:45:59.0451 8108 Wecsvc - ok
22:45:59.0466 8108 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
22:45:59.0468 8108 wercplsupport - ok
22:45:59.0495 8108 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
22:45:59.0497 8108 WerSvc - ok
22:45:59.0529 8108 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:45:59.0530 8108 WfpLwf - ok
22:45:59.0540 8108 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:45:59.0541 8108 WIMMount - ok
22:45:59.0542 8108 WinDefend - ok
22:45:59.0548 8108 WinHttpAutoProxySvc - ok
22:45:59.0585 8108 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
22:45:59.0587 8108 Winmgmt - ok
22:45:59.0716 8108 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
22:45:59.0744 8108 WinRM - ok
22:45:59.0855 8108 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
22:45:59.0856 8108 WinUsb - ok
22:45:59.0913 8108 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
22:45:59.0922 8108 Wlansvc - ok
22:46:00.0116 8108 wlidsvc (98f138897ef4246381d197cb81846d62) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:46:00.0145 8108 wlidsvc - ok
22:46:00.0244 8108 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:46:00.0244 8108 WmiAcpi - ok
22:46:00.0292 8108 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
22:46:00.0294 8108 wmiApSrv - ok
22:46:00.0297 8108 WMPNetworkSvc - ok
22:46:00.0313 8108 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
22:46:00.0315 8108 WPCSvc - ok
22:46:00.0333 8108 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
22:46:00.0335 8108 WPDBusEnum - ok
22:46:00.0348 8108 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:46:00.0349 8108 ws2ifsl - ok
22:46:00.0372 8108 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
22:46:00.0374 8108 wscsvc - ok
22:46:00.0376 8108 WSearch - ok
22:46:00.0528 8108 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
22:46:00.0560 8108 wuauserv - ok
22:46:00.0657 8108 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
22:46:00.0659 8108 WudfPf - ok
22:46:00.0691 8108 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:46:00.0693 8108 WUDFRd - ok
22:46:00.0710 8108 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
22:46:00.0712 8108 wudfsvc - ok
22:46:00.0735 8108 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
22:46:00.0739 8108 WwanSvc - ok
22:46:00.0775 8108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:46:01.0069 8108 \Device\Harddisk0\DR0 - ok
22:46:01.0101 8108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
22:46:01.0228 8108 \Device\Harddisk1\DR1 - ok
22:46:01.0230 8108 Boot (0x1200) (03c57e2351f86cf0435b4bff4d3f3e21) \Device\Harddisk0\DR0\Partition0
22:46:01.0232 8108 \Device\Harddisk0\DR0\Partition0 - ok
22:46:01.0241 8108 Boot (0x1200) (be3c21a2c3d3b2d9da39773b98bd27ee) \Device\Harddisk0\DR0\Partition1
22:46:01.0242 8108 \Device\Harddisk0\DR0\Partition1 - ok
22:46:01.0245 8108 Boot (0x1200) (7c1cca727edd0612f73d7ae3fcb9a043) \Device\Harddisk1\DR1\Partition0
22:46:01.0246 8108 \Device\Harddisk1\DR1\Partition0 - ok
22:46:01.0275 8108 Boot (0x1200) (eb826ece3edd25e56292603c9084a8d2) \Device\Harddisk1\DR1\Partition1
22:46:01.0276 8108 \Device\Harddisk1\DR1\Partition1 - ok
22:46:01.0276 8108 ============================================================
22:46:01.0276 8108 Scan finished
22:46:01.0276 8108 ============================================================
22:46:01.0282 2368 Detected object count: 1
22:46:01.0282 2368 Actual detected object count: 1
22:46:09.0917 2368 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:46:09.0917 2368 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Re: Prosím o kontrolu LOGU
a poslední log
ComboFix 12-07-31.03 - Dusan 01.08.2012 22:59:38.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.4094.2546 [GMT 2:00]
Spuštěný z: c:\users\Dusan\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Keyword Search
c:\users\Dusan\AppData\Local\GoalServer2009.exe
c:\users\Dusan\AppData\Local\GoalWebServer2009.exe
c:\users\Dusan\AppData\Local\HamachiSetup-1.0.3.0-en.exe
c:\users\Dusan\AppData\Local\libeay32.dll
c:\users\Dusan\AppData\Local\libssl32.dll
c:\users\Dusan\AppData\Local\stunnel.exe
c:\users\Dusan\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
c:\users\Dusan\AppData\Roaming\logs.dat
c:\users\Dusan\Documents\~WRL3531.tmp
c:\windows\Install
c:\windows\install\messenger.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\muzapp.exe
c:\windows\Tasks\At2.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-01 do 2012-08-01 )))))))))))))))))))))))))))))))
.
.
2012-08-01 21:07 . 2012-08-01 21:07 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-01 21:07 . 2012-08-01 21:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-01 20:50 . 2012-08-01 20:50 -------- d-----w- c:\users\Dusan\AppData\Local\Apple Computer
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\users\Dusan\AppData\Roaming\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\programdata\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-01 20:28 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-01 19:51 . 2012-08-01 19:51 388096 ----a-r- c:\users\Dusan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-01 19:51 . 2012-08-01 19:51 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-31 09:55 . 2012-07-31 09:55 -------- d-----w- c:\program files (x86)\Lavalys
2012-07-14 19:01 . 2012-07-14 19:01 -------- d-----w- c:\windows\SysWow64\3073
2012-07-13 18:31 . 2012-07-13 18:31 -------- d-----w- c:\users\Guest\AppData\Local\Macromedia
2012-07-10 16:10 . 2012-06-04 07:59 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-07-10 16:10 . 2012-06-04 07:59 99384 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-07-08 07:30 . 2012-07-08 07:30 -------- d-----w- c:\users\Dusan\AppData\Local\Macromedia
2012-07-05 16:45 . 2012-07-05 16:45 5030088 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-03 21:30 . 2012-07-03 21:31 -------- d-----w- c:\users\Dusan\AppData\Local\Facebook
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 15:19 . 2012-04-03 09:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-27 15:19 . 2011-10-23 01:51 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-26 07:02 . 2011-09-16 09:54 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-06-26 07:02 . 2011-09-16 09:54 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-06-05 12:22 . 2012-06-05 12:22 772552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-06-05 12:22 . 2010-09-22 23:46 687560 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-02 22:19 . 2012-06-22 07:33 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 07:33 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 07:34 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 07:34 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 07:33 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 07:33 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 07:33 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-22 07:33 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 07:33 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-16 21:19 . 2012-05-16 21:19 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-05-16 21:19 . 2012-05-16 21:19 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2011-09-11 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2011-09-11 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1C6A7DE2-27A9-337C-5162-777A023D70C9}]
2009-07-14 01:07 98304 ----a-w- c:\windows\SysWOW64\msoobjs.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-07-03 21432]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2012-06-04 3029112]
"Facebook Update"="c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-07-03 975288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-07-03 3524536]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-05-16 296056]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]
"DynamicUSB"="c:\program files (x86)\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 135664]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 250056]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-10-27 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-06-04 99384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 20552]
R3 DualCoreCenter;DualCoreCenter;c:\program files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys [2008-12-25 44344]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 135664]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 RushTopDevice_J;RushTopDevice_J;c:\program files (x86)\MSI\GreenPowerCenterII\RushJ64.sys [2009-03-04 33080]
R3 RushTopDevice2;RushTopDevice2;c:\program files (x86)\MSI\GreenPowerCenterII\RushTop64.sys [2008-12-17 75576]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-10-27 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-10-27 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-10-27 177640]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-06-04 203320]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-02 871408]
S1 aswSP;aswSP; [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2011-08-10 91864]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-07 202752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-01-19 63056]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-03-06 11576]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 15:19]
.
2012-07-21 c:\windows\Tasks\At1.job
- c:\windows\SysWOW64\waiitfor.exe [2009-07-13 01:14]
.
2012-07-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
- c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-03 21:36]
.
2012-08-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
- c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-03 21:36]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 21:07]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 21:07]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
- c:\users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-12 19:23]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
- c:\users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-12 19:23]
.
2012-07-31 c:\windows\Tasks\Norton Security Scan for Dusan.job
- c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe [2012-05-17 09:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-30 7574048]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-30 1833504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.155.229.197 213.155.255.12
FF - ProfilePath - c:\users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\5wdkzubo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/?charset=UTF-8 ... rch-web&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=230512_54x
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.hardId - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15494
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:55
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Citrix\ICA Client\ssonsvr.exe
c:\program files (x86)\Citrix\ICA Client\WFCRUN32.EXE
c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
c:\program files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
.
**************************************************************************
.
Celkový čas: 2012-08-01 23:13:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-01 21:13
.
Před spuštěním: 85 700 657 152 bytes free
Po spuštění: 85 379 530 752 bytes free
.
- - End Of File - - 539DC97D005C6BB6232F6FDE59CB1A0C
ComboFix 12-07-31.03 - Dusan 01.08.2012 22:59:38.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.4094.2546 [GMT 2:00]
Spuštěný z: c:\users\Dusan\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Keyword Search
c:\users\Dusan\AppData\Local\GoalServer2009.exe
c:\users\Dusan\AppData\Local\GoalWebServer2009.exe
c:\users\Dusan\AppData\Local\HamachiSetup-1.0.3.0-en.exe
c:\users\Dusan\AppData\Local\libeay32.dll
c:\users\Dusan\AppData\Local\libssl32.dll
c:\users\Dusan\AppData\Local\stunnel.exe
c:\users\Dusan\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
c:\users\Dusan\AppData\Roaming\logs.dat
c:\users\Dusan\Documents\~WRL3531.tmp
c:\windows\Install
c:\windows\install\messenger.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\muzapp.exe
c:\windows\Tasks\At2.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-01 do 2012-08-01 )))))))))))))))))))))))))))))))
.
.
2012-08-01 21:07 . 2012-08-01 21:07 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-01 21:07 . 2012-08-01 21:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-01 20:50 . 2012-08-01 20:50 -------- d-----w- c:\users\Dusan\AppData\Local\Apple Computer
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\users\Dusan\AppData\Roaming\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\programdata\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-01 20:28 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-01 19:51 . 2012-08-01 19:51 388096 ----a-r- c:\users\Dusan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-01 19:51 . 2012-08-01 19:51 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-31 09:55 . 2012-07-31 09:55 -------- d-----w- c:\program files (x86)\Lavalys
2012-07-14 19:01 . 2012-07-14 19:01 -------- d-----w- c:\windows\SysWow64\3073
2012-07-13 18:31 . 2012-07-13 18:31 -------- d-----w- c:\users\Guest\AppData\Local\Macromedia
2012-07-10 16:10 . 2012-06-04 07:59 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-07-10 16:10 . 2012-06-04 07:59 99384 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-07-08 07:30 . 2012-07-08 07:30 -------- d-----w- c:\users\Dusan\AppData\Local\Macromedia
2012-07-05 16:45 . 2012-07-05 16:45 5030088 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-03 21:30 . 2012-07-03 21:31 -------- d-----w- c:\users\Dusan\AppData\Local\Facebook
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 15:19 . 2012-04-03 09:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-27 15:19 . 2011-10-23 01:51 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-26 07:02 . 2011-09-16 09:54 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-06-26 07:02 . 2011-09-16 09:54 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-06-05 12:22 . 2012-06-05 12:22 772552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-06-05 12:22 . 2010-09-22 23:46 687560 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-02 22:19 . 2012-06-22 07:33 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 07:33 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 07:34 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 07:34 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 07:33 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 07:33 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 07:33 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-22 07:33 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 07:33 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-16 21:19 . 2012-05-16 21:19 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-05-16 21:19 . 2012-05-16 21:19 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2011-09-11 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2011-09-11 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1C6A7DE2-27A9-337C-5162-777A023D70C9}]
2009-07-14 01:07 98304 ----a-w- c:\windows\SysWOW64\msoobjs.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-07-03 21432]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2012-06-04 3029112]
"Facebook Update"="c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-07-03 975288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-07-03 3524536]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-05-16 296056]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]
"DynamicUSB"="c:\program files (x86)\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 135664]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 250056]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-10-27 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-06-04 99384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 20552]
R3 DualCoreCenter;DualCoreCenter;c:\program files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys [2008-12-25 44344]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 135664]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 RushTopDevice_J;RushTopDevice_J;c:\program files (x86)\MSI\GreenPowerCenterII\RushJ64.sys [2009-03-04 33080]
R3 RushTopDevice2;RushTopDevice2;c:\program files (x86)\MSI\GreenPowerCenterII\RushTop64.sys [2008-12-17 75576]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-10-27 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-10-27 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-10-27 177640]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-06-04 203320]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-02 871408]
S1 aswSP;aswSP; [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2011-08-10 91864]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-07 202752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-01-19 63056]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-03-06 11576]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 15:19]
.
2012-07-21 c:\windows\Tasks\At1.job
- c:\windows\SysWOW64\waiitfor.exe [2009-07-13 01:14]
.
2012-07-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
- c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-03 21:36]
.
2012-08-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
- c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-03 21:36]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 21:07]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-12-06 21:07]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
- c:\users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-12 19:23]
.
2012-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
- c:\users\Dusan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-12 19:23]
.
2012-07-31 c:\windows\Tasks\Norton Security Scan for Dusan.job
- c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe [2012-05-17 09:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-30 7574048]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-30 1833504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.155.229.197 213.155.255.12
FF - ProfilePath - c:\users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\5wdkzubo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/?charset=UTF-8 ... rch-web&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=230512_54x
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.hardId - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15494
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:55
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Citrix\ICA Client\ssonsvr.exe
c:\program files (x86)\Citrix\ICA Client\WFCRUN32.EXE
c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
c:\program files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
.
**************************************************************************
.
Celkový čas: 2012-08-01 23:13:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-01 21:13
.
Před spuštěním: 85 700 657 152 bytes free
Po spuštění: 85 379 530 752 bytes free
.
- - End Of File - - 539DC97D005C6BB6232F6FDE59CB1A0C
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu LOGU
Odinstaluj:
Norton Security Scan
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\windows\system32\user32.dll
c:\windows\SysWOW64\msoobjs.dll
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Norton Security Scan
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
Collect::
c:\windows\SysWOW64\waiitfor.exe
File::
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater\Updater.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
c:\windows\Tasks\Norton Security Scan for Dusan.job
c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe
Folder::
c:\progra~2\NORTON~2
DirLook::
c:\windows\SysWow64\3073
Driver::
gupdatem
gupdate
SkypeUpdate
Firefox::
FF - ProfilePath - c:\users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\5wdkzubo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=230512_54x
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.hardId - 7a8e664d00000000000040618601e903
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15494
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:55
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\windows\system32\user32.dll
c:\windows\SysWOW64\msoobjs.dll
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu LOGU
ComboFix 12-07-31.03 - Dusan 02.08.2012 9:44.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.4094.2675 [GMT 2:00]
Spuštěný z: c:\users\Dusan\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Dusan\Documents\CFScript.txt
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe"
"c:\program files (x86)\Google\Update\GoogleUpdate.exe"
"c:\program files (x86)\Skype\Updater\Updater.exe"
"c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job"
"c:\windows\Tasks\Norton Security Scan for Dusan.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater\Updater.exe
c:\programdata\boost_interprocess\20120802084936.125599
c:\programdata\boost_interprocess\20120802084936.125599\plex_frame_mutex
c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\users\Dusan\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
c:\windows\SysWOW64\waiitfor.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-02 do 2012-08-02 )))))))))))))))))))))))))))))))
.
.
2012-08-02 07:50 . 2012-08-02 07:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-02 07:07 . 2012-08-02 07:07 -------- d-----w- c:\users\Guest\AppData\Local\Adobe
2012-08-01 21:13 . 2012-08-02 07:50 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-01 20:50 . 2012-08-01 20:50 -------- d-----w- c:\users\Dusan\AppData\Local\Apple Computer
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\users\Dusan\AppData\Roaming\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\programdata\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-01 20:28 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-01 19:51 . 2012-08-01 19:51 388096 ----a-r- c:\users\Dusan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-01 19:51 . 2012-08-01 19:51 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-31 09:55 . 2012-07-31 09:55 -------- d-----w- c:\program files (x86)\Lavalys
2012-07-14 19:01 . 2012-07-14 19:01 -------- d-----w- c:\windows\SysWow64\3073
2012-07-13 18:31 . 2012-07-13 18:31 -------- d-----w- c:\users\Guest\AppData\Local\Macromedia
2012-07-10 16:10 . 2012-06-04 07:59 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-07-10 16:10 . 2012-06-04 07:59 99384 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-07-08 07:30 . 2012-07-08 07:30 -------- d-----w- c:\users\Dusan\AppData\Local\Macromedia
2012-07-05 16:45 . 2012-07-05 16:45 5030088 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-03 21:30 . 2012-07-03 21:31 -------- d-----w- c:\users\Dusan\AppData\Local\Facebook
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 15:19 . 2012-04-03 09:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-27 15:19 . 2011-10-23 01:51 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-26 07:02 . 2011-09-16 09:54 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-06-26 07:02 . 2011-09-16 09:54 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-06-05 12:22 . 2012-06-05 12:22 772552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-06-05 12:22 . 2010-09-22 23:46 687560 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-02 22:19 . 2012-06-22 07:33 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 07:33 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 07:34 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 07:34 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 07:33 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 07:33 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 07:33 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-22 07:33 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 07:33 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-16 21:19 . 2012-05-16 21:19 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-05-16 21:19 . 2012-05-16 21:19 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\SysWow64\3073 ----
.
2012-07-14 19:01 . 2012-08-01 20:19 6376 ----a-w- c:\windows\SysWow64\3073\inf3073.dat
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2011-09-11 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2011-09-11 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-08-01_21.08.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-08-02 06:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-02 06:50 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-02 06:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:10 . 2012-08-02 06:52 33938 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-02 05:07 . 2012-08-01 21:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 05:07 . 2012-08-02 07:53 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 05:07 . 2012-08-02 07:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-02 05:07 . 2012-08-01 21:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-02 07:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 21:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-02 22:08 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 22:08 . 2012-08-02 07:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 22:08 . 2012-08-02 07:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-02 22:08 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-31 10:56 . 2012-08-02 06:52 8770 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-854367754-585167149-2272254232-501_UserData.bin
- 2011-07-31 10:56 . 2012-08-01 14:06 8770 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-854367754-585167149-2272254232-501_UserData.bin
- 2012-08-01 21:08 . 2012-08-01 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-02 07:52 . 2012-08-02 07:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-08-01 21:08 . 2012-08-01 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-08-02 07:52 . 2012-08-02 07:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-02 05:29 . 2012-08-02 07:56 104066 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:12 . 2012-08-01 21:09 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2012-08-02 07:53 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:01 . 2012-08-02 07:51 393924 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-08-01 21:07 393924 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-14 19:04 . 2012-08-02 07:51 1169908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-501-8192.dat
- 2011-08-14 19:04 . 2012-08-01 20:47 1169908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-501-8192.dat
+ 2010-12-28 19:47 . 2012-08-02 07:51 2217424 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-1000-12288.dat
- 2010-12-28 19:47 . 2012-08-01 21:07 2217424 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-1000-12288.dat
+ 2009-07-14 02:34 . 2012-08-02 07:04 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2012-08-01 21:02 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1C6A7DE2-27A9-337C-5162-777A023D70C9}]
2009-07-14 01:07 98304 ----a-w- c:\windows\SysWOW64\msoobjs.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-07-03 21432]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2012-06-04 3029112]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-07-03 975288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-07-03 3524536]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-05-16 296056]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]
"DynamicUSB"="c:\program files (x86)\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 250056]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-10-27 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-06-04 99384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 20552]
R3 DualCoreCenter;DualCoreCenter;c:\program files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys [2008-12-25 44344]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 RushTopDevice_J;RushTopDevice_J;c:\program files (x86)\MSI\GreenPowerCenterII\RushJ64.sys [2009-03-04 33080]
R3 RushTopDevice2;RushTopDevice2;c:\program files (x86)\MSI\GreenPowerCenterII\RushTop64.sys [2008-12-17 75576]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-10-27 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-10-27 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-10-27 177640]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-06-04 203320]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-02 871408]
S1 aswSP;aswSP; [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2011-08-10 91864]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-07 202752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-01-19 63056]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-03-06 11576]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 15:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-30 7574048]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-30 1833504]
"combofix"="c:\combofix\CF4805.3XE" [2009-07-14 344576]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.155.229.197 213.155.255.12
FF - ProfilePath - c:\users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\5wdkzubo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/?charset=UTF-8 ... rch-web&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=230512_54x
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Facebook Update - c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Citrix\ICA Client\ssonsvr.exe
c:\program files (x86)\Citrix\ICA Client\WFCRUN32.EXE
c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
c:\program files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
.
**************************************************************************
.
Celkový čas: 2012-08-02 09:58:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-02 07:58
ComboFix2.txt 2012-08-01 21:13
.
Před spuštěním: 85 831 856 128 bytes free
Po spuštění: 85 352 726 528 bytes free
.
- - End Of File - - B23ABB5065F1F814545CE974A73389A6
Nahr nˇ probŘhlo ŁspŘçnŘ
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1033.18.4094.2675 [GMT 2:00]
Spuštěný z: c:\users\Dusan\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Dusan\Documents\CFScript.txt
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\progra~2\NORTON~2\Engine\372~1.5\Nss.exe"
"c:\program files (x86)\Google\Update\GoogleUpdate.exe"
"c:\program files (x86)\Skype\Updater\Updater.exe"
"c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job"
"c:\windows\Tasks\Norton Security Scan for Dusan.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Skype\Updater\Updater.exe
c:\programdata\boost_interprocess\20120802084936.125599
c:\programdata\boost_interprocess\20120802084936.125599\plex_frame_mutex
c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\users\Dusan\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
c:\windows\SysWOW64\waiitfor.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854367754-585167149-2272254232-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-02 do 2012-08-02 )))))))))))))))))))))))))))))))
.
.
2012-08-02 07:50 . 2012-08-02 07:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-02 07:07 . 2012-08-02 07:07 -------- d-----w- c:\users\Guest\AppData\Local\Adobe
2012-08-01 21:13 . 2012-08-02 07:50 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-01 20:50 . 2012-08-01 20:50 -------- d-----w- c:\users\Dusan\AppData\Local\Apple Computer
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\users\Dusan\AppData\Roaming\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\programdata\Malwarebytes
2012-08-01 20:28 . 2012-08-01 20:28 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-01 20:28 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-01 19:51 . 2012-08-01 19:51 388096 ----a-r- c:\users\Dusan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-08-01 19:51 . 2012-08-01 19:51 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-31 09:55 . 2012-07-31 09:55 -------- d-----w- c:\program files (x86)\Lavalys
2012-07-14 19:01 . 2012-07-14 19:01 -------- d-----w- c:\windows\SysWow64\3073
2012-07-13 18:31 . 2012-07-13 18:31 -------- d-----w- c:\users\Guest\AppData\Local\Macromedia
2012-07-10 16:10 . 2012-06-04 07:59 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-07-10 16:10 . 2012-06-04 07:59 99384 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-07-08 07:30 . 2012-07-08 07:30 -------- d-----w- c:\users\Dusan\AppData\Local\Macromedia
2012-07-05 16:45 . 2012-07-05 16:45 5030088 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-03 21:30 . 2012-07-03 21:31 -------- d-----w- c:\users\Dusan\AppData\Local\Facebook
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 15:19 . 2012-04-03 09:52 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-27 15:19 . 2011-10-23 01:51 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-26 07:02 . 2011-09-16 09:54 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-06-26 07:02 . 2011-09-16 09:54 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-06-05 12:22 . 2012-06-05 12:22 772552 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-06-05 12:22 . 2010-09-22 23:46 687560 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-02 22:19 . 2012-06-22 07:33 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 07:33 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 07:34 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 07:34 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 07:33 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 07:33 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 07:33 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-22 07:33 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 07:33 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-16 21:19 . 2012-05-16 21:19 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-05-16 21:19 . 2012-05-16 21:19 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\SysWow64\3073 ----
.
2012-07-14 19:01 . 2012-08-01 20:19 6376 ----a-w- c:\windows\SysWow64\3073\inf3073.dat
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2011-09-11 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2011-09-11 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2012-08-01_21.08.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-08-02 06:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-02 06:50 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-02 06:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 10:22 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:10 . 2012-08-02 06:52 33938 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-02 05:07 . 2012-08-01 21:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 05:07 . 2012-08-02 07:53 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 05:07 . 2012-08-02 07:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-02 05:07 . 2012-08-01 21:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-02 07:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-01 21:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-18 14:48 . 2012-08-02 07:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-18 14:48 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-02 22:08 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 22:08 . 2012-08-02 07:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-02 22:08 . 2012-08-02 07:55 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-02 22:08 . 2012-08-01 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-31 10:56 . 2012-08-02 06:52 8770 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-854367754-585167149-2272254232-501_UserData.bin
- 2011-07-31 10:56 . 2012-08-01 14:06 8770 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-854367754-585167149-2272254232-501_UserData.bin
- 2012-08-01 21:08 . 2012-08-01 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-02 07:52 . 2012-08-02 07:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-08-01 21:08 . 2012-08-01 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-08-02 07:52 . 2012-08-02 07:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-02 05:29 . 2012-08-02 07:56 104066 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:12 . 2012-08-01 21:09 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2012-08-02 07:53 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:01 . 2012-08-02 07:51 393924 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-08-01 21:07 393924 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-14 19:04 . 2012-08-02 07:51 1169908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-501-8192.dat
- 2011-08-14 19:04 . 2012-08-01 20:47 1169908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-501-8192.dat
+ 2010-12-28 19:47 . 2012-08-02 07:51 2217424 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-1000-12288.dat
- 2010-12-28 19:47 . 2012-08-01 21:07 2217424 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-854367754-585167149-2272254232-1000-12288.dat
+ 2009-07-14 02:34 . 2012-08-02 07:04 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2012-08-01 21:02 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1C6A7DE2-27A9-337C-5162-777A023D70C9}]
2009-07-14 01:07 98304 ----a-w- c:\windows\SysWOW64\msoobjs.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-07-03 21432]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2012-06-04 3029112]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-07-03 975288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-17 421888]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-07-03 3524536]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-05-16 296056]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]
"DynamicUSB"="c:\program files (x86)\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Dusan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 250056]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-10-27 36328]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-06-04 99384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 20552]
R3 DualCoreCenter;DualCoreCenter;c:\program files (x86)\MSI\GreenPowerCenterII\NTGLM7X64.sys [2008-12-25 44344]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 RushTopDevice_J;RushTopDevice_J;c:\program files (x86)\MSI\GreenPowerCenterII\RushJ64.sys [2009-03-04 33080]
R3 RushTopDevice2;RushTopDevice2;c:\program files (x86)\MSI\GreenPowerCenterII\RushTop64.sys [2008-12-17 75576]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-10-27 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-10-27 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-10-27 177640]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-06-04 203320]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-02 871408]
S1 aswSP;aswSP; [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2011-08-10 91864]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-07 202752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-01-19 63056]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\PandoraService.exe [2011-12-21 578264]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-05 3048136]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2007-03-06 11576]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 15:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-30 7574048]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-30 1833504]
"combofix"="c:\combofix\CF4805.3XE" [2009-07-14 344576]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.155.229.197 213.155.255.12
FF - ProfilePath - c:\users\Dusan\AppData\Roaming\Mozilla\Firefox\Profiles\5wdkzubo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/?charset=UTF-8 ... rch-web&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=230512_54x
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Facebook Update - c:\users\Dusan\AppData\Local\Facebook\Update\FacebookUpdate.exe
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Citrix\ICA Client\ssonsvr.exe
c:\program files (x86)\Citrix\ICA Client\WFCRUN32.EXE
c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
c:\program files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
.
**************************************************************************
.
Celkový čas: 2012-08-02 09:58:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-02 07:58
ComboFix2.txt 2012-08-01 21:13
.
Před spuštěním: 85 831 856 128 bytes free
Po spuštění: 85 352 726 528 bytes free
.
- - End Of File - - B23ABB5065F1F814545CE974A73389A6
Nahr nˇ probŘhlo ŁspŘçnŘ
Re: Prosím o kontrolu LOGU
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:01:59, on 2.8.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {1C6A7DE2-27A9-337C-5162-777A023D70C9} - C:\Windows\SysWow64\msoobjs.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [DynamicUSB] "C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService.exe) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13257 bytes
Scan saved at 10:01:59, on 2.8.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {1C6A7DE2-27A9-337C-5162-777A023D70C9} - C:\Windows\SysWow64\msoobjs.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [DynamicUSB] "C:\Program Files (x86)\DynamicUSBTool\DynamicUSB.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService.exe) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13257 bytes
Re: Prosím o kontrolu LOGU
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-02 10:04:27
-----------------------------
10:04:27.616 OS Version: Windows x64 6.1.7600
10:04:27.616 Number of processors: 4 586 0x402
10:04:27.617 ComputerName: DUSAN-PC UserName: Dusan
10:04:30.011 Initialize success
10:04:30.093 AVAST engine defs: 10022201
10:04:35.404 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-4
10:04:35.405 Disk 0 Vendor: ST3250620AS 3.AAE Size: 238475MB BusType: 3
10:04:35.407 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3
10:04:35.408 Disk 1 Vendor: WDC_WD7501AALS-00E8B0 05.00K05 Size: 715404MB BusType: 3
10:04:35.419 Disk 1 MBR read successfully
10:04:35.421 Disk 1 MBR scan
10:04:35.423 Disk 1 Windows 7 default MBR code
10:04:35.429 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
10:04:35.434 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 715302 MB offset 206848
10:04:35.444 Disk 1 scanning C:\Windows\system32\drivers
10:04:39.829 Service scanning
10:04:46.853 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
10:04:49.439 Modules scanning
10:04:49.443 Disk 1 trace - called modules:
10:04:49.460 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80046d42c0]<<splg.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
10:04:49.463 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8004b26060]
10:04:49.466 3 CLASSPNP.SYS[fffff880013ca43f] -> nt!IofCallDriver -> [0xfffffa80049769b0]
10:04:49.469 5 ACPI.sys[fffff8800100b781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa8004a8b060]
10:04:49.472 \Driver\atapi[0xfffffa80047fe230] -> IRP_MJ_CREATE -> 0xfffffa80046d42c0
10:04:51.322 AVAST engine scan C:\Windows
10:04:53.843 AVAST engine scan C:\Windows\system32
10:06:10.241 AVAST engine scan C:\Windows\system32\drivers
10:06:16.608 AVAST engine scan C:\Users\Dusan
10:23:45.226 AVAST engine scan C:\ProgramData
10:26:44.543 Scan finished successfully
10:30:55.092 Disk 1 MBR has been saved successfully to "C:\Users\Dusan\Documents\MBR.dat"
10:30:55.097 The log file has been saved successfully to "C:\Users\Dusan\Documents\aswMBR.txt"
Run date: 2012-08-02 10:04:27
-----------------------------
10:04:27.616 OS Version: Windows x64 6.1.7600
10:04:27.616 Number of processors: 4 586 0x402
10:04:27.617 ComputerName: DUSAN-PC UserName: Dusan
10:04:30.011 Initialize success
10:04:30.093 AVAST engine defs: 10022201
10:04:35.404 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-4
10:04:35.405 Disk 0 Vendor: ST3250620AS 3.AAE Size: 238475MB BusType: 3
10:04:35.407 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3
10:04:35.408 Disk 1 Vendor: WDC_WD7501AALS-00E8B0 05.00K05 Size: 715404MB BusType: 3
10:04:35.419 Disk 1 MBR read successfully
10:04:35.421 Disk 1 MBR scan
10:04:35.423 Disk 1 Windows 7 default MBR code
10:04:35.429 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
10:04:35.434 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 715302 MB offset 206848
10:04:35.444 Disk 1 scanning C:\Windows\system32\drivers
10:04:39.829 Service scanning
10:04:46.853 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
10:04:49.439 Modules scanning
10:04:49.443 Disk 1 trace - called modules:
10:04:49.460 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80046d42c0]<<splg.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
10:04:49.463 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8004b26060]
10:04:49.466 3 CLASSPNP.SYS[fffff880013ca43f] -> nt!IofCallDriver -> [0xfffffa80049769b0]
10:04:49.469 5 ACPI.sys[fffff8800100b781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa8004a8b060]
10:04:49.472 \Driver\atapi[0xfffffa80047fe230] -> IRP_MJ_CREATE -> 0xfffffa80046d42c0
10:04:51.322 AVAST engine scan C:\Windows
10:04:53.843 AVAST engine scan C:\Windows\system32
10:06:10.241 AVAST engine scan C:\Windows\system32\drivers
10:06:16.608 AVAST engine scan C:\Users\Dusan
10:23:45.226 AVAST engine scan C:\ProgramData
10:26:44.543 Scan finished successfully
10:30:55.092 Disk 1 MBR has been saved successfully to "C:\Users\Dusan\Documents\MBR.dat"
10:30:55.097 The log file has been saved successfully to "C:\Users\Dusan\Documents\aswMBR.txt"
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 86 hostů